Sei sulla pagina 1di 28

Red Hat Enterprise Linux OpenStack

Platform 6
Release Notes

Release details for Red Hat Enterprise Linux OpenStack Platform

OpenStack Documentation Team

Red Hat Enterprise Linux OpenStack Platform 6 Release Notes

Release details for Red Hat Enterprise Linux OpenStack Platform


OpenStack Do cumentatio n Team
Red Hat Custo mer Co ntent Services
rho s-do cs@redhat.co m

Legal Notice
Co pyright 20 15 Red Hat, Inc.
This do cument is licensed by Red Hat under the Creative Co mmo ns Attributio n-ShareAlike 3.0
Unpo rted License. If yo u distribute this do cument, o r a mo dified versio n o f it, yo u must pro vide
attributio n to Red Hat, Inc. and pro vide a link to the o riginal. If the do cument is mo dified, all Red
Hat trademarks must be remo ved.
Red Hat, as the licenso r o f this do cument, waives the right to enfo rce, and agrees no t to assert,
Sectio n 4 d o f CC-BY-SA to the fullest extent permitted by applicable law.
Red Hat, Red Hat Enterprise Linux, the Shado wman lo go , JBo ss, MetaMatrix, Fedo ra, the Infinity
Lo go , and RHCE are trademarks o f Red Hat, Inc., registered in the United States and o ther
co untries.
Linux is the registered trademark o f Linus To rvalds in the United States and o ther co untries.
Java is a registered trademark o f Oracle and/o r its affiliates.
XFS is a trademark o f Silico n Graphics Internatio nal Co rp. o r its subsidiaries in the United
States and/o r o ther co untries.
MySQL is a registered trademark o f MySQL AB in the United States, the Euro pean Unio n and
o ther co untries.
No de.js is an o fficial trademark o f Jo yent. Red Hat So ftware Co llectio ns is no t fo rmally
related to o r endo rsed by the o fficial Jo yent No de.js o pen so urce o r co mmercial pro ject.
The OpenStack Wo rd Mark and OpenStack Lo go are either registered trademarks/service
marks o r trademarks/service marks o f the OpenStack Fo undatio n, in the United States and o ther
co untries and are used with the OpenStack Fo undatio n's permissio n. We are no t affiliated with,
endo rsed o r spo nso red by the OpenStack Fo undatio n, o r the OpenStack co mmunity.
All o ther trademarks are the pro perty o f their respective o wners.

Abstract
The Release No tes do cument the majo r features, enhancements, and kno wn issues o f the Red
Hat Enterprise Linux OpenStack Platfo rm 6 release.

T able of Cont ent s

T able of Contents
. .hapt
C
. . . .er
. .1. .. Product
. . . . . . . .Int
. . roduct
. . . . . . ion
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2. . . . . . . . . .
1.1. Ab o ut this Releas e
2
1.2. Req uirements
3
1.3. Hyp ervis o r Sup p o rt
3
1.4. Co ntent Delivery Netwo rk (CDN) Channels
3
1.5. Pro d uc t Sup p o rt
4
. .hapt
C
. . . .er
. .2. .. Release
. . . . . . . Informat
. . . . . . . .ion
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6. . . . . . . . . .
2 .1. Enhanc ements
6
2 .2. Tec hno lo g y Preview
18
2 .3. Releas e No tes
19
2 .4. Kno wn Is s ues
20
. .hapt
C
. . . .er
. .3.
. .Upgrading
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2. 3. . . . . . . . . .
. . . . . . . . .Hist
Revision
. . . ory
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .2. 4. . . . . . . . . .

Red Hat Ent erprise Linux O penSt ack Plat form 6 Release Not es

Chapter 1. Product Introduction


Red Hat Enterprise Linux OpenStack Platform provides the foundation to build a private or public
Infrastructure-as-a-Service (IaaS) cloud on top of Red Hat Enterprise Linux. It offers a massively
scalable, fault-tolerant platform for the development of cloud-enabled workloads.
The current Red Hat system is based on OpenStack Juno, and packaged so that available physical
hardware can be turned into a private, public, or hybrid cloud platform including:
Fully distributed object storage
Persistent block-level storage
Virtual-machine provisioning engine and image storage
Authentication and authorization mechanism
Integrated networking
Web browser-based GUI for both users and administration.
The Red Hat Enterprise Linux OpenStack Platform IaaS cloud is implemented by a collection of
interacting services that control its computing, storage, and networking resources. The cloud is
managed using a web-based interface which allows administrators to control, provision, and
automate OpenStack resources. Additionally, the OpenStack infrastructure is facilitated through an
extensive API, which is also available to end users of the cloud.

1.1. About t his Release


This release of Red Hat Enterprise Linux OpenStack Platform is based on the OpenStack " Juno"
release. It includes additional features, known issues, and resolved issues specific to Red Hat
Enterprise Linux OpenStack Platform.
Only changes specific to Red Hat Enterprise Linux OpenStack Platform are included in this release
notes document. The release notes for the OpenStack " Juno" release itself are available at the
following location:
O p en St ack "Ju n o " R elease N o t es
https://wiki.openstack.org/wiki/ReleaseNotes/Juno
Red Hat Enterprise Linux OpenStack Platform uses components from other Red Hat products.
Specific information pertaining to the support of these components is available at:
https://access.redhat.com/site/support/policy/updates/openstack/platform/
To evaluate Red Hat Enterprise Linux OpenStack Platform, sign up at:
http://www.redhat.com/openstack/.

Chapt er 1 . Product Int roduct ion

Note
The Red Hat Enterprise Linux High Availability Add-On is available for Red Hat Enterprise
Linux OpenStack Platform use cases. See the following URL for more details on the add-on:
http://www.redhat.com/products/enterprise-linux-add-ons/high-availability/. See the following
URL for details on the package versions to use in combination with Red Hat Enterprise Linux
OpenStack Platform: https://access.redhat.com/site/solutions/509783

1.2. Requirement s
This version of Red Hat Enterprise Linux OpenStack Platform is supported on Red Hat Enterprise
Linux 7.
The Red Hat Enterprise Linux OpenStack Platform dashboard is a web-based interface that allows
you to manage OpenStack resources and services. The dashboard for this release supports the
latest stable versions of the following web browsers:
Chrome
Firefox
Firefox ESR
Internet Explorer 11 and later (with Compatibility Mode disabled)
To view the entire documentation suite for Red Hat Enterprise Linux OpenStack Platform, see:
https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux_OpenStack_Platform

1.3. Hypervisor Support


Red Hat Enterprise Linux OpenStack Platform is only supported for use with the l i bvi rt driver
(using KVM as the hypervisor on Compute nodes) or the VMware vCenter hypervisor driver. Refer to
https://access.redhat.com/knowledge/articles/744153 for more information regarding the
configuration of the VMware vCenter driver.
Red Hat does not provide support for other Compute virtualization drivers such as the deprecated
VMware " direct-to-ESX" hypervisor, and non-KVM libvirt hypervisors.

