{"id":"src_xABpZ7bTwpx9NQtaHEuhs","slug":"nomad-releases","name":"Nomad","type":"github","url":"https://github.com/hashicorp/nomad","orgId":"org_Yj55_xJFX2PSbzXjXof_V","productId":"prod_R673qs5oJyZ4NI7LXseXY","productSlug":"nomad","org":{"id":"org_Yj55_xJFX2PSbzXjXof_V","slug":"hashicorp","name":"HashiCorp"},"isPrimary":false,"isHidden":false,"discovery":"curated","metadata":"{\"evaluatedMethod\":\"github\",\"evaluatedAt\":\"2026-04-07T23:43:10.236Z\",\"changelogUrl\":\"https://github.com/hashicorp/nomad/blob/HEAD/CHANGELOG.md\",\"changelogDetectedAt\":\"2026-04-08T00:16:52.936Z\",\"wellKnownSweptAt\":\"2026-10-01T06:01:26.362Z\",\"sourceActor\":{\"nextAlarmAt\":\"2026-10-08T20:33:40.433Z\",\"lastAlarmAt\":\"2026-10-08T16:33:41.992Z\",\"managed\":true}}","notice":null,"kind":"platform","stars":16993,"starsFetchedAt":"2026-10-08T16:38:26.472Z","releaseCount":107,"releasesLast30Days":2,"avgReleasesPerWeek":0.2,"latestVersion":"v2.0.7","latestDate":"2026-09-18T16:18:15.000Z","changelogUrl":"https://github.com/hashicorp/nomad/blob/HEAD/CHANGELOG.md","hasChangelogFile":true,"lastFetchedAt":"2026-10-08T16:38:26.472Z","lastPolledAt":"2026-10-08T16:38:17.786Z","changeDetectedAt":null,"trackingSince":"2023-12-07T11:10:07.000Z","releases":[{"id":"rel_ZaT4YYE8FFVsPtQmEWeYl","version":"v2.0.7","type":"feature","title":"v2.0.7","summary":"Fixed bugs where namespaces and node pools could stop replicating between federated regions or be deleted in a follower region by an invalid replication token. Also fixes task restarts skipping shutdown_delay, image_pull_timeout not being respected past 5min, and unchanged jobs creating new versions when submitted with a different ACL token.","titleGenerated":"Nomad v2.0.7 fixes federation namespace and node pool replication","titleShort":"Federation replication fixed; shutdown_delay no longer skipped","breaking":"none","importance":3,"content":"\nIMPROVEMENTS:\n\n* dependency: Upgrade to the latest buf (1.72.0), protoc-gen-go (1.36.6), and protoc-gen-go-grpc (1.5.1) [[GH-28525](https://github.com/hashicorp/nomad/issues/28525)]\n* services: the default workload identity policy now allows using wildcard namespace queries for Nomad native services [[GH-28534](https://github.com/hashicorp/nomad/issues/28534)]\n* ui: fixed accessibility color contrast issues [[GH-28022](https://github.com/hashicorp/nomad/issues/28022)]\n\nBUG FIXES:\n\n* api: Fix job statuses error when request body is empty using HTTP2 [[GH-28541](https://github.com/hashicorp/nomad/issues/28541)]\n* client: Fixed a bug where task restart skipped `shutdown_delay` [[GH-25289](https://github.com/hashicorp/nomad/issues/25289)]\n* core: Fixed a bug where re-submitting an otherwise unchanged job with a different ACL token created a new job version and deployment [[GH-26810](https://github.com/hashicorp/nomad/issues/26810)]\n* deployments: Fixed a bug where system job updates would not result in a new deployment if the prior deployment failed [[GH-28545](https://github.com/hashicorp/nomad/issues/28545)]\n* docker: Fixed a bug where image_pull_timeout was not respected if more than 5min [[GH-28543](https://github.com/hashicorp/nomad/issues/28543)]\n* identity: Fixed a bug where clients would not attempt to recreate expired node identities [[GH-28566](https://github.com/hashicorp/nomad/issues/28566)]\n* namespaces: Fixed a bug where an invalid replication token could delete namespaces in a federated follower region [[GH-28552](https://github.com/hashicorp/nomad/issues/28552)]\n* namespaces: Fixed a bug where namespaces could stop replicating between federated regions [[GH-28552](https://github.com/hashicorp/nomad/issues/28552)]\n* node pools: Fixed a bug where an invalid replication token could delete node pools in a federated follower region [[GH-28552](https://github.com/hashicorp/nomad/issues/28552)]\n* node pools: Fixed a bug where blocking queries would not unblock if a node pool was added automatically by registering a node [[GH-28552](https://github.com/hashicorp/nomad/issues/28552)]\n* node pools: Fixed a bug where node pools could stop replicating between federated regions [[GH-28552](https://github.com/hashicorp/nomad/issues/28552)]","publishedAt":"2026-09-18T16:18:15.000Z","fetchedAt":"2026-09-18T19:35:21.697Z","url":"https://github.com/hashicorp/nomad/releases/tag/v2.0.7","media":[],"coverageCount":0},{"id":"rel_AM7UJ9TFsALz4FmmyPyTw","version":"v2.0.6","type":"feature","title":"v2.0.6","summary":"Closes a security hole where the Alloc FS API could access a secret directory symlinked into a task, and fixes a scheduler bug where task groups with per_alloc volumes could skip feasibility checks for allocs after the first placement failure. Also includes a go-getter security dependency upgrade and a Vault change_mode trigger fix.","titleGenerated":"Nomad v2.0.6 blocks secret dir access, fixes per_alloc feasibility checks","titleShort":"Secret-dir symlink access blocked; per_alloc feasibility fixed","breaking":"none","importance":3,"content":"\nSECURITY:\n\n* dependency: Upgrade to the latests go-getter [[GH-28510](https://github.com/hashicorp/nomad/issues/28510)]\n\nIMPROVEMENTS:\n\n* api: Updated the Go module to require at least 1.26.0 [[GH-28460](https://github.com/hashicorp/nomad/issues/28460)]\n* build: Updated Go to v1.27.1 [[GH-28451](https://github.com/hashicorp/nomad/issues/28451)]\n* client: Added the `unique.host_id` node attribute to the host fingerprint, when available [[GH-28406](https://github.com/hashicorp/nomad/issues/28406)]\n* job: Allow setting `reschedule.delay` to values as low as 1s [[GH-28477](https://github.com/hashicorp/nomad/issues/28477)]\n* jobspec2: Decouple from Nomad core with isolated Go module named `github.com/hashicorp/nomad/jobspec2` [[GH-28419](https://github.com/hashicorp/nomad/issues/28419)]\n* scheduler: Improved robustness of reschedule logic for invalid states [[GH-28445](https://github.com/hashicorp/nomad/issues/28445)]\n* ui: prevent stuck requests due to exceeding connection limit, enable HTTP2 [[GH-28364](https://github.com/hashicorp/nomad/issues/28364)]\n\nBUG FIXES:\n\n* api: Fixed a bug where a job plan diff sorted indexed fields such as `args` lexically, listing `args[10]` before `args[2]` [[GH-4421](https://github.com/hashicorp/nomad/issues/4421)]\n* client: prevent Alloc FS API from accessing secret dir when symlinked into task [[GH-28468](https://github.com/hashicorp/nomad/issues/28468)]\n* core: Fixed a bug where an artifact `checksum` of the form `file:<url>` (fetching the checksum from a remote file) was rejected during job validation [[GH-9764](https://github.com/hashicorp/nomad/issues/9764)]\n* jobspec: Fixed a bug where a task group containing only lifecycle tasks and no main task was accepted during job validation [[GH-17570](https://github.com/hashicorp/nomad/issues/17570)]\n* planner: Fixed a bug where valid evaluations could be unnecessarily retried, delaying workload placement under load [[GH-28452](https://github.com/hashicorp/nomad/issues/28452)]\n* scheduler: Fixed a bug where task groups with `per_alloc` volumes could skip real feasibility checks for allocs after the first placement failure in the same task group [[GH-28422](https://github.com/hashicorp/nomad/issues/28422)]\n* state: Fixed a bug where plans from older versioned followers did not have allocation resource schemas upgraded when written on the leader [[GH-28447](https://github.com/hashicorp/nomad/issues/28447)]\n* vault: Fixed a bug where a task's change_mode was triggered on each Vault token renewal [[GH-28409](https://github.com/hashicorp/nomad/issues/28409)]\n* vault: fixes an issue where dead tasks continued to have their tokens renewed [[GH-28501](https://github.com/hashicorp/nomad/issues/28501)]","publishedAt":"2026-09-09T19:55:19.000Z","fetchedAt":"2026-09-09T23:33:50.434Z","url":"https://github.com/hashicorp/nomad/releases/tag/v2.0.6","media":[],"coverageCount":0},{"id":"rel_PCPqcc2Gf49RCqYUSMPze","version":"v2.0.5","type":"feature","title":"v2.0.5","summary":"The DriverNetwork.Hash method is removed from the plugin/drivers package. Fixed a Docker bug where tasks could escape their assigned cpuset range, plus a fix preventing deleted allocations from remaining running.","titleGenerated":"Nomad v2.0.5 removes DriverNetwork.Hash and hardens Docker task isolation","titleShort":"DriverNetwork.Hash removed; Docker cpuset bug fixed","breaking":"major","importance":4,"content":"\nBREAKING CHANGES:\n\n* plugin: The `DriverNetwork.Hash` method has been removed from the `plugin/drivers` package. [[GH-28342](https://github.com/hashicorp/nomad/issues/28342)]\n\nIMPROVEMENTS:\n\n* build: Update Go to v1.26.5 [[GH-28260](https://github.com/hashicorp/nomad/issues/28260)]\n* checks: Nomad native service check IDs are now SHA256 [[GH-28361](https://github.com/hashicorp/nomad/issues/28361)]\n* cli: add `-json-output` and `-t` flags to `nomad job plan` for structured plan output [[GH-27369](https://github.com/hashicorp/nomad/issues/27369)]\n* consul: Added the issuing Nomad client's node ID to the metadata of Consul tokens created via workload identity [[GH-28133](https://github.com/hashicorp/nomad/issues/28133)]\n* consul: Check IDs are now derived from SHA256 instead of SHA1 [[GH-28362](https://github.com/hashicorp/nomad/issues/28362)]\n* jobspec: Removed the requirement that a variable validation `error_message` be a full English sentence, allowing messages written in any language [[GH-28246](https://github.com/hashicorp/nomad/issues/28246)]\n* planner: Added plan_apply_pipeline configuration that allows the leader to have more outstanding Raft writes when evaluating plans [[GH-28249](https://github.com/hashicorp/nomad/issues/28249)]\n* services: rendezvous hashes are now SHA256 [[GH-28363](https://github.com/hashicorp/nomad/issues/28363)]\n* template: Add `run_on_first_render` option to `change_script` to execute scripts on the initial template render via the task Poststart lifecycle hook. [[GH-27819](https://github.com/hashicorp/nomad/issues/27819)]\n\nBUG FIXES:\n\n* agent: Fixed a bug where the startup banner would display the wrong node ID for servers after restart [[GH-28276](https://github.com/hashicorp/nomad/issues/28276)]\n* api: Fixed a bug where the client allocation endpoints returned a 500 error instead of a 404 when the allocation's node could not be found [[GH-28261](https://github.com/hashicorp/nomad/issues/28261)]\n* auth: Fixed a bug where nodes could not sync allocations placed on them after being moved to a different node pool [[GH-28110](https://github.com/hashicorp/nomad/issues/28110)]\n* cli: Fixed a bug where `nomad operator root keyring remove` would not accept an abbreviated key ID [[GH-24148](https://github.com/hashicorp/nomad/issues/24148)]\n* client: Fix issue where deleted allocations may remain running [[GH-28394](https://github.com/hashicorp/nomad/issues/28394)]\n* client: Fixed a bug where a client could panic after an alloc is GC'd [[GH-28187](https://github.com/hashicorp/nomad/issues/28187)]\n* client: Fixed a bug where the client would not remount the secret and private tmpfs after a restart [[GH-28345](https://github.com/hashicorp/nomad/issues/28345)]\n* client: Fixed a bug where the previous allocation watcher would retry forever when the server returned a permanent error during data migration [[GH-28191](https://github.com/hashicorp/nomad/issues/28191)]\n* csi: Fixed a bug where evals blocked on missing CSI volumes would not unblock [[GH-28275](https://github.com/hashicorp/nomad/issues/28275)]\n* deployments: Fix garbage collection to respect threshold [[GH-28225](https://github.com/hashicorp/nomad/issues/28225)]\n* docker: Fixed a bug where tasks could execute outside of their assigned cpuset range [[GH-28272](https://github.com/hashicorp/nomad/issues/28272)]\n* drivers/java: Fixed a bug where the Java driver did not correctly decode the `work_dir` option [[GH-28330](https://github.com/hashicorp/nomad/issues/28330)]\n* jobspec: Fixed a bug where a negative `cores` value in a task's resource block was accepted during job validation and registration [[GH-10511](https://github.com/hashicorp/nomad/issues/10511)]\n* quota (Enterprise): Fixed a bug where disabling the use of cores in a quota would block the ability to use either cores or CPU in a job\n* scheduler: Ensure deployment IDs are not written to an evaluation when the generated deployment is not persisted to state due to plan apply retries [[GH-28307](https://github.com/hashicorp/nomad/issues/28307)]\n* scheduler: Fixed a bug where the scheduler could panic with a nil pointer dereference when checking host volume feasibility for an allocation whose job had been purged [[GH-28301](https://github.com/hashicorp/nomad/issues/28301)]\n* secrets: Fixed hooks to allow refetch during prestart [[GH-28237](https://github.com/hashicorp/nomad/issues/28237)]\n* services: Fixed a bug where task secrets were not interpolated into service check `Header` and `Args`, or into service `Tags` [[GH-28212](https://github.com/hashicorp/nomad/issues/28212)]\n* ui: Fixed SSO sign in display not displaying when SSO enabled [[GH-28262](https://github.com/hashicorp/nomad/issues/28262)]\n* ui: Fixed a bug where the job status panel would show \"Complete\" instead of \"Scaled Down\" for system and sysbatch jobs with zero allocations [[GH-27949](https://github.com/hashicorp/nomad/issues/27949)]\n* ui: Fixed the region identifier header showing as empty in single region clusters [[GH-28310](https://github.com/hashicorp/nomad/issues/28310)]\n* ui: Fixed version diff display and missing deployment version numbers [[GH-28294](https://github.com/hashicorp/nomad/issues/28294)]\n* ui: check websocket upgrade headers with multiple values [[GH-28234](https://github.com/hashicorp/nomad/issues/28234)]\n* ui: refetch nomad license when logging in with new token [[GH-28284](https://github.com/hashicorp/nomad/issues/28284)]","publishedAt":"2026-08-13T00:16:33.000Z","fetchedAt":"2026-08-13T02:52:05.316Z","url":"https://github.com/hashicorp/nomad/releases/tag/v2.0.5","media":[],"coverageCount":0},{"id":"rel_PztcJAfwhvBMSHKnANjW_","version":"ent-changelog-1.11.8","type":"feature","title":"v1.11.8 (Enterprise)","summary":"Fixed two Docker security issues: enforcement of allowed_modes or allow_privileged requirement for host namespace modes (CVE-2026-14891), and a symlink bypass of the volumes.enabled=false plugin configuration (CVE-2026-14896). Also fixed a cross-namespace host volume deletion bug and several scheduler issues affecting sticky volumes and feasibility checking.","titleGenerated":"Nomad v1.11.8 Enterprise fixes Docker and host volume security issues","titleShort":"Docker host namespace and symlink exploits fixed; namespace isolation hardened","breaking":"none","importance":4,"content":"SECURITY:\r\n\r\n* docker: Enforce `allowed_modes` or `allow_privileged` requirement to set host namespace modes in task. This is CVE-2026-14891. [[GH-28190](https://github.com/hashicorp/nomad/issues/28190)]\r\n* docker: Fixed a bug where docker tasks could use a symlink to bypass the plugin configuration for volumes.enabled=false. This is CVE-2026-14896. [[GH-28177](https://github.com/hashicorp/nomad/issues/28177)]\r\n* dynamic host volumes: Fixed a bug where users with `host-volume-delete` in one namespace could delete claims from another namespace [[GH-28205](https://github.com/hashicorp/nomad/issues/28205)]\r\n\r\nIMPROVEMENTS:\r\n\r\n* consul: Allow service, template, and connect blocks to fallback to the Nomad client agent's Consul token if workload identity is unavailable [[GH-28106](https://github.com/hashicorp/nomad/issues/28106)]\r\n* driver: Added optional `Init` function for task driver plugins [[GH-28104](https://github.com/hashicorp/nomad/issues/28104)]\r\n* driver: Added optional `Shutdown` function for task driver plugins [[GH-28102](https://github.com/hashicorp/nomad/issues/28102)]\r\n\r\nBUG FIXES:\r\n\r\n* api: allow using WI tokens on plan endpoint [[GH-28139](https://github.com/hashicorp/nomad/issues/28139)]\r\n* cli: Fixed a bug where complex HCL variables passed via -var flag could not be edited in the web UI [[GH-28138](https://github.com/hashicorp/nomad/issues/28138)]\r\n* dynamic host volumes: Fixed a bug where allocations claiming host volumes with the per_alloc flag would not prevent the volume from being deleted [[GH-28198](https://github.com/hashicorp/nomad/issues/28198)]\r\n* metrics: expired metrics are now periodically cleared from the Prometheus sink even if no collection occurs [[GH-28170](https://github.com/hashicorp/nomad/issues/28170)]\r\n* scheduler: Fixed a bug where a node could be marked feasible for a task group requesting multiple host volumes when a satisfied sticky volume request short-circuited the checks for the remaining requests [[GH-28097](https://github.com/hashicorp/nomad/issues/28097)]\r\n* scheduler: Fixed a bug where setting `sticky` on a static host volume could fail the evaluation instead of being rejected during feasibility checking [[GH-28097](https://github.com/hashicorp/nomad/issues/28097)]\r\n* scheduler: keep draining batch alloc counted when node is re-enabled [[GH-28018](https://github.com/hashicorp/nomad/issues/28018)]\r\n* task runner: Improve the memory management for secrets [[GH-28140](https://github.com/hashicorp/nomad/issues/28140)]\r\n* ui: Fixed a bug where jobs that share a ModifyIndex (for example, several jobs rescheduled in a single Raft transaction after a node failure) were omitted from the jobs page and the `/v1/jobs/statuses` endpoint [[GH-28132](https://github.com/hashicorp/nomad/issues/28132)]\r\n* ui: fixes an issue where streaming task logs would error [[GH-28137](https://github.com/hashicorp/nomad/issues/28137)]","publishedAt":"2026-07-08T16:53:09.000Z","fetchedAt":"2026-07-08T18:23:51.968Z","url":"https://github.com/hashicorp/nomad/releases/tag/ent-changelog-1.11.8","media":[],"coverageCount":0},{"id":"rel_mJuRhbNhwaKAVtfoZaBUr","version":"ent-changelog-1.10.14","type":"feature","title":"v1.10.14 (Enterprise)","summary":"Fixed two Docker security issues: CVE-2026-14891 enforces allowed_modes or allow_privileged requirement for host namespace modes, and CVE-2026-14896 closes a symlink bypass for volumes.enabled=false. Also fixed a cross-namespace host volume deletion vulnerability and multiple scheduler and UI bugs including a ModifyIndex collision that omitted jobs from the jobs page.","titleGenerated":"Nomad v1.10.14 fixes Docker privilege escalation and namespace isolation bugs","titleShort":"Docker privilege escalation fixed; namespace isolation hardened","breaking":"minor","importance":4,"content":"SECURITY:\r\n\r\n* docker: Enforce `allowed_modes` or `allow_privileged` requirement to set host namespace modes in task. This is CVE-2026-14891. [[GH-28190](https://github.com/hashicorp/nomad/issues/28190)]\r\n* docker: Fixed a bug where docker tasks could use a symlink to bypass the plugin configuration for volumes.enabled=false. This is CVE-2026-14896. [[GH-28177](https://github.com/hashicorp/nomad/issues/28177)]\r\n* dynamic host volumes: Fixed a bug where users with `host-volume-delete` in one namespace could delete claims from another namespace [[GH-28205](https://github.com/hashicorp/nomad/issues/28205)]\r\n\r\nIMPROVEMENTS:\r\n\r\n* consul: Allow service, template, and connect blocks to fallback to the Nomad client agent's Consul token if workload identity is unavailable [[GH-28106](https://github.com/hashicorp/nomad/issues/28106)]\r\n* driver: Added optional `Init` function for task driver plugins [[GH-28104](https://github.com/hashicorp/nomad/issues/28104)]\r\n* driver: Added optional `Shutdown` function for task driver plugins [[GH-28102](https://github.com/hashicorp/nomad/issues/28102)]\r\n\r\nBUG FIXES:\r\n\r\n* api: allow using WI tokens on plan endpoint [[GH-28139](https://github.com/hashicorp/nomad/issues/28139)]\r\n* cli: Fixed a bug where complex HCL variables passed via -var flag could not be edited in the web UI [[GH-28138](https://github.com/hashicorp/nomad/issues/28138)]\r\n* dynamic host volumes: Fixed a bug where allocations claiming host volumes with the per_alloc flag would not prevent the volume from being deleted [[GH-28198](https://github.com/hashicorp/nomad/issues/28198)]\r\n* metrics: expired metrics are now periodically cleared from the Prometheus sink even if no collection occurs [[GH-28170](https://github.com/hashicorp/nomad/issues/28170)]\r\n* scheduler: Fixed a bug where a node could be marked feasible for a task group requesting multiple host volumes when a satisfied sticky volume request short-circuited the checks for the remaining requests [[GH-28097](https://github.com/hashicorp/nomad/issues/28097)]\r\n* scheduler: Fixed a bug where setting `sticky` on a static host volume could fail the evaluation instead of being rejected during feasibility checking [[GH-28097](https://github.com/hashicorp/nomad/issues/28097)]\r\n* scheduler: keep draining batch alloc counted when node is re-enabled [[GH-28018](https://github.com/hashicorp/nomad/issues/28018)]\r\n* task runner: Improve the memory management for secrets [[GH-28140](https://github.com/hashicorp/nomad/issues/28140)]\r\n* ui: Fixed a bug where jobs that share a ModifyIndex (for example, several jobs rescheduled in a single Raft transaction after a node failure) were omitted from the jobs page and the `/v1/jobs/statuses` endpoint [[GH-28132](https://github.com/hashicorp/nomad/issues/28132)]\r\n* ui: fixes an issue where streaming task logs would error [[GH-28137](https://github.com/hashicorp/nomad/issues/28137)]","publishedAt":"2026-07-08T16:31:37.000Z","fetchedAt":"2026-07-08T18:23:51.968Z","url":"https://github.com/hashicorp/nomad/releases/tag/ent-changelog-1.10.14","media":[],"coverageCount":0},{"id":"rel_VgbpPluxs63m-FO9Xs0tP","version":"v2.0.4","type":"feature","title":"v2.0.4","summary":"Fixed a security bug where users with `host-volume-delete` permission in one namespace could delete claims from another namespace. Also fixed scheduler issues with sticky host volumes, a client panic after allocation garbage collection, and UI rendering of jobs with matching ModifyIndex values.","titleGenerated":"Nomad v2.0.4 fixes namespace isolation bug in dynamic host volumes","titleShort":"Dynamic host volumes namespace isolation fixed","breaking":"minor","importance":4,"content":"## 2.0.4 (July 07, 2026)\n\nSECURITY:\n\n* dynamic host volumes: Fixed a bug where users with `host-volume-delete` in one namespace could delete claims from another namespace [[GH-28205](https://github.com/hashicorp/nomad/issues/28205)]\n\nIMPROVEMENTS:\n\n* cli: Add a `-kv-path` flag to `nomad setup vault` to configure the Vault KV mount used by the generated workload policy [[GH-28183](https://github.com/hashicorp/nomad/issues/28183)]\n* cli: Added `-json` and `-t` options to the `operator autopilot get-config` command. [[GH-27991](https://github.com/hashicorp/nomad/issues/27991)]\n* client: Add tunable for Vault default lease duration on templates for paths without leases. [[GH-28199](https://github.com/hashicorp/nomad/issues/28199)]\n* consul: Allow service, template, and connect blocks to fallback to the Nomad client agent's Consul token if workload identity is unavailable [[GH-28106](https://github.com/hashicorp/nomad/issues/28106)]\n* driver: Added optional `Init` function for task driver plugins [[GH-28104](https://github.com/hashicorp/nomad/issues/28104)]\n* driver: Added optional `Shutdown` function for task driver plugins [[GH-28102](https://github.com/hashicorp/nomad/issues/28102)]\n* scheduler: Stop failed allocations first when downscaling a task group [[GH-27971](https://github.com/hashicorp/nomad/issues/27971)]\n\nDEPRECATIONS:\n\n* agent: Unauthenticated server join via the CLI or API is deprecated. [[GH-28176](https://github.com/hashicorp/nomad/issues/28176)]\n\nBUG FIXES:\n\n* api: allow using WI tokens on plan endpoint [[GH-28139](https://github.com/hashicorp/nomad/issues/28139)]\n* cli: Fixed a bug where complex HCL variables passed via -var flag could not be edited in the web UI [[GH-28138](https://github.com/hashicorp/nomad/issues/28138)]\n* client: Fixed a bug where a client could panic after an alloc is GC'd [[GH-28185](https://github.com/hashicorp/nomad/issues/28185)]\n* docker: Enforce allowed_modes or allow_privileged requirement to set host namespace modes in task [[GH-28190](https://github.com/hashicorp/nomad/issues/28190)]\n* dynamic host volumes: Fixed a bug where allocations claiming host volumes with the per_alloc flag would not prevent the volume from being deleted [[GH-28198](https://github.com/hashicorp/nomad/issues/28198)]\n* metrics: expired metrics are now periodically cleared from the Prometheus sink even if no collection occurs [[GH-28170](https://github.com/hashicorp/nomad/issues/28170)]\n* scheduler: Fixed a bug where a node could be marked feasible for a task group requesting multiple host volumes when a satisfied sticky volume request short-circuited the checks for the remaining requests [[GH-28097](https://github.com/hashicorp/nomad/issues/28097)]\n* scheduler: Fixed a bug where setting `sticky` on a static host volume could fail the evaluation instead of being rejected during feasibility checking [[GH-28097](https://github.com/hashicorp/nomad/issues/28097)]\n* scheduler: keep draining batch alloc counted when node is re-enabled [[GH-28018](https://github.com/hashicorp/nomad/issues/28018)]\n* task runner: Improve the memory management for secrets [[GH-28140](https://github.com/hashicorp/nomad/issues/28140)]\n* ui: Fixed a bug where jobs that share a ModifyIndex (for example, several jobs rescheduled in a single Raft transaction after a node failure) were omitted from the jobs page and the `/v1/jobs/statuses` endpoint [[GH-28132](https://github.com/hashicorp/nomad/issues/28132)]\n* ui: fixes an issue where streaming task logs would error [[GH-28137](https://github.com/hashicorp/nomad/issues/28137)]\n\n","publishedAt":"2026-07-07T19:12:06.000Z","fetchedAt":"2026-07-07T21:54:35.603Z","url":"https://github.com/hashicorp/nomad/releases/tag/v2.0.4","media":[],"coverageCount":0},{"id":"rel_GtkxMmL_QxMgzBmXvppmW","version":"ent-changelog-1.10.13","type":"feature","title":"v1.10.13 (Enterprise)","summary":"CLI debug bundles now redact token and certificate key flags and environment variables to prevent credential exposure. Fixed a bug where tasks could be killed mid-restart on template re-render, and restored support for multiple Vault namespaces in a single job.","titleGenerated":"Nomad v1.10.13 Enterprise redacts tokens from debug bundles and fixes task restart bug","titleShort":"Debug bundles no longer expose tokens; task restart bug fixed","breaking":"unknown","importance":null,"content":"SECURITY:\r\n\r\n* cli: Redact token and certificate key CLI flags and environment variables when writing debug bundle [[GH-28063](https://github.com/hashicorp/nomad/issues/28063)]\r\n\r\nIMPROVEMENTS:\r\n\r\n* build: Updated Go to 1.26.4 [[GH-28080](https://github.com/hashicorp/nomad/issues/28080)]\r\n* vault: adds token renewal retries [[GH-27947](https://github.com/hashicorp/nomad/issues/27947)]\r\n\r\nBUG FIXES:\r\n\r\n* audit (Enterprise): Fixed a bug where alloc exec and job actions requests from the webbrowser would be marked as anonymous in audit logs [[GH-28025](https://github.com/hashicorp/nomad/issues/28025)]\r\n* client: Fixed a bug where tasks could accidentally get killed mid-restart on template re-render [[GH-27960](https://github.com/hashicorp/nomad/issues/27960)]\r\n* client: fix a bug where we could accidentally overwrite task states [[GH-27944](https://github.com/hashicorp/nomad/issues/27944)]\r\n* consul: re-write consul service identity token when reattaching to task [[GH-27936](https://github.com/hashicorp/nomad/issues/27936)]\r\n* job (Enterprise): Renabled use of multiple vault namespaces in a single job\r\n* plugins: store verified and canonicalised plugin configuration in the agent [[GH-28083](https://github.com/hashicorp/nomad/issues/28083)]\r\n* template: Fixed a bug where templates with `change_mode=noop` would stop monitoring templates that fatally fail after initial rendering [[GH-28016](https://github.com/hashicorp/nomad/issues/28016)]\r\n* ui: Fix a bug where jobs with HCL variables submitted via Terraform could not be started or stopped in the web UI [[GH-28095](https://github.com/hashicorp/nomad/issues/28095)]\r\n* ui: Fix service detail page not rendering [[GH-28005](https://github.com/hashicorp/nomad/issues/28005)]\r\n* ui: Fixed a bug where the evaluation detail panel would render improperly [[GH-27987](https://github.com/hashicorp/nomad/issues/27987)]\r\n* ui: Fixed flickering on the log streaming pop out when viewing them from job overview page [[GH-28074](https://github.com/hashicorp/nomad/issues/28074)]\r\n* ui: Fixed the client drain popover form to provide an accessible name for assistive technologies [[GH-28047](https://github.com/hashicorp/nomad/issues/28047)]\r\n* ui: Fixed the drain popover deadline field so its label is properly associated with the input for improved accessibility [[GH-28029](https://github.com/hashicorp/nomad/issues/28029)]\r\n* ui: Fixed the namespace list being continually fetched when on the job overview page [[GH-28074](https://github.com/hashicorp/nomad/issues/28074)]","publishedAt":"2026-06-09T20:50:39.000Z","fetchedAt":"2026-06-09T23:05:49.214Z","url":"https://github.com/hashicorp/nomad/releases/tag/ent-changelog-1.10.13","media":[],"coverageCount":0},{"id":"rel_cnFxd2jf2WE12PMmHyh-M","version":"ent-changelog-1.11.7","type":"feature","title":"v1.11.7 (Enterprise)","summary":"Debug bundles now redact sensitive token and certificate key CLI flags and environment variables. Fixed a bug where tasks could be accidentally killed mid-restart on template re-render, and re-enabled use of multiple Vault namespaces in a single Enterprise job.","titleGenerated":"Nomad v1.11.7 Enterprise redacts sensitive CLI flags and fixes task restart bug","titleShort":"CLI flags redacted in debug bundles; task restart bug fixed","breaking":"unknown","importance":null,"content":"SECURITY:\r\n\r\n* cli: Redact token and certificate key CLI flags and environment variables when writing debug bundle [[GH-28063](https://github.com/hashicorp/nomad/issues/28063)]\r\n\r\nIMPROVEMENTS:\r\n\r\n* build: Updated Go to 1.26.4 [[GH-28080](https://github.com/hashicorp/nomad/issues/28080)]\r\n* vault: adds token renewal retries [[GH-27947](https://github.com/hashicorp/nomad/issues/27947)]\r\n\r\nBUG FIXES:\r\n\r\n* audit (Enterprise): Fixed a bug where alloc exec and job actions requests from the webbrowser would be marked as anonymous in audit logs [[GH-28025](https://github.com/hashicorp/nomad/issues/28025)]\r\n* client: Fixed a bug where tasks could accidentally get killed mid-restart on template re-render [[GH-27960](https://github.com/hashicorp/nomad/issues/27960)]\r\n* client: fix a bug where we could accidentally overwrite task states [[GH-27944](https://github.com/hashicorp/nomad/issues/27944)]\r\n* consul: re-write consul service identity token when reattaching to task [[GH-27936](https://github.com/hashicorp/nomad/issues/27936)]\r\n* job (Enterprise): Renabled use of multiple vault namespaces in a single job\r\n* plugins: store verified and canonicalised plugin configuration in the agent [[GH-28083](https://github.com/hashicorp/nomad/issues/28083)]\r\n* template: Fixed a bug where templates with `change_mode=noop` would stop monitoring templates that fatally fail after initial rendering [[GH-28016](https://github.com/hashicorp/nomad/issues/28016)]\r\n* ui: Fix a bug where jobs with HCL variables submitted via Terraform could not be started or stopped in the web UI [[GH-28095](https://github.com/hashicorp/nomad/issues/28095)]\r\n* ui: Fix service detail page not rendering [[GH-28005](https://github.com/hashicorp/nomad/issues/28005)]\r\n* ui: Fixed a bug where the evaluation detail panel would render improperly [[GH-27987](https://github.com/hashicorp/nomad/issues/27987)]\r\n* ui: Fixed flickering on the log streaming pop out when viewing them from job overview page [[GH-28074](https://github.com/hashicorp/nomad/issues/28074)]\r\n* ui: Fixed the client drain popover form to provide an accessible name for assistive technologies [[GH-28047](https://github.com/hashicorp/nomad/issues/28047)]\r\n* ui: Fixed the drain popover deadline field so its label is properly associated with the input for improved accessibility [[GH-28029](https://github.com/hashicorp/nomad/issues/28029)]\r\n* ui: Fixed the namespace list being continually fetched when on the job overview page [[GH-28074](https://github.com/hashicorp/nomad/issues/28074)]","publishedAt":"2026-06-09T20:50:22.000Z","fetchedAt":"2026-06-09T23:05:49.214Z","url":"https://github.com/hashicorp/nomad/releases/tag/ent-changelog-1.11.7","media":[],"coverageCount":0},{"id":"rel_jyEpiQvZK_hjgKO48jQhl","version":"v2.0.3","type":"feature","title":"v2.0.3","summary":"CLI flags and environment variables containing tokens and certificate keys are now redacted when writing debug bundles, addressing a security exposure. Added support for timeouts on batch jobs, and improved ACL token handling, Vault token renewal, and workload identity claims.","titleGenerated":"Nomad v2.0.3 redacts sensitive CLI flags in debug bundles and adds batch job timeouts","titleShort":"Debug bundles no longer expose tokens/certs; batch job timeouts added","breaking":"unknown","importance":null,"content":"\nFEATURES:\n\n* core: timeouts for batch jobs [[GH-27803](https://github.com/hashicorp/nomad/issues/27803)]\n\nSECURITY:\n\n* cli: Redact token and certificate key CLI flags and environment variables when writing debug bundle [[GH-28063](https://github.com/hashicorp/nomad/issues/28063)]\n\nIMPROVEMENTS:\n\n* acl: Support uploading client ACL tokens [[GH-27741](https://github.com/hashicorp/nomad/issues/27741)]\n* alloc: don't restore when allocDir is inaccessible [[GH-27933](https://github.com/hashicorp/nomad/issues/27933)]\n* api: added agent reload endpoint [[GH-27106](https://github.com/hashicorp/nomad/issues/27106)]\n* build: Updated Go to 1.26.4 [[GH-28080](https://github.com/hashicorp/nomad/issues/28080)]\n* client: Adds default_ineligible configuration option [[GH-27965](https://github.com/hashicorp/nomad/issues/27965)]\n* identity: allow additional claims to be added to workload identities [[GH-27786](https://github.com/hashicorp/nomad/issues/27786)]\n* vault: adds token renewal retries [[GH-27947](https://github.com/hashicorp/nomad/issues/27947)]\n\nBUG FIXES:\n\n* audit (Enterprise): Fixed a bug where alloc exec and job actions requests from the webbrowser would be marked as anonymous in audit logs [[GH-28025](https://github.com/hashicorp/nomad/issues/28025)]\n* cli: Fixed `job dispatch` and `job periodic force` failing with a paginator error against servers older than the CLI [[GH-27680](https://github.com/hashicorp/nomad/issues/27680)]\n* client: Fixed a bug where tasks could accidentally get killed mid-restart on template re-render [[GH-27960](https://github.com/hashicorp/nomad/issues/27960)]\n* consul: re-write consul service identity token when reattaching to task [[GH-27936](https://github.com/hashicorp/nomad/issues/27936)]\n* job (Enterprise): Renabled use of multiple vault namespaces in a single job\n* plugins: store verified and canonicalised plugin configuration in the agent [[GH-28083](https://github.com/hashicorp/nomad/issues/28083)]\n* template: Fixed a bug where templates with `change_mode=noop` would stop monitoring templates that fatally fail after initial rendering [[GH-28016](https://github.com/hashicorp/nomad/issues/28016)]\n* ui: Fix a bug where jobs with HCL variables submitted via Terraform could not be started or stopped in the web UI [[GH-28095](https://github.com/hashicorp/nomad/issues/28095)]\n* ui: Fix service detail page not rendering [[GH-28005](https://github.com/hashicorp/nomad/issues/28005)]\n* ui: Fixed flickering on the log streaming pop out when viewing them from job overview page [[GH-28074](https://github.com/hashicorp/nomad/issues/28074)]\n* ui: Fixed the client drain popover form to provide an accessible name for assistive technologies [[GH-28047](https://github.com/hashicorp/nomad/issues/28047)]\n* ui: Fixed the drain popover deadline field so its label is properly associated with the input for improved accessibility [[GH-28029](https://github.com/hashicorp/nomad/issues/28029)]\n* ui: Fixed the namespace list being continually fetched when on the job overview page [[GH-28074](https://github.com/hashicorp/nomad/issues/28074)]","publishedAt":"2026-06-09T18:40:56.000Z","fetchedAt":"2026-06-09T23:05:49.214Z","url":"https://github.com/hashicorp/nomad/releases/tag/v2.0.3","media":[],"coverageCount":0},{"id":"rel_Nakng4Zpbb3O6dTFesdXU","version":"ent-changelog-1.10.12","type":"feature","title":"v1.10.12 (Enterprise)","summary":"Fixed bugs where the client detail page, topology page, and evaluation detail panel would fail to render or render improperly in the UI.","titleGenerated":"Nomad v1.10.12 Enterprise fixes UI rendering on client and topology pages","titleShort":"Client detail, topology, and evaluation detail pages render correctly","breaking":"unknown","importance":null,"content":"## 1.10.12 Enterprise (May 22, 2026)\r\n\r\nBUG FIXES:\r\n\r\n* ui: Fixed a bug where the client detail page would fail to render [[GH-27958](https://github.com/hashicorp/nomad/issues/27958)]\r\n* ui: Fixed a bug where the topology page would fail to render [[GH-27958](https://github.com/hashicorp/nomad/issues/27958)]\r\n* ui: Fixed a bug where the evaluation detail panel would render improperly [[GH-27987](https://github.com/hashicorp/nomad/issues/27987)]","publishedAt":"2026-05-22T18:06:10.000Z","fetchedAt":"2026-05-22T20:05:34.160Z","url":"https://github.com/hashicorp/nomad/releases/tag/ent-changelog-1.10.12","media":[],"coverageCount":0},{"id":"rel_LCZ6GfxD_oDzXuZuChUTj","version":"ent-changelog-1.11.6","type":"feature","title":"v1.11.6 (Enterprise)","summary":"Fixed UI rendering failures on the client detail page and topology page, and improper rendering of the evaluation detail panel.","titleGenerated":"Nomad v1.11.6 Enterprise fixes UI rendering on client detail and topology pages","titleShort":"Client detail and topology pages render; evaluation panel fixed","breaking":"unknown","importance":null,"content":"## 1.11.6 Enterprise (May 22, 2026)\r\n\r\nBUG FIXES:\r\n\r\n* ui: Fixed a bug where the client detail page would fail to render [[GH-27958](https://github.com/hashicorp/nomad/issues/27958)]\r\n* ui: Fixed a bug where the topology page would fail to render [[GH-27958](https://github.com/hashicorp/nomad/issues/27958)]\r\n* ui: Fixed a bug where the evaluation detail panel would render improperly [[GH-27987](https://github.com/hashicorp/nomad/issues/27987)]\r\n","publishedAt":"2026-05-22T18:05:37.000Z","fetchedAt":"2026-05-22T20:05:34.160Z","url":"https://github.com/hashicorp/nomad/releases/tag/ent-changelog-1.11.6","media":[],"coverageCount":0},{"id":"rel_hsxNFFwM1XCUk_4fq1Wv1","version":"v2.0.2","type":"feature","title":"v2.0.2","summary":"Fixed