authentik
authentik 2026.8 ships: Actors, domain-joined Agents, and a push past browser-mediated SSO
A side-by-side editorial comparison of KubeVirt and RabbitMQ — release velocity, themes, recent moves, and the top alternatives to consider.
KubeVirt's 1.9 cycle is a bet on GPUs and cross-architecture VMs
Everything in the window belongs to one long v1.9.0 pre-release cycle — alpha.0 in May through rc.2 in late July — totaling roughly 1,650 changes from over 100 contributors. The release notes are cumulative, so each RC restates the prior list and appends what landed since. There is no stable v1.9.0 tag yet.
Two parallel trains, and the 'maintenance' label is now hiding real feature work
RabbitMQ is maintaining 4.2.x and 4.3.x side by side, cutting matching patches into both on the same day, and both trains raised their floor to Erlang/OTP 27. Most of the window is correctness work in the Raft-backed subsystems — quorum queues losing metrics after a restart, leaders committing log entries too optimistically, classic queue index paths accumulating slashes, topic bindings with empty routing keys matching everything. The newest 4.3.5, however, is labelled a maintenance release while carrying encrypted management-UI login tokens, a new authentication logging category, ETag support on the definitions endpoint, and a self-deleting Shovel TTL.
Everything in the window belongs to one long v1.9.0 pre-release cycle — alpha.0 in May through rc.2 in late July — totaling roughly 1,650 changes from over 100 contributors. The release notes are cumulative, so each RC restates the prior list and appends what landed since. There is no stable v1.9.0 tag yet.
The cycle's center of gravity is accelerator and device virtualization. NVIDIA Grace GPU passthrough arrives behind a feature gate with SMMUv3/IOMMUFD, ACPI Generic Initiator NUMA topology and PCI 64-bit hole sizing; GPUsWithDRA and HostDevicesWithDRA graduate to beta with E2E coverage; SR-IOV vGPU gains display support and a new metric correlates GPU UUIDs with VMIs. A second thread pushes the hardware envelope elsewhere: cross-architecture execution behind an alpha gate, workload SEV encryption to beta, and zstd compression for live-migration streams.
A stable v1.9.0 should follow shortly given rc.2 landed in late July and the recent commits are bug fixes rather than new gates. The alpha gates introduced here — cross-architecture virtualization and Grace I/O virtualization — are the ones to watch for graduation in the 1.10 cycle.
RabbitMQ is maintaining 4.2.x and 4.3.x side by side, cutting matching patches into both on the same day, and both trains raised their floor to Erlang/OTP 27. Most of the window is correctness work in the Raft-backed subsystems — quorum queues losing metrics after a restart, leaders committing log entries too optimistically, classic queue index paths accumulating slashes, topic bindings with empty routing keys matching everything. The newest 4.3.5, however, is labelled a maintenance release while carrying encrypted management-UI login tokens, a new authentication logging category, ETag support on the definitions endpoint, and a self-deleting Shovel TTL.
The bug pattern remains the tell: nearly every fix is in quorum queues, Khepri or Raft, which is where RabbitMQ moved its metadata and durability story after 4.3.0 removed Mnesia and partition-handling strategies outright. Layered on top is a steady tightening of the operational perimeter — protocol parsers rejecting malformed input strictly across AMQP 1.0, MQTT 5.0 and STOMP, pre-authentication frame limits on stream connections, HTTP API endpoints validating node membership, and headers that stop disclosing supported methods. Feature work is arriving inside patch releases rather than waiting for a minor.
Expect the 4.2.x train to slow toward end-of-life while 4.3.x patches keep absorbing both Khepri edge cases and security-surface work. The encrypted login token, currently opt-in behind a shared cluster secret, is the kind of setting that gets promoted to a default once rolling-upgrade friction is behind it.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either KubeVirt or RabbitMQ.
authentik 2026.8 ships: Actors, domain-joined Agents, and a push past browser-mediated SSO
Rancher's public feed is a build-tag stream: three branches bumped the same Go image on one afternoon
Buildkite keeps converting hand-rolled agent workarounds into first-class CI primitives.
Cursor's agents stop waiting to be asked - they subscribe, and they hold a goal until it's done.
Nexus does the diagnosis; the agent is now reaching into the status page too.
Warp turned its quarter of software-factory essays into infrastructure you can buy.
See all KubeVirt alternatives → · See all RabbitMQ alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. KubeVirt and RabbitMQ are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. KubeVirt and RabbitMQ are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top KubeVirt alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "KubeVirt alternatives" section above for the current picks, or visit /alternatives/kubevirt for the full list with editorial commentary on each.
Top RabbitMQ alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "RabbitMQ alternatives" section above for the current picks, or visit /alternatives/rabbitmq for the full list with editorial commentary on each.