Hey Team,
If any of your clusters still run the NGINX Ingress controller, please finish the move to Envoy Gateway soon. NGINX support on Qovery ended on August 31 and the upstream project is no longer maintained, and the migration guide walks through every step. If you missed our live session on moving from Heroku to AWS with an agent doing the work, the replay is online.
This release makes blueprints the default way to run a managed database, ships the first stable version of our Terraform provider, and shows what runs on each cluster.
🧱 Database Blueprints: the default way to run a managed database
Two weeks ago we opened a migration path from legacy managed databases to blueprints. Blueprints are now the only way to create a new cloud-managed database. When you add PostgreSQL, MySQL or Redis from the Console, the creation flow offers container mode for development, and the service catalog is where you pick a managed instance such as Amazon RDS for PostgreSQL. Your existing managed databases keep running as they are.
Most of the work since then went into making blueprint databases easy to use day to day:
- Connecting. A Connection URI button on the database copies a ready-to-use
postgresql://ormysql://URI, for anyone allowed to see credentials. From your laptop,qovery port-forward -p 5432:5432 <database URL from the Console>now works with blueprint databases, andqovery database list --show-credentialslists them. - Monitoring and alerts. RDS blueprint databases get a monitoring dashboard and alert rules for CPU, connections, freeable memory, free storage and read or write latency, once CloudWatch metrics are enabled.
- Catalog. Amazon RDS for PostgreSQL 18, Amazon MQ for RabbitMQ 4, and smaller and newer RDS instance types (db.t4g.micro, db.t4g.small and m8g).
Antoine built most of this. See the blueprints documentation for what the catalog covers today.
🏗️ Terraform Provider 1.0: your configuration is the source of truth
Until now, a change made in the Console could quietly survive a terraform apply, and leaving an attribute out of your configuration kept whatever value was there before. That made it hard to know whether Terraform or the Console was really in charge.
Version 1.0 of the Qovery Terraform provider makes your configuration the source of truth. A refresh reads the real state from the API, so a change made in the Console shows up in terraform plan and the next apply reverts it. An attribute you leave out now plans the Qovery default instead of keeping the last value. The release also adds a qovery_blueprint resource to manage catalog services, a typed build_settings block for build timeout, CPU, memory and cache, a GPU node pool override for Karpenter, and more Karpenter tuning.
resource "qovery_blueprint" "cache" {
environment_id = qovery_environment.production.id
name = "my-redis"
blueprint = "HELM/redis/8"
variables = { memory_limit = "1Gi" }
secret_variables = { password = var.redis_password }
}
This is a major version with breaking changes, for example the global Karpenter spot_enabled flag is gone and each node pool now sets its own. Read the upgrade guide before you bump the version, and run a plan first. Thanks to Guillaume for carrying this release.
📊 Cluster Workloads: see what runs on each cluster
Answering "what is running on this cluster, and who is using it?" meant opening every environment one by one. A new Workloads tab on the cluster page answers it in one place.
It shows how CPU and memory are allocated across the cluster, with the top five environments, the system components and the capacity left, followed by a table of every environment with its pods and allocated resources. Expand a row to see its services. Numbers are based on resource requests, which is what decides whether a new deployment fits. Built by Alessandro and Théo.
Read more in the clusters documentation.
🤖 Agent Task Automations: templates, run history and cost
Agent Tasks opened to everyone two weeks ago. The next questions were where to start and what each run did.
Environments now have an Automations tab that lists your Agent Tasks, or offers templates when you have none: Slack Coding Agent, Coding Agent, Sentry Incident Analyzer and Incident Analyzer. Each Agent Task has a Runs view with status, duration, trigger and payload for its latest runs, and every run shows what it cost. You can also pick the model from a dropdown loaded from your provider instead of editing JSON, including Bedrock regions. The build and deployment optimizer template now uses the qovery-speedup skill and only proposes changes through pull requests.
Get started with the Agent Tasks documentation.
🛠️ Minor updates
- You can now add storage to an application or container after its first deployment. Deleting a storage asks for confirmation and warns that its data is lost for good.
- The CLI can restart a service without a full redeploy, with
qovery application restart,qovery container restartandqovery database restart.qovery environment deployment logsprints the same deployment logs as the Console, and--watchnow waits for the services you asked about. See the CLI documentation. - Build settings for applications, jobs and Terraform services have their own page under Service > Settings, with timeout, CPU, RAM, ephemeral storage, BuildKit cache and Git submodules.
- Saving a service now warns you when Qovery could not set up the auto-deploy webhook, for example when your git account lacks admin rights on the repository.
- Service logs format JSON messages, make URLs clickable, and search in UTC when UTC is selected.
- The environment list can be sorted by name, last operation, cluster or last update.
- Observe can alert you when a TLS certificate renewal fails.
- Grafana 13, connected to your cluster's Prometheus, Loki and Alertmanager, and SigNoz, which collects OpenTelemetry traces, logs and metrics, are now in the service catalog as Helm services.
- On Scaleway Kapsule, image mirroring can be disabled so pods pull straight from your registry. See image mirroring.
- Changing the credentials of a managed EKS cluster now asks you to confirm, since it triggers a cluster redeployment.
- Organizations using SAML or OIDC no longer see an Add member button, since members come from the identity provider, and denied actions now appear in audit logs.
- Two new guides: expose a service privately with Tailscale and deploy microservices from a monorepo.
As always, let us know what you think and what you would like to see next.
Talk soon, The Qovery Team 🚀