an RPC permission denied error when using node_pool=\"all\" in ACL rules. Also fixed UI rendering bugs affecting the client detail page, topology page, and evaluation detail panel.","titleGenerated":"Nomad v2.0.2 fixes ACL permission denied error and UI rendering bugs","titleShort":"ACL node_pool=\"all\" permission error fixed; UI rendering bugs resolved","breaking":"unknown","importance":null,"content":"## 2.0.2 (May 22, 2026)\r\n\r\nBUG FIXES:\r\n\r\n* acl: fix rpc permission denied error when using node_pool=\"all\" [[GH-27973](https://github.com/hashicorp/nomad/issues/27973)]\r\n* ui: Fixed a bug where the client detail page would fail to render [[GH-27958](https://github.com/hashicorp/nomad/issues/27958)]\r\n* ui: Fixed a bug where the topology page would fail to render [[GH-27958](https://github.com/hashicorp/nomad/issues/27958)]\r\n* ui: Fixed a bug where the evaluation detail panel would render improperly [[GH-27987](https://github.com/hashicorp/nomad/issues/27987)]","publishedAt":"2026-05-22T15:44:49.000Z","fetchedAt":"2026-05-22T20:05:34.160Z","url":"https://github.com/hashicorp/nomad/releases/tag/v2.0.2","media":[],"coverageCount":0},{"id":"rel_A1weiL07a9bk4Fc8g2JTF","version":"ent-changelog-1.11.5","type":"feature","title":"v1.11.5 (Enterprise)","summary":"Fixed two security vulnerabilities: prevented unintended code execution outside the plugin directory in dynamic host volumes (CVE-2026-7474) and protected the logging FIFO from symlink swap attacks (CVE-2026-6959). Allocation logs directory is now bind-mounted read-only for task drivers with filesystem isolation support, and plugin clients no longer leak file descriptors on agent restart.","titleGenerated":"Nomad v1.11.5 Enterprise fixes security issues in dynamic host volumes and logging","titleShort":"Dynamic host volumes; logging FIFO hardened against CVEs","breaking":"unknown","importance":null,"content":"BREAKING CHANGES:\r\n\r\n* logging: The allocation logs directory is bind-mounted read-only for task drivers that support with filesystem isolation [[GH-27918](https://github.com/hashicorp/nomad/issues/27918)]\r\n\r\nSECURITY:\r\n\r\n* dynamic host volumes: Prevent unintended code execution outside the plugin directory (CVE-2026-7474) [[GH-27919](https://github.com/hashicorp/nomad/issues/27919)]\r\n* logging: Protect logging FIFO from symlink swap attacks (CVE-2026-6959) [[GH-27918](https://github.com/hashicorp/nomad/issues/27918)]\r\n* sentinel: require sentinel-override ACL capability for overriding soft-mandatory policies on volumes\r\n* ui: Upgraded Ember to 6.10 [[GH-27674](https://github.com/hashicorp/nomad/issues/27674)]\r\n\r\nIMPROVEMENTS:\r\n\r\n* build: Update Go toolchain to 1.26.3 [[GH-27924](https://github.com/hashicorp/nomad/issues/27924)]\r\n* drivers: include volume RequestName within mount config information if available [[GH-27710](https://github.com/hashicorp/nomad/issues/27710)]\r\n* server: RPC dial timeout is configurable [[GH-27862](https://github.com/hashicorp/nomad/issues/27862)]\r\n* services: warn on job submit when job has services but no shutdown_delay [[GH-27782](https://github.com/hashicorp/nomad/issues/27782)]\r\n\r\nBUG FIXES:\r\n\r\n* api: Fix a bug where the Create Job, Update Job, and Scale Job APIs could fail to respect EnforceIndex under concurrent requests [[GH-27832](https://github.com/hashicorp/nomad/issues/27832)]\r\n* core: avoid setting job to dead while waiting for allocations to reschedule [[GH-27852](https://github.com/hashicorp/nomad/issues/27852)]\r\n* csi: improve check of StagePublishBaseDir being subdirectory of MountDir [[GH-27717](https://github.com/hashicorp/nomad/issues/27717)]\r\n* deployments: reset ProgressDeadline after pausing and do not fail while paused [[GH-27804](https://github.com/hashicorp/nomad/issues/27804)]\r\n* drivers: kill plugin instance on dispense failure [[GH-27711](https://github.com/hashicorp/nomad/issues/27711)]\r\n* job (Enterprise): renabled use of multiple vault namespaces in a single job\r\n* plugins: Fixed a bug where plugin clients would continuously leak file descriptors when the agent was restarted [[GH-27885](https://github.com/hashicorp/nomad/issues/27885)]\r\n* scheduler: Fixed a bug where preemption of allocations by tasks that require devices could incorrectly fail placement [[GH-27880](https://github.com/hashicorp/nomad/issues/27880)]","publishedAt":"2026-05-12T19:54:35.000Z","fetchedAt":"2026-05-12T21:00:18.843Z","url":"https://github.com/hashicorp/nomad/releases/tag/ent-changelog-1.11.5","media":[],"coverageCount":0},{"id":"rel_fGb7NG0eFXBLYmsfQgUn9","version":"ent-changelog-1.10.11","type":"feature","title":"v1.10.11 (Enterprise)","summary":"Fixed two security vulnerabilities: logging FIFOs are now protected from symlink swap attacks (CVE-2026-6959), and dynamic host volumes prevent unintended code execution outside the plugin directory (CVE-2026-7474). The allocation logs directory is now bind-mounted read-only for task drivers with filesystem isolation, and a file descriptor leak in plugin clients on agent restart is fixed.","titleGenerated":"Nomad v1.10.11 Enterprise hardens logging and dynamic host volumes against security exploits","titleShort":"Logging and host volumes hardened against symlink swap and code execution attacks","breaking":"unknown","importance":null,"content":"BREAKING CHANGES:\r\n\r\n* logging: The allocation logs directory is bind-mounted read-only for task drivers that support with filesystem isolation [[GH-27918](https://github.com/hashicorp/nomad/issues/27918)]\r\n\r\nSECURITY:\r\n\r\n* dynamic host volumes: Prevent unintended code execution outside the plugin directory (CVE-2026-7474) [[GH-27919](https://github.com/hashicorp/nomad/issues/27919)]\r\n* logging: Protect logging FIFO from symlink swap attacks (CVE-2026-6959) [[GH-27918](https://github.com/hashicorp/nomad/issues/27918)]\r\n* sentinel: require sentinel-override ACL capability for overriding soft-mandatory policies on volumes\r\n* ui: Upgraded Ember to 6.10 [[GH-27674](https://github.com/hashicorp/nomad/issues/27674)]\r\n\r\nIMPROVEMENTS:\r\n\r\n* build: Update Go toolchain to 1.26.3 [[GH-27924](https://github.com/hashicorp/nomad/issues/27924)]\r\n* drivers: include volume RequestName within mount config information if available [[GH-27710](https://github.com/hashicorp/nomad/issues/27710)]\r\n* server: RPC dial timeout is configurable [[GH-27862](https://github.com/hashicorp/nomad/issues/27862)]\r\n* services: warn on job submit when job has services but no shutdown_delay [[GH-27782](https://github.com/hashicorp/nomad/issues/27782)]\r\n\r\nBUG FIXES:\r\n\r\n* api: Fix a bug where the Create Job, Update Job, and Scale Job APIs could fail to respect EnforceIndex under concurrent requests [[GH-27832](https://github.com/hashicorp/nomad/issues/27832)]\r\n* csi: improve check of StagePublishBaseDir being subdirectory of MountDir [[GH-27717](https://github.com/hashicorp/nomad/issues/27717)]\r\n* deployments: reset ProgressDeadline after pausing and do not fail while paused [[GH-27804](https://github.com/hashicorp/nomad/issues/27804)]\r\n* drivers: kill plugin instance on dispense failure [[GH-27711](https://github.com/hashicorp/nomad/issues/27711)]\r\n* job (Enterprise): renabled use of multiple vault namespaces in a single job\r\n* plugins: Fixed a bug where plugin clients would continuously leak file descriptors when the agent was restarted [[GH-27885](https://github.com/hashicorp/nomad/issues/27885)]\r\n* scheduler: Fixed a bug where preemption of allocations by tasks that require devices could incorrectly fail placement [[GH-27880](https://github.com/hashicorp/nomad/issues/27880)]","publishedAt":"2026-05-12T19:54:17.000Z","fetchedAt":"2026-05-12T21:00:18.843Z","url":"https://github.com/hashicorp/nomad/releases/tag/ent-changelog-1.10.11","media":[],"coverageCount":0},{"id":"rel_QLPTEIXz993mu0d3jtQPZ","version":"v2.0.1","type":"feature","title":"v2.0.1","summary":"Fixed two security vulnerabilities: dynamic host volumes could allow unintended code execution outside the plugin directory (CVE-2026-7474), and logging FIFO was vulnerable to symlink swap attacks (CVE-2026-6959). Allocation logs directory is now bind-mounted read-only for task drivers with filesystem isolation support, and a plugin file descriptor leak on agent restart is fixed.","titleGenerated":"Nomad v2.0.1 fixes security vulnerabilities in dynamic host volumes and logging","titleShort":"Dynamic host volumes and logging FIFO secured against code execution and symlink attacks","breaking":"unknown","importance":null,"content":"BREAKING CHANGES:\r\n\r\n* logging: The allocation logs directory is bind-mounted read-only for task drivers that support with filesystem isolation [[GH-27918](https://github.com/hashicorp/nomad/issues/27918)]\r\n\r\nSECURITY:\r\n\r\n* dynamic host volumes: Prevent unintended code execution outside the plugin directory (CVE-2026-7474) [[GH-27919](https://github.com/hashicorp/nomad/issues/27919)]\r\n* logging: Protect logging FIFO from symlink swap attacks (CVE-2026-6959) [[GH-27918](https://github.com/hashicorp/nomad/issues/27918)]\r\n* sentinel: require sentinel-override ACL capability for overriding soft-mandatory policies on volumes\r\n* ui: Upgraded Ember to 6.10 [[GH-27674](https://github.com/hashicorp/nomad/issues/27674)]\r\n\r\nIMPROVEMENTS:\r\n\r\n* api: Add \"latest\" flag for tagging the latest version of a job [[GH-27764](https://github.com/hashicorp/nomad/issues/27764)]\r\n* build: Update Go toolchain to 1.26.3 [[GH-27924](https://github.com/hashicorp/nomad/issues/27924)]\r\n* cli: Added retry for nomad job run monitoring [[GH-27887](https://github.com/hashicorp/nomad/issues/27887)]\r\n* cli: Automatically expand `nomad exec -it` to `-i -t` [[GH-27906](https://github.com/hashicorp/nomad/issues/27906)]\r\n* cli: `job plan` now propagates `-hcl2-strict=false` into the suggested `nomad job run -check-index` invocation when the user passed it on the plan command line [[GH-23656](https://github.com/hashicorp/nomad/issues/23656)]\r\n* cli: add monitoring and verbose option to job dispatch [[GH-27541](https://github.com/hashicorp/nomad/issues/27541)]\r\n* drivers: include volume RequestName within mount config information if available [[GH-27710](https://github.com/hashicorp/nomad/issues/27710)]\r\n* scheduler: Add a configuration field for the number of nodes that the scheduler considers when spread or affinity is in use. This can improve scheduler performance for some cluster shapes. [[GH-27650](https://github.com/hashicorp/nomad/issues/27650)]\r\n* server: RPC dial timeout is configurable [[GH-27862](https://github.com/hashicorp/nomad/issues/27862)]\r\n* services: warn on job submit when job has services but no shutdown_delay [[GH-27782](https://github.com/hashicorp/nomad/issues/27782)]\r\n\r\nBUG FIXES:\r\n\r\n* api: Fix a bug where the Create Job, Update Job, and Scale Job APIs could fail to respect EnforceIndex under concurrent requests [[GH-27832](https://github.com/hashicorp/nomad/issues/27832)]\r\n* core: avoid setting job to dead while waiting for allocations to reschedule [[GH-27852](https://github.com/hashicorp/nomad/issues/27852)]\r\n* csi: improve check of StagePublishBaseDir being subdirectory of MountDir [[GH-27717](https://github.com/hashicorp/nomad/issues/27717)]\r\n* deployments: reset ProgressDeadline after pausing and do not fail while paused [[GH-27804](https://github.com/hashicorp/nomad/issues/27804)]\r\n* drivers: kill plugin instance on dispense failure [[GH-27711](https://github.com/hashicorp/nomad/issues/27711)]\r\n* job (Enterprise): Renabled use of multiple vault namespaces in a single job\r\n* plugins: Fixed a bug where plugin clients would continuously leak file descriptors when the agent was restarted [[GH-27885](https://github.com/hashicorp/nomad/issues/27885)]\r\n* scheduler: Fixed a bug where preemption of allocations by tasks that require devices could incorrectly fail placement [[GH-27880](https://github.com/hashicorp/nomad/issues/27880)]","publishedAt":"2026-05-12T16:18:08.000Z","fetchedAt":"2026-05-12T21:00:18.843Z","url":"https://github.com/hashicorp/nomad/releases/tag/v2.0.1","media":[],"coverageCount":0},{"id":"rel_5MGhk9ALkle_Jfo1UmtNh","version":"ent-changelog-1.11.4","type":"feature","title":"v1.11.4 (Enterprise)","summary":"FEATURES:\r\n\r\n* config: add nonproduction config option for server, license, and reporting config [[GH-27646](https://github.com/hashicorp/nomad/issues...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"FEATURES:\r\n\r\n* config: add nonproduction config option for server, license, and reporting config [[GH-27646](https://github.com/hashicorp/nomad/issues/27646)]\r\n* core (Enterprise): Enable parsing and reporting with IBM PAO licenses\r\n\r\nSECURITY:\r\n\r\n* build: upgrade Go to 1.26.2 [[GH-27831](https://github.com/hashicorp/nomad/issues/27831)]\r\n* ui: Increased the client-side generated OIDC nonce entropy to 256-bit. [[GH-27749](https://github.com/hashicorp/nomad/issues/27749)]\r\n\r\nIMPROVEMENTS:\r\n\r\n* build: Upgrade to Go 1.26 [[GH-27685](https://github.com/hashicorp/nomad/issues/27685)]\r\n* metrics: adds a metric for total agent http connections [[GH-26756](https://github.com/hashicorp/nomad/issues/26756)]\r\n* secrets: increase secrets plugin execution timeout to 60s [[GH-27779](https://github.com/hashicorp/nomad/issues/27779)]\r\n* variables: Add variable events to the event stream [[GH-27637](https://github.com/hashicorp/nomad/issues/27637)]\r\n\r\nBUG FIXES:\r\n\r\n* agent: Fixed a potential panic in agents using systemd notification [[GH-27746](https://github.com/hashicorp/nomad/issues/27746)]\r\n* agent: fix api.Job.Version used in job PUT actions [[GH-27768](https://github.com/hashicorp/nomad/issues/27768)]\r\n* drivers: handle SIGPIPE in executor to handle possible write errors after client restart [[GH-27825](https://github.com/hashicorp/nomad/issues/27825)]\r\n* identity: fix bug where client identity failed to renew after server upgrade to >=1.11.0 [[GH-27773](https://github.com/hashicorp/nomad/issues/27773)]\r\n* oidc: Fixed a bug where the request cache could be corrupted by concurrent requests with the same nonce [[GH-27747](https://github.com/hashicorp/nomad/issues/27747)]","publishedAt":"2026-04-21T21:36:36.000Z","fetchedAt":"2026-04-21T22:03:09.518Z","url":"https://github.com/hashicorp/nomad/releases/tag/ent-changelog-1.11.4","media":[],"coverageCount":0},{"id":"rel_8miAr7jzefPSadTLtRHh7","version":"ent-changelog-1.10.10","type":"feature","title":"v1.10.10 (Enterprise)","summary":"FEATURES:\r\n\r\n* core (Enterprise): Enable parsing and reporting with IBM PAO licenses\r\n\r\nSECURITY:\r\n\r\n* build: upgrade Go to 1.26.2 [[GH-27831](https:/...