- Issued:
- 2023-05-03
- Updated:
- 2023-05-03
RHEA-2023:2102 - ACS 4.0 enhancement update
Synopsis
ACS 4.0 enhancement update
Type/Severity
Product Enhancement Advisory
Topic
Updated images are now available for Red Hat Advanced Cluster Security (RHACS). The updated image includes new features and bug fixes.
Description
Release of RHACS 4.0 provides these changes:
New features:
- Major release version change to 4.0
- Installing Central with an external PostgreSQL database (Technology Preview)
- RHACS Cloud Service Limited Availability
- Telemetry data collection in RHACS Cloud Service
- Red Hat Enterprise Linux CoreOS (RHCOS) node host scanning for security vulnerabilities
- Processes listening on endpoints API
- Network graph 2.0 (Technology Preview) updates
- FIPS compliance
- Alert messages sent to Central logs for expiring tokens
- Improvements for Sensor resync (Technology Preview)
- Documentation additions
Important: For offline configured installations that have set the collector.slimMode option to false: the rhacs-collector-rhel8 image now contains a subset of kernel modules and eBPF probes available in the support package download. If the collector status is unhealthy after an upgrade, follow the instructions for downloading kernel support packages and then upload them to Central. See: https://docs.openshift.com/acs/3.74/configuration/enable-offline-mode.html#download-kernel-support-package_enable-offline-mode
Notable technical changes: See the Release Notes.
Deprecated and removed features: See the Release Notes.
Bug fixes:
- Previously, in the RHACS portal, the Platform Configuration → Clusters page did not display information in the Cloud Provider field for Azure Red Hat OpenShift and Red Hat OpenShift Service on AWS (ROSA) clusters. This has been fixed.
- If the most recent critical alert in an environment was from a custom policy that triggers off of Kubernetes audit logs, it could cause the widgets on the main dashboard to fail. This has been fixed.
- Previously, the
image scan_timevalue was not updated for some images in the Image entity list. This issue occurred because the workflow for updating watched images and the workflow for manually scanning images did not actually re-scan the images when the image SHA remained the same. This has been fixed. - Fixed an issue in consistency with
roxctloutput and API output for the image vulnerability data. Previously,roxctlshowed the total number of CVEs. Now the unique number of CVEs is shown instead. - Fixed an issue with the
roxctl generate netpolcommand. Previously, the command generated network policies with thestatus{}field, which prevented applying policies to a cluster. The command no longer generates network policies with this field. - Fixed an issue where the Create Policy buttons were not visible when the certificate expiration banner was displayed.
- Error messages generated during runtime policy validation have been improved.
- Previously, RHACS failed to suspend a cron job when enforcing a deploy time policy. This issue has been fixed.
Known issues:
Currently, RHACS does not support alerts for security policy violations for containers running with default seccomp profiles-Unconfined. The alert violations for Unconfined seccomp profiles are generated only if the seccomp profile is explicitly set to "Unconfined" in the container specification. No workaround exists.
Solution
To take advantage of the new features, bug fixes, and enhancements in RHACS 4.0, you are advised to upgrade to RHACS 4.0.
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat Advanced Cluster Security for Kubernetes | 4 | x86_64 |
| Red Hat Advanced Cluster Security for Kubernetes for IBM Z and LinuxONE | 4 | s390x |
| Red Hat Advanced Cluster Security for Kubernetes for IBM Power, little endian | 4 | ppc64le |
Fixes
CVEs
References
- This page is not included, but the link has been rewritten to point to the nearest parent document.This page is not included, but the link has been rewritten to point to the nearest parent document.https://docs.openshift.com/acs/4.0/release_notes/40-release-notes.html
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at Security Contacts and Procedures.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.