Skip to main content

Seqera Enterprise v26.2

Seqera Platform Enterprise 26.2 adds event-driven Actions, triggered by bucket events, schedules, and pipeline run events. It also adds Co-Scientist agents that run as service accounts, a Projects view, a system-wide Nextflow version selector, and pre-flight validation for credentials and compute environments. Other additions are global search backed by the data lineage query language, customer-managed KMS encryption for pipeline secrets, and route-aware OpenTelemetry tracing. For identity and access management, 26.2 adds OIDC audience enforcement, RFC 8693 token exchange, refresh-token rotation, and more SCIM auditing.

Highlights​

  • You can launch a pipeline with a specific Nextflow version, chosen from a system-wide catalog of nf-launcher images. Each compute environment type sets a minimum version. See Compute environments.
  • Platform validates credentials and compute environments before launch, on a schedule, and on demand. Broken credentials surface before a run fails. This is enabled by default. See Upgrade notes.
  • Actions can be triggered by a bucket event, a schedule, or a pipeline run event, can start an agent instead of a pipeline, and record a trigger history. The three triggers are enabled by default in every workspace.
  • Global search, backed by the data lineage query language, searches across workspaces. It is on by default. To turn it off, set TOWER_GLOBAL_SEARCH_ENABLED to false.
  • You can encrypt pipeline secrets with a customer-managed AWS Key Management Service (KMS) key, set with TOWER_AWS_SECRETS_KMS_KEY_ID.
  • Enterprise deployments now send aggregate entity telemetry with the license check. This is enabled by default. See Upgrade notes.
  • Co-Scientist chat is available to every organization in the installation. It is enabled by default once the Co-Scientist agent backend is configured. See Upgrade notes.
  • You can configure reusable AI agents per workspace and start one from a run with Trigger agent. Each agent acts as its bound service account. Agents are enabled by default once the Co-Scientist agent backend is configured. See Upgrade notes.
  • A Projects view groups a workspace's pipelines, datasets, and runs by project, and launches from a project use an essentials-only launch form. This is enabled by default in every organization workspace. See Upgrade notes.
  • The standalone Co-Scientist web interface (provided by the portal-web chart) is removed. Co-Scientist is now part of Seqera Platform. See Upgrade notes.
  • A component compatibility catalog records which Nextflow, Fusion, and nf-launcher artifacts work with this Platform version, with deployment-local overrides for private registries. This is enabled by default. See Upgrade notes.
  • Platform can stamp the aud claim on the OIDC access tokens it issues and enforce it. Enforcement is off by default and only logs mismatches. See Upgrade notes.
  • Studios support private sessions restricted to an allow-list of users, per-user favorites, and a configurable automated stop grace period.
  • Route-aware OpenTelemetry tracing is available through the standard OTEL_* environment variables.
  • Studios gain a Logs tab that streams a session's process log directly from the compute environment. Logs survive an ungraceful shutdown.
  • The compute environment, credentials, and Actions lists are redesigned as row-card tables with attribute chips, grouping, and search.
  • From 26.2, Seqera publishes one frontend container image, platform/frontend:<tag>, which runs in unprivileged mode. The -unprivileged tag alias and the -root variant, which ran as the root user, are gone. See Upgrade notes.
  • Platform writes audit events only to the v2 schema. This is a breaking change for direct database consumers and ETL jobs that read the v1 tw_audit_log table. Update them to the v2 schema before you upgrade. See Upgrade notes.
info

The legacy distribution endpoint at cr.seqera.io/private is deprecated. Seqera publishes only bug fixes for existing major releases there. New major releases of Seqera Platform are available from cr.seqera.io/enterprise. Seqera provides updated credentials for the new endpoint. Contact your Seqera representative if you need access.

Feature updates and improvements​

Pipelines​

  • Added a Nextflow version selector. A system-wide catalog maps each selectable version to an nf-launcher image, sets a minimum version and launcher variant per compute environment type, and raises the floor for features that require it. The catalog defaults to Nextflow 26.04 and is not user-editable.
  • Extended the Nextflow version catalog back to 23.03.0-edge, for 70 versions in total. Pipelines pinned to an older runtime remain launchable. Releases from 25.04.1 and later resolve to public.cr.seqera.io/platform/nf-launcher images. The oldest entries, which were never mirrored there, resolve to quay.io/seqeralabs/nf-launcher.
  • Added synchronous pre-flight checks at launch. A launch now fails fast with an actionable reason instead of failing during execution.
  • Added an output directory option to the launch form, preserved across resume.
  • Aggregated launch validation failures into a single response and a multi-error failure message that reports every problem at once.
  • Added launch-time settings (profiles and the Nextflow syntax parser) to the run configuration tab, and surfaced them in the workflow configuration tab.
  • Validated the parameters text against the JSON-serialized size limit, using the tower.launch.config.maxSize value in the frontend validators.
  • Added a component compatibility catalog that records which Nextflow, Fusion, and nf-launcher artifacts are compatible with this Platform version, and enforces that compatibility at launch. Enabled by default. To turn it off, set TOWER_CATALOG_ENABLED to false. TOWER_CATALOG_SOURCE selects the catalog source (classpath:, file:, or licman for the live License Manager source) and TOWER_CATALOG_EMBEDDED sets the fallback used when a live source is unavailable.
  • Added deployment-local catalog overrides, supplied through your own application-catalog.yml. An override can remap an existing artifact to a private registry reference, add a deployment-only version, or hide a version from listings and pick validation. Overrides are marked origin: override, audited at launch, and never written back to the shared catalog. This subsumes the single TOWER_LAUNCH_CONTAINER pin.

