live wire
AI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat maps IBM CLEAR and EvalHub onto OpenShift AI for trace-level agent evaluationRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat maps IBM CLEAR and EvalHub onto OpenShift AI for trace-level agent evaluationRed Hat Developer
upstreambeat.ai
releaseCLUSTER MGMT

Submariner 0.24 goes GA in ACM 2.17 with cross-cluster networking fixes

The Important-rated release updates ACM’s multi-cluster data plane and addresses OVN-Kubernetes, Azure, service-discovery and lifecycle failures.

Before-and-after view of cross-cluster networking fixes in Submariner 0.24.
Side by side: what changed
By The News Desk· Sep 4, 2026

Red Hat has made Submariner 0.24 generally available with Red Hat Advanced Cluster Management for Kubernetes 2.17, turning the upstream May release into a supported ACM deliverable. The September 3 advisory rates the update Important and ships refreshed release images with enhancements and security fixes.

What changed

Submariner supplies direct pod and service connectivity across Kubernetes clusters and implements the Kubernetes Multi-Cluster Services API. Red Hat’s advisory lists 13 CVEs and more than 50 downstream issue references, but the operational fixes are the clearest reason for ACM operators to examine this release.

Named downstream corrections include consistent TLS-profile handling for multicluster networking, an uninstall blocker, and a failure to create an Azure gateway node on OpenShift 4.22. The upstream 0.24 notes add more detail: reconciliation no longer removes unrelated OVN-Kubernetes routes and policies, CoreDNS service discovery reports readiness correctly, gateway active-state labels are repaired, and Azure gateway MachineSets can use Marketplace images on ARO-style clusters.

The upstream release also fixes IPv6 nftables conflicts, a race that could remove a VXLAN interface during cable-driver changes, image-pull failures in subctl upgrade, and cases where multiple gateway pods were marked active.

Who is affected

This is primarily for ACM 2.17 operators using Submariner to connect services or pods across clusters. Teams running OVN-Kubernetes, Azure-hosted OpenShift, IPv6 or dual-stack networks, or automated cluster teardown and rebuild workflows have directly named fixes to validate.

The release matters to application platform teams as well: Submariner sits below cross-cluster service discovery, so incorrect readiness or route reconciliation can surface as application reachability failures rather than an obvious management-plane fault.

What to do

ACM 2.17 administrators should review RHSA-2026:63016, identify the listed release images for their deployment, and follow Red Hat’s update guidance. Before rollout, test exported-service DNS readiness and east-west connectivity between representative clusters.

Clusters matching the named risk areas should add targeted checks: verify that unrelated OVN-Kubernetes routes survive reconciliation, that Azure gateway nodes are created, and that only one gateway pod carries the active label. Because Red Hat classifies the advisory as Important and links 13 CVEs, postponing the update should be an explicit risk decision rather than routine patch deferral.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.

    Submariner 0.24 goes GA in ACM 2.17 with cross-cluster networking fixes — upstreambeat.ai