CloudBees is pleased to announce the newest CloudBees CD/RO long-term support (LTS) release. You can find specific information about this release in the following sections:
Security fixes
The following security fixes and improvements have been made as part of this release:
- Updated
kubectlto address x509 denial-of-Service vulnerability -
Updated the bundled
kubectlbinary in the CloudBees Flow agent image to a Go version containing the fix for a quadratic-complexity denial-of-service vulnerability in x509 hostname verification when processing certificates with large DNS SAN lists.
Feature enhancements
The following feature enhancements have been made as part of this release:
This release has no feature enhancements.
Resolved issues
The following issues have been resolved as part of this release:
- Fixed service inventory report generation failure
-
Fixed an issue in the EC-Helm Report Service Inventory step that could cause the Perl agent to continuously consume memory and be OOM-killed when processing large rendered Helm manifests. The fix improves the handling and serialization of large manifest payloads when writing them to the
/myJob/ec_microservice_deployment_summary/<service>/manifestsCD property, preventing excessive memory consumption and allowing the service inventory step to complete successfully.
- Improved catalog item run form parameter loading performance
-
Fixed an issue where catalog item run form evalutes each parameter’s
optionsDslsequentially, causing load times to increase with the number of parameters. Independent parameters now load their options in parallel for improved performance, while parameters usingdependsOncontinue to resolve sequentially to preserve cascading option behavior.
- Fixed embedded broker I/O failure
-
Fixed an issue where an embedded broker I/O failure could cause the job scheduler to stall, preventing jobs from being scheduled. The embedded broker now automatically recovers from I/O failures without disrupting running jobs.
- Application process steps dispatched to disabled resources
-
Fixed an issue where application process steps running on a Utility Resource could be dispatched to disabled resources. The system now selects an enabled resource from the resource pool when one is available.
- Fixed login redirect loop for legacy Commander pages
-
An issue is fixed where users were redirected to the login page in an endless loop when accessing the legacy Commander pages after signing in through the Flow/Auth UI because the
COMMANDER_SESSION_IDcookie was not set. The cookie is now set automatically after login to a lifetime value based on the server session timeout, eliminating the need to log in separately through/commander/login.php.<br/> Note: For multi-web-node deployments behind a load balancer, enable session affinity (sticky sessions), because PHP sessions are stored on individual nodes.
Known issues
The following issues are included as known issues in this release:
This release has no known issues.
SyncArtifactVersionsprocedure completes with success when it should fail-
SyncArtifactVersionsprocedure completes with success, rather than showing a warning, when manifest is missing andoverwrite = false.
- Automation Platform UI requires artifacts to use English characters in their file names
-
When you use the Automation Platform UI to upload and publish artifact files with non-English characters in their file names, the operation fails with the following error:
Upload file: Exit code 1: ERROR: Publish failure: Unexpected retrieval exception for repository error.
- Must restart server to apply LDAP changes
-
Modifications of LDAP user data (such as email addresses) on an Active Directory server after registration in CloudBees CD/RO do not appear properly in user details (in the Automation Platform UI, the Deploy UI, or
ectool) until the CloudBees CD/RO server is restarted.
- Not all Elasticsearch operations can be performed in a red state
-
(Microsoft Windows platforms only) If the Elasticsearch cluster used by CloudBees Analytics is in the red state (meaning that it only partly functions and some data is unavailable), then upgrade, reconfigure, and uninstall operations will not work. Since the Elasticsearch service cannot be stopped when a cluster is in a red state, you must stop the Elasticsearch service process from the task manager before running the installer for these actions.
- Microsoft Edge® doesn’t support SAML 2.0
-
The Microsoft Edge® browser does not work with SAML 2.0 and is missing a self-signed certificate during redirection from the identity provider to the service provider. Microsoft Edge® is not recommended for sign-in via SAML 2.0.