Actions​

You can now trigger Actions with a bucket event, a schedule, or a pipeline run event. All three triggers are enabled in every workspace by default, including personal workspaces. Restrict them with TOWER_ACTIONS_BUCKET_TRIGGER_ALLOWED_WORKSPACES, TOWER_ACTIONS_CRON_TRIGGER_ALLOWED_WORKSPACES, and TOWER_ACTIONS_PIPELINE_TRIGGER_ALLOWED_WORKSPACES. See Core features. Review whether these triggers are appropriate for your installation before upgrading.

  • Added the Bucket event trigger, which fires an Action when a marker file is created or deleted in an AWS S3 data repository.
  • Added the Schedule trigger, which fires an Action daily, weekly, or on a custom cron expression.
  • Added the Pipeline run event trigger, which fires an Action when a run of a Launchpad pipeline succeeds, fails, or is cancelled. Use it to have one pipeline launch the next.
  • Added an agent target. A bucket event, schedule, or pipeline run event Action can start an existing agent instead of launching a pipeline.
  • Added a Trigger history tab that lists each time an Action fired, with its status, payload, and target.
  • Redesigned the action form and Action page. You can now change the trigger when you edit an Action.
  • Added recorded pause reasons, shown on the Actions list and the Action page, and a Created by column on the Actions list.
  • Added protection against Actions that trigger themselves: a bucket event Action that watches its own pipeline's output is rejected, and a pipeline run event Action that would close a loop is suppressed.

Compute environments​

  • Redesigned the compute environment list as a row-card table, with attribute chips, a type label, an Invalid status, the compute environment ID, and grouped, searchable compute environment selects.
  • Added scheduled pre-flight validation for compute environments in the AVAILABLE state.
  • Added a maxCpusPerUser per-user vCPU cap.
  • Added encryption of pipeline secrets with a customer-managed KMS key, configured with TOWER_AWS_SECRETS_KMS_KEY_ID. Compute environments saved before this release continue to use the AWS-managed key.
  • Required spot provisioning for Fusion snapshots, and aligned the GCP provisioning interface accordingly.
  • Added a scheduled cleanup that soft-deletes orphaned credentials and compute environments belonging to deleted workspaces. Off by default. To turn it on, use TOWER_WORKSPACE_ORPHAN_CLEANUP_ENABLED.
  • Added TOWER_COMPUTE_ENV_LAST_USED_FLUSH_INTERVAL to control how often the last-used timestamp is flushed.
  • Added new environment variables for the validation and cleanup schedules. See Configuration overview for full descriptions and defaults:
    • TOWER_CRON_CREDENTIALS_VALIDATION_*: tick rate, delay, interval, batch size, concurrency, probe delay, transient retry intervals, and maximum unverifiable attempts
    • TOWER_CRON_COMPUTE_ENV_VALIDATION_*: tick rate, delay, interval, and batch size
    • TOWER_CRON_CREDENTIALS_ORPHAN_CLEANUP_* and TOWER_CRON_COMPUTE_ENV_ORPHAN_CLEANUP_*: tick rate, delay, batch size, and concurrency

AWS​

  • Added EBS volume encryption with an optional KMS key for AWS Cloud compute environments.
  • Added VPC and multiple subnet selection for AWS Cloud compute environments.
  • Added automatic GPU AMI selection for AWS Cloud compute environments.
  • Added log group persistence, forwarded to the CloudWatch agent.
  • Added security group name search to AWS dropdowns.
  • Added the AWS jump-role trust policy to the credentials form.
  • Added r8idn, r8idb, m8idn, m8idb, m9gd, c9gd, g7, and r9gd instance families to the NVMe list.

Azure​

  • Added bring-your-own networking for Azure Cloud compute environments.
  • Added OS disk size configuration for Azure Cloud compute environments.
  • Added configurable boot disk size for Azure Batch pools.
  • Added private Azure Container Registry image pull support for Azure Cloud.
  • Reworked the Azure credentials region field, and validated Azure Batch access on the compute environment rather than the credential.
  • Updated the list of available Azure regions.

GCP​

  • Added VPC network and subnet selection for Google Cloud compute environments, with metadata autofill, and exposed the network fields in the API model.
  • Added end-to-end Workload Identity Federation credential support for Google Cloud compute environments.
  • Updated the default GPU image family to CUDA 12.9.

