v2.5.0 #1765
0xJacky
announced in
Announcements
v2.5.0
#1765
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Important
If an installation ever ran NGINX UI 2.3.6 or earlier, or restored a backup from such an installation, upgrading alone does not invalidate credentials that may already have been exposed. Upgrade every instance to v2.5.0 first. In a cluster, confirm that each node relationship shows
Paired signaturebefore rotating the shared secrets. Then:[node] Secret(NGINX_UI_NODE_SECRET) on every instance with a new, unique random value and restart the instance.[app] JwtSecret(NGINX_UI_APP_JWT_SECRET) and restart NGINX UI to invalidate previously issued JWTs.Do not manually replace
Crypto.Secret: it protects persisted encrypted data and requires a supported migration. Backup archives use one-time encryption material; rotate the credentials contained in any exposed backup instead.Features
Bug Fixes
Contributors
@0xJacky
@chrstphe
@renovate
@sdjnmxd
This discussion was created from the release v2.5.0.
All reactions