Back to index 
Download the installer  for your operating system or run 
oc adm release extract --tools quay.io/openshift-release-dev/ocp-release:4.15.23-x86_64 Team Approvals: 
Tests:
Blocking jobs Informing jobs Upgrades from:
Untested upgrades: 
4.14.19 , 
4.14.21 , 
4.14.22 , 
4.14.23 , 
4.14.25 , 
4.14.26 , 
4.14.28 , 
4.14.29 , 
4.14.30 , 
4.15.11 , 
4.15.12 , 
4.15.13 , 
4.15.14 , 
4.15.15 , 
4.15.16 , 
4.15.17 , 
4.15.18 , 
4.15.19 , 
4.15.6 , 
4.15.7 , 
4.15.9 Upgrades to:
Loading changelog, this may take a while ...
Created: 2024-07-22 17:43:50 +0000 UTC
Image Digest: sha256:e39f4b55929f54a720ca84075544920ddc9fcc1e6a627005ebfd4c3b64e5716c
Release 4.15.23 was created from registry.ci.openshift.org/ocp/release:4.15.0-0.nightly-2024-07-22-104333 
Components 
New images 
Removed images 
kuryr-cni 
kuryr-controller 
 
Rebuilt images without code change 
machine-os-content sha256:7508a8d749d529dec05bcfcce7ff27d03e52c3b5d9c86e16de562f8d5eaf5be7 
ovirt-machine-controllers  git 5d708631  sha256:e42889c23664c856505a00cc7fdd554488a3c89c6858173ae9af08707944c67erhel-coreos sha256:b1c45a47ffeaad41f434352f657fd22dd1a4460ff54806326bbebca725294f84 
rhel-coreos-extensions sha256:bf34700dd98facb0bdcdd534e1806e8017907e1f8b087fea52f5255ee60d0de5 
 
OCPBUGS-34641 : Invalid Pull-Secret when using password which contains a colon character (#6381) #6381 OCPBUGS-31631 : Deploy dual stack with IPv6 on top of bond/vlan fails (#6245) #6245 MGMT-17593 : Bump x/net to at least v0.24.0 to mitigate CVE-2023-45288 (#6217) #6217 17549: Bump runc version to 1.1.12 to Mitigate CVE-2024-21626 (#6211) #6211  
Revert “MGMT-17549: Bump runc version to 1.1.12 to Mitigate CVE-2024-21626 (#6194)” (#6208) #6194  
MGMT-17549 : Bump runc version to 1.1.12 to Mitigate CVE-2024-21626 (#6194) #6194 MGMT-17541 : Replace broken golangci reference (#6191) #6191 OCPBUGS-30232 : Handle skipping hostPrefix validation for IPv6 For non-OVN/SDN networkTypes, the hostPrefix validation is not required and it is skipped. This fixes a regression introduced in the fix for https://issues.redhat.com/browse/OCPBUGS-23069  in which IPv6 CIDRs were not using the correct default hostPrefix. In addition, all cases where the validation is used are now covered. (#6137) #6137 NO-ISSUE: replace postgres images as current one disappeared from quay (#6135) #6135  
MGMT-16517 : Add Env Var Deployment Type & Set ABI (#6016) #6016 MGMT-16980 : Change the default value of ENABLE_SKIP_MCO_REBOOT to false (#6005) #6005 MGMT-16494 : Move ip hint file creation to ignition in order to change it in IBI process (#5926) #5926 OCPBUGS-24428 : Redact passwords logged in installConfigOverrides Ensure that any passwords included in installConfigOverrides are redacted in logs. (#5905) #5905 MGMT-16414 : When trying to create cluster with s390x architecture, an error occurs that stops cluster creation (#5876) #5876 NO-ISSUE: Bump OCP versions: 4.12 (#5783) #5783  
MGMT-16289 : Add configuration variable and cluster attribute defining if soft timeouts feature is enabled (#5740) #5740 NO-ISSUE: Bump OCP versions: 4.14, 4.11, 4.13, 4.15 (#5779) #5779  
fix: allow LVMS for MultiNode >=4.15.0 (#5757) #5757  
Update RHTAP references (#5776) #5776  
NO-ISSUE: add build tags option to enable FIPS build (#5768) #5768  
Update RHTAP references (#5774) #5774  
