NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #297 by repository stars
Last release 4 days ago
04 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Rarely documented
notes for 11 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
906 releases · first in 2021
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Netmaker v1.7.0 Release Notes 🚀
Run multiple customer environments from a single Netmaker server.
nmctl select the target org/tenant via X-Organization-ID / X-Tenant-ID (--org_id / --tenant_id), with nmctl organisation list and nmctl tenant list for discovery.Gateways can publish a TCP/WSS uplink so clients can reach the mesh in restrictive environments when UDP is blocked.
tcp_proxy_enabled and related listen/TLS settings).Connect endpoint detection and response platforms for posture checks from Integrations.
/api/v1/integrations/edr/{provider}).Connect mobile device management platforms for device compliance posture from Integrations.
/api/v1/integrations/mdm/{provider}).This release completes the SQL schema path and introduces multi-tenancy (org/tenant) bootstrap as part of the v1.7.0 migration.
Upgrade requirement (existing deployments):
migration-v1.6.0 has not completed on a prior v1.6.0 deployment.Impact:
👉 Action Required:
For detailed upgrade steps, refer to the official upgrade documentation:
Auto-relay peer reset - Reset a specific peer-to-peer connection that is using a relay (clear/reassign auto-relay for that peer pair) without resetting the entire network’s auto-relay state.
Host status - Host filtering uses live check-in status (Online/Offline/Disconnected) rather than a stale DB value.
MSP installs - nm-quick.sh -s flag to skip nmctl/mesh/netclient on MSP server installs.
IPv6-only machines
Netclients cannot currently auto-upgrade on IPv6-only systems.
Multi-network join performance
Multi-network netclient joins using an enrollment key still require optimisation.
systemd-resolved DNS limitation
On systems using systemd-resolved in uplink mode, only the first 3 entries in resolv.conf are honoured; additional entries are ignored. This may cause DNS resolution issues. Stub mode is recommended.
Windows Desktop App + mixed gateway modes
When the Windows Desktop App is connected to both:
the gateway monitoring component may disconnect from the Split Tunnel Gateway.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Netmaker v1.6.0 Release Notes 🚀
Using Netmaker's Egress function at local sites, paired with local routing rules, you can bridge entire networks (site-to-site). Now, Netmaker allows you to define ACL policies that control what traffic is allowed between these sites.
Netmaker's Egress function forwards traffic to external networks like offices and data centres. Netmaker's Access Controls can now target individual IPs inside of an egress range using the ip ACL target type. This enables you to limit access to specific IPs within an external network.
Simplified application-aware egress routing with a built-in catalogue of popular SaaS and cloud services.
Just-In-Time (JIT) access is a workflow within Netmaker where users request temporary access to the network, which is approved by administrators for a predefined time period. JIT access within Netmaker can now be scoped to user groups per network.
Netmaker provides audit logs of actions and events on the platform. Netmaker can now be integrated with certain providers to forward audit events to your security stack.
Enrollment keys are how devices join the network via Netclient. Administrators can now designate a default enrollment key for any network in order to simplify device onboarding.
This release introduces schema changes to the following core entities:
Impact:
👉 Action Required:
For detailed upgrade steps, refer to the official upgrade documentation:
Netclient registration UX — Host registration over OAuth/basic auth now returns clear websocket close reasons on failure (auth errors, missing access, posture violations, and server errors).
User group management — Streamlined user role permissions and group updates, role-downgrade handling.
Orphan reference cleanup — Removes stale network references left behind after resource deletion.
Scalability & reliability — Optimised node status calculation, offline-status hooks, zombie/orphan node cleanup, and ACL cache race fixes.
API hardening — Auth rate limiting on REST endpoints and activity-log permission fixes.
Egress improvements — CIDR validation for ACL egress IPs, multi-domain egress routing, and domain-answer handling for preset-based egress.
Failover removed — Legacy per-node failover APIs and CLI commands have been removed in favour of gateway-based patterns.
IPv6-only machines
Netclients cannot currently auto-upgrade on IPv6-only systems.
Multi-network join performance
Multi-network netclient joins using an enrollment key still require optimisation.
systemd-resolved DNS limitation
On systems using systemd-resolved in uplink mode, only the first 3 entries in resolv.conf are honoured; additional entries are ignored. This may cause DNS resolution issues. Stub mode is recommended.
Windows Desktop App + mixed gateway modes
When the Windows Desktop App is connected to both:
The gateway monitoring component may disconnect from the Split Tunnel Gateway.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Deprecated Legacy ACLs Legacy ACLs have been fully removed as part of the platform’s transition to the updated access control model.
These changes may impact existing deployments. Please review carefully before upgrading.
Legacy ACLs have been fully removed as part of the transition to the new access control model.
This release introduces schema changes to the following core entities:
For detailed upgrade steps, refer to the official upgrade documentation:
Traffic Logs have now moved into Beta.
Scalability & Reliability Improvements
Introduced a peer update debouncer that coalesces rapid-fire PublishPeerUpdate calls into a single broadcast — a 500ms resettable debounce window capped by a 3s max-wait deadline ensures back-to-back operations (bulk node updates, gateway changes, host deletions) produce one peer update instead of dozens, drastically reducing CPU and MQTT pressure on the control plane
Pre-warms peer update caches after each debounced broadcast so pull requests from hosts are served instantly from cache instead of triggering expensive on-demand computation
Batched metrics export to netmaker exporter via periodic ticker instead of publishing on every individual MQTT metrics message, reducing continuous CPU pressure from Prometheus scraping
Database Schema Migration
Added schema migrations for the Users, Groups, Roles, Networks, and Hosts tables.
Deprecated Legacy ACLs
Legacy ACLs have been fully removed as part of the platform’s transition to the updated access control model.
Paginated APIs
Introduced pagination support for Users and Hosts APIs.
DNS
Added native Active Directory support.
Posture Checks
Nodes can now skip the auto-update check during join, improving join reliability in controlled environments.
IDP Sync
Improved identity provider sync behavior:
HA Setup
Streamlined high availability (HA) setup and operational workflows.
Install Script
Added on-demand Monitoring Stack installation support via:
./nm-quick.sh -m
Monitoring Stack
Updated the monitoring stack to use the official Prometheus and Grafana images.
HA Gateways
Reset Auto Assigned gw when it is disconnected from the network.
IPv6-only machines
Netclients cannot currently auto-upgrade on IPv6-only systems.
Multi-network join performance
Multi-network netclient joins using an enrollment key still require optimization.
systemd-resolved DNS limitation
On systems using systemd-resolved in uplink mode, only the first 3 entries in resolv.conf are honored; additional entries are ignored. This may cause DNS resolution issues. Stub mode is recommended.
Windows Desktop App + mixed gateway modes
When the Windows Desktop App is connected to both:
the gateway monitoring component may disconnect from the Split Tunnel Gateway.
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →