Zum Inhalt springen

Portainer Release Notes

28 Einträge aus 5 Quellen. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform Provider Portainer von Portainer

Terraform Provider Portainer Version 2.0.1

Mit v2.0.1 lassen sich Stacks im Status Error nach Korrektur der Compose-Datei wieder aktualisieren, und portainer_stack_delete_by_name sowie portainer_registry_connection funktionieren nun überhaupt (inklusive GitHub-Registries mit type = 8), wobei Konfigurationen, die diese beiden referenzieren, bis zur Anpassung beim Plan fehlschlagen.

v2.0.1

Fixed

  • Stacks left in Error can be updated again (#147) A stack whose deployment had failed refused every further apply, in a fraction of a second and without sending a request. The only way out was starting the stack by hand in the Portainer UI. Fixing the compose file and re-applying now recovers the stack. A deployment that this provider itself started and that fails is still reported as a failure.

  • portainer_stack_delete_by_name now works at all Every call failed with 400 Invalid query parameter: namespace. Portainer requires a namespace query parameter that its API specification does not document, so the resource never sent it.

  • portainer_registry_connection now works at all Every check failed with 400 Username and password are required. Portainer demands credentials for all registry types, including public ones, so the data source never reached the connection test it exists to run. GitHub registries (type = 8) are also accepted now; the type was capped at 7.

Action required

Both fixes add a required argument to something that could not have been in working use, so no running configuration changes behaviour - but configurations that reference these two will now fail at plan time until they are updated:

resource "portainer_stack_delete_by_name" "example" {
  name        = "legacy-app" …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Kubesolo von Portainer

KubeSolo Version 1.2.1

KubeSolo 1.2.1 führt eine Konfigurationsdatei statt Kommandozeilen-Flags und Software-Grafana-Dashboards für den Metrics-Endpoint ein, importiert das local-path-provisioner-Image nur noch bei aktiviertem local-path-Speicher und behebt Fehler mit doppelten Pods, nftables-only-Hosts, kube-proxy sowie der Installation auf 32-bit ARM und RISC-V.

What's Changed

Feature

  • Introduced a configuration file to replace command-line flags #188
  • The local-path-provisioner image is only imported into containerd when local-path storage is enabled #195
    • Systems that don't use local-path storage no longer need the image or a registry pull for it
  • Added ready-to-import Grafana dashboards for the metrics endpoint #202
    • For more details, refer to this docs

Fixes

  • Fixed pods being duplicated and side-loaded images being lost when KubeSolo restarts #199
  • Fixed KubeSolo on nftables-only hosts and hosts with a read-only /proc/sys #190
  • kube-proxy no longer flushes the host's ip nat nftables table on startup #191
  • Fixed installing on 32-bit ARM and RISC-V hosts #198

Chore

  • Bumped google.golang.org/grpc 1.82.1 -> 1.83.2 #189 #193
  • Bumped go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc 1.35.0 -> 1.45.0 #196

Full Changelog: https://github.com/portainer/kubesolo/compare/v1.2.0...v1.2.1

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform Provider Portainer von Portainer

Terraform Provider Portainer Version 2.0.0

Version 2.0.0 ergänzt 81 neue Resources und Data Sources für die Business Edition API, behebt einen Stack-Deployment-Fehler unter Portainer 2.45 sowie ein Problem beim Anlegen von Edge-Agent-Environments und ersetzt Edge-Agent-Environments (Typ 4 und 7) bei geänderter Adresse künftig, wodurch ein neuer Edge-Key entsteht.

Release v2.0.0

Business Edition API coverage

This release roughly doubles what the provider can manage: 81 new resources and data sources covering the Business Edition API, alongside fixes for a stack deployment failure on Portainer 2.45 and a blocker that prevented Edge Agent environments from being created at all.

Nothing was removed or renamed. Every configuration valid on v1.35.0 is still valid, but read "Behaviour changes" before upgrading - one of them can replace an environment.

Behaviour changes

Edge Agent environments are replaced when their address changes. Portainer bakes the address into the edge key when the environment is created and never regenerates it, so an in-place update never actually took effect. Until now the provider emitted a warning and reported success, leaving the running agent on the old address. It now forces replacement instead, which issues a new edge key and means the agent has to be redeployed with it.

This only triggers for environment types 4 and 7, only when the address really changed, and not when the difference is the URL scheme alone. That last exclusion matters: Portainer normalises endpoint.URL down to the bare host, so environments created by older provider versions hold a scheme-less address in state and would otherwise be replaced on every apply.

