Skip to content

lakeFS Enterprise v1.97.0

Changelog

Important note: this version includes a KV migration that stores repository metadata inline in the repository record. Run lakefs migrate up with the new binary before rolling it out — a server with existing repositories will not start until the migration completes. Avoid changing repository metadata (including imports) while it runs; no downtime is needed, and the pre-migration metadata is retained so replicas on the previous version keep working during the rollout. Once migrated, earlier versions will not start against that store.

🆕 What's new:

  • RBAC: Tenant-aware scoping for fs: policy ARNs, enabling permissions to be scoped by tenant.  Note: Multi-tenancy users should review existing policies to ensure they still grant the intended access
  • Iceberg REST Catalog data plane ARNs are scoped per tenant as well
  • Note: multi-tenancy users should review existing policies to ensure they still grant the intended access
  • Improve repository API performance
  • Web UI: opening an integration UI link from commit metadata now asks for confirmation and shows the full destination URL first

🐛 Bugs Fixed:

  • Config: Honor configured external AWS auth values for caller identity max age, HTTP timeout, and valid STS hosts.
  • Honor max age configuration shorter than the default max age

Assets

checksums.txt1.8 kB2026-08-18
lakefs-enterprise_1.97.0_Darwin_arm64.tar.gzsha256:0f5686288b543427894fc68691e487fc8e3a28f498bf733e91917600449cfa3774.6 MB2026-08-18
lakefs-enterprise_1.97.0_Darwin_x86_64.tar.gzsha256:e75230268cfc8b2981e2b366ebabcd39d4d49c42c157f70fa424799ea4c1584b80.1 MB2026-08-18
lakefs-enterprise_1.97.0_Linux_arm64.tar.gzsha256:660c7fc2ef83d07ccca99ef995d9efc85cd7510b642afae55418330500510ee471.1 MB2026-08-18
lakefs-enterprise_1.97.0_Linux_x86_64.tar.gzsha256:4ab6eebd3a3697c73cc64564ab7ff640dace69f0b7f777a16d7af3a740c0616d78.5 MB2026-08-18
lakefs-enterprise_1.97.0_Windows_arm64.zipsha256:604fec3043226633ce126dc5b778ff71630bdcb1b618d313250560255aad9af371.4 MB2026-08-18
lakefs-enterprise_1.97.0_Windows_x86_64.zipsha256:d5dcb52b795d61784c501eca94f1b534aac38633801bc05e56a7abef21494ca080.1 MB2026-08-18

Docker

docker pull treeverse/lakefs-enterprise:1.97.0

Verify the signature (optional)

Requires Cosign:

cosign verify treeverse/lakefs-enterprise:1.97.0 \
    --certificate-identity-regexp='^https://github\.com/treeverse/lakeFS\-Enterprise/\.github/workflows/' \
    --certificate-oidc-issuer='https://token.actions.githubusercontent.com'
Expected output
Verification for index.docker.io/treeverse/lakefs-enterprise:1.97.0 --
The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - Existence of the claims in the transparency log was verified offline
  - The code-signing certificate was verified using trusted certificate authority certificates