Skip to main content
Version: 26.2

Configuration

note

Nextflow Tower Enterprise is now Seqera Platform Enterprise. Existing configuration parameters, configuration files, and API endpoints that include Tower currently remain unchanged.

Set Seqera configuration values using environment variables, a tower.yml configuration file, or individual values stored in AWS Parameter Store. Sensitive values such as database passwords should be stored securely (e.g., as SecureString type parameters in AWS Parameter Store).

Declare environment variables in a tower.env file. For example:

TOWER_CONTACT_EMAIL=hello@foo.com
TOWER_SMTP_HOST=your.smtphost.com

See the Environment variables option in each section below.

Configuration values not supported in tower.yml or AWS Parameter Store​

Due to the order of operations when deploying Seqera Enterprise, some configuration values can only be retrieved from environment variables (tower.env). The following configuration values are not supported for tower.yml or AWS Parameter Store configuration and must be set as environment variables:

Environment variable

Description

Value

TOWER_DB_USER

The user account to access your database. If you are using an external database, you must create this user manually. For installation in a new environment, this value must be set as an environment variable.

Default: tower

TOWER_DB_PASSWORD

The user password to access your database. If you are using an external database, you must create this password manually. For installation in a new environment, this value must be set as an environment variable.

Default: tower

TOWER_DB_URL

The URL to access your database. For installation in a new environment, this value must be set as an environment variable. See the 24.1 release notes for information about the DB URL format.

Example: jdbc:mysql://db:3306/tower?permitMysqlScheme=true

TOWER_APP_NAME

Application name. To run multiple instances of the same Seqera account, each instance must have a unique name, e.g., tower-dev and tower-prod. Can also be set in tower.yml with tower.appName.

Default: tower

TOWER_ENABLE_AWS_SES

Set true to enable AWS Simple Email Service for sending Seqera emails instead of SMTP.

Default: false

TOWER_ENABLE_PLATFORMS

A comma-separated list of execution backends to enable. At least one is required. A backend must be enabled here before compute environments of that type can be created. See Compute environments for the platform value that corresponds to each compute environment type.

altair-platform,awsbatch-platform,awscloud-platform,azbatch-platform,azcloud-platform,eks-platform,googlebatch-platform,googlecloud-platform,gke-platform,k8s-platform,local-platform,lsf-platform,moab-platform,slurm-platform,uge-platform

TOWER_ENABLE_UNSAFE_MODE

Set to true to allow HTTP connections to Seqera. HTTP must not be used in production deployments. HTTPS is used by default from version 22.1.x.

Default: false

Basic configuration​

Basic configuration options such as the Seqera instance server URL, application name, and license key.

Environment variable

Description

Value

TOWER_SERVER_URL

Your Seqera instance hostname, IP address, DNS name, or full reverse proxy path where the application is exposed. The https:// protocol is required for instances that use an SSL certificate. As of version 22.1, HTTPS is used by default. To use HTTP, set TOWER_ENABLE_UNSAFE_MODE=true.

Default: http://localhost:8000

TOWER_LICENSE

Your Seqera Enterprise license key (required). Contact us to obtain your license key. The key is base64-encoded by Seqera — paste this value exactly as received.

DT8G5F3...BBV90OW

TOWER_APP_NAME

Application name. To run multiple instances of the same Seqera account, each instance must have a unique name, e.g., tower-dev and tower-prod.

Default: tower

TOWER_CONFIG_FILE

Custom path for the tower.yml file.

path/to/tower/config

TOWER_LANDING_URL

Custom landing page for the application (requires version 21.10.1 or later). This value doesn't change the TOWER_SERVER_URL used for inbound Seqera connections.

https://your.custom.landing.example.net

TOWER_BACKEND_SERVER_PORT

Define the HTTP port used by the Seqera backend service (requires version 25.3 or later).

8080

TOWER_CRON_SERVER_PORT

Define the HTTP port used by the Seqera cron service (requires version 21.06.1 or later).

8080

TOWER_ROOT_USERS

Grant users access to the application admin panel.

user1@your-company.com,user2@your-company.com

TOWER_CONTACT_EMAIL

Your Seqera system administrator contact email.

seqera@your-company.com

TOWER_AUTH_DISABLE_EMAIL

Set to true to disable the email login. Ensure that you've configured an alternative authentication provider first.

Default: false

TOWER_USER_WORKSPACE_ENABLED

Enable or disable user private workspaces (requires version 22.1.0 or later).

Default: true

TOWER_SSL_CUSTOM_CA_CERT_FILE

Path to a PEM file containing your internal certificate authority (CA) certificate, mounted into the Platform container. When set, Platform provisions the certificate to Studio sessions so they can connect to endpoints signed by that CA. See Configure a private certificate authority for Studios.

/etc/seqera/certs/internal-ca.pem

Seqera and Redis databases​

Configuration values that control Seqera's interaction with databases and Redis instances. TOWER_DB_USER, TOWER_DB_PASSWORD, and TOWER_DB_URL must be specified using environment variables during initial Seqera Enterprise deployment in a new environment. A new installation will fail if DB values are only defined in tower.yml or the AWS Parameter Store. Once the database has been created, these values can be added to tower.yml or AWS Parameter Store entries and removed from your environment variables.

note

Database and cache version requirements:

From Seqera Enterprise version 26.1:

  • MySQL 8.4, the long-term support (LTS) release, is the recommended and tested database version. MySQL 5.7 and 8.0 have reached upstream end-of-life and are no longer tested or supported. Migrate to MySQL 8.4 before you upgrade.
  • Seqera Enterprise supports Redis 7.2, Redis 7.4, and Valkey 7.x. Redis 6.x is not supported.

For the full support matrices, see Database changes and Cache layer changes.

Follow your cloud provider specifications to upgrade your instance.

If you use a database other than the provided db container, you must create a user and database schema manually.

CREATE DATABASE tower;
ALTER DATABASE tower CHARACTER SET utf8 COLLATE utf8_bin;

CREATE USER 'tower' IDENTIFIED BY <password>;
GRANT ALL PRIVILEGES ON tower.* TO tower@'%' ;

Managed Redis services​

Seqera supports managed Redis services such as Amazon ElastiCache, Azure Managed Redis, or Google Memorystore.

caution

Microsoft is retiring Azure Cache for Redis. As of April 1, 2026, new customers cannot create instances, and from October 1, 2026, no new instances can be created. For new Azure deployments, use Azure Managed Redis.

When using a managed Redis service, you must specify the service IP address or DNS name for the TOWER_REDIS_URL as described in the following sections.

  • Use a single-node cluster, as multi-node clusters are not supported
  • Use an instance with at least 6 GB capacity (cache.m4.large or greater)
  • Specify your private ElastiCache instance in the Seqera environment variables:
TOWER_REDIS_URL=redis://<redis private IP>:6379

Database and Redis manual configuration​

If the DB username and password variables are left empty when using Docker Compose, default tower database values are applied automatically. With Kubernetes and custom DB deployments, tower values are not pre-filled.

note

We recommend using managed cloud database services for production deployments.

