Upgrade Path

authentik 2026.2.0 → 2026.5.0

5 versions, 1 with breaking changes, 1 required stop

Required stops

Version by version, oldest first

2026.2.1 – 2026.2.3: no action items (3 versions)

2026.2.4 – 2026.2.6: released after 2026.5.0; not on this route

2026.2.7 2026-09-09

Full release notes for 2026.2.7

2026.5.0 2026-05-22

Breaking

Listening on multiple IPs

For advanced use cases, authentik now supports setting listening settings to a comma-separated list of IPs. With this change, the default IP we listen on changed from 0.0.0.0 to [::] to better match ecosystem standards. Some IPv4-only environments might need to adapt those settings.

PostgreSQL custom connection options are deprecated

The AUTHENTIK_POSTGRESQL__CONN_OPTIONS and its replica equivalent are deprecated and will be removed in the next version. It was never properly used and may cause future breakages. If you're looking for a specific usage, open an issue to discuss alternative solutions.

From docs.goauthentik.io/releases/2026.5#breaking-changes

Full release notes for 2026.5.0

Release notes from github.com/goauthentik/authentik/releases, and the release notes on docs.goauthentik.io, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. authentik publishes one release-notes page per YYYY.M release on docs.goauthentik.io. Its “Breaking changes” section is quoted whole as “Breaking” on the first release of that line (YYYY.M.0; 2022.1 to 2022.8 started at YYYY.M.1), its “Deprecations” section as “Note”, and the opening paragraph of its “Upgrading” section as “Note” unless it only says “This release does not introduce any new requirements”. Fixes in patch releases (“Fixed in …”) are not quoted, and neither are GitHub release notes (lists of merged pull requests). Versions are covered from 2022.1.0. Required stops: the latest patch release of every YYYY.M line on the way, per the upgrade documentation.