Skip to main content

LoadoutHQ v1.2.4

Status: Upcoming

Released: 2026-08-17

Highlights​

  • Fixed browser session authentication when HTTPS is terminated by a trusted reverse proxy.

Upgrade notes​

  • Pin the chart and both application images to 1.2.4 in the release declaration.
  • For an Ingress, Gateway, or reverse-proxy deployment, set config.trustedProxyHops to the number of direct proxy hops between TLS termination and the API. Standard Helm and Docker Compose deployments use 1.
  • After upgrading, sign in and confirm that the login response creates a Secure, HttpOnly session cookie before exercising protected API routes.

Configuration and breaking changes​

  • Added config.trustedProxyHops, exposed to the API as TRUST_PROXY_HOPS. It defaults to 1 in Helm and Docker Compose production layouts, and to 0 for direct/local API use.

Known issues​

  • This release remains Upcoming until the versioned image and chart artifacts are published and verified.

Rollback considerations​

  • Rolling back to an earlier version reintroduces the session-cookie issue behind a TLS-terminating proxy. Existing session records remain compatible, but users may need to sign in again after the upgrade.