- Bump minimum supported Kubernetes to v1.20.6 and enable native impersonation for multi‑tenant clusters, altering controller behavior when both kubeConfig and ServiceAccountName are set.
- Add security hardening: namespace‑level tenant isolation, restricted pod security compliance, Seccomp default profile, image signing with Cosign & OIDC, and published SBOM.
- Introduce new capabilities: `flux diff kustomization` preview, undo server‑side apply changes, Hashicorp Vault token auth for SOPS, automatic cloud registry login for image automation and cross‑namespace ImageUpdateAutomation.