2026.2 Series Release Notes

27.0.0

New Features

  • The allowed auth_algorithm, encryption_algorithm and pfs values for OS::Neutron::IKEPolicy and OS::Neutron::IPsecPolicy now follow Neutron’s neutron-lib VPN definitions, so newer algorithms (for example the AES-GCM, AES-CCM and AES-CTR encryption modes and the additional PFS groups) can be used. Neutron remains the authority on which algorithms a given deployment actually accepts.

  • port_extra_properties on OS::Nova::Server networks now supports in-place updates where possible, avoiding unnecessary port detach/attach cycles.

  • The deprecated [DEFAULT] stack_user_domain option has been removed. Use the [DEFAULT] stack_user_domain_id option instead.

  • OS::Neutron::SecurityGroup now exposes a stateful property so Heat can request stateless groups when the Neutron stateful-security-group alias is enabled. Heat validates that alias before accepting templates with stateful: false; otherwise stacks should leave stateful unset to rely on Neutron’s legacy stateful default.

Upgrade Notes

  • When Neutron advertises the vpn-no-sha1-3des extension, new OS::Neutron::IKEPolicy and OS::Neutron::IPsecPolicy resources that do not set auth_algorithm now default to sha256 instead of sha1. Existing resources and stack updates keep their configured algorithms.

  • The following deprecated options in the [ec2authtoken] section have been removed. Due to this removal, the ec2authtoken middleware now requires that credential options are properly set in the [ec2authtoken] section or the per-cloud [ec2authtoken.<name>] sections.

    • auth_uri

    • allowed_auth_uris

    • ca_file

    • cert_file

    • key_file

  • The deprecated [oslo_policy] enforce_scope configuration option has been removed in oslo.policy version 6.0.0 which will impact Keystone as there is no longer any way to disable RBAC policy scope enforcement; scope checks are now always enforced regardless of configuration.

    If you are not upgrading the oslo.policy to 6.0.0, then there will not be any change in scope enforcement behaviour.

  • Support for Python 3.10 has been removed. Now Python 3.11 is the minimum version supported.

  • Integration with vitrage has been removed. The OS::Vitrage::Template resource type is no longer supported and is now hidden.

  • The enable_stack_abandon and enable_stack_adopt configuration options are no longer deprecated. Both features now work with the convergence engine, so these options remain supported for enabling stack abandon and stack adopt.

Bug Fixes

  • Delay the deletion of an OS::Nova::Server internal port until Nova confirms the interface detach. Previously, the port was removed from Neutron while still bound to the instance, which could corrupt the Nova instance info cache and leave the server’s addresses and networks attributes permanently empty, causing stack updates to fail with a RetryError.

  • Fixed a race in OS::Nova::Server network updates where the networks and addresses attributes could resolve to a stale or empty value right after an interface attach. The attach check now waits for the port’s fixed IPs to appear in the server addresses.

  • Fixed the broken heat-manage update_params command.

  • Fixed inconsistency between OS::Neutron::SecurityGroup embedded rules property and the``OS::Neutron::SecurityGroupRule`` resource. The embedded rules now support the same description field and document the same comprehensive list of protocols, resolving confusion about which protocols are actually supported.

  • Fixed port_extra_properties being silently ignored when only network (no subnet) was specified in OS::Nova::Server.

  • Fixed TypeError: unhashable type: 'dict' during stack updates when port_extra_properties contained dict-valued properties such as allowed_address_pairs.