- Issued:
- 2023-05-03
- Updated:
- 2023-05-03
RHEA-2023:2102 - Product Enhancement Advisory
Synopsis
ACS 4.0 enhancement update
Type/Severity
Product Enhancement Advisory
Topic
Updated images are now available for Red Hat Advanced Cluster Security
(RHACS). The updated image includes new features and bug fixes.
Description
Release of RHACS 4.0 provides these changes:
New features:
- Major release version change to 4.0
- Installing Central with an external PostgreSQL database (Technology Preview)
- RHACS Cloud Service Limited Availability
- Telemetry data collection in RHACS Cloud Service
- Red Hat Enterprise Linux CoreOS (RHCOS) node host scanning for security vulnerabilities
- Processes listening on endpoints API
- Network graph 2.0 (Technology Preview) updates
- FIPS compliance
- Alert messages sent to Central logs for expiring tokens
- Improvements for Sensor resync (Technology Preview)
- Documentation additions
Important: For offline configured installations that have set the `collector.slimMode` option to false: the `rhacs-collector-rhel8` image now contains a subset of kernel modules and eBPF probes available in the support package download. If the collector status is unhealthy after an upgrade, follow the instructions for downloading kernel support packages and then upload them to Central. See: https://docs.openshift.com/acs/3.74/configuration/enable-offline-mode.html#download-kernel-support-package_enable-offline-mode
Notable technical changes: See the Release Notes.
Deprecated and removed features: See the Release Notes.
Bug fixes:
- Previously, in the RHACS portal, the Platform Configuration → Clusters page did not display information in the Cloud Provider field for Azure Red Hat OpenShift and Red Hat OpenShift Service on AWS (ROSA) clusters. This has been fixed.
- If the most recent critical alert in an environment was from a custom policy that triggers off of Kubernetes audit logs, it could cause the widgets on the main dashboard to fail. This has been fixed.
- Previously, the `image scan_time` value was not updated for some images in the Image entity list. This issue occurred because the workflow for updating watched images and the workflow for manually scanning images did not actually re-scan the images when the image SHA remained the same. This has been fixed.
- Fixed an issue in consistency with `roxctl` output and API output for the image vulnerability data. Previously, `roxctl` showed the total number of CVEs. Now the unique number of CVEs is shown instead.
- Fixed an issue with the `roxctl generate netpol` command. Previously, the command generated network policies with the `status{}` field, which prevented applying policies to a cluster. The command no longer generates network policies with this field.
- Fixed an issue where the Create Policy buttons were not visible when the certificate expiration banner was displayed.
- Error messages generated during runtime policy validation have been improved.
- Previously, RHACS failed to suspend a cron job when enforcing a deploy time policy. This issue has been fixed.
Known issues:
Currently, RHACS does not support alerts for security policy violations for containers running with default `seccomp profiles-Unconfined`. The alert violations for Unconfined seccomp profiles are generated only if the seccomp profile is explicitly set to "Unconfined" in the container specification. No workaround exists.
Solution
To take advantage of the new features, bug fixes, and enhancements in RHACS 4.0, you are advised to upgrade to RHACS 4.0.
Affected Products
- Red Hat Advanced Cluster Security for Kubernetes 4 for RHEL 8 x86_64
- Red Hat Advanced Cluster Security for Kubernetes for IBM Z and LinuxONE 4 for RHEL 8 s390x
- Red Hat Advanced Cluster Security for Kubernetes for IBM Power, little endian 4 for RHEL 8 ppc64le
Fixes
- ROX-16829 - Release RHACS 4.0.0
ppc64le
| advanced-cluster-security/rhacs-central-db-rhel8@sha256:7a6d5a3b8ed335bf970703bb15fb63d93a5031fb86f74b3387f745fd878af144 |
