- Issued:
- 2021-02-24
- Updated:
- 2021-02-24
RHBA-2021:0652 - Bug Fix Advisory
Synopsis
Errata Advisory for Openshift Logging 5.0.0
Type/Severity
Bug Fix Advisory
Topic
Features and Bugs for Logging 5.0 version
Description
You use the Red Hat OpenShift Logging product to forward, store, and visualize log data from your cluster.
Release notes for the bugs fixed in this update are available in the OpenShift Logging Release Notes:
https://docs.openshift.com/container-platform/4.7/logging/cluster-logging-release-notes.html
Solution
For OpenShift Container Platform 4.7 see the following documentation, which
will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:
https://docs.openshift.com/container-platform/4.7/release_notes/ocp-4-7-release-notes.html
For Red Hat OpenShift Logging 5.0, see the following instructions to apply this update:
https://docs.openshift.com/container-platform/4.7/logging/cluster-logging-upgrading.html
Affected Products
- Red Hat OpenShift Container Platform 4.7 for RHEL 8 x86_64
Fixes
- BZ - 1845293 - Elasticsearch returning too_long_frame_exception when calling endpoints through external route after logging workload
- BZ - 1877906 - Remove --setopt=tsflags=nodocs from images
- BZ - 1877968 - Reduce log chatter in cluster logging operator
- BZ - 1879150 - Changes on spec.logStore.elasticsearch.nodeCount not reflected when decreasing the number of nodes
- BZ - 1881709 - elasticsearch-delete and elasticsearch-rollover pods hanging
- BZ - 1883444 - Performance tweaking for Elasticsearch
- BZ - 1883719 - Alert ElasticsearchBulkRequestsRejectionJumps never gets pending/firing due to there is no `bulk` thread pool.
- BZ - 1884477 - Provide up2date bundles for both cluster-logging-operators
- BZ - 1884812 - When ES starts up, it displays warnings regarding cert permissions
- BZ - 1885674 - Init container for fluentd failing due to certs
- BZ - 1885723 - Old kibana index causing crashloop
- BZ - 1886796 - The EO can't recreate ES deployments after upgrade cluster from 4.5 to 4.6
- BZ - 1886856 - The ES proxy container always restarts.
- BZ - 1886907 - Flood stage wateremark alert: Remove wording that read-only index block is auto-released
- BZ - 1887357 - ES pods can't recover from `Pending` status.
- BZ - 1887361 - Logging images missing in 4.7
- BZ - 1888420 - Collectors are missing metric for input sources
- BZ - 1888943 - ClusterLogForwarder with Output.Secret causes fluentd crash loop
- BZ - 1888958 - certificates are regenerated only when crt is missing.
- BZ - 1889573 - The EO CrashLoopBackOff after update the kibana resource configurations in clusterlogging instance.
- BZ - 1890072 - Log forwarding API with multiple outputs same secret cause issues
- BZ - 1890825 - Kibana Route not recreated after deletion
- BZ - 1890838 - Sometimes the elasticsearch-delete-xxx job failed at "Unexpected exception indices:admin/aliases/get"
- BZ - 1891666 - Should use OCP rather than OKD in description
- BZ - 1891738 - The CLO shouldn't depend on EO resources when deploy collector only clusterlogging instance
- BZ - 1891886 - LF GA syslog ( for RFC 3164 ) implementation incompatible with supported legacy feature
- BZ - 1892002 - Elasticsearch Operator is unable to update ES pods when they are in crashloopbackoff state
- BZ - 1892755 - Update Elasticsearch dashboard (metrics)
- BZ - 1893992 - Elasticsearch rollover pods failed with resource_already_exists_exception
- BZ - 1894634 - Fluent stops sending logs even though logging stack seems functional
- BZ - 1895581 - Unable to create 'app' index pattern in OpenShift Logging 4.5 when permissions are granted via group
- BZ - 1897731 - logging must gather should use fully qualified resource names
- BZ - 1898920 - Change ES Operator CSV to clarify the scope for this Operator
- BZ - 1899441 - Remove username/password from fluent conf
- BZ - 1899589 - panic observed in elasticsearch operator logs
- BZ - 1899905 - elasticsearch-rollover and elasticsearch-delete pods are in error states with 'ValueError: No JSON object could be decoded'
- BZ - 1900772 - Enable cluster admin to get complete mappings for indices
- BZ - 1901096 - fluentforward inability to connect blocks fluent pods from starting
- BZ - 1901424 - Kibana pod gets created even if the replicas are set to 0 when deploying fluentd stand-alone
- BZ - 1901505 - [logforward]error_class=ArgumentError error="time must be a Fluent::EventTime (or Integer): Float"
- BZ - 1901869 - The master-cert couldn't be regenerated
- BZ - 1903784 - The CLO swallows some errors associated with deploying managed storage
- BZ - 1903912 - Fluentd Pods remain Init:CrashLoopBackOff status when deploying fluentd standalone
- BZ - 1904071 - fluentd chunkLimitSize wrong values echoed
- BZ - 1905910 - Elasticsearch cluster can't be fully upgraded after upgrade from elasticsearch-operator.4.7.0-202012080225.p0 to elasticsearch-operator.4.7.0-202012082225.p0
- BZ - 1906765 - Access to the ES root url / from a project's pod on Openshift
- BZ - 1906895 - Elasticsearch Operator 4.7 csv missing wording for ECK and does not have 5.0 csv
- BZ - 1907758 - Facing error "Cannot authenticate user because admin user is not permitted to login via HTTP" in OCP 4.5.20
- BZ - 1908707 - fluentd fails to deliver message with Server returned nothing (no headers, no data)
- BZ - 1908958 - ElasticsearchClusterNotHealthy Is Red alert is noisy
- BZ - 1910259 - Missing Logging/Elasticsearch dashboard.
- BZ - 1912208 - ose-elasticsearch-proxy@dummy-sha in openshift-ose-elasticsearch-operator-bundle:v5.0.0
- BZ - 1913443 - Rename filename of prometheus recording file to match its content
- BZ - 1913464 - Elasticsearch Operator does not report on csv success
- BZ - 1913469 - Need link to the troubleshooting page of elasticsearch cluster when alert occurs
- BZ - 1917703 - [Logging 5.0] use catalog image name in CSV
- BZ - 1918876 - Kibana message: "Payload content length greater than maximum allowed"
- BZ - 1920215 - Elasticsearch Operator performs unnecessary index template seeding which can impact cluster performance
- BZ - 1925081 - The user token in kibana logs for logging.quiet: false
CVEs
(none)
References
(none)
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.