- Issued:
- 2021-05-19
- Updated:
- 2021-05-19
RHBA-2021:1550 - Bug Fix Advisory
Synopsis
OpenShift Container Platform 4.7.11 bug fix update
Type/Severity
Bug Fix Advisory
Topic
Red Hat OpenShift Container Platform release 4.7.11 is now available with
updates to packages and images that fix several bugs and add enhancements.
Description
Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.
This advisory contains the container images for Red Hat OpenShift Container
Platform 4.7.11. See the following advisory for the RPM packages for this
release:
https://access.redhat.com/errata/RHSA-2021:1551
Space precludes documenting all of the container images in this advisory.
See the following Release Notes documentation, which will be updated
shortly for this release, for details about these changes:
https://docs.openshift.com/container-platform/4.7/release_notes/ocp-4-7-rel ease-notes.html
You may download the oc tool and use it to inspect release image metadata
as follows:
(For x86_64 architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.7.11-x86_64
The image digest is
sha256:8c3f5392ac933cd520b4dce560e007f2472d2d943de14c29cbbb40c72ae44e4c
(For s390x architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.7.11-s390x
The image digest is
sha256:3755ab525f572d5ff24dfdbed56ddc6d7b5cacbcdd26960991e5764e181bceba
(For ppc64le architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.7.11-ppc64le
The image digest is
sha256:8e8bde4754783f95563177db73b4fbefa5648b888660ace79de0cc25a11cc8f4
All OpenShift Container Platform 4.7 users are advised to upgrade to these
updated packages and images when they are available in the appropriate
release channel. To check for available updates, use the OpenShift Console
or the CLI oc command. Instructions for upgrading a cluster are available
at
https://docs.openshift.com/container-platform/4.7/updating/updating-cluster
- between-minor.html#understanding-upgrade-channels_updating-cluster-between
- minor
Solution
For OpenShift Container Platform 4.7 see the following documentation, which
will be updated shortly for this release, for important instructions on how
to upgrade your cluster and fully apply this asynchronous errata update:
https://docs.openshift.com/container-platform/4.7/release_notes/ocp-4-7-release-notes.html
Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.7/updating/updating-cluster-cli.html
Affected Products
- Red Hat OpenShift Container Platform 4.7 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform for Power 4.7 for RHEL 8 ppc64le
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.7 for RHEL 8 s390x
Fixes
- BZ - 1908295 - Fix pipeline builder form yaml switcher validation issue
- BZ - 1919693 - [Tracker] Hung tasks on Single Node Openshift running realtime kernel
- BZ - 1929066 - kuryr-controller restart when enablePortPoolsPrepopulation = true
- BZ - 1932383 - [Migration]The SDN migration rollback failed.
- BZ - 1937097 - Add retries to opm index add
- BZ - 1939225 - message: "Clusters with less than 3 dedicated masters or a single worker are not supported" suggests that we support more than 3
- BZ - 1939488 - [4.7z] need ability to reconcile exgw annotations on pod add
- BZ - 1940005 - GCP PD CSI driver does not have CSIDriver instance
- BZ - 1940034 - cluster-resource-override: fix spelling mistake for run-level match expression in webhook configuration
- BZ - 1941214 - openshift-sdn/ovs DaemonSet should use maxUnavailable: 10%
- BZ - 1941840 - Intermittent apiserver and authentication cluster operator instability on OSD GCP cluster build with OVN
- BZ - 1941941 - [kuryr] Egress network policy with namespaceSelector in Kuryr behaves differently than in OVN-Kubernetes
- BZ - 1942027 - PersistentVolume yaml editor is read-only with system:persistent-volume-provisioner ClusterRole
- BZ - 1944955 - Close button (X) does not work in the new "Storage cluster exists" Warning alert message(introduced via fix for Bug 1867400)
- BZ - 1945594 - Consistant fallures of features/project-creation.feature Cypress test in CI
- BZ - 1945907 - [aws] support byo iam roles for instances
- BZ - 1947372 - Openshift 4.5.8 Deleting pv disk vmdk after delete machine
