- Improved performance of predicate expressions, raised app access upstream response header cap to 1 hour, and added internal SCIM PATCH flow optimizations.
- Added Kubernetes join allow‑rules targeting specific service accounts and namespaces with wildcard support; MFA prompts now include leaf‑cluster names and Device Trust untrusted‑device responses return a simple HTML page.
- Fixed numerous issues: Azure join trust‑chain failures, Teleport Connect VNet start on Linux with older tsh, host sudoers writing on newer Ubuntu, session summary now shows MITRE attack IDs, and Web UI audit‑review prompts display correc...