- Fixed cluster‑joining bugs for Kubernetes (including token audience handling) and corrected proxy peering address and Helm chart token‑mount issues.
- Added configurable resource labels in the Teleport operator Helm sub‑chart, supported long‑running kube exec/port‑forward, and allowed Azure VMs to join from a different subscription.
- Improved stability and audit: SSH/Kubernetes info now appears in audit logs, restored PAM auth, enabled license secret override, and fixed numerous panics, CPU spikes, DB provisioning, and session‑recording issues.