# 4.8.24

Created: 2021-12-08 07:04:56 +0000 UTC

Image Digest: `sha256:0708475f51e969dd9e6902d958f8ffed668b1b9c8d63b6241e7c9e40d9548eee`

Promoted from registry.ci.openshift.org/ocp/release:4.8.0-0.nightly-2021-12-06-234030


## Changes from 4.8.4

### Components

* Kubernetes upgraded from 1.21.1 to 1.21.6
* Red Hat Enterprise Linux CoreOS upgraded from 48.84.202107301701-0 to 48.84.202112022303-0


### Rebuilt images without code change

* [aws-ebs-csi-driver](https://github.com/openshift/aws-ebs-csi-driver) git [8c036e44](https://github.com/openshift/aws-ebs-csi-driver/commit/8c036e44147d9e4546c726b934dedda3940790af) `sha256:c652f4473ef20c3adf6dbd780dbc23208dd30ec52ac21fac803895e137a3c21f`
* [aws-ebs-csi-driver-operator](https://github.com/openshift/aws-ebs-csi-driver-operator) git [d1fe616c](https://github.com/openshift/aws-ebs-csi-driver-operator/commit/d1fe616c0da0edddb7019a64b0ad1136b36a5f26) `sha256:9ad247451d77190acf4b73b318da810ad6b46b114032e4e97a25bfc0a54427be`
* [azure-disk-csi-driver](https://github.com/openshift/azure-disk-csi-driver) git [2d461b39](https://github.com/openshift/azure-disk-csi-driver/commit/2d461b39bacc76f0b879f943015df4d2191f72f4) `sha256:334b3b6acec5c6b8cf268d16a11aa0f22fecd686ce1ec8f79bd7d4b845c52e4c`
* [azure-disk-csi-driver-operator](https://github.com/openshift/azure-disk-csi-driver-operator) git [d3a3c298](https://github.com/openshift/azure-disk-csi-driver-operator/commit/d3a3c298c91371ccd37896857f623f4494dd78a6) `sha256:47dcd8efb87c10a78c3831c5406608b200938be6f7618334acd243c1c837f104`
* [azure-machine-controllers](https://github.com/openshift/cluster-api-provider-azure) git [83010763](https://github.com/openshift/cluster-api-provider-azure/commit/830107632bf85869e13fbcb0848b27c310002d25) `sha256:35b734fb1e7f63304b45746c2986a30004e5e2041eef8785c6fc6e99b3623b0b`
* [baremetal-machine-controllers](https://github.com/openshift/cluster-api-provider-baremetal) git [a60d493e](https://github.com/openshift/cluster-api-provider-baremetal/commit/a60d493e45aa9d3c0391297fd77cb168092fed35) `sha256:07010ea51b154381dd5f0d6e6c7ee18592e3f6b2c63f96c74689c2e6ab19190f`
* [cluster-autoscaler](https://github.com/openshift/kubernetes-autoscaler) git [7bbde4cc](https://github.com/openshift/kubernetes-autoscaler/commit/7bbde4cc4ddb1d0030f23b789b4bbf48ab3ef79d) `sha256:97f4434fdb3e4b52f4a1230d42f3d2b30cbde1ea53da84ea5ac11164d85ea822`
* [cluster-bootstrap](https://github.com/openshift/cluster-bootstrap) git [1af395b7](https://github.com/openshift/cluster-bootstrap/commit/1af395b7881d951a824858f5d393357609bddbf0) `sha256:24a66808a20e69fabf5c6bb8ee59bc56224c0e201a41ea73371dcc955107adc8`
* [cluster-config-operator](https://github.com/openshift/cluster-config-operator) git [c1022410](https://github.com/openshift/cluster-config-operator/commit/c1022410bf9a000e84d9764f8e8a5cfa35cfa452) `sha256:1c479af5d3e6fb395c6a7b240d4c2e9627f82dd3c1b2ca4a6580e8b71977dda0`
* [cluster-csi-snapshot-controller-operator](https://github.com/openshift/cluster-csi-snapshot-controller-operator) git [07b3f810](https://github.com/openshift/cluster-csi-snapshot-controller-operator/commit/07b3f81036401073d68eb1ef152b96ab5e5a2fc6) `sha256:09cb15eb840b14bf093d1cf032dd752da055fa5613c62ab9f95b2b3d5b7d7e5d`
* [cluster-dns-operator](https://github.com/openshift/cluster-dns-operator) git [fdb2ebec](https://github.com/openshift/cluster-dns-operator/commit/fdb2ebecdeb992444964f84fd0b5c17f37d80536) `sha256:904d02ac25563efbe221950c47451188509fa2491c25b852f05aac1fb4f776ea`
* [cluster-openshift-controller-manager-operator](https://github.com/openshift/cluster-openshift-controller-manager-operator) git [286c1577](https://github.com/openshift/cluster-openshift-controller-manager-operator/commit/286c157755c8120ce969c7c15f969737b46b1a0a) `sha256:8ddda01195abd473b1770ebc6a2373f0db796f196bff8c47506932695a0ee745`
* [cluster-policy-controller](https://github.com/openshift/cluster-policy-controller) git [ec46ea5c](https://github.com/openshift/cluster-policy-controller/commit/ec46ea5ce3735fcb3d10290834f9ae5fb31148f0) `sha256:d34679b0089853be17452c236f1c5aa8a52ef0882495d8fa91cafa538fdf7b50`
* [cluster-samples-operator](https://github.com/openshift/cluster-samples-operator) git [31fb491f](https://github.com/openshift/cluster-samples-operator/commit/31fb491fc14faed6ebbe41a526764947069ff0a2) `sha256:f651b27a67edb8c78aa78dcf764b9fdf3e59c33d76b451efad896972fb0800f9`
* [cluster-update-keys](https://github.com/openshift/cluster-update-keys) git [87835b73](https://github.com/openshift/cluster-update-keys/commit/87835b737f0a90a6259150746114f251241bf52e) `sha256:f5b8da2529b012910774d1ba888b9b528be24d7d8a245defc843dd3134b3d7ad`
* [container-networking-plugins](https://github.com/openshift/containernetworking-plugins) git [71a8b346](https://github.com/openshift/containernetworking-plugins/commit/71a8b3469df865daf68cb893bfe313328d4be992) `sha256:5240ea7e387846bb8c9ac84e984e528a723572a0c63b0a06ffad47af3c5e8e80`
* [coredns](https://github.com/openshift/coredns) git [642b46ef](https://github.com/openshift/coredns/commit/642b46ef468d132d26c3f84a8bcb4b542d8df1e6) `sha256:fc94195d219afafed445884a40ea374b0c94ed64441ecaf1d79c367a961ff470`
* [csi-driver-manila](https://github.com/openshift/cloud-provider-openstack) git [3579eadc](https://github.com/openshift/cloud-provider-openstack/commit/3579eadc9b0e195a4bb80d9a43a33a250c4a8dd6) `sha256:9e5ccd34a912cc643007d02c9fe52f95cce8763bc722c7a664e6176a0bda188a`
* [csi-external-attacher](https://github.com/openshift/csi-external-attacher) git [596da63e](https://github.com/openshift/csi-external-attacher/commit/596da63ecf2886a9bce19c08ad1120e123b498af) `sha256:c2488d0cc3ee9035fcfad8a0a50c1c1b737f136dcd1bdbb1c0fa81c110fbbd4f`
* [csi-external-provisioner](https://github.com/openshift/csi-external-provisioner) git [3ea7e68a](https://github.com/openshift/csi-external-provisioner/commit/3ea7e68a518870d63c7da9485f8a69fa1555b452) `sha256:937c956360cb8fea0d0281e525ae0fcd27c6810903b45267613448d994dceecd`
* [csi-external-resizer](https://github.com/openshift/csi-external-resizer) git [b5dd2b39](https://github.com/openshift/csi-external-resizer/commit/b5dd2b39e9dfb83addd0c07654c3b9119e24cb36) `sha256:6049138a9aa5bd51e36f14332b6df79af1e1732787eb2244f9248f02e9dea805`
* [csi-external-snapshotter](https://github.com/openshift/csi-external-snapshotter) git [1e2cca95](https://github.com/openshift/csi-external-snapshotter/commit/1e2cca95999057e16fcfee07e8068f7a77f2e164) `sha256:b656b7d8dafcb3a45da38903526a59a4b26902224e8e204dbaaf10f54c5698cb`
* [csi-livenessprobe](https://github.com/openshift/csi-livenessprobe) git [a29b1153](https://github.com/openshift/csi-livenessprobe/commit/a29b1153451d6ffa6fbcb1dacbe25639c2523488) `sha256:d26140c64dfbf14d5af5ed2db905fd9065adecb09f217f1abd2250ae91b93fa7`
* [csi-node-driver-registrar](https://github.com/openshift/csi-node-driver-registrar) git [0519730f](https://github.com/openshift/csi-node-driver-registrar/commit/0519730f75f89c11f1ee07c7f81b0bcae1ddf705) `sha256:ce54c14b59a33c3f68bcaaeafeace71a502838e527d0fd812b0cfeaea772f67c`
* [csi-snapshot-controller](https://github.com/openshift/csi-external-snapshotter) git [1e2cca95](https://github.com/openshift/csi-external-snapshotter/commit/1e2cca95999057e16fcfee07e8068f7a77f2e164) `sha256:a0a2e0306d6d5e45155c72f326cae1259e453e4adc3c0b4650d21f58582b842d`
* [csi-snapshot-validation-webhook](https://github.com/openshift/csi-external-snapshotter) git [1e2cca95](https://github.com/openshift/csi-external-snapshotter/commit/1e2cca95999057e16fcfee07e8068f7a77f2e164) `sha256:02a280b9714cda6a97a16fc84fe71a3321ddb56056ddffa86af669d0761447af`
* [egress-router-cni](https://github.com/openshift/egress-router-cni) git [016bea1a](https://github.com/openshift/egress-router-cni/commit/016bea1a6f5ec53aab8e936f4120c32a05322027) `sha256:32e2b1044523d34d5951353db0b57a66cc7960a7734450ffe4fac21e5d7a159c`
* [etcd](https://github.com/openshift/etcd) git [aefa6bf5](https://github.com/openshift/etcd/commit/aefa6bf59b381938b50ab9ba4a7add9b4a767e27) `sha256:a60070bccdea39afbf11431e74917a210cda1f9cd01a616866d2f2c935a8a212`
* [gcp-machine-controllers](https://github.com/openshift/cluster-api-provider-gcp) git [34db56eb](https://github.com/openshift/cluster-api-provider-gcp/commit/34db56ebf7a8a46828f5830d42b26f9d2bdd0db1) `sha256:7ef014e5e137480e269c5dfcd63c3549eb4e1685d5fea6a8517e0811a27f5d4d`
* [gcp-pd-csi-driver](https://github.com/openshift/gcp-pd-csi-driver) git [0b618896](https://github.com/openshift/gcp-pd-csi-driver/commit/0b618896c6b7c977f96d133060c54ed1b6c87540) `sha256:433187c950372721a99c8fa2106b94f957c7e80c5e166b0a1931eaddd408d0cb`
* [gcp-pd-csi-driver-operator](https://github.com/openshift/gcp-pd-csi-driver-operator) git [35ebe860](https://github.com/openshift/gcp-pd-csi-driver-operator/commit/35ebe86003c339821d3a36186a66f8ef86049932) `sha256:eabfc70fd979e7d93df9ea0cb747874eec0db7db4618be23b304d5be70faf108`
* [grafana](https://github.com/openshift/grafana) git [b987e4b1](https://github.com/openshift/grafana/commit/b987e4b1e20b6cf814bbc408dd2a740aed92e410) `sha256:bfb2f86a35744e5a4377acea90e3027513a4d3260d086a19b84b9abe28c49c74`
* [ironic-inspector](https://github.com/openshift/ironic-inspector-image) git [9aafd074](https://github.com/openshift/ironic-inspector-image/commit/9aafd074adf6dbc7ee7c2c3150568578e82acc3f) `sha256:feb8cdb91b81c8169ae0cadfd3d6b113cd4c51009d2aaec22d90369285f0f888`
* [ironic-ipa-downloader](https://github.com/openshift/ironic-ipa-downloader) git [ba878326](https://github.com/openshift/ironic-ipa-downloader/commit/ba8783261ea8f21afdcd46eb8a86986597c38c75) `sha256:11269690bd34ec1b7446db2fe74bae15eb38efb1255dcdffdddb634b0a17a70d`
* [ironic-machine-os-downloader](https://github.com/openshift/ironic-rhcos-downloader) git [71967e7d](https://github.com/openshift/ironic-rhcos-downloader/commit/71967e7deca9e9d0e094cbaedb7fe7ce0267dd84) `sha256:d82f49614b4b2102fb3f93737a0e6b1729f2ff92eb11778928b619e99f17159a`
* [ironic-static-ip-manager](https://github.com/openshift/ironic-static-ip-manager) git [d2e40e34](https://github.com/openshift/ironic-static-ip-manager/commit/d2e40e34f8284d0ac7c4e9133b537baeac07b408) `sha256:6a8b12150090b4dcac17cafbf7daad521532d76aa7de7328324429eb324bd944`
* [keepalived-ipfailover](https://github.com/openshift/images) git [ad38e116](https://github.com/openshift/images/commit/ad38e116f3533e0e78621a2887d8b70cde7cba31) `sha256:e0570f644044aeaed1eec663aef3b6c1bd23ccf1a76ad9560a686145fd5ac582`
* [kube-rbac-proxy](https://github.com/openshift/kube-rbac-proxy) git [813c3da7](https://github.com/openshift/kube-rbac-proxy/commit/813c3da7222a4ccc95ef3827cd54b0ce93a8cbe5) `sha256:73331ff6219bdc97f91742969533ed87be1205679059d8cafacd129fb38de760`
* [kube-state-metrics](https://github.com/openshift/kube-state-metrics) git [94716629](https://github.com/openshift/kube-state-metrics/commit/947166293195d115500d4479c0c40c8c01a25ad0) `sha256:bb05660fa6f31f4b5e1910829e8426521f3a01e653970cf84c5154a136af3519`
* [kube-storage-version-migrator](https://github.com/openshift/kubernetes-kube-storage-version-migrator) git [901a6d22](https://github.com/openshift/kubernetes-kube-storage-version-migrator/commit/901a6d221d1cf79b4b6ba859bb43521e0ee635b3) `sha256:1d7edb5daf72120f14580b450c40b85d4c09128bc85c242684cce1f51bec3ac8`
* machine-os-content `sha256:a483b8f61dacaa714c6fb570ba5be023978ce91a60fdced2f410bdee8b1446bc`
* [multus-admission-controller](https://github.com/openshift/multus-admission-controller) git [64645feb](https://github.com/openshift/multus-admission-controller/commit/64645febe4129a794b1291d0a375a7b2bb7fba39) `sha256:14dc7dc258ab69bb82b1b3a7c1e5c9d750d571e11e0ebdf04cd85fbd2110cb13`
* [multus-cni](https://github.com/openshift/multus-cni) git [0c972341](https://github.com/openshift/multus-cni/commit/0c972341809c1e40f9ea6e1545774d9e1f580455) `sha256:4dfbe2051c551d80fd9a56d6595df691c033d5adeb1cebe003e4485bb5abe592`
* [multus-networkpolicy](https://github.com/openshift/multus-networkpolicy) git [187ad91f](https://github.com/openshift/multus-networkpolicy/commit/187ad91f119ff6b73610922012e7af4e704c5e93) `sha256:5305a4ea6a9f9d24476fd9fc5db096d9e831fbec714ec9196b36e0741ee086c8`
* [multus-route-override-cni](https://github.com/openshift/route-override-cni) git [1662c3ec](https://github.com/openshift/route-override-cni/commit/1662c3ec79b880fce5cd9c4e64f5ba0d4daffc00) `sha256:9e52591144e7720b29ce53b39a8a8f108b36b01af8fd3d033c1f81d5033c7434`
* [must-gather](https://github.com/openshift/must-gather) git [515e0502](https://github.com/openshift/must-gather/commit/515e0502a886f0d7e7e0125792251d5872cc503b) `sha256:a4dc776b581ba6c4b2d1a5a08ccd09598177e2934e9159d0eac4067b1bdcce01`
* [network-metrics-daemon](https://github.com/openshift/network-metrics-daemon) git [f02c63ae](https://github.com/openshift/network-metrics-daemon/commit/f02c63ae9475d2e51ee1b94b8e341ac8f9d590b7) `sha256:2e900c4db62b8a5250c119124403028b3eaccb239e1197e68993d8660b047c6e`
* [network-tools](https://github.com/openshift/network-tools) git [5ac3739e](https://github.com/openshift/network-tools/commit/5ac3739e4382eb10cdd9209c8947096997fe38a2) `sha256:bd942bdb6e3d3aa7cec309bee896c71637a6ddfcb5ecd5101a7f8599da9f8d40`
* [oauth-apiserver](https://github.com/openshift/oauth-apiserver) git [09435a5d](https://github.com/openshift/oauth-apiserver/commit/09435a5dd505b3b90eb7ce355ab41c8e4c1a349c) `sha256:6e1a98730f27d7f08f1f140226b67fb2f995df2e6555146f00d6c9067ad733d5`
* [oauth-proxy](https://github.com/openshift/oauth-proxy) git [3fc0d89b](https://github.com/openshift/oauth-proxy/commit/3fc0d89b2607808927f5b48168342f5dc3a1a271) `sha256:a696ee8062f4cb6da9828d337d72b1a5a66ec5052ab8ba5718252c8b8ca633ed`
* [oauth-server](https://github.com/openshift/oauth-server) git [374e2ee3](https://github.com/openshift/oauth-server/commit/374e2ee38a1910c6d56172e9d4ec1828c4dea1be) `sha256:14efdd28949662a9a30f354cb05ab0b4350167c594c5ab4303e1b2e6c6dbb6b5`
* [openshift-state-metrics](https://github.com/openshift/openshift-state-metrics) git [10142914](https://github.com/openshift/openshift-state-metrics/commit/101429149266e2c86a41b82baf47a033c9a93b02) `sha256:5a3b5acee12522900dabba877f3c0962e8145bb74e82f69f14834a67528da545`
* [openstack-cinder-csi-driver](https://github.com/openshift/cloud-provider-openstack) git [3579eadc](https://github.com/openshift/cloud-provider-openstack/commit/3579eadc9b0e195a4bb80d9a43a33a250c4a8dd6) `sha256:e1b89940d2959f8a0abd77760b3fcebdf909c19a0f12e646f87c260afb81617e`
* [openstack-cinder-csi-driver-operator](https://github.com/openshift/openstack-cinder-csi-driver-operator) git [1184ace0](https://github.com/openshift/openstack-cinder-csi-driver-operator/commit/1184ace0cd3b6fd90549eaf77737f230822c318d) `sha256:b3b9aeba2acedc36e9543d61537ed72950d2f359408faa591a0e46b49d0cc910`
* [ovirt-csi-driver-operator](https://github.com/openshift/ovirt-csi-driver-operator) git [7b6cd3d8](https://github.com/openshift/ovirt-csi-driver-operator/commit/7b6cd3d847c807663f63a6f293748c682c2cad2a) `sha256:ad8bc91b62991fa805baa15ebb195bce7c70b871350efac6ce1b1cb9c13dfbd1`
* [prom-label-proxy](https://github.com/openshift/prom-label-proxy) git [2faeb405](https://github.com/openshift/prom-label-proxy/commit/2faeb4050010914d6b55da38bffb44b95702e052) `sha256:8a5ac28f757afd594bff5855089a2b4bd96f1c6d7fe410136971bfda7304c3cb`
* [prometheus](https://github.com/openshift/prometheus) git [f3beb880](https://github.com/openshift/prometheus/commit/f3beb880dbde817bf5ed2befc1880445884e4be0) `sha256:b409668983f252eb22a8856c2e2815d6f90eb9ebda7f82ac2f4c783160e35a02`
* [prometheus-alertmanager](https://github.com/openshift/prometheus-alertmanager) git [7b5ac874](https://github.com/openshift/prometheus-alertmanager/commit/7b5ac8741d87542c43d002aef3b881d7f8065133) `sha256:d05dec20034bed91fb9b81f8ae8fb7cd8ec8187760bc3ec9d27af963a5e18040`
* [vsphere-csi-driver](https://github.com/openshift/vmware-vsphere-csi-driver) git [dd5345eb](https://github.com/openshift/vmware-vsphere-csi-driver/commit/dd5345eb7ed3c68eff6619ca434b5e83083f5bc9) `sha256:714987e64efdec2fb21a3fdcb6939b1f01271bd63c5eae5f0a931c1c0e3d3566`
* [vsphere-csi-driver-syncer](https://github.com/openshift/vmware-vsphere-csi-driver) git [dd5345eb](https://github.com/openshift/vmware-vsphere-csi-driver/commit/dd5345eb7ed3c68eff6619ca434b5e83083f5bc9) `sha256:5ed0625b365035a7a6f169ee04fd4987763a9156c391d65af3c0b314402ebd32`
* [vsphere-problem-detector](https://github.com/openshift/vsphere-problem-detector) git [c02283d6](https://github.com/openshift/vsphere-problem-detector/commit/c02283d6c979f4e63b76945951272b1cfd134c32) `sha256:42e502e7ac595efbe7e9d5fc0150bec81387c74405ad2204245602284cd7fa12`


