Submariner 0.24 goes GA in ACM 2.17 with cross-cluster networking fixes
The Important-rated release updates ACM’s multi-cluster data plane and addresses OVN-Kubernetes, Azure, service-discovery and lifecycle failures.
The Important-rated release updates ACM’s multi-cluster data plane and addresses OVN-Kubernetes, Azure, service-discovery and lifecycle failures.
The early-access branch adds new modules and lifecycle changes that OpenShift AI operators should test as an integrated platform, not as isolated components.
The update reaches internet-facing HTTP/2 and authentication paths, but several fixes matter only when specific Tomcat features are enabled.
The new containerized deployment keeps selected host data and recommendation processing inside Satellite, but it replaces hosted console services for managed hosts.
The open-source release adds an end-to-end path for training and serving draft models that predict several future tokens in one pass.
Three Red Hat engineering posts define complementary tests for guardrail policy, tool-call execution and failures that only emerge across complete agent traces.
Red Hat rates the asynchronous update Important and tells 4.17 operators to apply both its package and container-image payloads.
A local benchmark found the tested regex guardrail fast but inaccurate, while a DeBERTa classifier improved detection at a clear latency cost.
Platform teams can now attach authentication, rate limits and plans to GRPCRoute resources while using Kubernetes-native request and approval objects for API keys.
A new engineering note argues that agent stacks must normalize model-specific call formats, preserve multicall responses and separate reasoning from executable arguments.
The update spans RPM packages and container images; Red Hat advises all 4.19 clusters to move to 4.19.45 and provides no general workaround for most flaws.
The Important-rated service pack fixes 13 CVEs across common Quarkus extensions; teams should update the platform BOM and retest the features they actually ship.
A Ray Direct Transport engine cuts repeated model-weight synchronization by sending each inference rank only the shard it needs.
A new engineering tutorial connects MLflow, IBM CLEAR and EvalHub so teams can separate reasoning failures from bad tool calls in multistep agents.
A joint AWS, IBM and Red Hat architecture pairs governed content operations with managed OpenShift, AWS storage and search services.
The OpenShift 4.22 design preserves VM addresses across staged migrations, but its bare-metal and networking constraints demand careful lab validation.
A Red Hat account of its own IT cleanup puts dashboard retirement, spreadsheet consolidation and OpenShift standardization ahead of model deployment.
Version 0.3.45 lets CI operators assign CPU, memory and GPUs to OpenShell sandboxes instead of inheriting opaque host defaults.
A crafted archive can redirect extraction through malicious links and overwrite files outside the chosen directory with the extractor’s permissions.
The release adds native-friendly bridges for agent tools, embedding stores and declarative RAG ingestion while staying on Java 17 and 21.
Red Hat’s promotion removes year-one subscription charges, but customers still carry migration costs and must obtain private eligibility and later-year pricing before comparing offers.
OpenShift sandboxed containers 1.13 takes confidential AI on bare metal to GA while a new Agent Sandbox operator enters Technology Preview.
A four-step FastH3 profile produced complete 10-second audio-video files in about 8.7 seconds on eight NVIDIA B300 GPUs, but the project says its raw benchmark bundle is not yet public.
The proposed deployment record combines adversarial red-team results, PII-exposure scores and toxicity evaluations instead of treating benchmark accuracy as a safety certificate.
Red Hat’s limited-availability program requires a fresh RHEL 10 installation while it tests containerized operations and ML-DSA-signed content distribution.
A reproduced attack turns a small adapter into a covert exfiltration mechanism, shifting the defensive focus from weight inspection to deployment, network and provenance controls.
Standard GenAI spans and model-tagged token metrics let integration teams trace latency and attribute consumption by route and model.
Users keep critical security coverage after Sept. 3, but enhancements stop and some OpenShift 4.17 deployments need a platform move before RHACS 4.11.
A new engineering guide connects model formats and precision schemes to GPU fit, inference phases and measured serving performance.
The Important-rated asynchronous update spans curl, BIND, Unbound, dracut, the SMB client and openvt; 4.22 operators should move when the release reaches their channel.
A new Ansible Automation Platform guide connects event-driven triage, temporary mitigations, patching and policy controls into one operating model.
The August Kafka digest points operators to unresolved 4.4 blockers, a stricter replication-safety proposal and a Strimzi release with Kafka 4.3.1 support.
Four compact Granite models enter early access through Flink SQL, keeping forecasts and anomaly detection in the same governed pipeline as Kafka data.
Red Hat’s support assistant uses live product content, Granite Guardian and independently measured skill routing to keep troubleshooting answers inspectable.
Red Hat’s ART pipeline generates tailored adversarial prompts, escalates attacks only when cheaper probes fail, and tracks the results through OpenShift AI.
Three recent artifacts show platform teams making separate placement decisions for accelerators, batch work and media-aware requests rather than treating every inference call alike.
The reference pipeline separates document processing and model deployment, preserves intermediate data in object storage, and gives operators reproducible run history.
An experimental router path turns A2A agent and method metadata into trusted headers for existing authorization, rate-limit and telemetry policies.
The release improves compatibility with Kubernetes restricted Pod Security Standards, but user-authored steps and sidecars still need their own settings.
The proposed architecture would replace a Windows and SQL Server dependency with containers running beside IBM Z performance data, while adding forecasting and an anomaly-explanation agent.
A new engineering walkthrough targets MachineSets directly from Prometheus signals, with explicit RBAC and a warning not to let two autoscalers compete.
A new OpenShift AI walkthrough moves prompt-injection rail development into Jupyter, then shows where regex gives way to a small classifier.
A new learning path walks developers from a local Python stack to a verified image-mode virtual machine using hardened containers, Quadlets and bootc.
IBM says Red Hat OpenShift on IBM Cloud 4.16 became unsupported on August 26 and tells operators to move to version 4.17 or later.
The project’s new engineering guide explains why images break text-calibrated schedulers and how token estimation, cache affinity and encode disaggregation address the mismatch.
A new technical guide separates development and production choices across Helm- and Operator-managed Vault installations.
The code is on vLLM’s main branch and in a model-specific image, but it arrived after v0.28.0 and is not yet part of a newer general release.
Red Hat’s two-month notice gives 4.14 operators until November to arrange the optional third support term or move to another supported OpenShift release.
Red Hat rates CVE-2026-81624 Important, lists no acceptable mitigation and has not yet published errata for the affected Camel component.
The upstream identity release addresses OIDC policy bypasses, delegated-admin authorization gaps, token-exchange restrictions and an incomplete path-traversal fix.