- Issued:
- 2017-04-05
- Updated:
- 2017-04-05
RHBA-2017:0883 - Bug Fix Advisory
Synopsis
OpenShift Container Platform atomic-openshift-utils bug fix and enhancement
Type/Severity
Bug Fix Advisory
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
Topic
Updated atomic-openshift-utils and openshift-ansible packages that fix several bugs and add an enhancement are now available for OpenShift Container Platform 3.4 and 3.3.
Description
Red Hat OpenShift Container Platform is the company's cloud computing Platform-as-a-Service (PaaS) solution designed for on-premise or private cloud deployments.
The atomic-openshift-utils and openshift-ansible packages contain the installation utility and Ansible requirements for installing and upgrading OpenShift Container Platform 3.
This update fixes the following bugs:
- In containerized cluster environments, the CNI data directory located at /var/lib/cni was not properly configured to persist on the node host. This bug fix updates the installer to ensure that pod IP allocation data is persisted when restarting containerized nodes. (BZ#1429030)
- The logging operations facts for creating storage was missing. Logging operations storage was not correctly set up, and the logging-ops persistent volume claim (PVC) would fail to bind. This bug fix configures a separate secret for creating storage to back logging-ops PVCs. As a result, logging-ops PVCs are able to correctly bind. (BZ#1427598)
- A bracket was missing in a task for the openshift_storage_nfs role, causing the role to fail. This bug fix adds the missing bracket, and as a result the role no longer fails. (BZ#1430235)
- The openshift_hosted_metrics role required the `openshift_master_default_subdomain` fact to be set when evaluating the value for `openshift_hosted_metrics_public_url`, but it was not being set correctly. This caused the play to fail. This bug fix correctly sets the fact `openshift_master_default_subdomain` prior to setting `openshift_hosted_metrics_public_url`. As a result, the play completes successfully without needing to set `openshift_master_default_subdomain` in the inventory file. (BZ#1422839)
- Previously, the node service was restarted immediately after updating the master. This restart is now deferred until after the node upgrade steps have been completed. (BZ#1426888)
In addition, this update adds the following enhancement:
- The .NET Core image streams and Quickstart templates are now updated to include the content from the .NET Core 1.1 release. (BZ#1436704)
All OpenShift Container Platform 3.4 and 3.3 users are advised to upgrade to these updated packages.
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
To apply this update, run the following on all hosts where you intend to initiate Ansible-based installation or upgrade procedures:
# yum update atomic-openshift-utils
To update the default image streams to include the new .NET Core S2I image streams and Quickstart templates, see the following documentation.
For OpenShift Container Platform 3.4:
For OpenShift Container Platform 3.3:
This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258.
Affected Products
- Red Hat OpenShift Container Platform 3.4 x86_64
- Red Hat OpenShift Container Platform 3.3 x86_64
Fixes
