First published: Mon Jul 27 2020(Updated: )
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>This advisory contains the RPM packages for Red Hat OpenShift Container<br>Platform 3.11.248. See the following advisory for the container images for<br>this release:<br><a href="https://access.redhat.com/errata/RHBA-2020:2991" target="_blank">https://access.redhat.com/errata/RHBA-2020:2991</a> This release fixes the following bugs among others:<br><li> Previously, the egress IP tracker had methods that locked `eit.mutex` and had methods that called EVM functions that locked `evm.mutex`. Because `evm.mutex` had to write to the `evm.updates` channel, which was not buffered and was blocked until `eit.setNodeOffline ran, this function also locked `eit.mutex`. This caused a deadlock when there was a large amount of egress IPs. This bug fix removes the deadlock by buffering the updates channel so that it only serves as a notification system rather than containing actual data. (BZ#1824243)</li> <li> Previously, the conditional set on a task checking the `openshift_master_cluster_hostname` variable expected the `masters` group in the inventory to be set. This caused the `masters` group to fail if it was not defined. This bug fix adds a conditional to check if `masters` is defined; if `masters` is not defined, the task is skipped instead of failing on an undefined variable. (BZ#1828484)</li> <li> Previously, when providing a custom `openshift_node_groups` list, not a ConfigMaps were created. This was caused by new ConfigMap creation code that only created ConfigMaps if they were assigned to an active host. This code has been reverted, so all ConfigMaps specified in a `openshift_node_groups` list are created. (BZ#1845676)</li> <li> Previously, Prometheus counters that show the number of active sessions were preserved across router restarts and increased indefinitely. With this update, `haproxy_frontend_current_session` and `haproxy_server_current_session` now accurately depict the number of active sessions. The value of these counters are now reset upon router restart. (BZ#1847478)</li> <li> Previously, nodes in CI for GCP assigned masters and infra nodes were assigned to the same group. This caused all nodes to be labeled as masters and none as infra nodes. The node group mapping has been changed to allow infra and compute nodes to be assigned to the same group and apply the proper infra and compute labels. Now the CI cluster is built properly with all nodes labeled appropriately. (BZ#1848723)</li> All OpenShift Container Platform 3.11 users are advised to upgrade to these<br>updated packages and images.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/atomic-enterprise-service-catalog | <3.11.248-1.git.1.9aad2ef.el7 | 3.11.248-1.git.1.9aad2ef.el7 |
redhat/atomic-openshift-cluster-autoscaler | <3.11.248-1.git.1.b5530f6.el7 | 3.11.248-1.git.1.b5530f6.el7 |
redhat/atomic-openshift-descheduler | <3.11.248-1.git.1.108ef32.el7 | 3.11.248-1.git.1.108ef32.el7 |
redhat/atomic-openshift-dockerregistry | <3.11.248-1.git.1.bb4a1fc.el7 | 3.11.248-1.git.1.bb4a1fc.el7 |
redhat/atomic-openshift-metrics-server | <3.11.248-1.git.1.b53e0e3.el7 | 3.11.248-1.git.1.b53e0e3.el7 |
redhat/atomic-openshift-node-problem-detector | <3.11.248-1.git.1.628ff22.el7 | 3.11.248-1.git.1.628ff22.el7 |
redhat/atomic-openshift-service-idler | <3.11.248-1.git.1.4c42a90.el7 | 3.11.248-1.git.1.4c42a90.el7 |
redhat/golang-github-openshift-oauth-proxy | <3.11.248-1.git.1.9885abb.el7 | 3.11.248-1.git.1.9885abb.el7 |
redhat/golang-github-prometheus-alertmanager | <3.11.248-1.git.1.66abd18.el7 | 3.11.248-1.git.1.66abd18.el7 |
redhat/golang-github-prometheus-prometheus | <3.11.248-1.git.1.ad54f5b.el7 | 3.11.248-1.git.1.ad54f5b.el7 |
redhat/jenkins | <2-plugins-3.11.1593081747-1.el7 | 2-plugins-3.11.1593081747-1.el7 |
redhat/openshift-ansible | <3.11.248-1.git.0.fd212c7.el7 | 3.11.248-1.git.0.fd212c7.el7 |
redhat/openshift-enterprise-autoheal | <3.11.248-1.git.1.0020348.el7 | 3.11.248-1.git.1.0020348.el7 |
redhat/openshift-enterprise-cluster-capacity | <3.11.248-1.git.1.37b107c.el7 | 3.11.248-1.git.1.37b107c.el7 |
redhat/openshift-kuryr | <3.11.248-1.git.1.f90c804.el7 | 3.11.248-1.git.1.f90c804.el7 |
redhat/python-urllib3 | <1.24.3-1.el7 | 1.24.3-1.el7 |
redhat/atomic-enterprise-service-catalog | <3.11.248-1.git.1.9aad2ef.el7 | 3.11.248-1.git.1.9aad2ef.el7 |
