- Issued:
- 2019-06-11
- Updated:
- 2019-06-11
RHBA-2019:1302 - Bug Fix Advisory
Synopsis
OpenShift Container Platform 3.7 bug fix update
Type/Severity
Bug Fix Advisory
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
Red Hat OpenShift Container Platform release 3.7.119 is now available with
updates to packages and images that fix several bugs.
Description
Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.
This advisory contains the RPM packages for Red Hat OpenShift Container
Platform 3.7.119. See the following advisory for the container images for
this release:
https://access.redhat.com/errata/RHBA-2019:1303
This update fixes the following bugs:
- Egress router configuration made it impossible to connect to the public IP address of the node it was hosted on. As a result, if an egress pod was configured to use it's node as a name server via `/etc/resolv.conf`, it would be unable to perform DNS resolution. Now, traffic from an egress router pod to it's node is now routed via the SDN tunnel instead of the egress interface. Egress routers can now connect to their node's public IP address. (BZ#1595291)
- The `tuned` role was not applied during and upgrade, but only during a fresh install. The `tuned` role now is applied during upgrades to ensure that profiles are applied appropriately. (BZ#1594128)
All OpenShift Container Platform 3.7 users are advised to upgrade to these
updated packages and images.
Solution
Before applying this update, ensure all previously released errata
relevant to your system have been applied.
For OpenShift Container Platform 3.7 see the following documentation, which
will be updated shortly for release 3.7.119, for important instructions on
how to upgrade your cluster and fully apply this asynchronous errata
update:
https://docs.openshift.com/container-platform/3.7/release_notes/ocp_3_7_release_notes.html
This update is available via the Red Hat Network. Details on how to use the
Red Hat Network to apply this update are available at
https://access.redhat.com/articles/11258.
Affected Products
- Red Hat OpenShift Container Platform 3.7 x86_64
Fixes
- BZ - 1595291 - [Backport 3.7] Egress Router HTTP Proxy cannot reach the node which router pod runs
- BZ - 1694128 - Tuned profiles are not applied to OpenShift clusters that get upgraded from 3.6
CVEs
(none)
References
(none)
Red Hat OpenShift Container Platform 3.7
SRPM | |
---|---|
atomic-openshift-3.7.119-1.git.0.69f0256.el7.src.rpm | SHA-256: 759dd84c9a3660dc901fe114a7db60a4b986cda33c78137eb788e22ab0f23fbf |
openshift-ansible-3.7.119-1.git.0.713183a.el7.src.rpm | SHA-256: 4ca1e94c2ba3456857bbcb50e245c4517f1322c0b816e31f349a97a61c54c858 |
x86_64 | |
atomic-openshift-3.7.119-1.git.0.69f0256.el7.x86_64.rpm | SHA-256: 9809ed33109963a618354af002a8998782e06f124c42807c1184a9efe1605426 |
atomic-openshift-clients-3.7.119-1.git.0.69f0256.el7.x86_64.rpm | SHA-256: 9f1ddde12d327642bb72fc0fbc95ec7e184caf514ae94d0490d3bd5f6e819276 |
atomic-openshift-clients-redistributable-3.7.119-1.git.0.69f0256.el7.x86_64.rpm | SHA-256: a223d7946687d281e18359a49b68c9e1cc1a1f7e30b7a0a5bcad7db65dae3c1a |
