Docs Home
Viewing docs for
BYOCNot available for Self-Managed

BYOC 09.2026

On this page

Overview

Ververica Cloud 09.26 is a security and operations release for Bring Your Own Cloud. It hardens session handling, organization-managed API tokens, and domain verification, and adds pod scheduling controls for Flink and agent workloads on shared Kubernetes clusters.

New Features and Improvements

Flink JobManager and TaskManager pods, and the agent pods that run alongside them, can now be pinned to specific nodes in your Kubernetes cluster. Scheduling is configured as YAML in the console, using the standard nodeSelector, affinity, and tolerations fields.

This keeps Flink workloads on dedicated node groups in shared or multi-tenant clusters, and off nodes reserved for other tenants. Agent pod scheduling now persists as well, instead of being reset by the periodic reconcile job.

Organization-Managed API Tokens

Organization administrators can now create, list, and delete workspace-scoped API tokens for their own organization, and revoke any token the organization owns instead of only their own. Token scopes are enforced across the API, so a narrowly scoped token can no longer reach endpoints outside its scope, and a token issued in one organization cannot act on another organization's workspaces.

This gives organization administrators one place to manage automation credentials for the whole organization, while every token stays confined to the scope and the organization it was issued for.

Learn More: Single Sign-On Overview

SSO and Organization APIs in the API Reference

The Single Sign-On and Organization endpoints are now included in the BYOC OpenAPI specification and the interactive API reference, so you can browse and try them the same way as the rest of the platform API.

Organization and Single Sign-On management is now scriptable from a documented, testable API, instead of against undocumented endpoints.

Bug Fixes

Logout Revokes the Session Server-Side

Logging out of a password or Google session cleared the browser state but left the access token valid until it expired on its own. Logout now revokes the token at the gateway, so a captured token stops working as soon as you sign out.

Refresh Tokens Revoked at Logout

For Single Sign-On sessions, the refresh token stayed usable after logout and could be exchanged for a new session. Logout now revokes the refresh token and ends the grant at your identity provider.

Domain Verification

Two organizations could each claim ownership of the same domain by using its unicode and punycode spellings. Domain names are now normalized before verification, so the two spellings resolve to one domain. This matters because domain ownership gates Single Sign-On login and role binding.

Internationalized domain names also failed verification permanently, discarding a valid DNS proof. Those domains now verify correctly.

Clearer Single Sign-On Errors

When an identity provider returned a response without an email claim, sign-in failed with a misleading "incorrect credentials" message. The error now states what is missing. An intermittent failure on the token endpoint, caused by reading provider metadata too early, is also fixed.

Country on First-Time Single Sign-On Sign-Up

The first time a user signed in through Single Sign-On, their country was recorded as "N/A". It is now taken from the organization owner's profile.

Member Status and Role Editing

The Members page showed an empty Status column and a disabled Edit action for every member, leaving delete-and-reinvite as the only way to change a role. Invitation status is now returned correctly and role editing works again.

Trace IDs in API Error Responses

Error responses from the platform API always carried an empty trace ID, which made it hard to correlate a failed request with its logs when contacting support. Responses now carry a real trace ID.

Was this helpful?