Run terraform plan against your edge environments before upgrading. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Portainer

Portainer 2.45.1 LTS

Portainer 2.45.1 LTS härtet ausgehende Anfragen (Helm-Chart-Auflösung, Git HTTP/HTTPS) gegen SSRF, deaktiviert zertifikatsbasierte Authentifizierung für Azure-Blob-Backups im FIPS-Modus und aktualisiert Abhängigkeiten sowie kubectl und helm im kubectl-Shell-Image, um mehrere CVEs zu beheben.

Known issues

  • On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot

Known issues with Podman support

  • Podman environments aren't supported by auto-onboarding script
  • It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa)
  • Support for only CentOS 9, Podman 5 rootful

Changes

  • Hardened outbound requests against SSRF. Helm chart resolution and Git HTTP/HTTPS operations now go through the SSRF-aware transport, and the static rules that enforce this now match by type rather than by import alias, so an aliased import can no longer slip past them
  • Certificate-based authentication for Azure Blob backups is now disabled in FIPS mode
  • Added build-time static analysis that catches FIPS violations before they ship
  • Removed unused non-FIPS code paths from FIPS builds
  • Updated golang.org/x/mod to 0.40.0, fixing CVE-2026-56865 and CVE-2026-56864
  • Updated golang.org/x/crypto to 0.56.0, fixing CVE-2026-56854 (High), CVE-2026-78662 and CVE-2026-56855
  • Updated google.golang.org/grpc to 1.83.2, fixing CVE-2026-84304
  • Updated kubectl in the kubectl shell image to v1.37.0, which removes golang.org/x/net 0.49.0 entirely — fixing CVE-2026-39821 (Critical) along with 2 High and 5 Medium findings
  • Updated helm in the kubectl shell image to v4.2.4, taking golang.org/x/net to 0.56.0 and fixing CVE-2026-46600 (High) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Portainer Business von Portainer

Portainer Business 2.45.1 LTS: SSRF-Schutz und FIPS-Härtung

Portainer Business 2.45.1 LTS härtet ausgehende Anfragen gegen SSRF (Helm-Chart-Auflösung und Git-HTTP/HTTPS-Operationen laufen nun über den SSRF-geschützten Transport), deaktiviert zertifikatsbasierte Authentifizierung für Azure-Blob-Backups im FIPS-Modus und ergänzt eine Build-Analyse für FIPS-Verstöße.

September 17, 2026

Known Issues <a href="#known-issues" id="known-issues"></a>

  • On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot
  • kubectl port-forward fails with Portainer kubeconfig in some configurations

Known issues with Podman

  • Support for only CentOS 9, Podman 5 rootful
  • Auto onboarding a Podman environment defaults to “Standard” and not “Podman”
  • It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa)

Known issues with Talos clusters managed by Omni (BE only)

  • Loading Omni specific information in the Cluster Details view and configuring an existing Talos cluster is currently restricted to Portainer Admins. Environment Admins will get a forbidden error when attempting to do this. This only applies to Omni configuration, and does not affect authentication for any other functionality in the cluster

New in this release <a href="#new-in-this-release" id="new-in-this-release"></a>

  • Hardened outbound requests against SSRF. Helm chart resolution and Git HTTP/HTTPS operations now go through the SSRF-aware transport, and the static rules that enforce this now match by type rather than by import alias, so an aliased import can no longer slip past them
  • Certificate-based authentication for Azure Blob backups is now disabled in FIPS mode
  • Added build-time static analysis that catches FIPS violations before they ship …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Portainer

Portainer 2.39.8 LTS

Portainer 2.39.8 LTS aktualisiert die Go-Toolchain auf 1.25.14, golang.org/x/mod, golang.org/x/crypto sowie kubectl und Alpine-Pakete im kubectl-Shell-Image, um mehrere CVEs zu beheben.

