---
title: "HashiCorp Vault 2.0 Marks Shift to IBM Lifecycle with New Identity Federation"
source_name: "InfoQ"
original_url: "https://www.infoq.com/news/2026/04/vault-2-0-ibm-identity/?utm_campaign=infoq_content&utm_source=infoq&utm_medium=feed&utm_term=global"
canonical_url: "https://www.traeai.com/articles/46f864cd-6a25-40ff-8680-5c8aa695b86c"
content_type: "article"
language: "中文"
score: 5
tags: []
published_at: "2026-04-24T07:00:00+00:00"
created_at: "2026-04-24T11:08:37.761632+00:00"
---

# HashiCorp Vault 2.0 Marks Shift to IBM Lifecycle with New Identity Federation

Canonical URL: https://www.traeai.com/articles/46f864cd-6a25-40ff-8680-5c8aa695b86c
Original source: https://www.infoq.com/news/2026/04/vault-2-0-ibm-identity/?utm_campaign=infoq_content&utm_source=infoq&utm_medium=feed&utm_term=global

## Summary

traeai 为开发者、研究员和内容团队筛选高质量 AI 技术内容，提供摘要、评分、趋势雷达与一键内容产出。

## Key Takeaways

- 
- 
- 

## Content

Title: HashiCorp Vault 2.0 Marks Shift to IBM Lifecycle with New Identity Federation

URL Source: http://www.infoq.com/news/2026/04/vault-2-0-ibm-identity/

Published Time: 2026-04-24T07:00:00+0000

Markdown Content:
# HashiCorp Vault 2.0 Marks Shift to IBM Lifecycle with New Identity Federation - InfoQ

[BT](http://www.infoq.com/int/bt/ "bt")

## InfoQ Software Architects' Newsletter

A monthly overview of things you need to know as an architect or aspiring architect.

[View an example](https://www.infoq.com/software-architects-newsletter#placeholderPastIssues)

Enter your e-mail address 

Select your country - [x] I consent to InfoQ.com handling my data as explained in this [Privacy Notice](https://www.infoq.com/privacy-notice). 

[We protect your privacy.](http://www.infoq.com/privacy-notice/)

Close

Live Webinar and Q&A: Portable by Design: Data Mobility & Recovery Patterns for Multi-Cloud Systems (May 21, 2026)[Save Your Seat](http://www.infoq.com/url/pb/636fe2ee-466c-4b54-affd-c6007cf3dc9d/)

Close 

Toggle Navigation 

Facilitating the Spread of Knowledge and Innovation in Professional Software Development

English edition 

*   [English edition](http://www.infoq.com/news/2026/04/vault-2-0-ibm-identity/#)
*   [Chinese edition](https://www.infoq.cn/)
*   [Japanese edition](http://www.infoq.com/jp/)
*   [French edition](http://www.infoq.com/fr/)

[Write for InfoQ](http://www.infoq.com/write-for-infoq/ "Write for InfoQ")

Search 

[Register](http://www.infoq.com/reginit.action?)[Sign in](http://www.infoq.com/social/keycloakLogin.action?fl=login)

## Unlock the full InfoQ experience

Unlock the full InfoQ experience by logging in! Stay updated with your favorite authors and topics, engage with content, and download exclusive resources.

[Log In](http://www.infoq.com/social/keycloakLogin.action?fl=login)

or

### Don't have an InfoQ account?

[Register](http://www.infoq.com/reginit.action?)

*   **Stay updated on topics and peers that matter to you**Receive instant alerts on the latest insights and trends.
*   **Quickly access free resources for continuous learning**Minibooks, videos with transcripts, and training materials.
*   **Save articles and read at anytime**Bookmark articles to read whenever youre ready.

[Logo - Back to homepage](http://www.infoq.com/)

[News](http://www.infoq.com/news/)[Articles](http://www.infoq.com/articles/)[Presentations](http://www.infoq.com/presentations/)[Podcasts](http://www.infoq.com/podcasts/)[Guides](http://www.infoq.com/minibooks/)

### Topics

[Development](http://www.infoq.com/development/ "Development")

*   [Java](http://www.infoq.com/java/ "Java")
*   [Kotlin](http://www.infoq.com/kotlin/ "Kotlin")
*   [.Net](http://www.infoq.com/dotnet/ ".Net")
*   [C#](http://www.infoq.com/c_sharp/ "C#")
*   [Swift](http://www.infoq.com/swift/ "Swift")
*   [Go](http://www.infoq.com/golang/ "Go")
*   [Rust](http://www.infoq.com/rust/ "Rust")
*   [JavaScript](http://www.infoq.com/javascript/ "JavaScript")

### Featured in Development

*   #### [From VR to Flat Screens: Bridging the Input and Immersion Gap](http://www.infoq.com/presentations/game-vr-flat-screens)

Dany Lepage discusses the architectural journey of porting a hit VR title to seven non-VR platforms. He explains how his team solved the challenges of cross-progression, diverse input paradigms, and maintaining release velocity across Steam, iOS, and PlayStation. Beyond the tech, he shares candid lessons on the "product fit" gap when translating immersive social presence to 2D screens.

