live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
guidePLATFORM

FedRAMP-hosted Red Hat Lightspeed retires October 30—and the replacement changes what users get

Red Hat directs affected organizations to move analytics into Satellite, where host data stays local but the Compliance service is not available.

Timeline of Red Hat Lightspeed retirement and migration steps.
Timeline: dates from the story
By The News Desk· Sep 22, 2026the quick take — two AI hosts go live when you do

Red Hat says the FedRAMP-hosted deployment of Red Hat Lightspeed will be retired on October 30, 2026. A notice in the Red Hat Lightspeed release notes directs affected customers to an on-premises deployment with Red Hat Satellite.

This is more than an endpoint change. Red Hat’s Satellite 6.19 administration guide describes different service boundaries for hosted and in-Satellite Lightspeed. Platform teams should check those boundaries before treating the migration as a like-for-like replacement.

What changes

Hosted Lightspeed sends host data through Satellite to services in the Red Hat Hybrid Cloud Console. The in-Satellite option instead runs the analysis services locally on Satellite Server and does not send reports or Insights client data to the Hybrid Cloud Console.

Both modes provide Advisor recommendations and Vulnerability reporting. Red Hat’s availability table lists Compliance for hosted Lightspeed but not for Lightspeed in Satellite. The documentation also says the hosted console is not limited to those three named services, while an in-Satellite deployment cannot use the hosted services in the Hybrid Cloud Console.

That difference matters for FedRAMP users planning the move: local processing reduces dependence on the hosted service, but it may also change workflows that currently rely on Compliance or other console-hosted capabilities.

What affected teams need to do

Red Hat’s documented migration procedure requires administrators to log Satellite Server into registry.redhat.io, enable the in-Satellite service with satellite-installer, and re-register the Insights client on managed hosts. The installer command depends on whether the local service was enabled previously: Red Hat documents --iop-ensure present for an existing deployment and --enable-iop for a new one.

After migration, administrators should verify that Satellite’s Red Hat Lightspeed menu shows Vulnerability instead of Inventory Upload and confirm that host recommendations still appear. Red Hat notes that the client re-registration step can be executed across hosts with Satellite remote execution.

What to decide now

Affected organizations have just over five weeks from the date of this report to complete the transition. Before changing the deployment, platform and security teams should inventory their use of Compliance and other Hybrid Cloud Console services, confirm that Satellite 6.19’s local service set covers the required workflows, and schedule client re-registration across the managed estate.

The retirement notice is specific to the FedRAMP-hosted deployment. Red Hat’s documentation continues to describe the standard hosted Hybrid Cloud Console integration alongside the in-Satellite option; the notice does not say that every hosted Lightspeed deployment is ending.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.