2.22.2 release notes

July 17, 2026

NGINX Instance Manager 2.22.2 release notes

Upgrade Paths

NGINX Instance Manager 2.22.2 supports upgrades from these previous versions:

  • 2.19.0 - 2.22.1

If your NGINX Instance Manager version is older, you may need to upgrade to an intermediate version before upgrading to the target version.

Changes in default behavior

This release has the following changes in default behavior:

  • Warm-sync SSH host key handling

    This release changes warm-sync SSH host key handling.

    • Warm-sync now uses Trust On First Use, or TOFU, for SSH host key verification.
    • The script now replaces StrictHostKeyChecking=no with StrictHostKeyChecking=accept-new.
    • The script also removes UserKnownHostsFile=/dev/null so SSH can store host keys for later checks.
    • If a target host key changes, the next warm-sync run fails with Host key verification failed.

    Previously, warm-sync accepted SSH connections without host key validation. That behavior is no longer allowed.

    Warm-sync SSH options

    Previously:

    SSH_OPTS="-q -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no -o LogLevel=ERROR"

    Now:

    SSH_OPTS="-q -o StrictHostKeyChecking=accept-new -o LogLevel=ERROR"

    This change affects HA node synchronization. If a failover happens before you update a rotated host key, cluster nodes can fall out of sync.

  • TLS 1.1 support removed

    TLS 1.1 is no longer supported in this release. All TLS connections to and from the NGINX Management Suite API Gateway now require TLS 1.2 or TLS 1.3.

    Connection Previous Now
    Inbound HTTPS from clients to the NGINX Management Suite API Gateway TLSv1.1, TLSv1.2 TLSv1.2, TLSv1.3
    Outbound proxy connections from the API Gateway to internal NGINX Instance Manager services in Kubernetes TLSv1.1, TLSv1.2 TLSv1.2, TLSv1.3
    Outbound gRPC connections from the API Gateway to internal NGINX Instance Manager services in Kubernetes TLSv1.1, TLSv1.2 TLSv1.2, TLSv1.3

    Who is affected

    • VM or package-based deployments

      TLS 1.1 is no longer accepted on the external HTTPS listener (listen 443 ssl) in /etc/nginx/conf.d/nms-http.conf. Any API client, browser, or NGINX Agent connecting to NGINX Instance Manager over TLS 1.1 will have its connection rejected.

    • Kubernetes deployments

      TLS 1.1 is no longer accepted on:

      • The external HTTPS listener (listen 8443 ssl) in nms-http.conf
      • Outbound proxy connections from the API Gateway to all internal NGINX Instance Manager backend services: core, DPM, ingestion, integrations, and secmon
      • Outbound gRPC connections from the API Gateway to ingestion and DPM services

    Action required

    If any of the following use TLS 1.1, update them to use TLS 1.2 or TLS 1.3 before upgrading:

    • API clients or scripts connecting to the NGINX Instance Manager REST API
    • Browsers used to access the NGINX Instance Manager UI
    • NGINX Agents connecting to NGINX Instance Manager via gRPC in Kubernetes deployments
    • Any load balancer or reverse proxy in front of NGINX Instance Manager that terminates TLS and re-negotiates with NGINX Instance Manager using TLS 1.1

    No configuration changes are required on the NGINX Instance Manager side. The updated protocol list is applied automatically upon upgrade.

Known issues

You can find information about known issues in the Known Issues topic.