Back to index
4.8.0-0.ci-2023-05-18-073708
Download the installer for your operating system or run
oc adm release extract --tools registry.ci.openshift.org/ocp/release:4.8.0-0.ci-2023-05-18-073708
Tests:
- Blocking jobs
- Informing jobs
- upgrade-minor Failed periodic-ci-openshift-release-master-ci-4.8-upgrade-from-stable-4.7-e2e-aws-upgrade
Upgrades from:
Loading changelog, this may take a while ...
Created: 2023-05-18 07:39:49 +0000 UTC
Image Digest: sha256:82ed1941a661070019f5d58c70b3832f72ea2b3d29d2c6424d1fe960a067aef4
Components
- OCPBUGS-2598: ipsec: Run ovs-monitor-ipsec in the foreground and change probes #1606
- SDN-3508: HyperShift: Render cncc with proxy settings of the management cluster #1577
- NP-607: update microshift ovnk manifests #1589
- Bug 1896533: moved SetDegraded call out of object loop to process all items first #1600
- OCPBUGS-2362: Prefer oldest nodes, harden new alerts and revert setting new OVN-K alerts to info #1579
- fixed typo in comment #1597
- Jira OCPBUGS-1736: Always set PROXY variables for CNCC #1576
- Remove the allow_ra sysctl for ipv4 from default systl whitelist #1590
- SDN-2591: allow hybrid overlay to be enabled post install #1584
- SDN-3515: HyperShift: multus admission controller: expose metrics over HTTPs #1583
- rebase to k8s v1.25.0 #1571
- Bug OCPBUGS-2328: Fix for index out of range error #1588
- Add sysctl whitelist controller #1573
- Kuryr: Add missing keystoneauth options #1581
- OCPBUGS-1341: Set owner reference for pod network connectivity check #1566
- ovn-k, managed: pass join-subnet to control-plane #1582
- OCPBUGS-1083: Move OVNK alert level to info #1564
- Pass enable-udp-aggregation=true to ovn-kubernetes #1533
- OCPBUGS-1038: Multus IPAM detection should honor conflists #1570
- egress_ip: remove redundant config #1568
- OCPBUGS-1515: Use custom uint128 type when validating v6InternalSubnet #1561
- SDN-3283: HyperShift: Use a socks-proxy in ovnkube-master to allow for node heath checks #1539
- Bug: OCPBUGS-736: Kuryr: Use machine net MTU to create service net #1545
- Migrate Egress IP configuration during SDN migration and rollback #1536
- Allow empty vSphere status field in VIP sync #1558
- microshift: update ovnk manifests #1552
- Add ovn-kubernetes-microshift to image-stream #1556
- Migrate Multicast configuration during SDN migration and rollback #1543
- OVN-K: add patch/update service permissions to controller #1554
- Add controller to synchronize the API and Ingress VIP fields #1519
- Bug SDN-3458: HyperShift: Differentiate resources deployed by different CNO instances in status manager #1541
- OVN-K alerts: first tranche #1526
- SDN-3432: Add alert for OVNKubernetesControllerDisconnectedSouthboundDatabase #1548
- Add vSphere platform to allow dual-stack cluster #1518
- OKD-49: Adds support for scos to multus #1544
- Bug 1894268: Allow users to specify ovnkube join subnet #1508
- Bug OCPBUGS-917: Add EgressQoS DstCIDR format validation #1492
- Multus admission controller: Wait for token in Hypershift #1546
- Use fixed name for creating EgressFirewall CRs #1540
- Migrate Egress Firewall Configuration during SDN migration and Rollback #1534
- hypershift: set multus controller priority appropriate for hosted clusters #1538
- Bug 2094068: Add northboundstale alert runbook #1482
- microshift: compact ovn databases periodically #1537
- Hypershift: Allow configuring hostname and labels on the route #1531
- Multus admission controller changes for hypershift #1516
- HyperShift: Move CNCC to the controll-plane namespace #1525
- Bug OCPBUGS-216: Kuryr: Bump timeoutSeconds for livenessProbe #1528
- Add missing runbook links for OVN-kubernetes alerts #1523
- Bug 2103680: avoid overrriding disableNetworkDiagnostics on reconciliation #1527
- Render CRDs for both OSDN and OVNK during migration #1521
- Configure ignored namespaces into multus-admission-controller #1515
- Add microshift ovnk manifests #1517
- Bug 2116982: multus-admission-controller SNO number of replicas #1524
- Enable the cloud-network-config-controller for OpenStack #1505
- multi-networkpolicy: Enable on SR-IOV networks #1443
