Google Distributed Cloud(에어 갭 적용형) 1.9.1 GA에는 인터커넥트 관련 액세스 제어 목록의 템플릿을 생성하는 도구가 도입되었습니다.
Google Distributed Cloud 오프라인 1.9.1 GA에서 노드 및 운영체제 구성요소는 VM의 구성 시 자동 재시작 기능을 사용하여 클러스터 업그레이드 중에 KVM을 중지했다가 다시 시작한 후 VM에 새 VM 디스크를 사용하지 못할 수 있는 문제를 해결합니다.
모니터링 작동 가능 구성요소에서 IMSPodImageReconciller가 Artifact Registry의 모든 프로젝트를 루프하지 않았고 라이브러리 프로젝트에서 이미지를 찾을 수 없어 ims_unauthorized_image 알림이 항상 발생했습니다.
Google Distributed Cloud 에어 갭 비공개 정식 버전에서는 침입 감지 및 방지 시스템 Syslog가 각 조직으로 팬아웃됩니다.
Google Distributed Cloud 에어 갭 1.9.1 GA에서는 헤어핀 링크 CIDR을 사용하는 방화벽의 Border Gateway Protocol과 인스턴스 외부 CIDR을 사용하는 방화벽의 인터넷 제어 메시지 프로토콜에 대한 보안 규칙을 추가합니다.
최신 보안 패치와 중요 업데이트를 적용하기 위해 Google Distributed Cloud 버전을 1.14.2-gke.11로 업데이트했습니다.
[[["이해하기 쉬움","easyToUnderstand","thumb-up"],["문제가 해결됨","solvedMyProblem","thumb-up"],["기타","otherUp","thumb-up"]],[["이해하기 어려움","hardToUnderstand","thumb-down"],["잘못된 정보 또는 샘플 코드","incorrectInformationOrSampleCode","thumb-down"],["필요한 정보/샘플이 없음","missingTheInformationSamplesINeed","thumb-down"],["번역 문제","translationIssue","thumb-down"],["기타","otherDown","thumb-down"]],["최종 업데이트: 2025-09-04(UTC)"],[[["\u003cp\u003eGoogle Distributed Cloud air-gapped 1.9.1 is now generally available, offering a range of services including AI/ML, compute, databases, marketplace, networking, security, and storage.\u003c/p\u003e\n"],["\u003cp\u003eThe new release introduces predefined cluster roles for disaster recovery, enhancing the management capabilities for Infrastructure Operators and Platform Administrators.\u003c/p\u003e\n"],["\u003cp\u003eVersion 1.9.1 of Google Distributed Cloud includes a tool for generating templates for interconnect-related access control lists and improvements for Node and Operating System component failures.\u003c/p\u003e\n"],["\u003cp\u003eMultiple security vulnerabilities in both the Ubuntu OS image and container images have been addressed in this release, as well as updating the google distributed cloud version to 1.14.2.\u003c/p\u003e\n"],["\u003cp\u003eSeveral known issues have been identified in versions 1.9.0 and 1.9.1, including problems with VM backup and restore processes, \u003ccode\u003estandard-block\u003c/code\u003e storage class, node reprovisioning, node OS upgrades, add-on installations, GPU-to-VM coupling, and memory overrides.\u003c/p\u003e\n"]]],[],null,["# Google Distributed Cloud air-gapped 1.9.1 release notes\n\n\u003cbr /\u003e\n\nMarch 21, 2023 \\[GDC 1.9.1 General Availability\\]\n-------------------------------------------------\n\n*** ** * ** ***\n\n\nGoogle Distributed Cloud air-gapped 1.9.1 General Availability (GA) is now released.\n\nSee the [product overview](/distributed-cloud/hosted/docs/latest/gdch/overview) to learn about the features of Google Distributed Cloud air-gapped.\n\nThe following table lists services available in Google Distributed Cloud air-gapped.\n\n*** ** * ** ***\n\n\nGoogle Distributed Cloud air-gapped 1.9.1 GA introduces new predefined cluster roles for disaster recovery:\n\n- `dr-admin` created on a root admin cluster for an Infrastructure Operator (IO).\n\n- `gdch-dr-admin` created in the namespace `gdch-dr` for an IO for bucket creation.\n\n- `dr-restore-admin` created on an org admin cluster for an IO.\n\n- `dr-backup-admin` created on an org admin cluster for a Platform Administrator (PA).\n\n- `dr-system-admin` created in the namespace `dr-system` for a PA for bucket creation.\n\nFor details, see:\n\n- [Predefined identity and access roles tables for PA and AO](/distributed-cloud/hosted/docs/latest/gdch/platform/pa-user/iam/role-descriptions)\n\n*** ** * ** ***\n\n\nGoogle Distributed Cloud air-gapped 1.9.1 GA introduces a tool for generating templates for interconnect-related access control lists.\n\n*** ** * ** ***\n\n\nIn Google Distributed Cloud air-gapped 1.9.1 GA, the Node and Operating System component uses an auto restart on configuration feature of the VM to resolve the issue of potential failure to use a new VM disk for a VM after stopping and restarting KVM during cluster upgrade.\n\n*** ** * ** ***\n\n\nIn Monitoring operable component, `IMSPodImageReconciller` did not loop all projects in Artifact Registry and couldn't find images in the library project causing the `ims_unauthorized_image` alert to fire all the time.