First published: Thu May 28 2020(Updated: )
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>This advisory contains the RPM packages for Red Hat OpenShift Container<br>Platform 3.11.219. See the following advisory for the container images for<br>this release:<br><a href="https://access.redhat.com/errata/RHBA-2020:2216" target="_blank">https://access.redhat.com/errata/RHBA-2020:2216</a> This release fixes the following bugs among others:<br><li> Previously, DNS names were queried every time they occurred in an</li> EgressNetworkPolicy. Records were queried regardless of whether a particular DNS<br>record had been refreshed by a previous query, resulting in slow network<br>performance. DNS records are now queried based on unique names rather than per<br>each EgressNetworkPolicy. As a result, DNS query performance has been<br>significantly improved. (BZ#1772594)<br><li> Previously, the PKI directory was not properly mounted to the sync Pod. This</li> caused the `openshift-ca.crt` to be inaccessible, and as a result, was<br>recreated. The missing mounts and volumes have been added to the sync Pod, so<br>the `openshift-ca.crt` is available and is not incorrectly recreated. (BZ#1808068)<br><li> The Google Cloud Storage (GCS) driver was not reporting all errors due to a</li> variable shadowing issue. This issue has been resolved, allowing all errors to<br>be reported by the registry. (BZ#1814722)<br><li> The image registry was using repository names in metrics labels. This caused</li> Prometheus to have problems with reporting many metrics. This bug fix removes<br>repository names from labels, resulting in less generated metrics and better<br>performance. (BZ#1827744)<br><li> The variable `openshift_certificate_expiry_warning_days` was hard-coded in an</li> area of {product-title}'s underlying code calling the<br>`openshift_certificate_expiry` role during upgrades. This prevented the<br>`openshift_certificate_expiry_warning_days` variable from being overridden in<br>the inventory. This bug fix replaces the hard-coded value with a task to set a<br>value of six months if the variable has not been defined by the user. (BZ#1829492)<br><li> When redeploying certificates, the certificate expiry check provided little</li> value because the expectation was that the certificates would be replaced.<br>Additionally, there were situations where certificates were invalid and<br>redeployment was blocked by the check. This bug fix removes the checks, allowing<br>certificate redeployment to proceed without requiring additional inventory<br>variables to override expiry days or invalid/missing certificates. (BZ#1832379)<br>All OpenShift Container Platform 3.11 users are advised to upgrade to these<br>updated packages and images.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/atomic-enterprise-service-catalog | <3.11.219-1.git.1.717017c.el7 | 3.11.219-1.git.1.717017c.el7 |
redhat/atomic-openshift | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-cluster-autoscaler | <3.11.219-1.git.1.1ad3e34.el7 | 3.11.219-1.git.1.1ad3e34.el7 |
redhat/atomic-openshift-descheduler | <3.11.219-1.git.1.7e5b9ee.el7 | 3.11.219-1.git.1.7e5b9ee.el7 |
redhat/atomic-openshift-dockerregistry | <3.11.219-1.git.1.8323991.el7 | 3.11.219-1.git.1.8323991.el7 |
redhat/atomic-openshift-metrics-server | <3.11.219-1.git.1.6fe54fb.el7 | 3.11.219-1.git.1.6fe54fb.el7 |
redhat/atomic-openshift-node-problem-detector | <3.11.219-1.git.1.5ae8753.el7 | 3.11.219-1.git.1.5ae8753.el7 |
redhat/atomic-openshift-service-idler | <3.11.219-1.git.1.958cdae.el7 | 3.11.219-1.git.1.958cdae.el7 |
redhat/golang-github-openshift-oauth-proxy | <3.11.219-1.git.1.076ae14.el7 | 3.11.219-1.git.1.076ae14.el7 |
redhat/golang-github-prometheus-alertmanager | <3.11.219-1.git.1.9a593f8.el7 | 3.11.219-1.git.1.9a593f8.el7 |
redhat/golang-github-prometheus-prometheus | <3.11.219-1.git.1.3f6e657.el7 | 3.11.219-1.git.1.3f6e657.el7 |
redhat/openshift-ansible | <3.11.219-1.git.0.8845382.el7 | 3.11.219-1.git.0.8845382.el7 |
redhat/openshift-enterprise-autoheal | <3.11.219-1.git.1.c544df9.el7 | 3.11.219-1.git.1.c544df9.el7 |
redhat/openshift-enterprise-cluster-capacity | <3.11.219-1.git.1.ca1ee51.el7 | 3.11.219-1.git.1.ca1ee51.el7 |
redhat/openshift-kuryr | <3.11.219-1.git.1.717d59f.el7 | 3.11.219-1.git.1.717d59f.el7 |
redhat/atomic-enterprise-service-catalog | <3.11.219-1.git.1.717017c.el7 | 3.11.219-1.git.1.717017c.el7 |
redhat/atomic-enterprise-service-catalog-svcat | <3.11.219-1.git.1.717017c.el7 | 3.11.219-1.git.1.717017c.el7 |
redhat/atomic-openshift | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-clients | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-clients-redistributable | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-cluster-autoscaler | <3.11.219-1.git.1.1ad3e34.el7 | 3.11.219-1.git.1.1ad3e34.el7 |
redhat/atomic-openshift-descheduler | <3.11.219-1.git.1.7e5b9ee.el7 | 3.11.219-1.git.1.7e5b9ee.el7 |
redhat/atomic-openshift-docker-excluder | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-dockerregistry | <3.11.219-1.git.1.8323991.el7 | 3.11.219-1.git.1.8323991.el7 |
