- 发布:
- 2020-09-22
- 已更新:
- 2020-09-22
RHBA-2020:3715 - Bug Fix Advisory
概述
OpenShift Container Platform 4.4.23 bug fix update
类型/严重性
Bug Fix Advisory
标题
Red Hat OpenShift Container Platform release 4.4.23 is now available with
updates to packages and images that fix several bugs.
描述
Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.
This advisory contains the container images for Red Hat OpenShift Container
Platform 4.4.23. See the following advisory for the RPM packages for this
release:
https://access.redhat.com/errata/RHBA-2020:3716
Space precludes documenting all of the container images in this advisory.
See the following Release Notes documentation, which will be updated
shortly for this release, for details about these changes:
https://docs.openshift.com/container-platform/4.4/release_notes/ocp-4-4-release-notes.html
This update fixes the following bugs among others:
- Previously, CoreDNS 1.6.6 caused intermittent `invalid memory address or nil pointer dereference` errors, followed by timeouts in Kubernetes API access. With this release, an update to CoreDNS that fixes endpoint tombstone handling errors is backported to OpenShift Container Platform to resolve the issue. (BZ#1869310)
- Previously, the Image Registry Operator prematurely reported a healthy status if jobs were running. A running job is not a dependable indicator that the Operator is truly healthy, because the job might eventually fail. With this release, the Operator ignores running jobs when determining its health status and instead relies on the status of the last finished job for more accurate reporting. (BZ#1873534)
You may download the oc tool and use it to inspect release image metadata
as follows:
(For x86_64 architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.4.23-x86_64
The image digest is sha256:0455e0201f475a836f2474d4af7864a55208a33eb6932027f63109bbbd821b65
(For s390x architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.4.23-s390x
The image digest is sha256:58ac31981251add2f5f274aa1e7e6f9e637257f34cbab90ca26b8479e6448a9d
(For ppc64le architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.4.23-ppc64le
The image digest is sha256:275b866185e7e2758ed14cfa563cbd1d1208b51972232b5ac3281c08813ba30a
All OpenShift Container Platform 4.4 users are advised to upgrade to these
updated packages and images when they are available in the appropriate
release channel. To check for available updates, use the OpenShift Console
or the CLI oc command. Instructions for upgrading a cluster are available
at
https://docs.openshift.com/container-platform/4.4/updating/updating-cluster-between-minor.html#understanding-upgrade-channels_updating-cluster-between-minor.
解决方案
For OpenShift Container Platform 4.4 see the following documentation, which
will be updated shortly for this release, for important instructions on how
to upgrade your cluster and fully apply this asynchronous errata update:
https://docs.openshift.com/container-platform/4.4/release_notes/ocp-4-4-release-notes.html
Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.4/updating/updating-cluster-cli.html.
受影响的产品
- Red Hat OpenShift Container Platform 4.4 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform 4.4 for RHEL 7 x86_64
- Red Hat OpenShift Container Platform for Power 4.4 for RHEL 8 ppc64le
- Red Hat OpenShift Container Platform for Power 4.4 for RHEL 7 ppc64le
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.4 for RHEL 8 s390x
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.4 for RHEL 7 s390x
修复
- BZ - 1823709 - `oc explain network-attachment-definitions` returns empty description
- BZ - 1847524 - "downloads" pod does not work on the node which is disabled IPv6
- BZ - 1849322 - Recreating recently deleted NodePort service results in 'port is already allocated' error
- BZ - 1851095 - subscription_sync_total metric potentially not getting removed
- BZ - 1861221 - [sriov] [4.4.z] sriovnetworknodestates cannot be restored if it was deleted
- BZ - 1865889 - unable to recognize no matches for kind "servicemonitor.monitoring.coreos.com" in version "monitoring.coreos.com/v1"
- BZ - 1869310 - CoreDNS pods observing panic without any provbe failures
- BZ - 1870869 - [4.4] OCP 4.4.5: intermittent traffic failures with OVNKubernetes
- BZ - 1871832 - APIServerServiceUnavailableErrorjava error makes ImageChangesInProgress keeping true that blocked the upgrade processed
- BZ - 1873383 - [4.4] Need to upgrade host and kernel-rt layer atomically
- BZ - 1873534 - operator interprets running pruning job as success
- BZ - 1875381 - Pipeline Conditions WhiteScreen the Log View
CVE
参考
(none)
Red Hat 安全团队联络方式为 secalert@redhat.com。 更多联络细节请参考 https://access.redhat.com/security/team/contact/。