Changelog
Note
This is a mainline Coder release. We advise enterprise customers without a staging environment to install our latest stable release while we refine this version. Learn more about our Release Schedule.
BREAKING CHANGES
-
Tasks fully deprecated and removed
Tasks are fully deprecated and removed in Coder v2.38.
Migration: Users who rely on Tasks can stay on the v2.34 Extended Support Release during the support period.
-
Experimental chat API mounts removed (#29548)
The experimental chat API mounts have been removed. The new
/api/v2routes are now the only supported path.Migration: Update any clients or automation that call the experimental chat API mounts to use the
/api/v2routes. -
MCP servers on internal networks must be allowlisted (#28242)
Connections to MCP servers on internal networks now require their address ranges to be allowlisted with
--mcp-allowed-private-cidrs.Migration: After upgrading, add the CIDRs of any internal MCP servers to
--mcp-allowed-private-cidrs, or those connections will fail. -
Embedded NATS is now the default pubsub between
coderdreplicas (#29283)Coder now carries real-time events between
coderdreplicas over embedded NATS by default, instead of PostgresLISTEN/NOTIFY. Each replica runs an embedded NATS server and meshes with the others, with automatic mutual TLS for Enterprise. The API, CLI, and dashboard are unchanged. Thenats_pubsubexperiment has been removed.Migration: Before upgrading HA deployments, allow TCP port 6222 in both directions between every pair of replicas. With custom relays, set
CODER_CLUSTER_HOST, or Coder falls back to Postgres pubsub. To stay on Postgres pubsub, enable theno_nats_pubsubexperiment and restartcoderd. No data migration is needed. See the high availability docs.
Features
Coder Agents
New models and org-wide defaults
- Support for GPT-6 Sol, GPT-6 Luna, GPT-6.1 Sol, Claude Opus 5.5, and Claude Sonnet 5.5 (docs)
- Non-Anthropic models via AWS Bedrock Mantle
- Admins can set an org-wide default model under AI > Coder Agents settings; new chats use the org default instead of each user's last pick (docs)
Large file uploads
- Files outside the inline attachment allowlist (zips, datasets, tarballs, etc.) stream directly to the workspace filesystem with no size cap; the model only sees a path reference, not the file bytes
- Works from both existing chats and the new chat page; the UI routes attachment-compatible types inline and everything else to the workspace
Chat management
- Filter chats by status and PR status, including "no PR" (docs)
- Mark chats read or unread
- Reworked sidebar with a dropdown filter and section switcher
/clearcommand to reset context mid-conversation- Shareable prompt links that prefill the composer from a URL
AI Gateway
Claude Platform on AWS
- New "Claude Platform for AWS" option on Anthropic providers, configured with a region and workspace ID; no extra signing proxy required (docs)
- Authenticate with stored Claude Platform API keys, or fall back to the gateway's ambient AWS IAM credentials via SigV4 when no key is present
- Standard Anthropic model IDs and the full Messages API are preserved, along with central governance, usage attribution, and auditing
Bedrock IAM role authentication
- New
provider.Bedrockwith AWS SigV4 middleware; credentials resolve via static keys, the ambient credential chain, or AssumeRole, enabling IAM role and IRSA-based auth (docs) - OpenAI Chat Completions and Responses wire protocols over Bedrock's Mantle inference endpoint, alongside Anthropic Messages
- Budgets, rate limits, BYOK policy, and full interception recording (prompts, tokens, tool calls) continue to work unchanged
RBAC & Auth
- OAuth 2.1 support for standards-based application access, available behind a feature flag (docs)
- Admins can restrict OAuth apps to specific scopes
Workspace & Platform
- Embedded NATS pubsub for high-availability deployments (#29283); see Breaking Changes
Related releases
Coder VS Code Extension v1.16.4
- Fix Windows SSH "Bad owner or permissions" errors
- Workspace updates land on the correct template version (Coder 2.36+), with a prompt if an update fails
- Debug logs are captured automatically on connection failure
View the docs and the v1.16.4 changelog.
envbox v0.6.9
- Builds default to the host architecture, preventing mixed-architecture images when building locally
- Sysbox checksums are matched to the target platform automatically, fixing checksum failures on ARM64 and ARM64 cross-builds
- Remediated CVEs: bumped Go to 1.26.6 and updated Coder, gRPC, and DataDog tracing dependencies
View the full envbox changelog and the commit comparison.
Compare: v2.37.0...v2.38.0
Container image
docker pull ghcr.io/coder/coder:v2.38.0
Install/upgrade
Refer to our docs to install or upgrade Coder, or use a release asset below.