# Latest

**URL:** https://openziti.discourse.group/latest.md?page=1

[Latest](https://openziti.discourse.group/latest.md) · [Categories](https://openziti.discourse.group/categories.md)

**Page:** 2

---

## [Request to Resolve Persistent "Visit Share" Interstitial Page (Credit Card Verified Account)](https://openziti.discourse.group/t/request-to-resolve-persistent-visit-share-interstitial-page-credit-card-verified-account/6073)

<div class="topic-metadata">

**Author:** [@cybereye](https://openziti.discourse.group/u/cybereye)\
**Replies:** 0\
**Last updated:** [September 10, 2026, 9:57am UTC](https://openziti.discourse.group/t/request-to-resolve-persistent-visit-share-interstitial-page-credit-card-verified-account/6073 "2026-09-10T09:57:19Z")

</div>

Hi, zrok Support Team, I have verified my account by adding a credit card to avoid the free tier limitations, but the interstitial warning ("Visit share") page continues to appear for my shares. Even after registering m…

---

## [Stuck legacy environment throwing 500 error on CLI](https://openziti.discourse.group/t/stuck-legacy-environment-throwing-500-error-on-cli/6072)

<div class="topic-metadata">

**Author:** [@qatester](https://openziti.discourse.group/u/qatester)\
**Replies:** 0\
**Last updated:** [September 10, 2026, 3:34am UTC](https://openziti.discourse.group/t/stuck-legacy-environment-throwing-500-error-on-cli/6072 "2026-09-10T03:34:45Z")

</div>

Hello, I have an old environment from a deleted VM that is stuck. I managed to fetch its environment zId using zrok2 list environments --json, but running the delete environment command returns a 500 internal server erro…

---

## [\[ERROR\]: unable to create share (unable to create share: \[POST /share\]\[500\] shareInternalServerError "")](https://openziti.discourse.group/t/error-unable-to-create-share-unable-to-create-share-post-share-500-shareinternalservererror/5719)

<div class="topic-metadata">

**Author:** [@ma7555](https://openziti.discourse.group/u/ma7555)\
**Replies:** 11\
**Last updated:** [September 9, 2026, 9:03am UTC](https://openziti.discourse.group/t/error-unable-to-create-share-unable-to-create-share-post-share-500-shareinternalservererror/5719 "2026-09-09T09:03:57Z")

</div>

I was running a public share with reserved name. The docker restarted and i can’t get the same share to run again. Even tried with normal cli instead of docker. It is always the same error. zrok2 share public localhost:…

---

## [/enable 500 on share creation](https://openziti.discourse.group/t/enable-500-on-share-creation/6069)

<div class="topic-metadata">

**Author:** [@blik616287](https://openziti.discourse.group/u/blik616287)\
**Replies:** 2\
**Last updated:** [September 9, 2026, 8:41am UTC](https://openziti.discourse.group/t/enable-500-on-share-creation/6069 "2026-09-09T08:41:20Z")

</div>

Share creation fails for every share type and every environment on the account, while all reads succeed. One thing up front so nobody chases the wrong thing: the shares on this account were deleted by our own tooling …

---

## [New hosted account cannot enable an environment - HTTP 500 on v1 and v2](https://openziti.discourse.group/t/new-hosted-account-cannot-enable-an-environment-http-500-on-v1-and-v2/6052)

<div class="topic-metadata">

**Author:** [@bugfactoryceo](https://openziti.discourse.group/u/bugfactoryceo)\
**Replies:** 1\
**Last updated:** [September 8, 2026, 5:56am UTC](https://openziti.discourse.group/t/new-hosted-account-cannot-enable-an-environment-http-500-on-v1-and-v2/6052 "2026-09-08T05:56:11Z")

</div>

Our new free myzrok.io account cannot register its first Windows environment. The API consoles load and account sign-in works, but the consoles show only the account node and no registered environments. Latest reproduct…

