Skip to main content

Seqera Enterprise v26.2

Seqera Platform Enterprise 26.2 adds event-driven Actions, triggered by bucket events, schedules, and pipeline run events. It also adds Co-Scientist agents that run as service accounts, a Projects view, a system-wide Nextflow version selector, and pre-flight validation for credentials and compute environments. Other additions are global search backed by the data lineage query language, customer-managed KMS encryption for pipeline secrets, and route-aware OpenTelemetry tracing. For identity and access management, 26.2 adds OIDC audience enforcement, RFC 8693 token exchange, refresh-token rotation, and more SCIM auditing.

Highlights​

  • You can launch a pipeline with a specific Nextflow version, chosen from a system-wide catalog of nf-launcher images. Each compute environment type sets a minimum version. See Compute environments.
  • Platform validates credentials and compute environments before launch, on a schedule, and on demand. Broken credentials surface before a run fails. This is enabled by default. See Upgrade notes.
  • Actions can be triggered by a bucket event, a schedule, or a pipeline run event, can start an agent instead of a pipeline, and record a trigger history. The three triggers are enabled by default in every workspace.
  • Global search, backed by the data lineage query language, searches across workspaces. It is on by default. To turn it off, set TOWER_GLOBAL_SEARCH_ENABLED to false.
  • You can encrypt pipeline secrets with a customer-managed AWS Key Management Service (KMS) key, set with TOWER_AWS_SECRETS_KMS_KEY_ID.
  • Enterprise deployments now send aggregate entity telemetry with the license check. This is enabled by default. See Upgrade notes.
  • Co-Scientist chat is available to every organization in the installation. It is enabled by default once the Co-Scientist agent backend is configured. See Upgrade notes.
  • You can configure reusable AI agents per workspace and start one from a run with Trigger agent. Each agent acts as its bound service account. Agents are enabled by default once the Co-Scientist agent backend is configured. See Upgrade notes.
  • A Projects view groups a workspace's pipelines, datasets, and runs by project, and launches from a project use an essentials-only launch form. This is enabled by default in every organization workspace. See Upgrade notes.
  • The standalone Co-Scientist web interface (provided by the portal-web chart) is removed. Co-Scientist is now part of Seqera Platform. See Upgrade notes.
  • A component compatibility catalog records which Nextflow, Fusion, and nf-launcher artifacts work with this Platform version, with deployment-local overrides for private registries. This is enabled by default. See Upgrade notes.
  • Platform can stamp the aud claim on the OIDC access tokens it issues and enforce it. Enforcement is off by default and only logs mismatches. See Upgrade notes.
  • Studios support private sessions restricted to an allow-list of users, per-user favorites, and a configurable automated stop grace period.
  • Route-aware OpenTelemetry tracing is available through the standard OTEL_* environment variables.
  • Studios gain a Logs tab that streams a session's process log directly from the compute environment. Logs survive an ungraceful shutdown.
  • The compute environment, credentials, and Actions lists are redesigned as row-card tables with attribute chips, grouping, and search.
  • From 26.2, Seqera publishes one frontend container image, platform/frontend:<tag>, which runs in unprivileged mode. The -unprivileged tag alias and the -root variant, which ran as the root user, are gone. See Upgrade notes.
  • Platform writes audit events only to the v2 schema. This is a breaking change for direct database consumers and ETL jobs that read the v1 tw_audit_log table. Update them to the v2 schema before you upgrade. See Upgrade notes.

Nextflow 26.09.1-edge

Feature updates and improvements​

Language features​

  • Moved the type checker into nf-lang and brought static typing out of preview by @bentsherman in #7656

Google Batch​

  • Deprecated Google Batch machine type selection via Cloud Info by @bentsherman in #7677

Plugins​

  • Allowed a cache factory to decline a session by @jorgee in #7681

General​

  • Added a hint to nextflow log and nextflow clean errors that the commands do not support the cloud cache by @bentsherman in #7676
  • Removed a stray git push from the release task by @bentsherman in #7678

Bug fixes​

S3​

  • Fixed S3 upload retries by making ByteBufferInputStream resettable by @jorgee in #7577

