VMware Tanzu Application Service for VMs v2.11 Release Notes

Page last updated:

This topic contains release notes for VMware Tanzu Application Service for VMs (TAS for VMs) v2.11.

TAS for VMs is certified by the Cloud Foundry Foundation for 2022.

For more information about the Cloud Foundry Certified Provider Program, see How Do I Become a Certified Provider? on the Cloud Foundry website.

Because VMware uses the Percona Distribution for MySQL, expect a time lag between Oracle releasing a MySQL patch and VMware releasing TAS for VMs containing that patch.

Required Cloud Foundry Command-Line Interface (cf CLI) version: You must install cf CLI v7 when upgrading to or using TAS for VMs v2.11.

For more information, see Upgrading to cf CLI v7.


Releases

2.11.26

Release Date: 09/20/2022

  • [Security Fix] Bump Cloud Controller Ruby version to 2.7.6 and Go to 1.18.5
  • [Security Fix] Bump golang to 1.17.12 in routing release
  • [Feature] Enables TLS for all internal MySQL galera and monitoring components
  • [Feature Improvement] Bump golang to 1.18.2+ for diego, garden-runc, mapfs, mysql-monitoring, cf-networking, and silk
  • [Feature Improvement] Use the latest version of nats-release (built on golang 1.18.5)
  • Bump backup-and-restore-sdk to version 1.18.50
  • Bump bosh-system-metrics-forwarder to version 0.0.24
  • Bump bpm to version 1.1.19
  • Bump capi to version 1.109.11
  • Bump cf-networking to version 3.12.0
  • Bump cflinuxfs3 to version 0.319.0
  • Bump credhub to version 2.12.8
  • Bump diego to version 2.66.3
  • Bump dotnet-core-offline-buildpack to version 2.4.0
  • Bump garden-runc to version 1.22.0
  • Bump go-offline-buildpack to version 1.9.49
  • Bump java-offline-buildpack to version 4.50
  • Bump log-cache to version 2.11.13
  • Bump loggregator to version 106.6.9
  • Bump loggregator-agent to version 6.4.4
  • Bump mapfs to version 1.2.11
  • Bump metrics-discovery to version 3.1.2
  • Bump mysql-monitoring to version 9.18.0
  • Bump nats to version 50
  • Bump nfs-volume to version 5.0.18
  • Bump nginx-offline-buildpack to version 1.1.42
  • Bump nodejs-offline-buildpack to version 1.7.73
  • Bump php-offline-buildpack to version 4.4.65
  • Bump push-apps-manager-release to version 674.0.9
  • Bump python-offline-buildpack to version 1.7.57
  • Bump r-offline-buildpack to version 1.1.32
  • Bump ruby-offline-buildpack to version 1.8.57
  • Bump silk to version 3.12.0
  • Bump smb-volume to version 3.1.5
  • Bump staticfile-offline-buildpack to version 1.5.33
  • Bump statsd-injector to version 1.11.21
  • Bump syslog to version 11.8.2
  • Bump system-metrics-scraper to version 3.2.8
  • Bump uaa to version 74.5.48
Component Version Release Notes
ubuntu-xenial stemcell621.265
backup-and-restore-sdk1.18.50
v1.18.50
  ## Changes
  * Add final release 1.18.49 [ci skip]
  * Bump mariadb from 10.6.8 to 10.6.9 (#688)
  * Bump mysql from 5.7.37 to 5.7.38 (#674)
  * Bump postgres from 10.21 to 10.22 (#682)
  * Bump postgres from 11.16 to 11.17 (#683)
  * Bump postgres from 13.7 to 13.8 (#684)
  * Fix deploy postres ci job (#687)
  * [ci] Replace Xenial by Jammy (#689)
  ## Dependencies
  * **storage:** Updated to v1.25.0.
For more information, see [storage](https://github.com/googleapis/google-cloud-go). * **bosh-backup-and-restore:** Updated to v1.9.37.
For more information, see [bosh-backup-and-restore](https://github.com/cloudfoundry-incubator/bosh-backup-and-restore). * **api:** Updated to v0.94.0.
For more information, see [api](https://github.com/googleapis/google-api-go-client).
v1.18.49
  ## Changes
  * Add final release 1.18.47 [ci skip]
  ## Dependencies
  * **storage:** Updated to v1.24.0.
For more information, see [storage](https://github.com/googleapis/google-cloud-go). * **bosh-backup-and-restore:** Updated to v1.9.35.
For more information, see [bosh-backup-and-restore](https://github.com/cloudfoundry-incubator/bosh-backup-and-restore). * **gomega:** Updated to v1.20.0.
For more information, see [gomega](https://github.com/onsi/gomega).
v1.18.48
  ## Changes
  * Add final release 1.18.47 [ci skip]
  * Fix bpm-release download url
  * Parametrise minis-host and minio-port
  * Remove explicit port in BOSH_GW_HOST
  * Remove hardcoded port
  * Replace secrets in task definition
  ## Dependencies
  * **storage:** Updated to v1.24.0.
For more information, see [storage](https://github.com/googleapis/google-cloud-go). * **bosh-backup-and-restore:** Updated to v1.9.35.
For more information, see [bosh-backup-and-restore](https://github.com/cloudfoundry-incubator/bosh-backup-and-restore). * **gomega:** Updated to v1.20.0.
For more information, see [gomega](https://github.com/onsi/gomega).
binary-offline-buildpack1.0.45
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.24
bpm1.1.19
capi1.109.11
cf-autoscaling249.0.17
cf-cli1.38.0
cf-networking3.12.0
cflinuxfs30.319.0
credhub2.12.8
2.12.8
  ### Security Fixes
  - Bump various dependencies, including bumping postgresql from 42.4.0 to 42.4.1, which addresses [CVE-2022-31197](https://nvd.nist.gov/vuln/detail/CVE-2022-31197)
          
2.12.7
  ### Security Fixes
  - Bump various dependencies
  ### Bug Fixes
  - Improved test robustness on platforms with slow random number generation
  - Improved test robustness for several tests that handle database setup
          
diego2.66.3
dotnet-core-offline-buildpack2.4.0
garden-runc1.22.0
go-offline-buildpack1.9.49
haproxy9.8.0
java-offline-buildpack4.50
log-cache2.11.13
loggregator106.6.9
loggregator-agent6.4.4
mapfs1.2.11
v1.2.11
  ## Changes
  * Update vendored package golang-1-linux (#21)
          
v1.2.8
  ## What's Changed
  * Bump src/mapfs to `0ee84aa` #18
          
v1.2.7
  - [Bumps mapfs submodule to master@1600494](https://github.com/cloudfoundry/mapfs/commit/160049400a47577b0f3a8b2948974bc38ce76f18)
  - [Bump golang from 1.13 to 1.17](https://github.com/cloudfoundry/mapfs-release/commit/c287adda5cbdf345ff1b4985ae93cb72f1618f95)
          
metric-registrar1.1.16
metrics-discovery3.1.2
mysql-monitoring9.18.0
nats50
nfs-volume5.0.18
v5.0.18
  ## Changes
  * Update vendored package golang-1-linux (#215)
  ## Dependencies
  * **bosh-template:** Updated to v2.3.0.
For more information, see [bosh-template](https://github.com/cloudfoundry/bosh). * **gomega:** Updated to v1.20.2.
For more information, see [gomega](https://github.com/onsi/gomega). * **mapfs-release:** Updated to v`4413136`.
For more information, see [mapfs-release](https://github.com/cloudfoundry/mapfs-release).
v5.0.17
  ## Changes
  * Update vendored package golang-1-linux (#206)
  * [ci] Force use of iptables instead of nftables
  ## Dependencies
  * **ginkgo:** Updated to v1.16.5.
For more information, see [ginkgo](https://github.com/onsi/ginkgo). * **gomega:** Updated to v1.19.0.
For more information, see [gomega](https://github.com/onsi/gomega). * **mapfs-release:** Updated to v`90d2f31`.
For more information, see [mapfs-release](https://github.com/cloudfoundry/mapfs-release).
nginx-offline-buildpack1.1.42
nodejs-offline-buildpack1.7.73
notifications62
notifications-ui40
php-offline-buildpack4.4.65
push-apps-manager-release674.0.9
push-usage-service-release674.0.24
pxc0.44.0
python-offline-buildpack1.7.57
r-offline-buildpack1.1.32
routing0.236.0
ruby-offline-buildpack1.8.57
silk3.12.0
smb-volume3.1.5
v3.1.5
  ## Changes
  * Update vendored package golang-1-linux (#58)
          
v3.1.4
  ## Release Notes
  - Fix issue when multiple cf versions are included  (#55)
  ## Dependencies
  - The `smbbrokerpush` and `bbr-smbbroker` errands require either the `cf-cli-7-linux` or `cf-cli-6-linux` job from [cf-cli-release](https://bosh.io/releases/github.com/bosh-packages/cf-cli-release?all=1) to be colocated on the errand VM.
          
v3.1.3
  ## Release Notes
  - Added support for CF CLI v8 to errands (#45)
  - Fixed Jammy compilation issues (#53)
  ## Dependencies
  - Bump [src/code.cloudfoundry.org/smbbroker](https://github.com/cloudfoundry/smbbroker) (#41, #50)
  - Bump [src/code.cloudfoundry.org/smbdriver](https://github.com/cloudfoundry/smbdriver) (#47, #48, #51)
          
v3.1.2
  ## Release Notes
  - Support Bionic Stemcell #16
  - Add blobs for the `keyutils` package for both `bionic` and `jammy`.
  - We now install this package on any VM that runs the `smbdriver` bosh job iff that VM uses a `bionic` or `jammy` stemcell
  - This should allow the `smbdriver` to reliably mount SMB volumes on those stemcells, as discussed in #16
  ## Dependencies
  - The `smbbrokerpush` and `bbr-smbbroker` errands require either the `cf-cli-7-linux` or `cf-cli-6-linux` job from [cf-cli-release](https://bosh.io/releases/github.com/bosh-packages/cf-cli-release?all=1) to be colocated on the errand VM.
          
v3.1.1
  ## Release Notes
  * Bumps [bosh-template](https://github.com/cloudfoundry/bosh) from 2.2.0 to 2.2.1 (#22)
  * Bumps [rspec-its](https://github.com/rspec/rspec-its) from 1.2.0 to 1.3.0 (#23)
  * Bumps [rspec](https://github.com/rspec/rspec-metagem) to 3.11.0. (#37)
  * Bumps [src/code.cloudfoundry.org/smbdriver](https://github.com/cloudfoundry/smbdriver) to `1e97c5d` (#34)
  * Bumps [src/code.cloudfoundry.org/smbbroker](https://github.com/cloudfoundry/smbbroker) to `64ba567` (#36)
  * Bumps automake from 1.15 to 1.15.1 (#43 - fixes Bionic compilation)
  ## Dependencies
  - The `smbbrokerpush` and `bbr-smbbroker` errands require either the `cf-cli-7-linux` or `cf-cli-6-linux` job from [cf-cli-release](https://bosh.io/releases/github.com/bosh-packages/cf-cli-release?all=1) to be colocated on the errand VM.
          
smoke-tests4.5.0
staticfile-offline-buildpack1.5.33
statsd-injector1.11.21
syslog11.8.2
system-metrics-scraper3.2.8
uaa74.5.48
v74.5.48
  ### Dependency bumps
  - Various dependency bumps.
          
v74.5.47
  ### Fixes
  - Fixes a sporadic pre-start script failure due to a race condition of the `update-ca-certificates` commands [#391]
  ### Dependency bumps
  - Various dependency bumps.
          

