Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk4 min

OpenStack Hibiscus: DNS Security and Confidential Computing Explained

OpenStack 2026.2 Hibiscus adds DNS security capabilities and expands Nova’s support for confidential VMs, but operators still need compatible hosts, configuration, and attestation operations.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OpenStack 2026.2 “Hibiscus,” released September 30, 2026, adds DNS security capabilities in Designate and expands Nova support for AMD SEV-SNP and Intel TDX confidential virtual machines. These are release-level capabilities, not security switches activated by an upgrade: operators still need compatible infrastructure and configuration, and the release announcement describes the DNS changes at a high level rather than as a deployment guide.

What Hibiscus changes

Hibiscus is the OpenStack project’s 34th release. The OpenStack Foundation describes its six-month development cycle as involving around 600 contributors, roughly 11,500 code changes, and approximately 1.6 million CI jobs run by OpenDev Zuul. Those activity figures describe development and testing volume; they do not measure the security effectiveness of the new features.

The release announcement groups the relevant changes into two areas: DNS security in Designate, OpenStack’s DNS-as-a-service component, and expanded confidential-computing support in Nova, the compute service. The announcement also reported 42 OpenStack Security Advisories and 13 OpenStack Security Notes issued so far in 2026 as of September 30; those totals are not evidence that a particular Hibiscus feature has been independently security-tested. OpenStack’s Hibiscus announcement has the release overview, and the Hibiscus schedule records the April 2–September 30, 2026 coordinated cycle.

What Designate’s DNS security features cover

The Hibiscus summary names four Designate improvements: stronger cross-tenant isolation, stronger authentication, TLSA/DANE support, and tooling to help operators prepare for post-quantum cryptography. The announcement does not specify API behavior, configuration steps, interoperability details, or migration procedures for these features, so deployments should not infer particular settings or guarantees from the summary alone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

TLSA/DANE support is not automatic secure DNS

TLSA records are used by DANE to associate certificates or public keys with domain names. Their presence in the feature summary does not mean a cloud has automatically configured DNSSEC, published valid records, or established a trusted validation path. Operators need implementation-specific Designate documentation and a clear understanding of the DNS resolvers and validation behavior in their environment before relying on DANE.

Post-quantum preparation is not end-to-end post-quantum security

The announcement says Hibiscus includes tooling to prepare for post-quantum cryptography. It does not claim that OpenStack, Designate, or a deployment’s DNS traffic is now protected end to end with post-quantum algorithms. Treat this as preparation support, not proof that cryptographic components have been migrated.

What Nova’s confidential-computing support means

Hibiscus expands Nova support for AMD SEV-SNP and Intel TDX. The release announcement characterizes these technologies as providing hardware-backed memory encryption, stronger workload isolation, and attestation for sensitive workloads. Actual availability depends on compatible compute hardware, firmware, the host virtualization stack, and operator configuration; upgrading the control plane alone does not make existing hosts capable of running confidential instances.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Nova’s upstream administration guides describe support added in Nova 34.0.0, the Hibiscus release. Distributions may package different component versions or require additional deployment procedures, so operators should also check their distribution’s support matrix and firmware instructions.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Intel TDX prerequisites and attestation limits

Intel TDX requires TDX-capable Intel CPUs, enabled host firmware, and a supported KVM, QEMU, and libvirt stack. Operators must configure eligible images or flavors and the appropriate firmware settings. The Nova Intel TDX administration guide details those requirements.

Attestation needs separate operational attention. Nova provides plumbing for evidence generation, but does not manage the Quote Generation Service (QGS) or itself verify attestation. Operators must install and manage the QGS on TDX hosts, and a relying party must verify the resulting quote. Nova’s guide says attestation was tested but is not actively supported or guaranteed by Nova. A confidential VM starting successfully is therefore not evidence that remote attestation is working.

Rank #3
Sale
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

AMD SEV-SNP prerequisites

SEV-SNP requires capable AMD compute hosts and a suitable libvirt/KVM or QEMU stack. The Nova guide also specifies firmware and machine-type requirements, including UEFI and Q35 constraints. Operators select the amd-sev-snp memory-encryption model through flavor extra specs or image metadata. See the Nova AMD SEV administration guide for the full requirements and configuration details.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choosing between TDX and SEV-SNP

Neither technology is established by these sources as universally more secure or easier to deploy. The practical choice depends on what is already available and supportable in the target cloud.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Decision factor Intel TDX AMD SEV-SNP
Hardware and firmware TDX-capable Intel CPU and enabled host firmware are required. Capable AMD compute host and required firmware support are required.
Host software Supported KVM, QEMU, and libvirt stack. Suitable libvirt/KVM or QEMU stack.
Instance selection Configure eligible flavors or images and firmware settings. Select amd-sev-snp through flavor extra specs or image metadata; meet UEFI and Q35 constraints.
Attestation operations Operator manages QGS; a relying party verifies quotes. Nova does not manage QGS or verify attestation. The cited Nova guide establishes host and instance prerequisites; consult the guide and deployment documentation for the attestation architecture required by the environment.

Before choosing, compare compatible CPU and firmware availability across the fleet, host-stack versions, per-host capacity constraints, and who will own attestation services and quote verification. A mixed fleet may make one option more practical than the other for particular compute pools.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

Upgrade and lifecycle context

Hibiscus is a non-SLURP release. OpenStack says operators on the preceding SLURP release, Gazpacho, may skip Hibiscus and upgrade directly to 2027.1 Indri, expected in March 2027. Confirm that route against the deployment’s packaging and local maintenance policy rather than treating it as universal upgrade advice.

The official OpenStack series index lists Hibiscus as maintained and estimates its end of life as April 26, 2028. That is an estimate and may change; check the index when planning a maintenance window. The release date and series status are also recorded in the release announcement.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.