# env zero docs: Changelog

## Changelog

- [Changelog](https://docs.envzero.com/changelogs.md): Stay up to date with the latest features, improvements, and fixes in env zero. Updates are organized by release month and year.

### 2026

#### August 2026

- [Full SCIM Provisioning](https://docs.envzero.com/changelogs/2026/08/scim-full-provisioning.md): SCIM provisioning is generally available, adding provisioning modes, group push to env zero teams, token rotation, and a reconcile check for drift.
- [Search, reworked across env zero](https://docs.envzero.com/changelogs/2026/08/search-improvements.md): Project search ranks exact and prefix matches first, Cmd+K reports environment search errors, and list filters keep their URL state.
- [Tag Your Environments](https://docs.envzero.com/changelogs/2026/08/environment-tags.md): Attach key-value tags to environments, find them by tag in Explorer or the project list, and add or remove tags across many environments at once.

#### July 2026

- [V2 OIDC Tokens: Per-Cloud-Provider Audiences](https://docs.envzero.com/changelogs/2026/07/v2-oidc-tokens.md): OIDC credentials for AWS, Azure, GCP, and Vault can now use a provider-specific token audience instead of a single shared audience across all providers.
- [Say Hello to the New env zero CLI](https://docs.envzero.com/changelogs/2026/07/cli-for-ai-agents.md): A single binary replaces the old npm-based CLI, with project management commands, read-only sign-in, and built-in support for AI coding agents.
- [Download Your Plan as JSON](https://docs.envzero.com/changelogs/2026/07/download-plan-as-json.md): Download a deployment's plan as masked JSON from the step log's download menu, ready to feed into policy checks, diffing, or your own tooling.
- [env zero Free Plan](https://docs.envzero.com/changelogs/2026/07/free-plan.md): env zero now has a Free plan for evaluation and small-scale use, with 250 runs per month, 30 active environments, and community support.

#### May 2026

- [IP Allowlisting for Logins, API Keys, and the Agent API](https://docs.envzero.com/changelogs/2026/05/ip-allowlisting.md): Restrict access to your organization to a set of approved source IP addresses, covering UI logins, API keys, and the Agent API.
- [Saved Cloud Plans on the Remote Backend](https://docs.envzero.com/changelogs/2026/05/saved-cloud-plans-remote-backend.md): Save, inspect, and apply plan files end to end against the env zero remote backend with tofu plan -out, tofu show, and tofu apply.

#### April 2026

- [Centralized VCS Connections for All Providers](https://docs.envzero.com/changelogs/2026/04/vcs-connections-alignment.md): GitLab, Azure DevOps, and Bitbucket cloud VCS connections can now be managed centrally in Organization Settings alongside GitHub and self-hosted providers.

#### March 2026

- [Self-Service Agent: Create and Manage Agent Pools Without Contacting Support](https://docs.envzero.com/changelogs/2026/03/self-service-agent.md): Manage self-hosted agent pools in env zero from Organization Settings, generate authentication secrets, and assign agent pools to projects on your own schedule.
- [Simplify Terraform Cloud Migration With the env zero Migration Wizard](https://docs.envzero.com/changelogs/2026/03/tfc-migration-wizard.md): Migrate TFC or TFE workspaces to env zero using a guided wizard that discovers workspaces, transfers variables and state, and handles a controlled cutover.

#### February 2026

- [SCIM Provisioning: Automate User Lifecycle Management](https://docs.envzero.com/changelogs/2026/02/scim-provisioning.md): Use SCIM 2.0 with Okta or Microsoft Entra ID to auto-provision and deprovision env zero users, keeping access in sync with your identity provider continuously.

