← Back to all sparks
A

authentik

INFRA · APIS
Velocity5.0

Open-source identity provider and single sign-on platform

Two supported branches, every release a bot-driven cherry-pick — authentik is in pure maintenance here

identity-providerssomaintenance-branchesbackportsscimcontainer-hardening
Current state
All six releases in this window are patches across two maintained branches, 2026.5.x and 2026.2.x, and nearly every commit in them is a cherry-pick bot backporting a fix from main. The content is fixes and documentation rather than capability: reverting locale-driven flow re-requests in the flow executor, handling an exception in connector controller sync setup, fixing outgoing sync discovery running once per page, migrating OpenID conformance tests to upstream images, and additional SCIM provider documentation. The one change with an operational edge is 2026.5.6 dropping curl and runit from the container image.
Where it's heading
The release pattern says more than the contents: two branches maintained in parallel with the same fixes landing on each — 2026.2.6 and 2026.5.5 shipped the same day carrying the same conformance-test migration — which is the shape of a project supporting long-lived deployments rather than pushing users forward. Feature work is happening on main and is not visible in this feed; what reaches these branches is the fix subset. Removing curl and runit from the image continues a slow trimming of what ships inside the container.
Prediction
The visible pattern supports only more of the same: alternating 2026.5.x and 2026.2.x patches assembled from cherry-picks, until a new feature branch is cut. Nothing in these entries indicates what that branch will contain.

Recent moves

  1. 9d ago

    2026.5.6 drops curl and runit from the container image

    A patch on the 2026.5 branch that reverts locale-driven flow re-requests from the flow executor and drops curl and runit from the container image. The container change is the one item here with a real operational effect, trimming what ships inside the image for anyone building on it.

    View source ↗
  2. 16d ago

    2026.5.5 backport patch: connector sync and conformance tests

    Cherry-picked fixes onto 2026.5, covering an exception in connector controller sync setup and migration of OpenID conformance tests to upstream images. Shipped the same day as the equivalent 2026.2 patch.

    View source ↗
  3. 16d ago

    2026.2.6 backport patch: outgoing sync discovery fix

    The 2026.2 branch receives the same conformance-test migration as 2026.5.5 plus a fix for outgoing sync discovery running for each page. The clearest illustration of the two branches being kept in step.

    View source ↗
  4. 24d ago

    2026.5.4 backport patch: integration docs and dependency bumps

    Mostly documentation and dependency bumps backported to 2026.5 — DokuWiki logout URLs, additional SCIM provider docs. No functional change for existing deployments.

    View source ↗
  5. 24d ago

    2026.2.5 backport patch: release notes and test fixes

    A 2026.2 patch consisting of release-notes backports and a fix for e2e proxy tests. Housekeeping with no user-facing surface.

    View source ↗
  6. 1mo ago

    2026.5.3 backport patch: release notes

    Almost entirely release-notes cherry-picks onto the 2026.5 branch, carrying documentation for earlier releases. The thinnest release in the window.

    View source ↗