Back to index
Download the installer for your operating system or run
oc adm release extract --tools quay.io/openshift-release-dev/ocp-release:4.13.12-x86_64 Tests:
Blocking jobs Informing jobs Upgrades from:
Untested upgrades:
4.12.19 ,
4.12.20 ,
4.12.21 ,
4.12.22 ,
4.12.24 ,
4.12.26 ,
4.12.27 ,
4.12.28 ,
4.12.30 ,
4.13.3 ,
4.13.4 ,
4.13.8 Upgrades to:
Loading changelog, this may take a while ...
Changes from 4.13.2
Created: 2023-09-07 12:37:58 +0000 UTC
Image Digest: sha256:73946971c03b43a0dc6f7b0946b26a177c2f3c9d37105441315b4e3359373a55
Release 4.13.12 was created from registry.ci.openshift.org/ocp/release:4.13.0-0.nightly-2023-09-07-022650
Components
Rebuilt images without code change
OCPBUGS-12565 : CVE-2022-41723 ose-cloud-credential-operator-container: net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding [openshift-4] #543
Full changelog
OCPBUGS-18063 : cgroup: Match the name of the cgroup to what is expected by kubelet (#774) #774
update tsc karg to tsc=reliable (#757) #757
OCPBUGS-17845 : deflake ht aware test (#763) #763
OCPBUGS-17794 : rps: use default rps mask kernel API (#760) #760
Improve render error handling (#755) #755
nto:tuned: remove sched_min_granularity_ns settings (#726) #726
Fix a race in e2e test rollback.go code (#740) #740
E2E: Add memory manager sanity test case (#573) (#695) #573
e2e: latency testing: increase the expected threshold (#709) #709
Do not rollback settings on TuneD exit (#704) #704
Switch to rslave/HostToContainer volume mount propagation (#705) #705
e2e: perf-prof: disable truncating gomega output (#707) #707
OCPBUGS-14895 : Do not fail creating cgroups if they exist already (#684) #684
OCPBUGS-14331 : Fix updating numa core siblings map in GetCpuSiblings function (#669) #669
render: remove uid from render-sync target (#594) (#609) #594
Remove cpu-quota.crio.io: disable annotation (#670) #670
Add PerformanceProfiles to ‘oc adm must-gather’ (#657) #657
Full changelog
OCPBUGS-18398 : UPSTREAM <carry>: update build images to rhel9 #212
OCPBUGS-15859 : [4.13] Rebase openshift/etcd to 3.5.9 #204
Backport 15656 to release-3.5 #15815
Move go version to dedicated .go-version file #15860
Backport updating go to latest patch release 1.19.9 #15822
server: backport 15743, improved description of –initial-cluster-sta… #15774
etcdserver: verify field ‘username’ and ‘revision’ present when decoding a JWT token #15676
etcdserver: guarantee order of requested progress notifications #15695
server/auth: fix auth panic bug when user changes password #15512
backport 15294 #15619
etcdserver: set zap logging to wsproxy #15661
backport 15648 #15653
bump golang to 1.19.8 to fix four CVEs #15651
chore: enable strict mode for test CI #15558
Backport fixes all docker images of Architecture show amd64 #15612
Add testing of etcd in local image in release workflow #15608
Separate grpc server 3.5 #15589
Automated cherry-pick of #14860: Trigger release in current branch for github workflow case #15443
server/embed: fix data race when start insecure grpc #15517
Fix issue15271 #15515
Connection multiplexing regression tests for v3.5 #15491
Backport tls 1.3 support #15483
Use random scheduler Watch #15452
Run go mod tidy #15454
Backport update to latest go 1.19.7 release #15428
Backport bump to go 1.19.6 and golang.org/x/net to v0.7.0 #15337
Backport adjusting time resolution to microseconds #15240
etcdserver: add failpoints walBeforeSync and walAfterSync #15264
Backport: netutil: consistently format ipv6 addresses #15187
upgrade cockroachdb/datadriven to v1.0.2 to remove archived dependencies #15225
etcdserver: return membership.ErrIDNotFound when the memberID not found #15096
etcdserver: process the scenaro of the last WAL record being partially synced to disk #15069
Update nsswitch.conf for 3.5 #15041
