- Issued:
- 2020-02-19
- Updated:
- 2020-02-19
RHBA-2020:0492 - Bug Fix Advisory
Synopsis
OpenShift Container Platform 4.3.2 bug fix update
Type/Severity
Bug Fix Advisory
Topic
Red Hat OpenShift Container Platform release 4.3.2 is now available with
updates to packages and images that fix several bugs.
Description
Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.
This advisory contains the container images for Red Hat OpenShift Container
Platform 4.3.2. See the following advisory for the RPM packages for this
release:
https://access.redhat.com/errata/RHBA-2020:0491
Space precludes documenting all of the container images in this advisory.
See the following Release Notes documentation, which will be updated
shortly for this release, for details about these changes:
https://docs.openshift.com/container-platform/4.3/release_notes/ocp-4-3-release-notes.html
You may download the oc tool and use it to inspect release image metadata
as follows:
$ oc adm release info quay.io/openshift-release-dev/ocp-release:4.3.2-x86_64
The image digest is sha256:cadf53e7181639f6cc77d2430339102db2908de330210c1ff8c7a7dc1cb0e550
All OpenShift Container Platform 4.3 users are advised to upgrade to these
updated packages and images.
Solution
Before applying this update, ensure all previously released errata relevant
to your system have been applied.
For OpenShift Container Platform 4.3 see the following documentation, which
will be updated shortly for release 4.3.2, for important instructions on
how to upgrade your cluster and fully apply this asynchronous errata
update:
https://docs.openshift.com/container-platform/4.3/release_notes/ocp-4-3-release-notes.html
Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.3/updating/updating-cluster-cli.html.
Affected Products
- Red Hat OpenShift Container Platform 4.3 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform 4.3 for RHEL 7 x86_64
Fixes
- BZ - 1776082 - There is no "olm.skipRange" in ptp-operator csv
- BZ - 1779469 - Regression: [sig-network] Networking Granular Checks: Services should function for endpoint-Service: udp [Suite:openshift/conformance/parallel] [Suite:k8s] [Skipped:Network/OVNKubernetes]
- BZ - 1782574 - [4.3] local-storage-operator should not be installable in Openshfit-4.1
- BZ - 1782972 - Openshift installed with FIPS enabled cause exception in ansible module `
- BZ - 1783312 - Only the first occurrence of a console log link variable gets replaced
- BZ - 1784569 - [4.3.z] Service Account Pull Secrets Include IPv6 Addresses
- BZ - 1785291 - [4.3.z] Deprecate Jenkins Pipeline Strategy
- BZ - 1785492 - Normal user can't see Samples, Snippets tab in YAML sidebar
- BZ - 1787343 - Deletion of Network Policies enforced on same pod cause controller restart
- BZ - 1788062 - IPI on OpenStack fails with 'Security group rule already exists' error when OpenStack Neutron is under heavy load
- BZ - 1788065 - Remove EOL SCL images from Samples Operator
- BZ - 1788201 - Support Pipeline Operator 0.9.0
- BZ - 1788208 - Meteringconfig failed during ansible setup to gernate RSA private key with Openshift having FIPS enabled.
- BZ - 1788635 - Kuryr detecting Octavia version incorrectly
- BZ - 1789124 - Router doesn't listen on ipv6 interfaces when cluster network config indicates ipv6 support
- BZ - 1789150 - YAML snippets aren't showing up when editing resources, only on create
- BZ - 1789330 - Iteration problems on for loops
- BZ - 1789748 - [Kuryr] Cluster destroy command timesout
- BZ - 1790339 - LoadBalancer security groups not found on OSP16 deployments
- BZ - 1790523 - [4.3] dual-stack config for openshift-apiserver
- BZ - 1790750 - Metrics table rows pagination contains off by one bug [openshift-4.3]
- BZ - 1790805 - [4.3] No new ovs flows add to table 80 after restart sdn pod and create a allow-all networkpolicy
- BZ - 1791101 - Normal user cannot see and use installed operators [openshift-4.3]
- BZ - 1792240 - NetworkPolicyHandler: KeyError when deleting a network policy
- BZ - 1792419 - Cancelled Pipeline Runs Show As Failed
- BZ - 1792507 - candidate-4.3 channel missing from 4.3 console [openshift-4.3]
- BZ - 1793253 - HAProxy network infra pods fail to listen on IPv6 addresses
- BZ - 1794548 - Console and console operator should support IPv6 [openshift-4.3]
- BZ - 1796108 - back port IBM Cloud Platform into 4.3 (original PR: https://github.com/openshift/api/pull/557)
- BZ - 1796440 - ETCD backups should keep keys and data separate
- BZ - 1796822 - [OSP] allow retrieval of ignition files from behind an encrypted endpoint which uses a self-signed certificate
- BZ - 1797678 - OCP 4.3 - Node Feature Discovery (NFD) nfd-operator fails to deploy from CLI and github repo
- BZ - 1798060 - debugging issues with the bootstap host is hard because it's automatically removed
- BZ - 1798107 - [4.3] toolbox fails to pull registry.redhat.io/rhel8/support-tools in an environment with HTTP/HTTPS Proxy
- BZ - 1798667 - unknown field "passwd" in io.openshift.machineconfiguration.v1.MachineConfig.spec.config
- BZ - 1798789 - Ingress-operator fails without route53 privileges
- BZ - 1800324 - [4.3] Networking not working on default namespace
- BZ - 1800513 - Generate test fails when updating deps
- BZ - 1800662 - [4.3.z] Build tests fail using outdated image
CVEs
References
(none)
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.