---

## [Hosted zrok v1 POST /enable returns 500](https://openziti.discourse.group/t/hosted-zrok-v1-post-enable-returns-500/6050)

<div class="topic-metadata">

**Author:** [@Yoshino](https://openziti.discourse.group/u/Yoshino)\
**Replies:** 0\
**Last updated:** [September 7, 2026, 8:59pm UTC](https://openziti.discourse.group/t/hosted-zrok-v1-post-enable-returns-500/6050 "2026-09-07T20:59:00Z")

</div>

Client: zrok v1.1.11 \[1d736435\] OS: Windows Endpoint: https://api-v1.zrok.io Error: \[POST /enable\]\[500\] enableInternalServerError The local .zrok directory contains configuration only; no local environment or identity w…

---

## [Account returning HTTP 500 errors](https://openziti.discourse.group/t/account-returning-http-500-errors/6047)

<div class="topic-metadata">

**Author:** [@domsdo1958-source](https://openziti.discourse.group/u/domsdo1958-source)\
**Replies:** 1\
**Last updated:** [September 6, 2026, 6:47am UTC](https://openziti.discourse.group/t/account-returning-http-500-errors/6047 "2026-09-06T06:47:38Z")

</div>

Hi, My zrok account has been returning HTTP 500 errors on every account/share operation since this morning (Sep 6, 2026). It was working fine yesterday. Errors seen: zrok share public \<url\> → \[POST /share\]\[500\] share…

---

## [Request failed (500) when releasing environment (DbSX1q-R7j) - Account limit reached](https://openziti.discourse.group/t/request-failed-500-when-releasing-environment-dbsx1q-r7j-account-limit-reached/5957)

<div class="topic-metadata">

**Author:** [@jadieraristizabal](https://openziti.discourse.group/u/jadieraristizabal)\
**Replies:** 3\
**Last updated:** [September 6, 2026, 4:25am UTC](https://openziti.discourse.group/t/request-failed-500-when-releasing-environment-dbsx1q-r7j-account-limit-reached/5957 "2026-09-06T04:25:40Z")

</div>

Hi, I am a paying user of the $7/mo zrok plan. I am currently unable to create or delete environments. When I try to delete/release the environment JADIERPC\\jadie@JadierPC (zId: DbSX1q-R7j) from the web console, I get …

---

## [Cannot enable environment (500 Error)](https://openziti.discourse.group/t/cannot-enable-environment-500-error/6045)

<div class="topic-metadata">

**Author:** [@SaiyanK](https://openziti.discourse.group/u/SaiyanK)\
**Replies:** 0\
**Last updated:** [September 6, 2026, 4:16am UTC](https://openziti.discourse.group/t/cannot-enable-environment-500-error/6045 "2026-09-06T04:16:35Z")

</div>

$ zrok enable .... the zrok service returned an error: \[POST /enable\]\[500\] enableInternalServerError there was a problem enabling your environment! you are trying to use the zrok service at: https://api-v1.zrok.io y…

---

## [Hosted zrok2 environment cannot create any public share – \[POST /share\]\[500\] shareInternalServerError](https://openziti.discourse.group/t/hosted-zrok2-environment-cannot-create-any-public-share-post-share-500-shareinternalservererror/6044)

<div class="topic-metadata">

**Author:** [@tlaloc2k-ws](https://openziti.discourse.group/u/tlaloc2k-ws)\
**Replies:** 0\
**Last updated:** [September 6, 2026, 2:10am UTC](https://openziti.discourse.group/t/hosted-zrok2-environment-cannot-create-any-public-share-post-share-500-shareinternalservererror/6044 "2026-09-06T02:10:42Z")

</div>

Hi, I’m using hosted zrok with zrok2 v2.0.4 \[6ff92039\] on Windows 11. My environment appears healthy for account/config operations, but it cannot create any public share. Environment API endpoint: https://api-v2.zrok…

