Releases: DefGuard/proxy
Release list
v2.2.0-alpha1
Warning
This is an early alpha release, not meant for production use. Use it to test brand-new functionalities.
About this release
Configure exactly how users authenticate with multi-step MFA, including FIDO2 security keys. Administrators have full control over MFA flows for each location, with stronger authentication options for high-security environments.
The mobile client has also been redesigned, joining the rest of the refreshed Defguard family.
✨ What's new
- Multi-step configurable MFA methods
- Use FIDO2 hardware key as MFA factor - add it as a passkey in your profile, configure an MFA Flow with FIDO2 Security Key factor, assign it to your location and connect using the latest Desktop Client.
- Bulk actions for Firewall module
- Handling multiple locations with DNS configuration connected simultaneously
- Completely redesigned Mobile Client - try it out by joining our beta channels or by installing packages from the release assets (more details in the mobile release).
|
🧪 How to test
🚀 Quickly run the latest server components using one-line-script in pre-release mode.
🔄 Worried that your users have to upgrade the client applications? Here you can check the client vs server feature compatibility matrix.
🙋 Feedback
We want to get as much feedback as possible, so we encourage you to:
💬 open a GitHub discussion
🪲 report any missing features or bugs as issues
Full changelog
- update proto submodule by @wojcik91 in #372
- add step-start route for multi-step MFA flows by @wojcik91 in #382
- Stable to dev by @moubctez in #394
- Fido2 by @moubctez in #395
- FIDO2 take2 by @moubctez in #396
- handle remote-auth methods in multi-step MFA flows by @wojcik91 in #397
- Configure MFA methods on demand via client by @t-aleksander in #398
- fix trivy by @filipslezaklab in #400
- Client MTU by @moubctez in #401
Full Changelog: v2.1.0...v2.2.0-alpha1
v2.1.0
🎉 Welcome to Defguard 2.1 🎉
2.1 makes the device itself part of the access decision - admins define the security criteria a machine must meet, and non-compliant endpoints simply can't establish a connection - and it ships a rebuilt Desktop Client whose tray mode gets your users onto the VPN in two clicks.
🛡️ Device Posture verification - client and OS version, security updates, AD membership, antivirus, disk encryption,
🖥️ a redesigned Desktop Client with tray mode,
⌨️ defguard-client - drive the client from a terminal, MFA included,
🔒 Allowed IPs generated from Firewall Rules - least-privilege configs, no network recon,
🐧 service locations on Linux - Always-on VPN from system boot,
🧩 official support for running Defguard Gateway on VyOS as a container.
More details with videos in this blogpost.
🔐 As always, this release was pentested by ISEC, together with Striga.AI - all major findings were fixed before release. The full report will be published on our pentesting page.
📖 Documentation for the new features:
- Device Posture verification
- CLI client
- Generate Allowed IPs from Firewall Rules
- Service locations
- Running Gateway on VyOS
🚅 If you would like to test Defguard, we offer a quick and easy One-line install script.
Business features require free registration.
👉 https://defguard.net/get-free-business/
Once registered, simply apply your license to your instance.
We want to get as much feedback as possible, so we encourage you to:
💬 open a GitHub discussion
🪲 report any missing features or bugs as issues
What's Changed
- Implement posture checks by @j-chmielewski in #300
- Fix proxy warning page by @j-chmielewski in #301
- Report windows security update max age by @t-aleksander in #303
- Build debs for debian 12/ubuntu 22.04 by @jakub-tldr in #305
- Fix Dockerfile by @jakub-tldr in #306
- Fix posture errors separator by @j-chmielewski in #308
- chore: bump version to 2.1.0 (#309) by @wojcik91 in #310
- Hide footer when admin email is user email by @jakub-tldr in #311
- Revert "Hide footer when admin email is user email" by @jakub-tldr in #312
- Updated README by @kchudy in #314
- display OIDC error message by @j-chmielewski in #315
- Display OIDC error message (#315) by @j-chmielewski in #316
- Fix config in FreeBSD package by @moubctez in #318
- control Edge UI by Core settings by @wojcik91 in #319
- merge stable/2.x -> dev by @wojcik91 in #321
- Update proto by @filipslezaklab in #323
- Security patches (release/2.1) by @renovate[bot] in #351
- Security patches (release/2.1) by @renovate[bot] in #364
- chore: update proto submodule to handle disable_tunnels flag by @wojcik91 in #366
- Authenticate posture checks by @j-chmielewski in #367
- port remaining changes from stable branch by @wojcik91 in #369
- bump protos to stable/2.x by @j-chmielewski in #370
- bump core dependencies by @j-chmielewski in #371
- DG2608-18: Client IP address is taken from attacker-controlled forwarding headers and forwarded to Defguard Core by @moubctez in #383
- Migrate sbom ignore, bump deps by @t-aleksander in #384
- DG2608-19: [proxy] Enrollment and password reset session cookies are issued without the Secure attribute by @wojcik91 in #386
- Bump core dependency by @t-aleksander in #389
- Bump minimal version of components by @t-aleksander in #390
- Remove major docker tag from being automatically added by @t-aleksander in #393
Full Changelog: v2.0.1...v2.1.0
v2.1.0-beta1
🎉 Welcome to Defguard 2.1 Beta 1 🎉
This is a feature-complete beta release, not meant for production use. Penetration testing is still pending.
