Back to index
4.12.0-0.okd-2023-03-05-022504 Download installer and client with:
oc adm release extract --tools quay.io/openshift/okd:4.12.0-0.okd-2023-03-05-022504 No tests for this release
Upgrades from:
Upgrades to:
Loading changelog, this may take a while ...
Created: 2023-03-05 09:21:06 +0000 UTC
Image Digest: sha256:fef2d0803e6ee6ec36d1979a0b847441580fbd9ee3ad583c97edb7ff811ee3b6
Release 4.12.0-0.okd-2023-03-05-022504 was created from registry.ci.openshift.org/origin/release:4.12.0-0.okd-2023-03-05-022504
Components
Kubernetes 1.25.4
Fedora CoreOS upgraded from 37.20221225.3 to 37.20230205.3
Rebuilt images without code change
MGMT-13192 : dualstack SNO cluster fails to complete - getting error In dual stack installation we should set dhcp,dhcp6 kargs in order to wait for ipv6 address when node comes after reboot (#4914) #4914
Full changelog
OCPBUGS-29559 : Apply hypershift cluster-profile for ibm-cloud-managed #999
OCPBUGS-32328 : azure-path-fix: support auth via account key (without clientID) #1021
OCPBUGS-30484 : bump indirect google protobuf dependency #1015
NO-JIRA: remove bparees from owners #1019
OCPBUGS-29233 : bump aws-sdk-go from v1.44 to v1.50 #1012
AUTH-482 : set required-scc for openshift workloads #1008
NO-JIRA: bump golangci-lint to v1.56.2 #1013
OCPBUGS-29932 : cmd/move-blobs: log and exit 1 on error instead of panic #1006
OCPBUGS-29637 : azurepathfix: fix stack hub, government and workload identity setup #1003
OCPBUGS-29003 : move azure storage blobs from docker
back into /docker
#998
NO-JIRA: Add hack/local-dev.sh #996
OCPBUGS-28225 : pkg/storage/s3: enable bucket key on encryption settings #993
OCPBUGS-28230 : add FallbackToLogsOnError for easier debugging #992
NO-JIRA: build(deps): bump golang.org/x/oauth2 from 0.8.0 to 0.16.0 #989
OCPBUGS-26767 : MULTIARCH-4074: PowerVS: update supported regions #987
IR-409 : build(deps): bump github.com/IBM/platform-services-go-sdk from 0.18.15 to 0.55.0 #974
OCPBUGS-24997 : Updating ose-cluster-image-registry-operator-container image to be consistent with ART #979
IR-410 : build(deps): bump github.com/aliyun/alibaba-cloud-sdk-go from 1.61.1263 to 1.62.637 #980
OCPBUGS-11624 : manifests/02-rbac.yaml: stop using wild cards #964
OCPBUGS-24649 : add private endpoint permissions to Azure credentials request #971
OCPBUGS-24997 : Updating ose-cluster-image-registry-operator-container image to be consistent with ART #975
IR-412 : IBMCloud: Add support for endpoint overrides #955
CCO-248 : Revert “Merge pull request #965 from jstuever/TRT-1368” #967
OCPVE-790 : annotate credentials request manifests #959
OCPBUGS-24161 : Updating ose-cluster-image-registry-operator-container image to be consistent with ART #966
TRT-1368 : Revert “Merge pull request #935 from flavianmissi/CCO-248” #965
IR-366 , IR-367 , IR-411 : allow users to configure private storage accounts in Azure #930
IR-408 : request individual permissions for gcs #935
OCPBUGS-2889 : accept user/pass OR application credentials on Swift UPI secret #924
IR-406 , OCPBUGS-21853 : bump k8s and openshift packages #936
OCPBUGS-21853 : disable http2 for metrics endpoint #938
OCPBUGS-18969 : move pruner role creation from openshift-apiserver #925
OCPBUGS-19262 : Updating ose-cluster-image-registry-operator images to be consistent with ART #918
OCPBUGS-18469 : increase storage account key cache expiration #912
OCPBUGS-17060 : use Recreate on operator deployment #908
OCPBUGS-18103 : check if response is nil before using it #909
OCPVE-632 : add capability annotations to manifests #856
OCPBUGS-17882 : Add rbac permission IDMS, ITMS #891
TRT-1193 : Revert “IR-373: remove node-ca daemon” #899
CFE-846 : Add user defined tags to the GCP buckets created #873
IR-373 : remove node-ca daemon #867
build(deps): bump github.com/stretchr/testify from 1.8.1 to 1.8.4 #877
