Home / Companies / Kestra / Blog / Post Details
Content Deep Dive

We Audited Every Endpoint in Kestra. Here Is What We Fixed.

Blog post from Kestra

Post Details
Company
Date Published
Author
Loïc Mathieu
Word Count
2,095
Company Posts That Month
12
Language
English
Hacker News Points
-
Post removed?
No
Summary

Kestra 2.0 introduces a broad security overhaul alongside its rebuilt execution engine, driven by a systematic review that produced roughly sixty fixes and multiple published advisories. Its most significant architectural change removes database access from workers, which now communicate outbound with controllers over gRPC, limiting the impact of compromised workers and keeping secrets encrypted until use. The release strengthens authentication through bcrypt password hashing, constant-time credential comparisons, rate limiting, tighter access controls, and improved secret encryption and masking, while also addressing information leaks, stack-trace exposure, insecure file downloads, and previously open management endpoints. New protections include CSRF defenses for browser sessions, sanitization for Markdown, SVGs, and UI content to prevent XSS, configurable security headers, HTTP allow and deny lists to reduce SSRF risks, and safeguards against path traversal, ZIP bombs, ReDoS, SQL injection, and insufficient request validation. Although many protections are enabled by default, production deployments should configure initial authentication, worker TLS or mutual TLS, HTTP network restrictions, ZIP-bomb limits, and secure management-port access; Enterprise users can additionally restrict plugins and process execution in untrusted environments.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 8 451 99 43 -80%
MCP 1 2,241 148 72 -74%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.