Compare commits

...
Author SHA1 Message Date
Lucas Saintarbor 20fab76cfc Update CVE pages (#2174) 2026-01-29 15:43:33 -08:00
a94f94128a Merge release v2.13.2 to main (#2164)
* Sync changes from main to v2.13.2 (#2156)

* Fixed links to images

* Added documentation for using the keywords option in Chart.yaml

* Sync Product PR #587 (Add ec2:DescribeAvailabilityZones to control plane and etcd/worker permissions)

* Revert image link change, it would break the docs website

* Fixed some typos and backported docs

---------

Co-authored-by: mschroeder-fzj <m.schroeder@fz-juelich.de>
Co-authored-by: Billy Tat <btat@suse.com>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>

* v2.13.2 - Rancher Manager Release Maintenance (#2160)

* Update the versions table

* Update the Rancher:webhook version mapping table

* Update the CSP adapter compatibility matrix

* Update the deprecated features table

* Update release date (#2171)

---------

Co-authored-by: mschroeder-fzj <m.schroeder@fz-juelich.de>
Co-authored-by: Billy Tat <btat@suse.com>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>
2026-01-29 12:58:11 -08:00
5b60dca51d Merge release v2.12.6 to main (#2163)
* Sync changes from main to v2.12.6 (#2155)

* Fixed links to images

* Added documentation for using the keywords option in Chart.yaml

* Sync Product PR #587 (Add ec2:DescribeAvailabilityZones to control plane and etcd/worker permissions)

* Revert image link change, it would break the docs website

* Fixed some typos and backported docs

---------

Co-authored-by: mschroeder-fzj <m.schroeder@fz-juelich.de>
Co-authored-by: Billy Tat <btat@suse.com>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>

* v2.12.6 - Rancher Manager Release Maintenance (#2159)

* Update the versions table

* Update the Rancher:webhook version mapping table

* Update the CSP adapter compatibility matrix

* Update the deprecated features table

* Update release date (#2170)

---------

Co-authored-by: mschroeder-fzj <m.schroeder@fz-juelich.de>
Co-authored-by: Billy Tat <btat@suse.com>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>
2026-01-29 12:57:59 -08:00
78f538b5c3 Merge release v2.11.10 to main (#2162)
* Sync changes from main to v2.11.10 (#2154)

* Fixed links to images

* Added documentation for using the keywords option in Chart.yaml

* Sync Product PR #587 (Add ec2:DescribeAvailabilityZones to control plane and etcd/worker permissions)

* Revert image link change, it would break the docs website

* Fixed some typos and backported docs

---------

Co-authored-by: mschroeder-fzj <m.schroeder@fz-juelich.de>
Co-authored-by: Billy Tat <btat@suse.com>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>

* v2.11.10 - Rancher Manager Release Maintenance (#2158)

* Update the versions table

* Update the Rancher:webhook version mapping table

* Update the CSP adapter compatibility matrix

* Update the deprecated features table

* Update release date (#2169)

---------

Co-authored-by: mschroeder-fzj <m.schroeder@fz-juelich.de>
Co-authored-by: Billy Tat <btat@suse.com>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>
2026-01-29 12:57:48 -08:00
b6a5fcc2af Merge release v2.10.11 to main (#2173)
* Sync changes from main to v2.10.11 (#2153)

* Fixed links to images

* Added documentation for using the keywords option in Chart.yaml

* Sync Product PR #587 (Add ec2:DescribeAvailabilityZones to control plane and etcd/worker permissions)

* Revert image link change, it would break the docs website

* Fixed some typos and backported docs

---------

Co-authored-by: mschroeder-fzj <m.schroeder@fz-juelich.de>
Co-authored-by: Billy Tat <btat@suse.com>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>

* v2.10.11 - Rancher Manager Release Maintenance (#2157)

* Update the Rancher:webhook version mapping table

* Update the CNI popularity table

* Update the versions table

* Update the CSP adapter compatibility matrix

* Update the deprecated features table

* Update release date (#2168)

---------

Co-authored-by: Lucas Saintarbor <lucas.saintarbor@suse.com>
Co-authored-by: mschroeder-fzj <m.schroeder@fz-juelich.de>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>
2026-01-29 12:57:36 -08:00
Petr Kovar ab234cc365 Merge pull request #2113 from mschroeder-fzj/main
Creating Apps: Added doc for `keywords`
2026-01-27 16:26:47 +01:00
Marcel Schröder 6dc122f0f9 Fixed some typos and backported docs 2026-01-26 07:27:35 +01:00
Marcel Schröder 2c2d1fd70c Revert image link change, it would break the docs website 2026-01-26 07:14:59 +01:00
mschroeder-fzj 385a493e52 Merge branch 'rancher:main' into main 2026-01-26 07:03:54 +01:00
Billy Tat d870a1a12a Merge pull request #2148 from btat/product-sync/pr587-ec2-permissions
Sync Product PR #587 (Add ec2:DescribeAvailabilityZones to control plane and etcd/worker permissions)
2026-01-23 09:48:39 -08:00
Petr Kovar 3d9908ed90 Merge branch 'main' into main 2026-01-20 16:26:50 +01:00
Billy Tat be7c002fc6 Merge pull request #2150 from rancher/revert-2146-add-fossa-workflow
Revert "Add FOSSA scanning workflow"
2026-01-16 13:45:09 -08:00
Billy Tat c5aac3c2ea Revert "Add FOSSA scanning workflow" 2026-01-16 13:10:12 -08:00
Billy Tat 2a925479f5 Sync Product PR #587 (Add ec2:DescribeAvailabilityZones to control plane and etcd/worker permissions) 2026-01-15 16:14:25 -08:00
Sunil Singh 3db5dcfe5b Merge pull request #2146 from macedogm/add-fossa-workflow
Add FOSSA scanning workflow
2026-01-14 08:34:53 -08:00
Guilherme Macedo 493918ef4b Add FOSSA scanning workflow
Signed-off-by: Guilherme Macedo <guilherme@gmacedo.com>
2026-01-13 23:08:44 -03:00
Billy Tat b9dc7cf45f Merge pull request #2117 from axeal/patch-2
Clarify JSON array format for OIDC groups and full_group_path claims
2026-01-13 15:56:16 -08:00
Billy Tat 50a89fceea Apply to other versions 2026-01-13 15:22:44 -08:00
Alex Seymour c13e9c7023 Clarify JSON array format for OIDC groups and full_group_path claims
Clarify JSON array format for OIDC groups and full_group_path claims, after a recent case where an issue occurred as a result of the groups claim formatted as a comma-separated string
2026-01-13 15:15:41 -08:00
Billy Tat 86ce745693 Merge pull request #2139 from btat/copyright
Bump copyright year
2026-01-12 16:24:10 -08:00
Billy Tat ea4b542e49 Bump copyright year 2026-01-12 15:02:56 -08:00
mschroeder-fzj 5519e07a14 Merge branch 'rancher:main' into main 2026-01-12 09:29:20 +01:00
Petr Kovar 607605ef8c Merge pull request #2119 from rancher/copilot/update-deprecation-policy-links
Fix deprecated deprecation policy link in FAQ
2026-01-08 20:35:04 +01:00
Petr Kovar 6c6d269350 Merge branch 'main' into copilot/update-deprecation-policy-links 2026-01-08 20:00:00 +01:00
mschroeder-fzj 4bb5fd9918 Merge branch 'rancher:main' into main 2026-01-05 11:42:24 +01:00
Billy Tat 1db0a99873 Merge pull request #2133 from btat/fix-checkmark
Fix checkmark entity
2025-12-30 09:21:16 -08:00
Billy Tat 613ac34951 Fix checkmark entity 2025-12-30 08:29:25 -08:00
Billy Tat 8d0683cf27 Merge pull request #2130 from jmeza-xyz/etcd-tuning-fix-typo
[docs] etcd tuning fix typo etcd-args
2025-12-19 16:18:50 -08:00
Sunil Singh 8c8388e576 Merge pull request #2131 from sunilarjun/v2.13.1-registry-note
Adding admonition for registry issue v2.13.1
2025-12-19 15:13:48 -08:00
Sunil Singh 8b903fb7e6 Adding admonition for registry issue v2.13.1
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-12-19 14:37:40 -08:00
Meza e4ef173aef [docs] etcd tuning fix typos etcd-args
Signed-off-by: Meza <meza-xyz@proton.me>
2025-12-19 15:39:32 -05:00
Meza 941e23dbc5 [docs] Update etcd tuning with incorrect RKE1 references (#2128)
* [docs] Update etcd tuning with incorrect RKE1 references

