Welcome to the initial release of DataBee Cluster Administration Manual!
July 2026
- Benthos stream processing dependency is updated to v4.76.0; this resolves an upstream issue where HTTP 429 response headers were not populated in processor metadata, ensuring rate-limit signals propagate correctly through the pipeline.
- CDP Streaming (Flink)
cloud_resource_feedtable is provisioned in parallel to the Snowflake and Iceberg data lake targets to support the new Cloud Resource entity type. - Flink TaskManager pod resource limits are adjusted to resolve pods stuck in Pending state in the
emr-flinknamespace due to insufficient cluster resources. - CDP Streaming Snowflake backfill scripts are updated to align with current schema conventions.
resource_feedtable backfill is implemented for both Snowflake and Iceberg to populate historical Cloud Resource records retroactively.- A tenant-specific Kafka topic is provisioned for writing messages to the cyber schema; this is additive and does not alter existing topic routing.
- Iceberg optimizer table compaction (
rewrite_data_files) memory and resource configuration is tuned to resolve persistent OOM failures during hourly compaction runs. - Staging environment OKTA-managed local user creation now automatically assigns the user to the DataBee application and skips email confirmation, removing manual provisioning steps for staging cluster setup.
June 2026
- Kubernetes Pod Disruption Budget (PDB) policies for the iceberg-kafka-connect and snowflake-kafka-connect services are updated to allow controlled node draining during EKS node group upgrades, preventing upgrade failures caused by overly strict PDB restrictions.
- Bitnami container images are migrated from public AWS ECR (being decommissioned by Bitnami) to DataBee's private ECR registry, ensuring uninterrupted image pulls across all cluster environments.
- The SNOWFLAKE_SCHEMA key is now included in the cluster Snowflake secrets pushed by the data lake models service; previously missing, this key could cause data lake operations to fail when referenced.
- The
close_clisupport tool is deprecated; a replacement script using the Entity Management API endpoint is now available in the support pod for bulk entity closure operations. - Flink service logging format is corrected to prevent individual log lines from being indexed as separate DataDog events; this resolves excessive log indexing costs on affected clusters.
- A new iceberg BI cache service is introduced for Iceberg tenant deployments to pre-materialize BI view query results, enabling stable Tableau extract operations for views with long-running queries. The service supports configurable view groups with independent schedules and custom per-schedule actions (refresh or purge).
- The iceberg BI cache now uses a staged load approach: new data is fully prepared before replacing the existing cache, preventing Tableau dashboards from showing empty content when a cache refresh query fails.
May 2026
- Compliance Management capabilities are governed by a dedicated CCM entitlement, ensuring access to compliance features is aligned with licensed product offerings.
- Vulnerability Resilience and ISP Risk Intelligence entitlements are deprecated.
April 2026
- Tenant lifecycle management is fixed to ensure storage buckets created during tenant provisioning are properly deleted during tenant or cluster deletion.
- Vulnerability Resilience and ISP Risk Intelligence entitlements are deprecated across all platform services; capabilities are redistributed to the Security Hygiene and Security Threats entitlements.
- A cleanup script is available to remove stale Cognito SSO connections from Consul; stale connections caused the Create User Account button to appear disabled for affected tenants.
- The
user_access_reviewentitlement is registered in the platform; this entitlement must be provisioned for tenants to access User Access Review workflows.
March 2026
- An issue where activating the Security Threats entitlement did not dispatch the ArgoCD deployment event, leaving the entitlement provisioned in the UI but not deployed to the cluster, is fixed.
- Vulnerability Resilience entitlement deprecation begins across core data platform services; entitlement capabilities are migrated to Security Hygiene and Security Threats.
- The auth service is updated to handle secret lookups gracefully for tenants without provisioned secrets, eliminating spurious
ResourceNotFoundExceptionerrors in service logs. - Iceberg Kafka Connect memory limits are adjusted to resolve OOMKill restarts that caused in-flight message loss on affected clusters.
February 2026
- Azure Security entitlement is added to the platform; qualifying tenants can be provisioned with access to Azure Security Centre capabilities.
- Kafka Connect KEDA autoscaler minimum replica count is set to 1, preventing cluster membership disruption caused by scaling the deployment to zero and back up.
- Tenant provisioning template is updated: the stale data-lake writer credential deletion job is removed and a dedicated S3 bucket is provisioned for pipeline objects that exceed inline processing limits.
January 2026
- An issue where disabling a tenant did not fully stop associated data sources, feeds, and data collection is fixed.
December 2025
- Configuration text fields in the Report Provisioner now expand while editing and support word wrapping, making it easier to view and edit longer content such as SQL and conditions.
November 2025
- Cluster authentication now supports multiple identity provider group claims, allowing environments to configure the cluster users group as a comma-separated list.
- DataBee API enables only the entitlements selected when creating a tenant, instead of enabling all by default.
September 2025
- The issue where changes to the ClusterTenant model did not immediately update the interface, causing delays, is fixed.
- The issue where configuration pages (such as Report Provisioner) appeared disabled for Cluster Support users is fixed. Cluster Support users now have full access to these pages, consistent with Cluster Administrators.
- Support is added to the tenant model and UI to allow cluster admins to determine if a tenant is using federation for login during provisioning.
- The issue where an invalid authentication message was displayed in the tenant table is fixed.
August 2025
- Privileged Access Management and Business Continuity Management are added to the dashboards entitlements list in config-migration.
- The Vulnerability CDP is added to the CCM entitlement, so customers with either CCM or Vulnerability Resilience entitlement get access.
- DataHub is deployed as part of the Data Lake entitlement.
- The SQLVisualizer widget now requires the DataBee BeeKeeper entitlement to work.
July 2025
- The issue where data lake migration fails after switching to a tenant specific role is fixed.
- The issue where the Submit button on the Tenant Details form did not respond on click, is fixed.
June 2025
- The Support engineers are now granted the same permissions as tenant engineers to view support tickets.
- The issue where data lake migration failed after switching to a tenant specific role is fixed.
April 2025
- The Tableau Client ID, Tableau Secret ID, and Tableau Secret Value fields are moved from the Content Delivery configuration to a new Embedded Tableau configuration page; the Data Source Username and Data Source Password fields are now optional.
- The Support ticket system is enhanced to allow designated watchers to view and comment on tickets while respecting permission boundaries.
March 2025
- Cluster admins can view the customer support tickets of a tenant only when logged into the tenant UI.
- The issue where DataBee pulled support tickets without an associated account ID, is fixed.
February 2025
- New entitlements BluVector and ISP Risk Intelligence are now available on the Cluster page.
- Cluster admins can view tenant tickets only when logged into the tenant UI.
- The customer support tickets interface is improved with enhanced formatting, ticket number display, and search by ticket number features.
- The new customer support tickets are displayed in the ticket summary list upon creation.
January 2025
- Cluster admins can delete other admins and SSO tenant users.
- The issue where Tenants could not be set for SSO Support users is fixed.
- The issue where the entitlements no longer granted were still displayed, is fixed.
December 2024
- The cluster configuration for API key expiration is removed.
- The issue where users are redirected to the data lake page and encounter a connection failed error upon logging in to the cluster tenant is fixed.
November 2024
- A default checkbox that displays only the current active tenants on the cluster is added to the tenant list page.
August 2024
- Cluster administrators can configure per-user basis login permissions for each tenant.
Release 1.5.0
Key Features
- System Configuration: Configure cluster audit logging and branding
- Access Management: Create and manage local accounts, set up single sign-on for Comcast and assign users to roles including Cluster Administrator and Support engineer.
- Tenant Administration: Create and edit tenants