WarehousePG Enterprise Manager 1.4 release notes

The WarehousePG Enterprise Manager (WEM) 1.4.x documentation describes the latest patch release. Release notes for all 1.4.x versions are included below.

VersionRelease date
1.4.021 Sept 2026

WEM 1.4.0

Released: 21 Sept 2026

WEM 1.4.0 includes new features, enhancements, and bug fixes.

Highlights

  • ClickHouse for metrics and logs: WEM now stores and queries all metrics and logs in ClickHouse instead of Prometheus and Loki. See Architecture.
  • Cluster Management: Start, stop, restart, and recover a segment directly from WEM. See Verifying and managing cluster health.
  • Advanced backup functionality: Take and restore backups directly from WEM, list your backups, and schedule recurring backup and restore jobs. See Securing backups.
  • Safeguard for disaster recovery: Monitor disaster recovery readiness at a glance, and manage backups, restores, and promotion between your primary cluster and a DR standby, through whpg-dr integration. See Managing disaster recovery.
  • Granular access control: WEM's role-based access control (RBAC) model now extends to individual actions. Admins can grant permissions for actions such as running or deleting a backup, in addition to the existing tab-level permissions. See Performing administrative management.
  • PXF in its own tab: PXF management moves out of External Tables and into a dedicated tab in Data Analysis. See Analyzing data distribution.
  • Host agents on every cluster host: The host agent now runs on every WarehousePG host, not only the coordinator. Each agent registers itself with WEM on first connection and authenticates every subsequent connection with mutual TLS (mTLS). The host agent is upgraded to version 1.1.0, required for WEM 1.4. See Installing the host agent.

New features

  • ClickHouse-backed Logs panel: The Logs panel now reads from ClickHouse instead of Loki, with the same structured search and filtering. See Auditing system logs.
  • ClickHouse-backed Alerts panel: The Alerts panel now evaluates metric thresholds against ClickHouse instead of Prometheus. See Managing alerts.
  • Cluster Management actions: A new Cluster Management panel lets Admins start, stop, and restart the WarehousePG cluster, and recover a failed segment. Commands are dispatched through the host agent. See Verifying and managing cluster health.
  • Taking, restoring, and scheduling backups directly from WEM: The Backups panel can now take and restore backups directly. It also supports recurring backup and restore schedules. Backup timestamps now show in the host agent's own operating system time zone instead of the WEM server's. See Securing backups.
  • Safeguard disaster recovery panel: A new Safeguard panel checks DR readiness through WAL archiving status, backup age, and restore point age, and rolls them into a single readiness status. Add a storage repository and a DR standby cluster, take and verify backups, then run a restore for DR testing or promote the standby to a live, writable primary, all through whpg-dr integration. See Managing disaster recovery.
  • Mutual TLS host agent authentication: Each host agent now presents a short-lived certificate issued by WEM's internal certificate authority, renewed automatically before it expires. A 24-hour grace window lets an agent that was briefly offline recover its certificate without Admin intervention. See Installing the host agent.
  • Host agent self-registration and approval: Host agents register themselves with WEM on startup. A new Host Agents admin tab shows each agent's registration status, certificate expiry, and last heartbeat, with one-click approve or revoke actions. See Installing the host agent.
  • PXF as a dedicated Data Analysis tab: PXF management moves from External Tables into its own PXF tab under Data Analysis. See Analyzing data distribution.
  • Granular access control grants: WEM's role-based access control (RBAC) now works at the action level as well as the tab level. Admins can grant or deny individual actions, such as running a backup, deleting a backup, or terminating a session, to a specific role. See Performing administrative management.
  • Unified Query Editor output panel: Query results, EXPLAIN, and ANALYZE output now appear together in a single tabbed panel in the Query Editor. The database selector also supports searching and filtering. See Authoring and tuning SQL statements.
  • Dedicated WEM database role: WEM now connects to your WarehousePG cluster with a dedicated wem login role, created automatically during setup, instead of reusing the same superuser credentials for every connection. See Configuring WEM.

