Skip to main content

46 posts tagged with "seqera enterprise"

View All Tags

Seqera Enterprise v26.2

Seqera Platform Enterprise 26.2 adds event-driven Actions, triggered by bucket events, schedules, and pipeline run events. It also adds Co-Scientist agents that run as service accounts, a Projects view, a system-wide Nextflow version selector, and pre-flight validation for credentials and compute environments. Other additions are global search backed by the data lineage query language, customer-managed KMS encryption for pipeline secrets, and route-aware OpenTelemetry tracing. For identity and access management, 26.2 adds OIDC audience enforcement, RFC 8693 token exchange, refresh-token rotation, and more SCIM auditing.

Highlights​

  • You can launch a pipeline with a specific Nextflow version, chosen from a system-wide catalog of nf-launcher images. Each compute environment type sets a minimum version. See Compute environments.
  • Platform validates credentials and compute environments before launch, on a schedule, and on demand. Broken credentials surface before a run fails. This is enabled by default. See Upgrade notes.
  • Actions can be triggered by a bucket event, a schedule, or a pipeline run event, can start an agent instead of a pipeline, and record a trigger history. The three triggers are enabled by default in every workspace.
  • Global search, backed by the data lineage query language, searches across workspaces. It is on by default. To turn it off, set TOWER_GLOBAL_SEARCH_ENABLED to false.
  • You can encrypt pipeline secrets with a customer-managed AWS Key Management Service (KMS) key, set with TOWER_AWS_SECRETS_KMS_KEY_ID.
  • Enterprise deployments now send aggregate entity telemetry with the license check. This is enabled by default. See Upgrade notes.
  • Co-Scientist chat is available to every organization in the installation. It is enabled by default once the Co-Scientist agent backend is configured. See Upgrade notes.
  • You can configure reusable AI agents per workspace and start one from a run with Trigger agent. Each agent acts as its bound service account. Agents are enabled by default once the Co-Scientist agent backend is configured. See Upgrade notes.
  • A Projects view groups a workspace's pipelines, datasets, and runs by project, and launches from a project use an essentials-only launch form. This is enabled by default in every organization workspace. See Upgrade notes.
  • The standalone Co-Scientist web interface (provided by the portal-web chart) is removed. Co-Scientist is now part of Seqera Platform. See Upgrade notes.
  • A component compatibility catalog records which Nextflow, Fusion, and nf-launcher artifacts work with this Platform version, with deployment-local overrides for private registries. This is enabled by default. See Upgrade notes.
  • Platform can stamp the aud claim on the OIDC access tokens it issues and enforce it. Enforcement is off by default and only logs mismatches. See Upgrade notes.
  • Studios support private sessions restricted to an allow-list of users, per-user favorites, and a configurable automated stop grace period.
  • Route-aware OpenTelemetry tracing is available through the standard OTEL_* environment variables.
  • Studios gain a Logs tab that streams a session's process log directly from the compute environment. Logs survive an ungraceful shutdown.
  • The compute environment, credentials, and Actions lists are redesigned as row-card tables with attribute chips, grouping, and search.
  • From 26.2, Seqera publishes one frontend container image, platform/frontend:<tag>, which runs in unprivileged mode. The -unprivileged tag alias and the -root variant, which ran as the root user, are gone. See Upgrade notes.
  • Platform writes audit events only to the v2 schema. This is a breaking change for direct database consumers and ETL jobs that read the v1 tw_audit_log table. Update them to the v2 schema before you upgrade. See Upgrade notes.

Seqera Enterprise v26.1.5

Feature updates and improvements​

Pipelines​

  • Updated the bundled Nextflow version to 25.10.6.

Bug fixes​

Data Explorer​

  • Fixed the IGV genome viewer failing to load reference genomes in Data Explorer by signing reference genome URLs.
  • Fixed IGV genome viewer rendering in Data Explorer, which no longer depends on an externally hosted genome registry.
  • Fixed IGV previews of Google Cloud Storage files in Data Explorer returning an authorization error, by signing those URLs with V4 signatures.
  • Fixed IGV previews in Data Explorer failing at high zoom levels by signing index URLs independently of their data file URLs.

Upgrade notes​

No breaking changes. Standard upgrade procedure applies.

Seqera Enterprise v26.1.4

Feature updates and improvements​

info

The legacy distribution endpoint at cr.seqera.io/private is deprecated. Only bug fixes for existing major releases will continue to be published there. New major releases of Seqera Platform are available from cr.seqera.io/enterprise. Seqera will provide updated credentials for the new endpoint — contact your Seqera representative if you need access.

Access control​

  • Enabled IdP claims mapping by default for Enterprise.
  • Added an organization allowlist to the IdP claims-mapping feature flag.
  • Added a warning when revoking IdP group delegation.
  • Added audit logs for SCIM token events.
  • Added audit logging for team IdP group changes.
  • Added configurable OIDC scopes via TOWER_OIDC_SCOPES.

