The following enhancements and bug fixes have been implemented in this release of {PlatformNameShort}.
-
{LightspeedShortName} has been updated to 2.5.241127.(AAP-35307)
-
redhat.insightsAnsible collection has been updated to 1.3.0.(AAP-35161) -
ansible.edacollection has been updated to 2.2.0 in {ExecEnvShort} and decision environment images.(AAP-3398)
-
With this update, you can set PostgreSQL SSL/TLS mode to
verify-fullorverify-cawith the propersslrootcertconfiguration in the {HubName} Operator.(AAP-35368)
-
With this update,
IDandImagefields from a container image are used instead ofDigestandImageDigestto trigger a container update.(AAP-36575) -
With this update, you can now update the registry URL value in {EDAName} credentials.(AAP-35085)
-
With this update, the
kernel.keys.maxkeysandkernel.keys.maxbytessettings are increased on systems with large memory configuration.(AAP-34019) -
Added
ansible_connection=localto theinventory-growth fileand clarified its usage.(AAP-34016)
-
With this update, the Container growth topology and Container enterprise topology have been updated to include s390x (IBM Z) architecture test support.(AAP-35969)
With this update, the following CVEs have been addressed:
-
CVE-2024-52304
automation-controller:aiohttpvulnerable to request smuggling due to wrong parsing of chunk extensions.
-
With this update, missing {OperatorPlatformNameShort} custom resource definitions (CRDs) are added to the
aap-must-gathercontainer image.(AAP-35226) -
Disabled {Gateway} authentication in the proxy configuration to prevent HTTP 502 errors when the control plane is down.(AAP-36527)
-
The Red Hat favicon is now correctly displayed on {ControllerName} and {EDAName} API tabs.(AAP-30810)
-
With this update, the {ControllerName} admin password is now reused during upgrade from {PlatformNameShort} 2.4 to 2.5.(AAP-35159)
-
Fixed undefined variable (
_controller_enabled) when reconciling anAnsibleAutomationPlatformRestore. Fixed {HubName} Operatorpg_restoreerror on restores due to a wrong database secret being set.(AAP-35815)
-
Updated the minor version of uWSGI to obtain updated log verbiage.(AAP-33169)
-
Fixed job schedules running at the wrong time when the
rruleinterval was set toHOURLYorMINUTELY.(AAP-36572) -
Fixed an issue where sensitive data was displayed in the job output.(AAP-35584)
-
Fixed an issue where unrelated jobs could be marked as a dependency of other jobs.(AAP-35309)
-
Included pod anti-affinity configuration on default container group pod specification to optimally spread workload.(AAP-35055)
-
With this update, you cannot change the
postgresql_admin_usernamevalue when using a managed database node.(AAP-36577) -
Added update support for PCP monitoring role.
-
Disabled {Gateway} authentication in the proxy configuration to prevent HTTP 502 errors when the control plane is down.
-
With this update, you can use dedicated nodes for the Redis group.
-
Fixed an issue where disabling TLS on {Gateway} would cause installation to fail.
-
Fixed an issue where disabling TLS on {Gateway} proxy would cause installation to fail.
-
Fixed an issue where {Gateway} uninstall would leave container systemd unit files on disk.
-
Fixed an issue where the {HubName} container signing service creation failed when
hub_collection_signing=falsebuthub_container_signing=true. -
Fixed an issue with the
HOMEenvironment variable for receptor containers which would cause a “Permission denied” error on the containerized execution node. -
Fixed an issue where not setting up the GPG agent socket properly when many hub nodes are configured, resulted in not creating a GPG socket file in
/var/tmp/pulp. -
With this update, you can now change the {Gateway} port value after the initial deployment.
-
Fixed an issue where the
metrics-utilitycommand failed to run after updating {ControllerName}. -
Fixed the owner and group permissions on the
/etc/tower/uwsgi.inifile. -
Fixed an issue where not having
eda_node_typedefined in the inventory file would result in backup failure. -
Fixed an issue where not having
routable_hostnamedefined in the inventory file would result in a restore failure. -
With this update, the
inventory-growthfile is now included in the RPM installer. -
Fixed an issue where the dispatcher service went into
FATALstatus and failed to process new jobs after a database outage of a few minutes. -
Disabled {Gateway} authentication in the proxy configuration to allow access to the UI when the control plane is down.
-
With this update, the Receptor data directory can now be configured using the
receptor_datadirvariable.