Google Batch​

  • Fixed Google Batch array-child tasks reporting a null machine type by @pditommaso in #7629

Dependencies​

  • Bumped Bouncy Castle to 1.85 to fix critical CVEs by @pditommaso in #7658
  • Bumped pi-coding-agent to 0.84.4 to fix npm advisories by @pditommaso in #7659
  • Bumped slf4j to 2.0.19 by @pditommaso in #7661
  • Fixed npm advisories in the docs site dependencies by @pditommaso in #7660
  • Bumped nf-agent-pi@0.5.3
  • Bumped nf-amazon@3.11.1
  • Bumped nf-cloudcache@0.6.2
  • Bumped nf-google@1.28.1
  • Bumped nf-k8s@1.6.1

Full changelog: https://github.com/nextflow-io/nextflow/releases/tag/v26.09.1-edge

Nextflow 26.09.0-edge

Feature updates and improvements​

Language features​

  • Added direct execution of named workflows by @jorgee in #7379
  • Added workflow modules by @bentsherman in #7342
  • Deprecated the storeDir directive and documented an alternative approach by @bentsherman in #7574
  • Documented multiple architectures in the arch directive by @pditommaso in #7622
  • Made eval output names stable across runs by @bentsherman in #7575
  • Reported a syntax error for an invalid output or emit assignment by @bentsherman in #7547
  • Reported an error for an aliased type include by @bentsherman in #7557
  • Reported invalid escape sequences at the exact position by @bentsherman in #7608

Configuration​

  • Added a directory option to resolve report paths against outputDir by @bentsherman in #7553
  • Added the manifest.diagram config option by @pinin4fjords in #7578

Azure​

  • Added Azure Compute Gallery image and verification options by @LennyBEL in #7338

Google Batch​

  • Sped up submission of Google Batch array jobs by @thalassemia in #6847

Kubernetes​

  • Changed the default k8s compute resource type to Job by @bentsherman in #7524

Plugins​

  • Added extension points for task caching and object-storage access by @jorgee in #7638
  • Removed support for nf-weblog by @bentsherman in #7639

General​

  • Added automatic resource labels for any executor by @pditommaso in #7528
  • Added a codespell CI check and fixed existing typos by @ewels in #7594
  • Added configurable timeouts to SCM API requests by @robsyme in #7536
  • Added deep links to migration notes by @bentsherman in #7624
  • Added retries for request timeouts in the Tower and Wave HTTP clients by @pditommaso in #7604
  • Adopted the shared io.seqera:lib-util-net ProxyConfig for egress proxy handling by @pditommaso in #7587
  • Cleaned local task directories in hybrid runs by @bentsherman in #7611
  • Cleaned up ADR prose and fixed typos by @bentsherman in #7595
  • Cleaned up the 26.08.0-edge changelog by @pditommaso in #7527
  • Deduplicated include URI resolution logic by @bentsherman in #7644
  • Improved resilience to delayed shared file system visibility by @pditommaso in #7489
  • Made NXF_AGENT_MODE an explicit override of agent mode auto-detection by @bentsherman in #7615
  • Renamed SCM HTTP client timeouts to the global NXF_HTTPCLIENT_* namespace by @pditommaso in #7567
  • Stopped Nextflow submitting queued tasks after the session has aborted by @Mohit-Ak in #7482

Dependencies​

  • Aligned the nf-agent test Groovy dependency to 4.0.33 by @pditommaso in #7559
  • Fixed Jackson, Netty, and gRPC CVEs via API-scoped dependency constraints by @jorgee in #7329

Bug fixes​

Language features​

  • Fixed cloning of typed process outputs to also clone topics by @bentsherman in #7556
  • Fixed formatting of legacy type annotations by @bentsherman in #7525

Configuration​

  • Fixed a false warning for executor selectors by @bentsherman in #7555
  • Fixed the description for process config options with method overloads by @bentsherman in #7442
  • Fixed the resume config breaking other CLI commands by @bentsherman in #7581

S3​

  • Fixed S3 directory upload skipping symbolic links by @jorgee in #7515
  • Fixed workflow output publishing to S3 with the default path by @bentsherman in #7518