  [![Image 2: From VR to Flat Screens: Bridging the Input and Immersion Gap](https://imgopt.infoq.com/fit-in/100x100/filters:quality(80)/presentations/game-vr-flat-screens/en/smallimage/thumbnail-1775637585504.jpg)](http://www.infoq.com/presentations/game-vr-flat-screens) 

[All in development](http://www.infoq.com/development/)Follow Topic

[Architecture & Design](http://www.infoq.com/architecture-design/ "Architecture & Design")

*   [Architecture](http://www.infoq.com/architecture/ "Architecture")
*   [Enterprise Architecture](http://www.infoq.com/enterprise-architecture/ "Enterprise Architecture")
*   [Scalability/Performance](http://www.infoq.com/performance-scalability/ "Scalability/Performance")
*   [Design](http://www.infoq.com/design/ "Design")
*   [Case Studies](http://www.infoq.com/Case_Study/ "Case Studies")
*   [Microservices](http://www.infoq.com/microservices/ "Microservices")
*   [Service Mesh](http://www.infoq.com/servicemesh/ "Service Mesh")
*   [Patterns](http://www.infoq.com/DesignPattern/ "Patterns")
*   [Security](http://www.infoq.com/Security/ "Security")

### Featured in Architecture & Design

*   #### [How to Build an Exchange: Sub Millisecond Response Times and 24/7 Uptimes in the Cloud](http://www.infoq.com/presentations/exchange-systems-cloud)

Frank Yu shares Coinbase’s engineering philosophy for building resilient, fair, and fast financial exchanges. He explains the power of a single-threaded architecture combined with the Raft consensus algorithm to maintain 24/7 availability. He discusses how determinism enables zero-downtime rolling deployments and the ability to replay production logs for perfect bug reproduction.

  [![Image 3: How to Build an Exchange: Sub Millisecond Response Times and 24/7 Uptimes in the Cloud](https://imgopt.infoq.com/fit-in/100x100/filters:quality(80)/presentations/exchange-systems-cloud/en/smallimage/frank-yu-thumbnail-1776173818222.jpeg)](http://www.infoq.com/presentations/exchange-systems-cloud) 

[All in architecture-design](http://www.infoq.com/architecture-design/)Follow Topic

[AI Infrastructure](http://www.infoq.com/ai-ml-data-eng/ "AI Infrastructure")

*   [Big Data](http://www.infoq.com/bigdata/ "Big Data")
*   [Machine Learning](http://www.infoq.com/machinelearning/ "Machine Learning")
*   [NoSQL](http://www.infoq.com/nosql/ "NoSQL")
*   [Database](http://www.infoq.com/database/ "Database")
*   [Data Analytics](http://www.infoq.com/data-analytics/ "Data Analytics")
*   [Streaming](http://www.infoq.com/streaming/ "Streaming")

### Featured in AI, ML & Data Engineering

*   #### [Deepfakes, Disinformation, and AI Content Are Taking Over the Internet](http://www.infoq.com/presentations/deepfakes-ai)

Shuman Ghosemajumder explains how generative AI has transformed from a creative curiosity into a high-scale tool for disinformation and fraud. He shares insights on "Disinformation Automation," the fallacy of CAPTCHA in an AI world, and why engineering leaders must adopt zero-trust "cyber fusion" strategies to defend against automated attacks that mimic human behavior with chilling accuracy.

  [![Image 4: Deepfakes, Disinformation, and AI Content Are Taking Over the Internet](https://imgopt.infoq.com/fit-in/100x100/filters:quality(80)/presentations/deepfakes-ai/en/smallimage/shuman-ghosemajumder-thumbnail-1776248048343.jpeg)](http://www.infoq.com/presentations/deepfakes-ai) 

[All in ai-ml-data-eng](http://www.infoq.com/ai-ml-data-eng/)Follow Topic

[Culture & Methods](http://www.infoq.com/culture-methods/ "Culture & Methods")

*   [Agile](http://www.infoq.com/agile/ "Agile")
*   [Diversity](http://www.infoq.com/diversity/ "Diversity")
*   [Leadership](http://www.infoq.com/leadership/ "Leadership")
*   [Lean/Kanban](http://www.infoq.com/lean/ "Lean/Kanban")
*   [Personal Growth](http://www.infoq.com/personal-growth/ "Personal Growth")
*   [Scrum](http://www.infoq.com/scrum/ "Scrum")
*   [Sociocracy](http://www.infoq.com/sociocracy/ "Sociocracy")
*   [Software Craftmanship](http://www.infoq.com/software_craftsmanship/ "Software Craftmanship")
*   [Team Collaboration](http://www.infoq.com/team-collaboration/ "Team Collaboration")
*   [Testing](http://www.infoq.com/testing/ "Testing")
*   [UX](http://www.infoq.com/ux/ "UX")

### Featured in Culture & Methods

*   #### [Panel: Building a Culture that Works](http://www.infoq.com/presentations/panel-positive-culture)

The panelists share insights on evolving company culture. They discuss leveraging feedback loops, lending social capital, and the friction between legacy bureaucracy and agile engineering. The panel explains how to maintain cohesion in remote teams and use interviews to uncover the true "unmanicured" culture of a firm.

