- Added Standard Token Exchange (RFC 8693) support and dynamic authentication flow selection via client policies.
- Introduced Fine‑Grained Admin Permissions V2 and strengthened default security with TLS‑encrypted cluster communication, Operator‑generated NetworkPolicies, and reloadable management TLS material.
- Enhanced observability and deployment: Grafana dashboards, ECS‑formatted logs, rolling updates for optimized/custom images, richer Admin Events API filters, and CRL caching for X.509 authentication.