authentik 2023.10.0 → 2024.2.0
8 versions, 1 with breaking changes, 1 required stop
Required stops
- 2023.10.7
Latest 2023.10.x release.
Upgrade sequence: Upgrades must follow the sequence of major releases; do not skip directly from an older major version to the most recent version.
Always upgrade to the latest minor version (
.x) within eachmajor.minorversion before upgrading to the next major version. For example, if you're currently running2025.2.1, upgrade in the following order:- Upgrade to the latest
2025.2.x. - Then to the latest
2025.4.x. - Finally to the latest
2025.6.x.
Outposts: The version of the authentik server and all authentik outposts must match. Ensure that all outposts are upgraded at the same time as the core authentik instance.
Source: https://docs.goauthentik.io/install-config/upgrade/#important-considerations (checked 2026-09-28)
- Upgrade to the latest
Version by version, oldest first
2023.10.1 – 2023.10.6: no action items (6 versions)
2023.10.7 2024-01-29
Required stop
2024.2.0 2024-02-21
Breaking
Manual action is required
- Tenants have been renamed to brands
Tenants, which were previously used to change branding configuration, default flows, and several other settings, have been renamed to brands. The term "Brands" more accurately reflects their usage for configuring branding, logos, colors, and overall login flow behavior.
Existing tenant objects will automatically be renamed to brand objects. The API endpoints associated with brands have also been renamed.
Blueprints using authentik_tenants.tenant will need to be changed to use authentik_brands.brand.
For more information, refer to the documentation for brands.
Also, the event retention settings configured in brands (previously tenants, see above) have been removed and are now a system setting, managed in the Admin interface or via the API (see below).
There is no built-in migration path for this change. If you set something other than the default (days=365), you will need to update the setting in the admin interface.
- Helm chart breaking changes
The Helm Chart has a number of breaking changes. Find out more in the chart release notes.
Manual action may be required
- Required
offline_accessscope for Refresh tokens
The OAuth2 provider ships with a new default scope called offline_access, which must be requested by applications that need a refresh token. Previously, authentik would always issue a refresh token for the Authorization code and Device code OAuth grants.
Applications that require a refresh token will need their configuration to be updated to include the offline_access scope mapping.
- Database requirement changes
authentik now uses PostgreSQL schemas other than public.
If you have a custom PostgreSQL deployment, please ensure that the authentik user is allowed to create schemas. Usually, if the authentik user is owner of the database, it already can.
- Redis and cache configuration options have been improved
Thank you @PKizzle for this contribution!
Cache settings have been moved from the redis top-level config key to their own cache top-level config key.
Settings have also been added to configure the Redis instance/database used for tasks and websockets separately from cache. See here.
Typically, no changes to the configuration are required.
- Configuration options migrated to the Admin interface
The following config options have been moved from the config file and can now be set using the Admin interface (under System -> Settings) or the API:
AUTHENTIK_AVATARSAUTHENTIK_DEFAULT_USER_CHANGE_NAMEAUTHENTIK_DEFAULT_USER_CHANGE_EMAILAUTHENTIK_DEFAULT_USER_CHANGE_USERNAMEAUTHENTIK_GDPR_COMPLIANCEAUTHENTIK_IMPERSONATIONAUTHENTIK_FOOTER_LINKSAUTHENTIK_REPUTATION__EXPIRY
When upgrading to 2024.2, the currently configured options will be automatically migrated to the database, and can be removed from the .env or helm values file afterwards.
- Icons are now in a
public/subfolder
If your media folder is /media, icons are now stored in /media/public. authentik will automatically migrate the icons upon upgrading.
Note that even though that folder is named public, the files stored here are not automatically public. This is due to the naming of the default PostgreSQL schema.
- User sessions will be invalidated after this upgrade.
As such, users will need to log back in. Immediately after the upgrade completes, users are logged out automatically and are then prompted to log in again. This only occurs once.
- Removal of deprecated metrics
These metrics were renamed because they did not adhere to Prometheus best practices. The old metrics were kept for backwards compatibility and have now been removed.
authentik_outpost_flow_timing_get->authentik_outpost_flow_timing_get_secondsauthentik_outpost_flow_timing_post->authentik_outpost_flow_timing_post_secondsauthentik_outpost_ldap_requests->authentik_outpost_ldap_request_duration_secondsauthentik_outpost_ldap_requests_rejected->authentik_outpost_ldap_requests_rejected_totalauthentik_outpost_proxy_requests->authentik_outpost_proxy_request_duration_secondsauthentik_outpost_proxy_upstream_time->authentik_outpost_proxy_upstream_response_duration_secondsauthentik_outpost_radius_requests->authentik_outpost_radius_request_duration_secondsauthentik_outpost_radius_requests_rejected->authentik_outpost_radius_requests_rejected_totalauthentik_main_requests->authentik_main_request_duration_seconds
- The shorthand parameter for
--stage,-sfor theak test_emailcommand has been changed to-S
Release notes from github.com/goauthentik/authentik/releases, and the release notes on docs.goauthentik.io, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. authentik publishes one release-notes page per YYYY.M release on docs.goauthentik.io. Its “Breaking changes” section is quoted whole as “Breaking” on the first release of that line (YYYY.M.0; 2022.1 to 2022.8 started at YYYY.M.1), its “Deprecations” section as “Note”, and the opening paragraph of its “Upgrading” section as “Note” unless it only says “This release does not introduce any new requirements”. Fixes in patch releases (“Fixed in …”) are not quoted, and neither are GitHub release notes (lists of merged pull requests). Versions are covered from 2022.1.0. Required stops: the latest patch release of every YYYY.M line on the way, per the upgrade documentation.