redb 4.0 Released: XML Routes, Lazy References, Unique Keys and WS-Trust Across the Ecosystem
redb 4.0 delivers a coordinated major release across the entire ecosystem, updating redb.Core, redb.Route, redb.Tsak and redb.Identity in a single 4.0.0 version. Seventy-six NuGet packages, seven container images in GHCR and archives for Windows and Linux are now published. The Pro edition remains free and does not require a license key on the entire 4.x line.
redb.Route receives ten new packages and a substantial engine redesign. Declarative routes can now be defined in .route.xml files using the new redb.Route.Xml package and loaded into the same fluent DSL used for C# routes. The redb.Route.TestKit allows testing without brokers or route modifications through AdviceRoute, MockEndpoints and NotifyBuilder. Additional packages provide Scriban and Liquid templates, CSV, Protobuf, Avro and YAML data formats, JSONata transformations, in-memory or distributed caching, and XPath 2.0 support.
The routing engine now uses a single expression language and compiler for conditions, values and templates. New functions include stats, format, uuid and the modulo operator. The bean component allows custom objects to be used as endpoints with dependency injection. REST DSL, OpenAPI 3.0.3 generation, OpenTelemetry metrics inside routes and removal of Newtonsoft.Json in favour of System.Text.Json are also included.
Hosting improvements cover concurrent request limits with 429 responses, automatic consumer scaling for RabbitMQ, AMQP 1.0, IBM MQ, SQS and MQTT, WebSocket and SignalR support on the shared Kestrel host, and trusted proxy handling for X-Forwarded headers. Kafka consumers now preserve unprocessed records on partition revocation, and connectors for S3, Firebase and LLM providers received multiple stability and feature updates.
redb.Core introduces lazy references that load only on first access to Props when EnableLazyReferences is active, and unique keys via the new ValueUnique mechanism and [RedbUnique] attribute. Unique constraints are enforced by database indexes for scalars, nested objects, collections and entire subtrees. Schema upgrades are applied at startup with typed exceptions when rights are insufficient. CancellationToken support, save interceptors, per-request isolation levels and maintenance operations such as AnalyzeAsync are now available across PostgreSQL, MSSQL and SQLite.
redb.Tsak cluster coordination now relies on unique database keys from redb.Core. XML-only modules can be loaded and reloaded at runtime. The dashboard distinguishes load shedding from idle routes, Audit and Dead-letter pages are functional on PostgreSQL, and trusted proxy configuration is exposed for API throttling.
redb.Identity adds a WS-Trust SOAP facade supporting Issue, Validate, Cancel and Renew operations. Access tokens now include audience claims according to RFC 9068. The administrative console has been rebuilt with full pages instead of dialogs, and DPoP support behind TLS-terminating proxies has been improved.
Several security issues were addressed. Internal headers are now stripped on all three identity facades. Consent pages validate signed tickets and Origin headers. Introspection responses are restricted to token audiences. Dashboard pages require authentication with role-based access. Module signatures are verified on every load path, and the default password hasher is now bcrypt.
Clusters must be fully stopped before upgrading because mixed versions are unsupported. Large databases require a maintenance window for schema changes performed under exclusive locks. Full change logs are published at redb.ru/releases.
Related articles
Why Defending a Company Costs Millions While Attacks Can Succeed for Just Hundreds of Dollars
In the latest episode of Belyaev Podcast, CISO Vyacheslav Kasimov of Tochka Bank and Boris Evdokimov of ASNA pharmacy chain discussed the persistent asymmetry in cybersecurity spending. Attackers increasingly rely on affordable cloud services, automation, and rented infrastructure, while defenders must invest heavily in monitoring, access controls, backups, and skilled teams. The experts stressed that the absence of known breaches does not equal security, as undetected incidents or delayed discovery remain common risks. They advocated shifting from a "no" culture to risk-based decision making that helps business leaders understand potential losses, mitigation costs, and residual risk. The conversation also covered responsible use of AI in SOC operations and the long-term damage caused by loss of customer trust after incidents.
Beeline Offers One Month Free Access to Six Services for Prepaid Customers
Beeline has launched a promotional campaign allowing home users on prepaid plans to try up to six digital services for free over 30 days. The offer, tied to the operator's second annual Cellular Independence Day, runs from October 2 to October 9 and includes services such as Virtual Assistant PRO, unlimited mobile data, internet sharing without speed reduction, custom network name display, 250 GB of cloud storage, and access to over 650,000 e-books and audiobooks. Each selected service activates its own free period starting from the moment of connection and deactivates automatically afterward. Customers already paying for four or more of the listed services will receive 300 bonus rubles for communication instead. The unlimited data option is unavailable in the Chukotka Autonomous Okrug and Norilsk. Activation is handled exclusively through the Beeline mobile app, and users with existing paid subscriptions to any service cannot activate the free trial version of the same service.
Enterprise-Grade Web Protection on a Budget: How Cloud WAF Lowers Barriers for SMBs
A new overview from Reg.cloud explains how cloud-based Web Application Firewalls reduce the cost and complexity of protecting websites, APIs, and web applications for small and medium-sized Russian businesses. According to Positive Technologies data cited in the article, 75% of successful web application attacks in 2025 disrupted organizational operations, while 82% of SMBs faced cyber incidents in the past year. The piece details the differences between traditional on-premises WAF deployments and cloud offerings, emphasizing ready-made protection profiles for CMS platforms, SaaS services, and digital agencies. It outlines a three-stage operational model covering preparation, DNS-based traffic redirection, and ongoing policy tuning that can be handled by existing DevOps or development teams without dedicated security staff. The service currently offers a free tier supporting up to three applications at 50 requests per second, along with seven preconfigured security profiles and dual audit/blocking modes. The article concludes by stressing that WAF remains only one layer and must be combined with patching, access controls, and separate DDoS or anti-bot solutions.
Yandex B2B Tech Integrates Hybrid Full-Text and Vector Search in Single YDB Query
Yandex B2B Tech has added hybrid search to its YDB database, allowing full-text and vector approaches to run together inside one SQL query. The update helps small and medium businesses as well as large corporations locate exact document identifiers while also matching semantic meaning in descriptions, even when wording differs. Full-text search handles precise elements such as policy numbers, codes, and names, whereas vector search identifies conceptual similarity. Results from both methods are merged and ranked within the same transaction, keeping all data inside a single database instance. This removes the need to maintain a separate search engine and vector store or to reconcile information between them. The technology is aimed at chatbots, recommendation systems, and AI assistants that process technical content where both exact codes and human-readable problem descriptions matter equally. Hybrid search is now available in the on-premises YDB 26.3 release and in the cloud-based Managed Service for YDB.