The Cerbos PDP v0.56.0 release focuses on confidence in policy deployment. Store reloads through the Admin API can now confirm that new policies have compiled and are being served, a new metric tracks when the rule table was last refreshed successfully, and Hub audit logs gain an explicit ingest target in preparation for multi-workspace setups. This version also tightens policy validation and matching, and removes several long-deprecated configuration settings. For full details, see the release notes.
Confirmed store reloads
The Admin API can trigger a reload of the policy store. With wait=true, the request now waits until the rule table has been rebuilt from the new policies, so a successful response means those policies are live.
curl -i -u cerbos:cerbosAdmin \
'https://localhost:3592/admin/store/reload?wait=true'
If the rebuild fails, for example because a policy doesn't compile, the request returns a distinct error and the PDP continues serving the last good rule table. This makes the reload endpoint, and cerbosctl store reload --wait, suitable as a gate in CI/CD pipelines that need to know a policy change has taken effect before moving on.
Concurrent reload requests are now merged into a single rebuild, and each request is served by a reload that started after it was received, so every caller gets an answer that reflects the store as it was when they asked.
Track rule table freshness
The new cerbos_dev_rule_table_last_successful_refresh metric records when the rule table served by the engine was last refreshed from the policy source without any errors. It covers every storage backend, including disk, git, blob, database and Cerbos Hub.
If a refresh fails, the PDP keeps serving the previous rule table. Alerting on this metric lets you spot when a PDP has stopped picking up policy changes, so you can investigate before it drifts too far behind.
Cerbos Hub audit log ingest target
Client credentials are currently associated with a specific deployment in a Cerbos Hub workspace, and audit logs are sent to that workspace implicitly. In a future release, it will be possible to send audit logs to a different workspace from the one that holds your policies.
For forwards compatibility, the target workspace can now be specified explicitly with the new audit.hub.workspaceID setting, or the CERBOS_HUB_WORKSPACE_ID environment variable.
audit:
enabled: true
backend: hub
hub:
workspaceID: 87IGB1VDKCVZ
The setting is optional for now, and if specified must be the ID of the workspace that owns the deployment. When it isn't set, the PDP logs a deprecation warning. The setting will become required in a future version, so we recommend adding it to your configuration or Helm values now.
This release also reduces the memory used when the PDP has fallen behind in syncing audit logs to Cerbos Hub, and ingests audit log entries without re-marshalling them.
Policy validation and matching improvements
Several changes make policy evaluation more consistent across storage backends, resource kinds and query plans.
Principal policy precedence in query plans. PlanResources now gives principal policy rules, including explicit DENY rules, the same precedence they have in CheckResources. If you translate query plans into database filters, principal-level denies are now reflected in the generated plan.
Resource kinds with special characters. Resource kinds that follow the older naming pattern, such as udm:module:users/simple_regular-user, are now matched by role policies both as written and in their sanitized form. Principal policy globs are matched against both forms as well, so existing patterns such as *payroll* continue to match hr:payroll and existing rules stay in force.
Consistent scopePermissions validation. Policies that share a scope must use the same scopePermissions setting. This requirement is now enforced for every storage backend, including database stores, and conflicting policies are rejected at build time.
Other improvements in this release include a clearer error message when the configured disk storage directory doesn't exist, support for empty fixture files in test suites, tuned BadgerDB settings for the local audit log backend, and correct error codes for cancelled requests. The PDP is now built with Go 1.27.
Breaking changes and upgrade notes
The following deprecated configuration settings have been removed:
compile.cacheSizeandcompile.cacheDuration(deprecated since v0.47.0)storage.git.scratchDir(deprecated since v0.9.0)
Remove them from your configuration before upgrading.
The stricter scopePermissions validation may reject policy sets that loaded on earlier versions. Run cerbos compile against your policies, or cerbos compile-store for blob and database stores, before upgrading. As with any release that affects evaluation, validate your policies and workloads in staging before promoting to production.
Upgrade today
For the complete list of changes, see the full changelog and the v0.56.0 release notes.
Try Cerbos Hub to manage, test, and deploy policies across your PDPs, or book a call to talk through your authorization architecture with our team.
Tagged in




