Upgrade Path

authentik 2023.10.0 → 2024.2.0

8 versions, 1 with breaking changes, 1 required stop

Required stops

Version by version, oldest first

2023.10.1 – 2023.10.6: no action items (6 versions)

2023.10.7 2024-01-29

Full release notes for 2023.10.7

2024.2.0 2024-02-21

Breaking

Manual action is required

  • Tenants have been renamed to brands

Tenants, which were previously used to change branding configuration, default flows, and several other settings, have been renamed to brands. The term "Brands" more accurately reflects their usage for configuring branding, logos, colors, and overall login flow behavior.

Existing tenant objects will automatically be renamed to brand objects. The API endpoints associated with brands have also been renamed.

Blueprints using authentik_tenants.tenant will need to be changed to use authentik_brands.brand.

For more information, refer to the documentation for brands.

Also, the event retention settings configured in brands (previously tenants, see above) have been removed and are now a system setting, managed in the Admin interface or via the API (see below).

There is no built-in migration path for this change. If you set something other than the default (days=365), you will need to update the setting in the admin interface.

  • Helm chart breaking changes

The Helm Chart has a number of breaking changes. Find out more in the chart release notes.

Manual action may be required

  • Required offline_access scope for Refresh tokens

The OAuth2 provider ships with a new default scope called offline_access, which must be requested by applications that need a refresh token. Previously, authentik would always issue a refresh token for the Authorization code and Device code OAuth grants.

Applications that require a refresh token will need their configuration to be updated to include the offline_access scope mapping.

  • Database requirement changes

authentik now uses PostgreSQL schemas other than public.

If you have a custom PostgreSQL deployment, please ensure that the authentik user is allowed to create schemas. Usually, if the authentik user is owner of the database, it already can.

  • Redis and cache configuration options have been improved

Thank you @PKizzle for this contribution!

Cache settings have been moved from the redis top-level config key to their own cache top-level config key.

Settings have also been added to configure the Redis instance/database used for tasks and websockets separately from cache. See here.

Typically, no changes to the configuration are required.

  • Configuration options migrated to the Admin interface

The following config options have been moved from the config file and can now be set using the Admin interface (under System -> Settings) or the API:

  • AUTHENTIK_AVATARS
  • AUTHENTIK_DEFAULT_USER_CHANGE_NAME
  • AUTHENTIK_DEFAULT_USER_CHANGE_EMAIL
  • AUTHENTIK_DEFAULT_USER_CHANGE_USERNAME
  • AUTHENTIK_GDPR_COMPLIANCE
  • AUTHENTIK_IMPERSONATION
  • AUTHENTIK_FOOTER_LINKS
  • AUTHENTIK_REPUTATION__EXPIRY

When upgrading to 2024.2, the currently configured options will be automatically migrated to the database, and can be removed from the .env or helm values file afterwards.

  • Icons are now in a public/ subfolder

If your media folder is /media, icons are now stored in /media/public. authentik will automatically migrate the icons upon upgrading.

Note that even though that folder is named public, the files stored here are not automatically public. This is due to the naming of the default PostgreSQL schema.

  • User sessions will be invalidated after this upgrade.

As such, users will need to log back in. Immediately after the upgrade completes, users are logged out automatically and are then prompted to log in again. This only occurs once.

  • Removal of deprecated metrics

These metrics were renamed because they did not adhere to Prometheus best practices. The old metrics were kept for backwards compatibility and have now been removed.

  • authentik_outpost_flow_timing_get -> authentik_outpost_flow_timing_get_seconds
  • authentik_outpost_flow_timing_post -> authentik_outpost_flow_timing_post_seconds
  • authentik_outpost_ldap_requests -> authentik_outpost_ldap_request_duration_seconds
  • authentik_outpost_ldap_requests_rejected -> authentik_outpost_ldap_requests_rejected_total
  • authentik_outpost_proxy_requests -> authentik_outpost_proxy_request_duration_seconds
  • authentik_outpost_proxy_upstream_time -> authentik_outpost_proxy_upstream_response_duration_seconds
  • authentik_outpost_radius_requests -> authentik_outpost_radius_request_duration_seconds
  • authentik_outpost_radius_requests_rejected -> authentik_outpost_radius_requests_rejected_total
  • authentik_main_requests -> authentik_main_request_duration_seconds
  • The shorthand parameter for --stage, -s for the ak test_email command has been changed to -S

From docs.goauthentik.io/releases/2024.2#breaking-changes

Full release notes for 2024.2.0

Release notes from github.com/goauthentik/authentik/releases, and the release notes on docs.goauthentik.io, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. authentik publishes one release-notes page per YYYY.M release on docs.goauthentik.io. Its “Breaking changes” section is quoted whole as “Breaking” on the first release of that line (YYYY.M.0; 2022.1 to 2022.8 started at YYYY.M.1), its “Deprecations” section as “Note”, and the opening paragraph of its “Upgrading” section as “Note” unless it only says “This release does not introduce any new requirements”. Fixes in patch releases (“Fixed in …”) are not quoted, and neither are GitHub release notes (lists of merged pull requests). Versions are covered from 2022.1.0. Required stops: the latest patch release of every YYYY.M line on the way, per the upgrade documentation.