Upgrade Path

authentik 2025.6.0 → 2025.8.0

5 versions, 1 with breaking changes, 1 required stop

Required stops

Version by version, oldest first

2025.6.1 – 2025.6.3: no action items (3 versions)

2025.6.4 2025-07-22

Full release notes for 2025.6.4

2025.8.0 2025-08-20

Breaking

Worker and background tasks revamped

The authentik worker and background tasks have been reworked for better observability of tasks, and better configurability of scheduled tasks.

This rework also allowed us to not depend on Redis for background tasks. However, we replaced the engine used to manage these tasks, and as such, don't have a seamless migration path.

For instances with a high level of traffic, such as many users logging in, many sign up requests, etc., some tasks may be lost during the upgrade. Instances with low traffic can upgrade during periods of downtime.

To prevent losing tasks during the upgrade, instances with a high level of traffic should follow these instructions:

  1. Start by upgrading the authentik server.
  2. Inspect the old version task queue to check that all tasks are done. Execute the following commands in the not-yet-upgraded worker container:

docker-compose

docker compose exec worker bash -c 'DJANGO_SETTINGS_MODULE=authentik.root.settings celery -A authentik.root.celery inspect active'
docker compose exec worker bash -c 'DJANGO_SETTINGS_MODULE=authentik.root.settings celery -A authentik.root.celery inspect scheduled'
docker compose exec worker bash -c 'DJANGO_SETTINGS_MODULE=authentik.root.settings celery -A authentik.root.celery inspect reserved'

Kubernetes

kubectl exec -it deployment/authentik-worker -c worker -- bash -c 'DJANGO_SETTINGS_MODULE=authentik.root.settings celery -A authentik.root.celery inspect active'
kubectl exec -it deployment/authentik-worker -c worker -- bash -c 'DJANGO_SETTINGS_MODULE=authentik.root.settings celery -A authentik.root.celery inspect scheduled'
kubectl exec -it deployment/authentik-worker -c worker -- bash -c 'DJANGO_SETTINGS_MODULE=authentik.root.settings celery -A authentik.root.celery inspect reserved'
  1. Wait for all these commands to report the old task queues as "empty"
  2. Finish by upgrading the worker

Docker image deprecation notice for beryju/authentik and beryju/authentik-*

The beryju/authentik and beryju/authentik-* Docker images are no longer being updated. Users are now encouraged to use the following images:

  • Server image:
  • ghcr.io/goauthentik/server or authentik/server
  • Outpost images:
  • ghcr.io/goauthentik/ldap or authentik/ldap
  • ghcr.io/goauthentik/proxy or authentik/proxy
  • ghcr.io/goauthentik/rac or authentik/rac
  • ghcr.io/goauthentik/radius or authentik/radius

We recommend updating your Docker Compose files or other container configurations to use these new image paths.

Database encoding requirements

The PostgreSQL database must now use the UTF8 encoding. This is the default encoding that PostgreSQL uses. Unless you have specifically chosen a different encoding when creating the authentik database, no change is needed.

Renamed/removed settings

The AUTHENTIK_WORKER__CONCURRENCY setting has been renamed AUTHENTIK_WORKER__THREADS. The old setting is still available as an alias and will be removed in a future release.

The following settings have been removed and no longer have an effect:

  • AUTHENTIK_BROKER__URL
  • AUTHENTIK_BROKER__TRANSPORT_OPTIONS
  • AUTHENTIK_RESULT_BACKEND__URL

Renamed/removed metrics

The authentik_admin_workers metric has been renamed authentik_tasks_workers.

The following metrics have been removed:

  • authentik_system_tasks
  • authentik_system_tasks_time_seconds
  • authentik_system_tasks_status

Instead, the following metrics are now available:

  • authentik_tasks_total
  • authentik_tasks_errors_total
  • authentik_tasks_retries_total
  • authentik_tasks_rejected_total
  • authentik_tasks_in_progress
  • authentik_tasks_delayed_in_progress
  • authentik_tasks_duration_milliseconds

Prometheus metrics

The tasks metrics are no longer exposed by the server, but by the worker. For Helm chart users, add the following values to enable a ServiceMonitor to scrape those metrics:

worker:
    metrics:
        enabled: true
        serviceMonitor:
            enabled: true

Helm chart changes

Due to Bitnami upcoming changes to availability of their container images, the Helm chart default values have been updated to instead use docker.io/library/postgres and docker.io/library/redis. If you are setting custom values for either PostgreSQL or Redis, please review the associated Helm chart changes to update your values.

Redis has also been updated from 8.0 to 8.2.

From this point on, we recommend using the bundled PostgreSQL dependency for demonstration and test purposes only. See our installation documentation for alternatives to run PostgreSQL in a production environment.

From docs.goauthentik.io/releases/2025.8#breaking-changes

Full release notes for 2025.8.0

Release notes from github.com/goauthentik/authentik/releases, and the release notes on docs.goauthentik.io, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. authentik publishes one release-notes page per YYYY.M release on docs.goauthentik.io. Its “Breaking changes” section is quoted whole as “Breaking” on the first release of that line (YYYY.M.0; 2022.1 to 2022.8 started at YYYY.M.1), its “Deprecations” section as “Note”, and the opening paragraph of its “Upgrading” section as “Note” unless it only says “This release does not introduce any new requirements”. Fixes in patch releases (“Fixed in …”) are not quoted, and neither are GitHub release notes (lists of merged pull requests). Versions are covered from 2022.1.0. Required stops: the latest patch release of every YYYY.M line on the way, per the upgrade documentation.