Rancher 2.2.5 release, support K8S 1.15

Rancher 2.2.5 was released. Rancher is an open source, enterprise-class Kubernetes platform that can manage all cloud, all suites, all Kubernetes clusters to solve the different production environment infrastructure businesses may face difficulties, improve Kubernetes native UI and usability poor steep learning curve problem.

This version fixes a security vulnerability CVE-2019-13209 recently discovered, the official support Kubernetes 1.14, for the latest Kubernetes 1.15 also provides experimental support, in addition also brought a series of functions and optimization.

Fix CVE: CVE-2019-13209

Rancher 2.2.5 fixes a security vulnerability CVE-2019-13209 newly discovered. The problem was first discovered by Workiva of Matt Belisle and Alex Stevenson and reports, including the affected Rancher version v2.0.0-v2.0.15, v2.1.0-v2.1.10, v2.2.0-v2.2.4. Rancher v1.6 unaffected.

The vulnerability is called "cross-site Websocket hijacking attacks." An attacker can be accessed by Rancher managed by the cluster is the role of attacker / authority. It requires the attacker to log on to the server Rancher, then visit hosted by a third-party developer sites. Once completed, developers will be able to use the victim's rights and identity execute commands on Kubernetes API. For more information presentation .

Rancher 2.2.5 release in the same period, Rancher Labs also released the official Rancher v2.1.11 and v2.0.16, both versions also provide a fix for this vulnerability, available have not been upgraded to Rancher 2.2.x users.

Function and Optimization

  • Officially supported version Kubernetes 1.14

  • Add experimental support for Kubernetes 1.15 version

  • In Kubernetes 1.14 and above clusters, support CoreDNS provider as the default dns

  • In the UI-date information for the public certificate Rancher cluster configuration, and an alarm before the certificate expires 30 days

  • For Rancher directly configure a cluster, support for custom CA snapshot configuration, thereby S3 snapshot service will be trusted inside the signed certificate

  • Added support for Kubernetes v1.13 for EKS cluster

Bug fixes

Rancher refer to the  milestone  for a complete list.

For details, see the announcement .

Download: https://github.com/rancher/rancher/releases

Guess you like

Origin www.oschina.net/news/108294/rancher-2-2-5-released