v18.3.0
gravitational/teleportv18.3.0Oct 30, 2025by doggydogworld
AI Summary
Teleport v18.3.0 introduces several major features including a new Relay Service for optimized SSH connection routing, multi-cluster EC2 auto-discovery, Kubernetes health monitoring with automatic routing to healthy services, and ElastiCache Serverless database support. The release also enhances the web UI with workload identity listings and various bug fixes.
Key Highlights
- New Relay Service - lightweight proxy for SSH connections that bypasses the control plane for optimized network flows
- Multi-cluster Discovery - multiple Teleport clusters can discover the same EC2 instances independently
- Kubernetes Health Checks - continuous monitoring with automatic routing to healthy services displayed in web UI
- ElastiCache Serverless support for Database Access
- Web UI now lists all workload identity resources
New Features
- Web UI Workload Identity listing page
- Relay Service for SSH proxying
- Multi-cluster EC2 auto-discovery without interference
- Kubernetes cluster health monitoring with web UI status
- ElastiCache Serverless database connectivity
- SSO MFA browser window increased for QR codes
- Slack access plugin stability fix
- Okta-managed apps pinning in web UI
- GitLab join token management in Web UI
- tsh scp fix for files growing during transfer
- Moderated session peers can now perform file transfers
- AccessMonitoringRule regex conditions support
- SSE and streamable-HTTP MCP server support
- Workload Identities page in web UI
- Client tools managed updates store OS/ARCH for TELEPORT_HOME compatibility
Full Release Notes
## Description ### Web UI Workload ID Teleport's Web UI now lists all workload identity resources registered in the cluster. ### Relay Service Teleport now includes a new relay service that acts as a lightweight proxy service. This new service can receive connections from both SSH clients and agents. The relay service can be used to avoid routing SSH connections through the broader Teleport control plane, providing the ability to optimize network flows in large or complex deployments. ### Multi-cluster Discovery Multiple Teleport clusters can now discover the same EC2 instances simultaneously through auto-discovery, with each cluster operating independently without interference. ### Kubernetes Health Checks Teleport now continuously monitors the health of your registered Kubernetes clusters and displays their status directly in the web UI. When connecting to Kubernetes clusters, Teleport automatically routes you to healthy services, ensuring reliable access to your infrastructure. ### ElastiCache Serverless Teleport Database Access now supports connecting to ElastiCache Serverless databases. ### Other fixes and improvements * The browser window for SSO MFA is slightly taller in order to accommodate larger elements like QR codes. [#60703](https://github.com/gravitational/teleport/pull/60703) * Slack access plugin no longer crashes in the event access list is unsupported. [#60671](https://github.com/gravitational/teleport/pull/60671) * Okta-managed apps are now pinned correctly in the web UI. [#60667](https://github.com/gravitational/teleport/pull/60667) * Create and edit GitLab join tokens from the Web UI. [#60649](https://github.com/gravitational/teleport/pull/60649) * Teleport Connect now displays the profile name (instead of the cluster name) in the UI when referring to the profile; this affects only clusters where the cluster name was specifically set to something else than the proxy hostname during setup. [#60615](https://github.com/gravitational/teleport/pull/60615) * Fixed tsh scp failing on files that grow during transfer. [#60607](https://github.com/gravitational/teleport/pull/60607) * Allowed moderated session peers to perform file transfers. [#60604](https://github.com/gravitational/teleport/pull/60604) * Added support for regular expression conditions for AccessMonitoringRule. [#60598](https://github.com/gravitational/teleport/pull/60598) * Added support for SSE and streamable-HTTP MCP servers. [#60519](https://github.com/gravitational/teleport/pull/60519) * Added health checks for enrolled Kubernetes clusters. [#60492](https://github.com/gravitational/teleport/pull/60492) * MWI: `tbot`'s auto-generated service names are now simpler and easier to use in the `/readyz` endpoint. [#60458](https://github.com/gravitational/teleport/pull/60458) * Client tools managed updates stores OS and ARCH in the configuration. This ensures compatibility when `TELEPORT_HOME` directory is shared with a virtual instance running a different OS or architecture. [#60414](https://github.com/gravitational/teleport/pull/60414) * Added a Workload Identities page to the web UI to list workload identities. [#59479](https://github.com/gravitational/teleport/pull/59479) Enterprise: * Enabled Access Automation Rule schedule configuration within the WebUI. * Updated Entra ID plugin installation UI to support group filter configuration. * Okta: Allow changing time between importing Okta changes to Teleport from the default 30m with the new time_between_imports setting. ## Download Download the current and previous releases of Teleport at https://goteleport.com/download. ## Plugins Download the current release of Teleport plugins from the links below. * Slack [Linux amd64](https://cdn.teleport.dev/teleport-access-slack-v18.3.0-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-slack-v18.3.0-linux-arm64-bin.tar.gz) * Mattermost [Linux amd64](https://cdn.teleport.dev/teleport-access-mattermost-v18.3.0-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-mattermost-v18.3.0-linux-arm64-bin.tar.gz) * Discord [Linux amd64](https://cdn.teleport.dev/teleport-access-discord-v18.3.0-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-discord-v18.3.0-linux-arm64-bin.tar.gz) * Terraform Provider [Linux amd64](https://cdn.teleport.dev/terraform-provider-teleport-v18.3.0-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/terraform-provider-teleport-v18.3.0-linux-arm64-bin.tar.gz) | [macOS amd64](https://cdn.teleport.dev/terraform-provider-teleport-v18.3.0-darwin-amd64-bin.tar.gz) | [macOS arm64](https://cdn.teleport.dev/terraform-provider-teleport-v18.3.0-darwin-arm64-bin.tar.gz) | [macOS universal](https://cdn.teleport.dev/terraform-provider-teleport-v18.3.0-darwin-universal-bin.tar.gz) * Event Handler [Linux amd64](https://cdn.teleport.dev/teleport-event-handler-v18.3.0-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-event-handler-v18.3.0-linux-arm64-bin.tar.gz) | [macOS amd64](https://cdn.teleport.dev/teleport-event-handler-v18.3.0-darwin-amd64-bin.tar.gz) * PagerDuty [Linux amd64](https://cdn.teleport.dev/teleport-access-pagerduty-v18.3.0-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-pagerduty-v18.3.0-linux-arm64-bin.tar.gz) * Jira [Linux amd64](https://cdn.teleport.dev/teleport-access-jira-v18.3.0-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-jira-v18.3.0-linux-arm64-bin.tar.gz) * Email [Linux amd64](https://cdn.teleport.dev/teleport-access-email-v18.3.0-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-email-v18.3.0-linux-arm64-bin.tar.gz) * Microsoft Teams [Linux amd64](https://cdn.teleport.dev/teleport-access-msteams-v18.3.0-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-msteams-v18.3.0-linux-arm64-bin.tar.gz)