Release Notes for Tetrate Patch Service
New capabilities land here as they ship.
Technical Preview
The initial release of Tetrate Patch Service includes:
New Features
- Cluster inventory: an in-cluster agent reporting full snapshots of every running container image, with a per-cluster drill-down and version badges in the Clusters view.
- CVE scanning: nightly fleet-wide scans of every observed image, findings categorized as actionable, pending, or third party, and freshness warnings that never present missing data as clean.
- Release catalog: public machine-readable release manifests with registry-verified digests, powering categorization, upgrade available markers, and upgrade targets that never cross image variants.
- Managed data plane: a private per-customer GitOps repository reconciled by ArgoCD, with automated upgrade pull requests, one per environment, and evidence-based rollout tracking.
- Cloud account discovery: AWS account connections through an assumable IAM role with no stored credentials, fleet-wide cluster discovery, and per-cluster install targets with bulk installs.
- The
tetrateCLI: single-command cluster onboarding, multi-cluster planning across kubeconfig contexts, and managed product installs, for macOS and Linux.