build(deps): bump the k8s-dependencies group with 1 update #895
IR-363 : Update Azure Credentials Request manifest of the Cluster Image Registry Operator to use new API field for requesting permissions #890
build(deps): bump github.com/prometheus/common from 0.37.0 to 0.44.0 #878
CFE-682 : Add user defined labels to the GCP buckets created #872
CFE-682 : Update openshift/api package to latest version #887
IR-390 : Make a configmap for MCO to consume CAs #880
build(deps): bump github.com/aws/aws-sdk-go from 1.44.291 to 1.44.298 #879
build(deps): bump golang.org/x/net from 0.8.0 to 0.11.0 #871
build(deps): bump github.com/aliyun/aliyun-oss-go-sdk from 2.1.10+incompatible to 2.2.7+incompatible #869
.github/dependabot.yml: group certain dependencies #865
IR-389 : bump aws-sdk-go #860
.github: configure dependabot #861
IR-369 , IR-370 : support Azure workload identity #857
OCPBUGS-12132 : Updating ose-cluster-image-registry-operator images to be consistent with ART #854
Updating ose-cluster-image-registry-operator images to be consistent with ART #849
OCPBUGS-8224 : fix storage selection on IBM cloud #847
OCPBUGS-6797 : Add nil validation for IBM Cloud and Power VS infrastructure status in ibmcos #845
MULTIARCH-3212 : Use IBM COS as storage backend for PowerVS #843
OCPBUGS-6621 : bump aws-sdk-go #844
Add UserTags while creating Azure Storage Account #829
IR-341 : bump openshift/api #828
IR-270 : allow registry to create image objects #823
OCPBUGS-6175 : OpenStack: Add support for Proxy #833
IR-308 : Add support for External platform #825
OCPBUGS-4090 : swift: Retry connecting to OpenStack #819
IR-311 : storage: azure: use azidentity with an adapter #807
Bug 2065166 : Remove roles/iam.serviceAccountUser role #824
Updating ose-cluster-image-registry-operator images to be consistent with ART #821
IR-314 : Bump dependencies #816
Add config for golangci-lint and fix errors #820
hack/test-go.sh: generate coverage reports #818
OCPBUGS-3974 : check for nil pointer before dereferencing #814
Bug 2066388 : Add example for s3.regionEndpoint #815
OCPBUGS-2941 : Bump gophercloud #808
add myself to OWNERS #809
Full changelog
OCPBUGS-29567 : Apply hypershift cluster-profile for ibm-cloud-managed #106
OCPBUGS-27930 : Updating ose-cluster-kube-storage-version-migrator-operator-container image to be consistent with ART for 4.16 #103
OCPBUGS-24989 : Updating ose-cluster-kube-storage-version-migrator-operator-container image to be consistent with ART #101
OCPBUGS-21738 : bump library-go to include switch to HTTP/1.1 #95
OCPBUGS-19253 : Updating ose-cluster-kube-storage-version-migrator-operator images to be consistent with ART #94
Revert “specify master node selector on migrator pod” #93
OCPBUGS-17170 : specify master node selector on migrator pod #92
OCPBUGS-16513 : bump(*): update to 1.27.1 #91
Fix operator doc in README #90
Updating ose-cluster-kube-storage-version-migrator-operator images to be consistent with ART #89
OCPBUGS-6240 : Updating ose-cluster-kube-storage-version-migrator-operator images to be consistent with ART #87
Full changelog
E2E: Per Core Runtime Tuning Test automation (#509) (#568) #509
E2E: Network stack Pinning tests (#533) #533
Run node selector tests only if we 2 non Performanceworker nodes (#554) #554
skip multiple ranges test if cores < 20 and use core as key to delete cpu siblings (#543) #543
pao: latency-tests: read test log directly from pod (#547) #547
Add authentication to the /metrics endpoint (#553) #553
Update NTO images to be consistent with ART (#557) #557
OCPBUGS-5021 : [release-4.12] Fix two irqbalance tests - smp affinity vs online (#530) #530
Full changelog
WRKLDS-1015 : tolerate node-role.kubernetes.io/control-plane:NoExecute #574
OCPBUGS-29580 : Apply hypershift cluster-profile for ibm-cloud-managed #572
