Sign-in portal: single sign-on comes from your identity provider
The forward-auth sign-in portal now reuses a dashboard session only when an identity provider created it: an OIDC provider, a SAML provider or an LDAP directory. A dashboard session from a password or a passkey no longer signs anyone in to protected apps: those users sign in at the portal.
- Ingressi records how each dashboard session was signed in to. Sessions from before this release are not reused; their users sign in at the portal once.
- Signing in at the portal with Sign in with creates a reusable session, so the next protected app opens without asking again.
- The portal still passes the user's identity to the app in
X-Ingressi-*headers. Ingressi stays a relying party: it has no identity-provider endpoints and issues no tokens to other applications.
Other changes
- The dashboard navigation group Identity is now Users and sign-in.
- The documentation, the README and the image labels describe Ingressi as a self-hosted reverse proxy built on Caddy, with the web application firewall, access rules, rate limiting, the sign-in portal, client certificates and instance sync as optional features that stay off until an administrator turns them on.
- New: a test that a fresh install has none of those optional features turned on.
Images
docker pull ghcr.io/ingres-si/ingressi-web:2.0.3
docker pull ghcr.io/ingres-si/ingressi-caddy:2.0.3
docker pull ghcr.io/ingres-si/ingressi-l4-port-manager:2.0.3For linux/amd64 and linux/arm64. Each image is signed with Sigstore cosign and carries an SBOM and a build provenance attestation. To verify, with cosign 3 or later:
cosign verify ghcr.io/ingres-si/ingressi-web:2.0.3 \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-identity-regexp '^https://github\.com/ingres-si/ingressi/\.github/workflows/docker-build-trusted\.yml@refs/(heads|tags)/'The CycloneDX SBOM of the source tree is attached below.
Upgrading
Back up the data volumes, then run docker compose pull && docker compose up -d. The database migration runs on start.