redhat/atomic-openshift-excluder | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-hyperkube | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-hypershift | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-master | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-metrics-server | <3.11.219-1.git.1.6fe54fb.el7 | 3.11.219-1.git.1.6fe54fb.el7 |
redhat/atomic-openshift-node | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-node-problem-detector | <3.11.219-1.git.1.5ae8753.el7 | 3.11.219-1.git.1.5ae8753.el7 |
redhat/atomic-openshift-pod | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-sdn-ovs | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-service-idler | <3.11.219-1.git.1.958cdae.el7 | 3.11.219-1.git.1.958cdae.el7 |
redhat/atomic-openshift-template-service-broker | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-tests | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/golang-github-openshift-oauth-proxy | <3.11.219-1.git.1.076ae14.el7 | 3.11.219-1.git.1.076ae14.el7 |
redhat/openshift-ansible | <3.11.219-1.git.0.8845382.el7 | 3.11.219-1.git.0.8845382.el7 |
redhat/openshift-ansible-docs | <3.11.219-1.git.0.8845382.el7 | 3.11.219-1.git.0.8845382.el7 |
redhat/openshift-ansible-playbooks | <3.11.219-1.git.0.8845382.el7 | 3.11.219-1.git.0.8845382.el7 |
redhat/openshift-ansible-roles | <3.11.219-1.git.0.8845382.el7 | 3.11.219-1.git.0.8845382.el7 |
redhat/openshift-enterprise-autoheal | <3.11.219-1.git.1.c544df9.el7 | 3.11.219-1.git.1.c544df9.el7 |
redhat/openshift-enterprise-cluster-capacity | <3.11.219-1.git.1.ca1ee51.el7 | 3.11.219-1.git.1.ca1ee51.el7 |
redhat/openshift-kuryr-cni | <3.11.219-1.git.1.717d59f.el7 | 3.11.219-1.git.1.717d59f.el7 |
redhat/openshift-kuryr-common | <3.11.219-1.git.1.717d59f.el7 | 3.11.219-1.git.1.717d59f.el7 |
redhat/openshift-kuryr-controller | <3.11.219-1.git.1.717d59f.el7 | 3.11.219-1.git.1.717d59f.el7 |
redhat/prometheus | <3.11.219-1.git.1.3f6e657.el7 | 3.11.219-1.git.1.3f6e657.el7 |
redhat/prometheus-alertmanager | <3.11.219-1.git.1.9a593f8.el7 | 3.11.219-1.git.1.9a593f8.el7 |
redhat/prometheus-node-exporter | <3.11.219-1.git.1.7fa9674.el7 | 3.11.219-1.git.1.7fa9674.el7 |
redhat/python2-kuryr-kubernetes | <3.11.219-1.git.1.717d59f.el7 | 3.11.219-1.git.1.717d59f.el7 |
redhat/atomic-enterprise-service-catalog | <3.11.219-1.git.1.717017c.el7 | 3.11.219-1.git.1.717017c.el7 |
redhat/atomic-enterprise-service-catalog-svcat | <3.11.219-1.git.1.717017c.el7 | 3.11.219-1.git.1.717017c.el7 |
redhat/atomic-openshift | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-clients | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-cluster-autoscaler | <3.11.219-1.git.1.1ad3e34.el7 | 3.11.219-1.git.1.1ad3e34.el7 |
redhat/atomic-openshift-descheduler | <3.11.219-1.git.1.7e5b9ee.el7 | 3.11.219-1.git.1.7e5b9ee.el7 |
redhat/atomic-openshift-hyperkube | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-hypershift | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-master | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-metrics-server | <3.11.219-1.git.1.6fe54fb.el7 | 3.11.219-1.git.1.6fe54fb.el7 |
redhat/atomic-openshift-node | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-node-problem-detector | <3.11.219-1.git.1.5ae8753.el7 | 3.11.219-1.git.1.5ae8753.el7 |
redhat/atomic-openshift-pod | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-sdn-ovs | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-service-idler | <3.11.219-1.git.1.958cdae.el7 | 3.11.219-1.git.1.958cdae.el7 |
redhat/atomic-openshift-template-service-broker | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/atomic-openshift-tests | <3.11.219-1.git.0.0c21387.el7 | 3.11.219-1.git.0.0c21387.el7 |
redhat/golang-github-openshift-oauth-proxy | <3.11.219-1.git.1.076ae14.el7 | 3.11.219-1.git.1.076ae14.el7 |
redhat/openshift-ansible-test | <3.11.219-1.git.0.8845382.el7 | 3.11.219-1.git.0.8845382.el7 |
redhat/openshift-enterprise-autoheal | <3.11.219-1.git.1.c544df9.el7 | 3.11.219-1.git.1.c544df9.el7 |
redhat/openshift-enterprise-cluster-capacity | <3.11.219-1.git.1.ca1ee51.el7 | 3.11.219-1.git.1.ca1ee51.el7 |
redhat/prometheus | <3.11.219-1.git.1.3f6e657.el7 | 3.11.219-1.git.1.3f6e657.el7 |
redhat/prometheus-alertmanager | <3.11.219-1.git.1.9a593f8.el7 | 3.11.219-1.git.1.9a593f8.el7 |
redhat/prometheus-node-exporter | <3.11.219-1.git.1.7fa9674.el7 | 3.11.219-1.git.1.7fa9674.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHBA-2020:2215 is categorized as 'Important' due to its impact on Red Hat OpenShift Container Platform security and performance.
To fix RHBA-2020:2215, update all affected RPM packages to version 3.11.219-1 or later as specified in the advisory.
RHBA-2020:2215 affects Red Hat OpenShift Container Platform version 3.11.219 specifically for certain packages mentioned in the advisory.
Currently, there are no known workarounds for RHBA-2020:2215; applying the update is the recommended action.
The packages that need updating under RHBA-2020:2215 include atomic-openshift, atomic-openshift-clients, and several others, as listed in the advisory.