OCPBUGS-32346 : the apiservice controller waits until bootstrap complete #575
NO-ISSUE: Makefile: fixes test-e2e-encryption-rotation targets #577
NO-ISSUE: fix: TestRedeployOnConfigChange #576
OCPBUGS-22969 : Use v1 for flowcontrol API #559
OCPBUGS-18115 : Remove “include.release.openshift.io/ibm-cloud-managed:” annotation #566
OCPBUGS-18939 : manifest: drop slo latency metrics in favor of sli #547
WRKLDS-1004 : use AlwaysAllow UnhealthyPodEvictionPolicy in PDBs #562
OCPBUGS-24972 : Updating ose-cluster-openshift-apiserver-operator-container image to be consistent with ART #561
OCPBUGS-18115 : Remove “include.release.openshift.io/ibm-cloud-managed:” annotation #551
OCPBUGS-19231 : Updating ose-cluster-openshift-apiserver-operator images to be consistent with ART #548
OCPBUGS-21733 : bump library-go to include switch to HTTP/1.1 #552
WRKLDS-728 : Capabilities: drop build/apps APIService when capabilities are not enabled #532
switch image-registry cert CM #545
OCPBUGS-16554 : update dependencies to get rid of goproxy #546
AUTH-408 : bindata: set required-scc #544
Plumb featuregates to the openshift-apiserver #542
allow etcd healthcheck timeout closer to probe timeouts to avoid failing on slower etcd #540
Add AES-GCM encryption tests #539
OCPBUGS-14010 : increase timeout for probes #536
OCPBUGS-2765 : Library go bump #538
OCPBUGS-12813 : Updating ose-cluster-openshift-apiserver-operator images to be consistent with ART #534
Updating ose-cluster-openshift-apiserver-operator images to be consistent with ART #525
OCPBUGS-10040 : update openshift/api to include aesgcm provider in the default apiserver schema #526
API-1509 : Enable AESGCM encryption #521
OCPBUGS-4343 : update apf configuration to use v1beta3 #509
OCPBUGS-6233 : Bump dependencies and images #517
OCPBUGS-5300 : routes/status resources can leak sensitive data, exclude it from audit #511
make api team approver #506
OCPBUGS-3929 : update apf configuration to use v1beta2 #508
Full changelog
OCPBUGS-23848 : Bumps opentelemetry dependencies #341
OCPBUGS-29973 : Updating ose-cluster-openshift-controller-manager-operator-container image to be consistent with ART for 4.16 #337
OCPBUGS-29581 : Apply hypershift cluster-profile for ibm-cloud-managed #334
OCPBUGS-22969 : Use v1 for flowcontrol API #316
BUILD-854 : Add adambkaplan as approver #338
OCPBUGS-24888 : Updating ose-cluster-openshift-controller-manager-operator-container image to be consistent with ART #321
OCPBUGS-28666 : Replace ‘coreydaley’ with ‘sayan-biswas’ in OWNERS file #326
OCPBUGS-23624 : Add .snyk file to exclude vendor and ignore unit tests #325
WRKLDS-1016 : Bump k8s dependencies to 1.29.0 #324
OCPBUGS-24190 : Disable deployer-controller when deploymentconfig is disabled #320
OCPBUGS-22956 : Remove blockage of ConfigObserver by build informer HasSynced flag #315
Revert “Revert #300 “API-1666: add image pull secret cleanup controller”” #314
Revert #300 “API-1666: add image pull secret cleanup controller” #313
API-1642 : add image pull secret cleanup controller #300
API-1642 : Do not generate image pull secrets for internal registry when internal registry is disabled. #298
OCPBUGS-21830 : bump(k8s,openshift) to address CVE-2023-44487 #308
OCPBUGS-20164 : Include Build CRD in manifests #306
WRKLDS-806 : Bump kube dependencies to 1.28.2 #305
OCPBUGS-19136 : Updating ose-cluster-openshift-controller-manager-operator images to be consistent with ART #304
OCPBUGS-18932 : Always sort disabled controller list #302
OCPBUGS-18498 : Disable BuildConfigChange controller when Build cap is disabled #299
route-controller-manager deployment updates #295
OCPBUGS-16072 : Updating Kubernetes and other associated dependencies #296
OCPBUGS-13926 : change the operator log level to default normal in the deployment #289
BUILD-582 , OCPBUGS-14638 : bump(k8s): 1.27.1 #294
