Release Notes
26. August 2026

orcharhino 7.10 Release Notes


Release Highlights

Performance enhancements

The orcharhino 7.10 release includes several performance improvements. Task cleanup during the orcharhino upgrade now uses multiple cores instead of a single core, speeding up this step of the process. Additionally, for remote execution jobs, an optimization results in faster UI performance for users with many organizations assigned. It is planned to improve the remote execution UI in a future release even more.

Proxmox Compute Resource: UEFI Secure Boot Support

In orcharhino 7.10, the Proxmox compute resource now supports creating virtual machines with UEFI Secure Boot enabled, providing the possibility to provision operating systems that require Secure Boot. This improves platform security by ensuring that only trusted, signed boot components are loaded during system startup.

Enriched Audit Logs with User Login Details

Building on previous updates that allowed audit logs to be exported as a separate file to central logging tools (see knowledge base article), orcharhino 7.10 now enriches audited events with additional information about user logins, logouts and failed login attempts.

Example entries in audits

Continuous Documentation Improvements & Expansion

As orcharhino evolves, our documentation is continuously updated, expanded, and refined with user feedback in every release. Beyond structural updates to several chapters, this release adds helpful tips for daily tasks. For example, did you know that you can directly connect your hosts with host collections via the activation key? The documentation now hints this feature at the corresponding parts. If you use host collections to group systems for updates or even distribution upgrades, you can directly assign them to a collection during the registration process.

Tech Preview: Ansible Director Host Assignments

While still in Tech Preview, Ansible Director has gained important new automation capabilities in orcharhino 7.10. You can now assign Ansible roles directly to hosts or through host groups, and newly provisioned hosts schedule automatically an initial Ansible run. This ensures that systems receive their intended configuration immediately after the operating system is installed, reducing manual steps and making provisioning more consistent and reliable.

Assigning Ansible content using Ansible Director on the ‚Create Host‘ page (1)
Assigning Ansible content using Ansible Director on the ‚Create Host‘ page (2)

Changelog Features

Changelog CVE

  • CVE-2026-12515: Content-upload might have leaked information on other products.
  • CVE-2026-5135: Unauthorized modification of host configurations via broken access control.
  • CVE-2026-5136: Privilege escalation to administrator-level access via usergroup role assignment manipulation.
  • CVE-2026-5138: Information disclosure via improper validation of nested request parameters.
  • CVE-2026-5142: Cross-tenant private ssh key disclosure via taxonomy scoping bypass.

Changelog Bugfixes

  • Content (Containers): orcharhino gave a response ‚415 Unsupported Media Type‘ instead of ‚404‘ on oauth2 request against registry end point.
  • Content Management (Debian/Ubuntu): Changes in package metadata were not considered for package upgrades.
  • Content Management (Debian/Ubuntu): Publications with filters or incremental content view updates failed with ’sending query and params failed: number of parameters must be between 0 and 65535′.
  • Content Management: Incremental content views updates for rolling CVs crashed with undefined method ‚version_href‘.
  • Host Deployment (Ubuntu 24/26): Network deployment on UEFI was broken due to local disk boot.
  • Host Provisioning (Debian/Ubuntu): A single package upgrade triggered the update of all packages of the system.
  • Host Provisioning (Secure Boot): The documentation did not show modules to configure orcharhino Proxies to provision Secure Boot-enabled hosts for CentOS, Oracle Linux, and SUSE Linux Enterprise Server: https://docs.orcharhino.com/or/docs/sources/landing_page.html?page=provisioning_hosts/using_network_boot_to_provision_hosts.html
  • Host Provisioning (Ubuntu): The REX configuration for remote execution was throwing an error when a non-root user was used for the SSH connection via “sudo-rs“.
  • Installation: katello-certs-check crashed when used with wildcards certificates.
  • Maintenance (SLES): Updated the Knowledge Base article how to use the SLES Service Pack Job to re-assign the host collection https://atixservice.zendesk.com/hc/en-001/articles/29848147059740
  • OpenSCAP: The client installation on SUSE Linux Enterprise Server 16.0 failed due to missing cron package dependency.
  • Proxmox: Boot order for image based deployment was not updated correctly to use image template disks.
  • Proxmox: Prevented image template disks from being overwritten by conflicting compute profile disks during provisioning.
  • Red Hat Insights: The periodic ‚Upload Inventory Task‘ never finished if no connection to Red Hat Insights is configured.
  • Remote Execution: Registering a SLES15SP7 host using a custom SSH user for remote execution failed.
  • SCC Manager: An HTTP-Proxy that requires authentication did not work with SCC product synchronization.

Deprecations & Removals

Tech Previews

  • Ansible Director: Creating and assigning content in different organizations via UI is now possible.
  • Ansible Director: Facts collected during Ansible runs are now being sent to orcharhino.
  • Ansible Director: Non-admin users could not manage Ansible variables.
  • Ansible Director: orcharhino now automatically executes Ansible after the deployment of a host.
  • Ansible Director: Reports of Ansible runs are now being automatically generated.
  • OpenTofu: Ensured resources created via OpenTofu are removed if host creation fails.
  • OpenTofu: TfState information is filtered out in log files.

Weitere Release Notes

Bereit loszulegen?
Starten Sie noch heute Ihre
kostenlose Testphase!

Bei Fragen zu unseren Produkten und Leistungen oder allen
anderen Themen stehen wir selbstverständlich gerne zur Verfügung.

Suche