Back to index
4.12.0-0.okd-scos-2023-02-14-060109 Download installer and client with:
oc adm release extract --tools quay.io/okd/scos-release:4.12.0-0.okd-scos-2023-02-14-060109 Team Approvals:
No tests for this release
Created: 2023-02-14 10:29:38 +0000 UTC
Image Digest: sha256:968a5b06be2095ef337aaf4f5d951292875dd538b6e76d5cee826f3a6cd307d1
Release 4.12.0-0.okd-scos-2023-02-14-060109 was created from registry.ci.openshift.org/origin/release-scos:4.12.0-0.okd-scos-2023-02-14-060109
Components
Rebuilt images without code change
MGMT-13192 : dualstack SNO cluster fails to complete - getting error In dual stack installation we should set dhcp,dhcp6 kargs in order to wait for ipv6 address when node comes after reboot (#4914) #4914
MGMT-12863 : Assisted Spoke install-config does not generate icsp with multiple mirror to entries (#4748) #4748
MGMT-12635 : Add icsp-file support for all oc commands (#4684) (#4700) #4684
Full changelog
Bug OCPBUGS-5156: Add ApplicationSecurityGroups to InterfaceIPConfiguration #92
OCPBUGS-4783 : OpenStack: Support multi AZ environments #88
OCPBUGS-4784 : OpenStack: Only return egressIPConfiguration for first InternalIP #89
Full changelog
CNTRLPLANE-112 : Remove ARO HCP MIv2 Authentication for Ingress Operator #1222
CNTRLPLANE-112 : Add new Azure authentication type for managed Azure HCP for cluster-ingress #1191
NE-2009 : Relax pod bound validating admission rule for HyperShift #1221
NE-1969 : Set Degraded=True if unmanaged Gateway API CRDs exist #1205
NE-1957 : Add Gateway API DNS Feature e2e tests #1213
OCPBUGS-54650 , OCPBUGS-54651 , OCPBUGS-54652 : desiredSubscription: Specify annotations and SCC #1214
NE-2009 : Move VAP to Default featureset #1216
OCPBUGS-54568 : desiredIstio: Specify priorityClassName #1211
OCPBUGS-53424 : Wait for install plans to enter the “Requires Approval” phase before approving them #1203
NE-2008 : Add GRPC conformance tests #1208
NE-1277 : status: Add Gateway API objects to relatedObjects #933
NE-1994 : Add E2E test for Istio manual deployment #1204
NE-1969 : Add “v1” version to OpenShift GatewayClass controller name #1202
NE-1934 : Bump to OSSM 3.0 for Gateway API support #1152
CORS-3907 : Update ingress operator to with custom endpoints #1197
NE-1953 : Add experimental Gateway API group to Validating Admission Policy #1200
NE-1907 : Manage OSSM operator subscription manually to ensure a compatible version is installed #1112
NE-1981 : Move controller test helpers to dedicated package #1199
NE-1953 : Add Validating Admission Policy for Gateway API CRDs #1192
NE-1954 : Implement GatewayAPIController feature gate #1198
NE-1936 : Bump k8s.io dependencies to v0.32.1 #1184
OCPBUGS-31550 : Gateway API - recreating SMCP which breaks Gateway API #1115
OCPBUGS-32776 : Fix IBM Public Cloud DNS Provider Update Logic #1133
OCPBUGS-48780 : Fix IBMCloud DNS Propagation Issues in E2E #1164
OCPBUGS-43745 : Skip Test_IdleConnectionTerminationPolicyDeferred when DCM feature gate is enabled #1186
NE-1260 : Add Makefile target to run Gateway API conformance tests #1176
OCPBUGS-43745 : Add support for IdleCloseTerminationPolicy (Go http.Client) #1182
OCPBUGS-45585 : Updating ose-cluster-ingress-operator-container image to be consistent with ART for 4.19 #1173
OCPBUGS-41892 : Single Watch on GWAPI CRD #1165
NE-1790 : Follow up to enable Dynamic Configuration Manager feature gate #1174
