Seqera Enterprise v26.2
Seqera Platform Enterprise 26.2 adds event-driven Actions, triggered by bucket events, schedules, and pipeline run events. It also adds Co-Scientist agents that run as service accounts, a Projects view, a system-wide Nextflow version selector, and pre-flight validation for credentials and compute environments. Other additions are global search backed by the data lineage query language, customer-managed KMS encryption for pipeline secrets, and route-aware OpenTelemetry tracing. For identity and access management, 26.2 adds OIDC audience enforcement, RFC 8693 token exchange, refresh-token rotation, and more SCIM auditing.
Highlights
- You can launch a pipeline with a specific Nextflow version, chosen from a system-wide catalog of
nf-launcherimages. Each compute environment type sets a minimum version. See Compute environments. - Platform validates credentials and compute environments before launch, on a schedule, and on demand. Broken credentials surface before a run fails. This is enabled by default. See Upgrade notes.
- Actions can be triggered by a bucket event, a schedule, or a pipeline run event, can start an agent instead of a pipeline, and record a trigger history. The three triggers are enabled by default in every workspace.
- Global search, backed by the data lineage query language, searches across workspaces. It is on by default. To turn it off, set
TOWER_GLOBAL_SEARCH_ENABLEDtofalse. - You can encrypt pipeline secrets with a customer-managed AWS Key Management Service (KMS) key, set with
TOWER_AWS_SECRETS_KMS_KEY_ID. - Enterprise deployments now send aggregate entity telemetry with the license check. This is enabled by default. See Upgrade notes.
- Co-Scientist chat is available to every organization in the installation. It is enabled by default once the Co-Scientist agent backend is configured. See Upgrade notes.
- You can configure reusable AI agents per workspace and start one from a run with Trigger agent. Each agent acts as its bound service account. Agents are enabled by default once the Co-Scientist agent backend is configured. See Upgrade notes.
- A Projects view groups a workspace's pipelines, datasets, and runs by project, and launches from a project use an essentials-only launch form. This is enabled by default in every organization workspace. See Upgrade notes.
- The standalone Co-Scientist web interface (provided by the
portal-webchart) is removed. Co-Scientist is now part of Seqera Platform. See Upgrade notes. - A component compatibility catalog records which Nextflow, Fusion, and
nf-launcherartifacts work with this Platform version, with deployment-local overrides for private registries. This is enabled by default. See Upgrade notes. - Platform can stamp the
audclaim on the OIDC access tokens it issues and enforce it. Enforcement is off by default and only logs mismatches. See Upgrade notes. - Studios support private sessions restricted to an allow-list of users, per-user favorites, and a configurable automated stop grace period.
- Route-aware OpenTelemetry tracing is available through the standard
OTEL_*environment variables. - Studios gain a Logs tab that streams a session's process log directly from the compute environment. Logs survive an ungraceful shutdown.
- The compute environment, credentials, and Actions lists are redesigned as row-card tables with attribute chips, grouping, and search.
- From 26.2, Seqera publishes one frontend container image,
platform/frontend:<tag>, which runs in unprivileged mode. The-unprivilegedtag alias and the-rootvariant, which ran as the root user, are gone. See Upgrade notes. - Platform writes audit events only to the v2 schema. This is a breaking change for direct database consumers and ETL jobs that read the v1
tw_audit_logtable. Update them to the v2 schema before you upgrade. See Upgrade notes.