06-reference/research

spcs app runtime preview residue after ga

2026-09-29·research-brief·source: deep-research·by Ray Data Co (deep-research synthesis)
snowflakeapp-runtimespcspreview-vs-gasow-risk

The preview residue after App Runtime GA is real but tiny, and none of it sits on the build path — it sits on the governance path

The question

Verbatim: "Which Snowflake SPCS App Runtime capabilities remain in PREVIEW after the 2026-09-01 GA of the core runtime (the 2026-08-31 app.yml v2 release note is still flagged Preview) — and does depending on any of them re-introduce the account-wide SYSTEM$ENABLE_PREVIEW_ACCESS toggle that GA just removed?"

Context: [[2026-09-25-spcs-app-runtime-client-account-enablement-gate]] concluded that App Runtime is now promisable as a phase-2 Statement of Work (SOW) deliverable rather than carried as a risk. That conclusion holds only if the reference architecture avoids still-preview sub-features, because a single open-preview dependency would put the account-wide, all-or-nothing preview toggle back in the critical path.

Method note, stated because it bears on how much weight the inventory carries. Every status claim below comes from docs.snowflake.com or an official Snowflake release note, read 2026-09-29. Building a per-capability inventory required more primary pages than the standard three-WebFetch research cap allows, so the additional fetches were routed through two zero-context sub-agents that read raw HTML and ran regular-expression passes for admonition markup, rather than trusting a summarizer to preserve callout boxes. Fourteen distinct primary pages were read. No blog, Medium post, analyst note, or community thread was used for any status claim.

What we already know (from the vault)

What the web says

All citations below are docs.snowflake.com, read 2026-09-29.

The inventory

Status column: GA (asserted) means the 2026-09-01 GA release note names the capability explicitly. GA (inferred) means the docs page carries no preview badge but also never says "generally available" — Snowflake does not stamp GA pages, so this is inference from a missing badge and is the weaker of the two. Preview entries quote a verbatim badge.

Capability Status Primary source, read 2026-09-29 Re-arms SYSTEM$ENABLE_PREVIEW_ACCESS?
App Runtime core runtime GA (asserted) 2026-09-01 GA release note No
app.yml manifest v2, incl. version: 2 GA (asserted) 2026-09-01 GA note; app-yml reference, no badge No. The 2026-08-31 (Preview) title is stale; the body has no admonition and no flag instruction
Named deploy targets, --target, default_target GA (asserted) 2026-09-01 GA note; deploy-targets page No
Personal databases (database: USER$) GA (asserted) 2026-09-01 GA note; deploy-targets page No
Querying Snowflake as service or as signed-in user; execute_as_role GA (asserted) 2026-09-01 GA note No
Application Service SQL commands (CREATE / ALTER / DESCRIBE / DROP / SHOW, SYSTEM$GET_APPLICATION_SERVICE_LOGS) GA (asserted) 2026-09-01 GA note; commands-snowflake-apps index, no badge No
Artifact repository SQL commands (base form) GA (asserted) 2026-09-01 GA note; command index No
Sharing, privileges, account administrator setup GA (asserted) 2026-09-01 GA note; account-admin-setup page No
Remote build service, install / build / run, build_eai, build_job_location GA (inferred) app-yml reference, no per-field badge; limitations page documents build behaviour without a badge No, on current evidence
external_access_integrations field and egress via external access integrations GA (inferred) app-yml reference, no badge; limitations page No, on current evidence
Service endpoints and authenticated ingress (BIND SERVICE ENDPOINT) GA (inferred) security controls page (admonitions are operational, not preview) No, on current evidence
Scale and suspend (min_instances / max_instances, auto_suspend_secs, auto_resume) GA (inferred) app-yml reference, no badge No, on current evidence
Observability via the account event table GA (inferred) App Runtime observability page, no badge No, on current evidence
Feature policies, database-scoped (block APPLICATION_SERVICES / ARTIFACT_REPOSITORIES) GA (inferred) security controls page, no badge on the non-conditional form No, on current evidence
Feature policy rules, conditional (e.g. block Application Services only in a specific schema) Private Preview security controls page, verbatim: "which is in private preview" No — and that is worse, not better. The toggle cannot enable private preview at all; the documented path is a Snowflake Support request
Customer-hosted Python artifact repositories: INDEX_URL, AUTHENTICATION_SECRET, PACKAGE_RETENTION Open (public) Preview CREATE ARTIFACT REPOSITORY, verbatim: "which are in public preview" Yes, by the documented general rule — open preview is what the toggle gates. But no page connects these parameters to the toggle in one sentence; see the calibration note below
Python application support Not available (not preview) limitations page: "Support for Python is planned" Not applicable
Government regions, trial accounts Excluded limitations page; GA release note Not applicable