- Updating cluster-network-operator images to be consistent with ART #1507
- Add configmap list/watch rights to cloud-network-config-controller #1511
- The Multus admission controller should run as a deployment #1514
- Bug 2108232: Revert “Bug 2085089: Pass enable-udp-aggregation=true to ovn-kubernetes” #1510
- Bug 2100601: Update CNO to config EgressIP timeout for ovnk #1498
- Bug 2060079: Enhance sensitivity of SDN alert NodeProxyApplySlow #1491
- Bug 2103590: Add init container to ensure that Status.podIP is set before postStart hooks run #1503
- remove @squeed from owners #1497
- Bug 2085089: Pass enable-udp-aggregation=true to ovn-kubernetes #1489
- Bug 2089681: Disable EgressIP reachability check in hypershift deployments #1485
- Bug 2084062: Make northd probe interval default to 10 seconds #1494
- Bug 2100079: Update sdn-controller perms for “configmapsleases” leaderelection #1496
- Bug 2099357: k8s 1.24 bump: add RBAC coordination leases for ovn-k master #1490
- Bug 2094071: Add southboundStale alert runbook #1481
- Bug 2095772: bindata: managed: reduce memory requests to align with observed usage #1479
- Bug 2095756: client: register types during init, not later #1483
- Bug 2090336: Multus should log at a verbose log level (without a logfile) #1474
- Bug 2092047: cncc: add RBAC coordination.k8s.io leases #1461
- Bug 2089805: Enable config duration for OVN-Kubernetes #1455
- Bug 2090437: Bump CNO to k8s 1.24 #1459
- Bug 2073452: Copying CNI binaries should be an atomic operation. #1472
- Bug 2092495: ovn: use up to 4 northd threads in non-SNO clusters #1471
- Bug 2091167: incorrectly setting rbac role for certificatesigningrequests #1463
- Revert “Copying CNI binaries should be an atomic operation.” #1466
- Bug 2073452: Copying CNI binaries should be an atomic operation. #1462
- Bug 2076776: remove patch permissions from ovnkube-node service account #1450
- Bug 2089968: ensures type: Directory for multus host paths #1453
- Bug 2090343: [temporary] Adds multus debug logging #1456
- Bug 2087942: bump to go 1.18, lint improvements #1451
- Bug 2086461: Hypershift: Also add default for Azure mtu #1454
- Bug 2086461: AWS: Use hardcoded MTU to speed up cluster creation #1441
- Bug 2087556: Fix rendering DPU manifests #1448
- Bug 2086506: hypershift: respect statefulset when upgrading ovnk #1447
- Bug 2087135: Fixing Hypershift nodeport flow #1440
- Bug 2086544: Stop passing hosted cluster token as a parameter to ovnkube-master #1446
- Bug 2086437: Enable EgressQoS controller #1430
- Bug 2086143: Status controller: use a label, rather than watching all objects #1431
- Bug 2082235: manifests: Add in service, service-cert, and ServiceMonitor #1433
- Bug 2023295: Cleanup CNO relatedObjects #1432
- Bug 2079422: Bump PodDisruptionBudget to v1 #1427
- Re-reconcile network on configmap, stop watching all configmaps in proxy controllers #1416
- hypershift: add ovnkube-node-proxy container in ovnkube-node ds #1408
- Hypershift: enable TLS for ovnkube-master metrics #1423
- Add gm metric record to use for telemetry exposure #1425
- Revert “ovn: reduce SB<->ovn-controller inactivity probe to 30 seconds” #1428
- Bug 2082611: Limit Kuryr pods permissions #1367
- Bug 2076877: Bump FlowScema apiVersion to v1beta2 #1419
- bindata/network-diagnostics, cloud-network-config-controller: comply to restricted pod security level #1406
- Remove ObjectMeta.ClusterName usage #1421
- Hypershift: Fix ovnkube-master priority class and set resource requests on token-minter #1420
- add more sysctls to the multus allowlist #1411
- ovn: fix northd preStop command handling #1414
- Add control-plane-component label to ovnkube-master for hypershift #1422
- Add link to runbook urls #1417
- Hypershift: Copy all CNO conditions to HostedControlPlane status #1415
- ovn: reduce SB<->ovn-controller inactivity probe to 30 seconds #1412
- Bug 2075475: Add default-route field to egress-router k8s.v1.cni.cncf.io/networks #1390
- OCPVE-106 Customize rollout strategy to fix SNO upgrade #1392
- Bug 2080255: SDN: Re-add list/watch/get permissions for nodes needed for EgressIP #1409