- BZ - 1422839 - [3.3] Failed to upgrade 3.2 to 3.3 due to undefined variable openshift_master_default_subdomain
- BZ - 1426888 - [3.3] Stop restarting node after upgrading master rpms
- BZ - 1427598 - [3.4] Logging Ops Deployment Fails
- BZ - 1429030 - [3.4] Pod may get the duplicate IP if it is created after the node service restarted on containerized env
- BZ - 1430235 - [3.4] Missing right bracket in roles/openshift_storage_nfs/tasks/main.yml
- BZ - 1436704 - [3.4] Update .NET Core imagestream/templates in openshift-ansible
CVEs
(none)
References
(none)
Red Hat OpenShift Container Platform 3.4
| SRPM | |
|---|---|
| openshift-ansible-3.4.74-1.git.0.6542413.el7.src.rpm | SHA-256: cd7f47c3e266ecfeb7ffb0c51d2585a064dec6bc52409baf4c5fd722831990c0 |
| x86_64 | |
| atomic-openshift-utils-3.4.74-1.git.0.6542413.el7.noarch.rpm | SHA-256: c9a0e902194b5e28c3cb9d78d247c275400e819604fc704f74d611240146e4d3 |
| openshift-ansible-3.4.74-1.git.0.6542413.el7.noarch.rpm | SHA-256: d9a6cccc339f70dbcd2c9225f71f300298dc136bd2062fe7b5415a21db5557ff |
| openshift-ansible-callback-plugins-3.4.74-1.git.0.6542413.el7.noarch.rpm | SHA-256: 3e767ee1f09fd87414963edc139c01ef1acc42a9d337c69dcc6618355bec41d4 |
| openshift-ansible-docs-3.4.74-1.git.0.6542413.el7.noarch.rpm | SHA-256: df09a0123c5fc8b3d97e5476399193fad0b7f236f038f3a87b4548377be28482 |
| openshift-ansible-filter-plugins-3.4.74-1.git.0.6542413.el7.noarch.rpm | SHA-256: 587d41fa254059cd89271162afe116f2ccae573ac9bd14f64a284dc9d53aa6f4 |
| openshift-ansible-lookup-plugins-3.4.74-1.git.0.6542413.el7.noarch.rpm | SHA-256: 47cc8c21047f1cf29450d67a847e99c029f25e0a509ec0a4c2e17f16ba5352ca |
| openshift-ansible-playbooks-3.4.74-1.git.0.6542413.el7.noarch.rpm | SHA-256: c0bd018540ae2d6ae005f22240f8d1afe10998cdf7632906fca256846b3cb6a7 |
| openshift-ansible-roles-3.4.74-1.git.0.6542413.el7.noarch.rpm | SHA-256: e44c1b128b5e35a5a2d86cbcee2ecbf13556c2757014de8a55b34b77c2f16c28 |
Red Hat OpenShift Container Platform 3.3
| SRPM | |
|---|---|
| openshift-ansible-3.3.68-1.git.0.3792453.el7.src.rpm | SHA-256: 082460881123aa2773d32ff9bba8c1dc57c7ea7831b0f1df8163052e98b3dc9c |
| x86_64 | |
| atomic-openshift-utils-3.3.68-1.git.0.3792453.el7.noarch.rpm | SHA-256: e001cebbe8c4ff8a54eb6c8a8ff9d3beabee49d5156ddefb60dfbd52a6f5bd6c |
| openshift-ansible-3.3.68-1.git.0.3792453.el7.noarch.rpm | SHA-256: 75eaae31ead7abe1c0e509dd1b29cb523534469491fcb935cdecc03571b09139 |
| openshift-ansible-callback-plugins-3.3.68-1.git.0.3792453.el7.noarch.rpm | SHA-256: 2e34277a379e78cfec35ab6a4aff587714944cbe883afc71df6f5cb021becd55 |
| openshift-ansible-docs-3.3.68-1.git.0.3792453.el7.noarch.rpm | SHA-256: 13433c14db98d4c31b50750ece527b3ff451a26b2b4696e7af387735edbb19c5 |
| openshift-ansible-filter-plugins-3.3.68-1.git.0.3792453.el7.noarch.rpm | SHA-256: 545a8201110545f6eaa7436d7ffc09af5875259a68aadeac01214fa510d8901e |
| openshift-ansible-lookup-plugins-3.3.68-1.git.0.3792453.el7.noarch.rpm | SHA-256: f1a0141f83f166eae87a446e084771ae1037aed5bb00e16df09e0578e992d203 |
| openshift-ansible-playbooks-3.3.68-1.git.0.3792453.el7.noarch.rpm | SHA-256: b095186d9b4db3237393f5b11b80a8670113a5d1ae747fb689a95168f4c14703 |
| openshift-ansible-roles-3.3.68-1.git.0.3792453.el7.noarch.rpm | SHA-256: b8c894175573d7da2f6f1868de2f75321b07e67a76632186e67125b38c2c5b9d |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.