This message was deleted.
# general
a
This message was deleted.
g
nginx fixes will go into the October releases (v1.26.10+rke2r1) and it will be made available in Rancher as well and you’ll be able to upgrade. I would recommend against downgrading — it’s just a cosmetics issue since technically v1.26.9+rke2r1 isn’t available in Rancher like you said
b
Thanks. I'll wait for 1.26.10 then. Even though it's cosmetic, it should not display a lower version than the actually installed one. I know that a downgrade is not supported, but I wonder what happens if I choose this version (I should try with a test rancher). If it's harmful, this is an issue and should be fixed. Is this worth an issue on github?
g
Yes it is!
b
Ok. I'll create an issue for that..
RKE2 1.26.10 is out for 3 days now... but it's still not available in Rancher, not in Rancher 2.7.6, not in Rancher 2.7.9 (no suprise, it using the same rke-metadata-config). So how long do we need to wait for the new versions to become available?
It's 2 weeks now and still the latest rke2 version in Rancher is 1.26.8. 1.26.10 is also available for >1week, and still not promoted. Do you guys really call this "CVE management"? Just a hint: It's not.
g
v1.26.10+rke2r*1* was released more than a week ago. Before that was made available via the rancher UI, we decided to release v1.26.10+rke2r*2* for a separate reason. That came out on Thursday, and is going to be made available via the rancher UI early this week. You’re more than welcome to upgrade to either of those versions though by using the
Edit as YAML
option in the UI and putting in the version you want. The issue here sounds like just delays in the dependency chain: upstream/cve release --> rke2 release --> rancher ui release
b
Thanks, but I won't update immediately because of https://github.com/rancher/rancher/issues/43331 . I prefer to have the choice to edit my cluster parameters.