Environment variable

Description

Value

TOWER_DB_USER

The user account to access your database. If you are using an external database, you must create this user manually.

Default: tower

TOWER_DB_PASSWORD

The user password to access your database. If you are using an external database, you must create this password manually.

Default: tower

TOWER_DB_URL

The URL to access your database.

Example: jdbc:mysql://db:3306/tower?permitMysqlScheme=true

TOWER_DB_MIN_POOL_SIZE

Minimum database connection pool size.

Default: 5

TOWER_DB_MAX_POOL_SIZE

Maximum database connection pool size.

Default: 10

TOWER_DB_MAX_LIFETIME

Maximum lifespan of database connections, in milliseconds.

Default: 1800000

TOWER_REDIS_URL

The URL to access your Seqera Redis instance.

Example: redis://redis:6379

TOWER_REDIS_PASSWORD

The password of your Seqera Redis instance.

Opt-in Seqera features​

Configuration values that enable opt-in Seqera features per instance or workspace.

Core features​

Environment variable

Description

Value

TOWER_ENABLE_WAVE

Enable Seqera integration with Wave containers.

Default: false

WAVE_SERVER_URL

Define the Wave containers service endpoint URL.

Example: https://wave.seqera.io

TOWER_ENABLE_AWS_SSM

Enable Seqera configuration value retrieval from AWS Parameter Store.

Default: false

TOWER_ENABLE_AWS_SES

Use AWS Simple Email Service (SES) to send Seqera emails instead of SMTP.

Default: false

TOWER_ALLOW_NEXTFLOW_LOGS

Allow log and report files from Nextflow CLI runs (-with-tower) to be accessible in the Seqera UI. Run output files must be accessible to your Seqera workspace primary compute environment.

Default: false

TOWER_STEPPED_LAUNCH_FORM_ALLOWED_WORKSPACES

Disable the stepped launch form in the workspaces specified. Omit or set empty (TOWER_STEPPED_LAUNCH_FORM_ALLOWED_WORKSPACES=) to enable the new launch form in all workspaces, or provide a comma-separated list of workspace IDs to enable the form per workspace.

Default: Enabled for all workspaces

TOWER_PIPELINE_VERSIONING_ALLOWED_WORKSPACES

Enable pipeline versioning in the workspaces specified. Accepts a comma-separated list of workspace IDs.

Default: Disabled for all workspaces

TOWER_MEMBER_AUTO_CREATE_USER

Allow a Seqera account to be created when an organization member or team member is added by email address. Unlike the equivalent setting for workspace participants, this is enabled by default.

Default: true

TOWER_ACTIONS_BUCKET_TRIGGER_ALLOWED_WORKSPACES

Restrict bucket event actions to the workspaces specified. Accepts a comma-separated list of workspace IDs. Omit it, or set it empty (TOWER_ACTIONS_BUCKET_TRIGGER_ALLOWED_WORKSPACES=), to make bucket event actions available in every workspace. To disable them everywhere, set it to 0. Because workspace IDs are positive, no workspace matches.

Default: Available in all workspaces

TOWER_ACTIONS_CRON_TRIGGER_ALLOWED_WORKSPACES

Restrict scheduled actions to the workspaces specified. Accepts a comma-separated list of workspace IDs. Omit it, or set it empty (TOWER_ACTIONS_CRON_TRIGGER_ALLOWED_WORKSPACES=), to make scheduled actions available in every workspace. To disable them everywhere, set it to 0.

Default: Available in all workspaces

TOWER_ACTIONS_PIPELINE_TRIGGER_ALLOWED_WORKSPACES

Restrict pipeline run event actions to the workspaces specified. A pipeline run event action launches a pipeline when a run of a Launchpad pipeline reaches a terminal state. Use it to chain one pipeline to another. Accepts a comma-separated list of workspace IDs. Omit it, or set it empty (TOWER_ACTIONS_PIPELINE_TRIGGER_ALLOWED_WORKSPACES=), to make pipeline run event actions available in every workspace. To disable them everywhere, set it to 0.

Default: Available in all workspaces

TOWER_AGENT_CONFIGURATION_ALLOWED_ORGANIZATIONS

Restrict AI agents to the organizations specified, including the option for a bucket event, scheduled, or pipeline run event action to target an agent instead of launching a pipeline. Accepts a comma-separated list of organization IDs. Omit it, or set it empty, to enable agents in every organization once TOWER_AGENT_BACKEND_URL is set. This variable is organization-scoped, not workspace-scoped.

Default: Enabled for all organizations

TOWER_ACTIONS_TRIGGER_RATE_MAX_PER_WINDOW

How many times an action may fire within TOWER_ACTIONS_TRIGGER_RATE_WINDOW before Seqera Platform pauses it. Seqera Platform records the trigger that reaches the limit as suppressed. The action keeps its configuration until someone resumes it. Raise it to let an action fire more often. Lower it to cap the cost of a runaway action sooner.

Default: 20

TOWER_ACTIONS_TRIGGER_RATE_WINDOW

How far back Seqera Platform counts an action's triggers when applying TOWER_ACTIONS_TRIGGER_RATE_MAX_PER_WINDOW. Widening it makes the limit easier to reach, because more past triggers fall inside the count. The count is shared across replicas and survives a restart.

Default: 1h

TOWER_IDENTITY_FEDERATION_ALLOWED_WORKSPACES

Enable workload identity federation in the workspaces specified. Omit the variable, or set it empty (TOWER_IDENTITY_FEDERATION_ALLOWED_WORKSPACES=), to enable it for all workspaces, or provide a comma-separated list of workspace IDs to enable it per workspace. Personal workspaces are excluded in all cases.

Default: Enabled for all workspaces

TOWER_PARTICIPANT_AUTO_CREATE_USER

Allow a Seqera account to be created when a workspace participant is added by email address. When false, only people who already have an account can be added as workspace collaborators. Accounts created this way are marked as trusted. See Add a new participant.

Default: false

TOWER_ACTION_CYCLE_MAX_CHAIN_DEPTH

How many steps back Seqera Platform traces a run's chain of action triggers before it refuses the event. Seqera Platform suppresses a chain longer than this whether or not it closes a loop. Raise it for deliberately long automation chains. Each extra step is one more database read per finished run. Values below 1 or above 50 log a warning at startup, and a value that is not a whole number prevents backend startup.

Default: 20

Data features​

Configuration values used by Seqera for Datasets, Data Explorer, Data Lineage, and Studios.

Environment variable

Description

Value

TOWER_DATA_EXPLORER_ENABLED

Enable Data Explorer in all workspaces. To mount data inside a Studio, you must enable Data Explorer.

