Added AWS Secrets Manager as an optional secret storage backend and fixed stale KMS OpenAPI docs and duplicate script generation in raw applications.
Release history
windmill releases
Open-source developer platform to power your entire infra and turn scripts into webhooks, workflows and UIs. Fastest workflow engine (13x vs Airflow). Open-source alternative to Retool and Temporal.
All releases
38 shown
- Path name autocomplete with ghost text and folder cycling
- Partial index for expired cache resource cleanup
Fixed a bug where log cleanup failed to detect orphaned S3 objects across multiple servers and added database indexes to speed delete operations during concurrent cleanup, improving reliability and performance for multi-node deployments.
Added an object storage usage dashboard and manual cleanup tool, improved job count admin checks for SQL safety, allowed private AI endpoints, enhanced telemetry with job and script details, and separated the database health endpoint with controls for slow queries.
RLS was enforced on $var in the AI proxy and a SSRF vulnerability via the X-Resource-Path header was patched, improving request security.
Fixed a panic that occurred when cloud-hosted jobs attempted to create a PostgreSQL connection, improving reliability for cloud deployments.
- application-level heartbeat for websocket triggers
- Azure Key Vault secret storage backend
- OTEL http/protobuf export support
- HMAC signature verification added to Slack interactive callback endpoint
- Worker group restart endpoint
- Entra ID/Azure Workload Identity database auth
- Windows worker memory limit controls
- Configurable preview job tag override
- Improved CLI flow log streaming
- Hub flows support in raw app runnables
- OR logic for trigger filters
- MCP tools for job inspection
- Multiline secret support
Fixed Okta custom authorization server URL handling to prevent doubled /oauth2 path construction. Improved database health UI text readability and label layout.
- Path traversal prevention in service logs
- Workspace isolation on flow resume
- WAC workflow diagram visualization via WASM
- Brute force protection on login endpoint
- Webhook signature timestamp validation
- SSRF and local file read prevention
Updates git sync to latest CLI version for improved version parity and feature consistency across deployment systems.
Patch addressing CLI developer experience including phantom diffs, flow safety checks, trigger usability, and watch mode error clarity.
Patch fixing CLI app push crash, linting path resolution, message flag handling, and history timestamp display.
CLI patch fixing 13 bugs including exit codes, tar fallback on sync, variable encryption, and JSON output formatting.
- Database health diagnostics dashboard
- IAM RDS authentication
- CLI job/group/audit/token commands
- Workspace-level service accounts
- CLI schedule support
- Graceful restart coordination
- Mask sensitive values in job logs
- Soft-delete trashbin system
- Sensitive value masking in logs
- Git sync in Community Edition
- Instance-level AI configuration
- Self-approval in workflows
- Collapsible flow groups
- Prevented SQL injection in job query parameters
- Debounce workflow node
- Typed request bodies in OpenAPI
- Stale scripts detection
Fixes S3 file browser crash and schema inference issues with reset and language switching.
- CLI local script previews
- MCP Anthropic connectors readiness
Patches WAC module support, job debounce behavior, and adds required checkpoint.json mount for Python execution.
- Store hashed tokens instead of plaintext
- Hashed token storage
- OIDC end_user_email claim
- DB-backed webhooks
- SAML metadata endpoint
- Custom headers in AI resources
- Multiple secret variables
Fixes CLI flow lock generation to properly handle non-dotted path naming conventions in workflows.
Fixed PowerShell WindmillClient module loading issue on Windows workers, ensuring proper client functionality in Windows-based execution environments.
- Datatable config support in CLI settings sync
- Backend export for datatable configurations
- GitHub Enterprise Server (GHES) support for git sync
- Unified generate-metadata CLI command
- Kafka auto_commit option with UI badges
- Audit log daily partitioning with retention settings
- Minimal telemetry mode
- Git sync for workspace dependencies
- Kafka trigger offset and auto.offset.reset configuration
- Vertex AI Gemini model support
- Configurable indexer time window (default 7 days)
- Slack connection export/import in workspace settings