#### January 2026

- [Self-Service SSO: Speed Up Authentication and Stay in Control](https://docs.envzero.com/changelogs/2026/01/self-service-sso.md): Configure Azure AD or SAML 2.0 SSO in env zero from Organization Settings, manage domain mappings and role assignments on your schedule without support tickets.
- [Projects Page Refresh: Clearer Overview, Tags, and Improved UI](https://docs.envzero.com/changelogs/2026/01/projects-page-refresh.md): The refreshed Projects page in env zero shows richer metadata, environment status, sub-project hierarchy, and tag-based filtering to manage projects at scale.

### 2025

#### November 2025

- [Now Available (Beta): Code Optimizer Helps You Improve Infrastructure Code Quality and Safety](https://docs.envzero.com/changelogs/2025/11/code-optimizer-beta.md): Code Optimizer scans IaC in env zero using Checkov and TFLint, flags issues with environment context, and generates pull requests with suggested fixes.

#### September 2025

- [Introducing Ready-To-Use Policies](https://docs.envzero.com/changelogs/2025/09/ready-to-use-policies-change-log.md): Apply pre-built security, compliance, and cost policies in env zero at the organization, project, or environment level from a catalog without writing any code.
- [env zero MCP Server: Fast and Safe Infrastructure Actions from IDEs and Agents](https://docs.envzero.com/changelogs/2025/09/env-zero-mcp-server-change-log.md): Use the env zero MCP Server to plan, approve, and deploy infrastructure from your IDE or AI agent, with all env zero governance policies enforced on every run.

#### June 2025

- [Cloud Compass Adds Support for GCP](https://docs.envzero.com/changelogs/2025/06/cloud-compass-adds-support-for-gcp.md): Cloud Compass now supports GCP, completing multi-cloud coverage across AWS, Azure, and Google Cloud for IaC gap analysis, risk assessment, and resource import.
- [Polish & Improvements: June 2025](https://docs.envzero.com/changelogs/2025/06/polish-improvements-june-2025.md): June 2025: workflow output variables, audit log forwarding, self-hosted agent plugin caching, project-level credentials, dry run support, and VCS user mappings.

#### May 2025

- [New in Drift Remediation: Automated Code Updates to Keep IaC in Sync](https://docs.envzero.com/changelogs/2025/05/new-in-drift-remediation-automated-code-updates-to-keep-iac-in-sync.md): env zero can generate a pull request to update IaC to match detected cloud changes, adding code-to-cloud alongside the existing cloud-to-code remediation.

#### April 2025

- [Whats New: AI-Powered Summarization and Error Insights (Beta)](https://docs.envzero.com/changelogs/2025/04/whats-new-ai-powered-summarization-and-error-insights-beta.md): Use AI in env zero to get plain-language error explanations and plan summaries during deployments, with sensitive data redacted and no model training on data.
- [Drift Cause Analysis: Understand Why Drift Happened](https://docs.envzero.com/changelogs/2025/04/drift-cause-analysis-understand-why-drift-happened.md): Drift Cause Analysis uses AI in env zero to explain why resources drifted, tracing manual changes, unapplied commits, variable updates, and version mismatches.

#### March 2025

- [Introducing env zero Cloud Analyst: AI-Powered Infrastructure Intelligence](https://docs.envzero.com/changelogs/2025/03/introducing-env0-cloud-analyst-for-ai-powered-infrastructure-intelligence.md): Cloud Analyst in env zero answers plain-language questions about deployments, drift, and IaC usage, returning structured data and supporting custom dashboards.
- [Polish & Improvements: January-February 2025](https://docs.envzero.com/changelogs/2025/03/polish-improvements-january-2025.md): Jan-Feb 2025: dark mode, redesigned homepage, Oracle Cloud credentials, Cloud Compass all-accounts view, multi-org GitHub Enterprise, Dynatrace log forwarding.

#### February 2025

- [Drift Remediation Keep Your Infrastructure Aligned with Your Code](https://docs.envzero.com/changelogs/2025/02/drift-remediation.md): Reconcile infrastructure drift in env zero automatically or manually, reapplying IaC at the project or environment level while respecting all approval policies.
- [New: Spot Drift in Minutes With Cloud Compass - Even Before Fully Onboarding](https://docs.envzero.com/changelogs/2025/02/cloud-compass-drilldown.md): Cloud Compass detects drift and drift risk for all cloud resources, including unmanaged ones, with event-level details on what changed, who made it, and when.