1.4 . Cont ent Delivery Net work (CDN) Channels


This section discusses channel and repository settings required for deploying Red Hat Enterprise
Linux OpenStack Platform 6.
You can install Red Hat Enterprise Linux OpenStack Platform 6 through the Content D elivery Network
(CD N). To do so, configure su b scrip t io n - man ag er to use the correct channels.
Run the following command to enable a CD N channel:
# subscri pti o n-manag er repo s --enabl e= [reponame]
Run the following command to disable a CD N channel:

Red Hat Ent erprise Linux O penSt ack Plat form 6 Release Not es

# subscri pti o n-manag er repo s --d i sabl e= [reponame]


T ab le 1.1. R eq u ired C h an n els
C h an n el

R ep o sit o ry N ame

Red Hat Enterprise Linux


Red Hat Enterprise Linux
(RPMs)
Red Hat Enterprise Linux
6.0 (RPMS)
Red Hat Enterprise Linux
Installer 6.0 (RPMS)
Red Hat Enterprise Linux
Images

7 Server (RPMS)
7 Server - RH Common

rhel -7-server-rpms
rhel -7-server-rh-co mmo n-rpms

OpenStack Platform

rhel -7-server-o penstack-6 . 0 -rpms

OpenStack Platform

rhel -7-server-o penstack-6 . 0 i nstal l er-rpms


rhel -7-server-o penstack-6 . 0 -fi l es

OpenStack Platform

T ab le 1.2. O p t io n al C h an n els
C h an n el

R ep o sit o ry N ame

Red Hat Enterprise Linux 7 Server - Optional

rhel -7-server-o pti o nal -rpms

D isab le C h an n els
The following table outlines the channels you must disable to ensure Red Hat Enterprise Linux
OpenStack Platform 6 functions correctly.
T ab le 1.3. D isab le C h an n els
C h an n el

R ep o sit o ry N ame

Red Hat CloudForms Management Engine


Red Hat CloudForms Tools for RHEL 6
Red Hat Enterprise Virtualization
Red Hat Enterprise Linux 6 Server - Extended
Update Support

"cf-me-*"
"rhel -6 -server-cf-*"
"rhel -6 -server-rhev*"
"*-eus-rpms"

Warning
Some packages in the OpenStack software repositories conflict with packages provided by the
Extra Packages for Enterprise Linux (EPEL) software repositories.
The use of Red Hat Enterprise Linux OpenStack Platform on systems with the EPEL software
repositories enabled is unsupported.

1.5. Product Support


Available resources include:
C u st o mer Po rt al
The Red Hat Customer Portal offers a wide range of resources to help guide you through
planning, deploying, and maintaining your OpenStack deployment. Facilities available via

Chapt er 1 . Product Int roduct ion

the Customer Portal include:


Knowledge base articles and solutions.
Reference architectures.
Technical briefs.
Product documentation.
Support case management.
Access the Customer Portal at https://access.redhat.com/.
Mailin g List s
Red Hat provides these public mailing lists that are relevant to OpenStack users:
The rhsa-anno unce mailing list provides notification of the release of security fixes for
all Red Hat products, including Red Hat Enterprise Linux OpenStack Platform.
Subscribe at https://www.redhat.com/mailman/listinfo/rhsa-announce.
The rho s-l i st mailing list provides a forum for discussions about installing, running,
and using OpenStack on Red Hat based distributions.
Subscribe at https://www.redhat.com/mailman/listinfo/rhos-list.

Red Hat Ent erprise Linux O penSt ack Plat form 6 Release Not es

Chapter 2. Release Information


These release notes highlight technology preview items, recommended practices, known issues, and
deprecated functionality to be taken into consideration when deploying this release of Red Hat
OpenStack.
Notes for updates released during the support lifecycle of this Red Hat OpenStack release will appear
in the advisory text associated with each update or the Red Hat Enterprise Linux OpenStack Platform
Technical Notes. This document is available from the following page:
https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux_OpenStack_Platform

2.1. Enhancement s
B Z #106 2022
Copy-on-Write cloning for RBD -backed disks is now supported. As such, the Compute
service no longer needs to download a glance image to local disk and then copy it again to
RBD . Rather, disks can now be efficiently created directly in the Ceph system, thereby
speeding up the creation of instances and, in the process, saving bandwidth and disk
space.
B Z #89 106 2
An admin user can now specify the Provider network type (the physical mechanism by
which the virtual network is implemented), when creating a new network. Previously, the
dashboard (horizon) defaulted to the 'Local' provider network type, and it was not possible
to select another type. The types 'Flat', 'VLAN', 'GRE', and 'VXLAN', and 'Local' can now be
selected in the new 'Provider Network Type' drop-down field. D epending on the type, a
segmentation ID , tunnel ID , or physical network name must be additionally specified.
B Z #9 74 19 9
This feature exposes interactive web-based serial consoles to openstack VMs through a
websocket proxy. Generally used as a debugging tool (for example, VMs can be accessed
even if network configuration fails). A new service (websocket proxy) is now available that
handles websocket connections to the serial consoles of the VMs. The websocket proxy can
be deployed on a machine other than from the hypervisor.
B Z #9 78500
The host argument for the 'nova evacuate' command has been made optional. This means
that the user no longer has to know the host destination, simplifying evacuation in the case
of an unplanned failure.
B Z #1029 871
This enhancement enables changes to a subnet's IP address allocation pool using the
update command. Previously, administrators were unable to change the allocation pool
range for a subnet. If shrinking the pool, consideration must be given to IP addresses that
have already been allocated.
B Z #104 1054
Compute now automatically attempts a controlled shutdown for stop, rescue, and delete
instance actions. If the controlled shutdown fails, Compute falls back to a forced shutdown.

