- 发布:
- 2019-10-16
- 已更新:
- 2019-10-16
RHBA-2019:2922 - Bug Fix Advisory
概述
OpenShift Container Platform 4.2 Image Release Advisory
类型/严重性
Bug Fix Advisory
标题
Red Hat OpenShift Container Platform release 4.2, which fixes several bugs and includes various enhancements, is now available.
描述
Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.
This advisory contains the RPM container images for Red Hat OpenShift Container Platform 4.2. See the following advisory for the RPM packages for this release:
https://access.redhat.com/errata/RHBA-2019:2921
Space precludes documenting all of the container images in this advisory.
See the following Release Notes documentation, which will be updated
shortly for this release, for details about these changes:
https://docs.openshift.com/container-platform/4.2/release_notes/ocp-4-2-release-notes.html
All OpenShift Container Platform 4.2 users are advised to upgrade to these
updated packages and images.
解决方案
Before applying this update, ensure all previously released errata
relevant to your system have been applied.
受影响的产品
- Red Hat OpenShift Container Platform 4.2 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform 4.2 for RHEL 7 x86_64
修复
- BZ - 1572149 - `oc cp` with non-existent container or pod should prompt container or pod not found when copying from pod
- BZ - 1576543 - prometheus-operator pods getting OoM killed @ 750 nodes
- BZ - 1576547 - kube-state-metrics pods getting OoM killed @ 750 nodes
- BZ - 1610599 - Usage info is being printed on all errors
- BZ - 1642530 - Custom Resource is stuck if deleted repeatedly with PropagationPolicy Foreground
- BZ - 1643303 - Provisioning two APB services temporarily broke networking in the namespace
- BZ - 1644686 - Increased file i/o using experimental logging-fluentd based on 1.2.x
- BZ - 1646886 - Empty network diagram on console UI in CRI-O env
- BZ - 1654142 - [sriov-cni] Cannot allocate more than 1 vf to pod when the pod requested it via resource limit
- BZ - 1654174 - [sriov-cni] Non-existed vf will be assigned to pod if disable the sriov feature on the PF when the sriovdp is running
- BZ - 1654798 - [OSP] Kuryr-Kubernetes needs leader-elector container to be provided by OCP
- BZ - 1662263 - The binary version inside the OLM 4.0 downstream image is not quite useful
- BZ - 1664600 - [cloud-CA] Shouldn't be allowed to create more than one clusterautoscaler resource
- BZ - 1665010 - Should show Webhook secret and create a link to the secret
- BZ - 1665011 - CVO should have clean-up mechanism to limit finished updatepayload jobs
- BZ - 1666558 - [cloud] Failed to delete machine that has no label or providerSpec
- BZ - 1669544 - Clarification on KUBE_MAX_PD_VOLS for OpenShift/OpenStack Integration
- BZ - 1669657 - oc adm node-logs should get logs that span multiple boot events.
- BZ - 1671685 - Inaccurate error message when removing a clusterrolebinding from a group for non-existent cluster role
- BZ - 1674043 - Project status pod count is misleading
- BZ - 1674378 - [BUG] prometheus and alertmanager - all targets are not connected and in status down
- BZ - 1683055 - service-ca operator config needs validation
- BZ - 1683156 - Should show the error info in the subscription object
- BZ - 1683819 - empty value for key on label is actually valid for nodeselector (and other uses)
- BZ - 1684258 - toolbox should handle `--help` flag
- BZ - 1684427 - Wrong build steps when use an external image as a “stage” in multi-stage build
- BZ - 1684652 - Running "oc delete kubeapiserver.operator cluster" leads to permanent cluster death
- BZ - 1686271 - [OSP] Openshift-install got 409 for router deletion during destroy cluster
- BZ - 1686358 - [OSP] Bootstrap and api instance can not resolve internal osp with default subnet dns_nameservers
- BZ - 1687241 - [OSP] Sometimes bootstrap and api fail to dial openstack metadata server during booting even with correct security group
- BZ - 1687292 - [OSP] Sometimes masters fail to get ignition from load balancer vm and got error "dial tcp <LB ip>:22623: i/o timeout"
- BZ - 1687666 - console operator events should be in good format
- BZ - 1688658 - The InstallMode of the Descheduler operator should NOT be `AllNamespaces`
- BZ - 1689036 - Unjoin a cluster which not exists in the federation gives an unclear err msg
- BZ - 1690197 - cluster-nfd-operator is only being built for OCP, has no gating CI or origin jobs
- BZ - 1690734 - The federateddeployments crd's group should be types.federation.k8s.io not primitives.federation.k8s.io in federation installation UI
- BZ - 1690754 - Enabling unsafe sysctls in kubeletConfig is not taking affect
- BZ - 1691282 - Allow project admins to see Installed Operators page in the console
- BZ - 1692281 - Prometheus is not showing metrics for ASB
- BZ - 1692594 - OCP 4.1: oc delete project -l <label> command hangs intermittently while projects and their resources get actually deleted
- BZ - 1692664 - Enable Service API federation multiple time with different federation-group failed
- BZ - 1693180 - MachineSet and Machine pages need Event page for resources page consistency
- BZ - 1693865 - CI Operator does not expose pods deleted due to evictions well
- BZ - 1694303 - [OCP4 Beta] nodelink-controller and the machine-approver are not working on OpenStack
- BZ - 1694543 - The packageRepositioryVersions of catalogsourceconfig is different from the version of clusterserviceversion
- BZ - 1695522 - [OSP] All CSRs are pending due to machine controller not work well
- BZ - 1696628 - Using AWS when a secondary IP address is added the order of the list of InternalIPs is not preserved.
- BZ - 1696726 - [OCP4 Beta] [marketplace] NodeSelector missing for openshift-marketplace
- BZ - 1697728 - The elasticsearch pods weren't updated when redundancyPolicy changed
- BZ - 1698377 - Couldn't update elasticsearch CR successfully after deleting nodeSelector in clusterlogging CR.
- BZ - 1698543 - FailedCreatePodContainer "Delegation not available for unit type"
- BZ - 1698562 - ingress operator does not complain about missing defaulCertificate secret
- BZ - 1699341 - Synchronization firewall rules takes up to 90min
- BZ - 1699471 - test to ensure we never have more than 20 revisions
- BZ - 1700100 - [marketplace] certified-operators causing e2e failures
- BZ - 1700431 - EgressIP doesn't work with NetworkPolicy unless traffic from default project is allowed
- BZ - 1701041 - Proxy never returns response when watch fails to get established
- BZ - 1701050 - SSH connection hangs on Azure
- BZ - 1701410 - [OCP4 Beta] ingress-operator is not recognizing if the certificate Secret is changed
- BZ - 1701856 - [3.11] Large difference between manually calculated Memory related values and Prometheus query output
- BZ - 1702552 - Two "NAME" fields by command "oc get catalogsource"
- BZ - 1702582 - polling apply actions in CVO should report more resource specific errors
- BZ - 1702757 - Image pruning on api.ci is wedged due to too many images
- BZ - 1703234 - MCO is reading things frequently that it should not need to read
- BZ - 1703279 - coreos installer iso defaults to fedora-coreos.raw.gz
- BZ - 1703877 - [stability] MCD pod is periodically exiting with error during some e2e runs
- BZ - 1703885 - [ci] [aws] Router test fails with "error 7" while trying to reach backend
- BZ - 1704356 - [stability] Some e2e tests failing due to unable to detach EBS volume in under 10m
- BZ - 1704587 - MachineHealthCheck cannot be associated with target machine if it is created after the node becomes unhealthy
- BZ - 1704827 - oc login provides useless error when authentication is denied
- BZ - 1705123 - jenkins-slave produce process defunct [ Jenkins "SLAVE" ]
- BZ - 1705589 - kibana presenting blank page or timeout
- BZ - 1705712 - Unexpected Multus error messages
- BZ - 1705746 - Missing openapi CRD definitions for oc explain to work
- BZ - 1705748 - Missing openapi CRD definitions for oc explain to work
- BZ - 1705752 - Missing openapi CRD definitions for oc explain to work for image-registry operator CRD
- BZ - 1705753 - Missing openapi CRD definitions for oc explain to work for sample operator CRD
- BZ - 1706476 - [4.1] "many-to-many matching not allowed: matching labels must be unique on one side" shows in fresh environment
- BZ - 1706867 - [marketplace] Incorrectly reporting OperatorStatus degrading when restarting or upgrading marketplace operator
- BZ - 1706868 - Node detail page doesn't display node status
- BZ - 1707059 - no termination message provided by failing cluster-storage-operator pod
- BZ - 1707062 - no termination message provided by failing dns-operator pods
- BZ - 1707065 - no termination message provided by failing cluster-autoscaler-operator pod
- BZ - 1707229 - etcd grafana page is not auto refreshed
- BZ - 1707373 - podman is not configured with pull secret
- BZ - 1707471 - error: could not run steps: step src failed: could not wait for build: the build src failed after 0s with reason BuildPodEvicted: Pod The node had condition: [DiskPressure].
- BZ - 1707479 - workers are not created when pool default path other than "/var/lib/libvirt/images"
- BZ - 1707517 - CNO updates role bindings too frequently
- BZ - 1707545 - Ingress operator does not implement ingress controller conditions defined in the API
- BZ - 1707679 - The scc(CRD) resources can not be upgraded by 'oc patch' and 'oc edit'
- BZ - 1707749 - egressip column cannot be shown for hostsubnet and netnamespaces in CLI
- BZ - 1707834 - Cluster samples operator has a high read rate from operator
- BZ - 1707872 - Inefficient getLBHostedZone Function
- BZ - 1707875 - The ES deployment couldn't be created if the origin one is deleted in stuck
- BZ - 1707941 - image build doesn't handle COPY correctly in some cases
- BZ - 1708235 - On smaller mobile screens, the Monitoring UI graph controls don't fit in the graph container.
- BZ - 1708280 - oc get panics when fed empty list and -o=name|json|yaml|??
