authentik 2024.6.0 → 2024.8.0
6 versions, 1 with breaking changes, 1 required stop
Required stops
- 2024.6.5
Latest 2024.6.x release.
Upgrade sequence: Upgrades must follow the sequence of major releases; do not skip directly from an older major version to the most recent version.
Always upgrade to the latest minor version (
.x) within eachmajor.minorversion before upgrading to the next major version. For example, if you're currently running2025.2.1, upgrade in the following order:- Upgrade to the latest
2025.2.x. - Then to the latest
2025.4.x. - Finally to the latest
2025.6.x.
Outposts: The version of the authentik server and all authentik outposts must match. Ensure that all outposts are upgraded at the same time as the core authentik instance.
Source: https://docs.goauthentik.io/install-config/upgrade/#important-considerations (checked 2026-09-28)
- Upgrade to the latest
Version by version, oldest first
2024.6.1 – 2024.6.4: no action items (4 versions)
2024.6.5 2024-09-27
Required stop
2024.8.0 2024-09-03
Breaking
Manual action is required
- LDAP property mappings simplification
LDAP property mappings have been reworked to remove Object field. With this release, instead of returning a single user or group attribute for each property mapping, you can now return several of them. Here is an example of what new property mappings look like:
return {
"username": ldap.get("uid"), # list_flatten is automatically applied to top-level attributes
"attributes": {
"phone": list_flatten(ldap.get("phoneNumber")), # but not for attributes!
},
}
This property mapping populates the username and attributes.phone attributes of a user at the same time, reducing the number of mappings that are run and thus improving performance. Additionally, they are more straightforward to read, and this change allowed us to implement property mappings for OAuth and SAML sources as well.
authentik will automatically convert existing property mappings to this new format, by generating some Python code for each of the existing property mappings expressions. Property mappings that are managed by authentik will automatically get updated to the new format.
If you have any custom property mappings, we recommend converting them to this new format.
- OAuth and SAML sources now sync groups by default
OAuth (specifically OpenID and Okta) sources now sync groups by default when a groups claim is available.
SAML sources now sync groups by default when a http://schemas.xmlsoap.org/claims/Group attribute is available in the assertion.
To disable that behavior, create an OAuth/SAML source property mapping with the expression below and assign it as a user property mapping on the source.
return {
"groups": [],
}
- Terraform Resource rename
Several resources in the Terraform provider have been renamed to align with new functionality. This mainly applies to property mapping-related resources. With the authentik version 2024.8.1 of the Terraform provider, both the old and new resources are available, and resources can be moved to the new name using terraform state mv.
These resources have been renamed:
authentik_property_mapping_google_workspaceauthentik_property_mapping_ldapauthentik_property_mapping_microsoft_entraauthentik_property_mapping_racauthentik_property_mapping_radiusauthentik_property_mapping_samlauthentik_property_mapping_scim
Manual action may be required
- Changes to the external user type
Since the introduction of user types with 2023.8, the main difference between internal and external users has mostly been relevant when using the Enterprise version of authentik.
With this release, authentik improves support for B2C use-cases, which external users are intended for. It is now possible to configure a default application. External users not attempting to access a specific application will always be redirected to this default application.
As part of this, external users will no longer have access to the User and Admin interfaces. If you're using the open-source version and you require this workflow, you can change users to be Internal, which will have no side-effects. For Enterprise customers, please reach out to us with any questions.
Bulk changing the user type
In the container, run the command ak change_user_type --all --type internal to change all users to Internal. Instead of using --all you can also pass usernames to the command to only change individual users to internal.
- Changed HTTP healthcheck endpoints status code
For increased compatibility, the /-/health/live/ and /-/health/ready/ endpoints return 200 HTTP Status codes for successful checks. Previously these endpoints returned 204, which means in most cases no changes are required.
Release notes from github.com/goauthentik/authentik/releases, and the release notes on docs.goauthentik.io, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. authentik publishes one release-notes page per YYYY.M release on docs.goauthentik.io. Its “Breaking changes” section is quoted whole as “Breaking” on the first release of that line (YYYY.M.0; 2022.1 to 2022.8 started at YYYY.M.1), its “Deprecations” section as “Note”, and the opening paragraph of its “Upgrading” section as “Note” unless it only says “This release does not introduce any new requirements”. Fixes in patch releases (“Fixed in …”) are not quoted, and neither are GitHub release notes (lists of merged pull requests). Versions are covered from 2022.1.0. Required stops: the latest patch release of every YYYY.M line on the way, per the upgrade documentation.