Current Series Release Notes

In Development - Unreleased

Deprecation Notes

  • Overriding the Ansible python interpreter per node via the ansible_python_interpreter field in driver_info is deprecated. Use the [ansible]default_python_interpreter configuration option instead. The per-node override can be disabled with the new [ansible]allow_node_python_interpreter_override option, whose default is expected to change to False in a future release.

Security Issues

  • Adds the [ansible]allow_node_python_interpreter_override configuration option to the ansible deploy interface. The per-node ansible_python_interpreter value set in a node’s driver_info is passed to Ansible as a global extra-var, which means it also selects the interpreter used for the configdrive cleanup task that is delegated to the conductor and executed under the ironic-conductor service account. A caller able to update driver_info (for example a project owner under the default policy) could therefore influence which binary the conductor executes on its own host. Setting this option to False causes a per-node value to be rejected with a validation error, so that only the conductor-configured [ansible]default_python_interpreter is used, removing the caller’s ability to steer the conductor-side interpreter. The option defaults to True to preserve existing behavior; the default is expected to change to False in a future release. Operators that do not require per-node interpreter selection are encouraged to set it to False.

Bug Fixes

  • Fixes bug 2169173 to add validation that rejects Glance encrypted images during deployment validation. Ironic now checks for the cinder_encryption_key_id property in Glance images and raises a clear error message indicating that encrypted images are not supported for bare metal deployments. This prevents wasting deployment resources on images that cannot work with bare metal due to the fundamental architectural mismatch between encryption designed for virtualized environments and physical hardware access.

  • Fixes an issue where a pre-shared OCI registry credential supplied in the documented docker config.json “auth” format (the base64 encoding of username:password) was sent to the registry as an HTTP Basic password with an empty username. When a bearer token is requested, such a credential is now decoded and sent as proper HTTP Basic credentials, allowing registries which expect basic authentication to authenticate successfully. Opaque bearer tokens conveyed via the password, which are not base64 encoded username:password values, continue to be sent unchanged, preserving the prior behavior. See bug 2168735.

  • Fixes bootc container deployments dropping the username when a raw username:password basic authentication credential was supplied as a pull secret. The credential is now reconstructed and transmitted to the agent so that both the username and password are available for authentication to the remote container registry. See bug 2168735.

  • Fixes an inconsistency where the cpu.frequency field in inspection data was reported as an integer by Redfish (out-of-band) inspection but as a string by in-band inspection (IPA). Redfish inspection now reports cpu.frequency as a string to match in-band inspection.

  • Fixed Trait Based Networking (TBN) failing with an HTTP 500 error ('Portgroup' object has no attribute 'vendor') when attaching a VIF to a node that has portgroups. Portgroups have no vendor field, so filter expressions that reference port.vendor no longer match portgroups.

  • Fixed Trait Based Networking (TBN) failing VIF attachment when more than one action matched, for example when a port is a member of a portgroup and matches both an attach_portgroup and an attach_port action. All matching actions were executed in the same vif_attach() call, so the second attempt to bind the VIF failed the whole operation. Only the first matching action is now executed. See bug 2169647 for details.

  • Trait Based Networking (TBN) filter expressions that reference an unset value, such as port.vendor on a portgroup or port.category on a port without a category, now never match, regardless of comparator. Previously ordering comparators (<, <=, >, >=) and prefix match (=~) raised an error, and != matched.

  • Fixes the inspection rule plugin data actions (set-plugin-data, extend-plugin-data and unset-plugin-data) ignoring slash notation in path, so that they now accept the same dot or slash notation as the node attribute actions.

  • Fixes an issue where Lenovo servers in UEFI mode would get stuck in an infinite boot loop after Ironic provisioned RHCOS or other operating systems that require UEFI shim bootloaders when using custom deploy flows (e.g., OpenShift/Metal³ deployments with Redfish boot interfaces).

    After provisioning, when preparing the instance to boot from disk, the Redfish boot interfaces (redfish-virtual-media and redfish-https) set BootSourceOverrideTarget=Hdd which on Lenovo systems maps to a generic “Hard Disk” boot entry that bypasses the UEFI shim bootloader. The system would display a “Boot Option Restoration” screen and continuously reboot, requiring manual user intervention.

    The fix extends existing Lenovo UEFI handling from the agent deploy interface to the Redfish boot interfaces. During the prepare_instance phase, Ironic now skips setting the boot device for Lenovo UEFI systems, allowing the UEFI boot order (which has the shim bootloader first) to handle the boot process. This avoids triggering NVRAM changes that can be lost due to Lenovo’s NVRAM restore behavior.

    This change only affects Lenovo hardware in UEFI mode during instance preparation in the Redfish boot interfaces and does not affect legacy BIOS mode, other vendors, or other boot interfaces.

    For more details, see bug 2150628.

  • Fixes an issue where the neutron network interface could attach only some of the tenant VIFs of a node. Every port or port group with a tenant VIF attached is now plugged when configuring tenant networks, and a failure to plug any one of them fails the operation. Ports that are members of a port group are no longer skipped, so a port group can be defined while its member ports are still plugged individually, and they are likewise unbound when tenant networks are unconfigured. See bug 2169761 for details.

  • Fixes a file descriptor leak in Swift client connections. The SwiftAPI class was creating OpenStack SDK Connection objects without properly closing them, leading to file descriptor accumulation over time in deployments that use Swift for configdrive, firmware updates, or inspection data storage. All Swift client code now properly closes connections using context managers.