- Bug 2071859: Switch dnsPolicy to Default for OVN hostNetwork pods #1395
- Revert “Revert ipsec: Allow enablement/disablement at runtime” #1384
- ovnkube: export OVS metrics along with OVN metrics #1393
- Bug 2078910: Correct runbook_url field location within schema #1396
- Adds dougbtv to owners as approver and reviewer #1397
- Bug 2072215: Make the use of the ip-reconciler cronjob opt-in by detecting IPAM type usage #1369
- ovn-kube hypershift: fix pipefailure that prevents HA startup #1394
- Bug 2063123: Drop Node update permission for sdn-node #1350
- OVN-K alert: Increase severity and add runbook_url for NoRunningOvnMa… #1327
- Remove Kuryr mutating DNS webhook #1363
- raise the alert NoOvnMasterLeader to critical and add the runbook url #1328
- Bug 2072710: Make northd probe interval default to 10 seconds #1386
- hypershift: get control plane replicas from hcp #1385
- Bug 2072766: Reserve port TCP/9104 for cluster-network-operator #1378
- Multus: split pod/status rbac #1340
- add runbook link for NodeWithoutOVNKubeNodePodRunning and V4SubnetAll… #1366
- OVN: remove detecing db_ip via kapi #1368
- Hypershift: Respect publishing strategy of OVN southbound database service #1349
- Proxyconfig: Add a knob for Hypershift to enable proxying internal apiserver address #1381
- Bug 1983056: Kuryr: Update CRD from upstream #1360
- hypershift: disable TLS for ovnk master metrics #1382
- hypershift: enable publishNotReadyAddress explicitly for ovnk-master service #1372
- Bug 2070047: Bump max value of hist quantile for kuryr_cni_request_duration #1359
- Don’t return err with empty relatedClusterObject annotation #1379
- hypershift: enable ovnk-master metrics in management cluster #1374
- Use (un)setProgressing for pod status update #1376
- Use the hosted cluster token explicitly #1370
- HyperShift: Watch StatefulSets in the management cluster #1364
- Exclude openshift-kube-apiserver and openshift-apiserver service/endpoints from connectivity checks in hypershift #1375
- Run ovnkube-master statefulset pods in parallel #1361
- Add ibm-cloud-managed annotations to 02-cncc-credentials.yaml, this is required in HyperShift #1358
- Add ipsec daemonset for hypershift managed cluster #1356
- Add statefulset in status manager #1345
- hypershift ovnk route status #1341
- Add tuning cni sysctl allowlist to nodes #1347
- Bug 2058368: move enable memory trimming to readiness prob #1365
- Add ovnkube-node initContainer to make sure sbdb is up before running other containers #1354
- Vendor: pull in hypershift #1346
- Hypershift: Use token minter instead of a kubeconfig in ovn-kubernetes master #1344
- Add an option to define the client name for in-cluster config #1342
- Add ovnkube manifests for hypershift #1329
- network, bootstrap: don’t get apiserver from the environment #1339
- Fix MTU detection for multi path default routes #1338
- Multi cluster support in CNO #1319
- Fix golang image version in Dockerfile #1330
- Remove empty selector from the mtu prober job. #1331
- Switch to server-side apply #1304
- Probe MTU from a Job, rather than directly in the CNO #1313
- Bug 2058368: Move memory-trimming-on-compaction out of dbchecker to nbdb/sbdb #1320
- Fix group for CVO override used for running CNO locally #1314
- Bug 2058671: ip reconciler: auto clean failed jobs #1318
- Bug 2037721: Do not apply OVN-Kubernetes
PodDisruptionBudget
on single-node clusters #1307
- ovn: stop spawning the ovn-nbctl daemon #1315
- Bug 1944264: ovnkube: gracefully terminate databases from preStop #1312
- Bug 2044227: Add rolling update strategy for Kuryr-CNI. #1311
- Bug 2032559: Block DualStack migration for unsupported cluster types #1257
- Bug 2010361: SDN alerts: conform to monitoring team style guide #1248
- Update project owners #1309
- Bug 2048575: The Whereabouts ip-reconciler should use api-int load balancer #1302
- Bug 2048793: Kuryr: Decrease vif_annotation_timeout #1293
- Bug 2049613: Use a separate configmap for mtu migration config to avoid pod restart #1299
- Fix bond cni source directory path #1295
- Updating cluster-network-operator images to be consistent with ART #1294
