---
title: Release notes for the File Integrity Operator
---

# Release notes for the File Integrity Operator {#file-integrity-operator-release-notes}

The File Integrity Operator for OpenShift Container Platform continually runs file integrity checks on RHCOS nodes.

These release notes track the development of the File Integrity Operator in the OpenShift Container Platform.

## Release notes for OpenShift File Integrity Operator 1.4.1 {#file-integrity-operator-release-notes-1-4-1_file-integrity-operator-release-notes-v0}

OpenShift File Integrity Operator 1.4.1 is now available. The `stable` update channel tracks and receives updates for the File Integrity Operator. For more information, see [Updating the File Integrity Operator](/openshift-docs-markdown/security/file_integrity_operator/file-integrity-operator-updating#file-integrity-operator-updating). The following Red Hat Security Advisory (RHSA) is available:

- [RHSA-2026:54288 - OpenShift File Integrity Operator 1.4.1 bug fix and enhancement update](https://access.redhat.com/errata/RHSA-2026:54288)

This update includes upgraded golang dependencies in the underlying base images.

### New features and enhancements {#file-integrity-operator-1-4-1-new-features-and-enhancements_file-integrity-operator-release-notes-v0}

- With this release, the File Integrity Operator can manage `NetworkPolicy` resources with `create`, `delete`, `get`, and `update` commands. The `file-integrity-operator` service account now has matching namespace-scoped permissions. ([CMP-4497](https://issues.redhat.com/browse/CMP-4497))

## Release notes for OpenShift File Integrity Operator 1.4.0 {#file-integrity-operator-release-notes-1-4-0_file-integrity-operator-release-notes-v0}

Release notes for OpenShift File Integrity Operator 1.4.0.

The following Red Hat Security Advisory (RHSA) is available for the OpenShift File Integrity Operator 1.4.0:

- [RHSA-2026:22627 OpenShift File Integrity Operator Update](https://access.redhat.com/errata/RHSA-2026:22627)

### New features and enhancements {#file-integrity-operator-1-4-0-new-features-and-enhancements_file-integrity-operator-release-notes-v0}

- With this release, you can optionally set `priorityClassName` in the `FileIntegrity` custom resource (CR) to assign a `PriorityClass` to file integrity daemon pods. On nodes under resource pressure, the scheduler can preempt lower-priority workloads to make room for those pods, helping ensure nodes continue to receive integrity checks. ([RFE-9047](https://issues.redhat.com/browse/RFE-9047))

### Bug fixes {#file-integrity-operator-1-4-0-bug-fixes_file-integrity-operator-release-notes-v0}

- Before this update, `aide-worker-fileintegrity` pods could use increasing CPU and memory during hourly Advanced Intrusion Detection Environment (AIDE) scan cycles, often approaching DaemonSet resource limits and disrupting integrity checks on affected nodes. With this release, AIDE worker pods use CPU and memory more consistently during scans. ([CMP-4006](https://issues.redhat.com/browse/CMP-4006))

This update includes upgraded dependencies in the underlying base images.

## Release notes for OpenShift File Integrity Operator 1.3.8 {#file-integrity-operator-release-notes-1-3-8_file-integrity-operator-release-notes-v0}

Release notes for OpenShift File Integrity Operator 1.3.8.

The following Red Hat Security Advisory (RHSA) is available for the OpenShift File Integrity Operator 1.3.8:

- [RHSA-2025:23542 OpenShift File Integrity Operator Update](https://access.redhat.com/errata/RHSA-2025:23542)

### Bug fixes {#file-integrity-operator-1-3-8-bug-fixes_file-integrity-operator-release-notes-v0}

- Before this update, the file-integrity-operator pods and the aide pods running the database used by a recently installed File Integrity Operator (FIO) would go into a terminating state, adding error log entries that were not useful. With this release, the pods needed by FIO do not go into terminating state unless a relevant error occurred or they completed their work.  ([**CMP-3757**](https://issues.redhat.com/browse/CMP-3757))
- This update includes upgraded dependencies in the underlying base images.