Signed-off-by: Meza <meza-xyz@proton.me>

* Update versioned 2.12/2.13 and zh docs

Signed-off-by: Meza <meza-xyz@proton.me>

* Updated zh current doc

Signed-off-by: Meza <meza-xyz@proton.me>

---------

Signed-off-by: Meza <meza-xyz@proton.me>
2025-12-19 10:21:40 -08:00
Silvio Moioli 7aabf39e2c Merge branch 'main' into copilot/update-deprecation-policy-links 2025-12-16 08:57:52 +01:00
copilot-swe-agent[bot]andmoio d5155ccdee Update deprecation policy links to SUSE Rancher Prime page
Co-authored-by: moio <250541+moio@users.noreply.github.com>
2025-12-12 09:29:25 +00:00
copilot-swe-agent[bot] 8e43347812 Initial plan 2025-12-12 09:25:21 +00:00
mschroeder-fzj d8c3493599 Merge branch 'rancher:main' into main 2025-12-09 08:14:00 +01:00
mschroeder-fzj 3eb8905153 Added documentation for using the keywords option in Chart.yaml 2025-11-27 09:36:51 +01:00
mschroeder-fzj 66a6f2019d Fixed links to images 2025-11-27 09:36:16 +01:00
78 changed files with 871 additions and 603 deletions
+1 -1
View File
@@ -93,7 +93,7 @@ Subsequent executions will check for updated dependencies, if there are none, it
License License
======= =======
Copyright (c) 2014-2025 [SUSE, LLC.](https://www.suse.com/) Copyright (c) 2014-2026 [SUSE, LLC.](https://www.suse.com/)
Licensed under the Apache License, Version 2.0 (the "License"); Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License. you may not use this file except in compliance with the License.
+2 -1
View File
@@ -8,7 +8,7 @@ title: Deprecated Features in Rancher
## What is Rancher's deprecation policy? ## What is Rancher's deprecation policy?
We have published our official deprecation policy in the support [terms of service](https://rancher.com/support-maintenance-terms). The community version of Rancher follows the same deprecation policy as Rancher Prime. The official deprecation policy is documented in the [Rancher Prime Deprecation Policy](https://www.suse.com/support/rancher-prime/#Rancher-Prime-Deprecation-Policy).
## Where can I find out which features have been deprecated in Rancher? ## Where can I find out which features have been deprecated in Rancher?
@@ -16,6 +16,7 @@ Rancher will publish deprecated features as part of the [release notes](https://
| Patch Version | Release Date | | Patch Version | Release Date |
|---------------|---------------| |---------------|---------------|
| [2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2) | January 29, 2026 |
| [2.13.1](https://github.com/rancher/rancher/releases/tag/v2.13.1) | December 18, 2025 | | [2.13.1](https://github.com/rancher/rancher/releases/tag/v2.13.1) | December 18, 2025 |
| [2.13.0](https://github.com/rancher/rancher/releases/tag/v2.13.0) | November 25, 2025 | | [2.13.0](https://github.com/rancher/rancher/releases/tag/v2.13.0) | November 25, 2025 |
@@ -50,6 +50,38 @@ The following CLI tools are required for setting up the Kubernetes cluster. Plea
## Install the Rancher Helm Chart ## Install the Rancher Helm Chart
:::important
**Important:** In Rancher Community v2.13.1 if your registry configuration is one of the following you may see Rancher generate the `cattle-cluster-agent` image with an incorrect `docker.io` path segment:
- Environments where a **cluster-scoped container registry** is configured for system images.
- Environments where a **global `system-default-registry`** is configured (e.g. airgap setups), even if no cluster-scoped registry is set.
**Workaround for Affected Setups:** As a workaround, override the `cattle-cluster-agent` image via the `CATTLE_AGENT_IMAGE` environment variable. This value must **not** contain any registry prefix (Rancher will handle that automatically). It should be set only to the repository and tag, for example:`rancher/rancher-agent:v2.13.1`
**Helm `install` example:**
```bash
helm install rancher rancher-latest/rancher \
...
--set extraEnv[0].name=CATTLE_AGENT_IMAGE \
--set extraEnv[0].value=rancher/rancher-agent:v2.13.1
```
**Helm `upgrade` example:**
```bash
helm upgrade rancher rancher-latest/rancher \
...
--set extraEnv[0].name=CATTLE_AGENT_IMAGE \
--set extraEnv[0].value=rancher/rancher-agent:v2.13.1
```
**Important Upgrade Note:**
The `CATTLE_AGENT_IMAGE` override is intended only as a temporary workaround for the affected configurations. Once a Rancher version is available that corrects this behavior, the `CATTLE_AGENT_IMAGE` override should be **removed** from Helm values, so that Rancher can resume managing the agent image normally and automatically track future image and tag changes. See [#53187](https://github.com/rancher/rancher/issues/53187#issuecomment-3676484603) for further information.
:::
Rancher is installed using the [Helm](https://helm.sh/) package manager for Kubernetes. Helm charts provide templating syntax for Kubernetes YAML manifest documents. With Helm, we can create configurable deployments instead of just using static files. Rancher is installed using the [Helm](https://helm.sh/) package manager for Kubernetes. Helm charts provide templating syntax for Kubernetes YAML manifest documents. With Helm, we can create configurable deployments instead of just using static files.
For systems without direct internet access, see [Air Gap: Kubernetes install](../other-installation-methods/air-gapped-helm-cli-install/install-rancher-ha.md). For systems without direct internet access, see [Air Gap: Kubernetes install](../other-installation-methods/air-gapped-helm-cli-install/install-rancher-ha.md).
@@ -28,6 +28,38 @@ Note that upgrades _to_ or _from_ any chart in the [rancher-alpha repository](..
### Helm Version ### Helm Version
:::important
**Important:** In Rancher Community v2.13.1 if your registry configuration is one of the following you may see Rancher generate the `cattle-cluster-agent` image with an incorrect `docker.io` path segment:
- Environments where a **cluster-scoped container registry** is configured for system images.
- Environments where a **global `system-default-registry`** is configured (e.g. airgap setups), even if no cluster-scoped registry is set.
**Workaround for Affected Setups:** As a workaround, override the `cattle-cluster-agent` image via the `CATTLE_AGENT_IMAGE` environment variable. This value must **not** contain any registry prefix (Rancher will handle that automatically). It should be set only to the repository and tag, for example:`rancher/rancher-agent:v2.13.1`
**Helm `install` example:**
```bash
helm install rancher rancher-latest/rancher \
...
--set extraEnv[0].name=CATTLE_AGENT_IMAGE \
--set extraEnv[0].value=rancher/rancher-agent:v2.13.1
```
**Helm `upgrade` example:**
```bash
helm upgrade rancher rancher-latest/rancher \
...
--set extraEnv[0].name=CATTLE_AGENT_IMAGE \
--set extraEnv[0].value=rancher/rancher-agent:v2.13.1
```
**Important Upgrade Note:**
The `CATTLE_AGENT_IMAGE` override is intended only as a temporary workaround for the affected configurations. Once a Rancher version is available that corrects this behavior, the `CATTLE_AGENT_IMAGE` override should be **removed** from Helm values, so that Rancher can resume managing the agent image normally and automatically track future image and tag changes. See [#53187](https://github.com/rancher/rancher/issues/53187#issuecomment-3676484603) for further information.
:::
The upgrade instructions assume you are using Helm 3. The upgrade instructions assume you are using Helm 3.
<DeprecationHelm2 /> <DeprecationHelm2 />
@@ -15,10 +15,8 @@ The etcd data set is automatically cleaned up on a five-minute interval by Kuber
```yaml ```yaml
# RKE2/K3s config.yaml # RKE2/K3s config.yaml
--- ---
services: etcd-arg:
etcd: - "quota-backend-bytes=5368709120"
extra_args:
quota-backend-bytes: 5368709120
``` ```
## Scaling etcd Disk Performance ## Scaling etcd Disk Performance
@@ -32,12 +30,7 @@ To implement this solution in an RKE2/K3s cluster, the `/var/lib/etcd/data` and
```yaml ```yaml
# RKE2/K3s config.yaml # RKE2/K3s config.yaml
--- ---
services: etcd-arg:
etcd: - "data-dir=/var/lib/etcd/data"
extra_args: - "wal-dir=/var/lib/etcd/wal"
data-dir: '/var/lib/rancher/etcd/data/'
wal-dir: '/var/lib/rancher/etcd/wal/wal_dir'
extra_binds:
- '/var/lib/etcd/data:/var/lib/rancher/etcd/data'
- '/var/lib/etcd/wal:/var/lib/rancher/etcd/wal'
``` ```
@@ -35,6 +35,12 @@ In your IdP, create a new client with the settings below:
In the new OIDC client, create mappers to expose the user's fields. In the new OIDC client, create mappers to expose the user's fields.
:::note
The `groups` and `full_group_path` claims generated by the Groups and Group Path mappers, which you create within the OIDC client in your Identity Provider, should be JSON arrays, e.g. `"groups":["admins","devs","qa"]` and `"full_group_path":["/admins","/devs","/qa"]`.
:::
1. Create a new `Groups Mapper` with the settings below: 1. Create a new `Groups Mapper` with the settings below:
Setting | Value Setting | Value
@@ -153,4 +159,4 @@ In some cases, the "Invalid grant_type" error message may be misleading and is a
## Configuring OIDC Single Logout (SLO) ## Configuring OIDC Single Logout (SLO)
<ConfigureSLOOidc /> <ConfigureSLOOidc />
@@ -66,7 +66,8 @@ Before you create your own custom catalog, you should have a basic understanding
![values.yaml](/img/helm-app-2.6.png) ![values.yaml](/img/helm-app-2.6.png)
### Chart.yaml annotations ### Chart.yaml
#### Annotations
Rancher supports additional annotations that you can add to the `Chart.yaml` file. These annotations allow you to define application dependencies or configure additional UI defaults: Rancher supports additional annotations that you can add to the `Chart.yaml` file. These annotations allow you to define application dependencies or configure additional UI defaults:
@@ -76,10 +77,14 @@ Rancher supports additional annotations that you can add to the `Chart.yaml` fil
| catalog.cattle.io/display-name | A display name that should be displayed in the App Marketplace instead of the chart name | Display Name of Chart | | catalog.cattle.io/display-name | A display name that should be displayed in the App Marketplace instead of the chart name | Display Name of Chart |
| catalog.cattle.io/namespace | A fixed namespace where the chart should be deployed in. If set, this can't be changed by the user | fixed-namespace | | catalog.cattle.io/namespace | A fixed namespace where the chart should be deployed in. If set, this can't be changed by the user | fixed-namespace |
| catalog.cattle.io/release-name | A fixed release name for the Helm installation. If set, this can't be changed by the user | fixed-release-name | | catalog.cattle.io/release-name | A fixed release name for the Helm installation. If set, this can't be changed by the user | fixed-release-name |
| catalog.cattle.io/requests-cpu | Total amount of CPU that should be unreserverd in the cluster. If less CPU is available, a warning will be shown | 2000m | | catalog.cattle.io/requests-cpu | Total amount of CPU that should be unreserved in the cluster. If less CPU is available, a warning will be shown | 2000m |
| catalog.cattle.io/requests-memory | Total amount of memory that should be unreserverd in the cluster. If less memory is available, a warning will be shown | 2Gi | | catalog.cattle.io/requests-memory | Total amount of memory that should be unreserved in the cluster. If less memory is available, a warning will be shown | 2Gi |
| catalog.cattle.io/os | Restricts the OS where this chart can be installed. Possible values: `linux`, `windows`. Default: no restriction | linux | | catalog.cattle.io/os | Restricts the OS where this chart can be installed. Possible values: `linux`, `windows`. Default: no restriction | linux |
### Keywords
With the `keywords` option in the `Chart.yaml` file it is possible to provide a list of categories for sorting your application in the Rancher UI, like `infrastructure`, `monitoring` and more.
### questions.yml ### questions.yml
Inside the `questions.yml`, most of the content will be around the questions to ask the end user, but there are some additional fields that can be set in this file. Inside the `questions.yml`, most of the content will be around the questions to ask the end user, but there are some additional fields that can be set in this file.
@@ -54,6 +54,7 @@ IAM Policy for nodes with the `controlplane` role:
"autoscaling:DescribeTags", "autoscaling:DescribeTags",
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeAvailabilityZones",
"ec2:DescribeRouteTables", "ec2:DescribeRouteTables",
"ec2:DescribeSecurityGroups", "ec2:DescribeSecurityGroups",
"ec2:DescribeSubnets", "ec2:DescribeSubnets",
@@ -123,6 +124,7 @@ IAM policy for nodes with the `etcd` or `worker` role:
"Action": [ "Action": [
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeAvailabilityZones",
"ecr:GetAuthorizationToken", "ecr:GetAuthorizationToken",
"ecr:BatchCheckLayerAvailability", "ecr:BatchCheckLayerAvailability",
"ecr:GetDownloadUrlForLayer", "ecr:GetDownloadUrlForLayer",
@@ -19,6 +19,7 @@ In order to deploy and run the adapter successfully, you need to ensure its vers
| Rancher Version | Adapter Version | | Rancher Version | Adapter Version |
|-----------------|------------------| |-----------------|------------------|
| v2.13.2 | 108.0.0+up8.0.0 |
| v2.13.1 | 108.0.0+up8.0.0 | | v2.13.1 | 108.0.0+up8.0.0 |
| v2.13.0 | 108.0.0+up8.0.0 | | v2.13.0 | 108.0.0+up8.0.0 |
@@ -10,6 +10,8 @@ Rancher is committed to informing the community of security issues in our produc
| ID | Description | Date | Resolution | | ID | Description | Date | Resolution |
|----|-------------|------|------------| |----|-------------|------|------------|
| [CVE-2025-62879](https://github.com/rancher/backup-restore-operator/security/advisories/GHSA-wj3p-5h3x-c74q) | Rancher now provides new versions of the Rancher Backup chart which prevent the leak of secret S3 credentials via the Rancher Backup pod log. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2025-67601](https://github.com/rancher/rancher/security/advisories/GHSA-mc24-7m59-4q5p) | Rancher now removes the ability to fetch CA certificates stored in Rancher’s setting `cacerts` when using the `login` command. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2023-32199](https://github.com/rancher/rancher/security/advisories/GHSA-j4vr-pcmw-hx59) | Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation `authz.cluster.cattle.io/admin-globalrole-missing=true`. | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) and [v2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) | | [CVE-2023-32199](https://github.com/rancher/rancher/security/advisories/GHSA-j4vr-pcmw-hx59) | Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation `authz.cluster.cattle.io/admin-globalrole-missing=true`. | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) and [v2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) |
| [CVE-2024-58269](https://github.com/rancher/rancher/security/advisories/GHSA-mw39-9qc2-f7mg) | The Rancher audit log redaction process has changed to the following: <br/><br/><ul><li> It now redacts `kubectl.kubernetes.io/last-applied-configuration` annotations on both Response and Request body contents. Previously it did not redact Response body content.</li><li> It now redacts Cluster Import URLs on both Request URLs and Referer headers. Previously it did not redact Referer headers.</li></ul> | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) | | [CVE-2024-58269](https://github.com/rancher/rancher/security/advisories/GHSA-mw39-9qc2-f7mg) | The Rancher audit log redaction process has changed to the following: <br/><br/><ul><li> It now redacts `kubectl.kubernetes.io/last-applied-configuration` annotations on both Response and Request body contents. Previously it did not redact Response body content.</li><li> It now redacts Cluster Import URLs on both Request URLs and Referer headers. Previously it did not redact Referer headers.</li></ul> | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) |
| [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) | | [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) |
+1
View File
@@ -20,6 +20,7 @@ Each Rancher version is designed to be compatible with a single version of the w
| Rancher Version | Webhook Version | Availability in Prime | Availability in Community | | Rancher Version | Webhook Version | Availability in Prime | Availability in Community |
|-----------------|-----------------|-----------------------|---------------------------| |-----------------|-----------------|-----------------------|---------------------------|
| v2.13.2 | v0.9.2 | &check; | &check; |
| v2.13.1 | v0.9.1 | &check; | &check; | | v2.13.1 | v0.9.1 | &check; | &check; |
| v2.13.0 | v0.9.0 | &cross; | &check; | | v2.13.0 | v0.9.0 | &cross; | &check; |
@@ -16,6 +16,8 @@ Rancher 将在 GitHub 上发布的 Rancher 的[发版说明](https://github.com/
| Patch 版本 | 发布时间 | | Patch 版本 | 发布时间 |
| ----------------------------------------------------------------- | ------------------ | | ----------------------------------------------------------------- | ------------------ |
| [2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2) | 2026 年 01 月 29 日 |
| [2.13.1](https://github.com/rancher/rancher/releases/tag/v2.13.1) | 2025 年 12 月 18 日 |
| [2.13.0](https://github.com/rancher/rancher/releases/tag/v2.13.0) | 2025 年 11 月 25 日 | | [2.13.0](https://github.com/rancher/rancher/releases/tag/v2.13.0) | 2025 年 11 月 25 日 |
## 当一个功能被标记为弃用我可以得到什么样的预期? ## 当一个功能被标记为弃用我可以得到什么样的预期?
@@ -11,10 +11,8 @@ Kubernetes 每隔五分钟会自动清理 etcd 数据集。在某些情况下(
```yaml ```yaml
# RKE2/K3s config.yaml # RKE2/K3s config.yaml
--- ---
services: etcd-arg:
etcd: - "quota-backend-bytes=5368709120"
extra_args:
quota-backend-bytes: 5368709120
``` ```
## 扩展 etcd 磁盘性能 ## 扩展 etcd 磁盘性能
@@ -28,12 +26,7 @@ services:
```yaml ```yaml
# RKE2/K3s config.yaml # RKE2/K3s config.yaml
--- ---
services: etcd-arg:
etcd: - "data-dir=/var/lib/etcd/data"
extra_args: - "wal-dir=/var/lib/etcd/wal"
data-dir: '/var/lib/rancher/etcd/data/'
wal-dir: '/var/lib/rancher/etcd/wal/wal_dir'
extra_binds:
- '/var/lib/etcd/data:/var/lib/rancher/etcd/data'
- '/var/lib/etcd/wal:/var/lib/rancher/etcd/wal'
``` ```
@@ -36,71 +36,72 @@ weight: 1
```json ```json
{ {
"Version": "2012-10-17", "Version": "2012-10-17",
"Statement": [ "Statement": [
{ {
"Effect": "Allow", "Effect": "Allow",
"Action": [ "Action": [
"autoscaling:DescribeAutoScalingGroups", "autoscaling:DescribeAutoScalingGroups",
"autoscaling:DescribeLaunchConfigurations", "autoscaling:DescribeLaunchConfigurations",
"autoscaling:DescribeTags", "autoscaling:DescribeTags",
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeRouteTables", "ec2:DescribeAvailabilityZones",
"ec2:DescribeSecurityGroups", "ec2:DescribeRouteTables",
"ec2:DescribeSubnets", "ec2:DescribeSecurityGroups",
"ec2:DescribeVolumes", "ec2:DescribeSubnets",
