Version 1.23.x#

Release notes for Nubus for Kubernetes 1.23.x:

Version 1.23.0 - 2026-09-15#

Upgrade path

For the upgrade to version 1.23.0, your deployment must run on version 1.22.x or 1.21.x. For the general steps to upgrade an existing Nubus for Kubernetes deployment, see Upgrade in Univention Nubus for Kubernetes - Operation Manual [1].

Release highlights#

Guardian returns, based on Cerbos

The Guardian component is back in the Nubus umbrella chart. The new implementation uses Cerbos as its policy decision point. It lays the foundation for fine-grained authorization in future Nubus releases.

Keycloak container hardened

The Keycloak main container now mounts most volumes read-only. This reduces the attack surface by limiting the paths in the container that are writable at runtime.

SCIM client improvements

The SCIM client receives several improvements in this release, including object-type specific search endpoints and experimental support for group provisioning.

Migration steps#

This section lists necessary migration steps that may apply to you. You need to run them before the upgrade.

  1. Operators who configured the Notifications API can remove all Helm Chart values under nubusNotificationsApi from their custom values files. Nubus no longer provisions the PostgreSQL database notificationsapi and its database user. After the upgrade, operators can drop the database and the database user from their PostgreSQL instance.

Changes#

This section lists the changes in 1.23.0 grouped by component in Nubus for Kubernetes.

Guardian#

Nubus for Kubernetes adds the Guardian component to the umbrella chart again. The new Guardian builds on Cerbos as its policy decision point. It provides no functionality yet and is deactivated by default with the value false in the Helm Chart value nubusGuardian.enabled. Activating it doesn’t alter the behavior of your deployment.

Kerberos encryption types#

Nubus for Kubernetes 1.22 announced that the UDM HTTP REST API only writes strong Kerberos encryption types. The change didn’t take effect, and the component kept writing the weak types as well. Version 1.23 fixes this. The UMC server wasn’t affected.

Accounts keep their Kerberos keys until their next password change. Therefore accounts from 1.22, or from an earlier version, still have weak keys after the upgrade. To remove them, run the remove_krb5key_keytypes script in the UDM HTTP REST API as described in Dry run command to remove existing weak keys.

Notifications API#

Nubus for Kubernetes removes the Notifications API from the umbrella Helm Chart. The component is deprecated and no longer part of a Nubus deployment. The Portal Server feature toggle nubusPortalServer.portalServer.featureToggles.notifications_api is deactivated by default with the value false.

Portal Frontend#

The right sidebar of the portal now shows the display name of the signed-in user and falls back to the username if no display name is set. Earlier versions only showed the username.

Included errata updates#

The errata updates contain fixes for the following CVEs:

binutils
binutils-common
binutils-x86-64-linux-gnu
bsdutils
curl
libbinutils
libblkid1
libctf-nobfd0
libctf0
libcurl4
libexpat1
libexpat1-dev
libgprofng0
liblastlog2-2
liblzma5
libmount1
libpam-modules
libpam-modules-bin
libpam-runtime
libpam0g
libpq5
libpython3.11-minimal
libpython3.11-stdlib
libpython3.13-minimal
libpython3.13-stdlib
libsmartcols1
libuuid1
login
mount
nginx
nginx-common
openjdk-21-jre-headless
openssh-client
postgresql-client-15
python-dotenv
python3-ecdsa
python3-jose
python3-jwcrypto
python3-rsa
python3.11
python3.11-minimal
python3.11-venv
python3.13
python3.13-minimal
starlette
util-linux