3.5: remove the dependency on busybox #15037
Security: address HIGH Vulnerabilities #15018
client/pkg/v3: fixes Solaris build of transport #14920
Security: use distroless base image to address critical Vulnerabilities #15016
fix: specify the correct branch name of release-3.5 in workflow for… #15010
Add trivy nightly scan for release-3.5
#15006
clientv3: revert the client side change in 14547 #14995
etcdserver: fix nil pointer panic for readonly txn #14899
Backport: non mutating requests pass through quotaKVServer when NOSPACE #14884
etcdserver: intentionally set the memberID as 0 in corruption alarm #14852
Full changelog
OCPBUGS-17187 : Update to Kubernetes 1.26.7 #1649
releng/go: Bump images, versions and deps to use Go 1.20.6 #119367
Automated cherry pick of #119229: Fix the converts an empty string to nil. #119261
Automated cherry pick of #114464: Set permissions on volume before publishing update #114728
Automated cherry pick of #117865: Parallel StatefulSet pod create & delete #119223
Automated cherry pick of #115966: make MixedProtocolNotSupported public #118252
Automated cherry pick of #116749: Adding additional validations to queried endpoint #117225
releng/go: Update images, deps and version to go 1.20.5 #119201
Automated cherry pick of #119160: Only declare job as finished after removing all finalizers #119163
Automated cherry pick of #114338: kubeadm: set priority for “system-node-critical” Pods #119117
Automated cherry pick of #118460: Make etcd component status consistent with health probes #119038
Update schedule logic to properly calculate missed schedules #119138
AWS: fix code for picking region from zone #118364
Automated cherry pick of #118177: Fix the git-repo test error caused by the correct use of loop #118289
Automated cherry pick of #116251: Fix deadlock in ready test #119030
Automated cherry pick of #117243: Add node check to vSphere cloud provider #117937
Automated cherry pick of #117791: update serial number to a valid non-zero number in ca #118970
Automated cherry pick of #118150: kubeadm: remove function pointer comparison in phase test #118168
Automated cherry pick of #118257: dra scheduler plugin test: fix loopvar bug and “reserve” #118284
deps: Bump to cAdvisor v0.46.1 #118798
OCPBUGS-17145 : Increase service idle max timeout to 100 minutes #1657
OCPBUGS-15866 : remove readiness check for cache exclusion #1625
OCPBUGS-15866 : UPSTREAM: <drop>: hack/update-vendor.sh #1637
OCPBUGS-15246 : Bump to k8s 1.26.6 #1610
releng/go: Update images, deps and version to go 1.19.10 #118555
Automated cherry pick of #118515: kube-proxy avoid race condition using LocalModeNodeCIDR #118516
Automated cherry pick of #118356: Add ephemeralcontainer to imagepolicy securityaccount #118473
Automated cherry pick of #117792: kubeadm: Use internal etcd client through an interface #117916
Automated cherry pick of #117586: Add DisruptionTarget condition when preempting for critical #118221
Automated cherry pick of #118156: update webhook test to go 1.21 #118179
Cherry Pick of #114766: [Prepare for go1.20] *: Bump versions and fix tests #115051
Automated cherry pick of #118069: kubeadm: fix a bug where the static pod changes detection #118106
Automated cherry pick of #118104: Fix waiting for CRD sync at server start #118112
OCPBUGS-8738 : bump apiserver-lib-go #1611
OCPBUGS-14589 : [release-4.13] UPSTREAM: 118383: bump cadvisor for upstream patch 3301 #1596
OCPBUGS-13747 : 4.13: kubelet/cm: disable cpu load balancing on slices when using static cpu manager policy #1580
Full changelog
Updated secret permissions for openshift-route-controller-manager #2923
HOSTEDCP-1121 : Ensure SG reconciliation for aws endpoint #2885
chore(deps): update rhtap references (release-4.13) #2921
Revert “HOSTEDCP-1110: [backport-4.13] Allow HCP Specification to Support ICSP & IDMS” #2931
