# 4.7.21 Created: 2021-07-21 21:25:31 +0000 UTC Image Digest: `sha256:60454c3270a61432447c752a9d5ee3e7d84cebcfd5d371eb4daa263623923dac` Promoted from registry.ci.openshift.org/ocp/release:4.7.0-0.nightly-2021-07-21-150523 ## Changes from 4.7.2 ### Components * Kubernetes 1.20.0-beta.2 * Red Hat Enterprise Linux CoreOS upgraded from 47.83.202103051045-0 to 47.83.202107210005-0 ### New images * [driver-toolkit](https://github.com/openshift/driver-toolkit) git [044d4be0](https://github.com/openshift/driver-toolkit/commit/044d4be053f86d8f059197a76f641f99cf07d444) `sha256:29d7ddcae8690a45572a992633e1dbb366ea44fccfc270e29e0d2d1eb6473f62` ### Rebuilt images without code change * [aws-ebs-csi-driver](https://github.com/openshift/aws-ebs-csi-driver) git [f6a71bf7](https://github.com/openshift/aws-ebs-csi-driver/commit/f6a71bf783f3b7429a8c2fbbc6f3d586e6a7eb60) `sha256:d3f83158bd0532852499506456536116295f6d8745728d5cbfb65e1c249300d4` * [aws-ebs-csi-driver-operator](https://github.com/openshift/aws-ebs-csi-driver-operator) git [97f73eb7](https://github.com/openshift/aws-ebs-csi-driver-operator/commit/97f73eb7de4b474497169771239dcd81990d3f2e) `sha256:eafcca49321cfbfc9464d75ba95a6cc7d3566c5f975ccb7cbfd46a13df5f0c69` * [aws-pod-identity-webhook](https://github.com/openshift/aws-pod-identity-webhook) git [0074d6af](https://github.com/openshift/aws-pod-identity-webhook/commit/0074d6afef9e20f5a1bcbde85cd7c01e422202ca) `sha256:340983b4a5d058d6b82272db08464ac684bcac8b4db2d3c08f13136513b49020` * [cluster-bootstrap](https://github.com/openshift/cluster-bootstrap) git [6665cae3](https://github.com/openshift/cluster-bootstrap/commit/6665cae3374c18d466f11c9e0b8e41a61fcb0819) `sha256:c23f96a2ab9cbaa880c32afcb3b80483a276d481a954f674dd0f24a057adbc81` * [configmap-reloader](https://github.com/openshift/configmap-reload) git [25dfb671](https://github.com/openshift/configmap-reload/commit/25dfb671c6ce9a73f5594efe699ed410fbf01d44) `sha256:9defa0dd5339a3eb1277cbad710c6cd37fdf889de6b42aec5f88486369eeda07` * [container-networking-plugins](https://github.com/openshift/containernetworking-plugins) git [fc27124d](https://github.com/openshift/containernetworking-plugins/commit/fc27124d43b9dc995057b1f309d5f16e1b2ef151) `sha256:f11c5a5419d85b9579abe0ab27b07ef162d0501efe3dd2d6a0ae9861cfdf04cc` * [coredns](https://github.com/openshift/coredns) git [d4a3ba3f](https://github.com/openshift/coredns/commit/d4a3ba3f6e03426d2623da86635caba17c0c3926) `sha256:b70ae7a8ffe39c148fca93e6358a1256d52372233571b020fb089c23f1ce66c6` * [csi-driver-manila-operator](https://github.com/openshift/csi-driver-manila-operator) git [00b1f648](https://github.com/openshift/csi-driver-manila-operator/commit/00b1f648e74d8008ce32ae65eb4d6d8b5ac1bbed) `sha256:9e3dd6f1c4fe346bc1a02b68af0c90154eb44f578a71434544b560f775890b9c` * [csi-driver-nfs](https://github.com/openshift/csi-driver-nfs) git [9404d343](https://github.com/openshift/csi-driver-nfs/commit/9404d343c020fd1806691704f64d930c779ad639) `sha256:5ab250149ab64d6063a13681f0b696ee06e3cf5c05d3ce1add99930bc61232d2` * [csi-external-attacher](https://github.com/openshift/csi-external-attacher) git [f152de8a](https://github.com/openshift/csi-external-attacher/commit/f152de8ab08d9a4f13c97941afa01ef343b92b68) `sha256:e544fafcfb07d7fd362f7f37c017d7897fc88c2d4ac51800d2753da70ba41b4b` * [csi-external-provisioner](https://github.com/openshift/csi-external-provisioner) git [a49415e1](https://github.com/openshift/csi-external-provisioner/commit/a49415e114b90060c8cdbb88b1ca3f0a4c5d2ebc) `sha256:50f1227c0acd871ca0decc4de6bb85f18bdb30578ec93de00094d460d1752020` * [csi-external-resizer](https://github.com/openshift/csi-external-resizer) git [f77279e9](https://github.com/openshift/csi-external-resizer/commit/f77279e9561a02c18676dbcafcbe6db7d0ebd077) `sha256:be1bf5dd7d9bb37a972c5182451a1e4394fe7132a280c27f26fc46b3c77643a5` * [csi-external-snapshotter](https://github.com/openshift/csi-external-snapshotter) git [26773735](https://github.com/openshift/csi-external-snapshotter/commit/26773735c1cbf09de9bf31cb3c640abdca04cd83) `sha256:c5c96aa734a9144ccdd9f97337dd0f5010d9524d8108493642bdcdd84ee5307e` * [csi-livenessprobe](https://github.com/openshift/csi-livenessprobe) git [3dad0280](https://github.com/openshift/csi-livenessprobe/commit/3dad0280ea630cfcc87bcf02806c75b7a066d81e) `sha256:fcfcc90a8f0b0e70b3da0869e0c37e29cf68d8a681c6802a32227644612f9c58` * [csi-node-driver-registrar](https://github.com/openshift/csi-node-driver-registrar) git [2a77963e](https://github.com/openshift/csi-node-driver-registrar/commit/2a77963e5458da1bcde318b4609a6abefaf868d7) `sha256:a00ef0658d7d5b15aa4f24b849c476ea032e89ac3370488063e66abb840d106d` * [csi-snapshot-controller](https://github.com/openshift/csi-external-snapshotter) git [26773735](https://github.com/openshift/csi-external-snapshotter/commit/26773735c1cbf09de9bf31cb3c640abdca04cd83) `sha256:7780cca4686b3fddb551d3595910b1a864ad65da8425cc9219abc708f470bfd9` * [csi-snapshot-validation-webhook](https://github.com/openshift/csi-external-snapshotter) git [26773735](https://github.com/openshift/csi-external-snapshotter/commit/26773735c1cbf09de9bf31cb3c640abdca04cd83) `sha256:635296e6f91e60be3607c8954fc8eb5efa8b6c5f0465b004842882de280bc1f6` * [egress-router-cni](https://github.com/openshift/egress-router-cni) git [96ebd378](https://github.com/openshift/egress-router-cni/commit/96ebd3782cbb63de098e75ebcedeac60546cfee3) `sha256:581d4202e57825e09ef0410883975c75df80a8a9bb4c83f45de43080381f8999` * [gcp-pd-csi-driver](https://github.com/openshift/gcp-pd-csi-driver) git [091f0212](https://github.com/openshift/gcp-pd-csi-driver/commit/091f0212dfa6d93df37b99fcd2b4b9a4c6d5bbba) `sha256:5ebaeae1108fb28676e530718b381637a5a807fb3d3744fd11ea9211dca349fc` * [ironic-hardware-inventory-recorder](https://github.com/openshift/ironic-hardware-inventory-recorder-image) git [61c4cc7d](https://github.com/openshift/ironic-hardware-inventory-recorder-image/commit/61c4cc7dc99601fe32b239be8923a6ed693908b0) `sha256:2b6d470918ce293f6776dd1a81b0bcebc977225d490d3ca12e4289e6829c2300` * [ironic-inspector](https://github.com/openshift/ironic-inspector-image) git [916bdc6e](https://github.com/openshift/ironic-inspector-image/commit/916bdc6e005aaa73ef5c3a9b60f5c47cd0a10e29) `sha256:d965ac8f37325e9f738e10edb3751818044ad221c2e9766b98ecd17bb84161f4` * [ironic-static-ip-manager](https://github.com/openshift/ironic-static-ip-manager) git [43d640a0](https://github.com/openshift/ironic-static-ip-manager/commit/43d640a07582a5aaaa485ea85319bb0721dea251) `sha256:0054fcdaef6d766c0f4e24a14bb57ac6e5ddd7142cb8f5b659cbbc5fc8baa99e` * [k8s-prometheus-adapter](https://github.com/openshift/k8s-prometheus-adapter) git [212d80b4](https://github.com/openshift/k8s-prometheus-adapter/commit/212d80b4bd35fc6f19ec9ec537d0261a2a300cfd) `sha256:b467c2f587c62d94facc04777b176f73661b999282b44c6d7675baa1fc8f6d37` * [keepalived-ipfailover](https://github.com/openshift/images) git [0e45f638](https://github.com/openshift/images/commit/0e45f638fbf5fa9e9bdb507d81b2cb9f12fadbaf) `sha256:a6b028eee7e9ec4cae33c086e6372fbf226f8fbe502525109d28b07d727e72fe` * [kube-rbac-proxy](https://github.com/openshift/kube-rbac-proxy) git [14c288e6](https://github.com/openshift/kube-rbac-proxy/commit/14c288e6d19578d96e502def75995b882f1c9b37) `sha256:0134dcb8750dd70fd08603d11ab600e875e9f853d114feaed9f349a9ba990e1c` * [kube-state-metrics](https://github.com/openshift/kube-state-metrics) git [04bff708](https://github.com/openshift/kube-state-metrics/commit/04bff708e05190cbc18182a2dbb8a10930433c1d) `sha256:eb2a30e7f6c665a68c4e6cd100ba35186683eab5dda13e4c72670aed28001d3b` * [kube-storage-version-migrator](https://github.com/openshift/kubernetes-kube-storage-version-migrator) git [329a4b06](https://github.com/openshift/kubernetes-kube-storage-version-migrator/commit/329a4b06361cef8d70c8424d57466a6f5bcd4a59) `sha256:0d965f1f92b2cd65feea60929d3557f32aaf0f6f37247fc85fa557171b8d8d20` * machine-os-content `sha256:2e7b5fe6a2d6f6a9aff1a33e839f747a9d3d9a327b6492d4ac0a1c528279a17c` * [mdns-publisher](https://github.com/openshift/mdns-publisher) git [207a7e5d](https://github.com/openshift/mdns-publisher/commit/207a7e5d80dbca3ffb2dc205ebba516e29ebaa6d) `sha256:76fd21585b8ec59ca792fe1e31a701f15cbd59aa776820ba672ef810dcfa57ca` * [multus-admission-controller](https://github.com/openshift/multus-admission-controller) git [a7312f5e](https://github.com/openshift/multus-admission-controller/commit/a7312f5e55e9f34cc8b20f6cbfe1af0f363ca1e6) `sha256:68b86d9d20574adf08f0565c264315bf2fcab5d5ba6725aa7ae03f9bf0606679` * [multus-route-override-cni](https://github.com/openshift/route-override-cni) git [1662c3ec](https://github.com/openshift/route-override-cni/commit/1662c3ec79b880fce5cd9c4e64f5ba0d4daffc00) `sha256:d88254197c3df1f0e378606ec1a99c151202ba524c4aadc7237f015d606d746b` * [must-gather](https://github.com/openshift/must-gather) git [140ea5e8](https://github.com/openshift/must-gather/commit/140ea5e8081106c68668b6bd2d0873dc9032af0b) `sha256:9a2535b21ca764f48fb967704f569c1fd34b21190d2e50462fe22f466cc67001` * [network-metrics-daemon](https://github.com/openshift/network-metrics-daemon) git [b1926150](https://github.com/openshift/network-metrics-daemon/commit/b1926150fd61d1f5137d18606661ff451f504a98) `sha256:7d5d8db868c8980662600680d79fd3eddb0131a35c86ae7282369fd27380ac05` * [oauth-proxy](https://github.com/openshift/oauth-proxy) git [4bd47050](https://github.com/openshift/oauth-proxy/commit/4bd4705011c19a7556551c9a1dfaaa5eacc7898c) `sha256:f8900a0feeb2d12b81ec2b6f863a1bf6a96faef4981710d668680b6521639026` * [openshift-state-metrics](https://github.com/openshift/openshift-state-metrics) git [40b0968e](https://github.com/openshift/openshift-state-metrics/commit/40b0968ee1d488b791cdd6750fac6534abac122e) `sha256:2625d2fe24be9cd4fb6e3a4f0cbae8495af962a98e542e880ab4470939bf9a8e` * [openstack-cinder-csi-driver-operator](https://github.com/openshift/openstack-cinder-csi-driver-operator) git [117ce62c](https://github.com/openshift/openstack-cinder-csi-driver-operator/commit/117ce62c69b399c524850f4ca32324a4ed288acd) `sha256:fe2251d5ac73ed007bc7e81a055cdd9e84c2e33187b1beae6e8dce610e55cca1` * [openstack-machine-controllers](https://github.com/openshift/cluster-api-provider-openstack) git [471cf3ab](https://github.com/openshift/cluster-api-provider-openstack/commit/471cf3ab636c26ed7c9fba6330374a5ea1b36b43) `sha256:cb8f406d1de9a9b0dd5b6ca8db69e938c139af2ec2d6369a34ce425ef7e03e57` * [ovirt-csi-driver](https://github.com/openshift/ovirt-csi-driver) git [72545e63](https://github.com/openshift/ovirt-csi-driver/commit/72545e6381b3625bcb37e37c4c713862d04cb145) `sha256:52b0cf2e3767f535f31caea3fddf7249acf723e37d6a6047067fa57ba6e28989` * [ovirt-csi-driver-operator](https://github.com/openshift/ovirt-csi-driver-operator) git [f8808a04](https://github.com/openshift/ovirt-csi-driver-operator/commit/f8808a04dc6bfe7ce36a8238089dbae7ab29cbb6) `sha256:7d82a9004b883b422ff8d439c0316925f7d388f43e6396c7b47bf0b7d7f37943` * [pod](https://github.com/openshift/images) git [0e45f638](https://github.com/openshift/images/commit/0e45f638fbf5fa9e9bdb507d81b2cb9f12fadbaf) `sha256:dd4d47c77836319287ca2c052c8b5d5deceba3f15f093fb28ab5c6f86f1c9a22` * [prometheus](https://github.com/openshift/prometheus) git [cb5e53cd](https://github.com/openshift/prometheus/commit/cb5e53cdfedfee185feffcec13304dda87ff3055) `sha256:d61578fab2403067d8bdef920c3618c2d2557ad12fc40c76f3af511856d452f5` * [prometheus-alertmanager](https://github.com/openshift/prometheus-alertmanager) git [9954cc42](https://github.com/openshift/prometheus-alertmanager/commit/9954cc421d26ecf498ac82f3cbdc64ce3afa4c74) `sha256:6a3e096e41f22f66c098e4eabd9ee3465ed71fc0750de778cd2ca3fddf1fac40` * [prometheus-config-reloader](https://github.com/openshift/prometheus-operator) git [1f0fd51d](https://github.com/openshift/prometheus-operator/commit/1f0fd51df863c8773d2094e4ca78b4bd14cbf6e6) `sha256:02779f48b721b0a983a956ce7ff92589140643a73d1337db16653dba9c8a8892` * [prometheus-node-exporter](https://github.com/openshift/node_exporter) git [76974e2e](https://github.com/openshift/node_exporter/commit/76974e2ed037c4bf81387dabf7ccd388a724c5aa) `sha256:1c65bebe21d4132f2bfefeaf769218718cca2f48f42667d3bb5db0adb3975055` * [prometheus-operator](https://github.com/openshift/prometheus-operator) git [1f0fd51d](https://github.com/openshift/prometheus-operator/commit/1f0fd51df863c8773d2094e4ca78b4bd14cbf6e6) `sha256:676e8ae04fc442d38bb33515c4ed04e98eb8339b95dcf435e15b857c2d9ee71c` ### [aws-machine-controllers](https://github.com/openshift/cluster-api-provider-aws/tree/5368195c02ca672dc7f7a4ad571df5584fa4087f) * [Bug 1976192](https://bugzilla.redhat.com/show_bug.cgi?id=1976192): update aws-sdk-go to v1.38.25 [#415](https://github.com/openshift/cluster-api-provider-aws/pull/415) * [Bug 1942966](https://bugzilla.redhat.com/show_bug.cgi?id=1942966): Update EC2 instance types [#398](https://github.com/openshift/cluster-api-provider-aws/pull/398) * Updating ose-aws-machine-controllers builder & base images to be consistent with ART [#373](https://github.com/openshift/cluster-api-provider-aws/pull/373) * [Bug 1924471](https://bugzilla.redhat.com/show_bug.cgi?id=1924471): Bump dependencies to Kubernetes 1.20.6 to mitigate CVE-2021-3121 [#409](https://github.com/openshift/cluster-api-provider-aws/pull/409) * [Bug 1952614](https://bugzilla.redhat.com/show_bug.cgi?id=1952614): [OCPCLOUD-1115] Get instance tags from infrastructure object [#405](https://github.com/openshift/cluster-api-provider-aws/pull/405) * [Bug 1935636](https://bugzilla.redhat.com/show_bug.cgi?id=1935636): Ensure response body is closed when we are finished with the request [#391](https://github.com/openshift/cluster-api-provider-aws/pull/391) * [Full changelog](https://github.com/openshift/cluster-api-provider-aws/compare/5ffc5f422a80169b342c19f50b22a0c4883cc0e3...5368195c02ca672dc7f7a4ad571df5584fa4087f) ### [baremetal-installer, installer, installer-artifacts](https://github.com/openshift/installer/tree/23a2fe80a021a19ab4364904f6928a1f8c715dc0) * [Bug 1977481](https://bugzilla.redhat.com/show_bug.cgi?id=1977481): Dockerfile: repin libvirt [#5043](https://github.com/openshift/installer/pull/5043) * [Bug 1975819](https://bugzilla.redhat.com/show_bug.cgi?id=1975819): upi/vsphere: Use Afterburn guestinfo for static IP and hostname config [#5025](https://github.com/openshift/installer/pull/5025) * [Bug 1974282](https://bugzilla.redhat.com/show_bug.cgi?id=1974282): gather: collect networking information in log bundle [#5017](https://github.com/openshift/installer/pull/5017) * [Bug 1971163](https://bugzilla.redhat.com/show_bug.cgi?id=1971163): Updating AWS instance types [#4992](https://github.com/openshift/installer/pull/4992) * [Bug 1945467](https://bugzilla.redhat.com/show_bug.cgi?id=1945467): aws: allow use of unknown regions in known partitions [#4807](https://github.com/openshift/installer/pull/4807) * [Bug 1938426](https://bugzilla.redhat.com/show_bug.cgi?id=1938426): Set default values to machine pools before validation [#4750](https://github.com/openshift/installer/pull/4750) * [Bug 1967355](https://bugzilla.redhat.com/show_bug.cgi?id=1967355): pattern removed from sed to prevent expansion [#4975](https://github.com/openshift/installer/pull/4975) * [Bug 1956483](https://bugzilla.redhat.com/show_bug.cgi?id=1956483): Bump boot images for RHCOS fixes [#4961](https://github.com/openshift/installer/pull/4961) * [Bug 1947427](https://bugzilla.redhat.com/show_bug.cgi?id=1947427): add proxy params to bootstrap ignition [#4830](https://github.com/openshift/installer/pull/4830) * [Bug 1939014](https://bugzilla.redhat.com/show_bug.cgi?id=1939014): generate glance url considering the region [#4753](https://github.com/openshift/installer/pull/4753) * [Bug 1947216](https://bugzilla.redhat.com/show_bug.cgi?id=1947216): pkg/asset/installconfig/aws: Add iam permission for destorying clusters [#4827](https://github.com/openshift/installer/pull/4827) * [Bug 1948398](https://bugzilla.redhat.com/show_bug.cgi?id=1948398): remove ovirt_cafile from ovirt-credentials secret [#4842](https://github.com/openshift/installer/pull/4842) * [Bug 1962435](https://bugzilla.redhat.com/show_bug.cgi?id=1962435): aws: using dotted domain when looking for public hosted zone [#4948](https://github.com/openshift/installer/pull/4948) * [Bug 1940275](https://bugzilla.redhat.com/show_bug.cgi?id=1940275): Revert "baremetal: send full ignition to masters" [#4767](https://github.com/openshift/installer/pull/4767) * [Bug 1943500](https://bugzilla.redhat.com/show_bug.cgi?id=1943500): Bump gophercloud utils [#4794](https://github.com/openshift/installer/pull/4794) * [Bug 1958518](https://bugzilla.redhat.com/show_bug.cgi?id=1958518): aws: restore setting aws platform spec in infra resource [#4918](https://github.com/openshift/installer/pull/4918) * [Bug 1958428](https://bugzilla.redhat.com/show_bug.cgi?id=1958428): aws: support more auth options in manual mode [#4914](https://github.com/openshift/installer/pull/4914) * [Bug 1945907](https://bugzilla.redhat.com/show_bug.cgi?id=1945907): Byo aws iam roles 4.7 [#4813](https://github.com/openshift/installer/pull/4813) * [Bug 1954803](https://bugzilla.redhat.com/show_bug.cgi?id=1954803): aws: support for bring-your-own hosted zone [#4887](https://github.com/openshift/installer/pull/4887) * [Bug 1951571](https://bugzilla.redhat.com/show_bug.cgi?id=1951571): registry.svc.ci.openshift.org is no longer valid [#4853](https://github.com/openshift/installer/pull/4853) * [Bug 1954152](https://bugzilla.redhat.com/show_bug.cgi?id=1954152): manifests: populate aws user tags in infrastructure [#4882](https://github.com/openshift/installer/pull/4882) * [Bug 1935174](https://bugzilla.redhat.com/show_bug.cgi?id=1935174): RHCOS bump for LUKS, prjquota, etc [#4791](https://github.com/openshift/installer/pull/4791) * [Bug 1947122](https://bugzilla.redhat.com/show_bug.cgi?id=1947122): gcp: install google cloud sdk with yum the recommended way [#4824](https://github.com/openshift/installer/pull/4824) * [Bug 1933728](https://bugzilla.redhat.com/show_bug.cgi?id=1933728): baremetal: include netmask in DNSMasq dhcp range [#4698](https://github.com/openshift/installer/pull/4698) * [Bug 1930106](https://bugzilla.redhat.com/show_bug.cgi?id=1930106): bump ignition to v3_2 [#4701](https://github.com/openshift/installer/pull/4701) * [Full changelog](https://github.com/openshift/installer/compare/98e11541c24e95c864328b9b35c64b77836212ed...23a2fe80a021a19ab4364904f6928a1f8c715dc0) ### [baremetal-machine-controllers](https://github.com/openshift/cluster-api-provider-baremetal/tree/25cbb8d8f9e52244ccd6bf459e6dd4b84749de56) * [Bug 1936844](https://bugzilla.redhat.com/show_bug.cgi?id=1936844): [release-4.7] Changing the default behaviour of the CAPBM to request hard reboot [#144](https://github.com/openshift/cluster-api-provider-baremetal/pull/144) * [Full changelog](https://github.com/openshift/cluster-api-provider-baremetal/compare/4e254d08e0ad44a8ae5e4928cdc72d2dab599302...25cbb8d8f9e52244ccd6bf459e6dd4b84749de56) ### [baremetal-operator](https://github.com/openshift/baremetal-operator/tree/e36cbc13f82e290ca5f525a4da0fab516808d113) * [Bug 1972430](https://bugzilla.redhat.com/show_bug.cgi?id=1972430): Don't deprovision provisioned host due to error [#159](https://github.com/openshift/baremetal-operator/pull/159) * [Bug 1961341](https://bugzilla.redhat.com/show_bug.cgi?id=1961341): config: use rbacv1 instead of rbacv1beta1 [#148](https://github.com/openshift/baremetal-operator/pull/148) * [Bug 1910352](https://bugzilla.redhat.com/show_bug.cgi?id=1910352): Fail registration when boot MAC address conflicts [#131](https://github.com/openshift/baremetal-operator/pull/131) * [Bug 1936407](https://bugzilla.redhat.com/show_bug.cgi?id=1936407): Backport of BMO code to 4.7 to support different reboot modes [#132](https://github.com/openshift/baremetal-operator/pull/132) * [Full changelog](https://github.com/openshift/baremetal-operator/compare/8ddca62cb6bd1459f1f60b1e1e865f27347b2838...e36cbc13f82e290ca5f525a4da0fab516808d113) ### [baremetal-runtimecfg](https://github.com/openshift/baremetal-runtimecfg/tree/9c5da32ba602e5881178e56269b0506fcb54ff92) * [Bug 1962949](https://bugzilla.redhat.com/show_bug.cgi?id=1962949): Keepalived- verify that unicast peers list isn't empty on master nodes [#140](https://github.com/openshift/baremetal-runtimecfg/pull/140) * [Bug 1942488](https://bugzilla.redhat.com/show_bug.cgi?id=1942488): sort AddressesDefault by route priority, ifindex, and IPv4/IPv6 preference [#132](https://github.com/openshift/baremetal-runtimecfg/pull/132) * [Full changelog](https://github.com/openshift/baremetal-runtimecfg/compare/7cdf5fdf6947966780a1502ef37ad9e0ac647435...9c5da32ba602e5881178e56269b0506fcb54ff92) ### [cli, cli-artifacts, deployer, tools](https://github.com/openshift/oc/tree/8b4b09487463415374368af3bbc4ff2e6366477b) * [Bug 1976284](https://bugzilla.redhat.com/show_bug.cgi?id=1976284): skip-multiple-scopes with adm catalog mirror [#869](https://github.com/openshift/oc/pull/869) * [Bug 1963784](https://bugzilla.redhat.com/show_bug.cgi?id=1963784): Preserve AuthInfo when switching projects [#861](https://github.com/openshift/oc/pull/861) * [Bug 1970811](https://bugzilla.redhat.com/show_bug.cgi?id=1970811): set User-Agent when talking with registries [#848](https://github.com/openshift/oc/pull/848) * [Bug 1969928](https://bugzilla.redhat.com/show_bug.cgi?id=1969928): exclude security during exctraction [#844](https://github.com/openshift/oc/pull/844) * Fix unit test failure [#838](https://github.com/openshift/oc/pull/838) * [Bug 1942938](https://bugzilla.redhat.com/show_bug.cgi?id=1942938): [release-4.7] inspect clusteroperators as a backup to must-gather if it fails [#766](https://github.com/openshift/oc/pull/766) * [Bug 1924453](https://bugzilla.redhat.com/show_bug.cgi?id=1924453): Bump github.com/gogo/protobuf to v1.3.2 [#753](https://github.com/openshift/oc/pull/753) * [Bug 1942059](https://bugzilla.redhat.com/show_bug.cgi?id=1942059): when mirroring to a file destination, mount images under the index location [#779](https://github.com/openshift/oc/pull/779) * [Bug 1939477](https://bugzilla.redhat.com/show_bug.cgi?id=1939477): Fix unit test to use new IS [#769](https://github.com/openshift/oc/pull/769) * [Full changelog](https://github.com/openshift/oc/compare/c66c03f3012a10f16eb86fdce6330433adf6c9ee...8b4b09487463415374368af3bbc4ff2e6366477b) ### [cloud-credential-operator](https://github.com/openshift/cloud-credential-operator/tree/0783477aa72edf998344740933a99c0417ebe573) * [Bug 1958983](https://bugzilla.redhat.com/show_bug.cgi?id=1958983): rework GCP passthrough permissions checking [#338](https://github.com/openshift/cloud-credential-operator/pull/338) * [Bug 1948396](https://bugzilla.redhat.com/show_bug.cgi?id=1948396): oVirt credentials secret contains unnecessary "ovirt_cafile" [#322](https://github.com/openshift/cloud-credential-operator/pull/322) * [Bug 1948702](https://bugzilla.redhat.com/show_bug.cgi?id=1948702): [release-4.7] manifests/0000_90_cloud-credential-operator_04_alertrules: Drop CloudCredentialOperatorDown [#324](https://github.com/openshift/cloud-credential-operator/pull/324) * [Bug 1928151](https://bugzilla.redhat.com/show_bug.cgi?id=1928151): spell fix user-visible string [#301](https://github.com/openshift/cloud-credential-operator/pull/301) * [Full changelog](https://github.com/openshift/cloud-credential-operator/compare/0427557ed7300864ae0068b92c4c8bfee1629b3b...0783477aa72edf998344740933a99c0417ebe573) ### [cluster-authentication-operator](https://github.com/openshift/cluster-authentication-operator/tree/16bd3f3f4584442f42a83b4d8ee8e2f9fd0acb87) * [Bug 1971087](https://bugzilla.redhat.com/show_bug.cgi?id=1971087): add a controller to remove webhooktokenauthenticator config [#418](https://github.com/openshift/cluster-authentication-operator/pull/418) * [Bug 1956797](https://bugzilla.redhat.com/show_bug.cgi?id=1956797): bump kube to 0.20.6 to prevent delegated authz panics [#443](https://github.com/openshift/cluster-authentication-operator/pull/443) * [Bug 1941840](https://bugzilla.redhat.com/show_bug.cgi?id=1941840): endpoints controller: close response bodies [#440](https://github.com/openshift/cluster-authentication-operator/pull/440) * [Bug 1949941](https://bugzilla.redhat.com/show_bug.cgi?id=1949941): add a scraper and an alert to check for old-style tokens [#437](https://github.com/openshift/cluster-authentication-operator/pull/437) * [Full changelog](https://github.com/openshift/cluster-authentication-operator/compare/cf1e1a6c79db7cf29e7de2a90ecdc458bc13059c...16bd3f3f4584442f42a83b4d8ee8e2f9fd0acb87) ### [cluster-autoscaler](https://github.com/openshift/kubernetes-autoscaler/tree/c882ab7f35adfb0f438fa28f6579092aa0deea59) * Updating atomic-openshift-cluster-autoscaler builder & base images to be consistent with ART [#187](https://github.com/openshift/kubernetes-autoscaler/pull/187) * Updating vertical-pod-autoscaler builder & base images to be consistent with ART [#190](https://github.com/openshift/kubernetes-autoscaler/pull/190) * [Full changelog](https://github.com/openshift/kubernetes-autoscaler/compare/7f1d0ad0b53d17879034597d97dac23c9a23dbcb...c882ab7f35adfb0f438fa28f6579092aa0deea59) ### [cluster-autoscaler-operator](https://github.com/openshift/cluster-autoscaler-operator/tree/a3fecc8e7dc5d793eecf8bf77e311f5b29f5e7dd) * [Bug 1924478](https://bugzilla.redhat.com/show_bug.cgi?id=1924478): Bump dependencies to Kubernetes 1.20.6 to mitigate CVE-2021-3121 [#207](https://github.com/openshift/cluster-autoscaler-operator/pull/207) * [Full changelog](https://github.com/openshift/cluster-autoscaler-operator/compare/4b0831e0a8c151850e73ab643c2e15f5ffe22c23...a3fecc8e7dc5d793eecf8bf77e311f5b29f5e7dd) ### [cluster-baremetal-operator](https://github.com/openshift/cluster-baremetal-operator/tree/cb7d1e4ee178ea3f33eb9fc492bd002386006693) * [Bug 1972291](https://bugzilla.redhat.com/show_bug.cgi?id=1972291): Use a cache URL with the .svc.cluster.local suffix [#161](https://github.com/openshift/cluster-baremetal-operator/pull/161) * [Bug 1936544](https://bugzilla.redhat.com/show_bug.cgi?id=1936544): Inject proxy environment variables everywhere [#117](https://github.com/openshift/cluster-baremetal-operator/pull/117) * [Full changelog](https://github.com/openshift/cluster-baremetal-operator/compare/ea1ff11f6cd33532bd3f3cdd7e010e97de0fcd04...cb7d1e4ee178ea3f33eb9fc492bd002386006693) ### [cluster-config-operator](https://github.com/openshift/cluster-config-operator/tree/07e059a6b0c98e98d71f0c08dc741605e2431914) * [Bug 1954152](https://bugzilla.redhat.com/show_bug.cgi?id=1954152): vendor: bump to the latest openshift/api [#200](https://github.com/openshift/cluster-config-operator/pull/200) * [Full changelog](https://github.com/openshift/cluster-config-operator/compare/3bc7ea731d4fe149250fbc8e6805c3004d7967d8...07e059a6b0c98e98d71f0c08dc741605e2431914) ### [cluster-csi-snapshot-controller-operator](https://github.com/openshift/cluster-csi-snapshot-controller-operator/tree/fc036b59b83b25ac6d1050aee0a172abb54502c6) * [Bug 1961719](https://bugzilla.redhat.com/show_bug.cgi?id=1961719): manifests/05_operator_rbac: Drop the unused namespace property [#89](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/89) * [Bug 1967328](https://bugzilla.redhat.com/show_bug.cgi?id=1967328): Remove exclude annotation from manifests to include in ROKS [#91](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/91) * [Bug 1929881](https://bugzilla.redhat.com/show_bug.cgi?id=1929881): Fix installation on ROKS [#80](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/80) * [Full changelog](https://github.com/openshift/cluster-csi-snapshot-controller-operator/compare/95d85d4a9c9d61e02c980df28da66c5455028177...fc036b59b83b25ac6d1050aee0a172abb54502c6) ### [cluster-dns-operator](https://github.com/openshift/cluster-dns-operator/tree/cf8be7b279499d5010894b8c9bf79acc9853be36) * [Bug 1967766](https://bugzilla.redhat.com/show_bug.cgi?id=1967766): Corefile: Set bufsize to 512 bytes for all servers [#277](https://github.com/openshift/cluster-dns-operator/pull/277) * [Bug 1953097](https://bugzilla.redhat.com/show_bug.cgi?id=1953097): Corefile: Enable bufsize plugin for all servers [#267](https://github.com/openshift/cluster-dns-operator/pull/267) * [Bug 1953609](https://bugzilla.redhat.com/show_bug.cgi?id=1953609): Enable errors plugin for custom upstream resolvers [#268](https://github.com/openshift/cluster-dns-operator/pull/268) * [Bug 1942228](https://bugzilla.redhat.com/show_bug.cgi?id=1942228): Fix spurious reconciliation of DNS daemonset and service [#250](https://github.com/openshift/cluster-dns-operator/pull/250) * [Bug 1943826](https://bugzilla.redhat.com/show_bug.cgi?id=1943826): Corefile: Use 30 second max TTL for caching of negative responses [#254](https://github.com/openshift/cluster-dns-operator/pull/254) * [Bug 1937089](https://bugzilla.redhat.com/show_bug.cgi?id=1937089): Configure CoreDNS to shut down gracefully [#247](https://github.com/openshift/cluster-dns-operator/pull/247) * [Bug 1936587](https://bugzilla.redhat.com/show_bug.cgi?id=1936587): Set CoreDNS's cache's maximum TTL to 900 seconds [#245](https://github.com/openshift/cluster-dns-operator/pull/245) * [Full changelog](https://github.com/openshift/cluster-dns-operator/compare/b37ee1578d3c2a2b0e32723a17a818174662236a...cf8be7b279499d5010894b8c9bf79acc9853be36) ### [cluster-etcd-operator](https://github.com/openshift/cluster-etcd-operator/tree/51cb8c4147c45672c9645fae39bfcc6d696adc85) * [Bug 1976988](https://bugzilla.redhat.com/show_bug.cgi?id=1976988): [release-4.7]: Increase inertia duration for the EtcdMembersDegraded condition [#618](https://github.com/openshift/cluster-etcd-operator/pull/618) * [Bug 1976287](https://bugzilla.redhat.com/show_bug.cgi?id=1976287): Validate the status of the etcd snapshot during backup and restore [#617](https://github.com/openshift/cluster-etcd-operator/pull/617) * [Bug 1951447](https://bugzilla.redhat.com/show_bug.cgi?id=1951447): pkg/etcdenvvar/etcd_env.go: Sort endpoints to prevent rollout [#568](https://github.com/openshift/cluster-etcd-operator/pull/568) * [Bug 1958416](https://bugzilla.redhat.com/show_bug.cgi?id=1958416): pkg/dnshelpers: fallback to spec if status is not populated for serviceNetwork [#594](https://github.com/openshift/cluster-etcd-operator/pull/594) * [Bug 1955418](https://bugzilla.redhat.com/show_bug.cgi?id=1955418): manifests: Shift FlowSchema to level 50 [#582](https://github.com/openshift/cluster-etcd-operator/pull/582) * [Bug 1954121](https://bugzilla.redhat.com/show_bug.cgi?id=1954121): [release-4.7] Improve cert controller detection and correction of invalid certs [#577](https://github.com/openshift/cluster-etcd-operator/pull/577) * OWNERS: add lilic as reviewer [#588](https://github.com/openshift/cluster-etcd-operator/pull/588) * [Bug 1954073](https://bugzilla.redhat.com/show_bug.cgi?id=1954073): bindata, pkg: Propagate operator log level to etcd itself [#578](https://github.com/openshift/cluster-etcd-operator/pull/578) * [Full changelog](https://github.com/openshift/cluster-etcd-operator/compare/ee35da5b3ee486f786d7687849d57599d46dfc2e...51cb8c4147c45672c9645fae39bfcc6d696adc85) ### [cluster-image-registry-operator](https://github.com/openshift/cluster-image-registry-operator/tree/0f2df0aacba8c9c86ea45db241747a979af4028a) * [Bug 1977159](https://bugzilla.redhat.com/show_bug.cgi?id=1977159): bump aws-sdk-go to v1.38.35 [#704](https://github.com/openshift/cluster-image-registry-operator/pull/704) * [Bug 1973693](https://bugzilla.redhat.com/show_bug.cgi?id=1973693): Setting required pod anti-affinity rules [#697](https://github.com/openshift/cluster-image-registry-operator/pull/697) * [Bug 1960562](https://bugzilla.redhat.com/show_bug.cgi?id=1960562): manifests: fix selector in image-registry-operator [#689](https://github.com/openshift/cluster-image-registry-operator/pull/689) * [Bug 1957308](https://bugzilla.redhat.com/show_bug.cgi?id=1957308): Setting user tags always when Storage is Managed [#684](https://github.com/openshift/cluster-image-registry-operator/pull/684) * [Bug 1955176](https://bugzilla.redhat.com/show_bug.cgi?id=1955176): Setting user provided tags on bucket creation [#682](https://github.com/openshift/cluster-image-registry-operator/pull/682) * [Full changelog](https://github.com/openshift/cluster-image-registry-operator/compare/538ff7fed284953731785c495cf286ea33d97f50...0f2df0aacba8c9c86ea45db241747a979af4028a) ### [cluster-ingress-operator](https://github.com/openshift/cluster-ingress-operator/tree/b86f935f5e693f48dbf6ec23a490422b6e295eb7) * [Bug 1978845](https://bugzilla.redhat.com/show_bug.cgi?id=1978845): Specify topology spread constraints [#632](https://github.com/openshift/cluster-ingress-operator/pull/632) * [Bug 1973983](https://bugzilla.redhat.com/show_bug.cgi?id=1973983): Canary: Handle downgrades from 4.8 to 4.7 properly [#627](https://github.com/openshift/cluster-ingress-operator/pull/627) * [Bug 1960776](https://bugzilla.redhat.com/show_bug.cgi?id=1960776): Reconcile openshift-ingress namespace on upgrade [#616](https://github.com/openshift/cluster-ingress-operator/pull/616) * [Bug 1942603](https://bugzilla.redhat.com/show_bug.cgi?id=1942603): [release-4.7] Add the new NetworkPolicy-matching label to the namespace [#615](https://github.com/openshift/cluster-ingress-operator/pull/615) * [Bug 1954097](https://bugzilla.redhat.com/show_bug.cgi?id=1954097): Annotate services of type LoadBalancer with user tags (AWS only) [#606](https://github.com/openshift/cluster-ingress-operator/pull/606) * [Bug 1937214](https://bugzilla.redhat.com/show_bug.cgi?id=1937214): Fix spurious reconciliation of NodePort services [#570](https://github.com/openshift/cluster-ingress-operator/pull/570) * [Bug 1935891](https://bugzilla.redhat.com/show_bug.cgi?id=1935891): Canary: Perform canary test probes over https [#566](https://github.com/openshift/cluster-ingress-operator/pull/566) * [Bug 1936093](https://bugzilla.redhat.com/show_bug.cgi?id=1936093): Canary: Use cluster-wide proxy for canary client [#568](https://github.com/openshift/cluster-ingress-operator/pull/568) * [Bug 1934904](https://bugzilla.redhat.com/show_bug.cgi?id=1934904): Canary: Schedule canary server pods to worker and infra nodes [#564](https://github.com/openshift/cluster-ingress-operator/pull/564) * [Full changelog](https://github.com/openshift/cluster-ingress-operator/compare/c7625965839fe53059df5ea3224a867554bf6b86...b86f935f5e693f48dbf6ec23a490422b6e295eb7) ### [cluster-kube-apiserver-operator](https://github.com/openshift/cluster-kube-apiserver-operator/tree/099c6afa1f8b4fe7654207f7eabd7784b42ce2e3) * [Bug 1927321](https://bugzilla.redhat.com/show_bug.cgi?id=1927321): competing connectivitycheckcontrollers cause pod restarts during upgrades [#1041](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1041) * [Full changelog](https://github.com/openshift/cluster-kube-apiserver-operator/compare/60dc437fe7f19ea91be6900e5e4974d7dadbeb11...099c6afa1f8b4fe7654207f7eabd7784b42ce2e3) ### [cluster-kube-controller-manager-operator](https://github.com/openshift/cluster-kube-controller-manager-operator/tree/281590936f3a94d4ae1eb008709fda6614fe763b) * [Bug 1924488](https://bugzilla.redhat.com/show_bug.cgi?id=1924488): Bump github.com/gogo/protobuf to v1.3.2 [#508](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/508) * [Full changelog](https://github.com/openshift/cluster-kube-controller-manager-operator/compare/d95b6453169b9a43d01e939f060919d2a7a6e94f...281590936f3a94d4ae1eb008709fda6614fe763b) ### [cluster-kube-scheduler-operator](https://github.com/openshift/cluster-kube-scheduler-operator/tree/b2204ca23a57e9f01af915375e6a18fc86ffecda) * [Bug 1924490](https://bugzilla.redhat.com/show_bug.cgi?id=1924490): Bump github.com/gogo/protobuf to v1.3.2 [#334](https://github.com/openshift/cluster-kube-scheduler-operator/pull/334) * [Full changelog](https://github.com/openshift/cluster-kube-scheduler-operator/compare/776a21927cdedf968dd368638c14b7ba998dbe65...b2204ca23a57e9f01af915375e6a18fc86ffecda) ### [cluster-kube-storage-version-migrator-operator](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/tree/54484757581ec26f178c599215715bafd6029582) * Updating ose-cluster-kube-storage-version-migrator-operator builder & base images to be consistent with ART [#38](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/pull/38) * [Full changelog](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/compare/572caa117777db92d52564290522be3489f40074...54484757581ec26f178c599215715bafd6029582) ### [cluster-machine-approver](https://github.com/openshift/cluster-machine-approver/tree/9043e2bba8f4707a578895f8b29d4736a61a010c) * [Bug 1924492](https://bugzilla.redhat.com/show_bug.cgi?id=1924492): Bump dependencies to Kubernetes 1.20.6 to mitigate CVE-2021-3121 [#120](https://github.com/openshift/cluster-machine-approver/pull/120) * Updating ose-cluster-machine-approver builder & base images to be consistent with ART [#103](https://github.com/openshift/cluster-machine-approver/pull/103) * [Full changelog](https://github.com/openshift/cluster-machine-approver/compare/72a4740ff38e9c924d0f7cd760b6b5fd85283242...9043e2bba8f4707a578895f8b29d4736a61a010c) ### [cluster-monitoring-operator](https://github.com/openshift/cluster-monitoring-operator/tree/d6725052e00a206cab10f6c40abdfa1a3c2aff0f) * [Bug 1969963](https://bugzilla.redhat.com/show_bug.cgi?id=1969963): Recording rule for builds by strategy [#1206](https://github.com/openshift/cluster-monitoring-operator/pull/1206) * [Bug 1967966](https://bugzilla.redhat.com/show_bug.cgi?id=1967966): Switch back anti-affinity to soft from hard for Prometheus [#1200](https://github.com/openshift/cluster-monitoring-operator/pull/1200) * [Bug 1956565](https://bugzilla.redhat.com/show_bug.cgi?id=1956565): manifest allowlist: add acm_managed_cluster_info in 4.7 [#1144](https://github.com/openshift/cluster-monitoring-operator/pull/1144) * [Bug 1961069](https://bugzilla.redhat.com/show_bug.cgi?id=1961069): remove dependency of e2e tests on AWS [#1162](https://github.com/openshift/cluster-monitoring-operator/pull/1162) * [Bug 1957703](https://bugzilla.redhat.com/show_bug.cgi?id=1957703): [4.7]: Add hard anti-affinity constraints to Prometheuses [#1150](https://github.com/openshift/cluster-monitoring-operator/pull/1150) * [Bug 1950290](https://bugzilla.redhat.com/show_bug.cgi?id=1950290): remove KubeClientCertificateExpiration alert rule [#1171](https://github.com/openshift/cluster-monitoring-operator/pull/1171) * [Bug 1955482](https://bugzilla.redhat.com/show_bug.cgi?id=1955482): fix kube-state-metrics regexp patterns [#1163](https://github.com/openshift/cluster-monitoring-operator/pull/1163) * [Bug 1955482](https://bugzilla.redhat.com/show_bug.cgi?id=1955482): Drop high-cardinality metrics from kube-state-metrics which aren't used [#1141](https://github.com/openshift/cluster-monitoring-operator/pull/1141) * [Bug 1955469](https://bugzilla.redhat.com/show_bug.cgi?id=1955469): remove node_mountstats_nfs_* metrics [#1154](https://github.com/openshift/cluster-monitoring-operator/pull/1154) * [Bug 1955462](https://bugzilla.redhat.com/show_bug.cgi?id=1955462): drop container_memory_failures_total metric backport [#1160](https://github.com/openshift/cluster-monitoring-operator/pull/1160) * [Bug 1952149](https://bugzilla.redhat.com/show_bug.cgi?id=1952149): oc adm top reporting unknown status for Windows node [#1130](https://github.com/openshift/cluster-monitoring-operator/pull/1130) * [Bug 1955449](https://bugzilla.redhat.com/show_bug.cgi?id=1955449): drop crio image metrics [#1134](https://github.com/openshift/cluster-monitoring-operator/pull/1134) * [Bug 1945856](https://bugzilla.redhat.com/show_bug.cgi?id=1945856): Revert "Bug 1934516: [4.7]: jsonnet/prometheus.jsonnet: Apply system-cluster-critical class to cluster Prometheus " [#1103](https://github.com/openshift/cluster-monitoring-operator/pull/1103) * [Bug 1945851](https://bugzilla.redhat.com/show_bug.cgi?id=1945851): Backport Remove the "instance" and "pod" labels for kube-state-metrics metrics [#1101](https://github.com/openshift/cluster-monitoring-operator/pull/1101) * [Bug 1926876](https://bugzilla.redhat.com/show_bug.cgi?id=1926876): pkg/manifests: fix prometheus-proxy trustedCA [#1051](https://github.com/openshift/cluster-monitoring-operator/pull/1051) * [Bug 1932820](https://bugzilla.redhat.com/show_bug.cgi?id=1932820): Remove kube-apiserver-availability.rules [#1069](https://github.com/openshift/cluster-monitoring-operator/pull/1069) * [Full changelog](https://github.com/openshift/cluster-monitoring-operator/compare/dea798c5e45e05b431f203bb382fd06bafb88f6d...d6725052e00a206cab10f6c40abdfa1a3c2aff0f) ### [cluster-network-operator](https://github.com/openshift/cluster-network-operator/tree/6fc60497ad47aed067d17b35b6d144f6f15b80f5) * [Bug 1982217](https://bugzilla.redhat.com/show_bug.cgi?id=1982217): Use 10% for ovnkube-node for maxUnavailable [#1153](https://github.com/openshift/cluster-network-operator/pull/1153) * [Bug 1969860](https://bugzilla.redhat.com/show_bug.cgi?id=1969860): Escape characters on ini file [#1127](https://github.com/openshift/cluster-network-operator/pull/1127) * [Bug 1967994](https://bugzilla.redhat.com/show_bug.cgi?id=1967994): Backport daemonset to drop icmp frag needed packets received from other nodes in the cluster to Rel 4.7 [#1119](https://github.com/openshift/cluster-network-operator/pull/1119) * [Bug 1972183](https://bugzilla.redhat.com/show_bug.cgi?id=1972183): config: Set enable-profiling true by default and allow enable-profiling as a proxy argument [#1129](https://github.com/openshift/cluster-network-operator/pull/1129) * [Bug 1967388](https://bugzilla.redhat.com/show_bug.cgi?id=1967388): annotate flowcontrol with `networkoperator.openshift.io/ignore-errors` [#1118](https://github.com/openshift/cluster-network-operator/pull/1118) * [Bug 1967972](https://bugzilla.redhat.com/show_bug.cgi?id=1967972): Add tokenreviews permissions for kube-proxy [#1120](https://github.com/openshift/cluster-network-operator/pull/1120) * [Bug 1942603](https://bugzilla.redhat.com/show_bug.cgi?id=1942603): [release-4.7] Allow from router policy support for cluster network operator [#1087](https://github.com/openshift/cluster-network-operator/pull/1087) * [Bug 1937396](https://bugzilla.redhat.com/show_bug.cgi?id=1937396): kuryr/alerts: change the rule for free count [#1011](https://github.com/openshift/cluster-network-operator/pull/1011) * [Bug 1957749](https://bugzilla.redhat.com/show_bug.cgi?id=1957749): ovnkube: add missing resource requests for SBDB [#1088](https://github.com/openshift/cluster-network-operator/pull/1088) * [Bug 1954302](https://bugzilla.redhat.com/show_bug.cgi?id=1954302): Remove OVS daemonsets [#1076](https://github.com/openshift/cluster-network-operator/pull/1076) * [Bug 1956352](https://bugzilla.redhat.com/show_bug.cgi?id=1956352): [4.7] OVN kubernetes dual-stack conversion [#1082](https://github.com/openshift/cluster-network-operator/pull/1082) * [Bug 1941214](https://bugzilla.redhat.com/show_bug.cgi?id=1941214): Use 10% for ovs maxUnavailable for rolling update [#1031](https://github.com/openshift/cluster-network-operator/pull/1031) * [Bug 1936719](https://bugzilla.redhat.com/show_bug.cgi?id=1936719): OSD-6600 network-metrics missing priorityClass [#1007](https://github.com/openshift/cluster-network-operator/pull/1007) * [Bug 