Known Issues Affecting Network Protection and Secure AI Enforcers
Summary
Aqua has identified two known issues affecting specific Enforcer versions and configurations:
- Network connectivity issues when upgrading Enforcers with Network Protection enabled.
- Increased memory utilization and pods becoming stuck during termination when Secure AI is enabled.
Customers using the affected configurations should upgrade their Enforcers to a fixed release.
Understanding Enforcer Versions
Depending on where the Enforcer version is viewed, it may appear as either:
- A release name, such as U44 SP3
- A numeric build or image tag, such as 2022.4.874.32
For example, U44 SP3 and 2022.4.874.32 refer to the same Enforcer release. The full release-to-build mapping is included below.
Issue 1: Network Protection Connectivity Issues
Affected Configuration
This issue may occur when:
- Network Protection is enabled.
- Enforcers are being upgraded from U41, U42, or U43.
- The upgrade target is an affected U44 release earlier than U44 SP3.
The affected U44 releases are:
| Product Version | Build/Image Tag | Version |
|---|---|---|
| U44 Initial Release | 2022.4.874 | 2022.4.874.41959 |
| U44 SP1 | 2022.4.874.24 | 2022.4.874.41971 |
| U44 SP2 | 2022.4.874.25 | 2022.4.874.41982 |
Potential Symptoms
Affected environments may experience:
- DNS resolution failures
- Application or service connectivity failures
- Health check failures
- General network connectivity issues within protected workloads
Resolution
Upgrade the Enforcer to one of the following:
| Recommended Version | Build/Image Tag | Version |
| U44 SP3 | 2022.4.874.32 | 2022.4.874.41997 |
| U44 SP4 | 2022.4.874.34 | 2022.4.874.42012 |
| U45 or later | See the version table below |
For customers remaining on the U44 release train, U44 SP3 or later is required.Upgrade Recommendation
Before upgrading:
- Disable Network Protection.
- Complete the Enforcer upgrade.
- Confirm the Enforcer pods are running and healthy.
- Re-enable Network Protection.
- Confirm DNS resolution, application connectivity, and health checks are operating normally.
Issue 2: Secure AI Memory Utilization
Affected Configuration
This issue may occur when Secure AI is enabled on Enforcers running U42 through U44 SP3. This includes the following release ranges:
| Product Version | Build/Image Tag |
| U42 Initial Release through U42 SP4 | 2022.4.860 through 2022.4.860.50 |
| U43 Initial Release through U43 SP4 | 2022.4.868 through 2022.4.868.21 |
| U44 Initial Release through U44 SP3 | 2022.4.874 through 2022.4.874.32 |
Potential Symptoms
Affected environments may experience:
- Increased Enforcer memory utilization
- Enforcer pods remaining in the
Terminatingstate - Delayed or incomplete pod termination
- Resource pressure on the Kubernetes node
Resolution
Upgrade the Enforcer to one of the following:
| Recommended Version | Build/Image Tag | Version |
| U44 SP4 | 2022.4.874.34 | 2022.4.874.42012 |
| U45 or later | See the version table below |
For customers remaining on the U44 release train, U44 SP4 or later is required. If an immediate upgrade is not possible, consider temporarily disabling Secure AI until a fixed Enforcer version can be deployed.
Environments Affected by Both Issues
Customers using both Network Protection and Secure AI should upgrade to:
- U44 SP4 -
2022.4.874.34 - U45 or later
U44 SP4 contains the required fixes for both issues.
Enforcer Release and Build Mapping
Use the following table to compare the product release shown in the Aqua interface with the numeric Enforcer build or image tag.
| Release | Build/Image Tag | Version |
| U41 Initial Release | 2022.4.848 | 2022.4.848.41365 |
| U41 SP1 | 2022.4.848.16 | 2022.4.848.41386 |
| U42 Initial Release | 2022.4.860 | 2022.4.860.41575 |
| U42 SP1 | 2022.4.860.23 | 2022.4.860.41575 |
| U42 SP2 | 2022.4.860.24 | 2022.4.860.41580 |
| U42 SP3 | 2022.4.860.26 | 2022.4.860.41586 |
| U42 SP4 | 2022.4.860.50 | 2022.4.860.41608 |
| U43 Initial Release | 2022.4.868 | 2022.4.868.41710 |
| U43 SP1 | 2022.4.868.13 | 2022.4.868.41712 |
| U43 SP2 | 2022.4.868.15 | 2022.4.868.41718 |
| U43 SP3 | 2022.4.868.18 | 2022.4.868.41725 |
| U43 SP4 | 2022.4.868.21 | 2022.4.868.41731 |
| U44 Initial Release | 2022.4.874 | 2022.4.874.41959 |
| U44 SP1 | 2022.4.874.24 | 2022.4.874.41971 |
| U44 SP2 | 2022.4.874.25 | 2022.4.874.41982 |
| U44 SP3 | 2022.4.874.32 | 2022.4.874.41997 |
| U44 SP4 | 2022.4.874.34 | 2022.4.874.42012 |
| U45 Initial Release | 2022.4.880 | 2022.4.880.42217 |
| U45 SP1 | 2022.4.880.16 | 2022.4.880.42241 |
| U45 SP2 | 2022.4.880.18 | 2022.4.880.42257 |
| U45 SP4 | 2022.4.880.27 | 2022.4.880.42277 |
| U46 Initial Release | 2022.4.893 | 2022.4.893.42392 |
Recommended Action
Aqua recommends upgrading to U45 or later, where supported, to receive the latest security, stability, and vulnerability fixes.
Customers who need to remain on U44 should use the following minimum versions:
| Feature | Minimum U44 Version | Build/Image Tag | Version |
| Network Protection only | U44 SP3 | 2022.4.874.32 | 2022.4.874.41997 |
| Secure AI only | U44 SP4 | 2022.4.874.34 | 2022.4.874.42012 |
| Network Protection and Secure AI | U44 SP4 | 2022.4.874.34 | 2022.4.874.42012 |
Before deploying U45 or a later Enforcer release, confirm that the Aqua Platform has been upgraded to a compatible release.
Contact Aqua Support if assistance is needed to confirm the currently deployed Enforcer version, validate platform compatibility, or plan the upgrade.
Additional Resources
[1] https://docs.aquasec.com/v2022.4/release-information/

Did you find it helpful? Yes No
Send feedback