# Uncategorized

**URL:** https://openziti.discourse.group/c/uncategorized/1.md

[Latest](https://openziti.discourse.group/latest.md) · [Categories](https://openziti.discourse.group/categories.md)

---

## [Welcome to OpenZiti's Community!](https://openziti.discourse.group/t/welcome-to-openzitis-community/7)

<div class="topic-metadata">

**Author:** [@system](https://openziti.discourse.group/u/system)\
**Replies:** 6\
**Last updated:** [February 14, 2023, 3:26am UTC](https://openziti.discourse.group/t/welcome-to-openzitis-community/7 "2023-02-14T03:26:03Z")

</div>

OpenZiti was created and is actively maintained by NetFoundry Inc. This community represents our continued dedication to open source software. We have worked hard to create a secure, zero trust overlay network, and we wa…

---

## [Stale 429 Rate Limit Error on Share Creation (Account Reset Needed)](https://openziti.discourse.group/t/stale-429-rate-limit-error-on-share-creation-account-reset-needed/6163)

<div class="topic-metadata">

**Author:** [@vtseno](https://openziti.discourse.group/u/vtseno)\
**Replies:** 1\
**Last updated:** [October 5, 2026, 3:08pm UTC](https://openziti.discourse.group/t/stale-429-rate-limit-error-on-share-creation-account-reset-needed/6163 "2026-10-05T15:08:30Z")

</div>

My zrok account is completely locked out from creating shares due to a persistent rate limit error that has lasted for several days. When attempting to create a share for my environment using zrok2 share, it consistentl…

---

## [Zrok.io Account Issue(?)](https://openziti.discourse.group/t/zrok-io-account-issue/6161)

<div class="topic-metadata">

**Author:** [@tenuto886](https://openziti.discourse.group/u/tenuto886)\
**Replies:** 2\
**Last updated:** [October 5, 2026, 3:06pm UTC](https://openziti.discourse.group/t/zrok-io-account-issue/6161 "2026-10-05T15:06:18Z")

</div>

Hosted zrok.io account issue: zrok2 share public consistently returns HTTP 429. Client: zrok2 v2.0.7 \[79300f73\] zrok2 create name munkee-tenuto886 succeeds, but: zrok2 share public http://127.0.0.1:8771 --name-selecti…

---

## [One client with wrong clock caused whole network down](https://openziti.discourse.group/t/one-client-with-wrong-clock-caused-whole-network-down/6158)

<div class="topic-metadata">

**Author:** [@AlexZ](https://openziti.discourse.group/u/AlexZ)\
**Replies:** 5\
**Last updated:** [October 2, 2026, 1:46pm UTC](https://openziti.discourse.group/t/one-client-with-wrong-clock-caused-whole-network-down/6158 "2026-10-02T13:46:16Z")

</div>

Short summary before the long read: A windows client with a bad clock, trying to recconnect too often( about 40 times per second ) which causing api sessions number to raise and cleanup locking bbolt database, which in…

---

## [JWT Signer in ziti 2.0](https://openziti.discourse.group/t/jwt-signer-in-ziti-2-0/6148)

<div class="topic-metadata">

**Author:** [@montwepa](https://openziti.discourse.group/u/montwepa)\
**Replies:** 3\
**Last updated:** [October 1, 2026, 12:01pm UTC](https://openziti.discourse.group/t/jwt-signer-in-ziti-2-0/6148 "2026-10-01T12:01:01Z")

</div>

Hey guys, I experimented with "Add Identity by URL" about a year ago and came back to it now. I noticed there are now some new Auto Enrollment options in ZAC under JWT Signers, but I haven't been able to find much docum…

---

## [Request to remove two old Dlux Karaoke environments](https://openziti.discourse.group/t/request-to-remove-two-old-dlux-karaoke-environments/6133)

<div class="topic-metadata">

**Author:** [@kismer\_tkm](https://openziti.discourse.group/u/kismer_tkm)\
**Replies:** 2\
**Last updated:** [September 30, 2026, 7:20pm UTC](https://openziti.discourse.group/t/request-to-remove-two-old-dlux-karaoke-environments/6133 "2026-09-30T19:20:45Z")

</div>

Hello, could your team manually remove these old resources from my account on https://api-v1.zrok.io? Environment xKdqMW.7I — share dluxkaraoke12 Environment Y0kADe67jK — share dluxkaraoke345 Releasing dluxkaraoke345 …

