Ingressi is free
Ingressi 2.0 came with paid editions. They are gone: from this release every feature is free for everyone, with no license keys and no limits on hosts, nodes or users.
Why
The EU. Under the Cyber Resilience Act (Regulation (EU) 2024/2847), anyone who sells software in the EU becomes its "manufacturer": security requirements, conformity assessment, technical documentation, a support period measured in years, and reporting actively exploited vulnerabilities to ENISA within 24 hours. That is a compliance department's job, and Ingressi is made by one person in their spare time. Selling it is not worth that, so it is no longer for sale.
Everything that was paid is now included: SAML and LDAP sign-in, enforced SSO, SCIM provisioning, custom roles, access reviews, alerting, configuration history, scheduled backups, audit streaming, the AI analyst, change approvals, compliance reports, fleet management, high availability, white-label and API monetization.
The core stays under the MIT License. The code in ee/ stays under the Elastic License 2.0.
Donations are very welcome
With no sales, donations are what keeps Ingressi going. If it saves you time or money, please consider supporting it:
- GitHub Sponsors: https://github.com/sponsors/fuomag9
- Ko-fi: https://ko-fi.com/fuomag9
Changes
- No licenses. The License page,
/api/v1/license*, the daily online license check, automatic license updates and thelicense:read/license:writepermissions are removed. A license key installed earlier is deleted on the first start. - No limits. Every "needs a license" restriction is gone; a new high availability replica always joins the cluster.
- No usage ping. The anonymous usage ping is removed, with its question on the overview and its Settings section. Ingressi sends nothing to its developers.
- The
license_expiringalert rule type is removed. Existing rules of that type are ignored and can be deleted. - The documentation and the security policy no longer carry the Cyber Resilience Act material or long-term-support plans.
- The 2.0.x releases are withdrawn. Upgrade straight to 2.1.0, from 2.0.x or from 1.13.x.
Images
docker pull ghcr.io/ingres-si/ingressi-web:2.1.0
docker pull ghcr.io/ingres-si/ingressi-caddy:2.1.0
docker pull ghcr.io/ingres-si/ingressi-l4-port-manager:2.1.0For linux/amd64 and linux/arm64. Each image is signed with Sigstore cosign and carries an SBOM and a build provenance attestation. To verify, with cosign 3 or later:
cosign verify ghcr.io/ingres-si/ingressi-web:2.1.0 \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-identity-regexp '^https://github\.com/ingres-si/ingressi/\.github/workflows/docker-build-trusted\.yml@refs/(heads|tags)/'The CycloneDX SBOM of the source tree is attached below.
Upgrading
Back up the data volumes, then run docker compose pull && docker compose up -d. The database migration runs on start. Read the upgrade notes; from 1.13.x, also read Upgrading to Ingressi.