authentik: 2025.12.6 -> 2026.5.3
Changelog: https://docs.goauthentik.io/releases/2026.5
This commit is contained in:
@@ -30,6 +30,11 @@
|
||||
|
||||
- `boot.vesa` has been removed. It was deprecated in 2020 because Xorg now works better with kernel modesetting. If you still need the legacy VESA 800x600 fallback, set `boot.kernelParams = [ "vga=0x317" "nomodeset" ];` directly.
|
||||
|
||||
- `authentik` has been updated to 2026.5.3, which changes the default listen address from `0.0.0.0` to `[::]`.
|
||||
IPv4-only deployments might need to adjust their listen settings.
|
||||
Deployments running the server and worker in the same network namespace must also set at least the worker
|
||||
`AUTHENTIK_LISTEN__HTTP` address so that the server and worker do not bind to the same address.
|
||||
|
||||
- Support for the legacy U‐Boot image format has been removed from the initrd generators, as it is deprecated upstream and no longer used by any platform in Nixpkgs.
|
||||
|
||||
- Rustical migrates from `settings.http.host` and `settings.http.port` to `settings.http.bind` to support UNIX domain sockets as well as TCP sockets in one setting.
|
||||
|
||||
@@ -1,9 +0,0 @@
|
||||
diff --git a/config.yaml b/config.yaml
|
||||
index 2f07ea7..0f90432 100644
|
||||
--- a/config.yaml
|
||||
+++ b/config.yaml
|
||||
@@ -4,3 +4,4 @@ additionalProperties:
|
||||
packageName: api
|
||||
enumClassPrefix: true
|
||||
useOneOfDiscriminatorLookup: true
|
||||
+ disallowAdditionalPropertiesIfNotPresent: false
|
||||
@@ -3,14 +3,19 @@
|
||||
stdenvNoCC,
|
||||
callPackages,
|
||||
cacert,
|
||||
clangStdenv,
|
||||
cmake,
|
||||
fetchFromGitHub,
|
||||
buildGoModule,
|
||||
buildNpmPackage,
|
||||
bash,
|
||||
chromedriver,
|
||||
nodejs_24,
|
||||
python3,
|
||||
python314,
|
||||
makeWrapper,
|
||||
openapi-generator-cli,
|
||||
perl,
|
||||
rustPlatform,
|
||||
go,
|
||||
typescript,
|
||||
makeSetupHook,
|
||||
@@ -20,13 +25,18 @@
|
||||
let
|
||||
nodejs = nodejs_24;
|
||||
|
||||
version = "2025.12.6";
|
||||
version = "2026.5.3";
|
||||
|
||||
cargoPackageFlags = [
|
||||
"--package"
|
||||
"authentik"
|
||||
];
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "goauthentik";
|
||||
repo = "authentik";
|
||||
tag = "version/${version}";
|
||||
hash = "sha256-uIg47z4LaCawF/5ir4mKE6DpDnEpQ8DuObCNaq6TcYk=";
|
||||
hash = "sha256-nmAX8nwZpdDcFAPvC9hAEp0x43RnFtGLUTAm7NcvNZo=";
|
||||
};
|
||||
|
||||
meta = {
|
||||
@@ -46,24 +56,9 @@ let
|
||||
|
||||
client-go = stdenvNoCC.mkDerivation {
|
||||
pname = "authentik-client-go";
|
||||
version = "3.${version}";
|
||||
inherit meta;
|
||||
inherit version src meta;
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "goauthentik";
|
||||
repo = "client-go";
|
||||
tag = "v3.2025.12.4";
|
||||
hash = "sha256-+/CfOE2HkBU+ZddvdXGenB/z8xNFk8cujpZpMXyh3cY=";
|
||||
};
|
||||
|
||||
patches = [
|
||||
./client-go-config.patch
|
||||
];
|
||||
|
||||
postPatch = ''
|
||||
substituteInPlace ./config.yaml \
|
||||
--replace-fail '/local' "$(pwd)"
|
||||
'';
|
||||
sourceRoot = "${src.name}/packages/client-go";
|
||||
|
||||
nativeBuildInputs = [
|
||||
openapi-generator-cli
|
||||
@@ -86,10 +81,9 @@ let
|
||||
installPhase = ''
|
||||
runHook preInstall
|
||||
|
||||
cp go.mod go.sum $out
|
||||
|
||||
cd $out
|
||||
rm -rf test
|
||||
rm -f go.mod go.sum
|
||||
rm -f .travis.yml git_push.sh
|
||||
|
||||
runHook postInstall
|
||||
@@ -101,8 +95,8 @@ let
|
||||
inherit version src meta;
|
||||
|
||||
postPatch = ''
|
||||
substituteInPlace ./scripts/api/ts-config.yaml \
|
||||
--replace-fail '/local' "$(pwd)"
|
||||
substituteInPlace ./packages/client-ts/config.yaml \
|
||||
--replace-fail '/local' "$(pwd)/packages/client-ts"
|
||||
'';
|
||||
|
||||
nativeBuildInputs = [
|
||||
@@ -117,7 +111,7 @@ let
|
||||
openapi-generator-cli generate \
|
||||
-i ./schema.yml -o $out \
|
||||
-g typescript-fetch \
|
||||
-c ./scripts/api/ts-config.yaml \
|
||||
-c ./packages/client-ts/config.yaml \
|
||||
--additional-properties=npmVersion=${version} \
|
||||
--git-repo-id authentik --git-user-id goauthentik
|
||||
|
||||
@@ -128,32 +122,19 @@ let
|
||||
'';
|
||||
};
|
||||
|
||||
# prefetch-npm-deps does not save all dependencies even though the lockfile is fine
|
||||
website-deps = stdenvNoCC.mkDerivation {
|
||||
website-deps = buildNpmPackage {
|
||||
pname = "authentik-website-deps";
|
||||
inherit src version meta;
|
||||
|
||||
sourceRoot = "${src.name}/website";
|
||||
|
||||
outputHash =
|
||||
{
|
||||
"aarch64-linux" = "sha256-EbLneRDCyLLLBOZ2DUDpf2TbZoTL8QMXP4WlAZEzS90=";
|
||||
"x86_64-linux" = "sha256-yDjwN/+lX2i9WYDXq4yWwf9o8nA4342iHDDQH4Jt7eQ=";
|
||||
}
|
||||
.${stdenvNoCC.hostPlatform.system} or (throw "authentik-website-deps: unsupported host platform");
|
||||
|
||||
outputHashMode = "recursive";
|
||||
|
||||
nativeBuildInputs = [
|
||||
nodejs
|
||||
cacert
|
||||
];
|
||||
|
||||
buildPhase = ''
|
||||
npm ci --cache ./cache
|
||||
|
||||
rm -r ./cache node_modules/.package-lock.json
|
||||
'';
|
||||
inherit nodejs;
|
||||
npmDepsHash = "sha256-SkIZF+wQPgoZOGJc0YR8Ot07KCsAdA1985SLQaoibfA=";
|
||||
npmDepsFetcherVersion = 2;
|
||||
makeCacheWritable = true;
|
||||
npmInstallFlags = [ "--legacy-peer-deps" ];
|
||||
npmRebuildFlags = [ "--ignore-scripts" ];
|
||||
dontNpmBuild = true;
|
||||
|
||||
# dependencies of workspace projects are installed into separate node_modules folders with
|
||||
# symlinks between them, so we have to copy all of them
|
||||
@@ -208,8 +189,8 @@ let
|
||||
|
||||
outputHash =
|
||||
{
|
||||
"aarch64-linux" = "sha256-J9wGQe7iMfKznNk3woqi0VNVNA/dE6TGi2f44DOlG1c=";
|
||||
"x86_64-linux" = "sha256-9Q590Rw0mk3q5osxOKGWU7+XtKwkTyA+CLC2LxAA/3g=";
|
||||
"aarch64-linux" = "sha256-41xZEfLul92vJATZqyVnd7Pp++NzLL/u8NeJJPHpXrw=";
|
||||
"x86_64-linux" = "sha256-FpfOl6wNCgXLg86+vbjnYkcOnpaOZBCNxJiFDRT5W3s=";
|
||||
}
|
||||
.${stdenvNoCC.hostPlatform.system} or (throw "authentik-webui-deps: unsupported host platform");
|
||||
outputHashMode = "recursive";
|
||||
@@ -220,6 +201,7 @@ let
|
||||
];
|
||||
|
||||
buildPhase = ''
|
||||
chmod -R +w . ../packages/client-ts
|
||||
npm ci --cache ./cache --ignore-scripts
|
||||
|
||||
rm -r ./cache node_modules/.package-lock.json
|
||||
@@ -295,7 +277,7 @@ let
|
||||
];
|
||||
};
|
||||
|
||||
python = python3.override {
|
||||
python = python314.override {
|
||||
self = python;
|
||||
packageOverrides = final: prev: {
|
||||
# https://github.com/goauthentik/authentik/pull/16324
|
||||
@@ -376,62 +358,6 @@ let
|
||||
];
|
||||
};