---

## [Unauthorized api after 15 minutes after upgrading openziti/quickstart to 2.0.0](https://openziti.discourse.group/t/unauthorized-api-after-15-minutes-after-upgrading-openziti-quickstart-to-2-0-0/6036)

<div class="topic-metadata">

**Author:** [@CarlosHleb](https://openziti.discourse.group/u/CarlosHleb)\
**Replies:** 11\
**Last updated:** [September 25, 2026, 4:09am UTC](https://openziti.discourse.group/t/unauthorized-api-after-15-minutes-after-upgrading-openziti-quickstart-to-2-0-0/6036 "2026-09-25T04:09:05Z")

</div>

After updating openziti/quickstart docker image to 2.0.0. my keep-alive requests dont work anymore. when i start my api, i can create admins(on create it creates openziti identity for that admin). after 10-15 minutes i …

---

## [Ziti login -f admin1@gmail.com.json returns unAuthorized](https://openziti.discourse.group/t/ziti-login-f-admin1-gmail-com-json-returns-unauthorized/6087)

<div class="topic-metadata">

**Author:** [@CarlosHleb](https://openziti.discourse.group/u/CarlosHleb)\
**Replies:** 4\
**Last updated:** [September 25, 2026, 3:05am UTC](https://openziti.discourse.group/t/ziti-login-f-admin1-gmail-com-json-returns-unauthorized/6087 "2026-09-25T03:05:42Z")

</div>

i am running openziti/quickstart v2.0.0. when i exec inside ziti-controller and do zitiLogin(logs me in as default admin, username/password auth), i can list identities with ziti edge list identities and it works. when…

---

## [How does LE certs work for Ziti Controller V2+?](https://openziti.discourse.group/t/how-does-le-certs-work-for-ziti-controller-v2/6088)

<div class="topic-metadata">

**Author:** [@Dodo](https://openziti.discourse.group/u/Dodo)\
**Replies:** 3\
**Last updated:** [September 16, 2026, 12:47am UTC](https://openziti.discourse.group/t/how-does-le-certs-work-for-ziti-controller-v2/6088 "2026-09-16T00:47:49Z")

</div>

Hello OpenZiti Team! I noticed that my alt\_server\_certs no longer work for ziti controller v2.03. Is there a way to do this? While I have tested using an identity block to setup LE certs under web section, I noticed th…

---

## [Docker ziti-edge-tunnel Allow intercepts WITHOUT Docker network\_mode: host](https://openziti.discourse.group/t/docker-ziti-edge-tunnel-allow-intercepts-without-docker-network-mode-host/2802)

<div class="topic-metadata">

**Author:** [@dmuensterer](https://openziti.discourse.group/u/dmuensterer)\
**Replies:** 15\
**Last updated:** [September 11, 2026, 11:00am UTC](https://openziti.discourse.group/t/docker-ziti-edge-tunnel-allow-intercepts-without-docker-network-mode-host/2802 "2026-09-11T11:00:41Z")

</div>

Hi there, I am looking for a way to deploy ziti-edge-tunnel's as Docker containers being able to intercept without using network\_mode: host. I need to use docker internal networking as I need the ziti-edge-tunnel being…

---

## [\[ERROR\]: unable to create share (unable to create share: \[POST /share\]\[500\] shareInternalServerError "")](https://openziti.discourse.group/t/error-unable-to-create-share-unable-to-create-share-post-share-500-shareinternalservererror/5719)

<div class="topic-metadata">

**Author:** [@ma7555](https://openziti.discourse.group/u/ma7555)\
**Replies:** 11\
**Last updated:** [September 9, 2026, 9:03am UTC](https://openziti.discourse.group/t/error-unable-to-create-share-unable-to-create-share-post-share-500-shareinternalservererror/5719 "2026-09-09T09:03:57Z")

</div>

I was running a public share with reserved name. The docker restarted and i can’t get the same share to run again. Even tried with normal cli instead of docker. It is always the same error. zrok2 share public localhost:…

---

## [Removing Stale Environments](https://openziti.discourse.group/t/removing-stale-environments/6042)

<div class="topic-metadata">

**Author:** [@JT\_Valhalla](https://openziti.discourse.group/u/JT_Valhalla)\
**Replies:** 1\
**Last updated:** [September 5, 2026, 10:18pm UTC](https://openziti.discourse.group/t/removing-stale-environments/6042 "2026-09-05T22:18:56Z")

</div>

Hello, I'm a new user and I believe I've created three stale environments. My account is now limited so I can't do anything. Could you release the environments for me? The account name is johnt@valhalla-systems.com I'm…

