release.md
Run multiple customer environments from a single Netmaker server.
nmctl select the target org/tenant via X-Organization-ID / X-Tenant-ID (--org_id / --tenant_id), with nmctl organization list and nmctl tenant list for discovery.Gateways can publish a TCP/WSS uplink so clients can reach the mesh in restrictive environments when UDP is blocked.
tcp_proxy_enabled and related listen/TLS settings).Connect endpoint detection and response platforms for posture checks from Integrations.
/api/v1/integrations/edr/{provider}).Connect mobile device management platforms for device compliance posture from Integrations.
/api/v1/integrations/mdm/{provider}).This release completes the SQL schema path and introduces multi-tenancy (org/tenant) bootstrap as part of the v1.7.0 migration.
Upgrade requirement (existing deployments):
migration-v1.6.0 has not completed on a prior v1.6.0 deployment.Impact:
π Action Required:
For detailed upgrade steps, refer to the official upgrade documentation:
Auto-relay peer reset β Reset a specific peer-to-peer connection that is using a relay (clear/reassign auto-relay for that peer pair) without resetting the entire networkβs auto-relay state.
Migration reliability β v1.7.0 blocks startup until v1.6.0 migration completed on existing deployments; migration failures exit cleanly instead of panicking.
Host status β Host filtering uses live check-in status (Online/Offline/Disconnected) rather than a stale DB value.
MSP installs β nm-quick.sh -s flag to skip nmctl/mesh/netclient on MSP server installs.
IPv6-only machines
Netclients cannot currently auto-upgrade on IPv6-only systems.
Multi-network join performance
Multi-network netclient joins using an enrollment key still require optimization.
systemd-resolved DNS limitation
On systems using systemd-resolved in uplink mode, only the first 3 entries in resolv.conf are honored; additional entries are ignored. This may cause DNS resolution issues. Stub mode is recommended.
Windows Desktop App + mixed gateway modes
When the Windows Desktop App is connected to both:
the gateway monitoring component may disconnect from the Split Tunnel Gateway.