  [![Image 5: Panel: Building a Culture that Works](https://imgopt.infoq.com/fit-in/100x100/filters:quality(80)/presentations/panel-positive-culture/en/smallimage/ln-500x500-1775048593311.jpg)](http://www.infoq.com/presentations/panel-positive-culture) 

[All in culture-methods](http://www.infoq.com/culture-methods/)Follow Topic

[DevOps](http://www.infoq.com/devops/)

*   [Infrastructure](http://www.infoq.com/infrastructure/ "Infrastructure")
*   [Continuous Delivery](http://www.infoq.com/continuous_delivery/ "Continuous Delivery")
*   [Automation](http://www.infoq.com/automation/ "Automation")
*   [Containers](http://www.infoq.com/containers/ "Containers")
*   [Cloud](http://www.infoq.com/cloud-computing/ "Cloud")
*   [Observability](http://www.infoq.com/observability/ "Observability")

### Featured in DevOps

*   #### [Beyond One-Click: Designing an Enterprise-Grade Observability Extension for Docker](http://www.infoq.com/articles/enterprise-grade-observability-extension-docker)

Docker Extensions boost developer speed but create a "visibility gap" by isolating telemetry. To meet enterprise needs, extensions must act as bridges to centralized platforms. This article details how to use OpenTelemetry, policy-as-code, and encryption to build secure pipelines. Learn to balance developer productivity with the governance required for scalable, compliant observability.

  [![Image 6: Beyond One-Click: Designing an Enterprise-Grade Observability Extension for Docker](https://imgopt.infoq.com/fit-in/100x100/filters:quality(80)/articles/enterprise-grade-observability-extension-docker/en/smallimage/enterprise-grade-observability-extension-docker-thumbnail-1775560652994.jpg)](http://www.infoq.com/articles/enterprise-grade-observability-extension-docker) 

[All in devops](http://www.infoq.com/devops/)Follow Topic

[Events](https://events.infoq.com/ "Events")

### Helpful links

*   [About InfoQ](http://www.infoq.com/about-infoq "About InfoQ")
*   [InfoQ Editors](http://www.infoq.com/infoq-editors "InfoQ Editors")
*   [Write for InfoQ](http://www.infoq.com/write-for-infoq "Write for InfoQ")
*   [About C4Media](https://c4media.com/ "About C4Media")
*   [Diversity](https://c4media.com/diversity "Diversity")

### Choose your language

*   [En](http://www.infoq.com/news/2026/04/vault-2-0-ibm-identity/# "InfoQ English")
*   [中文](https://www.infoq.cn/)
*   [日本](http://www.infoq.com/jp/)
*   [Fr](http://www.infoq.com/fr/)

[![Image 7: InfoQ Architect Certification - image](https://imgopt.infoq.com/eyJidWNrZXQiOiAiYXNzZXRzLmluZm9xLmNvbSIsImtleSI6ICJ3ZWIvaGVhZGVyL2NvbmZlcmVuY2VzLzIwMjYvT25saW5lQ29ob3J0c01hcmNoMjAyNi10b3AtdjQuanBnIiwiZWRpdHMiOiB7ImpwZWciOiB7ICJxdWFsaXR5Ijo4MH19fQ==) Online InfoQ Architect Certification Join Luca Mezzalira for this 5-week online cohort. Master socio-technical architecture leadership. **Register Now.**](https://certification.qconferences.com/?utm_source=infoq&utm_medium=referral&utm_campaign=homepageheader_onlinecohortaprmayjun26)[![Image 8: QCon AI Boston - image](https://imgopt.infoq.com/eyJidWNrZXQiOiAiYXNzZXRzLmluZm9xLmNvbSIsImtleSI6ICJ3ZWIvaGVhZGVyL2NvbmZlcmVuY2VzLzIwMjYvUUNvbi1BSS1Cb3N0b24tMjAyNi10b3AuanBnIiwiZWRpdHMiOiB7ImpwZWciOiB7ICJxdWFsaXR5Ijo4MH19fQ==) QCon AI Boston Learn how leading engineering teams run AI in production—reliably, securely, and at scale. **Early Bird ends April 14.**](https://boston.qcon.ai/?utm_source=infoq&utm_medium=referral&utm_campaign=homepageheader_qaiboston26)[![Image 9: QCon San Francisco - image](https://imgopt.infoq.com/eyJidWNrZXQiOiAiYXNzZXRzLmluZm9xLmNvbSIsImtleSI6ICJ3ZWIvaGVhZGVyL2NvbmZlcmVuY2VzLzIwMjYvUUNvbi1TRi0yMDI2LXRvcC5qcGciLCJlZGl0cyI6IHsianBlZyI6IHsgInF1YWxpdHkiOjgwfX19) QCon San Francisco Learn what's next in AI and software, from teams already doing it. **Early Bird ends April 14.**](https://qconsf.com/?utm_source=infoq&utm_medium=referral&utm_campaign=homepageheader_qsf26)

[InfoQ Homepage](http://www.infoq.com/ "InfoQ Homepage")[News](http://www.infoq.com/news "News")HashiCorp Vault 2.0 Marks Shift to IBM Lifecycle with New Identity Federation

[DevOps](http://www.infoq.com/Devops/ "DevOps")

[Designing Data Layers for Agentic AI: Patterns for State, Memory, and Coordination at Scale (Webinar May 12th)](https://www.infoq.com/url/t/95243370-17c6-4296-86ff-b50308bd7ada/?label=YugabyteDB-EventPromoBox)

# HashiCorp Vault 2.0 Marks Shift to IBM Lifecycle with New Identity Federation

Apr 24, 2026 2 min read

by

*   [![Image 10: Author photo](https://cdn.infoq.com/statics_s1_20260421232814/images/profiles/5M64uDFY3OssVDUpmZe2jKsqQCiwVGdT.jpg)](http://www.infoq.com/profile/Mark-Silvester/)[Mark Silvester](http://www.infoq.com/profile/Mark-Silvester/)

Follow Platform and Architecture Manager

#### Write for InfoQ

**Feed your curiosity.**Help 550k+ global 

senior developers 

each month stay ahead.[Get in touch](https://www.infoq.com/write-for-infoq/)

Log in to listen to this article

Audio ready to play

 Your browser does not support the audio element. 