## Release notes for OpenShift File Integrity Operator 1.3.7 {#file-integrity-operator-release-notes-1-3-7_file-integrity-operator-release-notes-v0}

Release notes for OpenShift File Integrity Operator 1.3.7.

The following Red Hat Security Advisory (RHSA) is available for the OpenShift File Integrity Operator 1.3.7:

- [RHSA-2025:21913 OpenShift File Integrity Operator Update](https://access.redhat.com/errata/RHSA-2025:21913)

This update includes upgraded dependencies in underlying base images.

## Release notes for OpenShift File Integrity Operator 1.3.6 {#file-integrity-operator-release-notes-1-3-6_file-integrity-operator-release-notes-v0}

Release notes for OpenShift File Integrity Operator 1.3.6.

The following Red Hat Bug Fix Advisory (RHBA) is available for the OpenShift File Integrity Operator 1.3.6:

- [RHBA-2025:11535 OpenShift File Integrity Operator Bug Fix Update](https://access.redhat.com/errata/RHBA-2025:11535)

### Bug fixes {#file-integrity-operator-1-3-6-bug-fixes_file-integrity-operator-release-notes-v0}

- Before this update, running the `oc annotate fileintegrities/<fileintegrity-name> file-integrity.openshift.io/re-init-on-failed=` command would trigger a reinitialization on all nodes. Now, it only reinitializes the nodes where failures occurred. ([**OCPBUGS-18933**](https://issues.redhat.com/browse/OCPBUGS-18933))
- Before this update, resetting FIO cleared the `NodeHasIntegrityFailure` alert. This occurred because the `metric file_integrity_operator_node_failed` setting was also reset. With this release, restarting FIO does not affect the `NodeHasIntegrityFailure` alert. ([**OCPBUGS-42807**](https://issues.redhat.com/browse/OCPBUGS-42807))
- Before this update, when a new node was added to a cluster by scaling up the `machineset` object, FIO marked the new node as `Failed` before the node was ready. With this release FIO waits until the new node is ready. ([**OCPBUGS-36483**](https://issues.redhat.com/browse/OCPBUGS-36483))
- Before this update, the Advanced Intrusion Detection Environment (AIDE) daemonset pods would constantly force-initialize the AIDE database. With this release, FIO initializes the AIDE database only once. ([**OCPBUGS-37300**](https://issues.redhat.com/browse/OCPBUGS-37300))
- Before this update, some link paths in the Machine Config Operator (MCO) configuration, such as `/hostroot/etc/ipsec.d/openshift.conf` and `hostroot/etc/mco/internal-registry-pull-secret.json`, changed during an MCO update. This led to failed file integrity checks on nodes after the update, which disrupted user experience. With this update, the File Integrity Operator (FIO) uses the updated file link paths in the MCO configuration. File integrity checks now pass after an update, helping to ensure a stable cluster. ([**OCPBUGS-41628**](https://issues.redhat.com/browse/OCPBUGS-41628))

## Release notes for OpenShift File Integrity Operator 1.3.5 {#file-integrity-operator-release-notes-1-3-5_file-integrity-operator-release-notes-v0}

Release notes for OpenShift File Integrity Operator 1.3.5.

The following Red Hat Bug Fix Advisory (RHBA) is available for the OpenShift File Integrity Operator 1.3.5:

- [RHBA-2024:10366 OpenShift File Integrity Operator Update](https://access.redhat.com/errata/RHBA-2024:10366)

This update includes upgraded dependencies in underlying base images.

## Release notes for OpenShift File Integrity Operator 1.3.4 {#file-integrity-operator-release-notes-1-3-4_file-integrity-operator-release-notes-v0}

Release notes for OpenShift File Integrity Operator 1.3.4.

