- Fixed numerous bugs including S3 bucket creation in audit storage, RBAC session listing leakage, flag parsing in tsh logout, and metric overshoot after keepalive errors.
- Added security hardenings such as automatic disabling of service‑account token mounting, env‑var to disable device auto‑enroll, prevention of auto‑enroll escalation without TPM, and redaction of join tokens.
- Introduced new features like custom SQS consumer lock names, custom Firestore database support, expanded Discovery Service across all projects, kubeconfig context name in proxy output, and inclusion of Postgres backend PID in session eve...