# What's new in Scalr

Canonical: https://brew.new/browse/templates/email/pt1_k97wd5kkc09dr2hbaetees78t18fd2s2

Brand: scalr.com
Category: newsletter

![Preview of What's new in Scalr](https://cdn.brew.new/email-preview-049b139bd8366cc2-tracking_r57kj2ecbqgdqps8t9rdjrz8gh8fct8f-1790781711329.png)

## Email content

Scalr Product Update: September 2026

Scalr · Product Update · September 2026

Scalr

What is new in Scalr this September.

MCP governance controls, Terragrunt stacks, custom runner images, GHE data residency, and a redesigned workspace list among the highlights. Full release notes at updates.scalr.io.

AI and MCP

🛠️

MCP server tools availability policy

Admins can now see every tool the MCP server exposes, grouped by category, and enable or disable each one account-wide. Previously, enabling MCP gave all users the full tool set with no way to restrict it. Existing accounts migrate automatically with all tools on. Newly connected integrations start with no tools enabled until an admin turns them on. All policy changes are recorded in the audit log. Learn more

Infrastructure

🐳

Custom runner images (Beta)

Account admins can now register their own public container images for Scalr-managed runs alongside the built-in system images. Scalr syncs semantic version tags automatically, and you can set a version as the account default or override it per workspace. Contact Scalr support to enable this for your account. Learn more

🌍

GitHub Enterprise data residency support

Scalr now supports GitHub Enterprise Cloud data residency tenants. Set a custom URL such as https://subdomain.ghe.com when creating a GitHub provider and Scalr routes API calls, OAuth, webhooks, and PR checks to that tenant automatically. Existing connections are unaffected. Learn more

📜

Serverless agent pool webhook delivery history

Serverless agent pools now have a Webhook Deliveries tab showing the history of every attempt Scalr made to wake your agent, with status, run, workspace, triggered time, and a response snippet per delivery. Previously a failed delivery was invisible and a run would just sit waiting. Deliveries are retained for 7 days. A red indicator flags recent failures. Learn more

Security

🔒

Enforce anchored assume policy conditions

A new optional account-level security rule prevents assume policies for service accounts from relying solely on loose contains claim matching, which can grant access far more broadly than intended. Off by default, found under Security → Rules. Applies only to new or edited assume policies. Learn more

👥

SCIM enabled for all SAML providers

SCIM provisioning can now be enabled for any SAML identity provider, not just Okta and Azure AD. Automate user provisioning and removal from any SAML 2.0 compliant IdP. Enterprise plan only. Learn more

Terragrunt and OpenTofu

🗺️

Support for Terragrunt stacks

Scalr now supports Terragrunt's native terragrunt.stack.hcl stacks when unit sources live in the same repository. Automatic for Scalr-managed runners; self-hosted pools require agent 1.6.0. Terragrunt 0.80.0 or later is required. Learn more

📥

Support for tofu plan -generate-config-out

CLI-driven workspaces now support tofu plan -generate-config-out=FILENAME, letting OpenTofu write the resource configuration for you when importing existing infrastructure. Supported on dry runs only. Automatic for Scalr-managed runners; self-hosted pools require agent 1.7.0. Learn more

Read the full release notes

If you have questions about any of these features, open a ticket at support.scalr.com.

The Scalr Team

Docs

·

Changelog

·

Status

·

Unsubscribe

© 2026 Scalr, Inc. · Infrastructure Automation & Collaboration

Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97wd5kkc09dr2hbaetees78t18fd2s2)

[Browse email designs](https://brew.new/browse/templates)
