Update regarding Bionic Stemcells: Production readiness
Marco Voelz
Dear Cloud Foundry community,
End of April is approaching fast so here's your update regarding production readiness of Bionic stemcells.
TL;DR Bionic 0.28 is considered production ready for selected IaaS layers and will be the basis for a 1.x release of the stemcell.
Context We've created a GitHub project providing more transparency and insight into the current community stemcell process: https://github.com/orgs/cloudfoundry/projects/4 Follow this if you're interested in more detailed progress and want to get involved.
What is the current state?
Feedback? Please reply to this mail on the list and/or send us a message in #bosh-bionic on Cloud Foundry slack. Don’t hesitate to DM me or send me a mail if you want to reach out privately.
Warm regards Marco
PS If you're lacking context on what this mail is all about, see https://lists.cloudfoundry.org/g/cf-dev/message/9290 |
|
Thanks Marco for the update and to all contributors for their efforts to reach production readiness for bionic stemcell. I wonder whether the security advisories shared at [1] would in the future similarly be shared with the cloud foundry community for bionic based stemcell vulnerabilities (in addition to the existing current bionic-based rootfs vulnerabilities). On Wed, Apr 28, 2021 at 5:43 PM Marco Voelz via lists.cloudfoundry.org <marco.voelz=sap.com@...> wrote:
|
|
Chip Childers <cchilders@...>
The community's vulnerability management team was just discussing that last week, and I believe plans to coordinate with the Bionic stemcell folks to make that happen. +Paul Warren who has been leading the vuln mgmt team to confirm. Chip Childers Executive Director Cloud Foundry Foundation On Sun, May 2, 2021 at 4:42 PM Guillaume Berche <bercheg@...> wrote:
|
|
Great news, thanks Chip for the update, and thanks to the community's vulnerability management team for their continued work on bionic stemcells vulns. Guillaume. On Mon, May 3, 2021 at 3:31 PM Chip Childers <cchilders@...> wrote:
|
|
Aaron Huber
We have fully tested the 0.28 stemcell using the vSphere CPI with the following deployments/releases and everything appears to be fully functioning:
cf-deployment logsearch-boshrelease logsearch-for-cloudfoundry prometheus-boshrelease We still need a new release of smb-volume-release to fix https://github.com/cloudfoundry/smb-volume-release/issues/16 but I've updated the notes with our temporary work-around and we'll go to production with a dev release for now. Thanks to everyone involved for keeping the open source version of CF secure. Aaron |
|
Chip Childers <cchilders@...>
Awesome to see end user testing results being reported back to the wider community here, and I hope that this inspires others to do the same... :) Many thanks Aaron! Chip Childers Executive Director Cloud Foundry Foundation On Thu, May 6, 2021 at 2:56 PM Aaron Huber <aaron.m.huber@...> wrote: We have fully tested the 0.28 stemcell using the vSphere CPI with the following deployments/releases and everything appears to be fully functioning: |
|