Skip to content

Update an engine

Terminal window
geni engine update <engine-id> \
--max-concurrent-submissions 20 \
--engine-version 26.04.6-2 \
--read-only <bucket> \
--revoke-access <bucket>
Argument Meaning
<engine-id> The ID GENI generated when the engine was created
--max-concurrent-submissions <n> Caps how many submissions the engine runs in parallel
--engine-version <version> Docker image tag to run. No version is pinned by provider — any registered version is accepted on AWS or GCP
--read-only, --read-write, --write-only <bucket> Add or change access to a bucket — S3 or GCS URI (repeatable)
--revoke-access <bucket> Remove a bucket’s access

Every flag is optional — a flag you omit keeps its current value. Bucket flags merge into the engine’s existing access list rather than replacing it wholesale: an added bucket updates or adds its entry, a revoked one is removed, everything else is left as-is.

Running geni engine update <engine-id> with no flags at all re-applies the engine’s infrastructure without changing any setting. GENI uses this to roll out infrastructure-only fixes — such as new bucket lifecycle rules — to engines that were created before the fix shipped. It’s safe to re-run against an already up-to-date engine.

Move an existing Nextflow engine to the consolidated image

Section titled “Move an existing Nextflow engine to the consolidated image”

Engines created before 26.04.6-1 shipped are still running an older, provider-specific Nextflow image (26.04.1-s3 on AWS, 26.04.1-gcp on GCP, or the legacy 25.10.4). They keep working exactly as before — nothing about them changes on its own. To pick up the newer Nextflow release and config profiles, update the engine’s version explicitly:

Terminal window
geni engine update <engine-id> --engine-version 26.04.6-2

This re-applies the engine’s infrastructure with the new image — on AWS it’s a Batch job definition update, on GCP a fresh image copy into the environment’s Artifact Registry — and takes the engine through UPDATING back to ACTIVE, same as any other update. No submission history, bucket access, or concurrency setting is touched. Nothing else needs to change: the same workflows, queues, and geni submission create commands work unmodified against the upgraded engine.

--read-only, --read-write and --write-only each accept a prefix as well as a whole bucket, so you can narrow an engine’s access from an entire bucket down to just the folders its workflows actually use.

Say the engine currently has read-write access to the whole geni-lab-data bucket, granted when it was created:

Terminal window
geni engine create \
--name "Nextflow" \
--environment-id $ENVIRONMENT_ID \
--engine-version 26.04.6-2 \
--read-write gs://geni-lab-data

To restrict it to only project-a and project-b, revoke the whole-bucket grant and add the two prefixes in the same update:

Terminal window
geni engine update <engine-id> \
--revoke-access gs://geni-lab-data \
--read-write gs://geni-lab-data/project-a \
--read-write gs://geni-lab-data/project-b

The bucket-wide entry is removed and replaced by two prefix-scoped entries — the engine can read and write project-a and project-b, but nothing else in geni-lab-data, including any prefix not listed. There is no separate “exclude a prefix” flag: access is allow-listed, so a prefix is excluded simply by never granting it.

Create a queue.