OpenStack 2026.2 “Hibiscus,” released September 30, 2026, adds DNS security capabilities in Designate and expands Nova support for AMD SEV-SNP and Intel TDX confidential virtual machines. These are release-level capabilities, not security switches activated by an upgrade: operators still need compatible infrastructure and configuration, and the release announcement describes the DNS changes at a high level rather than as a deployment guide.
What Hibiscus changes
Hibiscus is the OpenStack project’s 34th release. The OpenStack Foundation describes its six-month development cycle as involving around 600 contributors, roughly 11,500 code changes, and approximately 1.6 million CI jobs run by OpenDev Zuul. Those activity figures describe development and testing volume; they do not measure the security effectiveness of the new features.
The release announcement groups the relevant changes into two areas: DNS security in Designate, OpenStack’s DNS-as-a-service component, and expanded confidential-computing support in Nova, the compute service. The announcement also reported 42 OpenStack Security Advisories and 13 OpenStack Security Notes issued so far in 2026 as of September 30; those totals are not evidence that a particular Hibiscus feature has been independently security-tested. OpenStack’s Hibiscus announcement has the release overview, and the Hibiscus schedule records the April 2–September 30, 2026 coordinated cycle.
What Designate’s DNS security features cover
The Hibiscus summary names four Designate improvements: stronger cross-tenant isolation, stronger authentication, TLSA/DANE support, and tooling to help operators prepare for post-quantum cryptography. The announcement does not specify API behavior, configuration steps, interoperability details, or migration procedures for these features, so deployments should not infer particular settings or guarantees from the summary alone.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
TLSA/DANE support is not automatic secure DNS
TLSA records are used by DANE to associate certificates or public keys with domain names. Their presence in the feature summary does not mean a cloud has automatically configured DNSSEC, published valid records, or established a trusted validation path. Operators need implementation-specific Designate documentation and a clear understanding of the DNS resolvers and validation behavior in their environment before relying on DANE.
Post-quantum preparation is not end-to-end post-quantum security
The announcement says Hibiscus includes tooling to prepare for post-quantum cryptography. It does not claim that OpenStack, Designate, or a deployment’s DNS traffic is now protected end to end with post-quantum algorithms. Treat this as preparation support, not proof that cryptographic components have been migrated.
What Nova’s confidential-computing support means
Hibiscus expands Nova support for AMD SEV-SNP and Intel TDX. The release announcement characterizes these technologies as providing hardware-backed memory encryption, stronger workload isolation, and attestation for sensitive workloads. Actual availability depends on compatible compute hardware, firmware, the host virtualization stack, and operator configuration; upgrading the control plane alone does not make existing hosts capable of running confidential instances.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Nova’s upstream administration guides describe support added in Nova 34.0.0, the Hibiscus release. Distributions may package different component versions or require additional deployment procedures, so operators should also check their distribution’s support matrix and firmware instructions.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Intel TDX prerequisites and attestation limits
Intel TDX requires TDX-capable Intel CPUs, enabled host firmware, and a supported KVM, QEMU, and libvirt stack. Operators must configure eligible images or flavors and the appropriate firmware settings. The Nova Intel TDX administration guide details those requirements.
Attestation needs separate operational attention. Nova provides plumbing for evidence generation, but does not manage the Quote Generation Service (QGS) or itself verify attestation. Operators must install and manage the QGS on TDX hosts, and a relying party must verify the resulting quote. Nova’s guide says attestation was tested but is not actively supported or guaranteed by Nova. A confidential VM starting successfully is therefore not evidence that remote attestation is working.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
AMD SEV-SNP prerequisites
SEV-SNP requires capable AMD compute hosts and a suitable libvirt/KVM or QEMU stack. The Nova guide also specifies firmware and machine-type requirements, including UEFI and Q35 constraints. Operators select the amd-sev-snp memory-encryption model through flavor extra specs or image metadata. See the Nova AMD SEV administration guide for the full requirements and configuration details.
Choosing between TDX and SEV-SNP
Neither technology is established by these sources as universally more secure or easier to deploy. The practical choice depends on what is already available and supportable in the target cloud.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitches| Decision factor | Intel TDX | AMD SEV-SNP |
|---|---|---|
| Hardware and firmware | TDX-capable Intel CPU and enabled host firmware are required. | Capable AMD compute host and required firmware support are required. |
| Host software | Supported KVM, QEMU, and libvirt stack. | Suitable libvirt/KVM or QEMU stack. |
| Instance selection | Configure eligible flavors or images and firmware settings. | Select amd-sev-snp through flavor extra specs or image metadata; meet UEFI and Q35 constraints. |
| Attestation operations | Operator manages QGS; a relying party verifies quotes. Nova does not manage QGS or verify attestation. | The cited Nova guide establishes host and instance prerequisites; consult the guide and deployment documentation for the attestation architecture required by the environment. |
Before choosing, compare compatible CPU and firmware availability across the fleet, host-stack versions, per-host capacity constraints, and who will own attestation services and quote verification. A mixed fleet may make one option more practical than the other for particular compute pools.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
Upgrade and lifecycle context
Hibiscus is a non-SLURP release. OpenStack says operators on the preceding SLURP release, Gazpacho, may skip Hibiscus and upgrade directly to 2027.1 Indri, expected in March 2027. Confirm that route against the deployment’s packaging and local maintenance policy rather than treating it as universal upgrade advice.
The official OpenStack series index lists Hibiscus as maintained and estimates its end of life as April 26, 2028. That is an estimate and may change; check the index when planning a maintenance window. The release date and series status are also recorded in the release announcement.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