2.11.23

Release Date: 08/10/2022

  • Bump backup-and-restore-sdk to version 1.18.47
  • Bump bosh-system-metrics-forwarder to version 0.0.23
  • Bump cf-autoscaling to version 249.0.17
  • Bump cf-networking to version 3.11.0
  • Bump cflinuxfs3 to version 0.312.0
  • Bump dotnet-core-offline-buildpack to version 2.3.44
  • Bump go-offline-buildpack to version 1.9.48
  • Bump java-offline-buildpack to version 4.49.1
  • Bump log-cache to version 2.11.12
  • Bump loggregator to version 106.6.8
  • Bump loggregator-agent to version 6.4.3
  • Bump metric-registrar to version 1.1.16
  • Bump metrics-discovery to version 3.1.1
  • Bump nginx-offline-buildpack to version 1.1.41
  • Bump nodejs-offline-buildpack to version 1.7.72
  • Bump php-offline-buildpack to version 4.4.64
  • Bump pxc to version 0.44.0
  • Bump python-offline-buildpack to version 1.7.56
  • Bump r-offline-buildpack to version 1.1.31
  • Bump routing to version 0.236.0
  • Bump ruby-offline-buildpack to version 1.8.56
  • Bump silk to version 3.11.0
  • Bump staticfile-offline-buildpack to version 1.5.32
  • Bump statsd-injector to version 1.11.20
  • Bump syslog to version 11.8.1
  • Bump system-metrics-scraper to version 3.2.7
  • Bump uaa to version 74.5.46
Component Version Release Notes
ubuntu-xenial stemcell621.256
backup-and-restore-sdk1.18.47
binary-offline-buildpack1.0.45
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.23
bpm1.1.18
capi1.109.10
cf-autoscaling249.0.17
cf-cli1.38.0
cf-networking3.11.0
cflinuxfs30.312.0
credhub2.12.6
diego2.62.0
dotnet-core-offline-buildpack2.3.44
garden-runc1.20.8
go-offline-buildpack1.9.48
haproxy9.8.0
java-offline-buildpack4.49.1
log-cache2.11.12
loggregator106.6.8
loggregator-agent6.4.3
mapfs1.2.6
metric-registrar1.1.16
metrics-discovery3.1.1
mysql-monitoring9.15.0
nats42
nfs-volume5.0.16
nginx-offline-buildpack1.1.41
nodejs-offline-buildpack1.7.72
notifications62
notifications-ui40
php-offline-buildpack4.4.64
push-apps-manager-release674.0.8
push-usage-service-release674.0.24
pxc0.44.0
python-offline-buildpack1.7.56
r-offline-buildpack1.1.31
routing0.236.0
v0.236.0
  ## What's Changed
  * Gorouter restart script waits for the gorouter to be running before reloading monit
  ## ✨  Built with go 1.17.12
  **Full Changelog**: https://github.com/cloudfoundry/routing-release/compare/0.235.0...0.236.0
          
ruby-offline-buildpack1.8.56
silk3.11.0
smb-volume3.1.0
smoke-tests4.5.0
staticfile-offline-buildpack1.5.32
statsd-injector1.11.20
syslog11.8.1
system-metrics-scraper3.2.7
uaa74.5.46

2.11.22

Release Date: 07/18/2022

  • [Security Fix] Update Content-Security-Policy
  • [Feature] Enable telemetry for iptables rules on Diego cells
  • [Feature] User has the ability to manage step up scaling app instances using Apps Manager
  • [Feature Improvement] Deprecate Spring Cloud Connectors & Spring Auto Configuration support in Java Buildpack.
  • [Bug Fix] Add health check script for Bosh DNS for Cloud Controller
  • [Bug Fix] Do not disable metadata on Log Cache aggregate drain
  • [Bug Fix] Fix dummy routes showing in the User Interface
  • [Bug Fix] Fix role assignment when users are created through the CLI
  • [Bug Fix] Fix share domain with organization screen from erroring out
  • [Bug Fix] Use Content-Disposition header as heapdump filename
  • [Bug Fix] When Autoscaler is configured to use the RabbitMQ Queue Depth scaling metric in an autoscaling rule, you can specify a RabbitMQ service instance. If you specify a service instance, Autoscaler only requests metrics from that service instance.
  • [Bug Fix] Autoscaler migration correctly handles manually-created service bindings index.
  • [Bug Fix] Fixes Autoscaler edge case when using http_throughput rules with scaling factor larger than 1.
  • Bump backup-and-restore-sdk to version 1.18.46
  • Bump cf-autoscaling to version 249.0.13
  • Bump cf-cli to version 1.38.0
  • Bump cf-networking to version 3.9.0
  • Bump cflinuxfs3 to version 0.309.0
  • Bump credhub to version 2.12.6
  • Bump diego to version 2.62.0
  • Bump dotnet-core-offline-buildpack to version 2.3.43
  • Bump garden-runc to version 1.20.8
  • Bump go-offline-buildpack to version 1.9.47
  • Bump loggregator-agent to version 6.4.2
  • Bump metrics-discovery to version 3.1.0
  • Bump nginx-offline-buildpack to version 1.1.39
  • Bump nodejs-offline-buildpack to version 1.7.71
  • Bump php-offline-buildpack to version 4.4.63
  • Bump push-apps-manager-release to version 674.0.8
  • Bump pxc to version 0.43.0
  • Bump r-offline-buildpack to version 1.1.30
  • Bump routing to version 0.235.0
  • Bump ruby-offline-buildpack to version 1.8.55
  • Bump silk to version 3.9.0
  • Bump staticfile-offline-buildpack to version 1.5.31
  • Bump syslog to version 11.8.0
  • Bump system-metrics-scraper to version 3.2.6
  • Bump uaa to version 74.5.44
Component Version Release Notes
ubuntu-xenial stemcell621.252
backup-and-restore-sdk1.18.46
binary-offline-buildpack1.0.45
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.22
bpm1.1.18
capi1.109.10
cf-autoscaling249.0.13
cf-cli1.38.0
cf-networking3.9.0
cflinuxfs30.309.0
credhub2.12.6
2.12.6
  ### Security Fixes
  - Bump various dependencies
          
2.12.5
  ### Security Fixes
  - Bump various dependencies
  ### Bug Fixes
  - Fix for URL path handling on Windows ([cloudfoundry/credhub issue 266](https://github.com/cloudfoundry/credhub/issues/266))
  ### Features
  - CredHub now logs as info instead of error when a credential isn't found
  - Added support for jammy-based stemcells that have openssl 3 ([pivotal/credhub-release issue 65](https://github.com/pivotal/credhub-release/issues/65))
          
diego2.62.0
dotnet-core-offline-buildpack2.3.43
garden-runc1.20.8
go-offline-buildpack1.9.47
haproxy9.8.0
java-offline-buildpack4.49
log-cache2.11.11
loggregator106.6.7
loggregator-agent6.4.2
mapfs1.2.6
metric-registrar1.1.13
metrics-discovery3.1.0
mysql-monitoring9.15.0
nats42
nfs-volume5.0.16
nginx-offline-buildpack1.1.39
nodejs-offline-buildpack1.7.71
notifications62
notifications-ui40
php-offline-buildpack4.4.63
push-apps-manager-release674.0.8
push-usage-service-release674.0.24
pxc0.43.0
python-offline-buildpack1.7.54
r-offline-buildpack1.1.30
routing0.235.0
0.235.0
  ## What's Changed
  * Gorouter healthchecker retries connection instead of monit (https://github.com/cloudfoundry/routing-release/pull/275)
  ## ✨  Built with go 1.17.11
  **Full Changelog**: https://github.com/cloudfoundry/routing-release/compare/0.234.0...0.235.0
          
0.234.0
  ## What's Changed
  * Gorouter: the metrics package now uses `lsof` to monitor file descriptors on MacOS @domdom82 https://github.com/cloudfoundry/gorouter/pull/312
  * 🐛 Bumped the `lager` dependency to resolve issues where the timeFormat flag was not honored, resulting in epoch timestamps vs human readable. Thanks @ameowlia!
  * Now tested with the bionic stemcell in CI
  ## ✨  Built with go 1.17.11
  **Full Changelog**: https://github.com/cloudfoundry/routing-release/compare/0.233.0...0.234.0
          
ruby-offline-buildpack1.8.55
silk3.9.0
smb-volume3.1.0
smoke-tests4.5.0
staticfile-offline-buildpack1.5.31
statsd-injector1.11.19
syslog11.8.0
system-metrics-scraper3.2.6
uaa74.5.44

2.11.21

Release Date: 06/23/2022

  • Bump diego to version 2.62.0
Component Version
ubuntu-xenial stemcell621.244
backup-and-restore-sdk1.18.42
binary-offline-buildpack1.0.45
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.22
bpm1.1.18
capi1.109.10
cf-autoscaling249.0.7
cf-cli1.32.0
cf-networking3.6.0
cflinuxfs30.301.0
credhub2.12.4
diego2.62.0
dotnet-core-offline-buildpack2.3.42
garden-runc1.20.6
go-offline-buildpack1.9.46
haproxy9.8.0
java-offline-buildpack4.49
log-cache2.11.11
loggregator106.6.7
loggregator-agent6.4.1
mapfs1.2.6
metric-registrar1.1.13
metrics-discovery3.0.13
mysql-monitoring9.15.0
nats42
nfs-volume5.0.16
nginx-offline-buildpack1.1.38
nodejs-offline-buildpack1.7.70
notifications62
notifications-ui40
php-offline-buildpack4.4.61
push-apps-manager-release674.0.7
push-usage-service-release674.0.24
pxc0.42.0
python-offline-buildpack1.7.54
r-offline-buildpack1.1.29
routing0.233.0
ruby-offline-buildpack1.8.54
silk3.6.0
smb-volume3.1.0
smoke-tests4.5.0
staticfile-offline-buildpack1.5.30
statsd-injector1.11.19
syslog11.7.10
system-metrics-scraper3.2.5
uaa74.5.41

2.11.20

Release Date: 06/09/2022

Warning: Breaking change
This version contains Diego 2.64.0, which bumps to Go 1.18. Go 1.18 no longer supports TLS 1.0 and 1.1 connections or certificates with a SHA-1 checksum. This is most likely to affect connections with external databases. We stated earlier that we wouldn’t bump to Go 1.18 until July 1, 2022. This TAS release with Diego 2.64.0 breaks that promise. We apologize. We are rolling back to Diego 2.62.0. If you already successfully deployed to this TAS release with Diego 2.64.0, then you are safe to continue using it.