NO-ISSUE: update OS_IMAGES filter to 4.11 (#5773) #5773  
MGMT-16303 : Disable skip MCO reboot for architecture s390x (#5765) #5765 Propagate OS_IMAGES var in deploy operator (#5762) #5762  
Update RHTAP references (#5767) #5767  
MGMT-15425 : Change chosen mce release to match openshift version (#5716) #5716 MGMT-14605 : Gather more data for hypershift tests (#5344) #5344 MGMT-16320 : Agent should connect to iBFT iSCSI targets (#5753) #5753 MGMT-16312 fix update host ignition for unbound host (#5751) #5751  
NO-ISSUE: Inventory code cleanup - unused params (#5755) #5755  
HOSTEDCP-999 : Fix incorrect ICSP for CAPI CI (#5747) #5747 MGMT-15690 : Add support for external platform (#5738) #5738 MGMT-16235 : Ensure that agent controller will watch for changes to ignition endpoint token. (#5736) #5736 MGMT-13461 : Fix Tang validation when day2 host join an imported cluster (#5700) #5700 MGMT-15972 : Remove Swagger definition for api_vip and ingress_vip (#5734) #5734 HOSTEDCP-999 : Fix incorrect check for CAPI image in ci (#5741) #5741 Update RHTAP references (#5733) #5733  
MGMT-16273 : Allow installing on iSCSI disks on OCI (#5728) #5728 MGMT-16291 : revert default faulty OCP images (#5737) #5737 MGMT-14810 : Remove API and Ingress VIP (#5501) #5501 HOSTEDCP-999 : Missed service-cidr for capi ipv6 CI test (#5721) #5721 NO-ISSUE: Bump github.com/google/uuid from 1.3.1 to 1.4.0 (#5726) #5726  
NO-ISSUE: Bump OCP versions: 4.14, 4.13, 4.12 (#5722) #5722  
Update baremetal operator (#5698) #5698  
MGMT-16001 : Sanitize reclaim agent daemonset name (#5699) #5699 HOSTEDCP-999 : Minor fixes for disconnected CAPI CI (#5713) #5713 AGENT-740 : Include baremetal host BMC fields in install-config override (#5675) #5675 NO-ISSUE: adding me to owners (#5709) #5709  
NO-ISSUE: Cluster code cleanups (#5715) #5715  
NO-ISSUE: Bump OCP versions: 4.12 (#5714) #5714  
MGMT-16236 : remove elastic APM (#5702) #5702 NO-ISSUE: Upgrade debug image to latest delve (#5711) #5711  
Update RHTAP references (#5688) #5688  
HOSTEDCP-999 : Setup CI for disconnected ipv6 CAPI (#5536) #5536 NO-ISSUE: Inventory code cleanups (#5695) #5695  
NO-ISSUE: dependabot optimize (#5697) #5697  
NO-ISSUE: Bump OCP versions: 4.14, 4.13, 4.15 (#5701) #5701  
NO-ISSUE: Remove unused functions (#5696) #5696  
NO-ISSUE: BMH and Agent controllers code cleanup (#5693) #5693  
NO-ISSUE: Remove unused functions from ctrl event wrapper (#5694) #5694  
NO-ISSUE: Bump github.com/Azure/go-autorest/autorest/adal (#5604) #5604  
NO-ISSUE: ClusterDeployments controller code cleanup (#5689) #5689  
NO-ISSUE: InfraEnv controller code cleanup (#5690) #5690  
MGMT-15271 : Append kargs to installer for s390x (#5665) #5665 Add missing scheme to ServiceMonitor (#5672) #5672  
Updating ose-agent-installer-api-server-container image to be consistent with ART (#5495) #5495  
MGMT-15971 : Create ManagedCluster CR so that the hub will show up as “Ready” in MCE (#5575) #5575 Update RHTAP references (#5682) #5682  
NO-JIRA:  Enable skip mco reboot functionality only if openshift version is 4.15 and higher (#5680) #5680  
NO-ISSUE: Bump OCP versions: 4.11, 4.12, 4.13 (#5681) #5681  
MGMT-16151 : allow CORS OPTIONS for s3 presigned url (#5674) #5674 Update RHTAP references (#5654) #5654  