0:00 0:00

Normal 1.25x 1.5x

Like

*   [Reading list](http://www.infoq.com/showbookmarks.action)

HashiCorp has released [Vault 2.0](https://developer.hashicorp.com/vault/docs/updates/release-notes), the first major version number change for the secrets management platform since version 1.0 launched in 2018.

This release arrives as engineering teams grapple with the operational complexity of securing communication across multi-cloud and containerised environments.

The move to version 2.0 represents more than just a feature update; it establishes the [IBM versioning and support model](https://www.hashicorp.com/en/blog/vault-enterprise-20-modernizes-identity-security-at-scale) following the recent acquisition. This shift explains the leap from version 1.21 directly to 2.0. Along with the versioning change, the platform now follows the IBM Support Cycle-2 policy, which guarantees at least two years of standard support for major releases. The release also arrives in the context of HashiCorp's 2023 licence change from the Mozilla Public License to the Business Source License, which prompted the community-driven OpenBao fork. For teams that moved to OpenBao or considered doing so, the direction of Vault under IBM ownership will be closely watched.

At the core of this iteration is a refined [identity-based security model](https://www.hashicorp.com/en/blog/the-future-of-secrets-and-identity-management) that prioritises how workload and service identities are verified across distributed environments.

A standout technical addition is the introduction of [Workload Identity Federation](https://www.hashicorp.com/blog/advancing-secret-sync-with-workload-identity-federation) for secret syncing. This feature allows Vault to authenticate with major cloud providers like AWS, Azure, and GCP without the need for long-lived static credentials. By leveraging OIDC tokens, engineering teams can reduce the risk of credential leakage during the synchronisation process. The release also includes modifications to the [internal storage engine](https://developer.hashicorp.com/vault/docs/configuration/storage) designed to improve performance for high-volume operations, which is particularly relevant for real-time encryption and authentication tasks at the enterprise scale.

The underlying architecture has been modified to remove several legacy components, resulting in [breaking changes](https://developer.hashicorp.com/vault/docs/updates/important-changes) that users must account for during the upgrade process. For instance, Azure authentication now requires explicit configuration settings rather than falling back to environment variables, a change that began with plugin updates in the 1.20 cycle and is now enforced as default behaviour. Additionally, the release introduces beta support for [SCIM 2.0 identity provisioning](https://developer.hashicorp.com/vault/api-docs/secret/identity/scim), allowing for the automated management of Vault entities and groups from external identity platforms. Removing older elements is intended to simplify the long-term maintenance of the codebase and allow for more frequent updates under the new ownership.

In the broader secrets management market, Vault 2.0 competes with cloud-native services such as [AWS Secrets Manager](https://aws.amazon.com/secrets-manager/) and [Azure Key Vault](https://azure.microsoft.com/en-gb/products/key-vault/), which offer tight integration within their respective platforms but limited cross-provider portability. Managed alternatives like [Akeyless](https://www.akeyless.io/) and [Doppler](https://www.doppler.com/) target teams seeking a hosted secrets solution without the operational overhead of running Vault. This update also introduces [SPIFFE JWT-SVID support](https://developer.hashicorp.com/vault/docs/auth/spiffe) to enable secure workload participation in SPIFFE-based identity meshes, positioning Vault as a bridge between proprietary and open identity standards.

The release also updates the [Public Key Infrastructure (PKI) secret engine](https://developer.hashicorp.com/vault/docs/secrets/pki) to facilitate the automation of certificate lifecycles. By providing tools for the issuance and renewal of certificates, the update aims to reduce the risks associated with manual credential management. This aligns with [zero-trust networking](https://www.hashicorp.com/solutions/zero-trust-security) principles increasingly adopted across enterprise infrastructure. Documentation updates provided alongside the release offer guidance on [migration strategies](https://developer.hashicorp.com/vault/docs/upgrading) for those currently running version 1.x installations, ensuring a stable transition as the platform enters its next phase of development.

## About the Author

[![Image 11](https://cdn.infoq.com/statics_s1_20260421232814/images/profiles/5M64uDFY3OssVDUpmZe2jKsqQCiwVGdT.jpg)](http://www.infoq.com/profile/Mark-Silvester/)

#### **Mark Silvester**

Mark Silvester is a Platform and Architecture Manager working at Griffiths Waite, a software consultancy based in Birmingham, UK. Responsible for platform strategy, with a focus on delivering innovative solutions for enterprise clients. Areas of interest include cloud-native technologies, DevOps practices, and the practical application of AI in engineering and architecture.

