Back to index
Download the installer for your operating system or run
oc adm release extract --tools quay.io/openshift-release-dev/ocp-release:4.13.69-x86_64 Qualifiers (status api ):
Tests:
Blocking jobsupgrade Succeeded periodic-ci-openshift-release-main-stable-4.y-e2e-aws-ovn-upgradeupgrade-minor Succeeded (2 retries) periodic-ci-openshift-release-main-stable-4.y-e2e-aws-ovn-upgrade Informing jobsaws-sdn-serial Succeeded (1 retry) periodic-ci-openshift-release-main-nightly-4.13-e2e-aws-sdn-serialaws-sdn-upgrade-4.13-micro Succeeded periodic-ci-openshift-release-main-nightly-4.13-e2e-aws-sdn-upgradeazure-ovn-upgrade-4.13-micro Succeeded periodic-ci-openshift-release-main-ci-4.13-e2e-azure-ovn-upgradedriver-toolkit Succeeded (1 retry) periodic-ci-openshift-release-main-nightly-4.13-e2e-aws-driver-toolkitfips-scan Succeeded periodic-ci-openshift-release-main-nightly-4.13-fips-payload-scanmetal-ipi-ovn-ipv6 Succeeded (1 retry) periodic-ci-openshift-release-main-nightly-4.13-e2e-metal-ipi-ovn-ipv6metal-ipi-sdn-ipv4 Succeeded periodic-ci-openshift-release-main-nightly-4.13-e2e-metal-ipi-sdn-ipv4 Upgrades from:
Untested upgrades:
4.12.19 ,
4.12.20 ,
4.12.21 ,
4.12.22 ,
4.12.23 ,
4.12.24 ,
4.12.25 ,
4.12.26 ,
4.12.27 ,
4.12.28 ,
4.12.29 ,
4.12.30 ,
4.12.31 ,
4.12.32 ,
4.12.33 ,
4.12.34 ,
4.12.35 ,
4.12.36 ,
4.12.38 ,
4.12.39 ,
4.12.40 ,
4.12.41 ,
4.12.43 ,
4.12.44 ,
4.12.45 ,
4.12.46 ,
4.12.47 ,
4.12.48 ,
4.12.49 ,
4.12.50 ,
4.12.51 ,
4.12.52 ,
4.12.53 ,
4.12.54 ,
4.12.55 ,
4.12.56 ,
4.12.57 ,
4.12.58 ,
4.12.59 ,
4.12.60 ,
4.12.61 ,
4.12.62 ,
4.12.63 ,
4.12.64 ,
4.12.65 ,
4.12.66 ,
4.12.67 ,
4.12.68 ,
4.12.69 ,
4.12.70 ,
4.12.71 ,
4.12.72 ,
4.12.73 ,
4.12.74 ,
4.12.75 ,
4.12.76 ,
4.12.77 ,
4.12.78 ,
4.12.79 ,
4.12.80 ,
4.12.81 ,
4.12.82 ,
4.12.83 ,
4.12.84 ,
4.12.85 ,
4.12.86 ,
4.12.87 ,
4.12.88 ,
4.12.89 ,
4.12.91 ,
4.13.10 ,
4.13.11 ,
4.13.12 ,
4.13.13 ,
4.13.14 ,
4.13.15 ,
4.13.16 ,
4.13.17 ,
4.13.18 ,
4.13.19 ,
4.13.21 ,
4.13.22 ,
4.13.23 ,
4.13.24 ,
4.13.26 ,
4.13.27 ,
4.13.28 ,
4.13.29 ,
4.13.3 ,
4.13.30 ,
4.13.31 ,
4.13.32 ,
4.13.33 ,
4.13.34 ,
4.13.35 ,
4.13.36 ,
4.13.37 ,
4.13.38 ,
4.13.39 ,
4.13.4 ,
4.13.41 ,
4.13.42 ,
4.13.43 ,
4.13.44 ,
4.13.45 ,
4.13.46 ,
4.13.47 ,
4.13.48 ,
4.13.49 ,
4.13.50 ,
4.13.51 ,
4.13.52 ,
4.13.53 ,
4.13.54 ,
4.13.55 ,
4.13.56 ,
4.13.57 ,
4.13.58 ,
4.13.59 ,
4.13.6 ,
4.13.60 ,
4.13.61 ,
4.13.62 ,
4.13.63 ,
4.13.64 ,
4.13.65 ,
4.13.7 ,
4.13.8 ,
4.13.9 Upgrades to:
Created: 2026-07-15 16:56:56 +0000 UTC
Image Digest: sha256:6ff433fc5d4e0a3e7a0496e41af47da5c9349afeaad949e6d3bb49764618e1b9
Components
New images
Removed images
agent-installer-utils
azure-workload-identity-webhook
cluster-olm-operator
monitoring-plugin
olm-catalogd
olm-operator-controller
ovn-kubernetes
ovn-kubernetes-microshift
Rebuilt images without code change
apiserver-network-proxy git f56c606a sha256:b361332ed0b89c5a6157b2c144a8b3e9864fe16dba81a6f80ac17da0cd49fe9a
machine-os-content sha256:9f1c27abb122351de98f3d8baa9df6d25d37005dd8f5bd154d7b63b45e7b7d49
rhel-coreos sha256:142888d77c065de0855da6e9e9d42532e0963011c69ed4c78723bd3b14b123a4
rhel-coreos-extensions sha256:ace3dd1d3f7eb09ca49b1e7c3199969e8dbfb93bf62e747e26d2a486e39f1e34
E2E: workload hints: compare existing profile with changes being made to avoid mcp getting stuck (#1069) #1069
OCPBUGS-33030 : [release-4.13][manual]Reduce number of reboots in offline tests (#1048) #1048
Scheduler plugin: ignore IRQs (#1027) #1027
irqbalance: set banned cpus list to 0 (#1003) #1003
OCPBUGS-24353 : rps: cherry-picks of rps fixes (#865) #865
Disable HTTP/2 for webhook and metrics servers (#846) #846
Remove obsolete protocols and weak ciphers (#843) #843
OCPBUGS-18493 : e2e: deflake IRQ load-balancing (#782) #782
Use RHEL9 as a base (#829) #829
OCPBUGS-17943 : Add rtentsk plugin to pp tuned profile Signed-off-by: Brent Rowsell <browsell@redhat.com> (#796) #796
nto: avoid timeout when there are too many CSV (#818) #818
