LogoLogo
DocsMain SiteStart Now
  • 2024
    • πŸ’ΏJIT access for passwordless databases
    • πŸ€–Docker Hub updates
    • 🌱Updates for Kubernetes API
    • 🌷Some spring sprucing
    • 🌁Multiple replica support for Kubernetes agent
    • πŸ“¨Include your issue directly in your zli send-logs command
    • πŸ€–Update to agent shutdown procedures
    • β˜‚οΈTable refresh
    • 🎿A small fix
    • 🌁Minor adjustments
    • πŸ”Introducing OpenPubkey SSH
  • 2023
    • 🧹End of year cleanup
    • πŸŒ„Use environments as proxy targets
    • πŸ‚Configurable MFA duration
    • 🍁Customize agent log levels
    • 🍏Connect to all Kubernetes targets in a single command
    • 🐝Sorting, grouping, and range search for `zli lt` and `zli la`
    • β˜€οΈThe divorce of targets and agents
    • β›΅Small fix for connecting to Kubernetes targets
    • 🌴Connect to Kubernetes targets without specifying a target group
    • πŸ—ΊοΈConnection improvements
    • ⛱️Google SSO users
    • πŸ”¨Kubernetes updates pt. 2
    • 🧰Kubernetes updates pt. 1
    • πŸͺŸSupport for Windows
    • πŸ•οΈA couple fixes
    • 🌻Changes to bzero's agent types
    • ☁️Passwordless access to GCP Cloud SQL
    • πŸ—οΈAuthenticate using Keycloak
    • πŸ‘ΎBastionZero's Terraform Provider is live
    • 🐦MFA setup enhancements
    • 🌷Access Linux targets with IdP username as target user
    • πŸ€Fixed Kube connection stability
    • ❄️Use Github Actions to grant just-in-time access
    • πŸ’ŒImproved ZLI error messaging
    • πŸ”‘SplitCert with databases is ready to demo
    • 🎿Authenticate using OneLogin
  • 2022
    • β˜ƒοΈGlobal MFA is enabled by default for new orgs
    • πŸ€–Headless authentication with service accounts
    • πŸ‚Secure your targets using the onboarding tool
    • 😎Need help? Send us your logs from the ZLI
    • ⏱️QuickStart installs the bzero agent
    • 🍁Some autumn housekeeping
    • πŸŽ‰Tab completion in the ZLI
    • πŸ“©Laying the foundation
    • βš’οΈRestart a bzero agent from the ZLI
    • πŸ“„Improved SSH config file management
    • πŸ’ΎConnect to multiple database targets
    • βš™οΈCreate policies from the ZLI
    • πŸ”₯Govern file transfers with policy
    • πŸ’‘Enhanced filtering with the ZLI
Powered by GitBook
On this page
  • bzero v. 7.3.1
  • Fixes
  • Web app & backend
  • New
  • Enhancements
  • Fixes

Was this helpful?

  1. 2022

Global MFA is enabled by default for new orgs

15 December 2022

PreviousAuthenticate using OneLoginNextHeadless authentication with service accounts

Last updated 1 year ago

Was this helpful?

bzero v. 7.3.1

IMPORTANT REMINDER

For those who use Helm to install the Kubernetes bzero agent, you must update the Helm repository to chart version >= 1.1.3 before doing a fresh install of the bzero agent. You can do this with helm repo update.

This action updates the bctl-agent role to include permissions for retrieving logs from pods within the deployed namespace for the zli send-logs feature. Even if you do not intend to use send-logs, you must be using chart version >= 1.1.3 for any new Helm installations to be compatible with the new backend changes. We strongly recommend everyone who uses Helm takes this action.

Fixes

  • [Released 8 December] Agent re-registration. Resolved issue if bzero agent is attempting to register on top of an existing registration, bzero will prompt user to use the -f flag to force a new registration

Web app & backend

New

  • Onboarding tool. To help aid users in onboarding targets to BastionZero, a self-serve, interactive onboarding guide is available within the web app underneath the support (?) icon in the top right corner. This tool provides guides for remote hosts, databases, Kubernetes clusters, web servers, and SSH tunnels. If you give it a try, let us know what you think!

Enhancements

  • Policies without a subject. Target connect, Kubernetes, and proxy policies can be created from the web app without any specified subjects. This enables you to mandate target access through access only

  • Global MFA. New BastionZero organizations will have global MFA enabled by default. Users will be prompted upon first log in to set up their MFA using their chosen authenticator app. While it is not possible to disable MFA for the entire org, administrators may choose to disable, re-enable, or reset an individual user's MFA

Fixes

  • Onboarding tool. Resolved minor issues in the onboarding tool

For questions or to give us feedback on how we can make our updates better, reach out to .

β˜ƒοΈ
just-in-time
product@bastionzero.com