Release 9.2.41.1¶
These are the Rolling Release Notes for Release 9.2.41.1. These release notes are applicable to both Privacera's Self-Managed version and PrivaceraCloud.
Apache Ranger¶
Hive Data Masking And Row-level Filter Wildcard Matching For New Tenants
Hive Data Masking And Row-level Filter Wildcard Matching For New Tenants¶
Enabled wildcard (*) matching on Hive data masking and row-level filter policy resources (database, table, column) for newly provisioned tenants.
Improved Audit Observability
Improved Audit Observability¶
Added metrics for audit events generated, sent, failed, and spooled, along with spool file count and size gauges. This improves visibility into audit delivery failures and on-disk spool growth for easier monitoring and alerting.
Fixed Intermittent mTLS Authentication Failures
Fixed Intermittent mTLS Authentication Failures¶
Fixed an issue where Ranger plugin REST clients could stop sending client certificates after another component changed JVM-wide SSL settings, causing Ranger Admin requests to fail with HTTP 400 errors. mTLS connections now consistently use the configured client certificate.
Improved Policy Update Performance for Large Policies
Improved Policy Update Performance for Large Policies¶
Optimized policy creation and updates for large policies by reducing redundant database operations and batching policy reference updates, improving performance and reducing database load.
PolicySync Connector¶
Databricks Unity Catalog, Databricks SQL Analytics, and Lake Formation - Resource-Scoped on-demand permission sync
Databricks Unity Catalog, Databricks SQL Analytics, and Lake Formation - Resource-Scoped on-demand permission sync¶
Added support for on-demand permission-sync events (PERMISSION_SYNC) scoped to the resource(s) named in the event. A permission change on a specific resource now syncs only that resource instead of triggering a full permission sync across all managed resources. Applies to the Databricks Unity Catalog, Databricks SQL Analytics, and Lake Formation connectors.
BigQuery — Fixed policy download failure with HTTP 400
BigQuery — Fixed policy download failure with HTTP 400¶
Fixed BigQuery PolicySync policy downloads failing with HTTP 400 because the Ranger client certificate was not loaded. The connector now includes the plugin SSL credential lookup fix, allowing policy downloads to present the client certificate.
MSSQL — Purview Tag Sync on Views and Shutdown Crash Fix
MSSQL — Purview Tag Sync on Views and Shutdown Crash Fix¶
Added support in the MSSQL connector for syncing Microsoft Purview tags applied to views and view columns, so tags on views now sync alongside tables. Also fixed a crash that could terminate the connector process during shutdown.
Databricks Unity Catalog - Updated PolicySync Dependencies
Databricks Unity Catalog - Updated PolicySync Dependencies¶
Upgraded PolicySync dependencies to address known security vulnerabilities identified in the CVE (Common Vulnerabilities and Exposures) report for the Databricks Unity Catalog connector.
Portal¶
[PrivaceraCloud only] Improved Tag Search and Attribute Validation
[PrivaceraCloud only] Improved Tag Search and Attribute Validation¶
Fixed an issue where tags were not displayed in the Add Tag search until they were first searched in the Portal’s top search box. Tags can now be searched and selected directly from the Add Tag dialog.
[PrivaceraCloud only] Improved Reliability of the PrivaceraCloud Admin Service
[PrivaceraCloud only] Improved Reliability of the PrivaceraCloud Admin Service¶
The PrivaceraCloud Admin Service now stays responsive even when it runs for a long time without a restart.
[PrivaceraCloud only] Account Expiry No Longer Depends on the Contact Email
[PrivaceraCloud only] Account Expiry No Longer Depends on the Contact Email¶
Accounts that pass their expiry date are now marked expired and disabled and have their applications stopped, even when the account's contact email does not match a user in that account.
[PrivaceraCloud only] Performance: Faster resource delete, and large deletes no longer block other background jobs
[PrivaceraCloud only] Performance: Faster resource delete, and large deletes no longer block other background jobs¶
Deleting a resource with many child resources is now much faster. Previously, a large delete could take hours and hold up other background jobs. Very wide tables no longer time out.
Privacera Diagnostics¶
Privacera Diagnostics Tool - Updated Dependencies
Privacera Diagnostics Tool - Updated Dependencies¶
Upgraded Privacera Diagnostics Tool dependencies to address known security vulnerabilities identified in the CVE (Common Vulnerabilities and Exposures) report for the Privacera Diagnostics Tool.
Trust3 AI Cloud¶
Runtime Planes¶
Prometheus and Grafana now come built in
Prometheus and Grafana now come built in¶
Self-Managed runtime planes now include Prometheus and Grafana by default, so you can see metrics for the plane without setting up your own monitoring stack.
Choose how an Omni connector is deployed
Choose how an Omni connector is deployed¶
You can now choose whether an Omni connector shares a deployment with others or runs in its own dedicated one. This is available through the API and connector configuration; the option will appear on the connector creation screen in a later release.
Control where runtime plane pods are placed
Control where runtime plane pods are placed¶
You can now set node affinity, tolerations, and topology spread rules for a runtime plane from its configuration screen. These settings now also apply to one-off and scheduled jobs, which previously ignored them.
Solr collections and schemas are now managed centrally
Solr collections and schemas are now managed centrally¶
Solr collection and schema management has moved into a single component, and you can now set the replication factor and retention period from the UI.
See recent application errors in the Portal
See recent application errors in the Portal¶
The Portal now shows recent errors for an application running on a runtime plane, so you can check what went wrong without opening a support request.
Updated Runtime Dependencies
Updated Runtime Dependencies¶
Upgraded Runtime dependencies to address known security vulnerabilities identified in the CVE (Common Vulnerabilities and Exposures) report.
- Prev topic: Releases