live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
guideSECURITY

RHACS 4.10 enters maintenance with a narrower fix policy and a January deadline

Users keep critical security coverage after Sept. 3, but enhancements stop and some OpenShift 4.17 deployments need a platform move before RHACS 4.11.

RHACS 4.10 maintenance versus 4.11 upgrade path
Side by side: what changed
By The News Desk· Sep 2, 2026the quick take — two AI hosts, this story only

Red Hat Advanced Cluster Security for Kubernetes 4.10 leaves full support after Sept. 3 and enters maintenance support on Sept. 4. The change does not end security coverage immediately, but it narrows what Red Hat commits to ship and starts a four-month clock toward the version’s Jan. 4, 2027 support cutoff. Red Hat’s lifecycle table lists RHACS 4.11 as the only release remaining in full support.

What maintenance support removes

During full support, Red Hat says qualified Critical and Important security advisories are released as available, along with urgent and selected high-priority bug fixes; other qualified fixes can arrive through periodic updates. In maintenance, Critical and Important security advisories continue, while urgent and selected high-priority bug fixes only may be released. Other bug-fix and enhancement advisories become discretionary, and Red Hat says new features and enhancements will not be provided.

That makes Sept. 4 a planning boundary rather than an immediate shutdown. Teams that only need eligible security fixes can remain on the latest RHACS 4.10 patch during the maintenance window. Teams waiting for product improvements, lower-priority fixes or new capabilities should treat 4.11 as the active line. All 4.10 users that need continuing technical support must leave the release before maintenance ends Jan. 4; after that date, software and documentation remain available, but Red Hat says technical support is limited to upgrade assistance.

Who has an extra platform dependency

The lifecycle matrix matters because RHACS 4.11 does not list exactly the same OpenShift versions as 4.10. RHACS 4.10 supports OpenShift 4.12, 4.14, 4.16, 4.17, 4.18, 4.19, 4.20 and 4.21. RHACS 4.11 supports 4.12, 4.14, 4.16, 4.18, 4.19, 4.20, 4.21 and 4.22.

The practical exception is OpenShift 4.17: it appears in the 4.10 row but not the 4.11 row. A team still pairing RHACS 4.10 with OpenShift 4.17 therefore needs to plan an OpenShift move to a version in the 4.11 compatibility row before treating RHACS 4.11 as its supported destination. Teams on the other listed OpenShift versions have a common compatibility target in 4.11.

What to do before upgrading

Red Hat’s RHACS 4.11 upgrade guide says Operator upgrades run automatically or manually according to the installation’s update-approval setting. Before upgrading, administrators should back up the Central database. If a SecuredCluster custom resource exists, its per-node collector must use CORE_BPF rather than KernelModule or EBPF.

RHACS 4.11 also changes container-image suffixes from -rhel8 to -rhel9 as part of its UBI 9 Minimal migration. Deployments with image mirrors, allowlists or firewall rules tied to the old names must update those controls before the upgrade.

The immediate task is to inventory RHACS 4.10 installations, their OpenShift versions and their update-approval settings. The September boundary removes feature work; the January boundary removes normal technical support.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.