Skip to content

Releases: SlashNephy/authentik-operator

v2026.8.1

Choose a tag to compare

@SlashNephy SlashNephy released this 16 Sep 04:34
39dfa18

The first patch release for authentik 2026.8. It fixes correctness and security issues found by a codebase-wide review, and moves the manager to production defaults.

Fixes

  • Re-enqueue a resource only when its deletion timestamp is first set. A failing finalize that wrote its status re-enqueued the resource immediately, bypassing the rate limiter (#59)
  • Bound the background delivery of role events by the lifetime of the manager, so the sends no longer block forever once the controller stops reading (#59)
  • Tolerate a Proxy Provider without an external host, and accept a v prefix in the authentik server version (#59)
  • Adopt a matching unmanaged PolicyBinding whenever a rule has no managed Binding, not only on the reconcile that records the first one. A rule added later created a duplicate Binding for a subject that already had one (#61)

Security

  • Watch only the metadata of Secrets. The contents of every Secret in the cluster were held in the cache of the operator; the credentials Secret of a resource is now read from the API server on demand. The required RBAC is unchanged (#60)
  • Redact confidential values in an authentik error body before it reaches the condition message and the Event of a resource (#60)
  • Pin the builder image to golang:1.27.1 with its manifest-list digest (#62)

Behavior changes

  • status.outpostUUID records the Outpost a Proxy Provider was added to. When outpost changes, the Provider joins the new Outpost first and leaves the recorded one afterwards. Outposts the operator never recorded are left untouched, and resources reconciled before this release only record their Outpost on the first reconcile (#61)
  • Leader election is enabled by default. The chart already passed --leader-elect, so a chart install is unaffected; a plain manifest needs --leader-elect=false to opt out (#62)
  • The manager logs structured JSON. Pass --zap-devel for the previous console output (#62)

Compatibility

Operator authentik
v2026.8.1 2026.8.x

Each operator release supports exactly one authentik minor version. Upgrade the operator together with authentik.

Installation

Store an API token in a Secret, then install the chart:

kubectl create namespace authentik-operator
kubectl -n authentik-operator create secret generic authentik-operator-token --from-literal=token=<token>
helm repo add authentik-operator https://slashnephy.github.io/authentik-operator
helm install authentik-operator authentik-operator/authentik-operator \
  --version 2026.8.1 \
  --namespace authentik-operator \
  --set clusterName=production \
  --set authentik.url=https://auth.example.com \
  --set authentik.token.secretName=authentik-operator-token
  • Container image: ghcr.io/slashnephy/authentik-operator:2026.8.1 (linux/amd64, linux/arm64)
  • The API token needs the permissions listed in the chart README.

v2026.8.0

Choose a tag to compare

@SlashNephy SlashNephy released this 15 Sep 15:38
22707ca

The first release of authentik-operator, a Kubernetes operator that manages authentik Applications, Providers, and access rights declaratively through the AuthentikApplication custom resource.

Compatibility

Operator authentik
v2026.8.0 2026.8.x

Each operator release supports exactly one authentik minor version. Upgrade the operator together with authentik.

Installation

Store an API token in a Secret, then install the chart:

kubectl create namespace authentik-operator
kubectl -n authentik-operator create secret generic authentik-operator-token --from-literal=token=<token>
helm repo add authentik-operator https://slashnephy.github.io/authentik-operator
helm install authentik-operator authentik-operator/authentik-operator \
  --version 2026.8.0 \
  --namespace authentik-operator \
  --set clusterName=production \
  --set authentik.url=https://auth.example.com \
  --set authentik.token.secretName=authentik-operator-token
  • Container image: ghcr.io/slashnephy/authentik-operator:2026.8.0 (linux/amd64, linux/arm64)
  • The API token needs the permissions listed in the chart README.

Features

  • AuthentikApplication CRD for an Application with a Proxy Provider (proxy, forward auth single, forward auth domain) or an OAuth2/OpenID Provider, and its access rules as PolicyBindings.
  • Ownership marker: objects created by the operator are marked with an RBAC role per cluster, so objects created in the UI are never modified or deleted without permission.
  • Drift repair on every resync (--resync-interval, 10 minutes by default).
  • Slug conflicts between CRs are detected cluster-wide and reported as Conflict.
  • Adoption of existing objects with spec.adopt: Never, IfMatch (reports the differences), or Force.
  • Access rules: unmanaged Bindings are reported, and removed only with spec.access.prune.
  • Outpost membership of Proxy Providers is kept in the specified Outpost.
  • OAuth2 credentials are exported to a Secret, which stays the source of truth for rotation.
  • Deletion follows spec.deletionPolicy (Retain or Delete) through a finalizer.
  • Marker cleanup removes markers left by objects deleted in the UI, and re-marks objects when the ownership role is recreated.
  • Helm chart with the CRD, RBAC, and connection settings (CA certificate and TLS verification).

The design is described in docs/spec.md.

Pull requests

Full Changelog: https://github.com/SlashNephy/authentik-operator/commits/v2026.8.0