Release 2026.40.0
Release period: 2026-09-24 to 2026-09-30
This release includes the following issues:
- JSON Schema Input Type for Building Block Definitions Is Now Available
- See and Filter How Far a Tenant Deletion Has Got
- Create or Update Workspace Group Bindings with a Single API Call
- Approve and Decline Tenant Deletions via the meshTenant API
- Tenant API Filter Now Finds All Tenants Marked for Deletion
- Manage And Restrict Your meshStack CLI Logins
- Marketplace Service Instances Keep Their Order
- Individual Supported Platforms Are Referenced by UUID
- Resizable Code Editors for Building Block Inputs
- meshTenant Now Tells You Who Created and Deleted a Tenant
- See Who Created and Deleted a Workspace in the Admin Area
- Building Blocks Now Respect the Supported Platforms of Their Definition
- Bulk Upgrade of All Matching Building Blocks Works and Explains Skipped Ones
- Clearer Required or Optional Choice for Inputs
- Readable Breadcrumb on the API Key Page of a Workspace
- Manage Workspace User Groups Through the meshObject API
- Destroyed Building Blocks Leave the Building Block List Right Away
- Repeating a Tenant Deletion Request No Longer Fails
- Tidier Loading Spinners on the Building Block Overview
- Hub Import Keeps JSON, Optional and Conditional Inputs
- Operator Input Notice for App Teams
- Smoother Scrolling Over Code Inputs
- JSON Inputs of a Building Block Definition No Longer Accept References
- Latest Run Card No Longer Counts Up While a Run Waits
- Choose Individual Platforms for a Building Block Definition
- Pick From a List of Values in a Building Block Input
- Runner Workload Identity Subjects Are Now Templates
Ticket Details
JSON Schema Input Type for Building Block Definitions Is Now Available
Audience: User
Description
You can now use "JSON Schema" as an input type on any Building Block Definition. The consumer fills in a form generated from your JSON Schema, and the value reaches the Building Block as JSON, just like a Code input. This option is marked as Beta while we continue to refine it.
See and Filter How Far a Tenant Deletion Has Got
Audience: User
Description
The meshTenant API now tells you how far the deletion of a tenant has got, not only that the tenant is marked for deletion. A script that deletes tenants can wait for the right step, for example until meshStack has deleted the tenant's building blocks, and find every tenant that an operator still has to delete in the cloud platform with a single request. In the tenant list in meshPanel, the deletion states now use the same words as the API: "Deleting Building Blocks", "Deleting in Platform", "Awaiting Deletion in Platform" and "Purging".
How to use
Read status.pendingDeletionState of a meshTenant v4, or filter the meshTenant v4 list by pendingDeletionState.
Create or Update Workspace Group Bindings with a Single API Call
Audience: User
Description
You can now create or update a workspace group binding by its name through the meshObject API. An update lets you change the role of the group in the workspace and renews the expiry date, so you can keep bindings alive when role recertification is enabled without deleting and recreating them. The workspace and the group of an existing binding stay fixed. We also no longer accept an expiry date of today or earlier when you create a workspace binding through the meshObject API, also for roles without recertification.
Approve and Decline Tenant Deletions via the meshTenant API
Audience: User
Description
You can now approve or decline a tenant deletion with an API key, the same way you do with the "Approve Deletion" and "Decline Deletion" buttons in meshPanel. This lets you automate the whole deletion: your script approves the deletion, waits until meshStack has deleted the tenant's building blocks and the tenant, and then removes the cloud subscription.
How to use
Call POST /api/meshobjects/meshtenants/{uuid}/approve-deletion to approve, or POST /api/meshobjects/meshtenants/{uuid}/decline-deletion with an optional reason to decline. Both use the meshTenant v4 format and return the tenant. Repeating an approval is safe. Declining only works while the deletion awaits approval, so a repeated decline answers with 409 Conflict. Your API key needs the new "Approve deletion" permission in the Tenants group. The Admin variant covers every tenant. The Platform Builder variant covers the tenants on a platform your workspace owns, and the tenants on a landing zone your workspace owns if your workspace is a contributor of that platform. The event log names the API key as the one who approved or declined.
Tenant API Filter Now Finds All Tenants Marked for Deletion
Audience: User
Description
When you listed tenants through the meshTenant API filtered by MARKED_FOR_DELETION, the result missed tenants whose deletion was already approved but not yet finished, for example while their building blocks were still being deleted. It also missed tenants that were being purged. These tenants are marked for deletion, but no filter returned them. We fixed the filter, so it now returns every tenant that is marked for deletion and not yet deleted. In API version v3, this also applies to the DELETED filter, because it includes the tenants marked for deletion.