Credentials​

  • Added a credential validation status, shown on the credentials list and detail pages, with an error alert for credentials in the INVALID state.
  • Added a scheduled validation cron, a launch-time gate, and an on-demand Validate button. The cron runs every 12 hours by default.
  • Added a work directory reachability probe at launch for AWS and Google Cloud credentials. Platform rejects a run whose work directory the credential cannot read before the run starts, instead of letting it fail during execution. The probe is bounded at five seconds and fails open, allowing the launch when the result is inconclusive.
  • Aligned the credentials list with the compute environment card layout.
  • Added workload identity federation to AWS credentials. Platform exchanges a short-lived token it signs for temporary AWS credentials through sts:AssumeRoleWithWebIdentity. The credential stores only a role ARN. Enabled by default. See Upgrade notes.
  • Added per-context subjects to workload identity federation tokens for AWS and Google Cloud. A token names the kind of work making the request: platform, data, studio, or workflow. Trust and permission policies can scope access by workload, and cloud audit logs can name the acting user. See Subjects and attribution.

Studios​

  • Added sharing for private Studios: the creator can allow one other workspace user to connect to and run the session. The allowed user is persisted on create and start, and exposed in the studio API response.
  • Added a configurable automated stop grace period. tower.data-studio.force-stop-threshold (default 10m) sets how long a studio must be stuck in a non-final state before it is force-stopped, and tower.data-studio.approaching-expiration-threshold (default 15m) sets how long before a scheduled auto-stop the extend warning appears.
  • Added persistent per-user favorites and filters that persist across navigation.
  • Added the ability to cancel Studios stuck in the stopping state.
  • Added a Logs tab to the Studio details page, showing the process log for the most recent session read from the compute environment's log stream. Logs are available while a session is starting and running, and after a stop or crash. They survive an ungraceful shutdown. The existing studio:read grant covers the tab, through GET /studios/{sessionId}/log. How far back logs go depends on the compute provider and its log retention.
  • Added Conda packages for Studios built from a custom container image. Wave builds the packages on top of the image, and the Studio details page shows the Conda configuration.
  • Added custom certificate authority configuration for Studios.
  • Added checkpoint revalidation for the last checkpoint.
  • Added NVIDIA environment variables for GPU Studios.
  • Added a waveBuildNotification user preference controlling Wave build emails for custom Studio environments.
  • Added a custom icon for a Studio, uploaded on create, start, or update and shown on the Studios list and details pages.
  • Added workload identity federation for Studios on AWS and Google Cloud compute environments whose credential uses it. A session gets its own cloud identity instead of the compute environment's credentials. Requires Seqera Connect client 0.14.0 or later in the Studio's container image.

Access control​

  • Added aud claim support on OIDC access tokens. TOWER_OIDC_ACCESS_TOKEN_AUDIENCE sets the audience stamped on issued tokens, and TOWER_OIDC_AUDIENCE_ENFORCEMENT_ENABLED (default false) controls whether incoming Platform-issued tokens are rejected on a mismatch or merely logged.
  • Added the RFC 8693 token_exchange flow.
  • Added OAuth 2.0 refresh-token rotation, with tokens hashed using truncated SHA-256.
  • Added OAuth 2.0 token revocation (POST /oauth/revoke, RFC 7009) and token introspection (POST /oauth/introspect, RFC 7662), both advertised in /.well-known/openid-configuration. Revocation ends the presenting client's refresh-token family and returns 200 whether or not the token existed. Introspection is restricted to confidential clients and currently answers for refresh tokens only: every access token is reported active: false. You cannot yet use it to validate access tokens.
  • Added configurable OIDC scopes via TOWER_OIDC_SCOPES.
  • Added support for extra static OIDC clients, and propagated identity provider (IdP) service roles in issued OIDC tokens.
  • Enabled IdP claims mapping by default for Enterprise deployments (TOWER_IDP_CLAIMS_MAPPING_ENABLED, default true), with an optional organization allow-list.
  • Added Co-Scientist chat as a custom-role permission.
  • Added the agent:read, agent:write, agent:execute, and agent:delete permissions, listed under AI with chat:execute in custom roles. The predefined owner, admin, and maintain workspace roles hold all four, launch and project hold agent:read and agent:execute, and connect and view hold none. A custom role also needs credentials:read to choose a GitHub App credential on the agent form.
  • Added a Projects permission category and a project predefined workspace role, which grants project_view:read and withholds the broader workspace_resources:read. Both appear in the workspace role picker and in custom-role templates. The Projects view they gate is enabled by default in every organization workspace. See Upgrade notes.
  • Split the data_link and data_link_object permissions.

Service accounts​

Service accounts turn on with agents. They are available in every organization once TOWER_AGENT_BACKEND_URL is set. To restrict them to specific organizations, set TOWER_AGENT_CONFIGURATION_ALLOWED_ORGANIZATIONS to a comma-separated list of organization IDs. See Upgrade notes.