Default: true

TOWER_DATA_EXPLORER_CLOUD_DISABLED_WORKSPACES

Disable Data Explorer automatic cloud bucket retrieval per workspace.

Example: <workspace-id1>,<workspace-id2>

TOWER_DATA_EXPLORER_LINK_STORE_TTL

Data Explorer cloud bucket cache duration.

Default: 30m

TOWER_DATA_EXPLORER_LINK_STORE_BACKOFF

The amount of time that elapses after an error, before a retry attempt is made.

Default: 10m

TOWER_DATA_EXPLORER_MAX_RETRIES

The number of retries Data Explorer will attempt to fetch cloud buckets in the event of temporary errors.

Default: 3

TOWER_DATA_EXPLORER_LINK_STORE_RETRY_AFTER

The period of time that retry attempts will be made even when max retries has been exceeded.

Default: 1d

TOWER_CONTENT_MAX_FILE_SIZE

Data Explorer download file size limit. Increasing this value may degrade performance.

Default: 25MB

TOWER_DATA_DATASETS_LIST_MAX_ALLOWED

Maximum and default number of items returned in a single page when listing datasets.

Default: 100

TOWER_DATA_DATASET_VERSIONS_LIST_MAX_ALLOWED

Maximum and default number of items returned in a single page when listing dataset versions.

Default: 100

TOWER_DATA_STUDIO_CONNECT_URL

The URL of the Studios connect proxy. The connect proxy is used internally by Seqera Platform. See Studios deployment.

Example: https://connect.example.com/

TOWER_DATA_STUDIO_WAVE_CUSTOM_IMAGE_REPOSITORY

The custom image repository for Wave containers. Ignored if custom image registry is not present.

Default: data-studios/<tool>

TOWER_DATA_STUDIO_WAVE_CUSTOM_IMAGE_NAME_STRATEGY

The custom image name strategy for Wave containers. See the Wave documentation for available options.

Default: tagPrefix

TOWER_DATA_STUDIO_WAVE_CUSTOM_IMAGE_REGISTRY

The custom image registry for Wave containers, used as the destination for Studio images that are customized with a conda environment. When left null, defers to whatever Wave has configured as the default.

Default: null

TOWER_OIDC_REGISTRATION_INITIAL_ACCESS_TOKEN

An access token used to register new clients in Seqera Platform. Any alphanumeric value is allowed. See Studios deployment. Requires the OIDC provider to be configured. See Cryptographic options.

d5XDoRzHpWo1c............mDnfBp

TOWER_DATA_STUDIO_ENABLE_PATH_ROUTING

Add this variable and set it to true to configure Studios requests to use path-based routing and a single, fixed domain for Studio sessions. See Studios deployment.

Default: null

TOWER_DATA_STUDIO_FORCE_STOP_THRESHOLD

The minimum time a Studio session must be in the stopping status before a stop request force-stops it. A force stop terminates the compute job immediately instead of waiting for a graceful shutdown.

Default: 10m

TOWER_OIDC_PEM_PATH

The file path to a PEM certificate used to sign the OIDC tokens for the OpenID connect provider. See Studios deployment.

Example: /data-studios-rsa.pem

TOWER_DATA_STUDIO_SSH_ALLOWED_WORKSPACES

Add this variable to enable SSH connection functionality in Studios. Set to comma-separated workspace IDs to enable for specific workspaces, an empty string ("") to enable for all workspaces, or null to disable for all workspaces. See Studios deployment for configuration details.

Default: null

TOWER_SSH_KEYS_MANAGEMENT_ENABLED

Enable SSH key management for Studios SSH connection functionality.

Default: false

TOWER_SSH_KEYS_SUPPORTED_TYPES

Comma-separated list of supported SSH public key types for user SSH key registration.

Default: ssh-rsa,ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521

TOWER_DATA_STUDIO_CONNECT_SSH_KEY_FINGERPRINT

SSH key fingerprint. This allows only SSH connections that have been authenticated with Seqera to connect to the server and is recommended for production environments. To generate the fingerprint, use ssh-keygen -lf <path-to-ssh-key>. See Studios deployment.

Example: SHA256:uNiVztksCsDhcc0u9e8BujQXVUpKZIDTMczCvj3tD2s

TOWER_DATA_STUDIO_CONNECT_SSH_PORT

Connection string display purposes.

Default: 22

TOWER_DATA_STUDIO_CONNECT_SSH_ADDRESS

This is set only if the SSH server runs on a different domain to the Connect proxy.

Example: ssh.example.com

TOWER_DATA_STUDIO_ALLOWED_WORKSPACES

Control which workspaces have Studios enabled. Leave unset (default) to enable Studios in all workspaces, set to an empty string to disable Studios for all workspaces, or provide a comma-separated list of workspace IDs to enable Studios only in those workspaces.

Default: Enabled for all workspaces

TOWER_DATA_STUDIO_DEFAULT_LIFESPAN

Default lifespan in hours for Studios when no workspace-specific settings are configured.

Default: 8

TOWER_DATA_STUDIO_PRIVATE_STUDIO_BY_DEFAULT

Default privacy setting for Studios when no workspace-specific or Studio-specific settings are configured. Set to true to make Studios private by default; the default value (false) makes Studios collaborative unless overridden on creation.

Default: false

TOWER_DATA_STUDIO_LIST_MAX_ALLOWED

Maximum and default number of items returned in a single page when listing Studios.

Default: 100

TOWER_DATA_STUDIO_FEATURE_MANIFEST_URL

The manifest URL used for feature version compatibility checks of Studio clients.

Example: https://example.com/manifest.json

TOWER_DATA_STUDIO_CONNECT_IFRAME_ALLOWED_WORKSPACES

Control which workspaces have the Studio iframe in Connect enabled. Set to null (undefined) to disable for all workspaces, set to an empty string to enable for all workspaces, or provide a comma-separated list of workspace IDs to enable per workspace.

Default: null

TOWER_DATA_STUDIO_WAVE_STATUS_CHECK_INITIAL_DELAY

Initial delay before the job that checks Wave build status for Studios in building status runs for the first time.

Default: 5s

TOWER_DATA_STUDIO_WAVE_STATUS_CHECK_RATE

Fixed rate at which Wave build status is checked for Studios in building status.

Default: 30s

TOWER_DATA_STUDIO_WAVE_DISALLOWED_REGISTRIES

Comma-separated list of registry URLs that are not allowed as build destinations for dockerfile-based Studio images. Registries in this list won't be used for pushing dockerfile builds.

Default: community.wave.seqera.io

TOWER_STUDIO_METRICS_ENABLED_WORKSPACES

Control which workspaces have Studio startup metrics collection enabled. Set to null (undefined) to disable for all workspaces, set to an empty string to enable for all workspaces, or provide a comma-separated list of workspace IDs to enable per workspace.

