Releases¶
What shipped in each version of the Kysira proxy, ext-proc, inference sidecar, and dashboard. Dates are when the tag was cut.
v0.7.3 — September 24, 2026¶
- Quieter admission-probe logging in the inference sidecar.
- Docs: new guidance on sizing inference for scale-out — see Sizing inference.
v0.7.2 — September 24, 2026¶
- Fix: active mode could still fall back to regex-only scoring when traffic repeats the same request. If you are on v0.7.0 or v0.7.1 in active mode, upgrade.
v0.7.1 — September 24, 2026¶
- Fix: active mode fell back to regex-only scoring on most requests under v0.7.0 defaults. Inline
INFERENCE_TIMEOUT_MSnow defaults to 300 ms (keep it below your traffic extension timeout — see Timeout ordering). - More accurate inference cost estimates, so a single slow request no longer locks the model out.
v0.7.0 — September 24, 2026¶
- Bounded inference latency. The inference sidecar limits concurrent scoring and falls back to regex and signature detection when it can't finish in time, instead of queueing or erroring. Set
KYSIRA_ADMISSION=offto restore the previous behaviour. - Faster Argus scoring on requests with long tokens in
AuthorizationandCookieheaders. - Circuit-breaker improvements.
- Request headers on the decision log, with sensitive values redacted. Disable with
KYSIRA_LOG_HEADERS=false.
v0.6.4 — September 18, 2026¶
- Argus v5 detection model.
- Security and package updates.
- Images are now also published to Amazon ECR. Release images no longer carry a
latesttag — pin a version. - Fixed the license-signing public key in the inference image.
v0.6.2 — August 28, 2026¶
- Circuit-breaker activity is now visible in the logs. ext-proc logs when the breaker opens and closes and when it sheds a request, so a burst of fail-open traffic can be traced to the breaker instead of guessed at. Adds the
kysira_extproc_breaker_open,kysira_extproc_breaker_opens_totalandkysira_extproc_breaker_short_circuit_totalmetrics. - Troubleshooting guide covers breaker behaviour — what an open breaker looks like from the caller's side, and what to check when it stays open.
v0.6.1 — August 28, 2026¶
- Release and build-pipeline maintenance only. No change to ext-proc or inference behaviour — nothing to do if you are already on 0.6.0.
v0.6.0 — August 28, 2026¶
- Shadow-mode scoring moved off the request path. In shadow mode ext-proc now answers immediately and scores in the background, so scoring latency never reaches the caller. Tunable with
shadowAsync,shadowWorkersandshadowQueue; setshadowAsyncto"false"to score inline as a latency rehearsal before switching to active enforcement. - Circuit breaker for inference failures. After a run of consecutive inference failures (
breakerThreshold, default 5) ext-proc fails open immediately rather than making every request wait outinferenceTimeoutMs, then retries afterbreakerCooldownMs. Set the threshold to0to disable it. - Dropped shadow scores are logged, not just counted. Watch
kysira_extproc_shadow_dropped_total: sustained drops mean inference is undersized, not that the queue is too small. - Request-body cap for scoring.
maxBodyBytes(default 1 MiB) bounds what ext-proc accumulates for scoring. Larger bodies are truncated for scoring only and still pass through untouched. - New ext-proc metrics for request duration and shadow-queue depth:
kysira_extproc_request_duration_seconds,kysira_extproc_shadow_queue_depth. - Security and package updates.
- Decision-log tooling. The log-pull script takes a configurable service name and log view, splits results into malicious vs. false-positive-risk, and can emit a markdown report.
v0.5.0 — July 27, 2026¶
- License-signing public key embedded at build time. The proxy image now carries its verification key from the moment it's built and it's wired into the customer Kubernetes chart — no manual key distribution step.
- Enforcement modes and rollout documented. New docs cover shadow vs. active enforcement and staged rollout.
- WAF enforcement toggle requires an authenticated admin token.
v0.4.0 — June 26, 2026¶
- Decision-log tooling. Added a script and internal runbook for pulling and summarizing ext-proc decision logs, broken down by enforcement impact — useful when tuning thresholds after a shadow-mode run.
- Cloud Run image access documented. Agent images (proxy, inference, dashboard) and grants for Cloud Run.
v0.3.0 — June 22, 2026¶
- Internal tooling and CI reliability improvements.
v0.2.3 — June 21, 2026¶
- Security review pass across the proxy, ext-proc, and inference services.
v0.2.2 / v0.2.1 — June 20–21, 2026¶
- Licensing service. License issuance and validation updated container.
- Quickstart rewrite. Docs now cover both the Kubernetes and Cloud Run deployment paths.
v0.2.0 — June 17, 2026¶
- New detection coverage: keyless JWT abuse and insecure deserialization (OWASP A07/A08).
- Dashboard redesign. New "Defense Grid" visualization for the threat monitor, showing the live attack surface as it's scored.
v0.1.2-alpha — June 12, 2026¶
- Argus detection engine. Each verdict with the engine that made the call (Argus AI / Model / Signature).
- Tuned SSTI and SSRF detection coverage.
v0.1.1-alpha — June 10, 2026¶
- Added latency and detection metrics.
v0.1.0-alpha — June 9, 2026¶
- First alpha release.