- BZ - 1709090 - Missing openapi CRD definitions for oc explain to work for controllermanager operator
- BZ - 1709213 - [DR][MSTR-363] Can't do recovery on the master restarted by the machine-set
- BZ - 1709239 - Remove gitrepo volume from CLI examples as it is not supported
- BZ - 1709251 - Template mongodb-persistent use version 3.6, but points to 3.2 doc
- BZ - 1709575 - Unable to oauth authenticate with github/keycloak to openshift jenkins instance
- BZ - 1709664 - Update cluster.spec.kubernetesApiEndpoints.serverEndpoints.serverAddress to an invalid address, the federatedcluster status still is Ready
- BZ - 1710079 - Missing button to create Cluster Logging CR after initial install of Cluster Logging operator
- BZ - 1710188 - The "Joining Clusters" part of the description of federation operator needs to be fixed
- BZ - 1710193 - The "Unjoining Clusters" part of the description of federation operator needs to be fixed
- BZ - 1710198 - The "Enabling federation for new API types" part of the description of federation operator needs to be fixed
- BZ - 1710201 - The "Example: federating deployments" part of the description of federation operator needs to be fixed
- BZ - 1710203 - The "Disabling federation for an API type" part of the description of federation operator needs to be fixed
- BZ - 1710206 - The "Created time" in the federation operator ui is not correct
- BZ - 1710220 - federation-group parameter has no effect for kubefedctl disable cmd
- BZ - 1710404 - Suggestion to adjust Elasticsearch OOTB cpu limit and memory request
- BZ - 1710502 - node-ca and image-registry incorrectly handle graceful shutdown
- BZ - 1710626 - kubelet exited with "failed to write xxx to cgroup.procs .. .scope/cgroup.procs: invalid argument
- BZ - 1710652 - Minor Spelling error while going through SDN logs
- BZ - 1710657 - Elasticsearch pods have an OOTB cpu limit of 1
- BZ - 1710856 - cluster-network-operator overwrites status field with third-party operators
- BZ - 1710937 - After disabling servicecatalog operators the apiservice remains - prevents project deletion
- BZ - 1711070 - OLM/OperatorHub components should not running in BestEffort QoS
- BZ - 1711073 - Monitoring components running in BestEffort QoS
- BZ - 1711075 - Auth components running in BestEffort QoS
- BZ - 1711158 - Issue with SDN pods
- BZ - 1711173 - Should gracefully exit when try to delete configs.imageregistry.operator.openshift.io
- BZ - 1711200 - Container fails to start with "no space left on device" even there is enough storage available
- BZ - 1711340 - Kubernetes Pod Template is randomly removed
- BZ - 1711364 - One of the dns pods continuous restart ,but the dns operator's status is available
- BZ - 1711373 - dns operator fails to integrate with metrics and stops syncing status
- BZ - 1711402 - CCO repeatedly OOMKilled in cluster with 2350 projects
- BZ - 1711431 - Cannot recover from bad serving cert secret on Kube api server
- BZ - 1711439 - Cluster DNS requests can be routed to un-ready CoreDNS pods
- BZ - 1711533 - Unprivileged access to discovery
- BZ - 1711563 - github.com/openshift/origin/vendor/k8s.io/kubernetes/pkg/scheduler/internal/queue TestHighProirotyFlushUnschedulableQLeftover
- BZ - 1711569 - Enable NodeLease tests
- BZ - 1711687 - [upgrade-4.2] Skew between 1.13 kubelet and 1.14 control plane causes restart issues in e2e runs
- BZ - 1711688 - Should access volume from different nodes storage e2e test is flaky/failing for aws/nfs, others
- BZ - 1712034 - Unable to mount volumes for pod
- BZ - 1712245 - Unable to use shell variable in build config environment variable section when variable name includes a '.'
- BZ - 1712317 - Make oc explain for Master CRDs show brief introduction under DESCRIPTION instead of <empty>
- BZ - 1712321 - [DR]etcd node lost connection after run 'etcd-snapshot-restore.sh'
- BZ - 1712528 - oc delete of a static pod results in multiple attempts to re-create the mirror pod before succeeding
- BZ - 1712566 - Cannot build 4.2 images - RPM version conflicts
- BZ - 1712645 - "server returned HTTP status 500 Internal Server Error" for some kubelet endpoints
- BZ - 1712721 - Can't scalep up ES nodes from 3 to N (N>3) in clusterlogging CRD instance.
- BZ - 1712826 - [DR]'etcd-snapshot-restore.sh' don't support pre-check or re-run
- BZ - 1712912 - Cluster console shows double container ram used in OCP 3.11
- BZ - 1713010 - AWS provider removes stopped instances when reconciling machines
- BZ - 1713105 - Missing node prevents machine from being delete
- BZ - 1713209 - [usability] Add obvious signal when use performs a Start Rollout action
- BZ - 1713374 - Machineset is scaled to 0, but machine and node aren't removed
- BZ - 1713389 - Cannot block registries to deploy pods if using whitelist for image policy (registrySources / allowedRegistries)
- BZ - 1713479 - During upgrade, LocalStorageCapacityIsolation feature gate is turned on temporarily
- BZ - 1714140 - [4.2]The generated InstallPlan object didn't refer to itself subscription object
- BZ - 1714184 - Include Metrics Support for CSI drivers .
- BZ - 1714699 - Rolling out OVS daemonset changes takes a very long time.
- BZ - 1714769 - Multiple type: Failure conditions on KubeletConfig CR status when no MCP selector is provided
- BZ - 1714771 - Updating the kube-apiserver certificate with a new certificate fails to reload the kube-apiserver certificate
- BZ - 1714897 - The initial status on dc detail page is not correct
- BZ - 1715108 - Switch installer and user interface to stable-4.2 channel, add *-4.2 channels to UI.
- BZ - 1715205 - PXE boot “ipv6.disable=1” does not work
- BZ - 1715370 - Some orphaned logs sent to .operations.* index by mistake.
- BZ - 1715634 - must-gather does not include logs from pods in openshift-cluster-version namespace
- BZ - 1716311 - "Provisioning should access volume from different nodes" test can't work in multi-AZ clusters
- BZ - 1716524 - [marketplace]Some opsrc can't be detected after the cluster upgrade
- BZ - 1716548 - AWS Installer chooses incorrect availability zones
- BZ - 1716697 - Build prints invalid image pull spec, containing both ":latest" tag and "@sha256" digest
- BZ - 1716703 - Advanced options such as env variables, labels, resource limits, etc. cannot be set in the s2i builder wizards
- BZ - 1717124 - cluster reader is unable to read configs.samples.operator.openshift.io
- BZ - 1717198 - scheduling e2e: reenable SchedulerPreemption tests
- BZ - 1717439 - Marketplace operator does not properly define related resources
- BZ - 1717494 - ingress operator fails to integrate with metrics and stops syncing status
- BZ - 1717497 - service-ca-operator leader election period is 2s causes excessive writing to etcd
- BZ - 1717533 - Networking details are missing for some deployment configs in web console overview
- BZ - 1717604 - buildcop: failures in e2e-aws container setup related to \"aws_lb\" \"api_external\"
- BZ - 1717610 - autoapproval tolerances too strict for some large scale ups
- BZ - 1717617 - Telemetry should include the condition reason on degraded operators
- BZ - 1717618 - Kube-scheduler-operator entering a permanent degraded state
- BZ - 1717631 - clusteroperator/cloud-credential does not define any related resources
- BZ - 1717632 - There should be cluster-monitoring alerts when an operator goes degraded or is unavailable
- BZ - 1717633 - clusteroperator/machine-api does not define any related resources
- BZ - 1717635 - clusteroperator/network does not define any related resources
- BZ - 1717636 - clusteroperator/operator-lifecycle-manager does not define any related resources
- BZ - 1717638 - clusteroperator/operator-lifecycle-manager-catalog does not define any related resources
- BZ - 1717639 - Random outages with egressIP
- BZ - 1717734 - clusteroperator/dns does not define enough related resources
- BZ - 1717737 - clusteroperator/ingress does not define enough related resources
- BZ - 1717970 - machine-config-daemon mark node as degraded due to "open /etc/machine-config-daemon/node-annotations.json: no such file or directory"
- BZ - 1718049 - Need SCTP module in RHEL CoreOS by default
- BZ - 1718412 - TemplateInstance object not taking into account values passed in through secret
- BZ - 1718454 - samples operator upgrade while unmanaged/removed needs to still update clusteroperator version, set available = true
- BZ - 1718726 - Worker node Allocatable pods capacity reverted from 500 back to 250 after update and reboot
- BZ - 1718878 - Hard pruning tests do not check layer links
- BZ - 1718879 - Cache mutation detected in CI
- BZ - 1719106 - Unable to expose kubelet_volume_stats_available_bytes and kubelet_volume_stats_capacity_bytes to Prometheus
- BZ - 1719188 - Processing and Degraded status should be False when openshiftcontrollermanager operator is unmanaged
- BZ - 1719417 - relatedObjects in clusteroperator authentication references non-existent authentication-operator namespace
- BZ - 1719481 - Project status page resource usage is not optimal
- BZ - 1719653 - Network mode Multitenant - apiserver can not connect to etcd because of netnamespaces
- BZ - 1719808 - [IPI] [OSP] Pulling debug logs from the bootstrap machine never works because bootstrap node has no public address
- BZ - 1719965 - TLS Keys Not Added to Registry Routes
- BZ - 1720045 - "query-browser" page is blank
- BZ - 1720119 - Node overview page shows incorrect metrics due to too wide selector
- BZ - 1720321 - must-gather does not collect all non-core CRs in the given namespace
- BZ - 1721380 - Builds using openshift imagestreams fail if the import has not completed yet
- BZ - 1721431 - Mess error message displays when user save Channel without any change.
- BZ - 1721516 - Template Service Broker does not clean up Cluster Scoped Resources
- BZ - 1721537 - Marketplace operator enters degraded & ultimately exits during upgrade
- BZ - 1721583 - [upgrade] Cluster upgrade should maintain a functioning cluster: replicaset "rs" never became ready
- BZ - 1721586 - `/etc/kubernetes/ca.crt` is not managed/updated
- BZ - 1721650 - Install is failing for 4.2 nightly
- BZ - 1721922 - alertmanager-main pod does not apply the toleration config
- BZ - 1722214 - openshift-cluster-samples-operator state is degraded
- BZ - 1722341 - duplicated tolerations in the DNS operator deployment
- BZ - 1722523 - must-gather loses metrics data collection
- BZ - 1722550 - creating the unsupported configmap for cert rotation should taint a cluster
- BZ - 1722568 - Increase the limit on the number of signatures in openshift.io/image-signature-import controller
- BZ - 1722754 - kubefedconfig.spec.scope field is null when installing a cluster scoped kubefed operator
- BZ - 1722759 - kubefedconfig.spec.featureGates is null when installing kubefed control plane with kubefed-operator
- BZ - 1722812 - openshift-etcd namespace isn't collected in must-gather
- BZ - 1722876 - Browser freezes if one hits sorting buttons in Installed Operators tab
- BZ - 1722879 - Type key instead of Kind
- BZ - 1722880 - missing sorting options for Status and Last Updated in APIs list of Installed Operator
- BZ - 1722894 - MCO is reporting a full text value for Reason - Reason must be a short constant
- BZ - 1722944 - rsyslog log collector dropping logs
- BZ - 1722959 - Access to the ES root url / from a project's pod on Openshift
- BZ - 1723143 - [kuryr]Recreation of the same app with the same project after deletion
- BZ - 1723472 - must-gather should redact kubectl.kubernetes.io/last-applied-configuration in secrets
- BZ - 1723528 - Create route form incorrectly states that hostnames can't be changed
- BZ - 1723531 - Content is overlapping on Machine Configs page
- BZ - 1723535 - clean up protocol specified in pom.xml for various jenkins plugin builds
- BZ - 1723565 - Wrong error message when no API Version is provided in InstallConfig
- BZ - 1723569 - Need to clean up extraneous secrets in node tuning operator namespace
- BZ - 1723577 - clusteroperator/node-tuning does not define enough related resources
- BZ - 1723672 - [marketplace] Specify right owner kind in child resources' labels
- BZ - 1723688 - PrometheusTargetScrapesDuplicate alert throws out in fresh environment
- BZ - 1723713 - clusteroperator/monitoring does not define any related resources
- BZ - 1723798 - podman-executed container ip conflict
- BZ - 1723818 - OLM upgrade failure from 4.1 to 4.2 due to packageserver csv OwnerConflict
- BZ - 1723835 - [marketplace] Missing openapi CRD definitions for oc explain to work
- BZ - 1723945 - Unable to identify age of cluster in relation to current version via PromQL
- BZ - 1724010 - meet error "invalid parameter 'start' ..."" to a valid timestamp" when run queries on firefox 52
- BZ - 1724053 - Log into Kibana console get "500 InternalError"
- BZ - 1724155 - Upgrade failure with "Marking Degraded due to: during bootstrap: unexpected on-disk state validating" error.