OCPBUGS-19459 : check for object being nil (#820) #820
Add kubeconfig path for IBM Managed OpenShift (#814) #814
OCPBUGS-14137 : e2e: perfprof: add SNO device recovery test (#653) (#806) #653
OCPBUGS-18868 : [release-4.14] e2e: add expected max latancy to hwlatdetec test & rename constant (#788) (#808) #788
Sync DaemonSet if operand image changes (#786) #786
Revert “Revert “Release leader election on manager exit (#773)” (#797)” (#802) #773
OCPBUGS-19351 : Keep Profile status.bootcmdline around (#803) #803
Revert “Release leader election on manager exit (#773)” (#797) #773
Release leader election on manager exit (#773) #773
Tighten the rules for modifying Tuned Profiles (#766) #766
OCPBUGS-18063 : cgroup: Match the name of the cgroup to what is expected by kubelet (#774) #774
update tsc karg to tsc=reliable (#757) #757
OCPBUGS-17845 : deflake ht aware test (#763) #763
OCPBUGS-17794 : rps: use default rps mask kernel API (#760) #760
Improve render error handling (#755) #755
nto:tuned: remove sched_min_granularity_ns settings (#726) #726
Fix a race in e2e test rollback.go code (#740) #740
E2E: Add memory manager sanity test case (#573) (#695) #573
e2e: latency testing: increase the expected threshold (#709) #709
Do not rollback settings on TuneD exit (#704) #704
Switch to rslave/HostToContainer volume mount propagation (#705) #705
e2e: perf-prof: disable truncating gomega output (#707) #707
OCPBUGS-14895 : Do not fail creating cgroups if they exist already (#684) #684
OCPBUGS-14331 : Fix updating numa core siblings map in GetCpuSiblings function (#669) #669
render: remove uid from render-sync target (#594) (#609) #594
Remove cpu-quota.crio.io: disable annotation (#670) #670
Add PerformanceProfiles to ‘oc adm must-gather’ (#657) #657
OCPBUGS-11709 : pao e2e: skip hugepages and numa tests properly (#643) #643
e2e: Fix RPS test for multi-worker cluster (#648) #648
OCPBUGS-12978 use WatchNamespace() when deleting Profiles (#645) #645
OCPBUGS-11336 : pao e2e: fix update test suit timeouts (#642) #642
Address CVE-2022-41723 (#633) #633
OCPBUGS-13148 : Configure cpu balancing cpu sets for all clusters (#647) #647
Revert PR558 and PR585 partially (#640) #640
workload-hints: disable stalld when rt disabled (#604) #604
e2e: add missing test id (#629) #629
Remove subPaths, they are broken (#624) #624
OCPNODE-1539 : perf profile: add script for preparing cgroups for CPU load balance disabling (#617) #617
Update NTO-generated MC on MachineCount <= 1 (#620) #620
OCPBUGS-11336 : e2e: profile updates tests revised (#618) #618
OCPBUGS-11813 : performance-profile: enable crun for high-performance runtime (#616) #616
A new env var NO_BZ_CHECKS disables Bz and Jira status checks (#614) #614
Revert #567 and cleanup PPC-generated TuneD config (#615) #615
Skip tests depending on Jira or Bz issue status (#599) #599
Recent 4.13 RHCOS incorporated RHEL9 kernel based on 5.14 which (#606) #606
Remove the preStop hook for openshift-tuned (#596) #596
Fix updating nodeSelector test (#598) #598
Full changelog
NO-ISSUE: Updating ose-cluster-update-keys-container image to be consistent with ART for 4.13 #78
OCPBUGS-43886 : keys: Update Red Hat keys to use SHA256 signatures #67
Adding the new CI Signer public key #50
Full changelog
OCPBUGS-79432 : CVE-2026-29063 Bump immutable #16330
ART-18919 : pin fsevents to latest #16481
NO-JIRA: enable multi-architecture yarn builds #16423
CONSOLE-5011 : migrate to yarn berry #16083
NO-JIRA: Bump builder image to v29 #15989
OCPBUGS-74437 : Bump lodash to latest #15972
OCPBUGS-44160 : bump dompurify to latest #15594
OCPBUGS-57100 : Add all files to vendor regardless of gitignore #15136
OCPBUGS-54892 : Show Observe section without PROMETHEUS and MONITORING flags #14960
OCPBUGS-45292 : A value submitted in From view is wrapped with single quotation after switching to Yaml view. #14573
OCPBUGS-44356 : Application creation fail when manually entering input scaling value in local setup #14509
