- Issued:
- 2016-03-24
- Updated:
- 2016-03-24
RHBA-2016:0510 - Bug Fix Advisory
Synopsis
Red Hat OpenShift Enterprise bug fix update
Type/Severity
Bug Fix Advisory
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
Topic
Updated atomic-openshift packages and images that fix a bug are now available for Red Hat OpenShift Enterprise 3.1.
Description
OpenShift Enterprise by Red Hat is the company's cloud computing Platform-as-a-Service (PaaS) solution designed for on-premise or private cloud deployments.
This update fixes the following bugs:
- Previously, cadvisor was improperly collecting network stats for processes for which it did not need to gather stats, creating potential for increased CPU utilization. This bug fix ensures cadvisor now only collects network stats for relevant processes, and significantly decreased CPU utilization is now observed. (BZ#1314495)
- Persistent volume claims (PVCs) were added to the list of volumes to preserve rather than the actual name of the persistent volume (PV) associated with the PVC. This caused the periodic cleanup process to unmount the volume if a pod utilizing the PVC had not yet entered running state. This bug fix ensures that the actual name of the PV associated with a PVC is used when determining which volumes can be cleaned up, preventing the cleanup process from considering them orphaned. As a result, PVs are no longer unmounted while the pod requiring the volume is starting. (BZ#1318472)
- EBS persistent volume (PV) attachment data cannot be cached reliably. After a persistent volume claim (PVC) was released, it retained a reference to the PVC to which it was bound. This caused volumes that had been detached to not be made available as they should have been. Also, if a PVC was deleted and the PV it was bound to was released, and another claim was created with the same name, it would try to bind the old PV. This bug fix ensures that cached volume attachment data is no longer relied upon and instead each request is checked to mount or unmount an EBS volume. The claim's UID is also now checked when trying to bind a PV based on the claim to ensure that the correct claim matches the correct PV. As a result, EBS volume attachment tasks are much more reliable. (BZ#1313560)
This update includes the following images:
openshift3/node:v3.1.1.6
openshift3/ose:v3.1.1.6
All OpenShift Enterprise 3 users are advised to upgrade to these updated packages and images.
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
After ensuring all packages on each host have been updated, restart the atomic-openshift-master service on each master to complete this update.
This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258.
The Red Hat Enterprise Linux container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com using the "docker pull" command. Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.
Affected Products
- Red Hat OpenShift Container Platform 3.1 x86_64
Fixes
- BZ - 1313560 - EBS persistent volume claims fail on re-use
- BZ - 1314495 - Updating to latest RHEL 7.2 Kernel causes higher load with Openshift Node process, time spent in regexp to high.
- BZ - 1318472 - Registry pod doesn't mount persistent volume(NFS) after restarting system
CVEs
(none)
Red Hat OpenShift Container Platform 3.1
| SRPM | |
|---|---|
| atomic-openshift-3.1.1.6-4.git.32.adf8ec9.el7aos.src.rpm | SHA-256: 01de7828d209ba9fbd601f3e3a657463b05e529520ecf2d3369116df58370859 |
| x86_64 | |
| atomic-openshift-3.1.1.6-4.git.32.adf8ec9.el7aos.x86_64.rpm | SHA-256: 682db2e50464d46dba93eae73cb34c8eb4d72862749e5a33fbf44972f295aa0a |
| atomic-openshift-clients-3.1.1.6-4.git.32.adf8ec9.el7aos.x86_64.rpm | SHA-256: 91ffdad00c3f1324b56cce90c937c6df4f52da68b8071367345149b9ce2a86c6 |
| atomic-openshift-clients-redistributable-3.1.1.6-4.git.32.adf8ec9.el7aos.x86_64.rpm | SHA-256: 7360521745f7f9e8923535b4a1cf52bdb5990db744cf3ca61b4566af2d833c21 |
| atomic-openshift-dockerregistry-3.1.1.6-4.git.32.adf8ec9.el7aos.x86_64.rpm | SHA-256: 9bbddfbaeda9acdbd3a8cd7daf83d2d0bd47a3561513800f1e3ca295d87faebb |
| atomic-openshift-master-3.1.1.6-4.git.32.adf8ec9.el7aos.x86_64.rpm | SHA-256: 146bb3916458e976fec74a001cfe66606894f09ffcda54a178a97f1148ccdc75 |
| atomic-openshift-node-3.1.1.6-4.git.32.adf8ec9.el7aos.x86_64.rpm | SHA-256: 645701f1da3c60c9ded8c81fc6241ab0d9d546611f4ffac2c8882da4aeaea764 |
| atomic-openshift-pod-3.1.1.6-4.git.32.adf8ec9.el7aos.x86_64.rpm | SHA-256: b923fb0643320fe9fa82d69b326b58ea13f08043a1923391f61690e3914b258e |
| atomic-openshift-recycle-3.1.1.6-4.git.32.adf8ec9.el7aos.x86_64.rpm | SHA-256: e9d2f7fe800f478c71959e89d37903b2283b8bfc609bc1e60bcd6004c8de3a0a |
| atomic-openshift-sdn-ovs-3.1.1.6-4.git.32.adf8ec9.el7aos.x86_64.rpm | SHA-256: 195a544a14523fa0671bbed691a8eaab7d7832411a98efffa68572a3820db656 |
| tuned-profiles-atomic-openshift-node-3.1.1.6-4.git.32.adf8ec9.el7aos.x86_64.rpm | SHA-256: d24b857156c864a22092c6e93db7bf2c824537f6f18af475b2a3605d0ff098bb |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.