  • [Security Fix] Added Content-Security-Policy headers in UAA responses
  • [Bug Fix] Sticky sessions no longer break when used with route-services that return HTTP 4xx/5xx responses
  • [Bug Fix/Improvement] Stop emitting debug metrics for agents and log-cache by default. Reduces load on logging system by >=720 metrics per vm per minute
  • [Breaking Change] If you followed the procedure in Autoscale application fails with MySQL Deadlock errors to manually add an index to an Autoscale database, and the index is not dropped before you upgrade to TAS for VMs v2.11.20, upgrading causes an error.
  • Bump backup-and-restore-sdk to version 1.18.42
  • Bump binary-offline-buildpack to version 1.0.45
  • Bump bosh-system-metrics-forwarder to version 0.0.22
  • Bump bpm to version 1.1.18
  • Bump capi to version 1.109.10
  • Bump cf-autoscaling to version 249.0.7
  • Bump cf-networking to version 3.6.0
  • Bump cflinuxfs3 to version 0.301.0
  • Bump diego to version 2.64.0
  • Bump dotnet-core-offline-buildpack to version 2.3.42
  • Bump garden-runc to version 1.20.6
  • Bump go-offline-buildpack to version 1.9.46
  • Bump java-offline-buildpack to version 4.49
  • Bump log-cache to version 2.11.11
  • Bump loggregator to version 106.6.7
  • Bump loggregator-agent to version 6.4.1
  • Bump metric-registrar to version 1.1.13
  • Bump metrics-discovery to version 3.0.13
  • Bump nfs-volume to version 5.0.16
  • Bump nginx-offline-buildpack to version 1.1.38
  • Bump nodejs-offline-buildpack to version 1.7.70
  • Bump php-offline-buildpack to version 4.4.61
  • Bump push-usage-service-release to version 674.0.24
  • Bump python-offline-buildpack to version 1.7.54
  • Bump r-offline-buildpack to version 1.1.29
  • Bump routing to version 0.233.0
  • Bump ruby-offline-buildpack to version 1.8.54
  • Bump silk to version 3.6.0
  • Bump staticfile-offline-buildpack to version 1.5.30
  • Bump statsd-injector to version 1.11.19
  • Bump syslog to version 11.7.10
  • Bump system-metrics-scraper to version 3.2.5
  • Bump uaa to version 74.5.41
Component Version Release Notes
ubuntu-xenial stemcell621.244
backup-and-restore-sdk1.18.42
binary-offline-buildpack1.0.45
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.22
bpm1.1.18
capi1.109.10
cf-autoscaling249.0.7
cf-cli1.32.0
cf-networking3.6.0
cflinuxfs30.301.0
credhub2.12.4
diego2.64.0
dotnet-core-offline-buildpack2.3.42
garden-runc1.20.6
go-offline-buildpack1.9.46
haproxy9.8.0
java-offline-buildpack4.49
log-cache2.11.11
loggregator106.6.7
loggregator-agent6.4.1
mapfs1.2.6
metric-registrar1.1.13
metrics-discovery3.0.13
mysql-monitoring9.15.0
nats42
nfs-volume5.0.16
nginx-offline-buildpack1.1.38
nodejs-offline-buildpack1.7.70
notifications62
notifications-ui40
php-offline-buildpack4.4.61
push-apps-manager-release674.0.7
push-usage-service-release674.0.24
pxc0.42.0
python-offline-buildpack1.7.54
r-offline-buildpack1.1.29
routing0.233.0
0.233.0
  ## What's Changed
  * TCP Router: Add locking to the haproxy_reloader script to avoid haproxy reload/restart race conditions by @geofffranks in https://github.com/cloudfoundry/routing-release/pull/269
  * TCP Router: Bump HAProxy from 1.8.13 to 2.5.4 by @cunnie in https://github.com/cloudfoundry/routing-release/pull/266
  * Gorouter: fix proxy round tripper race condition by @ameowlia and @geofffranks  in https://github.com/cloudfoundry/gorouter/pull/318
  * Routing API: fix timestamp precision issue that caused routes to be pruned unexpectedly by @geofffranks in https://github.com/cloudfoundry/routing-api/pull/24
  *  Routing API: remove `golang.x509ignoreCN` bosh property by @geofffranks and @mariash
  * Routing API: fix bug that caused TCP Router's HAProxy to reload every minute by @jrussett in https://github.com/cloudfoundry/routing-api/pull/26.
  ## Manifest Property Changes
  | Job | Property  | Notes |
  | --- | --- | --- |
  | `routing-api` | `golang.x509ignoreCN` | This property exposed a go debug flag for go version 1.15. Since go 1.16 this go debug flag has had no affect. Removing this bosh property is part of our effort to keep our code base free of cruft. |
  ## ✨  Built with go 1.17.10
  **Full Changelog**: https://github.com/cloudfoundry/routing-release/compare/0.232.0...0.233.0
          
0.232.0
  ## What's Changed
  * Fixing issue #250: Return a 503 not a 404 when all instances down by @kecirlotfi in https://github.com/cloudfoundry/routing-release/pull/268 and https://github.com/cloudfoundry/gorouter/pull/314
  * Fixing issue https://github.com/cloudfoundry/gorouter/pull/315: Fix route service pruning by @geofffranks
  ## Manifest Property Changes
  | Job | Property | default | notes |
  | --- | --- | --- | --- |
  | `gorouter` | `for_backwards_compatibility_only.empty_pool_response_code_503` | `0s` | This property was added to enable https://github.com/cloudfoundry/routing-release/pull/268 |
  ## New Contributors 🎉
  * @kecirlotfi made their first contribution! Thanks so much!
  ## ✨  Built with go 1.17.9
  **Full Changelog**: https://github.com/cloudfoundry/routing-release/compare/0.231.0...0.232.0
          
ruby-offline-buildpack1.8.54
silk3.6.0
smb-volume3.1.0
smoke-tests4.5.0
staticfile-offline-buildpack1.5.30
statsd-injector1.11.19
syslog11.7.10
system-metrics-scraper3.2.5
uaa74.5.41

2.11.19

Release Date: 04/20/2022

  • [Feature Improvement] Add option to configure CC BBR health check timeout
  • [Feature Improvement] Enforce service name uniqueness in shared services in spaces
  • [Bug Fix] Service offerings now appear to users in orgs/spaces with the appropriate service access
  • [Breaking Change] Syslog drains configured to use TLS now reject certificates signed with the SHA-1 hash function.
  • Bump backup-and-restore-sdk to version 1.18.39
  • Bump binary-offline-buildpack to version 1.0.43
  • Bump capi to version 1.109.9
  • Bump cf-autoscaling to version 249.0.2
  • Bump cflinuxfs3 to version 0.285.0
  • Bump credhub to version 2.12.4
  • Bump diego to version 2.62.0
  • Bump dotnet-core-offline-buildpack to version 2.3.41
  • Bump go-offline-buildpack to version 1.9.42
  • Bump java-offline-buildpack to version 4.48.2
  • Bump log-cache to version 2.11.8
  • Bump loggregator to version 106.6.4
  • Bump loggregator-agent to version 6.3.11
  • Bump metrics-discovery to version 3.0.10
  • Bump nginx-offline-buildpack to version 1.1.37
  • Bump nodejs-offline-buildpack to version 1.7.69
  • Bump php-offline-buildpack to version 4.4.59
  • Bump push-apps-manager-release to version 674.0.7
  • Bump pxc to version 0.42.0
  • Bump python-offline-buildpack to version 1.7.53
  • Bump r-offline-buildpack to version 1.1.28
  • Bump ruby-offline-buildpack to version 1.8.53
  • Bump uaa to version 74.5.37
Component Version Release Notes
ubuntu-xenial stemcell621.224
backup-and-restore-sdk1.18.39
binary-offline-buildpack1.0.43
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.21
bpm1.1.16
capi1.109.9
cf-autoscaling249.0.2
v249.0.2
  ## What's Changed
  * Bump github.com/onsi/gomega from 1.18.1 to 1.19.0 in /src by @dependabot in https://github.com/pivotal-cf/cf-autoscaling-release/pull/640
  * bump spring boot for cve CVE-2022-22965 by @Benjamintf1 in https://github.com/pivotal-cf/cf-autoscaling-release/pull/646
  * Bump log4j-to-slf4j from 2.17.1 to 2.17.2 in /src/cf-autoscaling/api by @dependabot in https://github.com/pivotal-cf/cf-autoscaling-release/pull/619
  * Bump log4j-api from 2.17.1 to 2.17.2 in /src/cf-autoscaling/api by @dependabot in https://github.com/pivotal-cf/cf-autoscaling-release/pull/618
  * Bump gson from 2.8.6 to 2.9.0 in /src/cf-autoscaling/api by @dependabot in https://github.com/pivotal-cf/cf-autoscaling-release/pull/611
  * Bump spock-core from 2.0-groovy-3.0 to 2.1-groovy-3.0 in /src/cf-autoscaling/api by @dependabot in https://github.com/pivotal-cf/cf-autoscaling-release/pull/613
  * Bump objenesis from 3.1 to 3.2 in /src/cf-autoscaling/api by @dependabot in https://github.com/pivotal-cf/cf-autoscaling-release/pull/479
  **Full Changelog**: https://github.com/pivotal-cf/cf-autoscaling-release/compare/v249.0.1...v249.0.2
          
v249.0.1
  ## What's Changed
  * Pin jackson-databind to 2.13.2.2 to address [CVE-2020-36518](https://nvd.nist.gov/vuln/detail/CVE-2020-36518)
  * Unpin tomcat dependencies in autoscale API in https://github.com/pivotal-cf/cf-autoscaling-release/pull/636
  * Bump autoscale API dependencies in https://github.com/pivotal-cf/cf-autoscaling-release/pull/612, https://github.com/pivotal-cf/cf-autoscaling-release/pull/625, https://github.com/pivotal-cf/cf-autoscaling-release/pull/525, https://github.com/pivotal-cf/cf-autoscaling-release/pull/634
  **Full Changelog**: https://github.com/pivotal-cf/cf-autoscaling-release/compare/v249...v249.0.1
          
cf-cli1.32.0
cf-networking3.3.0
cflinuxfs30.285.0
credhub2.12.4
2.12.4
  ### Security Fixes
  - Bump various dependencies.
          
2.12.3
  ### Security Fixes
  - Bump various dependencies.
          
diego2.62.0
dotnet-core-offline-buildpack2.3.41
garden-runc1.20.3
go-offline-buildpack1.9.42
haproxy9.8.0
java-offline-buildpack4.48.2
log-cache2.11.8
v2.11.8
  ## Release Highlights
  Pin Go back to go1.17.
  [Go 1.18 includes changes to memory management](https://tip.golang.org/doc/go1.18#runtime) and we'd like to get more familiarity with these changes and their impact before bumping.
  ### ✨ Built with golang 1.17.8
          
v2.11.7
  - fix bug with large messages (#58)
  - bump-golang to v0.100.0(now 1.18)
          
loggregator106.6.4
v106.6.4
  - fix bug with large messages (#430)
  - bump-golang to v0.100.0(now 1.18)
          
loggregator-agent6.3.11
v6.3.11
  - fix bug with large messages (#89)
  - bump-golang to v0.100.0(now 1.18)
          
mapfs1.2.6
metric-registrar1.1.12
metrics-discovery3.0.10
v3.0.10
  - fix bug with large messages (#22)
  - bump-golang to v0.100.0(now 1.18)
          
mysql-monitoring9.15.0
nats42
nfs-volume5.0.12
nginx-offline-buildpack1.1.37
nodejs-offline-buildpack1.7.69
notifications62
notifications-ui40
php-offline-buildpack4.4.59
push-apps-manager-release674.0.7
push-usage-service-release674.0.23
pxc0.42.0
python-offline-buildpack1.7.53
r-offline-buildpack1.1.28
routing0.231.0
ruby-offline-buildpack1.8.53
silk3.3.0
smb-volume3.1.0
smoke-tests4.5.0
staticfile-offline-buildpack1.5.29
statsd-injector1.11.18
syslog11.7.7
system-metrics-scraper3.2.4
uaa74.5.37

2.11.18

Release Date: 04/06/2022

  • [Security Fix] This release fixes CVE-2022-22965; note that the “fix” in the immediately prior version did not actually address the vulnerability, as Spring framework dependencies in UAA that should have been updated, were not. We have confirmed this version actually contains the dependency bumps, and that it is no longer vulnerable to our confirmed exploit. We consider this patch necessary for secure operation; see the VMware Security Advisory here for more details. This release also includes a new version of the Java Buildpack.
  • Bump java-offline-buildpack to version 4.48.2
  • Bump uaa to version 74.5.37
Component Version
ubuntu-xenial stemcell621.224
backup-and-restore-sdk1.18.34
binary-offline-buildpack1.0.42
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.21
bpm1.1.16
capi1.109.7
cf-autoscaling249
cf-cli1.32.0
cf-networking3.3.0
cflinuxfs30.279.0
credhub2.12.1
diego2.61.0
dotnet-core-offline-buildpack2.3.40
garden-runc1.20.3
go-offline-buildpack1.9.41
haproxy9.8.0
java-offline-buildpack4.48.2
log-cache2.11.6
loggregator106.6.3
loggregator-agent6.3.10
mapfs1.2.6
metric-registrar1.1.12
metrics-discovery3.0.9
mysql-monitoring9.15.0
nats42
nfs-volume5.0.12
nginx-offline-buildpack1.1.36
nodejs-offline-buildpack1.7.67
notifications62
notifications-ui40
php-offline-buildpack4.4.57
push-apps-manager-release674.0.6
push-usage-service-release674.0.23
pxc0.41.0
python-offline-buildpack1.7.51
r-offline-buildpack1.1.27
routing0.231.0
ruby-offline-buildpack1.8.52
silk3.3.0
smb-volume3.1.0
smoke-tests4.5.0
staticfile-offline-buildpack1.5.29
statsd-injector1.11.18
syslog11.7.7
system-metrics-scraper3.2.4
uaa74.5.37