|
||||
|
||||
# Running authentik currently requires a custom version.
|
||||
# Look in `pyproject.toml` for changes to the rev in the `[tool.uv.sources]` section.
|
||||
# See https://github.com/goauthentik/authentik/pull/14057 for latest version bump.
|
||||
djangorestframework = final.buildPythonPackage {
|
||||
pname = "djangorestframework";
|
||||
version = "3.16.0";
|
||||
format = "setuptools";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "authentik-community";
|
||||
repo = "django-rest-framework";
|
||||
rev = "896722bab969fabc74a08b827da59409cf9f1a4e";
|
||||
hash = "sha256-YrEDEU3qtw/iyQM3CoB8wYx57zuPNXiJx6ZjrIwnCNU=";
|
||||
};
|
||||
|
||||
propagatedBuildInputs = with final; [
|
||||
django
|
||||
pytz
|
||||
];
|
||||
|
||||
nativeCheckInputs = with final; [
|
||||
pytest-django
|
||||
pytest7CheckHook
|
||||
|
||||
# optional tests
|
||||
coreapi
|
||||
django-guardian
|
||||
inflection
|
||||
pyyaml
|
||||
uritemplate
|
||||
];
|
||||
|
||||
disabledTests = [
|
||||
"test_ignore_validation_for_unchanged_fields"
|
||||
"test_invalid_inputs"
|
||||
"test_shell_code_example_rendering"
|
||||
"test_unique_together_condition"
|
||||
"test_unique_together_with_source"
|
||||
];
|
||||
|
||||
pythonImportsCheck = [ "rest_framework" ];
|
||||
};
|
||||
|
||||
# authentik is currently not compatible with v1.18 and fails with the following error:
|
||||
# > AttributeError: 'Namespace' object has no attribute 'worker_fork_timeout'. Did you mean: 'worker_shutdown_timeout'?
|
||||
dramatiq = prev.dramatiq.overrideAttrs (_: rec {
|
||||
version = "1.17.1";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "Bogdanp";
|
||||
repo = "dramatiq";
|
||||
tag = "v${version}";
|
||||
hash = "sha256-NeUGhG+H6r+JGd2qnJxRUbQ61G7n+3tsuDugTin3iJ4=";
|
||||
};
|
||||
});
|
||||
|
||||
authentik-django = final.buildPythonPackage {
|
||||
pname = "authentik-django";
|
||||
inherit version src meta;
|
||||
@@ -548,7 +474,32 @@ let
|
||||
|
||||
inherit (python.pkgs) authentik-django;
|
||||
|
||||
# Provide a setup-hook to configure the Go vendor directory with up-to-date API bindings.
|
||||
worker = (rustPlatform.buildRustPackage.override { stdenv = clangStdenv; }) {
|
||||
pname = "authentik-worker";
|
||||
inherit version src meta;
|
||||
|
||||
cargoHash = "sha256-KExlNyT9G3R5rnt99beT2pYrWxezMLhGw+Q9T1X2kj4=";
|
||||
|
||||
nativeBuildInputs = [
|
||||
cmake
|
||||
go
|
||||
perl
|
||||
];
|
||||
|
||||
buildInputs = [ python ];
|
||||
|
||||
env = {
|
||||
PYO3_PYTHON = lib.getExe python;
|
||||
RUSTFLAGS = "--cfg tokio_unstable";
|
||||
};
|
||||
|
||||
cargoBuildFlags = cargoPackageFlags;
|
||||
|
||||
# Upstream currently has no Rust tests in this package.
|
||||
doCheck = false;
|
||||
};
|
||||
|
||||
# Provide a setup-hook to configure the Go source tree with up-to-date API bindings.
|
||||
# This is done to avoid the `vendorHash` depending on anything in the `client-go` build (e.g.
|
||||
# openapi-generator-cli version updates changing the produced content) and invalidating the hash.
|
||||
apiGoVendorHook =
|
||||
@@ -559,9 +510,10 @@ let
|
||||
(
|
||||
writeShellScript "authentik-api-go-vendor-hook" ''
|
||||
authentikApiGoVendorHook() {
|
||||
chmod -R +w vendor/goauthentik.io/api
|
||||
rm -rf vendor/goauthentik.io/api/v3
|
||||
cp -r ${client-go} vendor/goauthentik.io/api/v3
|
||||
chmod -R +w packages/client-go
|
||||
rm -rf packages/client-go
|
||||
cp -r ${client-go} packages/client-go
|
||||
chmod -R +w packages/client-go
|
||||
|
||||
echo "Finished authentikApiGoVendorHook"
|
||||
}
|
||||
@@ -593,10 +545,11 @@ let
|
||||
# calculate the vendorHash without other dependencies, so it is only based on the `go.sum` file
|
||||
overrideModAttrs.postPatch = "";
|
||||
|
||||
vendorHash = "sha256-pdQg02f1K4nOhsnadoplQYOhEybqZxn+yDQRN5RNygM=";
|
||||
vendorHash = "sha256-EVDOZ4USaJoIBDB8mM4ZSBfsSc1d/NOm1Qv/hUJ+8f4=";
|
||||
|
||||
postInstall = ''
|
||||
mv $out/bin/server $out/bin/authentik
|
||||
mv $out/bin/server $out/bin/authentik-server
|
||||
ln -s authentik-server $out/bin/authentik
|
||||
'';
|
||||
|
||||
subPackages = [ "cmd/server" ];
|
||||
@@ -612,11 +565,6 @@ stdenvNoCC.mkDerivation {
|
||||
postPatch = ''
|
||||
rm Makefile
|
||||
patchShebangs lifecycle/ak
|
||||
|
||||
# This causes issues in systemd services
|
||||
substituteInPlace lifecycle/ak \
|
||||
--replace-fail 'printf' '>&2 printf' \
|
||||
--replace-fail '>/dev/stderr' ""
|
||||
'';
|
||||
|
||||
installPhase = ''
|
||||
@@ -627,8 +575,9 @@ stdenvNoCC.mkDerivation {
|
||||
wrapProgram $out/bin/ak \
|
||||
--prefix PATH : ${
|
||||
lib.makeBinPath [
|
||||
(python.withPackages (ps: [ ps.authentik-django ]))
|
||||
worker
|
||||
proxy
|
||||
(python.withPackages (ps: [ ps.authentik-django ]))
|
||||
]
|
||||
} \
|
||||
--set TMPDIR /dev/shm \
|
||||
@@ -638,7 +587,7 @@ stdenvNoCC.mkDerivation {
|
||||
'';
|
||||
|
||||
passthru = {
|
||||
inherit proxy apiGoVendorHook;
|
||||
inherit proxy worker apiGoVendorHook;
|
||||
outposts = callPackages ./outposts.nix {
|
||||
inherit (proxy) vendorHash;
|
||||
inherit apiGoVendorHook;
|
||||
|
||||
Reference in New Issue
Block a user