OCPBUGS-45197 : Edit the secret and add the Chinese in the web-console, garbled characters will be displayed #14552
OCPBUGS-44585 : Need to allow blank for Project/namespace when setting SA Subject in ‘Project access tab’ #14497
OCPBUGS-36557 : Increase login flow state paramater length/entropy #14483
OCPBUGS-42951 : The filepath including leading slash makes error during parsing devfile using Gitlab #14383
OCPBUGS-41594 : Redirects to new PipelineRun logs URL from old PipelineRun logs URL #14263
OCPBUGS-35259 : fix vCenter cluster being empty #13952
OCPBUGS-32147 : Bump graphql-go to v1.3.0 #13922
OCPBUGS-33978 : Helm Plugin’s Catalog incorrectly renders a single index entry into multiple tiles #13872
OCPBUGS-34342 : Fix PipelineRun Logs tab navigation #13890
OCPBUGS-24395 : Extra space is in the translation text(Chinese) of ‘Create rolebinding’ and ‘replicate rolebinding’ #13405
OCPBUGS-33777 : restrict Masthead logo to max-height to 60px #13860
OCPBUGS-33749 : Add visual connector between VMs and non VMs workloads #13857
OCPBUGS-33382 : Routes created by devfiles do not always use HTTPS #13827
OCPBUGS-33650 : fix issues with Edit Route form #13851
OCPBUGS-32500 : PipelineRuns in Console show wrong status or load indefinitely #13780
OCPBUGS-31077 : Pipeline Name gets changed to “new-pipeline” on the Edit Pipeline YAML/Builder #13683
OCPBUGS-31595 : Fix operands list endpoint. #13714
OCPBUGS-29063 : add additional check to determine if file is binary #13579
OCPBUGS-28788 : Copy response code from proxied plugin requests #13561
OCPBUGS-29243 : Add a new allowInsecure option to the internet proxy #13593
OCPBUGS-27406 : Add Pipeline metrics tab using plugin #13525
OCPBUGS-23483 : add access to create, edit and delete silences for developer user from developer perspective #13349
OCPBUGS-25427 : Fix plugin proxy handler #13449
OCPBUGS-25465 : fix runtime error on Node details Overview when Machin… #13452
OCPBUGS-25146 : add access review for impersonate #13437
OCPBUGS-24591 : ConsolePlugin metrics must no longer be grouped by the vendor #13424
OCPBUGS-22241 : Save also the location.search and .hash values in localStorage to restore them after login #13271
OCPBUGS-24240 : Subsequent PipelineRuns take initial PipelineRun name into account #13385
OCPBUGS-23497 : Cannot Edit Shipwright Build #13352
OCPBUGS-11316 : Fix description for BuildAdapter SDK extension #12703
OCPBUGS-22986 : Correct logout process #13310
OCPBUGS-23065 : remove expandable toggle for conditional update risk d… #13316
OCPBUGS-22784 : add support for new features annotations while preservi… #13299
OCPBUGS-19532 : use active namespace in Create cta href of create action for operator backed #13179
OCPBUGS-18271 : update the KnativeServing API version to v1beta1 for global-config extension #13112
OCPBUGS-20232 : show all the legends for Pipeline metrics in PipelineRun TaskRun Duration chart #13224
OCPBUGS-20231 : fetch TaskRuns without selector and reduces the get TaskRuns requests #13223
OCPBUGS-20330 : Check if filtered object contains name property #13227
OCPBUGS-13285 : add multipath device type to LocalVolumeSet #12804
OCPBUGS-17481 : Fix that “Delete application” doesn’t work in topology when Pipelines operator is not installed #13083
OCPBUGS-18764 : Fixed Edit Application form for Knative Services #13147
OCPBUGS-18538 : OCP console mandate secret for repository creation #13135
OCPBUGS-18679 : [knative] Don’t rely on openshift/hello-openshift as a sample image #13140
OCPBUGS-18289 : Not able to import the repository with .tekton directory and func.yaml file present #13116
OCPBUGS-18443 : Fix crash when filtering the quick start catalog #13127
OCPBUGS-18312 : Web console slowness on Project>Project access page #13119
OCPBUGS-18335 : Fix DeploymentConfig list performance issues by lazy loading their ReplicationControllers #13120