Default: null

TOWER_STUDIO_METRICS_RETENTION_DAYS

Number of days to retain Studio startup metrics in the database before automatic deletion. Metrics older than this threshold are deleted by a daily scheduled job.

Default: 90

TOWER_LINEAGE_ALLOWED_WORKSPACES

Control which workspaces can use data lineage. Leave unset (default) or set to an empty string to enable lineage in all workspaces. To enable lineage only in specific workspaces, provide a comma-separated list of their IDs. Lineage is not available in personal workspaces. In 26.1, the default disabled lineage in all workspaces. See Upgrade deployment.

Default: Enabled for all workspaces

TOWER_GLOBAL_SEARCH_ENABLED

Show the global search bar in the top navigation. Because search results come from data lineage, a workspace also needs TOWER_LINEAGE_ALLOWED_WORKSPACES to include it. See Search data lineage records.

Default: true

TOWER_LINEAGE_STORE_PREFIX

Bucket name prefix for automatically provisioned lineage stores. The bucket is named <prefix>-<workspace-id> and its notification topic <prefix>-<workspace-id>-notifications.

Default: seqera-lineage

TOWER_LINEAGE_SNS_MAX_RETRIES

Total SNS delivery attempts for the lineage webhook. The AWS default of 3 spans roughly a minute and loses events across a Platform restart. AWS caps the total retry window at 3600 seconds and rejects a delivery policy that exceeds it. Seqera Platform trims an over-budget value to fit at startup.

Default: 17

TOWER_LINEAGE_SNS_MAX_DELAY_SECONDS

Ceiling on the delay between SNS delivery retries, in seconds. Counts toward the same 3600-second budget as TOWER_LINEAGE_SNS_MAX_RETRIES.

Default: 300

TOWER_LINEAGE_MIGRATE_SQS_TRANSPORT

Whether to migrate lineage workspaces off the retired SQS event transport once at startup. Runs on the cron instance only. Automatic for automatically provisioned workspaces. Platform flags customer-managed workspaces for reconfiguration instead, because it holds no permission over their resources. A workspace that fails is left errored. You can retry or disable it from its lineage settings page. See Upgrade deployment.

Default: true

Co-Scientist​

Configuration values Seqera Platform uses to reach a Co-Scientist deployment, control the Co-Scientist panel and agents, and restrict the Projects view. Set these only when Co-Scientist is deployed alongside your installation, except TOWER_SCIENTIST_VIEW_ALLOWED_WORKSPACES, which applies either way.

Environment variable

Description

Value

TOWER_AGENT_BACKEND_URL

Origin of the Co-Scientist agent backend (the ai-api. host). Use the host root only. Seqera Platform appends the request path. The Co-Scientist panel, agents, service accounts, and the Trigger agent button are unavailable until you set this value. The Platform Helm chart sets it automatically when the agent-backend subchart is enabled. Chart 1.0.4 enables the subchart by default.

Example: https://ai-api.platform.example.com

TOWER_AGENT_CONFIGURATION_ALLOWED_ORGANIZATIONS

Restrict agents, service accounts, and the Trigger agent button to the organizations specified. Accepts a comma-separated list of organization IDs. Omit it, or set it empty, to enable them in every organization once TOWER_AGENT_BACKEND_URL is set. While TOWER_AGENT_BACKEND_URL is empty, all three are off regardless of this variable. Never applies to personal workspaces. The variable governs the web interface, actions that target an agent, and the API. In an organization where the features are off, the /agents and service account endpoints return 404.

Default: Enabled for all organizations

TOWER_AI_CHAT_ALLOWED_ORGANIZATIONS

Restrict the Co-Scientist panel to the organizations specified. Accepts a comma-separated list of organization IDs. Omit it, or set it empty, to enable the panel in every organization once TOWER_AGENT_BACKEND_URL is set. The panel is never available in personal workspaces.

Default: Enabled for all organizations

TOWER_AUTH_COOKIE_DOMAIN

Domain that the Platform JWT cookie is scoped to. To let the Co-Scientist panel authenticate to the agent backend on its own subdomain, set it to the parent domain of Platform and the agent backend, with a leading dot. The Platform Helm chart sets it automatically when the agent-backend subchart is enabled.

Example: .platform.example.com

TOWER_SCIENTIST_VIEW_ALLOWED_WORKSPACES

Restrict the Projects view to the workspaces specified. Accepts a comma-separated list of workspace IDs. Omit it, or set it empty, to enable projects in every organization workspace. To disable them everywhere, set it to 0. Never applies to personal workspaces. Unlike the other variables in this table, it applies whether or not Co-Scientist is deployed.

Default: Enabled for all organization workspaces

note

Platform fails to start if TOWER_AGENT_BACKEND_URL is not a valid URI, does not use https, has no host, or contains a query string or fragment.

Cryptographic options​

Configuration values used by Seqera to encrypt your data.

caution

Do not modify your crypto secret key between starts. Changing this value will prevent the decryption of existing data.

Environment variable

Description

Value

TOWER_CRYPTO_SECRETKEY

The secret key used to encrypt credentials and secrets (required).

Random string of alphanumeric characters.

TOWER_OIDC_PEM_PATH

The file path to a PEM certificate used to sign tokens for Seqera Platform's built-in OIDC provider. Setting it turns on the OIDC provider. When it is unset, Platform serves no JWKS endpoint, cannot verify RS256 signatures, and no workload identity token exchange can complete for any cloud provider. This is required for Studios, workload identity federation, and Google Cloud Batch Workload Identity Federation.

Example: /oidc.rsa.pem

TOWER_AUTH_TOKEN_SIGNING_RS256_ENABLED

Sign Platform session, agent, and service tokens with RS256 against the OIDC keypair instead of HS256 against TOWER_JWT_SECRET, so that other services can verify them against the published JWKS endpoint. Requires TOWER_OIDC_PEM_PATH.

Default: false

TOWER_OIDC_ACCESS_TOKEN_AUDIENCE

The audience (aud) claim stamped on the OIDC access tokens Platform issues, and checked on incoming ones when TOWER_OIDC_AUDIENCE_ENFORCEMENT_ENABLED is true. Personal access tokens are opaque and unaffected.

Default: platform

TOWER_OIDC_AUDIENCE_ENFORCEMENT_ENABLED

Reject Platform-issued OIDC access tokens whose iss or aud claims do not match the current configuration. When false, mismatches are logged but the token is accepted.

Default: false

TOWER_JWT_SECRET

The secret used to generate the login JWT token (required).

Random string of 35 characters or more.

TOWER_SECRET_ROTATION_ENABLED

Enable (true) or disable (false) rotation of the encryption key used to encrypt credentials and secrets in your Platform database.

Default: false

TOWER_SECRET_ROTATION_PREVIOUS_KEY

Used to store the value of the key used to encrypt existing credentials and secrets (TOWER_CRYPTO_SECRETKEY value before rotation), to keep cryptographic features enabled while rotation is in progress. Requires TOWER_SECRET_ROTATION_ENABLED=true.

