- Added SSO client redirect CIDR option, configurable Machine ID via Kubernetes secrets, and an application tunnel service for Machine‑to‑Machine access.
- Improved stability and diagnostics: reduced event handler deadlocks, SIGUSR1 profiling, ConPTY support on Windows, and enhanced auto‑discovery resiliency for large clusters.
- Various bugfixes and security hardenings, including preventing arbitrary URL redirects, fixing SAML connector creation, Teleport Connect on Intel Macs, and added audit events for cloud integrations.