Aembit CLI changelog
Version history
Section titled “Version history”| Aembit CLI Version | Release Date | Platforms | Notes |
|---|---|---|---|
| 1.34.5772 | 8/27/2026 | Linux (amd64, arm64) Windows (amd64) | Add a glibc-linked Linux amd64 archive alongside the default musl build |
| 1.31.4764 | 5/2/2026 | Linux (amd64, arm64) Windows (amd64) | Add upstream HTTP proxy support; add --client-workload-id flag and OIDC token expiration validation; add support for gathering dynamic claims from environment variables |
| 1.24.3328 | 7/29/2025 | Linux (amd64, arm64) Windows (amd64) |
The version number has three parts: major.minor.patch. For example, 1.24.3328 indicates:
- Major version:
1- This indicates a major release that may include breaking changes. - Minor version:
24- This indicates a minor release that adds new features or improvements without breaking existing functionality. - Patch version:
3328- This indicates a patch release that includes bug fixes or minor improvements.
Changelog
Section titled “Changelog”Unreleased
Section titled “Unreleased”Aembit CLI (unreleased)
Section titled “Aembit CLI (unreleased)”- Added support for the AWS Metadata Service, AWS Role, and Kubernetes Service Account Trust Providers to
credentials get. Aembit CLI gathers attestation data from the local environment (Instance Metadata Service (IMDS), STSGetCallerIdentity, or the projected service account token), so--id-tokenisn’t needed for these Trust Providers. - Added
vm,kubernetes,ecs_fargate, andlambda_containeras accepted values for the--deployment-modeloption. The AWS Role Trust Provider requires this option.
August 27, 2026
Section titled “August 27, 2026”Aembit CLI 1.34.5772
Section titled “Aembit CLI 1.34.5772”- Added a second Linux amd64 archive,
aembit_agent_cli_linux_amd64_glibc_<version>.tar.gz, that links dynamically against glibc 2.28 or newer. The default archive still links statically against musl and remains the recommended download. Use the glibc build when the default build reportsfailed to lookup address informationon a host wheredigandcurlresolve the same name. See Choose a Linux build.
June 3, 2026
Section titled “June 3, 2026”Aembit CLI 1.32.4999
Section titled “Aembit CLI 1.32.4999”- Added
--client-tls-private-keyoption (and theAEMBIT_CLIENT_TLS_PRIVATE_KEYenvironment variable) to thecredentials getcommand for retrieving X.509-SVID certificates. Aembit CLI generates a Certificate Signing Request (CSR) locally from the supplied private key, submits it through the credential retrieval flow, and returns the signed certificate chain inCLIENT_CERT_CHAIN. Seeaembit credentials get --client-tls-private-key.
May 1, 2026
Section titled “May 1, 2026”Aembit CLI 1.31.1
Section titled “Aembit CLI 1.31.1”- Added
--client-workload-idoption to thecredentials getcommand. Use this to identify a specific Client Workload when multiple workloads share the same Trust Provider. Supply the workload’s Aembit Client ID: A UUID that Aembit generates when you choose Aembit Client ID as a Client Workload's Client Identification method. It identifies that single Client Workload.Learn more, not its own resource ID. - Added expiration validation for OIDC tokens provided with
--id-token.
July 22, 2025
Section titled “July 22, 2025”Initial release!