- BZ - 1724189 - Nodes in Not Ready state after adding API named certificate as per https://docs.openshift.com/container-platform/4.1/authentication/certificates/api-server.html
- BZ - 1724204 - [IPI] [OSP] oc get machines do not show infomation about openstack instances
- BZ - 1724248 - Cluster Monitoring Operator fails to complete - reconciling Cluster Monitoring Operator ServiceMonitor failed
- BZ - 1724274 - During upgrade, node-tuning operator status rapidly alternates between new and old version
- BZ - 1724332 - Test flake - Pod should be preferably scheduled to nodes pod can tolerate
- BZ - 1724346 - Install failure flake - timed out waiting for etcd - delayed DNS record creation?
- BZ - 1724430 - OCP 4.2 is using CRIO 1.13.9-1.rhaos4.1.gitd70609a.el8
- BZ - 1724484 - openshift-apiserver-operator pod is using alpha api
- BZ - 1724498 - Prometheus jobs for ingresses aren't working as expected if multiple ingresses exist
- BZ - 1724574 - CSI Mock tests don't work
- BZ - 1724660 - libpod 1.0.2-dev appears buggy, request a version bump
- BZ - 1724892 - Metric name does not along with the metrics result from Query Browser
- BZ - 1724916 - "No Prometheus datapoints found." in prometheus graph after navigating to Query Browser
- BZ - 1724977 - Negative setting for console customization keeps refreshing newer versions and yaml can not be updated again.
- BZ - 1725005 - Common user could not delete/edit project on console
- BZ - 1725027 - Should update `oc adm release info -h` help info with output : digest, name, pullspec
- BZ - 1725148 - Elasticsearch Operator sets resource limits when not requested
- BZ - 1725220 - CNO stuck in Progressing=True as it doesn't refresh Multus DS state on startup
- BZ - 1725259 - [ci] [azure] Managed cluster should should expose cluster services outside the cluster
- BZ - 1725526 - m4.xlarge is not supported in ap-northeast-2b
- BZ - 1725935 - Authentication operator degraded state is not nuanced enough for useful aggregated metrics
- BZ - 1726045 - cannot access to the service's externalIP with egressIP in openshift-ovs-multitenant environment
- BZ - 1726055 - Bad graph for the metrics with extremely large value
- BZ - 1726069 - multus pods as infra component should not keep experimental "critical-pod" annotation
- BZ - 1726137 - must-gather gather_network_logs script does not save output under /must-gather
- BZ - 1726296 - e2e-aws-upgrade-rollback-4.1-to-4.2 failure: Cluster operator machine-config is still updating
- BZ - 1726326 - Jenkins sync plugin tests fail after cri-o bump
- BZ - 1726370 - Cluster operator machine-config is reporting a failure: Failed to resync 4.2.0-0.nightly-2019-07-01-102521
- BZ - 1726374 - oc describe istag a:b no longer prints image metadata in 4.2
- BZ - 1726392 - Test Failure: authorization TestAuthorizationResourceAccessReview should succeed [Suite:openshift/conformance/serial]
- BZ - 1726449 - DNS operator does not have a level gate
- BZ - 1726451 - CCO operator does not have a level gate
- BZ - 1726453 - Ingress operator does not have a level gate
- BZ - 1726455 - Limits are not reconciled by CVO
- BZ - 1726573 - Could not find elasticsearch metrics in Prometheus server.
- BZ - 1726591 - User can't edit Environment Variables during deploy image progress
- BZ - 1726597 - [CONSOLE-1536] Inconsistent PF4 styles for alerts
- BZ - 1726639 - RFE: change level to 'unknown' for container logs
- BZ - 1726894 - Cannot change Requests values in image-registry operator config
- BZ - 1727012 - [4.2] ClusterOperator cloud-credential missing ClusterStatusConditionType Upgradeable
- BZ - 1727015 - [4.2] ClusterOperator cluster-autoscaler missing ClusterStatusConditionType Upgradeable
- BZ - 1727021 - [4.2] ClusterOperator machine-api missing ClusterStatusConditionType Upgradeable
- BZ - 1727022 - [4.2] ClusterOperator machine-config missing ClusterStatusConditionType Upgradeable
- BZ - 1727023 - [4.2] ClusterOperator marketplace missing ClusterStatusConditionType Upgradeable
- BZ - 1727024 - [4.2] ClusterOperator monitoring missing ClusterStatusConditionType Upgradeable
- BZ - 1727026 - [4.2] ClusterOperator network missing ClusterStatusConditionType Upgradeable
- BZ - 1727032 - [4.2] ClusterOperator operator-lifecycle-manager missing ClusterStatusConditionType Upgradeable
- BZ - 1727042 - [4.2] ClusterOperator operator-lifecycle-manager-packageserver missing ClusterStatusConditionType Upgradeable
- BZ - 1727044 - [4.2] ClusterOperator storage missing ClusterStatusConditionType Upgradeable
- BZ - 1727080 - Cluster did not complete upgrade: Working towards registry...: downloading update on nightlies due to CI/ART Dockerfile divergence
- BZ - 1727086 - [Feature:ProjectAPI] TestInvalidRoleRefs should succeed [Suite:openshift/conformance/parallel] flaky
- BZ - 1727104 - invalid machine config should cause a RenderDegraded error not NodeDegraded
- BZ - 1727249 - Could not add github idp successfully on console
- BZ - 1727258 - Link in breadcrumb bar on image stream tag page is wrong.
- BZ - 1727266 - Storage-admin can get but not describe pvc from other's project
- BZ - 1727282 - ca.crt is not set properly when creating identity providers in the web console
- BZ - 1727318 - e2e-aws-upgrade-rollback-4.1-to-4.2: ClusterOperatorNotAvailable: Cluster operator image-registry is still updating
- BZ - 1727595 - image registry operator fails to upgrade 4.1->4.2 due to proxy config
- BZ - 1727765 - wrong data in Reports list table
- BZ - 1727772 - text in Download report button are not aligned on Firefox
- BZ - 1727800 - [Performance] It takes very long time to redirect OperatorHub page to response user
- BZ - 1728062 - toolbox requires registry authentication
- BZ - 1728099 - [Performance] It takes very long time to redirect Developer Catalog page to response user
- BZ - 1728111 - oc adm node-logs --tail option 200k lines limit.
- BZ - 1728159 - No accepted 4.2 nightly build for a week (since 2019-07-01)
- BZ - 1728223 - operator-lifecycle-manager-packageserver failed to get available due to missing serviceaccount
- BZ - 1728352 - Update tox test environment vars
- BZ - 1728518 - [SDN] Node doesn't get un-taint when MTU value is fixed
- BZ - 1728523 - non-admin can open create dialog in other namespace
- BZ - 1728555 - Download oc link should point to the version consistent with cluster version
- BZ - 1728841 - The cluster update modal does not sort updates in its dropdown
- BZ - 1728954 - Rsyslog prometheus exporter couldn't start.
- BZ - 1728957 - API Explorer list keeps display loading instead of No API Found
- BZ - 1728985 - Disable Chargeback menu when user has no permission to view report
- BZ - 1729021 - User cannot be created because of missing permission boundary
- BZ - 1729091 - Cluster does not come up when networkType set to OVNKubernetes
- BZ - 1729289 - OAuth login page has wrong favicon
- BZ - 1729297 - Prometheus metrics for ES are unavailable after plugin update to 5.6.13.6
- BZ - 1729308 - ClusterVersion api does not make it clear it should not be edited
- BZ - 1729310 - dns.config.openshift.io does not make it clear it is read-only
- BZ - 1729311 - network.config.openshift.io does not make it clear it is read-only
- BZ - 1729316 - rsyslog log collector creating operations index with no date in the name
- BZ - 1729437 - Usage Report table overlaps when view on smaller screen size
- BZ - 1729440 - table on API Explorer list page overlaps when view on smaller screen size
- BZ - 1729457 - Dependency error of cri-o-1.14.6-1.rhaos4.2.el7.x86_64
- BZ - 1729512 - machine-controller does not wait for nodes to drain (4.2)
- BZ - 1729522 - Jenkins k8s client uses deprecated route paths
- BZ - 1729529 - Inconsistent presentation of memory statistics in Grafana creating confusion
- BZ - 1729576 - RHCOS L7 Routing Support on GCP not working
- BZ - 1729876 - Hosted Domain should be set as required
- BZ - 1729979 - drain takes 600s to evict the image-registry pod and container is still running afterwards
- BZ - 1730207 - Too many "No Action Needed for xxxxxxxxx" logs in rsyslog pod.
- BZ - 1730211 - Log rotation for rsyslog doesn't work
- BZ - 1730339 - Potential volume leak in CSI external provisioner
- BZ - 1730425 - y-axis labels in query browser are not sufficiently precise
- BZ - 1730540 - The example query would always added to the first query-input field
- BZ - 1730562 - Proxy setting cannot be adapted to master
- BZ - 1730652 - Rsyslog prometheus stats not being reported correctly.
- BZ - 1730719 - Build Defaults not being applied to pods
- BZ - 1730722 - image.config.openshift.io/cluster "blockedRegistries" spec is not properly blacklisting for build push operations
- BZ - 1730945 - Rsyslog pod always restart when set `ES_REBIND_INTERVAL` to a small value.
- BZ - 1731011 - [CA] Sometimes "--balance-similar-node-groups" option doesn't work well
- BZ - 1731059 - Pod with persistent volumes failed scheduling on Azure due to volume node affinity conflict
- BZ - 1731105 - `oc explain apiserver.spec.servingCerts` still explains defaultServingCertificate
- BZ - 1731191 - OAuth htpasswd end-to-end test is flaky
- BZ - 1731233 - 4.1 etcd clusters are reporting a down "etcd" service, but no alert is firing on the cluster
- BZ - 1731248 - rsyslog pod log spam
- BZ - 1731278 - Bootstrap user login test breaks kubeadmin user on Azure
- BZ - 1731306 - query-input textarea is missed in Query Browser default page
- BZ - 1731316 - Typo in the output of command `oc explain pv.spec.cinder`
- BZ - 1731317 - Add commitmeta.json to machine-os-content image content
- BZ - 1731319 - runtime error: "integer divide by zero" shows in Query Browser page if the time range is too small
- BZ - 1731322 - time range is not changed after dragging mouse in blank area of the graph
- BZ - 1731323 - Some operators cannot be upgraded from 4.1 to 4.2
- BZ - 1731338 - OPSRC and CSC should have different name
- BZ - 1731345 - the Y-axis should have value < 0
- BZ - 1731366 - Could not create app from template on console
- BZ - 1731392 - [multus-admission]multus admission did not take effect
- BZ - 1731394 - oc adm-must gather does not work if arbitrary command is passed as parameter
- BZ - 1731530 - Kubectl describe should check if kubectl describe prints relevant information for rc and pods
- BZ - 1731801 - Use correct style for Create button on Deployment Config page
- BZ - 1731845 - kubefed operator description in operator hub should be about kubefed operator not about kubefed
- BZ - 1731859 - Donut data is 0% instead of "No Data" or "No Request/Limit" when the resource does not have quota
- BZ - 1731873 - The page became blank when create instance on installed operator page
- BZ - 1731886 - It always prompts error when create CouchBase cluster from "Edit Form" model
- BZ - 1731892 - Restore or confirm test removals during openshift-controller-manager staging move
- BZ - 1732087 - The button on the OpenShift console for editing the configmap gets disabled after removing the resourceNames
- BZ - 1732120 - Node stuck on scheduling disabled due to MCD being degraded
- BZ - 1732138 - kibana [security_exception] no permissions for [indices:data/read/search]
- BZ - 1732141 - API Server: Improve config.openshift.io resource description
- BZ - 1732143 - Authentication: Improve config.openshift.io resource description
- BZ - 1732144 - Build: Improve config.openshift.io resource description
- BZ - 1732145 - Console: Improve config.openshift.io resource description
- BZ - 1732146 - DNS: Improve config.openshift.io resource description
- BZ - 1732148 - Image: Improve config.openshift.io resource description
- BZ - 1732150 - Scheduler: Improve config.openshift.io resource description
- BZ - 1732153 - Missing information about oc client version.
