2026.2 Series Release Notes¶
27.0.0¶
Nouvelles fonctionnalités¶
The allowed
auth_algorithm,encryption_algorithmandpfsvalues forOS::Neutron::IKEPolicyandOS::Neutron::IPsecPolicynow follow Neutron’sneutron-libVPN definitions, so newer algorithms (for example the AES-GCM, AES-CCM and AES-CTR encryption modes and the additional PFS groups) can be used. Neutron remains the authority on which algorithms a given deployment actually accepts.
port_extra_propertiesonOS::Nova::Servernetworks now supports in-place updates where possible, avoiding unnecessary port detach/attach cycles.
The deprecated
[DEFAULT] stack_user_domainoption has been removed. Use the[DEFAULT] stack_user_domain_idoption instead.
OS::Neutron::SecurityGroupnow exposes astatefulproperty so Heat can request stateless groups when the Neutronstateful-security-groupalias is enabled. Heat validates that alias before accepting templates withstateful: false; otherwise stacks should leavestatefulunset to rely on Neutron’s legacy stateful default.
Notes de mises à jours¶
When Neutron advertises the
vpn-no-sha1-3desextension, newOS::Neutron::IKEPolicyandOS::Neutron::IPsecPolicyresources that do not setauth_algorithmnow default tosha256instead ofsha1. Existing resources and stack updates keep their configured algorithms.
The following deprecated options in the
[ec2authtoken]section have been removed. Due to this removal, the ec2authtoken middleware now requires that credential options are properly set in the[ec2authtoken]section or the per-cloud[ec2authtoken.<name>]sections.auth_uriallowed_auth_urisca_filecert_filekey_file
The deprecated
[oslo_policy] enforce_scopeconfiguration option has been removed in oslo.policy version 6.0.0 which will impact Keystone as there is no longer any way to disable RBAC policy scope enforcement; scope checks are now always enforced regardless of configuration.If you are not upgrading the oslo.policy to 6.0.0, then there will not be any change in scope enforcement behaviour.
Support for Python 3.10 has been removed. Now Python 3.11 is the minimum version supported.
Integration with vitrage has been removed. The
OS::Vitrage::Templateresource type is no longer supported and is now hidden.
The
enable_stack_abandonandenable_stack_adoptconfiguration options are no longer deprecated. Both features now work with the convergence engine, so these options remain supported for enabling stack abandon and stack adopt.
Corrections de bugs¶
Delay the deletion of an
OS::Nova::Serverinternal port until Nova confirms the interface detach. Previously, the port was removed from Neutron while still bound to the instance, which could corrupt the Nova instance info cache and leave the server’saddressesandnetworksattributes permanently empty, causing stack updates to fail with a RetryError.
Fixed a race in
OS::Nova::Servernetwork updates where thenetworksandaddressesattributes could resolve to a stale or empty value right after an interface attach. The attach check now waits for the port’s fixed IPs to appear in the server addresses.
Fixed the broken
heat-manage update_paramscommand.
Fixed inconsistency between
OS::Neutron::SecurityGroupembeddedrulesproperty and the``OS::Neutron::SecurityGroupRule`` resource. The embedded rules now support the samedescriptionfield and document the same comprehensive list of protocols, resolving confusion about which protocols are actually supported.
Fixed
port_extra_propertiesbeing silently ignored when only network (no subnet) was specified inOS::Nova::Server.
Fixed
TypeError: unhashable type: 'dict'during stack updates whenport_extra_propertiescontained dict-valued properties such asallowed_address_pairs.