F5 NGINX Plus 37.1 Release Now Available

We are excited to announce the general availability of F5 NGINX Plus Release 37.1.

Following the launch of our major NGINX Plus 37.0 LTS release, NGINX Plus 37.1 is the latest delivery in our Continuous Release (CR) track. The CR track gives enterprise teams immediate access to new features and enhancements without waiting for annual LTS milestones.

NGINX Plus 37.1 focuses on two key operational features: Dynamic Rate Limiting and Enterprise JWT License Renewal Controls.

Key Capabilities in NGINX Plus 37.1 

1. Dynamic Rate Limiting via NGINX API

Rate limiting (limit_req) is an essential defense for shielding upstream services from spikes and enforcing tenant quotas. Historically, adjusting rate limits required modifying configuration files and executing an NGINX process reload.

In NGINX Plus 37.1, operators and automation tools can dynamically adjust rate parameters in real time directly through the NGINX API.

  • No Process Reloads: Adjust traffic-shaping thresholds on the fly without triggering configuration reloads or disturbing established HTTP/TCP connections.
  • Instant Incident Response: Programmatically tighten request limits during DDoS events or traffic spikes.
  • Automated SLA Enforcement: Scale tenant bandwidth or rate limits dynamically based on real-time backend telemetry or customer tier changes.

API REQUEST EXAMPLE

Adjust the request rate of a defined zone (api_zone) instantly without reloading NGINX:

curl -X PUT \ -H "Content-Type: application/json" \ -d '{"rate": "100r/s"}' \ http://localhost/api/10/http/rate_limit_zones/api_zone

2. Enterprise JWT License Renewal Controls

To support enterprise change management and strict compliance workflows, NGINX Plus 37.1 introduces the license_pending_token directive alongside an improved REST API for license management.

When NGINX Plus connects to the NGINX One Console during routine telemetry and usage reporting, an updated JSON Web Token (JWT) license is automatically fetched upon subscription extension or renewal. The license_pending_token directive controls how these renewed tokens are handled:

  • Immediate (Default / Not set): Renewed tokens received from the management plane are saved and applied immediately in memory (the exact same behavior introduced in R35).
  • Deferred (license_pending_token <file>;): Renewed tokens are saved to a designated <file> path on disk (relative to state_path), but not applied automatically. Operators can review and audit the token, applying it when ready by either:
  • Copying the file to <state_path>/nginx-mgmt-license (the active license token location)
  • Updating the token directly using the new PUT /api/10/license API endpoint
  • Manual (license_pending_token off;): Renewed tokens received from the management server are logged but discarded entirely. License renewals are managed exclusively through manual or CI/CD uploads via the PUT /api/10/license endpoint.

API Version Update (v9 to v10): NGINX Plus 37.1 updates the management API version from v9 to v10. While there are no breaking changes to existing endpoints, API version v10 is required to leverage these new license management capabilities.

Operational Note on License Uploads & Reporting: Invoking PUT /api/10/license validates the token, saves it to disk, and updates the active license immediately in memory (returning 200 OK on success, 409 on asset mismatch, or 400 on invalid input).

Changes Inherited from NGINX Open Source 

NGINX Plus 37.1 is now built on NGINX OSS 1.31.3 (updated from OSS 1.29.8 in the prior 37.0 release). This core upgrade brings performance optimizations, stability enhancements, and inherits all upstream functional changes and bug fixes.

For detailed information on the open-source core changes, see the official NGINX CHANGES file.

Upgrade Today 

NGINX Plus 37.1 is available immediately for all current subscribers via standard operating system package repositories.

Ready to get started or test the new release?

  • Explore the Documentation: Review full release details, directive specifications, and configuration parameters on the NGINX Documentation.
  • Test NGINX Plus: Request a 30-day free trial to evaluate enterprise-grade traffic management, dynamic security controls, and high-availability routing in your own environment.
  • Installation & Deployment Guide: Follow this guide for step-by-step instructions on deploying NGINX Plus or NGINX Open Source.

F5 NGINX in F5’s Application Delivery & Security Platform  

NGINX One is part of F5’s Application Delivery & Security Platform. It helps organizations deliver, improve, and secure new applications and APIs. This platform is a unified solution designed to ensure reliable performance, robust security, and seamless scalability for applications deployed across cloud, hybrid, and edge architectures.

NGINX One is the all-in-one, subscription-based package that unifies all of NGINX’s capabilities. NGINX One brings together the features of NGINX Plus, F5 NGINX App Protect, and NGINX Kubernetes and management solutions into a single, easy-to-consume package. NGINX Plus, a key component of NGINX One, adds features to open-source NGINX that are designed for enterprise-grade performance, scalability, and security.

Follow this guide for more information on installing and deploying NGINX Plus 37.0 or NGINX Open Source.

1 Like