--- layout: docs page_title: "1.14.0 release notes" description: |- Key updates for Vault 1.14.0 --- # Vault 1.14.0 release notes **GA date:** June 21, 2023 @include 'release-notes/intro.mdx' ## Known issues and breaking changes Version | Issue ------- | ------------------------------------------------------------ 1.14.0+ | [Users limited by control groups can only access issuer detail from PKI overview page](/vault/docs/upgrading/upgrade-to-1.14.x#ui-pki-control-groups) All | [API calls to update-primary may lead to data loss](/vault/docs/upgrading/upgrade-to-1.14.x#update-primary-data-loss) ## Vault companion updates Companion updates are Vault updates that live outside the main Vault binary.
Release Update Description
Vault Secrets Operator for Kubernetes GA Directly connect Vault secrets into Pods as native Kubernetes Secrets without modifying your application code.

Learn more: Vault Secrets Operator
Terraform GA Use LDAP authentication from the unified LDAP engine to Terraform Vault Provider.

Learn more: LDAP Secrets Engine
ENHANCED Support for additional PKI issuers and keys endpoints.

Learn more: PKI Secrets Engine
## Core updates Follow the learn more links for more information, or browse the list of [Vault tutorials updated to highlight changes for the most recent GA release](/vault/tutorials/new-release).
Release Update Description
Public Key Infrastructure (PKI) GA Use ACME to automate certificate lifecycle management for private PKI needs with standard ACME clients like Certbot and k8s cert-manager. Request certificates from a Vault server without needing to know Vault APIs or authentication mechanisms.

Learn more:  PKI Secrets Engine API: ACME
GA Use the improved PKI web UI to manage your PKI instance with intuitive configuration and reasonable defaults for workflows, metadata, issuer info, mount and tidy configuration, cross signing, multi-issuers etc.and includes.

Learn more:  PKI Secrets Engine
Security patches ENHANCED Various security improvements to remediate low severity and informational findings from a 3rd party security audit.

Learn more: Vault security model
Vault Agent BETA Fetch secrets directly into your application as environment variables.

Learn more: Process Supervisor Mode
GA Use a new subcommand and daemon, Vault Proxy, to access the proxy functionality of Vault Agent. Vault Proxy will handle Vault Agent proxy functionality going forward to simplify use case decisions for users.

Learn more: Vault Proxy
Plugin support GA Capture plugin metadata in the Vault audit log.

Learn more: Syslog audit device
GA Use X509 Authentication and Terraform Vault Provider in the MongoDB Atlas Database Secrets Engine.

Learn more:  MongoDB Atlas Database Secrets Engine
ENHANCED Dependency updates and more robust multiplexing for secrets and authentication plugins.

Learn more:  Serving a plugin with multiplexing (Plugin Development)
AWS support ENHANCED Monitoring and performance enhancements for the Vault Lambda extension.

Learn more:  Vault Lambda Extension guide
GA Use static roles for IAM users in the AWS Secrets Engine.

Learn more: AWS Secrets Engine
Vault GUI ENHANCED Streamlined and aligned navigation with HCP Vault UI.

Learn more: Vault UI
Transit ENHANCED Contributed by the OSS community. Support for public-key only Transit keys and BYOK-secured export of key material.

Learn more: Transit Secrets Engine
## Enterprise updates
Release Update Description
Vault replication ENHANCED Stability improvements based on customer feedback for Vault 1.13. See the Vault changelog for a full list of bug fixes.

Learn more:  Replication overview
License utilization reporting GA Enables automatic license utilization reporting for you and HashiCorp to ensure transparent, accurate billing.

Learn more:  Automated License utilization reporting
## Feature deprecations and EOL Deprecated in 1.14 | Retired in 1.14 ------------------ | --------------- Vault Agent API proxy support | [Duplicative Docker Images](https://hub.docker.com/_/vault) @include 'release-notes/deprecation-note.mdx'