live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
guideDEVELOPER HUB

RHDH 1.9 turns community plugins into a registry-planning problem

Forty previously bundled community plugins now resolve as OCI artifacts from GHCR, so disconnected installations need an explicit allowlist or mirror plan.

RHDH 1.9 moves community plugins from the app image to OCI registry paths.
Side by side: what changed
By The News Desk· Sep 19, 2026the quick take — two AI hosts go live when you do

Red Hat Developer Hub 1.9 changed where a large part of its plugin surface lives. Community-supported plugins that were previously wrapped inside the RHDH application image are now independent OCI artifacts served from ghcr.io. Red Hat’s verified support note says the practical symptom is an install-dynamic-plugins init container that cannot start because it times out while fetching package metadata. (Red Hat Customer Portal)

What moved outside the image

The 1.9 migration table maps 40 community-plugin artifacts from local ./dynamic-plugins/dist/... paths to oci://ghcr.io/redhat-developer/rhdh-plugin-export-overlays/...:<tag> references. (Dynamic plugins reference)

The affected set spans the integration surface platform teams are likely to enable:

  • Delivery and source control: Argo CD frontend/backend; Azure DevOps frontend/backend, annotator, search and scaffolder modules; Bitbucket Cloud and Server catalog/scaffolder modules; GitHub Actions, Issues, Insights and Pull Requests; GitLab frontend/backend; Jenkins frontend/backend/scaffolder; Gerrit scaffolder.
  • Operations and security: Datadog, Dynatrace, Lighthouse frontend/backend, PagerDuty frontend/backend and Security Insights.
  • Artifact and code quality: JFrog Artifactory, Nexus Repository Manager, Quay backend and SonarQube frontend/backend plus its scaffolder module.
  • Platform services: 3scale, Jira, ServiceNow and the DotNet and utility scaffolder modules.

That is the key boundary change: the core product image no longer carries these extensions, even when dynamic-plugins.default.yaml still describes them. Red Hat’s 1.9 release notes direct air-gapped users to add the OCI images they use to their mirroring workflow. (RHDH 1.9 release notes)

Choose allowlisting or mirroring

For a restricted cluster with controlled outbound access, the smaller operational change is to permit pulls from ghcr.io and update plugin configuration from the old local path to the exact OCI reference and tag in Red Hat’s migration table. This keeps GHCR in the runtime dependency chain, so it is unsuitable where external access is prohibited. (Dynamic plugins reference)

For a partially disconnected environment, Red Hat documents mirror-plugins.sh: mirror the 1.9 plugin catalog or a selected list directly into an internal registry, then replace the plugin references in the Backstage custom resource or Helm values. The script produces rhdh-plugin-mirroring-summary.txt with source-to-mirror mappings. (Installation guide)

For a fully air-gapped site, use the documented two-stage flow: export the catalog artifacts to disk on a connected host, transfer them across the boundary, then import them into the internal registry. The same guide also supports mirroring only explicit plugin URLs or a file containing one URL per line, which avoids importing a catalog larger than the approved plugin set. (Installation guide)

The upgrade check is therefore concrete: inventory enabled community plugins, match each to the migration table, choose direct GHCR access or an internal mirror, update every package reference, and verify the init-container logs before promoting RHDH 1.9.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.