SPLAT-1722 : Remove alibaba #1111
CORS-3755 : AWS: Add Ingress LB IPs to Infra CR when in-cluster DNS is enabled #1167
NE-1790 : Enable Dynamic Configuration Manager feature gate #1159
OSASINFRA-3642 : openstack: support setting external LB floating IP #1147
HOSTEDCP-2031 : Use Client Certificate Authentication for ARO HCP deployments #1151
OCPBUGS-43412 : Bump to k8s.io v0.31.1 (and deps) #1156
NE-1716 : Bump Gateway API to v1.0.0 and OSSM to v2.6 #1163
CFE-1134 : Watch infrastructure and update AWS tags #1148
OCPBUGS-43033 : e2e/ingress_dns: support both private & public #1153
OCPBUGS-37932 : Always log AWS service endpoints #1137
OCPBUGS-36340 : Retry IngressController and Route updates in E2E tests #1116
OCPBUGS-42004 : Set the MI client ID for the ARO HCP override #1144
AUTH-482 : set required-scc for openshift workloads #1031
OCPBUGS-36044 : Bump IBM/go-sdk-core to v5.17.4 #1120
OCPBUGS-41527 : Add tolerations to survive scheduler taint manager e2e tests on workers #1143
OCPBUGS-41112 : Updating ose-cluster-ingress-operator-container image to be consistent with ART for 4.18 #1140
OCPBUGS-39151 : Add Missing Scope Change Instructions #1135
OCPBUGS-38871 : ingress: deployment: explicitly set DeploymentStrategy in SingleReplica case #1134
OCPBUGS-37491 : Ingress operator status not degraded when canary route fails #1125
OCPBUGS-38217 : Clear LB Status Parameters on LB Type Change #1126
OCPBUGS-34418 : Allow router pods to use the “restricted” SCC #1064
OCPBUGS-38441 : Resolve DNS Resolution CI Flakes in Subnets and EIP E2E #1127
OCPBUGS-38079 : Bump controller-runtime to v0.18.4 #1122
NE-1798 : API bump for promotion of eipAllocation from feature gates to GA. #1118
NE-1688 : Enable Azure MSI authentication for ARO HCP #1119
NE-1674 : Add LB EIP Allocation for AWS #1109
NE-1531 : Fix Initialization of NLB Status Parameters #1114
NE-1531 : AWS Subnet Selection #1046
NE-1273 : Add a watch to the ingress operator so it will recreate the gwapi crds #1106
OCPBUGS-37627 : Fix getRouteHost error handling #1110
NE-1208 : Gateway API E2E Testing #1023
OCPBUGS-31664 : Fix SyncLoadBalancerFailed status message of IngressController #1102
OCPBUGS-36465 : Delete and recreate canary route to clear spec.host #1095
OCPBUGS-34413 : Refine logging for accurate infra CR status updates #1103
OCPBUGS-35342 : Add e2e test for connect timeout #1084
NO-JIRA: Add grzpiotrowski to OWNERS #1090
NO-JIRA: addowner-Thealisyed #1091
OCPBUGS-35356 : Retry IngressController updates in router status E2E #1085
OCPBUGS-9037 : Change Canary to use passthrough route #978
OCPBUGS-35368 : Add Regexp Anchor to TestAll #1087
OCPBUGS-23221 : internalServiceChanged: Fix target port logic #1052
OCPBUGS-34262 : Updating ose-cluster-ingress-operator-container image to be consistent with ART for 4.17 #1067
NE-1400 : Bump to OSSM 2.5 and Gateway API v0.6.2 CRDs #1018
OCPBUGS-33792 : Bump openshift/library-go to resolve NewPrometheusClient E2E failures #1054
OCPBUGS-32887 : Allow operator to update Route spec.subdomain #1047
OCPBUGS-32942 : Bump controller-runtime to v0.17.3 #1050
OCPBUGS-28673 : implement connect timeout tuning option #1035
NE-1317 : manifests - add ingress capability annotation #950
OCPBUGS-32371 : Bump openshift/api, and update CRD generation #1045
OCPBUGS-25193 : Add vnet subnet read and join permission for azure #1029
OCPBUGS-30834 : Update to go 1.21 #1040