### [aws-machine-controllers](https://github.com/openshift/cluster-api-provider-aws/tree/32869a752a758a476c030e4aa83e2bca54d81b05)

* [Bug 2016926](https://bugzilla.redhat.com/show_bug.cgi?id=2016926): do not requeue if the machine has been updated [#426](https://github.com/openshift/cluster-api-provider-aws/pull/426)
* [Bug 1974680](https://bugzilla.redhat.com/show_bug.cgi?id=1974680): Fix eventual consistency logic to be consistent [#416](https://github.com/openshift/cluster-api-provider-aws/pull/416)
* [Full changelog](https://github.com/openshift/cluster-api-provider-aws/compare/4c66f3d38d89e4076051daebe8915ef92b52fe8f...32869a752a758a476c030e4aa83e2bca54d81b05)


### [aws-pod-identity-webhook](https://github.com/openshift/aws-pod-identity-webhook/tree/58ef8af861317beceac26691d5c452af45ca0e4a)

* [Bug 2029253](https://bugzilla.redhat.com/show_bug.cgi?id=2029253): update go.mod for go1.16 [#148](https://github.com/openshift/aws-pod-identity-webhook/pull/148)
* [Full changelog](https://github.com/openshift/aws-pod-identity-webhook/compare/2b8eee2a4f0555c6d4ce7700fda774190574fb5d...58ef8af861317beceac26691d5c452af45ca0e4a)


### [baremetal-installer, installer, installer-artifacts](https://github.com/openshift/installer/tree/7123680a2275e9f6f33a0a325ab61a129a54c2af)

* [Bug 2023363](https://bugzilla.redhat.com/show_bug.cgi?id=2023363): Add ingress rules to master SG for compact clusters [#5386](https://github.com/openshift/installer/pull/5386)
* [Bug 2017986](https://bugzilla.redhat.com/show_bug.cgi?id=2017986): Set AWS Bootstrap Type == Master [#5338](https://github.com/openshift/installer/pull/5338)
* [Bug 2017258](https://bugzilla.redhat.com/show_bug.cgi?id=2017258): bump oVirt terraform provider version which fix "Disk is locked" bug [#5329](https://github.com/openshift/installer/pull/5329)
* [Bug 2002349](https://bugzilla.redhat.com/show_bug.cgi?id=2002349): Fix invalid UPI AWS instance type [#5199](https://github.com/openshift/installer/pull/5199)
* [Bug 2008823](https://bugzilla.redhat.com/show_bug.cgi?id=2008823): baremetal: Ensure ipv6 bootstrap VM client-id is predictable [#5250](https://github.com/openshift/installer/pull/5250)
* [Bug 2009019](https://bugzilla.redhat.com/show_bug.cgi?id=2009019): update legacy RHCOS boot image metadata [#5255](https://github.com/openshift/installer/pull/5255)
* [Bug 1982001](https://bugzilla.redhat.com/show_bug.cgi?id=1982001): Bump RHCOS 4.8 boot image [#5227](https://github.com/openshift/installer/pull/5227)
* Update OWNERS [#5242](https://github.com/openshift/installer/pull/5242)
* [Bug 2004236](https://bugzilla.redhat.com/show_bug.cgi?id=2004236): Document how to enable Octavia Day 2 [#5161](https://github.com/openshift/installer/pull/5161)
* [Bug 1973421](https://bugzilla.redhat.com/show_bug.cgi?id=1973421): [4.8] improve dual-stack install-config validation [#5114](https://github.com/openshift/installer/pull/5114)
* [Bug 1987848](https://bugzilla.redhat.com/show_bug.cgi?id=1987848): openstack: quotas/BYON improvements [#5122](https://github.com/openshift/installer/pull/5122)
* [Bug 1969651](https://bugzilla.redhat.com/show_bug.cgi?id=1969651): bump RHCOS 4.8 boot images [#5051](https://github.com/openshift/installer/pull/5051)
* [Bug 1981548](https://bugzilla.redhat.com/show_bug.cgi?id=1981548): [release-4.8] aws: move elastic ip permissions to create networking category [#5056](https://github.com/openshift/installer/pull/5056)
* OWNERS: add more core team members as approvers [#5124](https://github.com/openshift/installer/pull/5124)
* [Full changelog](https://github.com/openshift/installer/compare/1831f62e8edf693c6b9d398a1549c3f032b62706...7123680a2275e9f6f33a0a325ab61a129a54c2af)


