> For the complete documentation index, see [llms.txt](https://docs.portainer.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.portainer.io/whats-new.md).

# What's new in version 2.45

Portainer version 2.45 includes a number of new features and fixes, bringing the changes from the previous STS releases into the LTS stream. For a full list of changes, please refer to our [release notes](/release-notes.md).

{% embed url="<https://www.youtube.com/watch?v=NBb1VlkCacs>" %}

## Long Term Support (LTS) <a href="#short-term-support-sts" id="short-term-support-sts"></a>

2.45 is a Long Term Support, or "LTS", release of Portainer. LTS releases are intended to to be solid, tested, production-ready versions of Portainer, suitable for running in both testing and production environments. LTS releases generally do not have any additional features as compared to the previous STS release, but rather are a consolidation of all the new features and changes that have gone into the previous STS releases but with additional polishing and testing.

You can read more about our release principles in our [lifecycle policy](/start/lifecycle.md).

## New in this release

### A new look for the home page ![](/files/ampF8yKFDfHH1CzAQKil) ![](/files/FIZ3QK42QYpkLd2Bn9wr)

The [home page](/user/home.md) has been refreshed as part of Portainer's ongoing UI update. Environments are now displayed in helpful groupings, making it easier to spot environments that are down or unassigned. You can now sort your environments by group, platform, or health.

<figure><img src="/files/ZeR6YAUjAzTTALHmOSOf" alt=""><figcaption></figcaption></figure>

### Portainer Add-ons ![](/files/ampF8yKFDfHH1CzAQKil)&#x20;

Portainer now supports installable [add-ons](/admin/add-ons.md) - purpose-built tools that extend Portainer and run alongside it in your local Kubernetes cluster. Each add-on deploys as a Helm release and appears in the sidebar switcher; admins can install, upgrade, restart, and uninstall add-ons from a central catalog, monitor health via Resources, Events, and Logs tabs, and control team access. The first add-on, [Portainer-Run](https://portainer.ai/), is available now.

<figure><img src="/files/QIlVbgRP7i9v1x8QFN9r" alt=""><figcaption></figcaption></figure>

### New policies ![](/files/ampF8yKFDfHH1CzAQKil)

Portainer now offers several new [policy](/admin/environments/policies.md) types to help enforce security and governance across your environments:

* [Banner and Custom Change Confirmation policy](/admin/environments/policies/any-environment-type-policies/create-a-banner-and-change-confirmation-policy.md) - display a custom banner across a group of environments (Docker or Kubernetes) and require a confirmation prompt before changes are applied.
* [Pod Security Standards policy](/admin/environments/policies/kubernetes-policies/create-a-kubernetes-pod-security-standards-policy.md) - apply Kubernetes' built-in privileged, baseline, or restricted profiles per namespace, independently for enforce, audit, and warn modes.
* [Kubernetes Network Security policy](/admin/environments/policies/kubernetes-policies/create-a-kubernetes-network-security-policy.md) - define ingress and egress rules for pods using presets or custom label-based rules, deployed as native Kubernetes `NetworkPolicy` objects.
* [Kubernetes observability policy](/admin/environments/policies/kubernetes-policies/create-a-kubernetes-observability-policy.md) - connect Portainer to your [OneUptime](https://oneuptime.com/) instance to bring logs and metrics directly into the namespace details view. Choose to connect to an existing OneUptime agent or have Portainer deploy one for you.
* [Native Kubernetes RBAC support](/admin/environments/policies/kubernetes-policies/kubernetes-rbac-policy.md) - Kubernetes RBAC policies now support a native Kubernetes permission model, alongside the existing legacy Portainer privileges model, with permissions accumulating across cluster, team, and namespace roles.

<figure><img src="/files/vgIwftFNSUrZz1qHOSSZ" alt=""><figcaption></figcaption></figure>

### GitOps improvements ![](/files/ampF8yKFDfHH1CzAQKil) ![](/files/FIZ3QK42QYpkLd2Bn9wr)

GitOps management is now centralized and easier to configure end to end:

* A new [Sources view](/user/app-delivery/sources.md) provides a central place to create, edit, and manage Git connections, replacing the previous per-workflow credential entry.
* A new guided [GitOps workflow creation](/user/app-delivery/workflows.md) flow lets you configure a source, stack file, deployment targets, environment variables, registry settings, and rollout strategy (including parallel batches with automatic pause or rollback) in one operation.
* A new [Workflows dashboard](/user/app-delivery/workflows.md) gives a unified view of Docker, Edge, and Kubernetes workloads deployed from Git, so you can assess deployment health and jump to any stack that needs attention.

<figure><img src="/files/ZwEM2ItBqEtSyI1rcv8l" alt=""><figcaption></figcaption></figure>

### Docker image cleanup ![](/files/ampF8yKFDfHH1CzAQKil)

Keeping Docker environments tidy is easier with two new capabilities: [manual image pruning](/user/docker/images/prune-dangling-and-unused-images.md) from the Images view (dangling images or all unused images), and [automated image cleanup policies](/admin/environments/policies/docker-policies/cleanup-policy.md) that remove old or unused images on a schedule, based on age or storage thresholds, with the ability to protect specific images.

<figure><img src="/files/Td0EcmvQpCyn1fwE9SR5" alt=""><figcaption></figcaption></figure>

### Alerting improvements ![](/files/ampF8yKFDfHH1CzAQKil)

[Alerting](/user/alerting.md) has graduated to general availability, with several enhancements: select alert types now support multi-severity thresholds (critical, warning, info), the rules view adds category-based grouping and filtering, new Kubernetes rules cover etcd, API server, TLS certificate expiry, and NotReady nodes, and alert summaries now surface per-entity context for faster triage. Notifications can be sent to Slack, email, or Microsoft Teams.

