---
title: "Broader Model Access and Tighter Governance Controls in 2.38 - Coder Changelog"
description: "### What's new in 2.38"
image: "/_next/static/media/OpenGraph.f7fb2003.jpg"
---

![Changelog Masthead Background](https://coder.com/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fcde-masthead-bg.e195b191.jpg&w=2048&q=75&dpl=dpl_CeGt1kAouVVmPsYDse7mQQ2fz9n2)

[Back to changelog](https://coder.com/changelog)

v2.38October 6, 2026

# Broader Model Access and Tighter Governance Controls in 2.38

### What's new in 2.38

This release broadens which models and cloud providers teams can run through Coder, including OpenAI-compatible access over Bedrock and native Claude on AWS. It also gives admins stronger, more standardized ways to govern access, from IAM roles to OAuth 2.1.

### Coder Agents: New Models, Org-Wide Defaults, and Chat Management Improvements

This release adds new model support with org-level defaults, streams large file uploads straight to the workspace, and reworks chat filtering and search.

- **New models available with org-wide defaults**: GPT-6 Sol, GPT-6 Luna, GPT-6.1 Sol, Claude Opus 5.5, and Claude Sonnet 5.5 are [now supported](https://coder.com/docs/@main/ai-coder/agents/models), along with non-Anthropic models via AWS Bedrock Mantle. Admins can [set an org-wide default model](https://coder.com/docs/@main/ai-coder/agents/models#set-a-default-model) under AI > Coder Agents settings, so new chats use the org default instead of each user's last pick.
- **Large file uploads stream to the workspace**: Files outside the inline attachment allowlist (zips, datasets, tarballs, etc.) now stream directly to the workspace filesystem with no size cap, where the agent's tools can unzip, parse, and run tests on them. The model only sees a path reference, not the file bytes. This works from both existing chats and the new chat page, with the UI automatically routing attachment-compatible types inline and everything else to the workspace.
- **Chat management improvements**: [Filter chats](https://coder.com/docs/@main/ai-coder/agents/chat-search-syntax) by status, PR status (including "no PR"), and mark chats read or unread, with a reworked sidebar featuring a dropdown filter and section switcher. Use `/clear` to reset context mid-conversation, and share prompt links that prefill the composer from a URL for one-click runbooks or onboarding workflows.

### AI Gateway: Support for Claude Platform on AWS

Teams that buy Claude through AWS can now send Claude Code and other Anthropic tools through Coder to Anthropic's native API on AWS, with no extra signing proxy.

- **Set up in two fields**: Select "Claude Platform for AWS" on an Anthropic provider, then enter a region and workspace ID.
- **Authenticate without managing keys**: Requests use stored Claude Platform API keys, or fall back to the gateway's ambient AWS IAM credentials via SigV4 when no key is present.
- **Keep existing integrations unchanged**: Coder keeps its central governance, usage attribution and auditing, and developers keep standard Anthropic model IDs and the full Messages API.

Learn more in our [documentation](https://coder.com/docs/@main/ai-coder/ai-gateway/providers#claude-platform-for-aws).

![Add an Anthropic Provider in the Coder UI](https://coder.com/_next/image?url=https%3A%2F%2Fwww.datocms-assets.com%2F19109%2F1791121854-captured-sept-30-2026-from-cleanshot.jpeg%3Ffit%3Dclip%26fm%3Dwebp%26w%3D768&w=2048&q=75)
Add an Anthropic Provider in the Coder UI

### Embedded NATS Pubsub for High-Availability Deployments

Coder now carries real-time events between coderd replicas over embedded NATS by default, instead of Postgres LISTEN/NOTIFY, so HA deployments can absorb traffic bursts like a wave of agents reconnecting at once.

- **More headroom, no extra compute**: Each coderd replica runs an embedded NATS server and meshes with the others, with automatic mutual TLS for Enterprise. The API, CLI, and dashboard are unchanged.
- **Check port 6222 before upgrading (HA only)**: Allow TCP 6222 between all replicas in both directions. With custom relays, set `CODER_CLUSTER_HOST` or Coder falls back to Postgres pubsub.
- **Easy to opt out**: Enable `no_nats_pubsub` and restart coderd to return to Postgres pubsub. No data migration needed.