2.1 brings exciting new features:
-
Completely redesigned Desktop Client - try it out by installing the package for your OS from the client release assets


🚀 Here you can find a quick tutorial on how to quickly launch 2.1α using one-line-script in pre-relase mode.
We want to get as much feedback as possible, so we encourage you to:
💬 open a GitHub discussion
🪲 report any missing features or bugs as issues
What's Changed
- Security patches (release/2.1) by @renovate[bot] in #351
- Security patches (release/2.1) by @renovate[bot] in #364
- chore: update proto submodule to handle disable_tunnels flag by @wojcik91 in #366
- Authenticate posture checks by @j-chmielewski in #367
- port remaining changes from stable branch by @wojcik91 in #369
- bump protos to stable/2.x by @j-chmielewski in #370
- bump core dependencies by @j-chmielewski in #371
Full Changelog: v2.1.0-alpha1...v2.1.0-beta1
v2.0.2
This is a patch for the major 2.0 release. It contains small UI and packaging fixes.
The 2.0 was a significant step up from version 1.x, featuring:
🎨 a completely redesigned UI,
📦 a new and easy deployment approach (and component communication security),
🛠️ and some other major architectural changes.
More details with videos in this blogpost.
⬆︎ If you will be upgrading from 1.x - here you can find relevant documentation about the upgrade.
🚅 If you would like to test Defguard - we offer a quick and easy One-line install script.
Previously, these features were available without registration (within certain limits).
Starting from 2.0, a free Business license registration is required to use them.
👉 https://defguard.net/get-free-business/
Once registered, simply apply your license to your instance and enjoy access to Business functionality.
We want to get as much feedback as possible, so we encourage you to:
💬 open a GitHub discussion
🪲 report any missing features or bugs as issues
Other Changes
- Display OIDC error message (#315) by @j-chmielewski in #316
- Fix config in FreeBSD package by @moubctez in #318
Full Changelog: v2.0.1...v2.0.2
v2.1.0-alpha1
🎉 Welcome to Defguard 2.1 Alpha 1 🎉
First of all, this is an actual alpha, not meant for production, but a technology preview of what’s to come.
2.1 brings exciting new features:
-
Completely redesigned Desktop Client - try it out by installing the package for your OS from the client release assets


🚀 Here you can find a quick tutorial on how to quickly launch 2.1α using one-line-script in pre-relase mode.
We want to get as much feedback as possible, so we encourage you to:
💬 open a GitHub discussion
🪲 report any missing features or bugs as issues
What's Changed
- Implement posture checks by @j-chmielewski in #300
- Fix proxy warning page by @j-chmielewski in #301
- Report windows security update max age by @t-aleksander in #303
- Build debs for debian 12/ubuntu 22.04 by @jakub-tldr in #305
- Fix Dockerfile by @jakub-tldr in #306
- Fix posture errors separator by @j-chmielewski in #308
- chore: bump version to 2.1.0 (#309) by @wojcik91 in #310
- Hide footer when admin email is user email by @jakub-tldr in #311
- Revert "Hide footer when admin email is user email" by @jakub-tldr in #312
- Updated README by @kchudy in #314
- display OIDC error message by @j-chmielewski in #315
- Display OIDC error message (#315) by @j-chmielewski in #316
- Fix config in FreeBSD package by @moubctez in #318
- control Edge UI by Core settings by @wojcik91 in #319
- merge stable/2.x -> dev by @wojcik91 in #321
- Update proto by @filipslezaklab in #323
Full Changelog: v2.0.1...v2.1.0-alpha1
v2.0.1
This is a patch for the major 2.0 release. It includes fixes for issues reported by early adopters.
The 2.0 was a significant step up from version 1.x, featuring:
🎨 a completely redesigned UI,
📦 a new and easy deployment approach (and component communication security),
🛠️ and some other major architectural changes.
