# 4.5.0-0.okd-2021-06-22-181304 Created: 2021-06-22 18:19:45 +0000 UTC Image Digest: `sha256:aff854e6a066f93b5a41ddd916f192d442ac00c77cd365ae3d5e9b13b6771fd4` ## Changes from 4.5.0-0.okd-2021-01-22-120006 ### Components * Kubernetes 1.18.3 * Fedora CoreOS 32.20200629.3 ### Rebuilt images without code change * [cluster-authentication-operator](https://github.com/openshift/cluster-authentication-operator) git [a83cc709](https://github.com/openshift/cluster-authentication-operator/commit/a83cc7098374abb284df86fdf0129ee469cfacb8) `sha256:ba493c3cc875383958d1f7a807fc97d49fcac5af522f70874d50133c0730d8d5` * [cluster-bootstrap](https://github.com/openshift/cluster-bootstrap) git [04c97c30](https://github.com/openshift/cluster-bootstrap/commit/04c97c30e79430ad836fceff4c6f8c9429be6663) `sha256:fa46b1a574370682a210e9dd7c4db8f03d793ae3dbc4344e6028db7ca97cbe27` * [cluster-kube-apiserver-operator](https://github.com/openshift/cluster-kube-apiserver-operator) git [cc6cbbe4](https://github.com/openshift/cluster-kube-apiserver-operator/commit/cc6cbbe4db9a5bd5393f17c342716e979c1f2ab2) `sha256:40c3f1d85a9413ebe53db9422abc4989004f3debe2c4f9c6ffe23a0c23c0ea56` * [etcd](https://github.com/openshift/etcd) git [41904e79](https://github.com/openshift/etcd/commit/41904e79b6b8c8c3e006a23c66d39451ac3c6718) `sha256:a36b6103aaabeb13610f753249ebe3654053ea095be9cf7aa9951971ff5d2048` * [ironic-machine-os-downloader](https://github.com/openshift/ironic-rhcos-downloader) git [561c7d4c](https://github.com/openshift/ironic-rhcos-downloader/commit/561c7d4cb21fc2e5137f5919e5931f302a3cd383) `sha256:52d21b2d4e3a53e553d62b5d77a90942039e3672b6b0d7c02c7232b750281194` * [ironic-static-ip-manager](https://github.com/openshift/ironic-static-ip-manager) git [058e8fd2](https://github.com/openshift/ironic-static-ip-manager/commit/058e8fd2c99955d4012df6985eb8936ed1a7a4c2) `sha256:ca55da0d6d2b2705a745267bee1cdd918ae22a5454ef745ad45b81bcf32874e7` * [kube-storage-version-migrator](https://github.com/openshift/kubernetes-kube-storage-version-migrator) git [f7a9be91](https://github.com/openshift/kubernetes-kube-storage-version-migrator/commit/f7a9be91ec5eeb1f8a7ad2472349cbb75ade8a1a) `sha256:e63e9151c50310b62e080e3fd67033d2a70760bc9e2239f4ebef6f1579845612` ### [baremetal-runtimecfg](https://github.com/openshift/baremetal-runtimecfg/tree/5385547d7e1df49f4c0d97cc6200b1d9ae9f422f) * [Bug 1926730](https://bugzilla.redhat.com/show_bug.cgi?id=1926730): add CloseIdleConnections for HTTP K8S API healthcheck [#122](https://github.com/openshift/baremetal-runtimecfg/pull/122) * [Full changelog](https://github.com/openshift/baremetal-runtimecfg/compare/952b86b7a7f75f4d07c8ab142f73ae8ba7b1ebde...5385547d7e1df49f4c0d97cc6200b1d9ae9f422f) ### [cli, cli-artifacts, deployer, tools](https://github.com/openshift/oc/tree/297a4ac4250237ed5aed54e916ec7b88fda61bbe) * [Bug 1920676](https://bugzilla.redhat.com/show_bug.cgi?id=1920676): add timestamps marking start and end for must-gather and inspect [#718](https://github.com/openshift/oc/pull/718) * [Full