v2.36.0
jianchang512/pyvideotransv2.36.0Aug 4, 2026by github-actions[bot]
AI Summary
This release introduces comprehensive AI Governance features including budget tracking and enforcement, a standalone AI Gateway, and significant improvements to Coder Agents and User Secrets. It also includes several breaking changes related to authentication and database schema.
Key Highlights
- New AI Governance features track and enforce user and group AI spend.
- AI Gateway can now be deployed as a standalone process.
- Coder Agents receive major quality-of-life updates including chat summaries and full-text search.
- User Secrets are now generally available with bulk import capabilities.
Breaking Changes
- Dynamic client registration is disabled by default.
- Legacy `login_type=none` accounts are automatically converted to password login.
- The `provider` column has been removed from the `chat_model_configs` table.
New Features
- Budget tracking and enforcement for AI spend with Prometheus metrics.
- Standalone AI Gateway with start command, health endpoints, and Helm chart.
- Full-text search over chat messages and persisted chat summaries.
- Bulk user secret import endpoint and CLI command.
- Support for multiple OIDC redirect URIs.
- Workspace restart functionality via API.
Full Release Notes
## Changelog > [!NOTE] > This is a mainline Coder release. We advise enterprise customers without a staging environment to install our [latest stable release](https://github.com/coder/coder/releases/latest) while we refine this version. Learn more about our [Release Schedule](https://coder.com/docs/install/releases). ### BREAKING CHANGES - Dynamic client registration disabled by default (#27316) > `POST /oauth2/register` (RFC 7591 Dynamic Client Registration) is now controlled by a persistent admin setting, `oauth2_dcr_enabled`, independent of the experiment system. The setting **defaults to disabled**. A new audited `GET`/`PUT /api/v2/oauth2-provider/settings` endpoint lets an owner toggle it live without a restart. When disabled, new registrations are rejected with an RFC 7591-shaped 403, and `registration_endpoint` is omitted from discovery metadata. > > Migration: Deployments that rely on dynamic client registration must explicitly enable the new setting via the API or UI after upgrading. Existing registered clients are unaffected; only new registrations are gated. - `login_type=none` deprecated; existing accounts converted to password login (#26851) > `login_type=none` (legacy passwordless machine users) is deprecated in favor of premium service accounts. A database migration (`000554`) automatically converts existing non-system `login_type=none` accounts to `login_type=password`. Creation of new `login_type=none` accounts via `POST /users` and `coder users create` (including the deprecated `--disable-login` flag) is now rejected unless a service account is explicitly requested. > > Migration: Automatic for existing users. Legacy `login_type=none` accounts will be migrated to password login on first startup after upgrading. Review any automation that creates users with `login_type=none` and update it to use service accounts instead. - `chat_model_configs.provider` column removed (#26877) > The `provider` column has been dropped from the `chat_model_configs` table. Provider type is now derived exclusively from the linked `ai_providers` row via `ai_provider_id`. The experimental HTTP/SDK response for model configs drops the `provider` field and makes `ai_provider_id` required; consumers should resolve provider type by joining against the AI providers listing. Telemetry continues to emit `provider` via a JOIN, so BigQuery columns and Nexus dashboards are unaffected. > > Migration: Update any custom queries or SDK consumers that read `chat_model_configs.provider` directly. Resolve provider type via `ai_provider_id` and the AI providers listing instead. ### Features #### AI Governance ##### Budget tracking and enforcement User and group AI spend is now tracked, enforced, and exposed across the platform. - Record user daily AI spend on token usage and enforce budgets on the pre-request path (#26741, #26562, #26915) - User AI spend endpoint and group/member spend endpoints (#26978, #27123, #27130, #27568) - Prometheus metrics for AI Governance cost control (#27490) - CSV export for AI spend data (#27491) - Budget threshold notifications for users and admins (#27346, #27415) - Fall back to the Everyone group for AI spend attribution (#27364) - Dashboard: show spend for unlimited and zero AI budgets; announce cost controls in