OCPBUGS-31722 : Use centos7 tag for quay.io/centos7/httpd-24-centos7 image #1037
OCPBUGS-3522 : Include recent errors in canary checks fail #865
OCPBUGS-30091 : TestHostNetworkPortBinding: Delete t.Parallel() #1032
CFE-987 : Use RouterExternalCertificate feature gate for adding ROUTER_ENABLE_EXTERNAL_CERTIFICATE env var to the router pods #1017
CORS-2317 : Add Ingress LB IPs to Infra CR and set DNS unmanaged when BYO DNS is enabled #1016
OCPBUGS-28596 : Updating ose-cluster-ingress-operator-container image to be consistent with ART for 4.16 #1020
OCPBUGS-28230 : add FallbackToLogsOnError for easier debugging #1019
NE-1490 : update to go v1.20 #1012
OCPBUGS-15253 : Include namespace in prometheus alerts IngressWithoutClassName and UnmanagedRoutes #980
CCO-249 : Replace GCP role with explicit permissions #844
OCPBUGS-25006 : Updating ose-cluster-ingress-operator-container image to be consistent with ART #1006
OCPBUGS-24531 : Revert “ OCPBUGS-24531 Skip CI for scope change until OCPBUGS-24044 is resolved” #1011
OCPBUGS-24531 : Revert “Merge pull request #1007 from candita/OCPBUGS-24531-SkipScopeChangeTest” and add changes to skip test only for Azure and GCP #1008
OCPBUGS-24531 : Skip CI for scope change until OCPBUGS-24044 is resolved #1007
OCPVE-780 : annotate credentials request manifests #995
OCPBUGS-23742 : Bump controller-runtime to v0.16.3 #1001
NE-1402 : Add service endpoint override capability to IBM DNS provider #990
OCPBUGS-16762 : Revert “OCPBUGS-16762: Bump openshift/api for container.maxLength fix” #982
OCPBUGS-14994 : Don’t add clientca-configmap finalizer if deleting #948
OCPBUGS-22020 : Bump golang.org/x/net for CVE-2023-44487 #985
OCPBUGS-21803 : test/e2e: Add test case for 2000000 maxConnections #983
OCPBUGS-20192 : Require non-readonly filesystem in router container #981
OCPBUGS-16762 : Bump openshift/api for container.maxLength fix #979
OCPBUGS-3541 : Don’t create route metrics for ingress controllers that are not admitted #869
OCPBUGS-18248 : Prevent GatewayClass from getting recreated #975
OCPBUGS-19268 : Updating ose-cluster-ingress-operator images to be consistent with ART #977
OCPBUGS-15900 : TestMTLSWithCRLs: only try to parse HTTP status code from curl output when stdout is long enough. #973
OCPBUGS-3356 : E2E test for cookie length truncation #871
OCPBUGS-15978 : Check public DNS zone when reporting status #967
OCPBUGS-17359 : test/e2e: Don’t use openshift/origin-node #970
NE-1140 , NE-1145 : Set/delete HTTP request/response headers via IngressController API #872
OCPBUGS-16089 : Set spec.subdomain on the canary route #965
OCPBUGS-14995 : desiredRouterDeployment: Set HostPort if needed #947
OCPBUGS-10875 : gateway-service-dns: Set DNS policy appropriately #934
NE-1244 : Use permissions instead of the “Contributor” role in Azure CredentialsRequest #929
OCPBUGS-12790 : README: Fix Bugzilla link #968
RFE-3007 : Expose option-contstats as an unsupported option #887
NE-1189 : Refactor Test_desiredLoadBalancerService #886
NE-1187 : Use t.Run for table-driven tests #884
NE-1183 : Rename unit tests for specific functions #880
NE-1269 : Replace bindata using embed #905
RFE-3765 : Allow Ingress to Modify the HAProxy Log Length when using a Sidecar #900
OCPBUGS-9274 : canary: Tolerate infra node NoExecute taint #932
OCPBUGS-7546 : Allow only 1 disruption with 3 replicas #931
