OpenStack 2026.2 “Hibiscus,” released September 30, 2026, adds Designate DNS security capabilities and expands Nova support for AMD SEV-SNP and Intel TDX confidential virtual machines. These are release-level capabilities, not features that become fully operational just by upgrading: DNS behavior depends on the implementation details available in the deployed Designate version, while confidential VMs require compatible compute hardware, host configuration, and—if remote trust is needed—a separate attestation setup.
What Hibiscus changes
Hibiscus is OpenStack’s 34th release. Its headline security changes span two different layers: Designate, the DNS service, gains security-related features; Nova, the compute service, expands support for hardware-backed confidential computing.
The release ran from April 2 to September 30, 2026, a 26-week cycle. The OpenStack Foundation reports roughly 600 contributors and 11,500 code changes during the cycle, plus approximately 1.6 million CI jobs run by OpenDev Zuul. Those activity figures describe development and testing volume, not measured security outcomes. The announcement also reports 42 OpenStack Security Advisories and 13 OpenStack Security Notes issued so far in 2026 as of September 30; they are not a measure of Hibiscus’s feature effectiveness. OpenStack’s Hibiscus announcement provides the release overview.
What the DNS security announcement does—and does not—establish
The Hibiscus summary says Designate adds or improves four areas:
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
- Stronger isolation between tenants.
- Stronger authentication.
- TLSA/DANE support, which can publish DNS records used by clients to associate TLS certificates or keys with a domain.
- Tooling to help operators prepare for post-quantum cryptography.
These are feature-area descriptions, not a Designate deployment guide. The announcement does not specify API behavior, configuration steps, interoperability details, or migration requirements for these capabilities. In particular, TLSA/DANE support does not by itself configure DNSSEC, establish a secure resolver path, or guarantee that clients validate records. Likewise, tooling to prepare for post-quantum cryptography is not evidence that DNS or OpenStack has end-to-end post-quantum protection. Operators should consult documentation for the exact Designate package and deployment before changing production DNS or claiming a security guarantee.
How Nova’s confidential-computing options differ
Nova 34.0.0, included in Hibiscus, documents support for both Intel TDX and AMD SEV-SNP. Both rely on CPU-backed memory protection, but they are distinct platform technologies. The practical choice depends on which compatible servers and firmware an operator has, the supported host software stack, capacity constraints, and how attestation will be operated. The available upstream guides do not justify treating either option as universally more secure or easier.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
| Technology | Host requirements | Instance selection and constraints | Attestation boundary |
|---|---|---|---|
| Intel TDX | TDX-capable Intel CPU; enabled host firmware; supported KVM, QEMU, and libvirt stack. See the Nova TDX guide. | Configure eligible flavors or images and required firmware settings; follow the guide’s supported configuration. | Nova provides evidence-generation plumbing but does not manage the Quote Generation Service (QGS) or verify attestation. The guide says attestation was tested but is not actively supported or guaranteed by Nova. |
| AMD SEV-SNP | SEV-SNP-capable AMD compute hosts and a suitable configured libvirt/KVM or QEMU stack. See the Nova AMD SEV guide. | Select the amd-sev-snp memory-encryption model through flavor extra specs or image metadata; observe the guide’s firmware and Q35 machine-type constraints. |
Use the deployment’s chosen attestation architecture and verify its behavior separately; Nova’s release summary alone does not establish that attestation is configured or working. |
What operators need to configure and verify
Check the host before enabling either technology
- Confirm the compute host’s CPU supports the intended technology and that platform firmware exposes and enables it.
- Verify the distribution’s packaged Nova, QEMU, libvirt, and kernel versions against its support matrix. Upstream Nova documentation describes requirements, but vendor packaging and deployment procedures can differ.
- Follow the technology-specific Nova guide for host setup, machine type, firmware, and instance properties. Do not assume an ordinary flavor or image will become confidential after the control-plane upgrade.
- Check available host capacity and scheduling behavior for eligible instances against the actual fleet; the release announcement does not quantify performance or capacity impact.
For TDX, treat remote attestation as a separate operation
A TDX instance running is not proof that a relying party can validate its platform state. Operators must install and manage the QGS on TDX hosts, and the relying party must verify the generated quote. Nova does not perform that verification. Define who owns quote generation, trust policy, verification, and response to failed or unavailable attestation before exposing a workload that depends on remote proof.
For SEV-SNP, make the model selection explicit
Nova’s guide describes selecting amd-sev-snp through flavor extra specs or image properties, with required firmware and Q35 constraints. Apply the documented values to eligible workloads and confirm the resulting guest is launched on a correctly configured compatible host. The guide is the appropriate source for exact property names and setup steps; do not extrapolate them to a different packaged version without checking its documentation.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
For Designate, verify feature behavior in the deployed version
Because the release summary does not provide implementation steps, confirm the relevant Designate release documentation and test the tenant boundaries, authentication flow, TLSA/DANE record handling, and any post-quantum preparation tools in a controlled environment. Do not infer that a supported record type automatically protects resolution or that preparation tooling enables a post-quantum cryptographic deployment.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Should an operator upgrade to Hibiscus?
Hibiscus is a non-SLURP release. The OpenStack project says operators on Gazpacho, the preceding SLURP release, may skip Hibiscus and upgrade directly to 2027.1 Indri, expected in March 2027. Confirm that path against your distribution’s packaging, supported upgrade tooling, and local maintenance policy before acting. The Hibiscus schedule records the cycle dates.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
The official release index lists Hibiscus as maintained and gives an estimated end-of-life date of April 26, 2028; the date is an estimate and can change. Check the OpenStack releases index for current status before planning maintenance.
What the release claims mean for security
OpenStack describes the Nova additions as providing “hardware-backed memory encryption, stronger workload isolation and attestation for sensitive workloads.” That is the project’s characterization of the capabilities, not an independent evaluation of a deployment’s security. Protection depends on correctly configured supported hosts, eligible workloads, and the surrounding trust and operations model. The announcement publishes no named measurement of Designate’s security efficacy or real-world confidentiality gains for Hibiscus deployments.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