1927321](https://bugzilla.redhat.com/show_bug.cgi?id=1927321): competing connectivitycheckcontrollers cause pod restarts during upgrades [#1050](https://github.com/openshift/cluster-network-operator/pull/1050) * [Bug 1941212](https://bugzilla.redhat.com/show_bug.cgi?id=1941212): The Multus daemonset should handle 10% maxUnavailable [#1030](https://github.com/openshift/cluster-network-operator/pull/1030) * [Bug 1940806](https://bugzilla.redhat.com/show_bug.cgi?id=1940806): OVN Upgrade: fix upgrade order of node and master [#1029](https://github.com/openshift/cluster-network-operator/pull/1029) * [Bug 1929371](https://bugzilla.redhat.com/show_bug.cgi?id=1929371): Don't set ClusterOperator Version until rollout is complete [#983](https://github.com/openshift/cluster-network-operator/pull/983) * [Bug 1937829](https://bugzilla.redhat.com/show_bug.cgi?id=1937829): Cherry-pick dual stack migration [#1017](https://github.com/openshift/cluster-network-operator/pull/1017) * [Bug 1928028](https://bugzilla.redhat.com/show_bug.cgi?id=1928028): Kuryr: Let Kuryr autodetect primary CNI interface [#978](https://github.com/openshift/cluster-network-operator/pull/978) * [Bug 1935473](https://bugzilla.redhat.com/show_bug.cgi?id=1935473): Include LB members for Machines created on day-2 operation [#1002](https://github.com/openshift/cluster-network-operator/pull/1002) * [Full changelog](https://github.com/openshift/cluster-network-operator/compare/2cf98811eba874f02a2bdcb73844549a454cae8d...6fc60497ad47aed067d17b35b6d144f6f15b80f5) ### [cluster-node-tuning-operator](https://github.com/openshift/cluster-node-tuning-operator/tree/d546b54bcb292cd3691f4d25bbb8899690d5adab) * [Bug 1958885](https://bugzilla.redhat.com/show_bug.cgi?id=1958885): Switch to client-go leader-with-lease election. [#238](https://github.com/openshift/cluster-node-tuning-operator/pull/238) * [Bug 1960542](https://bugzilla.redhat.com/show_bug.cgi?id=1960542): manifests: fix selector in node-tuning-operator ServiceMonitor [#228](https://github.com/openshift/cluster-node-tuning-operator/pull/228) * [Bug 1928614](https://bugzilla.redhat.com/show_bug.cgi?id=1928614): Keep ignition units in sync with [service] plugin. [#215](https://github.com/openshift/cluster-node-tuning-operator/pull/215) * [Full changelog](https://github.com/openshift/cluster-node-tuning-operator/compare/24392937d275074c73294d3e02ea71b2f1e16299...d546b54bcb292cd3691f4d25bbb8899690d5adab) ### [cluster-openshift-apiserver-operator](https://github.com/openshift/cluster-openshift-apiserver-operator/tree/ecfa2d959fe2afcbd3e947658d267b085a1b2063) * [Bug 1955502](https://bugzilla.redhat.com/show_bug.cgi?id=1955502): explicitly allow apiserver pods to write to their root FS [#449](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/449) * [Bug 1927321](https://bugzilla.redhat.com/show_bug.cgi?id=1927321): competing connectivitycheckcontrollers cause pod restarts during upgrades [#444](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/444) * [Full changelog](https://github.com/openshift/cluster-openshift-apiserver-operator/compare/3e7d4b41ef5c311b1bdc58490bdf5b5655cfa22c...ecfa2d959fe2afcbd3e947658d267b085a1b2063) ### [cluster-openshift-controller-manager-operator](https://github.com/openshift/cluster-openshift-controller-manager-operator/tree/245005e3065238ecd4aef208c21456afa09ec38e) * [Bug 1944142](https://bugzilla.redhat.com/show_bug.cgi?id=1944142): Bump kubernetes to 0.20.5 [#204](https://github.com/openshift/cluster-openshift-controller-manager-operator/pull/204) * [Bug 1931856](https://bugzilla.redhat.com/show_bug.cgi?id=1931856): Set registry routes in operand config [#199](https://github.com/openshift/cluster-openshift-controller-manager-operator/pull/199) * [Full changelog](https://github.com/openshift/cluster-openshift-controller-manager-operator/compare/7d311b378ea9ccbf486a9fea9bce8ef53345c5ef...245005e3065238ecd4aef208c21456afa09ec38e) ### [cluster-policy-controller](https://github.com/openshift/cluster-policy-controller/tree/42791bac64066daac0922b3d77e4bd86edae3b4e) * [Bug 1924496](https://bugzilla.redhat.com/show_bug.cgi?id=1924496): Bump github.com/gogo/protobuf to v1.3.2 [#58](https://github.com/openshift/cluster-policy-controller/pull/58) * [Full changelog](https://github.com/openshift/cluster-policy-controller/compare/3ca5e1497a1d77b5337701087b4bdbcd81283f9f...42791bac64066daac0922b3d77e4bd86edae3b4e) ### [cluster-samples-operator](https://github.com/openshift/cluster-samples-operator/tree/0df8f92c275b9eccfb1b3ccdd79fb861ddee1d99) * [Bug 1923036](https://bugzilla.redhat.com/show_bug.cgi?id=1923036): Update Jenkins monitored templates names [#359](https://github.com/openshift/cluster-samples-operator/pull/359) * [Bug 1961518](https://bugzilla.redhat.com/show_bug.cgi?id=1961518): manifests: fix selector in ServiceMonitor [#375](https://github.com/openshift/cluster-samples-operator/pull/375) * [Bug 1950808](https://bugzilla.redhat.com/show_bug.cgi?id=1950808): add DeepCopy to avoid SharedInformer cache mutation [#370](https://github.com/openshift/cluster-samples-operator/pull/370) * [Full changelog](https://github.com/openshift/cluster-samples-operator/compare/c283ca0858ce3a6bc7e64f2b7d1c3e61cc351aab...0df8f92c275b9eccfb1b3ccdd79fb861ddee1d99) ### [cluster-storage-operator](https://github.com/openshift/cluster-storage-operator/tree/6d2c25f3cfb931deca457a0c6261651c1a64c464) * [Bug 1961719](https://bugzilla.redhat.com/show_bug.cgi?id=1961719): manifests: remove namespace from cluster-storage-operator-role binding [#170](https://github.com/openshift/cluster-storage-operator/pull/170) * [Bug 1959546](https://bugzilla.redhat.com/show_bug.cgi?id=1959546): Add alert about vsphere-problem-detector unable to connect [#169](https://github.com/openshift/cluster-storage-operator/pull/169) * [Full changelog](https://github.com/openshift/cluster-storage-operator/compare/fd2b47c06d0c7efae84c6ff44680f9025ac4f283...6d2c25f3cfb931deca457a0c6261651c1a64c464) ### [cluster-update-keys](https://github.com/openshift/cluster-update-keys/tree/b7e791773b67f9acd6f521b8c1f69778e43a7d94) * Pack both keys in one verifier-public-key-ci entry [#36](https://github.com/openshift/cluster-update-keys/pull/36) * Adding the new Openshift CI Signer key [#34](https://github.com/openshift/cluster-update-keys/pull/34) * [Full changelog](https://github.com/openshift/cluster-update-keys/compare/a7065d83eff2a4dfed1146ff9f7a4f599a73d618...b7e791773b67f9acd6f521b8c1f69778e43a7d94) ### [cluster-version-operator](https://github.com/openshift/cluster-version-operator/tree/fa7bfbc485b4256535b7de172d1083f83c9409ce) * [Bug 1970272](https://bugzilla.redhat.com/show_bug.cgi?id=1970272): Fixing the log message in rbac.go for clusterrole [#609](https://github.com/openshift/cluster-version-operator/pull/609) * [Bug 1970272](https://bugzilla.redhat.com/show_bug.cgi?id=1970272): Log object updates and show existing/required diff [#589](https://github.com/openshift/cluster-version-operator/pull/589) * [Bug 1969501](https://bugzilla.redhat.com/show_bug.cgi?id=1969501): install/0000_90_cluster-version-operator_02_servicemonitor: Soften ClusterOperatorDegraded [#587](https://github.com/openshift/cluster-version-operator/pull/587) * [Bug 1969378](https://bugzilla.redhat.com/show_bug.cgi?id=1969378): avoid hotlooping on RoleBindings with empty APIGroup [#584](https://github.com/openshift/cluster-version-operator/pull/584) * [Bug 1966977](https://bugzilla.redhat.com/show_bug.cgi?id=1966977): Prevent hotlooping in ImageStreams [#580](https://github.com/openshift/cluster-version-operator/pull/580) * [Bug 1959238](https://bugzilla.redhat.com/show_bug.cgi?id=1959238): pkg/cvo/sync_worker: Shift ClusterOperator pre-creation into the manifest-task node [#557](https://github.com/openshift/cluster-version-operator/pull/557) * [Bug 1943754](https://bugzilla.redhat.com/show_bug.cgi?id=1943754): Ensure automountServiceAccountToken is synced on service account updates [#539](https://github.com/openshift/cluster-version-operator/pull/539) * [Bug 1941217](https://bugzilla.redhat.com/show_bug.cgi?id=1941217): pkg/cvo/sync_worker: Skip precreation of baremetal ClusterOperator [#534](https://github.com/openshift/cluster-version-operator/pull/534) * [Bug 1926795](https://bugzilla.redhat.com/show_bug.cgi?id=1926795): install/0000_90_cluster-version-operator_02_servicemonitor.yaml: adjust "CannotRetrieveUpdates" to "warning" [#516](https://github.com/openshift/cluster-version-operator/pull/516) * [Full changelog](https://github.com/openshift/cluster-version-operator/compare/cf0e3d15edd16777dac91e894af733b1e245d53c...fa7bfbc485b4256535b7de172d1083f83c9409ce) ### [console](https://github.com/openshift/console/tree/b571ac9bad467db8459f25de9c5a4f3b54789312) * [Bug 1973572](https://bugzilla.redhat.com/show_bug.cgi?id=1973572): Hardcode strings in Home->Overview page [#9322](https://github.com/openshift/console/pull/9322) * [Bug 1942864](https://bugzilla.redhat.com/show_bug.cgi?id=1942864): Warning Alert for Encrypted PVs in Create StorageClass [#8464](https://github.com/openshift/console/pull/8464) * [Bug 1965526](https://bugzilla.redhat.com/show_bug.cgi?id=1965526): Removing library charts from the merged helm repo index entries. [#9076](https://github.com/openshift/console/pull/9076) * [Bug 1970796](https://bugzilla.redhat.com/show_bug.cgi?id=1970796): update cluster-local label for ksvc [#9220](https://github.com/openshift/console/pull/9220) * [Bug 1970720](https://bugzilla.redhat.com/show_bug.cgi?id=1970720): fix rotated pipelinerun status icon issue in safari [#9216](https://github.com/openshift/console/pull/9216) * [Bug 1969536](https://bugzilla.redhat.com/show_bug.cgi?id=1969536): Omit bitbucket branch in URL if it contains slash [#9180](https://github.com/openshift/console/pull/9180) * [Bug 1954962](https://bugzilla.redhat.com/show_bug.cgi?id=1954962): removes extra annotations form spec template for ksvc [#8823](https://github.com/openshift/console/pull/8823) * [Bug 1948537](https://bugzilla.redhat.com/show_bug.cgi?id=1948537): add hide/reveal button for kms token [#8616](https://github.com/openshift/console/pull/8616) * [Bug 1942160](https://bugzilla.redhat.com/show_bug.cgi?id=1942160): Update the scope of GitOpsService resource [#8450](https://github.com/openshift/console/pull/8450) * [Bug 1971667](https://bugzilla.redhat.com/show_bug.cgi?id=1971667): Track and show error messages in modals [#9232](https://github.com/openshift/console/pull/9232) * [Bug 1969791](https://bugzilla.redhat.com/show_bug.cgi?id=1969791): fixes: WebTerminal widget should send resize events [#9190](https://github.com/openshift/console/pull/9190) * [Bug 1969105](https://bugzilla.redhat.com/show_bug.cgi?id=1969105): Update IP address on pods list to show podIP other than … [#9172](https://github.com/openshift/console/pull/9172) * [Bug 1967106](https://bugzilla.redhat.com/show_bug.cgi?id=1967106): can't open terminal for pods that have more than one co… [#9117](https://github.com/openshift/console/pull/9117) * [Bug 1966275](https://bugzilla.redhat.com/show_bug.cgi?id=1966275): Fix Pipeline Parameters in Modals accept empty string defaults [#9085](https://github.com/openshift/console/pull/9085) * [Bug 1961567](https://bugzilla.redhat.com/show_bug.cgi?id=1961567): Remove the broken Devfile Sample for BuildConfigs [#8956](https://github.com/openshift/console/pull/8956) * [Bug 1963025](https://bugzilla.redhat.com/show_bug.cgi?id=1963025): Fix documentation link to network policies [#8953](https://github.com/openshift/console/pull/8953) * [Bug 1953606](https://bugzilla.redhat.com/show_bug.cgi?id=1953606): Fixing failure domain issue with custom pools (4.7 backport) [#8775](https://github.com/openshift/console/pull/8775) * [Bug 1970485](https://bugzilla.redhat.com/show_bug.cgi?id=1970485): Add pipeline annotation to secrets for private git repo import with pipeline [#9207](https://github.com/openshift/console/pull/9207) * [Bug 1964400](https://bugzilla.redhat.com/show_bug.cgi?id=1964400): Fix RGW Total Used Query [#9038](https://github.com/openshift/console/pull/9038) * [Bug 1958873](https://bugzilla.redhat.com/show_bug.cgi?id=1958873): Fix disk replacement during second replacement [#9083](https://github.com/openshift/console/pull/9083) * [Bug 1961887](https://bugzilla.redhat.com/show_bug.cgi?id=1961887): Update Taskrun tab to make namespace based calls [#8968](https://github.com/openshift/console/pull/8968) * [Bug 1959356](https://bugzilla.redhat.com/show_bug.cgi?id=1959356): Tech preview badge for arbiter [#8870](https://github.com/openshift/console/pull/8870) * [Bug 1964322](https://bugzilla.redhat.com/show_bug.cgi?id=1964322): The status of "Used Capacity Breakdown [Pods]" is "Not available" [#9028](https://github.com/openshift/console/pull/9028) * [Bug 1957499](https://bugzilla.redhat.com/show_bug.cgi?id=1957499): OperatorHub - console accepts any value for infraFeatures [#8859](https://github.com/openshift/console/pull/8859) * [Bug 1960686](https://bugzilla.redhat.com/show_bug.cgi?id=1960686): Fix hot loop in global config page [#8935](https://github.com/openshift/console/pull/8935) * [Bug 1947091](https://bugzilla.redhat.com/show_bug.cgi?id=1947091): Fix skipped task status when using conditions [#8582](https://github.com/openshift/console/pull/8582) * [Bug 1962493](https://bugzilla.redhat.com/show_bug.cgi?id=1962493): Hide TaskRun edit actions for rows in Pipelinerun's TaskRun tab [#8987](https://github.com/openshift/console/pull/8987) * [Bug 1966798](https://bugzilla.redhat.com/show_bug.cgi?id=1966798): [release-4.7] Remove monitoring labelling step for 4.7 tests [#9073](https://github.com/openshift/console/pull/9073) * [Bug 1951210](https://bugzilla.redhat.com/show_bug.cgi?id=1951210): Fix default resource log download file name [#8707](https://github.com/openshift/console/pull/8707) * [Bug 1944046](https://bugzilla.redhat.com/show_bug.cgi?id=1944046): Warn using an unsupported IE browser [#8494](https://github.com/openshift/console/pull/8494) * [release 4.7] Bug 1939553: Support binary file type secret entries [#8389](https://github.com/openshift/console/pull/8389) * [Bug 1960544](https://bugzilla.redhat.com/show_bug.cgi?id=1960544): Overly generic CSS rules for dd and dt elements breaks styling elsewhere in console [#8925](https://github.com/openshift/console/pull/8925) * [Bug 1960093](https://bugzilla.redhat.com/show_bug.cgi?id=1960093): Make console works against api proxy [#8914](https://github.com/openshift/console/pull/8914) * [Bug 