- BZ - 1948369 - Query is reporting "no datapoint" when label cluster="" is set but work when the label is removed or when running directly in Prometheus
- BZ - 1948702 - unneeded CCO alert already covered by CVO
- BZ - 1948958 - Ingress details page doesn't show referenced secret name and link
- BZ - 1949139 - Both old and new Clusterlogging CSVs stuck in Pending during upgrade
- BZ - 1949551 - kuryr-controller restarting after 3 days cluster running - pools without members
- BZ - 1949941 - create an information alert about the old-format tokens being unusable starting 4.8
- BZ - 1950131 - Egress Firewall does not reliably apply firewall rules
- BZ - 1950214 - Fix incorrect access review check on start pipeline kebab action
- BZ - 1950489 - The referred role doesn't exist if create rolebinding from rolebinding tab of role page
- BZ - 1950498 - Some on-prem namespaces missing from must-gather
- BZ - 1950926 - (release-4.7) Extend the OLM operator gatherer to include CSV display name
- BZ - 1951064 - [4.7z] OVN-Kube Master does not release election lock on shutdown
- BZ - 1951232 - Resolution fails to sort channel if inner entry does not satisfy predicate
- BZ - 1951571 - registry.svc.ci.openshift.org is no longer valid
- BZ - 1951657 - etcd consuming high amount of memory and CPU after upgrade to 4.6.17
- BZ - 1951815 - Reduce number of kubelet WATCH requests
- BZ - 1952209 - Inconsistency of time formats in the OpenShift web-console
- BZ - 1952293 - OKD 4.7 unable to access Project Topology View
- BZ - 1952578 - Console continues to poll the ClusterVersion resource when the user doesn't have authority
- BZ - 1952614 - Tracking bug for OCPCLOUD-1115 - support user-defined tags on AWS EC2 Instances
- BZ - 1952851 - Marketplace extract container does not request CPU or memory
- BZ - 1953071 - [4.7] ImagePullBackOff: Source image rejected: Too many open files
- BZ - 1953097 - CoreDNS resolution failure for external hostnames with "A: dns: overflow unpacking uint16"
- BZ - 1953579 - (release-4.7) Insights operator should collect related pod logs when operator is degraded
- BZ - 1953609 - CoreDNS's "errors" plugin is not enabled for custom upstream resolvers
- BZ - 1953707 - cannot upgrade openshift-kube-descheduler from 4.7.2 to latest
- BZ - 1953728 - Fix issues related to loading dynamic plugins
- BZ - 1953937 - PVC create page is breaking
- BZ - 1954073 - When setting etcd spec.LogLevel is not propagated to etcd operand
- BZ - 1954097 - [release-4.7] Tracking bug for NE-563 - support user-defined tags on AWS load balancers
- BZ - 1954152 - in-cluster operators need an API for additional AWS tags
- BZ - 1954610 - Default image for GCP does not support ignition V3
- BZ - 1954803 - [4.7] [aws] support byo private hosted zone
- BZ - 1955231 - kubelet service takes around 43 secs to start container when started from stopped state
- BZ - 1955476 - [Backport 4.7]Add vsphere_node_hw_version_total metric to the collected metrics
- BZ - 1955502 - [4.7] openshift-apiserver degraded after installing Stackrox [SCC]
- BZ - 1955669 - release-openshift-origin-installer-old-rhcos-e2e-aws-4.7 is permfailing
- BZ - 1956216 - Placeholder bug for OCP 4.7.0 rpm release
- BZ - 1956217 - Placeholder bug for OCP 4.7.0 extras release
- BZ - 1956218 - Placeholder bug for OCP 4.7.0 metadata release
- BZ - 1956313 - Console Devfile Import Dev Preview broken
- BZ - 1956318 - [4.7z] Need support external gateway via hybrid overlay
- BZ - 1956336 - [release-4.7] Event Listener Details page does not show Triggers section
- BZ - 1956352 - CNO must handle single-stack to dual-stack migration
- BZ - 1956749 - Openshift-apiserver CO unavailable in fresh OCP 4.7.5 installations
- BZ - 1957015 - [IPI baremetal] Two nodes hold the VIP post remove and start of the Keepalived container
- BZ - 1957646 - thanos-ruler pods failed to start up for "cannot unmarshal DNS message"
- BZ - 1958428 - aws: support more auth options in manual mode
- BZ - 1958518 - openshift-install 4.7.10 fails with segmentation error
CVEs
References
(none)
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.