Chapt er 2 . Release Informat ion

B Z #104 1119
Previously, when a rescue was done on an instance, the image_base_ref in the
instance_meta_data was used. If this attribute was not populated, the custom image_ref was
used instead. This posed a problem where the custom image used might be corrupt,
leading to errors; or too large, leading to timeouts. Also, if the base image was deleted, the
image ref on the instance_system_metadata would be invalid, leading to the rescue
operation failing. With this release, the user can now specify which image is to be used for
rescue (this could be a default base image, or a custom image).
B Z #104 1121
With this feature, there is now a standardized data reporting mechanism for VM diagnostics.
The historic diagnostics API had no formal specification. As a result, different virtualization
drivers in Nova reported a different data set and made it difficult for VM diagnostics to
consume the data in a predictable manner. With this update, a new version of the
diagnostic API was implemented in the version 3 API, and it now defines a standardized set
of data items that virtualization drivers must use for reporting.
B Z #104 1376
OpenStack Compute now supports associating SR-IOV PCI devices with networks and
binding Neutron SR-IOV ports to them. PCI-Passthrough to SR-IOV virtual functions
provide direct access to networking hardware specialized for virtualization with one
physical device supporting multiple virtual machines. By supporting SR-IOV devices,
virtual machines can now employ SR-IOV hardware for networking.
B Z #104 19 6 6
Role-based access control (RBAC) checks are now supported for actions that interact with
the Compute service (nova); rules are defined in the /etc/openstackdashboard/nova_policy.json configuration file. RBAC checks allow an administrator to
finely tune a user's access. For example, an administrator might allow end users to view the
complete flavor listing.
B Z #104 19 6 7
Role-based access control (RBAC) checks are now supported for actions calling the
network service; rules are defined in the /etc/openstack-dashboard/neutron_policy.json
configuration file. RBAC checks allow an administrator to finely tune a user's access. For
example, an administrator might prevent end users from creating a subnet or changing a
firewall policy.
B Z #104 19 71
An admin user can now evacuate a compute host using the dashboard. Two tabs now
provide information for hypervisors: 'Hypervisor' and 'Compute Host' (Admin >
Hypervisors). If a host is down, an 'Evacuate Host' action is now visible for it on the
Compute Host tab (providing a modal window to perform the evacuation).
B Z #104 19 86
Support has been added for Block Storage volume backups in the dashboard. Users can
now create, view, delete, and restore volume backups. Note: This functionality is not
displayed by default. To display volume-backup action items, update the /etc/openstackdashboard/local_settings file with: OPENSTACK_CIND ER_FEATURES = { 'enable_backup':
True, } After updating the file, restart the httpd service with 'systemctl restart httpd'.
B Z #104 19 9 1

Red Hat Ent erprise Linux O penSt ack Plat form 6 Release Not es

There was a need to enable/disable Neutron related features based on the extension list
from Neutron and remove Neutron related settings in local_settings.py. Neutron features like
LBaaS, FWaaS or VPNaaS are provided as extensions in Neutron. These features are now
enabled only when they are included in the extension list from Neutron. Also, changed the
default settings of enable_lb/firewall/vpn to True. The default of these settings were set to
False to avoid confusion to users because LB/FW/VPNaaS are optional features in
Neutron. With this change, the corresponding features in Horizon are enabled dynamically,
so it was reasonable to change the default to True. (FWaaS and VPNaaS are currently in
technical preview)
B Z #104 2023
An additional 'Action Log' tab is now available for specific instances (Project > Compute >
Instances > [instance]). The tab lists all actions which have been carried out on that
specific instance. For example, a tenant user can now use the 'Action Log' tab to see who
created or shut down an instance.
B Z #104 2028
With this feature, there is now a widget for managing Glance metadata dictionary. The
admin user is now able to edit properties of images directly under admin/images/edit.
B Z #104 2070
When using OpenStack Networking (neutron) with the dhcp_agent_scheduler extension, it
is now possible to add and remove D HCP agents from networks using the dashboard. This
makes it easier to manage the high availability of D HCP agents for OpenStack Networking.
When logged in as admin and navigating to the Admin Networks panel, a new D HCP
Agents column with the number of agents associated with each network is now visible.
Clicking on a network name displays the network's details together with a new 'D HCP
Agents' table where the admin can add and delete agents.
B Z #104 2113
Need for an interface to allow the user to assign domain role to users. The Identity
D ashboard has been extended to support managing roles and users in different domains.
B Z #104 216 0
The Orchestration service now allows the user to update a stack in a FAILED state.
Previously, failed stacks could only be deleted, not updated.
B Z #104 2271
The Telemetry service now uses the newer oslo.messaging library for RPC, thereby
replacing the deprecated openstack.common.rpc library.
B Z #104 239 6
This enhancement adds high availability for OpenStack Networking (neutron) virtual
routers. This was added due to the impact of virtual routers going down with a network
node; instances would lose external connectivity. Virtual routers can now be created with
the 'High availability' flag, if the administrator sets it as the default. As a result, routers will
then be created on multiple network nodes, with a designated single active instance node.
The active node forwards traffic while the standbys monitor the master. In the event of failure
impacting the active node, one of the standby will take over as the new active node.
B Z #104 259 4

Chapt er 2 . Release Informat ion

With this feature, you can now create and deploy D istributed Virtual Routers (D VR) using
the Open vSwitch (OVS) infrastructure (D VR is currently in Technical Preview).
B Z #104 4 271
With this enhancement, Tenant networks can now be created that use the 'dnsmasq'
process inside the D HCP agent to serve additional configuration to IPv6 D HCP clients,
including addressing and support for IPv6 stateful subnets. Note that the default gateway is
still set by Router Advertisement messages sent by the L3 agent.
B Z #104 4 272
With this enhancement, Tenant networks can now be created that use the 'dnsmasq'
process inside the D HCP agent to serve additional configuration to IPv6 D HCP clients,
including support for IPv6 stateless subnets.
B Z #104 6 786
This enhancement allows the creation of Tenant networks that use the 'radvd' process
within the L3 agent for Router Advertisement messages. As a result, instances are able to
use Stateless Address Autoconfiguration (SLAAC) or D HCPv6 to configure their IPv6
networking.
B Z #104 6 79 0
Extra Specs support for volume types has been added to the dashboard. An admin can
now add additional keys and values to volume types (GUI implementation of the 'cinder
type-key' command). To view extra specs, select Admin> Volumes > Volume Types, and
click the type's 'View Extra Specs' action.
B Z #104 6 800
The code in the glance.store package used to store images into different store backends
has been pulled out into a self-standing library.
B Z #1053088
OpenStack Networking (neutron) has introduced new attributes for IPv6 networks: 'Router
Advertisement' and 'Address Assignment', which enables IPv6 subnets to be configured
with more granularity. If OpenStack Networking is in use and an IPv6 subnet is being
created, the dashboard now offers the following options in the 'IPv6 Address Configuration
Mode' drop-down field: --" SLAAC: Address discovered from Openstack Router" --" D HCPv6
stateful: Address discovered from Openstack D HCP" --" D HCPv6 stateless: Address
discovered from Openstack Router and info from Openstack D HCP" Providing no option
means that addresses are configured manually or by a non-OpenStack system.
B Z #1056 389
The ability for an administrator to manage image metadata (custom properties) has been
added to the dashboard. The admin user can now add, update, or delete image metadata
(implements the 'glance image-update <imageID > --property <key>=<value>' command).
To view or update an image's metadata, select Admin > System > Images, and click the
image's 'Update Metadata' action.
B Z #1057828
Role-based access control (RBAC) checks are now supported for actions that interact with
the Orchestration service (heat); rules are defined in the /etc/openstackdashboard/heat_policy.json configuration file. RBAC checks allow an administrator to
finely tune a user's access. For example, an administrator might prevent end users from

Red Hat Ent erprise Linux O penSt ack Plat form 6 Release Not es

changing a stack template.


