Upgrade Path

authentik 2024.6.0 → 2024.8.0

6 versions, 1 with breaking changes, 1 required stop

Required stops

Version by version, oldest first

2024.6.1 – 2024.6.4: no action items (4 versions)

2024.6.5 2024-09-27

Full release notes for 2024.6.5

2024.8.0 2024-09-03

Breaking

Manual action is required

  • LDAP property mappings simplification

LDAP property mappings have been reworked to remove Object field. With this release, instead of returning a single user or group attribute for each property mapping, you can now return several of them. Here is an example of what new property mappings look like:

    return {
        "username": ldap.get("uid"), # list_flatten is automatically applied to top-level attributes
        "attributes": {
            "phone": list_flatten(ldap.get("phoneNumber")), # but not for attributes!
        },
    }

This property mapping populates the username and attributes.phone attributes of a user at the same time, reducing the number of mappings that are run and thus improving performance. Additionally, they are more straightforward to read, and this change allowed us to implement property mappings for OAuth and SAML sources as well.

authentik will automatically convert existing property mappings to this new format, by generating some Python code for each of the existing property mappings expressions. Property mappings that are managed by authentik will automatically get updated to the new format.

If you have any custom property mappings, we recommend converting them to this new format.

  • OAuth and SAML sources now sync groups by default

OAuth (specifically OpenID and Okta) sources now sync groups by default when a groups claim is available.

SAML sources now sync groups by default when a http://schemas.xmlsoap.org/claims/Group attribute is available in the assertion.

To disable that behavior, create an OAuth/SAML source property mapping with the expression below and assign it as a user property mapping on the source.

    return {
        "groups": [],
    }
  • Terraform Resource rename

Several resources in the Terraform provider have been renamed to align with new functionality. This mainly applies to property mapping-related resources. With the authentik version 2024.8.1 of the Terraform provider, both the old and new resources are available, and resources can be moved to the new name using terraform state mv.

These resources have been renamed:

  • authentik_property_mapping_google_workspace
  • authentik_property_mapping_ldap
  • authentik_property_mapping_microsoft_entra
  • authentik_property_mapping_rac
  • authentik_property_mapping_radius
  • authentik_property_mapping_saml
  • authentik_property_mapping_scim

Manual action may be required

  • Changes to the external user type

Since the introduction of user types with 2023.8, the main difference between internal and external users has mostly been relevant when using the Enterprise version of authentik.

With this release, authentik improves support for B2C use-cases, which external users are intended for. It is now possible to configure a default application. External users not attempting to access a specific application will always be redirected to this default application.

As part of this, external users will no longer have access to the User and Admin interfaces. If you're using the open-source version and you require this workflow, you can change users to be Internal, which will have no side-effects. For Enterprise customers, please reach out to us with any questions.

Bulk changing the user type

In the container, run the command ak change_user_type --all --type internal to change all users to Internal. Instead of using --all you can also pass usernames to the command to only change individual users to internal.

  • Changed HTTP healthcheck endpoints status code

For increased compatibility, the /-/health/live/ and /-/health/ready/ endpoints return 200 HTTP Status codes for successful checks. Previously these endpoints returned 204, which means in most cases no changes are required.

From docs.goauthentik.io/releases/2024.8#breaking-changes

Full release notes for 2024.8.0

Release notes from github.com/goauthentik/authentik/releases, and the release notes on docs.goauthentik.io, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. authentik publishes one release-notes page per YYYY.M release on docs.goauthentik.io. Its “Breaking changes” section is quoted whole as “Breaking” on the first release of that line (YYYY.M.0; 2022.1 to 2022.8 started at YYYY.M.1), its “Deprecations” section as “Note”, and the opening paragraph of its “Upgrading” section as “Note” unless it only says “This release does not introduce any new requirements”. Fixes in patch releases (“Fixed in …”) are not quoted, and neither are GitHub release notes (lists of merged pull requests). Versions are covered from 2022.1.0. Required stops: the latest patch release of every YYYY.M line on the way, per the upgrade documentation.