github ingres-si/ingressi v2.0.3
Ingressi v2.0.3

one hour ago

Sign-in portal: single sign-on comes from your identity provider

The forward-auth sign-in portal now reuses a dashboard session only when an identity provider created it: an OIDC provider, a SAML provider or an LDAP directory. A dashboard session from a password or a passkey no longer signs anyone in to protected apps: those users sign in at the portal.

  • Ingressi records how each dashboard session was signed in to. Sessions from before this release are not reused; their users sign in at the portal once.
  • Signing in at the portal with Sign in with creates a reusable session, so the next protected app opens without asking again.
  • The portal still passes the user's identity to the app in X-Ingressi-* headers. Ingressi stays a relying party: it has no identity-provider endpoints and issues no tokens to other applications.

Other changes

  • The dashboard navigation group Identity is now Users and sign-in.
  • The documentation, the README and the image labels describe Ingressi as a self-hosted reverse proxy built on Caddy, with the web application firewall, access rules, rate limiting, the sign-in portal, client certificates and instance sync as optional features that stay off until an administrator turns them on.
  • New: a test that a fresh install has none of those optional features turned on.

Images

docker pull ghcr.io/ingres-si/ingressi-web:2.0.3
docker pull ghcr.io/ingres-si/ingressi-caddy:2.0.3
docker pull ghcr.io/ingres-si/ingressi-l4-port-manager:2.0.3

For linux/amd64 and linux/arm64. Each image is signed with Sigstore cosign and carries an SBOM and a build provenance attestation. To verify, with cosign 3 or later:

cosign verify ghcr.io/ingres-si/ingressi-web:2.0.3 \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  --certificate-identity-regexp '^https://github\.com/ingres-si/ingressi/\.github/workflows/docker-build-trusted\.yml@refs/(heads|tags)/'

The CycloneDX SBOM of the source tree is attached below.

Upgrading

Back up the data volumes, then run docker compose pull && docker compose up -d. The database migration runs on start.

Don't miss a new ingressi release

NewReleases is sending notifications on new releases.