### [baremetal-operator](https://github.com/openshift/baremetal-operator/tree/02a2d3cf8747de12f8f845575a11b7dd4519046d)

* [Bug 2000442](https://bugzilla.redhat.com/show_bug.cgi?id=2000442): Add LIVE_ISO_FORCE_PERSISTENT_BOOT_DEVICE variable [#174](https://github.com/openshift/baremetal-operator/pull/174)
* [Full changelog](https://github.com/openshift/baremetal-operator/compare/015024fe8c50eca20850fcc550880b7357709613...02a2d3cf8747de12f8f845575a11b7dd4519046d)


### [baremetal-runtimecfg](https://github.com/openshift/baremetal-runtimecfg/tree/ae824ab2973b62f03d423ccab100533c7c8ad948)

* [Bug 1996573](https://bugzilla.redhat.com/show_bug.cgi?id=1996573): CoreDNS Corefile hosts - add support for dual-stack [#149](https://github.com/openshift/baremetal-runtimecfg/pull/149)
* [Full changelog](https://github.com/openshift/baremetal-runtimecfg/compare/c8b1456c0f0aa124490b47281557a1beaa5afcf1...ae824ab2973b62f03d423ccab100533c7c8ad948)


### [cli, cli-artifacts, deployer, tools](https://github.com/openshift/oc/tree/88e7eba36ac7cc026d064bb6e4a988acc18a144e)

* [Bug 2004193](https://bugzilla.redhat.com/show_bug.cgi?id=2004193): Registry mirror panic [#926](https://github.com/openshift/oc/pull/926)
* Add kevinrizza as catalog-approver [#921](https://github.com/openshift/oc/pull/921)
* [Bug 1992639](https://bugzilla.redhat.com/show_bug.cgi?id=1992639): revert incorrect allowance of ssh:// prefix with scp styled URLs [#898](https://github.com/openshift/oc/pull/898)
* [Bug 1974267](https://bugzilla.redhat.com/show_bug.cgi?id=1974267): make oc logs work with BuildConfig's JenkinsPipeline strategy [#867](https://github.com/openshift/oc/pull/867)
* [Full changelog](https://github.com/openshift/oc/compare/1077b0516d5baf6f2717e4cb34f58236c0fb7a8c...88e7eba36ac7cc026d064bb6e4a988acc18a144e)


### [cloud-credential-operator](https://github.com/openshift/cloud-credential-operator/tree/eb682c49d885fdb109f5867b8e09535f76ce89aa)

* [Bug 2027928](https://bugzilla.redhat.com/show_bug.cgi?id=2027928): pod-identity-webhook starts without tls [#429](https://github.com/openshift/cloud-credential-operator/pull/429)
* [Bug 2027832](https://bugzilla.redhat.com/show_bug.cgi?id=2027832): Stop putting CCO in degraded state when stale credentials are found [#428](https://github.com/openshift/cloud-credential-operator/pull/428)
* [Bug 2026098](https://bugzilla.redhat.com/show_bug.cgi?id=2026098): Check for aws status in infra platform status field before client setup [#425](https://github.com/openshift/cloud-credential-operator/pull/425)
* [Full changelog](https://github.com/openshift/cloud-credential-operator/compare/b8932e9fc555bc5bc356eddb3b48358caba72e92...eb682c49d885fdb109f5867b8e09535f76ce89aa)


### [cluster-authentication-operator](https://github.com/openshift/cluster-authentication-operator/tree/560ac283add7d24c07db1582db4c2ac7d80aaeba)

* [Bug 1997906](https://bugzilla.redhat.com/show_bug.cgi?id=1997906): csr request: use generate names to prevent getting stuck waiting for a cert [#494](https://github.com/openshift/cluster-authentication-operator/pull/494)
* [Bug 2003632](https://bugzilla.redhat.com/show_bug.cgi?id=2003632): manifests, bindata: explicitely set runAsUser for operator and operand [#484](https://github.com/openshift/cluster-authentication-operator/pull/484)
* [Bug 2003946](https://bugzilla.redhat.com/show_bug.cgi?id=2003946): Deploy PDB to prevent more than one replica going unavailable [#488](https://github.com/openshift/cluster-authentication-operator/pull/488)
* [Bug 1989587](https://bugzilla.redhat.com/show_bug.cgi?id=1989587): pkg/operator: Add deprecated stale status [#471](https://github.com/openshift/cluster-authentication-operator/pull/471)
* [Full changelog](https://github.com/openshift/cluster-authentication-operator/compare/348765e59b3d4466389ef9a6e0e4383393ab3c6b...560ac283add7d24c07db1582db4c2ac7d80aaeba)


### [cluster-autoscaler-operator](https://github.com/openshift/cluster-autoscaler-operator/tree/add29b86c2c920c68d21e9db50a16019266fcf58)

* [Bug 2026237](https://bugzilla.redhat.com/show_bug.cgi?id=2026237): Change ClusterAutoscalerUnschedulablePods severity to info [#232](https://github.com/openshift/cluster-autoscaler-operator/pull/232)
* [Bug 1995595](https://bugzilla.redhat.com/show_bug.cgi?id=1995595): add csidrivers and csistoragecapacities to autoscaler cluster role [#220](https://github.com/openshift/cluster-autoscaler-operator/pull/220)
* [Bug 1991501](https://bugzilla.redhat.com/show_bug.cgi?id=1991501): Do not recreate CA deployment when CA CR is being deleted [#217](https://github.com/openshift/cluster-autoscaler-operator/pull/217)
* [Full changelog](https://github.com/openshift/cluster-autoscaler-operator/compare/fdae5baad94f8b6a5b7a9077d5af8650f35c1e94...add29b86c2c920c68d21e9db50a16019266fcf58)


### [cluster-baremetal-operator](https://github.com/openshift/cluster-baremetal-operator/tree/1146017627352b72e0f2399f9f7e3423f0327eb2)

* [Bug 2000445](https://bugzilla.redhat.com/show_bug.cgi?id=2000445): Set LIVE_ISO_FORCE_PERSISTENT_BOOT_DEVICE=Never [#194](https://github.com/openshift/cluster-baremetal-operator/pull/194)
* [Bug 1975711](https://bugzilla.redhat.com/show_bug.cgi?id=1975711): Only start static ip set if provisioning net not disabled [#166](https://github.com/openshift/cluster-baremetal-operator/pull/166)
* [Full changelog](https://github.com/openshift/cluster-baremetal-operator/compare/04a2ae214a8f6cea458b26a89b53190cf60fcad6...1146017627352b72e0f2399f9f7e3423f0327eb2)


### [cluster-etcd-operator](https://github.com/openshift/cluster-etcd-operator/tree/35672edef2c867e135b0e9378a00764b363d8ba5)

* [Bug 2008414](https://bugzilla.redhat.com/show_bug.cgi?id=2008414): pkg/operator/metriccontroller: read etcd-operator SA token rather than using prometheus [#665](https://github.com/openshift/cluster-etcd-operator/pull/665)
* [Bug 1994483](https://bugzilla.redhat.com/show_bug.cgi?id=1994483): bindata/etcd: remove unix socket from advertised list [#642](https://github.com/openshift/cluster-etcd-operator/pull/642)
* [Bug 1999777](https://bugzilla.redhat.com/show_bug.cgi?id=1999777): [release-4.8]: pkg/operator: add cluster backup upgrade controller [#652](https://github.com/openshift/cluster-etcd-operator/pull/652)
* [Bug 1993800](https://bugzilla.redhat.com/show_bug.cgi?id=1993800): Bump library-go to include backoff fix of installers [#648](https://github.com/openshift/cluster-etcd-operator/pull/648)
* [Full changelog](https://github.com/openshift/cluster-etcd-operator/compare/300bdf3949e155295313cb6ecdc58dc7ecf17632...35672edef2c867e135b0e9378a00764b363d8ba5)


### [cluster-image-registry-operator](https://github.com/openshift/cluster-image-registry-operator/tree/499e84e43d1b100b5704b30a1b24a1017c9f38b2)

* [Bug 2015098](https://bugzilla.redhat.com/show_bug.cgi?id=2015098): Avoid disruptions [#725](https://github.com/openshift/cluster-image-registry-operator/pull/725)
* [Bug 2004028](https://bugzilla.redhat.com/show_bug.cgi?id=2004028): Update rolling update parameters [#717](https://github.com/openshift/cluster-image-registry-operator/pull/717)
* [Full changelog](https://github.com/openshift/cluster-image-registry-operator/compare/e137fea075b0e2c5a44f34faaf3c46f7ae070d93...499e84e43d1b100b5704b30a1b24a1017c9f38b2)


### [cluster-ingress-operator](https://github.com/openshift/cluster-ingress-operator/tree/cb614126da5151f1a115152ae1fc3ef70ee93ca1)

* [Bug 2017708](https://bugzilla.redhat.com/show_bug.cgi?id=2017708): Change default balancing algorithm to "leastconn" [#670](https://github.com/openshift/cluster-ingress-operator/pull/670)
* [Bug 1998103](https://bugzilla.redhat.com/show_bug.cgi?id=1998103): cleanup condition metrics for deleted ingress controllers [#649](https://github.com/openshift/cluster-ingress-operator/pull/649)
* [Bug 2000414](https://bugzilla.redhat.com/show_bug.cgi?id=2000414): Configure router to use "source" for passthrough [#651](https://github.com/openshift/cluster-ingress-operator/pull/651)
* [Full changelog](https://github.com/openshift/cluster-ingress-operator/compare/e9e62957e31cc5fd2166c4c6aeb164c426a90fed...cb614126da5151f1a115152ae1fc3ef70ee93ca1)


### [cluster-kube-apiserver-operator](https://github.com/openshift/cluster-kube-apiserver-operator/tree/cddab90b7699ceb50032e22b4b3cff5803dd1466)

* [Bug 2016213](https://bugzilla.redhat.com/show_bug.cgi?id=2016213): Exempt metrics scrapes from APF. [#1247](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1247)
* [Bug 2012010](https://bugzilla.redhat.com/show_bug.cgi?id=2012010): alerts: give exact oc get apirequestcounts command in APIRemovedInNextReleaseInUse alert [#1241](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1241)
* [Bug 2001244](https://bugzilla.redhat.com/show_bug.cgi?id=2001244): Enforce OpenShift's defined kubelet version skew policies [#1224](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1224)
* [Bug 1993800](https://bugzilla.redhat.com/show_bug.cgi?id=1993800): bump(library-go): staticpod/installer: fix backoff of installers [#1214](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1214)
* [Full changelog](https://github.com/openshift/cluster-kube-apiserver-operator/compare/7f3081b369dd33f994a0cf80d5ced6d432e3bf8f...cddab90b7699ceb50032e22b4b3cff5803dd1466)


### [cluster-kube-controller-manager-operator](https://github.com/openshift/cluster-kube-controller-manager-operator/tree/7fa48ebf34e8c810ce8cbe8b62a4e10a7326856c)

* [Bug 1993800](https://bugzilla.redhat.com/show_bug.cgi?id=1993800): Bump library-go to include backoff fix of installers [#560](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/560)
* [Full changelog](https://github.com/openshift/cluster-kube-controller-manager-operator/compare/9dc35db7ecc27c5807b5d9b9d1e1de3080416a09...7fa48ebf34e8c810ce8cbe8b62a4e10a7326856c)


### [cluster-kube-scheduler-operator](https://github.com/openshift/cluster-kube-scheduler-operator/tree/3c47d6f73c7e81dee830fb92629bd56a41375196)

* [Bug 1993800](https://bugzilla.redhat.com/show_bug.cgi?id=1993800): Bump library-go to include backoff fix of installers [#366](https://github.com/openshift/cluster-kube-scheduler-operator/pull/366)
* [Full changelog](https://github.com/openshift/cluster-kube-scheduler-operator/compare/170a5a66d6788179e23fa3529a7d5f76ee33caae...3c47d6f73c7e81dee830fb92629bd56a41375196)


### [cluster-kube-storage-version-migrator-operator](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/tree/e6d8251927350ef2ac8d283833954485827b9b85)

* [Bug 2022844](https://bugzilla.redhat.com/show_bug.cgi?id=2022844): Extensive number of requests from storage version operator in cluster – Part 1 [#78](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/pull/78)
* [Full changelog](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/compare/c4f4f8bbfc87b9fe057de2a05e484387eea1fddb...e6d8251927350ef2ac8d283833954485827b9b85)


