Issued:
2023-05-03
Updated:
2023-05-03

RHEA-2023:2102 - ACS 4.0 enhancement update


Synopsis

ACS 4.0 enhancement update

Type/Severity

Product Enhancement Advisory

Topic

Updated images are now available for Red Hat Advanced Cluster Security (RHACS). The updated image includes new features and bug fixes.

Description

Release of RHACS 4.0 provides these changes:

New features:

  • Major release version change to 4.0
  • Installing Central with an external PostgreSQL database (Technology Preview)
  • RHACS Cloud Service Limited Availability
  • Telemetry data collection in RHACS Cloud Service
  • Red Hat Enterprise Linux CoreOS (RHCOS) node host scanning for security vulnerabilities
  • Processes listening on endpoints API
  • Network graph 2.0 (Technology Preview) updates
  • FIPS compliance
  • Alert messages sent to Central logs for expiring tokens
  • Improvements for Sensor resync (Technology Preview)
  • Documentation additions

Important: For offline configured installations that have set the collector.slimMode option to false: the rhacs-collector-rhel8 image now contains a subset of kernel modules and eBPF probes available in the support package download. If the collector status is unhealthy after an upgrade, follow the instructions for downloading kernel support packages and then upload them to Central. See: https://docs.openshift.com/acs/3.74/configuration/enable-offline-mode.html#download-kernel-support-package_enable-offline-mode

Notable technical changes: See the Release Notes.

Deprecated and removed features: See the Release Notes.

Bug fixes:

  • Previously, in the RHACS portal, the Platform Configuration → Clusters page did not display information in the Cloud Provider field for Azure Red Hat OpenShift and Red Hat OpenShift Service on AWS (ROSA) clusters. This has been fixed.
  • If the most recent critical alert in an environment was from a custom policy that triggers off of Kubernetes audit logs, it could cause the widgets on the main dashboard to fail. This has been fixed.
  • Previously, the image scan_time value was not updated for some images in the Image entity list. This issue occurred because the workflow for updating watched images and the workflow for manually scanning images did not actually re-scan the images when the image SHA remained the same. This has been fixed.
  • Fixed an issue in consistency with roxctl output and API output for the image vulnerability data. Previously, roxctl showed the total number of CVEs. Now the unique number of CVEs is shown instead.
  • Fixed an issue with the roxctl generate netpol command. Previously, the command generated network policies with the status{} field, which prevented applying policies to a cluster. The command no longer generates network policies with this field.
  • Fixed an issue where the Create Policy buttons were not visible when the certificate expiration banner was displayed.
  • Error messages generated during runtime policy validation have been improved.
  • Previously, RHACS failed to suspend a cron job when enforcing a deploy time policy. This issue has been fixed.

Known issues: Currently, RHACS does not support alerts for security policy violations for containers running with default seccomp profiles-Unconfined. The alert violations for Unconfined seccomp profiles are generated only if the seccomp profile is explicitly set to "Unconfined" in the container specification. No workaround exists.

Solution

To take advantage of the new features, bug fixes, and enhancements in RHACS 4.0, you are advised to upgrade to RHACS 4.0.

Affected Products

ProductVersionArch
Red Hat Advanced Cluster Security for Kubernetes4x86_64
Red Hat Advanced Cluster Security for Kubernetes for IBM Z and LinuxONE4s390x
Red Hat Advanced Cluster Security for Kubernetes for IBM Power, little endian4ppc64le

Fixes

CVEs

References


Additional information