RHACS 4.10 enters maintenance with a narrower fix policy and a January deadline
Users keep critical security coverage after Sept. 3, but enhancements stop and some OpenShift 4.17 deployments need a platform move before RHACS 4.11.
Red Hat Advanced Cluster Security for Kubernetes 4.10 leaves full support after Sept. 3 and enters maintenance support on Sept. 4. The change does not end security coverage immediately, but it narrows what Red Hat commits to ship and starts a four-month clock toward the version’s Jan. 4, 2027 support cutoff. Red Hat’s lifecycle table lists RHACS 4.11 as the only release remaining in full support.
What maintenance support removes
During full support, Red Hat says qualified Critical and Important security advisories are released as available, along with urgent and selected high-priority bug fixes; other qualified fixes can arrive through periodic updates. In maintenance, Critical and Important security advisories continue, while urgent and selected high-priority bug fixes only may be released. Other bug-fix and enhancement advisories become discretionary, and Red Hat says new features and enhancements will not be provided.
That makes Sept. 4 a planning boundary rather than an immediate shutdown. Teams that only need eligible security fixes can remain on the latest RHACS 4.10 patch during the maintenance window. Teams waiting for product improvements, lower-priority fixes or new capabilities should treat 4.11 as the active line. All 4.10 users that need continuing technical support must leave the release before maintenance ends Jan. 4; after that date, software and documentation remain available, but Red Hat says technical support is limited to upgrade assistance.
Who has an extra platform dependency
The lifecycle matrix matters because RHACS 4.11 does not list exactly the same OpenShift versions as 4.10. RHACS 4.10 supports OpenShift 4.12, 4.14, 4.16, 4.17, 4.18, 4.19, 4.20 and 4.21. RHACS 4.11 supports 4.12, 4.14, 4.16, 4.18, 4.19, 4.20, 4.21 and 4.22.
The practical exception is OpenShift 4.17: it appears in the 4.10 row but not the 4.11 row. A team still pairing RHACS 4.10 with OpenShift 4.17 therefore needs to plan an OpenShift move to a version in the 4.11 compatibility row before treating RHACS 4.11 as its supported destination. Teams on the other listed OpenShift versions have a common compatibility target in 4.11.
What to do before upgrading
Red Hat’s RHACS 4.11 upgrade guide says Operator upgrades run automatically or manually according to the installation’s update-approval setting. Before upgrading, administrators should back up the Central database. If a SecuredCluster custom resource exists, its per-node collector must use CORE_BPF rather than KernelModule or EBPF.
RHACS 4.11 also changes container-image suffixes from -rhel8 to -rhel9 as part of its UBI 9 Minimal migration. Deployments with image mirrors, allowlists or firewall rules tied to the old names must update those controls before the upgrade.
The immediate task is to inventory RHACS 4.10 installations, their OpenShift versions and their update-approval settings. The September boundary removes feature work; the January boundary removes normal technical support.
sources
- Red Hat Advanced Cluster Security for Kubernetes Support Policyaccess.redhat.com
- RHACS 4.11: Upgrading by using the Operatordocs.redhat.com
comments · 0