Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion modules/api-list-performance-optimizations.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -7,4 +7,4 @@
= API list performance optimizations

[role="_abstract"]
API list performance was optimized to improve performance and resource consumption of certain endpoints returning `List<Type>` objects.
This release optimizes API list endpoints that return `List<Type>` objects, improving both performance and resource consumption.
4 changes: 2 additions & 2 deletions modules/bug-fixes-in-version-411.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
= Bug fixes in version 4.11

[role="_abstract"]
This release contains bug fixes and enhancements.
This release has bug fixes and enhancements.

// JIRA: ROX-31850

Expand All @@ -17,5 +17,5 @@ This release contains bug fixes and enhancements.
* Starting with {product-title-short} 4.11, the command `roxctl deployment check -f <deployment.yaml> --cluster <cluster name or id>` will evaluate the deployment against the policies as if the deployment is running on the cluster as specified.

// JIRA: ROX-32920
* Fixed an issue where the *Integrations* page tile layout spacing was excessively large when using the Mozilla Firefox browser. Large gaps between tiles on the integration page have been fixed, and the display is now a more uniform grid.
* Fixed an issue where the *Integrations* page tile layout spacing was excessively large when using the Mozilla Firefox browser. The display now uses a more uniform grid layout.

2 changes: 1 addition & 1 deletion modules/enhanced-vulnerability-management-reporting.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
= Enhanced vulnerability management reporting

[role="_abstract"]
This update includes enhancements in vulnerability management reporting that provide more data, additional filtering options, and scheduling flexibility.
This update includes enhancements in vulnerability management reporting that offer more data, additional filtering options, and scheduling flexibility.

This release includes the following changes:

Expand Down
2 changes: 1 addition & 1 deletion modules/faster-admission-controller.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@

[role="_abstract"]

Admission controller performance has been improved by keeping the image cache warm longer, and eliminating image fetches for policies that do not evaluate images.
This release improves admission controller performance by keeping the image cache warm longer and eliminating image fetches for policies that do not evaluate images.
The default memory limit of admission controller pods is now 1 Gi, which has increased from 500 Mi.
Original file line number Diff line number Diff line change
Expand Up @@ -7,4 +7,4 @@
= Image scan accuracy

[role="_abstract"]
Images are now uniquely identified by the combination of name and digest, rather than by digest alone. This new data model resolves several long-standing issues when multiple images share the same digest but have different names, for example, different registries or tags.
Images are now uniquely identified by the combination of name and digest, rather than by digest alone. This new data model resolves several long-standing issues when many images share the same digest but have different names, for example, different registries or tags.
4 changes: 2 additions & 2 deletions modules/init-container-vulnerability-scanning.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@

{product-title-short} now scans images used by init containers and displays init container information, if it exists, in the deployment details.

This feature is available as a Technology Preview and is disabled by default. To enable init container scanning, set the `ROX_INIT_CONTAINER_SUPPORT` feature flag to `true`.
This feature is available as a Technology Preview and defaults to off. To enable init container scanning, set the `ROX_INIT_CONTAINER_SUPPORT` feature flag to `true`.

When enabled, {product-title-short} extracts, scans, and displays init containers in the following {product-title-short} locations:

Expand All @@ -21,7 +21,7 @@ When enabled, {product-title-short} extracts, scans, and displays init container
* Risk Deployment details
* Vulnerability Management

Init containers are included in risk scores and compliance checks. However, policies do not evaluate init containers in this Technology Preview release.
Risk scores and compliance checks include init containers. However, policies do not evaluate init containers in this Technology Preview release.

[NOTE]
====
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@
[role="_abstract"]

// JIRA: ROX-32416
Installation methods have been consolidated to focus on Operator-based deployment as the primary installation approach.
This release consolidates installation methods to focus on Operator-based deployment as the primary installation approach.

This consolidation simplifies the installation experience and aligns with Kubernetes-native deployment patterns. The {product-title-short} Operator provides a consistent, automated installation and upgrade experience across all supported platforms.

6 changes: 3 additions & 3 deletions modules/notable-technical-changes-411.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -15,12 +15,12 @@ This release has the following changes:

Update to Patternfly 6::

The {product-title-short} web portal has been upgraded to PatternFly 6. PatternFly 6 provides an improved user experience with enhanced accessibility, better performance, and a modernized visual design.
The {product-title-short} web portal now uses PatternFly 6. PatternFly 6 provides an improved user experience with enhanced accessibility, better performance, and a modernized visual design.

