- Issued:
- 2024-07-16
- Updated:
- 2024-07-25
RHBA-2024:4558 - Bug Fix Advisory
Synopsis
RHOAI 2.11.0 - Red Hat OpenShift AI
Type/Severity
Bug Fix Advisory
Topic
Updated images are now available for Red Hat OpenShift AI.
Description
Release of RHOAI 2.11.0 provides these changes:
Solution
For Red Hat OpenShift AI 2.11.0 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:
https://access.redhat.com/documentation/en-us/red_hat_openshift_ai/2024
Affected Products
- Red Hat OpenShift AI 2 x86_64
Fixes
- RHOAIENG-2293 - Improve the error message when creating a pipeline run with a lot of characters
- RHOAIENG-3782 - Remove DS Pipelines Server Endpoint Hack
- RHOAIENG-382 - Inconsistency in Serving UI
- RHOAIENG-3826 - Remove old runs pages and routing and experiments temp feature flag
- RHOAIENG-4385 - DSPA - Add back the Folder Info
- RHOAIENG-5150 - Implement documentation to Tiles
- RHOAIENG-5368 - convert templates to websockets
- RHOAIENG-6287 - Reconciliation errors for DSP apiServer route length not surfacing in dspa
- RHOAIENG-6463 - Add option to disable envoy route
- RHOAIENG-6516 - Set main container as default for pipeline run pods to show log output
- RHOAIENG-6560 - Implement dynamic prometheus queries based on ConfigMap
- RHOAIENG-6561 - Implement error handling for kserve metrics prometheus queries
- RHOAIENG-6571 - Remove v1 upgrade related logic in Operator
- RHOAIENG-6649 - Viewing model "internal service" shows stacktrace page
- RHOAIENG-6794 - Inconsistency in model serving types
- RHOAIENG-7144 - Dashboard shows cached pipeline steps in gray (no info about what it means)
- RHOAIENG-72 - [case 03661266] Strict Pod Security Admission settings can make ODH Notebook Controller pod unable to start
- RHOAIENG-7209 - Default Pipelineroot fails
- RHOAIENG-7308 - [Snyk] Resolve DSP repo High Level snyk CVEs
- RHOAIENG-7346 - Credentials warning for SDK when run with pipeline service account
- RHOAIENG-1197 - "End date" picker in pipeline run creation page defaults to NaN when using Firefox on Linux
- RHOAIENG-2497 - static analysis dead code removal
- RHOAIENG-4189 - Improve too large error on Upload Pipeline
- RHOAIENG-4721 - eslint rule method-signature-style
- RHOAIENG-5510 - Add test coverage for pipeline MLMD hooks
- RHOAIENG-6522 - Create model metrics kserve page
- RHOAIENG-6637 - Registered Models - Archive Registered Models
- RHOAIENG-6638 - Model Version - Archive Registered Models
- RHOAIENG-6654 - Popover text for Pipelines isn't rendering in Project Overview tab
- RHOAIENG-6970 - Admin - Model Registry Table
- RHOAIENG-7081 - Download S3 and Minio from the dashboard backend
- RHOAIENG-7213 - update frontend browserslist message in build log
- RHOAIENG-7214 - 19 warnings from webpack building frontend
- RHOAIENG-7335 - [Spike] Investigate gRPC mocks for cypress tests for MLMD artifacts
- RHOAIENG-7338 - [Spike] Investigate gRPC mocks for cypress tests for MLMD compare runs
- RHOAIENG-7375 - Runs related to recurring runs forever load when parent is deleted
- RHOAIENG-7428 - The succeed icon for a run status is gray color (succeed should be green color)
- RHOAIENG-7430 - Missing the Collapse all and Expand all actions in the tool bar
- RHOAIENG-7481 - Add metrics columns to pipeline run table and modal param selector
- RHOAIENG-7501 - [AMD] Switch the image to be built with UBI or RHEL
- RHOAIENG-7525 - [SPIKE] Build opendatahub-io/notebooks in GitHub Action with caching
- RHOAIENG-7526 - Update pipeline metadata envoy service pod name
- RHOAIENG-7536 - create page objects for cypress home page tests
- RHOAIENG-7543 - Disable actions for runs in an archived experiment
- RHOAIENG-7544 - Pipeline artifact nodes dont open correct side details
- RHOAIENG-7545 - Pipeline task node details link to execution
- RHOAIENG-7692 - Add API Support for sorting Experiments by runs
- RHOAIENG-7715 - Allow experiments table to sort by last run started
- RHOAIENG-7787 - Generate Cypress Test results (Junit) and Report with Screenshots (on failures)
- RHOAIENG-7811 - Improve feature flags for TrustyAI / bias
- RHOAIENG-7920 - Enable TrustyAI in RHOAI for Drift Backend in 2.12
- RHOAIENG-7946 - Hide Status Icon on Hovered Artifact Nodes
- RHOAIENG-8359 - Move and update pipeline and run detail tabs
- RHOAIENG-8473 - Incorrect token setting for s3 download api
- RHOAIENG-8475 - Upgrade go toolset version in all our images.
