Changelogsince cloud@2026-09-24
Penv Cloud changelog
User-facing changes to Penv Cloud, newest first. Changes not yet deployed sit under Next release.
Changes to Penv Cloud, newest first. Changes to the penv binary: command line changelog.
Next release
Plans and add-ons
- SAML single sign-on moves from Enterprise to Pro. SCIM directory sync stays on Enterprise, and Pro can add it.
- Optional add-ons, priced per workspace, never per seat: SCIM directory sync, customer-managed keys, Delivery Insights, audit log streaming, extended audit history, approvals, compliance evidence, SMS and WhatsApp alerts, premium support, and a one-time assisted migration.
- A metered add-on includes a monthly allowance. Past it, the extra use pauses unless you turn on overage, which a spend cap you set bounds and a prepaid wallet pays. Automatic top-up is opt-in.
- By agreement on Enterprise: a dedicated instance, and daily secret scanning of your connected GitHub repositories.
Access and compliance
- Approvals: an environment can hold every change a person makes until a second person approves it, and people can ask for elevated access that ends by itself.
- Compliance evidence: access reviews that confirm or revoke every grant, and signed audit exports for your auditor.
Audit and alerts
- Audit log streaming reaches Datadog, Splunk HTTP Event Collector and Amazon S3 as well as an HTTPS endpoint.
- The extended audit history add-on keeps your log for a year on Free and Pro.
- SMS and WhatsApp alerts to verified phone numbers, carrying a link only, never a value.
Console
- Redesigned Overview, Projects, Audit Log, Approvals, Members and Roles, Integrations, Single Sign-On, Security, Encryption, Organization and Billing pages. Billing splits into Overview, Usage, Add-ons and History tabs; Alerts into Email and Channels.
- Delivery Insights: your CI runs, idle identities, expiring credentials and latency. Every plan sees the last 24 hours; Enterprise and the add-on see 30 days.
Connect a platform
Twenty platforms join the catalog, which now lists 52:
| Kind | Platforms |
|---|---|
| Kubernetes | ROSA, Alibaba Cloud ACK, ARO, CoreWeave, Azure Arc, Gardener, STACKIT SKE |
| CI and deployment | Octopus Deploy, Concourse, Codefresh, Namespace, Zuul, Depot CI |
| Cloud and workload identity | AWS outbound identity federation, Defakto, Cursor Cloud Agents |
| Identity provider | Curity, PingFederate, Ory, Authelia |
Fixes
- We accept a token whose
audis a list of exactly one entry naming your workspace. Kubernetes writes every service-account token that way, so before this fix a trust from Kubernetes, GKE, EKS, AKS or OKE saved and then refused every exchange. A list of two or more entries still fails. - On the AWS card, we refuse the session ARN
aws sts get-caller-identityprints and anything short of a whole role ARN, and say what to paste instead.