- BZ - 1732164 - [marketplace] Report default operator source failings to telemetry
- BZ - 1732193 - Master controllers try to detach a removed cinder volume every 2 minutes with "Resource not found" message.
- BZ - 1732299 - Only one container's volume is list in "Volumes" part on detail page after attach storage to all containers
- BZ - 1732300 - Wrong command format to create PVC in local storage example uage
- BZ - 1732302 - catalog-operator will panic when the installing operator's ClusterRole/ClusterRoleBinding exist
- BZ - 1732307 - Install kubefed operator with "All namespaces on the cluster" mode, but the kubefed operator can not be used in all namespaces
- BZ - 1732364 - Add SearchGuard permissions for Jaeger to create index templates.
- BZ - 1732377 - Can't create the recovery API server with 4.2 env
- BZ - 1732378 - Defaults Application Name option to Create New Application when user doesn't have any apps
- BZ - 1732503 - marketplace operator does not restore default OperatorSources from failed state
- BZ - 1732557 - Fix CSV Metadata to pass CVP validation
- BZ - 1732577 - Unable to restart marketplace when default opsrcs are marked for deletion
- BZ - 1732579 - CatalogSources should be permissive to errors in manifests
- BZ - 1732585 - Kibana shows 500 Internal Server Error after cluster reboot
- BZ - 1732598 - With multus configured pod can not get secondary interface (Regression bug)
- BZ - 1732613 - Setting config in Subscritpion for env vars takes a long time to reflect in operator pods
- BZ - 1732614 - machine-api-operator panic: runtime error: invalid memory address or nil pointer dereference
- BZ - 1732622 - TestImageStreamAdmitStatusUpdate test flake image AlreadyExists
- BZ - 1732649 - graph tip is unstable
- BZ - 1732678 - Text overflows in Top Consumers table
- BZ - 1732740 - [CONSOLE-1476] Give correct help info in YAML editor
- BZ - 1732745 - CatalogSource local-storage-manifests missing publisher field.
- BZ - 1732754 - Second selected query string should replace the existed one instead of directly appending the string at the end of previous one.
- BZ - 1732760 - The CSC and its' child resources will be deleted after the markektplace-operator pod restart
- BZ - 1732775 - [sriov] Package name do not match the repo name
- BZ - 1732836 - Sorting not working in Chargeback Reports listing table
- BZ - 1732858 - [IPI OSP] platform cloud name is hardcoded to openstack. Installer fails if other name is used
- BZ - 1732884 - Install Fails While Waiting for Cluster Monitoring Operator
- BZ - 1732914 - Operator upgrades fail when versions field of replacing CRDs is not set
- BZ - 1732936 - resources spec don't get updated by the cluster logging operator
- BZ - 1732941 - oc build requires git checkout, but we have tar ball
- BZ - 1733011 - Inappropriate message when view rsyslog pod logs by `oc exec $rsyslog-pod -- logs` after setting `LOGGING_FILE_PATH=console`
- BZ - 1733015 - 4.1.7 upgrade to 4.2 nightly fails with error 'a required extension is not available to update'
- BZ - 1733060 - The "Cancel" button doesn't take effect on rolebinding creation page
- BZ - 1733091 - Yaml page directs to Dashboard when user click a doc link from mouse hovering message
- BZ - 1733109 - Cert validity increases from 1 year to 10 years during rotation
- BZ - 1733116 - Operator local-storage does not exist in OperatorHub.
- BZ - 1733123 - sometimes drag to zoom feature is broken
- BZ - 1733279 - kubelet PLEG unhealthy, crio 1.14 hangs in ContainerStatus
- BZ - 1733315 - If resources for NFD are present on the cluster, the operator should update all resources that belong to NFD.
- BZ - 1733336 - oauth-openshift operand not starting
- BZ - 1733399 - Incorrect link for Expression in Alerting Rule Overview page
- BZ - 1733412 - Can't view rsyslog pod logs by `oc exec -c rsyslog $rsyslog-pod -- logs` when set `LOGGING_FILE_PATH` to file
- BZ - 1733431 - About page does not work for normal user
- BZ - 1733454 - OPSRC 's registory pod with lable "marketplace.catalogSourceConfig" in OCP4.2
- BZ - 1733464 - [ServiceBroker] Install ASB and TSB operators failed in OCP4.2
- BZ - 1733471 - [autoscaler] Update machineautoscaler targetting an invalid machineset should have the original machineset annotation been cleared
- BZ - 1733473 - [MDB] Shouldn't be allowed to create MDB with negative number of minAvailable
- BZ - 1733476 - [Azure] oc get machines do not show infomation about azure instances
- BZ - 1733490 - install kubefed operator failed with the downstream image
- BZ - 1733581 - failing tests: [sig-scheduling] NoExecuteTaintManager Multiple Pods [Serial] evicts pods with minTolerationSeconds
- BZ - 1733619 - GCP: message: 0 of 1 credentials requests provisioned, 0 reporting errors.
- BZ - 1733708 - 4.1.4 cluster creating 400+ eviction requests a second
- BZ - 1733825 - Incorrect memory usage for openshift-monitoring namespace
- BZ - 1733830 - many "Error on ingesting results from rule evaluation with different value but same timestamp" msg in prometheus-k8s pod logs
- BZ - 1733867 - [IPI] [OSP] All request rely on frontproxy failed due to node name can not be resolved within cluster
- BZ - 1733890 - Can't fetch packagemanifests(asb,tsb,elasticsearch clusterlogging) from app regisry redhat-operators-stage
- BZ - 1733892 - [IPI on OSP]Image registry pod cannot be running
- BZ - 1733897 - [sriov-operator]Failed to init the VF for mellanox_plugin
- BZ - 1733902 - [IPI on Azure]Report 409 error for azure storage container after remove spec.stroage.azure.container from imageregistry crd
- BZ - 1733955 - The kubefed downstream image creates and updates kubefedconfig failed
- BZ - 1734080 - Add Jaeger index mappings to Elasticsearch image
- BZ - 1734148 - [Azure IPI] e2e-azure fails on: users can manipulate groups [Suite:openshift/conformance/parallel] test
- BZ - 1734192 - Ingress operator cannot be upgraded from 4.1 to 4.2 on AWS
- BZ - 1734193 - AWS EBS volume support ignores the 'encrypted' property
- BZ - 1734196 - Prometheus when installed on the cluster should report telemetry
- BZ - 1734266 - Duplicate alerts in Alertmanager web console
- BZ - 1734284 - kube-apiserver ServiceMonitor is still in cluster-monitoring-operator
- BZ - 1734290 - Console cannot create clusterwide etcdcluster with forms
- BZ - 1734314 - Imagestream cannot be import in proxy enabled cluster
- BZ - 1734326 - RoleBindingRestriction could not be created for resource validation failed
- BZ - 1734343 - [UPI] [Baremetal] Install fails on machine-config operator
- BZ - 1734364 - Y-axis value crosses the graph border in Query Browser
- BZ - 1734390 - oauth-proxy is rejecting a valid service account
- BZ - 1734414 - Ingress operator cannot be upgraded from 4.1 to 4.2 on vSphere
- BZ - 1734486 - Configure new Scheduler Policy should take effect
- BZ - 1734504 - Parts of oc adm must-gather do not respect --config CLI option
- BZ - 1734540 - etcd clusters are reporting a down "etcd" service, but no alert is firing on the cluster
- BZ - 1734554 - Create a script to remove a failed etcd member and to allow it to be replaced
- BZ - 1734564 - Image Registry's service CA is constantly removed/re-created
- BZ - 1734592 - Empty fields are skipped when set SKIP_EMPTY=false and USE_MMEXTERNAL=false in rsyslog daemonset.
- BZ - 1734599 - The trust ca couldn't be added by image config
- BZ - 1734601 - The statefulset created with default yaml will get error in page after add storage to it
- BZ - 1734626 - [sriov] sriov-network-config-daemon pod become CrashLoopBackOff when initial the XXV710 VF
- BZ - 1734627 - Build fails for PullBuilderImageFailed with EOL images when upgrade from 4.1 to 4.2
- BZ - 1734673 - Rescheduling of pod cause local volume failed to mount
- BZ - 1734674 - CSI controller sidecars can't access CSI driver socket
- BZ - 1734704 - proxy environment, alertmanager-proxy container in alertmanager-main pods can not be started
- BZ - 1734709 - Group by list labels should not wrap
- BZ - 1734951 - rsyslog with MERGE_JSON_LOG=true does not handle non-JSON data
- BZ - 1735404 - ConfigMap with binaryData is not handled correctly in kubectl get or oc extract
- BZ - 1735511 - Rsyslog couldn't parse json log which has prefix space before the json string when set MERGE_JSON_LOG=true
- BZ - 1735520 - the search metrics textarea is not auto fit for the alert rule expression
- BZ - 1735530 - rsyslog undefined field handling - fluentd parity
- BZ - 1735538 - Pods stuck in container creating - Failed to run CNI IPAM ADD: failed to allocate for range 0
- BZ - 1735585 - Provide some links for users to add workloads easily
- BZ - 1735596 - kubefed downstream image is not correct
- BZ - 1735661 - Pods with many log lines will report "failed to create fsnotify watcher: too many open files"
- BZ - 1735710 - [sriov]Old network-attachment-definitions did not be deleted after update the networkNamespace
- BZ - 1735711 - ImageChangesInProgress stuck in true for long time
- BZ - 1735728 - [sriov] should add the description for the CR when using 'oc explain'
- BZ - 1735729 - [IPI] [OSP] Cloud provider is not working well
- BZ - 1736293 - GCP machine-controller does not honor requeue delay
- BZ - 1736795 - Remove scheduler-policy then recover name to original "" in scheduler/cluster still result in scheduler pod CrashLoopBackOff
- BZ - 1736800 - openshift-apiserver is down due to "x509: certificate signed by unknown authority" error
- BZ - 1736812 - openshift-controller-manager-operator pod is using alpha api
- BZ - 1736813 - openshift-kube-apiserver-operator pod is using alpha api
- BZ - 1736815 - openshift-kube-controller-manager-operator pod is using alpha api
- BZ - 1736819 - openshift-kube-scheduler-operator pod is using alpha api
- BZ - 1736843 - openshift-service-catalog-apiserver-operator pod is using alpha api
- BZ - 1736846 - openshift-service-catalog-controller-manager-operator pod is using alpha api
- BZ - 1736875 - Ifcfg configuration in Ignition didn't work as expected
- BZ - 1737026 - CNO StatusManager is not thread-safe
- BZ - 1737053 - Image registry verify jobs are broken
- BZ - 1737057 - Subscription CRD does not validate `config` block
- BZ - 1737081 - CatalogSource Status should have information on last observed state(s)
- BZ - 1737086 - machine-api-operator caused nightly builds to fail August 1 2019
- BZ - 1737102 - vSphere UPI: invalid guest ID "other26xLinux64Guest" for clone. Please set it to "rhel7_64Guest"
- BZ - 1737120 - multi-arch builds failing because image-references contains stale images
- BZ - 1737127 - oc idle service cause runtime error: invalid memory address or nil pointer dereference
- BZ - 1737134 - [Feature:Machines][Serial] Managed cluster should grow and decrease when scaling different machineSets simultaneously [Suite:openshift/conformance/serial] failing on e2e-aws 20%
- BZ - 1737175 - Multi-arch support
- BZ - 1737286 - The logs collected by rsyslog are not parsed
- BZ - 1737351 - Console should show templates from current namespace in Developer Catalog
- BZ - 1737385 - The CRDs defined in the kubefed-operator are different with the CRDs used in kubefed
- BZ - 1737389 - CSI: MountOption in storage class does not take effect for ebs volume
- BZ - 1737408 - Show storageclass's volumeBindingMode in storageclass's overview page
- BZ - 1737415 - Utilization card is stuck in loading state when no IP is reported in machine object
- BZ - 1737443 - MachineSet can endlessly create/delete new machinesets after it has been deleted.