Known issues

  • On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot

Known issues with Podman support

  • Podman environments aren't supported by auto-onboarding script
  • It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa)
  • Support for only CentOS 9, Podman 5 rootful

Changes

  • Upgraded the Go toolchain from 1.25.12 to 1.25.14 to address the following CVEs:
    • CVE-2026-39821
    • CVE-2026-56862
    • CVE-2026-56859
    • CVE-2026-56853
    • CVE-2026-33818
    • CVE-2026-56858
    • CVE-2026-56860
  • Upgraded golang.org/x/mod to 0.40.0 to address the following CVEs:
    • CVE-2026-56865
    • CVE-2026-56864
  • Upgraded golang.org/x/crypto to 0.55.0 in Portainer CE and compose-unpacker, which had lagged behind the other modules, to address GO-2026-6303
  • Upgraded kubectl in the kubectl shell image from 1.36.2 to 1.37.0, which is built with Go stdlib 1.26.6 and vendors golang.org/x/net 0.57.0, clearing 2 Critical findings (including CVE-2026-39821), 7 High and 7 Medium
  • Upgraded the Alpine packages in the kubectl shell image, moving openssl/libssl3 to 3.5.8-r0 and jq to 1.8.2-r0, clearing a further 9 High, 10 Medium and 1 Low findings …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform Provider Portainer von Portainer

Terraform Provider Portainer Version 1.35.0

Version 1.35.0 unterstützt Portainer 2.45.0 LTS mit neuen Kubernetes-Resources und -Data-Sources (u. a. Node Drain, Deployment Scale und Rollback), deckt die gesamte Portainer API ab (172 Resources und Data Sources) und enthält zwei Edge-Agent-Fixes.

Release v1.35.0

Support for Portainer 2.45.0 LTS, full coverage of the Portainer API, and two Edge Agent fixes.

The provider grows from 120 to 172 resources and data sources.

Portainer 2.45 support

2.45 introduced native Portainer APIs for Kubernetes alongside the kube-apiserver proxy. An audit of every route between 2.44.0 and 2.45.0 found the API delta is confined to the Kubernetes handler; everything else that changed upstream is internal refactoring with no payload change.

New resources:

  • portainer_kubernetes_node_drain - drain a node with all six kubectl drain options (force, timeout, grace period, ignore DaemonSets, delete emptyDir data, disable eviction)
  • portainer_kubernetes_deployment_scale - manage a deployment's replica count, with drift detection
  • portainer_kubernetes_deployment_rollback - roll a deployment back to an earlier revision
  • portainer_kubernetes_persistent_volume - pin a PersistentVolume's reclaim policy

New data sources: portainer_kubernetes_manifest_dry_run (validate manifests server-side before anything is applied), portainer_kubernetes_ingress_classes, portainer_kubernetes_resource_quotas, portainer_kubernetes_replicasets, portainer_kubernetes_deployments, portainer_kubernetes_pods, portainer_kubernetes_pod_logs.

Existing Kubernetes resources keep using the kube-apiserver proxy, so nothing changes for users on older Portainer versions.

GitOps …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Portainer MCP von Portainer

Portainer MCP 2.45.1: Healthcheck, Proxy-Tools und cryptography 50.0.0

Portainer MCP 2.45.1 lässt den Container-Healthcheck dem konfigurierten Bind folgen, akzeptiert bei den Proxy-Tools Objekt-Bodys mit Standard-Content-Type, verlangt endpointId bei Stack-Git-Operationen, sendet bei leeren JSON-Bodys {} und aktualisiert cryptography auf 50.0.0.

What's Changed

Full Changelog: https://github.com/portainer/portainer-mcp/compare/2.45.0...2.45.1

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Portainer MCP von Portainer

Portainer MCP 2.45.0: Policy-Request-Bodys korrigiert

Portainer MCP 2.45.0 behebt die Serialisierung der Request-Bodys von PolicyCreate und PolicyConflicts, prüft die Workarounds für Spec-Fehler erneut gegen Upstream 2.44 und aktualisiert pypa/gh-action-pypi-publish auf v1.14.2.

What's Changed

Full Changelog: https://github.com/portainer/portainer-mcp/compare/2.44.0...2.45.0

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Portainer

Portainer 2.45.0 LTS

Portainer 2.45.0 LTS bringt unter anderem erweiterte Kubernetes-Node-Drain-Optionen mit Agent-Failover, native APIs zum Schreiben von Kubernetes-Ressourcen, eine Manifest-Dry-run-API, Edge-Compute-Einstellungen bei der Einrichtung sowie Verbesserungen bei Git-Sources und Edge-Agent-Verbindungsprüfungen.