Manage And Restrict Your meshStack CLI Logins
Audience: User
Description
You can now see and end your meshStack CLI logins on the new "CLI Logins" page in your user profile. When you log in with the meshStack CLI, you now choose what the login may do: full access, no delete, or read-only.
Marketplace Service Instances Keep Their Order
Audience: User
Description
The service instances on a tenant's marketplace page now always appear in the same order. Before, the list could come back in a different order each time you opened it, and when you scrolled past the first page an instance could show up twice or be left out.
Individual Supported Platforms Are Referenced by UUID
Audience: User
Description
When you manage a building block definition through our API, an individual supported platform is now referenced by
the uuid of its meshPlatform, the way a meshTenant or a meshLandingZone references a platform. Platform types are
unchanged. If you manage definitions with our Terraform provider, upgrade it to version 0.26.3 or later.
Resizable Code Editors for Building Block Inputs
Audience: User
Description
You can now make the code editors for Building Block inputs taller, so long code or JSON is easier to read and edit. Drag the handle in the bottom right corner of the editor down. Editors still start at their usual height, and you cannot make them smaller than that. This covers CODE and LIST inputs when you order or edit a Building Block, and the default value, static value, JSON Schema and pre-run script editors in a Building Block Definition.
meshTenant Now Tells You Who Created and Deleted a Tenant
Audience: User
Description
The meshTenant API now reports who created and who deleted a tenant, not just when. Under status.lifecycle,
created carries the user, API key or API user that requested the tenant. markedForDeletion carries the one
that requested the deletion, also when an API key requested it. deleted carries the one that approved the
deletion. A purge needs no approval, so there deleted carries the system author.
The tenant deletion details in meshPanel now also name an API key or API user that requested the deletion.
How to use
Read a tenant via the meshTenant API and inspect the author of status.lifecycle.created,
status.lifecycle.markedForDeletion and status.lifecycle.deleted. For older tenants, meshStack takes each
author from the tenant's event log where it still has one, and reports the system author otherwise.
See Who Created and Deleted a Workspace in the Admin Area
Audience: User
Description
The workspace list in the admin area now shows who created a workspace and who deleted it, next to the time of creation and deletion. You find these details when you hover over the status badge of a workspace.
For workspaces that existed before this release, we show the creator that the workspace event log recorded. Where the log recorded none, we show the system as the creator.
Building Blocks Now Respect the Supported Platforms of Their Definition
Audience: User
Description
A building block definition lists the platforms it supports, but the API ignored that list and let you add the building block to a tenant on any platform. We now reject those requests, and we apply the same check to the building blocks you put in a landing zone. The panel was not affected, because it already offered building blocks only on tenants whose platform the definition supports.
Bulk Upgrade of All Matching Building Blocks Works and Explains Skipped Ones
Audience: User
Description
When you select all building blocks in a list and choose Actions > Upgrade, we now upgrade every building block that matches your current filter again. Before, this upgraded none of them and the summary said "No Building Block matched your selection", even when the list showed outdated building blocks.
A bulk upgrade also no longer carries a stored input value onto the new version when that version's validation rejects it, for example after you tightened the regular expression of an input. Such a building block stays on its current version, and the upgrade summary lists it under "cannot be upgraded automatically" with the input and your validation message. Upgrade it on its own to enter a valid value.
Clearer Required or Optional Choice for Inputs
Audience: User
Description
The switch that makes a Building Block Definition input optional is now a clear "Required or Optional" choice. Before, it was easy to miss.
Readable Breadcrumb on the API Key Page of a Workspace
Audience: User
Description
When you create or edit an API key in a workspace, the breadcrumb now shows "Create API Key" or "Edit API Key". Before, it showed the raw placeholder ":link".
Manage Workspace User Groups Through the meshObject API
Audience: User
Description
You can now create, update and delete workspace user groups through the meshObject API. Before, the only way to create a workspace user group was the declarative meshObject import, which needs an API user. Now you can also use an API key that has the new admin permissions for workspace user groups. This includes admin groups, which you create as workspace user groups in your admin workspace.
A system that manages groups, for example a sync from your identity provider, can mark the groups it creates with a source system and later list only its own groups. The source system of a group is set when the group is created and cannot change afterwards. Global groups stay read-only in the API.
Destroyed Building Blocks Leave the Building Block List Right Away
Audience: User
Description
When you watched a building block being destroyed in the building block list, its row kept showing "destroy in progress" after the destroy had finished, and it only went away when you reloaded the page.