2.11.17

Release Date: 03/31/2022

  • [Security Fix] This release was intended to address CVE-2022-22965, but did not actually update the vulnerable dependencies. Upgrade to a more recent patch version instead. See the VMware Security Advisory here for more details.
  • Bump uaa to version 74.5.36
Component Version
ubuntu-xenial stemcell621.224
backup-and-restore-sdk1.18.34
binary-offline-buildpack1.0.42
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.21
bpm1.1.16
capi1.109.7
cf-autoscaling249
cf-cli1.32.0
cf-networking3.3.0
cflinuxfs30.279.0
credhub2.12.1
diego2.61.0
dotnet-core-offline-buildpack2.3.40
garden-runc1.20.3
go-offline-buildpack1.9.41
haproxy9.8.0
java-offline-buildpack4.48.1
log-cache2.11.6
loggregator106.6.3
loggregator-agent6.3.10
mapfs1.2.6
metric-registrar1.1.12
metrics-discovery3.0.9
mysql-monitoring9.15.0
nats42
nfs-volume5.0.12
nginx-offline-buildpack1.1.36
nodejs-offline-buildpack1.7.67
notifications62
notifications-ui40
php-offline-buildpack4.4.57
push-apps-manager-release674.0.6
push-usage-service-release674.0.23
pxc0.41.0
python-offline-buildpack1.7.51
r-offline-buildpack1.1.27
routing0.231.0
ruby-offline-buildpack1.8.52
silk3.3.0
smb-volume3.1.0
smoke-tests4.5.0
staticfile-offline-buildpack1.5.29
statsd-injector1.11.18
syslog11.7.7
system-metrics-scraper3.2.4
uaa74.5.36

2.11.16

Release Date: 03/31/2022

  • [Feature Improvement] Move aggregate drains to the syslog-binding cache to improve deploy speed and reduce errors.
  • [Security Fix] This release fixes CVE-2022-23806 and CVE-2022-23772.
  • [Bug Fix] Assign cloud_controller.read and cloud_controller.write scopes to service brokers created using CF CLI v8
  • [Bug Fix] CAPI: Quota metrics are no longer filtered when syslog ingress is turned on
  • [Bug Fix] Propagate updated user provided service environment variables to bound applications for CF CLI v8
  • [Bug Fix] Resolve an issue resulting in tcp-router repeatedly respawning haproxy until it hits a forked process limit
  • [Bug Fix] Resolves an issue where invalid seeded router group values should caused breaking changes
  • [Bug fix] Remove x509ignoreCN option in Gorouter
  • Bump capi to version 1.109.7
  • Bump cf-autoscaling to version 249
  • Bump cf-networking to version 3.3.0
  • Bump cflinuxfs3 to version 0.279.0
  • Bump credhub to version 2.12.1
  • Bump diego to version 2.61.0
  • Bump dotnet-core-offline-buildpack to version 2.3.40
  • Bump garden-runc to version 1.20.3
  • Bump go-offline-buildpack to version 1.9.41
  • Bump java-offline-buildpack to version 4.48.1
  • Bump log-cache to version 2.11.6
  • Bump loggregator to version 106.6.3
  • Bump loggregator-agent to version 6.3.10
  • Bump metric-registrar to version 1.1.12
  • Bump metrics-discovery to version 3.0.9
  • Bump nginx-offline-buildpack to version 1.1.36
  • Bump nodejs-offline-buildpack to version 1.7.67
  • Bump php-offline-buildpack to version 4.4.57
  • Bump python-offline-buildpack to version 1.7.51
  • Bump r-offline-buildpack to version 1.1.27
  • Bump routing to version 0.231.0
  • Bump ruby-offline-buildpack to version 1.8.52
  • Bump silk to version 3.3.0
  • Bump staticfile-offline-buildpack to version 1.5.29
  • Bump uaa to version 74.5.35
Component Version Release Notes
ubuntu-xenial stemcell621.224
backup-and-restore-sdk1.18.34
binary-offline-buildpack1.0.42
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.21
bpm1.1.16
capi1.109.7
cf-autoscaling249
cf-cli1.32.0
cf-networking3.3.0
cflinuxfs30.279.0
credhub2.12.1
2.12.1
  ### Security Fixes
  - Bump various dependencies.
          
2.12.0
  ### Security Fixes
  - Bump various dependencies.
  ### Bug Fixes
  - Fixes an issue where CredHub experiences downtime during certificate rotation process by making CredHub properly load concatenated mTLS CA certificates.
  ### Features
  - CredHub is now compatible with Postgres 13, 14.
          
2.11.1
  ### Dependency Bumps
  - Bumps log4j2 to 2.17.1
          
2.11.0
  ### Security Fixes
  - Further addresses [CVE with Log4j library](https://github.com/advisories/GHSA-jfh8-c2jp-5v3q) and [its prior incomplete fix](https://github.com/advisories/GHSA-7rjr-3q55-vv33) by bumping to log4j2 2.16.0.
          
2.10.0
  ### Security Fixes
  - Addresses [CVE with Log4j library](https://github.com/advisories/GHSA-jfh8-c2jp-5v3q)
  ### Features
  - Adds a minimum duration server-level configuration fields for leaf and CA certificates: `certificates.leaf_minimum_duration_in_days` and `certificates.ca_minimum_duration_in_days`. When these fields are configured, if a request to generate or regenerate a certificate has a duration lower than the minimum, then the minimum duration is used instead. (https://github.com/cloudfoundry/credhub/pull/201)
          
diego2.61.0
dotnet-core-offline-buildpack2.3.40
garden-runc1.20.3
go-offline-buildpack1.9.41
haproxy9.8.0
java-offline-buildpack4.48.1
log-cache2.11.6
loggregator106.6.3
loggregator-agent6.3.10
mapfs1.2.6
metric-registrar1.1.12
metrics-discovery3.0.9
mysql-monitoring9.15.0
nats42
nfs-volume5.0.12
nginx-offline-buildpack1.1.36
nodejs-offline-buildpack1.7.67
notifications62
notifications-ui40
php-offline-buildpack4.4.57
push-apps-manager-release674.0.6
push-usage-service-release674.0.23
pxc0.41.0
python-offline-buildpack1.7.51
r-offline-buildpack1.1.27
routing0.231.0
0.231.0
  ## Bug Fixes
  - Removed the x509ignoreCN property. Now that `gorouter` is built on golang 1.17, it
no longer has any effect on gorouter behavior, and was only adding to confusion in
the properties
  - Resolve an issue with route-registrar using the same TTL as it's RegistrationInterval
for tcp routes, leading to unnecessary churn of pruned + re-registered routes.
  - Resolve an issue with Routing API where upserts to tcp routes were causing change
events to be emitted when the only change was a bump in TTL. This led to an issue
where tcp-router was constantly reloading haproxy with every route's heartbeat
registration call.
  ## Manifest Property Changes
  | Job | Property | 0.230.0 | 0.231.0 |
  | --- | --- | --- | --- |
  | `gorouter` | `golang.x509ignoreCN` | false | No longer exists |
  |  `route_registrar` | `golang.x509ignoreCN` | false | No longer exists |
  | `tcp_router` | `golang.x509ignoreCN` | false | No longer exists |
  ### ✨ Built with golang 1.17.8
  **Full Changelog**: https://github.com/cloudfoundry/routing-release/compare/0.230.0...0.231.0
          
0.230.0
  ## Feature
  * update gorouter for prometheus scraping by @Benjamintf1 in https://github.com/cloudfoundry/routing-release/pull/258
  ## Bug Fix
  * Invalid seeded router group manifest values should no longer cause breaking changes by default by @ameowlia in https://github.com/cloudfoundry/routing-release/pull/261
  ### ✨ Built with golang 1.17.7
  **Full Changelog**: https://github.com/cloudfoundry/routing-release/compare/0.229.0...0.230.0
          
ruby-offline-buildpack1.8.52
silk3.3.0
smb-volume3.1.0
smoke-tests4.5.0
staticfile-offline-buildpack1.5.29
statsd-injector1.11.18
syslog11.7.7
system-metrics-scraper3.2.4
uaa74.5.35

2.11.15

Release Date: 02/28/2022

  • [Feature Improvement] Due to routing-release now being built with Golang 1.17, all certificates provided MUST contain SAN entries on them. The previous workaround of setting “Enable temporary workaround for certs without SANs” will no longer function.
  • [Feature Improvement] Per Golang 1.17’s new and stricter IP parsing standards, any IP addrs with leading zeros in any octets will result in a BOSH template failure to allow operators to remove the leading zeros and try again (affects properties fed into diego-release, garden-runc-release, winc-release, nats-release, and routing-release),.
  • [Feature Improvement] UAA is compatible with MySQL 8
  • [Feature Improvement] Enable TLS for container-to-container communication. See docs here for more info. Warning: this feature introduces a migration to the bbs database. Rolling back from this release will cause database issues.
  • [Bug Fix] Cloud Controller Worker - PruneExcessAppRevisions job is more memory efficient
  • [Bug Fix] Fix default metric registrar blocked tags to include ‘ip’ and remove 'id’
  • [Bug Fix] Fixes an issue related to the parsing of the X-B3-TraceId and X-B3-SpanId HTTP headers
  • [Bug Fix] Restore missing networking and garden metrics
  • [Bug Fix] Smoke tests support for TLSv1.3 only option
  • Bump backup-and-restore-sdk to version 1.18.34
  • Bump cf-autoscaling to version 248
  • Bump cflinuxfs3 to version 0.274.0
  • Bump credhub to version 2.9.9
  • Bump diego to version 2.58.1
  • Bump garden-runc to version 1.20.0
  • Bump loggregator-agent to version 6.3.8
  • Bump metric-registrar to version 1.1.11
  • Bump metrics-discovery to version 3.0.8
  • Bump nats to version 42
  • Bump routing to version 0.229.0
  • Bump smoke-tests to version 4.5.0
  • Bump uaa to version 74.5.34
Component Version
ubuntu-xenial stemcell621.211
backup-and-restore-sdk1.18.34
binary-offline-buildpack1.0.42
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.21
bpm1.1.16
capi1.109.5
cf-autoscaling248
cf-cli (v7/v8)*1.32.0
cf-networking2.43.0
cflinuxfs30.274.0
credhub2.9.9
diego2.58.1
dotnet-core-offline-buildpack2.3.38
garden-runc1.20.0
go-offline-buildpack1.9.38
haproxy9.8.0
java-offline-buildpack4.48
log-cache2.11.5
loggregator106.6.2
loggregator-agent6.3.8
mapfs1.2.6
metric-registrar1.1.11
metrics-discovery3.0.8
mysql-monitoring9.15.0
nats42
nfs-volume5.0.12
nginx-offline-buildpack1.1.34
nodejs-offline-buildpack1.7.66
notifications62
notifications-ui40
php-offline-buildpack4.4.55
push-apps-manager-release674.0.6
push-usage-service-release674.0.23
pxc0.41.0
python-offline-buildpack1.7.49
r-offline-buildpack1.1.25
routing0.229.0
ruby-offline-buildpack1.8.50
silk2.43.0
smb-volume3.1.0
smoke-tests4.5.0
staticfile-offline-buildpack1.5.28
statsd-injector1.11.18
syslog11.7.7
system-metrics-scraper3.2.4
uaa74.5.34

* The cf-cli version corresponds to the commercial distribution on VMware Tanzu Network.

2.11.14

Release Date: 02/07/2022

Note: This version of TAS for VMs contains a known issue that can cause application traces to break. See Gorouter Sets an Invalid X-B3-SpanID Header in Known Issues.