Show more Show less

#### This content is in the [DevOps](http://www.infoq.com/Devops/) topic

Follow Topic

##### Related Topics:

*   [Architecture & Design](http://www.infoq.com/architecture-design/)### [Architecture & Design](http://www.infoq.com/architecture-design)

Followers: 10207

Follow Topic 
*   [DevOps](http://www.infoq.com/Devops/)### [DevOps](http://www.infoq.com/Devops)

Followers: 5047

Follow Topic 
*   [Application Security](http://www.infoq.com/applicationSecurity/)### [Application Security](http://www.infoq.com/applicationSecurity)

Followers: 90

Follow Topic 
*   [Identity Management](http://www.infoq.com/identity_mgmt/)### [Identity Management](http://www.infoq.com/identity_mgmt)

Followers: 31

Follow Topic 
*   [Hashicorp](http://www.infoq.com/hashicorp/)### [Hashicorp](http://www.infoq.com/hashicorp)

Followers: 12

Follow Topic 
*   [Operations management](http://www.infoq.com/om/)### [Operations management](http://www.infoq.com/om)

Followers: 25

Follow Topic 

*   
#### Related Editorial

    *   ##### [HashiCorp Vault 1.21 Brings SPIFFE Authentication, Granular Secret Recovery, and More](http://www.infoq.com/news/2026/03/hashicorp-vault-1-21/)

    *   ##### [HashiCorp’s New Guide Offers Practical Advice on Writing and Rightsizing Terraform Modules](http://www.infoq.com/news/2025/11/advice-rightsizing-terraform/)

    *   ##### [HashiCorp Previews “Agentic Infrastructure” Future with Project Infragraph](http://www.infoq.com/news/2025/10/hashicorp-project-infragraph/)

    *   ##### [HashiCorp Introduces MCP Servers for Terraform and Vault](http://www.infoq.com/news/2025/08/hashicorp-mcp-servers-terraform-/)

    *   ##### [HashiCorp Releases Terraform MCP Server for AI Integration](http://www.infoq.com/news/2025/05/terraform-mcp-server/)

*       
#### Related Sponsors

    *   ##### [Autonomous Production Operations Built on AWS](http://www.infoq.com/vendorcontent/show.action?vcr=00309f51-75f7-4bc9-a219-76b71e92d402&primaryTopicId=1893&vcrPlace=BOTTOM&pageType=NEWS_PAGE&vcrReferrer=https%3A%2F%2Fwww.infoq.com%2Fnews%2F2026%2F04%2Fvault-2-0-ibm-identity%2F)

    *   ##### [Advance your architecture career with the InfoQ Certified Architect Program—practical, peer-driven certification](http://www.infoq.com/vendorcontent/show.action?vcr=7b77e63a-aa33-4b76-9474-8ba7adae4772&primaryTopicId=1893&vcrPlace=BOTTOM&pageType=NEWS_PAGE&vcrReferrer=https%3A%2F%2Fwww.infoq.com%2Fnews%2F2026%2F04%2Fvault-2-0-ibm-identity%2F)

    *   ##### [Architecting for What’s Next: Key Software Trends Every Senior Practitioner Must Act On — Download the InfoQ eMag](http://www.infoq.com/vendorcontent/show.action?vcr=498e4f98-9a88-4cfd-8ca6-ed3f7d5b1ba6&primaryTopicId=1893&vcrPlace=BOTTOM&pageType=NEWS_PAGE&vcrReferrer=https%3A%2F%2Fwww.infoq.com%2Fnews%2F2026%2F04%2Fvault-2-0-ibm-identity%2F)

    *   ##### [The Rise of Client-Side Risk and the Trust Gap](http://www.infoq.com/vendorcontent/show.action?vcr=dbfb37c5-a393-4740-85e7-8497be3ac7c0&primaryTopicId=1893&vcrPlace=BOTTOM&pageType=NEWS_PAGE&vcrReferrer=https%3A%2F%2Fwww.infoq.com%2Fnews%2F2026%2F04%2Fvault-2-0-ibm-identity%2F)

    *   ##### [Understanding AI Agent Security](http://www.infoq.com/url/f/7f42b86b-2b7e-4739-bb97-15ed875fced5/)

*   #### Related Sponsor

[![Image 12: Related sponsor icon](https://imgopt.infoq.com//fit-in/218x500/filters:quality(100)/filters:no_upscale()/sponsorship/topic/ae9df779-fe62-46d8-a42e-92795ae3c56e/promptfoo-horizontal-logo-1775562471842.png)](http://www.infoq.com/url/f/d99bf7a8-0d65-45c1-901f-1c40ce627952/)Confidently test, evaluate, and red-team your LLM apps with **Promptfoo** — catch regressions, benchmark models, and ship high-quality AI features faster; start testing your prompts today. **[Learn More](http://www.infoq.com/url/f/7efac22a-bbf7-40dc-ad9b-ac098e66c623/).**  

### Related Content

*   ##### [HashiCorp Vault 1.21 Brings SPIFFE Authentication, Granular Secret Recovery, and More](http://www.infoq.com/news/2026/03/hashicorp-vault-1-21/)

Mar 28, 2026    
*   ##### [New Rowhammer Attacks on NVIDIA GPUs Enable Full System Takeover](http://www.infoq.com/news/2026/04/rowhammer-attacks-nvidia/)

Apr 14, 2026    
*   ##### [Anthropic Releases Claude Mythos Preview with Cybersecurity Capabilities but Withholds Public Access](http://www.infoq.com/news/2026/04/anthropic-claude-mythos/)

Apr 13, 2026    
*   ##### [Axios npm Package Compromised in Supply Chain Attack](http://www.infoq.com/news/2026/04/axios-supply-chain/)

Apr 02, 2026    
*   ##### [TanStack Start Introduces Import Protection to Enforce Server and Client Boundaries](http://www.infoq.com/news/2026/03/tanstack-import-protection/)

Mar 31, 2026    
*   ##### [Trustworthy Productivity: Securing AI Accelerated Development](http://www.infoq.com/articles/secure-ai-development/)

