Fixed issues in Cloudera AI on premises 1.5.5 SP4
This section lists the issues that have been fixed since the last release of Cloudera AI on premises.
- DSE-56443: Cloudera AI user interface returned a
431 Request Header Fields Too Largeerror for users with multiple group memberships -
Previously, if you were a member of a large number of groups, you might have encountered a
431 Request Header Fields Too Largeerror when you accessed the Cloudera AI Registry by using the user interface (UI). This issue occurred because the authentication token grew proportionally with group memberships. When the token size exceeded the header size limit of 8 KB, Knox rejected the request.This issue is now resolved. Cloudera AI Registry now successfully processes authentication tokens for users with multiple group memberships without exceeding the 8 KB header size limit.
- DSE-59641: Missing automatic cleanup of orphaned Istio VirtualServices and Gateway routes
-
Previously, orphaned Istio VirtualServices, Gateway API routes, and uncollected Persistent Volumes (PVs) were no longer retained in user namespaces when updating application subdomains or deleting associated workloads. This issue is now resolved. The cleanup workflow now automatically identifies and removes these lingering resources from affected namespaces, resolving the resource leak issue.
- DSE-55355: Unredacted sensitive data in Cloudera AI service logs
-
Previously, Cloudera AI service pods (Web, API, Reconciler, Operator, and DB) included unredacted sensitive information, such as environment variables, tokens, passwords, SSH configs, and Kerberos keytabs in service logs and diagnostic bundles. This issue is now resolved. Service logs are now automatically masked as [REDACTED] both in transit and at rest within diagnostic bundles.
- DSE-60253: Default accelerator quota is not updated when requested value equals max_gpu_count
-
Previously, when updating the default accelerator quota for a heterogeneous GPU type, setting the quota value equal to max_gpu_count, the maximum number of that accelerator type available on any node in the cluster, could cause the API to return a success response without saving the update to the database. This issue has been resolved.
- DSE-60254: No UI error is displayed when user or team quotas exceed the Workbench resource pool quota
-
Previously, when a Workbench resource pool quota was configured for CPU, memory, or GPU resources, the UI allowed administrators to enter user or team quota values that exceeded the resource pool quota without displaying a validation error. Although the backend API correctly rejected the request and returned an error message, the validation was not surfaced in the UI. This issue has been resolved for CPU, memory, and GPU resource types.
- DSE-59835: Heterogeneous GPU custom quota is not reset correctly after reverting to default quota
-
Previously, when resetting a user’s custom heterogeneous GPU quota to the default quota, the system could fail to persist the default quota configuration. As a result, workloads launched afterward could continue using the previously configured custom quota values instead of the default quota settings. This issue has been resolved.