- BZ - 1737466 - Ascending sort and Descending sort (Name, Status, Machine etc.) doesn't work at Bare Metal Hosts page
- BZ - 1737505 - Can not create a machineset with a node with a public ip on azure
- BZ - 1737558 - must-gather does not collect PVCs and events in openshift-image-registry namespace
- BZ - 1737575 - Unable to backup etcd data
- BZ - 1737577 - Cannot install app migration components in OCP 3.11
- BZ - 1737611 - master node certs expire and CSRs are not approved on Baremetal or any UPI
- BZ - 1737660 - e2e-azure - etcd server overloaded
- BZ - 1737683 - openshift-apiserver pod fall into CrashLoopBackOff when proxy enabled
- BZ - 1737756 - Host listing is not updated when an action is performed
- BZ - 1737780 - [sriov] DaemonSet did not be sync after updated the image of csv
- BZ - 1737788 - CSI volumes are not detached on RequestLimitExceeded errors
- BZ - 1737802 - [IPI] [OSP] Delete swift container containing ignition files after cluster is initialized
- BZ - 1737806 - scale up rhel node failed since the machine-config-daemon image was removed
- BZ - 1737850 - Tracking enable fips on rhcos
- BZ - 1737878 - Failed to install app-migration component by mig-operator on ocp 3.7-3.10
- BZ - 1737901 - Stop maintenance modal window show nmo name and name of node instead of bare metal host name
- BZ - 1738256 - samples operator needs to report degraded if imagestream imports continue to fail after 2 hours
- BZ - 1738284 - Proxy support - no proxy is not being set on kube-apiserver pods
- BZ - 1738401 - Ingress: Improve config.openshift.io resource description
- BZ - 1738403 - Networking-> ingress item better to be plural form for consistency
- BZ - 1738412 - The manifests for kubefed controller and webhook are not correct in the downstream kubefed-operator image
- BZ - 1738421 - [sriov] sriov operator should be able to restore sriovnetworknodepolicy if the default policy is deleted
- BZ - 1738432 - Generic operator client blocks removing fields from observed config
- BZ - 1738433 - [sriov] resourcename is not correct in NetworkAttachmentDefinition
- BZ - 1738475 - [GCP]Image registry operator goes to panic after add keyID
- BZ - 1738495 - insights operator is in the state DEGRADED
- BZ - 1738527 - cluster-version-operator is not applying Service Monitor
- BZ - 1738606 - Calls to GCP API hang forever when metadata access is blocked
- BZ - 1738690 - gcp e2e failing: [sig-auth] [Feature:NodeAuthenticator] The kubelet's main port 10250 should reject requests with no credentials [Suite:openshift/conformance/parallel] [Suite:k8s]
- BZ - 1738691 - GCP: e2e test failing: [sig-scheduling] Multi-AZ Cluster Volumes [sig-storage] should only be allowed to provision PDs in zones where nodes exist [Suite:openshift/conformance/parallel] [Suite:k8s]
- BZ - 1738702 - Openshift 4.2 web ui shows pod as "completed" when containers are still running
- BZ - 1738757 - graph tip is not user friendly
- BZ - 1738831 - parent MCP doesn't update machine count when there's another custom pool for a subset of the parent MCP
- BZ - 1738840 - Delete migplan should also delete migmigration resource
- BZ - 1738857 - All the masters and nodes become "NotReady" after restart the kubelet during do the certificates recovery
- BZ - 1738867 - Pods are Unavailable at a Bare Metal Hosts Inventory Dashboard
- BZ - 1738874 - [Baremental]‘Add Host’ button cannot work on /baremetalhosts page
- BZ - 1739120 - Overview Dashboard: Subsystem Health popover appears above masthead
- BZ - 1739151 - [WEB UI]: Unable to access Migration UI when OCP 3 cluster has the migration controller
- BZ - 1739214 - samples operator clusteroperator degraded reporting missing reason/detail information
- BZ - 1739225 - Timestamp component always shows dates in the future as relative dates
- BZ - 1739235 - Multi-version CRDs and admission webhooks should play nicely together in OpenShift 4.2
- BZ - 1739288 - No 'Cancel Rollout' menu on Replication Controller list page
- BZ - 1739310 - "No datapoints found." except for "Number of Pods" under "Compute -> Nodes"
- BZ - 1739312 - Documentation URL should link to 4.2
- BZ - 1739347 - bootkube.service failed for error "Cannot use two forms of the same flag: network net"
- BZ - 1739351 - Bare Metal Hosts appear in status "other" instead of "OK"
- BZ - 1739362 - The output message for "kubefedctl federate ns test-namespace" is not correct when test-namespace is not exist
- BZ - 1739364 - Baremetal host list should include node reference instead of machine reference
- BZ - 1739380 - text is hidden in the Query Broswer on firefox
- BZ - 1739390 - PopoverStatus button is misaligned
- BZ - 1739401 - Resources sync among multiple clusters is very slow
- BZ - 1739407 - Host status does not reflect operational status and does not show errors
- BZ - 1739445 - oc rpm is builing stale code vendored back into origin
- BZ - 1739462 - No logs are received when CDM_UNDEFINED_TO_STRING=true
- BZ - 1739562 - Panic during migration when cluster is in bad state
- BZ - 1739588 - [Grafana] Displaying confusing "Cache" memory usage
- BZ - 1739601 - static pods are subject to eviction
- BZ - 1739724 - Enable running make verify as a CI job
- BZ - 1739831 - Node metrics graphs are disordered during node startup
- BZ - 1739981 - Only show Update to another version when there's available updates
- BZ - 1739988 - CVO reports two failure series for cluster_version, which complicates queries
- BZ - 1740004 - [GCP] "oc get machine" does not show machine's TYPE/REGION/ZONE
- BZ - 1740027 - Installation with proxy enabled failed on bootstrap
- BZ - 1740035 - [IPI on Azure]Status.storage.azure.container doesn't be updated after specify a custom contianer
- BZ - 1740052 - Federate a namespace failed for the invalid object name
- BZ - 1740065 - --dry-run param does not take effect for kubefedctl federate --enable-type
- BZ - 1740121 - Install master as schedulerable node will met co authentication Err
- BZ - 1740201 - Migration from gluster to ceph results in empty volume
- BZ - 1740315 - [sig-scheduling] SchedulerPriorities [Serial] Pod should be preferably scheduled to nodes pod can tolerate
- BZ - 1740332 - OLM should install the operator for user defined Service Account for OperatorGroup after granting the proper permissions
- BZ - 1740363 - 59 degraded auth operators in telemeter
- BZ - 1740366 - Authentication operator stuck in degraded state (RouteHealthDegraded)
- BZ - 1740370 - 21 clusters reporting registry operator unavailable
- BZ - 1740387 - Console sync error reason codes are too vague
- BZ - 1740439 - Unless RHEL worker disable firewalld.service, "oc rsh/exec/logs" does not work
- BZ - 1740441 - the credentialsrequests name for ingress should follow same naming conventions
- BZ - 1740447 - Failed to upgrade ES pods because cpu limit is set to zero in the deployment
- BZ - 1740543 - [IPI] [OSP] FIP address assigned to bootstrap node is not released after bootstrap node is deleted
- BZ - 1740558 - The tuned pod doesn't set max virtual memory areas vm.max_map_count for elasticsearch pod in node.
- BZ - 1740559 - "many-to-many matching not allowed" for AlertmanagerConfigInconsistent rule
- BZ - 1740585 - jenkins-2-plugins: Updates for latest openshift-sync, openshift-client and workflow-cps
- BZ - 1740595 - [upgrade] servicemonitor for ingress is not updated after upgrading from 4.1.11 to 4.2
- BZ - 1740665 - [sriov] should use 'v1' instead of 'v1alpha2'
- BZ - 1740741 - Unexpected loss of pod hostports
- BZ - 1740748 - ubernetes: API server allows access to cluster-scoped custom resources as if resources were namespaced
- BZ - 1740933 - AWS 'destroy cluster' can leak resources due to races between cluster deletion and in-cluster resource creation
- BZ - 1741071 - [4.1.z]storage clusteroperator degraded reporting missing reason/detail information
- BZ - 1741119 - errors on events tab of node page
- BZ - 1741133 - DC doesn't adopt RCs
- BZ - 1741144 - inventory card: the lines that separate the rows should span the full width of the card
- BZ - 1741147 - When “By Storage” is selected, re-label the “X by Filesystem IO Time” title to “X by Average I/O Time”
- BZ - 1741149 - cluster overview dashboard -> top consumers card: “By CPU time” and “By Filesystem I/O Time” unit labels should be measured in nanoseconds
- BZ - 1741176 - Maintenance process should be driven by NodeMaintenance status
- BZ - 1741296 - Systems with multiple nics fail to boot/complete an install.
- BZ - 1741419 - Default storage class on OpenStack is using beta annotation is-default-class while aws/azure/gcp/vsphere is using stable version
- BZ - 1741422 - kubefed operator should install cluster scoped kubefed webhook in the "openshift-federation-system" namespace
- BZ - 1741432 - Should approve node csr before checking nodes to be ready
- BZ - 1741465 - AllowVolumeExpansion is enabled in default storage class for aws, but not for azure/gcp/openstack/vsphere.