AI Governance (#27458, #27543) - Dashboard: polished AI budget members table (#26805) - Network calls column and badges added to AI sessions table (#27269, #27341) ##### Seat counting - Count only workspace-capable users toward license seats (#27279) - Exclude AI Bridge usage from AI Governance seat counting (#27280) #### Standalone AI Gateway The AI Gateway can now be deployed as a standalone process with its own start command, health endpoints, observability stack, and Helm chart. - `coder ai-gateway start` command (#26605) - `/healthz` and `/readyz` endpoints (#26988) - Logging, tracing, and metrics (#27068) - Helm chart for standalone AI Gateway (#27256) - `--aigateway-proxy-target` flag (#27122) - Prefixed standalone metrics (#27526) - Known-models catalog and AI Gateway price generation (#27146) - AWS Bedrock mantle endpoint and Bedrock mantle protocol selector in the provider form (#26745, #27156) - Generate STS external ID for Bedrock role assumption (#26869) - Show Bedrock external ID in the provider edit form (#26919) - Synthetic gateway keys (#27170) - NATS mTLS pubsub implementation (#26902) #### Coder Agents ##### Chat quality of life - Full-text search over chat messages (#27126) - Manual chat compaction via `/compact` command (#27081) - Persisted whole-chat summary with background generation; summary tab in right sidebar with per-chat cost endpoint (#26657, #26649) - Workspace skills available in the agent chat slash menu (#25600) - Searchable agent model picker with instance-based grouping and custom provider icons (#26927, #27026) - Configurable reasoning effort per agent and advisor; model and effort override in `spawn_agent` (#26974, #27196, #27385) - Admins can override the chat compaction model (#27151) - Anthropic 1M context window toggle for Agents model configs (#27257) - Model content-filter refusals surfaced as a blocked chat error; reasoning-only refusals classified as terminal errors (#27118, #27476) - MCP server OAuth grant disconnect UI, provider-side revocation on disconnect, and graceful handling of revoked grants (#27299, #27300, #27264) - Chat lifecycle hooks: suffix messages, idle failure, and content updates dispatched from the backend and wired into chatd (#27401, #27428, #27429) - Notify users when chats are shared (#26914) - Structured error fields in `wait_agent` error payload; child error detail surfaced in `last_error` (#27478, #27477) - `WatchAIProviders` synchronizes provider changes to clients in real time (#27091) - Accumulate user daily AI spend and retain user constraints in compaction summaries (#26741, #27230) - `claude-fable-5` and `claude-mythos-5` added as known model defaults (#27131) - Support Anthropic `/v1/messages` route on Copilot (#26911) - Record all tool call types and provider item IDs for tool usage (#26855, #26856) - Remove chat chain mode and unused chat statuses (#26980, #27064) - Add chat suffix messages, idle failure, and content update support (#27428) #### Template Builder - Improved image management experience (#27018) - Auto-fill customization fields from the base template (#27272) - Browser back and forward support in the wizard (#27104) - Provisioner warning and disabled create button when no provisioners are available (#26935, #26938) - Module deselection from the main content area (#27113) - Template Builder session telemetry (#27124) - Show all step content without inner scroll (#27437) #### User Secrets - User secrets file parser and shared validator (#26723) - Bulk user secret import endpoint and SDK client (#26724) - Bulk secret import upload in the Add secret dialog (#26725) - Enable/disable support for user secrets (#27537) - `coder secret import` CLI command for bulk secret files (#27534) - Beta label removed; user secrets are now generally available (#27510) #### RBAC & Auth - Support multiple OIDC redirect URIs (#25408) - Agent runtime hour license claims and entitlement feature (#27459) #### Workspace & Platform - Workspace restart functionality via API (#25757) - Expose external auth token expiry in agent API and CLI (#26883) - Tailnet tunnels logged to the connection log (#27423) - Add dry-run flag via `CommandExecutor` interface (#26422) #### Dashboard - OSC 52 clipboard support in the web terminal (#26437) - Confirm before batch stopping workspaces (#27631) - Hide workspace resources when the user lacks workspace-create permission (#27278) - Rename "Dismiss warnings" to "Mute warnings" and make health callouts dismissible (#27554) - Show "Archived chats" sidebar heading when viewing archived chats (#26926) - Search