Summary

Aqua has identified two known issues affecting specific Enforcer versions and configurations:

  • Network connectivity issues when upgrading Enforcers with Network Protection enabled.
  • Increased memory utilization and pods becoming stuck during termination when Secure AI is enabled.

Customers using the affected configurations should upgrade their Enforcers to a fixed release.


Understanding Enforcer Versions

Depending on where the Enforcer version is viewed, it may appear as either:

  • A release name, such as U44 SP3
  • A numeric build or image tag, such as 2022.4.874.32

For example, U44 SP3 and 2022.4.874.32 refer to the same Enforcer release. The full release-to-build mapping is included below.


Issue 1: Network Protection Connectivity Issues

Affected Configuration

This issue may occur when:

  • Network Protection is enabled.
  • Enforcers are being upgraded from U41, U42, or U43.
  • The upgrade target is an affected U44 release earlier than U44 SP3.

The affected U44 releases are:

Product VersionBuild/Image TagVersion
U44 Initial Release2022.4.8742022.4.874.41959
U44 SP12022.4.874.242022.4.874.41971
U44 SP22022.4.874.252022.4.874.41982

Potential Symptoms

Affected environments may experience:

  • DNS resolution failures
  • Application or service connectivity failures
  • Health check failures
  • General network connectivity issues within protected workloads

Resolution

Upgrade the Enforcer to one of the following:

Recommended VersionBuild/Image TagVersion
U44 SP32022.4.874.322022.4.874.41997
U44 SP42022.4.874.342022.4.874.42012
U45 or laterSee the version table below


For customers remaining on the U44 release train, U44 SP3 or later is required.


Upgrade Recommendation

Before upgrading:

  1. Disable Network Protection.
  2. Complete the Enforcer upgrade.
  3. Confirm the Enforcer pods are running and healthy.
  4. Re-enable Network Protection.
  5. Confirm DNS resolution, application connectivity, and health checks are operating normally.


Issue 2: Secure AI Memory Utilization

Affected Configuration

This issue may occur when Secure AI is enabled on Enforcers running U42 through U44 SP3. This includes the following release ranges:

Product VersionBuild/Image Tag
U42 Initial Release through U42 SP42022.4.860 through 2022.4.860.50
U43 Initial Release through U43 SP42022.4.868 through 2022.4.868.21
U44 Initial Release through U44 SP32022.4.874 through 2022.4.874.32

Potential Symptoms

Affected environments may experience:

  • Increased Enforcer memory utilization
  • Enforcer pods remaining in the Terminating state
  • Delayed or incomplete pod termination
  • Resource pressure on the Kubernetes node

Resolution

Upgrade the Enforcer to one of the following:

Recommended VersionBuild/Image TagVersion
U44 SP42022.4.874.342022.4.874.42012
U45 or laterSee the version table below


For customers remaining on the U44 release train, U44 SP4 or later is required.
If an immediate upgrade is not possible, consider temporarily disabling Secure AI until a fixed Enforcer version can be deployed.


Environments Affected by Both Issues

Customers using both Network Protection and Secure AI should upgrade to:

  • U44 SP4 - 2022.4.874.34
  • U45 or later

U44 SP4 contains the required fixes for both issues.


Enforcer Release and Build Mapping

Use the following table to compare the product release shown in the Aqua interface with the numeric Enforcer build or image tag.

ReleaseBuild/Image TagVersion
U41 Initial Release2022.4.8482022.4.848.41365
U41 SP12022.4.848.162022.4.848.41386
U42 Initial Release2022.4.8602022.4.860.41575
U42 SP12022.4.860.232022.4.860.41575
U42 SP22022.4.860.242022.4.860.41580
U42 SP32022.4.860.262022.4.860.41586
U42 SP42022.4.860.502022.4.860.41608
U43 Initial Release2022.4.8682022.4.868.41710
U43 SP12022.4.868.132022.4.868.41712
U43 SP22022.4.868.152022.4.868.41718
U43 SP32022.4.868.182022.4.868.41725
U43 SP42022.4.868.212022.4.868.41731
U44 Initial Release2022.4.8742022.4.874.41959
U44 SP12022.4.874.242022.4.874.41971
U44 SP22022.4.874.252022.4.874.41982
U44 SP32022.4.874.322022.4.874.41997
U44 SP42022.4.874.342022.4.874.42012
U45 Initial Release2022.4.8802022.4.880.42217
U45 SP12022.4.880.162022.4.880.42241
U45 SP22022.4.880.182022.4.880.42257
U45 SP42022.4.880.272022.4.880.42277
U46 Initial Release2022.4.8932022.4.893.42392


Recommended Action

Aqua recommends upgrading to U45 or later, where supported, to receive the latest security, stability, and vulnerability fixes.


Customers who need to remain on U44 should use the following minimum versions:

FeatureMinimum U44 VersionBuild/Image TagVersion
Network Protection onlyU44 SP32022.4.874.322022.4.874.41997
Secure AI onlyU44 SP42022.4.874.342022.4.874.42012
Network Protection and Secure AIU44 SP42022.4.874.342022.4.874.42012


Before deploying U45 or a later Enforcer release, confirm that the Aqua Platform has been upgraded to a compatible release.


Contact Aqua Support if assistance is needed to confirm the currently deployed Enforcer version, validate platform compatibility, or plan the upgrade.


Additional Resources

[1] https://docs.aquasec.com/v2022.4/release-information/

image