Compute environments​

  • Added bring-your-own networking support for Azure Cloud compute environments.

Bug fixes​

Access control​

  • Fixed membership revocation by treating absent IdP group claims as empty.
  • Fixed IdP group mapping visibility to refresh when toggling SSO.
  • Fixed the IdP reconciler to create UserRole entries for workspace visibility.

Compute environments​

  • Fixed end-to-end GCP Cloud compute environment support for Workload Identity Federation (WIF) credentials.
  • Fixed GCP Batch error reporting to surface actionable API errors instead of a misleading WIF hint.
  • Fixed xpack-google secret resolution by setting GOOGLE_CLOUD_PROJECT on the GCP Batch head job.

Monitoring​

  • Fixed an OptimisticLockException when deleting audit log v2 records.

Upgrade notes​

No breaking changes. Standard upgrade procedure applies.

Seqera Enterprise v26.1.3

Feature updates and improvements​

info

The legacy distribution endpoint at cr.seqera.io/private is deprecated. Only bug fixes for existing major releases will continue to be published there. New major releases of Seqera Platform are available from cr.seqera.io/enterprise. Seqera will provide updated credentials for the new endpoint — contact your Seqera representative if you need access.

Pipelines​

  • Added pipeline schema, commit ID, head job CPUs, and head job memory to the workflow launch form summary, plus pipeline version and lineage fields when those features are active.

Bug fixes​

Compute environments​

  • Fixed AWS credential validation failing for credentials using assumeRoleArn when TOWER_ALLOW_INSTANCE_CREDENTIALS=true without an explicit role mode.

Pipelines​

  • Fixed duplicate credential detection to block GitHub App creation when a personal access token credential already exists for the same repository base URL.

Upgrade notes​

No breaking changes. Standard upgrade procedure applies.

Seqera Enterprise v26.1.2

info

This changelog covers both the 26.1.1 and 26.1.2 patch releases.

Feature updates and improvements​

info

The legacy distribution endpoint at cr.seqera.io/private is deprecated. Only bug fixes for existing major releases will continue to be published there. New major releases of Seqera Platform are available from cr.seqera.io/enterprise. Seqera will provide updated credentials for the new endpoint — contact your Seqera representative if you need access.

Bug fixes​

Pipelines​

  • Fixed the Nextflow syntax parser v2 toggle to seed its state from the saved launch configuration.
  • Fixed the workflow launch API response to include the syntaxParser field.
  • Fixed the pipeline edit form to persist a custom schema added for the first time.
  • Removed the lineage setting from the launch form's essential fields so users with the Launcher role can no longer override it.

Upgrade notes​

No breaking changes. Standard upgrade procedure applies.

Seqera Enterprise v26.1

Seqera Platform Enterprise version 26.1 introduces Co-Scientist for Enterprise, broader cloud credential support (AWS role-based access, Azure Entra service principal, GCP Workload Identity Federation), Nextflow data lineage in pipeline runs and Data Explorer, and a redesigned audit log experience with CSV export.

Highlights​

Seqera Enterprise v25.3.6

Feature updates and improvements​

info

The legacy distribution endpoint at cr.seqera.io/private is deprecated. Only bug fixes for existing major releases will continue to be published there. New major releases of Seqera Platform are available from cr.seqera.io/enterprise. Seqera will provide updated credentials for the new endpoint — contact your Seqera representative if you need access.

Access control​

  • Added PKCE and consent flow support to OIDC, enabling Seqera Platform to act as an identity provider for OIDC/OAuth2 clients such as the Seqera AI CLI.

Bug fixes​

Pipelines​

  • Fixed Nextflow timeline config generation to resolve NXF_TML_FILE via System.getenv instead of relying on shell variable expansion.
  • Fixed the Browse button in the pipeline launch form being hidden for users with Launch, Connect, or View workspace roles by gating it on the correct permission instead of the Studios studio:execute grant.

Upgrade notes​

No breaking changes. Standard upgrade procedure applies.

Seqera Enterprise v25.3.4

Feature updates and improvements​

info

The legacy distribution endpoint at cr.seqera.io/private is deprecated. Only bug fixes for existing major releases will continue to be published there. New major releases of Seqera Platform are available from cr.seqera.io/enterprise. Seqera will provide updated credentials for the new endpoint — contact your Seqera representative if you need access.

Compute environments​

  • Added support for ${username} dynamic notation in resource labels.

Studios​

  • Added configurable SSH timeout parameters for Studios connections.

Pipelines​

  • Improved workflow status transitions so that workflows in an unknown state correctly transition to running when a begin trace is received.
  • Updated schema radio control labels for clarity.

Bug fixes​

Compute environments​

  • Fixed an issue where resourceLabelIds was incorrectly tracked as a versionable compute environment control.

Pipelines​

  • Fixed job scheduler transaction rollback handling to prevent data inconsistency when an exception occurs while saving job status.
  • Fixed implicit default version resolution for pipelines.