Security and other enhancements::

* For security purposes, the functionality to export reports to PDF is removed. PDF report generation functionality was replaced with alternative implementations.
* For security purposes, this release removes the functionality to export reports to PDF. Alternative implementations replace PDF report generation.
//ROX-34861
* Istio support in {product-title-short} was simplified and the `env.istio` configuration parameter no longer exists. Existing instances of this variable will be ignored and Istio support is always enabled.
* This release simplifies Istio support in {product-title-short} and removes the `env.istio` configuration parameter. {product-title-short} ignores existing instances of this variable and always enables Istio support.


2 changes: 1 addition & 1 deletion modules/performance-operations-411.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -6,5 +6,5 @@
[id="performance-operations_{context}"]
= Performance and operations

[role="abstract"]
[role="_abstract"]
This release includes performance and operational improvements.
2 changes: 1 addition & 1 deletion modules/policy-scope-cluster-namespace-labels.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -9,5 +9,5 @@
[role="_abstract"]

// JIRA: ROX-29854
Policy scope selection capabilities have been expanded, allowing you to include clusters by label.
This release expands policy scope selection capabilities, allowing you to include clusters by label.

2 changes: 1 addition & 1 deletion modules/red-hat-hardened-image-scanning.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -7,4 +7,4 @@
= Red Hat hardened image scanning

[role="_abstract"]
Red{nbsp}Hat Advanced Cluster Security Clair can scan Red Hat hardened images (Project Hummingbird) and cross-reference findings with Red Hat VEX metadata, supporting validation and ongoing monitoring of hardened image CVE posture.
Red{nbsp}Hat Advanced Cluster Security Clair can scan Red{nbsp}Hat hardened images (Project Hummingbird) and cross-reference findings with Red{nbsp}Hat VEX metadata, supporting validation and ongoing monitoring of hardened image CVE posture.
2 changes: 1 addition & 1 deletion modules/splunk-integration-improvements.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -10,5 +10,5 @@

// JIRA: ROX-26107

The Splunk Technology Add On has been updated, adding support for File Activity violations and aligning with recent Splunk changes. The new version, 3.0.0, is available for download on SplunkBase.
This release updates the Splunk Technology Add On, adding support for File Activity violations and aligning with recent Splunk changes. The new version, 3.0.0, is available for download on SplunkBase.

6 changes: 3 additions & 3 deletions modules/technology-preview-features-411.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -7,11 +7,11 @@
= Technology Preview features

[role="_abstract"]
This release includes Technology Preview features that provide early access to upcoming product innovations.
This release includes Technology Preview features that offer early access to upcoming product innovations.

[IMPORTANT]
====
Technology Preview features are not supported with Red{nbsp}Hat production service level agreements (SLAs) and might not be functionally complete. Red{nbsp}Hat does not recommend using them in production. These features provide early access to upcoming product features, enabling customers to test functionality and provide feedback during the development process.
Technology Preview features are not supported with Red{nbsp}Hat production service level agreements (SLAs) and might not be functionally complete. Red{nbsp}Hat does not recommend using them in production. These features offer early access to upcoming product features, enabling customers to test functionality and give feedback during the development process.

For more information about the support scope of Red{nbsp}Hat Technology Preview features, see link:https://access.redhat.com/support/offerings/techpreview/[Technology Preview Features Support Scope^].
For more information about the support scope of Red{nbsp}Hat Technology Preview features, see "Technology Preview Features Support Scope".
====
66 changes: 35 additions & 31 deletions release_notes/411-release-notes.adoc
Original file line number Diff line number Diff line change
@@ -1,110 +1,114 @@
:_mod-docs-content-type: ASSEMBLY
[id="release-notes-411"]
= Red{nbsp}Hat Advanced Cluster Security for Kubernetes 4.11
include::modules/common-attributes.adoc[]
Comment thread
agantony marked this conversation as resolved.
:context: release-notes-411
:toc: macro
:toclevels: 3

toc::[]

[role="_abstract"]
Red{nbsp}Hat Advanced Cluster Security for Kubernetes (RHACS) is an enterprise-ready, Kubernetes-native container security solution that protects your vital applications across the build, deploy, and runtime stages of the application lifecycle.

RHACS deploys into your infrastructure and integrates with your DevOps tools and workflows. This integration provides better security and compliance, enabling DevOps and InfoSec teams to operationalize security.
{rh-rhacs-first} is an enterprise-ready, Kubernetes-native container security solution that protects your vital applications across the build, deploy, and runtime stages of the application lifecycle.

include::modules/common-attributes.adoc[]
{product-title-short} deploys into your infrastructure and integrates with your DevOps tools and workflows. This integration provides better security and compliance, enabling DevOps and InfoSec teams to operationalize security.