  • Added service accounts: non-human identities that belong to an organization and that an agent can run as. Organization owners add, view, edit, and delete them from the new Service accounts tab under Access control. A service account's page lists the workspaces it can act in, with a read-only Permissions matrix per workspace. Names follow the user-name rules and must be unique across the installation, and deleting a service account removes it from every workspace and frees its name.
  • Added workspace roles for service accounts. From a service account's edit page, Assign to workspace grants it any built-in or custom role except Owner. Each role change or removal applies immediately, and Update saves only the name and description. A service account can also be added from a workspace's participants list, where it carries a service account badge and its own avatar, and it gets View when no role is specified instead of the Launch a person gets.
  • Added a permission ceiling for service account role assignments. Anyone who adds a service account to a workspace or changes its role there must hold every permission that role grants in that workspace, or the request is rejected with a 403 naming the missing permissions. Root users are exempt.
  • Added sign-in and token restrictions for service accounts. Every interactive login path rejects a service account, and an email login for its address shows "Service accounts cannot sign in to Seqera Platform." instead of sending a link. A service account cannot create personal access tokens and is never granted the root role through the root users list. It holds only a minimal service_account user-context role. Platform refuses user-level operations, such as creating an organization.
  • Added organization membership rules for service accounts. A service account holds a fixed service_account organization role that cannot be changed or given to anyone else. It cannot join a team, be invited as a workspace collaborator, or be added or removed through the organization member endpoints, and it does not appear in the organization Members list. Each service account counts toward the organization's member limit.
  • Marked service accounts in the admin panel. The users list and the Members of organization and Workspace participants tabs show a service account badge and a distinct avatar, and the organization role column reads Service account. Editing a service account there locks its generated email and hides the first and last name, avatar, and email-notification fields. Platform rejects a change to any field other than the user name, organization, and description with a 400.
  • Added global search across workspaces, with infinite scroll and suggestions, backed by the data lineage query language. Enabled by default. To turn it off, set TOWER_GLOBAL_SEARCH_ENABLED to false.
  • Added an administrative endpoint for lineage storage reindexing, plus a reindex schedule configurable with TOWER_CRON_LINEAGE_REINDEX_*.
  • Aligned global search (⌘K / Ctrl+K) with the backend lineage search DSL: workspace scoping now uses org/name, the OR delimiter within a qualifier is now a comma (previously |), and typed input passes straight through to the backend.
  • Renamed Search to Lineage search, to make clear that results cover Data Lineage records only.
  • Reworked the lineage search modal: keyword filters are offered as suggestions as you type, a dismissible banner states that results cover lineage records only, and a workspace with lineage disabled gets an explanatory empty state offering to search across all workspaces instead.

Data lineage​

  • Made data lineage available in every organization workspace by default: it can be limited to specific workspaces by setting a comma-separated list of workspace IDs at TOWER_LINEAGE_ALLOWED_WORKSPACES. See Upgrade notes.
  • Added the lineage ID to the run info page.
  • Added filtering of lineage search results by pipeline.
  • Changed lineage record ingestion to consume SNS push notifications instead of polling SQS.

Data Explorer​

  • Added the object last-modified timestamp to the Data Explorer file listing.
  • Added re-signing of presigned URLs for a subset of parts of an in-progress multipart upload (uploadId and partNumbers). Long uploads now recover from expired signing credentials instead of failing. AWS S3 and S3-compatible storage only.

Secrets​

  • Redesigned the secrets list as a row-card table.

Monitoring and observability​

  • Added route-aware OpenTelemetry tracing. Tracing records nothing until you configure an exporter. The standard OTEL_* environment variables control sampling, resources, and export. Health, ping, Prometheus, metrics, OpenAPI, and favicon routes are excluded by default.
  • Added aggregate entity telemetry, sent with the license check. Payload identifiers are hashed, the reporting window defaults to 7 days, and the license check is retried with the telemetry attached. Controlled by TOWER_TELEMETRY_BASIC_ENABLED and TOWER_TELEMETRY_STANDARD_ENABLED (both default true) and TOWER_TELEMETRY_WINDOW_DAYS.
  • Audit log events are now written only to the v2 schema. The TOWER_AUDIT_LOG_V2_WRITE_MODE setting and the v1 write path have been removed. This is a breaking change for database consumers and ETL jobs that read the v1 tw_audit_log table. See Upgrade notes.
  • Added a request correlation ID, propagated through the logging context.
  • Added OAuth token metrics and a current-month CPU hours metric.
  • Added audit entries for pre-flight cron status transitions, a user_updated event for authentication provider changes, and metadata on the audit log v2 state element.
  • Added service accounts to the audit log. Actions a service account takes are recorded with a new service_account actor type, and creating, updating, and deleting one records service_account_created, service_account_updated, and service_account_deleted. In the admin audit log, the actor shows a Service account badge and its ID instead of its generated email, plus an Agent ID when an agent acted, which the CSV export carries in a new actorAgentId column.
  • Added an action_triggered audit log event. Platform writes it for every trigger of an Action, whether the trigger launched, failed, or was suppressed, and the event names the Action that fired.
  • Added dynamic axis scaling and precision to the job duration chart.

