live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
analysisPLATFORM

OpenShift 4.22 carries user-defined networks into EVPN-VXLAN fabrics

The new BGP EVPN support gives primary cluster user-defined networks a standards-based path into existing data-center fabrics, with virtualization migrations as the clearest early use case.

OpenShift network overlay joining an EVPN-VXLAN fabric
Side by side: what changed
By The News Desk· Aug 24, 2026

OpenShift 4.22 adds Border Gateway Protocol Ethernet VPN support for primary cluster user-defined networks, letting an OpenShift overlay participate in the EVPN control plane used by many data-center fabrics. Red Hat’s release notes describe the capability as a way for a ClusterUserDefinedNetwork to integrate more deeply with the surrounding network rather than stopping at the Kubernetes cluster boundary.

What changed

The design builds on two earlier networking steps: user-defined networks in OpenShift 4.18 and BGP support added in the 4.19 line. OpenShift 4.22 now connects those pieces to an EVPN control plane, while VXLAN carries the data plane. In Red Hat’s engineering explanation, OpenShift advertises MAC and IP reachability through BGP EVPN so selected user-defined networks can extend into a customer-managed EVPN fabric.

That moves the EVPN-VXLAN endpoint closer to workloads. Instead of terminating the overlay only at a top-of-rack or leaf switch, the OpenShift side can participate directly, while external EVPN border routers retain responsibility for reachability to wider internal networks, WAN links and the internet. Red Hat says the implementation supports both MAC-VRF and IP-VRF route advertisement for Layer 2 and Layer 3 user-defined networks.

Who should care

The most immediate audience is platform and network teams moving virtual machines onto OpenShift Virtualization. Red Hat positions EVPN as a way to preserve logical network membership, IP addressing and application dependencies while workloads move, reducing the need to redesign or readdress the network during a migration. The same architecture also matters to multi-tenant platforms that need segmentation to continue beyond the cluster boundary.

This is not a replacement for the data-center fabric. It is an integration point. Operators still need compatible EVPN-VXLAN infrastructure and a coordinated design between the OpenShift and network teams. The value is that both sides can use the same standards-based control plane instead of adding a proprietary gateway between them.

What to evaluate

Teams testing the feature should begin with one primary ClusterUserDefinedNetwork and a bounded workload set, then verify route advertisement, failure convergence, segmentation and access through the EVPN border routers. Virtualization programs should test whether migrated VMs keep the expected Layer 2 or Layer 3 identity and whether existing policy and monitoring still see the intended traffic paths.

The OpenShift 4.22 release notes are the product-level starting point; Red Hat’s linked advanced-networking documentation contains the configuration detail. The engineering post also says the architecture is intended to reach managed OpenShift offerings over time, but that forward-looking direction should not be treated as current managed-service availability.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.