atomic-openshift-cluster-capacity-3.7.119-1.git.0.69f0256.el7.x86_64.rpm | SHA-256: 8af99b234e49f12f7db431956a36528d62d7df4e5acfac70079da03091256302 |
atomic-openshift-docker-excluder-3.7.119-1.git.0.69f0256.el7.noarch.rpm | SHA-256: 95b3a771fcefaa975fded3cfc7c05490cda01260d0a308fbd751d4e3f006f0cf |
atomic-openshift-dockerregistry-3.7.119-1.git.0.69f0256.el7.x86_64.rpm | SHA-256: 31de41456ba79acdc4238fc7b28903ad1ee6acf1d03755478cfd89e4f1301cc5 |
atomic-openshift-excluder-3.7.119-1.git.0.69f0256.el7.noarch.rpm | SHA-256: 0bd4fb67973ee95e9c9de7ad9c8f0499afc2e7a3941093c32f15ded402089328 |
atomic-openshift-federation-services-3.7.119-1.git.0.69f0256.el7.x86_64.rpm | SHA-256: 385e772e0f5903165a8d87e8e149d5c0125688844a1a8c41a4e8cf80c5865f98 |
atomic-openshift-master-3.7.119-1.git.0.69f0256.el7.x86_64.rpm | SHA-256: 32b0b55015d8f02f911ef1d185c8837119982e937bfc11b820aadb5dbcee2b4a |
atomic-openshift-node-3.7.119-1.git.0.69f0256.el7.x86_64.rpm | SHA-256: 880e7812df36c8855c90d6bfcfce2aa3b8601eac3615fd79e4794c3e88816529 |
atomic-openshift-pod-3.7.119-1.git.0.69f0256.el7.x86_64.rpm | SHA-256: ab2a35994e694f818a042c3e935396197b3c783ff11f1217183ad9ec4c7ce807 |
atomic-openshift-sdn-ovs-3.7.119-1.git.0.69f0256.el7.x86_64.rpm | SHA-256: b388d6a7688eb4ef7e0971a00fea2dffbbb5921ba3e37378850049967b95e3f6 |
atomic-openshift-service-catalog-3.7.119-1.git.0.69f0256.el7.x86_64.rpm | SHA-256: 0499ecb5ac1bd9fbd974f577e5a4a73cdca92667995c680e4e3fa48e62e8be1a |
atomic-openshift-template-service-broker-3.7.119-1.git.0.69f0256.el7.x86_64.rpm | SHA-256: 89fc8b7dbaa8d3ee96d47fa83a918b60a1db694677288fe507e63dd6503fb530 |
atomic-openshift-tests-3.7.119-1.git.0.69f0256.el7.x86_64.rpm | SHA-256: dc6a04698c06cf6010f202610c63b999b60b99d608607e9b61d863dccf53782f |
atomic-openshift-utils-3.7.119-1.git.0.713183a.el7.noarch.rpm | SHA-256: 8ccead0d9dd0efaa4aa22db6e9457fcb176166b17a5db8f11b5de3d789561469 |
openshift-ansible-3.7.119-1.git.0.713183a.el7.noarch.rpm | SHA-256: 95b46d99751bc2344160634d5db37cf20d75461eaa9b98553da9f9a356ee3c09 |
openshift-ansible-callback-plugins-3.7.119-1.git.0.713183a.el7.noarch.rpm | SHA-256: e3e5091df430c201de6b95fb860b1bc31410d770b2983fb40f7f5694ae9dfe14 |
openshift-ansible-docs-3.7.119-1.git.0.713183a.el7.noarch.rpm | SHA-256: 8725d1d043bad13f2fdec25e09adef7ba2c745ae066751cf131d4e0473cac0ef |
openshift-ansible-filter-plugins-3.7.119-1.git.0.713183a.el7.noarch.rpm | SHA-256: 84d00439841b3f1dec7842105c0d0cb904335066f3c0109cced9e7a97055acb9 |
openshift-ansible-lookup-plugins-3.7.119-1.git.0.713183a.el7.noarch.rpm | SHA-256: 707eaa9e65b61dc2e3386060b3acca63795299f71beffb73602ab9236d237af1 |
openshift-ansible-playbooks-3.7.119-1.git.0.713183a.el7.noarch.rpm | SHA-256: f8c30ee0256f1ed7a001d734e02eda8981b6d28f2d2884b7e6b75bacffbc4d31 |
openshift-ansible-roles-3.7.119-1.git.0.713183a.el7.noarch.rpm | SHA-256: ebe2ed7d51f105eeec05b83ff8f7922858a2f746fa9650ca04e5d36497bbf1b1 |
tuned-profiles-atomic-openshift-node-3.7.119-1.git.0.69f0256.el7.x86_64.rpm | SHA-256: 5375b1113c1b68427c7c90ba6a366b96f0d6a0a9dd6e5e00ce42c245030e6e1e |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.