Known issues

  • On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot

Known issues with Podman support

  • Podman environments aren't supported by auto-onboarding script
  • It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa)
  • Support for only CentOS 9, Podman 5 rootful

Changes

New and improved features

  • Added advanced Kubernetes node drain options with agent failover
  • Added native Portainer APIs for writing Kubernetes secrets, configmaps, deployments and persistent volume claims, replacing direct kube-apiserver proxy calls
  • Added a generic Kubernetes manifest dry-run API
  • Edge Compute settings can now be configured during initial setup and via cli flags
  • Authentication events now record the real client IP from X-Forwarded-For when the request comes through a trusted proxy
  • The namespace YAML tab now shows every resource quota in the namespace
  • Added GetCharts() support to the async Edge agent, so chart data syncs on agent startup
  • Edge agent connectivity checks now report progress while probing, and wait longer before failing
  • Creating a git source now skips the source type selection step
  • The source form now explains git polling versus webhook triggers, and exposes the polling interval setting that was missing from the UI
  • Removed the redundant single-tab handle from the workflow details view …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Portainer

Portainer 2.39.7 LTS

Portainer 2.39.7 LTS behebt eine kritische Umgehung der Autorisierung im Docker-Proxy, bei der nicht erkannte API-Versionspräfixe die Zugriffskontrolle übergingen, und erweitert die Bind-Mount-Beschränkungen für Nicht-Admins auf Compose- und Swarm-Stacks.

Known issues

  • On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot

Known issues with Podman support

  • Podman environments aren't supported by auto-onboarding script
  • It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa)
  • Support for only CentOS 9, Podman 5 rootful

Changes

  • Fixed a critical Docker proxy authorization bypass. Unrecognised API version prefixes like /v1.47.0/ or /v01.47/ skipped access control entirely, letting non-admin users reach the Docker API directly
  • Closed a remaining gap in the CVE-2026-44849 (GHSA-5fxq-qcf3-244w) fix and broadened bind-mount restrictions for non-admin users, now including Compose and Swarm stack deployments

Deprecated and removed features

Deprecated features

  • None

Removed features

  • None

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Portainer Business von Portainer

Portainer Business 2.45.0 LTS: Kubernetes-APIs und Node-Drain-Optionen

Portainer Business 2.45.0 LTS bringt erweiterte Kubernetes-Node-Drain-Optionen mit Agent-Failover, native Portainer-APIs zum Schreiben von Kubernetes-Secrets, ConfigMaps, Deployments und Persistent Volume Claims, eine generische Manifest-Dry-run-API sowie Edge-Compute-Einstellungen bei der Ersteinrichtung und per CLI-Flags.

August 27, 2026

Known Issues <a href="#known-issues" id="known-issues"></a>

  • On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot
  • kubectl port-forward fails with Portainer kubeconfig in some configurations

Known issues with Podman

  • Support for only CentOS 9, Podman 5 rootful
  • Auto onboarding a Podman environment defaults to “Standard” and not “Podman”
  • It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa)

Known issues with Talos clusters managed by Omni (BE only)

  • Loading Omni specific information in the Cluster Details view and configuring an existing Talos cluster is currently restricted to Portainer Admins. Environment Admins will get a forbidden error when attempting to do this. This only applies to Omni configuration, and does not affect authentication for any other functionality in the cluster

New in this release <a href="#new-in-this-release" id="new-in-this-release"></a>

New and improved features

  • Added advanced Kubernetes node drain options with agent failover
  • Added native Portainer APIs for writing Kubernetes secrets, configmaps, deployments and persistent volume claims, replacing direct kube-apiserver proxy calls
  • Added a generic Kubernetes manifest dry-run API
  • Edge Compute settings can now be configured during initial setup and via cli flags …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Kubesolo von Portainer

KubeSolo Version 1.2.0

KubeSolo 1.2.0 bringt einen Prometheus-kompatiblen Metrics-Endpoint, Anbindung an einen vom Host verwalteten Container-Runtime (containerd oder CRI-O), CPU-Manager-Unterstützung, automatische MTU-Erkennung mit --mtu-Override sowie einen Portainer Edge Agent, der dem lts-Tag folgt und per --portainer-edge-image konfigurierbar ist.

What's Changed

Feature

  • Introduced a Prometheus-compatible metrics endpoint #176
    • Enable with --metrics-server; serves /metrics with control plane health gauges on 127.0.0.1:9105 (configurable via --metrics-bind-address)
  • Added support for attaching to a host-managed container runtime (containerd or CRI-O) #181
    • Set --container-runtime-endpoint (e.g. unix:///run/crio/crio.sock) to skip the embedded containerd; the host then supplies the runtime, OCI runtime, CNI plugin binaries and sandbox image
  • Added CPU manager support for latency-sensitive workloads #183
    • New --cpu-manager-policy, --cpu-manager-policy-options, --system-reserved and --reserved-cpus flags
    • For more details, refer to this docs
  • Auto-detect the network MTU, with an override via --mtu #179
    • Picks up reduced MTUs on VPN/tunnel/PPPoE links and applies them to the CNI bridge (cni0) and pod veth interfaces
    • For more details, refer to this docs
  • Portainer Edge Agent now tracks the lts tag, and the image is configurable via --portainer-edge-image #177
    • Any image other than the default is pulled from the registry rather than loaded from the embedded image

