Azure
When running pipelines on Azure, you might encounter the following issues.
Batch compute environments
Use separate Batch pools for head and compute nodes
Batch Forge creates separate head and worker pools with dedicated (on-demand) VMs by default. To save costs by running compute tasks on low-priority VMs, create the pools manually:
- Create two Batch pools in Azure:
- One dedicated pool
- One low-priority pool
Both pools must meet the requirements of a pre-existing pool, as detailed in the Nextflow documentation.
- Create a manual Azure Batch compute environment in Seqera Platform.
- In Compute pool name, specify your dedicated Batch pool.
- Specify the low-priority pool with the
process.queuedirective in yournextflow.configfile, either through the launch form or your pipeline repository.
Azure Kubernetes Service (AKS)
.../.git/HEAD.lock: Operation not supported
This error occurs when your Nextflow pod uses an Azure Files (SMB) persistent volume for storage. The jgit library that Nextflow uses attempts a filesystem link operation that Azure Files (SMB) doesn't support.
To resolve, add the following to your pipeline's Pre-run script field:
cat <<EOT > ~/.gitconfig
[core]
supportsatomicfilecreation = true
EOT
SSL
SSL CA certificate errors
This error can occur when a tool or library in your task container requires SSL certificates to validate an external data source. To resolve, mount the SSL certificates into the container. See SSL/TLS.
Connections using insecure transport are prohibited while --require_secure_transport=ON
This Azure SQL database error occurs because Azure's default MySQL configuration enforces SSL connections between the server and client, as described in SSL/TLS connectivity in Azure Database for MySQL.
To resolve, append useSSL=true&enabledSslProtocolSuites=TLSv1.2&trustServerCertificate=true to your TOWER_DB_URL connection string:
TOWER_DB_URL: jdbc:mysql://mysql:3306/tower?permitMysqlScheme=true/azuredatabase.com/tower?serverTimezone=UTC&useSSL=true&enabledSslProtocolSuites=TLSv1.2&trustServerCertificate=true
Azure Entra ID / OIDC
No enum constant … SELF_SIGNED_TLS_CLIENT_AUTH
On Seqera Platform v25.2.3 and earlier, Entra ID (Azure) authentication fails and the following error appears in the backend logs:
java.lang.IllegalArgumentException: No enum constant io.micronaut.security.oauth2.endpoint.AuthenticationMethod.SELF_SIGNED_TLS_CLIENT_AUTH**
A change in Azure's supported authentication methods causes this issue. The change is incompatible with the OIDC library in older versions of Seqera Platform.
To resolve, force the authentication method to client_secret_post by adding the following environment variable to your tower.env file or Kubernetes ConfigMap:
MICRONAUT_SECURITY_OAUTH2_CLIENTS_OIDC_OPENID_TOKEN_AUTH_METHOD=client_secret_post