lakeFS Enterprise v1.97.0¶
Changelog¶
Important note: this version includes a KV migration that stores repository metadata inline in the repository record. Run
lakefs migrate upwith the new binary before rolling it out — a server with existing repositories will not start until the migration completes. Avoid changing repository metadata (including imports) while it runs; no downtime is needed, and the pre-migration metadata is retained so replicas on the previous version keep working during the rollout. Once migrated, earlier versions will not start against that store.
What's new:¶
- RBAC: Tenant-aware scoping for fs: policy ARNs, enabling permissions to be scoped by tenant. Note: Multi-tenancy users should review existing policies to ensure they still grant the intended access
- Iceberg REST Catalog data plane ARNs are scoped per tenant as well
- Note: multi-tenancy users should review existing policies to ensure they still grant the intended access
- Improve repository API performance
- Web UI: opening an integration UI link from commit metadata now asks for confirmation and shows the full destination URL first
Bugs Fixed:¶
- Config: Honor configured external AWS auth values for caller identity max age, HTTP timeout, and valid STS hosts.
- Honor max age configuration shorter than the default max age
Assets¶
checksums.txt | 1.8 kB | 2026-08-18 | |
lakefs-enterprise_1.97.0_Darwin_arm64.tar.gz | sha256:0f5686288b543427894fc68691e487fc8e3a28f498bf733e91917600449cfa37 | 74.6 MB | 2026-08-18 |
lakefs-enterprise_1.97.0_Darwin_x86_64.tar.gz | sha256:e75230268cfc8b2981e2b366ebabcd39d4d49c42c157f70fa424799ea4c1584b | 80.1 MB | 2026-08-18 |
lakefs-enterprise_1.97.0_Linux_arm64.tar.gz | sha256:660c7fc2ef83d07ccca99ef995d9efc85cd7510b642afae55418330500510ee4 | 71.1 MB | 2026-08-18 |
lakefs-enterprise_1.97.0_Linux_x86_64.tar.gz | sha256:4ab6eebd3a3697c73cc64564ab7ff640dace69f0b7f777a16d7af3a740c0616d | 78.5 MB | 2026-08-18 |
lakefs-enterprise_1.97.0_Windows_arm64.zip | sha256:604fec3043226633ce126dc5b778ff71630bdcb1b618d313250560255aad9af3 | 71.4 MB | 2026-08-18 |
lakefs-enterprise_1.97.0_Windows_x86_64.zip | sha256:d5dcb52b795d61784c501eca94f1b534aac38633801bc05e56a7abef21494ca0 | 80.1 MB | 2026-08-18 |
Docker¶
Verify the signature (optional)¶
Requires Cosign:
cosign verify treeverse/lakefs-enterprise:1.97.0 \
--certificate-identity-regexp='^https://github\.com/treeverse/lakeFS\-Enterprise/\.github/workflows/' \
--certificate-oidc-issuer='https://token.actions.githubusercontent.com'
Expected output
Verification for index.docker.io/treeverse/lakefs-enterprise:1.97.0 --
The following checks were performed on each of these signatures:
- The cosign claims were validated
- Existence of the claims in the transparency log was verified offline
- The code-signing certificate was verified using trusted certificate authority certificates