Fixes …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Portainer Business von Portainer

Portainer Business 2.39.6 LTS: Fehlerbehebungen bei Teams, Kubernetes und Stacks

Portainer Business 2.39.6 LTS behebt unter anderem das fälschliche Entfernen des direkten Umgebungszugriffs eines Nutzers beim Löschen seines Teams, mehrfache Fehlermeldungen auf Kubernetes-Anwendungsseiten und einen „Invalid Swarm ID“-/503-Fehler beim Erstellen eines Stacks von einem Swarm-Worker-Node.

August 13, 2026

Known Issues <a href="#known-issues" id="known-issues"></a>

  • On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot
  • kubectl port-forward fails with Portainer kubeconfig in some configurations

Known issues with Podman

  • Support for only CentOS 9, Podman 5 rootful
  • Auto onboarding a Podman environment defaults to “Standard” and not “Podman”
  • It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa)

Known issues with Talos clusters managed by Omni (BE only)

  • Loading Omni specific information in the Cluster Details view and configuring an existing Talos cluster is currently restricted to Portainer Admins. Environment Admins will get a forbidden error when attempting to do this. This only applies to Omni configuration, and does not affect authentication for any other functionality in the cluster

New in this release <a href="#new-in-this-release" id="new-in-this-release"></a>

Bug Fixes

  • Fixed a user's direct environment access being incorrectly removed when a team they belonged to was deleted
  • Fixed multiple "Cannot read properties of undefined (reading 'message')" error toasts appearing on Kubernetes application pages when an API call failed without a response (e.g. while pods are restarting after a redeploy)
  • Fixed an "Invalid Swarm ID" / 503 error when creating a stack from a Swarm worker node …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Portainer

Portainer 2.39.6 LTS

Portainer 2.39.6 LTS führt einen SSRF-Schutz mit konfigurierbarer Allow-List (off/audit/enforce) ein, erzwingt standardmäßig eine serverseitige EdgeID bei der ersten Verbindung, behebt Path Traversal im Swarm-Compose-Deployer und aktualisiert mehrere Abhängigkeiten wegen CVEs.

Known issues

  • On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot

Known issues with Podman support

  • Podman environments aren't supported by auto-onboarding script
  • It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa)
  • Support for only CentOS 9, Podman 5 rootful

Changes

Security improvements

  • Implemented an SSRF protection mechanism with a configurable allow-list in settings (off / audit / enforce modes)
  • Changed a default setting to enforce server-side EdgeID on first connection
  • Fixed path traversal in the swarm compose deployer, where configs/secrets file paths escaped the project root
  • Upgraded the Go toolchain from 1.25.11 to 1.25.12 to address the following CVEs:
    • CVE-2026-42505
    • CVE-2026-39822
  • Upgraded github.com/go-git/go-git/v5 to 5.19.2 to address the following CVEs:
    • CVE-2026-71556
    • CVE-2026-71557
  • Upgraded oras.land/oras-go/v2 to 2.6.2 to address CVE-2026-50163
  • Upgraded go.opentelemetry.io/otel to 1.44.0 to address CVE-2026-41178
  • Upgraded github.com/klauspost/compress to 1.18.7 to address GHSA-259r-337f-4rfw
  • Upgraded golang.org/x/net to 0.56.0 and golang.org/x/text to 0.39.0 in the Portainer updater to address the following CVEs:
    • CVE-2026-46600
    • CVE-2026-56852 …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform Provider Portainer von Portainer

Terraform Provider Portainer Version 1.34.3

Version 1.34.3 sorgt dafür, dass active = false bei Repository-Stacks in portainer_stack bestehen bleibt, und portainer_environment mit type = 4 legt wieder einen Docker Edge Agent statt eines Kubernetes-Edge an.