#### January 2025

- [New Backstage Plugin: Manage and Deploy IaC from Your Internal Developer Portal](https://docs.envzero.com/changelogs/2025/01/backstage-integration.md): Use the env zero Backstage Plugin to create, deploy, and monitor cloud environments from Backstage, with deployment history, live logs, and redeploy support.

### 2024

#### December 2024

- [Introducing Drift Cause: Adding Context to Drift Management](https://docs.envzero.com/changelogs/2024/12/introducing-drift-cause-adding-context-to-drift-management.md): Drift Cause in env zero identifies who caused drift, how it was triggered, and when it occurred by correlating IaC state with out-of-band cloud audit logs.
- [Polish & Improvements - December 2024](https://docs.envzero.com/changelogs/2024/12/polish-improvements-december-2024.md): December 2024: multiple VCS agents, GitLab access token auth, Terragrunt cost estimation, Vault certificate auth, and deployment filtering by user and status.

#### November 2024

- [Cloud Compass Adds Support for Microsoft Azure](https://docs.envzero.com/changelogs/2024/11/cloud-compass-supports-for-microsoft-azure.md): Cloud Compass now supports Microsoft Azure for IaC coverage tracking, risk assessment, and GenAI-assisted resource import alongside AWS support in env zero.
- [Custom Flows For Tasks](https://docs.envzero.com/changelogs/2024/11/custom-flows-for-tasks.md): With this update, you can now configure custom hooks for your tasks, allowing you to define specific setups and teardowns for all ad-hoc tasks.

#### September 2024

- [Introducing Hybrid Agents and Secured Variables for Self-Hosted Agents](https://docs.envzero.com/changelogs/2024/09/mix-agents-and-variables.md): Mix SaaS and self-hosted agents within the same env zero organization, and share encrypted SaaS-stored variables securely with self-hosted agent deployments.
- [Streamline Onboarding With Automated Environment Import](https://docs.envzero.com/changelogs/2024/09/onboarding-import-external-environments.md): Import Terraform workspaces into env zero in bulk via Environment Discovery, scanning Git repositories and placing environments into projects automatically.

#### August 2024

- [Ansible Support](https://docs.envzero.com/changelogs/2024/08/ansible-support.md): Run Ansible playbooks as env zero environments with native approval flows, PR plan triggers, drift detection, TTL policies, and scheduling alongside IaC tools.

#### July 2024

- [Cloud Compass](https://docs.envzero.com/changelogs/2024/07/cloud-compass.md): Cloud Compass in env zero visualizes IaC coverage trends, resource management distribution, and per-resource severity scores to identify unmanaged resources.
- [GitOps Apply All](https://docs.envzero.com/changelogs/2024/07/gitops-apply-all.md): Apply all environments affected by a pull request in env zero using env0 apply --all, with individual and aggregate commit status checks reported to your VCS.
- [Move Environments between Projects](https://docs.envzero.com/changelogs/2024/07/move-environments-between-projects.md): Move environments between projects in env zero from the environment menu, then redeploy to apply the target project's credentials and variable configuration.

#### June 2024

- [Approval Flow for Workflows](https://docs.envzero.com/changelogs/2024/06/approval-flow-for-workflows.md): Gate workflow progression in env zero by requiring approval on sub-environments via the requiresApproval YAML field, UI checkboxes, or OPA approval policies.

