- Issued:
- 2026-09-08
- Updated:
- 2026-09-08
RHSA-2026:65542 - Security Advisory
Synopsis
Red Hat build of OpenTelemetry 3.11.0 release
Type/Severity
Security Advisory: Important
Topic
Red Hat build of OpenTelemetry 3.11.0 has been released
Description
This release of the Red Hat build of OpenTelemetry provides new features, security improvements, and bug fixes.
Breaking changes:
- With this update, the `add_metric_suffixes` field of the Prometheus Exporter configuration in the `OpenTelemetryCollector` custom resource is removed. To manage metric name suffixes, use the `translation_strategy` field instead.
Deprecations:
- Google Cloud Exporter is deprecated: The Google Cloud Exporter, which sends telemetry data to Google Cloud Operations Suite, is deprecated and will be removed in a future major release. You can export data to Google Cloud Operations Suite by using the OTLP HTTP Exporter with the Google Client Authorization Extension instead. For more information, see https://redhat.atlassian.net/browse/TRACING-6139.
Technology Preview features:
- OBI (Open Telemetry eBPF) Receiver: This update adds the OBI (Open Telemetry eBPF) Receiver to the Red Hat build of OpenTelemetry as a Technology Preview feature. The OBI Receiver uses eBPF to automatically inspect application executables and the OS networking layer, and capture trace spans, Rate Errors Duration (RED) metrics.
- Redaction Processor: This update adds the Redaction Processor to the Red Hat build of OpenTelemetry as a Technology Preview feature. The Redaction Processor removes sensitive data from telemetry data before it is exported. For more information, see https://redhat.atlassian.net/browse/TRACING-6502.
- Headers Setter Extension: This update adds the Headers Setter Extension to the Red Hat build of OpenTelemetry as a Technology Preview feature. The Headers Setter Extension sets headers on outgoing HTTP requests made by exporters. For more information, see https://redhat.atlassian.net/browse/TRACING-6504.
- Kubernetes Leader Elector Extension: This update adds the Kubernetes Leader Elector Extension to the Red Hat build of OpenTelemetry as a Technology Preview feature. The Kubernetes Leader Elector Extension enables OpenTelemetry components to run in HA mode across a Kubernetes cluster. The component that owns the lease becomes the leader and becomes the active instance. For more information, see https://redhat.atlassian.net/browse/TRACING-6478.
Enhancements:
- High availability for the Operator webhooks: This update introduces high availability support for the Red Hat build of OpenTelemetry Operator webhooks. The webhooks run in a separate deployment from the main Operator deployment. For more information, see https://redhat.atlassian.net/browse/TRACING-6157.
Bug fixes:
- Instrumentation CR status fields are updated automatically: Before this update, when creating or updating an Instrumentation custom resource (CR), the .status.observedGeneration and .status.conditions fields were not updated because the Red Hat build of OpenTelemetry Operator lacked a reconciliation controller for Instrumentation CRs. In this release, the Operator continuously reconciles Instrumentation CRs and populates these status fields upon creation or update without requiring an Operator restart. For more information, see https://issues.redhat.com/browse/TRACING-6412.
- Automatic RBAC of the Operator includes PersistentVolume and PersistentVolumeClaim resources: Before this update, the automatic Role-Based Access Control (RBAC) feature of the Red Hat build of OpenTelemetry Operator did not include the required permissions for PersistentVolume and PersistentVolumeClaim resources. As a consequence, the Kubernetes Cluster Receiver failed with RBAC errors. With this update, the Operator automatically grants the required permissions for these resources. As a result, the Kubernetes Cluster Receiver works correctly with the automatic RBAC feature. For more information, see https://redhat.atlassian.net/browse/TRACING-6381.
Solution
For details on how to apply this update, refer to:
Affected Products
- Red Hat OpenShift distributed tracing
Fixes
- TRACING-6412 - [Upstream] The Instrumentation CR's `status.observedGeneration` and `status.conditions` are never set because the operator lacks a reconciliation controller for Instrumentation.
- TRACING-6381 - 3.10 bug, k8sclusterreceiver requires more RBAC
amd64
| registry.redhat.io/rhosdt/opentelemetry-operator-bundle@sha256:b760df73ba4b903adfc466b427453907850b88a43c7d77c2aadec9d880577243 |
| registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:c978aa771ee250022ba72dd67db6ed63613f17f717bc1c07d107a5982d9e3160 |
| registry.redhat.io/rhosdt/opentelemetry-rhel9-operator@sha256:12f2ad8c82a43430eba0caa78fa3c95d7e31d2355d33869e3a470c1fd03901ae |
| registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel9@sha256:44df27737d7965f37444baa1dd4bb5f971c0ee4f18709b266184b39081b648c8 |
arm64
| registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:f44b6f7bd152dbfcfb4f1c067472464d013be031985b8e30370c925abde0c8ec |
| registry.redhat.io/rhosdt/opentelemetry-rhel9-operator@sha256:90c3079709e4ca7b69b9f4014cb76c18d0302c5957bb162d34d6dbd35a121cac |
| registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel9@sha256:a7a816f6276bcbaa5b01a8c634feaf37adffb941d48be747fbb7aca3c080b863 |
ppc64le
| registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:be10082c2fa3d382f9f3f6e9965a5671eb857219506cbe28a84e250abd513289 |
| registry.redhat.io/rhosdt/opentelemetry-rhel9-operator@sha256:3b4357f29551c2e1defbc9fe6d419323339effe87e4e7363e6c7ce7ddb373d3f |
| registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel9@sha256:bcbb3cc8a5b081b9afecebdc973cfd8fb78aa7300e20149b59ce28088f1f5a19 |
s390x
| registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:c16f2b226c6fa1df2b0c45271f7429afe5bfb9abeba4c9986a5f10c0ececc0a2 |
| registry.redhat.io/rhosdt/opentelemetry-rhel9-operator@sha256:8a8032c902dc640147300c7ba90c5c34d48c5dba640f501248f87fee8b1928b5 |
| registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel9@sha256:ad9ca1e9011c15176fc2455ddfa0d3fc8f7cdd35161a0ad784371d4cf26d59c2 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.