Release Changelog
v0.11.2
Section titled “v0.11.2”Bug: Fix issue where some images were not correctly handled for air-gapped deployments.
v0.11.1
Section titled “v0.11.1”Quality: Update the M42 Go toolchain to go1.26.6-pq1, incorporating upstream security fixes.
Feature: Add native ARM64 standalone cabetool distribution in addition to amd64, improving support for ARM-based deployments.
v0.11.0
Section titled “v0.11.0”BREAKING: Migrate SPIFFE CSI namespace routing from descriptor hashes to stable
QHx authority names. The default routing interface is now default-authority /
-default-authority-path rather than default-hash / -default-hash-path.
Namespaces map through namespace-map.yaml to QHxAuthority resources and
unbound namespaces use the configured default authority.
Feature: Add native ARM64 support for QHx Core, including native amd64 and ARM64 OCI images and Kubernetes integration testing.
Bug: Use the complete trust domain as the default QHxForeignCluster name.
Bug: Correct the PKI init-container dependency mirror to preserve native amd64 and ARM64 images, allowing the pki-agent path to initialize correctly on ARM64.
Refactor: Standardize Kubernetes workload and ownership labels across Helm-managed and QHx Manager-generated resources.
Quality: Update the M42 SPIFFE CSI driver to 52.6.5 with authority-based routing and native amd64 and ARM64 support.
Quality: Update QHx build dependencies and the post-quantum Go toolchain.
Quality: Expand integration coverage for multi-authority workload identity, authority lifecycle, namespace routing and federation.
CI/CD: Add native amd64 and ARM64 build and Kubernetes integration-test jobs with architecture-specific OCI artifacts.
CI/CD: Validate registry-mirrored and Zarf-based air-gap installation paths alongside the multi-architecture build pipeline.
CI/CD: Preserve Kubernetes integration-test diagnostics when kutest fails.
v0.10.0
Section titled “v0.10.0”BREAKING: Retire the QHxClusterPolicy resource type, which is now superseded by the QHxCluster resource.
BREAKING: Remove most existing fields from the QHxPolicy resource type, which now binds a namespace to a QHxAuthority instead of expressing PKI settings directly.
Feature: Introduce the QHxCluster, QHxAuthority and QHxForeignCluster Kubernetes resource types to allow multiple PKI authorities to be configured explicitly. The QHxPolicy resource type is changed to work with these resources.
Feature: Add automatic intra-cluster federation. Different PKI authorities within the same cluster now automatically federate with one another.
Feature: Add turnkey QHx Manager-orchestrated inter-cluster federation, based
on the new QHx Federation M2M (Manager-to-Manager) protocol. This feature
allows multiple QHx Clusters to be federated and achieve mutual trust between
all of the subsidiary authorities of each cluster. Federation is driven via the
QHxForeignCluster CRD and can be managed via the new qhx federation
subcommand of the QHx CLI. See Federation
Architecture for details.
Feature: Add managed uninstall orchestration to QHx Manager and the QHx Helm
chart. The uninstallSafety Helm value can be used to determine how to proceed
when uninstalling QHx (via helm uninstall) from a cluster which has running
user workloads which depend on QHx.
Feature: Add Prometheus metrics monitoring support.
Feature: Package the cabetool command line tool as part of the QHx distribution. This allows CABE operations to be performed using a simple CLI interface.
Bug: Fixed MQTT buffer replay non-determinism issue.
Refactor: Refactor Helm chart generation to use principled AST serialization.
Refactor: Remove the QHxSignedResource CRD.
Refactor: Updated COSE library to allow COSE_Key structures to use RFC 9360-style parameters.
Refactor: Updated COSE library to support ML-DSA and RSA signing for full compatibility with the range of algorithms suppoted by QHx. This supports the federation M2M protocol.
Refactor: Updated go-jose to support ML-DSA for opaque signing.
CI/CD: Added CPU and RSS consumption performance test to CI/CD.
CI/CD: Fixed issue with GHA runners hitting disk limits.
CI/CD: Enhancements to linter configurations in CI/CD.
CI/CD: Use cached images for Cilium CNI and other OCI images as part of kutest integration test framework to remove dependency on external network services.
Quality: Updated the CSI driver.
Quality: Updated the PKI software build version.
v0.9.0
Section titled “v0.9.0”BREAKING: The default installation of QHx now requires the cluster it is
installed on to have a valid storage class configured to provide backing for
persistent volumes. This is required to enable the khaled key server to
persist key information. QHx can still be installed on a cluster without any
valid storage classes by passing --set khaled.enable=false at install time.
Feature: CABE data encapsulation support. QHx now incorporates the Khaled key server to enable CABE. The QHx release of Khaled is post-quantum enabled.
Feature: High availability support has been introduced. This allows the QHx PKI infrastructure to operate in high availability mode. There is a requirement for an external database to be provisioned to enable coordinated data storage when enabling this feature.
Feature: OpenShift is now a supported installation target. You must pass --set kubernetesVariant=openshift when installing.
Feature: A customer portal has been provisioned to allow customers to generate access keys and access licenses and release information. This allows customers to generate keys they can use to download and provision QHx releases without support intervention. See https://portal.messier42.com/
CI/CD: VEX statements are now generated along with CycloneDX SBOM.
Refactor: Refactored configuration system to use a custom AST-driven YAML serializer to support Helm conditionals.
v0.8.0
Section titled “v0.8.0”Feature: Federation configuration support. This allows inter-cluster federation to be configured via the QHxClusterPolicy resource.