---

## [Removing Stale Environments](https://openziti.discourse.group/t/removing-stale-environments/6042)

<div class="topic-metadata">

**Author:** [@JT\_Valhalla](https://openziti.discourse.group/u/JT_Valhalla)\
**Replies:** 1\
**Last updated:** [September 5, 2026, 10:18pm UTC](https://openziti.discourse.group/t/removing-stale-environments/6042 "2026-09-05T22:18:56Z")

</div>

Hello, I'm a new user and I believe I've created three stale environments. My account is now limited so I can't do anything. Could you release the environments for me? The account name is johnt@valhalla-systems.com I'm…

---

## [ZDEW 2.9.7.2 / 2.11.3.0: OIDC login via external Keycloak fails with 404/405 at "Controller authentication" — works on 2.9.7.1 (controller 2.1.0-pre1)](https://openziti.discourse.group/t/zdew-2-9-7-2-2-11-3-0-oidc-login-via-external-keycloak-fails-with-404-405-at-controller-authentication-works-on-2-9-7-1-controller-2-1-0-pre1/6034)

<div class="topic-metadata">

**Author:** [@humter86](https://openziti.discourse.group/u/humter86)\
**Replies:** 1\
**Last updated:** [September 3, 2026, 5:20pm UTC](https://openziti.discourse.group/t/zdew-2-9-7-2-2-11-3-0-oidc-login-via-external-keycloak-fails-with-404-405-at-controller-authentication-works-on-2-9-7-1-controller-2-1-0-pre1/6034 "2026-09-03T17:20:30Z")

</div>

Hello OpenZiti team, First of all, thank you for the great project — we have been running OpenZiti in production for several services and appreciate the stability and design of the overlay. We are writing to report a re…

---

## [Free tier interstitial showing despite verified account with credit card](https://openziti.discourse.group/t/free-tier-interstitial-showing-despite-verified-account-with-credit-card/6030)

<div class="topic-metadata">

**Author:** [@synapsevzla](https://openziti.discourse.group/u/synapsevzla)\
**Replies:** 1\
**Last updated:** [September 3, 2026, 1:17pm UTC](https://openziti.discourse.group/t/free-tier-interstitial-showing-despite-verified-account-with-credit-card/6030 "2026-09-03T13:17:58Z")

</div>

Hello support team, I have verified my account by adding a credit card to avoid the free tier limitations, but the interstitial warning/page continues to appear. Could you please check my account status and help me clea…

---

## [Hosted zrok2 enable returning 500 / cannot release shares in API console](https://openziti.discourse.group/t/hosted-zrok2-enable-returning-500-cannot-release-shares-in-api-console/6028)

<div class="topic-metadata">

**Author:** [@steevejfr](https://openziti.discourse.group/u/steevejfr)\
**Replies:** 2\
**Last updated:** [September 1, 2026, 7:26am UTC](https://openziti.discourse.group/t/hosted-zrok2-enable-returning-500-cannot-release-shares-in-api-console/6028 "2026-09-01T07:26:39Z")

</div>

Hello, I'm using the hosted zrok service (api-v2.zrok.io) with zrok2 v2.0.4 on Windows 11. My environment is currently stuck and I'm unable to enable or release anything. Symptom 1 — zrok2 enable fails: Running zrok2 e…

---

## [Hosted zrok2 environment stuck – enable and release both return 500](https://openziti.discourse.group/t/hosted-zrok2-environment-stuck-enable-and-release-both-return-500/6027)

<div class="topic-metadata">

**Author:** [@biharkadeepak](https://openziti.discourse.group/u/biharkadeepak)\
**Replies:** 0\
**Last updated:** [August 28, 2026, 8:07am UTC](https://openziti.discourse.group/t/hosted-zrok2-environment-stuck-enable-and-release-both-return-500/6027 "2026-08-28T08:07:42Z")

</div>

I am using zrok2 v2.0.4 on Windows 11 with: Local zrok2 status reports that no local environment exists. However, the API console contains a stale environment: Description: MSI\\Deepak@MSI Created: July 14, 2026 Ru…

