Releases: SlashNephy/authentik-operator
Release list
v2026.8.1
The first patch release for authentik 2026.8. It fixes correctness and security issues found by a codebase-wide review, and moves the manager to production defaults.
Fixes
- Re-enqueue a resource only when its deletion timestamp is first set. A failing finalize that wrote its status re-enqueued the resource immediately, bypassing the rate limiter (#59)
- Bound the background delivery of role events by the lifetime of the manager, so the sends no longer block forever once the controller stops reading (#59)
- Tolerate a Proxy Provider without an external host, and accept a
vprefix in the authentik server version (#59) - Adopt a matching unmanaged PolicyBinding whenever a rule has no managed Binding, not only on the reconcile that records the first one. A rule added later created a duplicate Binding for a subject that already had one (#61)
Security
- Watch only the metadata of Secrets. The contents of every Secret in the cluster were held in the cache of the operator; the credentials Secret of a resource is now read from the API server on demand. The required RBAC is unchanged (#60)
- Redact confidential values in an authentik error body before it reaches the condition message and the Event of a resource (#60)
- Pin the builder image to
golang:1.27.1with its manifest-list digest (#62)
Behavior changes
status.outpostUUIDrecords the Outpost a Proxy Provider was added to. Whenoutpostchanges, the Provider joins the new Outpost first and leaves the recorded one afterwards. Outposts the operator never recorded are left untouched, and resources reconciled before this release only record their Outpost on the first reconcile (#61)- Leader election is enabled by default. The chart already passed
--leader-elect, so a chart install is unaffected; a plain manifest needs--leader-elect=falseto opt out (#62) - The manager logs structured JSON. Pass
--zap-develfor the previous console output (#62)
Compatibility
| Operator | authentik |
|---|---|
v2026.8.1 |
2026.8.x |
Each operator release supports exactly one authentik minor version. Upgrade the operator together with authentik.
Installation
Store an API token in a Secret, then install the chart:
kubectl create namespace authentik-operator
kubectl -n authentik-operator create secret generic authentik-operator-token --from-literal=token=<token>
helm repo add authentik-operator https://slashnephy.github.io/authentik-operator
helm install authentik-operator authentik-operator/authentik-operator \
--version 2026.8.1 \
--namespace authentik-operator \
--set clusterName=production \
--set authentik.url=https://auth.example.com \
--set authentik.token.secretName=authentik-operator-token- Container image:
ghcr.io/slashnephy/authentik-operator:2026.8.1(linux/amd64,linux/arm64) - The API token needs the permissions listed in the chart README.
v2026.8.0
The first release of authentik-operator, a Kubernetes operator that manages authentik Applications, Providers, and access rights declaratively through the AuthentikApplication custom resource.
Compatibility
| Operator | authentik |
|---|---|
v2026.8.0 |
2026.8.x |
Each operator release supports exactly one authentik minor version. Upgrade the operator together with authentik.
Installation
Store an API token in a Secret, then install the chart:
kubectl create namespace authentik-operator
kubectl -n authentik-operator create secret generic authentik-operator-token --from-literal=token=<token>
helm repo add authentik-operator https://slashnephy.github.io/authentik-operator
helm install authentik-operator authentik-operator/authentik-operator \
--version 2026.8.0 \
--namespace authentik-operator \
--set clusterName=production \
--set authentik.url=https://auth.example.com \
--set authentik.token.secretName=authentik-operator-token- Container image:
ghcr.io/slashnephy/authentik-operator:2026.8.0(linux/amd64,linux/arm64) - The API token needs the permissions listed in the chart README.
Features
AuthentikApplicationCRD for an Application with a Proxy Provider (proxy, forward auth single, forward auth domain) or an OAuth2/OpenID Provider, and its access rules as PolicyBindings.- Ownership marker: objects created by the operator are marked with an RBAC role per cluster, so objects created in the UI are never modified or deleted without permission.
- Drift repair on every resync (
--resync-interval, 10 minutes by default). - Slug conflicts between CRs are detected cluster-wide and reported as
Conflict. - Adoption of existing objects with
spec.adopt:Never,IfMatch(reports the differences), orForce. - Access rules: unmanaged Bindings are reported, and removed only with
spec.access.prune. - Outpost membership of Proxy Providers is kept in the specified Outpost.
- OAuth2 credentials are exported to a Secret, which stays the source of truth for rotation.
- Deletion follows
spec.deletionPolicy(RetainorDelete) through a finalizer. - Marker cleanup removes markers left by objects deleted in the UI, and re-marks objects when the ownership role is recreated.
- Helm chart with the CRD, RBAC, and connection settings (CA certificate and TLS verification).
The design is described in docs/spec.md.
Pull requests
- Design and foundation: #1, #19, #20, #21, #22, #23, #24, #25, #26
- Controller: #27, #28, #35, #42, #44, #45, #46, #47, #48
- Distribution and tests: #49, #50, #51, #53
- Dependency updates: #29, #30, #31, #32, #33
Full Changelog: https://github.com/SlashNephy/authentik-operator/commits/v2026.8.0