Dec 16, 2025   [![Image 13: Icon image](https://imgopt.infoq.com/fit-in/50x50/filters:quality(80)/articles/secure-ai-development/en/smallimage/thumbnail-1765541260371.jpg)](http://www.infoq.com/articles/secure-ai-development/) 
*   ##### [Stop Guessing, Start Improving: Using DORA Metrics and Process Behavior Charts](http://www.infoq.com/articles/DORA-metrics-PBCs/)

Dec 29, 2025   [![Image 14: Icon image](https://imgopt.infoq.com/fit-in/50x50/filters:quality(80)/articles/DORA-metrics-PBCs/en/smallimage/thumbnail-dora-metrics-1766410050172.jpg)](http://www.infoq.com/articles/DORA-metrics-PBCs/) 
*   Icon##### [Deepfakes, Disinformation, and AI Content Are Taking Over the Internet](http://www.infoq.com/presentations/deepfakes-ai/)

Apr 24, 2026   [![Image 15: Icon image](https://imgopt.infoq.com/fit-in/50x50/filters:quality(80)/presentations/deepfakes-ai/en/smallimage/shuman-ghosemajumder-thumbnail-1776248048343.jpeg)](http://www.infoq.com/presentations/deepfakes-ai/) 
*   ##### [Orchestrating Agentic and Multimodal AI Pipelines with Apache Camel](http://www.infoq.com/articles/orchestrating-agentic-multimodal-ai-pipelines-apache-camel/)

Apr 24, 2026   [![Image 16: Icon image](https://imgopt.infoq.com/fit-in/50x50/filters:quality(80)/articles/orchestrating-agentic-multimodal-ai-pipelines-apache-camel/en/smallimage/orchestrating-agentic-multimodal-ai-pipelines-apache-camel-thumbnail-1776763980414.jpg)](http://www.infoq.com/articles/orchestrating-agentic-multimodal-ai-pipelines-apache-camel/) 

### Related Sponsors

*   [![Image 17: Harder, Better, Prompter, Stronger: AI system prompt hardening](https://imgopt.infoq.com/fit-in/250x320/filters:quality(80)/sponsorship/rsc/f86d2e64-3d54-4df7-9b21-79f066639589/cover/Promptfoo3-1775560300828.jpg)](http://www.infoq.com/vendorcontent/show.action?vcr=f86d2e64-3d54-4df7-9b21-79f066639589&pageType=NEWS_PAGE&vcrPlace=TS_SPONSORED_CONTENT_TOP)#### [Harder, Better, Prompter, Stronger: AI system prompt hardening](http://www.infoq.com/vendorcontent/show.action?vcr=f86d2e64-3d54-4df7-9b21-79f066639589&pageType=NEWS_PAGE&vcrPlace=TS_SPONSORED_CONTENT_TOP)

System prompts define how LLM applications behave—but they are vulnerable to manipulation. This article explores prompt hardening techniques such as instruction shielding, syntax reinforcement, and layered prompting to defend AI systems against prompt injection and override attacks. 
*   [![Image 18: Inside MCP: A Protocol for AI Integration](https://imgopt.infoq.com/fit-in/250x320/filters:quality(80)/sponsorship/rsc/d19b4af8-f5b6-447c-bcbe-687c94145134/cover/Promptfoo1-1775560075453.jpg)](http://www.infoq.com/vendorcontent/show.action?vcr=d19b4af8-f5b6-447c-bcbe-687c94145134&pageType=NEWS_PAGE&vcrPlace=TS_SPONSORED_CONTENT_TOP)#### [Inside MCP: A Protocol for AI Integration](http://www.infoq.com/vendorcontent/show.action?vcr=d19b4af8-f5b6-447c-bcbe-687c94145134&pageType=NEWS_PAGE&vcrPlace=TS_SPONSORED_CONTENT_TOP)

The Model Context Protocol (MCP) defines a standard way for AI systems to interact with tools, data, and services. This article explains MCP’s architecture—hosts, clients, and servers—and how it enables structured, secure integrations between AI models and external systems. 
*   Sponsored by

[![Image 19: Icon image](https://imgopt.infoq.com//fit-in/275x500/filters:quality(100)/filters:no_upscale()/sponsorship/topic/ae9df779-fe62-46d8-a42e-92795ae3c56e/promptfoo-horizontal-logo-1775562471842.png)](http://www.infoq.com/url/f/d99bf7a8-0d65-45c1-901f-1c40ce627952/)

### Related Content

*   ##### [React Navigation 8.0 Alpha with Native Bottom Tabs, Reworked TypeScript Inference and History](http://www.infoq.com/news/2026/04/react-navigation-8-alpha/)

Apr 23, 2026    
*   ##### [Google Introduces Room 3.0: A Kotlin-First, Async, Multiplatform Persistence Library](http://www.infoq.com/news/2026/04/room-3-kotlin-async-sqlite/)

Apr 23, 2026    
*   ##### [Grafana Rearchitects Loki with Kafka and Ships a CLI to Bring Observability Into Coding Agent](http://www.infoq.com/news/2026/04/grafana-loki-ai-agents/)

Apr 23, 2026    
*   ##### [How Observability and Telemetry Can Enhance the Practice of Software Engineering](http://www.infoq.com/news/2026/04/observability-telemetry/)

Apr 23, 2026    
*   Icon##### [How to Build an Exchange: Sub Millisecond Response Times and 24/7 Uptimes in the Cloud](http://www.infoq.com/presentations/exchange-systems-cloud/)