- BZ - 1741468 - Set the cluster scoped kubefed controller manager as the default installation
- BZ - 1741470 - Group by lists should have divider and group labels together
- BZ - 1741473 - Create button on baremetal creation form should be in consistent style with other buttons
- BZ - 1741475 - OLM doesn't create new role for CLO when upgrading CLO from 4.1 to 4.2.
- BZ - 1741478 - Kubefed operator deployment scope does not match kubefed controller manager deployment scope
- BZ - 1741484 - Add --version parameter to webhook cmd and record the version into logs
- BZ - 1741532 - [ci] [azure] The HAProxy router should support reencrypt to services backed by a serving certificate automatically
- BZ - 1741534 - [ci] [azure] The HAProxy router should respond with 503 to unrecognized hosts
- BZ - 1741585 - remote-syslog error when the record has level=unknown
- BZ - 1741637 - [OSP] Installer prompts do not query for a required floating IP
- BZ - 1741645 - Telemetry should include the ClusterVersion conditions with reasons
- BZ - 1741663 - Fluentd single pod logging performance regression in 4.x
- BZ - 1741763 - [aws] Creating machine with invalid label results in panic
- BZ - 1741765 - [gcp] Failed to delete machine that has invalid zone
- BZ - 1741771 - [CPMA]cpma CLI needs an extra version flag to identity its version
- BZ - 1741773 - Insecure Traffic value is not correctly set when creating app by form
- BZ - 1741786 - CVO's default ClusterVersion races cluster-bootstrap pushing the installer's ClusterVersion
- BZ - 1741789 - duplicated templates shows when selecting all-projects project selector
- BZ - 1741797 - click on the alert or alert rule graph, it will slow down the browser
- BZ - 1741799 - The InstallPlan `source` field should NOT be empty
- BZ - 1741817 - After do certificate recovery the clusteroperator: machine-config will be degraded
- BZ - 1741821 - Usage Report table values are not shown correctly
- BZ - 1741822 - Request Header Identity provider configuration is not working
- BZ - 1741829 - [IPI] [OSP] system:node workers CSRs are pending to approve when cluster installation is finished
- BZ - 1741858 - Migration controller creation using OLM does not work with velero 1.1
- BZ - 1741955 - Increase OOTB kubeletConfig containerLogMaxSize
- BZ - 1742207 - enableUnidling flag under CNO doesn't work as expected on running cluster
- BZ - 1742744 - [ci][upgrade] Cluster upgrade fails because of machine config wedging
- BZ - 1742753 - Upgrade from 4.1 to 4.2 fails due to cloud-credential-operator
- BZ - 1742952 - cluster resource quota resource not visualized correctly
- BZ - 1743102 - Failing test: [sig-scheduling] SchedulerPreemption [Serial] validates pod anti-affinity works in preemption [Suite:openshift/conformance/serial] [Suite:k8s]
- BZ - 1743104 - Failing test: [sig-apps] Daemon set [Serial] should rollback without unnecessary restarts [Conformance] [Suite:openshift/conformance/serial/minimal] [Suite:k8s]
- BZ - 1743125 - Deploy pods failed to pull image in global proxy env
- BZ - 1743160 - machineconfig showing wrong ownerReferences kind for kubeletconfig
- BZ - 1743174 - Pod logs could not be accessed on proxy setting cluster
- BZ - 1743190 - [DR]Cluster crashed after etcd restored back to previous cluster state
- BZ - 1743194 - The Elasticsearch deployment disappear after cluster upgrade
- BZ - 1743257 - Monitoring operator is flapping the upgradeable status
- BZ - 1743302 - OpenStack, Kuryr: Fix conflicts with Octavia VRRP ports
- BZ - 1743314 - [RHHI.next] baremetal: installer uses wrong route IP for CACHEURL
- BZ - 1743345 - Uninstalling operator with csv contains the "clusterPermissions" field, related clusterrole, clusterrolebinding and sa can not be deleted
- BZ - 1743361 - Incorrect reporting in ClusterOperator
- BZ - 1743455 - console get error on polling promethus data against proxy enablement cluster
- BZ - 1743482 - local storage operator can not support "All namespaces on the cluster" installation mode
- BZ - 1743487 - duplicate error output can not be compressed for kubeletconfig
- BZ - 1743494 - A lot of information is missed for local storage operator
- BZ - 1743496 - Multus admission controller rejects NetworkAttachmentDefinitions with an empty config
- BZ - 1743507 - Should add internal registry address to noProxy globally
- BZ - 1743566 - Home->Explore->Access Review tab runtime error
- BZ - 1743610 - Cronjobs are not suspended when the migration is a quiesced migration
- BZ - 1743657 - ERR_TOO_MANY_RETRIES loop logging in to console
- BZ - 1743686 - Persistent volumes are not displayed correctly if we create more than one migration plan
- BZ - 1743725 - [4.2]monitoring clusteroperator degraded reporting missing reason/detail information
- BZ - 1743728 - 4.2.0-0.nightly-2019-08-19-161103 install completes with invalid URL for console on Azure
- BZ - 1743768 - Keepalived static pod cause to dentry cache increase to size of ~7GB
- BZ - 1743808 - Report metrics on installed operators
- BZ - 1743840 - Bootstrap etcd-signer lacks localhost cert, leading to: x509: certificate is valid for api..., not localhost
- BZ - 1743846 - MCD does not wait for nodes to drain
- BZ - 1743871 - [RHHI.next] baremetal: handle 409 conflict from Ironic in installer
- BZ - 1743873 - [ RHHI.next] baremetal: use openshift releases for ironic images
- BZ - 1743927 - Flaky tests: [Feature:ProjectAPI] TestProjectWatch should succeed [Suite:openshift/conformance/parallel]
- BZ - 1744002 - Disk Usage chart overflow in empty state
- BZ - 1744017 - proxy environment, "Service Unavailable" error in telemeter-client pod
- BZ - 1744029 - e2e flake: Failed to execute container related command like: logs, exec with error "tls: internal error"
- BZ - 1744049 - [AWS] machine-controller can not delete a machine when the machine's providerSpec is malformed
- BZ - 1744061 - [ci] [azure] Flaky test:The HAProxy router should serve routes that were created from an ingress
- BZ - 1744071 - [Disconnect]Can't import jenkins and other quay.io images which are included in payload.
- BZ - 1744111 - OCP 4.2 special resource operator (SRO) fails to deploy with nvidia-driver-validation Failed to allocate device vector A error
- BZ - 1744133 - Openstack : Haproxy events not logged to haproxy container after haproxy container recreated
- BZ - 1744153 - oc adm upgrade from 4.1.1 to 4.2.0-0.nightly-2019-08-21-040043 on loaded cluster stuck on marketplace-operator
- BZ - 1744167 - Need downstream NFD operator images built by ART
- BZ - 1744245 - Delete and recreate of a subscription object without delay should not cause operator install to fail.
- BZ - 1744297 - [Disruptive] Cluster upgrade should maintain a functioning cluster, "ClusterOperatorDegraded: Cluster operator insights is reporting a failure: Unable to report: gateway server reported unexpected error code: 415"
- BZ - 1744314 - Metering operator is calling a dated 'oauth-proxy' image
- BZ - 1744368 - ClusterOperator monitoring reports it is Available while alertmanager-main and prometheus-k8s stuck in Pending status
- BZ - 1744384 - openshift-apiserver pods do not remove proxy env vars after proxy/cluster removes proxy fields
- BZ - 1744422 - Kubelet when scheduling a busybox command that always fails in a pod should have an terminated reason
- BZ - 1744434 - [sig-storage] PersistentVolumes-local Stress with local volumes failed with err: timed out waiting for the condition
- BZ - 1744435 - test-cmd: error: --get-url test is borked
- BZ - 1744456 - [disconnected] rhel node worker can not be installed in a disconnected env
- BZ - 1744488 - The common users cannot use the resource provided by the 3rd level operator
- BZ - 1744490 - The icons disappear on operatorhub basic web page in the proxy cluster
- BZ - 1744532 - [Proxy]machine-config reporting Degraded is true
- BZ - 1744580 - MachineConfig updates cause unexpected results for static pod manifests
- BZ - 1744703 - The side navigation "Compute" section and "Bare Metal Hosts" subsection do not have active state when on the host details page and the create host page.
- BZ - 1744752 - MachineMAOMetricsDown is not firing when MAO is down
- BZ - 1744764 - [4.2]machine-config clusteroperator degraded reporting missing reason/detail information
- BZ - 1744893 - PVC should update the event after resizing finish successfully
- BZ - 1744908 - [Feature:Machines][Serial] Managed cluster should grow and decrease when scaling different machineSets simultaneously [Suite:openshift/conformance/serial]
- BZ - 1744929 - [sriov] sriov device plugin pod always recreated when created 3 or more sriovnetworknodepolicies with same priority
- BZ - 1744961 - node-tuning clusteroperator degraded reporting missing reason/detail information
- BZ - 1744965 - [Metrics] Ascending and descending sorting (by Value) doesn't work correct.
