2026.40 Infrastructure Changes

5 min read

Infrastructure

Added

  • Scope management selects Zitadel v1 or v2 APIs from the server version so mixed 3.x and 4.x tenants can share one image; operators can pin the mode with ZITADEL_API_MODE.

  • Frontend Helm charts (admin, chat, knowledge-upload, theme) configure cross-app navigation URLs via a structured frontends values object instead of flat *_APP_URL overrides.

  • sbx-storage exposes checkpoint deletion on a dedicated port; node-chat's dependency on it (disabled by default) is scoped to that port, so enabling it in an overlay grants delete-only access without requiring Cilium L7 proxying.

Fixed

  • Chat metrics jobs no longer load a full day of message debug data into memory when computing daily tool-call and MCP summaries.

  • Client insights reads now use indexed lookups on installation and time range instead of scanning the full insight table.

  • First installs no longer hang on the migration when the namespace has a default-deny policy. Charts with a migration hook now render a <fullname>-hooks network policy, for both cilium and kubernetes flavors. Remove any hand-made <fullname>-hooks policy, it clashes by name.

Feature Flags

Change

Environment Variable Name

Application Default Value (if env variable unset)

Example

Required

Applications

Short Description

Removed

FEATURE_FLAG_ENABLE_MCP_TOOL_POLICY_FOUR_STATE_UN_20686

-

-

-

backend-service-configuration

Removed

FEATURE_FLAG_ENABLE_MCP_TOOL_REFRESH_UN_19255

-

-

-

backend-service-configuration

Removed

FEATURE_FLAG_ENABLE_HTML_WITH_FENCE_UN_17927

-

-

-

backend-service-configuration

Removed

FEATURE_FLAG_ENABLE_CODE_EXECUTION_FENCE_UN_17972

-

-

-

backend-service-configuration

Removed

FEATURE_FLAG_ENABLE_CODE_EXECUTION_SIDE_PANEL_UN_18787

-

-

-

backend-service-configuration

Removed

FEATURE_FLAG_ENABLE_CODE_EXECUTION_UN_17498

-

-

-

backend-service-configuration

The feature flag was converted to the company setting codeExecutionEnabled, seeded by COMPANY_CONFIGURATION_CODE_EXECUTION_ENABLED

Added

FEATURE_FLAG_GENERATED_FILE_HALLUCINATION_CHECK_UN_22029

false

false

false

backend-service-configuration

Generated-file groundedness and generated-file Sources in Conduct

Added

FEATURE_FLAG_AGENTIC_TABLE_SHARE_LIBRARY_UN_23456

false

false

false

backend-service-configuration

Enables share modal for agentic table answer libraries.

Added

FEATURE_FLAG_AGENTIC_TABLE_BULK_ACTIONS_UN_23981

true

true

false

backend-service-configuration

Show the Bulk Actions button on agentic table sheets and the floating multi-select action bar it toggles

Added

FEATURE_FLAG_AGENTIC_TABLE_EDIT_WITH_AI_UN_24386

false

false

false

backend-service-configuration

Show Edit with AI on agentic-table answer cells: an ephemeral multi-turn refine that uses the column scope and tools, and commits only on accept

Added

FEATURE_FLAG_ENABLE_SCHEDULED_TASKS_UN_24104

false

false

false

backend-service-configuration

Enable Scheduled Tasks: let users schedule a prompt to run on a recurring schedule from a chat message, and manage their tasks from the navigation. Requires FEATURE_FLAG_ENABLE_NEW_ANSWER_FORMATTING_UN_14392.

Added

FEATURE_FLAG_INTERRUPTED_TURN_ALERT_UN_24137

false

false

false

backend-service-configuration

Show the "Response stopped early" alert when a Conduct turn halts before producing an answer. Off by default for the release; enable per company when ready

Added

FEATURE_FLAG_ENABLE_DOCUMENT_LINK_GRAPH_UN_26282

false

false

false

backend-service-configuration

Show a local link graph for Markdown and HTML files open in the chat side panel, and for Markdown files open in the Knowledge Base side panel. Off unless enabled for a company

Added

FEATURE_FLAG_ENABLE_AGENTIC_METADATA_EXTRACTION_UN_15619

false

false

false

backend-service-configuration

Use AI to extract structured metadata from documents during ingestion, per folder (experimental)

Added

FEATURE_FLAG_ENABLE_KB_FILE_PREVIEW_UN_23201

false

false

false

backend-service-configuration

Preview knowledge base files (PDF, Office, Markdown, text, CSV) in a nested viewer inside the file detail panel

Required infrastructure updates

Secure WebSocket token-to-ticket migration

To improve security, WebSocket connections are now authenticated with short-lived, single-use tickets issued by the Kong gateway instead of passing the user's access token. Tickets are stored in Redis for a few seconds and removed when used. This requires Redis 6.2 or newer (for GETDEL), reachable from Kong, with a writable primary, password authentication, and key expiry (TTL). By default, the existing redis-replication instance is used. Legacy token-based WebSocket authentication stays available during the client rollout.