"ec2:CreateSecurityGroup", "ec2:DescribeVolumes",
"ec2:CreateTags", "ec2:CreateSecurityGroup",
"ec2:CreateVolume", "ec2:CreateTags",
"ec2:ModifyInstanceAttribute", "ec2:CreateVolume",
"ec2:ModifyVolume", "ec2:ModifyInstanceAttribute",
"ec2:AttachVolume", "ec2:ModifyVolume",
"ec2:AuthorizeSecurityGroupIngress", "ec2:AttachVolume",
"ec2:CreateRoute", "ec2:AuthorizeSecurityGroupIngress",
"ec2:DeleteRoute", "ec2:CreateRoute",
"ec2:DeleteSecurityGroup", "ec2:DeleteRoute",
"ec2:DeleteVolume", "ec2:DeleteSecurityGroup",
"ec2:DetachVolume", "ec2:DeleteVolume",
"ec2:RevokeSecurityGroupIngress", "ec2:DetachVolume",
"ec2:DescribeVpcs", "ec2:RevokeSecurityGroupIngress",
"elasticloadbalancing:AddTags", "ec2:DescribeVpcs",
"elasticloadbalancing:AttachLoadBalancerToSubnets", "elasticloadbalancing:AddTags",
"elasticloadbalancing:ApplySecurityGroupsToLoadBalancer", "elasticloadbalancing:AttachLoadBalancerToSubnets",
"elasticloadbalancing:CreateLoadBalancer", "elasticloadbalancing:ApplySecurityGroupsToLoadBalancer",
"elasticloadbalancing:CreateLoadBalancerPolicy", "elasticloadbalancing:CreateLoadBalancer",
"elasticloadbalancing:CreateLoadBalancerListeners", "elasticloadbalancing:CreateLoadBalancerPolicy",
"elasticloadbalancing:ConfigureHealthCheck", "elasticloadbalancing:CreateLoadBalancerListeners",
"elasticloadbalancing:DeleteLoadBalancer", "elasticloadbalancing:ConfigureHealthCheck",
"elasticloadbalancing:DeleteLoadBalancerListeners", "elasticloadbalancing:DeleteLoadBalancer",
"elasticloadbalancing:DescribeLoadBalancers", "elasticloadbalancing:DeleteLoadBalancerListeners",
"elasticloadbalancing:DescribeLoadBalancerAttributes", "elasticloadbalancing:DescribeLoadBalancers",
"elasticloadbalancing:DetachLoadBalancerFromSubnets", "elasticloadbalancing:DescribeLoadBalancerAttributes",
"elasticloadbalancing:DeregisterInstancesFromLoadBalancer", "elasticloadbalancing:DetachLoadBalancerFromSubnets",
"elasticloadbalancing:ModifyLoadBalancerAttributes", "elasticloadbalancing:DeregisterInstancesFromLoadBalancer",
"elasticloadbalancing:RegisterInstancesWithLoadBalancer", "elasticloadbalancing:ModifyLoadBalancerAttributes",
"elasticloadbalancing:SetLoadBalancerPoliciesForBackendServer", "elasticloadbalancing:RegisterInstancesWithLoadBalancer",
"elasticloadbalancing:AddTags", "elasticloadbalancing:SetLoadBalancerPoliciesForBackendServer",
"elasticloadbalancing:CreateListener", "elasticloadbalancing:AddTags",
"elasticloadbalancing:CreateTargetGroup", "elasticloadbalancing:CreateListener",
"elasticloadbalancing:DeleteListener", "elasticloadbalancing:CreateTargetGroup",
"elasticloadbalancing:DeleteTargetGroup", "elasticloadbalancing:DeleteListener",
"elasticloadbalancing:DescribeListeners", "elasticloadbalancing:DeleteTargetGroup",
"elasticloadbalancing:DescribeLoadBalancerPolicies", "elasticloadbalancing:DescribeListeners",
"elasticloadbalancing:DescribeTargetGroups", "elasticloadbalancing:DescribeLoadBalancerPolicies",
"elasticloadbalancing:DescribeTargetHealth", "elasticloadbalancing:DescribeTargetGroups",
"elasticloadbalancing:ModifyListener", "elasticloadbalancing:DescribeTargetHealth",
"elasticloadbalancing:ModifyTargetGroup", "elasticloadbalancing:ModifyListener",
"elasticloadbalancing:RegisterTargets", "elasticloadbalancing:ModifyTargetGroup",
"elasticloadbalancing:SetLoadBalancerPoliciesOfListener", "elasticloadbalancing:RegisterTargets",
"iam:CreateServiceLinkedRole", "elasticloadbalancing:SetLoadBalancerPoliciesOfListener",
"kms:DescribeKey" "iam:CreateServiceLinkedRole",
], "kms:DescribeKey"
"Resource": [ ],
"*" "Resource": [
] "*"
} ]
] }
]
} }
``` ```
@@ -108,24 +109,25 @@ weight: 1
```json ```json
{ {
"Version": "2012-10-17", "Version": "2012-10-17",
"Statement": [ "Statement": [
{ {
"Effect": "Allow", "Effect": "Allow",
"Action": [ "Action": [
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ecr:GetAuthorizationToken", "ec2:DescribeAvailabilityZones",
"ecr:BatchCheckLayerAvailability", "ecr:GetAuthorizationToken",
"ecr:GetDownloadUrlForLayer", "ecr:BatchCheckLayerAvailability",
"ecr:GetRepositoryPolicy", "ecr:GetDownloadUrlForLayer",
"ecr:DescribeRepositories", "ecr:GetRepositoryPolicy",
"ecr:ListImages", "ecr:DescribeRepositories",
"ecr:BatchGetImage" "ecr:ListImages",
], "ecr:BatchGetImage"
"Resource": "*" ],
"Resource": "*"
} }
] ]
} }
``` ```
@@ -15,6 +15,8 @@ title: 安装 Adapter
| Rancher 版本 | Adapter 版本 | | Rancher 版本 | Adapter 版本 |
|-----------------|------------------| |-----------------|------------------|
| v2.13.2 | 108.0.0+up8.0.0 |
| v2.13.1 | 108.0.0+up8.0.0 |
| v2.13.0 | 108.0.0+up8.0.0 | | v2.13.0 | 108.0.0+up8.0.0 |
## 1. 获取对 Local 集群的访问权限 ## 1. 获取对 Local 集群的访问权限
@@ -10,6 +10,8 @@ Rancher 致力于向社区披露我们产品的安全问题。我们会针对已
| ID | 描述 | 日期 | 解决 | | ID | 描述 | 日期 | 解决 |
|----|-------------|------|------------| |----|-------------|------|------------|
| [CVE-2025-62879](https://github.com/rancher/backup-restore-operator/security/advisories/GHSA-wj3p-5h3x-c74q) | Rancher now provides new versions of the Rancher Backup chart which prevent the leak of secret S3 credentials via the Rancher Backup pod log. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2025-67601](https://github.com/rancher/rancher/security/advisories/GHSA-mc24-7m59-4q5p) | Rancher now removes the ability to fetch CA certificates stored in Rancher’s setting `cacerts` when using the `login` command. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2023-32199](https://github.com/rancher/rancher/security/advisories/GHSA-j4vr-pcmw-hx59) | Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation `authz.cluster.cattle.io/admin-globalrole-missing=true`. | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) and [v2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) | | [CVE-2023-32199](https://github.com/rancher/rancher/security/advisories/GHSA-j4vr-pcmw-hx59) | Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation `authz.cluster.cattle.io/admin-globalrole-missing=true`. | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) and [v2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) |
| [CVE-2024-58269](https://github.com/rancher/rancher/security/advisories/GHSA-mw39-9qc2-f7mg) | The Rancher audit log redaction process has changed to the following: <br/><br/><ul><li> It now redacts `kubectl.kubernetes.io/last-applied-configuration` annotations on both Response and Request body contents. Previously it did not redact Response body content.</li><li> It now redacts Cluster Import URLs on both Request URLs and Referer headers. Previously it did not redact Referer headers.</li></ul> | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) | | [CVE-2024-58269](https://github.com/rancher/rancher/security/advisories/GHSA-mw39-9qc2-f7mg) | The Rancher audit log redaction process has changed to the following: <br/><br/><ul><li> It now redacts `kubectl.kubernetes.io/last-applied-configuration` annotations on both Response and Request body contents. Previously it did not redact Response body content.</li><li> It now redacts Cluster Import URLs on both Request URLs and Referer headers. Previously it did not redact Referer headers.</li></ul> | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) |
| [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) | | [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) |
@@ -20,6 +20,8 @@ Rancher 将 Rancher-Webhook 作为单独的 deployment 和服务部署在 local
| Rancher Version | Webhook Version | Availability in Prime | Availability in Community | | Rancher Version | Webhook Version | Availability in Prime | Availability in Community |
|-----------------|-----------------|-----------------------|---------------------------| |-----------------|-----------------|-----------------------|---------------------------|
| v2.13.2 | v0.9.2 | &check; | &check; |
| v2.13.1 | v0.9.1 | &check; | &check; |
| v2.13.0 | v0.9.0 | &cross; | &check; | | v2.13.0 | v0.9.0 | &cross; | &check; |
## 为什么我们需要它? ## 为什么我们需要它?
@@ -16,6 +16,7 @@ Rancher 将在 GitHub 上发布的 Rancher 的[发版说明](https://github.com/
| Patch 版本 | 发布时间 | | Patch 版本 | 发布时间 |
| --------------------------------------------------------------- | -------------------- | | --------------------------------------------------------------- | -------------------- |
| [2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) | 2026 年 01 月 29 日 |
| [2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10) | 2025 年 9 月 25 日 | | [2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10) | 2025 年 9 月 25 日 |
| [2.10.9](https://github.com/rancher/rancher/releases/tag/v2.10.9) | 2025 年 8 月 27 日 | | [2.10.9](https://github.com/rancher/rancher/releases/tag/v2.10.9) | 2025 年 8 月 27 日 |
| [2.10.8](https://github.com/rancher/rancher/releases/tag/v2.10.8) | 2025 年 7 月 30 日 | | [2.10.8](https://github.com/rancher/rancher/releases/tag/v2.10.8) | 2025 年 7 月 30 日 |
@@ -36,71 +36,72 @@ weight: 1
```json ```json
{ {
"Version": "2012-10-17", "Version": "2012-10-17",
"Statement": [ "Statement": [
{ {
"Effect": "Allow", "Effect": "Allow",
"Action": [ "Action": [
"autoscaling:DescribeAutoScalingGroups", "autoscaling:DescribeAutoScalingGroups",
"autoscaling:DescribeLaunchConfigurations", "autoscaling:DescribeLaunchConfigurations",
"autoscaling:DescribeTags", "autoscaling:DescribeTags",
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeRouteTables", "ec2:DescribeAvailabilityZones",
"ec2:DescribeSecurityGroups", "ec2:DescribeRouteTables",
"ec2:DescribeSubnets", "ec2:DescribeSecurityGroups",
"ec2:DescribeVolumes", "ec2:DescribeSubnets",
"ec2:CreateSecurityGroup", "ec2:DescribeVolumes",
"ec2:CreateTags", "ec2:CreateSecurityGroup",
"ec2:CreateVolume", "ec2:CreateTags",
"ec2:ModifyInstanceAttribute", "ec2:CreateVolume",
"ec2:ModifyVolume", "ec2:ModifyInstanceAttribute",
"ec2:AttachVolume", "ec2:ModifyVolume",
"ec2:AuthorizeSecurityGroupIngress", "ec2:AttachVolume",
"ec2:CreateRoute", "ec2:AuthorizeSecurityGroupIngress",
"ec2:DeleteRoute", "ec2:CreateRoute",
"ec2:DeleteSecurityGroup", "ec2:DeleteRoute",
"ec2:DeleteVolume", "ec2:DeleteSecurityGroup",
"ec2:DetachVolume", "ec2:DeleteVolume",
"ec2:RevokeSecurityGroupIngress", "ec2:DetachVolume",
"ec2:DescribeVpcs", "ec2:RevokeSecurityGroupIngress",
"elasticloadbalancing:AddTags", "ec2:DescribeVpcs",
"elasticloadbalancing:AttachLoadBalancerToSubnets", "elasticloadbalancing:AddTags",
"elasticloadbalancing:ApplySecurityGroupsToLoadBalancer", "elasticloadbalancing:AttachLoadBalancerToSubnets",
"elasticloadbalancing:CreateLoadBalancer", "elasticloadbalancing:ApplySecurityGroupsToLoadBalancer",
"elasticloadbalancing:CreateLoadBalancerPolicy", "elasticloadbalancing:CreateLoadBalancer",
"elasticloadbalancing:CreateLoadBalancerListeners", "elasticloadbalancing:CreateLoadBalancerPolicy",
"elasticloadbalancing:ConfigureHealthCheck", "elasticloadbalancing:CreateLoadBalancerListeners",
"elasticloadbalancing:DeleteLoadBalancer", "elasticloadbalancing:ConfigureHealthCheck",
"elasticloadbalancing:DeleteLoadBalancerListeners", "elasticloadbalancing:DeleteLoadBalancer",
"elasticloadbalancing:DescribeLoadBalancers", "elasticloadbalancing:DeleteLoadBalancerListeners",
"elasticloadbalancing:DescribeLoadBalancerAttributes", "elasticloadbalancing:DescribeLoadBalancers",
"elasticloadbalancing:DetachLoadBalancerFromSubnets", "elasticloadbalancing:DescribeLoadBalancerAttributes",
"elasticloadbalancing:DeregisterInstancesFromLoadBalancer", "elasticloadbalancing:DetachLoadBalancerFromSubnets",
"elasticloadbalancing:ModifyLoadBalancerAttributes", "elasticloadbalancing:DeregisterInstancesFromLoadBalancer",
"elasticloadbalancing:RegisterInstancesWithLoadBalancer", "elasticloadbalancing:ModifyLoadBalancerAttributes",
"elasticloadbalancing:SetLoadBalancerPoliciesForBackendServer", "elasticloadbalancing:RegisterInstancesWithLoadBalancer",
"elasticloadbalancing:AddTags", "elasticloadbalancing:SetLoadBalancerPoliciesForBackendServer",
"elasticloadbalancing:CreateListener", "elasticloadbalancing:AddTags",
"elasticloadbalancing:CreateTargetGroup", "elasticloadbalancing:CreateListener",
"elasticloadbalancing:DeleteListener", "elasticloadbalancing:CreateTargetGroup",
"elasticloadbalancing:DeleteTargetGroup", "elasticloadbalancing:DeleteListener",
"elasticloadbalancing:DescribeListeners", "elasticloadbalancing:DeleteTargetGroup",
"elasticloadbalancing:DescribeLoadBalancerPolicies", "elasticloadbalancing:DescribeListeners",
"elasticloadbalancing:DescribeTargetGroups", "elasticloadbalancing:DescribeLoadBalancerPolicies",
"elasticloadbalancing:DescribeTargetHealth", "elasticloadbalancing:DescribeTargetGroups",
"elasticloadbalancing:ModifyListener", "elasticloadbalancing:DescribeTargetHealth",
"elasticloadbalancing:ModifyTargetGroup", "elasticloadbalancing:ModifyListener",
"elasticloadbalancing:RegisterTargets", "elasticloadbalancing:ModifyTargetGroup",
"elasticloadbalancing:SetLoadBalancerPoliciesOfListener", "elasticloadbalancing:RegisterTargets",
"iam:CreateServiceLinkedRole", "elasticloadbalancing:SetLoadBalancerPoliciesOfListener",
"kms:DescribeKey" "iam:CreateServiceLinkedRole",
], "kms:DescribeKey"
"Resource": [ ],
"*" "Resource": [
] "*"
} ]
] }
]
} }
``` ```
@@ -108,24 +109,25 @@ weight: 1
```json ```json
{ {
"Version": "2012-10-17", "Version": "2012-10-17",
"Statement": [ "Statement": [
{ {
"Effect": "Allow", "Effect": "Allow",
"Action": [ "Action": [
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ecr:GetAuthorizationToken", "ec2:DescribeAvailabilityZones",
"ecr:BatchCheckLayerAvailability", "ecr:GetAuthorizationToken",
"ecr:GetDownloadUrlForLayer", "ecr:BatchCheckLayerAvailability",
"ecr:GetRepositoryPolicy", "ecr:GetDownloadUrlForLayer",
"ecr:DescribeRepositories", "ecr:GetRepositoryPolicy",
"ecr:ListImages", "ecr:DescribeRepositories",
"ecr:BatchGetImage" "ecr:ListImages",
], "ecr:BatchGetImage"
"Resource": "*" ],
"Resource": "*"
} }
] ]
} }
``` ```
@@ -14,7 +14,8 @@ title: 安装 Adapter
::: :::
| Rancher 版本 | Adapter 版本 | | Rancher 版本 | Adapter 版本 |
|-----------------|:---------------:| |-----------------|:----------------:|
| v2.10.11 | v105.0.0+up5.0.1 |
| v2.10.10 | v105.0.0+up5.0.1 | | v2.10.10 | v105.0.0+up5.0.1 |
| v2.10.9 | v105.0.0+up5.0.1 | | v2.10.9 | v105.0.0+up5.0.1 |
| v2.10.8 | v105.0.0+up5.0.1 | | v2.10.8 | v105.0.0+up5.0.1 |
@@ -10,6 +10,8 @@ Rancher 致力于向社区披露我们产品的安全问题。我们会针对已
| ID | 描述 | 日期 | 解决 | | ID | 描述 | 日期 | 解决 |
|----|-------------|------|------------| |----|-------------|------|------------|
| [CVE-2025-62879](https://github.com/rancher/backup-restore-operator/security/advisories/GHSA-wj3p-5h3x-c74q) | Rancher now provides new versions of the Rancher Backup chart which prevent the leak of secret S3 credentials via the Rancher Backup pod log. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2025-67601](https://github.com/rancher/rancher/security/advisories/GHSA-mc24-7m59-4q5p) | Rancher now removes the ability to fetch CA certificates stored in Rancher’s setting `cacerts` when using the `login` command. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) | | [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) |
| [CVE-2024-58267](https://github.com/rancher/rancher/security/advisories/GHSA-v3vj-5868-2ch2) | The Rancher CLI is modified to print the `requestId` more visibly than as part of the login URL. It also adds a `cli=true` origin marker to the URL. The dashboard is modified to recognize the presence of the `requestId` and uses that to show a warning message to the user, asking for verification that they initiated a CLI login with the related Id. The non-presence of the origin marker enables the dashboard to distinguish between the modified CLI and older CLI’s, and adjust the message accordingly. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) | | [CVE-2024-58267](https://github.com/rancher/rancher/security/advisories/GHSA-v3vj-5868-2ch2) | The Rancher CLI is modified to print the `requestId` more visibly than as part of the login URL. It also adds a `cli=true` origin marker to the URL. The dashboard is modified to recognize the presence of the `requestId` and uses that to show a warning message to the user, asking for verification that they initiated a CLI login with the related Id. The non-presence of the origin marker enables the dashboard to distinguish between the modified CLI and older CLI’s, and adjust the message accordingly. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) |
| [CVE-2025-54468](https://github.com/rancher/rancher/security/advisories/GHSA-mjcp-rj3c-36fr) | `Impersonate-*` headers are removed for requests made through the `/meta/proxy` Rancher endpoint (e.g. when cloud credentials are being created) as the headers may contain identifiable and/or sensitive information. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) | | [CVE-2025-54468](https://github.com/rancher/rancher/security/advisories/GHSA-mjcp-rj3c-36fr) | `Impersonate-*` headers are removed for requests made through the `/meta/proxy` Rancher endpoint (e.g. when cloud credentials are being created) as the headers may contain identifiable and/or sensitive information. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) |
@@ -20,6 +20,7 @@ Rancher 将 Rancher-Webhook 作为单独的 deployment 和服务部署在 local
| Rancher Version | Webhook Version | Availability in Prime | Availability in Community | | Rancher Version | Webhook Version | Availability in Prime | Availability in Community |
| --------------- | --------------- | --------------------- | ------------------------- | | --------------- | --------------- | --------------------- | ------------------------- |
| v2.10.11 | v0.6.12 | &check; | &cross; |
| v2.10.10 | v0.6.11 | &check; | &cross; | | v2.10.10 | v0.6.11 | &check; | &cross; |
| v2.10.9 | v0.6.10 | &check; | &cross; | | v2.10.9 | v0.6.10 | &check; | &cross; |
| v2.10.8 | v0.6.9 | &check; | &cross; | | v2.10.8 | v0.6.9 | &check; | &cross; |
@@ -16,6 +16,7 @@ Rancher 将在 GitHub 上发布的 Rancher 的[发版说明](https://github.com/
| Patch 版本 | 发布时间 | | Patch 版本 | 发布时间 |
| --------------------------------------------------------------- | ------------------ | | --------------------------------------------------------------- | ------------------ |
| [2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10) | 2026 年 01 月 29 日 |
| [2.11.9](https://github.com/rancher/rancher/releases/tag/v2.11.9) | 2025 年 12 月 18 日 | | [2.11.9](https://github.com/rancher/rancher/releases/tag/v2.11.9) | 2025 年 12 月 18 日 |
| [2.11.8](https://github.com/rancher/rancher/releases/tag/v2.11.8) | 2025 年 11 月 24 日 | | [2.11.8](https://github.com/rancher/rancher/releases/tag/v2.11.8) | 2025 年 11 月 24 日 |
| [2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) | 2025 年 10 月 23 日 | | [2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) | 2025 年 10 月 23 日 |
@@ -36,71 +36,72 @@ weight: 1
```json ```json
{ {
"Version": "2012-10-17", "Version": "2012-10-17",
"Statement": [ "Statement": [
{ {
"Effect": "Allow", "Effect": "Allow",
"Action": [ "Action": [
"autoscaling:DescribeAutoScalingGroups", "autoscaling:DescribeAutoScalingGroups",
"autoscaling:DescribeLaunchConfigurations", "autoscaling:DescribeLaunchConfigurations",
"autoscaling:DescribeTags", "autoscaling:DescribeTags",
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeRouteTables", "ec2:DescribeAvailabilityZones",
"ec2:DescribeSecurityGroups", "ec2:DescribeRouteTables",
"ec2:DescribeSubnets", "ec2:DescribeSecurityGroups",
"ec2:DescribeVolumes", "ec2:DescribeSubnets",
"ec2:CreateSecurityGroup", "ec2:DescribeVolumes",
"ec2:CreateTags", "ec2:CreateSecurityGroup",
"ec2:CreateVolume", "ec2:CreateTags",
"ec2:ModifyInstanceAttribute", "ec2:CreateVolume",
"ec2:ModifyVolume", "ec2:ModifyInstanceAttribute",
"ec2:AttachVolume", "ec2:ModifyVolume",
"ec2:AuthorizeSecurityGroupIngress", "ec2:AttachVolume",
"ec2:CreateRoute", "ec2:AuthorizeSecurityGroupIngress",
"ec2:DeleteRoute", "ec2:CreateRoute",
"ec2:DeleteSecurityGroup", "ec2:DeleteRoute",
"ec2:DeleteVolume", "ec2:DeleteSecurityGroup",
"ec2:DetachVolume", "ec2:DeleteVolume",
"ec2:RevokeSecurityGroupIngress", "ec2:DetachVolume",
"ec2:DescribeVpcs", "ec2:RevokeSecurityGroupIngress",
"elasticloadbalancing:AddTags", "ec2:DescribeVpcs",
"elasticloadbalancing:AttachLoadBalancerToSubnets", "elasticloadbalancing:AddTags",
"elasticloadbalancing:ApplySecurityGroupsToLoadBalancer", "elasticloadbalancing:AttachLoadBalancerToSubnets",
"elasticloadbalancing:CreateLoadBalancer", "elasticloadbalancing:ApplySecurityGroupsToLoadBalancer",
"elasticloadbalancing:CreateLoadBalancerPolicy", "elasticloadbalancing:CreateLoadBalancer",
"elasticloadbalancing:CreateLoadBalancerListeners", "elasticloadbalancing:CreateLoadBalancerPolicy",
"elasticloadbalancing:ConfigureHealthCheck", "elasticloadbalancing:CreateLoadBalancerListeners",
"elasticloadbalancing:DeleteLoadBalancer", "elasticloadbalancing:ConfigureHealthCheck",
"elasticloadbalancing:DeleteLoadBalancerListeners", "elasticloadbalancing:DeleteLoadBalancer",
"elasticloadbalancing:DescribeLoadBalancers", "elasticloadbalancing:DeleteLoadBalancerListeners",
"elasticloadbalancing:DescribeLoadBalancerAttributes", "elasticloadbalancing:DescribeLoadBalancers",
"elasticloadbalancing:DetachLoadBalancerFromSubnets", "elasticloadbalancing:DescribeLoadBalancerAttributes",
"elasticloadbalancing:DeregisterInstancesFromLoadBalancer", "elasticloadbalancing:DetachLoadBalancerFromSubnets",
"elasticloadbalancing:ModifyLoadBalancerAttributes", "elasticloadbalancing:DeregisterInstancesFromLoadBalancer",
"elasticloadbalancing:RegisterInstancesWithLoadBalancer", "elasticloadbalancing:ModifyLoadBalancerAttributes",
"elasticloadbalancing:SetLoadBalancerPoliciesForBackendServer", "elasticloadbalancing:RegisterInstancesWithLoadBalancer",
"elasticloadbalancing:AddTags", "elasticloadbalancing:SetLoadBalancerPoliciesForBackendServer",
"elasticloadbalancing:CreateListener", "elasticloadbalancing:AddTags",
"elasticloadbalancing:CreateTargetGroup", "elasticloadbalancing:CreateListener",
"elasticloadbalancing:DeleteListener", "elasticloadbalancing:CreateTargetGroup",
"elasticloadbalancing:DeleteTargetGroup", "elasticloadbalancing:DeleteListener",
"elasticloadbalancing:DescribeListeners", "elasticloadbalancing:DeleteTargetGroup",
"elasticloadbalancing:DescribeLoadBalancerPolicies", "elasticloadbalancing:DescribeListeners",
"elasticloadbalancing:DescribeTargetGroups", "elasticloadbalancing:DescribeLoadBalancerPolicies",
"elasticloadbalancing:DescribeTargetHealth", "elasticloadbalancing:DescribeTargetGroups",
"elasticloadbalancing:ModifyListener", "elasticloadbalancing:DescribeTargetHealth",
"elasticloadbalancing:ModifyTargetGroup", "elasticloadbalancing:ModifyListener",
"elasticloadbalancing:RegisterTargets", "elasticloadbalancing:ModifyTargetGroup",
"elasticloadbalancing:SetLoadBalancerPoliciesOfListener", "elasticloadbalancing:RegisterTargets",
"iam:CreateServiceLinkedRole", "elasticloadbalancing:SetLoadBalancerPoliciesOfListener",
"kms:DescribeKey" "iam:CreateServiceLinkedRole",
], "kms:DescribeKey"
"Resource": [ ],
"*" "Resource": [
] "*"
} ]
] }
]
} }
``` ```
@@ -108,24 +109,25 @@ weight: 1
```json ```json
{ {
"Version": "2012-10-17", "Version": "2012-10-17",
"Statement": [ "Statement": [
{ {
"Effect": "Allow", "Effect": "Allow",
"Action": [ "Action": [
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ecr:GetAuthorizationToken", "ec2:DescribeAvailabilityZones",
"ecr:BatchCheckLayerAvailability", "ecr:GetAuthorizationToken",
"ecr:GetDownloadUrlForLayer", "ecr:BatchCheckLayerAvailability",
"ecr:GetRepositoryPolicy", "ecr:GetDownloadUrlForLayer",
"ecr:DescribeRepositories", "ecr:GetRepositoryPolicy",
"ecr:ListImages", "ecr:DescribeRepositories",
"ecr:BatchGetImage" "ecr:ListImages",
], "ecr:BatchGetImage"
"Resource": "*" ],
"Resource": "*"
} }
] ]
} }
``` ```
@@ -15,6 +15,7 @@ title: 安装 Adapter
| Rancher 版本 | Adapter 版本 | | Rancher 版本 | Adapter 版本 |
|-----------------|:----------------:| |-----------------|:----------------:|
| v2.11.10 | v106.0.0+up6.0.0 |
| v2.11.9 | v106.0.0+up6.0.0 | | v2.11.9 | v106.0.0+up6.0.0 |
| v2.11.8 | v106.0.0+up6.0.0 | | v2.11.8 | v106.0.0+up6.0.0 |
| v2.11.7 | v106.0.0+up6.0.0 | | v2.11.7 | v106.0.0+up6.0.0 |
@@ -10,6 +10,8 @@ Rancher 致力于向社区披露我们产品的安全问题。我们会针对已
| ID | 描述 | 日期 | 解决 | | ID | 描述 | 日期 | 解决 |
|----|-------------|------|------------| |----|-------------|------|------------|
| [CVE-2025-62879](https://github.com/rancher/backup-restore-operator/security/advisories/GHSA-wj3p-5h3x-c74q) | Rancher now provides new versions of the Rancher Backup chart which prevent the leak of secret S3 credentials via the Rancher Backup pod log. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2025-67601](https://github.com/rancher/rancher/security/advisories/GHSA-mc24-7m59-4q5p) | Rancher now removes the ability to fetch CA certificates stored in Rancher’s setting `cacerts` when using the `login` command. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2023-32199](https://github.com/rancher/rancher/security/advisories/GHSA-j4vr-pcmw-hx59) | Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation `authz.cluster.cattle.io/admin-globalrole-missing=true`. | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) and [v2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) | | [CVE-2023-32199](https://github.com/rancher/rancher/security/advisories/GHSA-j4vr-pcmw-hx59) | Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation `authz.cluster.cattle.io/admin-globalrole-missing=true`. | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) and [v2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) |
| [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) | | [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) |
| [CVE-2024-58267](https://github.com/rancher/rancher/security/advisories/GHSA-v3vj-5868-2ch2) | The Rancher CLI is modified to print the `requestId` more visibly than as part of the login URL. It also adds a `cli=true` origin marker to the URL. The dashboard is modified to recognize the presence of the `requestId` and uses that to show a warning message to the user, asking for verification that they initiated a CLI login with the related Id. The non-presence of the origin marker enables the dashboard to distinguish between the modified CLI and older CLI’s, and adjust the message accordingly. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) | | [CVE-2024-58267](https://github.com/rancher/rancher/security/advisories/GHSA-v3vj-5868-2ch2) | The Rancher CLI is modified to print the `requestId` more visibly than as part of the login URL. It also adds a `cli=true` origin marker to the URL. The dashboard is modified to recognize the presence of the `requestId` and uses that to show a warning message to the user, asking for verification that they initiated a CLI login with the related Id. The non-presence of the origin marker enables the dashboard to distinguish between the modified CLI and older CLI’s, and adjust the message accordingly. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) |
@@ -20,6 +20,7 @@ Rancher 将 Rancher-Webhook 作为单独的 deployment 和服务部署在 local
| Rancher Version | Webhook Version | Availability in Prime | Availability in Community | | Rancher Version | Webhook Version | Availability in Prime | Availability in Community |
|-----------------|-----------------|-----------------------|---------------------------| |-----------------|-----------------|-----------------------|---------------------------|
| v2.11.10 | v0.7.8 | &check; | &cross; |
| v2.11.9 | v0.7.8 | &check; | &cross; | | v2.11.9 | v0.7.8 | &check; | &cross; |
| v2.11.8 | v0.7.8 | &check; | &cross; | | v2.11.8 | v0.7.8 | &check; | &cross; |
| v2.11.7 | v0.7.7 | &check; | &cross; | | v2.11.7 | v0.7.7 | &check; | &cross; |
@@ -16,6 +16,7 @@ Rancher 将在 GitHub 上发布的 Rancher 的[发版说明](https://github.com/
| Patch 版本 | 发布时间 | | Patch 版本 | 发布时间 |
| ----------------------------------------------------------------- | ------------------ | | ----------------------------------------------------------------- | ------------------ |
| [2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6) | 2026 年 01 月 29 日 |
| [2.12.5](https://github.com/rancher/rancher/releases/tag/v2.12.5) | 2025 年 12 月 18 日 | | [2.12.5](https://github.com/rancher/rancher/releases/tag/v2.12.5) | 2025 年 12 月 18 日 |
| [2.12.4](https://github.com/rancher/rancher/releases/tag/v2.12.4) | 2025 年 11 月 24 日 | | [2.12.4](https://github.com/rancher/rancher/releases/tag/v2.12.4) | 2025 年 11 月 24 日 |
| [2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) | 2025 年 10 月 23 日 | | [2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) | 2025 年 10 月 23 日 |
@@ -11,10 +11,8 @@ Kubernetes 每隔五分钟会自动清理 etcd 数据集。在某些情况下(
```yaml ```yaml
# RKE2/K3s config.yaml # RKE2/K3s config.yaml
--- ---
services: etcd-arg:
etcd: - "quota-backend-bytes=5368709120"
extra_args:
quota-backend-bytes: 5368709120
``` ```
## 扩展 etcd 磁盘性能 ## 扩展 etcd 磁盘性能
@@ -28,12 +26,7 @@ services:
```yaml ```yaml
# RKE2/K3s config.yaml # RKE2/K3s config.yaml
--- ---
services: etcd-arg:
etcd: - "data-dir=/var/lib/etcd/data"
extra_args: - "wal-dir=/var/lib/etcd/wal"
data-dir: '/var/lib/rancher/etcd/data/'
wal-dir: '/var/lib/rancher/etcd/wal/wal_dir'
extra_binds:
- '/var/lib/etcd/data:/var/lib/rancher/etcd/data'
- '/var/lib/etcd/wal:/var/lib/rancher/etcd/wal'
``` ```
@@ -36,71 +36,72 @@ weight: 1
```json ```json
{ {
"Version": "2012-10-17", "Version": "2012-10-17",
"Statement": [ "Statement": [
{ {
"Effect": "Allow", "Effect": "Allow",
"Action": [ "Action": [
"autoscaling:DescribeAutoScalingGroups", "autoscaling:DescribeAutoScalingGroups",
"autoscaling:DescribeLaunchConfigurations", "autoscaling:DescribeLaunchConfigurations",
"autoscaling:DescribeTags", "autoscaling:DescribeTags",
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeRouteTables", "ec2:DescribeAvailabilityZones",
"ec2:DescribeSecurityGroups", "ec2:DescribeRouteTables",
"ec2:DescribeSubnets", "ec2:DescribeSecurityGroups",
"ec2:DescribeVolumes", "ec2:DescribeSubnets",
"ec2:CreateSecurityGroup", "ec2:DescribeVolumes",
"ec2:CreateTags", "ec2:CreateSecurityGroup",
"ec2:CreateVolume", "ec2:CreateTags",
"ec2:ModifyInstanceAttribute", "ec2:CreateVolume",
"ec2:ModifyVolume", "ec2:ModifyInstanceAttribute",
"ec2:AttachVolume", "ec2:ModifyVolume",
"ec2:AuthorizeSecurityGroupIngress", "ec2:AttachVolume",
"ec2:CreateRoute", "ec2:AuthorizeSecurityGroupIngress",
"ec2:DeleteRoute", "ec2:CreateRoute",
"ec2:DeleteSecurityGroup", "ec2:DeleteRoute",
"ec2:DeleteVolume", "ec2:DeleteSecurityGroup",
"ec2:DetachVolume", "ec2:DeleteVolume",
"ec2:RevokeSecurityGroupIngress", "ec2:DetachVolume",
"ec2:DescribeVpcs", "ec2:RevokeSecurityGroupIngress",
"elasticloadbalancing:AddTags", "ec2:DescribeVpcs",
"elasticloadbalancing:AttachLoadBalancerToSubnets", "elasticloadbalancing:AddTags",
"elasticloadbalancing:ApplySecurityGroupsToLoadBalancer", "elasticloadbalancing:AttachLoadBalancerToSubnets",
"elasticloadbalancing:CreateLoadBalancer", "elasticloadbalancing:ApplySecurityGroupsToLoadBalancer",
"elasticloadbalancing:CreateLoadBalancerPolicy", "elasticloadbalancing:CreateLoadBalancer",
"elasticloadbalancing:CreateLoadBalancerListeners", "elasticloadbalancing:CreateLoadBalancerPolicy",
"elasticloadbalancing:ConfigureHealthCheck", "elasticloadbalancing:CreateLoadBalancerListeners",
"elasticloadbalancing:DeleteLoadBalancer", "elasticloadbalancing:ConfigureHealthCheck",
"elasticloadbalancing:DeleteLoadBalancerListeners", "elasticloadbalancing:DeleteLoadBalancer",
"elasticloadbalancing:DescribeLoadBalancers", "elasticloadbalancing:DeleteLoadBalancerListeners",
"elasticloadbalancing:DescribeLoadBalancerAttributes", "elasticloadbalancing:DescribeLoadBalancers",
"elasticloadbalancing:DetachLoadBalancerFromSubnets", "elasticloadbalancing:DescribeLoadBalancerAttributes",
"elasticloadbalancing:DeregisterInstancesFromLoadBalancer", "elasticloadbalancing:DetachLoadBalancerFromSubnets",
"elasticloadbalancing:ModifyLoadBalancerAttributes", "elasticloadbalancing:DeregisterInstancesFromLoadBalancer",
"elasticloadbalancing:RegisterInstancesWithLoadBalancer", "elasticloadbalancing:ModifyLoadBalancerAttributes",
"elasticloadbalancing:SetLoadBalancerPoliciesForBackendServer", "elasticloadbalancing:RegisterInstancesWithLoadBalancer",
"elasticloadbalancing:AddTags", "elasticloadbalancing:SetLoadBalancerPoliciesForBackendServer",
"elasticloadbalancing:CreateListener", "elasticloadbalancing:AddTags",
"elasticloadbalancing:CreateTargetGroup", "elasticloadbalancing:CreateListener",
"elasticloadbalancing:DeleteListener", "elasticloadbalancing:CreateTargetGroup",
"elasticloadbalancing:DeleteTargetGroup", "elasticloadbalancing:DeleteListener",
"elasticloadbalancing:DescribeListeners", "elasticloadbalancing:DeleteTargetGroup",
"elasticloadbalancing:DescribeLoadBalancerPolicies", "elasticloadbalancing:DescribeListeners",
"elasticloadbalancing:DescribeTargetGroups", "elasticloadbalancing:DescribeLoadBalancerPolicies",
"elasticloadbalancing:DescribeTargetHealth", "elasticloadbalancing:DescribeTargetGroups",
"elasticloadbalancing:ModifyListener", "elasticloadbalancing:DescribeTargetHealth",
"elasticloadbalancing:ModifyTargetGroup", "elasticloadbalancing:ModifyListener",
"elasticloadbalancing:RegisterTargets", "elasticloadbalancing:ModifyTargetGroup",
"elasticloadbalancing:SetLoadBalancerPoliciesOfListener", "elasticloadbalancing:RegisterTargets",
"iam:CreateServiceLinkedRole", "elasticloadbalancing:SetLoadBalancerPoliciesOfListener",
"kms:DescribeKey" "iam:CreateServiceLinkedRole",
], "kms:DescribeKey"
"Resource": [ ],
"*" "Resource": [
] "*"
} ]
] }
]
} }
``` ```
@@ -108,24 +109,25 @@ weight: 1
```json ```json
{ {
"Version": "2012-10-17", "Version": "2012-10-17",
"Statement": [ "Statement": [
{ {
"Effect": "Allow", "Effect": "Allow",
"Action": [ "Action": [
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ecr:GetAuthorizationToken", "ec2:DescribeAvailabilityZones",
"ecr:BatchCheckLayerAvailability", "ecr:GetAuthorizationToken",
"ecr:GetDownloadUrlForLayer", "ecr:BatchCheckLayerAvailability",
"ecr:GetRepositoryPolicy", "ecr:GetDownloadUrlForLayer",
"ecr:DescribeRepositories", "ecr:GetRepositoryPolicy",
"ecr:ListImages", "ecr:DescribeRepositories",
"ecr:BatchGetImage" "ecr:ListImages",
], "ecr:BatchGetImage"
"Resource": "*" ],
"Resource": "*"
} }
] ]
} }
``` ```
@@ -15,6 +15,7 @@ title: 安装 Adapter
| Rancher 版本 | Adapter 版本 | | Rancher 版本 | Adapter 版本 |
|-----------------|:----------------:| |-----------------|:----------------:|
| v2.12.6 | 107.0.0+up7.0.0 |
| v2.12.5 | 107.0.0+up7.0.0 | | v2.12.5 | 107.0.0+up7.0.0 |
| v2.12.4 | 107.0.0+up7.0.0 | | v2.12.4 | 107.0.0+up7.0.0 |
| v2.12.3 | 107.0.0+up7.0.0 | | v2.12.3 | 107.0.0+up7.0.0 |
@@ -10,6 +10,8 @@ Rancher 致力于向社区披露我们产品的安全问题。我们会针对已
| ID | 描述 | 日期 | 解决 | | ID | 描述 | 日期 | 解决 |
|----|-------------|------|------------| |----|-------------|------|------------|
| [CVE-2025-62879](https://github.com/rancher/backup-restore-operator/security/advisories/GHSA-wj3p-5h3x-c74q) | Rancher now provides new versions of the Rancher Backup chart which prevent the leak of secret S3 credentials via the Rancher Backup pod log. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2025-67601](https://github.com/rancher/rancher/security/advisories/GHSA-mc24-7m59-4q5p) | Rancher now removes the ability to fetch CA certificates stored in Rancher’s setting `cacerts` when using the `login` command. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2023-32199](https://github.com/rancher/rancher/security/advisories/GHSA-j4vr-pcmw-hx59) | Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation `authz.cluster.cattle.io/admin-globalrole-missing=true`. | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) and [v2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) | | [CVE-2023-32199](https://github.com/rancher/rancher/security/advisories/GHSA-j4vr-pcmw-hx59) | Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation `authz.cluster.cattle.io/admin-globalrole-missing=true`. | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) and [v2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) |
| [CVE-2024-58269](https://github.com/rancher/rancher/security/advisories/GHSA-mw39-9qc2-f7mg) | The Rancher audit log redaction process has changed to the following: <br/><br/><ul><li> It now redacts `kubectl.kubernetes.io/last-applied-configuration` annotations on both Response and Request body contents. Previously it did not redact Response body content.</li><li> It now redacts Cluster Import URLs on both Request URLs and Referer headers. Previously it did not redact Referer headers.</li></ul> | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) | | [CVE-2024-58269](https://github.com/rancher/rancher/security/advisories/GHSA-mw39-9qc2-f7mg) | The Rancher audit log redaction process has changed to the following: <br/><br/><ul><li> It now redacts `kubectl.kubernetes.io/last-applied-configuration` annotations on both Response and Request body contents. Previously it did not redact Response body content.</li><li> It now redacts Cluster Import URLs on both Request URLs and Referer headers. Previously it did not redact Referer headers.</li></ul> | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) |
| [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) | | [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) |
@@ -20,6 +20,7 @@ Rancher 将 Rancher-Webhook 作为单独的 deployment 和服务部署在 local
| Rancher Version | Webhook Version | Availability in Prime | Availability in Community | | Rancher Version | Webhook Version | Availability in Prime | Availability in Community |
|-----------------|-----------------|-----------------------|---------------------------| |-----------------|-----------------|-----------------------|---------------------------|
| v2.12.6 | v0.8.5 | &check; | &cross; |
| v2.12.5 | v0.8.4 | &check; | &cross; | | v2.12.5 | v0.8.4 | &check; | &cross; |
| v2.12.4 | v0.8.4 | &check; | &cross; | | v2.12.4 | v0.8.4 | &check; | &cross; |
| v2.12.3 | v0.8.3 | &check; | &check; | | v2.12.3 | v0.8.3 | &check; | &check; |
@@ -16,6 +16,7 @@ Rancher 将在 GitHub 上发布的 Rancher 的[发版说明](https://github.com/
| Patch 版本 | 发布时间 | | Patch 版本 | 发布时间 |
| ----------------------------------------------------------------- | ------------------ | | ----------------------------------------------------------------- | ------------------ |
| [2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.1) | 2026 年 01 月 29 日 |
| [2.13.1](https://github.com/rancher/rancher/releases/tag/v2.13.1) | 2025 年 12 月 18 日 | | [2.13.1](https://github.com/rancher/rancher/releases/tag/v2.13.1) | 2025 年 12 月 18 日 |
| [2.13.0](https://github.com/rancher/rancher/releases/tag/v2.13.0) | 2025 年 11 月 25 日 | | [2.13.0](https://github.com/rancher/rancher/releases/tag/v2.13.0) | 2025 年 11 月 25 日 |
@@ -11,10 +11,8 @@ Kubernetes 每隔五分钟会自动清理 etcd 数据集。在某些情况下(
```yaml ```yaml
# RKE2/K3s config.yaml # RKE2/K3s config.yaml
--- ---
services: etcd-arg:
etcd: - "quota-backend-bytes=5368709120"
extra_args:
quota-backend-bytes: 5368709120
``` ```
## 扩展 etcd 磁盘性能 ## 扩展 etcd 磁盘性能
@@ -28,12 +26,7 @@ services:
```yaml ```yaml
# RKE2/K3s config.yaml # RKE2/K3s config.yaml
--- ---
services: etcd-args:
etcd: - "data-dir=/var/lib/etcd/data"
extra_args: - "wal-dir=/var/lib/etcd/wal"
data-dir: '/var/lib/rancher/etcd/data/'
wal-dir: '/var/lib/rancher/etcd/wal/wal_dir'
extra_binds:
- '/var/lib/etcd/data:/var/lib/rancher/etcd/data'
- '/var/lib/etcd/wal:/var/lib/rancher/etcd/wal'
``` ```
@@ -36,71 +36,72 @@ weight: 1
```json ```json
{ {
"Version": "2012-10-17", "Version": "2012-10-17",
"Statement": [ "Statement": [
{ {
"Effect": "Allow", "Effect": "Allow",
"Action": [ "Action": [
"autoscaling:DescribeAutoScalingGroups", "autoscaling:DescribeAutoScalingGroups",
"autoscaling:DescribeLaunchConfigurations", "autoscaling:DescribeLaunchConfigurations",
"autoscaling:DescribeTags", "autoscaling:DescribeTags",
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeRouteTables", "ec2:DescribeAvailabilityZones",
"ec2:DescribeSecurityGroups", "ec2:DescribeRouteTables",
"ec2:DescribeSubnets", "ec2:DescribeSecurityGroups",
"ec2:DescribeVolumes", "ec2:DescribeSubnets",
"ec2:CreateSecurityGroup", "ec2:DescribeVolumes",
"ec2:CreateTags", "ec2:CreateSecurityGroup",
"ec2:CreateVolume", "ec2:CreateTags",
"ec2:ModifyInstanceAttribute", "ec2:CreateVolume",
"ec2:ModifyVolume", "ec2:ModifyInstanceAttribute",
"ec2:AttachVolume", "ec2:ModifyVolume",
"ec2:AuthorizeSecurityGroupIngress", "ec2:AttachVolume",
"ec2:CreateRoute", "ec2:AuthorizeSecurityGroupIngress",
"ec2:DeleteRoute", "ec2:CreateRoute",
"ec2:DeleteSecurityGroup", "ec2:DeleteRoute",
"ec2:DeleteVolume", "ec2:DeleteSecurityGroup",
"ec2:DetachVolume", "ec2:DeleteVolume",
"ec2:RevokeSecurityGroupIngress", "ec2:DetachVolume",
"ec2:DescribeVpcs", "ec2:RevokeSecurityGroupIngress",
"elasticloadbalancing:AddTags", "ec2:DescribeVpcs",
"elasticloadbalancing:AttachLoadBalancerToSubnets", "elasticloadbalancing:AddTags",
"elasticloadbalancing:ApplySecurityGroupsToLoadBalancer", "elasticloadbalancing:AttachLoadBalancerToSubnets",
"elasticloadbalancing:CreateLoadBalancer", "elasticloadbalancing:ApplySecurityGroupsToLoadBalancer",
"elasticloadbalancing:CreateLoadBalancerPolicy", "elasticloadbalancing:CreateLoadBalancer",
"elasticloadbalancing:CreateLoadBalancerListeners", "elasticloadbalancing:CreateLoadBalancerPolicy",
"elasticloadbalancing:ConfigureHealthCheck", "elasticloadbalancing:CreateLoadBalancerListeners",
"elasticloadbalancing:DeleteLoadBalancer", "elasticloadbalancing:ConfigureHealthCheck",
"elasticloadbalancing:DeleteLoadBalancerListeners", "elasticloadbalancing:DeleteLoadBalancer",
"elasticloadbalancing:DescribeLoadBalancers", "elasticloadbalancing:DeleteLoadBalancerListeners",
"elasticloadbalancing:DescribeLoadBalancerAttributes", "elasticloadbalancing:DescribeLoadBalancers",
"elasticloadbalancing:DetachLoadBalancerFromSubnets", "elasticloadbalancing:DescribeLoadBalancerAttributes",
"elasticloadbalancing:DeregisterInstancesFromLoadBalancer", "elasticloadbalancing:DetachLoadBalancerFromSubnets",
"elasticloadbalancing:ModifyLoadBalancerAttributes", "elasticloadbalancing:DeregisterInstancesFromLoadBalancer",
"elasticloadbalancing:RegisterInstancesWithLoadBalancer", "elasticloadbalancing:ModifyLoadBalancerAttributes",
"elasticloadbalancing:SetLoadBalancerPoliciesForBackendServer", "elasticloadbalancing:RegisterInstancesWithLoadBalancer",
"elasticloadbalancing:AddTags", "elasticloadbalancing:SetLoadBalancerPoliciesForBackendServer",
"elasticloadbalancing:CreateListener", "elasticloadbalancing:AddTags",
"elasticloadbalancing:CreateTargetGroup", "elasticloadbalancing:CreateListener",
"elasticloadbalancing:DeleteListener", "elasticloadbalancing:CreateTargetGroup",
"elasticloadbalancing:DeleteTargetGroup", "elasticloadbalancing:DeleteListener",
"elasticloadbalancing:DescribeListeners", "elasticloadbalancing:DeleteTargetGroup",
"elasticloadbalancing:DescribeLoadBalancerPolicies", "elasticloadbalancing:DescribeListeners",
"elasticloadbalancing:DescribeTargetGroups", "elasticloadbalancing:DescribeLoadBalancerPolicies",
"elasticloadbalancing:DescribeTargetHealth", "elasticloadbalancing:DescribeTargetGroups",
"elasticloadbalancing:ModifyListener", "elasticloadbalancing:DescribeTargetHealth",
"elasticloadbalancing:ModifyTargetGroup", "elasticloadbalancing:ModifyListener",
"elasticloadbalancing:RegisterTargets", "elasticloadbalancing:ModifyTargetGroup",
"elasticloadbalancing:SetLoadBalancerPoliciesOfListener", "elasticloadbalancing:RegisterTargets",
"iam:CreateServiceLinkedRole", "elasticloadbalancing:SetLoadBalancerPoliciesOfListener",
"kms:DescribeKey" "iam:CreateServiceLinkedRole",
], "kms:DescribeKey"
"Resource": [ ],
"*" "Resource": [
] "*"
} ]
] }
]
} }
``` ```
@@ -108,24 +109,25 @@ weight: 1
```json ```json
{ {
"Version": "2012-10-17", "Version": "2012-10-17",
"Statement": [ "Statement": [
{ {
"Effect": "Allow", "Effect": "Allow",
"Action": [ "Action": [
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ecr:GetAuthorizationToken", "ec2:DescribeAvailabilityZones",
"ecr:BatchCheckLayerAvailability", "ecr:GetAuthorizationToken",
"ecr:GetDownloadUrlForLayer", "ecr:BatchCheckLayerAvailability",
"ecr:GetRepositoryPolicy", "ecr:GetDownloadUrlForLayer",
"ecr:DescribeRepositories", "ecr:GetRepositoryPolicy",
"ecr:ListImages", "ecr:DescribeRepositories",
"ecr:BatchGetImage" "ecr:ListImages",
], "ecr:BatchGetImage"
"Resource": "*" ],
"Resource": "*"
} }
] ]
} }
``` ```
@@ -15,6 +15,7 @@ title: 安装 Adapter
| Rancher 版本 | Adapter 版本 | | Rancher 版本 | Adapter 版本 |
|-----------------|------------------| |-----------------|------------------|
| v2.13.2 | 108.0.0+up8.0.0 |
| v2.13.1 | 108.0.0+up8.0.0 | | v2.13.1 | 108.0.0+up8.0.0 |
| v2.13.0 | 108.0.0+up8.0.0 | | v2.13.0 | 108.0.0+up8.0.0 |
@@ -10,6 +10,8 @@ Rancher 致力于向社区披露我们产品的安全问题。我们会针对已
| ID | 描述 | 日期 | 解决 | | ID | 描述 | 日期 | 解决 |
|----|-------------|------|------------| |----|-------------|------|------------|
| [CVE-2025-62879](https://github.com/rancher/backup-restore-operator/security/advisories/GHSA-wj3p-5h3x-c74q) | Rancher now provides new versions of the Rancher Backup chart which prevent the leak of secret S3 credentials via the Rancher Backup pod log. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2025-67601](https://github.com/rancher/rancher/security/advisories/GHSA-mc24-7m59-4q5p) | Rancher now removes the ability to fetch CA certificates stored in Rancher’s setting `cacerts` when using the `login` command. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2023-32199](https://github.com/rancher/rancher/security/advisories/GHSA-j4vr-pcmw-hx59) | Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation `authz.cluster.cattle.io/admin-globalrole-missing=true`. | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) and [v2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) | | [CVE-2023-32199](https://github.com/rancher/rancher/security/advisories/GHSA-j4vr-pcmw-hx59) | Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation `authz.cluster.cattle.io/admin-globalrole-missing=true`. | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) and [v2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) |
| [CVE-2024-58269](https://github.com/rancher/rancher/security/advisories/GHSA-mw39-9qc2-f7mg) | The Rancher audit log redaction process has changed to the following: <br/><br/><ul><li> It now redacts `kubectl.kubernetes.io/last-applied-configuration` annotations on both Response and Request body contents. Previously it did not redact Response body content.</li><li> It now redacts Cluster Import URLs on both Request URLs and Referer headers. Previously it did not redact Referer headers.</li></ul> | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) | | [CVE-2024-58269](https://github.com/rancher/rancher/security/advisories/GHSA-mw39-9qc2-f7mg) | The Rancher audit log redaction process has changed to the following: <br/><br/><ul><li> It now redacts `kubectl.kubernetes.io/last-applied-configuration` annotations on both Response and Request body contents. Previously it did not redact Response body content.</li><li> It now redacts Cluster Import URLs on both Request URLs and Referer headers. Previously it did not redact Referer headers.</li></ul> | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) |
| [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) | | [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) |
@@ -20,6 +20,7 @@ Rancher 将 Rancher-Webhook 作为单独的 deployment 和服务部署在 local
| Rancher Version | Webhook Version | Availability in Prime | Availability in Community | | Rancher Version | Webhook Version | Availability in Prime | Availability in Community |
|-----------------|-----------------|-----------------------|---------------------------| |-----------------|-----------------|-----------------------|---------------------------|
| v2.13.2 | v0.9.2 | &check; | &check; |
| v2.13.1 | v0.9.1 | &check; | &check; | | v2.13.1 | v0.9.1 | &check; | &check; |
| v2.13.0 | v0.9.0 | &cross; | &check; | | v2.13.0 | v0.9.0 | &cross; | &check; |
@@ -36,71 +36,72 @@ weight: 1
```json ```json
{ {
"Version": "2012-10-17", "Version": "2012-10-17",
"Statement": [ "Statement": [
{ {
"Effect": "Allow", "Effect": "Allow",
"Action": [ "Action": [
"autoscaling:DescribeAutoScalingGroups", "autoscaling:DescribeAutoScalingGroups",
"autoscaling:DescribeLaunchConfigurations", "autoscaling:DescribeLaunchConfigurations",
"autoscaling:DescribeTags", "autoscaling:DescribeTags",
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeRouteTables", "ec2:DescribeAvailabilityZones",
"ec2:DescribeSecurityGroups", "ec2:DescribeRouteTables",
"ec2:DescribeSubnets", "ec2:DescribeSecurityGroups",
"ec2:DescribeVolumes", "ec2:DescribeSubnets",
"ec2:CreateSecurityGroup", "ec2:DescribeVolumes",
"ec2:CreateTags", "ec2:CreateSecurityGroup",
"ec2:CreateVolume", "ec2:CreateTags",
"ec2:ModifyInstanceAttribute", "ec2:CreateVolume",
"ec2:ModifyVolume", "ec2:ModifyInstanceAttribute",
"ec2:AttachVolume", "ec2:ModifyVolume",
"ec2:AuthorizeSecurityGroupIngress", "ec2:AttachVolume",
"ec2:CreateRoute", "ec2:AuthorizeSecurityGroupIngress",
"ec2:DeleteRoute", "ec2:CreateRoute",
"ec2:DeleteSecurityGroup", "ec2:DeleteRoute",
"ec2:DeleteVolume", "ec2:DeleteSecurityGroup",
"ec2:DetachVolume", "ec2:DeleteVolume",
"ec2:RevokeSecurityGroupIngress", "ec2:DetachVolume",
"ec2:DescribeVpcs", "ec2:RevokeSecurityGroupIngress",
"elasticloadbalancing:AddTags", "ec2:DescribeVpcs",
"elasticloadbalancing:AttachLoadBalancerToSubnets", "elasticloadbalancing:AddTags",
"elasticloadbalancing:ApplySecurityGroupsToLoadBalancer", "elasticloadbalancing:AttachLoadBalancerToSubnets",
"elasticloadbalancing:CreateLoadBalancer", "elasticloadbalancing:ApplySecurityGroupsToLoadBalancer",
"elasticloadbalancing:CreateLoadBalancerPolicy", "elasticloadbalancing:CreateLoadBalancer",
"elasticloadbalancing:CreateLoadBalancerListeners", "elasticloadbalancing:CreateLoadBalancerPolicy",
"elasticloadbalancing:ConfigureHealthCheck", "elasticloadbalancing:CreateLoadBalancerListeners",
"elasticloadbalancing:DeleteLoadBalancer", "elasticloadbalancing:ConfigureHealthCheck",
"elasticloadbalancing:DeleteLoadBalancerListeners", "elasticloadbalancing:DeleteLoadBalancer",
"elasticloadbalancing:DescribeLoadBalancers", "elasticloadbalancing:DeleteLoadBalancerListeners",
"elasticloadbalancing:DescribeLoadBalancerAttributes", "elasticloadbalancing:DescribeLoadBalancers",
"elasticloadbalancing:DetachLoadBalancerFromSubnets", "elasticloadbalancing:DescribeLoadBalancerAttributes",
"elasticloadbalancing:DeregisterInstancesFromLoadBalancer", "elasticloadbalancing:DetachLoadBalancerFromSubnets",
"elasticloadbalancing:ModifyLoadBalancerAttributes", "elasticloadbalancing:DeregisterInstancesFromLoadBalancer",
"elasticloadbalancing:RegisterInstancesWithLoadBalancer", "elasticloadbalancing:ModifyLoadBalancerAttributes",
"elasticloadbalancing:SetLoadBalancerPoliciesForBackendServer", "elasticloadbalancing:RegisterInstancesWithLoadBalancer",
"elasticloadbalancing:AddTags", "elasticloadbalancing:SetLoadBalancerPoliciesForBackendServer",
"elasticloadbalancing:CreateListener", "elasticloadbalancing:AddTags",
"elasticloadbalancing:CreateTargetGroup", "elasticloadbalancing:CreateListener",
"elasticloadbalancing:DeleteListener", "elasticloadbalancing:CreateTargetGroup",
"elasticloadbalancing:DeleteTargetGroup", "elasticloadbalancing:DeleteListener",
"elasticloadbalancing:DescribeListeners", "elasticloadbalancing:DeleteTargetGroup",
"elasticloadbalancing:DescribeLoadBalancerPolicies", "elasticloadbalancing:DescribeListeners",
"elasticloadbalancing:DescribeTargetGroups", "elasticloadbalancing:DescribeLoadBalancerPolicies",
"elasticloadbalancing:DescribeTargetHealth", "elasticloadbalancing:DescribeTargetGroups",
"elasticloadbalancing:ModifyListener", "elasticloadbalancing:DescribeTargetHealth",
"elasticloadbalancing:ModifyTargetGroup", "elasticloadbalancing:ModifyListener",
"elasticloadbalancing:RegisterTargets", "elasticloadbalancing:ModifyTargetGroup",
"elasticloadbalancing:SetLoadBalancerPoliciesOfListener", "elasticloadbalancing:RegisterTargets",
"iam:CreateServiceLinkedRole", "elasticloadbalancing:SetLoadBalancerPoliciesOfListener",
"kms:DescribeKey" "iam:CreateServiceLinkedRole",
], "kms:DescribeKey"
"Resource": [ ],
"*" "Resource": [
] "*"
} ]
] }
]
} }
``` ```
@@ -108,24 +109,25 @@ weight: 1
```json ```json
{ {
"Version": "2012-10-17", "Version": "2012-10-17",
"Statement": [ "Statement": [
{ {
"Effect": "Allow", "Effect": "Allow",
"Action": [ "Action": [
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ecr:GetAuthorizationToken", "ec2:DescribeAvailabilityZones",
"ecr:BatchCheckLayerAvailability", "ecr:GetAuthorizationToken",
"ecr:GetDownloadUrlForLayer", "ecr:BatchCheckLayerAvailability",
"ecr:GetRepositoryPolicy", "ecr:GetDownloadUrlForLayer",
"ecr:DescribeRepositories", "ecr:GetRepositoryPolicy",
"ecr:ListImages", "ecr:DescribeRepositories",
"ecr:BatchGetImage" "ecr:ListImages",
], "ecr:BatchGetImage"
"Resource": "*" ],
"Resource": "*"
} }
] ]
} }
``` ```
+5 -5
View File
@@ -3,8 +3,8 @@ The following table summarizes different GitHub metrics to give you an idea of e
| Provider | Project | Stars | Forks | Contributors | | Provider | Project | Stars | Forks | Contributors |
| ---- | ---- | ---- | ---- | ---- | | ---- | ---- | ---- | ---- | ---- |
| Canal | https://github.com/projectcalico/canal | 721 | 97 | 18 | | Canal | https://github.com/projectcalico/canal | 720 | 97 | 20 |
| Flannel | https://github.com/flannel-io/flannel | 9.3k | 2.9k | 244 | | Flannel | https://github.com/flannel-io/flannel | 9.4k | 2.9k | 243 |
| Calico | https://github.com/projectcalico/calico | 6.9k | 1.5k | 396 | | Calico | https://github.com/projectcalico/calico | 6.9k | 1.5k | 400 |
| Weave | https://github.com/weaveworks/weave | 6.6k | 680 | 83 | | Weave | https://github.com/weaveworks/weave | 6.6k | 677 | 83 |
| Cilium | https://github.com/cilium/cilium | 23k | 3.5k | 1k | | Cilium | https://github.com/cilium/cilium | 23.5k | 3.6k | 1022 |
+41 -9
View File
@@ -17,11 +17,11 @@ Here you can find links to supporting documentation for the current released ver
<th>Community</th> <th>Community</th>
</tr> </tr>
<tr> <tr>
<td><b>v2.13.1</b></td> <td><b>v2.13.2</b></td>
<td><a href="https://ranchermanager.docs.rancher.com/v2.13">Documentation</a></td> <td><a href="https://ranchermanager.docs.rancher.com/v2.13">Documentation</a></td>
<td><a href="https://github.com/rancher/rancher/releases/tag/v2.13.1">Release Notes</a></td> <td><a href="https://github.com/rancher/rancher/releases/tag/v2.13.2">Release Notes</a></td>
<td><center>N/A</center></td> <td><center>N/A</center></td>
<td><center>&#10003</center></td> <td><center>&#10003;</center></td>
<td><center>&#10003;</center></td> <td><center>&#10003;</center></td>
</tr> </tr>
</table> </table>
@@ -38,9 +38,9 @@ Here you can find links to supporting documentation for the current released ver
<th>Community</th> <th>Community</th>
</tr> </tr>
<tr> <tr>
<td><b>v2.12.5</b></td> <td><b>v2.12.6</b></td>
<td><a href="https://ranchermanager.docs.rancher.com/v2.12">Documentation</a></td> <td><a href="https://ranchermanager.docs.rancher.com/v2.12">Documentation</a></td>
<td><a href="https://github.com/rancher/rancher/releases/tag/v2.12.5">Release Notes</a></td> <td><a href="https://github.com/rancher/rancher/releases/tag/v2.12.6">Release Notes</a></td>
<td><center>N/A</center></td> <td><center>N/A</center></td>
<td><center>&#10003;</center></td> <td><center>&#10003;</center></td>
<td><center>N/A</center></td> <td><center>N/A</center></td>
@@ -59,9 +59,9 @@ Here you can find links to supporting documentation for the current released ver
<th>Community</th> <th>Community</th>
</tr> </tr>
<tr> <tr>
<td><b>v2.11.9</b></td> <td><b>v2.11.10</b></td>
<td><a href="https://ranchermanager.docs.rancher.com/v2.11">Documentation</a></td> <td><a href="https://ranchermanager.docs.rancher.com/v2.11">Documentation</a></td>
<td><a href="https://github.com/rancher/rancher/releases/tag/v2.11.9">Release Notes</a></td> <td><a href="https://github.com/rancher/rancher/releases/tag/v2.11.10">Release Notes</a></td>
<td><center>N/A</center></td> <td><center>N/A</center></td>
<td><center>&#10003;</center></td> <td><center>&#10003;</center></td>
<td><center>NA</center></td> <td><center>NA</center></td>
@@ -80,9 +80,9 @@ Here you can find links to supporting documentation for the current released ver
<th>Community</th> <th>Community</th>
</tr> </tr>
<tr> <tr>
<td><b>v2.10.10</b></td> <td><b>v2.10.11</b></td>
<td><a href="https://ranchermanager.docs.rancher.com/v2.10">Documentation</a></td> <td><a href="https://ranchermanager.docs.rancher.com/v2.10">Documentation</a></td>
<td><a href="https://github.com/rancher/rancher/releases/tag/v2.10.10">Release Notes</a></td> <td><a href="https://github.com/rancher/rancher/releases/tag/v2.10.11">Release Notes</a></td>
<td><center>N/A</center></td> <td><center>N/A</center></td>
<td><center>&#10003;</center></td> <td><center>&#10003;</center></td>
<td><center>N/A</center></td> <td><center>N/A</center></td>
@@ -122,6 +122,14 @@ Here you can find links to supporting documentation for previous versions of Ran
<th>Support Matrix</th> <th>Support Matrix</th>
<th>Prime</th> <th>Prime</th>
<th>Community</th> <th>Community</th>
</tr>
<tr>
<td><b>v2.13.1</b></td>
<td><a href="https://ranchermanager.docs.rancher.com/v2.13">Documentation</a></td>
<td><a href="https://github.com/rancher/rancher/releases/tag/v2.13.1">Release Notes</a></td>
<td><center><a href="https://www.suse.com/suse-rancher/support-matrix/all-supported-versions/rancher-v2-13-1/">Support Matrix</a></center></td>
<td><center>&#10003;</center></td>
<td><center>&#10003;</center></td>
</tr> </tr>
<tr> <tr>
<td><b>v2.13.0</b></td> <td><b>v2.13.0</b></td>
@@ -143,6 +151,14 @@ Here you can find links to supporting documentation for previous versions of Ran
<th>Support Matrix</th> <th>Support Matrix</th>
<th>Prime</th> <th>Prime</th>
<th>Community</th> <th>Community</th>
</tr>
<tr>
<td><b>v2.12.5</b></td>
<td><a href="https://ranchermanager.docs.rancher.com/v2.12">Documentation</a></td>
<td><a href="https://github.com/rancher/rancher/releases/tag/v2.12.5">Release Notes</a></td>
<td><center><a href="https://www.suse.com/suse-rancher/support-matrix/all-supported-versions/rancher-v2-12-5/">Support Matrix</a></center></td>
<td><center>&#10003;</center></td>
<td><center>N/A</center></td>
</tr> </tr>
<tr> <tr>
<td><b>v2.12.4</b></td> <td><b>v2.12.4</b></td>
@@ -196,6 +212,14 @@ Here you can find links to supporting documentation for previous versions of Ran
<th>Support Matrix</th> <th>Support Matrix</th>
<th>Prime</th> <th>Prime</th>
<th>Community</th> <th>Community</th>
</tr>
<tr>
<td><b>v2.11.9</b></td>
<td><a href="https://ranchermanager.docs.rancher.com/v2.11">Documentation</a></td>
<td><a href="https://github.com/rancher/rancher/releases/tag/v2.11.9">Release Notes</a></td>
<td><center><a href="https://www.suse.com/suse-rancher/support-matrix/all-supported-versions/rancher-v2-11-9/">Support Matrix</a></center></td>
<td><center>&#10003;</center></td>
<td><center>NA</center></td>
</tr> </tr>
<tr> <tr>
<td><b>v2.11.8</b></td> <td><b>v2.11.8</b></td>
@@ -281,6 +305,14 @@ Here you can find links to supporting documentation for previous versions of Ran
<th>Support Matrix</th> <th>Support Matrix</th>
<th>Prime</th> <th>Prime</th>
<th>Community</th> <th>Community</th>
</tr>
<tr>
<td><b>v2.10.10</b></td>
<td><a href="https://ranchermanager.docs.rancher.com/v2.10">Documentation</a></td>
<td><a href="https://github.com/rancher/rancher/releases/tag/v2.10.10">Release Notes</a></td>
<td><center><a href="https://www.suse.com/suse-rancher/support-matrix/all-supported-versions/rancher-v2-10-10/">Support Matrix</a></center></td>
<td><center>&#10003;</center></td>
<td><center>N/A</center></td>
</tr> </tr>
<tr> <tr>
<td><b>v2.10.9</b></td> <td><b>v2.10.9</b></td>
@@ -8,7 +8,7 @@ title: Deprecated Features in Rancher
## What is Rancher's deprecation policy? ## What is Rancher's deprecation policy?
We have published our official deprecation policy in the support [terms of service](https://rancher.com/support-maintenance-terms). The community version of Rancher follows the same deprecation policy as Rancher Prime. The official deprecation policy is documented in the [Rancher Prime Deprecation Policy](https://www.suse.com/support/rancher-prime/#Rancher-Prime-Deprecation-Policy).
## Where can I find out which features have been deprecated in Rancher? ## Where can I find out which features have been deprecated in Rancher?
@@ -16,6 +16,7 @@ Rancher will publish deprecated features as part of the [release notes](https://
| Patch Version | Release Date | | Patch Version | Release Date |
|---------------|---------------| |---------------|---------------|
| [2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) | January 29, 2026 |
| [2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10) | September 25, 2025 | | [2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10) | September 25, 2025 |
| [2.10.9](https://github.com/rancher/rancher/releases/tag/v2.10.9) | August 27, 2025 | | [2.10.9](https://github.com/rancher/rancher/releases/tag/v2.10.9) | August 27, 2025 |
| [2.10.8](https://github.com/rancher/rancher/releases/tag/v2.10.8) | July 30, 2025 | | [2.10.8](https://github.com/rancher/rancher/releases/tag/v2.10.8) | July 30, 2025 |
@@ -29,7 +29,14 @@ Consult the documentation for your specific IdP to complete the listed prerequis
`Access Type` | `confidential` `Access Type` | `confidential`
`Valid Redirect URI` | `https://yourRancherHostURL/verify-auth` `Valid Redirect URI` | `https://yourRancherHostURL/verify-auth`
- In the new OIDC client, create mappers to expose the users fields. - In the new OIDC client, create mappers to expose the user's fields.
:::note
The `groups` and `full_group_path` claims generated by the Groups and Group Path mappers, which you create within the OIDC client in your Identity Provider, should be JSON arrays, e.g. `"groups":["admins","devs","qa"]` and `"full_group_path":["/admins","/devs","/qa"]`.
:::
- Create a new Groups Mapper with the settings below: - Create a new Groups Mapper with the settings below:
Setting | Value Setting | Value
@@ -66,7 +66,8 @@ Before you create your own custom catalog, you should have a basic understanding
![values.yaml](/img/helm-app-2.6.png) ![values.yaml](/img/helm-app-2.6.png)
### Chart.yaml annotations ### Chart.yaml
#### Annotations
Rancher supports additional annotations that you can add to the `Chart.yaml` file. These annotations allow you to define application dependencies or configure additional UI defaults: Rancher supports additional annotations that you can add to the `Chart.yaml` file. These annotations allow you to define application dependencies or configure additional UI defaults:
@@ -76,10 +77,14 @@ Rancher supports additional annotations that you can add to the `Chart.yaml` fil
| catalog.cattle.io/display-name | A display name that should be displayed in the App Marketplace instead of the chart name | Display Name of Chart | | catalog.cattle.io/display-name | A display name that should be displayed in the App Marketplace instead of the chart name | Display Name of Chart |
| catalog.cattle.io/namespace | A fixed namespace where the chart should be deployed in. If set, this can't be changed by the user | fixed-namespace | | catalog.cattle.io/namespace | A fixed namespace where the chart should be deployed in. If set, this can't be changed by the user | fixed-namespace |
| catalog.cattle.io/release-name | A fixed release name for the Helm installation. If set, this can't be changed by the user | fixed-release-name | | catalog.cattle.io/release-name | A fixed release name for the Helm installation. If set, this can't be changed by the user | fixed-release-name |
| catalog.cattle.io/requests-cpu | Total amount of CPU that should be unreserverd in the cluster. If less CPU is available, a warning will be shown | 2000m | | catalog.cattle.io/requests-cpu | Total amount of CPU that should be unreserved in the cluster. If less CPU is available, a warning will be shown | 2000m |
| catalog.cattle.io/requests-memory | Total amount of memory that should be unreserverd in the cluster. If less memory is available, a warning will be shown | 2Gi | | catalog.cattle.io/requests-memory | Total amount of memory that should be unreserved in the cluster. If less memory is available, a warning will be shown | 2Gi |
| catalog.cattle.io/os | Restricts the OS where this chart can be installed. Possible values: `linux`, `windows`. Default: no restriction | linux | | catalog.cattle.io/os | Restricts the OS where this chart can be installed. Possible values: `linux`, `windows`. Default: no restriction | linux |
### Keywords
With the `keywords` option in the `Chart.yaml` file it is possible to provide a list of categories for sorting your application in the Rancher UI, like `infrastructure`, `monitoring` and more.
### questions.yml ### questions.yml
Inside the `questions.yml`, most of the content will be around the questions to ask the end user, but there are some additional fields that can be set in this file. Inside the `questions.yml`, most of the content will be around the questions to ask the end user, but there are some additional fields that can be set in this file.
@@ -54,6 +54,7 @@ IAM Policy for nodes with the `controlplane` role:
"autoscaling:DescribeTags", "autoscaling:DescribeTags",
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeAvailabilityZones",
"ec2:DescribeRouteTables", "ec2:DescribeRouteTables",
"ec2:DescribeSecurityGroups", "ec2:DescribeSecurityGroups",
"ec2:DescribeSubnets", "ec2:DescribeSubnets",
@@ -123,6 +124,7 @@ IAM policy for nodes with the `etcd` or `worker` role:
"Action": [ "Action": [
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeAvailabilityZones",
"ecr:GetAuthorizationToken", "ecr:GetAuthorizationToken",
"ecr:BatchCheckLayerAvailability", "ecr:BatchCheckLayerAvailability",
"ecr:GetDownloadUrlForLayer", "ecr:GetDownloadUrlForLayer",
@@ -19,6 +19,7 @@ In order to deploy and run the adapter successfully, you need to ensure its vers
| Rancher Version | Adapter Version | | Rancher Version | Adapter Version |
|-----------------|------------------| |-----------------|------------------|
| v2.10.11 | v105.0.0+up5.0.1 |
| v2.10.10 | v105.0.0+up5.0.1 | | v2.10.10 | v105.0.0+up5.0.1 |
| v2.10.9 | v105.0.0+up5.0.1 | | v2.10.9 | v105.0.0+up5.0.1 |
| v2.10.8 | v105.0.0+up5.0.1 | | v2.10.8 | v105.0.0+up5.0.1 |
@@ -10,6 +10,8 @@ Rancher is committed to informing the community of security issues in our produc
| ID | Description | Date | Resolution | | ID | Description | Date | Resolution |
|----|-------------|------|------------| |----|-------------|------|------------|
| [CVE-2025-62879](https://github.com/rancher/backup-restore-operator/security/advisories/GHSA-wj3p-5h3x-c74q) | Rancher now provides new versions of the Rancher Backup chart which prevent the leak of secret S3 credentials via the Rancher Backup pod log. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2025-67601](https://github.com/rancher/rancher/security/advisories/GHSA-mc24-7m59-4q5p) | Rancher now removes the ability to fetch CA certificates stored in Rancher’s setting `cacerts` when using the `login` command. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) | | [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) |
| [CVE-2024-58267](https://github.com/rancher/rancher/security/advisories/GHSA-v3vj-5868-2ch2) | The Rancher CLI is modified to print the `requestId` more visibly than as part of the login URL. It also adds a `cli=true` origin marker to the URL. The dashboard is modified to recognize the presence of the `requestId` and uses that to show a warning message to the user, asking for verification that they initiated a CLI login with the related Id. The non-presence of the origin marker enables the dashboard to distinguish between the modified CLI and older CLI’s, and adjust the message accordingly. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) | | [CVE-2024-58267](https://github.com/rancher/rancher/security/advisories/GHSA-v3vj-5868-2ch2) | The Rancher CLI is modified to print the `requestId` more visibly than as part of the login URL. It also adds a `cli=true` origin marker to the URL. The dashboard is modified to recognize the presence of the `requestId` and uses that to show a warning message to the user, asking for verification that they initiated a CLI login with the related Id. The non-presence of the origin marker enables the dashboard to distinguish between the modified CLI and older CLI’s, and adjust the message accordingly. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) |
| [CVE-2025-54468](https://github.com/rancher/rancher/security/advisories/GHSA-mjcp-rj3c-36fr) | `Impersonate-*` headers are removed for requests made through the `/meta/proxy` Rancher endpoint (e.g. when cloud credentials are being created) as the headers may contain identifiable and/or sensitive information. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) | | [CVE-2025-54468](https://github.com/rancher/rancher/security/advisories/GHSA-mjcp-rj3c-36fr) | `Impersonate-*` headers are removed for requests made through the `/meta/proxy` Rancher endpoint (e.g. when cloud credentials are being created) as the headers may contain identifiable and/or sensitive information. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) |
@@ -20,6 +20,7 @@ Each Rancher version is designed to be compatible with a single version of the w
| Rancher Version | Webhook Version | Availability in Prime | Availability in Community | | Rancher Version | Webhook Version | Availability in Prime | Availability in Community |
|-----------------|-----------------|-----------------------|---------------------------| |-----------------|-----------------|-----------------------|---------------------------|
| v2.10.11 | v0.6.12 | &check; | &cross; |
| v2.10.10 | v0.6.11 | &check; | &cross; | | v2.10.10 | v0.6.11 | &check; | &cross; |
| v2.10.9 | v0.6.10 | &check; | &cross; | | v2.10.9 | v0.6.10 | &check; | &cross; |
| v2.10.8 | v0.6.9 | &check; | &cross; | | v2.10.8 | v0.6.9 | &check; | &cross; |
@@ -8,7 +8,7 @@ title: Deprecated Features in Rancher
## What is Rancher's deprecation policy? ## What is Rancher's deprecation policy?
We have published our official deprecation policy in the support [terms of service](https://rancher.com/support-maintenance-terms). The community version of Rancher follows the same deprecation policy as Rancher Prime. The official deprecation policy is documented in the [Rancher Prime Deprecation Policy](https://www.suse.com/support/rancher-prime/#Rancher-Prime-Deprecation-Policy).
## Where can I find out which features have been deprecated in Rancher? ## Where can I find out which features have been deprecated in Rancher?
@@ -16,6 +16,7 @@ Rancher will publish deprecated features as part of the [release notes](https://
| Patch Version | Release Date | | Patch Version | Release Date |
|---------------|---------------| |---------------|---------------|
| [2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10) | January 29, 2026 |
| [2.11.9](https://github.com/rancher/rancher/releases/tag/v2.11.9) | December 18, 2025 | | [2.11.9](https://github.com/rancher/rancher/releases/tag/v2.11.9) | December 18, 2025 |
| [2.11.8](https://github.com/rancher/rancher/releases/tag/v2.11.8) | November 24, 2025 | | [2.11.8](https://github.com/rancher/rancher/releases/tag/v2.11.8) | November 24, 2025 |
| [2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) | October 23, 2025 | | [2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) | October 23, 2025 |
@@ -29,7 +29,14 @@ Consult the documentation for your specific IdP to complete the listed prerequis
`Access Type` | `confidential` `Access Type` | `confidential`
`Valid Redirect URI` | `https://yourRancherHostURL/verify-auth` `Valid Redirect URI` | `https://yourRancherHostURL/verify-auth`
- In the new OIDC client, create mappers to expose the users fields. - In the new OIDC client, create mappers to expose the user's fields.
:::note
The `groups` and `full_group_path` claims generated by the Groups and Group Path mappers, which you create within the OIDC client in your Identity Provider, should be JSON arrays, e.g. `"groups":["admins","devs","qa"]` and `"full_group_path":["/admins","/devs","/qa"]`.
:::
- Create a new Groups Mapper with the settings below: - Create a new Groups Mapper with the settings below:
Setting | Value Setting | Value
@@ -66,7 +66,8 @@ Before you create your own custom catalog, you should have a basic understanding
![values.yaml](/img/helm-app-2.6.png) ![values.yaml](/img/helm-app-2.6.png)
### Chart.yaml annotations ### Chart.yaml
#### Annotations
Rancher supports additional annotations that you can add to the `Chart.yaml` file. These annotations allow you to define application dependencies or configure additional UI defaults: Rancher supports additional annotations that you can add to the `Chart.yaml` file. These annotations allow you to define application dependencies or configure additional UI defaults:
@@ -76,10 +77,14 @@ Rancher supports additional annotations that you can add to the `Chart.yaml` fil
| catalog.cattle.io/display-name | A display name that should be displayed in the App Marketplace instead of the chart name | Display Name of Chart | | catalog.cattle.io/display-name | A display name that should be displayed in the App Marketplace instead of the chart name | Display Name of Chart |
| catalog.cattle.io/namespace | A fixed namespace where the chart should be deployed in. If set, this can't be changed by the user | fixed-namespace | | catalog.cattle.io/namespace | A fixed namespace where the chart should be deployed in. If set, this can't be changed by the user | fixed-namespace |
| catalog.cattle.io/release-name | A fixed release name for the Helm installation. If set, this can't be changed by the user | fixed-release-name | | catalog.cattle.io/release-name | A fixed release name for the Helm installation. If set, this can't be changed by the user | fixed-release-name |
| catalog.cattle.io/requests-cpu | Total amount of CPU that should be unreserverd in the cluster. If less CPU is available, a warning will be shown | 2000m | | catalog.cattle.io/requests-cpu | Total amount of CPU that should be unreserved in the cluster. If less CPU is available, a warning will be shown | 2000m |
| catalog.cattle.io/requests-memory | Total amount of memory that should be unreserverd in the cluster. If less memory is available, a warning will be shown | 2Gi | | catalog.cattle.io/requests-memory | Total amount of memory that should be unreserved in the cluster. If less memory is available, a warning will be shown | 2Gi |
| catalog.cattle.io/os | Restricts the OS where this chart can be installed. Possible values: `linux`, `windows`. Default: no restriction | linux | | catalog.cattle.io/os | Restricts the OS where this chart can be installed. Possible values: `linux`, `windows`. Default: no restriction | linux |
### Keywords
With the `keywords` option in the `Chart.yaml` file it is possible to provide a list of categories for sorting your application in the Rancher UI, like `infrastructure`, `monitoring` and more.
### questions.yml ### questions.yml
Inside the `questions.yml`, most of the content will be around the questions to ask the end user, but there are some additional fields that can be set in this file. Inside the `questions.yml`, most of the content will be around the questions to ask the end user, but there are some additional fields that can be set in this file.
@@ -54,6 +54,7 @@ IAM Policy for nodes with the `controlplane` role:
"autoscaling:DescribeTags", "autoscaling:DescribeTags",
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeAvailabilityZones",
"ec2:DescribeRouteTables", "ec2:DescribeRouteTables",
"ec2:DescribeSecurityGroups", "ec2:DescribeSecurityGroups",
"ec2:DescribeSubnets", "ec2:DescribeSubnets",
@@ -123,6 +124,7 @@ IAM policy for nodes with the `etcd` or `worker` role:
"Action": [ "Action": [
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeAvailabilityZones",
"ecr:GetAuthorizationToken", "ecr:GetAuthorizationToken",
"ecr:BatchCheckLayerAvailability", "ecr:BatchCheckLayerAvailability",
"ecr:GetDownloadUrlForLayer", "ecr:GetDownloadUrlForLayer",
@@ -19,6 +19,7 @@ In order to deploy and run the adapter successfully, you need to ensure its vers
| Rancher Version | Adapter Version | | Rancher Version | Adapter Version |
|-----------------|------------------| |-----------------|------------------|
| v2.11.10 | v106.0.0+up6.0.0 |
| v2.11.9 | v106.0.0+up6.0.0 | | v2.11.9 | v106.0.0+up6.0.0 |
| v2.11.8 | v106.0.0+up6.0.0 | | v2.11.8 | v106.0.0+up6.0.0 |
| v2.11.7 | v106.0.0+up6.0.0 | | v2.11.7 | v106.0.0+up6.0.0 |
@@ -10,6 +10,8 @@ Rancher is committed to informing the community of security issues in our produc
| ID | Description | Date | Resolution | | ID | Description | Date | Resolution |
|----|-------------|------|------------| |----|-------------|------|------------|
| [CVE-2025-62879](https://github.com/rancher/backup-restore-operator/security/advisories/GHSA-wj3p-5h3x-c74q) | Rancher now provides new versions of the Rancher Backup chart which prevent the leak of secret S3 credentials via the Rancher Backup pod log. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2025-67601](https://github.com/rancher/rancher/security/advisories/GHSA-mc24-7m59-4q5p) | Rancher now removes the ability to fetch CA certificates stored in Rancher’s setting `cacerts` when using the `login` command. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2023-32199](https://github.com/rancher/rancher/security/advisories/GHSA-j4vr-pcmw-hx59) | Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation `authz.cluster.cattle.io/admin-globalrole-missing=true`. | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) and [v2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) | | [CVE-2023-32199](https://github.com/rancher/rancher/security/advisories/GHSA-j4vr-pcmw-hx59) | Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation `authz.cluster.cattle.io/admin-globalrole-missing=true`. | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) and [v2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) |
| [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) | | [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) |
| [CVE-2024-58267](https://github.com/rancher/rancher/security/advisories/GHSA-v3vj-5868-2ch2) | The Rancher CLI is modified to print the `requestId` more visibly than as part of the login URL. It also adds a `cli=true` origin marker to the URL. The dashboard is modified to recognize the presence of the `requestId` and uses that to show a warning message to the user, asking for verification that they initiated a CLI login with the related Id. The non-presence of the origin marker enables the dashboard to distinguish between the modified CLI and older CLI’s, and adjust the message accordingly. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) | | [CVE-2024-58267](https://github.com/rancher/rancher/security/advisories/GHSA-v3vj-5868-2ch2) | The Rancher CLI is modified to print the `requestId` more visibly than as part of the login URL. It also adds a `cli=true` origin marker to the URL. The dashboard is modified to recognize the presence of the `requestId` and uses that to show a warning message to the user, asking for verification that they initiated a CLI login with the related Id. The non-presence of the origin marker enables the dashboard to distinguish between the modified CLI and older CLI’s, and adjust the message accordingly. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) |
@@ -20,6 +20,7 @@ Each Rancher version is designed to be compatible with a single version of the w
| Rancher Version | Webhook Version | Availability in Prime | Availability in Community | | Rancher Version | Webhook Version | Availability in Prime | Availability in Community |
|-----------------|-----------------|-----------------------|---------------------------| |-----------------|-----------------|-----------------------|---------------------------|
| v2.11.10 | v0.7.8 | &check; | &cross; |
| v2.11.9 | v0.7.8 | &check; | &cross; | | v2.11.9 | v0.7.8 | &check; | &cross; |
| v2.11.8 | v0.7.8 | &check; | &cross; | | v2.11.8 | v0.7.8 | &check; | &cross; |
| v2.11.7 | v0.7.7 | &check; | &cross; | | v2.11.7 | v0.7.7 | &check; | &cross; |
@@ -8,7 +8,7 @@ title: Deprecated Features in Rancher
## What is Rancher's deprecation policy? ## What is Rancher's deprecation policy?
We have published our official deprecation policy in the support [terms of service](https://rancher.com/support-maintenance-terms). The community version of Rancher follows the same deprecation policy as Rancher Prime. The official deprecation policy is documented in the [Rancher Prime Deprecation Policy](https://www.suse.com/support/rancher-prime/#Rancher-Prime-Deprecation-Policy).
## Where can I find out which features have been deprecated in Rancher? ## Where can I find out which features have been deprecated in Rancher?
@@ -16,6 +16,7 @@ Rancher will publish deprecated features as part of the [release notes](https://
| Patch Version | Release Date | | Patch Version | Release Date |
|---------------|---------------| |---------------|---------------|
| [2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6) | January 29, 2026 |
| [2.12.5](https://github.com/rancher/rancher/releases/tag/v2.12.5) | December 18, 2025 | | [2.12.5](https://github.com/rancher/rancher/releases/tag/v2.12.5) | December 18, 2025 |
| [2.12.4](https://github.com/rancher/rancher/releases/tag/v2.12.4) | November 24, 2025 | | [2.12.4](https://github.com/rancher/rancher/releases/tag/v2.12.4) | November 24, 2025 |
| [2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) | October 23, 2025 | | [2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) | October 23, 2025 |
@@ -15,10 +15,8 @@ The etcd data set is automatically cleaned up on a five-minute interval by Kuber
```yaml ```yaml
# RKE2/K3s config.yaml # RKE2/K3s config.yaml
--- ---
services: etcd-arg:
etcd: - "quota-backend-bytes=5368709120"
extra_args:
quota-backend-bytes: 5368709120
``` ```
## Scaling etcd Disk Performance ## Scaling etcd Disk Performance
@@ -32,12 +30,7 @@ To implement this solution in an RKE2/K3s cluster, the `/var/lib/etcd/data` and
```yaml ```yaml
# RKE2/K3s config.yaml # RKE2/K3s config.yaml
--- ---
services: etcd-arg:
etcd: - "data-dir=/var/lib/etcd/data"
extra_args: - "wal-dir=/var/lib/etcd/wal"
data-dir: '/var/lib/rancher/etcd/data/'
wal-dir: '/var/lib/rancher/etcd/wal/wal_dir'
extra_binds:
- '/var/lib/etcd/data:/var/lib/rancher/etcd/data'
- '/var/lib/etcd/wal:/var/lib/rancher/etcd/wal'
``` ```
@@ -29,7 +29,14 @@ Consult the documentation for your specific IdP to complete the listed prerequis
`Access Type` | `confidential` `Access Type` | `confidential`
`Valid Redirect URI` | `https://yourRancherHostURL/verify-auth` `Valid Redirect URI` | `https://yourRancherHostURL/verify-auth`
- In the new OIDC client, create mappers to expose the users fields. - In the new OIDC client, create mappers to expose the user's fields.
:::note
The `groups` and `full_group_path` claims generated by the Groups and Group Path mappers, which you create within the OIDC client in your Identity Provider, should be JSON arrays, e.g. `"groups":["admins","devs","qa"]` and `"full_group_path":["/admins","/devs","/qa"]`.
:::
- Create a new Groups Mapper with the settings below: - Create a new Groups Mapper with the settings below:
Setting | Value Setting | Value
@@ -66,7 +66,8 @@ Before you create your own custom catalog, you should have a basic understanding
![values.yaml](/img/helm-app-2.6.png) ![values.yaml](/img/helm-app-2.6.png)
### Chart.yaml annotations ### Chart.yaml
#### Annotations
Rancher supports additional annotations that you can add to the `Chart.yaml` file. These annotations allow you to define application dependencies or configure additional UI defaults: Rancher supports additional annotations that you can add to the `Chart.yaml` file. These annotations allow you to define application dependencies or configure additional UI defaults:
@@ -76,10 +77,14 @@ Rancher supports additional annotations that you can add to the `Chart.yaml` fil
| catalog.cattle.io/display-name | A display name that should be displayed in the App Marketplace instead of the chart name | Display Name of Chart | | catalog.cattle.io/display-name | A display name that should be displayed in the App Marketplace instead of the chart name | Display Name of Chart |
| catalog.cattle.io/namespace | A fixed namespace where the chart should be deployed in. If set, this can't be changed by the user | fixed-namespace | | catalog.cattle.io/namespace | A fixed namespace where the chart should be deployed in. If set, this can't be changed by the user | fixed-namespace |
| catalog.cattle.io/release-name | A fixed release name for the Helm installation. If set, this can't be changed by the user | fixed-release-name | | catalog.cattle.io/release-name | A fixed release name for the Helm installation. If set, this can't be changed by the user | fixed-release-name |
| catalog.cattle.io/requests-cpu | Total amount of CPU that should be unreserverd in the cluster. If less CPU is available, a warning will be shown | 2000m | | catalog.cattle.io/requests-cpu | Total amount of CPU that should be unreserved in the cluster. If less CPU is available, a warning will be shown | 2000m |
| catalog.cattle.io/requests-memory | Total amount of memory that should be unreserverd in the cluster. If less memory is available, a warning will be shown | 2Gi | | catalog.cattle.io/requests-memory | Total amount of memory that should be unreserved in the cluster. If less memory is available, a warning will be shown | 2Gi |
| catalog.cattle.io/os | Restricts the OS where this chart can be installed. Possible values: `linux`, `windows`. Default: no restriction | linux | | catalog.cattle.io/os | Restricts the OS where this chart can be installed. Possible values: `linux`, `windows`. Default: no restriction | linux |
### Keywords
With the `keywords` option in the `Chart.yaml` file it is possible to provide a list of categories for sorting your application in the Rancher UI, like `infrastructure`, `monitoring` and more.
### questions.yml ### questions.yml
Inside the `questions.yml`, most of the content will be around the questions to ask the end user, but there are some additional fields that can be set in this file. Inside the `questions.yml`, most of the content will be around the questions to ask the end user, but there are some additional fields that can be set in this file.
@@ -54,6 +54,7 @@ IAM Policy for nodes with the `controlplane` role:
"autoscaling:DescribeTags", "autoscaling:DescribeTags",
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeAvailabilityZones",
"ec2:DescribeRouteTables", "ec2:DescribeRouteTables",
"ec2:DescribeSecurityGroups", "ec2:DescribeSecurityGroups",
"ec2:DescribeSubnets", "ec2:DescribeSubnets",
@@ -123,6 +124,7 @@ IAM policy for nodes with the `etcd` or `worker` role:
"Action": [ "Action": [
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeAvailabilityZones",
"ecr:GetAuthorizationToken", "ecr:GetAuthorizationToken",
"ecr:BatchCheckLayerAvailability", "ecr:BatchCheckLayerAvailability",
"ecr:GetDownloadUrlForLayer", "ecr:GetDownloadUrlForLayer",
@@ -19,6 +19,7 @@ In order to deploy and run the adapter successfully, you need to ensure its vers
| Rancher Version | Adapter Version | | Rancher Version | Adapter Version |
|-----------------|------------------| |-----------------|------------------|
| v2.12.6 | 107.0.0+up7.0.0 |
| v2.12.5 | 107.0.0+up7.0.0 | | v2.12.5 | 107.0.0+up7.0.0 |
| v2.12.4 | 107.0.0+up7.0.0 | | v2.12.4 | 107.0.0+up7.0.0 |
| v2.12.3 | 107.0.0+up7.0.0 | | v2.12.3 | 107.0.0+up7.0.0 |
@@ -10,6 +10,8 @@ Rancher is committed to informing the community of security issues in our produc
| ID | Description | Date | Resolution | | ID | Description | Date | Resolution |
|----|-------------|------|------------| |----|-------------|------|------------|
| [CVE-2025-62879](https://github.com/rancher/backup-restore-operator/security/advisories/GHSA-wj3p-5h3x-c74q) | Rancher now provides new versions of the Rancher Backup chart which prevent the leak of secret S3 credentials via the Rancher Backup pod log. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2025-67601](https://github.com/rancher/rancher/security/advisories/GHSA-mc24-7m59-4q5p) | Rancher now removes the ability to fetch CA certificates stored in Rancher’s setting `cacerts` when using the `login` command. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2023-32199](https://github.com/rancher/rancher/security/advisories/GHSA-j4vr-pcmw-hx59) | Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation `authz.cluster.cattle.io/admin-globalrole-missing=true`. | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) and [v2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) | | [CVE-2023-32199](https://github.com/rancher/rancher/security/advisories/GHSA-j4vr-pcmw-hx59) | Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation `authz.cluster.cattle.io/admin-globalrole-missing=true`. | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) and [v2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) |
| [CVE-2024-58269](https://github.com/rancher/rancher/security/advisories/GHSA-mw39-9qc2-f7mg) | The Rancher audit log redaction process has changed to the following: <br/><br/><ul><li> It now redacts `kubectl.kubernetes.io/last-applied-configuration` annotations on both Response and Request body contents. Previously it did not redact Response body content.</li><li> It now redacts Cluster Import URLs on both Request URLs and Referer headers. Previously it did not redact Referer headers.</li></ul> | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) | | [CVE-2024-58269](https://github.com/rancher/rancher/security/advisories/GHSA-mw39-9qc2-f7mg) | The Rancher audit log redaction process has changed to the following: <br/><br/><ul><li> It now redacts `kubectl.kubernetes.io/last-applied-configuration` annotations on both Response and Request body contents. Previously it did not redact Response body content.</li><li> It now redacts Cluster Import URLs on both Request URLs and Referer headers. Previously it did not redact Referer headers.</li></ul> | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) |
| [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) | | [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) |
@@ -20,6 +20,7 @@ Each Rancher version is designed to be compatible with a single version of the w
| Rancher Version | Webhook Version | Availability in Prime | Availability in Community | | Rancher Version | Webhook Version | Availability in Prime | Availability in Community |
|-----------------|-----------------|-----------------------|---------------------------| |-----------------|-----------------|-----------------------|---------------------------|
| v2.12.6 | v0.8.5 | &check; | &cross; |
| v2.12.5 | v0.8.4 | &check; | &cross; | | v2.12.5 | v0.8.4 | &check; | &cross; |
| v2.12.4 | v0.8.4 | &check; | &cross; | | v2.12.4 | v0.8.4 | &check; | &cross; |
| v2.12.3 | v0.8.3 | &check; | &check; | | v2.12.3 | v0.8.3 | &check; | &check; |
@@ -8,7 +8,7 @@ title: Deprecated Features in Rancher
## What is Rancher's deprecation policy? ## What is Rancher's deprecation policy?
We have published our official deprecation policy in the support [terms of service](https://rancher.com/support-maintenance-terms). The community version of Rancher follows the same deprecation policy as Rancher Prime. The official deprecation policy is documented in the [Rancher Prime Deprecation Policy](https://www.suse.com/support/rancher-prime/#Rancher-Prime-Deprecation-Policy).
## Where can I find out which features have been deprecated in Rancher? ## Where can I find out which features have been deprecated in Rancher?
@@ -16,6 +16,8 @@ Rancher will publish deprecated features as part of the [release notes](https://
| Patch Version | Release Date | | Patch Version | Release Date |
|---------------|---------------| |---------------|---------------|
| [2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2) | January 29, 2026 |
| [2.13.1](https://github.com/rancher/rancher/releases/tag/v2.13.1) | December 18, 2025 |
| [2.13.0](https://github.com/rancher/rancher/releases/tag/v2.13.0) | November 25, 2025 | | [2.13.0](https://github.com/rancher/rancher/releases/tag/v2.13.0) | November 25, 2025 |
## What can I expect when a feature is marked for deprecation? ## What can I expect when a feature is marked for deprecation?
@@ -50,6 +50,38 @@ The following CLI tools are required for setting up the Kubernetes cluster. Plea
## Install the Rancher Helm Chart ## Install the Rancher Helm Chart
:::important
**Important:** In Rancher Community v2.13.1 if your registry configuration is one of the following you may see Rancher generate the `cattle-cluster-agent` image with an incorrect `docker.io` path segment:
- Environments where a **cluster-scoped container registry** is configured for system images.
- Environments where a **global `system-default-registry`** is configured (e.g. airgap setups), even if no cluster-scoped registry is set.
**Workaround for Affected Setups:** As a workaround, override the `cattle-cluster-agent` image via the `CATTLE_AGENT_IMAGE` environment variable. This value must **not** contain any registry prefix (Rancher will handle that automatically). It should be set only to the repository and tag, for example:`rancher/rancher-agent:v2.13.1`
**Helm `install` example:**
```bash
helm install rancher rancher-latest/rancher \
...
--set extraEnv[0].name=CATTLE_AGENT_IMAGE \
--set extraEnv[0].value=rancher/rancher-agent:v2.13.1