Apr 23, 2026   [![Image 20: Icon image](https://imgopt.infoq.com/fit-in/50x50/filters:quality(80)/presentations/exchange-systems-cloud/en/smallimage/frank-yu-thumbnail-1776173818222.jpeg)](http://www.infoq.com/presentations/exchange-systems-cloud/) 
*   ##### [Dropbox Collaborates with GitHub to Reduce Monorepo Size from 87GB to 20GB](http://www.infoq.com/news/2026/04/dropbox-reduces-git-optimization/)

Apr 22, 2026    

### **The InfoQ** Newsletter

A round-up of last week’s content on InfoQ sent out every Tuesday. Join a community of over 250,000 senior developers. [View an example](https://assets.infoq.com/newsletter/regular/en/newsletter_sample/newsletter_sample.html)

Enter your e-mail address 

Select your country - [x] I consent to InfoQ.com handling my data as explained in this [Privacy Notice](https://www.infoq.com/privacy-notice). 

[We protect your privacy.](http://www.infoq.com/privacy-notice/)

*   [Development](http://www.infoq.com/development/) 

    *   ##### [C++26: Reflection, Memory Safety, Contracts, and a New Async Model](http://www.infoq.com/news/2026/04/cpp-26-reflection-safety-async/ "C++26: Reflection, Memory Safety, Contracts, and a New Async Model")

    *   ##### [From VR to Flat Screens: Bridging the Input and Immersion Gap](http://www.infoq.com/presentations/game-vr-flat-screens/ "From VR to Flat Screens: Bridging the Input and Immersion Gap")

    *   ##### [Cursor 3 Introduces Agent-First Interface, Moving beyond the IDE Model](http://www.infoq.com/news/2026/04/cursor-3-agent-first-interface/ "Cursor 3 Introduces Agent-First Interface, Moving beyond the IDE Model")

*   [Architecture & Design](http://www.infoq.com/architecture-design/) 

    *   ##### [How to Build an Exchange: Sub Millisecond Response Times and 24/7 Uptimes in the Cloud](http://www.infoq.com/presentations/exchange-systems-cloud/ "How to Build an Exchange: Sub Millisecond Response Times and 24/7 Uptimes in the Cloud")

    *   ##### [Dropbox Collaborates with GitHub to Reduce Monorepo Size from 87GB to 20GB](http://www.infoq.com/news/2026/04/dropbox-reduces-git-optimization/ "Dropbox Collaborates with GitHub to Reduce Monorepo Size from 87GB to 20GB")

    *   ##### [Cloudflare Outlines MCP Architecture as Enterprises Confront Security and Governance Risks](http://www.infoq.com/news/2026/04/cloudflare-mcp/ "Cloudflare Outlines MCP Architecture as Enterprises Confront Security and Governance Risks")

*   [Culture & Methods](http://www.infoq.com/culture-methods/) 

    *   ##### [How Observability and Telemetry Can Enhance the Practice of Software Engineering](http://www.infoq.com/news/2026/04/observability-telemetry/ "How Observability and Telemetry Can Enhance the Practice of Software Engineering")

    *   ##### [Panel: Building a Culture that Works](http://www.infoq.com/presentations/panel-positive-culture/ "Panel: Building a Culture that Works")

    *   ##### [Platform as a Product: Delivering Value While Balancing Competing Priorities](http://www.infoq.com/news/2026/04/platform-product-deliver-value/ "Platform as a Product: Delivering Value While Balancing Competing Priorities")

*   [AI, ML & Data Engineering](http://www.infoq.com/ai-ml-data-eng/) 

    *   ##### [Deepfakes, Disinformation, and AI Content Are Taking Over the Internet](http://www.infoq.com/presentations/deepfakes-ai/ "Deepfakes, Disinformation, and AI Content Are Taking Over the Internet")

    *   ##### [Orchestrating Agentic and Multimodal AI Pipelines with Apache Camel](http://www.infoq.com/articles/orchestrating-agentic-multimodal-ai-pipelines-apache-camel/ "Orchestrating Agentic and Multimodal AI Pipelines with Apache Camel")

    *   ##### [Dynamic Moments: Weaving LLMs into Deep Personalization at DoorDash](http://www.infoq.com/presentations/llm-personalization/ "Dynamic Moments: Weaving LLMs into Deep Personalization at DoorDash")

*   [DevOps](http://www.infoq.com/devops/) 

    *   ##### [HashiCorp Vault 2.0 Marks Shift to IBM Lifecycle with New Identity Federation](http://www.infoq.com/news/2026/04/vault-2-0-ibm-identity/ "HashiCorp Vault 2.0 Marks Shift to IBM Lifecycle with New Identity Federation")

    *   ##### [Grafana Rearchitects Loki with Kafka and Ships a CLI to Bring Observability Into Coding Agent](http://www.infoq.com/news/2026/04/grafana-loki-ai-agents/ "Grafana Rearchitects Loki with Kafka and Ships a CLI to Bring Observability Into Coding Agent")

    *   ##### [GitHub Acknowledges Recent Outages, Cites Scaling Challenges and Architectural Weaknesses](http://www.infoq.com/news/2026/04/github-outages-scaling/ "GitHub Acknowledges Recent Outages, Cites Scaling Challenges and Architectural Weaknesses")

## **The InfoQ** Newsletter

A round-up of last week’s content on InfoQ sent out every Tuesday. Join a community of over 250,000 senior developers. [View an example](https://assets.infoq.com/newsletter/regular/en/newsletter_sample/newsletter_sample.html)

*   Get a quick overview of content published on a variety of innovator and early adopter technologies
*   Learn what you don’t know that you don’t know
*   Stay up to date with the latest information from the topics you are interested in

Enter your e-mail address 

Select your country - [x] I consent to InfoQ.com handling my data as explained in this [Privacy Notice](https://www.infoq.com/privacy-notice). 

