July 04, 2026
Stackers Network Digest — July 04, 2026
The Big Picture
The week straddling the US Independence Day holiday was dominated by governance and release-cycle mechanics rather than code drops. OpenStack 2026.2 "Hibiscus" hit milestone-2 (and its membership freeze), voting opened for the 2027.1 "I" release name, and the TC began framing the next election cycle. Underneath that, two structural conversations stand out: a proposed RISC-V SIG backed by ZTE hardware donations, and a call to action from the TC chair on the state of OpenStack's security documentation. Operators, meanwhile, kept the list busy with real-world pain around Horizon dependencies, Ironic/Nova placement, aarch64 Secure Boot, and kolla-ansible MFA.
Releases & Announcements
- Hibiscus (2026.2) hits M-2. July 2 was milestone-2 and the membership freeze for new deliverables. The release countdown has moved into R-12 (Jul 06–10) per Előd Illés's weekly countdown. Vitrage's deprecation governance change merged, following Venus's earlier retirement — noonedeadpunk continues to drive both teardowns.
- 2027.1 "I" release naming poll is open. Allison Price opened CIVS voting that closes Monday, July 6 at 11:59pm PT. Cast your ranking here before it shuts.
- 2027.1 election dates published. TC and PTL nominations open August 5; voting runs August 26 – September 16. Four TC seats are up. Teams currently on the DPL model will be polled shortly about whether to continue or elect a PTL. If you want to be eligible, check your Gerrit email and CIVS opt-in now.
Security
The week's most consequential thread is Goutham Pacha Ravi's security documentation crisis note — a TC-level call to reprioritize security work across the community. There's no CVE attached; the ask is for contributors and downstream vendors to help resource the effort. Anyone with security-doc bandwidth should engage on-list.
Separately, Adrian Jarvis (Catalyst Cloud) published Keystone security patches backported to Stein, with a Rocky port in progress. This is out-of-tree work for very old branches, but potentially useful to operators still running Stein.
Development & Technical Decisions
- Removing
enforce_scopeconfig. Stephen Finucane kicked off a coordinated cleanup to drop theenforce_scopepolicy config option now that scoped tokens are the norm. Patches are up per project — nova, cinder, glance, keystone, neutron. Operators who still rely on the flag should speak up before this lands. - Contributor Experience WG proposal. At the June 23 TC meeting, Goutham floated a new working group to absorb the dormant First Contact SIG and structure the "Bridging the Gap" work led by fungi, ildikov and clarkb, with focus areas on onboarding, project health and contributor recognition. Full detail in the TC weekly summary and its linked governance reviews.
- Nova + Ironic placement/AZ behavior. Nathan Harper reported back that moving an Ironic compute node into a parent aggregate works — provided the associated
nova-compute-ironicprocess (or at least a nova-compute) lives in the same AZ. Useful field data point for operators enrolling bare metal at scale.
Operator Pain Points
Several deployment threads didn't get resolved and could use expert eyes:
- kolla + Horizon 2023.1 XStatic-jQuery constraint hell. Rob Jefferson is stuck on conflicting upper-constraints for XStatic-jQuery and XStatic-jQuery-Migrate when building Horizon container images. Neither
upper_constraints_removenor version overrides worked. Second post with no replies. - kolla-ansible MFA is a no-op? Johannes Kastl on 2026.1 found that setting
multi_factor_auth_enabledvia Terraform simply broke application credentials without ever prompting for TOTP — and asks whether Keystone MFA is actually pluggable through kolla-ansible or effectively unsupported. - aarch64 Secure Boot on Nova. Jadon Naas is trying to run Secure Boot guests on Ampere Max hosts on 2025.2, but
COMPUTE_SECURITY_UEFI_SECURE_BOOTisn't reported despite libvirt/LXD working directly. Anyone with aarch64 Nova experience: see the thread.
Heads Up / Action Needed
- Vote in the 2027.1 "I" release name poll by Monday, July 6, 23:59 PT.
- Hibiscus membership freeze is in effect as of July 2 — no new deliverables for 2026.2.
- Election prep: verify Gerrit email + CIVS opt-in ahead of August 5 nominations.
- Cinder Festival of Reviews originally scheduled for July 3 is postponed to July 10 due to the US holiday.
- Weigh in on
enforce_scoperemoval if your deployment or downstream distro still uses it.
Community & Events
- RISC-V SIG proposal. Xiang Li (ZTE) proposed a RISC-V SIG targeting OpenStack compatibility with the emerging RVA23 server class. ZTE is offering to donate hardware and staff engineers for CI. Discussion is on the SIG whiteboard etherpad. If you care about non-x86/ARM architectures, now is the moment to shape scope.
- Ops Radio Hour recap. Ildiko Vancsa summarized the June 26 session: the Operator's Contributor Guide is getting updates from Chris and Ildiko, and the group discussed Windows-on-KVM gotchas (UTC clock, jumbo frames). Open questions the group couldn't answer: OVN BGP Agent support in kolla-ansible, and status of Neutron bug #2056799. Recording: YouTube. Next call: July 31, 13:00 UTC.
- Public Cloud SIG met July 1 (details).
- Neutron bug deputy report for week 26 of 2026 landed from Miguel Lavalle — routine triage, no fires flagged.
This week in code · Week of 2026-07-04
Most active projects
- openstack/nova 20 merges ▲ +51% 🔥
- openstack/ironic 15 merges ▼ -41%
- openstack/glance 11 merges ▲ +13%
- openstack/sunbeam-charms 29 merges ▲ +123% 🔥
- openstack/neutron 17 merges ▼ -56%