Your existing TOWER_CRYPTO_SECRETKEY before rotation.

TOWER_SECRET_ROTATION_CHUNK_SIZE

The number of records to extract in chunks until all secrets and credentials are processed. Requires TOWER_SECRET_ROTATION_ENABLED=true.

Default: 50

Secret key rotation​

Rotate the key used to encrypt the credentials and secrets stored in your Platform database. Encryption key rotation is a security best practice and should be performed at an interval specified by your organization's security requirements, or in the event of a suspected compromise of your secret key.

Enable rotation by setting the following configuration values:

  • TOWER_SECRET_ROTATION_ENABLED=true
  • TOWER_SECRET_ROTATION_PREVIOUS_KEY=<EXISTING_TOWER_CRYPTO_SECRET_KEY_VALUE>
  • TOWER_CRYPTO_SECRETKEY=<NEW_SECRET_KEY_VALUE>

With rotation enabled and the previous and new key values set, secret key rotation will run as part of the Platform cron service during application startup. Normal application startup is not affected by this process, and Platform is fully operational while the credentials and secrets in your database are being encrypted using your new secret key.

warning
  • To prevent data loss, perform a backup of your Platform database and securely back up your current crypto secret key before enabling and performing key rotation.
  • All backend pods or containers for your Enterprise deployment must contain the same previous and new secret key values in their Platform config and must be in a ready/running state before starting the Platform cron service.

The Admin panel Encryption tab displays the status of completed or errored encryption tasks.

Backend memory requirements​

The Platform backend and cron services run on the Java Virtual Machine (JVM). Allocate at least 4 GB of memory to each service for stable operation under load.

For Kubernetes, set resource limits in your pod specifications:

resources:
limits:
memory: "4Gi"
requests:
memory: "4Gi"

For Docker Compose, set memory limits in your service definitions:

services:
backend:
mem_limit: 4g
memswap_limit: 4g
note

These default memory allocation limits are included in the Kubernetes manifest templates (tower-svc.yml and tower-cron.yml). For Docker Compose, add the mem_limit settings to your service definitions as shown above.

JVM memory tuning​

For production deployments, configure JVM memory parameters with the JAVA_OPTS environment variable. This baseline configuration suits most deployments:

JAVA_OPTS="-Xms1000M -Xmx2000M -XX:MaxDirectMemorySize=800m -Dio.netty.maxDirectMemory=0 -Djdk.nio.maxCachedBufferSize=262144"

The JAVA_TOOL_OPTIONS environment variable is a supported alternative to JAVA_OPTS. The JVM reads it directly at startup and confirms pickup with a Picked up JAVA_TOOL_OPTIONS line in the service logs. Set one variable or the other, not both. Options passed on the command line (which is how JAVA_OPTS is applied) take precedence over JAVA_TOOL_OPTIONS when the same flag appears in both.

note

These default JVM memory settings are included in the configuration templates provided in these docs:

ParameterDescription
-Xms / -XmxInitial and maximum heap size — the memory pool for Java objects.
-XX:MaxDirectMemorySizeOff-heap memory for NIO operations, network buffers, and file I/O. Handles concurrent workflow API operations.
-Dio.netty.maxDirectMemory=0Disables Netty's internal memory tracking and relies on the JVM direct memory limit instead.
-Djdk.nio.maxCachedBufferSizeLimits the size of cached NIO buffers to prevent excessive memory retention.

Adjust these baseline values based on the symptoms you observe.

Increase -XX:MaxDirectMemorySize if you observe:

  • OutOfMemoryError: Direct buffer memory in the logs
  • High concurrent workflow launch rates (more than 100 simultaneous workflows)
  • Large configuration payloads or heavy API usage

Increase heap memory (-Xmx) if you observe:

  • OutOfMemoryError: Java heap space in the logs
  • Garbage collection pauses that affect performance
  • Growing memory usage under sustained load

For deployments running 200 or more concurrent workflows, increase the heap and direct memory limits:

JAVA_OPTS="-Xms1000M -Xmx3000M -XX:MaxDirectMemorySize=1600m -Dio.netty.maxDirectMemory=0 -Djdk.nio.maxCachedBufferSize=262144"

Set the container or pod memory limit higher than the JVM limits to accommodate non-heap memory usage.

warning

These are starting values. Monitor your deployment's memory usage and adjust for your workload. Undersized memory allocation can cause out-of-memory (OOM) failures and service instability.

Compute environments​

Configuration values to enable computing platforms and customize Batch Forge resource naming.

Environment variable

Description

Value

TOWER_ENABLE_PLATFORMS

Comma-separated list of the execution backends to enable. At least one is required. A backend must be enabled here before compute environments of that type can be created.

altair-platform,awsbatch-platform,awscloud-platform,azbatch-platform,azcloud-platform,eks-platform,googlebatch-platform,googlecloud-platform,gke-platform,k8s-platform,local-platform,lsf-platform,moab-platform,slurm-platform,uge-platform

MICRONAUT_ENVIRONMENTS

Configuration values to control the behavior of the Seqera cron and backend containers. Do not edit these values

Backend configuration: prod, redis, ha Cron configuration: prod, redis, cron

TOWER_FORGE_PREFIX

Override the default TowerForge prefix, appended to AWS resources created by Batch Forge, with a custom value.

Default: TowerForge

TOWER_ALLOW_INSTANCE_CREDENTIALS

Enable legacy role-based AWS credentials. When true, users provide an IAM role ARN only when creating AWS credentials. Access keys, secret keys, and External ID are not used.

Default: false

TOWER_AWS_SECRETS_KMS_KEY_ID

Installation-wide customer-managed KMS key that encrypts the temporary AWS Secrets Manager secrets created for runs that use pipeline secrets. Accepts a key ARN or a key ID. Applies to AWS Batch and AWS Cloud compute environments, and only when the compute environment does not define its own Pipeline secrets KMS key. A key is account- and region-specific. Set this default only when every AWS Batch and AWS Cloud compute environment in the installation targets the same AWS account and region. The compute environment credentials require kms:GenerateDataKey and kms:Decrypt on the key, granted either in the key policy or in the credentials' own IAM policy. A malformed value prevents backend startup.

Default: none (AWS-managed key)

TOWER_COMPUTE_ENV_LAST_USED_FLUSH_INTERVAL

How often Seqera Platform writes buffered compute environment last-used timestamps to the database. Seqera Platform buffers the write instead of making it inside the launch, to avoid deadlocks between concurrent launches on the same compute environment.

Default: 1s

Available platform values​

TOWER_ENABLE_PLATFORMS (tower_enable_platforms in the Terraform installer) controls which compute environment types are available in your installation. A platform must be listed here before a compute environment of that type can be created — if a compute environment type does not appear in the Platform UI, the corresponding value is missing from this variable.