- BZ - 1745004 - [RHHI.next] baremetal: bootstrap ironic services sometimes fail on startup
- BZ - 1745050 - [ci] [gcp] Flaky test: The HAProxy router should serve routes that were created from an ingress
- BZ - 1745054 - [ci] [gcp] Flaky test: The HAProxy router should support reencrypt to services backed by a serving certificate automatically
- BZ - 1745057 - [ci] [gcp] Flaky test: The HAProxy router should respond with 503 to unrecognized hosts
- BZ - 1745240 - must-gather isn't collecting controllerconfig/machine-config-operator
- BZ - 1745418 - [Feature:Builds][Conformance] oc new-app should succeed with a --name of 58 characters [Suite:openshift/conformance/parallel/minimal]
- BZ - 1745485 - sometimes, the graph is disappeared from query browser page
- BZ - 1745493 - Imagestream cannot be imported in cluster which enables trusted CA for cluster proxy
- BZ - 1745497 - Can not select metrics if typed partially matched metrics with capital letters
- BZ - 1745532 - `oc get --ignore-not-found -f -` does not behave like `oc get --ignore-not-found kind/name.. `
- BZ - 1745567 - Project stuck in Terminating
- BZ - 1745571 - [DR][bare metal] Pod hang with container create error
- BZ - 1745626 - [olm] Address grpc-go CVEs
- BZ - 1745627 - [operator-regsitry] Address grpc-go CVEs
- BZ - 1745720 - e2e-gcp-serial: [sig-storage] CSI Volumes [Driver: pd.csi.storage.gke.io][Serial] tests are failing
- BZ - 1745767 - Machine-config-controller panic on pathological mirror configuration
- BZ - 1745772 - downloads pod doesn't respond to drain
- BZ - 1745807 - [Proxy]console operator reporting Available False
- BZ - 1745811 - OCP 4.2 - Azure image-registry pods in CrashLoopBackoff after cluster install
- BZ - 1745865 - Pods by Storage gives No datapoints found
- BZ - 1745875 - Failed to add RHEL worker behind proxy
- BZ - 1745877 - missed ")" for "Memory Usage (Swap" on grafana "Kubernetes / Compute Resources / Namespace (Pods)" page
- BZ - 1745907 - [upi-gcp] can not finish installation due to missing dns entry and lb for *.apps
- BZ - 1745909 - [upi-gcp] control plane needs to be added to lb before "Monitor for bootstrap-complete"
- BZ - 1745942 - [sriov] The soft link file 'latest' in manifest block the marketplace pod
- BZ - 1745946 - [Operator-registory]one wrong nest operator will impact the registory server pod
- BZ - 1745963 - Problems with service account in the controller
- BZ - 1745973 - Insights operator should not report "degraded" after one unsuccessful upload attempt
- BZ - 1745978 - [CPMA]ResouceQuota is generated a wrong apiVersion by cpma utility
- BZ - 1746015 - [osp] Machine couldn't be deleted
- BZ - 1746016 - [osp] machine-controller logs unuseful info
- BZ - 1746019 - [osp] Machines should have event
- BZ - 1746021 - [osp] Create a machine with invalid subnet, logs should output subnet is invalid
- BZ - 1746051 - [4.2]operator-lifecycle-manager/operator-lifecycle-manager-catalog clusteroperator degraded reporting missing reason/detail information
- BZ - 1746054 - Set limit on length of conditions in csv
- BZ - 1746097 - configmap of trusted-ca-bundle for alertmanager fails to be mounted in alertmanager pod
- BZ - 1746119 - Installer fails to create a cluster on GCP when using N2 machine type with allow_stopping_for_update set to false
- BZ - 1746155 - Image registry operator upgrade failure contributing to severe CI upgrade status
- BZ - 1746159 - upgrade from 4.1.9 to 4.1.11 failed by 'replicaset-controller Error creating: pods "packageserver-6474c74cdd-" is forbidden: error looking up service account openshift-operator-lifecycle-manager/packageserver: serviceaccount "packageserver" not found'
- BZ - 1746172 - Unrelated volumes could be counted by volume counting predicates
- BZ - 1746193 - Subscriptions to operator with multiple channels are not acted upon unless defaultChannel set for package
- BZ - 1746194 - Should deny create the `same` subscription in the same namespace
- BZ - 1746197 - Pods for marketplace CatalogSource and CatalogSourceConfig consuming large amounts of memory
- BZ - 1746199 - catalog-operator consumes 11GB RSS
- BZ - 1746230 - GCP: master machine objects missing target pools
- BZ - 1746270 - Unable to deprecate/remove a version from CRD if that version was previously storage version
- BZ - 1746329 - [sriov] NetworkAttachmentDefinition always be recreated even if it is exist after sriov operater is recreated
- BZ - 1746342 - Openshift-samples clusteroperator still reports avaliable true when set sampleoperator to Removed
- BZ - 1746360 - cluster-network-operator: openshift-sdn mode should not be required
- BZ - 1746375 - Use operator to rollout new openshift-apiserver on proxy CA change
- BZ - 1746377 - There should be more index pattern in kibana
- BZ - 1746459 - destroy-cluster sometimes fails to delete AWS snapshot
- BZ - 1746467 - The router in OCP4 accepts TLS1.0 and TLS1.1 connections with no way to disable them
- BZ - 1746499 - Attempts to push build output to external registry fail
- BZ - 1746521 - csr approver might not approve server csr
- BZ - 1746546 - Dashboard: Pods By CPU Time is inaccurate and displays a bizarre unit
- BZ - 1746671 - Web console should NOT be blank when installing operators even if something wrong in this operator
- BZ - 1746686 - telemeter client config reloader uses wrong port
- BZ - 1746687 - Faied to execute Migration operation since user cannot get replicationcontrollers.
- BZ - 1746695 - Normal users could not view project logs in Kibana.
- BZ - 1746706 - Edit environment will trigger warning alert for reloading current page info
- BZ - 1746715 - If an OpenShift username called "admin" exists then it should not get admin rights in Grafana
- BZ - 1746717 - [ci] [gcp] Managed cluster should should expose cluster services outside the cluster
- BZ - 1746736 - [ci] [aws-upi] Networking should provide Internet connection for containers
- BZ - 1746748 - [IPI] [OSP] After a correct installation, destroy command fails because of "FATAL Resource not found"
- BZ - 1746793 - Bump operators.coreos.com API version to v1
- BZ - 1746796 - `oc get all` outputs several empty lines
- BZ - 1746811 - [Operator-registory]"no bundle found" wrong operator will impact the load of the following operators packagemanifests
- BZ - 1746881 - Requests failures and TLS issues during tests
- BZ - 1746899 - MIG UI: Clicking the migration plan delete buton does not delete the plan.
- BZ - 1746925 - Custom logo file cant be found when SVG
- BZ - 1746926 - /etc/containers/registries.conf content extracted from cluster bootstrap ignition file needs to be decoded from base64
- BZ - 1746942 - spec.logLevel on openshiftapiservers/cluster has no effect on openshift-apiserver logging
- BZ - 1746966 - downloads route in openshift-console project should be edge/Redirect
- BZ - 1746968 - rsyslog and fluentd write /etc/hostname at startup, causes systemd-hostnamed to not start
- BZ - 1746970 - Failure migrating cronjobs with internal images
- BZ - 1747020 - csi-external-provisioner: the "--leader-election-namespace" argument is not supported
- BZ - 1747124 - etcd: can't build unsupported upstream arch
- BZ - 1747204 - e2e-aws-scaleup-rhel7 fails consistently
- BZ - 1747245 - [osp] Machine could be created successfully when label is not correct
- BZ - 1747246 - [osp] machine-api-controller pod stuck in CrashLoopBackOff
- BZ - 1747260 - openshift-apiserver-operator: "Deleted target configmap openshift-apiserver/trusted-ca-bundle because source config does not exist" log msg every 3s
- BZ - 1747343 - [ci][Azure] In-tree Volumes [Driver: ceph][Feature:Volumes] [Testpattern: Inline-volume (default fs)] subPath should support existing single file
- BZ - 1747366 - [proxy] Error while validating cloud credentials in proxy-enabled upi/aws install
- BZ - 1747376 - ASB and TSB operator pod create failed with "Error: container create failed: container_linux.go:345: starting container process caused "exec: \"/tini\": stat /tini: no such file or directory"
- BZ - 1747377 - CSI: attachable-volumes-csi-ebs.csi.aws.com=39 does not work for csi ebs driver
- BZ - 1747400 - Service Catalog faile to consume the CA in the proxy cluster
- BZ - 1747432 - missing terminationMessagePolicy: FallbackToLogsOnError in MCO containers
- BZ - 1747434 - Plugin-based NavItems are not highlighted as active on page refresh
- BZ - 1747474 - Dynamically provisioned storage doesn't work on OpenStack
- BZ - 1747480 - Authentication operator persistently rolls out oauth-openshift pods
- BZ - 1747519 - Installer gets stuck deleting owned VPCs on AWS when there are untagged subnets or security groups
- BZ - 1747575 - openshift-install 4.2 Azure does not install /etc/udev/rules.d/66-azure-storage.rules
- BZ - 1747608 - Worker nodes unable to communicate with cluster after applying updated api certs
- BZ - 1747840 - [Azure] the TTL for *.apps DNS record should not be zero on Azure platform
- BZ - 1747918 - Service plans tab page filter for CluserSerivceClass page will drag down web console
- BZ - 1747922 - Migration from openshifht 3.7 is stuck in EnsureQuiesced state
- BZ - 1747937 - [proxy]Cannot fetch https://rubygems.org/ when create build with ruby image in http_proxy cluster
- BZ - 1747950 - MachineSet and Machine tab should not select namespace
- BZ - 1748081 - When following disaster recovery procedure, if `INITIAL_CLUSTER` is not properly defined, `/usr/local/bin/etcd-snapshot-restore.sh` stops executing with no error message
- BZ - 1748150 - [ci] [sig-scheduling] SchedulerPreemption [Serial] Test Panicked: runtime error: invalid memory address or nil pointer dereference
- BZ - 1748174 - [CPMA]Failed to apply Github auth provider if one of organizations or teams not be specified in source cluster
- BZ - 1748210 - [4.2][oauth-proxy]OCP Images Allow Use of Ciphers Vulnerable to CVE-2016-2183 (Sweet32)
- BZ - 1748211 - UI should provide warning when node maintenance may impact cluster health
- BZ - 1748219 - Baremetal management UI should be disabled on non-baremetal cluster
- BZ - 1748271 - [HTTPS_PROXY] build met warning message about: MountVolume.SetUp failed when build in https_proxy cluster
- BZ - 1748280 - Updating customization for console logo will make the pod loop crash
- BZ - 1748309 - Migration from openshifht 3.7 is stuck in StagePodsCreated state
- BZ - 1748354 - Kuryr missing external_svc_net from configuration
- BZ - 1748372 - oc adm must-gather must prefix lines from stdout and stderr
- BZ - 1748405 - Unschedulable status is not reflected in the UI
- BZ - 1748436 - Must-gather does not collect information from the image registry
- BZ - 1748440 - Document possible concern of migrating UID range from source cluster to destination could lead to UID range overlap with namespaces
- BZ - 1748444 - Subscriptions without a sourceNamespace set hang forever without any failure status
- BZ - 1748501 - Admission plugins "unknown" during cluster configuration
- BZ - 1748638 - openshift-install 4.2 GCloud does not install /lib/udev/rules.d/65-gce-disk-naming.rules
- BZ - 1748682 - [disconnected] release-image.service failed in disconnected env which is blocking bootkube service boot up
- BZ - 1748771 - some icons of operators loading got 404 error
- BZ - 1748798 - [DR]Fail to re-adding etcd(etcd-member-add.sh) to cluster
- BZ - 1748799 - Ordering in Usage Report table will re-send getting report requests
- BZ - 1748807 - [Baremtal and Openstack] API LB supports maximum 2k concurrent connections
- BZ - 1748823 - Some reports data are not shown correctly and sorting doesn't work
- BZ - 1748844 - cluster creating too many eviction requests a second
- BZ - 1748855 - blank page returned when loading environment variable editor on deploy image page
- BZ - 1748914 - Drop the hard-coded DNS suffix from CatalogSources