  • [Security Fix] Diego - Bump containerd to v1.5.9 to address (CVE-2021-43816)
  • [Security Fix] Bump routing release to 0.228.0 to address (CVE-2021-44716)
  • [Feature] Monit thresholds for the Cloud Controller worker are configurable
  • [Feature] Apps can be step-scaled up or down in Autoscaler. See About App Autoscaler.
  • [Feature Improvement] Golang v1.17 contains stricter IP parsing standards, so IP addresses with leading zeros in any octets cause a BOSH template failure. Operators can remove the leading zeros and try deploying again. This affects properties that feed into cf-networking-release, silk-release, loggregator-agent-release, and syslog-release. Syslog drains and metric registrar endpoints registered using user-provided services might also be affected.
  • [Bug Fix] Cloud Controller worker PruneExcessAppRevisions job is more memory efficient
  • [Bug Fix] Fix race conditions that could cause Autoscaler to crash
  • Bump backup-and-restore-sdk to version 1.18.32
  • Bump binary-offline-buildpack to version 1.0.42
  • Bump bosh-system-metrics-forwarder to version 0.0.21
  • Bump bpm to version 1.1.16
  • Bump capi to version 1.109.5
  • Bump cf-autoscaling to version 247
  • Bump cf-networking to version 2.43.0
  • Bump cflinuxfs3 to version 0.272.0
  • Bump diego to version 2.57.0
  • Bump dotnet-core-offline-buildpack to version 2.3.38
  • Bump go-offline-buildpack to version 1.9.38
  • Bump java-offline-buildpack to version 4.48
  • Bump log-cache to version 2.11.5
  • Bump loggregator to version 106.6.2
  • Bump loggregator-agent to version 6.3.7
  • Bump metric-registrar to version 1.1.10
  • Bump metrics-discovery to version 3.0.7
  • Bump nats to version 41
  • Bump nginx-offline-buildpack to version 1.1.34
  • Bump nodejs-offline-buildpack to version 1.7.66
  • Bump php-offline-buildpack to version 4.4.55
  • Bump pxc to version 0.41.0
  • Bump python-offline-buildpack to version 1.7.49
  • Bump r-offline-buildpack to version 1.1.25
  • Bump routing to version 0.228.0
  • Bump ruby-offline-buildpack to version 1.8.50
  • Bump silk to version 2.43.0
  • Bump smoke-tests to version 4.4.0
  • Bump staticfile-offline-buildpack to version 1.5.28
  • Bump statsd-injector to version 1.11.18
  • Bump syslog to version 11.7.7
  • Bump system-metrics-scraper to version 3.2.4
  • Bump uaa to version 74.5.31
Component Version
ubuntu-xenial stemcell621.198
backup-and-restore-sdk1.18.32
binary-offline-buildpack1.0.42
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.21
bpm1.1.16
capi1.109.5
cf-autoscaling247
cf-cli (v7/v8)*1.32.0
cf-networking2.43.0
cflinuxfs30.272.0
credhub2.9.8
diego2.57.0
dotnet-core-offline-buildpack2.3.38
garden-runc1.19.30
go-offline-buildpack1.9.38
haproxy9.8.0
java-offline-buildpack4.48
log-cache2.11.5
loggregator106.6.2
loggregator-agent6.3.7
mapfs1.2.6
metric-registrar1.1.10
metrics-discovery3.0.7
mysql-monitoring9.15.0
nats41
nfs-volume5.0.12
nginx-offline-buildpack1.1.34
nodejs-offline-buildpack1.7.66
notifications62
notifications-ui40
php-offline-buildpack4.4.55
push-apps-manager-release674.0.6
push-usage-service-release674.0.23
pxc0.41.0
python-offline-buildpack1.7.49
r-offline-buildpack1.1.25
routing0.228.0
ruby-offline-buildpack1.8.50
silk2.43.0
smb-volume3.1.0
smoke-tests4.4.0
staticfile-offline-buildpack1.5.28
statsd-injector1.11.18
syslog11.7.7
system-metrics-scraper3.2.4
uaa74.5.31

* The cf-cli version corresponds to the commercial distribution on VMware Tanzu Network.

2.11.13

Release Date: 12/21/2021

Warning:

See the following warnings:

Note: This version of TAS for VMs contains a known issue that can cause application traces to break. See Gorouter Sets an Invalid X-B3-SpanID Header in Known Issues.

  • [Security Fix] Fix uncontrolled recursion related to Log4j (CVE-2021-45105)
  • Bump credhub to version 2.9.8 which has Log4j 2.17.0
  • Bump java-offline-buildpack to version 4.47
  • Bump uaa to version 74.5.30 which has Log4j 2.17.0
Component Version
ubuntu-xenial stemcell~621
backup-and-restore-sdk1.18.28
binary-offline-buildpack1.0.40
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.20
bpm1.1.15
capi1.109.4
cf-autoscaling242
cf-cli (v7/v8)*1.32.0
cf-networking2.42.0
cflinuxfs30.268.0
credhub2.9.8
diego2.54.0
dotnet-core-offline-buildpack2.3.36
garden-runc1.19.30
go-offline-buildpack1.9.37
haproxy9.8.0
java-offline-buildpack4.47
log-cache2.11.4
loggregator106.6.1
loggregator-agent6.3.5
mapfs1.2.6
metric-registrar1.1.9
metrics-discovery3.0.6
mysql-monitoring9.15.0
nats40
nfs-volume5.0.12
nginx-offline-buildpack1.1.32
nodejs-offline-buildpack1.7.63
notifications62
notifications-ui40
php-offline-buildpack4.4.53
push-apps-manager-release674.0.6
push-usage-service-release674.0.23
pxc0.39.0
python-offline-buildpack1.7.47
r-offline-buildpack1.1.23
routing0.227.0
ruby-offline-buildpack1.8.48
silk2.41.0
smb-volume3.1.0
smoke-tests4.3.1
staticfile-offline-buildpack1.5.26
statsd-injector1.11.16
syslog11.7.6
system-metrics-scraper3.2.3
uaa74.5.30

* The cf-cli version corresponds to the commercial distribution on VMware Tanzu Network.

2.11.12

Release Date: 12/16/2021

Warning:

See the following warnings:

Note: This version of TAS for VMs contains a known issue that can cause application traces to break. See Gorouter Sets an Invalid X-B3-SpanID Header in Known Issues.

  • [Security Fix] Fix remote code execution vulnerability related to Log4j (CVE-2021-45046)
  • Bump credhub to version 2.9.7 which has Log4j 2.16.0
  • Bump java-offline-buildpack to version 4.45
  • Bump php-offline-buildpack to version 4.4.53
  • Bump uaa to version 74.5.29 which has Log4j 2.16.0
Component Version
ubuntu-xenial stemcell~621
backup-and-restore-sdk1.18.28
binary-offline-buildpack1.0.40
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.20
bpm1.1.15
capi1.109.4
cf-autoscaling242
cf-cli (v7/v8)*1.32.0
cf-networking2.42.0
cflinuxfs30.268.0
credhub2.9.7
diego2.54.0
dotnet-core-offline-buildpack2.3.36
garden-runc1.19.30
go-offline-buildpack1.9.37
haproxy9.8.0
java-offline-buildpack4.45
log-cache2.11.4
loggregator106.6.1
loggregator-agent6.3.5
mapfs1.2.6
metric-registrar1.1.9
metrics-discovery3.0.6
mysql-monitoring9.15.0
nats40
nfs-volume5.0.12
nginx-offline-buildpack1.1.32
nodejs-offline-buildpack1.7.63
notifications62
notifications-ui40
php-offline-buildpack4.4.53
push-apps-manager-release674.0.6
push-usage-service-release674.0.23
pxc0.39.0
python-offline-buildpack1.7.47
r-offline-buildpack1.1.23
routing0.227.0
ruby-offline-buildpack1.8.48
silk2.41.0
smb-volume3.1.0
smoke-tests4.3.1
staticfile-offline-buildpack1.5.26
statsd-injector1.11.16
syslog11.7.6
system-metrics-scraper3.2.3
uaa74.5.29

* The cf-cli version corresponds to the commercial distribution on VMware Tanzu Network.

2.11.11

Release Date: 12/15/2021

Warning:

See the following warnings:

Note: This version of TAS for VMs contains a known issue that can cause application traces to break. See Gorouter Sets an Invalid X-B3-SpanID Header in Known Issues.

  • [Security Fix] Java and PHP Buildpacks - Fix remote code execution vulnerability related to Log4j (CVE-2021-44228)
  • [Bug Fix] Fix “pre-start scripts failed. Failed Jobs: policy-server” error Upgrading to CF Networking Release 2.40.0
  • [Bug Fix] Enable audit logging file rotation to reduce I/O load during log rotation
  • [Bug Fix] Smoke Tests uses specified domain for Isolation Segments
  • Bump backup-and-restore-sdk to version 1.18.28
  • Bump cf-networking to version 2.42.0
  • Bump cflinuxfs3 to version 0.268.0
  • Bump java-offline-buildpack to version 4.44
  • Bump loggregator-agent to version 6.3.5
  • Bump php-offline-buildpack to version 4.4.52
  • Bump routing to version 0.227.0
  • Bump silk to version 2.41.0
  • Bump smoke-tests to version 4.3.1
  • Bump syslog to version 11.7.6
Component Version
ubuntu-xenial stemcell~621
backup-and-restore-sdk1.18.28
binary-offline-buildpack1.0.40
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.20
bpm1.1.15
capi1.109.4
cf-autoscaling242
cf-cli (v7/v8)*1.32.0
cf-networking2.42.0
cflinuxfs30.268.0
credhub2.9.6
diego2.54.0
dotnet-core-offline-buildpack2.3.36
garden-runc1.19.30
go-offline-buildpack1.9.37
haproxy9.8.0
java-offline-buildpack4.44
log-cache2.11.4
loggregator106.6.1
loggregator-agent6.3.5
mapfs1.2.6
metric-registrar1.1.9
metrics-discovery3.0.6
mysql-monitoring9.15.0
nats40
nfs-volume5.0.12
nginx-offline-buildpack1.1.32
nodejs-offline-buildpack1.7.63
notifications62
notifications-ui40
php-offline-buildpack4.4.52
push-apps-manager-release674.0.6
push-usage-service-release674.0.23
pxc0.39.0
python-offline-buildpack1.7.47
r-offline-buildpack1.1.23
routing0.227.0
ruby-offline-buildpack1.8.48
silk2.41.0
smb-volume3.1.0
smoke-tests4.3.1
staticfile-offline-buildpack1.5.26
statsd-injector1.11.16
syslog11.7.6
system-metrics-scraper3.2.3
uaa74.5.28

* The cf-cli version corresponds to the commercial distribution on VMware Tanzu Network.

2.11.10

Release Date: 12/13/2021

Warning:

See the following warnings:

Note: This version of TAS for VMs contains a known issue that can cause application traces to break. See Gorouter Sets an Invalid X-B3-SpanID Header in Known Issues.

  • [Security Fix] UAA and CredHub - Fix remote code execution vulnerability related to Log4j (CVE-2021-44228)
  • [Bug Fix] Diego - Envoy v1.19 uses the original TCP connection pool so that it can accept more than 1024 downstream connections
  • [Breaking Change] Gorouter - zipkin trace-id size complies with w3 standard of 16 bytes instead of the previous 8 bytes
  • Bump credhub to version 2.9.6 which has Log4j 2.15.0
  • Bump diego to version 2.54.0
  • Bump routing to version 0.227.0
  • Bump uaa to version 74.5.28 which has Log4j 2.15.0
Component Version
ubuntu-xenial stemcell621.176
backup-and-restore-sdk1.18.26
binary-offline-buildpack1.0.40
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.20
bpm1.1.15
capi1.109.4
cf-autoscaling242
cf-cli (v7/v8)*1.32.0
cf-networking2.40.0
cflinuxfs30.264.0
credhub2.9.6
diego2.54.0
dotnet-core-offline-buildpack2.3.36
garden-runc1.19.30
go-offline-buildpack1.9.37
haproxy9.8.0
java-offline-buildpack4.42
log-cache2.11.4
loggregator106.6.1
loggregator-agent6.3.4
mapfs1.2.6
metric-registrar1.1.9
metrics-discovery3.0.6
mysql-monitoring9.15.0
nats40
nfs-volume5.0.12
nginx-offline-buildpack1.1.32
nodejs-offline-buildpack1.7.63
notifications62
notifications-ui40
php-offline-buildpack4.4.48
push-apps-manager-release674.0.6
push-usage-service-release674.0.23
pxc0.39.0
python-offline-buildpack1.7.47
r-offline-buildpack1.1.23
routing0.227.0
ruby-offline-buildpack1.8.48
silk2.40.0
smb-volume3.1.0
smoke-tests4.3.0
staticfile-offline-buildpack1.5.26
statsd-injector1.11.16
syslog11.7.5
system-metrics-scraper3.2.3
uaa74.5.28

* The cf-cli version corresponds to the commercial distribution on VMware Tanzu Network.

