Skip to content

Release 9.2.43.1

These are the Rolling Release Notes for Release 9.2.43.1. These release notes are applicable to both Privacera's Self-Managed version and PrivaceraCloud.

Apache Ranger

Improved Grant and Revoke Performance for Large Policies

Improved Grant and Revoke Performance for Large Policies

Improved the performance of APIs that add or remove users, groups, or roles in a policy (grant, deny, data masking, and row-level filter). Only the changed principals are now updated, so response times no longer grow with policy size, which removes timeouts on policies with thousands of policy items that are updated frequently. When multiple requests update the same policy at the same time, Ranger now returns HTTP 409 within a bounded time so the client can retry, and requests that cannot succeed, such as a duplicate principal reference, fail immediately with HTTP 400 instead of after several retries.

Ranger database setup on existing MySQL or PostgreSQL

Ranger database setup on existing MySQL or PostgreSQL

Ranger database setup now completes successfully when re-run on an existing MySQL or PostgreSQL database, even when one of the tables is missing.

PolicySync Connector

Databricks Unity Catalog Connector — Reliable Lake Formation Forwarding for AWS Table-Level Federation

Databricks Unity Catalog Connector — Reliable Lake Formation Forwarding for AWS Table-Level Federation

  • The connector now forwards its on-demand Lake Formation sync for every relevant Unity Catalog table change, including in-place table updates and table drops, so Lake Formation permissions stay aligned with Unity Catalog. When a table cannot be forwarded, the connector records the reason for easier troubleshooting.
  • Added observability metrics for the federation forwarding workflow — forward outcomes, latency, throughput, and queue depth — for better monitoring and alerting.

Portal

Dashboard Moved Under Access Control for All Tenants

Dashboard Moved Under Access Control for All Tenants

The Dashboard is now available to every tenant and appears under Access Control directly above Resource Policies.

Clone Policy No Longer Gets Stuck

Clone Policy No Longer Gets Stuck

The Clone Policy modal no longer hangs when your environment has a large number of services, and now lists every service of the same type as the policy you are cloning.

[PrivaceraCloud only] API Keys: One-Time Display for Tenant API Keys

[PrivaceraCloud only] API Keys: One-Time Display for Tenant API Keys

The tenant API key is now displayed in full only at the time of generation. Once you close the Generated API Key dialog, the key can no longer be viewed in the Portal.

[Self-Managed only] Updated Portal Dependencies and Base Image

[Self-Managed only] Updated Portal Dependencies and Base Image

Upgraded Portal dependencies and updated the base image to a newer version to address known security vulnerabilities identified in the CVE (Common Vulnerabilities and Exposures) report.

Privacera Diagnostics

Runtime Plane Diagnostics Shared with Privacera Support

Runtime Plane Diagnostics Shared with Privacera Support

Starting with this release, your Runtime plane sends connector error logs and test results captured by diagnostics to PrivaceraCloud, where Privacera Support can use them to troubleshoot issues for you — with little or no involvement needed on your side.

This is enabled by default and can be turned off for each Runtime plane. For more information, see Sync Diagnostics to PrivaceraCloud.

Trust3 AI Cloud

Runtime Planes

Choose a deployment size when you create a runtime plane

Choose a deployment size when you create a runtime plane

You can now choose Small, Medium, or Large when you create a runtime plane, and the plane's components are sized for that choice.

EBS is now the default storage for new AWS runtime planes

EBS is now the default storage for new AWS runtime planes

New AWS runtime planes use EBS for storage by default, and EFS remains available as a selectable option. Existing planes keep the storage they were created with.

Scoped API keys in the Portal

Scoped API keys in the Portal

You can now create API keys with a specific scope from the Portal instead of keys that carry full access. The Portal's inactive-users API has its own scope, so a key issued for it cannot be used elsewhere.