B Z #1058578
Add support for D atastores to Horizon (Trove dashboard). Basic support for Trove has
been added to Horizon (Trove dashboard): Added D atastore type/version drop down in
Launch Instance Added D atastore type/version in Instance D etails
B Z #106 2037
With this feature, there is now a separate Identity dashboard.
B Z #106 4 129
The Telemetry service now supports CSV download of daily usage data. In the dashboard,
this feature is available through the 'D ownload CSV summary' button of the Admin >
Overview panel. This button also becomes available after querying usage data.
B Z #107374 0
Keystone now supports domain specific identity backends. This allows for a single
Keystone instance to use multiple identity backends, such as centralized LD AP for normal
users and a Keystone specific SQL database for service users.
B Z #1076 305
MongoD B is still the preferred Telemetry back end for large installations; however, with this
release SQL now features improved read/write processing, which may be suitable for small
installations. This was accomplished through extensive refactoring of the database tables,
query structuring, and optional parallelization of the ceilometer-collector service.
B Z #1076 307
The user can now sort tables by timestamp in the dashboard (a timestamp parser has been
added). For example, in the Project > Compute > Overview window, the user can now sort
instances by 'Time since created'.
B Z #1076 309
Table filtering has been updated in the dashboard to use API query attributes. A drop-down
box and an input field for filtering have been added to tables for admin instances, admin
images, and project instances. For example, the admin instances table might be filtered for
'Status=Active'.
B Z #10786 28
With this release, parameters in HOT templates can now be defined with the type " boolean" .
B Z #108074 3
Code for the Sahara dashboard has been merged into the dashboard (horizon) code. If
Sahara is correctly installed (openstack-sahara) and configured, no further dashboard
configuration is necessary to display the 'D ata Processing' tab for each region (Project >
D ata Processing).
B Z #1081828
This feature improves the workflow of creating a load balancer. You can now create a load
balancer by specifying the IP address and port number.
B Z #1081834

10

Chapt er 2 . Release Informat ion

You can now configure the openstack-cinder-volume service to limit I/O bandwidth when
copying data between volumes. This allows you to throttle the load placed on the
openstack-cinder-volume node for long-running I/O copy operations. To use this feature,
configure the 'volume_copy_blkio_cgroup_name' and 'volume_copy_bps_limit' settings in
/etc/cinder/cinder.conf of the openstack-cinder-volume node accordingly.
B Z #108289 5
The state of an instance provided potentially interesting metrics, particularly to consumers
of polled instance-related metrics. These metrics were already available to pollsters, but
was not included in the resource metadata recorded for the instance in previous releases.
With this release, the current instance state is now included in resource metadata reported
for polled instance-related meters.
B Z #1083057
The systemd script no longer explicitly sets a log file. This ensures that syslog settings take
precedence during logging.
B Z #1084 072
A new feature allows users to download an image's data partially and restart the download
at any time, as long as the image data is available in the server. This has been implemented
using the 'Content-Range' header, which follows the form " Content-Range: bytes
FIRST_BYTE-LAST_BYTE/INSTANCE_BYTES" . This header will be parsed only on
download requests and there is no support on the client library yet. Refer to the HTTP's
specification for more information about the specific forms of this header.
B Z #1084 26 6
The Orchestration service now supports an OS::Nova::ServerGroup resource, which allows
you to apply scheduling constraints (like affinity or anti-affinity) to a group of servers.
B Z #10856 4 5
This enhancement enables ipset kernel groups to be used for matching IP addresses in
iptables security groups. The previous implementation of security groups, which made
intensive use of iptables rules, resulted in an exponential growth of iptables rules in some
cases. Specifically, multiple IP addresses previously needed to be added to the security
groups of each Compute node's network port. As a result of this enhancement, the size of
iptables rules on Compute nodes are significantly reduced, resulting in a performance
increase in accepting new connections.
B Z #1086 06 8
Previously, the Telemetry service always aggregated across all disks associated with an
individual instance, making it impossible to bill for individual volume. This release now
features the ability to gather disk metrics for individual devices. Specifically, the Telemetry
service now supports new per-device disk.device.{read|write}.{requests|bytes} meters, in
addition to the original aggregated disk.{read|write}.{requests|bytes} meters.
B Z #1086 522
Orchestration now supports OS::Sahara::Cluster, OS::Sahara::NodeGroupTemplate, and
OS::Sahara:ClusterTemplate resource types, so that users can manage OpenStack D ata
Processing resources through Orchestration templates.
B Z #1089 125