OCPBUGS-15100 : Fix previous attempt of adding a missing trailing dot to hostname #956
OCPBUGS-14396 : Set controller-runtime logger to a null logger for E2E #946
OCPBUGS-14998 : Only use RoleARN for Route53 API #951
OCPBUGS-15100 : Create valid DNS names for Gateway API on GCP #949
OCPBUGS-13106 : Add ingress controller status logging on waitForIngressControllerCondition #924
OCPBUGS-13190 : Avoid spurious updates for internalTrafficPolicy #927
OCPBUGS-13810 : Update TestAWSELBConnectionIdleTimeout to not use wildcard DNS record #944
NE-1294 : Add support for AWS shared VPC in another account #928
CCO-318 : Enable Azure Workload Identity authentication. #906
OCPBUGS-6661 , OCPBUGS-9464 : Move mTLS CRL handling into the router, and fix accidental duplication of CRLs #939
OCPBUGS-13963 : Bump vendors k8s libraries to 0.27.2 #936
Revert “OCPBUGS-6661, OCPBUGS-9464: Move mTLS CRL handling into the router, and fix accidental duplication of CRLs” #938
OCPBUGS-6661 , OCPBUGS-9464 : Move mTLS CRL handling into the router, and fix accidental duplication of CRLs #930
OCPBUGS-5478 : add UBI based Dockerfile #925
CCO-318 : Read feature gates for future usage #908
OCPBUGS-12913 : Deflake TestRouterCompressionOperation #920
OCPBUGS-6784 : bump controller-runtime to fix the multi namespace cache indexing #913
OCPBUGS-12579 : Address CVE-2022-41723 #915
OCPBUGS-12790 : Replace Bugzilla link with Red Hat Issue Tracker #916
OCPBUGS-10714 : gatewayclass: Update for OSSM 2.4 API change #901
OCPBUGS-10189 : Updating ose-cluster-ingress-operator images to be consistent with ART #898
OCPBUGS-10846 : Fix TestClientTLS flakes #904
NE-1184 : Test_desiredHttpErrorCodeConfigMap: Kill dead code and fix format #881
OCPBUGS-4054 : configurable-route: Don’t use NewKindWithCache #860
NE-1186 : Test_getRR: Fix typo: “excepted” → “expected” #883
CORS-2467 : dns: azure: use azidentity with an adapter #846
NE-1105 : Add support for Gateway API #890
OCPBUGS-7424 : Bump vendored k8s libraries to 1.26.1 #888
CFE-679 : Add user defined tags to the created DNS resources #874
OCPBUGS-6247 : Updating ose-cluster-ingress-operator images to be consistent with ART #862
CORS-2072 : GCP - Parse Zone ID with a project ID embedded #855
NE-1092 : Add proxy protocol support for IBMCloud loadbalancers #812
OCPBUGS-6384 : Address CVE-2022-41717 #876
OCPBUGS-4827 : Add missing AWS permission for ListTagsForResources #868
OCPBUGS-6701 : Avoid spurious updates for scope in IngressClass #879
OCPBUGS-6698 : Fix conflict error message in ensureNodePortService #877
OCPBUGS-6700 : updateIngressClass: Fix log message #878
NE-1124 : Add support for External platform to CIO #873
OCPBUGS-4573 : Target metrics port by name in internal service #864
OCPBUGS-434 : Absorb PodsScheduled condition into MinAvailable #854
OCPBUGS-4759 : Do not manage DNS for an ingresscontroller with domain mismatch in GCP #866
OCPBUGS-4703 : Replace liveness-grace-period-seconds annotation #863
OCPBUGS-3404 : Bump openshift/api for matchExpressions doc fix #856
OPNET-133 : Support remote worker #858
OCPBUGS-1725 : Ingress controller should not have affinity policy in single-replica clusters #810
OCPBUGS-1807 : Fix bad handleSingleNode4Dot11Upgrade
log message #808
Full changelog
OCPBUGS-45640 : Updating ose-cluster-kube-storage-version-migrator-operator-container image to be consistent with ART for 4.19 #122
API-1835 : bump library-go #120