Co-Scientist​

Once TOWER_AGENT_BACKEND_URL points Seqera Platform at the Co-Scientist agent backend, chat is enabled for every organization by default. Set TOWER_AI_CHAT_ALLOWED_ORGANIZATIONS to restrict it to a list of organization IDs. See Upgrade notes.

  • Added the Co-Scientist chat assistant, docked beside page content, with a close control and conversation history that can be selected and deleted.
  • Added compute environment and list-page view context, retained referenced context in chat messages, and page context with screenshots.
  • Added structured tool result rendering and a Co-Scientist usage display.
  • Sped up the page screenshots that chat attaches as page context, and shortened the time the page is unresponsive while one is captured.

Agents​

Once TOWER_AGENT_BACKEND_URL points Seqera Platform at the Co-Scientist agent backend, agents are enabled for every organization by default, together with service accounts and the Trigger agent button. Set TOWER_AGENT_CONFIGURATION_ALLOWED_ORGANIZATIONS to restrict them to a list of organization IDs. See Upgrade notes.

  • Added Agents to the AI section of the workspace navigation, for configuring reusable AI agents in a workspace. An agent has a name, an optional description, and Agent instructions, and can start from the Fix failed runs, Summarize successful runs, or Summarize failed runs template. You manage it with Pause, Resume, Edit, and Remove from the agents list or its own page. Agent configuration is stored by the Co-Scientist agent backend, and each change is recorded as an agent_created, agent_updated, agent_enabled, agent_disabled, or agent_deleted audit event.
  • Added a Trigger agent button to run details, beside the execution log or in the error panel of a failed run, and to each run in a project's Runs tab. It lists the workspace's active agents, launches the one you select with the run's context, and opens the resulting session in the Co-Scientist panel. When the workspace has no agents, it offers Add agent instead. The button needs Co-Scientist chat and the agent:execute permission, and a failed launch shows the reason Platform or the agent backend returned instead of a generic error.
  • Added a check of an agent's service account each time the agent is saved or launched. Platform refuses the request with a 409 that names the failed condition, instead of running the agent with the launching user's permissions. The conditions are that the service account was deleted or disabled, is not a participant in the workspace, or has a role without agent:execute. A run that passes acts as the service account, and Platform hands its credentials to the agent backend through a single-use /ephemeral URL.
  • Added automatic disabling of the agents bound to a service account when that account is removed from their workspace or deleted from the organization. They then show as Inactive and drop out of Trigger agent, instead of failing at their next launch. Re-adding the service account does not re-enable them. Resume each one from the Agents page.
  • Added an optional GitHub App credential to the Agent permissions section of the agent form, next to the Service account the agent runs as. The agent uses that workspace credential to clone, commit, and push. Platform rejects a credential from another workspace, of another type, or marked invalid, with a 400 on save and a 409 at launch. The form blocks saving while the bound credential is missing or invalid.
  • Added a Sessions tab to the agent page, listing the agent's background runs with their Status, Trigger, Service account, and Run ID. The list refreshes while a run is in progress. Sessions can be searched by keyword, and View session opens a session in the Co-Scientist panel through a link you can share.
  • Added Fork conversation to agent sessions in the Co-Scientist panel. Agent sessions open read-only there, with the notice "Agent sessions are read-only. Fork the conversation to continue it as your own chat." Forking copies the session into a chat of your own and opens it.

Projects​

The Projects view is enabled by default in every organization workspace. Set TOWER_SCIENTIST_VIEW_ALLOWED_WORKSPACES to a comma-separated list of workspace IDs to restrict it. See Upgrade notes.

  • Added a Projects view, opened from a Workspace/Projects switcher in the side navigation, that groups a workspace's pipelines, datasets, and runs by project. A project is a workspace label named proj_<name>: Add project creates the label and applies it to the pipelines and datasets you choose, Edit renames it or changes those resources, and Delete removes the label and its resource associations but not the resources. Project names must be unique in the workspace, ignoring case, and each action requires the matching label permission.
  • Added project pages with Runs, Datasets, and Reports tabs, each filtered to the project's label, plus a <workspace name> overview that covers the whole workspace. On Datasets, adding a dataset or version and editing dataset details happen in dialogs, and a dataset added there gets the project's label. Reports collects the reports of successful runs on the Runs pages loaded so far, with search, preview, and Download, and a run's View reports opens it filtered to that run.
  • Added launching from a project. On a project's Runs tab, Launch pipeline lists only the pipelines that carry the project's label. It and a failed run's Relaunch open an essentials-only launch form: Run parameters shows only the parameters the pipeline schema marks as required, with a Show all parameters toggle, and the Advanced settings and Summary steps are left out. Runs launched from a project carry its label. On a project with no pipelines, Launch pipeline is hidden and only users with pipeline_label:write are offered Add pipeline.
  • Added project awareness to the workspace Labels settings page: proj_ labels show a Project badge and link to their project, the Show filter gains a Project option, and creating, renaming, or deleting a proj_ label warns what that does to the project. The pipeline and dataset forms hide proj_ labels from their Labels field and refuse to create one there. Editing a pipeline or dataset keeps it in its projects.

