authentik 2025.6.0 → 2025.8.0
5 versions, 1 with breaking changes, 1 required stop
Required stops
- 2025.6.4
Latest 2025.6.x release.
Upgrade sequence: Upgrades must follow the sequence of major releases; do not skip directly from an older major version to the most recent version.
Always upgrade to the latest minor version (
.x) within eachmajor.minorversion before upgrading to the next major version. For example, if you're currently running2025.2.1, upgrade in the following order:- Upgrade to the latest
2025.2.x. - Then to the latest
2025.4.x. - Finally to the latest
2025.6.x.
Outposts: The version of the authentik server and all authentik outposts must match. Ensure that all outposts are upgraded at the same time as the core authentik instance.
Source: https://docs.goauthentik.io/install-config/upgrade/#important-considerations (checked 2026-09-28)
- Upgrade to the latest
Version by version, oldest first
2025.6.1 – 2025.6.3: no action items (3 versions)
2025.6.4 2025-07-22
Required stop
2025.8.0 2025-08-20
Breaking
Worker and background tasks revamped
The authentik worker and background tasks have been reworked for better observability of tasks, and better configurability of scheduled tasks.
This rework also allowed us to not depend on Redis for background tasks. However, we replaced the engine used to manage these tasks, and as such, don't have a seamless migration path.
For instances with a high level of traffic, such as many users logging in, many sign up requests, etc., some tasks may be lost during the upgrade. Instances with low traffic can upgrade during periods of downtime.
To prevent losing tasks during the upgrade, instances with a high level of traffic should follow these instructions:
- Start by upgrading the authentik server.
- Inspect the old version task queue to check that all tasks are done. Execute the following commands in the not-yet-upgraded worker container:
docker-compose
docker compose exec worker bash -c 'DJANGO_SETTINGS_MODULE=authentik.root.settings celery -A authentik.root.celery inspect active'
docker compose exec worker bash -c 'DJANGO_SETTINGS_MODULE=authentik.root.settings celery -A authentik.root.celery inspect scheduled'
docker compose exec worker bash -c 'DJANGO_SETTINGS_MODULE=authentik.root.settings celery -A authentik.root.celery inspect reserved'
Kubernetes
kubectl exec -it deployment/authentik-worker -c worker -- bash -c 'DJANGO_SETTINGS_MODULE=authentik.root.settings celery -A authentik.root.celery inspect active'
kubectl exec -it deployment/authentik-worker -c worker -- bash -c 'DJANGO_SETTINGS_MODULE=authentik.root.settings celery -A authentik.root.celery inspect scheduled'
kubectl exec -it deployment/authentik-worker -c worker -- bash -c 'DJANGO_SETTINGS_MODULE=authentik.root.settings celery -A authentik.root.celery inspect reserved'
- Wait for all these commands to report the old task queues as "empty"
- Finish by upgrading the worker
Docker image deprecation notice for beryju/authentik and beryju/authentik-*
The beryju/authentik and beryju/authentik-* Docker images are no longer being updated. Users are now encouraged to use the following images:
- Server image:
ghcr.io/goauthentik/serverorauthentik/server
- Outpost images:
ghcr.io/goauthentik/ldaporauthentik/ldapghcr.io/goauthentik/proxyorauthentik/proxyghcr.io/goauthentik/racorauthentik/racghcr.io/goauthentik/radiusorauthentik/radius
We recommend updating your Docker Compose files or other container configurations to use these new image paths.
Database encoding requirements
The PostgreSQL database must now use the UTF8 encoding. This is the default encoding that PostgreSQL uses. Unless you have specifically chosen a different encoding when creating the authentik database, no change is needed.
Renamed/removed settings
The AUTHENTIK_WORKER__CONCURRENCY setting has been renamed AUTHENTIK_WORKER__THREADS. The old setting is still available as an alias and will be removed in a future release.
The following settings have been removed and no longer have an effect:
AUTHENTIK_BROKER__URLAUTHENTIK_BROKER__TRANSPORT_OPTIONSAUTHENTIK_RESULT_BACKEND__URL
Renamed/removed metrics
The authentik_admin_workers metric has been renamed authentik_tasks_workers.
The following metrics have been removed:
authentik_system_tasksauthentik_system_tasks_time_secondsauthentik_system_tasks_status
Instead, the following metrics are now available:
authentik_tasks_totalauthentik_tasks_errors_totalauthentik_tasks_retries_totalauthentik_tasks_rejected_totalauthentik_tasks_in_progressauthentik_tasks_delayed_in_progressauthentik_tasks_duration_milliseconds
Prometheus metrics
The tasks metrics are no longer exposed by the server, but by the worker. For Helm chart users, add the following values to enable a ServiceMonitor to scrape those metrics:
worker:
metrics:
enabled: true
serviceMonitor:
enabled: true
Helm chart changes
Due to Bitnami upcoming changes to availability of their container images, the Helm chart default values have been updated to instead use docker.io/library/postgres and docker.io/library/redis. If you are setting custom values for either PostgreSQL or Redis, please review the associated Helm chart changes to update your values.
Redis has also been updated from 8.0 to 8.2.
From this point on, we recommend using the bundled PostgreSQL dependency for demonstration and test purposes only. See our installation documentation for alternatives to run PostgreSQL in a production environment.
Release notes from github.com/goauthentik/authentik/releases, and the release notes on docs.goauthentik.io, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. authentik publishes one release-notes page per YYYY.M release on docs.goauthentik.io. Its “Breaking changes” section is quoted whole as “Breaking” on the first release of that line (YYYY.M.0; 2022.1 to 2022.8 started at YYYY.M.1), its “Deprecations” section as “Note”, and the opening paragraph of its “Upgrading” section as “Note” unless it only says “This release does not introduce any new requirements”. Fixes in patch releases (“Fixed in …”) are not quoted, and neither are GitHub release notes (lists of merged pull requests). Versions are covered from 2022.1.0. Required stops: the latest patch release of every YYYY.M line on the way, per the upgrade documentation.