- Issued:
- 2019-09-25
- Updated:
- 2019-09-25
RHBA-2019:2820 - Bug Fix Advisory
Synopsis
OpenShift Container Platform 4.1.17 bug fix update
Type/Severity
Bug Fix Advisory
Topic
Red Hat OpenShift Container Platform release 4.1.17 is now available with
updates to packages and images that fix several bugs.
Description
Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.
This advisory contains the container images for Red Hat
OpenShift Container Platform 4.1.17. See the following advisory for the
RPM packages for this release:
https://access.redhat.com/errata/RHBA-2019:2819
This release fixes the following bugs:
- The cluster-version operator's defaulting logic could outrace the cluster-bootstrap logic and inject unintended ClusterVersion content.The cluster-version operator has been updated to no longer supply a default ClusterVersion during the bootstrap phase. Existing clusters affected by the race could be manually recovered by updating their in-cluster ClusterVersion to use your desired channel and clusterID. (BZ#1708697)
- Cause: Logging changed container logs to use log level unknown because there was no way to accurately determine container log levels for all types of container logs. The remote syslog plugin broke because it does not know how to handle log level unknown. The syslog plugin has now been changed to use the configured default log level of info when it sees level unknown. (BZ#1741590)
Space precludes documenting all of the container images in this advisory.
See the following Release Notes documentation, which will be updated
shortly for this release, for details about these changes:
https://docs.openshift.com/container-platform/4.1/release_notes/ocp-4-1-rel ease-notes.html
You may download the oc tool and use it to inspect release image metadata
as follows:
$ oc adm release info quay.io/openshift-release-dev/ocp-release:4.1.17
The image digest is sha256:747e0d41ee2f1af8b234e8c96c3291225a120fab3af53ae691afb4f51ce02b85
All OpenShift Container Platform 4.1 users are advised to upgrade to these
updated packages and images.
Solution
Before applying this update, ensure all previously released errata
relevant to your system have been applied.
For OpenShift Container Platform 4.1 see the following documentation, which
will be updated shortly for release 4.1.17, for important instructions on
how to upgrade your cluster and fully apply this asynchronous errata
update:
https://docs.openshift.com/container-platform/4.1/release_notes/ocp-4-1-release-notes.html
Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.1/updating/updating-cluster-cli.html.
Affected Products
- Red Hat OpenShift Container Platform 4.1 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform 4.1 for RHEL 7 x86_64
Fixes
- BZ - 1659362 - kubelet targets are down
- BZ - 1666028 - links to prometheus and grafana are missing from the UI in 4.0-art-latest-2019-01-12-000105
- BZ - 1674341 - "error: metrics not available yet" for `oc adm top node`
- BZ - 1708697 - UPI installs default to fast update channel
- BZ - 1729918 - Configure new Scheduler Policy should take effect
- BZ - 1732580 - CatalogSources should be permissive to errors in manifests
- BZ - 1734003 - [4.1 backport] Synchronization firewall rules takes up to 90min
- BZ - 1737586 - Can't fetch packagemanifests(asb,tsb,elasticsearch clusterlogging) from app regisry redhat-operators-stage
- BZ - 1738203 - clusteroperator/operator-lifecycle-manager-catalog does not define any related resources
- BZ - 1740258 - After adding second ingresscontroller produces TLS handshake error coming from prometheus.
- BZ - 1740337 - Install master as schedulerable node will met co authentication Err
- BZ - 1740937 - Pods for marketplace CatalogSource and CatalogSourceConfig consuming large amounts of memory
- BZ - 1741062 - [4.1.z]marketplace clusteroperator degraded reporting missing reason/detail information
- BZ - 1743376 - Missing openapi CRD definitions for oc explain to work for sample operator CRD
- BZ - 1747461 - The router in OCP4 accepts TLS1.0 and TLS1.1 connections with no way to disable them [4.1 backport]
- BZ - 1748995 - [4.1.z] Must-gather does not collect information from the image registry
- BZ - 1749070 - cluster creating too many eviction requests a second
- BZ - 1750867 - [Operator-registory]"no bundle found" wrong operator will impact the load of the following operators packagemanifests
CVEs
References
(none)
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.