Nomad
Workload orchestrator for deploying containers and legacy applications
Nomad's July release closed two Docker CVEs that let tasks escape their own driver configuration.
◆Recent moves
- 24d ago
Two Docker CVEs and a cross-namespace volume delete
Host namespace modes could be set without the configured allowed_modes or allow_privileged check, and a symlink could bypass volumes.enabled=false — two ways a task escaped its own driver configuration. A third fix stops a namespace-scoped host-volume-delete permission from removing another namespace's claims.
View source ↗ - 24d ago
Same CVE batch backported to the 1.10 line
The 1.10 Enterprise counterpart, cut in the same minute with identical content. The paired release habit means both supported lines close container-isolation gaps simultaneously rather than on separate schedules.
View source ↗ - 1mo ago
Debug bundle redaction, Vault retries, template restart fix
Tokens and certificate key flags are now redacted when writing a debug bundle — the file operators routinely hand to support. Also fixes tasks getting killed mid-restart on template re-render, and audit logs marking browser-originated exec requests as anonymous.
View source ↗ - 1mo ago
1.11 twin of the June maintenance release
Byte-identical to its 1.10 counterpart released in the same minute. It appears separately in the feed but carries no distinct content.
View source ↗ - 2mo ago
Three web UI rendering fixes
Client detail, topology and evaluation detail pages all failed to render, fixed here. A UI-only release with no scheduler or driver changes.
View source ↗ - 2mo ago
1.11 twin of the May UI fix release
The same three UI rendering fixes, cut thirty seconds apart on the other supported line. Duplicate content in the feed.
View source ↗