What's new in 7.22rc3 (2026-Feb-26 10:37):
- ! certificate - added support for multiple ACME certificates (services that use a previously generated certificate need to be reconfigured after the certificate expires) (additional fixes);
- ! device-mode - added option to configure device-mode via Netinstall or FlashFig using a “mode script” (additional fixes);
- app - added health check for apps, which automatically rewrites the composed YAML;
- app - clean the backup directory after container repull;
- app - fixed element that was failing to start;
- app - fixed potential port collisions between apps;
- app - show DNS URL for app only if it has a reverse-proxy (additional fixes);
- bgp - make remote.address parameter optional;
- bridge - added local and static MAC synchronization for MLAG (additional fixes);
- bridge - added MLAG support per bridge interface (/interface/bridge/mlag menu is moved to /interface/bridge; configuration is automatically updated after upgrade; downgrading to an older version will result in MLAG configuration loss) (additional fixes);
- bridge - fixed performance regression in complex setups with vlan-filtering (introduced in v7.20);
- bth - use separate Let's Encrypt certificate for file-share;
- container - automatically stop/repull/start the container on repull or remote-image change;
- device-mode - removed authorized-public-key-hash property;
- dhcpv6-relay - fixed link-layer address inconsistency with the original link-layer address in relay-forward packets (additional fixes);
- fetch - fixed fetch treating relative paths from redirects as hostnames;
- health - added CPU temperature monitoring to L009 with ARM64;
- ip - added reverse-proxy (additional fixes);
- ipsec - improved aes256-ctr stability on L009;
- isis - improved stability and fixed a small memory leak;
- l3hw - fixed missing VLAN counters on reboot (introduced in v7.21);
- l3hw - improved system stability when enabling VLAN offloading under active traffic (introduced in v7.21);
- leds - fixed WiFi LEDs on hAP AX S (introduced in v7.22rc1);
- poe-out - firmware update for CRS354-48P-4S+2Q+ (the update will cause a brief power interruption to poe-out interfaces);
- poe-out - fixed controller-error for CRS354-48P-4S+2Q+;
- route - do not set blackhole flag for synthetic routes;
- route - fixed connected routes sometimes not working (introduced in v7.22rc1);
- route - removed preset rules and use routing/settings policy-rules (introduced in v7.22beta1);
- routerboard - allow changing /system/routerboard/settings via Netinstall or FlashFig using a "mode script" (additional fixes);
- system - improved upgrade service stability when the server is unreachable;
- user - properly apply login delay (introduced in v7.20);
- wifi - improved stability of interfaces in station mode during roaming;
- wifi - improved support for 802.11be access points (additional fixes);
- winbox - added missing route flags;
- winbox - added route ISIS tab;
- winbox - show MPLS tab only to relevant routes;