Platform API​

  • Fixed Task.getExit() return type alignment to Integer in the API.

Monitoring and observability​

  • Fixed cookie banner visibility logic for enterprise deployments to correctly hide the banner when no non-essential cookies are configured.

Upgrade notes​

No breaking changes. Standard upgrade procedure applies.

Seqera Enterprise v25.3.3

Feature updates and improvements​

info

The legacy distribution endpoint at cr.seqera.io/private is deprecated. Only bug fixes for existing major releases will continue to be published there. New major releases of Seqera Platform are available from cr.seqera.io/enterprise. Seqera will provide updated credentials for the new endpoint — contact your Seqera representative if you need access.

Studios​

  • (Public preview) Added SSH connectivity to Studios which enables direct connection to running Studio sessions using standard SSH clients, supporting VS Code Remote SSH and terminal access. See Studios SSH configuration for more information.

Pipelines​

  • Added custom schema support to pipeline versions.
  • Added edit launch pipeline.
  • Enabled custom schema retrieval for pipeline versions.

See Pipeline versioning for more information.

Access Control​

  • Removed participants on workspace deletion.
  • Improved error message when deleting custom roles.
  • Added pagination to roles list page.
  • Added the ability to view an effective permissions summary for any user/workspace combination in the UI or via API.
  • Added the ability to reset a custom role's permissions to match any predefined role (Admin, Maintain, Launch, Connect, View).

Custom roles quota enforcement​

The maxCustomRolesPerOrg quota is now enforced on custom role creation. Organizations at or near their quota limit will be unable to create additional custom roles. Review your organization's custom role usage if you need to create additional roles. Contact support to adjust your quotas if needed.

General​

  • Restored custom navigation menu support in user dropdown.
  • Updated styles for container responsiveness and padding adjustments and footer.
  • Added only current page in task pagination.
  • Added storage for SSH public keys for use in Studios.

Bug fixes​

  • Cleared parameters when changing between pipeline with and without parameters.
  • Fixed correctly updated versions list when version is published.
  • Prevented re-assignations of pipeline.launch when working with versions.
  • Updated schema when schemaName field value changes.
  • Prevented adding empty parameters when reseting parameters form with defaults after config profile change.

Upgrade steps​

This release maintains backward compatibility with version 25.2.x.

note
  • Make a backup of your Platform database prior to upgrade.
  • If you are upgrading from a version prior to 25.1, complete all intermediate major version upgrades before upgrading to 25.3.
  • Ensure that no pipelines or Studio sessions are in a running state during this upgrade as active run data and analysis may be lost.

See Upgrade deployment for installation guidance.

Seqera Enterprise v25.3.1

info

The legacy distribution endpoint at cr.seqera.io/private is deprecated. Only bug fixes for existing major releases will continue to be published there. New major releases of Seqera Platform are available from cr.seqera.io/enterprise. Seqera will provide updated credentials for the new endpoint — contact your Seqera representative if you need access.

Bug fixes​

Compute environments​

  • Resolved an issue with long-running jobs and sts caching.

Nextflow​

Nextflow upgraded to 25.10.2​

Seqera Platform 25.3.1 includes Nextflow 25.10.2 (previously 25.04.8).

According to the 25.10.0, 25.10.1, and 25.10.2 release notes, there are breaking changes for AWS configurations and the deprecated Google Life Sciences executor. However, existing pipelines will continue to work. New recommended syntax is now available:

New features:

  • Workflow params: New params block for declaring pipeline parameters with type annotations (requires strict syntax)
  • Workflow outputs out of preview: Workflow outputs are now production-ready (remove nextflow.preview.output flag if using)
  • Type annotations: Support for type annotations on parameters, workflows, processes, and functions (requires strict syntax)
  • Auth and Launch commands: New nextflow auth and nextflow launch commands for Seqera Platform integration

Enhancements:

  • Nextflow plugin registry for more efficient plugin downloads
  • Simpler syntax for workflow handlers (onComplete, onError sections in workflows)
  • Simpler syntax for dynamic directives (no closure required with strict syntax)
  • Configurable date formatting via NXF_DATE_FORMAT environment variable

Breaking changes:

  • google-lifesciences executor removed (use google-batch instead)
  • AWS Java SDK upgraded from v1 to v2 (affects aws.client config options)
  • Package nextflow.config.schema renamed to nextflow.config.spec

See the Nextflow 25.10 migration guide for full details.

Note: The default Nextflow version can be overridden by setting NXF_VER in a pre-run script:

export NXF_VER=25.04.8

Nextflow launcher image​

If you host your nf-launcher container image on a private image registry, copy the nf-launcher image to your private registry. Then update your tower.env with the following environment variable:

TOWER_LAUNCH_CONTAINER=<FULL_PATH_TO_YOUR_PRIVATE_IMAGE>

If you're using AWS Batch, you will need to configure a custom job-definition and populate the TOWER_LAUNCH_CONTAINER with the job-definition name instead.