changelog](https://github.com/openshift/oc/compare/6082e941e6d62f3a0c6ca8ba52927100948b1d0d...297a4ac4250237ed5aed54e916ec7b88fda61bbe) ### [cluster-config-operator](https://github.com/openshift/cluster-config-operator/tree/25cc96541cc82a943a0cfd984062d357633bdac4) * [Bug 1905576](https://bugzilla.redhat.com/show_bug.cgi?id=1905576): [release-4.5] Add warning of the consequences of changing bound token issuer [#180](https://github.com/openshift/cluster-config-operator/pull/180) * [Full changelog](https://github.com/openshift/cluster-config-operator/compare/4800f81259d717eb5898b1cfe7fc96762378876a...25cc96541cc82a943a0cfd984062d357633bdac4) ### [cluster-dns-operator](https://github.com/openshift/cluster-dns-operator/tree/f8387b7d931bce337c921e7450167b8ec1313381) * [Bug 1935297](https://bugzilla.redhat.com/show_bug.cgi?id=1935297): Set CoreDNS readiness probe period and timeout each to 3 seconds [#242](https://github.com/openshift/cluster-dns-operator/pull/242) * [Full changelog](https://github.com/openshift/cluster-dns-operator/compare/bd312639caff6e1578c4777ccc7d10fb5a6707fd...f8387b7d931bce337c921e7450167b8ec1313381) ### [cluster-etcd-operator](https://github.com/openshift/cluster-etcd-operator/tree/8a842f8e56c4573885ddee899a3fdd227e6a047e) * [Bug 1939318](https://bugzilla.redhat.com/show_bug.cgi?id=1939318): pkg/operator/metriccontroller: cleanup transports [#555](https://github.com/openshift/cluster-etcd-operator/pull/555) * [Bug 1924913](https://bugzilla.redhat.com/show_bug.cgi?id=1924913): A valid etcd endpoint should have the URL scheme prepended. [#536](https://github.com/openshift/cluster-etcd-operator/pull/536) * [Full changelog](https://github.com/openshift/cluster-etcd-operator/compare/893d29c06f10dd366eea5b0426f600aea42be958...8a842f8e56c4573885ddee899a3fdd227e6a047e) ### [cluster-image-registry-operator](https://github.com/openshift/cluster-image-registry-operator/tree/10ef3754063b870a9da813f5076955f28101e417) * [Bug 1970966](https://bugzilla.redhat.com/show_bug.cgi?id=1970966): Using http.DefaultTransport timeouts [#692](https://github.com/openshift/cluster-image-registry-operator/pull/692) * [Bug 1916859](https://bugzilla.redhat.com/show_bug.cgi?id=1916859): Sync status to spec with regards to Swift config [#656](https://github.com/openshift/cluster-image-registry-operator/pull/656) * [Full changelog](https://github.com/openshift/cluster-image-registry-operator/compare/dec4ffeb7d84f6d7ec3fd222b82b8747d112528e...10ef3754063b870a9da813f5076955f28101e417) ### [cluster-ingress-operator](https://github.com/openshift/cluster-ingress-operator/tree/70b0e7a795f7e8acc44bc116f6133c21b7744bee) * [Bug 1896168](https://bugzilla.redhat.com/show_bug.cgi?id=1896168): Back port HAProxy reload failures alert fix [#487](https://github.com/openshift/cluster-ingress-operator/pull/487) * [Bug 1920421](https://bugzilla.redhat.com/show_bug.cgi?id=1920421): Add "ingress.operator.openshift.io/hard-stop-after" annotation [#538](https://github.com/openshift/cluster-ingress-operator/pull/538) * [Full changelog](https://github.com/openshift/cluster-ingress-operator/compare/171507d5814b6ba081cab72ffa2afd6c52d1f283...70b0e7a795f7e8acc44bc116f6133c21b7744bee) ### [cluster-network-operator](https://github.com/openshift/cluster-network-operator/tree/d699ba8f10d124284d1cbcfb6426f4be9d7e81c4) * [Bug 