<figure><img src="/files/1YC6c1wNL6QKTQRrrUPc" alt=""><figcaption></figcaption></figure>

### GPU visibility ![](/files/ampF8yKFDfHH1CzAQKil)

Kubernetes environments with detected GPU nodes now display a dedicated [GPU view](/user/kubernetes/gpu.md) with three tables: a GPU summary (capacity, allocatable, allocated, and available counts, plus node health), a GPU Nodes table, and a GPU Workloads table showing per-pod GPU requests and scheduling status.

<figure><img src="/files/di6iIlQAA5RSRt7t6BKw" alt=""><figcaption></figcaption></figure>

### New ways to back up Portainer ![](/files/ampF8yKFDfHH1CzAQKil)

Two [new backup destinations](/admin/settings/general.md#back-up-portainer) are available: **scheduled local backup** on a defined cron schedule with configurable retention and a custom storage path, and **Azure Blob Storage**, joining S3 as a supported cloud destination for on-demand and scheduled backups.

<figure><img src="/files/lvUIpMqOcuhcfdO4GQaU" alt=""><figcaption></figcaption></figure>

### Add KubeSolo edge environments directly from Portainer ![](/files/ampF8yKFDfHH1CzAQKil)&#x20;

You can now [onboard KubeSolo edge environments](/admin/environments/add/add-a-kubesolo-edge-environment.md) through the Environment Wizard, which generates the setup command and walks you through deploying the Portainer Edge Agent, whether KubeSolo is already running or being installed fresh.

<figure><img src="/files/JFnlKt9aVkqfMaDrBt3u" alt=""><figcaption></figcaption></figure>

### A dedicated node shell ![](/files/ampF8yKFDfHH1CzAQKil)

Administrators can now open a root shell directly on any cluster node from the [Nodes table](/user/kubernetes/cluster/details.md#nodes), without needing SSH. Disabled by default; enable per cluster in Cluster → Setup → [Security](/user/kubernetes/cluster/setup.md#security), or centrally through a [Kubernetes Security Policy](/admin/environments/policies/kubernetes-policies/kubernetes-security-policy.md).

<figure><img src="/files/h4WHJurZ0bW6yVjpo4Cf" alt=""><figcaption></figcaption></figure>

### SSRF mitigation ![](/files/ampF8yKFDfHH1CzAQKil) ![](/files/FIZ3QK42QYpkLd2Bn9wr)

Portainer now includes [built-in SSRF mitigation](/admin/settings/general.md#ssrf). Define an allowlist of permitted proxy destinations and choose how Portainer responds to requests outside that list: enforce (block), audit (log only), or take no action.

<figure><img src="/files/CY42wnglPnxFK0KGvzje" alt=""><figcaption></figcaption></figure>

### New Recommendations view ![](/files/ampF8yKFDfHH1CzAQKil)

The new [Recommendations](/admin/recommendations.md) view surfaces actionable suggestions when Portainer detects environment issues or configuration gaps, each with a direct action to take you straight to the relevant area for resolution.

<figure><img src="/files/huVwHj4hXh09hI32kY5P" alt=""><figcaption></figcaption></figure>

### Default Service Account imagePullSecret management  ![](/files/ampF8yKFDfHH1CzAQKil) ![](/files/FIZ3QK42QYpkLd2Bn9wr)

Portainer now automatically updates the default [Service Account](/user/kubernetes/more-resources/service-accounts.md) in a namespace when registry access is added or removed as part of a [registry policy](/admin/environments/policies/kubernetes-policies/kubernetes-registry-policy.md) (BE only) or from the [Registries view](/user/kubernetes/cluster/registries.md#managing-access). When access is granted, the registry secret is added as an imagePullSecret to the default Service Account, allowing Pods in the namespace to pull images from the private registry automatically. When access is removed, the secret is removed from the default Service Account while any other existing imagePullSecrets are retained. This change is accompanied by an improved Service account details view, which allows you to view Service Account details and edit the YAML.

<figure><img src="/files/KzEgiX0P68Lwdvxf0aTH" alt=""><figcaption></figcaption></figure>

### Kubernetes volumes page restructure and improvements  ![](/files/ampF8yKFDfHH1CzAQKil) ![](/files/FIZ3QK42QYpkLd2Bn9wr)

Previous Volumes and Storage tabs found on the [Kubernetes volumes page](/user/kubernetes/volumes.md) have been replaced with three sections - Persistent Volumes, Persistent Volume Claims, and Storage Classes - giving each resource type its own focused view. You can now edit a volume's reclaim policy and resize persistent volume claims directly from the Actions menu, and storage classes can be set as the cluster default with a single click.&#x20;

<figure><img src="/files/H6VUWYsaefOP35AOONsQ" alt=""><figcaption></figcaption></figure>

### Manage Portainer using Terraform ![](/files/ampF8yKFDfHH1CzAQKil) ![](/files/FIZ3QK42QYpkLd2Bn9wr)

[Portainer can now be automated](#manage-portainer-using-terraform) using our [official Terraform provider](https://registry.terraform.io/providers/portainer/portainer/latest/docs), letting you manage environments, users, teams, stacks, and other resources as code, and integrate Portainer into existing Infrastructure as Code and CI/CD workflows.&#x20;

You can find a full walkthrough of how to deploy a Docker stack with Terraform in our [How-to articles](https://www.portainer.io/how-to/how-to-deploy-a-docker-stack-with-terraform).