11

Red Hat Ent erprise Linux O penSt ack Plat form 6 Release Not es

The Telemetry service can now poll for SNMP metrics in a generic way. This allows the
Telemetry service to gather additional SNMP metricts without writing a new pollster for each
new metric.
B Z #109 026 9
OpenStack Compute can now optionally provide a config drive to instances based on a
property on the image in the OpenStack Image service. Previously, Compute configuration
determined whether a config drive was used and what format to use for it. With this update,
users can now indicate config drive requirements using image properties.
B Z #109 074 1
A new rule now makes it possible to restrict an image's downloads by using the built-in
policy engine. This rule (" download_image" : " role:admin or rule:restricted" ) must be added
to the policy.json file to ensure it is effective.
B Z #109 1579
The Orchestration service now features an OS::Glance::Image resource type, which allows
images to be created in the Image service as part of a Heat template.
B Z #109 39 76
A new OS-END POINT-POLICY extension was added to Keystone. This extension allows for
assigning separate policies to specific services or even individual endpoints. Policy
assignment is now more flexible.
B Z #109 5055
A 'Metadata' column has been added to the Flavors table (Admin > System > Flavors) that
displays whether extra specs have been specified for a flavor ('Yes' or 'No'). The user can
now click on either the column value or the 'Update Metadata' action to view or update
defined metadata.
B Z #109 6 56 7
With this release, floating IP addresses created in Orchestration templates can now be
updated in-place to connect to a different server. Previously a change to a template to move
the attached port would result in a new Floating IP being created and the existing one
removed.
B Z #109 7514
In previous releases, every virtual CPU was configured as a socket. Some guest operating
systems have arbitrary limits on the number of sockets they support, but are not limited in
the number of cores or threads. This prevented an instance's OS from taking full advantage
of the virtual CPUs configured. With this release, the Compute service can now control an
instance's virtual CPU topology. This allows an administrator and/or tenant users to
specify constraints for the number of threads, cores and sockets to use for a guest instance.
The Compute service will use the constraint information to configure a suitable guest CPU
topology. With this, a guest OS such as Windows can take full advantage of all virtual
CPUs without encountering support limits.
B Z #109 7517
Need for a feature to enable resetting the state of a volume exposed in the administrator
dashboard. This functionality was available only through the CLI command: # cinder resetstate --state available <volume-id> Exposed the functionality of the 'cinder reset-state'
command in the UI. As is the case with the 'cinder reset-state' command, this change

12

Chapt er 2 . Release Informat ion

permits an operator to select any valid status, regardless of the current status of the volume.
B Z #109 79 89
Previous Compute versions delegated all CPU placement to the operating system kernel.
Although the kernel attempted to keep guest processes running on a single NUMA node,
this was not enforced. This meant that guests could drift across NUMA nodes, resulting in
an inefficient usage of host resources and limiting guest performance. With this update,
Compute can now place guest instances on specific host NUMA nodes. The cloud
administrator or tenant user can set preferences for the guest NUMA topology layout by
enabling a scheduler filter that performs intelligent NUMA placement (affinity server group
using hw:numa_policy=strict metadata). Compute takes into account the guest topology
and then pins the guest instance to one or more host NUMA nodes, resulting in a more
consistent guest performance and efficient use of host resources.
B Z #109 79 9 7
With this feature, administrators can now reset the state of a snapshot.
B Z #1100538
With this release, the Orchestration service now features OS::Heat::SwiftSignal and
OS::Heat::SwiftSignalHandle resource types, which provide an alternate implementation of
WaitConditions that use OpenStack Object Storage to store data.
B Z #1100539
You can now configure a separate storage back end for Telemetry alarms. In previous
releases, alarm-related data could only be stored in the same storage back-end as sample
data. This was inconvenient, as neither the volume nor the nature of these data are similar.
On a different back end, however, different criteria can now be usefully applied when
selecting the appropriate database.
B Z #1101371
With this feature, basic support for Trove was added to Horizon. Management of
incremental backups is now supported.
B Z #1101378
The Block Storage service now allows you to set Consistency Groups. With this, you can
group multiple volumes together as a single entity; this, in turn, allows you to perform
operations on multiple volumes (for example, create snapshots) at once, rather than
individually.
B Z #11034 04
With this enhancement, all tables are now included during the creation of the database
schema. This behavior allows for easier plugin management. Consequently, all OpenStack
Networking (neutron) tables are present in the database after upgrading to Red Hat
Enterprise Linux OpenStack Platform 6.
B Z #110356 0
You can now perform a 'cinder retype' through the dashboard. This allows you to migrate
volumes or to change any volumes setting (that are set from the volume's type) through the
web interface.
B Z #1104 9 24

13

Red Hat Ent erprise Linux O penSt ack Plat form 6 Release Not es

A single guest can now have multiple network interfaces attached to the same logical host
network. Previous versions of OpenStack Compute had an artificial restriction that a single
guest cannot have multiple network interfaces connected to the same host network. There
are, however, some valid use cases where this is required and thus Compute could not
satisfy those use cases. With this update, the tenant user can now set up guest network
interfaces without any restrictions imposed by Compute.
B Z #11054 06
The MongoD B back end can now persist notification payloads, which in turn allows event
processing for Telemetry services configured to use a MongoD B back end. In previous
releases, this functionality was only available through the SQLAlchemy back end, which
was not fully supported in Red Hat Enterprise Linux OpenStack Platform.
B Z #11074 9 1
Functionality for Cinder Quality of Service (QoS) extra specs management such as
maximum IO/seconds (maxIOPS) is now available in the administrator dashboard.
Currently qos specs must be managed via the cinder CLI commands: - cinder-qos-create cinder-qos-delete - cinder-qos-key - cinder-qos-list - cinder-qos-show And their
associations to volume types are handled with the cinder CLI commands: - cinder-qosassociate - cinder-qos-get-association - cinder-qos-disassociate - cinder-qosdisassociate-all
B Z #11079 25
Cinder CLI has a upload-to-image function that supports uploading a volume into glance
as an image - this functionality needs to be made available in Horizon. -It is now possible
to use a glance image as source to create a cinder volume in Horizon.
B Z #11084 36
This enhancement adds MAC address learning management to the D ashboard (horizon).
Users are able to view and toggle the MAC address learning state of a port, in environments
where this feature is supported.
B Z #11089 9 2
The Block Storage scheduler now features a new volume number (count) weigher. This
adds more flexibility in volume scheduling policy, as it allows you to configure volume
distribution based on the number of volumes per back-end (rather than available back-end
space).
B Z #1109 4 09
The description for the 'Create Volume Type' dialogue has been enhanced to make it clear
that creating a type is equivalent to the 'cinder type-create' command. After the volume type
is created, the user can then further define the type by adding extra specs.
B Z #1109 4 20
In Horizon, there's a feature need to automatically populate the " Format" field in the Create
Image modal after the user has filled out the Image Source/Image File fields. Auto populate
the image format field based on the file extension.
B Z #111059 2