1942027](https://bugzilla.redhat.com/show_bug.cgi?id=1942027): Fix RBAC check when creating a resource [#8448](https://github.com/openshift/console/pull/8448) * [Bug 1956336](https://bugzilla.redhat.com/show_bug.cgi?id=1956336): Fix Triggers section in eventlistener details page [#8842](https://github.com/openshift/console/pull/8842) * [Bug 1953937](https://bugzilla.redhat.com/show_bug.cgi?id=1953937): Fixing PVC creation page issue in 4.7(Reverting wrong commit) [#8784](https://github.com/openshift/console/pull/8784) * [Bug 1952578](https://bugzilla.redhat.com/show_bug.cgi?id=1952578): Don't poll ClusterVersion when user doesn't have authority [#8749](https://github.com/openshift/console/pull/8749) * [Bug 1950489](https://bugzilla.redhat.com/show_bug.cgi?id=1950489): Fix "Create binding" link from Role page, RoleBindings tab [#8685](https://github.com/openshift/console/pull/8685) * [Bug 1948958](https://bugzilla.redhat.com/show_bug.cgi?id=1948958): Fix ingress details page to show referenced secret name [#8633](https://github.com/openshift/console/pull/8633) * [Bug 1944955](https://bugzilla.redhat.com/show_bug.cgi?id=1944955): Fix close button in the new 'Storage cluster exists' warning alert modal [#8524](https://github.com/openshift/console/pull/8524) * [Bug 1956313](https://bugzilla.redhat.com/show_bug.cgi?id=1956313): Save additional parameters from build guidance container and drop it [#8841](https://github.com/openshift/console/pull/8841) * [Bug 1953728](https://bugzilla.redhat.com/show_bug.cgi?id=1953728): Fix issues related to loading dynamic plugins [#8780](https://github.com/openshift/console/pull/8780) * [Bug 1945594](https://bugzilla.redhat.com/show_bug.cgi?id=1945594): fixing-project-creation-and-updated-packageJson [#8536](https://github.com/openshift/console/pull/8536) * [Bug 1950214](https://bugzilla.redhat.com/show_bug.cgi?id=1950214): Fix start pipeline action access review [#8681](https://github.com/openshift/console/pull/8681) * [Bug 1948369](https://bugzilla.redhat.com/show_bug.cgi?id=1948369): Remove cluster label from predefined monitoring queries [#8613](https://github.com/openshift/console/pull/8613) * [Bug 1954109](https://bugzilla.redhat.com/show_bug.cgi?id=1954109): Backport telemetry dynamic extension to release-4.7 [#8783](https://github.com/openshift/console/pull/8783) * [Bug 1952209](https://bugzilla.redhat.com/show_bug.cgi?id=1952209): Consistent formatting of dates and times [#8734](https://github.com/openshift/console/pull/8734) * [Bug 1952293](https://bugzilla.redhat.com/show_bug.cgi?id=1952293): adds check for templates [#8736](https://github.com/openshift/console/pull/8736) * [Bug 1942843](https://bugzilla.redhat.com/show_bug.cgi?id=1942843): Modified description for storage class encryption - 4.7 Backport [#8462](https://github.com/openshift/console/pull/8462) * [Bug 1948938](https://bugzilla.redhat.com/show_bug.cgi?id=1948938): [release-4.7] Prow script point to deleted resource [#8619](https://github.com/openshift/console/pull/8619) * [Bug 1944855](https://bugzilla.redhat.com/show_bug.cgi?id=1944855): Update Dockerfile.product for nodejs v14.16.0 [#8488](https://github.com/openshift/console/pull/8488) * [Bug 1945153](https://bugzilla.redhat.com/show_bug.cgi?id=1945153): Remove pipeline Tech preview badge for pipelines GA operator [#8528](https://github.com/openshift/console/pull/8528) * [Bug 1943643](https://bugzilla.redhat.com/show_bug.cgi?id=1943643): fix pipeline metrics endpoint for 1.4 osp [#8489](https://github.com/openshift/console/pull/8489) * [Bug 1944349](https://bugzilla.redhat.com/show_bug.cgi?id=1944349): fix backwards incompatible trigger api changes [#8503](https://github.com/openshift/console/pull/8503) * [Bug 1943441](https://bugzilla.redhat.com/show_bug.cgi?id=1943441): Add 'Roll Back' action for Replication Controllers and Replica Sets [#8475](https://github.com/openshift/console/pull/8475) * [Bug 1925792](https://bugzilla.redhat.com/show_bug.cgi?id=1925792): Fix translation for edit annotation [#8078](https://github.com/openshift/console/pull/8078) * [Bug 1941468](https://bugzilla.redhat.com/show_bug.cgi?id=1941468): Change link for not available state [#8431](https://github.com/openshift/console/pull/8431) * [Bug 1939608](https://bugzilla.redhat.com/show_bug.cgi?id=1939608): Fix null handling in FilterToolbar_ to prevent possible exceptions [#8394](https://github.com/openshift/console/pull/8394) * [Bug 1937356](https://bugzilla.redhat.com/show_bug.cgi?id=1937356): Fix to show correct internal image-stream name in container image edit flow's internal registry image-stream dropdown for kn service [#8353](https://github.com/openshift/console/pull/8353) * [Bug 1927198](https://bugzilla.redhat.com/show_bug.cgi?id=1927198): fix pvc string in pvc.view [#8126](https://github.com/openshift/console/pull/8126) * [Bug 1927311](https://bugzilla.redhat.com/show_bug.cgi?id=1927311): avoid 404 errors attempting to load en-US [#8128](https://github.com/openshift/console/pull/8128) * [Bug 1931382](https://bugzilla.redhat.com/show_bug.cgi?id=1931382): Hide pipeline section in container image edit flow [#8209](https://github.com/openshift/console/pull/8209) * [Bug 1933665](https://bugzilla.redhat.com/show_bug.cgi?id=1933665): [release-4.7] Create ImageStream and other resources for samples step by step [#8255](https://github.com/openshift/console/pull/8255) * [Bug 1935672](https://bugzilla.redhat.com/show_bug.cgi?id=1935672): [release-4.7] fix pipelinerun status icon rendering issue [#8311](https://github.com/openshift/console/pull/8311) * [Bug 1932272](https://bugzilla.redhat.com/show_bug.cgi?id=1932272): Fix KMS validation error for 4.7 release [#8221](https://github.com/openshift/console/pull/8221) * [Bug 1937313](https://bugzilla.redhat.com/show_bug.cgi?id=1937313): Removed loaded prop and nested component [#8351](https://github.com/openshift/console/pull/8351) * [Bug 1936803](https://bugzilla.redhat.com/show_bug.cgi?id=1936803): support service binding operator version 0.5.0 [#8335](https://github.com/openshift/console/pull/8335) * [Bug 1937469](https://bugzilla.redhat.com/show_bug.cgi?id=1937469): Pod/node/ip/template isn't showing when vm is running [#8357](https://github.com/openshift/console/pull/8357) * [Bug 1932277](https://bugzilla.redhat.com/show_bug.cgi?id=1932277): Create new pool with arbiter - wrong replica (4.7 release) [#8234](https://github.com/openshift/console/pull/8234) * [Bug 1930152](https://bugzilla.redhat.com/show_bug.cgi?id=1930152): Do not fail new VM wizard when no storage classes are available [#8190](https://github.com/openshift/console/pull/8190) * [Bug 1937086](https://bugzilla.redhat.com/show_bug.cgi?id=1937086): Fix topology crash due to selfLink deprecation [#8317](https://github.com/openshift/console/pull/8317) * [Full changelog](https://github.com/openshift/console/compare/794bd63089bd2175c8ac8015bedb588880fbf3ec...b571ac9bad467db8459f25de9c5a4f3b54789312) ### [console-operator](https://github.com/openshift/console-operator/tree/44a0308f894abae02f066a40ba394c8aa7331424) * [Bug 1960589](https://bugzilla.redhat.com/show_bug.cgi?id=1960589): [release-4.7] quickstarts: remove "spec.version" [#547](https://github.com/openshift/console-operator/pull/547) * [Bug 1936337](https://bugzilla.redhat.com/show_bug.cgi?id=1936337): Check for error when generating default and user-defined config for the console-config configmap [#512](https://github.com/openshift/console-operator/pull/512) * [Full changelog](https://github.com/openshift/console-operator/compare/c1efdfc6294cd32c071142da770b9410a97aff3c...44a0308f894abae02f066a40ba394c8aa7331424) ### [csi-driver-manila, openstack-cinder-csi-driver](https://github.com/openshift/cloud-provider-openstack/tree/d3f709218512df9f46e11c1d13347fc68774d72c) * [Bug 1969345](https://bugzilla.redhat.com/show_bug.cgi?id=1969345): Backport ignore proxy connecting to CSI sockets [#54](https://github.com/openshift/cloud-provider-openstack/pull/54) * [Bug 1933659](https://bugzilla.redhat.com/show_bug.cgi?id=1933659): Add udev to the driver image [#47](https://github.com/openshift/cloud-provider-openstack/pull/47) * [Full changelog](https://github.com/openshift/cloud-provider-openstack/compare/7def9722bc0c3c34336ceee8331eee27ec3f4c7f...d3f709218512df9f46e11c1d13347fc68774d72c) ### [docker-builder](https://github.com/openshift/builder/tree/82eeeac0c8cbad90f951885cc11939ecd51eda76) * Updating openshift-enterprise-builder builder & base images to be consistent with ART [#188](https://github.com/openshift/builder/pull/188) * [Bug 1943726](https://bugzilla.redhat.com/show_bug.cgi?id=1943726): add bracket logging on openshift/builder calls into buildah to assist test-platform team triage [#237](https://github.com/openshift/builder/pull/237) * [Bug 1945692](https://bugzilla.redhat.com/show_bug.cgi?id=1945692): move entitlement related secrets back to mounts.conf [#240](https://github.com/openshift/builder/pull/240) * [Bug 1924554](https://bugzilla.redhat.com/show_bug.cgi?id=1924554): bump(cni) 0.8.1 [#234](https://github.com/openshift/builder/pull/234) * [Bug 1940052](https://bugzilla.redhat.com/show_bug.cgi?id=1940052): retry image pulls during builds [#226](https://github.com/openshift/builder/pull/226) * [Bug 1939218](https://bugzilla.redhat.com/show_bug.cgi?id=1939218): bump(containers/*): [#224](https://github.com/openshift/builder/pull/224) * [Full changelog](https://github.com/openshift/builder/compare/67e88c5fafb9c49f228f48810e34af07db9581f0...82eeeac0c8cbad90f951885cc11939ecd51eda76) ### [docker-registry](https://github.com/openshift/image-registry/tree/ef29671b437cfa7ac82a17001ce57fe527539d53) * [Bug 1977159](https://bugzilla.redhat.com/show_bug.cgi?id=1977159): bump aws-sdk-go to v1.38.35 [#282](https://github.com/openshift/image-registry/pull/282) * [Full changelog](https://github.com/openshift/image-registry/compare/8e0c068aef607fceffe3e179c3a9701f51c51dff...ef29671b437cfa7ac82a17001ce57fe527539d53) ### [etcd](https://github.com/openshift/etcd/tree/c61e5afde9485fac9233c0db6ab950bfb511e1b5) * [Bug 1970141](https://bugzilla.redhat.com/show_bug.cgi?id=1970141): discover-etcd-initial-cluster: retry if member is not part of member list and dataDir exists [#82](https://github.com/openshift/etcd/pull/82) * [ETCD-178](https://issues.redhat.com/browse/ETCD-178): Bug 1944386: openshift-tools: fix on off flow and add unit tests [#74](https://github.com/openshift/etcd/pull/74) * [Full changelog](https://github.com/openshift/etcd/compare/cca97c76b915b1d14abd39814995fa1e2d087145...c61e5afde9485fac9233c0db6ab950bfb511e1b5) ### [gcp-machine-controllers](https://github.com/openshift/cluster-api-provider-gcp/tree/5f6589d4ef9496e63ebc072f4d863151bbeb4407) * [Bug 1924508](https://bugzilla.redhat.com/show_bug.cgi?id=1924508): Bump dependencies to Kubernetes 1.20.6 to mitigate CVE-2021-3121 [#164](https://github.com/openshift/cluster-api-provider-gcp/pull/164) * [Bug 1935636](https://bugzilla.redhat.com/show_bug.cgi?id=1935636): Ensure response body is closed when we are finished with the request [#151](https://github.com/openshift/cluster-api-provider-gcp/pull/151) * [Full changelog](https://github.com/openshift/cluster-api-provider-gcp/compare/186b21520ddb0f1e29d3a709715369135fcaebcd...5f6589d4ef9496e63ebc072f4d863151bbeb4407) ### [gcp-pd-csi-driver-operator](https://github.com/openshift/gcp-pd-csi-driver-operator/tree/9ffe95b9499258b8e2b5e1b8df9889abe3c9f73f) * [Bug 1940005](https://bugzilla.redhat.com/show_bug.cgi?id=1940005): Add CSIDriver object [#18](https://github.com/openshift/gcp-pd-csi-driver-operator/pull/18) * [Full changelog](https://github.com/openshift/gcp-pd-csi-driver-operator/compare/3583e00c7ff4f31957c0e9223d8c1dea3f4c23c3...9ffe95b9499258b8e2b5e1b8df9889abe3c9f73f) ### [grafana](https://github.com/openshift/grafana/tree/b02c35dc2d01fce696a3edc28839a9f9fd0150a3) * Updating grafana builder & base images to be consistent with ART [#54](https://github.com/openshift/grafana/pull/54) * [Full changelog](https://github.com/openshift/grafana/compare/cf0a81cb4b68a2543249def193e1b83e94734725...b02c35dc2d01fce696a3edc28839a9f9fd0150a3) ### [haproxy-router](https://github.com/openshift/router/tree/9cc0c8fcebf613785511468c7df601117b13e5aa) * [Bug 1967733](https://bugzilla.redhat.com/show_bug.cgi?id=1967733): template helper - generateHAProxyWhiteListFile, use right arg type [#297](https://github.com/openshift/router/pull/297) * [Bug 1965402](https://bugzilla.redhat.com/show_bug.cgi?id=1965402): Revert 'Bug 1896977: Enhance host name validation in router' [#293](https://github.com/openshift/router/pull/293) * [Bug 1963243](https://bugzilla.redhat.com/show_bug.cgi?id=1963243): Add a condition to check if the Endpoints ID is duplicated [#288](https://github.com/openshift/router/pull/288) * [Bug 1942534](https://bugzilla.redhat.com/show_bug.cgi?id=1942534): [4.7 backport] Route gets admitted with invalid host name if override annotation is used [#273](https://github.com/openshift/router/pull/273) * [Bug 1938921](https://bugzilla.redhat.com/show_bug.cgi?id=1938921): router/template: Cache compiled regular expressions [#269](https://github.com/openshift/router/pull/269) * [Full changelog](https://github.com/openshift/router/compare/30e2fb5b65753e6b6593f61b16768a5229b5bd97...9cc0c8fcebf613785511468c7df601117b13e5aa) ### [hello-openshift, tests](https://github.com/openshift/origin/tree/f59ac6a11e0dbe8590181dd823ef8e5b87e784a9) * Re-enable quota test [#26284](https://github.com/openshift/origin/pull/26284) * [Bug 1980540](https://bugzilla.redhat.com/show_bug.cgi?id=1980540): Use cluster-logging for operator installation smoke test. [#26315](https://github.com/openshift/origin/pull/26315) * [Bug 1977383](https://bugzilla.redhat.com/show_bug.cgi?id=1977383): [release-4.7] Update resource quota test for compatibility with service ca configmap publishing [#26303](https://github.com/openshift/origin/pull/26303) * [Bug 1928862](https://bugzilla.redhat.com/show_bug.cgi?id=1928862): [4.7] Bump openshift/kubernetes [#26259](https://github.com/openshift/origin/pull/26259) * [Bug 1978000](https://bugzilla.redhat.com/show_bug.cgi?id=1978000): builds: comment out multi-namespace template test [#26296](https://github.com/openshift/origin/pull/26296) * NOOP - Trigger a new CI build [#26291](https://github.com/openshift/origin/pull/26291) * [Bug 1977383](https://bugzilla.redhat.com/show_bug.cgi?id=1977383): [release-4.7] Skip cluster quota test to enable service ca publisher to merge to o/k [#26283](https://github.com/openshift/origin/pull/26283) * [Bug 1970411](https://bugzilla.redhat.com/show_bug.cgi?id=1970411): properly remove project after test ends [#26217](https://github.com/openshift/origin/pull/26217) * [Bug 1966358](https://bugzilla.redhat.com/show_bug.cgi?id=1966358): Dockerfile.rhel: fix a bash typo [#26194](https://github.com/openshift/origin/pull/26194) * [Bug 1961367](https://bugzilla.redhat.com/show_bug.cgi?id=1961367): Add Cinder client to the test image [#26171](https://github.com/openshift/origin/pull/26171) * [Bug 1955600](https://bugzilla.redhat.com/show_bug.cgi?id=1955600): test/extended/router: Fix-up Unidling test [#26120](https://github.com/openshift/origin/pull/26120) * [Bug 1963115](https://bugzilla.redhat.com/show_bug.cgi?id=1963115): narrow verify /run test to /run/secrets [#26180](https://github.com/openshift/origin/pull/26180) * [Bug 1963115](https://bugzilla.redhat.com/show_bug.cgi?id=1963115): move verify run test from tools to cli image to avoid additional /run content [#26176](https://github.com/openshift/origin/pull/26176) * [Bug 1958797](https://bugzilla.redhat.com/show_bug.cgi?id=1958797): test/extended/router/idle: Only run on OVNKubernetes or OpenShiftSDN [#26145](https://github.com/openshift/origin/pull/26145) * [Bug 1947705](https://bugzilla.redhat.com/show_bug.cgi?id=1947705): Add test of documented backup/restore procedure [#26110](https://github.com/openshift/origin/pull/26110) * [Bug 1955669](https://bugzilla.redhat.com/show_bug.cgi?id=1955669): flake testKubeletToAPIServerGracefulTermination [#26121](https://github.com/openshift/origin/pull/26121) * [Bug 1942055](https://bugzilla.redhat.com/show_bug.cgi?id=1942055): upgrade/upgrade.go: Enhance upgrade ack time out error [#26012](https://github.com/openshift/origin/pull/26012) * [Bug 1941574](https://bugzilla.redhat.com/show_bug.cgi?id=1941574): test/extended/router/idle: skip test on virt platforms [#25999](https://github.com/openshift/origin/pull/25999) * [Bug 1940866](https://bugzilla.redhat.com/show_bug.cgi?id=1940866): Add BareMetalPlatformType into e2e upgrade service unsupported list [#25989](https://github.com/openshift/origin/pull/25989) * [Bug 1927953](https://bugzilla.redhat.com/show_bug.cgi?id=1927953): test/extended/router/idle: address flakes/failures seen in CI [#25892](https://github.com/openshift/origin/pull/25892) * [Bug 1931622](https://bugzilla.redhat.com/show_bug.cgi?id=1931622): test: add vsphere to unsupported platforms for LB service [#25913](https://github.com/openshift/origin/pull/25913) * [Bug 1932806](https://bugzilla.redhat.com/show_bug.cgi?id=1932806): release-4.7: e2e: test OAuth API connections in the tests by that name [#25894](https://github.com/openshift/origin/pull/25894) * [Bug 1935707](https://bugzilla.redhat.com/show_bug.cgi?id=1935707): [release-4.7] test: Detect when the master pool is still updating after upgrade [#25941](https://github.com/openshift/origin/pull/25941) * [Bug 1931401](https://bugzilla.redhat.com/show_bug.cgi?id=1931401): fix sig-cli flakes [#25910](https://github.com/openshift/origin/pull/25910) * [Bug 1939477](https://bugzilla.redhat.com/show_bug.cgi?id=1939477): Update tests to use Ruby 2.7 [#25966](https://github.com/openshift/origin/pull/25966) * [Bug 1927554](https://bugzilla.redhat.com/show_bug.cgi?id=1927554): adjust route host for redis/nodejs/cakephp to accomodate new apiserver restrictions [#25884](https://github.com/openshift/origin/pull/25884) * [Full changelog](https://github.com/openshift/origin/compare/98a759fa802ab87153d0c75b18bc977a91154f69...f59ac6a11e0dbe8590181dd823ef8e5b87e784a9) ### [hyperkube](https://github.com/openshift/kubernetes/tree/558d959332b3f1f7bf786673bf294e6e0932bb18) * [Bug 1981634](https://bugzilla.redhat.com/show_bug.cgi?id=1981634): UPSTREAM: <drop>: use the legacy service-ca.crt content for clusters started in 4.7 or before [#857](https://github.com/openshift/kubernetes/pull/857) * [Bug 1977383](https://bugzilla.redhat.com/show_bug.cgi?id=1977383): [release-4.7] Ensure service ca configmap is created in all namespaces [#834](https://github.com/openshift/kubernetes/pull/834) * [Bug 1977383](https://bugzilla.redhat.com/show_bug.cgi?id=1977383): [release-4.7] Fix watch conformance test [#843](https://github.com/openshift/kubernetes/pull/843) * [Bug 1977383](https://bugzilla.redhat.com/show_bug.cgi?id=1977383): Update resource quota test for compatibility with service ca configmap publishing [#839](https://github.com/openshift/kubernetes/pull/839) * [Bug 1975553](https://bugzilla.redhat.com/show_bug.cgi?id=1975553): only chown if non-windows machine with projected volumes [#826](https://github.com/openshift/kubernetes/pull/826) * [Bug 1928862](https://bugzilla.redhat.com/show_bug.cgi?id=1928862): [release-4.7] UPSTREAM: <carry>: kube-apiserver: ignore SIGTERM/INT after the first one [#739](https://github.com/openshift/kubernetes/pull/739) * [Bug 1966810](https://bugzilla.redhat.com/show_bug.cgi?id=1966810): UPSTREAM: 102224: Fix expired unit test certs [#780](https://github.com/openshift/kubernetes/pull/780) * [Bug 1963263](https://bugzilla.redhat.com/show_bug.cgi?id=1963263): UPSTREAM: 102000: Ref counting is only applicable to Remote endpoints [#763](https://github.com/openshift/kubernetes/pull/763) * [Bug 1955883](https://bugzilla.redhat.com/show_bug.cgi?id=1955883): UPSTREAM: 99095: Prevent Kubelet stuck in DiskPressure when imagefs minreclaim is set [#725](https://github.com/openshift/kubernetes/pull/725) * [Bug 1951726](https://bugzilla.redhat.com/show_bug.cgi?id=1951726): Speed up PV provisioning for vsphere driver (ocp-4.7) [#690](https://github.com/openshift/kubernetes/pull/690) * [Bug 1942141](https://bugzilla.redhat.com/show_bug.cgi?id=1942141): fixes cinder PV labelling [#635](https://github.com/openshift/kubernetes/pull/635) * [Bug 1951815](https://bugzilla.redhat.com/show_bug.cgi?id=1951815): UPSTREAM: 99393: kubelet: reduce configmap and secret watch [#692](https://github.com/openshift/kubernetes/pull/692) * [Bug 1955231](https://bugzilla.redhat.com/show_bug.cgi?id=1955231): UPSTREAM: 101345: kubelet: improve the node informer sync check [#721](https://github.com/openshift/kubernetes/pull/721) * [Bug 1952917](https://bugzilla.redhat.com/show_bug.cgi?id=1952917): UPSTREAM: 100228: For LoadBalancer Service type don't create a HNS policy for empty or invalid external loadbalancer IP [#697](https://github.com/openshift/kubernetes/pull/697) * [Bug 1928862](https://bugzilla.redhat.com/show_bug.cgi?id=1928862): Enable snapshot tests [#569](https://github.com/openshift/kubernetes/pull/569) * [Bug 1945856](https://bugzilla.redhat.com/show_bug.cgi?id=1945856): 99729:Only system-node-critical pods should be OOM Killed last [#642](https://github.com/openshift/kubernetes/pull/642) * [Bug 1927717](https://bugzilla.redhat.com/show_bug.cgi?id=1927717): UPSTREAM: 98939: fixes race in TestSyncPodsDeletesWhenSourcesAreReady [#567](https://github.com/openshift/kubernetes/pull/567) * [Bug 1931702](https://bugzilla.redhat.com/show_bug.cgi?id=1931702): UPSTREAM: 96958: kubelet: remove periodic messages from log-level 2 [#589](https://github.com/openshift/kubernetes/pull/589) * [Bug 1931745](https://bugzilla.redhat.com/show_bug.cgi?id=1931745): UPSTREAM: 98956: Fix race when KillPod followed by IsPodPendingTermining [#590](https://github.com/openshift/kubernetes/pull/590) * [Bug 1929674](https://bugzilla.redhat.com/show_bug.cgi?id=1929674): kubelet: fix create sandbox delete pod race [#591](https://github.com/openshift/kubernetes/pull/591) * [Bug 1933094](https://bugzilla.redhat.com/show_bug.cgi?id=1933094): UPSTREAM: 98742: Sync completed pods until their containers have been terminated [#595](https://github.com/openshift/kubernetes/pull/595) * [Full changelog](https://github.com/openshift/kubernetes/compare/5fbfd197c16d3c5facbaa1d7b9f3ea58cf6b36e9...558d959332b3f1f7bf786673bf294e6e0932bb18) ### [insights-operator](https://github.com/openshift/insights-operator/tree/e7955cf0b199caa53726431df5d8800be5af049a) * [release 4.7] Bug 1960645: Adds virt_platform metric to the collected metrics (#428) [#428](https://github.com/openshift/insights-operator/pull/428) * [release 4.7] Bug 1953579: GatherClusterOperators and GatherClusterOperatorsPodAndEvents (#410) [#410](https://github.com/openshift/insights-operator/pull/410) * Add vsphere_node_hw_version_total metric (#416) [#416](https://github.com/openshift/insights-operator/pull/416) * [Bug 1950926](https://bugzilla.redhat.com/show_bug.cgi?id=1950926): Extend OLM data with CSV display name (#400) (#402) [#400](https://github.com/openshift/insights-operator/pull/400) * [Bug 1942068](https://bugzilla.redhat.com/show_bug.cgi?id=1942068): Gahter datahubs.installers.datahub.sap.com resources from SAP clusters (#383) [#383](https://github.com/openshift/insights-operator/pull/383) * [Bug 1939061](https://bugzilla.redhat.com/show_bug.cgi?id=1939061): Sap license management logs gatherer 4.7 (#372) [#372](https://github.com/openshift/insights-operator/pull/372) * Adds memory usage to the metadata (#364) [#364](https://github.com/openshift/insights-operator/pull/364) * [Bug 1935070](https://bugzilla.redhat.com/show_bug.cgi?id=1935070): Extend the OLM operator data with related … (#362) [#362](https://github.com/openshift/insights-operator/pull/362) * [Bug 1934442](https://bugzilla.redhat.com/show_bug.cgi?id=1934442): Gather info about unhealthy SAP pods (#360) [#360](https://github.com/openshift/insights-operator/pull/360) * [Bug 1936802](https://bugzilla.redhat.com/show_bug.cgi?id=1936802): Authentication log gatherer - do not scan all the pods in openshfit-authentication (#369) [#369](https://github.com/openshift/insights-operator/pull/369) * [Bug 1936861](https://bugzilla.redhat.com/show_bug.cgi?id=1936861): Include namespace name in binarydata configmap path & test (#368) (#370) [#368](https://github.com/openshift/insights-operator/pull/368) * [Full changelog](https://github.com/openshift/insights-operator/compare/4d0bc3a840b801b18270ff614678bacad65d93b8...e7955cf0b199caa53726431df5d8800be5af049a) ### [ironic](https://github.com/openshift/ironic-image/tree/1a7f41bb1c2c04ccd06958669a24a08a0bf22258) * [Bug 1958965](https://bugzilla.redhat.com/show_bug.cgi?id=1958965): Updated ironic packages [#166](https://github.com/openshift/ironic-image/pull/166) * [Bug 1937695](https://bugzilla.redhat.com/show_bug.cgi?id=1937695): Supply a default for COPY args [#155](https://github.com/openshift/ironic-image/pull/155) * [Full changelog](https://github.com/openshift/ironic-image/compare/2a57b0b842aa9439dbe73064fcf8f5874ede6a8c...1a7f41bb1c2c04ccd06958669a24a08a0bf22258) ### [ironic-ipa-downloader](https://github.com/openshift/ironic-ipa-downloader/tree/df6bb639fd9bf26ce276ae78e78548fba53783d1) * [Bug 1937809](https://bugzilla.redhat.com/show_bug.cgi?id=1937809): Update ironic-images package [#63](https://github.com/openshift/ironic-ipa-downloader/pull/63) * [Full changelog](https://github.com/openshift/ironic-ipa-downloader/compare/b8956beec4813085b13b49639f55810ef229dfdc...df6bb639fd9bf26ce276ae78e78548fba53783d1) ### [ironic-machine-os-downloader](https://github.com/openshift/ironic-rhcos-downloader/tree/7ef152158f515f17a2678f7ead8a7363644cdf02) * [Bug 1973367](https://bugzilla.redhat.com/show_bug.cgi?id=1973367): Modify dhcp kernel args based on ipv4/ipv6 [#55](https://github.com/openshift/ironic-rhcos-downloader/pull/55) * [Bug 1971549](https://bugzilla.redhat.com/show_bug.cgi?id=1971549): Unconditionally remove TMPDIR [#45](https://github.com/openshift/ironic-rhcos-downloader/pull/45) * [Full changelog](https://github.com/openshift/ironic-rhcos-downloader/compare/4cdc8c311630d0d9807accb12e63bbfa8bbc3ad4...7ef152158f515f17a2678f7ead8a7363644cdf02) ### [jenkins, jenkins-agent-base, jenkins-agent-maven, jenkins-agent-nodejs](https://github.com/openshift/jenkins/tree/d3eacc24156ef726caae230b9b4620059a76f781) * [release 4.7] Bug 1947810: Update Jenkins to 2.277.3 and disable setup wizard [#1259](https://github.com/openshift/jenkins/pull/1259) * [Bug 1952562](https://bugzilla.redhat.com/show_bug.cgi?id=1952562): bump config-file-provider to 3.7.1 [#1265](https://github.com/openshift/jenkins/pull/1265) * [release 4.7] Bug 1929118: update kubernetes-client-api [#1230](https://github.com/openshift/jenkins/pull/1230) * [Full changelog](https://github.com/openshift/jenkins/compare/41fc44729e398eac8a06c8222cf653c80f125a2c...d3eacc24156ef726caae230b9b4620059a76f781) ### [kube-proxy, sdn](https://github.com/openshift/sdn/tree/798a46be0fa09aeec90b25a4c4cf11bf0b2c5b6f) * [Bug 1962637](https://bugzilla.redhat.com/show_bug.cgi?id=1962637): ValidateMTU: check only the interface that holds the node ip [#304](https://github.com/openshift/sdn/pull/304) * [Bug 1923231](https://bugzilla.redhat.com/show_bug.cgi?id=1923231): rebase to sdn-4.7-kubernetes-1.20.0-rc.0 [#286](https://github.com/openshift/sdn/pull/286) * [Bug 1941993](https://bugzilla.redhat.com/show_bug.cgi?id=1941993): Fix incorrect unmonitoring of egress nodes [#279](https://github.com/openshift/sdn/pull/279) * [Bug 1924830](https://bugzilla.redhat.com/show_bug.cgi?id=1924830): CVE-2021-3121 gogo/protobuf lacks certain index validation [#265](https://github.com/openshift/sdn/pull/265) * [Bug 1936920](https://bugzilla.redhat.com/show_bug.cgi?id=1936920): networkpolicy: pass traffic through NAT to handle possible tuple collisions [#272](https://github.com/openshift/sdn/pull/272) * [Full changelog](https://github.com/openshift/sdn/compare/3acf8c465a21c23acb62c50de1aee40f717bf528...798a46be0fa09aeec90b25a4c4cf11bf0b2c5b6f) ### [kuryr-cni, kuryr-controller](https://github.com/openshift/kuryr-kubernetes/tree/c7654fb7ee98d42b3c2329f4ad0039f8f87828f0) * [Bug 1972631](https://bugzilla.redhat.com/show_bug.cgi?id=1972631): Workaround OVN bug causing subports to be DOWN [#525](https://github.com/openshift/kuryr-kubernetes/pull/525) * [Bug 1970320](https://bugzilla.redhat.com/show_bug.cgi?id=1970320): Fix Subnet retrival when creating Service without Selector [#522](https://github.com/openshift/kuryr-kubernetes/pull/522) * [Bug 1949541](https://bugzilla.redhat.com/show_bug.cgi?id=1949541): Fixing bug, Kuryr-Controller crashes when it's missing the status [#501](https://github.com/openshift/kuryr-kubernetes/pull/501) * [Bug 1959766](https://bugzilla.redhat.com/show_bug.cgi?id=1959766): Fix NPs for OVN LBs with hairpin traffic [#516](https://github.com/openshift/kuryr-kubernetes/pull/516) * [Bug 1929066](https://bugzilla.redhat.com/show_bug.cgi?id=1929066): Skip