redhat/atomic-enterprise-service-catalog-svcat | <3.11.248-1.git.1.9aad2ef.el7 | 3.11.248-1.git.1.9aad2ef.el7 |
redhat/atomic-openshift-cluster-autoscaler | <3.11.248-1.git.1.b5530f6.el7 | 3.11.248-1.git.1.b5530f6.el7 |
redhat/atomic-openshift-descheduler | <3.11.248-1.git.1.108ef32.el7 | 3.11.248-1.git.1.108ef32.el7 |
redhat/atomic-openshift-dockerregistry | <3.11.248-1.git.1.bb4a1fc.el7 | 3.11.248-1.git.1.bb4a1fc.el7 |
redhat/atomic-openshift-metrics-server | <3.11.248-1.git.1.b53e0e3.el7 | 3.11.248-1.git.1.b53e0e3.el7 |
redhat/atomic-openshift-node-problem-detector | <3.11.248-1.git.1.628ff22.el7 | 3.11.248-1.git.1.628ff22.el7 |
redhat/atomic-openshift-service-idler | <3.11.248-1.git.1.4c42a90.el7 | 3.11.248-1.git.1.4c42a90.el7 |
redhat/golang-github-openshift-oauth-proxy | <3.11.248-1.git.1.9885abb.el7 | 3.11.248-1.git.1.9885abb.el7 |
redhat/jenkins | <2-plugins-3.11.1593081747-1.el7 | 2-plugins-3.11.1593081747-1.el7 |
redhat/openshift-ansible | <3.11.248-1.git.0.fd212c7.el7 | 3.11.248-1.git.0.fd212c7.el7 |
redhat/openshift-ansible-docs | <3.11.248-1.git.0.fd212c7.el7 | 3.11.248-1.git.0.fd212c7.el7 |
redhat/openshift-ansible-playbooks | <3.11.248-1.git.0.fd212c7.el7 | 3.11.248-1.git.0.fd212c7.el7 |
redhat/openshift-ansible-roles | <3.11.248-1.git.0.fd212c7.el7 | 3.11.248-1.git.0.fd212c7.el7 |
redhat/openshift-enterprise-autoheal | <3.11.248-1.git.1.0020348.el7 | 3.11.248-1.git.1.0020348.el7 |
redhat/openshift-enterprise-cluster-capacity | <3.11.248-1.git.1.37b107c.el7 | 3.11.248-1.git.1.37b107c.el7 |
redhat/openshift-kuryr-cni | <3.11.248-1.git.1.f90c804.el7 | 3.11.248-1.git.1.f90c804.el7 |
redhat/openshift-kuryr-common | <3.11.248-1.git.1.f90c804.el7 | 3.11.248-1.git.1.f90c804.el7 |
redhat/openshift-kuryr-controller | <3.11.248-1.git.1.f90c804.el7 | 3.11.248-1.git.1.f90c804.el7 |
redhat/prometheus | <3.11.248-1.git.1.ad54f5b.el7 | 3.11.248-1.git.1.ad54f5b.el7 |
redhat/prometheus-alertmanager | <3.11.248-1.git.1.66abd18.el7 | 3.11.248-1.git.1.66abd18.el7 |
redhat/prometheus-node-exporter | <3.11.248-1.git.1.32f87fc.el7 | 3.11.248-1.git.1.32f87fc.el7 |
redhat/python2-kuryr-kubernetes | <3.11.248-1.git.1.f90c804.el7 | 3.11.248-1.git.1.f90c804.el7 |
redhat/python2-urllib3 | <1.24.3-1.el7 | 1.24.3-1.el7 |
redhat/atomic-enterprise-service-catalog | <3.11.248-1.git.1.9aad2ef.el7 | 3.11.248-1.git.1.9aad2ef.el7 |
redhat/atomic-enterprise-service-catalog-svcat | <3.11.248-1.git.1.9aad2ef.el7 | 3.11.248-1.git.1.9aad2ef.el7 |
redhat/atomic-openshift-cluster-autoscaler | <3.11.248-1.git.1.b5530f6.el7 | 3.11.248-1.git.1.b5530f6.el7 |
redhat/atomic-openshift-descheduler | <3.11.248-1.git.1.108ef32.el7 | 3.11.248-1.git.1.108ef32.el7 |
redhat/atomic-openshift-metrics-server | <3.11.248-1.git.1.b53e0e3.el7 | 3.11.248-1.git.1.b53e0e3.el7 |
redhat/atomic-openshift-node-problem-detector | <3.11.248-1.git.1.628ff22.el7 | 3.11.248-1.git.1.628ff22.el7 |
redhat/atomic-openshift-service-idler | <3.11.248-1.git.1.4c42a90.el7 | 3.11.248-1.git.1.4c42a90.el7 |
redhat/golang-github-openshift-oauth-proxy | <3.11.248-1.git.1.9885abb.el7 | 3.11.248-1.git.1.9885abb.el7 |
redhat/openshift-ansible-test | <3.11.248-1.git.0.fd212c7.el7 | 3.11.248-1.git.0.fd212c7.el7 |
redhat/openshift-enterprise-autoheal | <3.11.248-1.git.1.0020348.el7 | 3.11.248-1.git.1.0020348.el7 |
redhat/openshift-enterprise-cluster-capacity | <3.11.248-1.git.1.37b107c.el7 | 3.11.248-1.git.1.37b107c.el7 |
redhat/prometheus | <3.11.248-1.git.1.ad54f5b.el7 | 3.11.248-1.git.1.ad54f5b.el7 |
redhat/prometheus-alertmanager | <3.11.248-1.git.1.66abd18.el7 | 3.11.248-1.git.1.66abd18.el7 |
redhat/prometheus-node-exporter | <3.11.248-1.git.1.32f87fc.el7 | 3.11.248-1.git.1.32f87fc.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHBA-2020:2990 includes RPM packages for Red Hat OpenShift Container Platform 3.11.248 with various updates to packages like atomic-enterprise-service-catalog and atomic-openshift-cluster-autoscaler.
To implement the fixes for RHBA-2020:2990, upgrade the affected packages listed in the advisory to their specified versions.
RHBA-2020:2990 affects several packages including atomic-enterprise-service-catalog and atomic-openshift-cluster-autoscaler, specifically version 3.11.248.
The advisory RHBA-2020:2990 does not specify the severity level, but it contains important updates that can impact the functionality of the OpenShift platform.
More information about RHBA-2020:2990 can be found in the Red Hat advisory documentation and associated references.