AI Models & Platforms

OpenStack 2026.2 Hibiscus Adds Confidential Computing, vGPU Support

mm
Add Unite.AI to your preferred sources on Google

The OpenStack community released OpenStack 2026.2 (Hibiscus) on September 30, 2026, the 34th release of the open source cloud infrastructure software, adding confidential-computing support for AMD and Intel platforms, new management options for GPU-accelerated workloads, and efficiency improvements for large-scale deployments.

Around 600 contributors collaborated during the six-month Hibiscus development cycle, a 21% increase from OpenStack 2026.1 Gazpacho, and they delivered 11,500 code changes, a 28% increase release over release, according to the project. During the same cycle, the OpenDev Zuul continuous integration system ran approximately 1.6 million jobs to build, test and publish software across the OpenStack ecosystem; over the past five years, Zuul has run more than 14.2 million jobs supporting OpenStack development.

Confidential Computing and Security

Confidential computing is a key area of investment in the release, according to the announcement. The per-project release highlights, reported directly from the project teams, state that Nova can now launch instances with AMD SEV-SNP memory encryption, the third generation of AMD’s Secure Encrypted Virtualization. The release notes describe SEV-SNP as providing stronger integrity protection than SEV-ES and enabling platform attestation, which lets guest owners verify the integrity of their virtual machines through signed attestation reports. Operators request SEV-SNP instances with the hw:mem_encryption_model=amd-sev-snp flavor extra spec or the equivalent image property.

Nova also now supports Intel Trust Domain Extensions (TDX) for confidential computing on Intel platforms, specifically 5th Gen Xeon Scalable processors or later. According to the release notes, TDX provides hardware-enforced memory encryption and CPU state isolation, protecting guests from the hypervisor and other privileged software, and attestation is supported through the Quote Generation Service.

Designate, the DNS service, added support for TLSA records, defined in RFC 6698, which are used for DANE certificate pinning, and it gained post-quantum-cryptography readiness tooling, including a configurable check mode that can block service startup on quantum-vulnerable certificate algorithms or outdated TLS versions. Designate also fixed OSSA-2026-034, a cross-tenant zone ownership bypass that let a tenant create a subzone, superzone or duplicate of another tenant’s zone by scheduling it to a different pool, enabling DNS traffic hijacking and denial of service. Zone ownership conflict checks now search across all pools.

Cyborg addressed CVE-2026-40213 and CVE-2026-40214 by scoping requests to projects, requiring service-token validation and tightening access to hardware management APIs, and it added opt-in persona-based policy defaults for reader, member, manager, service and admin roles ahead of a planned default change in the 2027.1 release. Glance, the image service, shipped fixes for CVE-2026-71196, CVE-2026-71197, CVE-2026-71198 and OSSA-2026-038.

Across the project, 42 OpenStack Security Advisories and 13 OpenStack Security Notes have been issued so far in 2026, according to the release page, and the OpenStack Vulnerability Management Team coordinates the responsible handling and disclosure of security vulnerabilities.

Support for AI and Accelerated Workloads

Nova’s libvirt driver now supports Cyborg-managed mediated devices, such as virtual GPUs, through a new MDEV accelerator request binding type. The release notes state that operators can manage the vGPU lifecycle through Cyborg as an alternative to Nova’s native support, with a new OWNER_NOVA trait preventing scheduling collisions between Nova-managed and Cyborg-managed devices.

Manila, the shared filesystem service, added new share drivers for the Weka and Lustre parallel filesystems, expanding support for high-performance parallel filesystem workloads such as AI, machine learning and HPC. Ironic, the bare-metal service, coordinated with Nova to significantly improve the performance of resource tracking in nova-compute services running the Ironic driver, according to the release highlights. The Ironic team reported that it handled more security bugs in the 2026.2 cycle than in any other six-month period in the project’s history, prompting a series of stability and hardening improvements, and its dedicated firmware interface is now the recommended path for managing device firmware updates.

Efficiency at Scale

Neutron, the networking service, reduced the memory footprint in ML2/OVS HA router deployments by more than 15x, according to the release highlights, by replacing a daemon with a shell script for keepalived state-change monitoring. Neutron also added an EVPN service plugin and OVN agent extension to provision BGP EVPN Type-5 route advertisements, plus a Private VLAN service plugin that provides port isolation through promiscuous, isolated and community ports.

Watcher’s VM Workload Consolidation strategy now considers reserved capacity in addition to live usage when consolidating workloads, and two new actions expand its automation: delete permanently removes an instance and its resources, while shelve reclaims a host’s compute capacity while preserving instance data. Glance added parallel image import support, downloads from preferred stores and new APIs for cache cleaning, cache pruning and listing cached nodes. Horizon, the project dashboard, enabled oslo.policy’s enforce_scope and enforce_new_defaults settings by default in line with OpenStack’s secure RBAC model, officially supports Python 3.14 and dropped support for Python 3.9 and 3.10.

Upgrade Path and Next Release

Hibiscus is a non-SLURP release. The Skip Level Upgrade Release Process, introduced in 2022, gives operators the option to upgrade once per year rather than every six months while maintaining OpenStack’s six-month release cadence. Operators running OpenStack 2026.1 Gazpacho, the previous SLURP release issued in April 2026, can choose to skip Hibiscus and upgrade directly to OpenStack 2027.1 Indri, which is expected in March 2027.

Release notes and source code for Hibiscus are available through the official OpenStack releases site. OpenStack community leaders are scheduled to discuss the new features and development work in an OpenInfra Live episode on October 1, 2026, at 14:00 UTC, with panelists from the Nova, Neutron, Manila, Ironic, Watcher and Freezer projects, the OpenStack Technical Committee and the Vulnerability Management Team.

Theo Nash is an AI-generated specialist at Unite.AI, covering AI infrastructure, compute, and the hardware systems that power modern artificial intelligence. His work focuses on the technical foundations behind large-scale AI workloads, including data centers, accelerators, networking, and the software stacks that tie them together.

With an analytical and engineering-driven perspective, Theo examines how advances in GPUs, custom silicon, memory architectures, and distributed systems enable new generations of AI models. He pays particular attention to performance trade-offs, energy efficiency, scalability, and the practical constraints that shape real-world deployment of AI infrastructure.

Articles authored by Theo Nash are AI-generated and reviewed by Unite.AI’s editorial team to ensure technical accuracy, clarity, and responsible coverage of the rapidly evolving AI compute landscape.