The following Red Hat Bug Fix Advisory (RHBA) is available for the OpenShift File Integrity Operator 1.3.4:

- [RHBA-2024:2946 OpenShift File Integrity Operator Bug Fix and Enhancement Update](https://access.redhat.com/errata/RHBA-2024:2946)

### Bug fixes {#file-integrity-operator-1-3-4-bug-fixes_file-integrity-operator-release-notes-v0}

- Before this update, File Integrity Operator would issue a `NodeHasIntegrityFailure` alert due to multus certificate rotation. With this release, the alert and failing status are now correctly triggered. ([**OCPBUGS-31257**](https://issues.redhat.com/browse/OCPBUGS-31257))

## Release notes for OpenShift File Integrity Operator 1.3.3 {#file-integrity-operator-release-notes-1-3-3_file-integrity-operator-release-notes-v0}

Release notes for OpenShift File Integrity Operator 1.3.3.

The following Red Hat Bug Fix Advisory (RHBA) is available for the OpenShift File Integrity Operator 1.3.3:

- [RHBA-2023:5652 OpenShift File Integrity Operator Bug Fix and Enhancement Update](https://access.redhat.com/errata/RHBA-2023:5652)

This update addresses a CVE in an underlying dependency.

### New features and enhancements {#file-integrity-operator-1-3-3-new-features-and-enhancements_file-integrity-operator-release-notes-v0}

- You can install and use the File Integrity Operator in an OpenShift Container Platform cluster running in FIPS mode.

  > [!IMPORTANT]
  > To enable FIPS mode for your cluster, you must run the installation program from a Red Hat Enterprise Linux (RHEL) computer configured to operate in FIPS mode. For more information about configuring FIPS mode on RHEL, see [Switching RHEL to FIPS mode](https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/security_hardening/switching-rhel-to-fips-mode_security-hardening).
  >
  > When running Red Hat Enterprise Linux (RHEL) or Red Hat Enterprise Linux CoreOS (RHCOS) booted in FIPS mode, OpenShift Container Platform core components use the RHEL cryptographic libraries that have been submitted to NIST for FIPS 140-2/140-3 Validation on only the x86_64, ppc64le, and s390x architectures.

### Bug fixes {#file-integrity-operator-1-3-3-bug-fixes_file-integrity-operator-release-notes-v0}

- Before this update, some FIO pods with private default mount propagation in combination with `hostPath: path: /` volume mounts would break the CSI driver relying on multipath. This problem has been fixed and the CSI driver works correctly. ([Some OpenShift Operator pods blocking unmounting of CSI volumes when multipath is in use](https://access.redhat.com/solutions/7017081))
- This update resolves CVE-2023-39325. ([**CVE-2023-39325**](https://access.redhat.com/security/cve/CVE-2023-39325))

## Release notes for OpenShift File Integrity Operator 1.3.2 {#file-integrity-operator-release-notes-1-3-2_file-integrity-operator-release-notes-v0}

Release notes for OpenShift File Integrity Operator 1.3.2.

The following Red Hat Bug Fix Advisory (RHBA) is available for the OpenShift File Integrity Operator 1.3.2:

- [RHBA-2023:5107 OpenShift File Integrity Operator Bug Fix Update](https://access.redhat.com/errata/RHBA-2023:5107)

This update addresses a CVE in an underlying dependency.

## Release notes for OpenShift File Integrity Operator 1.3.1 {#file-integrity-operator-release-notes-1-3-1_file-integrity-operator-release-notes-v0}

Release notes for OpenShift File Integrity Operator 1.3.1.