- RHOAIENG-8493 - Cypress test for experiments table time
- RHOAIENG-8550 - Enable RHOAI Operator e2e tests
- RHOAIENG-8568 - Remove docs link from storage path popover in pipelines
- RHOAIENG-8585 - We should not show metrics when we are on the versions runs view
- RHOAIENG-1006 - Fix performance issues in odh model controller
- RHOAIENG-5426 - Update Template in Operator Repo with prerquisites
- RHOAIENG-7484 - make container builder configurable for odh-controller operator
- RHOAIENG-8483 - Operator performance enhancement
- RHOAIENG-1068 - TrustyAI CounterfactualExplainer tests timeouts
- RHOAIENG-7638 - Ray cluster doesn't start when pod security is enforced
- RHOAIENG-8590 - vLLM: Sync to upstream and refresh image for 2.11
- RHOAIENG-8591 - TGIS and Caikit-TGIS: Sync to upstream and refresh image for 2.11
- RHOAIENG-8836 - Unable to "Create Pipeline Server" in RHOAI 2.11-nightly when object storage endpoint ends with /
- RHOAIENG-4712 - Update OVMS to 2024.1
- RHOAIENG-8508 - OpenShift AI valid sub needs correction
- RHOAIENG-6295 - Missing TrustCABundle in DSCI cause error in operator pod
- RHOAIENG-7310 - [Snyk] Resolve DSP tekton repo critical snyk CVEs
- RHOAIENG-7919 - New KServe Gateway/Service
- RHOAIENG-8296 - Upgrade Go from 1.20 to 1.21
- RHOAIENG-8497 - Make RHOAI platform name easy to get by other via API
- RHOAIENG-8995 - Secret type mismatch between OpenshiftDefaultIngress and Self-signed knative certificate
- RHOAIENG-8554 - Design and add static-checks GitHub action to opendatahub-io/kubeflow
- RHOAIENG-8784 - Add GitHub workflow to sync branches within the notebooks repository
- RHOAIENG-3956 - Add logic for configmap creation for Kserve metrics in ODH Model Controller
- RHOAIENG-9427 - BuildConfig definition for RStudio image points to wrong branch
- RHOAIENG-9448 - DSC sample shows incorrect serving cert value
- RHOAIENG-9732 - Models cannot be loaded in either kserve or modelmesh in disconnected clusters when using RHOAI 2.11
- RHOAIENG-9753 - Wrong image is used for odh-notebook-controller-manager pod after upgrade
- RHOAIENG-1196 - Packages JupyterLab and Notebook versions advertised do not match installed ones on AiKit spawned image
- RHOAIENG-2306 - Cannot submit Ray Job using CodeFlare SDK with FIPS
- RHOAIENG-2312 - Importing `numpy` fails in code-server workbench when running scripts from the IDE
- RHOAIENG-2944 - Data Science Pipelines v2 General Improvements
- RHOAIENG-3971 - [ccs] Document tracking pipeline artifacts
- RHOAIENG-3972 - [ccs] Document comparing runs feature
- RHOAIENG-4170 - [ccs Epic] User documentation for Data Science Pipeline Experiments, artifacts and comparing runs
- RHOAIENG-4375 - The custom CA certificate bundle isn't grabbed by SDK TokenAuthentication by default