1941604](https://bugzilla.redhat.com/show_bug.cgi?id=1941604): Include LB members for Machines created on day-2 operation [#1032](https://github.com/openshift/cluster-network-operator/pull/1032) * [Bug 1924137](https://bugzilla.redhat.com/show_bug.cgi?id=1924137): Increase the initialDelaySeconds for liveness and readiness probes [#967](https://github.com/openshift/cluster-network-operator/pull/967) * [Bug 1849154](https://bugzilla.redhat.com/show_bug.cgi?id=1849154): Fixes Proxy ReadinessEndpoints Validation [#677](https://github.com/openshift/cluster-network-operator/pull/677) * [Full changelog](https://github.com/openshift/cluster-network-operator/compare/007caefad66802f8b412626fadca29c6366df05e...d699ba8f10d124284d1cbcfb6426f4be9d7e81c4) ### [cluster-version-operator](https://github.com/openshift/cluster-version-operator/tree/7f24cf21a88839664470ec4fbf6409151348fd62) * [Bug 1940652](https://bugzilla.redhat.com/show_bug.cgi?id=1940652): Bump logging to --v=5 [#533](https://github.com/openshift/cluster-version-operator/pull/533) * [Bug 1857478](https://bugzilla.redhat.com/show_bug.cgi?id=1857478): pkg/verify: Parallelize HTTP(S) signature retrieval [#487](https://github.com/openshift/cluster-version-operator/pull/487) * [Bug 1931025](https://bugzilla.redhat.com/show_bug.cgi?id=1931025): pkg/cvo: Use shutdownContext for final status synchronization [#525](https://github.com/openshift/cluster-version-operator/pull/525) * [Full changelog](https://github.com/openshift/cluster-version-operator/compare/0a34ac3632dd869e9975fc6e9ebdcb95ef9374b8...7f24cf21a88839664470ec4fbf6409151348fd62) ### [console](https://github.com/openshift/console/tree/0aa7f9777bf4b8a620b1b4f9c5c7375a9ae140ef) * [Bug 1915032](https://bugzilla.redhat.com/show_bug.cgi?id=1915032): make filesystem queries compatible with both RHCOS and RHEL nodes [#7796](https://github.com/openshift/console/pull/7796) * [Bug 1895202](https://bugzilla.redhat.com/show_bug.cgi?id=1895202): Access server API via kubernetes.default.svc from Helm endpoints [#7133](https://github.com/openshift/console/pull/7133) * [Full changelog](https://github.com/openshift/console/compare/6b465ad3745ac2c945000e5dffd493d51d936715...0aa7f9777bf4b8a620b1b4f9c5c7375a9ae140ef) ### [docker-builder](https://github.com/openshift/builder/tree/45d9a1a546bd435f79115b458c66e27c5ecae1b0) * [Bug 1921966](https://bugzilla.redhat.com/show_bug.cgi?id=1921966): narrow scope of rhsm transient bind mount [#214](https://github.com/openshift/builder/pull/214) * Force use of runc, since we know we're privileged, and customize our seccomp filter [#208](https://github.com/openshift/builder/pull/208) * [Full changelog](https://github.com/openshift/builder/compare/0fff08e88e26e49fbbb442c179f81376a9bffbb1...45d9a1a546bd435f79115b458c66e27c5ecae1b0) ### [haproxy-router](https://github.com/openshift/router/tree/c49016551ebd729e93368fe4a3cc3b4603bae6e0) * [Bug 1938923](https://bugzilla.redhat.com/show_bug.cgi?id=1938923): router/template: Cache compiled regular expressions [#271](https://github.com/openshift/router/pull/271) * [Bug 