Release v3.9.8
What Changed
6Upgrade Guide
# Back up database first, then:
$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.8
$ helm rollback dify 0
# Back up database first, then:
$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.8
$ helm rollback dify 0
# Back up database first, then:
$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.7
$ helm rollback dify 0
api-insecure image is excluded from the CVE table above.flask rbac-migrate-member-roles (mandatory; members have no access until this finishes)flask rbac-migrate-dataset-permissions --apply (mandatory; dataset access is incorrect under RBAC until this finishes)flask backfill-plugin-auto-upgrade (mandatory) before restoring traffic# Back up database first, then:
$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.11.0
$ helm rollback dify 0
api-insecure image is excluded from the CVE table above.ALLOW_INLINE_STYLES environment variable that allows inline CSS styles in Markdown rendering. When enabled, HTML elements with inline style attributes in Markdown content are preserved instead of being stripped, enabling richer formatting in chat responses and knowledge base documents.DetachedInstanceError in the password reset flow, which has been resolved by correcting the ORM session handling.# Back up database first, then:
$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.6
$ helm rollback dify 0
# Back up database first, then:
$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.5
$ helm rollback dify 0
api-insecure image is excluded from the CVE table above.cluster_id inserts on pod restart are now skipped, preventing the constraint violation.# Back up database first, then:
$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.10.0
$ helm rollback dify 0
api-insecure image is excluded from the CVE table above.# Back up database first, then:
$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.4
$ helm rollback dify 0
api-insecure image is excluded from the CVE table above.# Back up database first, then:
$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.3
$ helm rollback dify 0
api-insecure image is excluded from the CVE table above.# Back up database first, then:
$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.2
$ helm rollback dify 0
api-insecure image is excluded from the CVE table above.Example Helm values for Azure managed identity:
global:
podLabels:
azure.workload.identity/use: "true"
plugin_daemon:
# azure managed service account
serviceAccountName: "plugin-daemon-mi"
enterpriseAudit:
serviceAccountName: "enterprise-audit-mi"
azureBlob:
useManagedIdentity: true
Example per-database credential environment variables:
# If not set, will fallback to externalDatabase.username, externalDatabase.password
databaseCredentials:
dify:
user: ""
password: ""
enterprise:
user: ""
password: ""
audit:
user: ""
password: ""
plugin_daemon:
user: ""
password: ""
# Back up database first, then:
$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.9.1
$ helm rollback dify 0
api-insecure image is excluded from the CVE table above.