Skip to main content

v26.08

Knocknoc 26.08 is a focused release. It adds Fastly ACL and native nftables enforcement, improves Palo Alto visibility, improves administratorssharpens operational diagnostics,diagnostics for administrators, and resolvesclears up smaller user user-experience issues. In August muchMuch of the team werespent inAugust Las Vegas forat Black Hat, BSides and DEFCON,DEFCON in Las Vegas while work continued on several larger product improvementschanges in the background. 26.09 is taking shape behind the scenes, with several larger changes lining up,shape, and we look forward to sharing themit soon!
soon.

What's new

    Fastly ACL Supportsupport.

    Knocknoc can now grantGrant and revoke access at the Fastly edge by managing IP entries in an existing Fastly ACL, applied to the live service version at once. Fastly guide

    Native nftables enforcement. Manage native nftables named sets as a Linux backend, a modern alternative to IPSet, with IPv4 and IPv6 support. nftables guide Clearer Palo Alto and Panorama diagnostics. Operator-issued grants are attributed in Panorama, and PAN-OS errors now name the actual cause.

    Plus admin quality-of-life improvements, dependency updates and reliability fixes.

    Fastly ACL support

    Grant and revoke access at the Fastly edge by managing IP entries in an existing Fastly ACL. Changes apply to the active service version immediately, withoutwith publishing ano new service version orto hostingpublish aand no separate IP feed.
    feed to host.

    nftables support uplift

    enforcement

    Knocknoc can now manageManage native nftables named sets as a Linux enforcement backend. This providesbackend, a modern alternative to IPSet on current Linuxsystems, systems and supportswith both IPv4 and IPv6 access.
    The setup experienceSetup includes discovered-set suggestions, inline validation, connection testing, and guidance for common configuration problems. The agent can also provision default sets and run on nftables-only hosts without requiring IPSet.

    Admin and user experience

    quality-of-life
    • Post-login waiting-room redirectsredirects.: eachEach Knoc can wait for access to become active before automatically sending the user to its destination,destination. whilst thisThis is typicallyusually 30ms-30 to 200ms depending on the control layer, and some slower backends benefit from this being configured.it.
    • Faster admin filteringfiltering.: searchSearch controls now sit directly above the tables they filter. The Knocs and API keys pages also includeadd filters for their most useful operational fields, and filter state is retainedkept in the page URL.
    • Rejected agent diagnosticsdiagnostics.: theThe Agents page now records connection attempts the server rejects, explains the likely cause and next step, and lets administratorsyou copy or mute each diagnosticone instead of searching throughthe repeated log entries.logs.
    • Session managementmanagement.: endEnd all active sessions for a specific user or administrator directly from their identity page, without ending the current administrator'syour own session.
    • Network contextcontext.: hover overHover or tap the current IP address after login to see its country, continent, ASN, network owner,owner and domain. Private addresses are identified separately.
    • Inactive-user reviewreview.: theThe Identities page highlights local users who have never signed in or have not signed in for 90 days, with new activity and expiry filters tofor help administrators reviewreviewing stale access.
    • Knoc icons are now shown in the table. The admin Knocs table,table now shows Knoc icons, making largerlonger lists easier to scan.

    Palo Alto and Panorama improvements

    • Manual Adminadmin grants nowattributed. attributed: accessAccess granted manually by an administrator is marked in Panorama's User-ID table as the operating admin, making it easier to distinguishso operator-issued access is easy to tell from a normal user grants.grant.
    • More useful diagnosticsdiagnostics.: PAN-OS configuration errors now distinguish missing permissions, invalid virtual systems, disconnected Panorama targets, capacity limits, busy devices,devices and timeouts.

    Reliability, security and maintenance

    • VariousDependency libraries have been updated,updates, including Golang.
    • HAProxy backend events are handled and reported more reliably.

    How do I upgrade?

    Upgrade the Knocknoc Server and Agents through your operating system's package manager as usual. See the updates and upgrades guide for instructions.
    .

    ReleaseReleased date: 31st31 August 20262026.