# Cerbos v0.36.0

## Highlights

To reduce the overhead of writing large audit log entries to slow sinks (files and `stdout`, for example), Cerbos now writes audit logs in the background. If you send very large batch requests containing a lot of data to Cerbos, this should help improve the response times.

A community contribution from @rcrowe makes the Kafka audit backend use system CA certificates if none are provided explicitly in configuration. It also addresses a case where asynchronous Kafka writes start blocking when the downstream brokers are down.

The new [`cerbosctl inspect`](https://docs.cerbos.dev/cerbos/0.38.1/cli/cerbosctl#inspect-policies) command provides command-line access to the `inspect` Admin API endpoint introduced in the previous release. Currently it supports listing actions covered by each policy. More policy inspection options are planned for future releases.

### Cerbos Hub integration

Early adopters of the [Cerbos Hub](/content/product-cerbos-hub/index.html) audit log collection feature can now filter out audit log entries locally before they are sent to Hub.

For consistency, the `bundle` storage driver has been renamed to `hub`. To migrate, change `storage.driver: bundle` to `storage.driver: hub` and rename any configuration values starting with `storage.bundle` to `storage.hub`.

Embedded PDP users can use the `cerbosctl hub epdp list-candidates` command to scan a policy repo and list the set of policies that would be included in a Cerbos Embedded PDP bundle.

## Changelog

### Bug Fixes

- Default expectation to `EFFECT_DENY` for unspecified actions in tests ( [#2116](https://github.com/cerbos/cerbos/pull/2116))

- Eagerly establish gRPC connection to avoid initial delay ( [#2105](https://github.com/cerbos/cerbos/pull/2105))

- Handle folded strings and indented newlines in YAML correctly ( [#2128](https://github.com/cerbos/cerbos/pull/2128))

- Ignore context cancellation when writing audit log entries ( [#2113](https://github.com/cerbos/cerbos/pull/2113))

- Include implicit `EFFECT_DENY` in test failure details ( [#2117](https://github.com/cerbos/cerbos/pull/2117))

- Kafka TLS using system CA ( [#2120](https://github.com/cerbos/cerbos/pull/2120))

- Stop blocking Kafka audit publishing when an outage occurs ( [#2122](https://github.com/cerbos/cerbos/pull/2122))

### Features

- Add cerbosctl hub epdp list-candidates command ( [#2078](https://github.com/cerbos/cerbos/pull/2078))

- Add cerbosctl inspect policies command ( [#2101](https://github.com/cerbos/cerbos/pull/2101))

### Enhancements

- Add audit log filtering to Hub backend ( [#2073](https://github.com/cerbos/cerbos/pull/2073))

- Apply perf patch to YAML parser ( [#2132](https://github.com/cerbos/cerbos/pull/2132))

- Write audit logs asynchronously ( [#2104](https://github.com/cerbos/cerbos/pull/2104))

### Documentation

- Add documentation for Dagger Cerbos module ( [#2106](https://github.com/cerbos/cerbos/pull/2106))

- Document Hub features ( [#2133](https://github.com/cerbos/cerbos/pull/2133))

- Document how to verify cosign signatures ( [#2094](https://github.com/cerbos/cerbos/pull/2094))