- RHOAIENG-4981 - feat: add support for Timestamp Feature in Must-Gather Logs
- RHOAIENG-5119 - Disconnected Engineering Bugs/Stories to complete
- RHOAIENG-5148 - [UI] VectorDB Tile
- RHOAIENG-52 - Token Authentication failing in clusters with self-signed certificates
- RHOAIENG-5221 - Data Science Pipelines v2 Executions
- RHOAIENG-5232 - Data Science Pipelines v2 Artifacts
- RHOAIENG-6325 - Creation of mesh VirtualServices for InferenceServices (InferenceGraph support)
- RHOAIENG-6346 - Reintroduce AppWrapper in API tiers documentation
- RHOAIENG-6428 - Create a POC to test the OBO integration
- RHOAIENG-6590 - Data Science Pipelines App Logs
- RHOAIENG-6614 - Upstream Ray rayjob_lightweight_test bug
- RHOAIENG-6711 - ODH Model Controller overwrites existing SMMR during reconciliation
- RHOAIENG-6780 - [Elyra] Include logs of pipeline using python script in main container logs
- RHOAIENG-6856 - Support caikit-nlp embeddings service (http)
- RHOAIENG-6962 - [Quality] Distributed WL Tuning Stack LA 2.10 - testing
- RHOAIENG-7221 - Update tests and create automation to verify that normal user is able to submit jobs
- RHOAIENG-7336 - Verify Data Science Pipelines KFP tests in ods-ci run successfully in odh-nightly
- RHOAIENG-738 - [DOCS- Installation] Troubleshooting common installation problems
- RHOAIENG-7419 - Address SNYK scan results for vLLM
- RHOAIENG-7426 - Artifacts nodes show more than two statues, and uses status icons for Execution nodes.
- RHOAIENG-7479 - Pipeline run table metrics
- RHOAIENG-7792 - [IDE] Elyra: Logs using python scripts
- RHOAIENG-7810 - Tabular Data Drift detection
- RHOAIENG-7846 - UBI based Ray runtime container image
- RHOAIENG-7873 - Use RHOAI Ray runtime container image in CodeFlare SDK by default
- RHOAIENG-7875 - Document custom Ray runtime container image build
- RHOAIENG-7922 - Update inferenceservice-config CM
- RHOAIENG-7938 - GetClusterServiceVersion() may return nil error and nil pointer.
- RHOAIENG-8160 - Fix env variables in release workflows
- RHOAIENG-8182 - Disable openshift-ci building must-gather image
- RHOAIENG-8232 - Notebook controller logs an error message on cluster without internal registry
- RHOAIENG-8254 - DSC cannot be deleted after deleting DSCI
- RHOAIENG-8262 - Add Custom Volumes/Volume Mounts for Ray Clusters
- RHOAIENG-8287 - enableDirectPvcVolumeMount is disabed in ODH Kserve config
- RHOAIENG-8291 - [Cherry pick] Creation of mesh VirtualServices for InferenceServices (InferenceGraph support)
- RHOAIENG-8398 - [Elyra] Adjust the public API route for workbench elyra plugin
- RHOAIENG-8765 - Remove artifact preview from pipelines
- RHOAIENG-8774 - vLLM: modify servingruntime definition to use OpenAI API server
