Skip to content

release notes: add OSISM 10.3.0 - #1097

Merged
berendt merged 6 commits into
mainfrom
release-notes/10.3.0
Oct 5, 2026
Merged

berendt merged 6 commits into
mainfrom
release-notes/10.3.0

Conversation

@berendt

@berendt berendt commented Oct 1, 2026

Copy link
Copy Markdown
Member

Adds the release notes section for OSISM 10.3.0, generated from the component CHANGELOGs between OSISM 10.2.0 and OSISM 10.3.0.

Generated with generate-release-changelog.sh using claude-sonnet-5. Please review the generated section before merging.

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

✅⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ ACTION actionlint 5 0 0 0.04s
✅ JSON jsonlint 4 0 0 0.09s
✅ JSON prettier 4 0 0 0.36s
✅ JSON v8r 4 0 0 8.79s
✅ MARKDOWN markdownlint 171 0 0 3.49s
✅ MARKDOWN markdown-table-formatter 171 0 0 0.43s
✅ REPOSITORY betterleaks yes no no 0.93s
✅ REPOSITORY checkov yes no no 19.53s
✅ REPOSITORY git_diff yes no no 0.09s
✅ REPOSITORY secretlint yes no no 1.62s
✅ REPOSITORY trufflehog yes no no 4.14s
✅ SPELL codespell 181 0 0 0.76s
⚠️ SPELL lychee 181 1 0 39.32s
✅ YAML prettier 6 0 0 0.55s
✅ YAML v8r 6 0 0 7.39s
✅ YAML yamllint 6 0 0 0.6s

Detailed Issues

⚠️ SPELL / lychee - 1 error
📝 Summary
---------------------
🔍 Total.........1172
🔗 Unique.........884
✅ Successful....1069
⏳ Timeouts.........1
🔀 Redirected.......9
👻 Excluded.......101
❓ Unknown..........0
🚫 Errors...........1
⛔ Unsupported......1

Errors in docs/guides/deploy-guide/metalbox.md
[404] https://github.com/osism/metalbox/blob/main/zuul/vars/container-images-openstack-2024.2.yml (at 83:101) | Rejected status code: 404 Not Found

Errors in docs/release-notes/osism-7.md
[TIMEOUT] https://www.openstack.org/software/openstack-bobcat (at 978:38) | Request timed out

Hint: Followed 9 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,JSON_JSONLINT,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_SECRETLINT,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,SPELL_CODESPELL,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@berendt
berendt force-pushed the release-notes/10.3.0 branch 3 times, most recently from bb1b386 to 72f02c9 Compare October 1, 2026 22:22
@berendt
berendt requested a review from ideaship October 1, 2026 22:22
Comment thread docs/release-notes/osism-10.md Outdated
Generated from the component CHANGELOGs between OSISM 10.2.0 and
OSISM 10.3.0 by scripts/generate-release-changelog.sh in
osism/release.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Christian Berendt <berendt@osism.tech>
@berendt
berendt force-pushed the release-notes/10.3.0 branch from 72f02c9 to 1054267 Compare October 2, 2026 07:32
Comment thread docs/release-notes/osism-10.md
Comment thread docs/release-notes/osism-10.md Outdated
Add a "Security fixes" section to the OSISM 10.3.0 release notes. It
states that the release includes all security fixes known and patched
up to 1 October 2026 and links the advisories that are fixed in
addition to OSISM 10.2.0: OSSA-2026-037 (Keystone), OSSA-2026-038
(Glance) and OSSA-2026-039 (Octavia).

The Kolla images move from 0.20260814.0 in OSISM 10.2.0 to
0.20261001.0 in OSISM 10.3.0. The fixes for these three advisories
landed in osism/container-images-kolla between those two tags; the
advisories up to OSSA-2026-034 were already part of OSISM 10.2.0.

Also note that image overrides pointing at the rolling tags should be
removed when upgrading, so the images pinned by the release are used
again.

Assisted-by: Claude:claude-fable-5-1
Signed-off-by: Christian Berendt <berendt@osism.tech>
The hostname check runs during bootstrap, outside of kolla-ansible,
so hostname_split_accepted belongs in environments/configuration.yml
and not in environments/kolla/configuration.yml. Apply the review
suggestion on the OSISM 10.3.0 release notes accordingly.

Assisted-by: Claude:claude-fable-5-1
Signed-off-by: Christian Berendt <berendt@osism.tech>
@berendt
berendt requested review from ideaship and jklare October 2, 2026 09:12
Comment thread docs/release-notes/osism-10.md Outdated
The SONiC validation improvements, the baremetal cleaning RAID modes
and the netbox-manager changes are only relevant for the MetalBox and
the OSISM Manager running on it. Listed between the general changes,
they read as new functionality of an OSISM Manager that is used to
deploy an OpenStack environment.

Move them into a dedicated MetalBox section at the end of the OSISM
10.3.0 release notes and state that these changes only affect the
MetalBox, as suggested in the review.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Christian Berendt <berendt@osism.tech>
The deprecation notice of the hardening play still claimed that the
ansible-hardening role does not work reliably with Ubuntu 24.04. That
is no longer true: since osism-ansible 0.20260811.0 (OSISM 10.2.0) the
image patches the role to create the privilege separation directory
before validating sshd_config (osism/container-image-osism-ansible#765).
On Ubuntu 24.04 ssh.service is socket-activated and often stopped, so
/run/sshd was missing and the validation failed intermittently.

Keep the deprecation, but describe the former problem and the fix
instead. Also make the related OSISM 10.2.0 entry name the hardening
play and Ubuntu 24.04, so it can be connected to the deprecation.

Nothing changed for the hardening role between OSISM 10.2.0 and
10.3.0: the role pin is the same and osism-ansible got no further
hardening patches.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Christian Berendt <berendt@osism.tech>
Comment thread docs/release-notes/osism-10.md Outdated
The collections only deploy valkey instead of redis from OpenStack
2025.2 on. OSISM 10 is based on OpenStack 2025.1, so the change has
no effect there and does not belong in the OSISM 10.3.0 notes.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Christian Berendt <berendt@osism.tech>
@berendt
berendt merged commit 1d367a7 into main Oct 5, 2026
3 checks passed
@berendt
berendt deleted the release-notes/10.3.0 branch October 5, 2026 08:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

4 participants