Release Changelog
v0.9.0
Section titled “v0.9.0”BREAKING: The default installation of QHx now requires the cluster it is
installed on to have a valid storage class configured to provide backing for
persistent volumes. This is required to enable the khaled key server to
persist key information. QHx can still be installed on a cluster without any
valid storage classes by passing --set khaled.enable=false at install time.
Feature: CABE data encapsulation support. QHx now incorporates the Khaled key server to enable CABE. The QHx release of Khaled is post-quantum enabled.
Feature: High availability support has been introduced. This allows the QHx PKI infrastructure to operate in high availability mode. There is a requirement for an external database to be provisioned to enable coordinated data storage when enabling this feature.
Feature: OpenShift is now a supported installation target. You must pass --set kubernetesVariant=openshift when installing.
Feature: A customer portal has been provisioned to allow customers to generate access keys and access licenses and release information. This allows customers to generate keys they can use to download and provision QHx releases without support intervention. See https://portal.messier42.com/
CI/CD: VEX statements are now generated along with CycloneDX SBOM.
Refactor: Refactored configuration system to use a custom AST-driven YAML serializer to support Helm conditionals.
v0.8.0
Section titled “v0.8.0”Feature: Federation configuration support. This allows inter-cluster federation to be configured via the QHxClusterPolicy resource.
Feature: License tracking and auditing support. The qhx CLI can be used to install and manage QHx licenses and view license status.
Feature: Allow Prometheus monitoring of the QHx PKI server and agent.
Feature: Ensure PKI server and agent workloads generated by QHx Manager respect the configured image pull policy.
CI: Update underlying Go version.
v0.7.1
Section titled “v0.7.1”Bug: Correct an issue where PKI images were not correctly tagged.
v0.7.0
Section titled “v0.7.0”Feature: MQTT protocol support. This adds support for pubsub-style MQTT protocol functionality in addition to the existing HTTP protocol functionality in QHx Proxy.
Feature: MQTT protocol message notarization support.
Feature: MQTT store-and-forward support. This adds support for store-and-forward functionality around MQTT messages for operation DDIL environments.
Feature: Add MQTT protocol support to QHx CLI for receiving and outputting notarization data.
Feature: Allow disabling upstream keepalive in QHx Proxy.
Feature: An OpenAPI schema is now provided. This schema is generated automatically from internal schemas.
Feature: Rate limit policy reconciliation to avoid overly frequent policy re-evaluation.
Feature: Add TPM policy support. This allows namespace or cluster-level policies to be configured to enforce TPM PCR values before admitting a node and issuing workload identities. Usage requires enablement at install time and subsequent configuration in a policy resource. Nodes must provided suitable TPM devices.
Feature: Add new QHx Attestor plugin to support TPM and PCR-based attestation as a precondition of workload identity issuance.
Refactor: Introduce QHx Agent. QHx Agent is a process scheduled on every node of a cluster and which is intended to support future networking augmentations.
CI: Update build system to support multi-person dev-test iteration workflows.
CI: Move from relying on separately shipped and versioned PKI infrastructure images to using internally released PKI infrastructure images to construct unified PKI images with the QHx Attestor plugin under a QHx release version number. This avoids the need for end users to track a separate PKI image version.
CI: Update underlying Go version.
CI: Add internal automated performance test infrastructure.
CI: Add internal bare metal performance test infrastructure.
CI: Add SLSA provenance attestation to release images.
CI: Integration testing around MQTT, MQTT notarization and MQTT store-and-forward functionality.
CI: Augment internal integration test harness to allow bail-and-keep debugging when debugging specific integration tests.
CI: Fix a CI bug around non-deterministic behavior of artifact uploads when uploading documentation.
Bug: Ensure the CSI driver is updated and rolled automatically when policies are changed requiring an underlying CSI driver routing change.
Bug: Add pod security labels to allow QHx to be installed as-is on Talos Linux or other Kubernetes environments with default pod security policy enforcement.
v0.6.1
Section titled “v0.6.1”Bug: Fix a bug where imagePullSecrets were not referenced properly by all QHx Manager-controlled resources.
v0.6.0
Section titled “v0.6.0”Feature: Add QHxPolicy namespace-level policy Kubernetes resource kind,
allowing namespace-level algorithm policy to be expressed.
Feature: QHx Manager now dynamically creates and manages PKI infrastructure
instances itself dynamically as needed in response to created QHxPolicy,
rather than relying on static infrastructure deployed as part of the Helm
chart. PKI instances are managed automatically by a control loop supervised by
QHx Manager, and spun up and down dynamically as QHxPolicy resources are
created or revised.
Feature: The SPIFFE CSI driver provided as part of QHx Core now routes
workloads to the correct PKI infrastructure instance based on the configured
QHxPolicy for the workload namespace.
Feature: Add release signing to the Zarf release package. v0.5.1 introduced support for release signing to the Helm-based install flow.
Helm Values: Introduce spiffeCSIDriverImage and initImage Helm values.
Documentation: Add documentation for QHxPolicy.
Quality: Internal augmentation of kutest integration test framework to exercise
QHxPolicy.
v0.5.1
Section titled “v0.5.1”Feature: Introduce sigstore-style release signing.
Feature: Introduce SBOMs as part of release automation.
v0.5.0
Section titled “v0.5.0”Breaking Change: The default certificate format is now ML-DSA-65.
Feature: Introduce standard NIST FIPS 204 ML-DSA support, including ML-DSA-44, ML-DSA-65 and ML-DSA-87. Legacy pre-standard Dilithium3 certificates continue to be supported for compatibility.
Feature: Implement support for ML-DSA in JWT tokens based on pre-standard
draft-ietf-cose-dilithium-11 and standard NIST FIPS 204. This is used to
support QHx Notary functionality.
Feature: QHx Manager now manages webhook TLS certificates automatically independently of SPIRE to avoid bootstrapping dependencies.
Feature: Allow QHx Manager to serve different TLS certificates for different clients based on whether post-quantum signature schemes are supported by a client. This allows legacy clients to connect to QHx Manager endpoints.
Feature: Revupped to current PQ-enhanced PKI infrastructure release version.
Feature: Revupped to current PQ-enhanced Go build.
Feature: Show the signature algorithm used when passing --print-workload to
qhx curl.
Quality: Work on internal integration test infrastructure.
Quality: Internal CI/CD work to integrate more linters and static analysis tools.
Helm values: Introduce clusterDomain, webhookCertTTL,
webhookCertRotationInterval Helm values.
Helm values: Introduce imagePullPolicy Helm value allowing image pull policy
for QHx images to be configured.
v0.4.0
Section titled “v0.4.0”Initial alpha release.