On Aug. 14, 2018, information was released about another set of “speculative execution” issues with Intel microprocessor hardware known as “L1 Terminal Fault”.  As with earlier issues like Spectre and Meltdown, this information was coordinated with the release of updated software solutions to help mitigate the issue.

At the time the embargo was lifted, the OpenShift SRE team worked to begin remediation (detailed below) on all OpenShift Online clusters.  All Pro clusters finished remediation shortly before 18h00 EDT August 14, 2018. All Starter clusters were patched as of 23h30 EDT August 14, 2018.

The work done to remediate included applying the new kernel, disabling Hyper-Threading, and adjusting cluster parameters around CPU allocation and overcommit settings.  These changes may have an impact on overall cluster performance, so we will closely monitor performance and scale up with additional compute nodes as needed.

OpenShift Dedicated customers have been notified separately regarding the remediation of their clusters.

For further information, please refer to:

 

Red Hat OpenShift SRE Security


About the author

Dave Baker has been with Red Hat since 2017.  He's currently working as a Design Architect in the Secure Engineering team within Product Security, and has spent the last years in various security related roles helping to protect Red Hat OpenShift Container Platform and many other products.

Read full bio