Skip to main content
Version: 8.2607.x.x LTS

Release notes

info

Changes marked with ⚠️ may be breaking, have security impact, or affect user experience. Review these changes carefully, and adapt your pattern configuration as required.

How to install and use plugins

Download the plugin JAR files from the Nevis Portal.

Go to the Downloads section, and select the corresponding LTS26.

Enter the version in the Search field.

On how to use this library, see Editing Project Pattern Libraries.

nevisAdmin 8.2607.0 Release Notes

Release information

  • Release Date: 2026-07-22
  • RPM: nevisadmin4-8.2607.0.9-1.noarch.rpm
  • GUI Version: FE 8.2607.0-1597 - BE 8.2607.0.9

Breaking changes

  • UPGRADED: nevisAdmin 4 is now compiled and run with Java 25. Using Java 21 is no longer supported. (NEVISADMV4-10734)
  • BREAKING CHANGE: The REST calls to nevisAdmin 4 with paths ending with a trailing slash are no longer accepted. (NEVISADMV4-10671)
  • BREAKING CHANGE: The GET /inventories/{inventoryKey} and the GET /inventories/{inventoryKey}/head REST endpoint requests now use the Accept header instead of the Content-Type header. (NEVISADMV4-10772)
  • CHANGED: Uploading a plugin library now returns HTTP 201 (Created) instead of HTTP 200 (OK). (NEVISADMV4-10426)

Changes and new features

  • NEW: We have introduced a validation check during deployment generation that triggers a warning if the local commitId does not match the remote HEAD for the inventory or the project. This ensures that your deployments are based on the most up-to-date configurations. You can disable this check by setting nevisadmin.validation.revision-uptodate.enabled=false. (IP-1430)
  • NEW: Previous versions of version-controlled projects may now be imported as detached heads, using the Revert action. (NEVISADMV4-10643)
  • NEW: Added support for configuring a custom truststore to verify the TLS certificate of the IdP metadata endpoint when accessing the SAML metadata service. This is required when the IdP uses a certificate issued by an internal or private CA. (IP-2319, NEVISADMV4-10841)
  • NEW: Added support for mapping SAML assertion roles to nevisAdmin 4 group keys via a configurable role-to-group mapping. This allows IdPs that provide application roles instead of nevisAdmin group names to control group membership. (IP-2319, NEVISADMV4-10842)
  • NEW: Projects and inventories with custom git credentials will display the repository username and the ID of the secret holding the repository password on their Settings page. (NEVISADMV4-10659)
  • FIXED: We fixed a bug in classic deployment where out-of-sync system time caused deployments to hang. (NEVISADMV4-9788)
  • FIXED: We fixed an issue where the SAML redirection sometimes did not return to favicon.ico. (IP-1758)
  • CHANGED: nevisAdmin now shows the default value that applies when not selecting any value in drop-downs in the patterns. (NEVISADMV4-10642)
  • CHANGED: Links in the pattern help are now opened in a new browser tab. (IP-1381)
  • CHANGED: We added validation to ensure Pattern IDs contain only alphanumeric characters. This behavior can be disabled by setting nevisadmin.validation.pattern-id.enabled=false. (IP-1957)
  • CHANGED: The classic deployment working directory on the target server is now randomized for every deployment. This behavior can be disabled by setting nevisadmin.deltadeployment.unique.work.dir=false via system property or environment variable. (NEVISADMV4-10634)
  • CHANGED: On the Deployment History page, inventory and project revisions are now loaded lazily to improve page loading performance. (NEVISADMV4-10843)