### [cluster-machine-approver](https://github.com/openshift/cluster-machine-approver/tree/828e403f08f371888b458ad1d210ae989e66fe2b)

* [Bug 2024689](https://bugzilla.redhat.com/show_bug.cgi?id=2024689): Allow fallback to serving cert renewal accounting for egress IPs on SDN [#142](https://github.com/openshift/cluster-machine-approver/pull/142)
* [Full changelog](https://github.com/openshift/cluster-machine-approver/compare/724abd216ea546671fbfa4c9060180ff1619c85a...828e403f08f371888b458ad1d210ae989e66fe2b)


### [cluster-monitoring-operator](https://github.com/openshift/cluster-monitoring-operator/tree/e9cb2177162129c836ac37d8c9c090237b993fe7)

* [Bug 2018431](https://bugzilla.redhat.com/show_bug.cgi?id=2018431): [4.8] add kube_persistentvolumeclaim_labels and kube_persistentvolume_labels [#1459](https://github.com/openshift/cluster-monitoring-operator/pull/1459)
* [Bug 2012039](https://bugzilla.redhat.com/show_bug.cgi?id=2012039): Allow namespace label in metric allow list [#1436](https://github.com/openshift/cluster-monitoring-operator/pull/1436)
* [Bug 2005205](https://bugzilla.redhat.com/show_bug.cgi?id=2005205): improve update and status reporting 4.8 [#1428](https://github.com/openshift/cluster-monitoring-operator/pull/1428)
* Revert "Bug 1999057: jsonnet: Sync with kube-prometheus" [#1394](https://github.com/openshift/cluster-monitoring-operator/pull/1394)
* [Bug 1999057](https://bugzilla.redhat.com/show_bug.cgi?id=1999057): jsonnet: Sync with kube-prometheus [#1360](https://github.com/openshift/cluster-monitoring-operator/pull/1360)
* [Bug 1997497](https://bugzilla.redhat.com/show_bug.cgi?id=1997497): Backport etcd telemetry [#1344](https://github.com/openshift/cluster-monitoring-operator/pull/1344)
* [Bug 1995699](https://bugzilla.redhat.com/show_bug.cgi?id=1995699): Get insights on series churn during upgrades [#1349](https://github.com/openshift/cluster-monitoring-operator/pull/1349)
* [Bug 1999148](https://bugzilla.redhat.com/show_bug.cgi?id=1999148): alert: ClusterMonitoringOperatorReconciliationErrors: reduce range du… [#1351](https://github.com/openshift/cluster-monitoring-operator/pull/1351)
* [Bug 1991836](https://bugzilla.redhat.com/show_bug.cgi?id=1991836): Revise Alert Severity in OCP 4.8 [#1342](https://github.com/openshift/cluster-monitoring-operator/pull/1342)
* [Bug 1984753](https://bugzilla.redhat.com/show_bug.cgi?id=1984753): jsonnet: Sync with kube-prometheus [#1323](https://github.com/openshift/cluster-monitoring-operator/pull/1323)
* [Bug 1978208](https://bugzilla.redhat.com/show_bug.cgi?id=1978208): Sync dependencies for 4.8 release backports [#1264](https://github.com/openshift/cluster-monitoring-operator/pull/1264)
* [Bug 1982778](https://bugzilla.redhat.com/show_bug.cgi?id=1982778): jsonnet: thanosquery: Use HTTP probes as opposed to exec [#1289](https://github.com/openshift/cluster-monitoring-operator/pull/1289)
* [Bug 1976765](https://bugzilla.redhat.com/show_bug.cgi?id=1976765): Update AlertmanagerMembersInconsistent rule [#1283](https://github.com/openshift/cluster-monitoring-operator/pull/1283)
* [Bug 1988991](https://bugzilla.redhat.com/show_bug.cgi?id=1988991): pkg/client/client.go: Add retry logic for daemonset create [#1309](https://github.com/openshift/cluster-monitoring-operator/pull/1309)
* [Full changelog](https://github.com/openshift/cluster-monitoring-operator/compare/16caab3f8109f201f82f6be19e239b3b91755e5c...e9cb2177162129c836ac37d8c9c090237b993fe7)


### [cluster-network-operator](https://github.com/openshift/cluster-network-operator/tree/17becc47a03a57c5c2a30eb50898927e1c1748ae)

* [Bug 2008589](https://bugzilla.redhat.com/show_bug.cgi?id=2008589): [4.8z] Slow OVN Recovery on SNO [#1200](https://github.com/openshift/cluster-network-operator/pull/1200)
* [Bug 1985308](https://bugzilla.redhat.com/show_bug.cgi?id=1985308): Add a newline between user CAs and system CAs [#1162](https://github.com/openshift/cluster-network-operator/pull/1162)
* [Bug 1990928](https://bugzilla.redhat.com/show_bug.cgi?id=1990928): [Backport 4.8] Whereabouts should have RBAC for leases [#1185](https://github.com/openshift/cluster-network-operator/pull/1185)
* [Bug 1985588](https://bugzilla.redhat.com/show_bug.cgi?id=1985588): Update service network status to reflect dual stack entries [#1164](https://github.com/openshift/cluster-network-operator/pull/1164)
* [Bug 1987046](https://bugzilla.redhat.com/show_bug.cgi?id=1987046): Add pre-puller ds to reduce upgrade downtime [#1167](https://github.com/openshift/cluster-network-operator/pull/1167)
* [Bug 1988425](https://bugzilla.redhat.com/show_bug.cgi?id=1988425): Change to use mountPath: /host [#1169](https://github.com/openshift/cluster-network-operator/pull/1169)
* [Full changelog](https://github.com/openshift/cluster-network-operator/compare/a5ebd1ebc3549acb84c74145612460f416788e21...17becc47a03a57c5c2a30eb50898927e1c1748ae)


### [cluster-node-tuning-operator](https://github.com/openshift/cluster-node-tuning-operator/tree/8e9c8730897f8d56fa94b1bef2649e6abbf049c1)

* [Bug 2018053](https://bugzilla.redhat.com/show_bug.cgi?id=2018053): tuned: add timeout and restarts [#286](https://github.com/openshift/cluster-node-tuning-operator/pull/286)
* [Bug 2013678](https://bugzilla.redhat.com/show_bug.cgi?id=2013678): TuneD: workaround for high CPU utilization of [scheduler] plug-in. [#280](https://github.com/openshift/cluster-node-tuning-operator/pull/280)
* [Bug 1998120](https://bugzilla.redhat.com/show_bug.cgi?id=1998120): Add a cgroup blacklisting rule to parent openshift profile. [#266](https://github.com/openshift/cluster-node-tuning-operator/pull/266)
* [Bug 1999608](https://bugzilla.redhat.com/show_bug.cgi?id=1999608): Reload when deps of recommended profile change. [#268](https://github.com/openshift/cluster-node-tuning-operator/pull/268)
* [Bug 1986992](https://bugzilla.redhat.com/show_bug.cgi?id=1986992): Handle kube-apiserver disruption more gracefully. [#257](https://github.com/openshift/cluster-node-tuning-operator/pull/257)
* [Bug 1985908](https://bugzilla.redhat.com/show_bug.cgi?id=1985908): scheduler: new option cgroup_ps_blacklist [#254](https://github.com/openshift/cluster-node-tuning-operator/pull/254)
* [Full changelog](https://github.com/openshift/cluster-node-tuning-operator/compare/6be3f671b023377ef0e71fd60d2c57dfb0e25afa...8e9c8730897f8d56fa94b1bef2649e6abbf049c1)


### [cluster-openshift-apiserver-operator](https://github.com/openshift/cluster-openshift-apiserver-operator/tree/837db83388c0aeafac0068d5f3a0d5adbbefbbb3)

* [Bug 2003946](https://bugzilla.redhat.com/show_bug.cgi?id=2003946): Deploy PDB to prevent more than one replica going unavailable [#473](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/473)
* [Bug 1994655](https://bugzilla.redhat.com/show_bug.cgi?id=1994655): apiservice-controller: don't update the failing condition when an operator has been requested to shutdown [#482](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/482)
* [Bug 1996044](https://bugzilla.redhat.com/show_bug.cgi?id=1996044): bindata: run openshift-apiserver as root explicitly. [#467](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/467)
* [Full changelog](https://github.com/openshift/cluster-openshift-apiserver-operator/compare/d0b22d8766f72cdfa31e85ec4097b7556099dadc...837db83388c0aeafac0068d5f3a0d5adbbefbbb3)


### [cluster-storage-operator](https://github.com/openshift/cluster-storage-operator/tree/a2092b4526bc99a217d19d7376d59c23a6804a46)

* [Bug 1996672](https://bugzilla.redhat.com/show_bug.cgi?id=1996672): Add proxy support to cinder CSI [#210](https://github.com/openshift/cluster-storage-operator/pull/210)
* [Full changelog](https://github.com/openshift/cluster-storage-operator/compare/874422cb87565b17402aacf4712408b47d9a527f...a2092b4526bc99a217d19d7376d59c23a6804a46)


### [cluster-version-operator](https://github.com/openshift/cluster-version-operator/tree/887cf90963a370dda85c7753eceabdcdcaea17eb)

* [Bug 1982683](https://bugzilla.redhat.com/show_bug.cgi?id=1982683): [release-4.8] Respect noProxy [#691](https://github.com/openshift/cluster-version-operator/pull/691)
* [Bug 2025955](https://bugzilla.redhat.com/show_bug.cgi?id=2025955): Removing the extra indentation [#696](https://github.com/openshift/cluster-version-operator/pull/696)
* [Bug 2015025](https://bugzilla.redhat.com/show_bug.cgi?id=2015025): lib/resourcemerge/imagestream.go: Copy all data for new tag reference [#679](https://github.com/openshift/cluster-version-operator/pull/679)
* [Bug 2011954](https://bugzilla.redhat.com/show_bug.cgi?id=2011954): pkg/cvo/upgradeable: Include messages for multiple-reason Upgradeable=False [#672](https://github.com/openshift/cluster-version-operator/pull/672)
* [Bug 1999092](https://bugzilla.redhat.com/show_bug.cgi?id=1999092): Add and enable admin ack Upgradeable condition gate [#647](https://github.com/openshift/cluster-version-operator/pull/647)
* [Bug 1999777](https://bugzilla.redhat.com/show_bug.cgi?id=1999777): Ensure recent etcd backup before allowing minor-version updates [#649](https://github.com/openshift/cluster-version-operator/pull/649)
* [Bug 1980411](https://bugzilla.redhat.com/show_bug.cgi?id=1980411): [release-4.8] pkg/cvo/egress: Load HTTPS proxy from Proxy status [#627](https://github.com/openshift/cluster-version-operator/pull/627)
* [Full changelog](https://github.com/openshift/cluster-version-operator/compare/ea6e779ef89710879e2c08c0e5847a5b5e860b28...887cf90963a370dda85c7753eceabdcdcaea17eb)


### [configmap-reloader](https://github.com/openshift/configmap-reload/tree/0d221296e3918abc3c1367a1e7c220baf000965a)

* Updating configmap-reload builder & base images to be consistent with ART [#32](https://github.com/openshift/configmap-reload/pull/32)
* [Full changelog](https://github.com/openshift/configmap-reload/compare/abc5c26e2e5034639f271a2b4f360b581da2a17d...0d221296e3918abc3c1367a1e7c220baf000965a)