Feature: License tracking and auditing support. The qhx CLI can be used to install and manage QHx licenses and view license status.
Feature: Allow Prometheus monitoring of the QHx PKI server and agent.
Feature: Ensure PKI server and agent workloads generated by QHx Manager respect the configured image pull policy.
CI: Update underlying Go version.
v0.7.1
Section titled “v0.7.1”Bug: Correct an issue where PKI images were not correctly tagged.
v0.7.0
Section titled “v0.7.0”Feature: MQTT protocol support. This adds support for pubsub-style MQTT protocol functionality in addition to the existing HTTP protocol functionality in QHx Proxy.
Feature: MQTT protocol message notarization support.
Feature: MQTT store-and-forward support. This adds support for store-and-forward functionality around MQTT messages for operation DDIL environments.
Feature: Add MQTT protocol support to QHx CLI for receiving and outputting notarization data.
Feature: Allow disabling upstream keepalive in QHx Proxy.
Feature: An OpenAPI schema is now provided. This schema is generated automatically from internal schemas.
Feature: Rate limit policy reconciliation to avoid overly frequent policy re-evaluation.
Feature: Add TPM policy support. This allows namespace or cluster-level policies to be configured to enforce TPM PCR values before admitting a node and issuing workload identities. Usage requires enablement at install time and subsequent configuration in a policy resource. Nodes must provided suitable TPM devices.
Feature: Add new QHx Attestor plugin to support TPM and PCR-based attestation as a precondition of workload identity issuance.
Refactor: Introduce QHx Agent. QHx Agent is a process scheduled on every node of a cluster and which is intended to support future networking augmentations.
CI: Update build system to support multi-person dev-test iteration workflows.
CI: Move from relying on separately shipped and versioned PKI infrastructure images to using internally released PKI infrastructure images to construct unified PKI images with the QHx Attestor plugin under a QHx release version number. This avoids the need for end users to track a separate PKI image version.
CI: Update underlying Go version.
CI: Add internal automated performance test infrastructure.
CI: Add internal bare metal performance test infrastructure.
CI: Add SLSA provenance attestation to release images.
CI: Integration testing around MQTT, MQTT notarization and MQTT store-and-forward functionality.
CI: Augment internal integration test harness to allow bail-and-keep debugging when debugging specific integration tests.
CI: Fix a CI bug around non-deterministic behavior of artifact uploads when uploading documentation.
Bug: Ensure the CSI driver is updated and rolled automatically when policies are changed requiring an underlying CSI driver routing change.
Bug: Add pod security labels to allow QHx to be installed as-is on Talos Linux or other Kubernetes environments with default pod security policy enforcement.
v0.6.1
Section titled “v0.6.1”Bug: Fix a bug where imagePullSecrets were not referenced properly by all QHx Manager-controlled resources.
v0.6.0
Section titled “v0.6.0”Feature: Add QHxPolicy namespace-level policy Kubernetes resource kind,
allowing namespace-level algorithm policy to be expressed.
Feature: QHx Manager now dynamically creates and manages PKI infrastructure
instances itself dynamically as needed in response to created QHxPolicy,
rather than relying on static infrastructure deployed as part of the Helm
chart. PKI instances are managed automatically by a control loop supervised by
QHx Manager, and spun up and down dynamically as QHxPolicy resources are
created or revised.
Feature: The SPIFFE CSI driver provided as part of QHx Core now routes
workloads to the correct PKI infrastructure instance based on the configured
QHxPolicy for the workload namespace.
Feature: Add release signing to the Zarf release package. v0.5.1 introduced support for release signing to the Helm-based install flow.
Helm Values: Introduce spiffeCSIDriverImage and initImage Helm values.
Documentation: Add documentation for QHxPolicy.
Quality: Internal augmentation of kutest integration test framework to exercise
QHxPolicy.
v0.5.1
Section titled “v0.5.1”Feature: Introduce sigstore-style release signing.
Feature: Introduce SBOMs as part of release automation.
v0.5.0
Section titled “v0.5.0”Breaking Change: The default certificate format is now ML-DSA-65.
Feature: Introduce standard NIST FIPS 204 ML-DSA support, including ML-DSA-44, ML-DSA-65 and ML-DSA-87. Legacy pre-standard Dilithium3 certificates continue to be supported for compatibility.
Feature: Implement support for ML-DSA in JWT tokens based on pre-standard
draft-ietf-cose-dilithium-11 and standard NIST FIPS 204. This is used to
support QHx Notary functionality.
Feature: QHx Manager now manages webhook TLS certificates automatically independently of SPIRE to avoid bootstrapping dependencies.
Feature: Allow QHx Manager to serve different TLS certificates for different clients based on whether post-quantum signature schemes are supported by a client. This allows legacy clients to connect to QHx Manager endpoints.
Feature: Revupped to current PQ-enhanced PKI infrastructure release version.
Feature: Revupped to current PQ-enhanced Go build.
Feature: Show the signature algorithm used when passing --print-workload to
qhx curl.
Quality: Work on internal integration test infrastructure.
Quality: Internal CI/CD work to integrate more linters and static analysis tools.
Helm values: Introduce clusterDomain, webhookCertTTL,
webhookCertRotationInterval Helm values.
Helm values: Introduce imagePullPolicy Helm value allowing image pull policy
for QHx images to be configured.
v0.4.0
Section titled “v0.4.0”Initial alpha release.