OCPBUGS-13926 : add loglevel controller for OCM-o #292
Revert “13895: [WRKLDS-730] route-controller-manager deployment updates” #293
OCPBUGS-13895 : [WRKLDS-730] route-controller-manager deployment updates #288
Updating ose-cluster-openshift-controller-manager-operator images to be consistent with ART #287
Updating ose-cluster-openshift-controller-manager-operator images to be consistent with ART #286
Updating ose-cluster-openshift-controller-manager-operator images to be consistent with ART #285
Bump golang.org/x/net from 0.5.0 to 0.7.0 #284
Updating ose-cluster-openshift-controller-manager-operator images to be consistent with ART #279
OCPBUGS-10568 : migrate to using lease objects for leader election #282
Add Divyanshu Agrawal as a reviewer #283
OCPBUGS-4343 : update apf configuration to use v1beta3 #273
Updating ose-cluster-openshift-controller-manager-operator images to be consistent with ART #274
WRKLDS-594 : bump(k8s): 1.26.1 #277
OCPBUGS-5275 : remove unnecessary RBAC for leader-locking-ingress-to-route-controller #276
OCPBUGS-3929 : update apf configuration to use v1beta2 #272
let deployer pods patch/apply replication controllers #270
Bug 2111979 : Set openshift.io/run-level to nil in openshift-controller-manager nam… #269
Full changelog
Bump fedora-coreos to latest stable #555
Revert “Dockerfile.ci: report real FCOS version” #552
Revert “DEBUG: don’t pull in fresh FCOS” #532
Dockerfile.ci: report real FCOS version #549
manifests: remove extensions manifests #548
selinux fixes: allow iptables wrapper to write to tmpfs #546
Dockerfile: replace existing kubelet #543
Add a service which applies custom SELinux fixes #541
Dockerfile: enable services via systemd presets #540
Dockerfile: install netcat #538
Bump fedora-coreos to latest stable #531
overlay: prevent NM from modifying resolv.conf #528
Bump fedora-coreos to latest stable #526
Dockerfile.rpms: use stable CRIO releases #521
Bump openshift-os to latest release-4.12 #523
Bump openshift-os to latest release-4.12 #518
Dockerfile: remove rpm-ostree override #515
Full changelog
Add e2e test for cluster creation with AWS KMS #2201
HOSTEDCP-826 : Customize DNS base domain prefix #2235
feat: Add pod gone check to prober + DNS operator leader elect #2209
fix(ibmcloud): Explicitly set HCCO controllers #2208
ensure reconcilation of apiserver port is in 4.12 #2195
Cleanup default security group only if authorized #2212
fix(cpo): Set restart annotation on multus-admission-controller #2190
fix(cpo): Remove OLM collect for IBM Cloud to reduce artifacts and rbac #2189
fix(cpo): Reduce CNO access if Calico used as network provider #2184
Skip destroyAWSDefaultSecurityGroup if not AWS #2168
Create default security group for AWS clusters #2162
AUTH-323 : pki: split out konnectivity certs from the rootCA #2156
fix(ibmcloud): Initialize image registry config on creates and bad config #2104
fix(cpo): Allow KAS profiling disablement #2122
reduce ignition server scope #2140
OpenID add support for groups claim in the config #2129
fix(cpo): Restart registry operator on annotation #2121
Fix CAPA crd generation #2120
Set k8s.io/kubernetes dependency to v0.23.3 #2118
fix(cpo): Separate RBAC for NTO + CNO #2112
Merge main up to db7c22ae into ‘release-4.12’ #2101
Merge main into release-4.12 branch #2053
Full changelog
Updating ose-network-interface-bond-cni images to be consistent with ART #37
Full changelog
Updating ose-network-metrics-daemon images to be consistent with ART (#60) #60
Fix gofmt check issue (#68) #68
Update golang.org/x/text to 0.7.0 (#66) #66
Full changelog
OCPBUGS-6703 : fix: adds logic that searches for the correct name when using a heads… (#554) #554
Updating oc-mirror-plugin images to be consistent with ART (#515) #515
Full changelog
Source code for this page located on github