Learn more in our [documentation](https://coder.com/docs/@main/admin/networking/high-availability#setup).

### Authenticate to Bedrock with IAM roles

Coder now supports role-based AWS authentication for Bedrock, so teams can move off long-lived static credentials.

- **New `provider.Bedrock` with AWS SigV4 middleware**: Credentials resolve via static keys, the ambient credential chain, or AssumeRole, enabling IAM-role and IRSA-based auth for workspaces.
- **OpenAI-compatible model access**: Alongside Anthropic Messages, Coder now supports the OpenAI Chat Completions and Responses wire protocols over Bedrock's Mantle inference endpoint, extending access beyond Anthropic-only models.
- **No loss of governance**: Budgets, rate limits, BYOK policy, and full interception recording (prompts, tokens, tool calls) all continue to work exactly as they do today.

Learn more in our [documentation](https://coder.com/beta-docs/ai-coder/ai-gateway/providers).

### Secure workspace access with OAuth 2.1

- **Standards-based application access**: Coder now officially supports OAuth 2.1, letting users connect to Coder through systems like GitHub instead of relying on a shared secret.
- **Scoped app permissions**: Admins can restrict an OAuth app to specific scopes, for example, limiting a GitHub app to only the actions it needs.
- **Enable when you're ready**: OAuth 2.1 is available behind a feature flag, so teams can turn it on and configure it for their system.

[Check the integration docs](https://coder.com/docs/admin/integrations/oauth2-provider) for setup details and the testing steps teams should complete before upgrading.

### Coder VS Code Extension v1.16.4: More Reliable Connections, Less Guesswork

This release fixes a Windows SSH permissions bug that caused "Bad owner or permissions" errors, and makes workspace updates land on the correct template version (Coder 2.36+), prompting you if an update fails. It also auto-captures debug logs on connection failure, so there's no need to reproduce the issue with debug logging on. Learn more in our [documentation](https://coder.com/docs/user-guides/workspace-access/vscode) and view the VS Code changelog [here](https://github.com/coder/vscode-coder/releases/tag/v1.16.4).

### Envbox updates: ARM64 build fixes and CVE remediation

Envbox is Coder's tool for running Docker-in-Docker workspaces inside a single Kubernetes pod, without needing privileged host access. Here’s what’s new in v0.6.9:

- **Builds default to the host architecture**: The `Makefile` automatically detects and targets the host platform, preventing mixed-architecture images when building locally.
- **Sysbox `checksums` are matched automatically**: Envbox selects the correct Sysbox `checksum` for the target platform, eliminating checksum failures when building on ARM64 or cross-building for ARM64.
- **Remediated CVEs via dependency updates**: Bumped Go to 1.26.6 and updated Coder, gRPC, and DataDog tracing dependencies, helping teams clear vulnerability-scanning gates on their images.

View the [full envbox changelog here](https://github.com/coder/envbox/releases/tag/0.6.9), and the [commit comparison](https://github.com/coder/envbox/compare/0.6.7...0.6.9) from the last pre-release on GitHub.

### Breaking Changes

- **Tasks are fully deprecated and removed** in Coder v2.38. Users can stay on the [v2.34 Extended Support Release](https://coder.com/changelog/coder-2-34) during the support period.
- [#29548](https://github.com/coder/coder/pull/29548): The experimental chat API mounts have been removed. Please use the new /api/v2 routes, which are now the only supported path.
- [#28242](https://github.com/coder/coder/pull/28242): Deployments with MCP servers on internal networks must `allowlist` them with `--mcp-allowed-private-cidrs` after upgrading, or those connections will fail.
- [#29283](https://github.com/coder/coder/pull/29283): Embedded NATS is now the default pubsub between `coderd` replicas. Before upgrading HA deployments, allow TCP port 6222 between every pair of replicas, or enable the `no_nats_pubsub` experiment to stay on Postgres pubsub. The `nats_pubsub` experiment has been removed.

View the [full changelog](https://github.com/coder/coder/releases/tag/v2.38.0) on GitHub. If you have questions or feedback, join the conversation on [Discord](https://discord.gg/coder) or email us directly!
