LoadoutHQ v1.2.4
Status: Upcoming
Released: 2026-08-17
Highlights
- Fixed browser session authentication when HTTPS is terminated by a trusted reverse proxy.
Upgrade notes
- Pin the chart and both application images to
1.2.4in the release declaration. - For an Ingress, Gateway, or reverse-proxy deployment, set
config.trustedProxyHopsto the number of direct proxy hops between TLS termination and the API. Standard Helm and Docker Compose deployments use1. - After upgrading, sign in and confirm that the login response creates a
Secure,HttpOnlysession cookie before exercising protected API routes.
Configuration and breaking changes
- Added
config.trustedProxyHops, exposed to the API asTRUST_PROXY_HOPS. It defaults to1in Helm and Docker Compose production layouts, and to0for direct/local API use.
Known issues
- This release remains Upcoming until the versioned image and chart artifacts are published and verified.
Rollback considerations
- Rolling back to an earlier version reintroduces the session-cookie issue behind a TLS-terminating proxy. Existing session records remain compatible, but users may need to sign in again after the upgrade.