### [console](https://github.com/openshift/console/tree/622bf63922c2ec79c49f7e527c4a9d846f468c7e)

* [Bug 2024206](https://bugzilla.redhat.com/show_bug.cgi?id=2024206): Fix resource metrics 403 errors for project admin users [#10496](https://github.com/openshift/console/pull/10496)
* [Bug 2026950](https://bugzilla.redhat.com/show_bug.cgi?id=2026950): Fix autofocus on pf select component for search resource dropdown [#10577](https://github.com/openshift/console/pull/10577)
* [Bug 2017469](https://bugzilla.redhat.com/show_bug.cgi?id=2017469): key not a valid prop name causing display issue in env editor [#10419](https://github.com/openshift/console/pull/10419)
* [Bug 2009224](https://bugzilla.redhat.com/show_bug.cgi?id=2009224): Regular user cannot restore VM snapshot [#10436](https://github.com/openshift/console/pull/10436)
* [Bug 2020162](https://bugzilla.redhat.com/show_bug.cgi?id=2020162): PVC is deleted along with VM even with "Delete Disks" unchecked [#10399](https://github.com/openshift/console/pull/10399)
* [Bug 2017326](https://bugzilla.redhat.com/show_bug.cgi?id=2017326): Update PatternFly/react-console [#10384](https://github.com/openshift/console/pull/10384)
* [Bug 1984102](https://bugzilla.redhat.com/show_bug.cgi?id=1984102): Switch Cypress OLM tests to use supported Red Hat operators [#9560](https://github.com/openshift/console/pull/9560)
* [Bug 2005871](https://bugzilla.redhat.com/show_bug.cgi?id=2005871): Cannot create Network Attachment Definition through UI [#10314](https://github.com/openshift/console/pull/10314)
* [Bug 1997901](https://bugzilla.redhat.com/show_bug.cgi?id=1997901): Cannot delete user created vm template [#10367](https://github.com/openshift/console/pull/10367)
* [Bug 2001212](https://bugzilla.redhat.com/show_bug.cgi?id=2001212): Notifications is not translated on the top right bar [#10040](https://github.com/openshift/console/pull/10040)
* [Bug 2002649](https://bugzilla.redhat.com/show_bug.cgi?id=2002649): Fix SerialConsole display bug [#10034](https://github.com/openshift/console/pull/10034)
* [Bug 1994983](https://bugzilla.redhat.com/show_bug.cgi?id=1994983): use strict promoted template list [#9824](https://github.com/openshift/console/pull/9824)
* [Bug 1977659](https://bugzilla.redhat.com/show_bug.cgi?id=1977659): Adjusting to new reference models changes - cherry-picked rls 4.8 [#9379](https://github.com/openshift/console/pull/9379)
* [Bug 2013091](https://bugzilla.redhat.com/show_bug.cgi?id=2013091): adds check for status in ksvc in util logic [#10211](https://github.com/openshift/console/pull/10211)
* [Bug 1998692](https://bugzilla.redhat.com/show_bug.cgi?id=1998692): Normal user cannot create VM because it cannot access v2v-vmware [#10171](https://github.com/openshift/console/pull/10171)
* (4.8 Backport) Bug 1981416: Change OCM links from cloud. to console.redhat.com [#9470](https://github.com/openshift/console/pull/9470)
* [Bug 2010076](https://bugzilla.redhat.com/show_bug.cgi?id=2010076): Update prow setup v4.8 [#10168](https://github.com/openshift/console/pull/10168)
* [Bug 1999717](https://bugzilla.redhat.com/show_bug.cgi?id=1999717): Block and File and Object dashboards should not be part of OCP Console for ODF Managed Services [#9952](https://github.com/openshift/console/pull/9952)
* [Bug 2005917](https://bugzilla.redhat.com/show_bug.cgi?id=2005917): CONSOLE-2152: Improve upgrade messaging when ClusterVersion Upgradeable=False [#10103](https://github.com/openshift/console/pull/10103)
* [Bug 1993236](https://bugzilla.redhat.com/show_bug.cgi?id=1993236): Do not drop environment variables without name but with a value, also fix crash when ref is empty [#9799](https://github.com/openshift/console/pull/9799)
* [Bug 2000474](https://bugzilla.redhat.com/show_bug.cgi?id=2000474): Create BuildConfig webhook secrets before creating knative resources [#9970](https://github.com/openshift/console/pull/9970)
* [Bug 1996758](https://bugzilla.redhat.com/show_bug.cgi?id=1996758): Update Resource Dropdown Tech preview text [Release-4.8] [#9838](https://github.com/openshift/console/pull/9838)
* [Bug 1990141](https://bugzilla.redhat.com/show_bug.cgi?id=1990141): Console overview operators shown upgrading when still waiting on approval [#9732](https://github.com/openshift/console/pull/9732)
* [Bug 1995118](https://bugzilla.redhat.com/show_bug.cgi?id=1995118): Virtualization is not available in Home Overview [#9826](https://github.com/openshift/console/pull/9826)
* [Bug 1999931](https://bugzilla.redhat.com/show_bug.cgi?id=1999931): move event sources add option to serverless add group [#9958](https://github.com/openshift/console/pull/9958)
* [Bug 1984367](https://bugzilla.redhat.com/show_bug.cgi?id=1984367): OCS deployment using Multus: UI allows StorageCluster creation with empty public and cluster network in "Internal - Attached Devices" [#9566](https://github.com/openshift/console/pull/9566)
* [Bug 1992720](https://bugzilla.redhat.com/show_bug.cgi?id=1992720): Update Ingress to v1 API version [#9788](https://github.com/openshift/console/pull/9788)
* [Bug 1983644](https://bugzilla.redhat.com/show_bug.cgi?id=1983644): Add a TechPreviewBadge for Multus [#9539](https://github.com/openshift/console/pull/9539)
* [Bug 1972987](https://bugzilla.redhat.com/show_bug.cgi?id=1972987): chore(i18n): update translations [#9284](https://github.com/openshift/console/pull/9284)
* [Bug 1982458](https://bugzilla.redhat.com/show_bug.cgi?id=1982458): Remove kube admin notifier for kubeadmin crc user [#9516](https://github.com/openshift/console/pull/9516)
* [Bug 1985193](https://bugzilla.redhat.com/show_bug.cgi?id=1985193): Add create resource extension [#9601](https://github.com/openshift/console/pull/9601)
* [Bug 1989798](https://bugzilla.redhat.com/show_bug.cgi?id=1989798): Fix previously deleted dragged files that show up in import yaml editor [#9718](https://github.com/openshift/console/pull/9718)
* [Bug 1985081](https://bugzilla.redhat.com/show_bug.cgi?id=1985081): Fix Pipeline Download All [#9596](https://github.com/openshift/console/pull/9596)
* [Bug 1987167](https://bugzilla.redhat.com/show_bug.cgi?id=1987167): Add inspect url to devconsole monitoring chart [#9671](https://github.com/openshift/console/pull/9671)
* [Bug 1972258](https://bugzilla.redhat.com/show_bug.cgi?id=1972258): adds check for kamelet source in provider [#9254](https://github.com/openshift/console/pull/9254)
* [Bug 1971911](https://bugzilla.redhat.com/show_bug.cgi?id=1971911): Do not render samples column and helm link when add page customization disabled them [#9240](https://github.com/openshift/console/pull/9240)
* [Bug 1976144](https://bugzilla.redhat.com/show_bug.cgi?id=1976144): fix optional workspace checkbox check/uncheck [#9343](https://github.com/openshift/console/pull/9343)
* [Bug 1984242](https://bugzilla.redhat.com/show_bug.cgi?id=1984242): filter null yaml objects before validating to prevent undefined exception [#9565](https://github.com/openshift/console/pull/9565)
* [Bug 1973696](https://bugzilla.redhat.com/show_bug.cgi?id=1973696): Fix time range issue for devconsole monitoring dashboard [#9298](https://github.com/openshift/console/pull/9298)
* [Bug 1986581](https://bugzilla.redhat.com/show_bug.cgi?id=1986581): Web console doesn't list all the registries credentials in a secret [#9651](https://github.com/openshift/console/pull/9651)
* [Bug 1985356](https://bugzilla.redhat.com/show_bug.cgi?id=1985356): Check for nonexistent CSVs in installed block [#9735](https://github.com/openshift/console/pull/9735)
* [Bug 1989152](https://bugzilla.redhat.com/show_bug.cgi?id=1989152): [Release-4.8] Use specific release for files used in e2e tests [#9700](https://github.com/openshift/console/pull/9700)
* [Full changelog](https://github.com/openshift/console/compare/5045bcbbda40b1efab47aa03790c5b83c0f8b903...622bf63922c2ec79c49f7e527c4a9d846f468c7e)


### [console-operator](https://github.com/openshift/console-operator/tree/e77c02ee15d4b1849d359108048762b9559cd3d5)

* [Bug 2018391](https://bugzilla.redhat.com/show_bug.cgi?id=2018391): Remove SimpleHTTP 'server' response header value [#606](https://github.com/openshift/console-operator/pull/606)
* [Bug 1987315](https://bugzilla.redhat.com/show_bug.cgi?id=1987315): Bump openshift/api to add missing 'include.release.openshift.io/single-node-developer' annotation to the ConsolePlugin CRD [#591](https://github.com/openshift/console-operator/pull/591)
* [Bug 2003639](https://bugzilla.redhat.com/show_bug.cgi?id=2003639): Use kubernetes.io/hostname for workload anti-affi… …nity [#589](https://github.com/openshift/console-operator/pull/589)
* [Bug 2001268](https://bugzilla.redhat.com/show_bug.cgi?id=2001268): console-operator should report Available=true when at least available replica exists [#583](https://github.com/openshift/console-operator/pull/583)
* [Full changelog](https://github.com/openshift/console-operator/compare/696f4645f37ded0426b04adcc1ac5ed4d79053c0...e77c02ee15d4b1849d359108048762b9559cd3d5)


### [csi-driver-manila-operator](https://github.com/openshift/csi-driver-manila-operator/tree/f6ffb0d7c2935db9d349f8dc1c51d9ea1b0df5ce)

* [Bug 2002554](https://bugzilla.redhat.com/show_bug.cgi?id=2002554): Do not degrade cluster on failure to reach Manila [#125](https://github.com/openshift/csi-driver-manila-operator/pull/125)
* [Bug 1987020](https://bugzilla.redhat.com/show_bug.cgi?id=1987020): Use cluster Proxy when available [#109](https://github.com/openshift/csi-driver-manila-operator/pull/109)
* [Bug 1988506](https://bugzilla.redhat.com/show_bug.cgi?id=1988506): Backport e2e testing [#111](https://github.com/openshift/csi-driver-manila-operator/pull/111)
* [Full changelog](https://github.com/openshift/csi-driver-manila-operator/compare/7e862529de616e3a4b07c81da4afc2e714e8e2e1...f6ffb0d7c2935db9d349f8dc1c51d9ea1b0df5ce)


### [csi-driver-nfs](https://github.com/openshift/csi-driver-nfs/tree/583088efa37346e23ed056b57ea24e61b0e5b9d8)

* Updating csi-driver-nfs builder & base images to be consistent with ART [#40](https://github.com/openshift/csi-driver-nfs/pull/40)
* [Full changelog](https://github.com/openshift/csi-driver-nfs/compare/9404d343c020fd1806691704f64d930c779ad639...583088efa37346e23ed056b57ea24e61b0e5b9d8)


### [docker-builder](https://github.com/openshift/builder/tree/b59f2b3a9f1571b78f8337211b80a49a6da91269)

* [Bug 1992639](https://bugzilla.redhat.com/show_bug.cgi?id=1992639): bump(s2i): revert incorrect ssh scp fix [#259](https://github.com/openshift/builder/pull/259)
* [Full changelog](https://github.com/openshift/builder/compare/c089361b7e5eae73addb235621ae69d63bd6b2c6...b59f2b3a9f1571b78f8337211b80a49a6da91269)


### [docker-registry](https://github.com/openshift/image-registry/tree/369fd303a1a7e5a2fcc594a63e72dc9cacb4d41f)

* [Bug 2012163](https://bugzilla.redhat.com/show_bug.cgi?id=2012163): Supporting mirror authentication during pull through [#297](https://github.com/openshift/image-registry/pull/297)
* Updating openshift-enterprise-registry builder & base images to be consistent with ART [#270](https://github.com/openshift/image-registry/pull/270)
* [Full changelog](https://github.com/openshift/image-registry/compare/a87e6c50cd973723de8b5471453de7c345403d56...369fd303a1a7e5a2fcc594a63e72dc9cacb4d41f)


### [driver-toolkit](https://github.com/openshift/driver-toolkit/tree/58bf9f0e1f5ed9f2168373f8b150ad2cd2e8d18b)

* [Bug 2011460](https://bugzilla.redhat.com/show_bug.cgi?id=2011460): Add imagestream for driver-toolkit [#65](https://github.com/openshift/driver-toolkit/pull/65)
* [Bug 1988478](https://bugzilla.redhat.com/show_bug.cgi?id=1988478): Use kernel config to determine GCC version [#55](https://github.com/openshift/driver-toolkit/pull/55)
* [Full changelog](https://github.com/openshift/driver-toolkit/compare/03737139adc98cab7e3f66f546589a6fa5307ed1...58bf9f0e1f5ed9f2168373f8b150ad2cd2e8d18b)


### [haproxy-router](https://github.com/openshift/router/tree/9c9f9f422fd55b6535bd2a669a88657f97569c4d)

* [Bug 1990370](https://bugzilla.redhat.com/show_bug.cgi?id=1990370): haproxy-config.template: Fix power-of-two balancing [#324](https://github.com/openshift/router/pull/324)
* [Full changelog](https://github.com/openshift/router/compare/ce657305237bdae4c7860af144440a8ef98a986b...9c9f9f422fd55b6535bd2a669a88657f97569c4d)


