Russian Deckhouse Team Releases Stronghold 1.18 Enhancing Key Security and Audit Capabilities
2026-06-17 16:59
Favorite

en.Wedoany.com Reported - The Russian Deckhouse team (part of Flant) has released Deckhouse Stronghold 1.18, a Russian solution for securely managing the lifecycle of secrets. The new version focuses on integration with external key management systems, expanded audit capabilities, and optimization for enterprise infrastructure operations.

The core innovation of this version is the introduction of managed key functionality, enabling Deckhouse Stronghold to work with external KMS without storing private keys in local repositories, thereby reducing the risk of leaks and meeting stringent security and compliance requirements. Additionally, the system now supports authentication via external SAML 2.0 identity providers, enabling web single sign-on, and leverages WebAuthn (FIDO2/Passkeys) for more convenient and secure system login, completely eliminating reliance on passwords.

Daily management operations have been upgraded to the web interface, including KV-mount replication parameter configuration, audit log monitoring, and service log viewing, without the need for CLI tools. Audit logs feature flexible filtering capabilities, allowing the exclusion of sensitive fields from records, thereby improving event analysis convenience, simplifying the investigation of potential incidents, and aiding compliance with data processing policies.

Stronghold 1.18 supports loading external plugins as containers. Previously, when used in the Deckhouse Kubernetes Platform, repositories were only provided "as-is," lacking a plugin loading mechanism in the cluster and available only in standalone mode. Now, engineers can integrate their own solutions compatible with HashiCorp Vault, adapting the product to infrastructure characteristics without modifying code.

Vladimir Devyataykin, Product Manager for Deckhouse Stronghold, stated that the new version evolves the product into a full-fledged enterprise-grade secret store within large enterprise infrastructures. While focusing on new security features, it makes secret management in Deckhouse Stronghold simpler and more efficient by supporting external KMS, expanding audit capabilities, and migrating management operations to the web interface.

This article is compiled by Wedoany. All AI citations must indicate the source as "Wedoany". If there is any infringement or other issues, please notify us promptly, and we will modify or delete it accordingly. Email: news@wedoany.com