- RHOAIENG-8775 - vLLM: sync release with main
- RHOAIENG-8819 - Failed to deploy ibm-granite/granite-3b-code-instruct model with vLLM runtime
- RHOAIENG-8834 - Ray Job is deleting automatically for the Appwrapper based Ray cluster workload creation
- RHOAIENG-8887 - Upgrade Kueue component to version 0.7.0
- RHOAIENG-8986 - Fail to deploy model serving component with 2 errors in DSC
- RHOAIENG-9175 - Broken link to Fraud Detection tutorial in Dashboard Home (RHOAI 2.11.0)
- RHOAIENG-9178 - [kserve] - anyio Race Condition
- RHOAIENG-9345 - [ccs] Document pipeline task executions
- RHOAIENG-9346 - [ccs] Document changes resulting from pipelines dashboard restructure
- RHOAIENG-9791 - [ccs] Produce KCS article on how to deploy KServe RawDeployment models in SNO
CVEs
- CVE-2020-26555
- CVE-2021-46909
- CVE-2021-46972
- CVE-2021-47069
- CVE-2021-47073
- CVE-2021-47236
- CVE-2021-47310
- CVE-2021-47311
- CVE-2021-47353
- CVE-2021-47356
- CVE-2021-47456
- CVE-2021-47495
- CVE-2022-48624
- CVE-2023-2953
- CVE-2023-5090
- CVE-2023-52464
- CVE-2023-52560
- CVE-2023-52615
- CVE-2023-52626
- CVE-2023-52667
- CVE-2023-52669
- CVE-2023-52675
- CVE-2023-52686
- CVE-2023-52700
- CVE-2023-52703
- CVE-2023-52781
- CVE-2023-52813
- CVE-2023-52835
- CVE-2023-52877
- CVE-2023-52878
- CVE-2023-52881
- CVE-2024-3651
- CVE-2024-24806
- CVE-2024-26583
- CVE-2024-26584
- CVE-2024-26585
- CVE-2024-26656
- CVE-2024-26675
- CVE-2024-26735
- CVE-2024-26759
- CVE-2024-26801
- CVE-2024-26804
- CVE-2024-26826
- CVE-2024-26859
- CVE-2024-26906
- CVE-2024-26907
- CVE-2024-26974
- CVE-2024-26982
- CVE-2024-27397
- CVE-2024-27410
- CVE-2024-28182
- CVE-2024-32002
- CVE-2024-32004
- CVE-2024-32020
- CVE-2024-32021
- CVE-2024-32465
- CVE-2024-32487
- CVE-2024-35789
- CVE-2024-35835
- CVE-2024-35838
- CVE-2024-35845
- CVE-2024-35852
- CVE-2024-35853
- CVE-2024-35854
- CVE-2024-35855
- CVE-2024-35888
- CVE-2024-35890
- CVE-2024-35958
- CVE-2024-35959
- CVE-2024-35960
- CVE-2024-36004
- CVE-2024-36007
References
(none)
x86_64
rhoai/odh-codeflare-operator-rhel8@sha256:025f455d093c4c5698c1e1c0e64c5a8c7e18608224aaafff67a783bccd91f59a |
rhoai/odh-dashboard-rhel8@sha256:dbd1963d374b2488a9589dfb432cc258b35a535ce3e96f5b9d6efe92fdbda63e |
rhoai/odh-data-science-pipelines-argo-argoexec-rhel8@sha256:da9487174390b01edbe9bb32d022307c851e4707d390affd7b1d8242aed3bff5 |
rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel8@sha256:94abf97e15ac55552627238b47a3b36d5cacb70f81a26c87d4deca0b5f0fab67 |
rhoai/odh-data-science-pipelines-operator-controller-rhel8@sha256:40b68ad2216c30ed40b8563ca17d640309c8d7c1acbe07d62989c2b7254b78f1 |
rhoai/odh-kf-notebook-controller-rhel8@sha256:78a68a4687045b25d7d46837380a02c119a1c6a0ae2ceceddab5b46979ab8c8e |
