authentik 2025.4.0 → 2025.6.0
4 versions, 1 with breaking changes, 1 required stop
Required stops
- 2025.4.4
Latest 2025.4.x release.
Upgrade sequence: Upgrades must follow the sequence of major releases; do not skip directly from an older major version to the most recent version.
Always upgrade to the latest minor version (
.x) within eachmajor.minorversion before upgrading to the next major version. For example, if you're currently running2025.2.1, upgrade in the following order:- Upgrade to the latest
2025.2.x. - Then to the latest
2025.4.x. - Finally to the latest
2025.6.x.
Outposts: The version of the authentik server and all authentik outposts must match. Ensure that all outposts are upgraded at the same time as the core authentik instance.
Source: https://docs.goauthentik.io/install-config/upgrade/#important-considerations (checked 2026-09-28)
- Upgrade to the latest
Version by version, oldest first
2025.4.1 – 2025.4.2: no action items (2 versions)
2025.4.3: released after 2025.6.0; not on this route
2025.4.4 2025-07-22
Required stop
2025.6.0 2025-06-04
Breaking
- Helm chart dependencies upgrades:
- The PostgreSQL chart has been updated to version 16.7.4. The PostgreSQL image is no longer pinned in authentik's default values and has been upgraded from version 15 to 17. Follow our PostgreSQL upgrade instructions to update to the latest PostgreSQL version.
- The Redis chart has been updated to version 21.1.6. There are no breaking changes and Redis has been upgraded from version 7 to 8.
- Deprecated and frozen
:latestcontainer image tag after 2025.2
Using the :latest tag with container images is not recommended as it can lead to unintentional updates and potentially broken setups. The tag will not be removed, however it will also not be updated past 2025.2. We strongly recommend using a specific version tag for authentik instances' container images, such as :2025.6.
- CSS: We’ve made some improvements to our theming system. If your authentik instance uses custom CSS, you might need to review flow and user interfaces for any visual changes.
Release notes from github.com/goauthentik/authentik/releases, and the release notes on docs.goauthentik.io, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. authentik publishes one release-notes page per YYYY.M release on docs.goauthentik.io. Its “Breaking changes” section is quoted whole as “Breaking” on the first release of that line (YYYY.M.0; 2022.1 to 2022.8 started at YYYY.M.1), its “Deprecations” section as “Note”, and the opening paragraph of its “Upgrading” section as “Note” unless it only says “This release does not introduce any new requirements”. Fixes in patch releases (“Fixed in …”) are not quoted, and neither are GitHub release notes (lists of merged pull requests). Versions are covered from 2022.1.0. Required stops: the latest patch release of every YYYY.M line on the way, per the upgrade documentation.