14

Chapt er 2 . Release Informat ion

This feature adds a configurable policy for managing SSH host keys, allowing system
administrators to choose how secure they wish their SSH connections to be. As a result,
Cinder can store and verify SSH host keys, increasing security for drivers using SSH
connections.
B Z #11109 88
With this feature, Nova can now take snapshots of network based Cinder volumes.
B Z #11109 9 4
With this release, when retrieving a list of events from the Orchestration API, clients can now
request a paginated list and avoid having to retrieve what may be a very large amount of
data in a single request.
B Z #111256 0
This feature improves the page loading performance when displaying the Project Volumes
page.
B Z #1114 171
This enhancement adds a SMBFS driver to Block Storage (cinder). As a result, Samba and
Windows shares are now able to serve as volume backends.
B Z #11176 08
With this release, the Orchestration API output when showing a stack now includes the
username of the owner of a stack (i.e. the user who created it).
B Z #11176 09
A transformer has been added that allows samples to be derived from primary
measurements associated with different meters. Previously, derived samples could only be
computed within a transformer based on the successive value of primary samples
associated with the same meters. With this update, derived meters can now be constructed
based on arithmetic rules involving multiple primary meters.
B Z #11176 13
Support for Neutron D VR (D istributed Virtual Router) has been implemented in Horizon.
(D VR is currently in Technical Preview) Neutron D VR includes new changes to neutron CLI
specifically in areas of router-creation, router-scheduling, show commands etc., while
adding in admin functionality for distributed virtual router (D VR) functionality to Horizon.
B Z #11189 4 3
Need to be able to disable console access when not accessible from outside a cloudprovider's infrastructure. -A config option added to
/etc/openstack_dashboard/local_settings: CONSOLE_TYPE. Valid options are " AUTO" ,
" VNC" , " SPICE" , " RD P" or None. When it's set to None, console access is disabled.
B Z #11204 85
A new volume driver has been added that supports SMB shares from Windows. The driver
supports Windows Server 2012 (R2 included). Volumes are exported through SMB shares
as disk images (similar flow to the NFS driver).
B Z #112184 3
With this release, Keystone now supports the standard JSON Home document format for API

15

Red Hat Ent erprise Linux O penSt ack Plat form 6 Release Not es

With this release, Keystone now supports the standard JSON Home document format for API
discovery. Keystone's previously supported API discovery response format was a nonstandard JSON document. This format required a client to have Keystone specific
knowledge to understand how to use the response. The JSON Home document format
allows API discovery to use a standardized format, allowing client applications to perform
API discovery across multiple services in a standard way.
B Z #112276 7
The puppet-keystone puppet module now supports deploying Keystone in Apache HTTPD .
B Z #1124 133
Add support for Spark jobs in Sahara data processing UI. Support for Spark ED P jobs in
the data processing dashboard has been added. The changes are: -Added Spark as a job
type when creating jobs -Added some help text for Spark job creation -Hide appropriate
configuration fields when launching a Spark job -Made job type drop down translatable
B Z #112509 3
There was a need to add the ability for admins to create/update/delete custom properties
and metadata for Images. This is useful for admins and users to meaningfully describe
images by sharing key-value pairs and tag metadata. A new " Update metadata" option is
now visible in the Admin Images panel that enables you to custom properties and
metadada for Images.
B Z #11274 05
When using nova-network with multiple networks, it is now possible to set the MTU, enable
or disable D HCP, set the D HCP server, and indicate whether the network shares addresses
with other networks. Previously, it was not possible to set these parameters on a pernetwork basis, making it more difficult to use nova-network with multiple networks. With this
update, administrators now have more flexibility with settings when using multiple networks
with nova-network.
B Z #1127526
In previous releases, the accuracy and timeliness of Telemetry samples could be negatively
impacted if the central agent became overloaded by a large number of resources. To
mitigate this, the Telemetry service now features workload partitioning; this features allows
the central agent to scale horizontally with each instance polling a disjointed set of
resources. To do this, the 'tooz' utility coordinates group membership accross multiple
central agents that share polling of resources.
B Z #112839 8
Need for a feature wherein operators can disable L3 Router features by configuration
options. -New config option 'enable_router' to OPENSTACK_NEUTRON_NETWORK. The
default is True as router feature is enabled in most deployments and it is the current default
behavior of Horizon. If this option is False, Router panel disappears. -Network Topology
panel shows routers in the topology map and also has " Create Router" button. If
" enable_router" is set to False, routers in the topology map are not displayed, and " Create
Router" button is not shown. -'enable_floatingip' option to
OPENSTACK_NEUTRON_NETWORK. Similar to the floating IP feature in Neutron provided
by L3 router extension, if this option is set to False, " Floating IP" tab and
" Associate/D isassociate Floating IP" menu in the instance table are not shown.
B Z #1129 518
This release adds Cinder Consistency Group support for the EMC VNX D irect D river.

16

Chapt er 2 . Release Informat ion

B Z #1130371
With this release, the " heat stack list" command now provides a " --show-nested" option that
includes any nested stacks in the output. Normally, only stacks created directly by the user
appear in the list and nested stacks are omitted.
B Z #1130372
Tooz-driven group membership coordination is now used, which allows multiple ceilometeralarm-evaluator services to share the workload. The group membership-based solution
provides a simple but robust technique for managing workload sharing that is less
problematic than the previous RPC-fanout-based solution. Alarm evaluators can now be
set up on multiple nodes using configuration for individual instances; if an evaluator fails,
its workload is transferred to the other evaluators.
B Z #1130726
With this release, keystone now emits CAD F notifications for role assignment events,
providing a more complete audit trail. Role assignment operations affect a user's access to
cloud resources; keeping an audit trail of these actions can be important to detect
malicious actions.
B Z #113176 8
The Orchestration service now features an OS::Heat::SoftwareD eployments resource, which
can deploy a single SoftwareConfiguration to a group of servers. This is helpful for
deploying a cluster where each server has to be configured with the IP addresses of every
server in the cluster.
B Z #1132103
This feature updates cinderclient so that users are now prompted for a password via the
command line if no password is specified via an environment variable or the --os-password
option.
B Z #1132104
If no password is provided using either --os-password or env[OS_PASSWORD ], pythonglanceclient now falls back to password entry using tty.
B Z #114 9 59 9
With this feature, you can now use Cinder to create a volume by specifying either the image
ID or image name.
B Z #1158170
To allow individual operations such as POST samples API to be selectively configured as
admin-only, this update includes configurable Role-Based Access Control for the
ceilometer API. As a result, individual API operations can now be restricted to admin (or any
other individual role) by adding a rule to the '/etc/ceilometer/policy.json' file of the form:
" telemetry:create_samples" : " rule:context_is_admin"
B Z #116 04 05
RBD snapshots and cloning are now used for Ceph-based ephemeral disk snapshots. With
this update, data is manipulated within the Ceph server, rather than transferred across
nodes, resulting in better snapshotting performance for Ceph.