The list now removes the row as soon as the destroy has finished, without a reload, and also removes the building block from your selection, so a bulk action no longer counts it. This applies to the building block lists in the admin area and in the platform builder area, including the list of a single building block definition.
Repeating a Tenant Deletion Request No Longer Fails
Audience: User
Description
Deleting a tenant through the meshObject API is now idempotent. meshStack deletes a tenant asynchronously, so a
delete request you sent while an earlier one was still running used to fail with 400 Bad Request, which broke a
second terraform destroy. You now get the same 202 Accepted as the first time.
How to use
We also corrected the error codes on this endpoint. A delete request meshStack cannot carry out, for example because the tenant still has service instances on it or is still being created in the cloud platform, now answers with 409 Conflict and the reason. It previously reported 400 Bad Request for all of these cases.
Tidier Loading Spinners on the Building Block Overview
Audience: User
Description
The loading spinner in the 'Pending' badges on a building block's Overview tab now fits the badge text.
Hub Import Keeps JSON, Optional and Conditional Inputs
Audience: User
Description
When you import a building block definition from the meshStack Hub, we now fill in every input as the Hub module defines it. JSON inputs keep their type and JSON schema, optional inputs stay optional, and conditional inputs keep their condition. Before, you had to set these by hand after the import.
Operator Input Notice for App Teams
Audience: User
Description
When a Building Block waits for an input only the platform operator can provide, an app team no longer sees a call to action in the new Building Block experience. The header now states that the Building Block is waiting for the platform operator, and the link to fill in the input is shown to the platform operator only.
Smoother Scrolling Over Code Inputs
Audience: User
Description
Scrolling a long Building Block Definition form no longer stops when the mouse pointer crosses a code input, such as a default value, a static value, a JSON schema or the Terraform pre-run script. A code input takes the wheel only while it still has content to scroll, and hands it back to the page at its end.
JSON Inputs of a Building Block Definition No Longer Accept References
Audience: User
Description
A JSON input of a Building Block Definition now rejects a schema that contains a JSON Schema reference, in meshPanel and in the meshObject API alike. Until now a reference could point into the same schema. We dropped references so that every schema reads exactly as it is written, which keeps the checks on your schema and the form built from it in step.
How to use
Write each sub-schema where it is used instead of referring to it. The error message you get when you save the version names the reference to replace.
Latest Run Card No Longer Counts Up While a Run Waits
Audience: User
Description
On the Overview of a building block, the Latest Run card no longer shows a run duration that keeps counting up while the run waits for approval or for input. You see the duration again once the run continues, and a fixed duration once it has finished. The card now also tells you how long ago the latest run was created (for example "8m ago") in the workspace area as well, the same way the building block list of your platform team already does.
Choose Individual Platforms for a Building Block Definition
Audience: User
Description
You can now pick individual platforms in the Supported Platforms field of a building block definition, not only whole platform types, so you can offer a definition on one platform instead of on every platform of its type. The dropdown lists the platforms under their platform type, and you can search it by either name. Using a platform type still means every platform of that type, and you can mix both in one definition.
Pick From a List of Values in a Building Block Input
Audience: User
Description
A Building Block input whose JSON Schema offers a fixed list of values now shows a searchable multi-select. Every value you pick appears as a badge that you can remove with a single click. Until now you added one entry at a time and typed or chose each value in its own row.
How to use
Give a JSON input a schema with an array of enum values, and the form picks the multi-select by itself:
{ "type": "array", "items": { "enum": ["dev", "test", "prod"] } }
You no longer have to add "uniqueItems": true to get it. To allow the same value twice, set "uniqueItems": false, and the form keeps one row per entry.
Runner Workload Identity Subjects Are Now Templates
Audience: User
Description
A building block runner declares the subject of its workload identity tokens as a template with the placeholders {{ workspaceIdentifier }} and {{ buildingBlockDefinitionUuid }}. meshStack fills them in for every version of a building block definition and shows the result under Implementation and Workload Identity Setup, or as status.versions[].workloadIdentityFederation in the meshObject API, so you no longer assemble the subject yourself when you set up trust in a cloud provider.
How to use
A self-hosted runner sends its template as spec.workloadIdentityFederation.subjectTemplate. Subjects you already
registered are rewritten to the new placeholder syntax. A template without placeholders is allowed and gives every
definition on that runner the same identity. A runner that still sends spec.workloadIdentityFederation.subject or
the old