Requirements:

Component

Action

Description

kong-plugins

Update version: 2.8.0

To support newest helm-chart configuration.

kong-plugins

Change helm-chart configuration

Follow the readme documentation of the Single-use Websocket tickets (Redis):

https://github.com/Unique-AG/helm-charts/tree/main/charts/kong-plugins#single-use-websocket-tickets-redis

redis

Update version: 6.2 or newer

Tickets are stored in Redis for a few seconds and removed when used. This requires Redis 6.2 or newer (for GETDEL).

web-app-chat, web-app-knowledge-upload, web-app-admin, web-app-theme

Set environment variable:

WEBSOCKET_AUTH_MODE: ticket

Enabling the Websocket ticket approach

Code interpreter display switches move to assistant configuration

The two code interpreter display flags are gone. Both switches are now plain fields in the Code display section of the assistant configuration:

Old feature flag

New configuration field

New default

FEATURE_FLAG_ENABLE_CODE_EXECUTION_FENCE_UN_17972

enable_code_execution_fence

true

FEATURE_FLAG_ENABLE_HTML_WITH_FENCE_UN_17927

enable_html_with_fence

true

Behaviour change: both flags used to default to off. The new configuration fields default to true. So HTML files now show as an interactive card with a code view for every client, unless an operator sets enable_html_with_fence to false.

enable_html_with_fence only works when enable_code_execution_fence is also on. If either switch is off, HTML files fall back to a plain HtmlRendering block.

Action required: remove both environment variables from your environment. If you do not want the HTML card, set enable_html_with_fence to false (true by default) in the assistant configuration. If you do not want the FILE card, set enable_code_execution_fence to false(true by default) in the assistant configuration.

Code Execution moves from a feature flag to a company setting

The Code Execution tool is no longer controlled by FEATURE_FLAG_ENABLE_CODE_EXECUTION_UN_17498. It is now a company setting called codeExecutionEnabled, served by backend-service-configuration. The old flag is still present but it is ignored.

Action required. The new setting is off by default. If you run Code Execution today, you must set the new variable on backend-service-configuration, or the tool disappears after the upgrade.

yaml
configurationBackend:
  env:
    COMPANY_CONFIGURATION_CODE_EXECUTION_ENABLED: "*:true"

Use *:true to turn it on for every company on the deployment. Use a list of company IDs when only some companies may run it:

yaml
    COMPANY_CONFIGURATION_CODE_EXECUTION_ENABLED: "225336703097770043:true;257914415460909091:true"

The two forms behave differently. *:true writes a deployment-wide default. A company that an admin has switched by hand keeps its own value. A companyId:true pair writes a per-company value, which is stronger, and it is written again on every restart — also over a value an admin set by hand.

Before you turn it on, check these three points:

  • The Code Execution sandbox runs on Azure OpenAI. Do not turn it on if your models come from on-premise, AWS, or a non-Azure LiteLLM.

  • FEATURE_FLAG_USE_OPENAI_V1_13819 must be on. If it is off, keep Code Execution off, or the tool is offered and the call fails.

Scope count moves from scope management to ingestion

This change is only relevant when using the dedicated chart for client insights-exporter and and having network policies enabled. If you’re using the generic backend-servicechart or do not have network policies enabled this adjustment does not need to be made.

countOfScopes is no longer emitted by backend-service-scope-management. client-insights-exporter must scrape it from backend-service-ingestion instead. Until both sides of this wiring are deployed, the metric stops.

Action required. Apply both changes in the same release window.

On client-insights-exporter, add this under internalServices.dependencies in the preview, offset, and stable defaults. On Prod, use the same block with namespace finance-gpt.

yaml
ingestion:
  enabled: true
  name: node-ingestion
  namespace: chat

On backend-service-ingestion, add this under internalServices.dependents in the preview, offset, and stable defaults:

yaml
clientInsightsExporter:
  name: client-insights-exporter
  namespace: apps

Reflector service now needs the credentials passed through the kong plugin

As the reflector service now is secured via cookie credentials, they need to be allowed to pass through the Kong plugin in order to avoid CORS issues.

Example of CORS plugin to allow credentials

yaml
- apiVersion: configuration.konghq.com/v1
    kind: KongPlugin
    metadata:
      name: reflector-cors
    plugin: cors
    config:
      origins:
        - {THE PUBLIC URL OF THE CHAT APP (example: next.unique.app)}
      credentials: true
      max_age: 600
- apiVersion: networking.k8s.io/v1
    kind: Ingress
    metadata:
      annotations:
        external-dns.alpha.kubernetes.io/hostname: {THE PUBLIC URL OF THE REFLECTOR SERVICE (example: reflector.next.unique.app)}
        konghq.com/plugins: {YOUR EXISTING PLUGINS},reflector-cors
      name: reflector
Last updated