17

Red Hat Ent erprise Linux O penSt ack Plat form 6 Release Not es

B Z #11779 9 5
This enhancement allows SR-IOV virtual functions (VF) to passthrough to 'flat' project
network types. This is due to PCI passthrough with SR-IOV not being VLAN-specific. As a
result, OpenStack Networking project networks with the " flat" network type can now take
advantage of SR-IOV networking support.
B Z #1180216
Previously, the OS::Heat::ResourceGroup resource in a template failed validation if
configured with size " 0" . Since some template authors use this mechanism to create
optional parts of a template, a size of zero no longer causes a validation failure.
B Z #1180335
With this release, support for specifying a redis-sentinel in the backend URL had been
added. This allows ceilometer fail over between a cluster of redis services, as to avoid the
redis service being a single point of failure. As a result, the tooz client can use a cluster of
redis services as the backend with the sentinel failing over mastership of the cluster as
necessary.
B Z #11806 07
RBD snapshots and cloning are now used for Ceph-based ephemeral disk snapshots. With
this update, data is manipulated within the Ceph server, rather than transferred across
nodes, resulting in better snapshotting performance for Ceph.
B Z #11834 21

OpenStack Sahara enables the fast provisioning and easy management of Hadoop
clusters on OpenStack. Hadoop is used to store and analyze large amounts of data, which
is usually unstructured but can be a combination of both complex and structured data.
OpenStack Sahara is fully supported in this release. For information on how to install
OpenStack Sahara, refer to: https://access.redhat.com/documentation/enUS/Red_Hat_Enterprise_Linux_OpenStack_Platform/6/html/Installation_and_Configuration_Guide/ch
OpenStack_Sahara_Installation.html
B Z #11854 4 4
This update introduces the rabbitmq-cluster resource agent for managing clustered
RabbitMQ instances with the Pacemaker cluster manager.
B Z #1186 070
This enhancement includes a feature, virt-v2v, which allows users the ability to convert
images from a variety of hypervisors to run on OpenStack cloud.

2.2. T echnology Preview


B Z #1100535
Ironic, an OpenStack bare-metal provisioning service, is now included in this release as a
technology preview. This project provisions bare metal machines using common
technologies (such as PXE boot and IPMI) to cover a wide range of hardware, while
supporting pluggable drivers to allow the addition of vendor-specific functionality.
B Z #11834 14
Trove (D atabase-as-a-Service) is included in this release as a Technology Preview. This

18

Chapt er 2 . Release Informat ion

service allows users to quickly and easily utilize the features of a relational or nonrelational database without the burden of administrative overhead. With Trove, users and
database administrators can provision and manage multiple database instances as
needed. For more information about Trove, refer to https://wiki.openstack.org/wiki/Trove.
B Z #119 0788
This release includes a v2 and a v3 version of the OpenStack Compute API. While v2 of the
API is fully supported, v3 is experimental and remains a technology preview.
B Z #119 8508
This release includes D istributed Virtual Routing (D VR) as a technical preview. D VR
enables the placement of L3 Routers across Compute nodes, allowing network traffic to be
directed between them (East-West) without first requiring routing through a Network node.
B Z #119 8855
VPN-as-a-Service (VPNaaS) is included in this release as a Technology Preview. VPNaaS
allows tenants to use VPN features for network connectivity.
B Z #119 8856
The Firewall-as-a-Service (FWaaS) plug-in adds perimeter firewall management to
Networking. FWaaS uses iptables to apply firewall policy to all Networking routers within a
project. FWaaS is currently in technical preview; untested operation is not recommended.
B Z #119 889 7
The OpenD aylight driver for OpenStack Networking is included in this release as a
Technology Preview.

2.3. Release Not es


B Z #1158213
In High Availability environments deployed through the Red Hat Enterprise Linux
OpenStack Platform Installer, SELinux no longer needs to be Permissive on the HA
controller to allow VNC access. A bug that required this in previous releases has since been
fixed.
B Z #89 4 4 4 0
Red Hat OpenStack does not yet fully support being used with ipv6 networking
technologies. Only ipv4 is supported at this time.
B Z #9 75014
In order for Nova's resize command to work when using the libvirt driver and attempting to
resize between nodes (the default resize method), the Nova users on the compute nodes
must have permission to perform passwordless SSH to the other compute nodes. To set this
up, generate SSH keys for the Nova user on each compute node, and then add the
generated keys from the other compute nodes to the ~/authorized_keys file for the Nova user
on each compute node.
B Z #104 2550
This update enables OpenStack Networking (neutron) to create a Provider Network that
uses an upstream device with Router Advertisement multicasts. As a result, instances are
able to use Stateless Address Autoconfiguration (SLAAC) to configure their IPv6

19

Red Hat Ent erprise Linux O penSt ack Plat form 6 Release Not es

able to use Stateless Address Autoconfiguration (SLAAC) to configure their IPv6


networking.
B Z #116 9 4 70
Support for the XML format in the Nova v2 API was deprecated in Red Hat Enterprise Linux
OpenStack Platform 5 and has been removed in Red Hat Enterprise Linux OpenStack
Platform 6. Customers wishing to interact with the Nova v2 API need to use the JSON
format, which has wide OpenStack SD K support.
B Z #1184 6 6 3
The sysfsutils package is now a dependency of the Compute service. This package
provides the Compute service with the ability to attach Block Storage volumes. In previous
releases, sysfsutils was not a hard dependency of the Compute service; this required users
to manually install sysfsutils as well during manual Compute installations. With this
release, installing Compute packages will automatically install sysfsutils as well.

2.4 . Known Issues


B Z #114 19 23
The Red Hat Enterprise Linux OpenStack Platform Installer does not support UEFI booting.
As a result, when attempting to perform a PXE-boot on a UEFI host, the installer will fail to
download the required PXE images. To work around this, switch the host to 'legacy' mode
for PXE booting.
B Z #114 4 034
D uring subnet creation of the Public API, Admin API, and Management networks, the Red
Hat Enterprise Linux OpenStack Platform installer does not validate whether: 1) IPAM is set
to 'D HCP' and boot mode 'dhcp' (provisioning network), or 2) IPAM is set to 'internal db'
and boot mode set to 'static' If IPAM is set to 'internal db', then the range of IP addresses
must be greater than or equal to the number of controllers (3) plus the number of VIPs (1012 depending on which network). Because these settings are not validated, it is possible for
subnets to be created without enough IPs to allocate enough VIPs. In such cases,
generating VIPs could result in puppet errors. To prevent this, you need to manually ensure
that your API subnets (Admin, Public, Management) have enough available IP addresses to
allocate enough VIPs.
B Z #9 9 0073
The Block Storage GlusterFS volume driver configuration does not provide a way to move
a GlusterFS server from one address to another. As a result, attempting to do so will result
in Block Storage using the new address as a new GlusterFS server, while still trying to
access volume data at the old location. Workaround: Update the SQL D B's cinder.volume
table provider_location field to point to the desired location for volumes you are moving.
B Z #116 7073
The SELinux policies for Keystone are missing some enforcement rules for certain
operations. As a result, SELinux will cause keystone to malfunction if SELinux is set to
enforcing mode. Since this is an early release of Red Hat Enterprise Linux OpenStack
Platform 6.0, not all SELinux issues have been found. Red Hat recommends to set SELinux
to permissive mode. For more information on how to enable and disable SELinux, see:
https://access.redhat.com/documentation/enUS/Red_Hat_Enterprise_Linux/7/html/SELinux_Users_and_Administrators_Guide/sectSecurity-Enhanced_Linux-Working_with_SELinux-Enabling_and_D isabling_SELinux.html

