Penv Cloud
Start free
Docs
Changelogsince cloud@2026-09-24

Penv Cloud changelog

User-facing changes to Penv Cloud, newest first. Changes not yet deployed sit under Next release.

Changes to Penv Cloud, newest first. Changes to the penv binary: command line changelog.

Next release

Plans and add-ons

  • SAML single sign-on moves from Enterprise to Pro. SCIM directory sync stays on Enterprise, and Pro can add it.
  • Optional add-ons, priced per workspace, never per seat: SCIM directory sync, customer-managed keys, Delivery Insights, audit log streaming, extended audit history, approvals, compliance evidence, SMS and WhatsApp alerts, premium support, and a one-time assisted migration.
  • A metered add-on includes a monthly allowance. Past it, the extra use pauses unless you turn on overage, which a spend cap you set bounds and a prepaid wallet pays. Automatic top-up is opt-in.
  • By agreement on Enterprise: a dedicated instance, and daily secret scanning of your connected GitHub repositories.

Access and compliance

  • Approvals: an environment can hold every change a person makes until a second person approves it, and people can ask for elevated access that ends by itself.
  • Compliance evidence: access reviews that confirm or revoke every grant, and signed audit exports for your auditor.

Audit and alerts

  • Audit log streaming reaches Datadog, Splunk HTTP Event Collector and Amazon S3 as well as an HTTPS endpoint.
  • The extended audit history add-on keeps your log for a year on Free and Pro.
  • SMS and WhatsApp alerts to verified phone numbers, carrying a link only, never a value.

Console

  • Redesigned Overview, Projects, Audit Log, Approvals, Members and Roles, Integrations, Single Sign-On, Security, Encryption, Organization and Billing pages. Billing splits into Overview, Usage, Add-ons and History tabs; Alerts into Email and Channels.
  • Delivery Insights: your CI runs, idle identities, expiring credentials and latency. Every plan sees the last 24 hours; Enterprise and the add-on see 30 days.

Connect a platform

Twenty platforms join the catalog, which now lists 52:

Fixes

  • We accept a token whose aud is a list of exactly one entry naming your workspace. Kubernetes writes every service-account token that way, so before this fix a trust from Kubernetes, GKE, EKS, AKS or OKE saved and then refused every exchange. A list of two or more entries still fails.
  • On the AWS card, we refuse the session ARN aws sts get-caller-identity prints and anything short of a whole role ARN, and say what to paste instead.