The module lifecycle stage: General Availability
The module has requirements for installation
v1.18.0
- Managed Keys for key material in external trusted systems without storing private keys inside Stronghold. Supported for
Transit,PKI, andSSHsecrets engines. - Managed key support in
Yandex KMSandPKCS#11. - User authentication via an external
SAML 2.0Identity Provider using theWeb SSOprofile. - Web UI for managing
KVmount replication settings. PKIsupports single-elementRDNs in distinguished names for compatibility with OpenSSL / Microsoft CA.- Audit devices support record filtering and excluding specific fields.
- Snapshot verification via
stronghold operator raft snapshot inspect. - Added ability to manage max_ttl parameter for ACME certificates.
- Improved compatibility with Auto-Snapshots Vault Enterprise — snapshot configuration is preserved when migrating from Vault Enterprise.
- CVE GHSA-jqcq-xjh3-6g23, CVE-2026-33186, CVE-2026-33487, CVE-2025-15558
v1.17.0
- Added
WebAuthnsupport — passwordless authentication (FIDO2/Passkeys). - Support for external Stronghold plugins running on DKP.
- Namespace lock features and a UI to manage them.
- Web UI support for the
LDAP secrets engine. - Added
Yandex KMSas asealbackend. - Extended
Agentusage scenarios. - Added support for
raftnodes innon-votermode. - Refined deployment scenarios on arbiter node groups and test cluster parameters.
v1.16.0
- Added support for namespaces (
Namespaces). - Multi-factor authentication (
MFA) withTOTPandMultifactor. - Deckhouse Stronghold
CE(Community Edition) available for free installation. - Web UI support for managing
OIDCroles,AppRole, and password policies. - Added replication metrics.
- Added
SealWrap— additional encryption for the most sensitive internal data on top of Stronghold’s standard cryptographic barrier. - Added
CryptoPro seal wrapperfor scenarios using Russian cryptography. - Web UI has fuller Russian localization and a dark theme.
- Added
ClickHousesupport and a web UI to work with it. - Added
TLS 1.3with GOST ciphersMagmaandKuznyechik. - Added support for
GOST 34.10-2012 X.509certificates.
v1.15.0
- Scheduled backup of
Raft snapshotstoS3or the filesystem with API-driven management. - Extended
KVreplication capabilities. - Improved web UI.
- Automatic unseal via
HSM/PKCS#11, including Rutoken ECP 3.0 support.
v1.1.0
- Automatic unseal with keys held in Stronghold node memory
- Russian-language user interface
- Listed in the Russian software registry, entry No. 22339 dated 24.04.2024
- Integration with the platform secrets delivery module `secrets-store-integration``
v1.0.0
- Deployment as a DKP module
- Integration with platform DEX authentication