#### May 2024

- [Docker image Alpine and Node upgrade](https://docs.envzero.com/changelogs/2024/05/docker-image-alpine-and-node-upgrade.md): env zero deployment container updated: Alpine upgraded to 3.19, Node to 20.12.2, and pip to 24.0, improving performance and security for tasks and custom flows.
- [Variable Sets](https://docs.envzero.com/changelogs/2024/05/variable-sets.md): Create reusable Variable Sets in env zero and assign them to organizations, projects, templates, or environments to eliminate duplicated variable configuration.
- [Variables Improvements](https://docs.envzero.com/changelogs/2024/05/variables-improvements.md): Scope-based filtering, priority sorting for required variables, and collapsible grouping for sensitive variables in the env zero Variables Table.
- [Webhook Notification Target](https://docs.envzero.com/changelogs/2024/05/webhook-notifications.md): Set up webhook notification targets in env zero to send HTTP callbacks on deployment events, enabling automated responses in external systems and CI pipelines.

#### April 2024

- [Approval Policies and Custom Flows Enhancements](https://docs.envzero.com/changelogs/2024/04/approval-policies-and-custom-flows-enhancements.md): Assign multiple approval policies and custom flows per env zero project, with template-level enforcement and combined project and environment-level execution.
- [Environment Outputs](https://docs.envzero.com/changelogs/2024/04/environment-outputs.md): Export Terraform, OpenTofu, or Terragrunt outputs and pass them as inputs to other environments in the same env zero project, linking data across deployments.
- [Global Environment Search](https://docs.envzero.com/changelogs/2024/04/global-environment-search.md): Search all environments across your organization in env zero using the top navigation search icon or CMD+K, with results scoped to your accessible environments.
- [Navigation Improvement](https://docs.envzero.com/changelogs/2024/04/navigation-improvement.md): Refreshed env zero navigation bar with a modern design, separated org and project settings, a nested sub-project tree, and enhanced cross-project search.

#### March 2024

- [Create Environment Without Deploy](https://docs.envzero.com/changelogs/2024/03/create-environment-without-deploy.md): Use the preventAutoDeploy flag in env zero's Create Environment API or Terraform Provider to create environments without triggering an immediate deployment run.
- [Organization Role Assignments for Teams](https://docs.envzero.com/changelogs/2024/03/organization-role-assignments-for-teams.md): Assign custom roles to teams at the organization level in env zero, adding org-wide access control alongside existing project and environment-level assignments.
- [VCS environments in workflows](https://docs.envzero.com/changelogs/2024/03/vcs-environments-in-workflows.md): Define workflow sub-environments inline using the vcs field in workflow YAML, specifying repository, path, and IaC type without pre-creating env zero templates.

#### February 2024

- [Email Notifications](https://docs.envzero.com/changelogs/2024/02/email-notifications.md): Configure custom email recipients and event triggers per project in env zero, sending notifications for failed deployments, budget alerts, and completions.
- [Environment Discovery](https://docs.envzero.com/changelogs/2024/02/environment-discovery.md): Automatically create, plan, deploy and destroy Environments in env zero by creating pull requests within a preconfigured directory structure
- [BREAKING CHANGE - Separate environment "Drift Status" from the Deployment status](https://docs.envzero.com/changelogs/2024/02/separate-environment-drift-status-from-the-general-status.md): Breaking change: drift status moves to a separate driftStats field in env zero. The DRIFTED deployment status is deprecated starting February 29, 2024.

#### January 2024

- [New: Modules Continuous Integration Testing](https://docs.envzero.com/changelogs/2024/01/new-modules-continuous-integration-testing.md): Run automated tests against Terraform modules in the env zero Private Module Registry using OpenTofu test files, triggered on merges and pull requests.
- [Introducing: Targeted Deployments](https://docs.envzero.com/changelogs/2024/01/targeted-deployments.md): Deploy specific Terraform resources or modules in env zero using Targeted Deployments, scoping a run to only the resources that need updating via UI or API.
- [Partial Workflow Deployment](https://docs.envzero.com/changelogs/2024/01/workflow-sub-graph-deployment.md): Run or destroy a subset of a workflow in env zero with Partial Workflow Deployment, choosing to start from a specific node or redeploy a single sub-environment.

