2026.1 Series Release Notes¶
17.0.0-3¶
Security Issues¶
Fixed two security flaws with the v2 API: any user could update/delete a lease from any project via the v2 API, provided that they had the lease ID. Additionally, any user could use the v2 API to list all leases, including those in another project. LP#2162719
Operators that cannot yet upgrade should consider instead disabling the v2 API with the following config in
blazar.conf:[api] api_v2_controllers =
17.0.0¶
New Features¶
Add support for traits with
flavor:instancereservations.
The payload of a notification has been extended to send the entire lease data.
Bug Fixes¶
Fixes an issue where the amount of instances in an instance reservation could not be updated when the lease is active. LP#2138386