Skip to content

Releases

What shipped in each version of the Kysira proxy, ext-proc, inference sidecar, and dashboard. Dates are when the tag was cut.


v0.7.3 — September 24, 2026

  • Quieter admission-probe logging in the inference sidecar.
  • Docs: new guidance on sizing inference for scale-out — see Sizing inference.

v0.7.2 — September 24, 2026

  • Fix: active mode could still fall back to regex-only scoring when traffic repeats the same request. If you are on v0.7.0 or v0.7.1 in active mode, upgrade.

v0.7.1 — September 24, 2026

  • Fix: active mode fell back to regex-only scoring on most requests under v0.7.0 defaults. Inline INFERENCE_TIMEOUT_MS now defaults to 300 ms (keep it below your traffic extension timeout — see Timeout ordering).
  • More accurate inference cost estimates, so a single slow request no longer locks the model out.

v0.7.0 — September 24, 2026

  • Bounded inference latency. The inference sidecar limits concurrent scoring and falls back to regex and signature detection when it can't finish in time, instead of queueing or erroring. Set KYSIRA_ADMISSION=off to restore the previous behaviour.
  • Faster Argus scoring on requests with long tokens in Authorization and Cookie headers.
  • Circuit-breaker improvements.
  • Request headers on the decision log, with sensitive values redacted. Disable with KYSIRA_LOG_HEADERS=false.

v0.6.4 — September 18, 2026

  • Argus v5 detection model.
  • Security and package updates.
  • Images are now also published to Amazon ECR. Release images no longer carry a latest tag — pin a version.
  • Fixed the license-signing public key in the inference image.

v0.6.2 — August 28, 2026

  • Circuit-breaker activity is now visible in the logs. ext-proc logs when the breaker opens and closes and when it sheds a request, so a burst of fail-open traffic can be traced to the breaker instead of guessed at. Adds the kysira_extproc_breaker_open, kysira_extproc_breaker_opens_total and kysira_extproc_breaker_short_circuit_total metrics.
  • Troubleshooting guide covers breaker behaviour — what an open breaker looks like from the caller's side, and what to check when it stays open.

v0.6.1 — August 28, 2026

  • Release and build-pipeline maintenance only. No change to ext-proc or inference behaviour — nothing to do if you are already on 0.6.0.

v0.6.0 — August 28, 2026

  • Shadow-mode scoring moved off the request path. In shadow mode ext-proc now answers immediately and scores in the background, so scoring latency never reaches the caller. Tunable with shadowAsync, shadowWorkers and shadowQueue; set shadowAsync to "false" to score inline as a latency rehearsal before switching to active enforcement.
  • Circuit breaker for inference failures. After a run of consecutive inference failures (breakerThreshold, default 5) ext-proc fails open immediately rather than making every request wait out inferenceTimeoutMs, then retries after breakerCooldownMs. Set the threshold to 0 to disable it.
  • Dropped shadow scores are logged, not just counted. Watch kysira_extproc_shadow_dropped_total: sustained drops mean inference is undersized, not that the queue is too small.
  • Request-body cap for scoring. maxBodyBytes (default 1 MiB) bounds what ext-proc accumulates for scoring. Larger bodies are truncated for scoring only and still pass through untouched.
  • New ext-proc metrics for request duration and shadow-queue depth: kysira_extproc_request_duration_seconds, kysira_extproc_shadow_queue_depth.
  • Security and package updates.
  • Decision-log tooling. The log-pull script takes a configurable service name and log view, splits results into malicious vs. false-positive-risk, and can emit a markdown report.

v0.5.0 — July 27, 2026

  • License-signing public key embedded at build time. The proxy image now carries its verification key from the moment it's built and it's wired into the customer Kubernetes chart — no manual key distribution step.
  • Enforcement modes and rollout documented. New docs cover shadow vs. active enforcement and staged rollout.
  • WAF enforcement toggle requires an authenticated admin token.

v0.4.0 — June 26, 2026

  • Decision-log tooling. Added a script and internal runbook for pulling and summarizing ext-proc decision logs, broken down by enforcement impact — useful when tuning thresholds after a shadow-mode run.
  • Cloud Run image access documented. Agent images (proxy, inference, dashboard) and grants for Cloud Run.

v0.3.0 — June 22, 2026

  • Internal tooling and CI reliability improvements.

v0.2.3 — June 21, 2026

  • Security review pass across the proxy, ext-proc, and inference services.

v0.2.2 / v0.2.1 — June 20–21, 2026

  • Licensing service. License issuance and validation updated container.
  • Quickstart rewrite. Docs now cover both the Kubernetes and Cloud Run deployment paths.

v0.2.0 — June 17, 2026

  • New detection coverage: keyless JWT abuse and insecure deserialization (OWASP A07/A08).
  • Dashboard redesign. New "Defense Grid" visualization for the threat monitor, showing the live attack surface as it's scored.

v0.1.2-alpha — June 12, 2026

  • Argus detection engine. Each verdict with the engine that made the call (Argus AI / Model / Signature).
  • Tuned SSTI and SSRF detection coverage.

v0.1.1-alpha — June 10, 2026

  • Added latency and detection metrics.

v0.1.0-alpha — June 9, 2026

  • First alpha release.