Convergences and contradictions

Synthesis for RDCO

The headline: the parent brief's recommendation survives, and it survives for a slightly different reason than expected. The fear was that App Runtime GA was a partial GA with preview sub-features scattered through the build path, so that any realistic reference architecture would trip one of them and re-arm the account-wide toggle. That is not what the documentation shows. The default path for a Node.js or Next.js application deployed from an app.yml v2 manifest, with named targets, a personal-database development target, external access integration egress, an authenticated service endpoint, autoscaling and event-table logging, is entirely GA-asserted or GA-by-absent-badge. The preview residue is two items, and neither is on that path. Depending on nothing outside that path means the toggle stays out of the architecture, and the enablement conversation with a client security team stays what [[2026-09-25-spcs-app-runtime-client-account-enablement-gate]] said it became: a role-based access control and region conversation, not a preview-terms conversation.

The non-obvious finding is where the preview residue actually sits: in the governance path, not the build path. The one private-preview item is conditional feature policy rules, which is the mechanism for blocking Application Services everywhere except a named schema. That is precisely the control a cautious client security reviewer is most likely to ask for during the enablement conversation, because it is the natural counter-offer to "grant the deploy role CREATE COMPUTE POOL at account level." Today the answer is that database-scoped feature policies exist and schema-scoped conditional rules do not, and the account-wide preview toggle cannot buy them, since private preview is only reachable through a Snowflake Support request. So the enablement checklist that the parent brief made the gating milestone needs one more line, and it is a line about what we cannot offer rather than what we need granted. Saying that before the client asks is strictly better than discovering it mid-review.

The second item is a real toggle trap, but it is easy to steer around and easy to walk into by accident. Customer-hosted Python artifact repositories, configured through INDEX_URL, AUTHENTICATION_SECRET and PACKAGE_RETENTION, are labelled public preview on an otherwise unbadged GA command page. Open preview is exactly what SYSTEM$ENABLE_PREVIEW_ACCESS gates, so reaching for those parameters would pull the all-or-nothing, all-users, preview-terms-accepting account toggle back into the path for the sake of a dependency-hosting convenience. The saving grace is that App Runtime does not support Python applications at all yet, so a Node.js deployment has no reason to touch them. The risk is not this quarter; the risk is the day Python support ships and someone wires up a private package index without checking the parameter's badge. Worth writing into the architecture note now, while the reason is fresh.

Calibration, because this is the kind of claim that gets quoted into an SOW. Two weaknesses are worth stating plainly rather than smoothing over. First, "GA (inferred)" is doing real work in the inventory above. Snowflake badges previews but does not badge GA, so for capabilities the GA release note did not enumerate by name — external access integration egress, autoscaling, observability, the build configuration fields — the evidence is an absent badge, not an affirmative statement. That is good enough to design on and thin for a contractual promise. The eight capabilities the GA note enumerates are the ones that can be quoted directly. Second, the assertion that a GA feature does not require the preview toggle is not documented anywhere; it follows from the GA note's "no longer in Preview" plus the toggle's own scope statement, which is a two-source inference rather than a single sentence. Both of those are honest limits on the answer, and neither changes the recommendation: App Runtime stays committable as a phase-2 deliverable with an enablement checklist as the gating milestone, and it does not revert to carried risk.

Why this is in the vault

This closes the single open follow-up that [[2026-09-25-spcs-app-runtime-client-account-enablement-gate]] left load-bearing: whether its phase-2 SOW recommendation depends on preview sub-features that would re-arm the account-wide toggle. It also supplies the concrete addition to the enablement checklist that brief made the gating milestone — schema-scoped conditional feature policy rules are private preview and cannot be offered — and flags the customer-hosted Python artifact repository parameters as a future toggle trap for whenever App Runtime Python support ships.

Open follow-ups

Related

Sources

Vault:

Primary sources, all docs.snowflake.com, all read 2026-09-29: