live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
releaseSUPPLY CHAIN

OpenShift Pipelines 1.24 tightens network defaults and changes multicluster routing

The GA release adds default network policies, moves observability to OpenTelemetry and introduces CEL-based PipelineRun placement as a Technology Preview.

OpenShift Pipelines control plane with network policies and telemetry changes.
AI-generated illustration
By The News Desk· Sep 21, 2026the quick take — two AI hosts go live when you do

Red Hat has listed OpenShift Pipelines 1.24 as generally available, with changes spanning network isolation, multicluster execution, observability and source-control integrations. The release notes say the version is supported on OpenShift Container Platform 4.14, 4.16 and 4.18 through 4.22.

What changed

The operator and Manual Approval Gate now create default NetworkPolicy resources. For the operator, the default rules limit controller and proxy-webhook traffic to DNS, the Kubernetes API, Prometheus metrics and webhook traffic. Administrators can reconcile, override or disable the proxy-webhook policy through the TektonPipeline custom resource. Manual Approval Gate also enables restrictive ingress and egress policies by default, with an explicit opt-out in its custom resource.

For multicluster builds, the release adds Technology Preview routing based on Common Expression Language. Tekton Kueue can evaluate PipelineRun labels, annotations or event types and route individual runs through managedBy() and multiKueue() functions, replacing the previous all-or-nothing override.

OpenShift Pipelines components also move their observability plumbing from OpenCensus to OpenTelemetry. The change affects metrics names: standard Knative and OpenTelemetry prefixes replace the older tekton_pipelines_controller_* infrastructure metrics. Pipelines as Code now configures tracing directly through the OpenTelemetry SDK and supports parent-based samplers.

Other operational changes include compressed task termination messages, which Red Hat says can raise effective result capacity from roughly 33 to 187 results, and support for recording CustomRun resources in Tekton Results. The web console gains persistent date-range and datasource filters for PipelineRun and TaskRun views.

Who is affected

Platform teams should review monitoring rules and dashboards that depend on the old metrics prefixes. Clusters using Pipelines as Code should also note that Tekton Hub integration has been removed there, while the related tkn hub commands are deprecated in favor of Artifact Hub.

The release includes several source-control fixes. GitLab definitions and referenced tasks are now pinned to the event SHA, branch-creation push events can trigger runs, and token rotation checks write access before revoking the old token. Bitbucket Data Center scoped tokens can authenticate through service accounts without a dedicated user field.

What to do

Before upgrading, operators should compare existing namespace and component network policies with the new defaults, inventory alerts that use legacy Tekton metric names, and test any Pipelines as Code workflow that depends on Tekton Hub. CEL-based multicluster placement remains a Technology Preview, so it should be evaluated separately from production routing policy.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.