The following Red Hat Bug Fix Advisory (RHBA) is available for the OpenShift File Integrity Operator 1.3.1:

- [RHBA-2023:3600 OpenShift File Integrity Operator Bug Fix Update](https://access.redhat.com/errata/RHBA-2023:3600)

### New features and enhancements {#file-integrity-operator-1-3-1-new-features-and-enhancements_file-integrity-operator-release-notes-v0}

- FIO now includes kubelet certificates as default files, excluding them from issuing warnings when they’re managed by OpenShift Container Platform. ([**OCPBUGS-14348**](https://issues.redhat.com/browse/OCPBUGS-14348))
- FIO now correctly directs email to the address for Red Hat Technical Support. ([**OCPBUGS-5023**](https://issues.redhat.com/browse/OCPBUGS-5023))

### Bug fixes {#file-integrity-operator-1-3-1-bug-fixes_file-integrity-operator-release-notes-v0}

- Before this update, the File Integrity Operator (FIO) would not clean up `FileIntegrityNodeStatus` CRDs when nodes are removed from the cluster. FIO now correctly cleans up node status CRDs on node removal.  ([**OCPBUGS-4321**](https://issues.redhat.com/browse/OCPBUGS-4321))
- Before this update, FIO would also erroneously indicate that new nodes failed integrity checks. FIO now correctly shows node status CRDs when adding new nodes to the cluster. This provides correct node status notifications. ([**OCPBUGS-8502**](https://issues.redhat.com/browse/OCPBUGS-8502))
- Before this update, when FIO was reconciling `FileIntegrity` CRDs, it would pause scanning until the reconciliation was done. This caused an overly aggressive re-initiatization process on nodes not impacted by the reconciliation. This problem also resulted in unnecessary daemonsets for machine config pools which are unrelated to the `FileIntegrity` being changed. FIO correctly handles these cases and only pauses AIDE scanning for nodes that are affected by file integrity changes. ([**CMP-1097**](https://issues.redhat.com/browse/CMP-1097))

### Known Issues {#file-integrity-operator-1-3-1-known-issues_file-integrity-operator-release-notes-v0}

In FIO 1.3.1, increasing nodes in IBM Z(R) clusters might result in `Failed` File Integrity node status. For more information, see [Adding nodes in IBM Power(R) clusters can result in failed File Integrity node status](https://access.redhat.com/solutions/7028861).

## Release notes for OpenShift File Integrity Operator 1.2.1 {#file-integrity-operator-release-notes-1-2-1_file-integrity-operator-release-notes-v0}

Release notes for OpenShift File Integrity Operator 1.2.1.

The following Red Hat Bug Fix Advisory (RHBA) is available for the OpenShift File Integrity Operator 1.2.1:

- [RHBA-2023:1684 OpenShift File Integrity Operator Bug Fix Update](https://access.redhat.com/errata/RHBA-2023:1684)
- This release includes updated container dependencies.

## Release notes for OpenShift File Integrity Operator 1.2.0 {#file-integrity-operator-release-notes-1-2-0_file-integrity-operator-release-notes-v0}

Release notes for OpenShift File Integrity Operator 1.2.0.

The following Red Hat Bug Fix Advisory (RHBA) is available for the OpenShift File Integrity Operator 1.2.0:

- [RHBA-2023:1273 OpenShift File Integrity Operator Enhancement Update](https://access.redhat.com/errata/RHBA-2023:1273)

### New features and enhancements {#file-integrity-operator-1-2-0-new-features-and-enhancements_file-integrity-operator-release-notes-v0}

- The File Integrity Operator Custom Resource (CR) now contains an `initialDelay` feature that specifies the number of seconds to wait before starting the first AIDE integrity check. For more information, see [Creating the FileIntegrity custom resource](/openshift-docs-markdown/security/file_integrity_operator/file-integrity-operator-understanding#understanding-file-integrity-custom-resource_file-integrity-operator).
- The File Integrity Operator is now stable and the release channel is upgraded to `stable`. Future releases will follow [Semantic Versioning](https://semver.org/). To access the latest release, see [Updating the File Integrity Operator](/openshift-docs-markdown/security/file_integrity_operator/file-integrity-operator-updating#olm-preparing-upgrade_file-integrity-operator-updating).