- BZ - 1748927 - Migration stuck in ensurequiesced state
- BZ - 1749021 - Conflicts between PackageManifests with the same name from different sources on Console
- BZ - 1749036 - Operator Details view becomes flapping when an Operator does not have the proper permissions to run
- BZ - 1749075 - failed to send heartbeat for resource "8ccc9a07-ed5d-4584-b845-3773bc5da3ff":
- BZ - 1749131 - [OVN] Non-host-network pod is able to access the aws metadata
- BZ - 1749152 - When cluster operator object is deleted, samples operator does not restore the Degraded condition to status for 5+ minutes
- BZ - 1749199 - [CI][Console]Auth test.is authenticated as cluster admin user
- BZ - 1749209 - [IPI] [OSP] Kuryr - pods not getting annotated in Kuryr Controller due to watcher stopped
- BZ - 1749276 - OpenStack: Dynamically provisioned storage not removed when cluster destroyed
- BZ - 1749403 - OVN on Azure install fails
- BZ - 1749409 - not getting full list of necessary permissions before installation is attempted
- BZ - 1749446 - upgrade failure - openshift-sdn/sdn Daemonset is not available
- BZ - 1749451 - [4.2]Clusters must report a metric that includes number of cores separated by node-role label, os arch, os type, and os version
- BZ - 1749457 - Clusters must report a metric on whether masters are schedulable to telemetry
- BZ - 1749478 - KCM does not recover when its temporary secrets are deleted
- BZ - 1749557 - panic in image signature controller
- BZ - 1749581 - IngressController resource's scale subresource has incorrect label selector path
- BZ - 1749618 - Kibana pod failed to start: /opt/rh/rh-nodejs6/root/usr/bin/node: bad option: --max-http-header-size=65536
- BZ - 1749643 - Migration is failing when marketplace upgrade from 4.1.14 to 4.2.0-0.nightly-2019-09-04-142146
- BZ - 1749645 - Operation cannot be fulfilled on configmaps "trusted-ca-bundle" in openshift-apiserver namespaces
- BZ - 1749651 - [ci][openstack-serial] grow and decrease cluster failed when scaling different machineSets simultaneously
- BZ - 1749714 - [IPI] [OSP] sg-worker lack 1936/tcp(router) 9537/tcp(crio metrics) 9101/tcp(sdn metrics) for prometheus pods
- BZ - 1749816 - Document Known Issues and Beef Up Validation
- BZ - 1749890 - When deleting objects owned by the CVO, some components are not recreated for 30-40 minutes
- BZ - 1750269 - vSphere UPI: failed to initialize the cluster: Some cluster operators are still updating: authentication, console
- BZ - 1750281 - Query Browser takes the alert rule expression as query parameter by default
- BZ - 1750286 - Bootkube will report etcd cluster is up even all etcd-members are not ready
- BZ - 1750323 - [sriov] network-attachment-definitions should be sync by sriov operator when it was deleted
- BZ - 1750344 - Host dashboard metrics missing
- BZ - 1750433 - 1/3 etcd-member pods crashloopback
- BZ - 1750588 - Jenkins shows error instead of login screen after cluster upgrade from 4.1.11 to 4.1.13
- BZ - 1750610 - openshift-kube-apiserver pod spec is wrong for the loglevel flag -v
- BZ - 1750636 - [IPI] [OSP] Destroy cluster will not prune bootstrap fip if installation failed to wait for bootstrap to complete
- BZ - 1750654 - The phase message of csc won't change when the env changed
- BZ - 1750665 - Change default upload frequency from 10m to 2hrs
- BZ - 1750786 - RequestHeader IdP - `oc login` fails because oauth-server sets incompatible headers
- BZ - 1750790 - Custom logo volume mounts not set on the deployment when setting custom logo
- BZ - 1750851 - [gcp][serial][sig-autoscaling] [HPA] test failures
- BZ - 1750868 - All downstream 4.2 elasticsearch5 builds on brew since Sept. 5 are stuck in "building" state
- BZ - 1750906 - Can't scroll to the bottom of the Installed Operator list with an operator installed in all namespaces
- BZ - 1750926 - Disable the remaining [sig-storage] CSI Volumes CSI Topology test using GCE PD driver [Serial] tests
- BZ - 1750968 - [4.2] e2e-gcp-serial: [sig-storage] ... [Serial] tests are failing
- BZ - 1750980 - User modifications should be stomped on update
- BZ - 1750991 - [proxy]cluster-network-operator considers an https readiness endpoint invalid when using httpsProxy with http scheme
- BZ - 1751070 - NetworkAttachmentDefinition always be created in 'default' namespaces
- BZ - 1751084 - [ci] [aws]Kubernetes resource CRUD operations.PersistentVolumeClaim.displays a YAML editor for creating a new resource instance
- BZ - 1751147 - Authentication operator pods should have proxy env vars
- BZ - 1751260 - OLM release-1.0 installation deploys stable version instead of release 1.0 version
- BZ - 1751359 - Console crashed when switch to "Edit Form" view to create "Custom Resource" managed by the Operator
- BZ - 1751367 - local-storage tests that use gce-pd-ssd are failing
- BZ - 1751375 - Azure: Azure e2e/serial tests still report etcd server overloaded
- BZ - 1751571 - Bad request for "Disk Space" under "USE Method / Node" on grafana page
- BZ - 1751650 - [ASB] automationbroker can not be installed by openshift-ansible-service-broker-operator in OCP4.2
- BZ - 1751711 - External CSI provisioner creates volumes for in-tree storage class
- BZ - 1751767 - Starting the node maintenance produces an error in browser console
- BZ - 1751854 - Alerting: Deleting all text from Alert Manager YAML Editor causes it to disappear
- BZ - 1751905 - OpenShift 4.2 on Azure Installation Failed With Resource Deletion Error
- BZ - 1751954 - openshift-sdn: build release binaries without cgo
- BZ - 1751959 - When installing the GA of Service Mesh 1.0 on a vanilla IPI AWS 4.2 (nightly) the CPU settings for pilot prohibit the Pods starting
- BZ - 1752008 - multus: build binaries without cgo
- BZ - 1752023 - build ovn-kubernetes with cgo disabled.
- BZ - 1752027 - Warning message for unhealty Ceph in case of starting Maintenance contains not valid info
- BZ - 1752088 - Recovery e2e test hangs when cloud-controller pod is on machine that is chosen for deletion
- BZ - 1752132 - [GCP] e2e failure:[Feature:Builds][webhook] TestWebhook [Suite:openshift/conformance/parallel]
- BZ - 1752371 - [kuryr]etcd traffic from service subnet to master nodes blocked
- BZ - 1752395 - Could not mount azure file on ipi installed ocp
- BZ - 1752412 - cannot delete the '0' number for resource limit setting
- BZ - 1752453 - Multus no longer finds binaries in /opt/multus/bin
- BZ - 1752557 - [vSphere][UPI] Build tests fail with insufficient resources
- BZ - 1752572 - incorrect case shown for config maps and secrets keys
- BZ - 1752578 - [GCP] e2e failure: [sig-auth] ServiceAccounts should allow opting out of API token automount [Conformance] [Suite:openshift/conformance/parallel/minimal] [Suite:k8s]
- BZ - 1752581 - [GCP] e2e failure: [Feature:Builds][webhook] TestWebhookGitHubPushWithImageStream [Suite:openshift/conformance/parallel]
- BZ - 1752582 - [GCP] e2e failure: [Feature:UserAPI] groups should work [Suite:openshift/conformance/parallel]
- BZ - 1752831 - [Disconnect]Can't access jenkins console in disconnected env behind http proxy in aws platform
- BZ - 1752883 - Problems with push secret when using external images
- BZ - 1752905 - Kuryr unable to annotate pods in namespaces without `openshift.io/run-level` annotation
- BZ - 1752916 - must-gather doesn't collect config.imageregistry resource
- BZ - 1752979 - [GCP] e2e failure: "Failed to import expected imagestreams"
- BZ - 1752982 - [GCP] e2e failure: namespace is empty but is not yet removed
- BZ - 1752988 - e2e test does not verify all OLM resources are available
- BZ - 1753012 - [GCP] e2e failure: PV alerts firing
- BZ - 1753014 - Kuryr bootstrap not finishing due to API lbaas with ERROR status
- BZ - 1753018 - "UpdateStrategy" Descriptor is not taking/applying settings correctly
- BZ - 1753032 - vSphere UPI e2e add bootstrap gather
- BZ - 1753070 - Tests must allow skipping certain platform invariants to do node skew testing
- BZ - 1753091 - "504 Gateway Time-out" for all monitoring routes in http_proxy environment
- BZ - 1753152 - [CPMA] Oauth is skipped if Mapping field is missing
- BZ - 1753156 - [MSTR-829] kube-apiserver pod cannot access external https address after proxy CA is set
- BZ - 1753286 - VM Start, Stop and Migrate actions not available when any VM in a namespace is being imported
- BZ - 1753304 - [CPMA] Secret encoded twice
- BZ - 1753321 - Add additoinal reviewer to the project
- BZ - 1753411 - [IPI][BAREMETAL] namespace not created for kni static pods
- BZ - 1753494 - Failed to GET cluster-nfd-operator manifest from redhat-operators-art registry: Unauthorized access
- BZ - 1753536 - Node Feature Discovery operator install from redhat-operators-art stuck in UpgradePending
- BZ - 1753672 - Setting HTTP_PROXY, HTTPS_PROXY or NO_PROXY wont rollout console deployment
- BZ - 1753871 - NFD operand pods crash looping after install from OperatorHub: version not set!
- BZ - 1753886 - Stop authentication operator stomping its own route
- BZ - 1753932 - [IPI][OSP] [Feature:Platform][Smoke] Managed cluster should ensure control plane pods do not run in best-effort QoS [Suite:openshift/conformance/parallel] fails
- BZ - 1753988 - [Upgrade]node become not ready since the "CNI network "" not found"
- BZ - 1753995 - [4.2] No pod failover when multiple nodes are NotReady cherrypick
- BZ - 1753997 - volumeMode is not passed when cloning a DataVolume
- BZ - 1754045 - Jenkins shows error instead of login screen after cluster upgrade from 4.1.11 to 4.1.13
- BZ - 1754115 - [IPI][OpenStack]: Support Boot from Volume
- BZ - 1754186 - Move extended build tests from ruby:2.x to ruby:2.5
- BZ - 1754638 - Missing CNI default network
- BZ - 1754825 - "Permission denied" when access mounted dir with azure file volume
- BZ - 1755044 - Memory leak CRIO due to no garbage collection in /run/crio/exits for exited containers
- BZ - 1755125 - Schema change in ClusterResourceQuota from 4.1 to 4.2 results in breakage
- BZ - 1756109 - I see expected channel results for OLM 4.2.0 channels
- BZ - 1756141 - New IngressController operator API field incorrectly marked optional in OpenAPI spec
- BZ - 1756166 - Route with 2 named ports sends traffic to wrong one with the correct one is down [4.2]
- BZ - 1756283 - [sriov] sriov operator tag should be use 4.2 not latest
- BZ - 1756454 - User upgrading a cluster from 4.1 to 4.2 before official release may bypass security protection
- BZ - 1757124 - [IPI][OpenStack] Intermittent DNS errors for ingress records within the pods
- BZ - 1757222 - [Docs] Document known issue of imagestreams in openshift namespace are not handled with migrations.
- BZ - 1757487 - [Docs] Backup creation fails for a project with 1000Gi pvc
- BZ - 1757858 - After logging upgraded, new elasticsearch deployment object recreated with new pvc
- BZ - 1757918 - [DOCS] CORS configuraiton documentation has changed in 4.2
- BZ - 1758312 - Bump boot images to pick up signed RPMs
- BZ - 1758632 - Web UI is not accessible when migration operator is installed using OLM
- BZ - 1759122 - Upgrading a managed cluster from 4.1.18 to 4.2.0-rc.1 results in CCO CA cert issues
- BZ - 1759146 - `rhcos.json` referenced by installer is pointing at internal-only URL for the `baseURI`
- BZ - 1759245 - [proxy] Need to add "metadata.google.internal." to noProxy list on GCP
- BZ - 1759253 - [proxy] Need to add "metadata.google.internal." to noProxy list on GCP
- BZ - 1759966 - GCP backend for api server has incorrect ranges allowed for heath checks
- BZ - 1760497 - Update available channels in UI for 4.2 release
- BZ - 1760859 - upgrade.yml playbook didn't update cri-o package during upgrade
- BZ - 1760873 - [UPI][BAREMETAL] RHCOS 4.2 installation does not work when trying to use a secondary disk for /var/lib/containers
参考
(none)
Red Hat 安全团队联络方式为 secalert@redhat.com。 更多联络细节请参考 https://access.redhat.com/security/team/contact/。