Changelog: what’s new in Clusterward
Clusterward is under continuous development and ships several times a week. This page summarizes, month by month, what you can newly do in the cockpit, what has improved and which bugs have been fixed. In the cockpit, the same list appears once per user after each update.
- Release
September 2026
- New
- 24
- Improved
- 14
- Fixed
- 11
The biggest month yet: WordPress and Uptime Kuma from the app catalog, logs and monitoring on the service, backups with restore, secrets in Scaleway Secret Manager, Envoy Gateway as a second ingress controller – and, at the end of the month, isolated environments and a thorough security audit, plus the SQL console and controller switches that take DNS along.
SQL console
Look at production data read-only: its own login, a read-only transaction, every query in the audit log.
More on the SQL consoleWordPress from the app catalog
Four fields, and you get a database, a disk with snapshots, a cron job and a certificate – protected until setup is complete.
More on WordPressLogs & monitoring
Logs from all instances, 30 days of usage and uptime checks with alerting – without an agent in the cluster.
More on Logs & monitoring- NewApp catalog with WordPress
A WordPress site with its own database, a disk with daily snapshots, a cron job and a certificate, from four fields. Until setup is complete, a password protects the installer.
- NewEarlier version in one click
“Restore this version…” rolls out exactly the image of an earlier healthy version – for Helm services, the chart version and values. Every rollout pins its image by digest.
- NewReserved and maximum resources separated
CPU and memory per service can be set as a reservation and as an upper limit.
- NewUptime Kuma in the app catalog
Your own status and uptime monitor from Apps → App catalog: a name, a domain and the cluster are enough, no database needed. Its data sits on a disk with snapshots, and a setup password keeps strangers out until you have created your account.
- FixedConfiguration check and version display
Services are no longer wrongly reported as drifted, and the instance list shows the correct version again.
- FixedHelm services after an interrupted deploy
If a chart deploy is cut off by an operator restart, the next deploy rolls the release back to its last good version instead of failing with “another operation is in progress”.
- FixedCatalog apps: domain, DNS and version
A new domain now reaches the app, the DNS record points at NGINX even when Envoy is the default controller, and new apps run the tested major version instead of the newest tag.
- Release
August 2026
- New
- 8
- Fixed
- 2
Day-to-day operations: notifications, volumes with snapshots, Kubernetes and add-on upgrades from the cockpit, roles per application and real client addresses.
Notifications
Failed deployments, unhealthy pods and expiring certificates via Slack, Teams, webhook or email.
More on NotificationsVolumes with snapshots
Persistent disks per service, scheduled snapshots and a snapshot before every deletion.
More on VolumesUpgrades from the cockpit
Update the Kubernetes version, node pools and add-ons such as ingress and cert-manager.
More on Cluster updates- NewNotifications
Slack, Teams, your own signed webhook or email; events selectable per channel, once per event with an all-clear.
- NewVolumes with snapshots
A persistent disk per service that survives deployments, with a snapshot schedule and a snapshot before every deletion.
- NewNode pools, Kubernetes version and add-ons
Scale, create and remove pools, Kubernetes upgrades with confirmation, add-on versions matched to the cluster version.
- NewRoles and access per application
Roles with levels per area; if you choose, a user sees only their own applications.
- NewIP allowlist for the workspace
The cockpit reachable only from your address ranges, with no way to lock yourself out.
- NewReal client addresses
PROXY protocol on the Scaleway load balancer: your applications see the visitor’s address instead of the load balancer’s.
- NewRestrict domains to addresses
Open a domain only to specific IPs or networks, for example for a staging environment.
- New“Updates ready” and application groups
The dashboard shows every service whose branch has newer commits, with Deploy right in the row; applications can be organized into groups.
- Release
July 2026
- New
- 6
- Improved
- 2
- Fixed
- 2
Customer onboarding becomes a construction kit: the pipeline designer, customers that your application orders itself, and the import of existing databases and buckets.
Pipeline designer
Onboarding from building blocks for environment, database, buckets and domain – with an order check.
More on Tenant pipelinesImport existing data
Copy external Postgres and MySQL databases and S3 buckets into your new resources.
More on databases- NewPipeline designer
Assemble onboarding pipelines from building blocks; a run can be canceled and cleanly rolled back.
- NewYour application orders customers itself
Registered applications request onboarding and offboarding; Clusterward reports the progress back.
- NewCustomers with a lifecycle
One page shows every customer with their status, sorted by what needs attention.
- NewDatabase and bucket import
Take over schema and data from an external database, copy objects from an S3 bucket – with a progress indicator.
- NewVariable templates
Save a set of environment variables once and apply it to any service.
- NewRedirects per domain
A domain redirects to another host, for example www to the main domain.
- ImprovedRegistry per cluster
Every cluster pushes to and pulls from the registry in its own project, created during provisioning.
- ImprovedEdit DNS records and larger uploads
Proxy setting and comment per record; uploads up to 64 MB instead of 1 MB.
- Release
June 2026
- New
- 5
- Improved
- 1
Multiple customers on one cluster: tenant onboarding from templates, offboarding with backup, Object Storage with its own key and wildcard certificates.
Customer onboarding
Create a customer’s entire stack from a reusable template – only the customer data is added.
More on Tenant pipelinesObject Storage
Buckets per application with their own IAM key and bucket policy, public or private.
More on Object Storage- NewCustomer onboarding from templates
A customer’s database, buckets, domain and application in one run; a wizard asks only for the customer data.
- NewOffboarding with backup
When a customer leaves, the database and buckets are backed up first, and only then torn down.
- NewObject Storage
Scaleway projects as S3 providers, buckets with visibility settings and dedicated keys that serve several buckets of one application.
- NewManaged wildcard certificates
One certificate for all subdomains, issued and renewed by Clusterward – without a Let’s Encrypt limit per customer.
- NewHelp in the cockpit
Articles on setup, terminology and day-to-day work, written from the operator’s point of view.
- ImprovedLive progress during provisioning
Every step with its duration in the wizard, on the cluster page and on the dashboard.
- Release
May 2026
- New
- 6
The launch of Clusterward: secure Kapsule clusters, deployments from Git, container or Helm chart, managed databases, DNS and certificates – from one cockpit with mandatory 2FA.
Clusters secure by default
Private Network, nodes without a public IP and API access only from your addresses.
More on Cluster provisioningDeployments
From Git, a container image or a Helm chart, with a health check and restart without a rebuild.
More on Deployments- NewProvision Kapsule clusters
Create clusters with a Private Network, gateway and nodes without a public IP in your Scaleway project.
- NewDeploy applications
Git, container and Helm services, built in the cluster or with GitHub Actions, with a health check.
- NewEnvironment variables and restart without rebuild
Variables encrypted per service; changed values go live with a restart, without a new build.
- NewManaged PostgreSQL and MySQL
Database instances in the private network, one database with its own user per service.
- NewAutomatic DNS and certificates
Records in Cloudflare zones and Let’s Encrypt certificates for every host.
- NewSign-in with mandatory 2FA
Personal accounts, every sign-in with a second factor.
How Clusterward is shipped
Every change you would notice in the cockpit is listed in the product changelog before it ships. After an update, the list opens once per user, on all devices. Internally, the rule is: a new add-on version is only recommended after it has run live once, and every security requirement such as private nodes or mandatory 2FA is a default, not an option.
What a feature does in detail is explained on the respective product page, for example Cluster updates or Notifications. If you are missing a feature, let us know via our Contact page.
See new features live
In the demo, we show the latest changes on a real workspace and take your wishes for the next ones on board.