## Release notes for OpenShift File Integrity Operator 1.0.0 {#file-integrity-operator-release-notes-1-0-0_file-integrity-operator-release-notes-v0}

Release notes for OpenShift File Integrity Operator 1.0.0.

The following Red Hat Bug Fix Advisory (RHBA) is available for the OpenShift File Integrity Operator 1.0.0:

- [RHBA-2023:0037 OpenShift File Integrity Operator Bug Fix Update](https://access.redhat.com/errata/RHBA-2023:0037)

## Release notes for OpenShift File Integrity Operator 0.1.32 {#file-integrity-operator-release-notes-0-1-32_file-integrity-operator-release-notes-v0}

Release notes for OpenShift File Integrity Operator 0.1.32.

The following Red Hat Bug Fix Advisory (RHBA) is available for the OpenShift File Integrity Operator 0.1.32:

- [RHBA-2022:7095 OpenShift File Integrity Operator Bug Fix Update](https://access.redhat.com/errata/RHBA-2022:7095)

### Bug fixes {#file-integrity-operator-0-1-32-bug-fixes_file-integrity-operator-release-notes-v0}

- Before this update, alerts issued by the File Integrity Operator did not set a namespace, making it difficult to understand from which namespace the alert originated. Now, the Operator sets the appropriate namespace, providing more information about the alert. ([**BZ#2112394**](https://bugzilla.redhat.com/show_bug.cgi?id=2112394))
- Before this update, The File Integrity Operator did not update the metrics service on Operator startup, causing the metrics targets to be unreachable. With this release, the File Integrity Operator now ensures the metrics service is updated on Operator startup. ([**BZ#2115821**](https://bugzilla.redhat.com/show_bug.cgi?id=2115821))

## Release notes for OpenShift File Integrity Operator 0.1.30 {#file-integrity-operator-release-notes-0-1-30_file-integrity-operator-release-notes-v0}

Release notes for OpenShift File Integrity Operator 0.1.30.

The following Red Hat Bug Fix Advisory (RHBA) is available for the OpenShift File Integrity Operator 0.1.30:

- [RHBA-2022:5538 OpenShift File Integrity Operator Bug Fix and Enhancement Update](https://access.redhat.com/errata/RHBA-2022:5538)

### New features and enhancements {#file-integrity-operator-0-1-30-new-features-and-enhancements_file-integrity-operator-release-notes-v0}

- The File Integrity Operator is now supported on the following architectures:

  - IBM Power(R)
  - IBM Z(R) and IBM(R) LinuxONE

### Bug fixes {#file-integrity-operator-0-1-30-bug-fixes_file-integrity-operator-release-notes-v0}

- Before this update, alerts issued by the File Integrity Operator did not set a namespace, making it difficult to understand where the alert originated. Now, the Operator sets the appropriate namespace, increasing understanding of the alert. ([**BZ#2101393**](https://bugzilla.redhat.com/show_bug.cgi?id=2101393))

## Release notes for OpenShift File Integrity Operator 0.1.24 {#file-integrity-operator-release-notes-0-1-24_file-integrity-operator-release-notes-v0}

Release notes for OpenShift File Integrity Operator 0.1.24.

The following Red Hat Bug Fix Advisory (RHBA) is available for the OpenShift File Integrity Operator 0.1.24:

- [RHBA-2022:1331 OpenShift File Integrity Operator Bug Fix](https://access.redhat.com/errata/RHBA-2022:1331)

### New features and enhancements {#file-integrity-operator-0-1-24-new-features-and-enhancements_file-integrity-operator-release-notes-v0}

- You can now configure the maximum number of backups stored in the `FileIntegrity` Custom Resource (CR) with the `config.maxBackups` attribute. This attribute specifies the number of AIDE database and log backups left over from the `re-init` process to keep on the node. Older backups beyond the configured number are automatically pruned. The default is set to five backups.