Azure​

  • Fixed nf-azure plugin tier-1 bugs by @adamrtalbot in #6831

Google Batch​

  • Fixed nextflow clean aborting on GCS pseudo-directories by @bentsherman in #7630
  • Fixed the env config scope not applied with Google Batch by @bentsherman in #7609
  • Fixed Google Batch storing symlinked task outputs as gcsfuse placeholders by @bentsherman in #7612

Plugins​

  • Fixed resolution of non-core plugin dependencies from the registry by @bentsherman in #7613

General​

  • Fixed a typo in the error message for an invalid LID path by @ewels in #7593
  • Fixed the lineage checksum computed in standard mode regardless of label by @bentsherman in #7582
  • Fixed a local executor resource accounting race by @pditommaso in #7652
  • Fixed the multi-revision test failing locally by @bentsherman in #7541
  • Fixed the output index file write to object storage by @bentsherman in #7635
  • Improved NFS lock error handling in DefaultCacheStore by @matthdsm in #6997

Full changelog: https://github.com/nextflow-io/nextflow/releases/tag/v26.09.0-edge

Seqera Cloud v26.2.0_cycle73

Feature updates and improvements​

Monitoring​

  • Added a live task execution timeline to the run Tasks tab, showing each task's queued and running time.

Pipelines​

  • Extended the Nextflow version list back to 23.03, from a previous floor of 25.10.
  • Added the pipeline diagram declared in manifest.diagram to the launchpad pipeline details page.

Studios​

  • Added custom Studio icons, shown in the Studios list and on the Studios page.

Co-Scientist​

  • Moved the sandbox chip into the chat composer toolbar, beside the context chips.

Data lineage​

  • Made data lineage available in organization workspaces for runs on AWS compute environments.
  • Added pipeline:<name> and pipelineId:<id> qualifiers to lineage search, matching a pipeline's runs, tasks, and published files.
  • Added pipeline names to lineage search results and a See syntax tips link to the search modal.
  • Changed data lineage ingestion from SQS polling to SNS notifications and added s3:ListBucket to the lineage IAM policy; manually configured workspaces must be reconfigured.

General​

  • Added the reason an action stopped or failed to the Actions list.
  • Redesigned the Actions list as a table showing each action's source, status, last event, and creator, with usage details in a dialog.
  • Added guided empty states to list pages, naming the next step to take.

Bug fixes​

Co-Scientist​

  • Fixed a closed Co-Scientist chat reopening on page refresh.
  • Fixed the left navigation staying collapsed after closing the Co-Scientist chat.

Pipelines​

  • Fixed GitHub Redeliver not retrying an action trigger whose launch failed.

Studios​

  • Fixed Studios SSH authorization rate limiting applying across all sessions instead of per session.

General​

  • Fixed labels beyond the first 100 missing from the launch form and label search, and label assignments dropping selections not on the current page.
  • Fixed an unstable sort order that repeated or omitted labels when paging through the label list.

Seqera Cloud v26.2.0_cycle72

Breaking changes​

  • Google Batch and Google Cloud compute environments now require a VPC network when Use private address is enabled, and Google Batch also requires a subnet. Both the compute environment form and the API reject a create or update request that enables private addressing without them. Previously, the environment was accepted and failed later at pipeline launch.

Feature updates and improvements​

Compute environments​

  • Added the AWS r9gd instance family to the local NVMe list.
  • Removed the Preview badge from Seqera Compute in the compute environment platform list.

Credentials​

  • Removed the Beta notice from Azure Entra service principal credentials.
  • Added a Set up Workload Identity Federation in GCP panel to Google Workload Identity credentials, listing the values to copy into your Google Cloud project: the OpenID Connect issuer URL, the google.subject mapping that makes Cloud Audit Logs trace activity back to the acting Seqera user, and a recommended attribute condition that pins the workload identity pool to your organization and workspace. The provider, service account email, and token audience fields moved to a Connect the federated identity panel.