Security fixes

  • Addressed reported security issues in API routes and host agent privileged-command handling, including a helper command that accepted an arbitrary file path and one that followed a world-writable path during binary discovery, and updated internal dependencies to pick up upstream security fixes.

Changes

  • Minimum host agent version is 1.1.0: WEM 1.4 requires acp-host-agent 1.1.0 or later on every cluster node. Upgrade the host agent before or alongside your WEM upgrade. See Upgrading the host agent.
  • Prometheus and Loki are no longer used: WEM's metrics and log pipeline switches to ClickHouse. Switching doesn't carry over existing telemetry. Historical metrics and logs already stored in Prometheus and Loki stay where they are, and become unavailable in WEM after you upgrade. The Collector no longer pushes to Prometheus or Loki, and the SQL exporter and Prometheus remote-write receiver are removed. If you're upgrading, export or archive anything you need to keep, then plan to decommission any Prometheus or Loki instances you ran solely for WEM. See Upgrading WarehousePG Enterprise Manager.
  • WHPG_PXF_BIN, WHPG_PXF_BASE, and WHPG_OS_USER configuration parameters removed: PXF actions now dispatch through the host agent instead of running locally on the WEM host. PXF binary and configuration discovery always uses fixed, safe paths, and WEM no longer needs to know or match PXF's OS user. If you set any of these parameters explicitly, remove them from wem.conf when you upgrade. See Configuration reference.
  • Refresh controls standardized: Refresh buttons across the application are now icon-only, with an accessible label for screen readers, instead of a mix of icon and text buttons.
  • Existing User alert rules aren't migrated: Upgrading removes Prometheus, where User alert rules were stored. They're deleted rather than carried over to ClickHouse. System rules are unaffected, they're recreated automatically using ClickHouse SQL, and alert history is preserved regardless of which engine originally raised it. Note down any User alert rules before upgrading and recreate them afterward through the Rules tab. See Upgrading WarehousePG Enterprise Manager.

Bug fixes

  • Fixed a certificate validation gap in the mTLS grace-window check that let a host agent certificate with a future NotBefore date pass.
  • Fixed WEM retrying a timed-out configuration push to an agent with an expired certificate on every reconcile cycle instead of skipping it immediately.
  • Fixed ClickHouse reconnection to happen automatically after a transient connection failure.
  • Made error messages for connection failures and missing databases more specific.
  • Fixed scheduler contention between the canary check scheduler, backup and resource schedule checks, and alert rule loading that crashed the scheduler under concurrent load.
  • Fixed configuration drift not being corrected after a host restart or network interruption. The host agent's automatic configuration push now runs on every re-registration instead of only the first one.
  • Fixed HBA management view gaps by adding a missing Other Rules tile, correcting the superuser role label, and fixing pagination in the partition management dialog that made entries past the first page inaccessible.
  • Fixed the CPU usage chart exceeding 100% on multi-segment hosts.
  • Fixed the blocked-query count counting a query waiting on multiple locks more than once.
  • Fixed the Query Editor crashing when running EXPLAIN or ANALYZE on a query that returns an error.
  • Removed a misleading success notification shown after a failed query.
  • Fixed WHPG_WEM_USER to default gracefully when unset.
  • Fixed errors reading or applying pg_hba.conf to return a structured error response instead of an unhandled failure.
  • Fixed PXF task handlers on the host agent not registering at startup, which caused WEM to report "Cannot reach the PXF host agent" until the agent was restarted after PXF was installed.
  • Fixed the Backups panel not reliably resolving a segment's data directory right after a host agent was approved. The agent now re-registers immediately after approval.
  • Fixed excessive warning-level logging while a host agent waited for a revoked certificate to be replaced. The agent also now forces a reconnect after repeated renewal failures, so a revoked certificate is rejected promptly instead of retried indefinitely.
  • Fixed log collection on WarehousePG builds where pg_current_logfile() isn't available.
  • Consolidated log scanning into a single privileged call on the host agent instead of five separate ones.
  • Fixed the host agent's connection to WEM resolving to an unusable IPv6 address on hosts without IPv6 support.

Could this page be better? Report a problem or suggest an addition!