v18.1.5
gravitational/teleportv18.1.5Aug 19, 2025by doggydogworld
AI Summary
Teleport v18.1.5 is a patch release that fixes multiple issues including AWS CLI access with OIDC integration, Windows desktop connection problems, and various bugs. Note: This release includes a regression that prevents connecting to Windows desktops via the Web UI, with workarounds available including using Teleport Connect or changing keyboard layout settings.
Key Highlights
- Fix AWS CLI access using AWS OIDC integration
- Updated Go to 1.24.6 for improved performance and security
- Added CockroachDB support for Database MCP server with web access and session playback
- New OIDC joining mode for Kubernetes delegated joining supporting EKS, AKS, and GKE
- Device Trust now supports `required-for-humans` mode to enforce device enrollment for humans while allowing bots on unenrolled devices
New Features
- teleport-kube-agent Helm chart now supports kubernetes joining with `teleportClusterName` config
- Database MCP server now supports CockroachDB databases
- Added `--auth` flag to `tctl plugins install scim` for Bearer token and OAuth authentication
- Teleport `event-handler` now accepts HTTP Status Code 204 for Grafana Alloy and newer Fluentd support
- Added `--force` option to `tctl workload-identity x509-issuer-overrides sign-csrs` for HSM clusters
- `tctl top` can now display raw Prometheus metrics
- Added `TeleportDatabaseV3` and `TeleportAppV3` support to Teleport Kubernetes Operator
- Enriched windows.desktop.session.start audit event with certificate metadata
- Allow use of ResourceGroupsTaggingApi for KMS Key deletion
- Enterprise: Allow OIDC authentication to complete without email verification when connector is configured accordingly
Full Release Notes
> [!WARNING] > This release includes a regression that prevents connecting to Windows desktops via the Web UI. > > The following workarounds are available: > - Downgrade proxy servers to 18.1.4 > - Use Teleport Connect instead of the web UI to access desktops > - Set your preferred keyboard layout (under account settings) to something other than _system_ ## Description * Fix AWS CLI access using AWS OIDC integration. [#57977](https://github.com/gravitational/teleport/pull/57977) * Fixed an issue that could cause revocation checks to fail in Windows environments. [#57880](https://github.com/gravitational/teleport/pull/57880) * Fixed the case where the auto-updated client tools did not use the intended version. [#57870](https://github.com/gravitational/teleport/pull/57870) * Bound Keypair Joining: Fix lock generation on sequence desync. [#57863](https://github.com/gravitational/teleport/pull/57863) * Fix database PKINIT issues caused missing CDP information in the certificate. [#57850](https://github.com/gravitational/teleport/pull/57850) * Fixed connection issues to Windows Desktop Services (v17 or earlier) in Teleport Connect. [#57842](https://github.com/gravitational/teleport/pull/57842) * The teleport-kube-agent Helm chart now supports kubernetes joining. `teleportClusterName` must be set to enable the feature. [#57824](https://github.com/gravitational/teleport/pull/57824) * Fixed the web UI's access request submission panel getting stuck when scrolling down the page. [#57797](https://github.com/gravitational/teleport/pull/57797) * Enroll new Kubernetes agents in Managed Updates. [#57784](https://github.com/gravitational/teleport/pull/57784) * Teleport now supports displaying more than 2k tokens. [#57772](https://github.com/gravitational/teleport/pull/57772) * Updated Go to 1.24.6. [#57764](https://github.com/gravitational/teleport/pull/57764) * Database MCP server now supports CockroachDB databases. [#57762](https://github.com/gravitational/teleport/pull/57762) * Added support for CockroachDB Web Access and interactive CockroachDB session playback. [#57762](https://github.com/gravitational/teleport/pull/57762) * Added the `--auth` flag to the `tctl plugins install scim` CLI command to support Bearer token and OAuth authentication methods. [#57759](https://github.com/gravitational/teleport/pull/57759) * Fix Alt+Click not being registered in remote desktop sessions. [#57757](https://github.com/gravitational/teleport/pull/57757) * Kubernetes Access: `kubectl port-forward` now exits cleanly when backend pods are removed. [#57738](https://github.com/gravitational/teleport/pull/57738) * Kubernetes Access: Fixed a bug when forwarding multiple ports to a single pod. [#57736](https://github.com/gravitational/teleport/pull/57736) * Fixed unlink-package during