2.11.9

Release Date: 11/23/2021

  • [Bug Fix] Fix log cache nozzle metrics
  • [Breaking Change] All Gorouter certificates require a SubjectAltName extension. If any Gorouter certificates lack a SubjectAltName, deployment fails. If you need to complete a deployment before configuring new Gorouter certificates, select Enable temporary workaround for certs without SANs in the Networking pane of the TAS for VMs tile. For more information about updating certificates, see Routing and Golang 1.15 X.509 CommonName deprecation in the Knowledge Base.
  • [Bug Fix] Cloud Controller - Ensure app lifecycle_type is not nil when determining app lifecycle
  • Bump backup-and-restore-sdk to version 1.18.26
  • Bump bpm to version 1.1.15
  • Bump cf-autoscaling to version 242
  • Bump cf-networking to version 2.40.0
  • Bump cflinuxfs3 to version 0.264.0
  • Bump dotnet-core-offline-buildpack to version 2.3.36
  • Bump go-offline-buildpack to version 1.9.37
  • Bump loggregator to version 106.6.1
  • Bump nodejs-offline-buildpack to version 1.7.63
  • Bump php-offline-buildpack to version 4.4.48
  • Bump push-usage-service-release to version 674.0.23
  • Bump python-offline-buildpack to version 1.7.47
  • Bump r-offline-buildpack to version 1.1.23
  • Bump routing to version 0.226.0
  • Bump ruby-offline-buildpack to version 1.8.48
  • Bump silk to version 2.40.0
  • Bump staticfile-offline-buildpack to version 1.5.26
Component Version
ubuntu-xenial stemcell621.0
backup-and-restore-sdk1.18.26
binary-offline-buildpack1.0.40
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.20
bpm1.1.15
capi1.109.4
cf-autoscaling242
cf-cli (v7/v8)*1.32.0
cf-networking2.40.0
cflinuxfs30.264.0
credhub2.9.4
diego2.53.0
dotnet-core-offline-buildpack2.3.36
garden-runc1.19.30
go-offline-buildpack1.9.37
haproxy9.8.0
java-offline-buildpack4.42
log-cache2.11.4
loggregator-agent6.3.4
loggregator106.6.1
mapfs1.2.6
metric-registrar1.1.9
metrics-discovery3.0.6
mysql-monitoring9.15.0
nats40
nfs-volume5.0.12
nginx-offline-buildpack1.1.32
nodejs-offline-buildpack1.7.63
notifications-ui40
notifications62
php-offline-buildpack4.4.48
push-apps-manager-release674.0.6
push-usage-service-release674.0.23
pxc0.39.0
python-offline-buildpack1.7.47
r-offline-buildpack1.1.23
routing0.226.0
ruby-offline-buildpack1.8.48
silk2.40.0
smb-volume3.1.0
smoke-tests4.3.0
staticfile-offline-buildpack1.5.26
statsd-injector1.11.16
syslog11.7.5
system-metrics-scraper3.2.3
uaa74.5.26

* The cf-cli version corresponds to the commercial distribution on VMware Tanzu Network.

2.11.8

Release Date: 10/19/2021

  • [Security Fix] CAPI - Address service broker SSRF CVE-2021-22099
  • [Security Fix] CAPI - Cap label selectors at 50 in queries and improve label selector performance to mitigate DOS vulnerability CVE-2021-22101
  • [Feature Improvement] Set default for System metrics scrape interval to 15s
  • [Bug Fix] Fix certificate rotation by fixing CredHub’s import of concatenated certificates
  • [Bug Fix] Fix “System metrics scrape interval” configuration in manifest
  • Bump backup-and-restore-sdk to version 1.18.21
  • Bump bpm to version 1.1.14
  • Bump capi to version 1.109.4
  • Bump cf-networking to version 2.39.0
  • Bump cflinuxfs3 to version 0.262.0
  • Bump credhub to version 2.9.4
  • Bump log-cache to version 2.11.4
  • Bump nginx-offline-buildpack to version 1.1.32
  • Bump nodejs-offline-buildpack to version 1.7.62
  • Bump php-offline-buildpack to version 4.4.46
  • Bump push-usage-service-release to version 674.0.22
  • Bump pxc to version 0.39.0
  • Bump python-offline-buildpack to version 1.7.46
  • Bump silk to version 2.39.0
Component Version
ubuntu-xenial stemcell621.0
backup-and-restore-sdk1.18.21
binary-offline-buildpack1.0.40
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.20
bpm1.1.14
capi1.109.4
cf-autoscaling239
cf-cli (v7/v8)*1.32.0
cf-networking2.39.0
cflinuxfs30.262.0
credhub2.9.4
diego2.53.0
dotnet-core-offline-buildpack2.3.34
garden-runc1.19.30
go-offline-buildpack1.9.34
haproxy9.8.0
java-offline-buildpack4.42
log-cache2.11.4
loggregator-agent6.3.4
loggregator106.6.0
mapfs1.2.6
metric-registrar1.1.9
metrics-discovery3.0.6
mysql-monitoring9.15.0
nats40
nfs-volume5.0.12
nginx-offline-buildpack1.1.32
nodejs-offline-buildpack1.7.62
notifications-ui40
notifications62
php-offline-buildpack4.4.46
push-apps-manager-release674.0.6
push-usage-service-release674.0.22
pxc0.39.0
python-offline-buildpack1.7.46
r-offline-buildpack1.1.21
routing0.224.0
ruby-offline-buildpack1.8.46
silk2.39.0
smb-volume3.1.0
smoke-tests4.3.0
staticfile-offline-buildpack1.5.24
statsd-injector1.11.16
syslog11.7.5
system-metrics-scraper3.2.3
uaa74.5.26

* The cf-cli version corresponds to the commercial distribution on VMware Tanzu Network.

2.11.7

Release Date: 09/30/2021

  • [Security Fix] Fixes an issue where BBS socket connections could be kept alive unnecessarily
  • [Feature Improvement] Disable Diego container proxy ALPN
  • Bump backup-and-restore-sdk to version 1.18.19
  • Bump binary-offline-buildpack to version 1.0.40
  • Bump cflinuxfs3 to version 0.259.0
  • Bump diego to version 2.53.0
  • Bump dotnet-core-offline-buildpack to version 2.3.34
  • Bump java-offline-buildpack to version 4.42
  • Bump nginx-offline-buildpack to version 1.1.31
  • Bump nodejs-offline-buildpack to version 1.7.61
  • Bump php-offline-buildpack to version 4.4.45
  • Bump python-offline-buildpack to version 1.7.45
  • Bump r-offline-buildpack to version 1.1.21
  • Bump ruby-offline-buildpack to version 1.8.46
  • Bump uaa to version 74.5.26
Component Version
ubuntu-xenial stemcell621.0
backup-and-restore-sdk1.18.19
binary-offline-buildpack1.0.40
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.20
bpm1.1.13
capi1.109.1
cf-autoscaling239
cf-cli (v7/v8)*1.32.0
cf-networking2.38.0
cflinuxfs30.259.0
credhub2.9.1
diego2.53.0
dotnet-core-offline-buildpack2.3.34
garden-runc1.19.30
go-offline-buildpack1.9.34
haproxy9.8.0
java-offline-buildpack4.42
log-cache2.11.2
loggregator-agent6.3.4
loggregator106.6.0
mapfs1.2.6
metric-registrar1.1.9
metrics-discovery3.0.6
mysql-monitoring9.15.0
nats40
nfs-volume5.0.12
nginx-offline-buildpack1.1.31
nodejs-offline-buildpack1.7.61
notifications-ui40
notifications62
php-offline-buildpack4.4.45
push-apps-manager-release674.0.6
push-usage-service-release674.0.20
pxc0.37.0
python-offline-buildpack1.7.45
r-offline-buildpack1.1.21
routing0.224.0
ruby-offline-buildpack1.8.46
silk2.38.0
smb-volume3.1.0
smoke-tests4.3.0
staticfile-offline-buildpack1.5.24
statsd-injector1.11.16
syslog11.7.5
system-metrics-scraper3.2.3
uaa74.5.26

* The cf-cli version corresponds to the commercial distribution on VMware Tanzu Network.

2.11.6

Release Date: 09/16/2021

  • [Security Fix] Usage Service - Bump rails dependency to address CVE-2021-22942
  • [Bug Fix] garden-runc - Fix handling reserved space on ext4 and generating bundle mounts when SMB volumes are present
  • Bump backup-and-restore-sdk to version 1.18.18
  • Bump cf-autoscaling to version 239
  • Bump cflinuxfs3 to version 0.256.0
  • Bump garden-runc to version 1.19.30
  • Bump log-cache to version 2.11.2
  • Bump push-usage-service-release to version 674.0.20
  • Bump routing to version 0.224.0
  • Bump uaa to version 74.5.25
Component Version
ubuntu-xenial stemcell621.0
backup-and-restore-sdk1.18.18
binary-offline-buildpack1.0.39
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.20
bpm1.1.13
capi1.109.1
cf-autoscaling239
cf-cli (v7/v8)*1.32.0
cf-networking2.38.0
cflinuxfs30.256.0
credhub2.9.1
diego2.50.0
dotnet-core-offline-buildpack2.3.32
garden-runc1.19.30
go-offline-buildpack1.9.34
haproxy9.8.0
java-offline-buildpack4.40
log-cache2.11.2
loggregator-agent6.3.4
loggregator106.6.0
mapfs1.2.6
metric-registrar1.1.9
metrics-discovery3.0.6
mysql-monitoring9.15.0
nats40
nfs-volume5.0.12
nginx-offline-buildpack1.1.30
nodejs-offline-buildpack1.7.57
notifications-ui40
notifications62
php-offline-buildpack4.4.44
push-apps-manager-release674.0.6
push-usage-service-release674.0.20
pxc0.37.0
python-offline-buildpack1.7.43
r-offline-buildpack1.1.20
routing0.224.0
ruby-offline-buildpack1.8.42
silk2.38.0
smb-volume3.1.0
smoke-tests4.3.0
staticfile-offline-buildpack1.5.24
statsd-injector1.11.16
syslog11.7.5
system-metrics-scraper3.2.3
uaa74.5.25

* The cf-cli version corresponds to the commercial distribution on VMware Tanzu Network.

2.11.5

Release Date: 09/09/2021

  • [Security Fix] Gorouter built with Go 1.16.7 to address CVE-2021-36221
  • [Bug Fix] CAPI - Some metrics for CAPI were not being properly emitted
  • [Bug Fix] Usage Service - Address performance of /system_report/task_usages endpoint on large foundations
  • Bump backup-and-restore-sdk to version 1.18.15
  • Bump bpm to version 1.1.13
  • Bump cflinuxfs3 to version 0.252.0
  • Bump credhub to version 2.9.1
  • Bump go-offline-buildpack to version 1.9.34
  • Bump java-offline-buildpack to version 4.40
  • Bump log-cache to version 2.11.1
  • Bump loggregator-agent to version 6.3.4
  • Bump push-usage-service-release to version 674.0.18
  • Bump pxc to version 0.37.0
  • Bump routing to version 0.221.0
Component Version
ubuntu-xenial stemcell621.0
backup-and-restore-sdk1.18.15
binary-offline-buildpack1.0.39
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.20
bpm1.1.13
capi1.109.1
cf-autoscaling238
cf-cli (v7/v8)*1.32.0
cf-networking2.38.0
cflinuxfs30.252.0
credhub2.9.1
diego2.50.0
dotnet-core-offline-buildpack2.3.32
garden-runc1.19.29
go-offline-buildpack1.9.34
haproxy9.8.0
java-offline-buildpack4.40
log-cache2.11.1
loggregator-agent6.3.4
loggregator106.6.0
mapfs1.2.6
metric-registrar1.1.9
metrics-discovery3.0.6
mysql-monitoring9.15.0
nats40
nfs-volume5.0.12
nginx-offline-buildpack1.1.30
nodejs-offline-buildpack1.7.57
notifications-ui40
notifications62
php-offline-buildpack4.4.44
push-apps-manager-release674.0.6
push-usage-service-release674.0.18
pxc0.37.0
python-offline-buildpack1.7.43
r-offline-buildpack1.1.20
routing0.221.0
ruby-offline-buildpack1.8.42
silk2.38.0
smb-volume3.1.0
smoke-tests4.3.0
staticfile-offline-buildpack1.5.24
statsd-injector1.11.16
syslog11.7.5
system-metrics-scraper3.2.3
uaa74.5.24

* The cf-cli version corresponds to the commercial distribution on VMware Tanzu Network.