---

## [HA not working as expected with ext-jwt signer (without JIT enrollment)](https://openziti.discourse.group/t/ha-not-working-as-expected-with-ext-jwt-signer-without-jit-enrollment/5812)

<div class="topic-metadata">

**Author:** [@marratj](https://openziti.discourse.group/u/marratj)\
**Replies:** 32\
**Last updated:** [August 28, 2026, 6:44am UTC](https://openziti.discourse.group/t/ha-not-working-as-expected-with-ext-jwt-signer-without-jit-enrollment/5812 "2026-08-28T06:44:40Z")

</div>

I have an 2.0.0-pre12 setup that is configured to use a local Keycloak instance as an external JWT signer without JIT enrollment of external identities. This means I'm pre-creating the identities for users in Ziti with t…

---

## [My hosted zrok v2 account is stuck](https://openziti.discourse.group/t/my-hosted-zrok-v2-account-is-stuck/6026)

<div class="topic-metadata">

**Author:** [@Shishir606](https://openziti.discourse.group/u/Shishir606)\
**Replies:** 0\
**Last updated:** [August 28, 2026, 6:29am UTC](https://openziti.discourse.group/t/my-hosted-zrok-v2-account-is-stuck/6026 "2026-08-28T06:29:58Z")

</div>

My hosted zrok v2 account is stuck. POST /share returns: \[500\] shareInternalServerError After disabling, POST /enable returns: \[500\] enableInternalServerError Deleting the environment from the API Console also fails…

---

## [The zrok service returned an error: \[POST /enable\]\[500\] enableInternalServerError](https://openziti.discourse.group/t/the-zrok-service-returned-an-error-post-enable-500-enableinternalservererror/6025)

<div class="topic-metadata">

**Author:** [@Mashalien](https://openziti.discourse.group/u/Mashalien)\
**Replies:** 1\
**Last updated:** [August 28, 2026, 6:06am UTC](https://openziti.discourse.group/t/the-zrok-service-returned-an-error-post-enable-500-enableinternalservererror/6025 "2026-08-28T06:06:29Z")

</div>

I recently downloaded Zrok and needed to use the v1 version for Foundry, downloading the 1.1.11 version since that seemed most recent for v1. However, every time I try to enable Zrok, this error comes back: "the zrok se…

---

## [OpenZiti edge router MFA posture nil-pointer panic causing authenticated router DoS](https://openziti.discourse.group/t/openziti-edge-router-mfa-posture-nil-pointer-panic-causing-authenticated-router-dos/6022)

<div class="topic-metadata">

**Author:** [@mike.gorman](https://openziti.discourse.group/u/mike.gorman)\
**Replies:** 0\
**Last updated:** [August 26, 2026, 8:18pm UTC](https://openziti.discourse.group/t/openziti-edge-router-mfa-posture-nil-pointer-panic-causing-authenticated-router-dos/6022 "2026-08-26T20:18:12Z")

</div>

Summary The OpenZiti edge router evaluates posture checks locally when an OIDC/JWT-session client dials or binds a service. The router's MFA posture check (router/posture/mfa.go, MfaCheck.Evaluate) reads state.Woken.Ti…

---

## [Unauthenticated Memory Exhaustion via Unbounded Pre-Auth Request Body Buffering](https://openziti.discourse.group/t/unauthenticated-memory-exhaustion-via-unbounded-pre-auth-request-body-buffering/6019)

<div class="topic-metadata">

**Author:** [@mike.gorman](https://openziti.discourse.group/u/mike.gorman)\
**Replies:** 0\
**Last updated:** [August 26, 2026, 7:41pm UTC](https://openziti.discourse.group/t/unauthenticated-memory-exhaustion-via-unbounded-pre-auth-request-body-buffering/6019 "2026-08-26T19:41:27Z")