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"FEATURES:\r\n\r\n* core (Enterprise): Enable parsing and reporting with IBM PAO licenses\r\n\r\nSECURITY:\r\n\r\n* build: upgrade Go to 1.26.2 [[GH-27831](https://github.com/hashicorp/nomad/issues/27831)]\r\n* ui: Increased the client-side generated OIDC nonce entropy to 256-bit. [[GH-27749](https://github.com/hashicorp/nomad/issues/27749)]\r\n\r\nIMPROVEMENTS:\r\n\r\n* build: Upgrade to Go 1.26 [[GH-27685](https://github.com/hashicorp/nomad/issues/27685)]\r\n\r\nBUG FIXES:\r\n\r\n* agent: Fixed a potential panic in agents using systemd notification [[GH-27746](https://github.com/hashicorp/nomad/issues/27746)]\r\n* agent: fix api.Job.Version used in job PUT actions [[GH-27768](https://github.com/hashicorp/nomad/issues/27768)]\r\n* drivers: handle SIGPIPE in executor to handle possible write errors after client restart [[GH-27825](https://github.com/hashicorp/nomad/issues/27825)]\r\n* oidc: Fixed a bug where the request cache could be corrupted by concurrent requests with the same nonce [[GH-27747](https://github.com/hashicorp/nomad/issues/27747)]","publishedAt":"2026-04-21T21:36:19.000Z","fetchedAt":"2026-04-21T22:03:09.518Z","url":"https://github.com/hashicorp/nomad/releases/tag/ent-changelog-1.10.10","media":[],"coverageCount":0},{"id":"rel_ZXJ5zbrAF4bbt8Hi0NsC4","version":"v2.0.0","type":"feature","title":"v2.0.0","summary":"## 2.0.0 (April 21, 2026)\n\nFEATURES:\n\n* config: add nonproduction config option for server, license, and reporting config [[GH-27646](https://github.c...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 2.0.0 (April 21, 2026)\n\nFEATURES:\n\n* config: add nonproduction config option for server, license, and reporting config [[GH-27646](https://github.com/hashicorp/nomad/issues/27646)]\n* core (Enterprise): Enable parsing and reporting with IBM PAO licenses\n\nSECURITY:\n\n* build: upgrade Go to 1.26.2 [[GH-27831](https://github.com/hashicorp/nomad/issues/27831)]\n* ui: Increased the client-side generated OIDC nonce entropy to 256-bit. [[GH-27749](https://github.com/hashicorp/nomad/issues/27749)]\n\nIMPROVEMENTS:\n\n* build (Enterprise): Added support for ppc64le CPU architecture on Linux\n* build: Upgrade to Go 1.26 [[GH-27685](https://github.com/hashicorp/nomad/issues/27685)]\n* metrics: adds a metric for total agent http connections [[GH-26756](https://github.com/hashicorp/nomad/issues/26756)]\n* secrets: increase secrets plugin execution timeout to 60s [[GH-27779](https://github.com/hashicorp/nomad/issues/27779)]\n* server: Added support for raft-WAL logstore [[GH-27493](https://github.com/hashicorp/nomad/issues/27493)]\n* variables: Add variable events to the event stream [[GH-27637](https://github.com/hashicorp/nomad/issues/27637)]\n\nBUG FIXES:\n\n* agent: Fixed a potential panic in agents using systemd notification [[GH-27746](https://github.com/hashicorp/nomad/issues/27746)]\n* agent: fix api.Job.Version used in job PUT actions [[GH-27768](https://github.com/hashicorp/nomad/issues/27768)]\n* drivers: handle SIGPIPE in executor to handle possible write errors after client restart [[GH-27825](https://github.com/hashicorp/nomad/issues/27825)]\n* identity: fix bug where client identity failed to renew after server upgrade to >=1.11.0 [[GH-27773](https://github.com/hashicorp/nomad/issues/27773)]\n* oidc: Fixed a bug where the request cache could be corrupted by concurrent requests with the same nonce [[GH-27747](https://github.com/hashicorp/nomad/issues/27747)]\n* tls: fix parsing of combined key files when creating tls expiry metric [[GH-27667](https://github.com/hashicorp/nomad/issues/27667)]\n\n","publishedAt":"2026-04-21T17:52:36.000Z","fetchedAt":"2026-04-21T18:05:36.613Z","url":"https://github.com/hashicorp/nomad/releases/tag/v2.0.0","media":[],"coverageCount":0},{"id":"rel_WiPRPRYLB8-6wR3G-6vdr","version":"ent-changelog-1.10.9","type":"feature","title":"v1.10.9 (Enterprise)","summary":"SECURITY:\r\n\r\n* security: Upgrade tooling to Go 1.25.8 [[GH-27653](https://github.com/hashicorp/nomad/issues/27653)]\r\n\r\nIMPROVEMENTS:\r\n\r\n* consul (ente...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"SECURITY:\r\n\r\n* security: Upgrade tooling to Go 1.25.8 [[GH-27653](https://github.com/hashicorp/nomad/issues/27653)]\r\n\r\nIMPROVEMENTS:\r\n\r\n* consul (enterprise): adds ability to specify cluster specific consul tokens with environment variables [[GH-27574](https://github.com/hashicorp/nomad/issues/27574)]\r\n\r\nBUG FIXES:\r\n\r\n* acl: Fixed a bug where a bearer-token authenticated request could panic the handler for checking claims [[GH-27550](https://github.com/hashicorp/nomad/issues/27550)]\r\n* artifact: Fix artifact inspection when using `file` mode [[GH-27552](https://github.com/hashicorp/nomad/issues/27552)]\r\n* config: Fixed a bug where the keyring block could only be specified a maximum of two times [[GH-27579](https://github.com/hashicorp/nomad/issues/27579)]\r\n* config: Fixed parsing of Vault and Consul blocks as JSON that included objects such as `task_identity` [[GH-27595](https://github.com/hashicorp/nomad/issues/27595)]\r\n* consul: fixes bug where clients were passing node token to connect envoy container, causing acl not found errors [[GH-27574](https://github.com/hashicorp/nomad/issues/27574)]\r\n* drivers: Pass error when included in fingerprint response [[GH-27537](https://github.com/hashicorp/nomad/issues/27537)]\r\n* http: Ensure the correct HTTP protocol version is set on event stream responses [[GH-27586](https://github.com/hashicorp/nomad/issues/27586)]\r\n* job status: Fixes regression setting job status when jobs have matching prefix [[GH-27516](https://github.com/hashicorp/nomad/issues/27516)]\r\n* keyring (Enterprise): Fixed a bug where in mixed-version clusters with pre-1.9 servers, a keyring rotation that returns an error for an unavailable KMS could prevent future server restarts [[GH-27581](https://github.com/hashicorp/nomad/issues/27581)]\r\n* state: Fixed a potential state store corruption bug in the service/batch scheduler and deployment watcher [[GH-27548](https://github.com/hashicorp/nomad/issues/27548)]","publishedAt":"2026-03-17T17:40:39.000Z","fetchedAt":"2026-04-08T00:01:07.245Z","url":"https://github.com/hashicorp/nomad/releases/tag/ent-changelog-1.10.9","media":[],"coverageCount":0},{"id":"rel_Ujmw_kaTvN7BjGRkDsSmf","version":"ent-changelog-1.8.21","type":"feature","title":"v1.8.21 (Enterprise)","summary":"SECURITY:\r\n\r\n* security: Upgrade tooling to Go 1.25.8 [[GH-27653](https://github.com/hashicorp/nomad/issues/27653)]\r\n\r\nBUG FIXES:\r\n\r\n* acl: Fixed a bu...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"SECURITY:\r\n\r\n* security: Upgrade tooling to Go 1.25.8 [[GH-27653](https://github.com/hashicorp/nomad/issues/27653)]\r\n\r\nBUG FIXES:\r\n\r\n* acl: Fixed a bug where a bearer-token authenticated request could panic the handler for checking claims [[GH-27550](https://github.com/hashicorp/nomad/issues/27550)]\r\n* artifact: Fix artifact inspection when using `file` mode [[GH-27552](https://github.com/hashicorp/nomad/issues/27552)]\r\n* config: Fixed a bug where the keyring block could only be specified a maximum of two times [[GH-27579](https://github.com/hashicorp/nomad/issues/27579)]\r\n* config: Fixed parsing of Vault and Consul blocks as JSON that included objects such as `task_identity` [[GH-27595](https://github.com/hashicorp/nomad/issues/27595)]\r\n* drivers: Pass error when included in fingerprint response [[GH-27537](https://github.com/hashicorp/nomad/issues/27537)]\r\n* http: Ensure the correct HTTP protocol version is set on event stream responses [[GH-27586](https://github.com/hashicorp/nomad/issues/27586)]\r\n* job status: Fixes regression setting job status when jobs have matching prefix [[GH-27516](https://github.com/hashicorp/nomad/issues/27516)]\r\n* keyring (Enterprise): Fixed a bug where a keyring rotation that returns an error for an unavailable KMS could prevent future server restarts\r\n* state: Fixed a potential state store corruption bug in the service/batch scheduler and deployment watcher [[GH-27548](https://github.com/hashicorp/nomad/issues/27548)]","publishedAt":"2026-03-17T17:40:17.000Z","fetchedAt":"2026-04-08T00:01:07.245Z","url":"https://github.com/hashicorp/nomad/releases/tag/ent-changelog-1.8.21","media":[],"coverageCount":0}],"pagination":{"nextCursor":"2026-03-17T17:40:17.000Z|2026-04-08T00:01:07.245Z|rel_Ujmw_kaTvN7BjGRkDsSmf","limit":20},"summaries":{"rolling":null,"monthly":[]}}