- Bug 2041546: ovn-kubernetes: set RAFT election timer at RAFT cluster creation time #1282
- Bug 2034484: Upgrade library-go version #1247
- Bug 2042796: whereabouts, reconciler: disable retries on failure #1290
- Bug 2039345: Verify against mininimal IPv6 MTU value for clusters with IPv6 networks #1276
- Bug 2034155: Adds back –disable-snat-multiple-gws #1254
- Bug 2039321: SDN: Expose controller metrics for collection #1250
- clean up OWNERS #1287
- Bug 2041989: no CredentialsRequests in ibm-cloud-managed #1280
- Bug 2035459: modify cluster-network-features for OpenshiftSDN #1251
- Bug 1896533: Nonexistent Namespaces Degradation logging message #1128
- Bug 2038732: Add egress* patch credentials for ovnkube-master #1285
- Bug 2041329: cncc: add serviceAccountNames to CredentialsRequests #1283
- Bug 2010663: OVN-K alerts: conform to monitoring team style guide #1246
- Bug 2021191: Project admins should be able to list net-attach-defs in their namespaces #1226
- BUG 2034413: cncc: create Cloud CredentialsRequest in /manifests #1277
- Bug 2034460: cncc: handle advanced AWS and Azure configurations #1275
- Bug 2034153: Fix MTU migration verification for OpenShiftSDN #1259
- Bug 1943363: ovn: try to gracefully terminate ovn-northd #1221
- Bug 2018093: Kuryr: Add resource requests for pods #1269
- Bug 2036861: multitenant - Add openshift-kube-apiserver-operator to global namespaces #1272
- Bug 2035093: Cloud network config controller: Fix for Hypershift #1268
- Bug 2034398: Whereabouts CRD should include a “podref” field. #1262
- Bug 2034517: watch and apply changes of the ovs-flows-config configmap #1231
- Bug 2034322: Move infrastructure bootstrap to its own package #1261
- Bug 2033422: bootstrapOVNGatewayConfig should only be called once #1258
- Add MTU migration support for OVNKubernetes and OpenshiftSDN #1241
- Cloud network config controller - CNO deployment #1112
- Bug 2022144: sbdb and nbdb containers leave pid around if they restarted or crashed #1256
- OVN-K alerts: Fix incorrect metric name reference #1237
- Pod networking on DPU host in Infra and Tenant clusters #1249
- OVN-K: Enable OVN metrics to be consumed by ServiceMonitor #1236
- Bump openshift/build-machinery-go #1253
- SDN 2316: Use GatewayConfig in OVN-K to set gateway modes #1209
- Add CNI to DPU and enable Kube-Proxy on DPU #1220
- NETOBSERV-31: Expose CNI type features as a config-map #1204
- Bump openshift/api module #1242
- The ip-reconciler should not restart on failures. #1238
- SDN: Do not tolerate a controller failure during upgrade #1213
- Set upgrade strategy on kube-proxy #1214
- openshift-sdn/daemonset: Mount /host/opt/cni/bin at /host-cni-bin #1172
- Specific SDN controller alert #1206
- update for ART #1233
- bindata/network: specify pod-security levels via labels not annotations #1224
- Add bond-cni #1205
- Bug 1961509: DHCP Daemon should have memory and CPU limits set #1218
- Add ip6tables NOTRACK rules for udp/6081 #1222
- Bug 1962206: DHCP daemon should have maxunavailable for upgrade strategy #1219
- Bug 1976399: Raft election timer: move the logic to ovndbchecker #1161
- Bug 2009078: Remove NetworkPodsCrashLooping alert for ovn-kubernetes #1212
- Bug 1914053: whereabouts: add ip-reconciler cronjob #1207
- Add Kuryr to be able to create events objects. #1210
- fix a typo in a field name #1208
- podsecurity: enforce privileged for network namespaces #1203
- Bug 1988483: OVN drop icmp frag from other nodes on Azure cluster #1132
- Bug 1985486: Use proxy to connect to OSP cloud #1173
- Updating cluster-network-operator images to be consistent with ART #1198
- Bug 2003676: Restrict serving SDN metrics to loopback only #1197
- Bug 2002713: Add millisecond resolution to OVN logs #1196
- Bug 1939435: proxyconfig - accept IPv6 address literals for noProxy #1191
- Bug 1986061: Monitor openshift-network-diagnostics namespace #1190
- Bug 1960101: Fix update-codegen hack, pull in changes from openshift/api, bump k8.io deps to v0.22.1 #1140
- Bug 1997050: Fix panic with unknown networks #1188
- Bug 1998508: Fix the install-time “waiting for other operators” statuses #1192
