Upgrade Path

authentik 2025.2.0 → 2025.4.0

5 versions, 1 with breaking changes, 1 required stop

Required stops

Version by version, oldest first

2025.2.1 – 2025.2.3: no action items (3 versions)

2025.2.4 2025-04-08

Full release notes for 2025.2.4

2025.4.0 2025-04-30

Breaking

  • Reputation score limit: The default values for the new upper and lower limits on Reputation score are -5 and 5. This could break custom policies that rely on the reputation scores decreasing or increasing beyond these limits. You can set your custom limits under System > Settings.
  • Deprecated and frozen :latest container image tag after 2025.2

Using the :latest tag with container images is not recommended as it can lead to unintentional updates and potentially broken setups.

The tag will not be removed, however it will also not be updated past 2025.2.

We strongly recommend using a specific version tag for authentik instances' container images, such as :2025.4.

For this release:

  • The Redis chart will be upgraded to the latest version. As the image is not pinned, it will also get upgraded.
  • The PostgreSQL chart will be upgraded to the latest version, but the image will remain pinned to 15.8.0-debian-12-r18.

For the next release:

  • The Redis chart will be upgraded to the latest version again.
  • The PostgreSQL chart will be upgraded to the latest version again, and the image will no longer be pinned, which will bring it to PostgreSQL major version 17. This will require following PostgreSQL major upgrade steps, for which we provide documentation.

For subsequent releases:

  • The Redis chart will be upgraded to the latest version.
  • The PostgreSQL chart will be upgraded to the latest version, with major upgrades being called out in authentik release notes.

We encourage users to pin their PostgreSQL image version.

Manual action might be required

Sessions are now stored in the database

Previously, sessions were stored by default in the cache. Now, they are stored in the database. This allows for numerous other performance improvements. On high traffic instances, requests to old instances after the upgrade has started will fail to authenticate.

From docs.goauthentik.io/releases/2025.4#breaking-changes

Full release notes for 2025.4.0

Release notes from github.com/goauthentik/authentik/releases, and the release notes on docs.goauthentik.io, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. authentik publishes one release-notes page per YYYY.M release on docs.goauthentik.io. Its “Breaking changes” section is quoted whole as “Breaking” on the first release of that line (YYYY.M.0; 2022.1 to 2022.8 started at YYYY.M.1), its “Deprecations” section as “Note”, and the opening paragraph of its “Upgrading” section as “Note” unless it only says “This release does not introduce any new requirements”. Fixes in patch releases (“Fixed in …”) are not quoted, and neither are GitHub release notes (lists of merged pull requests). Versions are covered from 2022.1.0. Required stops: the latest patch release of every YYYY.M line on the way, per the upgrade documentation.