```
**Helm `upgrade` example:**
```bash
helm upgrade rancher rancher-latest/rancher \
...
--set extraEnv[0].name=CATTLE_AGENT_IMAGE \
--set extraEnv[0].value=rancher/rancher-agent:v2.13.1
```
**Important Upgrade Note:**
The `CATTLE_AGENT_IMAGE` override is intended only as a temporary workaround for the affected configurations. Once a Rancher version is available that corrects this behavior, the `CATTLE_AGENT_IMAGE` override should be **removed** from Helm values, so that Rancher can resume managing the agent image normally and automatically track future image and tag changes. See [#53187](https://github.com/rancher/rancher/issues/53187#issuecomment-3676484603) for further information.
:::
Rancher is installed using the [Helm](https://helm.sh/) package manager for Kubernetes. Helm charts provide templating syntax for Kubernetes YAML manifest documents. With Helm, we can create configurable deployments instead of just using static files. Rancher is installed using the [Helm](https://helm.sh/) package manager for Kubernetes. Helm charts provide templating syntax for Kubernetes YAML manifest documents. With Helm, we can create configurable deployments instead of just using static files.
For systems without direct internet access, see [Air Gap: Kubernetes install](../other-installation-methods/air-gapped-helm-cli-install/install-rancher-ha.md). For systems without direct internet access, see [Air Gap: Kubernetes install](../other-installation-methods/air-gapped-helm-cli-install/install-rancher-ha.md).
@@ -28,6 +28,38 @@ Note that upgrades _to_ or _from_ any chart in the [rancher-alpha repository](..
### Helm Version ### Helm Version
:::important
**Important:** In Rancher Community v2.13.1 if your registry configuration is one of the following you may see Rancher generate the `cattle-cluster-agent` image with an incorrect `docker.io` path segment:
- Environments where a **cluster-scoped container registry** is configured for system images.
- Environments where a **global `system-default-registry`** is configured (e.g. airgap setups), even if no cluster-scoped registry is set.
**Workaround for Affected Setups:** As a workaround, override the `cattle-cluster-agent` image via the `CATTLE_AGENT_IMAGE` environment variable. This value must **not** contain any registry prefix (Rancher will handle that automatically). It should be set only to the repository and tag, for example:`rancher/rancher-agent:v2.13.1`
**Helm `install` example:**
```bash
helm install rancher rancher-latest/rancher \
...
--set extraEnv[0].name=CATTLE_AGENT_IMAGE \
--set extraEnv[0].value=rancher/rancher-agent:v2.13.1
```
**Helm `upgrade` example:**
```bash
helm upgrade rancher rancher-latest/rancher \
...
--set extraEnv[0].name=CATTLE_AGENT_IMAGE \
--set extraEnv[0].value=rancher/rancher-agent:v2.13.1
```
**Important Upgrade Note:**
The `CATTLE_AGENT_IMAGE` override is intended only as a temporary workaround for the affected configurations. Once a Rancher version is available that corrects this behavior, the `CATTLE_AGENT_IMAGE` override should be **removed** from Helm values, so that Rancher can resume managing the agent image normally and automatically track future image and tag changes. See [#53187](https://github.com/rancher/rancher/issues/53187#issuecomment-3676484603) for further information.
:::
The upgrade instructions assume you are using Helm 3. The upgrade instructions assume you are using Helm 3.
<DeprecationHelm2 /> <DeprecationHelm2 />
@@ -15,10 +15,8 @@ The etcd data set is automatically cleaned up on a five-minute interval by Kuber
```yaml ```yaml
# RKE2/K3s config.yaml # RKE2/K3s config.yaml
--- ---
services: etcd-arg:
etcd: - "quota-backend-bytes=5368709120"
extra_args:
quota-backend-bytes: 5368709120
``` ```
## Scaling etcd Disk Performance ## Scaling etcd Disk Performance
@@ -32,12 +30,7 @@ To implement this solution in an RKE2/K3s cluster, the `/var/lib/etcd/data` and
```yaml ```yaml
# RKE2/K3s config.yaml # RKE2/K3s config.yaml
--- ---
services: etcd-arg:
etcd: - "data-dir=/var/lib/etcd/data"
extra_args: - "wal-dir=/var/lib/etcd/wal"
data-dir: '/var/lib/rancher/etcd/data/'
wal-dir: '/var/lib/rancher/etcd/wal/wal_dir'
extra_binds:
- '/var/lib/etcd/data:/var/lib/rancher/etcd/data'
- '/var/lib/etcd/wal:/var/lib/rancher/etcd/wal'
``` ```
@@ -35,6 +35,12 @@ In your IdP, create a new client with the settings below:
In the new OIDC client, create mappers to expose the user's fields. In the new OIDC client, create mappers to expose the user's fields.
:::note
The `groups` and `full_group_path` claims generated by the Groups and Group Path mappers, which you create within the OIDC client in your Identity Provider, should be JSON arrays, e.g. `"groups":["admins","devs","qa"]` and `"full_group_path":["/admins","/devs","/qa"]`.
:::
1. Create a new `Groups Mapper` with the settings below: 1. Create a new `Groups Mapper` with the settings below:
Setting | Value Setting | Value
@@ -66,7 +66,8 @@ Before you create your own custom catalog, you should have a basic understanding
![values.yaml](/img/helm-app-2.6.png) ![values.yaml](/img/helm-app-2.6.png)
### Chart.yaml annotations ### Chart.yaml
#### Annotations
Rancher supports additional annotations that you can add to the `Chart.yaml` file. These annotations allow you to define application dependencies or configure additional UI defaults: Rancher supports additional annotations that you can add to the `Chart.yaml` file. These annotations allow you to define application dependencies or configure additional UI defaults:
@@ -76,10 +77,14 @@ Rancher supports additional annotations that you can add to the `Chart.yaml` fil
| catalog.cattle.io/display-name | A display name that should be displayed in the App Marketplace instead of the chart name | Display Name of Chart | | catalog.cattle.io/display-name | A display name that should be displayed in the App Marketplace instead of the chart name | Display Name of Chart |
| catalog.cattle.io/namespace | A fixed namespace where the chart should be deployed in. If set, this can't be changed by the user | fixed-namespace | | catalog.cattle.io/namespace | A fixed namespace where the chart should be deployed in. If set, this can't be changed by the user | fixed-namespace |
| catalog.cattle.io/release-name | A fixed release name for the Helm installation. If set, this can't be changed by the user | fixed-release-name | | catalog.cattle.io/release-name | A fixed release name for the Helm installation. If set, this can't be changed by the user | fixed-release-name |
| catalog.cattle.io/requests-cpu | Total amount of CPU that should be unreserverd in the cluster. If less CPU is available, a warning will be shown | 2000m | | catalog.cattle.io/requests-cpu | Total amount of CPU that should be unreserved in the cluster. If less CPU is available, a warning will be shown | 2000m |
| catalog.cattle.io/requests-memory | Total amount of memory that should be unreserverd in the cluster. If less memory is available, a warning will be shown | 2Gi | | catalog.cattle.io/requests-memory | Total amount of memory that should be unreserved in the cluster. If less memory is available, a warning will be shown | 2Gi |
| catalog.cattle.io/os | Restricts the OS where this chart can be installed. Possible values: `linux`, `windows`. Default: no restriction | linux | | catalog.cattle.io/os | Restricts the OS where this chart can be installed. Possible values: `linux`, `windows`. Default: no restriction | linux |
### Keywords
With the `keywords` option in the `Chart.yaml` file it is possible to provide a list of categories for sorting your application in the Rancher UI, like `infrastructure`, `monitoring` and more.
### questions.yml ### questions.yml
Inside the `questions.yml`, most of the content will be around the questions to ask the end user, but there are some additional fields that can be set in this file. Inside the `questions.yml`, most of the content will be around the questions to ask the end user, but there are some additional fields that can be set in this file.
@@ -54,6 +54,7 @@ IAM Policy for nodes with the `controlplane` role:
"autoscaling:DescribeTags", "autoscaling:DescribeTags",
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeAvailabilityZones",
"ec2:DescribeRouteTables", "ec2:DescribeRouteTables",
"ec2:DescribeSecurityGroups", "ec2:DescribeSecurityGroups",
"ec2:DescribeSubnets", "ec2:DescribeSubnets",
@@ -123,6 +124,7 @@ IAM policy for nodes with the `etcd` or `worker` role:
"Action": [ "Action": [
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeAvailabilityZones",
"ecr:GetAuthorizationToken", "ecr:GetAuthorizationToken",
"ecr:BatchCheckLayerAvailability", "ecr:BatchCheckLayerAvailability",
"ecr:GetDownloadUrlForLayer", "ecr:GetDownloadUrlForLayer",
@@ -19,6 +19,8 @@ In order to deploy and run the adapter successfully, you need to ensure its vers
| Rancher Version | Adapter Version | | Rancher Version | Adapter Version |
|-----------------|------------------| |-----------------|------------------|
| v2.13.2 | 108.0.0+up8.0.0 |
| v2.13.1 | 108.0.0+up8.0.0 |
| v2.13.0 | 108.0.0+up8.0.0 | | v2.13.0 | 108.0.0+up8.0.0 |
### 1. Gain Access to the Local Cluster ### 1. Gain Access to the Local Cluster
@@ -10,6 +10,8 @@ Rancher is committed to informing the community of security issues in our produc
| ID | Description | Date | Resolution | | ID | Description | Date | Resolution |
|----|-------------|------|------------| |----|-------------|------|------------|
| [CVE-2025-62879](https://github.com/rancher/backup-restore-operator/security/advisories/GHSA-wj3p-5h3x-c74q) | Rancher now provides new versions of the Rancher Backup chart which prevent the leak of secret S3 credentials via the Rancher Backup pod log. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2025-67601](https://github.com/rancher/rancher/security/advisories/GHSA-mc24-7m59-4q5p) | Rancher now removes the ability to fetch CA certificates stored in Rancher’s setting `cacerts` when using the `login` command. For more information. | 29 Jan 2026 | Rancher [v2.13.2](https://github.com/rancher/rancher/releases/tag/v2.13.2), [v2.12.6](https://github.com/rancher/rancher/releases/tag/v2.12.6), [v2.11.10](https://github.com/rancher/rancher/releases/tag/v2.11.10), and [v2.10.11](https://github.com/rancher/rancher/releases/tag/v2.10.11) |
| [CVE-2023-32199](https://github.com/rancher/rancher/security/advisories/GHSA-j4vr-pcmw-hx59) | Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation `authz.cluster.cattle.io/admin-globalrole-missing=true`. | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) and [v2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) | | [CVE-2023-32199](https://github.com/rancher/rancher/security/advisories/GHSA-j4vr-pcmw-hx59) | Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation `authz.cluster.cattle.io/admin-globalrole-missing=true`. | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) and [v2.11.7](https://github.com/rancher/rancher/releases/tag/v2.11.7) |
| [CVE-2024-58269](https://github.com/rancher/rancher/security/advisories/GHSA-mw39-9qc2-f7mg) | The Rancher audit log redaction process has changed to the following: <br/><br/><ul><li> It now redacts `kubectl.kubernetes.io/last-applied-configuration` annotations on both Response and Request body contents. Previously it did not redact Response body content.</li><li> It now redacts Cluster Import URLs on both Request URLs and Referer headers. Previously it did not redact Referer headers.</li></ul> | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) | | [CVE-2024-58269](https://github.com/rancher/rancher/security/advisories/GHSA-mw39-9qc2-f7mg) | The Rancher audit log redaction process has changed to the following: <br/><br/><ul><li> It now redacts `kubectl.kubernetes.io/last-applied-configuration` annotations on both Response and Request body contents. Previously it did not redact Response body content.</li><li> It now redacts Cluster Import URLs on both Request URLs and Referer headers. Previously it did not redact Referer headers.</li></ul> | 23 Oct 2025 | Rancher [v2.12.3](https://github.com/rancher/rancher/releases/tag/v2.12.3) |
| [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) | | [CVE-2024-58260](https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86) | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the `Manage Users` permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher [v2.12.2](https://github.com/rancher/rancher/releases/tag/v2.12.2), [v2.11.6](https://github.com/rancher/rancher/releases/tag/v2.11.6), [v2.10.10](https://github.com/rancher/rancher/releases/tag/v2.10.10), and [v2.9.12](https://github.com/rancher/rancher/releases/tag/v2.9.12) |
@@ -20,6 +20,8 @@ Each Rancher version is designed to be compatible with a single version of the w
| Rancher Version | Webhook Version | Availability in Prime | Availability in Community | | Rancher Version | Webhook Version | Availability in Prime | Availability in Community |
|-----------------|-----------------|-----------------------|---------------------------| |-----------------|-----------------|-----------------------|---------------------------|
| v2.13.2 | v0.9.2 | &check; | &check; |
| v2.13.1 | v0.9.1 | &check; | &check; |
| v2.13.0 | v0.9.0 | &cross; | &check; | | v2.13.0 | v0.9.0 | &cross; | &check; |
## Why Do We Need It? ## Why Do We Need It?
@@ -8,7 +8,7 @@ title: Deprecated Features in Rancher
## What is Rancher's deprecation policy? ## What is Rancher's deprecation policy?
We have published our official deprecation policy in the support [terms of service](https://rancher.com/support-maintenance-terms). The community version of Rancher follows the same deprecation policy as Rancher Prime. The official deprecation policy is documented in the [Rancher Prime Deprecation Policy](https://www.suse.com/support/rancher-prime/#Rancher-Prime-Deprecation-Policy).
## Where can I find out which features have been deprecated in Rancher? ## Where can I find out which features have been deprecated in Rancher?
@@ -29,7 +29,14 @@ Consult the documentation for your specific IdP to complete the listed prerequis
`Access Type` | `confidential` `Access Type` | `confidential`
`Valid Redirect URI` | `https://yourRancherHostURL/verify-auth` `Valid Redirect URI` | `https://yourRancherHostURL/verify-auth`
- In the new OIDC client, create mappers to expose the users fields. - In the new OIDC client, create mappers to expose the user's fields.
:::note
The `groups` and `full_group_path` claims generated by the Groups and Group Path mappers, which you create within the OIDC client in your Identity Provider, should be JSON arrays, e.g. `"groups":["admins","devs","qa"]` and `"full_group_path":["/admins","/devs","/qa"]`.
:::
- Create a new Groups Mapper with the settings below: - Create a new Groups Mapper with the settings below:
Setting | Value Setting | Value
@@ -66,7 +66,8 @@ Before you create your own custom catalog, you should have a basic understanding
![values.yaml](/img/helm-app-2.6.png) ![values.yaml](/img/helm-app-2.6.png)
### Chart.yaml annotations ### Chart.yaml
#### Annotations
Rancher supports additional annotations that you can add to the `Chart.yaml` file. These annotations allow you to define application dependencies or configure additional UI defaults: Rancher supports additional annotations that you can add to the `Chart.yaml` file. These annotations allow you to define application dependencies or configure additional UI defaults:
@@ -76,10 +77,14 @@ Rancher supports additional annotations that you can add to the `Chart.yaml` fil
| catalog.cattle.io/display-name | A display name that should be displayed in the App Marketplace instead of the chart name | Display Name of Chart | | catalog.cattle.io/display-name | A display name that should be displayed in the App Marketplace instead of the chart name | Display Name of Chart |
| catalog.cattle.io/namespace | A fixed namespace where the chart should be deployed in. If set, this can't be changed by the user | fixed-namespace | | catalog.cattle.io/namespace | A fixed namespace where the chart should be deployed in. If set, this can't be changed by the user | fixed-namespace |
| catalog.cattle.io/release-name | A fixed release name for the Helm installation. If set, this can't be changed by the user | fixed-release-name | | catalog.cattle.io/release-name | A fixed release name for the Helm installation. If set, this can't be changed by the user | fixed-release-name |
| catalog.cattle.io/requests-cpu | Total amount of CPU that should be unreserverd in the cluster. If less CPU is available, a warning will be shown | 2000m | | catalog.cattle.io/requests-cpu | Total amount of CPU that should be unreserved in the cluster. If less CPU is available, a warning will be shown | 2000m |
| catalog.cattle.io/requests-memory | Total amount of memory that should be unreserverd in the cluster. If less memory is available, a warning will be shown | 2Gi | | catalog.cattle.io/requests-memory | Total amount of memory that should be unreserved in the cluster. If less memory is available, a warning will be shown | 2Gi |
| catalog.cattle.io/os | Restricts the OS where this chart can be installed. Possible values: `linux`, `windows`. Default: no restriction | linux | | catalog.cattle.io/os | Restricts the OS where this chart can be installed. Possible values: `linux`, `windows`. Default: no restriction | linux |
### Keywords
With the `keywords` option in the `Chart.yaml` file it is possible to provide a list of categories for sorting your application in the Rancher UI, like `infrastructure`, `monitoring` and more.
### questions.yml ### questions.yml
Inside the `questions.yml`, most of the content will be around the questions to ask the end user, but there are some additional fields that can be set in this file. Inside the `questions.yml`, most of the content will be around the questions to ask the end user, but there are some additional fields that can be set in this file.
@@ -54,6 +54,7 @@ IAM Policy for nodes with the `controlplane` role:
"autoscaling:DescribeTags", "autoscaling:DescribeTags",
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeAvailabilityZones",
"ec2:DescribeRouteTables", "ec2:DescribeRouteTables",
"ec2:DescribeSecurityGroups", "ec2:DescribeSecurityGroups",
"ec2:DescribeSubnets", "ec2:DescribeSubnets",
@@ -123,6 +124,7 @@ IAM policy for nodes with the `etcd` or `worker` role:
"Action": [ "Action": [
"ec2:DescribeInstances", "ec2:DescribeInstances",
"ec2:DescribeRegions", "ec2:DescribeRegions",
"ec2:DescribeAvailabilityZones",
"ecr:GetAuthorizationToken", "ecr:GetAuthorizationToken",
"ecr:BatchCheckLayerAvailability", "ecr:BatchCheckLayerAvailability",
"ecr:GetDownloadUrlForLayer", "ecr:GetDownloadUrlForLayer",