### [hyperkube, pod](https://github.com/openshift/kubernetes/tree/c180a7cb22ca0f5e7db459a299405ea69e556128)

* [Bug 2022741](https://bugzilla.redhat.com/show_bug.cgi?id=2022741): UPSTREAM: 106260: Don't guess SELinux support on error [#1054](https://github.com/openshift/kubernetes/pull/1054)
* [Bug 2021997](https://bugzilla.redhat.com/show_bug.cgi?id=2021997): Read k8s version from hyperkube Dockerfile [#1045](https://github.com/openshift/kubernetes/pull/1045)
* Updating openshift-enterprise-hyperkube builder & base images to be consistent with ART [#559](https://github.com/openshift/kubernetes/pull/559)
* [Bug 2017027](https://bugzilla.redhat.com/show_bug.cgi?id=2017027): UPSTREAM: <drop>: bump apiserver-library-go [#1069](https://github.com/openshift/kubernetes/pull/1069)
* [Bug 2022265](https://bugzilla.redhat.com/show_bug.cgi?id=2022265): Rebase v1.21.6 [#1060](https://github.com/openshift/kubernetes/pull/1060)
* Updating openshift-enterprise-pod images to be consistent with ART [#680](https://github.com/openshift/kubernetes/pull/680)
* [Bug 2020644](https://bugzilla.redhat.com/show_bug.cgi?id=2020644): Image policy should mutate DeploymentConfigs, StatefulSets, and new CronJobs [#1050](https://github.com/openshift/kubernetes/pull/1050)
* [Bug 1994655](https://bugzilla.redhat.com/show_bug.cgi?id=1994655): openshift-apiserver should not set Available=False APIServicesAvailable on update [#955](https://github.com/openshift/kubernetes/pull/955)
* [Bug 2008403](https://bugzilla.redhat.com/show_bug.cgi?id=2008403): Rebase v1.21.5 [#981](https://github.com/openshift/kubernetes/pull/981)
* [Bug 2011460](https://bugzilla.redhat.com/show_bug.cgi?id=2011460): UPSTREAM: <carry>: openshift-hack/images/os/Dockerfile: Add io.openshift.build.versions, etc. [#1005](https://github.com/openshift/kubernetes/pull/1005)
* [Bug 1995714](https://bugzilla.redhat.com/show_bug.cgi?id=1995714): UPSTREAM: <carry>: admission/managementcpusoverride: cover the roll-back case [#895](https://github.com/openshift/kubernetes/pull/895)
* [Bug 1994457](https://bugzilla.redhat.com/show_bug.cgi?id=1994457): Update to kubernetes 1.21.4 [#888](https://github.com/openshift/kubernetes/pull/888)
* [Bug 1993754](https://bugzilla.redhat.com/show_bug.cgi?id=1993754): UPSTREAM: 104347: Pass additional flags to subpath mount to avoid fla… [#940](https://github.com/openshift/kubernetes/pull/940)
* [Bug 1998391](https://bugzilla.redhat.com/show_bug.cgi?id=1998391): UPSTREAM: 104530: [1.21] bump runc to 1.0.2 [#912](https://github.com/openshift/kubernetes/pull/912)
* [Bug 1957133](https://bugzilla.redhat.com/show_bug.cgi?id=1957133): do not throw error when we can't get canonical path [#854](https://github.com/openshift/kubernetes/pull/854)
* [Full changelog](https://github.com/openshift/kubernetes/compare/38b3eccb7e23fd950b6c7b5ec1cc3075b630aac3...c180a7cb22ca0f5e7db459a299405ea69e556128)


### [insights-operator](https://github.com/openshift/insights-operator/tree/0a81fa44a7b981a64c8e34d25b0d5206564f4cd7)

* [Bug 2027720](https://bugzilla.redhat.com/show_bug.cgi?id=2027720): gather webhook configurations (#508) (#560) [#508](https://github.com/openshift/insights-operator/pull/508)
* [Bug 2026646](https://bugzilla.redhat.com/show_bug.cgi?id=2026646): Gather all the container logs from related namespaces of degraded clusteroperator (#516) (#554) [#516](https://github.com/openshift/insights-operator/pull/516)
* [Bug 2021572](https://bugzilla.redhat.com/show_bug.cgi?id=2021572): Anonymize identity provider attributes in the (#520) (#527) (#541) [#520](https://github.com/openshift/insights-operator/pull/520)
* [Bug 2020601](https://bugzilla.redhat.com/show_bug.cgi?id=2020601): Anonymize the ImageRegistry storage information also in status (#536) [#536](https://github.com/openshift/insights-operator/pull/536)
* obfuscation ovn clusters bug (#523) [#523](https://github.com/openshift/insights-operator/pull/523)
* Bug TBD: Gather installed PSP names (#489) (#490) [#489](https://github.com/openshift/insights-operator/pull/489)
* [Bug 1977342](https://bugzilla.redhat.com/show_bug.cgi?id=1977342): Fix obfuscation translation table secret 4.8 (#467) [#467](https://github.com/openshift/insights-operator/pull/467)
* Gather all MachineConfig definitions (#449) (#459) [#449](https://github.com/openshift/insights-operator/pull/449)
* [Bug 1974877](https://bugzilla.redhat.com/show_bug.cgi?id=1974877): Add egress ips to anonymizer to 4.8 (#462) [#462](https://github.com/openshift/insights-operator/pull/462)
* [Full changelog](https://github.com/openshift/insights-operator/compare/4303ecc6ff377cfcc7068b488fd68321e4893ae3...0a81fa44a7b981a64c8e34d25b0d5206564f4cd7)


### [ironic](https://github.com/openshift/ironic-image/tree/fa8525ea51101fb69b8766d927a5123986a74725)

* [Bug 2023765](https://bugzilla.redhat.com/show_bug.cgi?id=2023765): Compare IPs using the short form of IPv6 address [#233](https://github.com/openshift/ironic-image/pull/233)
* [Bug 2017413](https://bugzilla.redhat.com/show_bug.cgi?id=2017413): [4.8] fix Image provisioning fails with file name too long [#229](https://github.com/openshift/ironic-image/pull/229)
* [Bug 2025755](https://bugzilla.redhat.com/show_bug.cgi?id=2025755): Enable vMedia provisioning of SuperMicro X11/X12 [#237](https://github.com/openshift/ironic-image/pull/237)
* [Bug 2003035](https://bugzilla.redhat.com/show_bug.cgi?id=2003035): Sync sushy to include the latest bugfixes for 4.8 [#214](https://github.com/openshift/ironic-image/pull/214)
* [Bug 1991979](https://bugzilla.redhat.com/show_bug.cgi?id=1991979): [4.8] Sync image with ironic [#206](https://github.com/openshift/ironic-image/pull/206)
* [Bug 1975137](https://bugzilla.redhat.com/show_bug.cgi?id=1975137): [4.8] Sync image with the latest ironic code [#187](https://github.com/openshift/ironic-image/pull/187)
* [Full changelog](https://github.com/openshift/ironic-image/compare/227b76b752d742de4fe9cfe746bfd88d352d75fa...fa8525ea51101fb69b8766d927a5123986a74725)


### [ironic-hardware-inventory-recorder](https://github.com/openshift/ironic-hardware-inventory-recorder-image/tree/b3ecae8d1c6cd84a8784cf3dd17532797af7b724)

* Updating ironic-hardware-inventory-recorder-image builder & base images to be consistent with ART [#504](https://github.com/openshift/ironic-hardware-inventory-recorder-image/pull/504)
* [Full changelog](https://github.com/openshift/ironic-hardware-inventory-recorder-image/compare/61c4cc7dc99601fe32b239be8923a6ed693908b0...b3ecae8d1c6cd84a8784cf3dd17532797af7b724)


### [jenkins, jenkins-agent-base, jenkins-agent-maven, jenkins-agent-nodejs](https://github.com/openshift/jenkins/tree/b6350470611671e97424c0905cecb4494f9b6814)

* [Bug 2020614](https://bugzilla.redhat.com/show_bug.cgi?id=2020614): Update Jenkins and plugins per 2021-11 advisory [#1347](https://github.com/openshift/jenkins/pull/1347)
* [Bug 2008114](https://bugzilla.redhat.com/show_bug.cgi?id=2008114): Upgrade Jenkins to 2.289.3 (and related fixes) [#1324](https://github.com/openshift/jenkins/pull/1324)
* [Full changelog](https://github.com/openshift/jenkins/compare/8f554e2ad7ab8636cdbf55b5d0bde4577a5c0af6...b6350470611671e97424c0905cecb4494f9b6814)


### [k8s-prometheus-adapter](https://github.com/openshift/k8s-prometheus-adapter/tree/bfffea3bf70fc5203814886f6483a569f2f22c87)

* [Bug 2002281](https://bugzilla.redhat.com/show_bug.cgi?id=2002281): 4.8: pkg/resourceprovider: guard from negative metrics [#55](https://github.com/openshift/k8s-prometheus-adapter/pull/55)
* [Full changelog](https://github.com/openshift/k8s-prometheus-adapter/compare/2856bc27f7319c069c02cbc5210852c34ef6e4ef...bfffea3bf70fc5203814886f6483a569f2f22c87)


### [kube-proxy, sdn](https://github.com/openshift/sdn/tree/62479b7460d72578e5217efd6ed86087913405ec)

* [Bug 2027397](https://bugzilla.redhat.com/show_bug.cgi?id=2027397): [EgressIP] move ct(commit) action from OVS group to flow [#377](https://github.com/openshift/sdn/pull/377)
* [Bug 2014166](https://bugzilla.redhat.com/show_bug.cgi?id=2014166): Remove locking from EgressIPTracker.Ping [#362](https://github.com/openshift/sdn/pull/362)
* [Bug 2002290](https://bugzilla.redhat.com/show_bug.cgi?id=2002290): [4.8] proxy: don't re-check every userspace proxy rule on every change [#347](https://github.com/openshift/sdn/pull/347)
* [Bug 1987239](https://bugzilla.redhat.com/show_bug.cgi?id=1987239): when assigning and releasing egressIP try more than once before failing [#326](https://github.com/openshift/sdn/pull/326)
* [Bug 1999946](https://bugzilla.redhat.com/show_bug.cgi?id=1999946): improve SDN's OVS healthcheck and logging [#341](https://github.com/openshift/sdn/pull/341)
* [Bug 1995871](https://bugzilla.redhat.com/show_bug.cgi?id=1995871): Disable conntrack for vxlan traffic [#337](https://github.com/openshift/sdn/pull/337)
* [Full changelog](https://github.com/openshift/sdn/compare/6ac86f3f551508a892ee0d8a781475d9d1262537...62479b7460d72578e5217efd6ed86087913405ec)


### [kuryr-cni, kuryr-controller](https://github.com/openshift/kuryr-kubernetes/tree/43dd2f6dc30e0536486a5e6678290a48af423532)

* [Bug 2022722](https://bugzilla.redhat.com/show_bug.cgi?id=2022722): Make completed Pods Ports reusable [#600](https://github.com/openshift/kuryr-kubernetes/pull/600)
* [Bug 2018232](https://bugzilla.redhat.com/show_bug.cgi?id=2018232): Update TOX_CONSTRAINTS_FILE for stable/xena [#587](https://github.com/openshift/kuryr-kubernetes/pull/587)
* [Bug 1995013](https://bugzilla.redhat.com/show_bug.cgi?id=1995013): Remove ep_slices from klb on endpoint delete event [#550](https://github.com/openshift/kuryr-kubernetes/pull/550)
* [Bug 1989550](https://bugzilla.redhat.com/show_bug.cgi?id=1989550): Increase keystoneauth's connection pool size [#546](https://github.com/openshift/kuryr-kubernetes/pull/546)
* [Full changelog](https://github.com/openshift/kuryr-kubernetes/compare/8a4c2d85d5e5ce17214e989b11b33a2584bcb199...43dd2f6dc30e0536486a5e6678290a48af423532)


### [libvirt-machine-controllers](https://github.com/openshift/cluster-api-provider-libvirt/tree/9542e5ac08b7731a37d20c881695aab904201c22)

* Updating ose-libvirt-machine-controllers builder & base images to be consistent with ART [#217](https://github.com/openshift/cluster-api-provider-libvirt/pull/217)
* [Full changelog](https://github.com/openshift/cluster-api-provider-libvirt/compare/1a48d4b99ab5a2ce89fa909d12f3256f7489544f...9542e5ac08b7731a37d20c881695aab904201c22)


### [machine-api-operator](https://github.com/openshift/machine-api-operator/tree/7870c095fcb4509c445ed36c800f99ae919daf30)

