Upcoming Workshop: Citizen Developer Agentic Software Factory on AWS
Seats follow your identity provider, custom attributes are safe to change, config can be loaded and promoted from any instance, and external resources show on the environment graph.
September versioned the contract between components. This release covers the work that came after it: who holds a seat, what happens when an admin changes a custom attribute that policies depend on, and how you move configuration from one instance to another without retyping it.
For SCIM users, the active flag and an optional seat rule decide who holds a seat. Group membership does not.
In September a seat was any active member or pending invitation, and SCIM stopped creating users at the limit. That stopped organizations with more synced users than seats from ever finishing a sync. It also gave no way to say which synced users are licensed.
The rules now:
SCIM is never refused at the limit. A user who wants a seat when none is free waits in line, and the request succeeds. When a seat is released, or your plan adds seats, the user who has waited longest gets it. Group pushes from your IdP always succeed. An account needs a seat to access the organization, so a waiting user keeps their group memberships but cannot sign in to the organization until a seat is free.
Seat rules. The SCIM integration takes two optional fields, seat_attribute and seat_value. Set them together and only users whose attribute matches hold a seat. For example, mark licensed users in Entra with an app role and set:
seat_attribute: roles
seat_value: licensed
Matching is case-insensitive and reads values, not display names. With no rule, every active user wants a seat, the same as before.
Change an integration in place. The Integrations tab now has Edit for integrations with config, so you can set or change a seat rule without deleting and recreating SCIM. Changing the rule applies it to every provisioned user right away. Enabling and disabling an integration now asks you to confirm first.
See who holds a seat. The Members tab has two new columns. Source shows whether a member came from Massdriver or from SCIM. Holds Seat shows a check or an X. The Groups and Members tabs also show a seat meter, for example "8 of 10 seats used", for anyone who can manage billing. The meter shows on self-hosted servers too.
On the API, the organization members list carries Account.holdsSeat and Account.source, and updateIntegration changes an integration's config.
Removing an attribute value no longer locks every project that used it.
Before this release, removing a value from a custom attribute, or deleting the attribute, made every project, environment, component, and bundle carrying the old value impossible to update. A rename failed with DOMAIN Value is not allowed in enum even though the user never touched the attribute. Group policies that named the removed value kept existing and silently granted nothing.
Now:
required applies when you create an entity.
would leave policy on group "payments-eng" (project:view) matching no value
— edit or delete it first
the organization naming convention uses {{attrs.DOMAIN}} — edit the convention first
Adding values is always allowed. Values already set on entities stay in place.
Load, copy, promote, and compare config from the instance's Config tab.
The Config options menu used to disappear after the first deploy. It now shows for every instance, in form view and JSON view, with these actions:
When you load config, a banner lists the fields that were kept and the fields that were dropped because the current bundle version does not accept them. Nothing deploys until you save.
The copy and promote dialog now tells you that the destination moves to the source's bundle version, and which required fields it cannot copy. Promote is also in the instance Actions menu. Copy now checks your instance:configure permission on the destination, the same check the API makes.
See the remote references and environment defaults an environment uses.
A new toggle in the environment graph's controls draws external resources as faded nodes, with dashed lines to every instance that uses them. Each node shows the resource name, type, version, and a link to the resource. Remote references are green and environment defaults are blue. Before this, a remote reference was a small icon on a handle, and environment defaults did not show on the graph.
The environment default and remote reference pickers also show whether the environment can use each resource: Granted, No grant, or Same environment, with a link to the resource. If replacing an environment default fails partway, the previous default is restored.
Build your organization's naming convention in organization settings.
The naming convention from September is now editable in the UI, on the Name prefix tab. Drag atoms from the side panel into the template at any position, reorder them, or type the template directly. A live preview shows the name the template produces.
Resources created under a custom naming convention can now be looked up by their identifier, for example hellokargo-staging-iam.role. Before this fix, mass resource get, mass resource grant list, and the Terraform provider could not find them.
Import picks a version. The resource import dialog has a version selector next to the type, with release channels and exact versions. It defaults to the latest release. Importing a type that has only semantic versions no longer fails, and importing a type with both 0.0.0 and newer versions uses the newest.
Ranges on resources resolve at deploy. A bundle that declares resource_type: foobar@~1 in its resources block now produces a foobar resource at the newest 1.x version, and the payload is validated against that version's schema. If no published version is in the range, the deploy fails instead of using a different version. The resource's REST payload reports available_upgrade when a newer version in range has been published since the last deploy.
Access follows the repository. Resource types use the same permissions as bundle repositories:
repo:view decides who sees a resource type in the catalog.repo:pull on every resource type it references in dependencies and resources. A refused publish names each type, for example no access to postgres-connection@1.2.3.
Existing groups were given repo:view and repo:pull on resource type repositories, and groups that could publish resource types were given repo:push, so nobody lost access in the upgrade.
Each version has a changelog. Repository details have a Changelog tab that shows the CHANGELOG.md of the version you select.
Export downloads work for OCI-published types. Down a rendered export, such as a kubeconfig, failed for resource types published from massdriver.yaml. It works now, with no republish needed.
dependency in $md.enum. A param that builds its dropdown from a dependency can use dependency: in place of connection:. Provisioners can read /massdriver/dependencies.json, which holds the same content as /massdriver/connections.json.
params:
properties:
region:
type: string
$md.enum:
dependency: aws_authentication
options: .allowedRegions
+dev channel, including ones that point at the same version as their stable channel today
Access tokens work only in the organization that created them.
A personal access token or service account token now works only against the organization it was created in. Before this change, a token created in one organization could be used in any other organization the account belonged to.
If you use one personal token across more than one organization, create a token in each organization. Browser sessions are not affected.
The platform image no longer includes curl, and the image upgrades its base packages at build time. This clears the critical and high CVE findings that scanners reported on 2.5.0.
massdrivercloud/massdriver and massdrivercloud/massdriver-ui are published for both linux/amd64 and linux/arm64`` MD_PROVISIONER_LOGGER_IMAGE sets the provisioner logger image, in the same way as the init and exit container images
| Component | Version |
|---|---|
| Helm chart | 0.2.7 |
| Massdriver | 2.5.5 |
| UI | 2.1.6 |
Self-hosted installs pick up the platform and UI images through the chart.
Two changes need action before or after you upgrade:
unauthenticated on the other organizations. Create a token in each organization.
Resource types become versioned OCI artifacts, connections carry version ranges, and deployment approvals get separation of duty.
Version 1.3.0 of the Massdriver Platform featuring SCIM 2.0, Integrations Console, and Claude Code Plugin.
Version 1.2.0 of the Massdriver Platform.