Skip to main content

Compute environment pre-flight checks

Pre-flight checks confirm that a compute environment is usable before you launch a pipeline. They run at three points, and the checks differ at each:

  • When you create or update a compute environment, Platform reads the status recorded for the selected credential.
  • On a recurring background schedule, Platform re-validates credentials against the cloud provider and re-checks compute environments.
  • At launch time, Platform re-checks both.

Problems surface before submission rather than mid-run. Pre-flight checks only flag conditions that would block a launch.

Seqera Platform Cloud runs pre-flight checks in every workspace. You cannot disable them.

Checked conditions​

Pre-flight checks confirm the following conditions. Verify them before you create a compute environment:

Credentials

  • The access keys, service account key, or managed identity are valid and have not been rotated or revoked.
  • The IAM role or service account has the permissions the cloud provider requires. See the relevant compute environment page for the minimum required policy.

Work directory

  • The bucket or storage container exists in the same region as the compute environment. This applies to AWS Batch and AWS Cloud compute environments only.
  • The credential attached to the compute environment has read and write access to the work directory path.

Wave (if enabled)

  • The Wave service is running and reachable from Seqera Platform.

Tower Agent (high-performance computing (HPC) and grid compute environments only)

  • Tower Agent is reachable from Platform. See Tower Agent for installation and startup instructions.

Validation process​

Validation runs at four points:

Compute environment creation and update checks​

This check runs when you create a compute environment, and when you update one to use different credentials. Platform reads the stored status of the selected credential. If the credential has been deleted or is INVALID, Platform rejects the request with a 400 Bad Request that names the credential and the recovery step. The check runs before any provider validation.

This check does not apply to compute environments that use a managed identity, because no credential is attached.

On update, Platform checks only the newly selected credential. Other edits, such as a name or description change, are not blocked. To restore a compute environment whose credential has failed, replace the INVALID or deleted credential with a working one.

Credential validation​

This check runs on a recurring schedule. For each AWS, Google Cloud, and Azure credential in scope, Platform calls the provider API to confirm that the credential is still accepted. For AWS role-based credentials and Google Cloud Workload Identity Federation, the check confirms the credential is well-formed. It cannot fully verify the underlying role or identity provider trust configuration.

When a credential fails this check, Platform marks it INVALID and records the provider error on the credential record. The error appears in the launch-time error message when a pipeline is blocked, but not in the compute environment banner. To see the provider error, check the credential record.

A transient probe failure, such as a network interruption or provider throttling, does not mark the credential INVALID. Platform retries the credential with exponential backoff. Some failures show that the credential can never validate, such as an Azure storage or Batch account hostname that no longer resolves. After 10 consecutive failures of this kind, Platform marks the credential INVALID.

Compute environment validation​

This check runs on a recurring schedule. Platform reads the status of the associated credential. If the credential is INVALID, Platform marks the compute environment INVALID immediately.

An INVALID compute environment displays a banner with the error message. An AVAILABLE compute environment has its lastValidated timestamp refreshed.

note

This check covers AWS Batch, AWS Cloud, Azure Batch, Azure Cloud, Google Cloud Batch, and Google Cloud compute environments.

Pipeline launch-time checks​

These checks run when a user submits a pipeline launch. If any check fails, Platform blocks the launch and reports every failure in one error.

CheckWhat it does
Compute environment statusReads the last recorded status from the database. Blocks the launch if the compute environment is INVALID.
Credential statusReads the last recorded status from the database. Blocks the launch if the credential associated with the compute environment is INVALID.
Wave connectivityFor compute environments with Wave enabled, confirms that the Wave service connection is active.
Tower AgentFor HPC compute environments, confirms that a Tower Agent is online for the environment.

Validate a credential manually​

After you rotate the keys or fix the underlying issue on an INVALID credential, trigger an immediate re-validation:

  1. Go to Credentials in your workspace.
  2. Find the credential, open its ⋮ menu, and select Validate.

Platform makes a live call to the cloud provider and updates the credential status immediately. If the check passes, the credential returns to AVAILABLE. The Validate action is available only while the credential is INVALID.

Compute environments marked INVALID because of this credential do not recover automatically. Use Validate on each affected compute environment after restoring the credential.

Validate a compute environment manually​

After you fix the underlying issue on an INVALID compute environment, trigger an immediate re-validation without waiting for the next background sweep:

  1. Go to Compute environments in your workspace.
  2. Find the compute environment, open its ⋮ menu, and select Validate.

Platform runs pre-flight checks and updates the compute environment status immediately. If all checks pass, the compute environment returns to AVAILABLE.

Validate the credential before the compute environment

If both the credential and its associated compute environment are INVALID, restore the credential to AVAILABLE first. If the credential is still INVALID, the compute environment remains INVALID.

Error reference​

For pre-flight check error messages, causes, and resolutions, see Pre-flight checks troubleshooting.