pool pre population if no Status is present on CRD [#505](https://github.com/openshift/kuryr-kubernetes/pull/505) * [Bug 1941941](https://bugzilla.redhat.com/show_bug.cgi?id=1941941): Include service subnet to be open for namespaceSelector set to all. [#504](https://github.com/openshift/kuryr-kubernetes/pull/504) * [Bug 1929066](https://bugzilla.redhat.com/show_bug.cgi?id=1929066): Fix port pools [#455](https://github.com/openshift/kuryr-kubernetes/pull/455) * [Bug 1949551](https://bugzilla.redhat.com/show_bug.cgi?id=1949551): kuryr-controller restarting after 3 days cluster running - pools without members [#502](https://github.com/openshift/kuryr-kubernetes/pull/502) * [Bug 1938960](https://bugzilla.redhat.com/show_bug.cgi?id=1938960): Ignore headless services in NP code [#487](https://github.com/openshift/kuryr-kubernetes/pull/487) * [Bug 1938960](https://bugzilla.redhat.com/show_bug.cgi?id=1938960): Do not default protocol to TCP for allow-all NPs [#480](https://github.com/openshift/kuryr-kubernetes/pull/480) * [Bug 1930017](https://bugzilla.redhat.com/show_bug.cgi?id=1930017): Narrow connection to the cluster only on namespaceSelector [#460](https://github.com/openshift/kuryr-kubernetes/pull/460) * [Bug 1928029](https://bugzilla.redhat.com/show_bug.cgi?id=1928029): Get trunks more diligently [#449](https://github.com/openshift/kuryr-kubernetes/pull/449) * [Full changelog](https://github.com/openshift/kuryr-kubernetes/compare/a31d885264e7a68ff49b6baa96bb5868dae9e5a3...c7654fb7ee98d42b3c2329f4ad0039f8f87828f0) ### [libvirt-machine-controllers](https://github.com/openshift/cluster-api-provider-libvirt/tree/033be25ca038fe773b23c076e9ac64926de72474) * [Bug 1938316](https://bugzilla.redhat.com/show_bug.cgi?id=1938316): [release-4.7] Update MAO and set metrics on :8081 address [#219](https://github.com/openshift/cluster-api-provider-libvirt/pull/219) * [Full changelog](https://github.com/openshift/cluster-api-provider-libvirt/compare/b57e18b197838f6d6c377cca00fd47f9af645f3f...033be25ca038fe773b23c076e9ac64926de72474) ### [machine-api-operator](https://github.com/openshift/machine-api-operator/tree/e179bb5ce397b543cd3f716f75fa4cd40046e0ad) * [Bug 1924517](https://bugzilla.redhat.com/show_bug.cgi?id=1924517): Bump dependencies to Kubernetes 1.20.6 to mitigate CVE-2021-3121 [#867](https://github.com/openshift/machine-api-operator/pull/867) * [Bug 1955689](https://bugzilla.redhat.com/show_bug.cgi?id=1955689): Webhook filter should check for both mutating and validating webhooks [#861](https://github.com/openshift/machine-api-operator/pull/861) * [Bug 1947372](https://bugzilla.redhat.com/show_bug.cgi?id=1947372): vSphere, detach virtual disks before virtual machine destroy if node not available [#841](https://github.com/openshift/machine-api-operator/pull/841) * [Bug 1954610](https://bugzilla.redhat.com/show_bug.cgi?id=1954610): Update GCP default image to match 4.7 release [#856](https://github.com/openshift/machine-api-operator/pull/856) * [Bug 1929721](https://bugzilla.redhat.com/show_bug.cgi?id=1929721): Add SecurityProfile.EncryptionAtHost parameter to enable host-based VM encryption [#818](https://github.com/openshift/machine-api-operator/pull/818) * [Full changelog](https://github.com/openshift/machine-api-operator/compare/13126c309bc4f2cd535f536c6925e245a44ac649...e179bb5ce397b543cd3f716f75fa4cd40046e0ad) ### [machine-config-operator](https://github.com/openshift/machine-config-operator/tree/8eadb800abc91dd9759edc4be57235eb80ad695d) * [Bug 1976232](https://bugzilla.redhat.com/show_bug.cgi?id=1976232): Explicitly set keyfile as the default plugin of NetworkManager for RHEL7 [#2641](https://github.com/openshift/machine-config-operator/pull/2641) * [Bug 1971864](https://bugzilla.redhat.com/show_bug.cgi?id=1971864): Stop setting nopreempt on bootstrap keepalived.conf [#2616](https://github.com/openshift/machine-config-operator/pull/2616) * [Bug 1973006](https://bugzilla.redhat.com/show_bug.cgi?id=1973006): daemon: cordon the node before performing drain [#2623](https://github.com/openshift/machine-config-operator/pull/2623) * [Bug 1961341](https://bugzilla.redhat.com/show_bug.cgi?id=1961341): rbac: update remaining apis to v1 [#2620](https://github.com/openshift/machine-config-operator/pull/2620) * [Bug 1971374](https://bugzilla.redhat.com/show_bug.cgi?id=1971374): daemon/drain.go: bump initial drain sleeps down to 1min [#2612](https://github.com/openshift/machine-config-operator/pull/2612) * [Bug 1970154](https://bugzilla.redhat.com/show_bug.cgi?id=1970154): operator/sync.go confirm renderedconfig osimageurl matches cvo [#2607](https://github.com/openshift/machine-config-operator/pull/2607) * [Bug 1968759](https://bugzilla.redhat.com/show_bug.cgi?id=1968759): Bump drain timeout to 1h [#2605](https://github.com/openshift/machine-config-operator/pull/2605) * [Bug 1949348](https://bugzilla.redhat.com/show_bug.cgi?id=1949348): gcp-routes should wait until network is stopped [#2593](https://github.com/openshift/machine-config-operator/pull/2593) * [Bug 1962288](https://bugzilla.redhat.com/show_bug.cgi?id=1962288): [ovirt] Stop using db file for static internal records [#2581](https://github.com/openshift/machine-config-operator/pull/2581) * [Bug 1964568](https://bugzilla.redhat.com/show_bug.cgi?id=1964568): Delete duplicated generated mc [#2591](https://github.com/openshift/machine-config-operator/pull/2591) * Updating ose-machine-config-operator builder & base images to be consistent with ART [#2399](https://github.com/openshift/machine-config-operator/pull/2399) * [Bug 1949348](https://bugzilla.redhat.com/show_bug.cgi?id=1949348): not allow healthcheck traffic to loop through the node [#2526](https://github.com/openshift/machine-config-operator/pull/2526) * [Bug 1953475](https://bugzilla.redhat.com/show_bug.cgi?id=1953475): daemon: return nil for unsupported operation on an OS [#2544](https://github.com/openshift/machine-config-operator/pull/2544) * docs/README: Useless bump to get a new commit hash [#2584](https://github.com/openshift/machine-config-operator/pull/2584) * [Bug 1956749](https://bugzilla.redhat.com/show_bug.cgi?id=1956749): vsphere: platform none, vmxnet3v4 fix move to base [#2564](https://github.com/openshift/machine-config-operator/pull/2564) * [Bug 1950261](https://bugzilla.redhat.com/show_bug.cgi?id=1950261): create the ovs-config-executed file to signal ovs is running on the host [#2532](https://github.com/openshift/machine-config-operator/pull/2532) * [Bug 1957015](https://bugzilla.redhat.com/show_bug.cgi?id=1957015): [on-prem] Backport duplicate VIP fixes [#2566](https://github.com/openshift/machine-config-operator/pull/2566) * [Bug 1932383](https://bugzilla.redhat.com/show_bug.cgi?id=1932383): Connect default NIC to cluster network [#2427](https://github.com/openshift/machine-config-operator/pull/2427) * [Bug 1942488](https://bugzilla.redhat.com/show_bug.cgi?id=1942488): Use new --prefer-ipv6 flag to "runtimecfg node-ip" as appropriate [#2525](https://github.com/openshift/machine-config-operator/pull/2525) * [Bug 1950498](https://bugzilla.redhat.com/show_bug.cgi?id=1950498): Add on-prem namespaces to relatedObjects [#2533](https://github.com/openshift/machine-config-operator/pull/2533) * [Bug 1951028](https://bugzilla.redhat.com/show_bug.cgi?id=1951028): configure-ovs doesn't handle bond interfaces correctly for OVNKubernetes [#2536](https://github.com/openshift/machine-config-operator/pull/2536) * [Bug 1944394](https://bugzilla.redhat.com/show_bug.cgi?id=1944394): Do "systemctl daemon-reload" after running "runtimecfg node-ip" [#2497](https://github.com/openshift/machine-config-operator/pull/2497) * Fixes: Bug 1943143: [vsphere] hostnames are changed when upgrading from 4.6 to 4.7.x causing upgrades to fail [#2490](https://github.com/openshift/machine-config-operator/pull/2490) * [Bug 1941246](https://bugzilla.redhat.com/show_bug.cgi?id=1941246): vSphere: Disable tx-udp-tnl offload [#2495](https://github.com/openshift/machine-config-operator/pull/2495) * [Bug 1941128](https://bugzilla.redhat.com/show_bug.cgi?id=1941128): pkg/operator/status: Use 'DegradedPool' reason for Upgradeable=False [#2473](https://github.com/openshift/machine-config-operator/pull/2473) * [Bug 1941367](https://bugzilla.redhat.com/show_bug.cgi?id=1941367): Make getting the suffix of an MC more robust [#2476](https://github.com/openshift/machine-config-operator/pull/2476) * [Bug 1933205](https://bugzilla.redhat.com/show_bug.cgi?id=1933205): Revert "pkg/daemon: Add IgnitionVersion to Daemon" [#2438](https://github.com/openshift/machine-config-operator/pull/2438) * [Bug 1927783](https://bugzilla.redhat.com/show_bug.cgi?id=1927783): [vsphere] set hostname with --static to provide consistent node name for CSR approval [#2405](https://github.com/openshift/machine-config-operator/pull/2405) * [Bug 1931863](https://bugzilla.redhat.com/show_bug.cgi?id=1931863): Apply system-connections-merged to all platforms [#2426](https://github.com/openshift/machine-config-operator/pull/2426) * [Bug 1936008](https://bugzilla.redhat.com/show_bug.cgi?id=1936008): templates: add After=ostree-finalize-staged.service to kubelet.service [#2455](https://github.com/openshift/machine-config-operator/pull/2455) * [Bug 1929257](https://bugzilla.redhat.com/show_bug.cgi?id=1929257): Fix 1:1 mapping for kubeletconfig:MC and some e2e test fixes [#2462](https://github.com/openshift/machine-config-operator/pull/2462) * [Bug 1939278](https://bugzilla.redhat.com/show_bug.cgi?id=1939278): Backport kubelet CA no-drain rotation [#2464](https://github.com/openshift/machine-config-operator/pull/2464) * [Bug 1933368](https://bugzilla.redhat.com/show_bug.cgi?id=1933368): operator/sync.go restore err when required pools not leveled [#2441](https://github.com/openshift/machine-config-operator/pull/2441) * [Bug 1932860](https://bugzilla.redhat.com/show_bug.cgi?id=1932860): Remove recycler pod templates [#2434](https://github.com/openshift/machine-config-operator/pull/2434) * [Bug 1931615](https://bugzilla.redhat.com/show_bug.cgi?id=1931615): OVS Config: fixes detecting bond NM files with static IP [#2452](https://github.com/openshift/machine-config-operator/pull/2452) * [Full changelog](https://github.com/openshift/machine-config-operator/compare/ff9431921ef6c22f602da46c07980622f2809546...8eadb800abc91dd9759edc4be57235eb80ad695d) ### [multus-cni](https://github.com/openshift/multus-cni/tree/5530094db7607fc9292e3b269fcf5a85b0dad3df) * [Bug 1927896](https://bugzilla.redhat.com/show_bug.cgi?id=1927896): make a copy of global RuntimeConfig on merge [#91](https://github.com/openshift/multus-cni/pull/91) * [Bug 1936334](https://bugzilla.redhat.com/show_bug.cgi?id=1936334): Updating multus-cni builder & base images to be consistent with ART [#81](https://github.com/openshift/multus-cni/pull/81) * [Full changelog](https://github.com/openshift/multus-cni/compare/7aa53b3cb5ae0ae4b03906803c7aff37447d4357...5530094db7607fc9292e3b269fcf5a85b0dad3df) ### [multus-whereabouts-ipam-cni](https://github.com/openshift/whereabouts-cni/tree/dfe6b395b67c0cede73e6edf758976ae208b930c) * [Bug 1931950](https://bugzilla.redhat.com/show_bug.cgi?id=1931950): [backport 4.7] Fix for IPv6 when leading hextets equal zero [#49](https://github.com/openshift/whereabouts-cni/pull/49) * [Full changelog](https://github.com/openshift/whereabouts-cni/compare/900aa4231bd31026b3a305f8077c8959f51d8059...dfe6b395b67c0cede73e6edf758976ae208b930c) ### [oauth-apiserver](https://github.com/openshift/oauth-apiserver/tree/69f527e90f599e0f509cfce73ba7b95656f03f7f) * [Bug 1917904](https://bugzilla.redhat.com/show_bug.cgi?id=1917904): bump k8s.io/apiserver to 1.20.4 [#43](https://github.com/openshift/oauth-apiserver/pull/43) * [Full changelog](https://github.com/openshift/oauth-apiserver/compare/d00e67a0b5e0d7c303b201a5bbcb943a9bc26774...69f527e90f599e0f509cfce73ba7b95656f03f7f) ### [oauth-server](https://github.com/openshift/oauth-server/tree/61db550b94b09356eebabcffd39aea8d90eb6089) * [Bug 1965932](https://bugzilla.redhat.com/show_bug.cgi?id=1965932): bump kube to 0.20.4 [#79](https://github.com/openshift/oauth-server/pull/79) * [Full changelog](https://github.com/openshift/oauth-server/compare/3215761a70426326f0be2ca675b0e9b9fdae341e...61db550b94b09356eebabcffd39aea8d90eb6089) ### [openshift-apiserver](https://github.com/openshift/openshift-apiserver/tree/f9ac08715d1b7890a5aa66a8fb16e847a7f6b727) * [Bug 1965402](https://bugzilla.redhat.com/show_bug.cgi?id=1965402): Revert 'Bug 1965402: Enhance API host name validation' [#211](https://github.com/openshift/openshift-apiserver/pull/211) * [Bug 1961557](https://bugzilla.redhat.com/show_bug.cgi?id=1961557): sets shutdown-delay-duration from OpenShiftAPIServerConfig [#199](https://github.com/openshift/openshift-apiserver/pull/199) * [Bug 1917904](https://bugzilla.redhat.com/show_bug.cgi?id=1917904): bump k8s.io/apiserver to 1.20.4 [#187](https://github.com/openshift/openshift-apiserver/pull/187) * [Full changelog](https://github.com/openshift/openshift-apiserver/compare/d7ccc71549d84594bfc7f5deda2ed61de7bde100...f9ac08715d1b7890a5aa66a8fb16e847a7f6b727) ### [openshift-controller-manager](https://github.com/openshift/openshift-controller-manager/tree/39b6393236e5abab331de1ab3384d0d165510457) * [Bug 1955210](https://bugzilla.redhat.com/show_bug.cgi?id=1955210): fixed LANG for the builder container [#180](https://github.com/openshift/openshift-controller-manager/pull/180) * [Full changelog](https://github.com/openshift/openshift-controller-manager/compare/e0755cd0dca5e8a0cdae0a52d7127f75f20b1e9a...39b6393236e5abab331de1ab3384d0d165510457) ### [operator-lifecycle-manager](https://github.com/operator-framework/operator-lifecycle-manager/tree/c6d1c295b5d995f61cfe496359d3e70bdbc244a7) * [Bug 1972075](https://bugzilla.redhat.com/show_bug.cgi?id=1972075): Add OperatorCondition status sync and update operator upgradeable check [#2206](https://github.com/operator-framework/operator-lifecycle-manager/pull/2206) * [Bug 1945702](https://bugzilla.redhat.com/show_bug.cgi?id=1945702): Fix inconsistent dependency candidate order. [#2149](https://github.com/operator-framework/operator-lifecycle-manager/pull/2149) * [Bug 1962314](https://bugzilla.redhat.com/show_bug.cgi?id=1962314): Explicitly set `readOnlyRootFilesystem: false` on created registry pods. [#2171](https://github.com/operator-framework/operator-lifecycle-manager/pull/2171) * [Bug 1963141](https://bugzilla.redhat.com/show_bug.cgi?id=1963141): Make