Cerbos v0.56.0 (2026-09-30)
Changelog
Breaking changes
- Remove deprecated configuration settings
-
compile.cacheSizeandcompile.cacheDuration(deprecated since v0.47.0) andstorage.git.scratchDir(deprecated since v0.9.0) have been removed.
Features
- Support specifying a target for Hub audit log ingest
-
Currently, client credentials are associated with a specific deployment in a Cerbos Hub workspace. Audit logs are implicitly sent to that workspace. In future, it will be possible to send audit logs to a different workspace to the one that holds the policies. For forwards compatibility, the target workspace can now be explicitly specified with the
audit.hub.workspaceIDsetting. For now, this remains optional and if specified must be the ID of the workspace that owns the deployment. The setting will become required in a future version.
Enhancements
- Metric to track last error-free refresh from policy source
-
New
cerbos_dev_rule_table_last_successful_refreshmetric added to track when the rule table served by the engine was successfully refreshed from the policy source without any errors. - Optimize Hub audit log backlog sync
-
Reduce the memory used when the PDP has fallen behind in syncing audit logs to Cerbos Hub.
Bug fixes
- Admin API store reload with
wait=truenow actually waits for the policies to compile and reports any failures. -
Previously the reload request returned before policies were recompiled, so a reload that pulled in policies that fail to compile reported success while the PDP kept serving the previous rule table. The request now returns after the rule table rebuild completes and fails with a distinct error if the rebuild failed. Concurrent reload requests are merged, and each request is served by a reload that started after it was received.
- Detect invalid
scopePermissions -
Rejects policies whose
scopePermissionssetting conflicts with other policies in the same scope. This was documented but the enforcement of it was buggy. - Fix matching for resource kinds with special characters in the name
-
Role policies were not correctly matching resources whose names contained certain special characters.
- Fix principal policy precedence in query plan
-
Explicit deny rules in principal policies were being ignored by the query planner due to faulty logic. This fix restores the expected behaviour of giving precedence to principal policy rules.