### 2023

#### December 2023

- [Remote Apply](https://docs.envzero.com/changelogs/2023/12/remote-apply.md): Run terraform apply locally with uncommitted code while execution happens inside env zero, keeping organization policies, governance, and audit logging active.

#### November 2023

- [Breaking Change to Parent and Sub Projects Variables Behaviour](https://docs.envzero.com/changelogs/2023/11/change-to-project-variables-behaviour.md): Breaking change in env zero: project variables cascade to sub-projects, enabling unified management and consistent configuration across the project hierarchy.
- [Easy OIDC Authentication Integration](https://docs.envzero.com/changelogs/2023/11/easy-oidc-authentication-integration.md): Configure OIDC credentials in env zero without storing sensitive data, then assign them to projects to generate short-lived tokens automatically per deployment.
- [BREAKING CHANGE - incoming traffic from env0 extended IP list](https://docs.envzero.com/changelogs/2023/11/improved-resiliency.md): env zero expanded its infrastructure across additional AWS regions and AZs. Update your IP allowlists to include the new addresses by December 4, 2023.
- [Self Hosted Remote State](https://docs.envzero.com/changelogs/2023/11/self-hosted-remote-state.md): Store Terraform remote state in your own cloud bucket using env zero's self-hosted remote state, keeping state data within your account and chosen region.
- [Usage Dashboard](https://docs.envzero.com/changelogs/2023/11/usage-dashboard.md): Track users, monthly deployments, and deployment limits in the env zero Usage Dashboard, available under Organization Settings > Billing.

#### October 2023

- [Immediate Persistence of Variables Regardless of Deployment Outcome](https://docs.envzero.com/changelogs/2023/10/immediate-persistence-of-variables-regardless-of-deployment-outcome.md): env zero now saves environment variables at deployment time rather than only on success, so variable changes are retained even when a deployment fails.
- [Official OpenTofu Support](https://docs.envzero.com/changelogs/2023/10/official-opentofu-support.md): OpenTofu, the Linux Foundation-managed Terraform fork, is now a natively supported IaC framework in env zero and is backward compatible with Terraform.

#### September 2023

- [Budget Notifications](https://docs.envzero.com/changelogs/2023/09/budget-notifications.md): Set project-level spending budgets in env zero and receive alerts when cloud costs cross weekly, monthly, or yearly thresholds via notification channels.
- [VS-Code Extension](https://docs.envzero.com/changelogs/2023/09/vs-code-extension.md): Deploy and monitor env zero environments from VS Code, viewing environments by git branch, triggering deployments, approving changes, and tailing live logs.

#### August 2023

- [Native Kubernetes Authentication](https://docs.envzero.com/changelogs/2023/08/better-kubernetes-support.md): Set up Kubernetes authentication natively in env zero using kubeconfig, AWS EKS, Azure AKS, or GCP GKE credentials with per-project cluster access control.
- [Docker Deployment Agent](https://docs.envzero.com/changelogs/2023/08/docker-deployment-agent.md): Run env zero self-hosted agents as Docker containers by pulling the Docker image and starting it, without needing a Kubernetes cluster or persistent storage.
- [Organization Costs](https://docs.envzero.com/changelogs/2023/08/organization-costs.md): View cloud costs across all projects from the Organization Dashboard Cost tab in env zero, giving a complete picture of multi-project spending over time.