Platform valueCompute environment type
awsbatch-platformAWS Batch
awscloud-platformAWS Cloud
azbatch-platformAzure Batch
azcloud-platformAzure Cloud
googlebatch-platformGoogle Cloud Batch
googlecloud-platformGoogle Cloud
eks-platformAmazon EKS
gke-platformGoogle Kubernetes Engine
k8s-platformKubernetes
slurm-platformSlurm
lsf-platformIBM Spectrum LSF
uge-platformGrid Engine
altair-platformAltair PBS Pro
moab-platformMoab
local-platformLocal (evaluation and development only)

Specify values as a comma-separated list with no spaces:

TOWER_ENABLE_PLATFORMS=awsbatch-platform,azcloud-platform,k8s-platform
note

Azure Batch and Azure Cloud are separate compute environment types with separate platform values. Enabling azbatch-platform does not make Azure Cloud compute environments available, and vice versa.

Compute environment cleanup​

A scheduled cron job can transition compute environments that are stuck in CREATING or DELETING states into terminal states (ERRORED or INVALID). The cleanup job is disabled by default.

Environment variable

Description

Value

TOWER_COMPUTE_ENV_CLEANUP_ENABLED

Enable the compute environment cleanup cron job, which transitions compute environments stuck in CREATING to ERRORED, and those stuck in DELETING to INVALID. Only organization-scoped compute environments are processed; user-scoped ones are excluded.

Default: false

TOWER_COMPUTE_ENV_CLEANUP_DELAY

Stagger between consecutive batch start times. Batch i is scheduled to start i × time-offset seconds after the job tick.

Default: 1m

TOWER_COMPUTE_ENV_CLEANUP_INTERVAL

Interval at which the compute environment cleanup cron job runs.

Default: 1h

TOWER_COMPUTE_ENV_CLEANUP_BATCH_SIZE

Number of organizations processed per batch in the compute environment cleanup job.

Default: 10

TOWER_COMPUTE_ENV_CLEANUP_TIME_OFFSET

Delay between consecutive batch tasks in the compute environment cleanup job.

Default: 60s

TOWER_COMPUTE_ENV_CLEANUP_STUCK_CREATING_TIMEOUT

Time after which a compute environment stuck in the CREATING state is transitioned to ERRORED.

Default: 1h

TOWER_COMPUTE_ENV_CLEANUP_STUCK_DELETING_TIMEOUT

Time after which a compute environment stuck in the DELETING state is transitioned to INVALID.

Default: 1h

Workspace orphan cleanup​

Two scheduled cron jobs can soft-delete credentials and compute environments whose workspace has been deleted. Both jobs are disabled by default.

Environment variable

Description

Value

TOWER_WORKSPACE_ORPHAN_CLEANUP_ENABLED

Enable the two cleanup cron jobs that soft-delete credentials and compute environments whose workspace has been deleted. Removal uses the same path as a user-initiated deletion, and writes one audit log entry per removed item. Because previous versions did not remove these items when a workspace was deleted, a large backlog may exist. Consider lowering the batch size and concurrency for the first runs.

Default: false

TOWER_CRON_CREDENTIALS_ORPHAN_CLEANUP_TICK_RATE

How often the credentials cleanup job checks for credentials whose workspace has been deleted.

Default: 60s

TOWER_CRON_CREDENTIALS_ORPHAN_CLEANUP_DELAY

Delay before the first credentials cleanup run after startup. The delay varies by up to 50% either way, to spread the load across replicas.

Default: 30s

TOWER_CRON_CREDENTIALS_ORPHAN_CLEANUP_BATCH_SIZE

Maximum number of credentials the job removes per run.

Default: 100

TOWER_CRON_CREDENTIALS_ORPHAN_CLEANUP_CONCURRENCY

Maximum number of credentials removed concurrently on a single replica. Must be 1 or higher.

Default: 5

TOWER_CRON_COMPUTE_ENV_ORPHAN_CLEANUP_TICK_RATE

How often the compute environment cleanup job checks for compute environments whose workspace has been deleted.

Default: 60s

TOWER_CRON_COMPUTE_ENV_ORPHAN_CLEANUP_DELAY

Delay before the first compute environment cleanup run after startup. The delay varies by up to 50% either way, to spread the load across replicas.

Default: 30s

TOWER_CRON_COMPUTE_ENV_ORPHAN_CLEANUP_BATCH_SIZE

Maximum number of compute environments the job removes per run.

Default: 100

TOWER_CRON_COMPUTE_ENV_ORPHAN_CLEANUP_CONCURRENCY

Maximum number of compute environments removed concurrently on a single replica. Deleting a compute environment also removes the cloud resources Batch Forge created for it. Must be 1 or higher.

Default: 5

Git integration​

Seqera Platform has built-in support for public and private Git repositories. Create Git provider credentials to allow Seqera to interact with the following services:

caution

Credentials configured in your SCM providers list override Git credentials in your (organization or personal) workspace.

Public Git repositories can be accessed without authentication, but are often subject to throttling. We recommend always adding Git credentials to your Seqera workspace, regardless of the repository type you use.

Credentials and other secrets must not be hard-coded in environment variables in production environments. Credentials added using the application UI are SHA256-encrypted before secure storage and not exposed by any Seqera API.

Environment variable

Description

TOWER_SCM_PROVIDERS_GITHUB_USER

Your GitHub username.

TOWER_SCM_PROVIDERS_GITHUB_PASSWORD

Your GitHub (classic or fine-grained) access token.

TOWER_SCM_PROVIDERS_GITLAB_USER

Your GitLab username.

TOWER_SCM_PROVIDERS_GITLAB_PASSWORD

Your GitLab (Personal, Group, or Project) access token.

TOWER_SCM_PROVIDERS_GITLAB_TOKEN

Your GitLab (Personal, Group, or Project) access token.

TOWER_SCM_PROVIDERS_BITBUCKET_USER

Your BitBucket username.

TOWER_SCM_PROVIDERS_BITBUCKET_PASSWORD

Your BitBucket App password.

TOWER_SCM_PROVIDERS_GITEA_USER

Your Gitea username.

TOWER_SCM_PROVIDERS_GITEA_PASSWORD

Your Gitea token.

TOWER_SCM_PROVIDERS_AZUREREPOS_USER

Your Azure DevOps repository username.

TOWER_SCM_PROVIDERS_AZUREREPOS_TOKEN

Your Azure DevOps repository personal access token.

Local repositories​

Seqera Enterprise can connect to workflows stored in local Git repositories. To do so, volume mount your local repository folder in your Seqera backend container. Then, update your tower.yml:

tower:
pipeline:
allow-local-repos:
- /path/to/repo

Mail server​

Configure values for SMTP email service integration. Production SMTP hosts must use a TLS-protected connection. See SSL/TLS.

AWS deployments also support Amazon Simple Email Service (SES).