- LANG environment variable must be set to
en.US.UTF-8 -
The LANG environment variable must be set to
en.US.UTF-8; otherwise, the upgrade fails. Refer to link:https://docs.cloudbees.com/d/kb-360046953992[KBEC-00452 - Error installing CloudBees CD/RO 10.0.x when theLANGenvironment variable is different thanen.US.UTF-8for details.
- Schedules missing configuration do display runtime error prompts
-
Error prompts for runtimes started by a schedule are not visible if the schedule was created with a missing configuration.
- Changing name in Release Dashboard changes stage status color
-
The stage inclusion status in the Release Dashboard changes color after a stage is renamed.
- Steps that cannot access their child steps are not retried
-
If an application process step cannot expand to its child steps (because of an invalid run condition or an invalid formal parameter), then the step is not retried even if it uses
retry on errorerror handling. The job eventually completes with an error.
- Retry count missing from pipeline runtime page
-
The retry count for group tasks or rules using
automated retry on erroris missing from the Pipeline runtime page.
- Email notifications are not supported for complex environment mapping
-
Multiple mapped environments with the same name from different projects are not supported in email notifications.
- Path-to-production view missing from imported project
-
A project import might not include the path-to-production view.
- All subreleases must be present to link to a release
-
All subreleases of a release must appear before the release in the DSL for the release-to-subrelease links to be created.
- CloudBees Analytics report editor doesn’t include search by assignee
-
The ability to search by assignee in a Deployment Report is not available in the CloudBees Analytics report editor.
- Additional Release Command Center configurations for Jira
-
If Release Command Center was set up for Jira for user stories and defects, and the JIRA project name was mapped to the release project name using the field mapping
projectName:releaseProjectName, then before upgrading to 10.0, the field mapping must be updated to mention the actual release project name using the following field mapping format:"release-project-name-in-CloudBees CD/RO":releaseProjectName.
- Approval by email on manual tasks
-
Approval by email on manual tasks should not expect parameters.
ectool exportandectool importshould only be used between same server versions-
If you use the
ectool exportto export your system configuration from a previous release, and then useectool importto import the same configuration to a CloudBees CD/RO 10.0 server, some out-of-the-box content introduced in the releases since the version from which the full export was done, such as new or updated plugins, new catalog items, and persona-based menu items, may be missing in the CloudBees CD/RO server UI. It is recommended to useectool exportandectool importonly between servers at the same version.
- SSO requires additional PHP configuration
-
SSO does not work unless PHP configuration is changed due to a security-related request. As a workaround, change
session.cookie_samesiteto"Strict"in/opt/electriccloud/electriccommander/apache/conf/php.iniand restart the web server.
- No UI to run or review pre-v10.1 triggers
-
CloudBees CD/RO v10.1 introduced new triggers and an updated UI for them. Pre-v10.1 triggers will continue to work but there is no UI to review or run them.
- Legacy definitions and references cause unexpected behavior for full data exports
-
Before using the export command to perform a full data export from the CloudBees CD/RO database, delete any legacy definitions and references to
serviceobjects from applications and releases.
- Reverting changes is not possible for all objects
-
You can only revert changes for high-level design objects such as applications procedures, procedure steps, workflow definitions, and state definitions.
Restarting the CloudBees CD/RO server while new records are created for all tracked objects might take at least as long as an export or import of all projects (10 to 40 minutes for a large project).
- Recursively traversing nested group hierarchies may cause performance issues
-
Enabling Recursively Traverse Group Hierarchy might impact system performance when the LDAP group hierarchy is traversed. The amount of impact varies with the configurations of the CloudBees CD/RO and LDAP servers, the depth of group hierarchy in the LDAP server, and the network latency between the servers. Ensure that your directory provider can handle the additional load for supporting nested group hierarchy traversal.
- Disabling and re-enabling change tracking may cause performance issues
-
System performance might decrease if you disable change tracking at the server level and then re-enable it. Change tracking is enabled by default. For details about using change tracking, refer to change tracking.