#### July 2023

- [Approval Policies](https://docs.envzero.com/changelogs/2023/07/approval-policies.md): Apply OPA-based approval policies in env zero to cancel, pause for review, or approve deployments based on plan output, enforcing infrastructure guardrails.
- [env zero-Hosted Encrypted State](https://docs.envzero.com/changelogs/2023/07/env0-hosted-encrypted-state.md): Use env zero-hosted encrypted state as a PVC alternative for self-hosted agents, encrypting the working directory with a customer-provided key in env zero.
- [Plan and Apply from PR comments support for Azure DevOps](https://docs.envzero.com/changelogs/2023/07/plan-and-apply-from-pr-comments-support-for-azure-devops.md): Trigger env zero plan and apply operations for Azure DevOps pull requests using PR comments, without logging into the env zero platform directly.
- [Self Hosted Agents Monitoring](https://docs.envzero.com/changelogs/2023/07/self-hosted-agents-monitoring.md): View the current state of all self-hosted agents from the Organization Settings Agents page in env zero, with a full overview of each agent's status.
- [Update Environment Variables without Deploying](https://docs.envzero.com/changelogs/2023/07/update-environment-variables-without-deploying.md): Save changes to environment variables in env zero without triggering a deployment, so updates are staged and applied on the next redeploy.

#### June 2023

- [AWS Session Tags for OIDC](https://docs.envzero.com/changelogs/2023/06/aws-session-tags-for-oidc.md): env zero OIDC tokens now include AWS session tags via principal_tags claims, enabling IAM trust policies to enforce per-deployment access rules in AWS.
- [Helm Support](https://docs.envzero.com/changelogs/2023/06/helm-support.md): Deploy Helm charts as env zero environments with native approval flows, PR plan triggers, drift detection, TTL policies, and scheduling alongside IaC tools.
- [2 PR Plan and Remote Backend for Workflow](https://docs.envzero.com/changelogs/2023/06/pr-plan-and-remote-backend-for-workflow.md): Enable remote backend storage for all sub-environments in a workflow and trigger PR plan executions across deployed workflow environments from a pull request.

#### May 2023

- [Bulk Operations](https://docs.envzero.com/changelogs/2023/05/bulk-operations.md): Deploy, destroy, lock, or run tasks on multiple env zero environments at once, selecting environments within a project or across projects from the dashboard.
- [Environment RBAC Granularity](https://docs.envzero.com/changelogs/2023/05/environment-role-based-access-granularity.md): Assign custom roles at the environment level in env zero, granting users or teams access to one environment without raising permissions across the project.
- [Moving Projects and Sub Projects](https://docs.envzero.com/changelogs/2023/05/moving-projects-and-sub-projects.md): Move projects and sub-projects to different parent projects in env zero to reorganize your hierarchy without losing associated environments or configurations.
- [Project-Level Remote Backend Enforcement](https://docs.envzero.com/changelogs/2023/05/project-level-remote-backend-enforcement.md): Enforce the env zero Remote Backend for all new Terraform environments in a project using the Force Remote Backend policy in project settings.

#### April 2023

- [Private Plugins](https://docs.envzero.com/changelogs/2023/04/private-plugins.md): Store env zero plugins in private Git repositories to integrate internal tooling, reuse org-specific code in custom flows, and keep proprietary logic private.
- [Private Provider Registry](https://docs.envzero.com/changelogs/2023/04/private-provider-registry.md): Manage proprietary Terraform providers in env zero's Private Provider Registry, keeping custom provider binaries secure and accessible across your organization.

#### March 2023

- [PR Comments With Role Based Access](https://docs.envzero.com/changelogs/2023/03/pr-comments-plan-and-apply-role-based-access.md): Map VCS users to env zero custom roles so PR comment-triggered plan and apply enforce env zero RBAC, not just VCS repository commenter permissions.
- [Remote State Access Control](https://docs.envzero.com/changelogs/2023/03/remote-state-access-control.md): Restrict access to Terraform remote state in env zero by specifying which projects and sub-projects are authorized to read that environment's state data.