General​

  • Added a default workspace preference to the user profile.
  • Added a panel search input to the navigation switcher, and made list pages preserve their page and search filters across item navigation.
  • Made the docked sidenav the default experience, and made row cards clickable.
  • Added nf-launcher 25.10.6, 25.10.7, and 26.08.0-edge to the version catalog.
  • Added a startup warning when tower.oidc.pem.path is unconfigured.
  • Added a compact relative date display across list views.

Bug fixes​

Pipelines​

  • Fixed the output directory not being preserved on resume.
  • Fixed workspace participants whose role lacks pipeline:write, such as Launch, being unable to resume a run whose launch had Pull latest enabled. The resume failed with Field 'pullLatest' is not writable: unset or use previous value.
  • Fixed optimization targets not being returned verbatim on launch, and the optimization banner not appearing when relaunching a shared pipeline run.
  • Fixed the custom schema being discarded when added for the first time in edit mode.
  • Fixed the Nextflow syntax parser v2 toggle not being seeded from the saved launch configuration, and a Nextflow version being unselectable when the source pinned none.
  • Fixed duplicate GitHub credentials being created across personal access token and GitHub App types.
  • Fixed the credentials field not being mandatory in the Add data repository form.
  • Fixed a path picked from an Azure data link in the launch form, for the output directory or a path parameter, including the storage account (az://<account>.<container>/…), which Nextflow cannot resolve. The picker now inserts az://<container>/…, and on an Azure compute environment it disables data links whose credentials differ from the compute environment's.

Actions​

  • Fixed a pipeline action triggered by a GitHub webhook failing to launch on an HPC compute environment connected through Tower Agent, with Cannot retrieve user ID: missing authenticated user in current request context.
  • Fixed a redelivered GitHub webhook launching its pipeline again. Platform now records each X-GitHub-Delivery ID and launches once per delivery unless the first launch failed.
  • Fixed the action form's Add and Update buttons staying disabled after an invalid pipeline revision was corrected, which left the form unusable until the page was reloaded.

Compute environments​

  • Fixed unusable credentials being accepted on a compute environment.
  • Fixed the compute environment form allowing submission while invalid, and the Add credentials button missing in create mode.
  • Fixed the SLURM and HPC executor message being reported as an error rather than a warning.
  • Fixed the compute environment form not requiring a VPC when external IP addresses are disabled.

AWS​

  • Fixed AWS Cloud head-job failures not being surfaced.
  • Fixed vpcId and subnet selection not being applied to the AWS Cloud head job.
  • Fixed runs being flagged for attention when a UserData script failed, and downgraded all AWS UserData-check permission denials to warnings.
  • Fixed ecs:DescribeContainerInstances permission errors being logged at error level.

Azure​

  • Fixed nextflowConfig not being preserved on forged Azure Cloud compute environments.
  • Fixed the unsupported Fusion snapshots toggle appearing on the Azure compute environment form.
  • Fixed Entra credential comparison and made the managed identity regular expression case-insensitive.

GCP​

  • Fixed GOOGLE_CLOUD_PROJECT not being set on the GCP Batch head job, which prevented secret resolution.
  • Fixed pipeline secrets not being pinned to the compute environment region.

Studios​

  • Fixed baseline Studio capabilities not being used when the manifest is missing or the Studio version is absent from it.
  • Fixed mount configuration being double-quoted on every compute environment type, which could leave a session unable to reach its mounted data.

Data lineage​

  • Fixed the session ID of resumed runs not resolving without runName.
  • Fixed lineage being reported as not enabled for submitted runs when it was enabled.
  • Fixed the launch toggle remaining enabled when lineage settings are unset or the compute environment does not support lineage.
  • Fixed the Launcher role being able to override the lineage setting.
  • Fixed the launch form requesting lineage in a user workspace.

Data Explorer​

  • Fixed GCS genomic file URLs not being signed with V4, which broke IGV preview.
  • Fixed IGV reference genome URLs not being signed, and corrected IGV rendering.
  • Fixed S3 buckets disappearing when an ACL fetch is denied.

Access control​

  • Fixed IdP group mapping visibility not refreshing when SSO is toggled.
  • Fixed the custom role form ignoring the selected template. Choosing a template now applies its permissions, the form preselects the template its permissions were prefilled from, and Restore defaults is renamed Reset to template.
  • Fixed an uploaded avatar not persisting when an administrator creates a user.
  • Fixed a new participant not being assigned the role requested for them.

General​

  • Fixed the sidebar section not being preserved when switching workspace, including on redirect.
  • Fixed features not being refetched after authentication.
  • Fixed the default workspace preference not being cleared correctly.
  • Fixed the global search keyboard shortcut hint showing ⌘K on Windows and Linux instead of Ctrl+K.
  • Fixed the runs list not rendering in personal workspaces.

Upgrade notes​

Only one frontend container image is published​

From 26.2, Seqera publishes a single frontend container image. This is a breaking change for any deployment that pins a tag variant, and for any deployment that pins the plain tag and relies on the container listening on port 80.

