Another quarter, another checkpoint on the NethServer 8 journey: we’re happy to announce milestone 8.10! This cycle we focused on:
- delivering the long-awaited Mail improvements
- turning finished UX designs into new cluster-admin pages
- giving more visibility into CrowdSec protection
- laying the groundwork for single sign-on
- core and application updates
Enhancements
Here are the highlights introduced since milestone 8.9.
The full list is available in the release notes for milestone 8.10.
Turn off automatic updates from the Software Center
With an active subscription, applications are updated automatically overnight. You can now switch this off from the Software Center, for the whole cluster or for single applications, without command-line procedures. Applications left out are marked with an Updates disabled tag and can still be updated by hand.
New TLS certificates settings
The TLS certificates page has a new ACME settings tab. Besides the certificate authority address, it lets you choose how each node proves domain ownership to Let’s Encrypt: through port 443 (the default TLS-ALPN-01 challenge) or through the legacy port 80 (HTTP-01 challenge).
Frontend proxies
If your NethServer sits behind a reverse proxy, a load balancer, or a CDN, the new Frontend proxies tab of the HTTP routes page tells it which proxies to trust, so it can see the real address of visitors. Previously this was possible only with API calls.
New Grafana dashboards
Two new Grafana dashboards are available with the Metrics application:
Containersshows the CPU, memory, and disk space used by each application, so you can quickly find out what is keeping a node busy or filling its disk. Disk usage is refreshed once a day.CrowdSec Bansshows the history of blocked attackers over the whole log retention period (one year by default): a world map, bans over time, top countries, providers, attack types, and the IP addresses that keep coming back.
Smarter System logs search
The System logs page can now search with regular expressions, and errors and warnings stand out with colors, so problems are easier to spot at a glance. Thanks to @pagaille for the contribution ![]()
CrowdSec: see what’s going on
New CrowdSec pages show what was previously visible only from the command line:
Detections: the history of suspicious activities, with source and detailsCollections: turn detection for each service on or offBlocklists: local and community blocklists, and the allowlist, in one place
CrowdSec can also protect NethVoice against password-guessing attacks on phones and web applications, and its ban history is now available in Grafana, as described above.
Clusters with an active subscription will also get a new Threat Shield page. Stay tuned: we’ll share more about it in a dedicated announcement soon!
Phone extension for users
Users have a new Phone extension field, which can be set from cluster-admin and from the User Management portal.
Mail: alias addresses from the user domain
A new mail domain option turns the mail attribute of each user into an extra email address for that user, which also works as a sender address.
New subscription portal
The new portal for Enterprise subscription customers is online at https://beta.my.nethesis.it. It provides monitoring, alerts, and inventory for clusters running Core 3.23 or later.
- New clusters: first update the core to the latest version, then get the subscription token from the new portal and paste it in the
Subscriptionpage. - Already registered clusters: no action is needed. They connect to the new portal automatically once updated to Core 3.23 or later.
Other changes
Core
- Pages load faster on clusters without internet access.
- Tables remember your
Items per pagechoice. - The installer no longer accepts Debian 12, as announced in milestone 8.8.
- Forwarding to external addresses finally works reliably: forwarded messages are no longer rejected as forged by the destination server.
- The antivirus
Third-party signatures ratingsetting is now applied. - Logins with Active Directory are more reliable and fill the logs with less noise.
Webmail and WebTop
- Roundcube creates the
DraftsandSentfolders at the first login. - WebTop is updated to 5.35.7, and Thunderbird now configures mail accounts with fully encrypted connections from the start.
Piler mail archive
- Piler now runs on our own container image, so we can ship security updates faster and test each new Piler release before it reaches you.
- The container runs with fewer privileges, and Piler logs are now visible in the
System logspage. - Importing mail from an IMAP account works again.
- The service is more robust: it no longer keeps running half broken, and mail still queued is archived before it stops.
Other applications
- Dependency-Track moves to version 5. Existing installations need a manual upgrade.
- Loki and Nextcloud updates.
Bug fixes
20+ bugs have been addressed across core components and applications to improve stability and reliability. Here is a brief list:
- Samba: syslog-ng disk buffers accumulate after container recreation · Issue #8132 · NethServer/dev · GitHub
- Nextcloud stuck in maintenance mode: nextcloud-app starts before Redis has loaded its AOF · Issue #8149 · NethServer/dev · GitHub
- Mail 1.9.0: postfix container crashloops if the user domain name contains an underscore · Issue #8196 · NethServer/dev · GitHub
The full list is available on our GitHub issue tracker.
Roadmap
The single sign-on (SSO) goal of the previous milestone produced its first result: the developer documentation now describes how NS8 identity provider applications plug into the system. Consider it an open working draft. Its reference implementation, the new ns8-idp application, is already under development (alpha).
Besides open issues, with priority to the backup ones, the next goals are:
- Single sign-on for Nextcloud, Roundcube, Mail, NethVoice, and WebTop, with the new ns8-idp application
- Moving application data to an additional volume after the application is installed, with the
volumectlcommand - Dovecot 2.4 for the Mail application, including the migration of existing mail servers
We’ll also start the UI design of:
- Operating system updates and scheduled node reboots, important for kernel security fixes and Rocky Linux minor updates
- Let’s Encrypt DNS challenge, which is much slower than the current methods and may need a different workflow
- Application-specific alerts, and how to display them
Follow the roadmap on our project page.
Join the NS8 community
Your participation helps shape the direction of the project:
- Join the forum discussions using the tag ns8
- Share feedback, report bugs, and propose improvements
- Contribute translations on Weblate
Thanks for being part of the journey — together we’re building the future of NethServer.
The NethServer Team




















