v1.13.9
hashicorp/vaultv1.13.9Oct 24, 2023by hc-github-team-es-release-engineering
AI Summary
Patch release for version 1.13.9 including Go 1.20.10 bump and improvements to plugin registration and storage replication stability.
Key Highlights
- Bumped Go version to 1.20.10
- Added `tls-server-name` argument for plugin registration
- Fixed deadlock in expiration manager preventing state changes
- Disabled encryption operations for cloud managed keys in Transit Engine
Full Release Notes
## 1.13.9 ### October 25, 2023 CHANGES: * core: Bump Go version to 1.20.10. * replication (enterprise): Switch to non-deprecated gRPC field for resolver target host IMPROVEMENTS: * api/plugins: add `tls-server-name` arg for plugin registration [[GH-23549](https://github.com/hashicorp/vault/pull/23549)] * core: Use a worker pool for the rollback manager. Add new metrics for the rollback manager to track the queued tasks. [[GH-22567](https://github.com/hashicorp/vault/pull/22567)] BUG FIXES: * command/server: Fix bug with sigusr2 where pprof files were not closed correctly [[GH-23636](https://github.com/hashicorp/vault/pull/23636)] * events: Ignore sending context to give more time for events to send [[GH-23500](https://github.com/hashicorp/vault/pull/23500)] * expiration: Prevent large lease loads from delaying state changes, e.g. becoming active or standby. [[GH-23282](https://github.com/hashicorp/vault/pull/23282)] * kmip (enterprise): Improve handling of failures due to storage replication issues. * kmip (enterprise): Return a structure in the response for query function Query Server Information. * mongo-db: allow non-admin database for root credential rotation [[GH-23240](https://github.com/hashicorp/vault/pull/23240)] * replication (enterprise): Fix a bug where undo logs would only get enabled on the initial node in a cluster. * replication (enterprise): Fix a missing unlock when changing replication state * secrets/transit (enterprise): Address an issue using sign/verify operations with managed keys returning an error about it not containing a private key * secrets/transit (enterprise): Address panic when using GCP,AWS,Azure managed keys for encryption operations. At this time all encryption operations for the cloud providers have been disabled, only signing operations are supported. * secrets/transit (enterprise): Apply hashing arguments and defaults to managed key sign/verify operations * secrets/transit: Do not allow auto rotation on managed_key key types [[GH-23723](https://github.com/hashicorp/vault/pull/23723)]