Release Changelog
v0.6.1
Section titled “v0.6.1”Bug: Fix a bug where imagePullSecrets were not referenced properly by all QHx Manager-controlled resources.
v0.6.0
Section titled “v0.6.0”Feature: Add QHxPolicy namespace-level policy Kubernetes resource kind,
allowing namespace-level algorithm policy to be expressed.
Feature: QHx Manager now dynamically creates and manages PKI infrastructure
instances itself dynamically as needed in response to created QHxPolicy,
rather than relying on static infrastructure deployed as part of the Helm
chart. PKI instances are managed automatically by a control loop supervised by
QHx Manager, and spun up and down dynamically as QHxPolicy resources are
created or revised.
Feature: The SPIFFE CSI driver provided as part of QHx Core now routes
workloads to the correct PKI infrastructure instance based on the configured
QHxPolicy for the workload namespace.
Feature: Add release signing to the Zarf release package. v0.5.1 introduced support for release signing to the Helm-based install flow.
Helm Values: Introduce spiffeCSIDriverImage and initImage Helm values.
Documentation: Add documentation for QHxPolicy.
Quality: Internal augmentation of kutest integration test framework to exercise
QHxPolicy.
v0.5.1
Section titled “v0.5.1”Feature: Introduce sigstore-style release signing.
Feature: Introduce SBOMs as part of release automation.
v0.5.0
Section titled “v0.5.0”Breaking Change: The default certificate format is now ML-DSA-65.
Feature: Introduce standard NIST FIPS 204 ML-DSA support, including ML-DSA-44, ML-DSA-65 and ML-DSA-87. Legacy pre-standard Dilithium3 certificates continue to be supported for compatibility.
Feature: Implement support for ML-DSA in JWT tokens based on pre-standard
draft-ietf-cose-dilithium-11 and standard NIST FIPS 204. This is used to
support QHx Notary functionality.
Feature: QHx Manager now manages webhook TLS certificates automatically independently of SPIRE to avoid bootstrapping dependencies.
Feature: Allow QHx Manager to serve different TLS certificates for different clients based on whether post-quantum signature schemes are supported by a client. This allows legacy clients to connect to QHx Manager endpoints.
Feature: Revupped to current PQ-enhanced PKI infrastructure release version.
Feature: Revupped to current PQ-enhanced Go build.
Feature: Show the signature algorithm used when passing --print-workload to
qhx curl.
Quality: Work on internal integration test infrastructure.
Quality: Internal CI/CD work to integrate more linters and static analysis tools.
Helm values: Introduce clusterDomain, webhookCertTTL,
webhookCertRotationInterval Helm values.
Helm values: Introduce imagePullPolicy Helm value allowing image pull policy
for QHx images to be configured.
v0.4.0
Section titled “v0.4.0”Initial alpha release.