* [Bug 2026562](https://bugzilla.redhat.com/show_bug.cgi?id=2026562): MaxUnhealthy should not be a string type [#962](https://github.com/openshift/machine-api-operator/pull/962)
* [Bug 2022838](https://bugzilla.redhat.com/show_bug.cgi?id=2022838): GCP CI runs are complaining about APIs not being enabled [#953](https://github.com/openshift/machine-api-operator/pull/953)
* [Bug 1999585](https://bugzilla.redhat.com/show_bug.cgi?id=1999585): [release-4.8] add alert for machine with long deletion phase [#908](https://github.com/openshift/machine-api-operator/pull/908)
* [Bug 2000038](https://bugzilla.redhat.com/show_bug.cgi?id=2000038): Respect MaxUnhealthy limit for external remediation [#910](https://github.com/openshift/machine-api-operator/pull/910)
* [Bug 1993117](https://bugzilla.redhat.com/show_bug.cgi?id=1993117): Make sure nodes don't have attached volumes before vm deletion [#903](https://github.com/openshift/machine-api-operator/pull/903)
* [Bug 1977634](https://bugzilla.redhat.com/show_bug.cgi?id=1977634): Prevent machine from stucking in Deleting phase on vSphere if related node object not found [#896](https://github.com/openshift/machine-api-operator/pull/896)
* [Full changelog](https://github.com/openshift/machine-api-operator/compare/115522033fd678820d70e570e6748ba488b36115...7870c095fcb4509c445ed36c800f99ae919daf30)


### [machine-config-operator](https://github.com/openshift/machine-config-operator/tree/1aeaf8c9c93dc772e65e23668dd435d06d833bcf)

* [Bug 2028025](https://bugzilla.redhat.com/show_bug.cgi?id=2028025): [Release 4.8] daemon: make cordon/uncordon more robust and better logging [#2853](https://github.com/openshift/machine-config-operator/pull/2853)
* [Bug 2017493](https://bugzilla.redhat.com/show_bug.cgi?id=2017493): configure-ovs: Persist addr-gen-mode for ipv6 connections [#2810](https://github.com/openshift/machine-config-operator/pull/2810)
* [Bug 2021073](https://bugzilla.redhat.com/show_bug.cgi?id=2021073): [ipi onprem] cherry pick Keepalived default ingress scripts fixes [#2826](https://github.com/openshift/machine-config-operator/pull/2826)
* [Bug 2026085](https://bugzilla.redhat.com/show_bug.cgi?id=2026085): Send WARN message to stderr [#2836](https://github.com/openshift/machine-config-operator/pull/2836)
* [Bug 2024511](https://bugzilla.redhat.com/show_bug.cgi?id=2024511): [release-4.8] [on-prem] Manual backporting of keepalived arp retries [#2831](https://github.com/openshift/machine-config-operator/pull/2831)
* [Bug 2016275](https://bugzilla.redhat.com/show_bug.cgi?id=2016275): [on-prem] Set coredns bufsize to 512 [#2807](https://github.com/openshift/machine-config-operator/pull/2807)
* [Bug 2011083](https://bugzilla.redhat.com/show_bug.cgi?id=2011083): templates: Silence audit events from container infra by default [#2793](https://github.com/openshift/machine-config-operator/pull/2793)
* [Bug 1985736](https://bugzilla.redhat.com/show_bug.cgi?id=1985736): [ON-PREM] HAProxy - Verify that NM prepender script was applied using initcontainer [#2692](https://github.com/openshift/machine-config-operator/pull/2692)
* [Bug 2000958](https://bugzilla.redhat.com/show_bug.cgi?id=2000958): fixes 1 to 1 kubelet config mapping [#2753](https://github.com/openshift/machine-config-operator/pull/2753)
* [Bug 1999531](https://bugzilla.redhat.com/show_bug.cgi?id=1999531): Set timeoutSeconds for keepalived liveness probe [#2741](https://github.com/openshift/machine-config-operator/pull/2741)
* [Bug 2004122](https://bugzilla.redhat.com/show_bug.cgi?id=2004122): Set ovs syslog level to info [#2762](https://github.com/openshift/machine-config-operator/pull/2762)
* [Bug 1973873](https://bugzilla.redhat.com/show_bug.cgi?id=1973873): match tlsSecurityProfile  doc with kubelet.conf file [#2628](https://github.com/openshift/machine-config-operator/pull/2628)
* [Bug 2000500](https://bugzilla.redhat.com/show_bug.cgi?id=2000500): bump SystemMemoryExceedsReservation alert threshold to 95% [#2748](https://github.com/openshift/machine-config-operator/pull/2748)
* [Bug 1976110](https://bugzilla.redhat.com/show_bug.cgi?id=1976110): configure-ovs: fix nondeterministic master in slave profiles [#2644](https://github.com/openshift/machine-config-operator/pull/2644)
* [Bug 1985735](https://bugzilla.redhat.com/show_bug.cgi?id=1985735): [ON-PREM] HAProxy - enable listening sockets retrieval from old processes [#2691](https://github.com/openshift/machine-config-operator/pull/2691)
* [Bug 1998106](https://bugzilla.redhat.com/show_bug.cgi?id=1998106): vSpehere: disable vmxnet3 tx csum offload [#2736](https://github.com/openshift/machine-config-operator/pull/2736)
* [Bug 1995809](https://bugzilla.redhat.com/show_bug.cgi?id=1995809): crio: complete crio default config [#2724](https://github.com/openshift/machine-config-operator/pull/2724)
* [Bug 1993385](https://bugzilla.redhat.com/show_bug.cgi?id=1993385): crio: use conmon from path [#2714](https://github.com/openshift/machine-config-operator/pull/2714)
* [Bug 1975078](https://bugzilla.redhat.com/show_bug.cgi?id=1975078): Gracefully shutdown taking around 6-7 mins (libvirt provider) [#2636](https://github.com/openshift/machine-config-operator/pull/2636)
* [Full changelog](https://github.com/openshift/machine-config-operator/compare/d0db13627e8b48f7021cd4a44d964c55f15b65e1...1aeaf8c9c93dc772e65e23668dd435d06d833bcf)


### [mdns-publisher](https://github.com/openshift/mdns-publisher/tree/1c707a28e88b42780fb37fad4532be7220acd1c5)

* [Bug 1988145](https://bugzilla.redhat.com/show_bug.cgi?id=1988145): Update zeroconf vendoring [#35](https://github.com/openshift/mdns-publisher/pull/35)
* [Full changelog](https://github.com/openshift/mdns-publisher/compare/2c42cc4d95ef276b81cd78d9509e2dc34f3713c1...1c707a28e88b42780fb37fad4532be7220acd1c5)


### [multus-whereabouts-ipam-cni](https://github.com/openshift/whereabouts-cni/tree/19b24930b961395418403856aa570e349999d0c7)

* [Bug 2009497](https://bugzilla.redhat.com/show_bug.cgi?id=2009497): Release on cancel, sync for 4.8 [#70](https://github.com/openshift/whereabouts-cni/pull/70)
* [Bug 1990113](https://bugzilla.redhat.com/show_bug.cgi?id=1990113): Syncs with upstream for leader election [backport 4.8] [#63](https://github.com/openshift/whereabouts-cni/pull/63)
* [Full changelog](https://github.com/openshift/whereabouts-cni/compare/9a05258711b1b459c0b24293a6d8fa77c9e5d852...19b24930b961395418403856aa570e349999d0c7)


### [openshift-apiserver](https://github.com/openshift/openshift-apiserver/tree/e3b259b9f70f3ea3695b73c4f090785c7b964399)

* [Bug 2020644](https://bugzilla.redhat.com/show_bug.cgi?id=2020644): Image policy should mutate DeploymentConfigs [#259](https://github.com/openshift/openshift-apiserver/pull/259)
* [Bug 1992639](https://bugzilla.redhat.com/show_bug.cgi?id=1992639): revert incorrect ssh scp fix [#241](https://github.com/openshift/openshift-apiserver/pull/241)
* [Full changelog](https://github.com/openshift/openshift-apiserver/compare/394986946b6db0d21da5567973bb674aa138d74f...e3b259b9f70f3ea3695b73c4f090785c7b964399)


### [openshift-controller-manager](https://github.com/openshift/openshift-controller-manager/tree/69a83a3f3c290519692a66fd5ffe89586eb1b4b9)

* [Bug 2006793](https://bugzilla.redhat.com/show_bug.cgi?id=2006793): BC ICT still must check spec last triggered image ID in case BC was last processed when cluster was pre 4.8 [#206](https://github.com/openshift/openshift-controller-manager/pull/206)
* [Full changelog](https://github.com/openshift/openshift-controller-manager/compare/2e25328c64ac83e6f25449a6a2507c145352abc9...69a83a3f3c290519692a66fd5ffe89586eb1b4b9)


### [openstack-machine-controllers](https://github.com/openshift/cluster-api-provider-openstack/tree/eb8656e9dfb4e6945ba8a7776433bc19e9397ba8)

* [Bug 2000542](https://bugzilla.redhat.com/show_bug.cgi?id=2000542): Adds Proxy to provider client http transport [#199](https://github.com/openshift/cluster-api-provider-openstack/pull/199)
* [Bug 1985015](https://bugzilla.redhat.com/show_bug.cgi?id=1985015): Eliminate instanceCreate volume leak [#192](https://github.com/openshift/cluster-api-provider-openstack/pull/192)
* [Full changelog](https://github.com/openshift/cluster-api-provider-openstack/compare/3024c78c7026e804f8c4b5765c652110f6df4d7a...eb8656e9dfb4e6945ba8a7776433bc19e9397ba8)


### [operator-lifecycle-manager, operator-registry](https://github.com/openshift/operator-framework-olm/tree/5649248e3d41134d2f0af130b5d00bcd588e7d3d)

* [Bug 1996162](https://bugzilla.redhat.com/show_bug.cgi?id=1996162): Check for pruned bundles on add in replaces mode [#165](https://github.com/openshift/operator-framework-olm/pull/165)
* [Bug 1986476](https://bugzilla.redhat.com/show_bug.cgi?id=1986476): resolver: remove legacy support for fallback parsing of CSVs [#140](https://github.com/openshift/operator-framework-olm/pull/140)
* [Bug 1994038](https://bugzilla.redhat.com/show_bug.cgi?id=1994038): clarify maxOpenShiftVersion upgrade error message [#173](https://github.com/openshift/operator-framework-olm/pull/173)
* [Bug 1994038](https://bugzilla.redhat.com/show_bug.cgi?id=1994038): Update kubebuilder installation in the build root dockerfile [#174](https://github.com/openshift/operator-framework-olm/pull/174)
* [Bug 1994110](https://bugzilla.redhat.com/show_bug.cgi?id=1994110): fix(openshift): drop z from next calculated y-stream [#167](https://github.com/openshift/operator-framework-olm/pull/167)
* [Bug 1989779](https://bugzilla.redhat.com/show_bug.cgi?id=1989779): installplans: retry crd updates on conflicts [#156](https://github.com/openshift/operator-framework-olm/pull/156)
* [Bug 1989711](https://bugzilla.redhat.com/show_bug.cgi?id=1989711): fix(openshift): block upgrades on invalid max properties (#2302) [#155](https://github.com/openshift/operator-framework-olm/pull/155)
* [Bug 1990650](https://bugzilla.redhat.com/show_bug.cgi?id=1990650): Add PriorityClass setting to registry pods for default CatalogSource (#2304) [#158](https://github.com/openshift/operator-framework-olm/pull/158)
* [Bug 1986023](https://bugzilla.redhat.com/show_bug.cgi?id=1986023): Translate legacy "bundle dependencies" to properties. [#134](https://github.com/openshift/operator-framework-olm/pull/134)
* [Full changelog](https://github.com/openshift/operator-framework-olm/compare/e1ceb8eecd87e1ace272b18b2041a191b8e91533...5649248e3d41134d2f0af130b5d00bcd588e7d3d)


### [operator-marketplace](https://github.com/operator-framework/operator-marketplace/tree/3f3d7d1f9e914aff08d2ca2b5663358c8b611656)

* [Bug 1998938](https://bugzilla.redhat.com/show_bug.cgi?id=1998938): Use client-go's leader election implementation [#421](https://github.com/operator-framework/operator-marketplace/pull/421)
* [Bug 1990650](https://bugzilla.redhat.com/show_bug.cgi?id=1990650): Add priorityclass annotation to default catalogsources [#418](https://github.com/operator-framework/operator-marketplace/pull/418)
* [Full changelog](https://github.com/operator-framework/operator-marketplace/compare/e39ff59d5abc3e27effc7b726329d06a37644f2e...3f3d7d1f9e914aff08d2ca2b5663358c8b611656)


### [ovirt-csi-driver](https://github.com/openshift/ovirt-csi-driver/tree/c57863f25ec68b34f3928e02b9b750cfcef3c99c)

* [Bug 2013945](https://bugzilla.redhat.com/show_bug.cgi?id=2013945): pvc stuck on pending status when using preallocated storage domain [#89](https://github.com/openshift/ovirt-csi-driver/pull/89)
* [Full changelog](https://github.com/openshift/ovirt-csi-driver/compare/c0b1ec3222eb9ddabdc44200d7270898ea48eef5...c57863f25ec68b34f3928e02b9b750cfcef3c99c)