Pipelines​

  • Added deduplication of repeated GitHub webhook deliveries to an action, preventing a resend from launching the pipeline a second time. A delivery that cannot be recorded now returns 500, and GitHub offers the resend rather than reporting success.
  • Added an audit log record for every action firing.
  • Added a Created by column to the Actions list.
  • Grouped the action form into Details, Trigger, and Target sections. The form omits the Trigger section for GitHub and Seqera sources, which a webhook endpoint drives instead.

Bug fixes​

Compute environments​

  • Fixed Kubernetes, EKS, and GKE compute environment validation reporting every connection failure as Unexpected error while processing request, so connection timeouts, refused connections, DNS failures, TLS and certificate errors, and endpoints that are not a Kubernetes API server now each report what failed.
  • Fixed GKE cluster discovery reporting a generic 400 for revoked keys, exceeded quotas, and unreachable API endpoints instead of the underlying Google Cloud error.
  • Fixed compute environment validation reusing a cached client from a different compute environment, so correcting a field and resubmitting, or updating credentials, now validates against the new values.
  • Fixed GKE compute environments that use Workload Identity Federation failing with a 500 when reading run logs or downloading files.
  • Fixed Azure Cloud compute environment creation failing with an unexplained error when the credentials cannot read back a resource the forge has just created, so the error now names the resource and the missing read permission.
  • Fixed pipeline additions against Tower Agent compute environments intermittently failing with Timeout waiting for command response.

Studios​

  • Fixed Studios with mounted data links failing to start on Seqera Compute and on AWS Cloud, Azure Cloud, and Google Cloud compute environments.

Wave v1.38.0

Feature updates and improvements​

General​

  • Added support for an authenticating egress proxy for outbound HTTP clients via the shared lib-util-net ProxyConfig by @pditommaso in #1125
  • Changed env-var-overridable config properties to use kebab-case keys so they can be set from environment variables by @bebosudo in #1096
  • Aligned the build toolchain and runtime to Java 25 while keeping the bytecode target at Java 17 by @cristianrcv in #1077
  • Allowed the Claude review agent to submit approving PR reviews by @pditommaso in #1105
  • Refreshed the self-install documentation by @christopher-hakkaart in #1106

Dependencies​

  • Upgraded org.postgresql:postgresql to 42.7.12 (COMP-2149) by @cristianrcv in #1112
  • Upgraded io.netty:netty-bom to 4.2.17.Final (COMP-2376) by @cristianrcv in #1135
  • Upgraded the jib plugin to 3.5.4 for Java 25 class file support (COMP-2511) by @munishchouhan in #1136
  • Updated node dependency to v24.19.0 by @seqeralabs-renovate[bot] in #1111
  • Updated node dependency to v24.20.0 by @seqeralabs-renovate[bot] in #1122
  • Updated node dependency to v24.21.0 by @seqeralabs-renovate[bot] in #1134
  • Updated actions/checkout action to v4.4.0 by @seqeralabs-renovate[bot] in #1103
  • Updated actions/checkout action to v6.1.0 by @seqeralabs-renovate[bot] in #1104
  • Updated actions/setup-java action to v4.9.1 by @seqeralabs-renovate[bot] in #1108
  • Updated actions/setup-java action to v5.7.0 by @seqeralabs-renovate[bot] in #1109
  • Updated aws-actions/amazon-ecr-login action to v2.1.6 by @seqeralabs-renovate[bot] in #1102
  • Updated aws-actions/amazon-ecr-login action to v2.1.7 by @seqeralabs-renovate[bot] in #1121
  • Updated aws-actions/configure-aws-credentials action to v6.2.3 by @seqeralabs-renovate[bot] in #1110
  • Updated aws-actions/configure-aws-credentials action to v6.2.4 by @seqeralabs-renovate[bot] in #1127
  • Updated docker/login-action action to v4.6.0 by @seqeralabs-renovate[bot] in #1117
  • Updated anthropics/claude-code-action action to v1.0.191 by @seqeralabs-renovate[bot] in #1101
  • Updated anthropics/claude-code-action action to v1.0.198 by @seqeralabs-renovate[bot] in #1116
  • Updated anthropics/claude-code-action action to v1.0.206 by @seqeralabs-renovate[bot] in #1120
  • Updated anthropics/claude-code-action action to v1.0.213 by @seqeralabs-renovate[bot] in #1126
  • Updated anthropics/claude-code-action action to v1.0.219 by @seqeralabs-renovate[bot] in #1133