OCPBUGS-17876 : Fix topology crash when a console.topology/data/factory extension tries to resolve a resource with version from the CRDs which doesn’t exists #13095
OCPBUGS-16668 : Dynamic plugin translation support for plurals broken #13041
OCPBUGS-17181 : Creation of GH webhook and attaching it to repo while importing from git using PAC #13060
OCPBUGS-16040 : fix bug where binary secret values are corrupted on edit and add test coverage #13048
OCPBUGS-16659 : Fix RTE in bridge. #13038
OCPBUGS-16158 : “Duplicate RoleBinding” leads to “Unsupported value” error #13008
OCPBUGS-16434 : Fix stop PLR option #13031
OCPBUGS-14265 : Regression: OpenShift Console no-longer filters SecretList when displaying ServiceAccount #12865
OCPBUGS-13641 : Do not fetch catalog sources on CSV or Subscription details pages. #12811
OCPBUGS-16421 : When removing the project owner from the project in GUI, instead of that user, the group (the default group added as project admin through the project template) will be removed. #13030
OCPBUGS-15998 : Upload JAR file does not work if the Cluster Samples Operator is disabled #12992
OCPBUGS-15810 : only show pipelines doc link for downstream #12981
OCPBUGS-15982 : get Kamelets from the camel-k-operator namespace as well #12988
OCPBUGS-16244 : Fix operator backed catalog page when copied CSVs disabled #13019
OCPBUGS-15194 : Remove tech preview badge from Pipeline repository pages #12916
OCPBUGS-10326 : re-enable operator-install-single-namespace.spec.ts test #12653
OCPBUGS-15848 : The upgrade Helm Release tab in OpenShift GUI Developer console is not refreshing with updated values. #12976
OCPBUGS-15890 : Use proxy with web socket connection and monitoring dashboard #12978
OCPBUGS-15720 , OCPBUGS-15721 , OCPBUGS-15722 : Helm Chart installation form hangs on create if JSON-schema is using 2019-09 or 2020-20 standard revisions #12963
OCPBUGS-14426 : account for single object in status.conditions instead… #12875
OCPBUGS-14267 : Add Pipeline metrics unsupported empty page #12864
OCPBUGS-15410 : Add Git Repository (PAC) doesn’t setup GitLab and Bitbucket configuration correct #12936
OCPBUGS-15787 : Remove access review check for PipelineResource from Pipeline section #12967
OCPBUGS-15228 : Create helm release page doesn’t show a YAML editor when schema isn’t available (httpd-imagestreams chart) #12937
[release 4.13] OCPBUGS-15360: Serverless functions UI warning is misleading #12931
OCPBUGS-14166 : Fixed Make Serverless Form Error #12857
OCPBUGS-14336 : use service port name instead targetPort in the Pipeline Event listener route #12870
OCPBUGS-14310 : Could not import multiple resources via JSON (while YAML supports this) #12868
OCPBUGS-15335 : Delete annotation ‘tekton.dev/v1beta1TaskRuns’ when rerun the PLR #12927
OCPBUGS-15130 : Helm Repository “Edit” button results in 404 #12909
OCPBUGS-14189 : Corrected Labels for resolving the bug related to the Create Route Checkbox #12858
OCPBUGS-13642 : Fix OLM k8sResourcePrefix descriptor dropdown behavior #12812
OCPBUGS-11974 : Add page title to Devconsole pages #12844
OCPBUGS-15465 , OCPBUGS-15481 : Remove PipelineResource CRD check because it’s not installed with PO 1.11 anymore and disable operator-uninstall test #12949
OCPBUGS-14943 : visiting Configurations page returns error Cannot read… #12897
OCPBUGS-12785 : Project admin can update and view subscription from operator details page #12780
OCPBUGS-14574 : only copy workload annotations to debug pod #12879
OCPBUGS-14258 : Add vSphere cluster field. #12862
OCPBUGS-14195 : Topology UI doesn’t recognize Serverless Rust function for proper UI icon #12860
OCPBUGS-10527 : When there are 2 pipelines displayed in the dropdown menu, selecting one, unchecks the Add Pipeline checkbox #12658
OCPBUGS-14165 : propagate labels to pipeline resources #12856
OCPBUGS-13959 : Wait with CRD/model translation until i18n bundles are loaded #12842