</div>

Summary AppEnv.CreateRequestContext in controller/env/appenv.go calls io.ReadAll(r.Body) to buffer the entire HTTP request body into memory before any authentication or authorization check is performed. This function is …

---

## [Existing Session Remains Valid After Account Is Deactivated in External IdP](https://openziti.discourse.group/t/existing-session-remains-valid-after-account-is-deactivated-in-external-idp/5999)

<div class="topic-metadata">

**Author:** [@tomc](https://openziti.discourse.group/u/tomc)\
**Replies:** 5\
**Last updated:** [August 26, 2026, 7:40pm UTC](https://openziti.discourse.group/t/existing-session-remains-valid-after-account-is-deactivated-in-external-idp/5999 "2026-08-26T19:40:18Z")

</div>

I’m testing OpenZiti 2.0.1 with Authentik as the external OIDC identity provider. I authenticated successfully through Authentik and established an OpenZiti session. I then deactivated the corresponding user account in …

---

## [Legacy Enrollment Path Doubles Per-Request Memory Allocation, Amplifying Memory Exhaustion DoS](https://openziti.discourse.group/t/legacy-enrollment-path-doubles-per-request-memory-allocation-amplifying-memory-exhaustion-dos/6018)

<div class="topic-metadata">

**Author:** [@mike.gorman](https://openziti.discourse.group/u/mike.gorman)\
**Replies:** 0\
**Last updated:** [August 26, 2026, 7:38pm UTC](https://openziti.discourse.group/t/legacy-enrollment-path-doubles-per-request-memory-allocation-amplifying-memory-exhaustion-dos/6018 "2026-08-26T19:38:48Z")

</div>

Summary The unauthenticated enrollment endpoint (/edge/client/v1/enroll) with legacy MIME types (text/plain, application/pkcs7, application/x-pem-file) allocates the request body twice: once globally in CreateRequestCont…

---

## [Proxmox Backup over Ziti fails on large datasets (HTTP/2.0 connection failed)](https://openziti.discourse.group/t/proxmox-backup-over-ziti-fails-on-large-datasets-http-2-0-connection-failed/5975)

<div class="topic-metadata">

**Author:** [@golden-monkey](https://openziti.discourse.group/u/golden-monkey)\
**Replies:** 10\
**Last updated:** [August 26, 2026, 11:41am UTC](https://openziti.discourse.group/t/proxmox-backup-over-ziti-fails-on-large-datasets-http-2-0-connection-failed/5975 "2026-08-26T11:41:04Z")

</div>

Hi community, we are experiencing an issue regarding our remote backups which uses a ziti overlay network to connect the source to our remote backup target. Currently, every scheduled backup we run fails. We are using …

---

## [ZET does not recover after prolonged controller/network outage once API session expires](https://openziti.discourse.group/t/zet-does-not-recover-after-prolonged-controller-network-outage-once-api-session-expires/5993)

<div class="topic-metadata">

**Author:** [@tomc](https://openziti.discourse.group/u/tomc)\
**Replies:** 6\
**Last updated:** [August 25, 2026, 8:47pm UTC](https://openziti.discourse.group/t/zet-does-not-recover-after-prolonged-controller-network-outage-once-api-session-expires/5993 "2026-08-25T20:47:52Z")

</div>

I am seeing ziti-edge-tunnel fail to recover after controller and network connectivity are restored following a prolonged outage. A short network interruption appears to be handled normally. The problem occurs when conn…

---

## [Ziti Edge Desktop For Windows Disable PROXY](https://openziti.discourse.group/t/ziti-edge-desktop-for-windows-disable-proxy/6012)

<div class="topic-metadata">

**Author:** [@cao](https://openziti.discourse.group/u/cao)\
**Replies:** 2\
**Last updated:** [August 24, 2026, 3:09pm UTC](https://openziti.discourse.group/t/ziti-edge-desktop-for-windows-disable-proxy/6012 "2026-08-24T15:09:35Z")