users by display name (#27398) - `AppearanceProvider` introduced to decouple `externalImages` from theme (#27197) ### Bug fixes #### Server - Preserve scopes on Entra v1 token refresh (#24851) - Allow user-admin password resets to succeed (#26537) - Recover timed out agents (#27254) - Retry quickgen without temperature when the model rejects it (#27120) - Remove compaction timeout (#27007) - Clarify wait agent timeout (#27335) - Avoid request recorder race (#27525) - Prevent concurrent token refreshes (#26530) - Match `sync.Map` semantics in the typed wrapper (#27582) - Sanitize workspace MCP tool names (#26928) - Reject workspace proxy hostname prefixes (#27544) - Fix runner bootstrap race (#26989) - Remove standalone AI Gateway HTTP listener dependency on loading providers (#27303) - Give chat message IDs an append-order guarantee (#27495) - Order the chat prompt query and its boundary by ID (#27619) - Resolve duplicate 000554 migration collision (#27581) - Explain default GitHub app org visibility on login rejection (#27374) #### AI - Handle Sonnet 5 adaptive thinking in Bedrock (#27339) - Disable keep-alive on the STS assume-role client (#26971) - Validate Bedrock protocol at provider construction (#27234) - Stop sending adaptive thinking to pre-4.6 Anthropic models (#27314) - Hide and reject chat models from disabled AI providers (#27070) - Textualize advisor prompt tool exchanges (#27059) - Classify aibridge 403 as `ChatErrorKindUsageLimit` (#27538) - Extract plain-text provider error bodies (#27597) - Remove chatd usage limit enforcement (#27535) - Remove 403 from key failover; cooldown on 401 (#27419) - Delete unused `ChatMessagePart.Signature` field (#27588) - Stop manual title generation from writing to `chat_messages` (#27087) - Serialize chat model config default election with advisory lock (#27114) - Use pasted-text attachments as chat title input (#27067) #### Security & Auth - Harden OAuth2 redirect validation (#27274) - Enforce max body size on CSP violation report endpoint (#27243) - Normalize path before rate-limit bucket keying (#27273) - Redact env var values in agent debug manifest endpoint (#26904) - Enforce required external auth on task create (#26718) #### Template Builder - Declare `project_id` variable in GCP template builder bases (#27015) - Fix login helper race condition (#27107) - Prompt for DigitalOcean base variables (#27268) - Stop build progress bar from looping (#27276) - Smooth compose loader to files page transition (#27277) #### Dashboard - Keep activity bump editable when `allow_user_autostop` is on (#27083) - Replace ansi-to-html in the log viewer (#27206) - Wrap workspace topbar controls on narrow viewports (#27313) - Stack settings layouts on mobile (#27334) - Keep mobile model picker effort row and last model visible (#27336) - Align AI Settings model provider dropdowns (#27391) - Remember reasoning effort per model on new chat (#27457) - Use variable defaults as field values, not just placeholders in Template Builder (#27032) - During workspace bulk start/stop, skip workspaces already in the target state (#27108) - Do not send or use stale init dynamic parameter state (#27283) - Show selected owner's external auth when creating a workspace (#26653) - Don't show admin settings dropdown to all users (#27481) - Remove excess calls to `prepareSQLFilter` for workspace and template endpoints (#27248) ### Documentation - AI Gateway cost controls placeholder page (#27570) - Document wildcard hostname suffixes (#27482) - Template creation docs updated to present the Template Builder as the primary creation path (#26993) - DOCKER_HOST guidance for non-default Docker socket paths (#26807) - `write-docs` authoring skill added (#26767) - Document Bedrock mantle protocol (#27296) - Frontend pattern rule contract (FE1-FE10) and frontend review skill for pre-PR audits (#27407, #27408) - Clarification of install methods in Get Started guide (#27466) - SCIM 2.0 handler opt-in and legacy flag documentation (#27469) - Audit and fix `manifest.json` page descriptions for SEO (#27267) - Vale rules: `BrandNames`, `GerundHeading`, directional language, and contractions (#25501, #25502, #26729) - Add `@coder/docs` as CODEOWNER for docs content and tooling (#27240) Compare: [`v2.35.0...v2.36.0`](https://github.com/coder/coder/compare/v2.35.0...v2.36.0) ## Container image - `docker pull ghcr.io/coder/coder:v2.36.0` ## Install/upgrade Refer to our docs to [install](https://coder.com/docs/install) or [upgrade](https://coder.com/docs/install/upgrade) Coder, or use a release asset below.