2.11.4

Release Date: 07/20/2021

  • [Bug Fix] Ensure Cloud Controller organization and space quota validations include limit for tasks run against an app that has been exceeded
  • [Bug Fix] Garden recovers after a machine restarts
  • Bump capi to version 1.109.1
  • Bump dotnet-core-offline-buildpack to version 2.3.32
  • Bump garden-runc to version 1.19.29
  • Bump nginx-offline-buildpack to version 1.1.30
  • Bump nodejs-offline-buildpack to version 1.7.57
  • Bump php-offline-buildpack to version 4.4.44
  • Bump python-offline-buildpack to version 1.7.43
  • Bump r-offline-buildpack to version 1.1.20
  • Bump staticfile-offline-buildpack to version 1.5.24
Component Version
ubuntu-xenial stemcell621.0
backup-and-restore-sdk1.18.2
binary-offline-buildpack1.0.39
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.20
bpm1.1.12
capi1.109.1
cf-autoscaling238
cf-cli (v7/v8)*1.32.0
cf-networking2.38.0
cflinuxfs30.249.0
credhub2.9.0
diego2.50.0
dotnet-core-offline-buildpack2.3.32
garden-runc1.19.29
go-offline-buildpack1.9.33
haproxy9.8.0
java-offline-buildpack4.39
log-cache2.11.0
loggregator-agent6.3.3
loggregator106.6.0
mapfs1.2.6
metric-registrar1.1.9
metrics-discovery3.0.6
mysql-monitoring9.15.0
nats40
nfs-volume5.0.12
nginx-offline-buildpack1.1.30
nodejs-offline-buildpack1.7.57
notifications-ui40
notifications62
php-offline-buildpack4.4.44
push-apps-manager-release674.0.6
push-usage-service-release674.0.13
pxc0.36.0
python-offline-buildpack1.7.43
r-offline-buildpack1.1.20
routing0.216.0
ruby-offline-buildpack1.8.42
silk2.38.0
smb-volume3.1.0
smoke-tests4.3.0
staticfile-offline-buildpack1.5.24
statsd-injector1.11.16
syslog11.7.5
system-metrics-scraper3.2.3
uaa74.5.24

* The cf-cli version corresponds to the commercial distribution on VMware Tanzu Network.

2.11.3

Release Date: 07/15/2021

  • [Security Fix] Fixed context path 404 vulnerability
  • [Security Fix] UAA - Bump dependencies and address CVEs
  • [Bug Fix] Prevent TCP routes from using system component ports. For more information, see TCP Routes Stop Working in the Knowledge Base. If you try to create or update a router group to include system component ports, the Routing API returns an error. Current invalid router groups that include system component ports are not changed, but a warning is logged. In TAS for VMs v2.12.0, invalid router groups cause a deploy failure. For more information, see Check and fix invalid router groups before TAS 2.12 in the Knowledge Base.
  • [Bug Fix] Fix metric-registrar crashing when non-url formatted drains exist
  • [Bug Fix] Add an option to remove extra metadata from syslog drains
  • [Breaking Change] Gorouter sends all responses with transfer-encoded chunks. Some responses that were not chunked in previous versions now use transfer-encoded chunks. For more information, see Clients receive responses with no Content-Length header and a chunked encoded body after upgrading Tanzu Application Service for VMs in the Knowledge Base. (edited 20 Oct 2021)
  • Bump binary-offline-buildpack to version 1.0.39
  • Bump cf-networking to version 2.38.0
  • Bump cflinuxfs3 to version 0.249.0
  • Bump dotnet-core-offline-buildpack to version 2.3.31
  • Bump garden-runc to version 1.19.28
  • Bump go-offline-buildpack to version 1.9.33
  • Bump metric-registrar to version 1.1.9
  • Bump metrics-discovery to version 3.0.6
  • Bump nginx-offline-buildpack to version 1.1.29
  • Bump nodejs-offline-buildpack to version 1.7.56
  • Bump php-offline-buildpack to version 4.4.43
  • Bump push-apps-manager-release to version 674.0.6
  • Bump pxc to version 0.36.0
  • Bump python-offline-buildpack to version 1.7.42
  • Bump r-offline-buildpack to version 1.1.19
  • Bump routing to version 0.216.0
  • Bump ruby-offline-buildpack to version 1.8.42
  • Bump silk to version 2.38.0
  • Bump staticfile-offline-buildpack to version 1.5.23
  • Bump syslog to version 11.7.5
  • Bump system-metrics-scraper to version 3.2.3
  • Bump uaa to version 74.5.24
Component Version
ubuntu-xenial stemcell621.0
backup-and-restore-sdk1.18.2
binary-offline-buildpack1.0.39
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.20
bpm1.1.12
capi1.109.0
cf-autoscaling238
cf-cli (v7/v8)*1.32.0
cf-networking2.38.0
cflinuxfs30.249.0
credhub2.9.0
diego2.50.0
dotnet-core-offline-buildpack2.3.31
garden-runc1.19.28
go-offline-buildpack1.9.33
haproxy9.8.0
java-offline-buildpack4.39
log-cache2.11.0
loggregator-agent6.3.3
loggregator106.6.0
mapfs1.2.6
metric-registrar1.1.9
metrics-discovery3.0.6
mysql-monitoring9.15.0
nats40
nfs-volume5.0.12
nginx-offline-buildpack1.1.29
nodejs-offline-buildpack1.7.56
notifications-ui40
notifications62
php-offline-buildpack4.4.43
push-apps-manager-release674.0.6
push-usage-service-release674.0.13
pxc0.36.0
python-offline-buildpack1.7.42
r-offline-buildpack1.1.19
routing0.216.0
ruby-offline-buildpack1.8.42
silk2.38.0
smb-volume3.1.0
smoke-tests4.3.0
staticfile-offline-buildpack1.5.23
statsd-injector1.11.16
syslog11.7.5
system-metrics-scraper3.2.3
uaa74.5.24

* The cf-cli version corresponds to the commercial distribution on VMware Tanzu Network.

2.11.2

Release Date: 06/22/2021

  • [Security Fix] Bump some dependencies to resolve security vulnerabilities
  • Bump bpm to version 1.1.12
  • Bump cf-autoscaling to version 238
  • Bump cf-networking to version 2.37.0
  • Bump cflinuxfs3 to version 0.239.0
  • Bump java-offline-buildpack to version 4.39
  • Bump loggregator-agent to version 6.3.3
  • Bump metric-registrar to version 1.1.6
  • Bump metrics-discovery to version 3.0.5
  • Bump nats to version 40
  • Bump nodejs-offline-buildpack to version 1.7.52
  • Bump php-offline-buildpack to version 4.4.40
  • Bump push-apps-manager-release to version 674.0.5
  • Bump silk to version 2.37.0
  • Bump statsd-injector to version 1.11.16
Component Version
ubuntu-xenial stemcell621.0
backup-and-restore-sdk1.18.2
binary-offline-buildpack1.0.38
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.20
bpm1.1.12
capi1.109.0
cf-autoscaling238
cf-cli (v7/v8)*1.32.0
cf-networking2.37.0
cflinuxfs30.239.0
credhub2.9.0
diego2.50.0
dotnet-core-offline-buildpack2.3.28
garden-runc1.19.25
go-offline-buildpack1.9.31
haproxy9.8.0
java-offline-buildpack4.39
log-cache2.11.0
loggregator-agent6.3.3
loggregator106.6.0
mapfs1.2.6
metric-registrar1.1.6
metrics-discovery3.0.5
mysql-monitoring9.15.0
nats40
nfs-volume5.0.12
nginx-offline-buildpack1.1.26
nodejs-offline-buildpack1.7.52
notifications-ui40
notifications62
php-offline-buildpack4.4.40
push-apps-manager-release674.0.5
push-usage-service-release674.0.13
pxc0.35.0
python-offline-buildpack1.7.39
r-offline-buildpack1.1.17
routing0.213.0
ruby-offline-buildpack1.8.39
silk2.37.0
smb-volume3.1.0
smoke-tests4.3.0
staticfile-offline-buildpack1.5.21
statsd-injector1.11.16
syslog11.7.0
system-metrics-scraper3.2.2
uaa74.5.22

* The cf-cli version corresponds to the commercial distribution on VMware Tanzu Network.

2.11.1

Release Date: 05/27/2021

  • [Security Fix] Usage Service - Upgrade Rails gem to address CVE-2021-22880
  • [Feature Improvement] Patch versions can be upgraded without a stemcell upgrade. See Looser Stemcell Version Requirements when Upgrading TAS for VMs v2.11.1 and Later.
  • [Feature Improvement] MySQL binlogs volume is capped at 33% of available disk storage
  • [Feature Improvement] Improve metric-registrar to handle unreachable CC more gracefully, delete smoke-test app in the case of failure, and integrate CUPS caching
  • [Feature Improvement] Adds support for SNI routes
  • [Feature Improvement] Adds per request metrics reporting, which makes metric frequency proportional to request frequency
  • [Bug Fix] Smoke Test allows the operator to provide the apps_domain property when deploying TAS and also properly configures user provided space when deploying an isolation segment
  • [Bug Fix] Fix race condition and prevent network policy MySQL database from being able to get into an invalid state.
  • Bump binary-offline-buildpack to version 1.0.38
  • Bump bpm to version 1.1.11
  • Bump cf-autoscaling to version 237
  • Bump cf-networking to version 2.36.0
  • Bump cflinuxfs3 to version 0.238.0
  • Bump diego to version 2.50.0
  • Bump dotnet-core-offline-buildpack to version 2.3.28
  • Bump garden-runc to version 1.19.25
  • Bump go-offline-buildpack to version 1.9.31
  • Bump log-cache to version 2.11.0
  • Bump loggregator to version 106.6.0
  • Bump nginx-offline-buildpack to version 1.1.26
  • Bump nodejs-offline-buildpack to version 1.7.51
  • Bump notifications to version 62
  • Bump php-offline-buildpack to version 4.4.39
  • Bump push-usage-service-release to version 674.0.13
  • Bump pxc to version 0.35.0
  • Bump python-offline-buildpack to version 1.7.39
  • Bump r-offline-buildpack to version 1.1.17
  • Bump routing to version 0.213.0
  • Bump ruby-offline-buildpack to version 1.8.39
  • Bump silk to version 2.36.0
  • Bump smoke-tests to version 4.3.0
  • Bump staticfile-offline-buildpack to version 1.5.21
Component Version
ubuntu-xenial stemcell621.0
backup-and-restore-sdk1.18.2
binary-offline-buildpack1.0.38
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.20
bpm1.1.11
capi1.109.0
cf-autoscaling237
cf-cli (v7/v8)*1.32.0
cf-networking2.36.0
cflinuxfs30.238.0
credhub2.9.0
diego2.50.0
dotnet-core-offline-buildpack2.3.28
garden-runc1.19.25
go-offline-buildpack1.9.31
haproxy9.8.0
java-offline-buildpack4.36
log-cache2.11.0
loggregator-agent6.2.0
loggregator106.6.0
mapfs1.2.6
metric-registrar1.1.1
metrics-discovery3.0.3
mysql-monitoring9.15.0
nats39
nfs-volume5.0.12
nginx-offline-buildpack1.1.26
nodejs-offline-buildpack1.7.51
notifications-ui40
notifications62
php-offline-buildpack4.4.39
push-apps-manager-release674.0.2
push-usage-service-release674.0.13
pxc0.35.0
python-offline-buildpack1.7.39
r-offline-buildpack1.1.17
routing0.213.0
ruby-offline-buildpack1.8.39
silk2.36.0
smb-volume3.1.0
smoke-tests4.3.0
staticfile-offline-buildpack1.5.21
statsd-injector1.11.15
syslog11.7.0
system-metrics-scraper3.2.2
uaa74.5.22

* The cf-cli version corresponds to the commercial distribution on VMware Tanzu Network.