---

## [ZDEW 2.9.7.2 / 2.11.3.0: OIDC login via external Keycloak fails with 404/405 at "Controller authentication" — works on 2.9.7.1 (controller 2.1.0-pre1)](https://openziti.discourse.group/t/zdew-2-9-7-2-2-11-3-0-oidc-login-via-external-keycloak-fails-with-404-405-at-controller-authentication-works-on-2-9-7-1-controller-2-1-0-pre1/6034)

<div class="topic-metadata">

**Author:** [@humter86](https://openziti.discourse.group/u/humter86)\
**Replies:** 1\
**Last updated:** [September 3, 2026, 5:20pm UTC](https://openziti.discourse.group/t/zdew-2-9-7-2-2-11-3-0-oidc-login-via-external-keycloak-fails-with-404-405-at-controller-authentication-works-on-2-9-7-1-controller-2-1-0-pre1/6034 "2026-09-03T17:20:30Z")

</div>

Hello OpenZiti team, First of all, thank you for the great project — we have been running OpenZiti in production for several services and appreciate the stability and design of the overlay. We are writing to report a re…

---

## [Hosted zrok2 enable returning 500 / cannot release shares in API console](https://openziti.discourse.group/t/hosted-zrok2-enable-returning-500-cannot-release-shares-in-api-console/6028)

<div class="topic-metadata">

**Author:** [@steevejfr](https://openziti.discourse.group/u/steevejfr)\
**Replies:** 2\
**Last updated:** [September 1, 2026, 7:26am UTC](https://openziti.discourse.group/t/hosted-zrok2-enable-returning-500-cannot-release-shares-in-api-console/6028 "2026-09-01T07:26:39Z")

</div>

Hello, I'm using the hosted zrok service (api-v2.zrok.io) with zrok2 v2.0.4 on Windows 11. My environment is currently stuck and I'm unable to enable or release anything. Symptom 1 — zrok2 enable fails: Running zrok2 e…

---

## [HA not working as expected with ext-jwt signer (without JIT enrollment)](https://openziti.discourse.group/t/ha-not-working-as-expected-with-ext-jwt-signer-without-jit-enrollment/5812)

<div class="topic-metadata">

**Author:** [@marratj](https://openziti.discourse.group/u/marratj)\
**Replies:** 32\
**Last updated:** [August 28, 2026, 6:44am UTC](https://openziti.discourse.group/t/ha-not-working-as-expected-with-ext-jwt-signer-without-jit-enrollment/5812 "2026-08-28T06:44:40Z")

</div>

I have an 2.0.0-pre12 setup that is configured to use a local Keycloak instance as an external JWT signer without JIT enrollment of external identities. This means I'm pre-creating the identities for users in Ziti with t…

---

## [Ziti Edge Desktop For Windows Disable PROXY](https://openziti.discourse.group/t/ziti-edge-desktop-for-windows-disable-proxy/6012)

<div class="topic-metadata">

**Author:** [@cao](https://openziti.discourse.group/u/cao)\
**Replies:** 2\
**Last updated:** [August 24, 2026, 3:09pm UTC](https://openziti.discourse.group/t/ziti-edge-desktop-for-windows-disable-proxy/6012 "2026-08-24T15:09:35Z")

</div>

I'm using Ziti Edge Desktop for Windows 2.9.5, it works well in my sandbox environment. When I testing ZEDW in a corporate network, it failed to connect to Ziti Controller and Router, after a little bit troubleshooting,…

---

## [Domain Posture Check Failure](https://openziti.discourse.group/t/domain-posture-check-failure/5979)

<div class="topic-metadata">

**Author:** [@cao](https://openziti.discourse.group/u/cao)\
**Replies:** 5\
**Last updated:** [August 7, 2026, 6:59am UTC](https://openziti.discourse.group/t/domain-posture-check-failure/5979 "2026-08-07T06:59:23Z")

</div>

I'm running windows Edge Client 2.9.5 to access OpenZiti Overlay Network, it works well. I try to create a Posture Check OS System Check, it works well. I try to create a Posture Check with Domain check, BUT it doesn't…

---

## [Yo....just sayin Hi to the NF team](https://openziti.discourse.group/t/yo-just-sayin-hi-to-the-nf-team/5988)

<div class="topic-metadata">

**Author:** [@ojbfive](https://openziti.discourse.group/u/ojbfive)\
**Replies:** 1\
**Last updated:** [August 6, 2026, 1:59pm UTC](https://openziti.discourse.group/t/yo-just-sayin-hi-to-the-nf-team/5988 "2026-08-06T13:59:16Z")

</div>

Hey gang....I still got it after 3 years, using OZ 2.0 for multi cloud mgt with Ubuntu VM's.