1896168](https://bugzilla.redhat.com/show_bug.cgi?id=1896168): metrics: Rework template_router_reload_failure metric [#216](https://github.com/openshift/router/pull/216) * [Bug 1920421](https://bugzilla.redhat.com/show_bug.cgi?id=1920421): Add tunnel-timeout and hard-stop-after options to haproxy template [#250](https://github.com/openshift/router/pull/250) * [Bug 1921252](https://bugzilla.redhat.com/show_bug.cgi?id=1921252): Prevent unnecessary reloads in router shards [#251](https://github.com/openshift/router/pull/251) * [Full changelog](https://github.com/openshift/router/compare/0e67768035666639b910f417fbb87f40fffb6e97...c49016551ebd729e93368fe4a3cc3b4603bae6e0) ### [hyperkube, tests](https://github.com/openshift/origin/tree/d8ef5ad4fbce39a1f10b569e5f408dcdb20a2e1b) * [Bug 1957927](https://bugzilla.redhat.com/show_bug.cgi?id=1957927): test/e2e/upgrade/upgrade.go: Bump upgrade ACK timeout to 4 minutes [#26135](https://github.com/openshift/origin/pull/26135) * [Bug 1951663](https://bugzilla.redhat.com/show_bug.cgi?id=1951663): Fix volume loop bugs [#26094](https://github.com/openshift/origin/pull/26094) * [Bug 1930554](https://bugzilla.redhat.com/show_bug.cgi?id=1930554): Update multicast test image for use in release-4.5 [#25933](https://github.com/openshift/origin/pull/25933) * BUG 1891106: UPSTREAM: 95259: allocate service-account flowschema to global-default [#25627](https://github.com/openshift/origin/pull/25627) * [Bug 1928978](https://bugzilla.redhat.com/show_bug.cgi?id=1928978): UPSTREAM: 89885: SQUASH: Fix cinder crash [#25899](https://github.com/openshift/origin/pull/25899) * [Bug 1887311](https://bugzilla.redhat.com/show_bug.cgi?id=1887311): UPSTREAM: 94712: [credentialprovider] avoid potential secret leaking while reading .dockercfg [#25694](https://github.com/openshift/origin/pull/25694) * [Bug 1894918](https://bugzilla.redhat.com/show_bug.cgi?id=1894918): Panic output due to timeouts in kube-apiserver [#25751](https://github.com/openshift/origin/pull/25751) * [Bug 1916660](https://bugzilla.redhat.com/show_bug.cgi?id=1916660): UPSTREAM: 97916: kube-aggregator: fix apiservice availability gauge [#25800](https://github.com/openshift/origin/pull/25800) * [Bug 1879208](https://bugzilla.redhat.com/show_bug.cgi?id=1879208): fixes a data race in SerializeObject function [#25824](https://github.com/openshift/origin/pull/25824) * [Full changelog](https://github.com/openshift/origin/compare/65bd32d2f3f16fa48cbc3501c448c4f4aeaf5566...d8ef5ad4fbce39a1f10b569e5f408dcdb20a2e1b) ### [insights-operator](https://github.com/openshift/insights-operator/tree/0cc098a1f4a7125f5fb99309a1a4cadb0e19b2c1) * [Bug 1889679](https://bugzilla.redhat.com/show_bug.cgi?id=1889679): Collect installplans [#244](https://github.com/openshift/insights-operator/pull/244) * [Bug 1914255](https://bugzilla.redhat.com/show_bug.cgi?id=1914255): Red Hat image and crashlooping OpenShift pod collection [#308](https://github.com/openshift/insights-operator/pull/308) * [Bug 1894243](https://bugzilla.redhat.com/show_bug.cgi?id=1894243): Fixes records index on diskrecorder [#262](https://github.com/openshift/insights-operator/pull/262) * [release 4.5] Bug 1887763: Adds