- Bug 1990631: ovnkube: use ovn-nbctl daemon monitor mode to restart and log issues #1182
- Bug 1914398: Changed pod user to non-root #1124
- Bug 1991551: allow sdn (and others) to use new events.k8s.io API #1177
- Bug 1989246: use new default leader election values to handle apiserver rollout on SNO #1175
- Bug 1992507: Use prometheus rule annotations comply with the OpenShift alerting guidelines #1181
- Bug 1989734: Whereabouts should have RBAC for leases #1174
- Bug 1984049: Slow OVN Recovery on SNO #1159
- Bug 1990725: Add missing node name into KuryrSDNPodNotReady Alert #1176
- Bug 1987019: Support external control plane topology #1158
- Docs: add architecture overview, remove outdated HACKING guide. #1078
- Remove valadas from owners #1081
- Bug 1989122: let openshift-sdn use EndpointSliceProxying #1166
- Updating cluster-network-operator images to be consistent with ART #1136
- Bug 1981055: ovnkube-master handle 60 seconds downtime of API server gracefully in SNO #1154
- Bug 1985033: Make inactivity_probe configurable #1165
- Bug 1984449: Change to use mountPath: /host #1160
- Bug 1961757: ovnkube: set ovn-controller lflow cache limit to 1GB #1147
- Revert: Add env variable OVS_SYS_LOG_LEVEL for ovn nodes to setup ovs syslog level #1163
- Bug 1981975: Update service network status to reflect dual stack entries #1155
- Bug 1970985: SDN-1955: Add pre-puller ds to reduce upgrade downtime #1141
- Bug 1961811: Add a newline between user CAs and system CAs #1156
- OVNKube: check if br-ex1 is available and pass it as a parameter #1152
- Make egress IP and ICNI mutually exclusive when bootstrapping OVN-kube #1145
- Bug 1970129: Add env variable OVS_SYS_LOG_LEVEL for ovn nodes to setup ovs syslog level #1142
- Add alerts for issues with load balancers/ports. #1148
- Include alerts for critical lbs #1146
- Removing old kuryr-kubernetes CRDs #989
- Bug 1962951: enable ovs column diffs feature #1101
- Bug 1975016: Kuryr: Store OpenStack credentials in a secret #1139
- Add JacobTanenbaum to list of approvers #1099
- Updating .ci-operator.yaml
build_root_image
from openshift/release #1130
- Full changelog
- Revert PAO and later changes #330
- Bug 2017427: tuned: add timeout and restarts #282
- Makefile cleanup, replace yq with yaml-patch from openshift/build-machinery-go #274
- Bug 2016988: openshift profile: fix malformed patch #283
- Bug 2013321: TuneD: workaround for high CPU utilization of [scheduler] plug-in. #278
- RBAC: tighten the rules and remove unnecessary listers. #276
- podsecurity: enforce privileged for openshift-cluster-node-tuning-operator namespace #275
- Updating cluster-node-tuning-operator images to be consistent with ART #273
- Bug 2004508: TuneD: Revert the ConfigParser changes. #271
- Updating cluster-node-tuning-operator images to be consistent with ART #270
- OWNERS: updating based on team changes. #269
- e2e tests: s/plugin/plug-in/ and TuneD renaming #253
- Bug 1998247: Reload when deps of recommended profile change. #267
- Bug 1997486: Ship the latest TuneD and stalld. #265
- Bug 1994891: Fix e2e tests after the recent 1.22.0 bump #264
- Bug 1992560: monitoring: comply with OpenShift alerting guidelines #263
- Bug 1994891: Bump vendor dependencies to k8s 1.22.0 #261
- Bug 1985739: Move OpenShift profile to TuneD. #258
- Bug 1986477: Handle kube-apiserver disruption more gracefully. #256
- scheduler: new option cgroup_ps_blacklist #250
- Address a race in the stalld e2e test. #249
- IBM Cloud manifest profile patch for operator deployment #252
- Ship the latest TuneD, adjust default Tuned CR. #245
- Updating to the latest stalld v1.13.0. #246
- openshift-tuned event-driven change processing #243
- Adjusting the OWNERS file due to team changes. #244
- Updating to the latest stalld v1.12.0. #242
- Bug 1974277: Fix conditional order for setting net device param. #239
- Bug 1973154: Switch back to NTO-shipped stalld. #236
- Updating cluster-node-tuning-operator images to be consistent with ART #235
- More precise description of MCP matching. #219
- Updating .ci-operator.yaml
build_root_image
from openshift/release #234
- Full changelog
Source code for this page located on github