chore(deps): update rhtap references (release-4.13) #2904
Update RHTAP references (release-4.13) #2866
HOSTEDCP-1046 : Add ImageDigestMirrorSet to Config API comment #2870
HOSTEDCP-1046 : Add IDMS to the list of valid config manifests #2863
Update RHTAP references (release-4.13) #2833
HOSTEDCP-1110 : [backport-4.13] Allow HCP Specification to Support ICSP & IDMS #2839
OCPBUGS-15743 : Let getMachinesForNodePool return machines ordered by creation Timestamp #2767
4.13: Add management cluster KAS network policy #2786
Leader election config update. #2801
OCPBUGS-16160 : fix deletion bug when hostedzone is already deleted #2813
HOSTEDCP-1061 : [release-4.13] Implement dedicated request serving nodes for HostedClusters #2809
Update RHTAP references (release-4.13) #2816
OCPBUGS-16057 : use ignition-proxy Service to populate ignitionEndpoint with strategy NodePort #2798
OCPBUGS-14862 Improve clarity around hypershift operator permissions #2810
HOSTEDCP-1101 : Add snyk-secret HO RHTAP scripts #2799
OCPBUGS-16125 : [release-4.13] Update vendored dependencies #2797
OCPBUGS-15774 : autoscaling balance similar groups #2805
OCPBUGS-15965 : Reject VPCE Connections during VPCE Service cleanup #2789
Update RHTAP references (release-4.13) #2751
OCPBUGS-15171 : Skip AWS resource deletion for ‘Unknown’ OIDC state #2701
HOSTEDCP-1008 : Add NodePoolTransitionSeconds metric #2758
OCPBUGS-15281 : Check OwningIngressController also in Labels #2715
HOSTEDCP-1060 : refactor ignition-server reconcilation and add ignition-server proxy #2748
HOSTEDCP-1073 : enforce blocked rollout of HCP #2735
HOSTEDCP-1003 : Set AWS conditions only for AWS platform #2670
OCPBUGS-15268 properly handle user CA bundle not existing #2710
OCPBUGS-15301 : [release-4.13] fix(oauth): Do not proxy IBM Cloud IAM endpoints #2696
OCPBUGS-14030 : Include default ingress CA in root CA bundle #2599
OCPBUGS-14490 : Enable HCCO to reconcile over the OperatorHub’s disableAllDefaultSources object #2645
OCPBUGS-14801 : Set DisableStrictZoneCheck = true
in the AWS Cloud Provider config #2666
HOSTEDCP-1048 : Add impersonate feature to the CLI and document HC dump procedure #2681
OCPBUGS-14872 : Honor global ingress configuration LoadBalancer type on AWS #2677
OCPBUGS-14436 : Add ClusterUpgradeDuration metric #2637
HOSTEDCP-1009 : Allow external-dns image to be set in install cli #2652
Red Hat Trusted App Pipeline update hypershift-operator-release-413 #2641
Red Hat Trusted App Pipeline purge hypershift #2640
OCPBUGS-13735 : Cluster-api SA can’t create events and fix permissions wrongly included #2610
OCPBUGS-14242 : Remove external-dns –events flag #2621
OCPBUGS-14155 : Reconcile oauthDeployment annotations even if kubeadmin secret is not found #2613
OCPBUGS-13399 : Fix errors from HCP controller removeServiceCAAnnotationAndSecret() #2552
HOSTEDCP-1010 : Set ETCD Storage Size as immutable field and equalised the default size among both api versions #2611
Full changelog
OCPBUGS-14773 : extend configmap gatherer to get gateway-mode-config (#788) (#791) #788
[release-4.13 ]OCPBUGS-15031: fix the config serialization & add test (#794) (#796) #794
OCPBUGS-14318 : gather PDBs only from openshift namespaces (#786) #786
Full changelog
Switch to udevadm command install instead of package [OKD] #83
“Bug OCPBUGS-15777: Switch to udevadm command install instead of package” #81
Full changelog
OCPBUGS-4417 : Denormalize IP name before checking if pod is alive [Backport 4.13] #168
OCPBUGS-15956 : Updating ose-multus-whereabouts-ipam-cni images to be consistent with ART #138
Bug 16002 : Change default binary to RHEL8 image #144
Restores RHEL specific binary build in dockerfile and updates to rhel9/8 #139
Full changelog
Source code for this page located on github