OCPBUGS-13783 : fix runtime error on OperatorHub details pages #12830
OCPBUGS-12770 : fix buildconfig form ns #12776
OCPBUGS-12850 : add support for minimal status of tekton #12784
OCPBUGS-12740 : update helm release empty state text #12773
OCPBUGS-11866 : delete associated pipeline, triggertemplate and eventlistener when deleting app #12730
OCPBUGS-12186 : Pipeline doesn’t render correctly when displayed but looks fine in edit mode #12748
OCPBUGS-11218 : use PipelineRun template from ‘pipelines-as-code-pipelinerun-go’ configMap for Go runtime #12696
OCPBUGS-12273 : When Creating Sample Devfile from the Samples Page, Topology Icon is not set #12757
OCPBUGS-12272 : Importing a kn Service shows a non-working Open URL decorator also when the Add Route checkbox was unselected #12756
OCPBUGS-12173 : taskrun ui fails when using object type results #12745
OCPBUGS-10832 : Edit Deployment (and DC) form doesn’t enable Save button when changing strategy type #12674
OCPBUGS-11919 : Reduce metrics cardinality by grouping well-known and other perspectives and plugins #12742
OCPBUGS-10266 : Fixes argocd link for non-KAM added application envs #12649
OCPBUGS-10265 : Fixes resource status alignment issue #12648
OCPBUGS-10299 : Fixes card sizes not even issue when commit info is not available on Environments page #12651
OCPBUGS-12172 : Users don’t know what type of resource is being created by Import from Git or Deploy Image flows #12744
OCPBUGS-10678 : Do not show builder ImageStreams without sampleRepo as samples #12668
OCPBUGS-11232 : fix All projects selection on Pipelines page in dev perspective #12698
OCPBUGS-11390 : Move operator install status to it’s own route/page #12706
OCPBUGS-11107 : Fix alerts source display values #12688
OCPBUGS-11248 : fix translation string for Image pull secret created alert #12699
OCPBUGS-10833 : update the default pipelineRun template name #12675
OCPBUGS-10679 : Show type of sample on the samples view #12639
OCPBUGS-10474 : OpenShift pipeline TaskRun(s) column Duration is not present as column in UI #12656
And 1 elided commits (e.g. from squash or rebase merges)
Full changelog
OCPBUGS-84928 : Replace google.golang.org/grpc with github.com/openshift-sustaining/grpc-go v1.64.1-sec.1 to avoid go version bump and fix CVE-2026-33186 #185
Full changelog
Upgrade glibc, use dnf (#130) #130
Fixing the regexp used to get the correct GCC version. (#129) #129
Updating the docs to use ubi9 instead of ubi8. (#128) #128
Moving to rhel9 base image. (#125) #125
Remove abi since it was not in 9.2 rpms (#124) #124
Full changelog
OCPBUGS-77756 : fix vendor for hermetic 4.13 #7822
OCPBUGS-53901 : bump golang-jwt v4 #5948
OCPBUGS-39184 : fix: bump github.com/IBM/go-sdk-core/v5 #4627
OCPBUGS-41515 : set Konnectivity cipher suites #4284
NO-JIRA: hack: make the e2e script generic #4202
HOSTEDCP-1146 : cpo: use CPO spec container image if it is a sha256 reference #3296
OCPBUGS-22971 : Add konnectivity-proxy container to CNO #3167
OCPBUGS-23455 : Use the same etcd snapshot for all replicas during etcd restore #3205
NO-JIRA: Red Hat Trusted App Pipeline purge hypershift-operator-release-413 #3217
chore(deps): update rhtap references (release-4.13) #3043
Update RHTAP references (release-4.13) #2996
OCPBUGS-17182 : add need-management-kas-access label to olm-collect-profiles pods #2871
OCPBUGS-16225 : Add missing probes to two services #2821
fix(olm): Use 4.13 catalog source images #2978
Updated secret permissions for openshift-route-controller-manager #2923
HOSTEDCP-1121 : Ensure SG reconciliation for aws endpoint #2885
chore(deps): update rhtap references (release-4.13) #2921
Revert “HOSTEDCP-1110: [backport-4.13] Allow HCP Specification to Support ICSP & IDMS” #2931
chore(deps): update rhtap references (release-4.13) #2904
Update RHTAP references (release-4.13) #2866
HOSTEDCP-1046 : Add ImageDigestMirrorSet to Config API comment #2870
HOSTEDCP-1046 : Add IDMS to the list of valid config manifests #2863