  • Seqera no longer publishes the -root or -unprivileged tag variants of the frontend image cr.seqera.io/enterprise/platform/frontend:<tag>. A manifest referencing cr.seqera.io/enterprise/platform/frontend:<tag>-unprivileged or cr.seqera.io/enterprise/platform/frontend:<tag>-root fails to pull on 26.2.

Before upgrading, point every frontend image reference at the plain tag and make the port match:

  • Kubernetes: set the container ports.containerPort and the frontend service's targetPort to 8000, leaving the service port at 80.
  • Docker Compose: map the host port to container port 8000, for example 8000:8000.

NGINX_LISTEN_PORT (default 8000) still overrides the listening port if you need a different one. Set targetPort, or the container side of the port mapping, to the same value. See Kubernetes deployment and Docker Compose deployment.

Telemetry on the license check​

Seqera Platform Enterprise 26.2 sends aggregate entity telemetry alongside the existing license check. Identifiers in the payload are hashed before transmission and the reporting window covers the previous 7 days by default.

This is enabled by default. The two tiers do not combine:

  • TOWER_TELEMETRY_STANDARD_ENABLED (default true) reports entity-level records: one per run, Studios session, Studios audit event, day of Data Explorer activity, and workspace. Set it to false to fall back to the aggregate counters alone.
  • TOWER_TELEMETRY_BASIC_ENABLED (default true) reports the aggregate usage counters Platform sent before entity-level telemetry existed. It is only consulted when standard telemetry is off.
  • TOWER_TELEMETRY_WINDOW_DAYS (default 7) sets the reporting window.

To opt out entirely, set both flags to false. Platform then runs no telemetry query and sends no telemetry data. The installation still reports the opt-out, which lets Seqera tell it apart from an installation that stopped reporting. Licensing and quota retrieval are unaffected by either flag. See Telemetry.

User IDs, repository names, Studios template and image references, and organization and workspace names are hashed before they leave the installation.

Co-Scientist chat is enabled by default​

Once TOWER_AGENT_BACKEND_URL is set, Co-Scientist chat is available to every organization in the installation. To restrict it, set TOWER_AI_CHAT_ALLOWED_ORGANIZATIONS to a comma-separated list of organization IDs. The Platform Helm chart sets TOWER_AGENT_BACKEND_URL automatically when the agent-backend subchart is enabled.

Chat sends page context, including screenshots of the page the user is viewing, to the configured AI backend. Before you upgrade, check whether that is acceptable for your installation. If it is not, set the variable.

Agents, service accounts, and the Trigger agent button are enabled with the agent backend​

Once TOWER_AGENT_BACKEND_URL is set, agents, service accounts, and the Trigger agent button on run pages are available in every organization of the installation unless you restrict them. The Platform Helm chart sets the variable when the agent-backend subchart is enabled. When the subchart is disabled, all three features are off, as is Co-Scientist chat. None of them is available in a personal workspace.

TOWER_AGENT_CONFIGURATION_ALLOWED_ORGANIZATIONS is empty by default, which makes agents available in every organization. To restrict them, set it to a comma-separated list of organization IDs.

Co-Scientist web interface is removed​

The Platform Helm chart no longer includes the portal-web subchart, and the standalone Co-Scientist web interface and its CLI install endpoint are removed. Users work in the Co-Scientist panel in Seqera Platform and install the CLI from npm. When you upgrade from v26.1, remove the portal-web values and global.portalWebDomain from your helm installation values, and retire the web interface DNS record. See Install Co-Scientist.

Projects move into Seqera Platform and use proj_ labels instead of project_. Rename existing project_* labels to keep them as projects. The Projects view is enabled by default. See The Projects view is enabled by default.

The Projects view is enabled by default​

Seqera Platform Enterprise 26.2 adds the Projects view and enables it by default. To restrict the view, set TOWER_SCIENTIST_VIEW_ALLOWED_WORKSPACES to a comma-separated list of workspace IDs, or to 0 to turn it off in every workspace.

MCP server image moves to the enterprise/ registry project​

MCP server images from 1.4.3 are published only to cr.seqera.io/enterprise/mcp/server. cr.seqera.io/ai/mcp/server serves releases up to 1.4.2 and receives no new ones. Use Platform chart 1.0.4 or later, which defaults to the new repository. On an earlier chart, set mcp.image.repository: enterprise/mcp/server. If you mirror images, add enterprise/mcp/server to your mirror, and remove any mcp.image.repository: ai/mcp/server override from your values. See Install Co-Scientist.

The component compatibility catalog is enabled by default​

TOWER_CATALOG_ENABLED now defaults to true. On upgrade, with no configuration change, Platform serves the /catalog/* endpoints. The launch version picker and launch validation read the catalog instead of the built-in version list. By default, that is the bundled catalog-state.json. In 26.2, the bundled catalog lists the same Nextflow versions as the built-in list and defaults to 26.04. No previously selectable version is lost. Set TOWER_CATALOG_ENABLED to false to restore the previous behavior. See Component compatibility catalog.