</div>

I'm using Ziti Edge Desktop for Windows 2.9.5, it works well in my sandbox environment. When I testing ZEDW in a corporate network, it failed to connect to Ziti Controller and Router, after a little bit troubleshooting,…

---

## [Windows ziti-edge-tunnel returns posture state was nil for Process Checks (OS Check works fine)](https://openziti.discourse.group/t/windows-ziti-edge-tunnel-returns-posture-state-was-nil-for-process-checks-os-check-works-fine/5881)

<div class="topic-metadata">

**Author:** [@ImFeelingBetter](https://openziti.discourse.group/u/ImFeelingBetter)\
**Replies:** 6\
**Last updated:** [August 24, 2026, 3:02pm UTC](https://openziti.discourse.group/t/windows-ziti-edge-tunnel-returns-posture-state-was-nil-for-process-checks-os-check-works-fine/5881 "2026-08-24T15:02:47Z")

</div>

Hi everyone!, Hope anyone can help me because i've been pulling my hair for hours and can't find the issue (most probably myself). I'm trying to implement a simple running process posture check in windows, the client c…

---

## [Zrok GUI – A Graphical Interface for zrok](https://openziti.discourse.group/t/zrok-gui-a-graphical-interface-for-zrok/6010)

<div class="topic-metadata">

**Author:** [@muratgul](https://openziti.discourse.group/u/muratgul)\
**Replies:** 0\
**Last updated:** [August 15, 2026, 12:46pm UTC](https://openziti.discourse.group/t/zrok-gui-a-graphical-interface-for-zrok/6010 "2026-08-15T12:46:27Z")

</div>

Hi everyone, I recently built a small GUI application that makes zrok easier to use without relying entirely on the command line. The goal of the project is to provide a simple graphical interface for managing and usin…

---

## [Browzer - openziti](https://openziti.discourse.group/t/browzer-openziti/5996)

<div class="topic-metadata">

**Author:** [@Sachini](https://openziti.discourse.group/u/Sachini)\
**Replies:** 1\
**Last updated:** [August 11, 2026, 11:26am UTC](https://openziti.discourse.group/t/browzer-openziti/5996 "2026-08-11T11:26:54Z")

</div>

Hello Team, Getting this error after SSO login(keycloak) on the browser console. Any idea how to resolve it? Uncaught (in promise) Error: The request could not be completed. The session is not authorized or the credent…

---

## [OpenZiti identity with Entra-signed JWT cannot access resources](https://openziti.discourse.group/t/openziti-identity-with-entra-signed-jwt-cannot-access-resources/5997)

<div class="topic-metadata">

**Author:** [@carol](https://openziti.discourse.group/u/carol)\
**Replies:** 2\
**Last updated:** [August 11, 2026, 9:22am UTC](https://openziti.discourse.group/t/openziti-identity-with-entra-signed-jwt-cannot-access-resources/5997 "2026-08-11T09:22:16Z")

</div>

Hello everyone, I’m running OpenZiti, and overall everything is working fine. Last week, I tried to configure network access through identity, but it’s not working as expected. Sometimes I can log in to the UI console…

---

## [Ziti 2.0.2 Availability in Stable Repositories](https://openziti.discourse.group/t/ziti-2-0-2-availability-in-stable-repositories/6001)

<div class="topic-metadata">

**Author:** [@tomc](https://openziti.discourse.group/u/tomc)\
**Replies:** 1\
**Last updated:** [August 11, 2026, 4:20am UTC](https://openziti.discourse.group/t/ziti-2-0-2-availability-in-stable-repositories/6001 "2026-08-11T04:20:17Z")

</div>

I noticed that Ziti 2.0.1 is affected by the security issues addressed in Ziti 2.0.2, so upgrading to 2.0.2 appears advisable. However, it looks like 2.0.1 is still the version available from the OpenZiti stable package…

[Previous page](https://openziti.discourse.group/latest.md)

[Next page](https://openziti.discourse.group/latest.md?page=2)