More details with videos in this blogpost.
⬆︎ If you will be upgrading from 1.x - here you can find relevant documentation about the upgrade.
🚅 If you would like to test Defguard - we offer a quick and easy One-line install script.
Previously, these features were available without registration (within certain limits).
Starting from 2.0, a free Business license registration is required to use them.
👉 https://defguard.net/get-free-business/
Once registered, simply apply your license to your instance and enjoy access to Business functionality.
We want to get as much feedback as possible, so we encourage you to:
💬 open a GitHub discussion
🪲 report any missing features or bugs as issues
What's Changed
- chore: prepare 2.0.1 release by @wojcik91 in #296
- fix pnpm lockfile format by @wojcik91 in #297
- update openssl crate by @wojcik91 in #302
- fix proxy warning page (#301) by @wojcik91 in #304
Full Changelog: v2.0.0...v2.0.1
v2.0.0
🎉 Welcome to Defguard 2.0 🎉
It’s a significant step up from version 1.x, featuring:
🎨 a completely redesigned UI,
📦 a new and easy deployment approach (and component communication security),
🛠️ and some other major architectural changes.
More details with videos in this blogpost.
⬆︎ If you will be upgrading from 1.x - here you can find relevant documentation about the upgrade.
🚅 If you would like to test Defguard - we offer a quick and easy One-line install script.
Previously, these features were available without registration (within certain limits).
Starting from 2.0, a free Business license registration is required to use them.
👉 https://defguard.net/get-free-business/
Once registered, simply apply your license to your instance and enjoy access to Business functionality.
We want to get as much feedback as possible, so we encourage you to:
💬 open a GitHub discussion
🪲 report any missing features or bugs as issues
What's Changed
- Disable latest Docker tag in release workflow by @wojcik91 in #221
- Disable APT repository signing/upload by @jakub-tldr in #225
- Core certificate authority, part 1: Proxy by @t-aleksander in #223
- Multiproxy private cookies by @j-chmielewski in #229
- http healthcheck endpoints always respond by @j-chmielewski in #234
- Cookie key proto by @j-chmielewski in #235
- Implement proxy wizard by @t-aleksander in #233
- Implement remote MFA with new, separate RPC message by @j-chmielewski in #238
- Fix proxy healthceck endpoint availability when waiting for setup by @t-aleksander in #239
- include lsb_release in Docker image by @wojcik91 in #240
- bump version 2.0.0 by @wojcik91 in #248
- Crl by @j-chmielewski in #250
- Open desktop app page by @moubctez in #254
- More user friendly certificate permission denied errors by @t-aleksander in #256
- deprecate callback/redirect URL settings by @wojcik91 in #255
- Use proper file permission for certificates by @moubctez in #257
- Unadopted UI by @j-chmielewski in #259
- Prepare Alpha Two by @moubctez in #260
- Show link-invalid when using disabled user token by @jakub-tldr in #261
- Provision HTTPS certificates for Core and Proxy by @t-aleksander in #263
- Faster cargo deny and update dependencies by @moubctez in #264
- Handle ClearHttpsCerts message by @j-chmielewski in #265
- support protobuf versioning by @wojcik91 in #262
- update minimum core version to 2.0.0 by @wojcik91 in #266
- add workflow to tag latest image on release by @wojcik91 in #267
- copy APT repo update workflow from main by @wojcik91 in #268
- Get rid of cross-rs by @moubctez in #270
- Fix FreeBSD package name by @moubctez in #272
- Auto adoption time limit by @jakub-tldr in #274
- Preserve old package versions on APT repository by @jakub-tldr in #276
- Ensure acme server is stopped when challenge fails by @j-chmielewski in #275
- add core client cert validation by @wojcik91 in #273
- Add defaults when parsing toml by @t-aleksander in #279
- Build packages with custom user by @moubctez in #278
- Use CAP_NET_BIND_SERVICE by @moubctez in #281
- Save certificates before completing setup, test write access by @t-aleksander in #280
- Fine tune packages by @moubctez in #283
- improve baseline HTTP security for no-reverse proxy deployment scenarios by @wojcik91 in #282
- adjust rate limiter config by @wojcik91 in #284
- use Docker registry as build cache by @wojcik91 in #286
- make rate limiter opt-in by @wojcik91 in #287
- Fix minor 2.0 bugs by @t-aleksander in #289
- Inform user about common causes of invalid let's encrypt order status by @t-aleksander in #290
- update core deps in preparation for 2.0 release by @wojcik91 in #291
Full Changelog: v1.6.0...v2.0.0
v2.0.0-beta2
🎉 Welcome to Defguard 2.0 Beta 2 🎉
This is the final beta before the stable release. Our primary focus has been on stabilising the platform and ensuring everything is ready for a smooth, production-grade launch.
