Volcano
v1.15.2Orchestration & Management2026년 8월 29일
스케줄러 서비스 거부 취약점과 스케줄링 및 워크로드 관리 결함을 고친 보안 중심 유지보수 릴리스입니다. 스케줄러 운영과 `Dynamic Resource Allocation` 사용 환경에 관련된 변경이 포함되어 있습니다.
영향 확인 (1)
security
Dynamic Resource Allocation용량 계산의 반복 처리 취약점 수정Dynamic Resource Allocation을 사용하는 경우 적용됩니다.GHSA-j38h-7pfq-cxmw 취약점은
Dynamic Resource Allocation의 용량 계산에서 테넌트가 제어하는 장치 수나 작업 수에 비례해 반복이 발생하던 문제입니다. 인증된 테넌트가 스케줄러의 CPU 시간을 소진할 수 있었고, 계산 중 스케줄러 캐시 잠금이 유지되면 클러스터 전체의 스케줄링이 멈출 수 있었습니다. 용량 집계를 상수 시간 곱셈으로 바꾸고 입력 검증과 오버플로 처리를 보강했습니다.
그 외 기록된 변경 4건 전체fixes 4
fixes (4)
- * [release-1.15] Prevent a nil-pointer panic in backfill when node scoring fails to select a best node by @mesutoezdil in #5916
- * [release-1.15] Recheck predicate and device feasibility after tentative reclaim evictions, allowing reclaim to continue until a concrete device allocation is possible by @miantalha45 in #5898
- * [release-1.15] Fix HAMi Ascend normal preemption when evicting lower-priority workloads makes sufficient device capacity available by @miantalha45 in #5866
- * [release-1.15] Keep PodGroups Running while scheduled member Pods are gracefully terminating and avoid misleading
NotEnoughResourcesconditions by @halcyon-r in #5840
Volcano 스택에 추가
조치가 필요한 릴리스가 나왔을 때 주간 메일로 알려드립니다. 이번 릴리스의 보안 패치 같은 것들입니다.