| advanced-cluster-security/rhacs-collector-rhel8@sha256:1b111d7dda10ed8034027e5fb371598819e5b096dc8fa1b565c59afe2f57c223 |
| advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:8eb4d64dfe105f91e63fbaeab5e6b5b12ca266852e87cd71b0dd6d0d7cd7b339 |
| advanced-cluster-security/rhacs-main-rhel8@sha256:792806ec7b7be2de26d7459c39da2f2b70fb8a5a006ff78fa20151d6296da1cc |
| advanced-cluster-security/rhacs-operator-bundle@sha256:a5aaf42f88aa7a43462dad536d2dee8b8bdce3bf6046ab6747a3b680e0d252cf |
| advanced-cluster-security/rhacs-rhel8-operator@sha256:37fbc04cfccaca6f1f46f8e2667dd72d2dca19405f36f932a2cc96571d7a66be |
| advanced-cluster-security/rhacs-roxctl-rhel8@sha256:87a47736ba5b3e5cec2c5a70fd4150095b677c442fbdd8a27aa70eea6594d66b |
| advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:2e6c764d3859201de961fe1d8411f994d277a1d31f6f35cbc91129516749c92a |
| advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:64a6370c20200ac6a8f958372479ea191acc6e29ec325a2ffed8605138ebde5d |
| advanced-cluster-security/rhacs-scanner-rhel8@sha256:bbf8a5ee40989b4237fba7e73d3993eaff68753029261e1b103b9cbc193294f2 |
| advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:7feb84c8795d40d08a3039483a846d79de71cfda7ab680206e900eb2a51d6321 |
s390x
| advanced-cluster-security/rhacs-central-db-rhel8@sha256:54402051955fcf00d5b3c2788013b2b1a4c2c2cb1f8077f6b43b95680a2a13f8 |
| advanced-cluster-security/rhacs-collector-rhel8@sha256:2956a383283ca83d3f1d347730f11b4b740a85130f006115fa0fe52eb6193a59 |
| advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:354f47a53973ec673605340fb1e8212eecbfd2f46e8807381a4d28521ff0f0d9 |
| advanced-cluster-security/rhacs-main-rhel8@sha256:f86b53ab40ef596cbede00d12d0a62056c88e378ea37372d114327d0dd7ba4af |
| advanced-cluster-security/rhacs-operator-bundle@sha256:951beae6ef95fa9f1ed677e4f8ab3c0c381057844a7fa6a1b84c8c96201d70e2 |
| advanced-cluster-security/rhacs-rhel8-operator@sha256:4c0d6b8a7fb47d877472f1863bfeec03f7f36f01ddfaf7876d4d91cbcd6d9bcc |
| advanced-cluster-security/rhacs-roxctl-rhel8@sha256:6858e9a39a9e7ae9073e9069d6ca41d3d15c1a8a9719b13bc4524f80643147e2 |
| advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:cdf28d93b255de45e09a80c9c467e396048f626db011c0176baa5462a968b667 |
| advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:3060dc48a3a24eee4eed10437df0f390e5c6e596fa7daa449d8b14d46992b21c |
| advanced-cluster-security/rhacs-scanner-rhel8@sha256:e559ad768626cfd9975c6377939928bfbf87a4a2bd9a5d2d6cff0b475cff2ed7 |
| advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:0c7948b4c29e9494dd424c73848bd54d8c9b1ddda01b2d2881ae7930d494a4c3 |
x86_64
| advanced-cluster-security/rhacs-central-db-rhel8@sha256:017f7776493c0af283bc90360de7c585d6f637174d71ed760e8250ba3e84405f |
| advanced-cluster-security/rhacs-collector-rhel8@sha256:04aabd34daf17a573cdc9c50c655dbe5bbd53e53756745d9f52b932b1ee5d2a6 |
| advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:f27fe193f7b4c5cd513b9cfc37a958ba6dbb787c0c5a01820cd1194baff9bd31 |
| advanced-cluster-security/rhacs-main-rhel8@sha256:98903b986c59b6597988bb711ba4f18a80874afbc4bbf36aeefd53f6c9e49910 |
| advanced-cluster-security/rhacs-operator-bundle@sha256:0e7e55c46aa3a9926b184d031ff0adf0e4d208819a98a78aede2a7152d52bc30 |
| advanced-cluster-security/rhacs-rhel8-operator@sha256:facc3bf545f5b43ec551434bad89a621140fea3fff040cd4553fe475fc4aa42f |
| advanced-cluster-security/rhacs-roxctl-rhel8@sha256:6301bec93393fc8a0e1dafcb58f65c04692d639fad6a57dfd9bbb0ec81b0b1c5 |
| advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:5f6b6d9f666406f77295cd04ac36afa21d9163afe5469f9df26edeec80134cda |
| advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:d50ecb364e91e90a934c34d17b97b63db30c33a30a1e8ea0b8d6f5614e125e2a |
| advanced-cluster-security/rhacs-scanner-rhel8@sha256:4a22fb7282d5a41b3d98db37b0f29e5de5c93ddd11a2fdfb37b5554b0728e888 |
| advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:298ffb1b14cc0d6965590d18c60bbf0f2aebbe69259fc5fa707e6502d045f937 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.