MachineConfigPool gatherer [#214](https://github.com/openshift/insights-operator/pull/214) * [Bug 1905106](https://bugzilla.redhat.com/show_bug.cgi?id=1905106): Collect spec config for clusteroperator resources [#287](https://github.com/openshift/insights-operator/pull/287) * [Full changelog](https://github.com/openshift/insights-operator/compare/8cc4b493e997573907e6f3d13e4f080a2569c9fd...0cc098a1f4a7125f5fb99309a1a4cadb0e19b2c1) ### [jenkins, jenkins-agent-maven, jenkins-agent-nodejs](https://github.com/openshift/jenkins/tree/981213b424f19ebdd300d57b06b1bfa9231b5931) * [Bug 1952560](https://bugzilla.redhat.com/show_bug.cgi?id=1952560): bump config-file-provider to 3.7.1 [#1267](https://github.com/openshift/jenkins/pull/1267) * [release 4.5] Bug 1952340: Jenkins 2.277.3 update and disable setup wizard [#1262](https://github.com/openshift/jenkins/pull/1262) * [release 4.5] Bug 1929120: update kubernetes-client-api [#1232](https://github.com/openshift/jenkins/pull/1232) * [release 4.5] Bug 1929918: Upgrade Jenkins to 2.263.3 [#1235](https://github.com/openshift/jenkins/pull/1235) * [Bug 1922554](https://bugzilla.redhat.com/show_bug.cgi?id=1922554): Update ant plugin CVE-2020-11979 [#1210](https://github.com/openshift/jenkins/pull/1210) * [Full changelog](https://github.com/openshift/jenkins/compare/843db39086f6d81f0bf87eea975c87496dc51b8d...981213b424f19ebdd300d57b06b1bfa9231b5931) ### [kube-proxy, sdn](https://github.com/openshift/sdn/tree/c9be458a3a926d98c1dfb43b8f74e1bd4cb4ed49) * [Bug 1935297](https://bugzilla.redhat.com/show_bug.cgi?id=1935297): Prefer local endpoint for cluster DNS service [#268](https://github.com/openshift/sdn/pull/268) * [Bug 1904456](https://bugzilla.redhat.com/show_bug.cgi?id=1904456): NetworkPolicy performance fixes, v2 [#258](https://github.com/openshift/sdn/pull/258) * [Bug 1891455](https://bugzilla.redhat.com/show_bug.cgi?id=1891455): Fix error handling from DNS nameservers [#211](https://github.com/openshift/sdn/pull/211) * [Full changelog](https://github.com/openshift/sdn/compare/b3566de316eba806ff23d8e0807295bc334e85fd...c9be458a3a926d98c1dfb43b8f74e1bd4cb4ed49) ### [machine-api-operator](https://github.com/openshift/machine-api-operator/tree/8d1a1524b20a1bbcf24688db50a5dde9b0d90471) * [Bug 1888206](https://bugzilla.redhat.com/show_bug.cgi?id=1888206): Adjust alert timing and severity [#729](https://github.com/openshift/machine-api-operator/pull/729) * [Full changelog](https://github.com/openshift/machine-api-operator/compare/dda08985cd47f0d9ce224670bb4c86d956ce83e7...8d1a1524b20a1bbcf24688db50a5dde9b0d90471) ### [oauth-server](https://github.com/openshift/oauth-server/tree/b1027b69fb5ba13e84e2b6328a20e32accf45d49) * [Bug 1905991](https://bugzilla.redhat.com/show_bug.cgi?id=1905991): Detecting broken connections to the Kube API takes up to 15 minutes [#66](https://github.com/openshift/oauth-server/pull/66) * [Full changelog](https://github.com/openshift/oauth-server/compare/7f359aa34c616031272903e1bb01af6bee1e2c0a...b1027b69fb5ba13e84e2b6328a20e32accf45d49) ### [openshift-apiserver](https://github.com/openshift/openshift-apiserver/tree/43052234d142895624e46486dfb810e9a01ebbc5) * [Bug 