Dependency upgrades

  • jgit to 7.7.0.202606012155-r (NEVISADMV4-10860)
  • jsch to 2.28.3 (NEVISADMV4-10860)
  • jackson to 3.1.4 (NEVISADMV4-10860)
  • jackson-annotations to 2.22 (NEVISADMV4-10860)
  • fasterxml-jackson to 2.22.0 (NEVISADMV4-10860)
  • jetty to 12.1.10 (NEVISADMV4-10860)
  • groovy to 5.0.6 (NEVISADMV4-10860)
  • snakeyaml to 2.6 (NEVISADMV4-10671)
  • aspectj to 1.9.25.1 (NEVISADMV4-10671)
  • jakarta-xml-bind-api to 4.0.5 (NEVISADMV4-10671)
  • jaxb-runtime to 4.0.9 (NEVISADMV4-10860)
  • slf4j to 2.0.18 (NEVISADMV4-10860)
  • logback-classic to 1.5.37 (NEVISADMV4-10860)
  • guava 33.6.0-jre (NEVISADMV4-10671)
  • commonmark to 0.29.0 (NEVISADMV4-10860)
  • opensaml 5.2.1 (NEVISADMV4-10671)
  • spring-boot to 4.1.0 (NEVISADMV4-10860)
  • springdoc-openapi-starter-webmvc-ui to 3.0.3 (NEVISADMV4-10671)
  • mariadb-java-client to 3.5.9 (NEVISADMV4-10860)
  • postgresql to 42.7.12 (NEVISADMV4-10860)
  • shiro 2.1.0 (NEVISADMV4-10671)
  • nimbus-jose-jwt to 10.9.1 (NEVISADMV4-10860)
  • bcprov-jdk18on to 1.84 (NEVISADMV4-10671)
  • bcpkix-jdk18on to 1.84 (NEVISADMV4-10671)
  • bcpg-jdk18on to 1.84 (NEVISADMV4-10671)
  • bcutil-jdk18on to 1.84 (NEVISADMV4-10671)
  • kubernetes-java-client to 27.0.0 (NEVISADMV4-10860)

Patterns 8.2607.0 Release Notes

Release information

  • Release Date: 2026-07-22
  • Build Version: 8.2607.0.6

Changes

⚠️ The docker image versions encoded in the patterns have been increased for all Nevis components to 8.2607.0.

Using the new image versions is required to ensure that the generated configuration is compatible. Ensure you download the images and push them to the container registry of your cluster. See the component release notes for further information.

Changes already released in LTS24 patch releases (7.2511.x, 7.2605.x) are not repeated here — see the corresponding release notes in the LTS24 patterns release notes.

General

  • NEVISADMV4-10820: Configuration generation for complex deployments with many patterns is now significantly faster.
  • PAT-1112: Fixed custom properties set via nevisMeta Instance → Advanced Settings → Custom Properties being silently ignored when the key matched a property that has a default value.
  • PAT-1102: Fixed silent overwrite and false conflict for shared Groovy scripts.

Kubernetes Deployment

  • PAT-1096: Added path match configuration to the Gateway API Settings pattern.
  • ⚠️ IP-2582: Renamed the Virtual Host pattern's Gateway API Host property to Gateway Host. When Gateway Host is set, the generated NevisGateway resource's hostHeaderOverride now restores the HTTP Host header to the value configured via Frontend Addresses instead of duplicating Gateway Host. This corrects the header forwarded to nevisProxy when using Gateway Host to match an upstream-rewritten hostname.

Application Protection

  • NEVISPROXY-7881: Added env.conf customization support to the Generic nevisProxy Settings pattern.
  • PAT-1091: The nevisProxy Observability pattern now supports OpenTelemetry Logs configuration.
  • PAT-1099: Added gRPC support to the nevisProxy Observability pattern.
  • PAT-1095: Fixed Cookie Customization not being applied on the nevisMeta Web Console.
  • PAT-1082: Added custom parameter support to the Authorization Policy pattern.

Identity Management

  • PAT-1128: Fixed the nevisIDM Password Login pattern generating an AuthState with the Default client instead of the configured Client Name when the pattern is used with separate screens.

Authentication

  • PAT-1090: Fixed the nevisAuth Connector pattern when entering an FQDN as Kubernetes URL.

Mobile Authentication & FIDO2 Passwordless

  • NEVISFIDO-2584: The nevisFIDO Instance patterns now generate server.tls.client-auth instead of the legacy server.tls.require-client-auth boolean property. nevisFIDO 8.2607.0 or newer is required.
  • PAT-1101: Fixed userId expression in FIDO2 Onboarding.