Update RHTAP references (release-4.13) #2833
HOSTEDCP-1110 : [backport-4.13] Allow HCP Specification to Support ICSP & IDMS #2839
OCPBUGS-15743 : Let getMachinesForNodePool return machines ordered by creation Timestamp #2767
4.13: Add management cluster KAS network policy #2786
Leader election config update. #2801
OCPBUGS-16160 : fix deletion bug when hostedzone is already deleted #2813
HOSTEDCP-1061 : [release-4.13] Implement dedicated request serving nodes for HostedClusters #2809
Update RHTAP references (release-4.13) #2816
OCPBUGS-16057 : use ignition-proxy Service to populate ignitionEndpoint with strategy NodePort #2798
OCPBUGS-14862 Improve clarity around hypershift operator permissions #2810
HOSTEDCP-1101 : Add snyk-secret HO RHTAP scripts #2799
OCPBUGS-16125 : [release-4.13] Update vendored dependencies #2797
OCPBUGS-15774 : autoscaling balance similar groups #2805
OCPBUGS-15965 : Reject VPCE Connections during VPCE Service cleanup #2789
Update RHTAP references (release-4.13) #2751
OCPBUGS-15171 : Skip AWS resource deletion for ‘Unknown’ OIDC state #2701
HOSTEDCP-1008 : Add NodePoolTransitionSeconds metric #2758
OCPBUGS-15281 : Check OwningIngressController also in Labels #2715
HOSTEDCP-1060 : refactor ignition-server reconcilation and add ignition-server proxy #2748
HOSTEDCP-1073 : enforce blocked rollout of HCP #2735
HOSTEDCP-1003 : Set AWS conditions only for AWS platform #2670
OCPBUGS-15268 properly handle user CA bundle not existing #2710
OCPBUGS-15301 : [release-4.13] fix(oauth): Do not proxy IBM Cloud IAM endpoints #2696
OCPBUGS-14030 : Include default ingress CA in root CA bundle #2599
OCPBUGS-14490 : Enable HCCO to reconcile over the OperatorHub’s disableAllDefaultSources object #2645
OCPBUGS-14801 : Set DisableStrictZoneCheck = true in the AWS Cloud Provider config #2666
HOSTEDCP-1048 : Add impersonate feature to the CLI and document HC dump procedure #2681
OCPBUGS-14872 : Honor global ingress configuration LoadBalancer type on AWS #2677
OCPBUGS-14436 : Add ClusterUpgradeDuration metric #2637
HOSTEDCP-1009 : Allow external-dns image to be set in install cli #2652
Red Hat Trusted App Pipeline update hypershift-operator-release-413 #2641
Red Hat Trusted App Pipeline purge hypershift #2640
OCPBUGS-13735 : Cluster-api SA can’t create events and fix permissions wrongly included #2610
OCPBUGS-14242 : Remove external-dns –events flag #2621
OCPBUGS-14155 : Reconcile oauthDeployment annotations even if kubeadmin secret is not found #2613
OCPBUGS-13399 : Fix errors from HCP controller removeServiceCAAnnotationAndSecret() #2552
HOSTEDCP-1010 : Set ETCD Storage Size as immutable field and equalised the default size among both api versions #2611
HOSTEDCP-947 : Increases default etcd PV size to 8Gi #2569
HOSTEDCP-926 : Send metric when HO/CPO decide to skip cloud resource deletion #2594
HOSTEDCP-975 : Backport nodepools metrics #2601
Red Hat Trusted App Pipeline update hypershift #2603
OCPBUGS-13594 : Sync proxy TrustedCA to guest cluster #2556
fix nil deref in DefaultWorkerSecurityGroupID check #2574
OCPBUGS-13215 : Let the aws endpoint to use the hypershift owned SG #2529
OCPBUGS-13497 : Add internal/external elb tags to subnets #2553
OCPBUGS-13531 : Clean up existing VPC endpoint connections #2554
Stop triggering rollout on labels/taint change #2548
Fixes HCCO reconcile error for kubevirt csi driver #2538
Fix kubevirt csi daemonset reconcile loop #2542
HOSTEDCP-980 : Include HostedClusterDegraded in hypershift_hostedclusters_failure_conditions metric #2525
Bug HOSTEDCP-788: [release-4.13] Configurable SRE MetricsSet #2544
ACM-5173 [backport 4.13] get pull secret instead of dockerconfigjson from mce credentials #2487
OCPBUGS-13085 : Account for expectedState == false when capturing hostedClustersWithFailureCondition #2516
OCPBUGS-13076 : Ensure ingress controllers are removed before load balancers #2514
