RepoJournal
HashiCorp

@hashicorp

Terraform, Vault, Consul - infra-as-code for ops teams

Keep up with HashiCorp in about 3 minutes a day: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

One email a day. Unsubscribe in one click.

Pick a date

Topics: Go Infrastructure Full archive →

The Wire · Showcase

TFE TOKEN POLICY LANDS, CONSUL K8S 2.0 BREAKS GROUND, SECURITY PATCHES ROLL

By RepoJournal · Filed · About HashiCorp

Terraform Enterprise gains token TTL enforcement while Consul K8s ships its biggest breaking change yet, and three separate security updates patch Go vulnerabilities across the platform.

The Terraform provider for TFE just merged a new resource for token time-to-live policies [1], letting organizations enforce maximum lifespans on API tokens and auto-revoke anything that exceeds the limit. This is the credential hygiene upgrade teams have been waiting for. Meanwhile, Consul K8s 2.0.0 dropped today [2] with a breaking change to the API gateway controller and Go 1.26 to close security gaps, requiring compatibility checks against Consul 2.0.x before you upgrade. The same security hole that prompted the 2.0 release also hit the maintenance branches: both 1.8.13 and 1.9.8 patched x/net to 0.55.0 to resolve GO-2026-4918 [3] [4], along with a fix for incorrect FIPS version checks that was spamming logs. Over in Packer land, the SDK gained native support for macOS command and option keys in boot commands [6], finally making it natural to automate Mac builds. The Google Compute plugin fixed a serialization bug where empty ShieldedVMStateConfig was leaking into API requests [5], and the Amazon plugin has vulnerability patches in flight [7].

One email a day. Unsubscribe in one click.

Action items

References

  1. [1] New resource 'tfe_org_max_token_ttl_policy' to create/update token time to live ↗ hashicorp/terraform-provider-tfe
  2. [2] v2.0.0 ↗ hashicorp/consul-k8s
  3. [3] v1.8.13 ↗ hashicorp/consul-k8s
  4. [4] v1.9.8 ↗ hashicorp/consul-k8s
  5. [5] fix: avoid sending empty ShieldedInstanceInitialState on image create ↗ hashicorp/packer-plugin-googlecompute
  6. [6] Add bootcommand mappings for left/right command and option keys ↗ hashicorp/packer-plugin-sdk
  7. [7] Vunerablity Fix for the crypto and net ↗ hashicorp/packer-plugin-amazon

Quick answers

What shipped in HashiCorp on May 25, 2026?
Terraform Enterprise gains token TTL enforcement while Consul K8s ships its biggest breaking change yet, and three separate security updates patch Go vulnerabilities across the platform. In total, 9 commits, 6 pull requests, and 3 releases landed.
Who contributed to HashiCorp on May 25, 2026?
4 developers shipped this update, including sana-faraz, andyroyle, torarnv, and hariom-hashicorp.
What were the notable HashiCorp updates?
New resource 'tfe_org_max_token_ttl_policy' to create/update token time to live, v2.0.0, and v1.8.13.

More from @hashicorp

Daily updates, in your inbox

Follow HashiCorp

Keep up with HashiCorp in about 3 minutes a day: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

One email a day. Unsubscribe in one click. Read a past issue →

Elsewhere on the wire

Want every project, not just this one?