Copyright

Copyright © 2019 Balasys IT Ltd.. All rights reserved. This document is protected by copyright and is distributed under licenses restricting its use, copying, distribution, and decompilation. No part of this document may be reproduced in any form by any means without prior written authorization of Balasys.

This documentation and the product it describes are considered protected by copyright according to the applicable laws.

This product includes software developed by the OpenSSL Project for use in the OpenSSL Toolkit (http://www.openssl.org/). This product includes cryptographic software written by Eric Young (eay@cryptsoft.com)

Linux™ is a registered trademark of Linus Torvalds.

Windows™ 10 is registered trademarks of Microsoft Corporation.

The Balasys™ name and the Balasys™ logo are registered trademarks of Balasys IT Ltd.

The Proxedo™ name and the Proxedo™ logo are registered trademarks of Balasys IT Ltd.

AMD Ryzen™ and AMD EPYC™ are registered trademarks of Advanced Micro Devices, Inc.

Intel® Core™ and Intel® Xeon™ are trademarks of Intel Corporation or its subsidiaries in the U.S. and/or other countries.

All other product names mentioned herein are the trademarks of their respective owners.

DISCLAIMER

Balasys is not responsible for any third-party websites mentioned in this document. Balasys does not endorse and is not responsible or liable for any content, advertising, products, or other material on or available from such sites or resources. Balasys will not be responsible or liable for any damage or loss caused or alleged to be caused by or in connection with use of or reliance on any such content, goods, or services that are available on or through any such sites or resources.

2026-07-16 .Copyright

The following new features, bug fixes and improvements have been completed for Release 4.15.0 Proxedo API Security.

Features

  • OpenAPI 3.2 support
    OpenAPI 3.2 is now supported as an Enforcer Plugin and a File Brick type.

Bug Fixes

  • Configuration limited to 1 MB on Kubernetes
    On Kubernetes environments, the size of the component configuration was limited to 1 MB, including File Bricks. This limitation has been lifted, proxedo-api-security-core-config ConfigMap and Secret objects will not be created.

  • Consul startup failure after prolonged downtime
    Consul startup failure after more than 168 hours of downtime. This has been corrected.

  • Server error on OpenAPI schema validation Fixed an error where an HTTP 500 error was returned during OpenAPI schema validation instead of an HTTP 400 validation error, when a broken reference was present in the schema.

Improvements

  • Reduced disk usage of logging on VM
    On VM environments, PAS related container logs are now collected under /opt/balasys/var/log by a new log-manager service. This results in better performance on systems with large load and long log retention.

  • Container logs now contain milliseconds
    Logs managed by syslog-ng inside containers now have millisecond resolution.

  • Containers check available disk space
    Containers that need disk space to run now check available disk space. This means that containers can provide more meaningful error messages upon restart if disk space is too low.

  • syslog-ng has been replaced with axosyslog
    The syslog-ng 4.8 used by PAS services has been replaced with axosyslog 4.25.

  • pas-waf-ruleset-updater has been renamed
    The pas-waf-ruleset-updater service has been renamed to waf-ruleset-updater for clarity.

  • Client TLS and Backend TLS has been renamed
    Client TLS and Backend TLS bricks have been renamed to Client-facing TLS and Backend-facing TLS, respectively.

  • Error Policy fields have been grouped and renamed
    Error Policy bricks' Request and Response fields have been grouped together and the Request prefix has been removed from each of them. The Request and Response fields have been renamed to Action in their respective groups. Response Error Headers field has been renamed to Additional Error Headers.

  • Container debug commands have been renamed
    The pas-*-network-and-process-debug-login commands have been renamed to pas-*-debug-login.