ClusterOperator Available condition sticky. [#2173](https://github.com/operator-framework/operator-lifecycle-manager/pull/2173) * [Bug 1962312](https://bugzilla.redhat.com/show_bug.cgi?id=1962312): Simplify deployment status check to reduce flapping. [#2170](https://github.com/operator-framework/operator-lifecycle-manager/pull/2170) * [Bug 1962302](https://bugzilla.redhat.com/show_bug.cgi?id=1962302): Set reason/message for Available condition in packageserver co [#2168](https://github.com/operator-framework/operator-lifecycle-manager/pull/2168) * [Bug 1959009](https://bugzilla.redhat.com/show_bug.cgi?id=1959009): Use DeploymentAvailable instead of custom test for CSV status. [#2151](https://github.com/operator-framework/operator-lifecycle-manager/pull/2151) * [Bug 1924467](https://bugzilla.redhat.com/show_bug.cgi?id=1924467): Bumps k8s.io dependencies to v0.20.6 [#2121](https://github.com/operator-framework/operator-lifecycle-manager/pull/2121) * [Bug 1949139](https://bugzilla.redhat.com/show_bug.cgi?id=1949139): Preserve existing ServiceAccount owner references during installs. [#2088](https://github.com/operator-framework/operator-lifecycle-manager/pull/2088) * [Bug 1951657](https://bugzilla.redhat.com/show_bug.cgi?id=1951657): fix(catalog): Reduce namespace resync in resolution failure [#2107](https://github.com/operator-framework/operator-lifecycle-manager/pull/2107) * [Bug 1952851](https://bugzilla.redhat.com/show_bug.cgi?id=1952851): Add resource requests for bundle unpacker [#2109](https://github.com/operator-framework/operator-lifecycle-manager/pull/2109) * [Bug 1951232](https://bugzilla.redhat.com/show_bug.cgi?id=1951232): Fix resolution error if inner entry doesn't provide a required API. [#2106](https://github.com/operator-framework/operator-lifecycle-manager/pull/2106) * [Bug 1947909](https://bugzilla.redhat.com/show_bug.cgi?id=1947909): Do not adopt copied CSVs [#2089](https://github.com/operator-framework/operator-lifecycle-manager/pull/2089) * [Bug 1937375](https://bugzilla.redhat.com/show_bug.cgi?id=1937375): only override deployment resources when explicitly defined in subscription config [#2036](https://github.com/operator-framework/operator-lifecycle-manager/pull/2036) * [Bug 1933839](https://bugzilla.redhat.com/show_bug.cgi?id=1933839): bump k8s.io/apiserver for webhook authorizer panic fix [#2022](https://github.com/operator-framework/operator-lifecycle-manager/pull/2022) * [Bug 1936707](https://bugzilla.redhat.com/show_bug.cgi?id=1936707): Allow non-CSV-owned ServiceAccounts to satisfy CSV requirements. [#2034](https://github.com/operator-framework/operator-lifecycle-manager/pull/2034) * [Bug 1938405](https://bugzilla.redhat.com/show_bug.cgi?id=1938405): Support jittering relatively small resync intervals. [#2041](https://github.com/operator-framework/operator-lifecycle-manager/pull/2041) * Updating operator-lifecycle-manager builder & base images to be consistent with ART [#2013](https://github.com/operator-framework/operator-lifecycle-manager/pull/2013) * [Bug 1934724](https://bugzilla.redhat.com/show_bug.cgi?id=1934724): fix(resolver): Allow skipped versions to be installed initially [#2027](https://github.com/operator-framework/operator-lifecycle-manager/pull/2027) * [Bug 1929904](https://bugzilla.redhat.com/show_bug.cgi?id=1929904): Infer package name property for unannotated CSVs, if possible. [#2033](https://github.com/operator-framework/operator-lifecycle-manager/pull/2033) * [Full changelog](https://github.com/operator-framework/operator-lifecycle-manager/compare/45ee0b4e47b9cac58c14892f998307a73ab46879...c6d1c295b5d995f61cfe496359d3e70bdbc244a7) ### [operator-marketplace](https://github.com/operator-framework/operator-marketplace/tree/96bab9b9f5bb2c8fce141992230cf75e48f14f78) * Updating marketplace-operator builder & base images to be consistent with ART [#367](https://github.com/operator-framework/operator-marketplace/pull/367) * [Full changelog](https://github.com/operator-framework/operator-marketplace/compare/eb79c0de7b3e8296aaf179a083346d5ee9157b36...96bab9b9f5bb2c8fce141992230cf75e48f14f78) ### [operator-registry](https://github.com/operator-framework/operator-registry/tree/06e950de5ebca66e493f6cd2414e73c8978090d3) * [Bug 1968680](https://bugzilla.redhat.com/show_bug.cgi?id=1968680): fix(containerd): drop xattrs during unpack [#676](https://github.com/operator-framework/operator-registry/pull/676) * [Bug 1924468](https://bugzilla.redhat.com/show_bug.cgi?id=1924468): Bump the k8s dependencies to v1.20.6 [#638](https://github.com/operator-framework/operator-registry/pull/638) * [Bug 1937097](https://bugzilla.redhat.com/show_bug.cgi?id=1937097): Add retries to opm index add [#643](https://github.com/operator-framework/operator-registry/pull/643) * [Full changelog](https://github.com/operator-framework/operator-registry/compare/a97d366a92d302ff2056fa2d19aa3e48b0fbc99c...06e950de5ebca66e493f6cd2414e73c8978090d3) ### [ovirt-machine-controllers](https://github.com/openshift/cluster-api-provider-ovirt/tree/01b9bf8368a3da974bf1c9114c618a548d346acd) * [Bug 1939358](https://bugzilla.redhat.com/show_bug.cgi?id=1939358): extract node machine ipaddress from the engine instead using DNS . [#98](https://github.com/openshift/cluster-api-provider-ovirt/pull/98) * [Bug 1939360](https://bugzilla.redhat.com/show_bug.cgi?id=1939360): providerIDController ignore nodes that have no machine [#99](https://github.com/openshift/cluster-api-provider-ovirt/pull/99) * [Bug 1939199](https://bugzilla.redhat.com/show_bug.cgi?id=1939199): move to go 1.15 and registry.ci.openshift.org [#97](https://github.com/openshift/cluster-api-provider-ovirt/pull/97) * [Bug 1927256](https://bugzilla.redhat.com/show_bug.cgi?id=1927256): Bump K8s dependencies to 1.20 [#92](https://github.com/openshift/cluster-api-provider-ovirt/pull/92) * [Full changelog](https://github.com/openshift/cluster-api-provider-ovirt/compare/4708c8bbbf01634892f4699dedb3d7a34392903b...01b9bf8368a3da974bf1c9114c618a548d346acd) ### [ovn-kubernetes](https://github.com/openshift/ovn-kubernetes/tree/5354db111f53d4414fb9f86e90cb410fcb14ebd1) * [Bug 1972484](https://bugzilla.redhat.com/show_bug.cgi?id=1972484): egress firewall as ACLs + service connectivity fixes [#592](https://github.com/openshift/ovn-kubernetes/pull/592) * [Bug 1940566](https://bugzilla.redhat.com/show_bug.cgi?id=1940566): Properly log when hybrid overlay errors out [#543](https://github.com/openshift/ovn-kubernetes/pull/543) * [Bug 1970779](https://bugzilla.redhat.com/show_bug.cgi?id=1970779): Remove getDefaultIfAddr and use getNetworkInterfaceIPAddresses [#571](https://github.com/openshift/ovn-kubernetes/pull/571) * [Bug 1962590](https://bugzilla.redhat.com/show_bug.cgi?id=1962590): NewAddressSet: return nil in case of error [#546](https://github.com/openshift/ovn-kubernetes/pull/546) * [Bug 1970322](https://bugzilla.redhat.com/show_bug.cgi?id=1970322): revert 487 [#570](https://github.com/openshift/ovn-kubernetes/pull/570) * [Bug 1962819](https://bugzilla.redhat.com/show_bug.cgi?id=1962819): CNI cmdCheck: treat ingress_policing_rate=0 as not found [#548](https://github.com/openshift/ovn-kubernetes/pull/548) * [Bug 1965075](https://bugzilla.redhat.com/show_bug.cgi?id=1965075): CARRY: fix missed learn for hybrid exgw [#556](https://github.com/openshift/ovn-kubernetes/pull/556) * [Bug 1946682](https://bugzilla.redhat.com/show_bug.cgi?id=1946682): egress firewall as ACLs [#487](https://github.com/openshift/ovn-kubernetes/pull/487) * [Bug 1942603](https://bugzilla.redhat.com/show_bug.cgi?id=1942603): [release-4.7] Allow from router network policy support [#526](https://github.com/openshift/ovn-kubernetes/pull/526) * [Bug 1956980](https://bugzilla.redhat.com/show_bug.cgi?id=1956980): [release-4.7] fix ForEachAddressSet() as it is not calling the callback functions [#523](https://github.com/openshift/ovn-kubernetes/pull/523) * [Bug 1959737](https://bugzilla.redhat.com/show_bug.cgi?id=1959737): Fix: egress IP route health check detection state on restart [#538](https://github.com/openshift/ovn-kubernetes/pull/538) * [Bug 1956270](https://bugzilla.redhat.com/show_bug.cgi?id=1956270): service controller should not use the target-port [#519](https://github.com/openshift/ovn-kubernetes/pull/519) * [Bug 1947097](https://bugzilla.redhat.com/show_bug.cgi?id=1947097): [4.7z] Ensure no SNAT on GR for DisableSNATMultipleGws [#533](https://github.com/openshift/ovn-kubernetes/pull/533) * [Bug 1939488](https://bugzilla.redhat.com/show_bug.cgi?id=1939488): Backport Handle Multus network-status annotations on pod update [#467](https://github.com/openshift/ovn-kubernetes/pull/467) * [Bug 1956318](https://bugzilla.redhat.com/show_bug.cgi?id=1956318): Revert "removing the hybrid overlay externalGW code" [#521](https://github.com/openshift/ovn-kubernetes/pull/521) * [Bug 1951064](https://bugzilla.redhat.com/show_bug.cgi?id=1951064): master: cancel leader election on exit [#505](https://github.com/openshift/ovn-kubernetes/pull/505) * [Bug 1950131](https://bugzilla.redhat.com/show_bug.cgi?id=1950131): fix deadlock in EgressFirewall DNS code [#513](https://github.com/openshift/ovn-kubernetes/pull/513) * [Bug 1951552](https://bugzilla.redhat.com/show_bug.cgi?id=1951552): master: Delay deleting Namespace's address set for 20 seconds [#507](https://github.com/openshift/ovn-kubernetes/pull/507) * [Bug 1950432](https://bugzilla.redhat.com/show_bug.cgi?id=1950432): [4.7] pods: bind pod logical switch ports to the node's chassis with requested-chassis [#503](https://github.com/openshift/ovn-kubernetes/pull/503) * [Bug 1924826](https://bugzilla.redhat.com/show_bug.cgi?id=1924826): Backport Update gogo/protobuf to v1.3.2. [#464](https://github.com/openshift/ovn-kubernetes/pull/464) * [Bug 1943316](https://bugzilla.redhat.com/show_bug.cgi?id=1943316): [4.7] master: enable logical datapath groups for OVN >= 20.12 [#478](https://github.com/openshift/ovn-kubernetes/pull/478) * [Bug 1946696](https://bugzilla.redhat.com/show_bug.cgi?id=1946696): iptables: add filter on node local traffic [#489](https://github.com/openshift/ovn-kubernetes/pull/489) * [Bug 1947835](https://bugzilla.redhat.com/show_bug.cgi?id=1947835): Fix service update for policy type assertion [#493](https://github.com/openshift/ovn-kubernetes/pull/493) * [Bug 1942702](https://bugzilla.redhat.com/show_bug.cgi?id=1942702): backport lr-nat-del/add fixes [#484](https://github.com/openshift/ovn-kubernetes/pull/484) * [Bug 1931520](https://bugzilla.redhat.com/show_bug.cgi?id=1931520): Backport Fix ACL syntax for dual-stack [#465](https://github.com/openshift/ovn-kubernetes/pull/465) * [Bug 1943310](https://bugzilla.redhat.com/show_bug.cgi?id=1943310): [4.7] Enable DB memory trimming on compaction [#477](https://github.com/openshift/ovn-kubernetes/pull/477) * [Bug 1932268](https://bugzilla.redhat.com/show_bug.cgi?id=1932268): detect if the cluster has endpoint slices [#442](https://github.com/openshift/ovn-kubernetes/pull/442) * [Bug 1935180](https://bugzilla.redhat.com/show_bug.cgi?id=1935180): Backport Fix mcast querier [#468](https://github.com/openshift/ovn-kubernetes/pull/468) * [Bug 1937829](https://bugzilla.redhat.com/show_bug.cgi?id=1937829): Cherry-pick dual-stack conversion [#460](https://github.com/openshift/ovn-kubernetes/pull/460) * [Bug 1934645](https://bugzilla.redhat.com/show_bug.cgi?id=1934645): Backport enable support for BFD on external gateway routes [#462](https://github.com/openshift/ovn-kubernetes/pull/462) * [Bug 1925475](https://bugzilla.redhat.com/show_bug.cgi?id=1925475): Bump OVN to ovn2.13-20.12.0-24.el8fdp [#451](https://github.com/openshift/ovn-kubernetes/pull/451) * [Bug 1937238](https://bugzilla.redhat.com/show_bug.cgi?id=1937238): Refactor chain setup for NodePort and ExternalIP [#457](https://github.com/openshift/ovn-kubernetes/pull/457) * [Full changelog](https://github.com/openshift/ovn-kubernetes/compare/ef03521f5daede4fe0f8afd9f42035259636006b...5354db111f53d4414fb9f86e90cb410fcb14ebd1) ### [prom-label-proxy](https://github.com/openshift/prom-label-proxy/tree/db87872c6aba7e4e9def29b33beea582557ce940) * Updating prom-label-proxy builder & base images to be consistent with ART [#330](https://github.com/openshift/prom-label-proxy/pull/330) * [Full changelog](https://github.com/openshift/prom-label-proxy/compare/88d4df5541251ea122687610870e725b0099213a...db87872c6aba7e4e9def29b33beea582557ce940) ### [service-ca-operator](https://github.com/openshift/service-ca-operator/tree/f65053f55de7b1793956629c8fa02edb7bb0e5cc) * [Bug 1981634](https://bugzilla.redhat.com/show_bug.cgi?id=1981634): add vulnerable legacy injector to allow for upgrade clusters to use [#170](https://github.com/openshift/service-ca-operator/pull/170) * [Full changelog](https://github.com/openshift/service-ca-operator/compare/e113f2498bb2b54202449ddc3488cb8471997a10...f65053f55de7b1793956629c8fa02edb7bb0e5cc) ### [telemeter](https://github.com/openshift/telemeter/tree/e4dac5123ef6b3ecb16b5151e2e8f8aeb8b1f21a) * Updating telemeter builder & base images to be consistent with ART [#369](https://github.com/openshift/telemeter/pull/369) * [Full changelog](https://github.com/openshift/telemeter/compare/8742aae6505eebe6a12bffba8223a66ee5fc4a88...e4dac5123ef6b3ecb16b5151e2e8f8aeb8b1f21a) ### [thanos](https://github.com/openshift/thanos/tree/823d7cd2ee5de3cdab771cfd4b2557852dff7514) * [Bug 1944575](https://bugzilla.redhat.com/show_bug.cgi?id=1944575): pkg/rules: fix deduplication of equal alerts with different labels [#52](https://github.com/openshift/thanos/pull/52) * [Bug 1957646](https://bugzilla.redhat.com/show_bug.cgi?id=1957646): cmd/thanos: use miekgdns resolver as default [#56](https://github.com/openshift/thanos/pull/56) * [Full changelog](https://github.com/openshift/thanos/compare/0526ff025d325790d57df34cf2d66810a25da578...823d7cd2ee5de3cdab771cfd4b2557852dff7514) ### [vsphere-problem-detector](https://github.com/openshift/vsphere-problem-detector/tree/8f7c1246e6bcb99d8cdf667851b8d61f637f2801) * [Bug 1959546](https://bugzilla.redhat.com/show_bug.cgi?id=1959546): Update to current master [#40](https://github.com/openshift/vsphere-problem-detector/pull/40) * [Bug 1936975](https://bugzilla.redhat.com/show_bug.cgi?id=1936975): Fix deadlock when enqueing functions into the pool [#35](https://github.com/openshift/vsphere-problem-detector/pull/35) * [Full changelog](https://github.com/openshift/vsphere-problem-detector/compare/602c27477b66fd8752b7c39a13b6b948731e60eb...8f7c1246e6bcb99d8cdf667851b8d61f637f2801)