SMTP service integration​

To use an SMTP gateway for mail service, set SMTP user and password values to null.

caution

Your organization's email security policy may prevent the TOWER_CONTACT_EMAIL address from receiving Seqera emails. If this occurs after successful SMTP configuration, you may need to configure spf, dkim, and dmarc records for your domain. Contact your IT support staff for further assistance.

Environment variable

Description

Value

TOWER_SMTP_USER

Your email service user.

Example: user

TOWER_SMTP_PASSWORD

Your email service password.

TOWER_SMTP_HOST

Your email service host name, excluding protocol.

Example: email-smtp.eu-west-1.amazonaws.com

TOWER_SMTP_PORT

Your email service port. Most cloud services block port 25 by default.

Default: 587

TOWER_CONTACT_EMAIL

The email address used to send Seqera emails.

Example: seqera@your-company.com

TOWER_SMTP_AUTH

Use SMTP authentication when calling your email service endpoint.

Default: true

TOWER_SMTP_STARTTLS_ENABLED

Switch the connection to a TLS-protected connection before issuing login commands. Must be true for production SMTP hosts.

Recommended: true

TOWER_SMTP_STARTTLS_REQUIRED

Require the use of the STARTTLS command. Must be true for production SMTP hosts.

Recommended: true

TOWER_ENABLE_AWS_SES

Use AWS SES (Simple Email Service) to use Seqera emails, instead of SMTP.

Default: false

AWS SES integration​

In AWS deployments, you can use AWS Simple Email Service (SES) instead of traditional SMTP for sending Seqera platform emails.

note

Simple Email Service (SES) is only supported in Seqera deployments on AWS.

To configure AWS SES as your Seqera email service:

  1. Set TOWER_ENABLE_AWS_SES=true in your environment variables.
  2. Specify the email address used to send Seqera emails with one of the following:
    • the TOWER_CONTACT_EMAIL environment variable
    • a mail.from entry in tower.yml
    • a /config/<application_name>/mail/from AWS Parameter Store entry
  3. The AWS SES service must run in the same region as your Seqera instance.
  4. The Seqera IAM role must include the ses:SendRawEmail permission.

Nextflow launch container​

caution

Do not replace the Seqera-provided default image unless absolutely necessary.

Environment VariableDescriptionValue
TOWER_LAUNCH_CONTAINERThe container image to run the Nextflow execution. This setting overrides the launch container selection for all organizations and workspaces in your account, and disables the per-run Nextflow version selector.Example: quay.io/seqeralabs/nf-launcher:j17-23.04.3

Component compatibility catalog​

The component compatibility catalog records which Nextflow, Fusion, and nf-launcher versions work with this Seqera Platform version. The Nextflow version selector and launch validation read from it.

Environment variable

Description

Value

TOWER_CATALOG_ENABLED

Enable the component compatibility catalog. When enabled, the launch form's Nextflow version selector, launch validation, and the nf-launcher and Fusion versions used at launch are read from the catalog at TOWER_CATALOG_SOURCE. Set it to false to use the built-in version list of earlier releases.

Default: true

TOWER_CATALOG_SOURCE

Where Seqera Platform reads the catalog from. classpath:catalog-state.json is the catalog bundled with the release. file:/path/to/state.json reads a catalog file you supply, for example in an air-gapped installation. licman reads the live catalog from the Seqera License Manager, with a cached copy and TOWER_CATALOG_EMBEDDED as fallbacks. A catalog that cannot be read or parsed at startup prevents backend startup.

Default: classpath:catalog-state.json

TOWER_CATALOG_EMBEDDED

The catalog used when TOWER_CATALOG_SOURCE is licman and neither the License Manager nor the cached copy is available.

Default: classpath:catalog-state.json

TOWER_CATALOG_LICMAN_URL

License Manager URL for the live catalog when TOWER_CATALOG_SOURCE is licman. If unset, Seqera Platform uses the license server URL. If neither is set in licman mode, the backend fails to start.

Default: License server URL

TOWER_CATALOG_LICMAN_TIMEOUT

Connect and read timeout for the live catalog request. If the request exceeds this timeout, Seqera Platform uses the cached copy or the embedded catalog instead.

Default: 5s

TOWER_CATALOG_REFRESH_INTERVAL

How often the cron service refreshes the cached copy from the live licman source.

Default: 5m

TOWER_CATALOG_REFRESH_INITIAL_DELAY

Delay before the first catalog refresh after startup.

Default: 10s

Seqera API​

Enable the API endpoints to host the Seqera Enterprise OpenAPI specification and use the tw CLI. Set custom API rate limits and timeouts.

note

To configure API rate limit environment variables, you must add ratelim to the MICRONAUT_ENVIRONMENTS. Without ratelim being set, the rate limit configuration variables below are ignored.

Environment variableDescriptionValue
TOWER_ENABLE_OPENAPIEnable the OpenAPI documentation endpoint, e.g., cloud.seqera.io/openapi/index.html.Default: false
TOWER_RATELIMIT_PERIODSpecify the maximum number of HTTP requests that can be made during the TOWER_RATELIMIT_REFRESH period.Default: 20
TOWER_RATELIMIT_REFRESHAPI rate limit refresh period.Default: 1s
TOWER_RATELIMIT_TIMEOUTThe waiting period before rejecting requests over the TOWER_RATELIMIT_PERIOD limit during the refresh period.Default: 500ms

OIDC access tokens​

Configuration values for the audience claim on the OIDC access tokens Seqera Platform issues, and for enforcing it.

Environment variable

Description

Value

TOWER_OIDC_ACCESS_TOKEN_AUDIENCE

The audience (aud) claim stamped on the OIDC access tokens Seqera Platform issues, and checked on the ones it receives. When TOWER_AUTH_TOKEN_SIGNING_RS256_ENABLED is set, it also applies to Platform session, agent, and service tokens. It does not affect personal access tokens. If unset, the audience is platform, which covers every service behind the Platform API.

Default: platform

TOWER_OIDC_AUDIENCE_ENFORCEMENT_ENABLED

Reject Platform-issued OIDC access tokens whose iss or aud claim does not match. When false, Seqera Platform logs mismatches and still accepts the tokens. Use this to check your clients before you enforce. Seqera Platform compares both claims against the current configuration. With TOWER_AUTH_TOKEN_SIGNING_RS256_ENABLED also set, changing TOWER_SERVER_URL or TOWER_OIDC_ACCESS_TOKEN_AUDIENCE rejects every session, agent, and service token until it expires.

Default: false

Custom navigation menu​

Modify your Seqera instance's navigation menu options.

tower:
navbar:
menus:
- label: "My Community"
url: "https://host.com/foo"
- label: "My Pipelines"
url: "https://other.com/bar"

Telemetry​

Seqera Platform sends usage telemetry to the Seqera License Manager alongside the license check. Telemetry is enabled by default. To opt out, set both TOWER_TELEMETRY_STANDARD_ENABLED and TOWER_TELEMETRY_BASIC_ENABLED to false.