Bug fixes​

Container building​

  • Fixed Kubernetes builds being reported as failed on Kubernetes 1.36 and later even though the image was built and pushed (COMP-2368) by @munishchouhan in #1128
  • Fixed PATH in the Pixi Docker template so commands resolve in OCI-to-SIF converted images by @munishchouhan in #1131

General​

  • Fixed blob transfer jobs reporting success after uploading a 0-byte object by surfacing transfer errors when caching blobs (COMP-2142) by @stefanoboriero in #1100

Full changelog: https://github.com/seqeralabs/wave/compare/v1.37.0...v1.38.0

Seqera Cloud v26.2.0_cycle71

Feature updates and improvements​

Secrets​

  • Migrated the workspace and user secrets lists to the shared row-card table already used by compute environments and credentials. Edit and Delete moved into the row's kebab menu, and the whole row opens the edit form for users with update permission.

Bug fixes​

Credentials​

  • Fixed the inline credentials form in compute environment creation offering fewer options than the Credentials page. AWS supports role-based credentials with external ID generation, Google supports Workload Identity Federation, and Azure uses the same credential fields as that page.
  • Fixed the row actions column reserving an empty strip in the compute environment and credentials lists for users without permission to act on the row.
  • Fixed the credentials kebab menu opening an empty panel for users without permission to act on the row.

Pipelines​

  • Fixed lineage resolution for resumed runs. Each run in a resume chain now shows its own Lineage ID, instead of every run in the chain showing the most recently indexed one. A resumed run shows - while it executes, then its own Lineage ID once it completes.

Seqera Cloud v26.2.0_cycle70

Feature updates and improvements​

Compute environments​

  • Grouped compute environment selects by platform, listed the workspace primary environment first, and added an in-panel search that matches on name, region, and platform.
  • Changed the pre-selected compute environment in launch forms from the alphabetically first environment to the workspace primary environment.

General​

  • Removed the count badges from the Runs, Reports, Datasets, and Projects tabs.

Bug fixes​

Credentials​

  • Fixed the Password field helper text on the GitLab and Gitea credential forms to state that a personal access token must be entered in both the Access token and Password fields, and that the Password field is required for Nextflow versions before 26.04.

Pipelines​

  • Fixed the launch form to preserve the output directory when resuming a run, instead of publishing to the pipeline default.
  • Fixed user-typed launch parameters being discarded when a config profile or revision change re-fetched the parameters.
  • Fixed schema default parameters being dropped from the submitted parameters after selecting a config profile.
  • Fixed nested parameter groups being submitted as null, which disabled Launch with no way to clear the error.

Seqera Cloud v26.2.0_cycle69

Feature updates and improvements​

Studios​

  • Added filtering to the Studios list, with the selected filters persisted across navigation.

Compute environments​

  • Added an OS disk size setting to Azure Cloud compute environments.
  • Added an optional Region field to the Azure credential forms, with autocomplete suggestions and free-text entry for regions outside the catalog.

Pipelines​

  • Added support for Nextflow v26.08.0-edge.
  • Improved launch performance by reducing the number of SCM calls made on the launch path.

Data Explorer​

  • Added search to the data link selector in the bucket action form.

Bug fixes​

Compute environments​

  • Fixed false "region not found" warnings on Azure credentials by probing Azure Batch in the credential's own region instead of westeurope, and by validating Batch access on the compute environment rather than the credential.
  • Fixed compute environment deletion being possible while creation was still in progress.
  • Fixed the compute environment details page to redirect to the compute environment list after a deletion.
  • Fixed forged Azure Cloud compute environments losing their Nextflow configuration.
  • Fixed runs being flagged for attention when a UserData script failed.

Credentials​

  • Fixed credential validation to back off and escalate probes that fail permanently, instead of retrying them at the same rate.

Monitoring and observability​

  • Fixed the runs toolbar disappearing in loading and empty states.

Credits​

  • Fixed the credits report download to show progress and offer a cancel control.

General​

  • Fixed the default workspace preference not being cleared correctly.