1931404](https://bugzilla.redhat.com/show_bug.cgi?id=1931404): fixes a data race in SerializeObject function [#188](https://github.com/openshift/openshift-apiserver/pull/188) * [Bug 1905991](https://bugzilla.redhat.com/show_bug.cgi?id=1905991): Detecting broken connections to the Kube API takes up to 15 minutes [#164](https://github.com/openshift/openshift-apiserver/pull/164) * [Full changelog](https://github.com/openshift/openshift-apiserver/compare/f9b8a5cbab010497bfdaf83d68b657268d1c5011...43052234d142895624e46486dfb810e9a01ebbc5) ### [openshift-controller-manager](https://github.com/openshift/openshift-controller-manager/tree/6041ed1a40d7ad3ca6913b79d926384c4dce1159) * remove use of BUILD_ISOLATION env var (no longer inspected in openshift/builder) [#163](https://github.com/openshift/openshift-controller-manager/pull/163) * [Full changelog](https://github.com/openshift/openshift-controller-manager/compare/630ceaaee52cb21967fae8dfa54c0da84d7c3e2e...6041ed1a40d7ad3ca6913b79d926384c4dce1159) ### [operator-lifecycle-manager](https://github.com/operator-framework/operator-lifecycle-manager/tree/5c6c4ed9f3fc59f387f568e5b4f210e18bacd168) * [Bug 1940651](https://bugzilla.redhat.com/show_bug.cgi?id=1940651): Allow non-CSV-owned ServiceAccounts to satisfy CSV requirements. [#2052](https://github.com/operator-framework/operator-lifecycle-manager/pull/2052) * [Bug 1933779](https://bugzilla.redhat.com/show_bug.cgi?id=1933779): Support InstallPlan steps upgrading existing ClusterIP Services. [#2021](https://github.com/operator-framework/operator-lifecycle-manager/pull/2021) * [Bug 1928263](https://bugzilla.redhat.com/show_bug.cgi?id=1928263): Fix zero-delay resyncs for certain registry update policies. [#2006](https://github.com/operator-framework/operator-lifecycle-manager/pull/2006) * [Bug 1904584](https://bugzilla.redhat.com/show_bug.cgi?id=1904584): Check sa owner 4.5 [#1909](https://github.com/operator-framework/operator-lifecycle-manager/pull/1909) * [Bug 1896079](https://bugzilla.redhat.com/show_bug.cgi?id=1896079): Services should not have duplicate ownerrefs [#1857](https://github.com/operator-framework/operator-lifecycle-manager/pull/1857) * [Bug 1921484](https://bugzilla.redhat.com/show_bug.cgi?id=1921484): use OLM client when installing CRDs [#1985](https://github.com/operator-framework/operator-lifecycle-manager/pull/1985) * [Full changelog](https://github.com/operator-framework/operator-lifecycle-manager/compare/ab6eead0a5bb9222bce8d6be76a6907456c888ea...5c6c4ed9f3fc59f387f568e5b4f210e18bacd168) ### [ovn-kubernetes](https://github.com/openshift/ovn-kubernetes/tree/b8ac1b415821ff7d2fd477cfe4b07b35991319e2) * [Bug 1921283](https://bugzilla.redhat.com/show_bug.cgi?id=1921283): [4.5] Fix MCS-blocking iptables rules [#426](https://github.com/openshift/ovn-kubernetes/pull/426) * [Bug 1882694](https://bugzilla.redhat.com/show_bug.cgi?id=1882694): Pin OVS to latest 4.4.22 RPM version [#290](https://github.com/openshift/ovn-kubernetes/pull/290) * [Full changelog](https://github.com/openshift/ovn-kubernetes/compare/f8c79282e0004dd443d75839b17cfca6c4868645...b8ac1b415821ff7d2fd477cfe4b07b35991319e2)