Release Team Meeting 2024-11-13

Present: @ekohl (chair), @iballou, @ColeHiggins2, @qcjames53, @Odilhao

I took over last minute from @pcreech so there was no agenda.

Foreman nightly

RHEL 9.5 has been released and we rebuilt foreman-selinux so that now requires a very new selinux-policy package. At least AlmaLinux is still on 9.4 so that can’t be satisfied (see Foreman-nightly-rpm-pipeline 2508 failed - #2 by ekohl). In the short term we’ve disabled AlmaLinux in our pipelines (disable Almalinux for nightly until 9.5 is out by evgeni · Pull Request #508 · theforeman/jenkins-jobs · GitHub). It also means nightly is currently uninstallable on some EL versions.

In addition to that, RHEL 9.5 changed the default Java to OpenJDK 17. This was decided very late and didn’t land in CentOS Stream yet, which means we were caught by surprise. Fixes #38010 - Include keyalg in keytool for OpenJDK 17 · theforeman/puppet-certs@dc0f12e · GitHub is needed for compatibility. This issue affects all existing Katello installations running on RHEL 9 and we can expect other EL distros to be affected in the short term as well.

Foreman 3.13

  • Technically already released, still working on release notes. @ekohl will write up the Debian 11 deprecation.
  • We discussed releasing RC2 early because of the OpenJDK 17 change, but decided against it and follow the regular scheme (which is next Tuesday). This means we can’t work on RHEL 9.5, but because of the SELinux changes it’d mean we become incompatible with some other versions. There’s a decent chance that’s no longer an issue next week.

Foreman 3.12

  • We want to release 3.12.1 release with a fix for CVE-2024-8553 but the aforementioned RHEL 9.5 issues complicate this a bit.
  • Short term we’ll at least get it ready (3.12.1 release TODO - Foreman) and see what the selinux-policy on EL9 situation is.

Foreman 3.11

This has the same issues as 3.12: we want to do a 3.11.4 release with a fix for CVE-2024-8553 but it’s behind 3.12.1 in the queue.

Katello 4.15

Katello 4.14

1 Like