#### February 2023

- [Custom TTL Policy](https://docs.envzero.com/changelogs/2023/02/custom-ttl-policy.md): Set any TTL duration in months, weeks, days, or hours for env zero environments at the org or project level to prevent resources running indefinitely.
- [New Integrations - Plugins and Sumo Logic](https://docs.envzero.com/changelogs/2023/02/new-integrations-plugins-and-sumo-logic.md): New env zero plugins include TFLint, TFSec, Trivy, and Lightlytics, plus a new Sumo Logic log forwarding integration configurable from Organization Settings.
- [Sub Projects](https://docs.envzero.com/changelogs/2023/02/sub-projects.md): Nest projects within projects in env zero using Sub Projects, with RBAC permissions cascading from parent to all child sub-projects in the hierarchy.

#### January 2023

- [Deployment Comments](https://docs.envzero.com/changelogs/2023/01/deployment-comments.md): Add markdown comments to deployments, environment creation, destruction, and tasks in env zero to record context and improve team communication around changes.
- [Environment Locking](https://docs.envzero.com/changelogs/2023/01/environment-locking.md): Lock environments in env zero to block deployments and changes, with a visible banner showing which admin locked it, when, and the reason provided.
- [Remote Plans](https://docs.envzero.com/changelogs/2023/01/remote-plans.md): Run terraform plan locally with uncommitted code while executing inside env zero, enforcing your organization's governance policies and audit requirements.
- [Workflow Enhancement](https://docs.envzero.com/changelogs/2023/01/workflow-settings-enhancement.md): Configure per-environment variables, revisions, and workspace names when creating or deploying env zero Workflows, customizing each sub-environment separately.

### 2022

#### December 2022

- [Azure DevOps Integration](https://docs.envzero.com/changelogs/2022/12/azure-devops-integration.md): Connect Azure DevOps repositories to env zero to create templates, manage private modules, and enable continuous deployment from your Azure DevOps projects.
- [Log Forwarding to Google Cloud Logging](https://docs.envzero.com/changelogs/2022/12/log-forwarding-to-google-cloud-logging.md): Forward IaC deployment logs from env zero to Google Cloud Logging, centralizing infrastructure data alongside other GCP observability and monitoring sources.
- [Private Module Registry - Folder Based Modules](https://docs.envzero.com/changelogs/2022/12/module-registry-modules-from-path.md): Store multiple Terraform modules in a single repository using the env zero Private Module Registry's folder-based module support, reducing repository sprawl.
- [Plugins](https://docs.envzero.com/changelogs/2022/12/plugins.md): Add security scanners, policy enforcement, and notification integrations to IaC deployments using env zero Plugins defined in your env0.yaml configuration file.
- [Project Level Custom Flow](https://docs.envzero.com/changelogs/2022/12/project-level-custom-flow.md): Apply one shared custom flow YAML to all project environments in env zero, sourced from a separate repository to separate IaC code from deployment policies.

#### November 2022

- [Audit Log](https://docs.envzero.com/changelogs/2022/11/audit-log.md): Track organization activity in env zero audit logs, showing who performed each action, when it occurred, and detailed metadata, accessible via the UI or API.
- [Personal API Keys](https://docs.envzero.com/changelogs/2022/11/personal-api-keys.md): Generate personal API keys tied to your user account in env zero for the Terraform Provider, REST API, or Remote Backend, inheriting your RBAC permissions.
- [Project Costs](https://docs.envzero.com/changelogs/2022/11/project-costs.md): View aggregated cloud costs for entire projects in env zero, with cost graphs providing organization-level spending visibility beyond per-environment estimates.