20

Chapt er 2 . Release Informat ion

B Z #116 8277
The Red Hat Access plug-in for Red Hat Enterprise Linux OpenStack Platform does not
support Internet Explorer 9. Internet Explorer 9 users attempting to leverage the Red Hat
Access plug-in in Red Hat Enterprise Linux OpenStack Platform will be unsuccessful.
B Z #116 9 135
The Red Hat Access plug-in for Red Hat Enterprise Linux OpenStack Platform does not
support Internet Explorer 9. Internet Explorer 9 users attempting to leverage the Red Hat
Access plug-in in Red Hat Enterprise Linux OpenStack Platform will be unsuccessful.
B Z #116 9 138
Known bugs with Microsoft Internet Explorer 9 Cross Origin Resource Sharing (CORS) will
prevent Internet Explorer 9 users from leveraging the Red Hat Access plug-in for Red Hat
Enterprise Linux OpenStack Platform. There is no workaround other than using a different
browser. The inability to use the Red Hat Access plug-in on Internet Explorer 9 will not affect
the overall functionality of the Horizon dashboard. Only Red Hat Access plug-in features
will be disabled.
B Z #11739 87
In deployments using IPv6 networks with OpenStack Networking, IPv6 subnets do not have
a gateway set. As a result, IPv6 networks do not work as expected.
B Z #1174 215
Stateful D HCPv6 is currently nonfunctional in the Red Hat Enterprise Linux OpenStack
Platform 6 (Juno) GA as a result of upstream bug 1377843. Further details are available at
https://bugs.launchpad.net/neutron/+bug/1377843.
B Z #117536 7
D ue to a missing dependency to python-oslo-utils, python-glanceclient fails to work. As a
current workaround, install both the python-oslo-utils and the python-glanceclient package
at the same time using the following command: yum install -y python-oslo-utils pythonglanceclient
B Z #11776 11
A known issue has been identified for interactions between High Availability (VRRP) routers
and L2 Population. Currently, when connecting a HA router to a subnet, HA routers use a
distributed port by design. Each router has the same port details on each node that it's
scheduled on, and only the master router has IPs configured on that port; all the slaves
have the port without any IPs configured. Consequently, L2Population uses the stale
information to advise that the router is present on the node (which it states in the port
binding information for that port). As a result, each node that has a port on that logical
network has a tunnel created only to the node where the port is presumably bound. In
addition, a forwarding entry is set so that any traffic to that port is sent through the created
tunnel. However, this action may not succeed as there is not guarantee that the master
router is on the node specified in the port binding. Furthermore, in the event that the master
router is in fact on the node, a failover event would cause it to migrate to another node and
result in a loss of connectivity with the router.
B Z #1181307
The python-pbr package required by Red Hat Enterprise Linux OpenStack Platform puppet
modules is not present in Red Hat Enterprise Linux OpenStack Platform 6. Installation
using Packstack will fail if Ironic (a Technology Preview package) is enabled. Manual

21

Red Hat Ent erprise Linux O penSt ack Plat form 6 Release Not es

installation is required for Ironic at the moment.


B Z #11826 4 2
When an overcloud node boots up, it runs os-collect-config as a part of registration. The
os-collect-config script saves data from the Orchestration (heat) metadata API locally and
then calls os-refresh-config any time that metadata has changed. Subsequent calls to the
registration script call subscription-manager again and it returns a non-zero exit code. With
the return of a non-zero exit code, the script fails, the stack results in a timeout, and multiple
registrations can occur. There is no current workaround.
B Z #118309 9
An iptables setting in the undercloud causes overcloud nodes to fail to register since the
nodes have no external access. As a workaround, run the following command on the
undercloud image: iptables -D FORWARD -j REJECT --reject-with icmp-host-prohibited
B Z #1183104
Previous to the Satellite 6 release, the katello-agent and its dependencies needed the rhel7-server-rh-common-beta-rpms repository to be enabled. Since the Satellite 6 release,
necessary packages have been moved to the rhel-7-server-rh-common-rpms repository.
However, upstream code still references the rhel-7-server-rh-common-beta-rpms repository
which no longer have the latest packages, causing Satellite instances to fail.
B Z #119 5252
A quiet dependency on a newer version of selinux-policy causes openstack-selinux 0.6.23
to fail to install modules when paired with selinux-policy packages from Red Hat Enterprise
Linux 7.0 or 7.0.z. This causes Keystone and other OpenStack services to receive 'AVC'
denials under some circumstances, causing them to malfunction. Two workarounds allow
services to function correctly: 1) Leave openstack-selinux at 0.6.18-2.el7ost until you are
ready to update to Red Hat Enterprise Linux 7.1. At that time, a 'yum update' will resolve the
issue. 2) Install the updated selinux-policy and selinux-policy-targeted packages from Red
Hat Enterprise Linux 7.1 (version selinux-policy-3.13.1-23.el7 or later), then update
openstack-selinux to version 0.6.23-1.el7ost.

22

Chapt er 3. Upgrading

Chapter 3. Upgrading
For details on upgrading from a previous version of Red Hat Enterprise Linux OpenStack Platform,
refer to https://access.redhat.com/articles/1317223/. This article also contains links to instructions for
each recommended upgrade method.

23

Red Hat Ent erprise Linux O penSt ack Plat form 6 Release Not es

Revision History
R evisio n 6 .0.1- 1
T h u Mar 05 2015
D o n D o min g o
Updated for first maintenance release of Red Hat Enterprise Linux OpenStack Platform 6.0.
R evisio n 6 .0.0- 5
T u e Mar 03 2015
D o n D o min g o
Added some items relevant to GA release and edited some notes for clarity.
R evisio n 6 .0.0- 4
Wed Feb 11 2015
Release for Red Hat Enterprise Linux OpenStack Platform 6.0.

24

D o n D o min g o

Potrebbero piacerti anche