Environment variable

Description

Value

TOWER_TELEMETRY_STANDARD_ENABLED

Report entity-level telemetry to the Seqera License Manager: one record per workflow run, Studios session, Studios audit event, day of Data Explorer activity, and workspace. When enabled, Seqera Platform does not send the aggregate counters controlled by TOWER_TELEMETRY_BASIC_ENABLED, because they can be derived from the records. Set it to false to report the aggregate counters only. Seqera Platform hashes user IDs, repository names, Studios template and image references, and workspace names before they leave the installation.

Default: true

TOWER_TELEMETRY_BASIC_ENABLED

Report the aggregate usage counters that Seqera Platform sent before entity-level telemetry. Only applies when TOWER_TELEMETRY_STANDARD_ENABLED is false. About half of these counters carry a row per user, such as sign-ins, launches, resource consumption, and Studios and Data Explorer activity. Seqera Platform hashes the user IDs and organization and workspace names in them. Set both variables to false to opt out of telemetry. No telemetry query runs and no telemetry data leaves the installation, but the installation still reports that it has opted out. Licensing and quota retrieval are unaffected.

Default: true

TOWER_TELEMETRY_WINDOW_DAYS

Number of complete UTC days of entity-level telemetry sent on each run, ending with the previous day. Because Seqera Platform sends the whole window on every run, a later run recovers the data of any run that fails to reach the License Manager. Raising it increases the payload size. Lower it if collecting the window puts too much load on the database.

Default: 7

Logging​

Logging-related configuration values to aid troubleshooting. See Audit logs for more information on application event logging. Use TOWER_CRON_AUDIT_LOG_CLEAN_UP_ENABLED to disable automatic audit log deletion, and restart Platform after changing audit log settings.

Environment variable

Description

Value

TOWER_CRON_AUDIT_LOG_CLEAN_UP_ENABLED

Set false to disable automatic deletion of audit log records. This applies to both the legacy (v1) and v2 audit log tables. Restart Platform after changing this value.

Default: true

TOWER_CRON_AUDIT_LOG_CLEAN_UP_TIME_OFFSET

Application event audit log retention period. When cleanup is enabled, Seqera Platform deletes audit log records older than this period from both the legacy (v1) and v2 audit log tables. Value includes units (30d, 24h, 60m, etc.). Value: "Default: 365d"

TOWER_AUDIT_LOG_V2_CSV_EXPORT_MAX_LOGS

Maximum number of audit log v2 records allowed in a single CSV export.

Default: 500000

TOWER_LOG_APPENDER

The output format of Platform logs.

Options: STDOUT, JSON

TOWER_LOG_LEVEL

Platform backend logging detail level.

Options: TRACE, DEBUG, INFO, WARN, ERROR

TOWER_SECURITY_LOGLEVEL

Platform authentication logging detail level.

Options: TRACE, DEBUG, INFO, WARN, ERROR

TOWER_LOG_DIR

Base directory to store Platform logs.

Default: /. (deployment root directory)

TOWER_LOG_PATTERN

The logging format emitted to STDOUT. See here for a reference of the full logback pattern syntax. Keep %X{trace_id:--} %X{span_id:--} in any override to preserve correlation between logs and traces, and %X{requestId:--} to keep the request correlation ID.

%d{MMM-dd HH:mm:ss.SSS} [%t] %X{ip:--} %X{requestId:--} %X{trace_id:--} %X{span_id:--} %-5level %logger{36} - %msg%n # Default logging pattern shown

TOWER_LOG_MAX_HISTORY

The maximum number of backend log files retained by the system.

Default: 10 (days)

TOWER_LOG_MAX_SIZE

The maximum file size of the Platform backend log file. When this limit is reached, a new log file is created.

Default: 200MB

LOGGER_LEVELS_IO_SEQERA_TOWER_AGENT

Tower Agent logging detail level.

Options: TRACE, DEBUG, INFO, WARN, ERROR

TOWER_AGENT_HEARTBEAT

Tower Agent polling interval.

Example: 10s

TOWER_SSH_LOGLEVEL

Event logging detail level for the SSH connection library used by Seqera.

Options: TRACE, DEBUG, INFO, WARN, ERROR

TOWER_ALLOW_NEXTFLOW_LOGS

Set true to allow Seqera to retrieve logs and reports for runs launched with Nextflow CLI.

Default: false

Distributed tracing​

Seqera Platform emits OpenTelemetry traces with stable, route-aware span names. You can observe endpoint latency, error rate, and throughput per API route rather than per raw URL.

Platform has no tracing switch of its own. Standard OpenTelemetry configuration governs tracing, and the tracing libraries ship in every installation. With no exporter configured, Platform uses an always-off sampler and records no spans. Tracing costs nothing until you turn it on.

To send traces to a collector, set the standard exporter variables:

OTEL_TRACES_EXPORTER=otlp
OTEL_EXPORTER_OTLP_ENDPOINT=http://collector:4318
OTEL_EXPORTER_OTLP_PROTOCOL=http/protobuf

Set OTEL_SERVICE_NAME, OTEL_RESOURCE_ATTRIBUTES, OTEL_TRACES_SAMPLER, and OTEL_TRACES_SAMPLER_ARG as appropriate for your deployment. To turn tracing off again, set OTEL_TRACES_EXPORTER=none.

note

Platform writes the active trace and span IDs into the logging context. The default TOWER_LOG_PATTERN includes %X{trace_id:--} %X{span_id:--} so that log lines correlate with traces. If you override the pattern, keep both fields.

Audit log v2​

Configuration values for the v2 audit log subsystem and the audit log cleanup cron job. The v2 audit log adds support for pre/post change state capture and CSV export limits.

Environment variable

Description

Value

TOWER_AUDIT_LOG_V2_CSV_EXPORT_MAX_LOGS

Maximum number of records allowed in a single audit log CSV export.

Default: 500000

TOWER_AUDIT_LOG_V2_PRE_POST_CHANGE_ENABLED

Enable capturing pre- and post-change state images for audit log target resources in air-gapped Enterprise deployments. In deployments that are not air-gapped this is enabled through License Manager.

Default: false

TOWER_CRON_AUDIT_LOG_CLEAN_UP_ENABLED

Enable the audit log cleanup cron job.

Default: true

TOWER_CRON_AUDIT_LOG_CLEAN_UP_INTERVAL

Interval at which the audit log cleanup cron job runs.

Default: 5m

TOWER_CRON_AUDIT_LOG_CLEAN_UP_DELAY

Initial delay before the audit log cleanup cron job starts after application startup.

Default: 10s

TOWER_CRON_AUDIT_LOG_CLEAN_UP_CHUNK_SIZE

Maximum number of audit log records deleted per cleanup run.

Default: 1000