upgrade/downgrade. [#57720](https://github.com/gravitational/teleport/pull/57720) * Add new oidc joining mode for Kubernetes delegated joining to support providers that can be configured to provide public OIDC endpoints, like EKS, AKS, and GKE. [#57683](https://github.com/gravitational/teleport/pull/57683) * Teleport `event-handler` now accepts HTTP Status Code 204 from the recipient. This adds support for sending events to Grafana Alloy and newer Fluentd versions. [#57680](https://github.com/gravitational/teleport/pull/57680) * Enrich the windows.desktop.session.start audit event with additional certificate metadata. [#57676](https://github.com/gravitational/teleport/pull/57676) * Allow the use of ResourceGroupsTaggingApi for KMS Key deletion. [#57671](https://github.com/gravitational/teleport/pull/57671) * Added `--force` option to `tctl workload-identity x509-issuer-overrides sign-csrs` to allow displaying the output of partial failures, intended for use in clusters that make use of HSMs. [#57662](https://github.com/gravitational/teleport/pull/57662) * Tctl top can now display raw prometheus metrics. [#57632](https://github.com/gravitational/teleport/pull/57632) * Enable resource label conditions for notification routing rules. [#57616](https://github.com/gravitational/teleport/pull/57616) * Use the bot details page to view and edit bot configuration, and see active instances with their upgrade status. [#57542](https://github.com/gravitational/teleport/pull/57542) * Device Trust: added `required-for-humans` mode to allow bots to run on unenrolled devices, while enforcing checks for human users. [#57222](https://github.com/gravitational/teleport/pull/57222) * Add `TeleportDatabaseV3` support to the Teleport Kubernetes Operator. [#56948](https://github.com/gravitational/teleport/pull/56948) * Add `TeleportAppV3` support to the Teleport Kubernetes Operator. [#56948](https://github.com/gravitational/teleport/pull/56948) * Fix TELEPORT_SESSION and SSH_SESSION_ID environmental variables not matching in an SSH session. [#55272](https://github.com/gravitational/teleport/pull/55272) * Fix a potential state corruption of Teleport agents running against a Kubernetes backend. [#57733](https://github.com/gravitational/teleport/pull/57733) Enterprise: * Allow OIDC authentication to complete if email verification is not provided when the OIDC connecter is set to enforce verified email addresses. ## Download Download the current and previous releases of Teleport at https://goteleport.com/download. ## Plugins Download the current release of Teleport plugins from the links below. * Slack [Linux amd64](https://cdn.teleport.dev/teleport-access-slack-v18.1.5-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-slack-v18.1.5-linux-arm64-bin.tar.gz) * Mattermost [Linux amd64](https://cdn.teleport.dev/teleport-access-mattermost-v18.1.5-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-mattermost-v18.1.5-linux-arm64-bin.tar.gz) * Discord [Linux amd64](https://cdn.teleport.dev/teleport-access-discord-v18.1.5-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-discord-v18.1.5-linux-arm64-bin.tar.gz) * Terraform Provider [Linux amd64](https://cdn.teleport.dev/terraform-provider-teleport-v18.1.5-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/terraform-provider-teleport-v18.1.5-linux-arm64-bin.tar.gz) | [macOS amd64](https://cdn.teleport.dev/terraform-provider-teleport-v18.1.5-darwin-amd64-bin.tar.gz) | [macOS arm64](https://cdn.teleport.dev/terraform-provider-teleport-v18.1.5-darwin-arm64-bin.tar.gz) | [macOS universal](https://cdn.teleport.dev/terraform-provider-teleport-v18.1.5-darwin-universal-bin.tar.gz) * Event Handler [Linux amd64](https://cdn.teleport.dev/teleport-event-handler-v18.1.5-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-event-handler-v18.1.5-linux-arm64-bin.tar.gz) | [macOS amd64](https://cdn.teleport.dev/teleport-event-handler-v18.1.5-darwin-amd64-bin.tar.gz) * PagerDuty [Linux amd64](https://cdn.teleport.dev/teleport-access-pagerduty-v18.1.5-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-pagerduty-v18.1.5-linux-arm64-bin.tar.gz) * Jira [Linux amd64](https://cdn.teleport.dev/teleport-access-jira-v18.1.5-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-jira-v18.1.5-linux-arm64-bin.tar.gz) * Email [Linux amd64](https://cdn.teleport.dev/teleport-access-email-v18.1.5-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-email-v18.1.5-linux-arm64-bin.tar.gz) * Microsoft Teams [Linux amd64](https://cdn.teleport.dev/teleport-access-msteams-v18.1.5-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-msteams-v18.1.5-linux-arm64-bin.tar.gz)