rhoai/odh-kuberay-operator-controller-rhel8@sha256:e4fa0b35222f1d17f8b0495d2c40e7fc7c3f85749bd46b631c514fc450a51edc |
rhoai/odh-kueue-controller-rhel8@sha256:b626d3a5819b6b3fda5f3dc03939810714329952a25f2bc2cf7d63cdb69737ea |
rhoai/odh-ml-pipelines-api-server-rhel8@sha256:0c3671d396c7a2a871038ddd4ac35ef7cefa6cf47138220c091f9ecaa0abe55e |
rhoai/odh-ml-pipelines-api-server-v2-rhel8@sha256:ba47dde21fc78e362a1d3ac945a4ed6ebc12e37d8f6d9e66ec3d2fff58bdb201 |
rhoai/odh-ml-pipelines-artifact-manager-rhel8@sha256:071d439a9a34b15dd5b76c53b7c97f7448d9d8a9d34e0be5b88bce6ab7ade207 |
rhoai/odh-ml-pipelines-cache-rhel8@sha256:773d1c75a166c9623e651f3b7c447bedb36d068f5765f695daf2eaed307c1100 |
rhoai/odh-ml-pipelines-driver-rhel8@sha256:0f5bf678db6e08c53272219b1e912d0672c11a5e9d0373e109847b75259d6047 |
rhoai/odh-ml-pipelines-launcher-rhel8@sha256:c3a8bc2dce95904d882ae656e9fdeaa332b2b5c8ebdbe33842e532d87f6909ce |
rhoai/odh-ml-pipelines-persistenceagent-rhel8@sha256:221545de08b0715d1184442d29f6c6da3ad3862b00c2490a024fb422df8d4136 |
rhoai/odh-ml-pipelines-persistenceagent-v2-rhel8@sha256:ef272bbba7d539cf32f1f7220af591f9327b4caeeda151c0b3d17827c7b190bb |
rhoai/odh-ml-pipelines-scheduledworkflow-rhel8@sha256:9ed954c14538cf358fac923e26ae59e1a2491339c573b9851e2d2e810fc85bb2 |
rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel8@sha256:d241df0ef04dcb3984769f4d90258219a755e8b15199f66fab7386cb54d41105 |
rhoai/odh-mlmd-grpc-server-rhel8@sha256:26ec71e9db33b894580aebe9363ac074fed248ee1683e838aeb0c24dee84202a |
rhoai/odh-mm-rest-proxy-rhel8@sha256:398f53b95d16e6f1c46af208906e3da2d9bcf45a50678b3d0554e1a862c96004 |
rhoai/odh-model-controller-rhel8@sha256:1eb2a53c60b93d51d39b03f92f897e0bcd93db986ecf5849b681fbcfb365f1a1 |
rhoai/odh-modelmesh-rhel8@sha256:c72c42acc531099049ce16ac01ab93b16ddf684d540a139493df97c0f55af654 |
rhoai/odh-modelmesh-runtime-adapter-rhel8@sha256:47b1868d8c6c03bf644b9afc02a6b59b671673983c2b66b23bba5dadc1c5a1c5 |
rhoai/odh-modelmesh-serving-controller-rhel8@sha256:c6030721ab4689034d235e5232528e81dcc11d2fdd7aeedf4cbf54cf4426fcfd |
rhoai/odh-notebook-controller-rhel8@sha256:355703ed8f76932c8d8c3cafd466c14ba5c464a11d7467d4cb979cab94c9dd19 |
rhoai/odh-operator-bundle@sha256:e53aa3f343e365b3b32f86ab37a2c4780a46aa50c15df98626205d66ec7f90de |
rhoai/odh-rhel8-operator@sha256:e6930fabaf63ca6bae0f23c17ef73b0c0ba610445a6defbe9e1346d748754bdd |
rhoai/odh-training-operator-rhel8@sha256:b0d4e7a7120d083ffd63ce96cf82f04a5af08dea038cb819387717c75292fd7d |
rhoai/odh-trustyai-service-operator-rhel8@sha256:4e84e906ea94b7152ff3cc4b5144362e1245ce17ef05b8c3b72a7ed99415c5b2 |
rhoai/odh-trustyai-service-rhel8@sha256:43c1f3c25637902486d252aa27c3152f9b7d040c66c652bac02fcfe2b0f4b880 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.