### Bug fixes {#openshift-file-integrity-operator-0-1-24-bug-fixes_file-integrity-operator-release-notes-v0}

- Before this update, upgrading the Operator from versions older than 0.1.21 to 0.1.22 could cause the `re-init` feature to fail. This was a result of the Operator failing to update `configMap` resource labels. Now, upgrading to the latest version fixes the resource labels. ([**BZ#2049206**](https://bugzilla.redhat.com/show_bug.cgi?id=2049206))
- Before this update, when enforcing the default `configMap` script contents, the wrong data keys were compared. This resulted in the `aide-reinit` script not being updated properly after an Operator upgrade, and caused the `re-init` process to fail. Now,`daemonSets` run to completion and the AIDE database `re-init` process executes successfully. ([**BZ#2072058**](https://bugzilla.redhat.com/show_bug.cgi?id=2072058))

## Release notes for OpenShift File Integrity Operator 0.1.22 {#file-integrity-operator-release-notes-0-1-22_file-integrity-operator-release-notes-v0}

Release notes for OpenShift File Integrity Operator 0.1.22.

The following Red Hat Bug Fix Advisory (RHBA) is available for the OpenShift File Integrity Operator 0.1.22:

- [RHBA-2022:0142 OpenShift File Integrity Operator Bug Fix](https://access.redhat.com/errata/RHBA-2022:0142)

### Bug fixes {#openshift-file-integrity-operator-0-1-22-bug-fixes_file-integrity-operator-release-notes-v0}

- Before this update, a system with a File Integrity Operator installed might interrupt the OpenShift Container Platform update, due to the  `/etc/kubernetes/aide.reinit` file. This occurred if the `/etc/kubernetes/aide.reinit` file was present, but later removed before the `ostree` validation. With this update, `/etc/kubernetes/aide.reinit` is moved to the `/run` directory so that it does not conflict with the OpenShift Container Platform update. ([**BZ#2033311**](https://bugzilla.redhat.com/show_bug.cgi?id=2033311))

## Release notes for OpenShift File Integrity Operator 0.1.21 {#file-integrity-operator-release-notes-0-1-21_file-integrity-operator-release-notes-v0}

Release notes for OpenShift File Integrity Operator 0.1.21.

The following Red Hat Bug Fix Advisory (RHBA) is available for the OpenShift File Integrity Operator 0.1.21:

- [RHBA-2021:4631 OpenShift File Integrity Operator Bug Fix and Enhancement Update](https://access.redhat.com/errata/RHBA-2021:4631)

### New features and enhancements {#file-integrity-operator-0-1-21-new-features-and-enhancements_file-integrity-operator-release-notes-v0}

- The metrics related to `FileIntegrity` scan results and processing metrics are displayed on the monitoring dashboard on the web console. The results are labeled with the prefix of `file_integrity_operator_`.
- If a node has an integrity failure for more than 1 second, the default `PrometheusRule` provided in the operator namespace alerts with a warning.
- The following dynamic Machine Config Operator and Cluster Version Operator related filepaths are excluded from the default AIDE policy to help prevent false positives during node updates:

  - /etc/machine-config-daemon/currentconfig
  - /etc/pki/ca-trust/extracted/java/cacerts
  - /etc/cvo/updatepayloads
  - /root/.kube
- The AIDE daemon process has stability improvements over v0.1.16, and is more resilient to errors that might occur when the AIDE database is initialized.

### Bug fixes {#openshift-file-integrity-operator-0-1-21-bug-fixes_file-integrity-operator-release-notes-v0}

- Before this update, when the Operator automatically upgraded, outdated daemon sets were not removed. With this release, outdated daemon sets are removed during the automatic upgrade.

**Additional resources**
{._additional-resources}

- [Understanding the File Integrity Operator](/openshift-docs-markdown/security/file_integrity_operator/file-integrity-operator-understanding#understanding-file-integrity-operator)
- [Updating the File Integrity Operator](/openshift-docs-markdown/security/file_integrity_operator/file-integrity-operator-updating#olm-preparing-upgrade_file-integrity-operator-updating)
