What’s New in F5 NGINX Instance Manager 2.23 and F5 NGINX One Console

We are excited to release F5 NGINX Instance Manager 2.23 and enhancements to F5 NGINX One Console. This release expands security visibility for Kubernetes environments, adds auditable access to raw usage telemetry, simplifies security-hardened deployments, and extends operating system support.

We are also delivering updates to NGINX One Console, our SaaS management plane, including improved instance identification and new configuration template workflows planned for the first half of September.

Here is a closer look at what is coming.

Security monitoring for NGINXGateway Fabric 

NGINX Instance Manager 2.23 extends Security Monitoring to NGINX Gateway Fabric deployments running F5 WAF for NGINX.

Security events from WAF-enabled NGINX Gateway Fabric instances will now be part of  the same Security Monitoring dashboard used for NGINX Ingress Controller and NGINX data plane instances. This provides a more unified view of application security activity across your Kubernetes and NGINX environments.

Previously, NGINX Instance Manager security event visibility was limited to supported instances using NGINX Agent v2. With this release, NGINX Instance Manager can also receive security events from NGINX Gateway Fabric deployments running NGINX Agent v3.

From the dashboard, you can view:

  • Total blocked and flagged requests for a selected time range

  • A breakdown of detected attack types, such as SQL injection and cross-site scripting

  • Request-level details, including source IP, URI, matched signature, and WAF action

  • Filters for specific NGINX Gateway Fabric instances and Kubernetes namespaces

This release focuses specifically on security event visibility. Instance management, instance groups, configuration management, and policy publishing for NGINX Gateway Fabric are not supported in this release.

Audit-ready visibility withNGINXUsage Records 

NGINX Instance Manager 2.23 introduces NGINX Usage Records, providing direct access to the raw usage reporting by NGINX deployments.

A new Usage dashboard displays one row for each usage report, with separate views for:

  • VM-based NGINX Plus deployments

  • Kubernetes-based NGINX Ingress Controller and NGINX Gateway Fabric deployments

Records are ordered by reported time, with the newest records displayed first. The dashboard defaults to the previous seven days and supports filtering by: Date range,Instance,Kubernetes cluster,Product type,Subscription token

You can also export filtered records to a CSV file for offline analysis, reconciliation, or audit workflows.

Usage records are stored exactly as received, without transformation or aggregation, in the NGINX Instance Manager embedded local database. This capability works in all supported deployment modes, including disconnected environments.

The default retention period is 120 days and can be configured for up to one year. Expired records are removed through an automatic daily cleanup process.

NGINX Usage Records do not collect or store hostnames, IP addresses, or other personally identifiable information.

Official rootless deployment with Docker Compose

NGINX Instance Manager 2.23 introduces official rootless container images, removing the need to build and maintain custom images for non-root environments.

All container processes run as the non-root nms user. This reduces the runtime attack surface and makes it easier to deploy NGINX Instance Manager in environments with strict security-hardening requirements.

The prebuilt image includes:

  • NGINX Instance Manager

  • Security Monitoring

  • F5 WAF for NGINX Compiler v5.14.1

The rootless deployment also provides:

  • A single /data location for persistent state

  • Automatic first-boot initialization of certificates and credentials

  • Runtime configuration through environment variables

  • Support for connected and disconnected licensing modes

  • Maintenance mode for backup, restore, and debugging

  • A built-in watchdog for critical NGINX Instance Manager processes

  • Support for custom TLS certificates and outbound proxies

  • Named Docker volumes, with options for NFS-backed storage

The deployment requires Docker Engine 20.10 or later, Docker Compose v2 or later, and a reachable ClickHouse service. The minimum recommended resources are four CPU cores and 4 GB of memory.

The container also includes nim-backup and nim-restore commands, with maintenance mode available to support safer backup and restore operations.

This official rootless option is intended to simplify production deployments while reducing the need for elevated container privileges.

New platform support 

NGINX Instance Manager 2.23 adds support for:

  • Ubuntu 26

  • Rocky Linux 10

NGINX Instance Manager 2.23 also includes security updates, stability improvements, and bug fixes.

NGINX OneConsole Updates

We are continuing to evolve NGINX One Console as our SaaS-based management plane.

NGINXAgent display names 

NGINX One Console now shows the instance display name configured in NGINX Agent.

This makes it easier to identify and distinguish instances using meaningful names selected by your organization, rather than relying only on automatically discovered identifiers. It is especially helpful in environments with many instances, multiple teams, or standardized naming conventions.

Config Explorer

New read-only Config Explorer is live on NGINX One Console for viewing Staged configurations (pending deployment), Instance configurations and Config sync group configurations.

Configuration templates 

New configuration template capabilities are planned for the first half of September 2026.

Key Deliverables:

  • Template Submissions UI Workflow - Create and edit workflows for template submissions, powered by a reusable JSON component that dynamically renders template inputs based on template schema. Backend services updated to support submission requirements and leverage existing infrastructure.

  • Staged Configuration Management - Support for storing and managing configurations generated from template submissions. Staged configurations can be manually deployed to instances or config sync groups.

What’s next 

We are also working on native gRPC-based workflows for F5 WAF across both NGINX Instance Manager and NGINX One Console. These capabilities are part of our broader effort to deliver consistent security visibility and management across self-managed and SaaS management planes.

We look forward to hearing how you use these capabilities and what you would like to see next. Share your questions and feedback here in the F5 DevCentral community.

1 Like