Upgrade Path

authentik 2025.10.0 → 2025.12.0

5 versions, 1 with breaking changes, 1 required stop

Required stops

Version by version, oldest first

2025.10.1 – 2025.10.3: no action items (3 versions)

2025.10.4 2026-02-12

Full release notes for 2025.10.4

2025.12.0 2026-01-13

Breaking

RBAC

As a first step to overhaul authentik's access control system, much of how groups and roles work internally is altered in this release. We recommend you check any custom code (e.g. expression policies, property mappings) that deals with group/role memberships or access control.

Group name uniqueness

Warning

Make sure your group names are unique before starting the upgrade.

From 2024.6, authentik enforced group name uniqueness through the API. However, groups created earlier or groups created by non-API mechanisms (e.g. a sync from a Source) may have left groups with duplicate names in your system. With 2025.12, group name uniqueness will now be enforced on the database-level.

We played with automatically renaming duplicates, but ultimately found it too confusing for admins. Instead, we made the migration fail loudly in case offending groups exist and now require manual renaming.

Permission inheritance

Groups already inherit is_superuser from their ancestor groups. With 2025.12, groups will also inherit all permissions from their ancestor groups.

Group hierarchy

Groups can now have multiple parent groups. Specifically, the Group.parent field (which was a ForeignKey) is now migrated to Group.parents (which is a ManyToManyField).

User permissions

All permissions now must be attached to a role. The direct relationships between the User and Permission models still exist (User.user_permissions and User.userobjectpermission_set), but they are not used and will be removed in a future release.

Storage improvements

File storage has been reworked to unify media file configuration (icons, branding options), and allow future uses of file storage including CSV Data Exports.

Files stored by authentik are now served from the /files prefix, and not from /media anymore. Any custom reverse proxy configuration handling those paths will need to be updated.

Storage mount changes

If local storage is used, authentik now expects a mount at /data for file storage. The existing /media mount must be moved to /data/media.

For Docker Compose users, the migration is as follows:

# Shut down authentik
docker compose down
# Create the new storage folder
mkdir -p ./data
# Move the old media storage to the new location
mv ./media ./data/media
# Download the new Docker Compose with the updated paths and start authentik. See below for details.

Storage configuration changes

New storage configuration options are available. See the storage settings reference for details.

From docs.goauthentik.io/releases/2025.12#breaking-changes

Full release notes for 2025.12.0

Release notes from github.com/goauthentik/authentik/releases, and the release notes on docs.goauthentik.io, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. authentik publishes one release-notes page per YYYY.M release on docs.goauthentik.io. Its “Breaking changes” section is quoted whole as “Breaking” on the first release of that line (YYYY.M.0; 2022.1 to 2022.8 started at YYYY.M.1), its “Deprecations” section as “Note”, and the opening paragraph of its “Upgrading” section as “Note” unless it only says “This release does not introduce any new requirements”. Fixes in patch releases (“Fixed in …”) are not quoted, and neither are GitHub release notes (lists of merged pull requests). Versions are covered from 2022.1.0. Required stops: the latest patch release of every YYYY.M line on the way, per the upgrade documentation.