HOSTEDCP-937 : Add new metric to expose hypershift operator info #2499
Fixed assignment to entry in nil map #2510
OCPBUGS-12786 : fix(hcco): Get OLM CatalogSource images from defined map #2484
add hyperv1.SilenceClusterAlertsLabel to HostedCluster on deletion #2480
OCPBUGS-12844 : Delete kubeadmin secret when an idp is defined #2491
HOSTEDCP-917 : Add publicAndPrivate <-> Private e2e test #2490
OCPBUGS-12689 : hosted clusters default KAS PDA config should be consistent with OCP #2496
HOSTEDCP-969 : Consolidate labels for metrics #2497
HOSTEDCP-969 : Move metrics #2495
OCPBUGS-12737 : Pass OPENSHIFT_RELEASE_IMAGE env variable to CNO #2472
OCPBUGS-12225 : Add new OCP 4.13 storage admission plugin #2462
OCPBUGS-12198 : remove ACL for aws bucket #2457
kubevirt: Block metadata server egress #2439
HOSTEDCP-638 : Add latest ocp supported info to -v command for cli and operator #2447
add pull-secret to imagePullSecrets for NTO, CNO, and olm-collect-profiles #2432
e2e: Cleanup shared OIDC provider on SIGTERM #2448
OCPBUGS-11842 : allow z-stream upgrade even if CVO Upgradeable is false #2431
Relax MCO API strict decoding #2442
Enable monitoring for hypershift & HCP namespace #2429
OCPBUGS-11545 : Pass runAsUser to CNO so it can run its managed services with proper security context #2392
OCPBUGS-10422 : Create new EC2 client for AWS identity provider health check #2402
OCPBUGS-10995 : Honor scheduler profile in HostedCluster configuration #2337
OCPBUGS-11725 : Update HostedCluster oauthCallbackURLTemplate #2409
HOSTEDCP-568 : Update Konnectiviy socks5 proxy for IBM exception #2404
bug OCPBUGS-10422: Preserve false status of ValidAWSIdentityProvider condition #2401
HOSTEDCP-802 : add cli flag to enable upgrade type #2388
OCPBUGS-11606 : properly reconcile with user specified changes for in proxy configuration #2394
Let install apply to aggregate errors #2375
Revert “Create a second scheme that always registers prometheusoperatorv1 GVKs #2376
HOSTEDCP-939 : [release-4.13] Setup shared OIDC provider for e2e clusters #2364
OCPBUGS-10422 : Ensure identity provider health check condition is persisted and remove awsendpoint control plane finalizer if invalid aws creds #2283
HOSTEDCP-850 : Fix nodepool autoscaler logic #2363
HOSTEDCP-806 : Fix ValidAWSKMSConfig condition #2361
OCPBUGS-10867 : Switch NTO metrics auth to certs generated by HCP controller #2331
OCPBUGS-10823 ensure well known public domains do not get proxied on image imports #2353
OCPBUGS-10645 : Add storage operators perms. to watch HostedControlPlane #2305
SDA-8706 : No more specifying the scrape interval at servicemonitors & podmonitors level #2355
OCPBUGS-11013 : Do not proxy when guest cluster resolution fails #2339
OCPBUGS-11055 : fix external APIServer address selection based on endpointAccess #2349
HOSTEDCP-934 : [release-4.13] Validate PublishingStrategyMapping #2343
HOSTEDCP-900 : Modified AWSPrivateLinkController and AWSEndpointServiceController to respect PausedUntil spec field #2284
HOSTEDCP-903 : Propagate AWSEndpointService conditions #2307
OCPBUGS-10792 : [release-4.13] Create a second scheme that always registers prometheusoperatorv1 GVKs #2312
HOSTEDCP-801 : [release-4.13] Expose external DNS for private cluster endpoints #2313
Update HCP version in capi cluster ref #2266
OCPBUGS-10504 : Deletion of the VPCEnpoint on conflicting service names #2309
HOSTEDCP-839 : Audit log sidecars for openshift-apiserver and openshift-oauth-apiserver #2296
OCPBUGS-10586 : Use appropriate serving certificate for OAuth #2294
Validate etcd KMS config #2260
Force controleplane upgrade always #2291
Disable inplace upgrade e2e tests #2303
HOSTEDCP-809 : Clone CA key/cert to TLS key/cert #2262
OCPBUGS-8369 : Fix cleanup of volumes on cluster deletion #2252
Full changelog
“OCPBUGS-29791: [release-4.13] Address CVE-2024-1725: Restrict access to infrastructure PVCs by requiring matching infraClusterLabels on tenant PVCs” #35
Full changelog