Release v1.34.3

Bug Fixes

  • portainer_stack: active = false now persists on repository stacks (#139) - the update path stopped the stack before the git redeploy, which restarted it, so active = false never took effect (perpetual true -> false diff). The stop now runs after the redeploy.
  • portainer_environment: type = 4 creates a Docker Edge Agent, not Kubernetes (#140) - an Edge Agent create now sends ContainerEngine=docker, so Portainer provisions the requested Docker edge (type 4) instead of a Kubernetes edge (type 7).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Portainer

Portainer 2.44.0 STS: Workflow-Details, GPU-Anzeige und Sicherheitsfixes

Portainer 2.44.0 STS ergänzt einen einfachen Workflow-Detailbildschirm, GPU-Anzeige in den Environment-Details und persistente Statusverfolgung, behebt Sicherheitslücken wie unbefugten Zugriff über übrig gebliebene Service Accounts und Path Traversal im Swarm-Compose-Deployer und aktualisiert bbolt, BuildKit sowie mehrere Abhängigkeiten.

Known issues

  • On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot

Known issues with Podman support

  • Podman environments aren't supported by auto-onboarding script
  • It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa)
  • Support for only CentOS 9, Podman 5 rootful

Changes

New and improved features

  • Added a basic workflow details screen
  • Added GPU visibility in the Environment Details view
  • Made the Portainer setup token easier to spot in the installation logs
  • Tracked the Source, Workflow, and Artifact status persistently
  • Upgraded bbolt to v1.5.0 for performance and robustness improvements
  • Moved the build pipeline to BuildKit v0.31.2 (previously v0.27.0); image build provenance attestations moved to the SLSA v1.0 format (previously v0.2) — any tooling that parses attestations needed to be verified against the new format

Security improvements

  • Fixed unauthorized access via leftover service accounts
  • Fixed path traversal in the swarm compose deployer, where configs/secrets file paths escaped the project root
  • CVE remediation:
    • Upgraded oras.land/oras-go/v2 to 2.6.1 to remediate CVEs
    • Upgraded containerd to 1.7.33 / v2 2.2.5 to remediate CVEs
    • Upgraded google.golang.org/grpc to 1.82.1 to remediate GHSA-hrxh-6v49-42gf
    • Upgraded axios to 1.18.0 to remediate CVEs …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Portainer Business von Portainer

Portainer Business 2.44.0 STS: Workflow-Details und GPU-Anzeige

Portainer Business 2.44.0 STS ergänzt einen einfachen Workflow-Detailbildschirm, GPU-Anzeige in den Umgebungsdetails und ein besser erkennbares Setup-Token in den Installationslogs.

July 30, 2026

Known issues <a href="#known-issues" id="known-issues"></a>

  • On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot.
  • In some Portainer Server Kubernetes installs, removing the local Kubernetes environment can prevent add-ons from being detected or managed correctly. For more information and a workaround, see this FAQ.
  • When creating a GitOps workflow, Compose files not named docker-compose.yml or compose.yml are detected as Kubernetes manifests, so Docker edge groups aren't offered as deployment targets.

Known issues with Podman support

  • Support for only CentOS 9, Podman 5 rootful.

Known issues with Talos clusters managed by Omni (BE only)

  • Loading Omni specific information in the Cluster Details view and configuring an existing Talos cluster is currently restricted to Portainer Admins. Environment Admins will get a forbidden error when attempting to do this. This only applies to Omni configuration, and does not affect authentication for any other functionality in the cluster.

New in this release <a href="#new-in-this-release" id="new-in-this-release"></a>

New and improved features

  • Added a basic workflow details screen
  • Added GPU visibility in the Environment Details view
  • Made the Portainer setup token easier to spot in the installation logs …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Portainer MCP von Portainer

Portainer MCP 2.44.0: Abhängigkeiten gegen Sicherheitswarnungen aktualisiert

Portainer MCP 2.44.0 aktualisiert acht gesperrte Abhängigkeiten, um alle offenen Dependabot-Sicherheitswarnungen zu beheben, und zieht übersehene Versions-Pins der Version 2.43 nach.

What's Changed

New Contributors

Full Changelog: https://github.com/portainer/portainer-mcp/compare/2.43.3...2.44.0

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform Provider Portainer von Portainer

Terraform Provider Portainer Version 1.34.2

Version 1.34.2 behebt in portainer_environment für Edge Agents, dass public_ip nie an Portainer gesendet wurde und dass environment_address bei jedem Plan von https://host zu host abwich.

Release v1.34.2

Fixed

Two Edge Agent fixes in portainer_environment:

  • public_ip was never sent to Portainer for Edge Agent environments (#137)

  • environment_address drifted from https://host to host on every plan (#136)

Originalquelle(öffnet in neuem Tab)Problem melden