The latest OpenStack Ussuri release drops May 13, bringing with it a focus on improving the reliability, security, and extending use case support for the software infrastructure platform. The update also highlights the ongoing activity behind the widely used software infrastructure layer that continues to trade on its robustness compared to newer options.

The OpenStack Foundation (OSF) noted that the latest release, which is the 21st since the initial “Austin” release nearly a decade ago, includes “tens-of-thousands” of actual updates spread across 24,000 code changes.

Among the more important updates cited by OSF Executive Director Jonathan Bryce is the expansion of IPv6 support to the Kuryr container networking plugin. Kuryr is the link that delivers the OpenStack networking into containers, or as Bryce explained, “is a way that you can overlay Kubernetes or Docker or other container runtimes on top of an OpenStack environment.”

Another update is to the Nova compute service that supports cold migration and the resizing of servers between Nova cells. Bryce explained that Nova cells allow an OpenStack cloud deployment to scale horizontally as they expand to more physical servers and workloads over time. The cold migration support allows users to more easily migrate workloads from hardware that is set to be decommissioned to the OpenStack cloud environment.

The OpenStack Ironic bare metal management platform also now has automated bare metal hardware provisioning. This allows the Ironic platform to be provisioned and controlled outside of its traditional Nova environment and instead in a different management environment like Kubernetes.

For security, the OpenStack Ussuri update allows for more control using the Octavia load balancer service over the transport layer security (TLS) settings for different tenants and different workloads. And the Kolla containerized deployment platform for OpenStack also added initial support for TLS encryption of backend API services. Bryce explained that this allows for end-to-end encryption inside of the cloud for the different control plane activities.

“Security is an area that is a moving target and there's continual security threats out there. And when you're talking about infrastructure-as-a-service layer, embracing and implementing the latest encryption standards at each layer in the stack … the job is never done there so that's one of the reasons why our community so active,” added Mark Collier, COO of the OpenStack Foundation.

OpenStack Remains Relevant

As part of the Ussuri update, the OSF also touted the depth in which OpenStack is being used in commercial environments. This includes the platform being used in more than 75 public cloud data centers and thousands of private clouds on more than 10 million compute cores.

The reminder is becoming increasingly important for the OSF community, which has started to see some of its shine rubbed off by the Kubernetes-focused container environment. That environment is centered around the Cloud Native Computing Foundation (CNCF).

Bryce during the press conference used the well-worn trope that all of these platforms are part of the “toolbox” to meet the needs of enterprises and operators and that the focus should be on ensuring interoperability between open source projects.

“I think that we have to make sure within the open source communities that we are focused on how to use these different tools together because that's really what I think is the key to continuing to drive adoption and usage of them,” Bryce said.

OpenStack, for instance, is a critical component of the Airship open infrastructure project that is being used by operators to manage their virtualized environments. AT&T recently explained that the upcoming 2.0 update will further advance the ability for operators to migrate from virtual machine (VM)-based virtual network functions (VNFs) to container-based cloud-native network functions (CNFs).

"It's another one of those examples where we see a community kind of developing these entire solutions based off of a lot of open source tools," Bryce said.