### [ovirt-machine-controllers](https://github.com/openshift/cluster-api-provider-ovirt/tree/cbf023408f4e8cee956e5996aa013346e1d16b65)

* [Bug 1989676](https://bugzilla.redhat.com/show_bug.cgi?id=1989676): correct IPAddress detection for OVNKubernetes [#116](https://github.com/openshift/cluster-api-provider-ovirt/pull/116)
* [Full changelog](https://github.com/openshift/cluster-api-provider-ovirt/compare/b6eaef62a476bd6275b51f353e5d5f5c18b398a2...cbf023408f4e8cee956e5996aa013346e1d16b65)


### [ovn-kubernetes](https://github.com/openshift/ovn-kubernetes/tree/46a77c4cdb4d797fcce009442d537dad01018298)

* [Bug 2027487](https://bugzilla.redhat.com/show_bug.cgi?id=2027487): [4.8z] addressManager should not call sync() from ErrorCallback [#853](https://github.com/openshift/ovn-kubernetes/pull/853)
* [Bug 2022043](https://bugzilla.redhat.com/show_bug.cgi?id=2022043): [4.8z] Avoid stale annotations by re-subscribing to netlink [#829](https://github.com/openshift/ovn-kubernetes/pull/829)
* [Bug 2014332](https://bugzilla.redhat.com/show_bug.cgi?id=2014332): [4.8z] Scale fixes for pods/exgws [#798](https://github.com/openshift/ovn-kubernetes/pull/798)
* [Bug 2011391](https://bugzilla.redhat.com/show_bug.cgi?id=2011391): [4.8] bump OVN to 20.12.0-183.el8fdp [#783](https://github.com/openshift/ovn-kubernetes/pull/783)
* [Bug 1986708](https://bugzilla.redhat.com/show_bug.cgi?id=1986708): Add routes for pod: fail only after checking all the gw addresses / ips [#774](https://github.com/openshift/ovn-kubernetes/pull/774)
* [Bug 2005480](https://bugzilla.redhat.com/show_bug.cgi?id=2005480): [4.8z] Remove waiting for namespace and namespace lock contention [#760](https://github.com/openshift/ovn-kubernetes/pull/760)
* [release 4.8] Bug 1994624: Infer subnet for node /128 IPv6 addresses [#661](https://github.com/openshift/ovn-kubernetes/pull/661)
* [Bug 2004336](https://bugzilla.redhat.com/show_bug.cgi?id=2004336): Ensure host interfaces are deleted by CNI [#745](https://github.com/openshift/ovn-kubernetes/pull/745)
* [Bug 2005464](https://bugzilla.redhat.com/show_bug.cgi?id=2005464): [4.8z] Fixes skipping pods accidentally in retry [#758](https://github.com/openshift/ovn-kubernetes/pull/758)
* [Bug 2005357](https://bugzilla.redhat.com/show_bug.cgi?id=2005357): [4.8z] Fixes misuse of pod annotations during update event [#753](https://github.com/openshift/ovn-kubernetes/pull/753)
* [Bug 1996739](https://bugzilla.redhat.com/show_bug.cgi?id=1996739): Fix ensurePod to call addPodExternalGW only for annotation updates [#752](https://github.com/openshift/ovn-kubernetes/pull/752)
* [Bug 2004488](https://bugzilla.redhat.com/show_bug.cgi?id=2004488): panic after EgressFirewall deletion and DNS record expiration [#749](https://github.com/openshift/ovn-kubernetes/pull/749)
* [Bug 2004269](https://bugzilla.redhat.com/show_bug.cgi?id=2004269): Sync ECMP routes on startup and fixes stale ECMP routes [#743](https://github.com/openshift/ovn-kubernetes/pull/743)
* [Bug 1999638](https://bugzilla.redhat.com/show_bug.cgi?id=1999638): Fix duplicate incrementing of subnet allocation metric [#700](https://github.com/openshift/ovn-kubernetes/pull/700)
* [Bug 1996729](https://bugzilla.redhat.com/show_bug.cgi?id=1996729): NetworkPolicy: bulk-add pods to new policies (or on restart) [#678](https://github.com/openshift/ovn-kubernetes/pull/678)
* [Bug 2000214](https://bugzilla.redhat.com/show_bug.cgi?id=2000214): Fix GetPortAddresses for HBO [#711](https://github.com/openshift/ovn-kubernetes/pull/711)
* [Bug 2001641](https://bugzilla.redhat.com/show_bug.cgi?id=2001641): egressfirewall not set after upgrade [#722](https://github.com/openshift/ovn-kubernetes/pull/722)
* [Bug 1996201](https://bugzilla.redhat.com/show_bug.cgi?id=1996201): Fixes cases of timed out while waiting for OVS port binding [#686](https://github.com/openshift/ovn-kubernetes/pull/686)
* [Bug 2001542](https://bugzilla.redhat.com/show_bug.cgi?id=2001542): fix reserve joinSwitch LRP IPs [#720](https://github.com/openshift/ovn-kubernetes/pull/720)
* [Bug 2001363](https://bugzilla.redhat.com/show_bug.cgi?id=2001363): [4.8z] Ensure client handling of canceled/dropped OVSDB monitor [#718](https://github.com/openshift/ovn-kubernetes/pull/718)
* [Bug 1999895](https://bugzilla.redhat.com/show_bug.cgi?id=1999895): Revert "[release-4.8] fix reserve joinSwitch LRP IPs" [#706](https://github.com/openshift/ovn-kubernetes/pull/706)
* [Bug 1996965](https://bugzilla.redhat.com/show_bug.cgi?id=1996965): Add quotes around nexthop and dst-ip fields [#680](https://github.com/openshift/ovn-kubernetes/pull/680)
* [Bug 1994937](https://bugzilla.redhat.com/show_bug.cgi?id=1994937): Fix: sync egress IP for missed events on start-up [#665](https://github.com/openshift/ovn-kubernetes/pull/665)
* [Bug 1997049](https://bugzilla.redhat.com/show_bug.cgi?id=1997049): fix reserve joinSwitch LRP IPs [#681](https://github.com/openshift/ovn-kubernetes/pull/681)
* [Bug 1985957](https://bugzilla.redhat.com/show_bug.cgi?id=1985957): Backport ovnkube-trace requires ip package to be installed to 4.8 [#656](https://github.com/openshift/ovn-kubernetes/pull/656)
* [Bug 1988487](https://bugzilla.redhat.com/show_bug.cgi?id=1988487): Fix lgw eip 4.8 [#636](https://github.com/openshift/ovn-kubernetes/pull/636)
* [Bug 1976241](https://bugzilla.redhat.com/show_bug.cgi?id=1976241): Update existing policy ACLs on start [#635](https://github.com/openshift/ovn-kubernetes/pull/635)
* [Full changelog](https://github.com/openshift/ovn-kubernetes/compare/542b44dd38fb0653e72c52f02db081fee5608869...46a77c4cdb4d797fcce009442d537dad01018298)


### [prometheus-config-reloader, prometheus-operator](https://github.com/openshift/prometheus-operator/tree/8f4efab9e7fa34f79a5900d95113f62908889168)

* [Bug 1979575](https://bugzilla.redhat.com/show_bug.cgi?id=1979575): [4.8]: Add timeout to informers cache sync [#132](https://github.com/openshift/prometheus-operator/pull/132)
* [Full changelog](https://github.com/openshift/prometheus-operator/compare/9d679a145d5eabe58a86bce6cf0da72bd07dd026...8f4efab9e7fa34f79a5900d95113f62908889168)


### [prometheus-node-exporter](https://github.com/openshift/node_exporter/tree/9ad2cf906b9c0c44110401f121dc5cf7d657acca)

* [Bug 1984074](https://bugzilla.redhat.com/show_bug.cgi?id=1984074): netclass: retrieve interface names and filter before parsing [#91](https://github.com/openshift/node_exporter/pull/91)
* [Full changelog](https://github.com/openshift/node_exporter/compare/c9264499d45ecafa1a296db2c00f0a0411e8dc5a...9ad2cf906b9c0c44110401f121dc5cf7d657acca)


### [service-ca-operator](https://github.com/openshift/service-ca-operator/tree/b66c45062dd1c4fc4ce7de2f587647522af60e11)

* Updating ose-service-ca-operator images to be consistent with ART [#177](https://github.com/openshift/service-ca-operator/pull/177)
* Update go version to 1.16 [#179](https://github.com/openshift/service-ca-operator/pull/179)
* [Full changelog](https://github.com/openshift/service-ca-operator/compare/bcc6df48bc48dff748481c5284d05e0c2066f4e6...b66c45062dd1c4fc4ce7de2f587647522af60e11)


### [telemeter](https://github.com/openshift/telemeter/tree/eabad556e8759422b85b2f27248c52626245f1ba)

* Updating telemeter builder & base images to be consistent with ART [#374](https://github.com/openshift/telemeter/pull/374)
* [Full changelog](https://github.com/openshift/telemeter/compare/d6ceb8a4e94f775510591974b2cdeb19819abda0...eabad556e8759422b85b2f27248c52626245f1ba)


### [tests](https://github.com/openshift/origin/tree/afb0cd2c22518d599d0bcf6b6c2ede00ef439b40)

* [Bug 2028021](https://bugzilla.redhat.com/show_bug.cgi?id=2028021): Bump update time limit 4.8 [#26657](https://github.com/openshift/origin/pull/26657)
* [Bug 1929650](https://bugzilla.redhat.com/show_bug.cgi?id=1929650): Increase OVN upgrade timeout by 15m [#26654](https://github.com/openshift/origin/pull/26654)
* [Bug 2025724](https://bugzilla.redhat.com/show_bug.cgi?id=2025724): Add admin ack Upgradeable condition gate test [#26635](https://github.com/openshift/origin/pull/26635)
* [Bug 2020644](https://bugzilla.redhat.com/show_bug.cgi?id=2020644): Add more tests for image policy [#26584](https://github.com/openshift/origin/pull/26584)
* [Bug 2019519](https://bugzilla.redhat.com/show_bug.cgi?id=2019519): Skip test 'clone repository using git:// protocol should clone using git:// if no proxy is configured' [#26562](https://github.com/openshift/origin/pull/26562)
* fix: add proxy support to OAuthServer tests [#26539](https://github.com/openshift/origin/pull/26539)
* [Bug 2008114](https://bugzilla.redhat.com/show_bug.cgi?id=2008114): Add role label to jenkins imagestream [#26503](https://github.com/openshift/origin/pull/26503)
* [Bug 2002552](https://bugzilla.redhat.com/show_bug.cgi?id=2002552): Retry kubeconfig checks, when kube-apiserver is temporarily unavailable [#26458](https://github.com/openshift/origin/pull/26458)
* [Bug 1989402](https://bugzilla.redhat.com/show_bug.cgi?id=1989402): Add tests required internet into Skipped:Disconnected list [#26369](https://github.com/openshift/origin/pull/26369)
* [Bug 1986259](https://bugzilla.redhat.com/show_bug.cgi?id=1986259): Enable TestEndpointAdmission test only for OpenShift SDN [#26351](https://github.com/openshift/origin/pull/26351)
* Re-enable cluster quota test [#26234](https://github.com/openshift/origin/pull/26234)
* [Bug 1978090](https://bugzilla.redhat.com/show_bug.cgi?id=1978090): testPodSandboxCreation: skip sandbox errors for pods which were not deleted during network update [#26297](https://github.com/openshift/origin/pull/26297)
* [Full changelog](https://github.com/openshift/origin/compare/98fef630978d040b8c53726ba9b0751e0651c3a8...afb0cd2c22518d599d0bcf6b6c2ede00ef439b40)


### [thanos](https://github.com/openshift/thanos/tree/f7c1227d2009f439d4200e305246659ebea299f8)

* [Bug 1994156](https://bugzilla.redhat.com/show_bug.cgi?id=1994156): dockerignore: remove vendor from ignored list [#70](https://github.com/openshift/thanos/pull/70)
* [Full changelog](https://github.com/openshift/thanos/compare/c358e963a7c2fad1a4de605a09f4af5e7d2d07f4...f7c1227d2009f439d4200e305246659ebea299f8)


### [vsphere-csi-driver-operator](https://github.com/openshift/vmware-vsphere-csi-driver-operator/tree/18cd9873078206f26d25ecf18893ba0864c0cf62)

* [Bug 2021620](https://bugzilla.redhat.com/show_bug.cgi?id=2021620): Close connection to vCenter API [#51](https://github.com/openshift/vmware-vsphere-csi-driver-operator/pull/51)
* [Full changelog](https://github.com/openshift/vmware-vsphere-csi-driver-operator/compare/edbdd69cb34ced19b0cc0f3a180df56f1ca4899d...18cd9873078206f26d25ecf18893ba0864c0cf62)