- Issued:
- 2021-08-11
- Updated:
- 2021-08-11
RHBA-2021:3135 - Bug Fix Advisory
Synopsis
Red Hat OpenShift Container Storage 4.7.3 bug fix update
Type/Severity
Bug Fix Advisory
Topic
Updated images that fix several bugs are now available for Red Hat OpenShift Container Storage 4.7.3 on Red Hat Enterprise Linux 8 from Red Hat Container Registry.
Description
Red Hat OpenShift Container Storage is software-defined storage integrated with and optimized for the Red Hat OpenShift Container Platform. Red Hat OpenShift Container Storage is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Container Storage provisions a multicloud data management service with an S3 compatible API.
This advisory fixes the following bugs:
- The time threshold is defined by the ceph configuration parameter `osd_op_complaint_time`. This alert is important to notify OpenShift Container Storage administrators about the slow operations which can be an indication of extreme load, a slow storage device, or a software bug. (BZ#1966139)
- Previously, the encrypted RBD PVC creation failed due to failure in parsing the connection parameters for a Hashicorp Vault KMS. Since initializing of a Hashicorp Vault KMS as a store for PV encryption passphrases failed and volumes that wanted to use Hashicorp Vault to store/retrieve PV encryption passphrases could not be created, existing volumes could not be used. This update fixes the parsing of the Vault connection parameters, resulting in initializing of the KMS connection, successful storing and retrieving of PV encryption passphrases from Hashicorp Vault. (BZ#1979604)
- This feature allows configuring of the `VAULT_BACKEND` parameter for selecting the type of backend used by Hashicorp Vault. The autodetection of the backend used by Hashicorp Vault is not always working as expected. In case, if a non-common configuration is used, the automatically detected configuration parameter might be set incorrectly. By allowing users to configure the `VAULT_BACKEND` (or `vaultBackend`) parameter, non-common configurations can now be forced to use a particular type of backend. (BZ#1983931)
- Previously, during Object Bucket Claim creation failure, `lib-bucket-provisioner` would send a delete request to the provisioned for cleanup purposes before retrying. Noobaa provisioner was looking at the reclaim policy of the Object Bucket and in some cases did not delete the underlying bucket. Leading to buckets not getting deleted during cleanup flows. This update fixes the cleanup scenarios where the underlying bucket should have been deleted regardless of the reclaim policy. This is also the expected behavior in the `lib-bucket-provisioner` docs. The condition checking the reclaim policy before deleting was removed to fix this issue. (BZ#1959331)
- Previously, the `must-gather-helper` pod creation failed and skipped the ceph collections. This was caused by due to incorrect YAML deployment. This update fixes the selection of correct deployment YAML resulting in creating and running the `must-gather-helper` pod successfully. (BZ#1979155)
Users of Red Hat OpenShift Container Storage are advised to upgrade to these updated images, which fixes these bugs.
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
Affected Products
- Red Hat OpenShift Data Foundation 4 for RHEL 8 x86_64
- Red Hat OpenShift Data Foundation for IBM Power, little endian 4 for RHEL 8 ppc64le
- Red Hat OpenShift Data Foundation for IBM Z and LinuxONE 4 for RHEL 8 s390x
Fixes
- BZ - 1966139 - [RFE] Add Slow Ops alert
- BZ - 1979155 - [4.7 clone] must-gather-helper pod fails to come up on ODF Managed Services setup, hence no ceph collection succeeds
- BZ - 1979604 - Creation of encrypted RBD PVC fails in OCS 4.7.2
- BZ - 1983931 - [RFE] VAULT_BACKEND parameter should be added to the csi-kms-connection-details
- BZ - 1984751 - Update to RHCS 4.2z2-async Ceph container image at OCS 4.7.3
CVEs
References
(none)
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.