---

## [\[Question\] BrowZer production-readiness — evaluating for GKE deployment](https://openziti.discourse.group/t/question-browzer-production-readiness-evaluating-for-gke-deployment/5943)

<div class="topic-metadata">

**Author:** [@ss\_vinoth22](https://openziti.discourse.group/u/ss_vinoth22)\
**Replies:** 1\
**Last updated:** [July 20, 2026, 2:45pm UTC](https://openziti.discourse.group/t/question-browzer-production-readiness-evaluating-for-gke-deployment/5943 "2026-07-20T14:45:39Z")

</div>

Environment Controller version: 1.1.15 Deployment: GKE (Google Kubernetes Engine) Client fleet: 35+ clients total, including 17+ Linux edge-tunnel (ZET) IoT devices Summary Evaluating BrowZer as a clientless alternativ…

---

## [\[Question/Docs\] Using a same-version DR restore as an upgrade test environment (1.1.15 → current), GKE-hosted](https://openziti.discourse.group/t/question-docs-using-a-same-version-dr-restore-as-an-upgrade-test-environment-1-1-15-current-gke-hosted/5942)

<div class="topic-metadata">

**Author:** [@ss\_vinoth22](https://openziti.discourse.group/u/ss_vinoth22)\
**Replies:** 0\
**Last updated:** [July 12, 2026, 10:07am UTC](https://openziti.discourse.group/t/question-docs-using-a-same-version-dr-restore-as-an-upgrade-test-environment-1-1-15-current-gke-hosted/5942 "2026-07-12T10:07:51Z")

</div>

Environment Controller version: 1.1.15 Deployment: GKE (Google Kubernetes Engine) Topology: single (non-HA) controller Client fleet: 35+ clients total, including 17+ Linux edge-tunnel (ZET) IoT devices Summary We want …

---

## [Network interruption causes ziti-tunnel to fail to recover](https://openziti.discourse.group/t/network-interruption-causes-ziti-tunnel-to-fail-to-recover/5928)

<div class="topic-metadata">

**Author:** [@maika](https://openziti.discourse.group/u/maika)\
**Replies:** 5\
**Last updated:** [July 7, 2026, 11:45am UTC](https://openziti.discourse.group/t/network-interruption-causes-ziti-tunnel-to-fail-to-recover/5928 "2026-07-07T11:45:06Z")

</div>

Hello, I am encountering an issue when using ziti-tunnel. After a network interruption and when the network returns to normal, the ziti network fails to recover for unused service. This type of network interruption may…

---

## [Upgrade 1.1.15 -\> 1.6.3](https://openziti.discourse.group/t/upgrade-1-1-15-1-6-3/4784)

<div class="topic-metadata">

**Author:** [@ZzenlD](https://openziti.discourse.group/u/ZzenlD)\
**Replies:** 23\
**Last updated:** [July 4, 2026, 4:34am UTC](https://openziti.discourse.group/t/upgrade-1-1-15-1-6-3/4784 "2026-07-04T04:34:49Z")

</div>

Hello everyone, I am currently trying to upgrade from version 1.1.15 to 1.6.3. After adding trustDomain to my controller-config, all connections are working again. However, I have moved the ZAC to a separate port, the …

---

## [The apiAddresses of the Controller do not appear](https://openziti.discourse.group/t/the-apiaddresses-of-the-controller-do-not-appear/5922)

<div class="topic-metadata">

**Author:** [@maika](https://openziti.discourse.group/u/maika)\
**Replies:** 4\
**Last updated:** [July 1, 2026, 3:49pm UTC](https://openziti.discourse.group/t/the-apiaddresses-of-the-controller-do-not-appear/5922 "2026-07-01T15:49:20Z")

</div>

Hello, I installed OpenZiti 2.0. When adding a new Controller to a cluster, I commented out - binding: edge-management and its corresponding options: { } because I didn't want edge-management to be exposed to the public…

---

## [Force enable MFA, but it doesn’t work](https://openziti.discourse.group/t/force-enable-mfa-but-it-doesn-t-work/5792)

<div class="topic-metadata">

**Author:** [@maika](https://openziti.discourse.group/u/maika)\
**Replies:** 4\
**Last updated:** [June 30, 2026, 12:58am UTC](https://openziti.discourse.group/t/force-enable-mfa-but-it-doesn-t-work/5792 "2026-06-30T00:58:07Z")