OCPBUGS-20062 : “gracefully” shutdown KSVM pod. #118
NO-JIRA: operator/starter.go: don’t report an error on shutdown #117
OCPBUGS-41169 : Updating ose-cluster-kube-storage-version-migrator-operator-container image to be consistent with ART for 4.18 #116
NO-JIRA: bump(*) #113
OCPBUGS-34306 : Updating ose-cluster-kube-storage-version-migrator-operator-container image to be consistent with ART for 4.17 #110
OCPBUGS-34306 : Updating ose-cluster-kube-storage-version-migrator-operator-container image to be consistent with ART for 4.17 #109
AUTH-482 : set required-scc for openshift workloads #107
OCPBUGS-29567 : Apply hypershift cluster-profile for ibm-cloud-managed #106
OCPBUGS-27930 : Updating ose-cluster-kube-storage-version-migrator-operator-container image to be consistent with ART for 4.16 #103
OCPBUGS-24989 : Updating ose-cluster-kube-storage-version-migrator-operator-container image to be consistent with ART #101
OCPBUGS-21738 : bump library-go to include switch to HTTP/1.1 #95
OCPBUGS-19253 : Updating ose-cluster-kube-storage-version-migrator-operator images to be consistent with ART #94
Revert “specify master node selector on migrator pod” #93
OCPBUGS-17170 : specify master node selector on migrator pod #92
OCPBUGS-16513 : bump(*): update to 1.27.1 #91
Fix operator doc in README #90
Updating ose-cluster-kube-storage-version-migrator-operator images to be consistent with ART #89
OCPBUGS-6240 : Updating ose-cluster-kube-storage-version-migrator-operator images to be consistent with ART #87
Full changelog
E2E: Network stack Pinning tests (#533) #533
Run node selector tests only if we 2 non Performanceworker nodes (#554) #554
skip multiple ranges test if cores < 20 and use core as key to delete cpu siblings (#543) #543
pao: latency-tests: read test log directly from pod (#547) #547
Add authentication to the /metrics endpoint (#553) #553
Update NTO images to be consistent with ART (#557) #557
OCPBUGS-5021 : [release-4.12] Fix two irqbalance tests - smp affinity vs online (#530) #530
Remove trailing space from test name (#546) #546
Fix default hard eviction threshold when PCC is applied (#520) #520
Full changelog
Skip destroyAWSDefaultSecurityGroup if not AWS #2168
Create default security group for AWS clusters #2162
AUTH-323 : pki: split out konnectivity certs from the rootCA #2156
fix(ibmcloud): Initialize image registry config on creates and bad config #2104
fix(cpo): Allow KAS profiling disablement #2122
reduce ignition server scope #2140
OpenID add support for groups claim in the config #2129
fix(cpo): Restart registry operator on annotation #2121
Fix CAPA crd generation #2120
Set k8s.io/kubernetes dependency to v0.23.3 #2118
fix(cpo): Separate RBAC for NTO + CNO #2112
Merge main up to db7c22ae into ‘release-4.12’ #2101
Merge main into release-4.12 branch #2053
Release 4.12 rebase latest #2047
Fix OpenID OAuth config parsing #2029
Fast foward release-4.12 to main #2003
OCPBUGS-5133 : Reinstate hosted cluster configuration propagation #1981
Remove CAPA command from deployment #1970
Fast forward release-4.12 to main #1964
Remove CAPI manager container command path #1969
v1beta1: add missing S3 publishing strategy type #1968
Fast forward ‘release-4.12’ branch to ‘main’ #1932
Full changelog
Updating ose-kubevirt-csi-driver-rhel8 images to be consistent with ART #12
Full changelog
Source code for this page located on github