📖 A comprehensive list of the changes implemented since Alpha 2 is documented in detail here: https://defguard.net/blog/defguard-2-0-release-beta-1/.
🛠️ We highly recommend previewing it yourself. We prepared a guide explaining how to run the alpha2 before. To run the beta2 just use 2.0.0-beta2 image tags instead of 2.0.0-alpha2.
We want to get as much feedback as possible, so we encourage you to:
💬 open a GitHub discussion
🪲 report any missing features or bugs as issues
What's Changed
- copy APT repo update workflow from main by @wojcik91 in #268
- Get rid of cross-rs by @moubctez in #270
- Fix FreeBSD package name by @moubctez in #272
- Auto adoption time limit by @jakub-tldr in #274
- Preserve old package versions on APT repository by @jakub-tldr in #276
- Ensure acme server is stopped when challenge fails by @j-chmielewski in #275
- add core client cert validation by @wojcik91 in #273
- Add defaults when parsing toml by @t-aleksander in #279
- Build packages with custom user by @moubctez in #278
- Use CAP_NET_BIND_SERVICE by @moubctez in #281
- Save certificates before completing setup, test write access by @t-aleksander in #280
- Fine tune packages by @moubctez in #283
- improve baseline HTTP security for no-reverse proxy deployment scenarios by @wojcik91 in #282
- adjust rate limiter config by @wojcik91 in #284
- use Docker registry as build cache by @wojcik91 in #286
- make rate limiter opt-in by @wojcik91 in #287
Full Changelog: v2.0.0-beta1...v2.0.0-beta2
v2.0.0-beta1
🎉 Welcome to Defguard 2.0 Beta 1 🎉
📖 A comprehensive list of the changes implemented since Alpha 2 is documented in detail here: https://defguard.net/blog/defguard-2-0-release-beta-1/
🛠️ We highly recommend previewing it yourself. We prepared a guide explaining how to run the alpha2 before. To run the beta1 just use 2.0.0-beta1 image tags instead of 2.0.0-alpha2.
We want to get as much feedback as possible, so we encourage you to:
💬 open a GitHub discussion
🪲 report any missing features or bugs as issues
What's Changed
- Show link-invalid when using disabled user token by @jakub-tldr in #261
- Provision HTTPS certificates for Core and Proxy by @t-aleksander in #263
- Faster cargo deny and update dependencies by @moubctez in #264
- Handle ClearHttpsCerts message by @j-chmielewski in #265
- support protobuf versioning by @wojcik91 in #262
- update minimum core version to 2.0.0 by @wojcik91 in #266
- add workflow to tag latest image on release by @wojcik91 in #267
Full Changelog: v2.0.0-alpha2...v2.0.0-beta1
v2.0.0-alpha2
🎉 Welcome to Defguard 2.0 Alpha 2 🎉
📖 A comprehensive list of the changes implemented since Alpha 1 is documented in detail here: https://defguard.net/blog/defguard-2-0-release-alpha-2/
🛠️ We also highly recommend reviewing our detailed technical overview of all changes and the comprehensive showcase of all features in this article.
We want to get as much feedback as possible, so we encourage you to:
💬 open a GitHub discussion
🪲 report any missing features or bugs as issues
Detailed Changes
- Disable latest Docker tag in release workflow by @wojcik91 in #221
- Disable APT repository signing/upload by @jakub-tldr in #225
- Core certificate authority, part 1: Proxy by @t-aleksander in #223
- Multiproxy private cookies by @j-chmielewski in #229
- http healthcheck endpoints always respond by @j-chmielewski in #234
- Cookie key proto by @j-chmielewski in #235
- Implement proxy wizard by @t-aleksander in #233
- Implement remote MFA with new, separate RPC message by @j-chmielewski in #238
- Fix proxy healthceck endpoint availability when waiting for setup by @t-aleksander in #239
- include lsb_release in Docker image by @wojcik91 in #240
- bump version 2.0.0 by @wojcik91 in #248
- Crl by @j-chmielewski in #250
- Open desktop app page by @moubctez in #254
- More user friendly certificate permission denied errors by @t-aleksander in #256
- deprecate callback/redirect URL settings by @wojcik91 in #255
- Use proper file permission for certificates by @moubctez in #257
- Unadopted UI by @j-chmielewski in #259
- Prepare Alpha Two by @moubctez in #260
Full Changelog: v1.6.0...v2.0.0-alpha2