//Release dates
include::modules/release-dates-411.adoc[leveloffset=+1]

//About release 4.11
include::modules/about-release-411.adoc[leveloffset=+1]

//NEW AND ENHANCED FUNCTIONALITY

//New features
include::modules/new-features-411.adoc[leveloffset=+1]

//ENHANCED VULNERABILITY MANAGEMENT REPORTING
//Enhanced vulnerability management reporting
include::modules/enhanced-vulnerability-management-reporting.adoc[leveloffset=+2]

//RED HAT HARDENED IMAGE SCANNING
//Red Hat hardened image scanning
include::modules/red-hat-hardened-image-scanning.adoc[leveloffset=+2]

//POLICY SCOPE USING CLUSTER AND NAMESPACE LABELS

//Policy scope support for cluster and namespace labels
include::modules/policy-scope-cluster-namespace-labels.adoc[leveloffset=+2]

//POLICY FOR OC DEBUG/PODS ATTACH

//Policy-based detection and enforcement for oc debug and pods attach
include::modules/policy-detection-enforcement-oc-debug-pods-attach.adoc[leveloffset=+2]

//SCHEDULING COMPLIANCE OPERATOR TAILORED PROFILES

//Support for Compliance Operator tailored profiles scheduling
include::modules/compliance-operator-tailored-profiles-scheduling.adoc[leveloffset=+2]

//SPLUNK TA UPDATE

//Splunk integration improvements
include::modules/splunk-integration-improvements.adoc[leveloffset=+2]

[role="_additional-resources"]
.Additional resources

* link:https://splunkbase.splunk.com/app/5315[Splunkbase]

//PERFORMANCE AND OPERATIONS
//Performance and operations
include::modules/performance-operations-411.adoc[leveloffset=+1]

//IMAGE SCAN ACCURACY
//Image scan accuracy
include::modules/image-data-model-refactoring-technical-details.adoc[leveloffset=+2]


//LIGHTWEIGHT RUNTIME DATA COLLECTION
//Lightweight runtime data collection
include::modules/lightweight-runtime-data-collection.adoc[leveloffset=+2]

//FASTER ADMISSION CONTROLLER
//Faster admission controller
include::modules/faster-admission-controller.adoc[leveloffset=+2]

// API FOR LISTS - FASTER AND LESS RESOURCE INTENSIVE
//API list performance optimizations
include::modules/api-list-performance-optimizations.adoc[leveloffset=+2]

//UBI FOUNDATION
//Migration to UBI 9 minimal base images
include::modules/ubi9-minimal-migration.adoc[leveloffset=+2]

//SIMPLIFIED DEPLOYMENT OPTIONS

//Installation method consolidation to Operator-based deployment
include::modules/installation-method-consolidation-operator-based.adoc[leveloffset=+2]

//MORE CONTROL OVER CLUSTER REGISTRATION SECRETS (CRS)
//Cluster registration secrets improvements
include::modules/cluster-registration-secrets-improvements.adoc[leveloffset=+2]

//TECHNOLOGY PREVIEW FEATURES
//Technology Preview features
include::modules/technology-preview-features-411.adoc[leveloffset=+1]

[role="_additional-resources"]
.Additional resources
* link:https://access.redhat.com/support/offerings/techpreview/[Technology Preview Features Support Scope]

//Init container vulnerability scanning
include::modules/init-container-vulnerability-scanning.adoc[leveloffset=+2]

//Dynamic path support for file activity monitoring
include::modules/dynamic-path-support-for-file-activity-monitoring.adoc[leveloffset=+2]

[role="_additional-resources"]
.Additional resources
* xref:../operating/manage_security_policies/configuring-file-activity-monitoring.adoc#configuring-file-activity-monitoring[Configuring file activity monitoring]

//Policy differentiation for CVE origin from base images or application layers
include::modules/policy-differentiation-cve-origin-base-application-layers.adoc[leveloffset=+2]

//FROM TECH PREVIEW TO GA
//Technology Preview features promoted to General Availability
include::modules/technology-preview-to-ga-411.adoc[leveloffset=+1]

// Vulnerability Management
//RHACS vulnerability management in OpenShift console plugin
include::modules/rhacs-vulnerability-management-openshift-console-plugin-ga.adoc[leveloffset=+2]

[role="_additional-resources"]
.Additional resources
* xref:../configuration/accessing-vulnerability-information-in-web-console.adoc#accessing-vulnerability-information-in-web-console[Accessing vulnerability information in the {ocp} web console]

//Base image GA
//Standardized base image definition and layer detection
include::modules/base-image-ga.adoc[leveloffset=+2]

//Notable technical changes
include::modules/notable-technical-changes-411.adoc[leveloffset=+1]

//Deprecated and removed features
include::modules/deprecated-and-removed-features-411.adoc[leveloffset=+1]

//Bug fixes in version 4.11
include::modules/bug-fixes-in-version-411.adoc[leveloffset=+1]

//Image versions
include::modules/image-versions.adoc[leveloffset=+1]