edbctl 1.10.0 release notes v1

Released: 5 Oct 2026

The edbctl 1.10.0 release includes new features, improvements, bug fixes, and security fixes to enhance the functionality and performance of the Hybrid Manager (HM) CLI tool.

TypeDescription
FeatureAdded a clickhouse-operator-credentials secret to the core install-secrets scenario for Hybrid Manager 2026.10 or later, generated and replicated automatically so the ClickHouse operator no longer connects with a fixed, shared password.
ImprovementChanged edbctl hybrid-manager create-install-secrets and list-install-secrets to skip, with a warning, any --scenario value that has no install secrets (such as pgd) or that edbctl doesn't recognize, instead of failing.
ImprovementMoved the ClickHouse Keeper credentials required by Hybrid Manager 2026.9 from the observability install-secrets scenario to core, so they're created whenever core is selected.
ImprovementAdded a Source column to edbctl federation list-pairings showing whether each pairing was created manually (manual) or adopted (adopted). In edbctl federation get-pairing, a Source row with the same value replaces the Adopted row.
ImprovementUpdated the default latest Innovation Release (IR) version reference to v2026.10.
Bug fixPrevented edbctl hybrid-manager create-install-secrets from asking whether to generate the Langflow superuser username and password and the ClickHouse Keeper password, and from accepting values for them from EDB_AI_LANGFLOW_SUPERUSER, EDB_AI_LANGFLOW_SUPERUSER_PASSWORD, and EDB_OBSERVABILITY_CLICKHOUSE_KEEPER_PASSWORD. Like all other generated install secrets, these are now always generated, and their associated variables are ignored. Existing secrets are left unchanged.
Bug fixFixed edbctl hybrid-manager parse-operator-logs not showing component names next to their versions for logs from Hybrid Manager operator 2.2.0 or later.
Bug fixFixed edbctl hybrid-manager list-install-secrets reporting that it was creating secrets when --scenario is omitted.
Bug fixFixed edbctl hybrid-manager list-install-secrets producing unparseable json, json-raw, yaml, and xml output when --version is an alias such as latest-ir or --scenario is omitted. Informational messages now go to stderr.
Bug fixFixed --verify-signature on edbctl image sync-to-local-registry and edbctl image export-to-archive rejecting EDB release images. Release images for Hybrid Manager 2026.9, 1.4.3, or later now pass verification.
Security fixUpdated third-party dependencies to resolve known security vulnerabilities.