2.11.0

Release Date: March 30, 2021

Component Version
ubuntu-xenial stemcell621.117
backup-and-restore-sdk1.18.2
binary-offline-buildpack1.0.36
bosh-dns-aliases0.0.3
bosh-system-metrics-forwarder0.0.20
bpm1.1.7
capi1.109.0
cf-autoscaling235
cf-cli (v7/v8)*1.32.0
cf-networking2.35.0
cflinuxfs30.231.0
credhub2.9.0
diego2.49.0
dotnet-core-offline-buildpack2.3.24
garden-runc1.19.18
go-offline-buildpack1.9.26
haproxy9.8.0
java-offline-buildpack4.36
log-cache2.10.0
loggregator-agent6.2.0
loggregator106.4.0
mapfs1.2.6
metric-registrar1.1.1
metrics-discovery3.0.3
mysql-monitoring9.15.0
nats39
nfs-volume5.0.12
nginx-offline-buildpack1.1.20
nodejs-offline-buildpack1.7.42
notifications-ui40
notifications61
php-offline-buildpack4.4.31
push-apps-manager-release674.0.2
push-usage-service-release674.0.11
pxc0.32.0
python-offline-buildpack1.7.30
r-offline-buildpack1.1.12
routing0.211.0
ruby-offline-buildpack1.8.31
silk2.35.0
smb-volume3.1.0
smoke-tests4.2.0
staticfile-offline-buildpack1.5.15
statsd-injector1.11.15
syslog11.7.0
system-metrics-scraper3.2.2
uaa74.5.22

* The cf-cli version corresponds to the commercial distribution on VMware Tanzu Network.

How to Upgrade

To upgrade to TAS for VMs v2.11, see Configuring TAS for VMs for Upgrades.

When upgrading to TAS for VMs v2.11, be aware of the following upgrade considerations:

  • TAS for VMs v2.11 is compatible with Ops Manager v2.10. If you are using a previous version of Ops Manager, you must upgrade to Ops Manager v2.10 before you upgrade to TAS for VMs v2.11.

  • Upgrade the cf CLI to either the latest cf CLI v7 release or the commercial cf CLI distribution available on VMware Tanzu Network.

  • If you are upgrading from Pivotal Application Service (PAS) v2.7 or TAS for VMs v2.8 and later, you can upgrade directly to TAS for VMs v2.11. TAS for VMs v2.11 is an LTS version of TAS for VMs. See Long-Term Support for TAS for VMs v2.11 below for more information.

  • To minimize downtime for developers pushing apps, upgrade from PAS v2.7.41 or later, or TAS for VMs v2.10.21 or later. Upgrading from earlier patch versions can result in an Unknown Error when pushing apps.

  • If you are upgrading from PAS v2.6 or earlier, you must upgrade to PAS v2.7 before you upgrade to TAS for VMs v2.11.

  • Some partner service tiles may be incompatible with TAS for VMs v2.11. VMware is working with partners to ensure their tiles are updated to work with the latest versions of TAS for VMs.

    For information about which partner service releases are currently compatible with TAS for VMs v2.11, review the appropriate partners services release documentation at https://docs.pivotal.io or contact the partner organization that produces the tile.

  • If upgrading from PAS 2.7.x, NSX-T app-firewall rules may need to be adjusted. App containers now use port 61002 for inbound App SSH (previously this was over port 2222).

New Features in TAS for VMs v2.11

TAS for VMs v2.11 includes the following major features:

Long-Term Support for TAS for VMs v2.11

TAS for VMs v2.11 is a long-term supported (LTS) version of TAS for VMs. TAS for VMs v2.11 will be supported through April 2024.

Over the lifecycle of TAS for VMs v2.11, VMware will release security patches that occasionally include feature enhancements and maintenance updates. VMware will also continue to release new versions of TAS for VMs.

You can jump upgrade directly from previous versions of TAS for VMs to the LTS version of TAS for VMs. For more information, see Jump Upgrading to TAS for VMs v2.11.

Deployment on VMware Cloud Foundation

TAS for VMs v2.11 can be deployed on VMware Cloud Foundation (VCF) v4.1. For instructions and more information, see Deploying TAS for VMs to VCF.

Deployment on VMware Cloud on Amazon Web Services

TAS for VMs v2.11 can be deployed to VMware Cloud (VMC) on Amazon Web Services (AWS). For instructions and more information, see Deploying TAS for VMs to VMC.

Optionally Use Human-Readable Timestamps for Component Logs

TAS for VMs v2.11 introduces RFC3339 log format support for several TAS for VMs components. You can configure these components to produce logs with human-readable RFC3339 timestamps with the Timestamp format for component logs configuration option in the TAS for VMs tile. Logs that use human-readable timestamps are often easier to debug.

RFC3339-formatted timestamps follow the RFC3339 spec, include nine points of precision where possible, and are in UTC. For example:

  • 2019-11-21T22:16:18.750673404Z
  • 2019-11-21T22:16:18.750000000Z

For more information about configuring the Timestamp format for component logs field, see System Logging in Configuring TAS for VMs.

In TAS for VMs v2.11.0, if you select the Converge to human-readable RFC3339 format option under Timestamp format for component logs, then the following components and related jobs use RFC3339 timestamps:

Component Jobs
Logging log-cache-nozzle, loggregator_agent, loggr-forwarder-agent, loggr-syslog-agent, prom_scraper, doppler, loggregator_trafficcontroller, reverse_log_proxy, reverse_log_proxy_gateway, log-cache-cf-auth-proxy, log-cache-gateway, log-cache-syslog-server, log-cache, loggr-syslog-binding-cache, loggr-upd-forwarder, syslog_forwarder
CAPI cc_deployment_updater, cc_uploader, cloud_controller_clock, cloud_controller_ng, cloud_controller_worker, rotate_cc_database_key, tps
UAA uaa

This new feature is related to a breaking change. For more information, see Timestamps for Component Logs in Diego Logs when Upgrading below.

Cloud Foundry V3 APIs Availability

TAS for VMs v2.11 supports Cloud Foundry V3 APIs. This feature improves response time when working with services. Use the Cloud Foundry V3 API endpoints when listing, creating, or modifying any service that works with TAS for VMs v2.11 and later.

Stemcell Version Requirements Less Strict when Upgrading TAS for VMs v2.11.1 and Later

TAS for VMs v2.11.1 and later have fewer minor version restrictions for stemcells. This allows you to upgrade to a newer TAS for VMs patch without upgrading the stemcell.

When you stage TAS for VMs for deployment, Ops Manager installs TAS for VMs using the latest stemcell by default.

In TAS for VMs v2.11.0 and earlier, if the latest stemcell was different from the stemcell that was used when installing TAS for VMs previously, then Ops Manager re-created all of the VMs in your TAS for VMs installation during the upgrade.

In TAS for VMs v2.11.1 and later, you can upgrade to later patches of TAS for VMs without upgrading the stemcell or re-creating all VMs.

Resolved Issues

TAS for VMs v2.11 includes the following resolved issues:

CredHub Primary Encryption Key Verification

When you configure the CredHub server for TAS for VMs, you must select a primary encryption key. In TAS for VMs v2.11, if you do not select a primary encryption key, or if you mark more than one key as the primary encryption key, deployment fails more quickly than in previous releases of TAS for VMs.

For more information, see Configure CredHub in Configuring TAS for VMs.

Apps Manager Uses the CAPI V2 Endpoint

For greater stability, Apps Manager uses the Cloud Controller API (CAPI) V2 endpoint instead of the experimental V3 endpoint.

Improved Handling for Disabled Service Plans in Apps Manager

In TAS for VMs, disabled service plans are handled gracefully in the Apps Manager UI.

Improved App Autoscaler Handling of RabbitMQ-Based Autoscaling Rules

In TAS for VMs v2.11, App Autoscaler uses fewer resource-intensive RabbitMQ endpoints when available to reduce load on RabbitMQ.

Breaking Changes

TAS for VMs v2.11 includes the following breaking changes:

Option Removed: Disable SSL Certificate Verification for this Environment

In TAS for VMs v2.11.0 and later, the option to disable SSL certificate verification for an environment is removed.

Before you upgrade to TAS for VMs v2.11, you must deselect the option to disable SSL certificate verification in the Networking pane of the TAS for VMs tile. For more information, see Configure Networking in Configuring TAS for VMs.

If the Disable SSL certificate verification for this environment option is enabled when you try to upgrade to TAS for VMs, the upgrade fails with the following error:

attempt to upgrade to PAS 2.11+ with Skip SSL Verification enabled, please disable
Skip SSL Verification prior to upgrade by un-checking "Disable SSL certificate
verification for this environment" under "Networking"

If you plan to automate the installation of TAS for VMs v2.11, you must remove references to the corresponding property .ha_proxy.skip_cert_verify.

Gorouter Update to Golang v1.15 Introduces Stricter Transfer-Encoding Header Standards in TAS for VMs v2.11.0 and Later

In TAS for VMs v2.11.0 and later, stricter header standards break Spring apps that incorrectly set the header.

For information about how to avoid this breaking change, see Applications on TAS for VMs get 502 chunked response error in the Knowledge Base. You must complete the resolution steps described in this Knowledge Base article before you upgrade to TAS for VMs v2.11.0 or later.

Note: This breaking change was also present in Pivotal Application Service (PAS) v2.7.30, PAS v2.8.24, TAS for VMs v2.9.18, and TAS for VMs v2.10.10. If you are on any of these versions or earlier, you must upgrade to v2.7.31, v2.8.25, v2.9.21, or v2.10.11 before upgrading or jump upgrading to 2.11.0 or later. For more information, see Applications on TAS for VMs get 502 chunked response error.

Timestamps for Component Logs in Diego Logs when Upgrading

The Timestamp format for component logs feature replaces the Format of timestamps in Diego logs feature in the App Containers pane of the TAS for VMs tile. However, when you upgrade to TAS for VMs v2.11, the option that was selected under Format of timestamps in Diego logs in your previous deployment is applied to Timestamp format for component logs. For more information, see Timestamp Format for Component Logs Replaces Timestamp Format for Diego Logs.

Dynamic Egress Policies Are Removed

You cannot upgrade to TAS for VMs v2.11 if you are using Dynamic Egress policies.

To see if you have Dynamic Egress policies, see List Egress Policies in the TAS for VMs v2.10 documentation.

To delete each of your policies, see Delete an Egress Policy in the TAS for VMs v2.10 documentation.

Cloud Controller Enforces Uniqueness of Service Bindings

When you upgrade to TAS for VMs v2.11, Cloud Controller introduces a database migration that forces service bindings between service instances and apps to be unique. If duplicate service bindings exist when you upgrade, the migration fails. To work around this issue, you must delete any duplicate bindings before you upgrade.

Known Issues

TAS for VMs v2.11 includes the following known issues:

Rolling App Deployment Does Not Timeout

Rolling app deployments do not properly timeout when the startup timeout is reached. You may experience a rolling app deployment process that hangs indefinitely.

If you experience a hanging rolling app deployment, you can manually terminate the process. For more information about terminating the rolling app deployment process, see the cf CLI v7 procedure in Cancel a Deployment.

Pre-Start Scripts Fail on policy-server Job

When upgrading to TAS for VMs v2.11.9, the policy-server pre-start script runs a database migration that drops a stored procedure that is no longer needed. If your networkpolicyserver database does not have the stored procedure, you might see the following error in diego_database policy-server stdout logs:

PROCEDURE networkpolicyserver.drop_destination_index does not exist handling 66

To work around this error, add the migration to your networkpolicyserver.gorp_migrations table and skip the migration.

For more information, see “pre-start scripts failed. Failed Jobs: policy-server” error Upgrading to CF Networking Release 2.40.0 in Tanzu Application Service for VMs in the Knowledge Base.

Gorouter Sets an Invalid X-B3-SpanID Header

An issue with the Gorouter’s implementation of X-B3-SpanId and X-B3-TraceId headers can cause invalid span IDs to be set after updating the X-B3-TraceId header to the new 16-byte standard. As a result, some applications and libraries invalidate the X-B3-SpanId value, breaking traces of the application.

This issue affects versions of TAS for VMs that contain routing-release v0.227.0 and v0.228.0.