- Issued:
- 2025-08-07
- Updated:
- 2025-08-07
RHEA-2025:13453 - Product Enhancement Advisory
Synopsis
Red Hat OpenShift GitOps enhancement update
Type/Severity
Product Enhancement Advisory
Topic
Red Hat OpenShift GitOps v1.17.0 release
Description
An update is now available for Red Hat OpenShift GitOps.
This release includes several enhancements and bug fixes to improve the stability and security of the GitOps Operator.
Notable changes in this release include:
- Major version upgrade of Argo CD from v2.14 to v3.0
- Minor version upgrade of Argo CD Rollouts from v1.7 to v1.8
- Tech Preview release of Argo CD Agent
- Support for OpenShift 4.19
- Updated documentation on using HashiCorp Vault with OpenShift GitOps
- Deprecation of the Keycloak SSO provider in OpenShift GitOps
- Removal of support for `.spec.initialRepositories` and `.spec.repositoryCredentials` fields in the Argo CD CRD
Please note that this release includes a major version upgrade of Argo CD, which may introduce breaking changes. It is strongly recommended to review the release notes to assess any potential impact on your existing configurations.
Refer to the release notes in the references section for more details.
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
Fixes
- GITOPS-7374 - 1.17.0 RC2 - Unable to create ApplicationSet webhook route
- GITOPS-5961 - Drop support for .spec.initialRepositories & spec.repositoryCredentials in ArgoCD CRD
- GITOPS-6630 - SAST Scan result: PATH_MANIPULATION (CWE-22)
- GITOPS-6858 - HashiCorp Vault Support for OpenShift GitOps
- GITOPS-5016 - Argo Agent: Integration into Red Hat productization
- GITOPS-6248 - Stuck Applicationset progressive sync
- GITOPS-6675 - Gitops operator is not accepting regular expression in sourceNamespaces - Application in non-controlplane namespaces
- GITOPS-6703 - After Upgrade to v.1.16 not able to add --metrics-application-labels in spec.controller.extraCommandArgs with multiple values
- GITOPS-6881 - Upgrade Argo CD to major version v3 in OpenShift GitOps (v1.17)
- GITOPS-6889 - Fine-Grained RBAC for application update and delete sub-resources
- GITOPS-7009 - Health status in the Application CR
- GITOPS-5969 - Unable to edit http repo credentials from argocd UI - openshift-gitops
- GITOPS-6326 - ArgoCDExport image doesn't work with Argo CD v2.13.x artifacts
- GITOPS-6662 - Extensions that use 'extensions` volumes cannot be reconciled
- GITOPS-6777 - gitops-plugin Pods should comply with the Pod Security restricted policy
- GITOPS-6806 - Only one replica is created for redis-ha-haproxy
- GITOPS-7018 - SourceNamespaces with long project name causing Reconciler error: must be no more than 63 characters
- GITOPS-5870 - Progressive Delivery in OpenShift Console's Topology View
- GITOPS-6668 - Enable JSON logging option for all GitOps components
- GITOPS-6775 - Argo CD Agent: Proxy redis traffic from principal to agent
- GITOPS-6886 - Logs RBAC enforcement as a first-class RBAC citizen
- GITOPS-6887 - Changes to RBAC with Dex SSO Authentication
- GITOPS-7010 - Argo Agent : Provide option in Argo CD CR to enable/disable Principal Component
- GITOPS-7070 - Deprecate Keycloak in OpenShift GitOps
- GITOPS-7112 - Argo Agent : Installation of Argo CD components on spoke OCP clusters using OLM
- GITOPS-7124 - Document Keycloak deprecation; recommend Dex or Red Hat Build of Keycloak in OpenShift GitOps docs
CVEs
(none)
amd64
| registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:8290eccc7a0b736bcf30e31ccc9d364e53a3b07bf2c04e6b591df04c08393736 |
| registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:10f07b1c8a165023c768fc852973e5e648968637f3a74dd7af9fe72e821b538a |
| registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:f5a7e876b370e5ab57eb80da691034e7e59dce5b0d0a2d398fe0ffc0a758439a |
| registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:28c5771e64f2605f5d42f1d358b1658b1626ca4a6950d34d01a1b9a34374d25e |
| registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:5f35a4ed723fa364bd58bc56a9491915ec8bed256a056b07429e1957580b1c4f |
| registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:b108bb9cf99bb77b97921376b3c095d466489708320fe50aa3808a86cfb0587f |
| registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:e2a4f47d42dde1e7c3b7a072c5b357be19e7ea8b422c38f28a075850e478b82f |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:279dbcfa78a159705125b75c5a5069790dca0eb9a7944629787adab1d6431020 |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:544226c8a3e830119a0b71f24caa4b30a2dff327d8e68a3562a900ce7b07e497 |
| registry.redhat.io/openshift-gitops-1/gitops-operator-bundle@sha256:58cfcb4b920d75b83ed2662a8e226724075518ad105f42f2f497dc4463a3221f |
| registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:f1adab2487a700636c49279689a8e0ecdfd3588caca27e994b3cddeb9dbcf5ac |
arm64
| registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:96f449fd3ec50a09bc6532c2cc489b58ec57accfe86f3ee7493f7d36ab03192e |
| registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:749c0445914de5d4366d40c181a2982ec3ec939614628a38aa0430c36a6b1a99 |
| registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:fc4c88407957bf7c87ff156655cab3dc2a2eb2a93c9612b8fa7f148ddd0651fd |
| registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:8f0760975c33427b2871e9c29f832c57ab7bed6775f22ce90809add55f20edb5 |
| registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:8168018c4ffadcda01fea61ec2bf005b556a28966dfdf60cf922a37392bcc987 |
| registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:3798a714cb72699bfa5974ab99aeb3ae0723b770eea6a6484ff047ad7b905971 |
| registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:a7db561fe12caff1d5af93a5c8c3d0d9debb1f70832e4744a2199f46f05d8f06 |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:8400d30003577752111770b049ee0ea74e8959cc2775d3b9e093cfff048d70a1 |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:7b4456ea7be3bed43db6383307ec129aa13411969b1018b45d444cef37be82c7 |
| registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:bc976ddb02be78f5ff03c4fc70ba7f237d166b201938af7d1ce4a95e6a089eb0 |
ppc64le
| registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:5a86816dfd873a28a1bc8974a14cf87f85ab61a2373d25730cd9b2197155798d |
| registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:4e6d39d139d5dab784a077d976c1716d2d989f7c24e935d86d45dce0cf9cd639 |
| registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:a27d2a7a13e3a3e9fd11c8954410fcddcf03689d2e9704dc621eca4e7f1c64ea |
| registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:f07e5ab505bf57d92246419cf4ca9e8b0b303303c5fef2beed428bf1e569a6a4 |
| registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:fd968ea6d503ba995ae00887a2ae7db32231f9fe2fb8d542e0cf8d32bf9019ed |
| registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:2afa378576462d70c1e2658895eda7c4df01f108a5a9130acc7b212284f73586 |
| registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:918a9ddf32f1b129f26420b200fbdf64df685da9eb1d11ecc62fd73b1dae08fc |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:9c3c2610fecc60740e3868846091aa93d45c527cddae85797617ac708a2ca277 |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:fc5c0fb5bbe59073977ca1f949e974666ee5df7c5f2a217340cb78467d434cbf |
| registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:f7efa21eab879e1a2841331b9335b2f14cd1f14b2f9d25616dea7843e36d72c6 |
s390x
| registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:38d3ca753d82ad8ffb9b49ec9554da6d074476124fb933cef2dadd001dc6af12 |
| registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:26000abc9e6fad2ab2fc2221df54b8a99bbf259cde888f4c245e1d11ac2a5f28 |
| registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:2ccf6a371ea2ca33e663ec5d14c90e552bfead74a141da4e79cd6459b4a18c16 |
| registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:6780d77376dd09e9bb1e43e73e2b369de206dd952f46587f7afb278ba0d82c33 |
| registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:abb2ea18aafa2acca8fd7e9de85f514042d3edd0b59ecd9b7047eca1fac86435 |
| registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:72e11f6365e42370e6e1e5edc230f3f725a864450e00934ba24ad48520fef3df |
| registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:8f6f58d0bd4623324e03a3525087502293a3607032ea3c05e5d835d7357b19ac |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:0e328f355b13676bcbf73450e8e312349acf26c4ebff859722f0a4f888e9f1ab |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:d4698271ca4ed6804e124ce801d3e95ff467f4a55abca389bca12bef44904b6d |
| registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:61c1ccfac0c5cf11a8a3181fc8e1af7a67ad659e430468b999447a1c287d68c2 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.