v17.7.11

gravitational/teleportv17.7.11Dec 9, 2025by doggydogworld

AI Summary

Performance and stability release addressing memory consumption issues, database connectivity, and various bug fixes across multiple components.

Key Highlights

  • Reduced memory consumption of Application service
  • Fixed high memory consumption in Auth Service when listing large resources
  • Fixed tsh db connect in non-TLS routing mode
  • Added Workload Identities page to web UI
  • Fixed Kubernetes App Discovery poll_interval
  • Fixed AWS Console access with IP Pinning enabled

New Features

  • Memory optimizations
  • Database connectivity fixes
  • Web UI additions

Full Release Notes

## Description

* Reduced memory consumption of the Application service. [#62013](https://github.com/gravitational/teleport/pull/62013)
* Prevented stuck `teleport-cluster` Helm chart rollouts in small Kubernetes clusters. Removed resource requests from configuration check hooks. [#62004](https://github.com/gravitational/teleport/pull/62004)
* Updated Go to 1.24.11. [#61954](https://github.com/gravitational/teleport/pull/61954)
* Updates `tsh workload-identity issue-x509` to automatically create the specified folder if it does not exist. [#61951](https://github.com/gravitational/teleport/pull/61951)
* Fixed a bug where JWT-SVID timestamp claims would be represented using scientific notation. [#61922](https://github.com/gravitational/teleport/pull/61922)
* Fixed a bug causing high memory consumption in the Teleport Auth Service when clients were listing large resources. [#61848](https://github.com/gravitational/teleport/pull/61848)
* Prevent data races when terminating interactive Kubernetes sessions. [#61822](https://github.com/gravitational/teleport/pull/61822)
* Fix `tsh db connect` failing to connect to databases using separate ports configuration (non-TLS routing mode). [#61811](https://github.com/gravitational/teleport/pull/61811)
* Fixed bug where Kubernetes App Discovery `poll_interval` is not set correctly. [#61792](https://github.com/gravitational/teleport/pull/61792)
* Fixed relative path evaluation for SFTP in proxy recording mode. [#61759](https://github.com/gravitational/teleport/pull/61759)
* Fixed `tsh kube ls` showing deleted clusters. [#61743](https://github.com/gravitational/teleport/pull/61743)
* Fixed workload identity templating to support certain numeric values that previously gave a "expression did not evaluate to a string" error. [#61739](https://github.com/gravitational/teleport/pull/61739)
* Fixed AWS Console access when using AWS IAM Roles Anywhere or AWS OIDC integrations, when IP Pinning is enabled. [#61655](https://github.com/gravitational/teleport/pull/61655)
* Added ability to update existing Azure OIDC integration with `tctl`. [#61593](https://github.com/gravitational/teleport/pull/61593)
* Prevented Trivy from reporting false positives when scanning the Teleport binaries. [#61540](https://github.com/gravitational/teleport/pull/61540)
* Updated tsh debug output to include tsh client version when --debug flag is set. [#61526](https://github.com/gravitational/teleport/pull/61526)
* Fixed web upload/download failure behind load balancers when web listen address is unspecified. [#61394](https://github.com/gravitational/teleport/pull/61394)
* Fixed corrupted private keys breaking tsh. [#61387](https://github.com/gravitational/teleport/pull/61387)
* Fix an issue connections to MongoDB Atlas clusters fail if clusters use certs signed by Google Trust Services (GTS). [#61325](https://github.com/gravitational/teleport/pull/61325)
* GOAWAY errors received from Kubernetes API Servers configured with a non-zero --goaway-chance are now forward to clients to be retried. [#61255](https://github.com/gravitational/teleport/pull/61255)
* Added a Workload Identities page to the web UI to list workload identities. [#59478](https://github.com/gravitational/teleport/pull/59478)

## Download

Download the current and previous releases of Teleport at https://goteleport.com/download.

## Plugins

Download the current release of Teleport plugins from the links below.
* Slack [Linux amd64](https://cdn.teleport.dev/teleport-access-slack-v17.7.11-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-slack-v17.7.11-linux-arm64-bin.tar.gz) 
* Mattermost [Linux amd64](https://cdn.teleport.dev/teleport-access-mattermost-v17.7.11-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-mattermost-v17.7.11-linux-arm64-bin.tar.gz)
* Discord [Linux amd64](https://cdn.teleport.dev/teleport-access-discord-v17.7.11-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-discord-v17.7.11-linux-arm64-bin.tar.gz)
* Terraform Provider [Linux amd64](https://cdn.teleport.dev/terraform-provider-teleport-v17.7.11-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/terraform-provider-teleport-v17.7.11-linux-arm64-bin.tar.gz) | [macOS amd64](https://cdn.teleport.dev/terraform-provider-teleport-v17.7.11-darwin-amd64-bin.tar.gz) | [macOS arm64](https://cdn.teleport.dev/terraform-provider-teleport-v17.7.11-darwin-arm64-bin.tar.gz) | [macOS universal](https://cdn.teleport.dev/terraform-provider-teleport-v17.7.11-darwin-universal-bin.tar.gz)
* Event Handler [Linux amd64](https://cdn.teleport.dev/teleport-event-handler-v17.7.11-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-event-handler-v17.7.11-linux-arm64-bin.tar.gz) | [macOS amd64](https://cdn.teleport.dev/teleport-event-handler-v17.7.11-darwin-amd64-bin.tar.gz)
* PagerDuty [Linux amd64](https://cdn.teleport.dev/teleport-access-pagerduty-v17.7.11-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-pagerduty-v17.7.11-linux-arm64-bin.tar.gz)
* Jira [Linux amd64](https://cdn.teleport.dev/teleport-access-jira-v17.7.11-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-jira-v17.7.11-linux-arm64-bin.tar.gz)
* Email [Linux amd64](https://cdn.teleport.dev/teleport-access-email-v17.7.11-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-email-v17.7.11-linux-arm64-bin.tar.gz)
* Microsoft Teams [Linux amd64](https://cdn.teleport.dev/teleport-access-msteams-v17.7.11-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-msteams-v17.7.11-linux-arm64-bin.tar.gz)