Data lineage is available in every workspace by default​

Data lineage is now available in every organization workspace. In 26.1, leaving the TOWER_LINEAGE_ALLOWED_WORKSPACES environment variable unset (the default) disabled lineage everywhere. An installation that never set it gains lineage in every workspace on upgrade. Lineage is never available in personal workspaces.

  • Availability alone does not turn lineage on for runs: a run records lineage by default only in a workspace whose lineage settings turn on Enable lineage by default.
  • To limit lineage to specific workspaces, set TOWER_LINEAGE_ALLOWED_WORKSPACES to a comma-separated list of their IDs before upgrading. See Upgrade deployment.

Audit log v1 writes are removed​

Seqera Platform Enterprise 26.2 writes audit events only to the v2 schema. This is a breaking change for direct database consumers and custom ETL jobs that still read new events from the legacy v1 schema (tw_audit_log table).

  • The TOWER_AUDIT_LOG_V2_WRITE_MODE setting is removed and has no effect. Remove it from your configuration.
  • Platform writes no new rows to the v1 schema. Existing rows remain until the audit log retention period deletes them. As long as the table has records, they stay visible in the Table v1 tab of the Admin panel Audit logs page, which is hidden once the legacy table is empty.

OIDC audience enforcement​

The OIDC access tokens that Seqera Platform issues can now carry an aud claim, set with TOWER_OIDC_ACCESS_TOKEN_AUDIENCE. Enforcement is a separate switch that starts in warn-only mode. With TOWER_OIDC_AUDIENCE_ENFORCEMENT_ENABLED at its default of false, Platform logs audience and issuer violations on the OIDC access tokens it issues but still accepts the tokens. Set it to true only after confirming your clients present the expected audience. See OIDC access tokens.

Nextflow version floors per compute environment type​

The Nextflow version catalog sets a minimum Nextflow version for several compute environment types, and features that require a newer runtime raise that floor further. Compute environments pinned to an older Nextflow version may need updating. Review your pinned versions before upgrading.

Grant consolidation​

The ComputeEnvironment_Validate grant is folded into ComputeEnvironment_Write. Custom roles that held the validate grant without write access lose it on upgrade, and the built-in Maintain role can no longer validate compute environments. Add compute_environment:write to any custom role that still needs to validate.

Google Cloud pipeline secrets are now regional​

Platform now creates pipeline secrets for Google Batch and Google Cloud compute environments with user-managed replication pinned to the compute environment's region, instead of global replication. This applies to every Google Cloud compute environment, not only those in projects that enforce constraints/gcp.resourceLocations. A regional Secret Manager outage now fails secret creation where global replication would have succeeded. This is deliberate, because the job runs in the same region.

Pre-flight checks are enabled by default​

Seqera Platform Enterprise 26.2 enables pre-flight checks and credential validation by default. TOWER_PREFLIGHT_CHECK_ENABLED and TOWER_CREDENTIALS_VALIDATION_ENABLED both default to true. After upgrading, an installation that has not set either variable validates credentials on create and update, and re-validates credentials and compute environments every 12 hours. It rejects launches against INVALID credentials or compute environments with a 400, and hides INVALID credentials in the compute environment creation form.

A credential that a provider-side policy change has quietly broken therefore starts blocking launches at upgrade rather than failing the run. Review the credentials list after upgrading.

To keep the previous behavior, set both variables to false. Disable them together. With credential validation off and pre-flight checks on, Platform still rejects launches against INVALID credentials, but the Credentials page hides the INVALID status and the Validate action. See Compute environment pre-flight checks.

Compute environments reject unusable credentials​

Creating or updating a compute environment against an invalid or deleted credential previously succeeded silently and produced a compute environment that could not run. It now returns a 400. Automation that creates or updates compute environments should handle this response.

Workload identity federation is enabled by default​

Seqera Platform Enterprise 26.2 enables workload identity federation in every organization workspace. It takes effect once the OIDC provider is configured with TOWER_OIDC_PEM_PATH. To restrict it, set TOWER_IDENTITY_FEDERATION_ALLOWED_WORKSPACES to a comma-separated list of workspace IDs. See Enable workload identity federation.

This is a breaking change for Google Cloud credentials that already use workload identity. Before 26.2, they presented the workflow subject on every call. In an enabled workspace they now present platform, data, studio, or workflow, depending on the request. An impersonation binding against the exact workflow subject, or against an attribute.workload value, stops matching and the workspace loses access. Before upgrading, update those bindings to admit every subject, or leave the workspace out of TOWER_IDENTITY_FEDERATION_ALLOWED_WORKSPACES to keep the workflow subject. See Existing Google Cloud credentials.

IdP group claim handling​

Platform now treats absent IdP group claims as an empty set instead of ignoring them. A user whose claims arrive without group information loses their delegated memberships. Confirm that your identity provider sends group claims on every assertion before upgrading.

Platform API specification version​

The Platform API specification in this release is version 1.227.0 (Seqera Enterprise 26.1.5: 1.184.0). Many response properties are now declared nullable. Regenerate any client or contract test generated from an earlier specification.