We Audited Every Endpoint in Kestra. Here Is What We Fixed.
Blog post from Kestra
Kestra 2.0 introduces a broad security overhaul alongside its rebuilt execution engine, driven by a systematic review that produced roughly sixty fixes and multiple published advisories. Its most significant architectural change removes database access from workers, which now communicate outbound with controllers over gRPC, limiting the impact of compromised workers and keeping secrets encrypted until use. The release strengthens authentication through bcrypt password hashing, constant-time credential comparisons, rate limiting, tighter access controls, and improved secret encryption and masking, while also addressing information leaks, stack-trace exposure, insecure file downloads, and previously open management endpoints. New protections include CSRF defenses for browser sessions, sanitization for Markdown, SVGs, and UI content to prevent XSS, configurable security headers, HTTP allow and deny lists to reduce SSRF risks, and safeguards against path traversal, ZIP bombs, ReDoS, SQL injection, and insufficient request validation. Although many protections are enabled by default, production deployments should configure initial authentication, worker TLS or mutual TLS, HTTP network restrictions, ZIP-bomb limits, and secure management-port access; Enterprise users can additionally restrict plugins and process execution in untrusted environments.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 8 | 451 | 99 | 43 | -80% |
| MCP | 1 | 2,241 | 148 | 72 | -74% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.