</div>

Hello, I created a new Auth Policy in the Console and enabled TOTP MFA for Secondary Authentication in this policy. I then set this Auth Policy for an Identity. However, after I joined this Identity using Ziti Desktop E…

---

## [Replace traditional VPN with OpenZiti, and few additional questions?](https://openziti.discourse.group/t/replace-traditional-vpn-with-openziti-and-few-additional-questions/5888)

<div class="topic-metadata">

**Author:** [@Idriel](https://openziti.discourse.group/u/Idriel)\
**Replies:** 5\
**Last updated:** [June 12, 2026, 8:30am UTC](https://openziti.discourse.group/t/replace-traditional-vpn-with-openziti-and-few-additional-questions/5888 "2026-06-12T08:30:16Z")

</div>

Hi, i was going through docs and youtube movies but I cannot create a clear picture for VPN like access, has anyone replaced a traditional VPN with OpenZiti and gained better usability along with improved security? It s…

---

## [OpenZiti SpringBoot Version Upgrade Exception](https://openziti.discourse.group/t/openziti-springboot-version-upgrade-exception/5875)

<div class="topic-metadata">

**Author:** [@Juggernaut](https://openziti.discourse.group/u/Juggernaut)\
**Replies:** 5\
**Last updated:** [June 5, 2026, 8:30am UTC](https://openziti.discourse.group/t/openziti-springboot-version-upgrade-exception/5875 "2026-06-05T08:30:55Z")

</div>

Hi everyone，I deployed an OpenZiti SDN environment following the official guide, and completed configuration for Identities, Services and other relevant components. Afterwards, I built a simple project referencing the m…

---

## [Zac Authentication cant verify](https://openziti.discourse.group/t/zac-authentication-cant-verify/5877)

<div class="topic-metadata">

**Author:** [@McGonagall666](https://openziti.discourse.group/u/McGonagall666)\
**Replies:** 2\
**Last updated:** [June 4, 2026, 2:30pm UTC](https://openziti.discourse.group/t/zac-authentication-cant-verify/5877 "2026-06-04T14:30:06Z")

</div>

---

## [Can't Install OpenZiti2.0](https://openziti.discourse.group/t/cant-install-openziti2-0/5854)

<div class="topic-metadata">

**Author:** [@maika](https://openziti.discourse.group/u/maika)\
**Replies:** 4\
**Last updated:** [May 28, 2026, 2:15am UTC](https://openziti.discourse.group/t/cant-install-openziti2-0/5854 "2026-05-28T02:15:28Z")

</div>

Hello, I followed the instructions in OpenZiti 2.x to install, but the installed version is still v1.6.15. Please help me take a look

---

## [Zssh - SSH Identity Management Through OpenZiti](https://openziti.discourse.group/t/zssh-ssh-identity-management-through-openziti/5842)

<div class="topic-metadata">

**Author:** [@dmuensterer](https://openziti.discourse.group/u/dmuensterer)\
**Replies:** 5\
**Last updated:** [May 22, 2026, 4:49pm UTC](https://openziti.discourse.group/t/zssh-ssh-identity-management-through-openziti/5842 "2026-05-22T16:49:40Z")

</div>

Hi all, we've been using zssh for zero-trust SSH and really like how it works. One thing that bugs us is the disconnect between Ziti identity management and SSH authentication. Right now, Ziti handles the network layer …

---

## [Router fails to fire re-establishing hosted services after most controller raft leader changes, causing chronic terminator state drift](https://openziti.discourse.group/t/router-fails-to-fire-re-establishing-hosted-services-after-most-controller-raft-leader-changes-causing-chronic-terminator-state-drift/5830)

<div class="topic-metadata">

**Author:** [@msbusk](https://openziti.discourse.group/u/msbusk)\
**Replies:** 2\
**Last updated:** [May 19, 2026, 6:21pm UTC](https://openziti.discourse.group/t/router-fails-to-fire-re-establishing-hosted-services-after-most-controller-raft-leader-changes-causing-chronic-terminator-state-drift/5830 "2026-05-19T18:21:28Z")

</div>

raft leader changes do not consistently trigger the router's HostedServiceRegistry.HandleReestablish path. The router's hosted-terminator view silently drifts from the controller's view until a user-facing failure surfac…

[Next page](https://openziti.discourse.group/c/uncategorized/1.md?page=1)