OCPBUGS-59699 : Bump github.com/golang/glog to v1.2.4 (#117) #117
[release 4.13] OCPBUGS-60541: Replace e2e test image (#132) #132
swtich golint install method (#129) #129
Correct 4.16 owners file (#130) #130
Added METRIC_TEST_IMAGE var (#90) #90
Update the k8s dependencies to 1.26.10 (#83) #83
Full changelog
Dockerfile: move to RHEL9 base image #83
Updating ose-network-tools images to be consistent with ART #75
Full changelog
changes the owners file (#1012) #1012
OCPBUGS-48513 : e2e: use same version of crane as in go.mod (#1025) #1025
Bump version to include v5.11.0 of go-git (#823) #823
OCPBUGS-385 : Capability to override default channel (#749) (#791) #749
OCPBUGS-19429 : Fix cross EUS channel upgrade path calculation (#775) #775
OCPBUGS-21460 : Fix CVE-2023-44487 and CVE-2023-39325 (#714) #714
Fix OCPBUGS-17546: pod catalogsource generated by oc-mirror will crashloopBackOff randomly (#700) #700
Fix OCPBUGS-14402 (#675) #675
OCPBUGS-18556 : operator catalogs from oc-mirror fail to deploy because of invalid caches (#691) #691
OCPBUGS-18106 : manual cherrypick (#684) #684
OCPBUGS-17998 : fix: ICSP with incorrect mirror path (#685) #685
OCPBUGS-17453 : Fix “ OCI index found, but accept header does not support OCI indexes (#677) #677
OCPBUGS-16372 : A variety of changes needed for correct operation with multi… (#661) #661
OCPBUGS-13871 : fix: changes on help info content (#654) #654
Fix OCPBUGS-11840: ParseImageReference supports cases where both tag and digest are present in a ref (#637) #637
Removes Ross and adds Jeremy in the OWNER file (#645) #645
OCPBUGS-13591 , OCPBUGS-13592 : Limit the nested repository path while mirroring the images (#635) #635
CFE-658 : Implementation of filtering by channel for OCI catalog (#628) #628
Deprecate –use-oci-feature in favor of –include-local-oci-catalogs (#621) #621
Update OWNERS for CFE team (#625) #625
Revert adding ‘–cache-dir /tmp/cache’ to catalog images (#616) #616
OCPBUGS-12259 : fix: skips bundles with ‘skips’ field on head bundle (#617) #617
fix: work around OCPBUGS-6741 by explicitly setting –cache-dir (#606) #606
OCPBUGS-11908 : Fix (#607) #607
OCPBUGS-10348 fix: changes to include the registry path (#602) #602
Fix OCPBUGS-8156: Upgrade to containerd v1.6.18 (#596) #596
fix extract dir for cincinnati-graph-data container (#584) #584
Bugfix check imagesetconfig for valid oci protocol when oci feature is used (#595) #595
Remove “unsupported” wording from info on console (#594) #594
Bugfix for destination registry nested paths length (#583) #583
Fix OCPBUGS-5168: Upgrade helm.sh/helm/v3 to v3.11.2 fixing CVE-2022-23526 and CVE-2022-23525 (#592) #592
OCPBUGS-10051 : fix: remove catalog reference from ImageContentSourcePolicy.yaml (#587) #587
OCPBUGS-8216 : fix: remove an unecessary error message (#581) #581
docs: add information about unsupported scenario (#578) #578
Updating oc-mirror-plugin images to be consistent with ART (#570) #570
Full changelog
: OCPBUGS-27594,OCPBUGS-27679: Update go-git to v5.11.0 #75
OCPBUGS-23403 : [release-4.13] Address http2 vulnerability #58
OCPBUGS-21363 : [release-4.13] Bump golang.org/x/net to v0.17.0 #40
UPSTREAM: <carry>: add downstream owners #42
OCPBUGS-7683 : Bump helm to v3.11.1 to address CVE-2023-25165 #19
OCPBUGS-6447 : bump golang/x/net to v0.4.0 for CVE-2022-41717 #17
Update owners file #18
Updating ose-olm-rukpak images to be consistent with ART #14
image source: avoid shadowing /bin with emptyDir mount #12
Merge the upstream v0.10.0 rukpak tag #11
Merge the upstream v0.9.0 tag #10
Updating ose-olm-rukpak images to be consistent with ART #9
Add BZ component to OWNERS #8
downstream sync 8/8/2022 #7
Ensure the non-e2e CI checks can run successfully #5
Dockerfile: Disable workspace mode #4
Bootstrap the rukpak repository #2
Create OWNERS #1
And 2 elided commits (e.g. from squash or rebase merges)
Full changelog
Source code for this page located on github