#### October 2022

- [Business Tier now available in AWS Marketplace](https://docs.envzero.com/changelogs/2022/10/business-tier-now-available-in-aws-marketplace.md): Subscribe to env zero directly through AWS Marketplace, consolidating billing and procurement for all env zero subscription tiers within your AWS account.
- [Custom Roles](https://docs.envzero.com/changelogs/2022/10/custom-roles.md): Define custom RBAC roles in env zero with fine-grained permission sets, assignable to individual users or teams at the organization or project level.
- [env zero - The Game](https://docs.envzero.com/changelogs/2022/10/env0-game.md): An easter egg from env zero's hackathon: double-click an active deployment status to launch a browser game while you wait for the deployment to complete.
- [Mobile support](https://docs.envzero.com/changelogs/2022/10/env0-mobile-support.md): Manage env zero environments from mobile browsers at any resolution, with a streamlined view showing key environment status and cloud insights on the go.
- [OIDC Additional Claims](https://docs.envzero.com/changelogs/2022/10/oidc-additional-claims.md): env zero OIDC tokens now include projectId, templateId, environmentId, and deployerEmail claims for fine-grained authorization in AWS IAM and other systems.
- [Remote Backend](https://docs.envzero.com/changelogs/2022/10/remote-backend.md): Store Terraform state in env zero's Remote Backend with automatic configuration, state locking, version history, and support for authenticated local runs.
- [SAML Admin Group Integration](https://docs.envzero.com/changelogs/2022/10/saml-admin-group-integration.md): Map SAML IdP groups to org-admin roles in env zero using a naming convention, automatically granting admin permissions to all users within matching IdP groups.

#### September 2022

- [Removing Python 2, and other 3rd party updates.](https://docs.envzero.com/changelogs/2022/09/removing-python-2-and-other-3rd-party-updates.md): Breaking changes in the env zero deployment container: Python 2 removed, Alpine updated to 3.16, and Node, AWS CLI, and Azure CLI versions upgraded.

#### August 2022

- [Logs forwarding to Coralogix](https://docs.envzero.com/changelogs/2022/08/log-forwarding-to-coralogix.md): Forward IaC deployment logs from env zero to Coralogix for centralized monitoring, metrics, traces, and analytics alongside your other observability data.
- [OpenID Connect (OIDC) Support](https://docs.envzero.com/changelogs/2022/08/oidc-support.md): Authenticate to cloud providers using short-lived OIDC JWT tokens generated per deployment in env zero, removing the need to store long-lived credentials.

#### July 2022

- [CloudFormation Support](https://docs.envzero.com/changelogs/2022/07/cloudformation-support.md): Manage AWS CloudFormation stacks in env zero with continuous deployment, RBAC policies, custom flows, and workflow orchestration alongside other IaC tools.
- [Terragrunt run-all support](https://docs.envzero.com/changelogs/2022/07/terragrunt-run-all-support.md): Run multiple Terragrunt modules in one deployment with run-all in env zero, enabling CI/CD, drift detection, and cost estimation across all modules at once.
- [HashiCorp Vault Support For Self-Hosted Agent](https://docs.envzero.com/changelogs/2022/07/vault-hashicorp-vault-support.md): Resolve HashiCorp Vault secrets automatically on each deployment using the env zero self-hosted agent, keeping credentials within your private network.

#### June 2022

- [Cost Monitoring for Terragrunt](https://docs.envzero.com/changelogs/2022/06/cost-monitoring-for-terragrunt.md): Track actual cloud costs for Terragrunt environments in env zero, correlating weekly spending with deployments using Terratag-powered cost monitoring.
- [env zero Workflows](https://docs.envzero.com/changelogs/2022/06/env0-workflows.md): Orchestrate multi-environment deployments with dependency ordering using env zero Workflows, defined in a YAML file and visualized as a deployment graph.
- [Managing Pulumi Version](https://docs.envzero.com/changelogs/2022/06/managing-pulumi-version.md): Pin Pulumi templates to a specific CLI version in env zero using the ENV0_PULUMI_VERSION variable or the template wizard, avoiding unexpected version upgrades.
- [TTL Policy Per Project](https://docs.envzero.com/changelogs/2022/06/ttl-policy-per-project.md): Override organization-level TTL policies at the project level in env zero, giving project admins control over environment time-to-live defaults and maximums.

#### May 2022

- [Non Admin API Keys](https://docs.envzero.com/changelogs/2022/05/non-admin-api-keys.md): Create user-scoped API keys with project-level RBAC in env zero, giving team members API access without granting full organization admin permissions.