[We protect your privacy.](http://www.infoq.com/privacy-notice/)

[**May 7 | June 10, 2026 | Online** Architecture decisions are hard to validate while shipping. Join a **5-week online cohort** for **senior engineers, architects, and team leads** to pressure-test real decisions, apply practical frameworks, and work through challenges with a confidential peer group. Facilitated by Luca Mezzalira, Principal Architect at AWS, this cohort helps you: * Pressure-test real decisions. * Apply frameworks to real problems. * Publish on InfoQ.com and earn your certification. **RESERVE YOUR PLACE**](https://certification.qconferences.com/?utm_source=infoq&utm_medium=referral&utm_campaign=largefooterad_onlinecohortaprmayjun26)

[Home](http://www.infoq.com/ "Home")[Create account](http://www.infoq.com/reginit.action "Create account")Log In[QCon Conferences](http://qconferences.com/ "QCon Conferences")[Events](https://events.infoq.com/)[Write for InfoQ](http://www.infoq.com/write-for-infoq/ "Write for InfoQ")[InfoQ Editors](http://www.infoq.com/infoq-editors/ "InfoQ Editors")[About InfoQ](http://www.infoq.com/about-infoq/ "About InfoQ")[About C4Media](https://c4media.com/ "About C4Media")[Media Kit](https://get.infoq.com/infoq-mediakit/ "Media Kit")[InfoQ Developer Marketing Blog](https://devmarketing.c4media.com/?utm_source=infoq "InfoQ Developer Marketing Blog")[Diversity](https://c4media.com/diversity "Diversity")

#### Events

*   ##### [Online InfoQ Architect Certification](https://certification.qconferences.com/?utm_source=infoq&utm_medium=referral&utm_campaign=footer_onlinecohortaprmayjun26)

May 7, 2026 
*   ##### [QCon AI Boston](https://boston.qcon.ai/?utm_source=infoq&utm_medium=referral&utm_campaign=footer_qaiboston26)

June 1-2, 2026 
*   ##### [Online InfoQ Architect Certification](https://certification.qconferences.com/?utm_source=infoq&utm_medium=referral&utm_campaign=footer_onlinecohortaprmayjun26)

June 10, 2026 
*   ##### [QCon San Francisco](https://qconsf.com/?utm_source=infoq&utm_medium=referral&utm_campaign=footer_qsf26)

November 16-20, 2026 

#### Follow us on

[Youtube 232K Followers](https://www.youtube.com/infoq)[Linkedin 26K Followers](http://www.linkedin.com/company/infoq)[RSS 19K Readers](https://feed.infoq.com/)[X 57.1k Followers](http://twitter.com/infoq)[Facebook 21K Likes](https://www.facebook.com/InfoQ-75911537320)[Bluesky New](https://bsky.app/profile/infoq.com)[Instagram New](https://www.instagram.com/infoqdotcom/)

#### Stay in the know

[The InfoQ Podcast![Image 21: The InfoQ Podcast Logo - Stay in the know](https://imgopt.infoq.com/eyJidWNrZXQiOiAiYXNzZXRzLmluZm9xLmNvbSIsImtleSI6ICJ3ZWIvZm9vdGVyL2luZm9xLXBvZGNhc3QuanBnIiwiZWRpdHMiOiB7ImpwZWciOiB7ICJxdWFsaXR5Ijo4MH19fQ==)](http://www.infoq.com/podcasts/)[Engineering Culture Podcast![Image 22: Engineering Culture Podcast Logo - Stay in the knoww](https://imgopt.infoq.com/eyJidWNrZXQiOiAiYXNzZXRzLmluZm9xLmNvbSIsImtleSI6ICJ3ZWIvZm9vdGVyL2luZm9xLXBvZGNhc3QtZW5naW5lZXJpbmctY3VsdHVyZS5qcGciLCJlZGl0cyI6IHsianBlZyI6IHsgInF1YWxpdHkiOjgwfX19)](http://www.infoq.com/podcasts/#engineering_culture)[The Software Architects' Newsletter![Image 23: The Software Architects' Newsletter Logo - Stay in the know](https://imgopt.infoq.com/eyJidWNrZXQiOiAiYXNzZXRzLmluZm9xLmNvbSIsImtleSI6ICJ3ZWIvZm9vdGVyL2luZm9xLWFyY2hpdGVjdC1uZXdzbGV0dGVyLmpwZyIsImVkaXRzIjogeyJqcGVnIjogeyAicXVhbGl0eSI6ODB9fX0=)](http://www.infoq.com/software-architects-newsletter/)

 General Feedback [feedback@infoq.com](mailto:feedback@infoq.com) Advertising [sales@infoq.com](mailto:sales@infoq.com) Editorial [editors@infoq.com](mailto:editors@infoq.com) Marketing [marketing@infoq.com](mailto:marketing@infoq.com)

InfoQ.com and all content copyright © 2006-2026 C4Media Inc.

[Privacy Notice](http://www.infoq.com/privacy-notice), [Terms And Conditions](http://www.infoq.com/terms-and-conditions), [Cookie Policy](http://www.infoq.com/cookie-policy)

Close

[BT](http://www.infoq.com/int/bt/ "bt")
