Newsletters




Kestra 2.0 Delivers One Governed Orchestration Layer Across Every Environment 


Kestra is adding new enterprise capabilities enabled by Kestra 2.0, addressing the security, governance, and control requirements of enterprise orchestration.

Released to the developer community earlier this month, Kestra 2.0 gives enterprises one governed orchestration layer across data, infrastructure, applications, and business processes, and removes the architectural constraint that has kept many regulated and security-conscious organizations from adopting one, according to the company.  

“Enterprises did not set out to run five orchestration tools. It happened one team at a time, and the result is that the work a business depends on most is the work it can see least,” said Emmanuel Darras, CEO and co-founder of Kestra. “Kestra 2.0 brings unified orchestration to the Fortune 500, where companies have the most domains to govern and the least freedom in where execution can happen, providing one place to run and govern every workflow.”

Unified orchestration brings four domains that have historically been run separately, on separate tools, under one governed layer:

  • Data. Ingestion, transformation, data lakes and warehouses, and machine learning pipelines.
  • Infrastructure. Enterprise job scheduling, cloud and container infrastructure, provisioning and configuration, CI/CD, and IT and security runbooks.
  • Applications. Microservice coordination, API workflows, event-driven processes, and SaaS integrations.
  • Business processes. Approvals, onboarding, order-to-cash, ticket and issue tracking, and integration with existing enterprise systems. 

Kestra 2.0 delivers four enterprise outcomes, including:

  • Execution wherever security requires it. Workers hold no database connection and no credentials, opening a single outbound connection to the controller. Deployments that were previously out of reach become straightforward: segmented network zones, other clouds, other regions, on-premises, and fully air-gapped environments. Governance no longer stops at the network boundary.
  • Controlled production access for AI agents. Any workflow can be exposed as a tool an external agent calls, with execution approval required before anything reaches production, action-based access control, and full audit logging. Agents are treated as authenticated users, so an agent retrieves only what the person behind it is authorized to see.
  • Predictable capacity on shared infrastructure. Teams sharing one deployment no longer compete for the same compute. Workloads are isolated and capacity can be reserved per team, so a heavy job in one domain does not starve a critical one in another.
  • Failure handling an enterprise can rely on. When something goes wrong, teams decide what happens rather than discovering it afterward. Work can be retried, redispatched, or failed deliberately, so operations that must never run twice fail loudly instead of silently duplicating.

Kestra 2.0's rebuilt engine is designed to scale more efficiently and flexibly as enterprise workloads grow.

Kestra 2.0 is backed by bug and security fixes through September 2027. It includes breaking changes and ships with migration tooling that rewrites most flows automatically and flags the few that need a human decision, said the vendor.  

Kestra 2.0 is generally available now. The open-source edition is available at kestra.io and on GitHub, and Kestra Enterprise is available directly from Kestra.

For more information about this news, visit https://kestra.io.


Sponsors