\n\n*** ** * ** ***\n\n\nIn Google Distributed Cloud air-gapped Private General Availability, Intrusion Detection and Prevention Systems Syslog fans-out to each organization.\n\n*** ** * ** ***\n\n\nGoogle Distributed Cloud air-gapped 1.9.1 GA adds security rules for Border Gateway Protocol on firewalls using hairpin links CIDR and for Internet Control Message Protocol on firewalls using instance external CIDR.\n\n*** ** * ** ***\n\n\nUpdated Google Distributed Cloud version to 1.14.2-gke.11 to apply the latest security patches and important updates.\n\nSee [Google Distributed Cloud 1.14.2 release notes](https://cloud.google.com/anthos/clusters/docs/bare-metal/latest/release-notes#March_01_2023) for details.\n\n*** ** * ** ***\n\n\nUpdated Canonical Ubuntu OS image version to 20230227 to apply the latest security patches and important updates.\n\nThe following security vulnerabilities are fixed:\n\n- [CVE-2022-2601](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2601)\n- [CVE-2022-3775](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3775)\n- [CVE-2022-2601](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2601)\n- [CVE-2022-3775](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3775)\n\n*** ** * ** ***\n\n\nThe following container image security vulnerabilities are fixed:\n\n- [CVE-2023-0286](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0286)\n- [CVE-2023-0215](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0215)\n- [CVE-2022-4450](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4450)\n- [CVE-2022-2097](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2097)\n- [CVE-2022-32221](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32221)\n- [CVE-2022-41903](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41903)\n- [CVE-2022-23521](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23521)\n- [CVE-2022-39260](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39260)\n- [CVE-2022-29187](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29187)\n- [CVE-2022-24765](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24765)\n- [CVE-2022-39253](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39253)\n- [CVE-2021-46848](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46848)\n- [CVE-2022-42898](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42898)\n\n*** ** * ** ***\n\n\nGoogle Distributed Cloud air-gapped 1.9.1 has a known issue where role-based access control (RBAC) and schema settings in the VM manager is stopping users from starting VM backup and restore processes.\n\n*** ** * ** ***\n\nGoogle Distributed Cloud air-gapped 1.9.0 has a known issue where\n\nremote server management software\n\nis occasionally unable to retrieve the key from HSM.\n\n*** ** * ** ***\n\n\nGoogle Distributed Cloud air-gapped 1.9.1 GA has a known issue where using the `standard-block` storage class might prevent virtual machines (VMs) from starting or restarting.\n\n*** ** * ** ***\n\n\nGoogle Distributed Cloud air-gapped 1.9.1 GA has a known issue where a compute node becomes stuck after reprovisioning a machine.\n\n*** ** * ** ***\n\n\nGoogle Distributed Cloud air-gapped 1.9.1 GA has a known issue during the Node OS upgrade where a the server is stuck in deprovisioning because `boot.ipxe` URL is invalid.\n\n*** ** * ** ***\n\n\nGoogle Distributed Cloud air-gapped 1.9.1 GA has a known issue during the Node OS upgrade where a node fails the `machine-init` job.\n\n*** ** * ** ***\n\n\nGoogle Distributed Cloud air-gapped 1.9.1 GA has a known issue where the upgrade from 1.9.0 to 1.9.1 is blocked because the `ods-fleet` add-on failed to install.\n\n*** ** * ** ***\n\nGoogle Distributed Cloud air-gapped 1.9.0 has a known issue in the UI that lets you select an incompatible coupling of GPU to VM type.\n\n*** ** * ** ***\n\nGoogle Distributed Cloud air-gapped 1.9.0 has a known issue where VMs with memory greater than 32 GB require a memory override due to an incorrect QEMU overhead calculation.\n\n*** ** * ** ***\n\n\nGoogle Distributed Cloud air-gapped 1.9.1 GA has a known issue where alerts in organization system clusters don't reach the ticketing system."]]