MGMT-16151 : allow CORS HEAD for s3 presigned url, as UI uses preflight checks (#5671) #5671 MGMT-16061 : changing dnsmasq configuration for sno in order to meet single ip installation flow for ibu (#5658) #5658 MGMT-16077 : Add 4.15 release and OS images (#5673) #5673 AGENT-723 : Use json.Marshal to correctly process vSphere credentials (#5592) #5592 NO-ISSUE: Fix for error in wait_for_cmd_amount function (#5670) #5670  
MGMT-15902 : Trigger reboots for node event when day2 node moves to done (#5648) #5648 NO-JIRA:  Allow the command in wait_for_cmd_amount to receive arguments (#5668) #5668  
MGMT-16164 : Install 4.14 redhat-operators catalog for LSO (#5669) #5669 MGMT-15878 : Ensure that hosts emit event showing why preparation failed. (#5521) #5521 MGMT-15878 : Add a condition to show the last preparation failure (#5524) #5524 MGMT-16151 : change default envoy sidecar timeout value (#5667) #5667 MGMT-16114 : Update 4.14 release image to use GA version (#5651) #5651 MGMT-16052 : Fix cluster HighAvailabilityMode nil pointer in update flow (#5659) #5659 Bump OCP versions: 4.14, 4.12 (#5661) #5661  
MGMT-15405 : Add a URL to infraenv to show download link from static network config (#5638) #5638 OCPBUGS-19823 : Ignore hostPrefix validation for plugins other than OVN/SDN (#5565) #5565 MGMT-15271 : Add the boot command line to the host inventory (#5649) #5649 MGMT-15680 : Adds InfraEnv ctrl watch for pull secret changes (#5589) #5589 NO-ISSUE: Bump github.com/jackc/pgconn from 1.12.0 to 1.14.1 (#5653) #5653  
MGMT-16061 : changing dnsmasq configuration for sno in order to meet single ip installation flow for ibu (#5613) #5613 NO-ISSUE: Bump github.com/jackc/pgtype from 1.11.0 to 1.14.0 (#5647) #5647  
Update RHTAP references (#5637) #5637  
Bump OCP versions: 4.13 (#5645) #5645  
NO-ISSUE: Bump go.opentelemetry.io/otel/exporters/otlp (#5644) #5644  
MGMT-15683 : Ensure that manifest filename has valid name part (#5635) #5635 NO-ISSUE: Bump go.opentelemetry.io/contrib from 0.20.0 to 1.20.0 (#5641) #5641  
NO-ISSUE: Bump go.uber.org/atomic from 1.7.0 to 1.11.0 (#5619) #5619  
Update RHTAP references (#5624) #5624  
MGMT-15684 : Return appropriate HTTP error code for invalid manifest file path (#5634) #5634 Bump OCP versions: 4.14 (#5633) #5633  
NO-ISSUE: Bump github.com/jackc/pgproto3/v2 from 2.3.0 to 2.3.2 (#5632) #5632  
MGMT-16037 : fix messaging errors on big clusters (#5628) #5628 MGMT-16039 : upgrade to golang 1.20 (#5616) #5616 NO-ISSUE: Bump github.com/Azure/go-autorest/autorest (#5622) #5622  
Revert “NO-ISSUE: use kubectl 1.28.2 (#5572)” (#5618) #5572  
Bump OCP versions: 4.12 (#5615) #5615  
MGMT-16045 : mitigate CVE-2023-44487 (#5614) #5614 MGMT-15902 : Add event that shows the number of reboots for a node before completing installation (#5591) #5591 Add skopeo to OCP build (#5558) #5558  
NO-ISSUE: Bump cloud.google.com/go/compute from 1.6.1 to 1.23.1 (#5601) #5601  
NO-ISSUE: Bump github.com/pierrec/lz4 (#5600) #5600  
NO-ISSUE: vendor current master (#5594) #5594  
NO-ISSUE: fixing dependabot issues (#5595) #5595  
Bump OCP versions: 4.13, 4.14 (#5593) #5593  
Update RHTAP references (#5590) #5590  
MGMT-16001 : Sanitize reclaim daemonset name (#5579) #5579 Bump OCP versions: 4.11, 4.12, 4.13 (#5586) #5586  
MGMT-13198 : Add API endpoint to create assisted installer event (#5578) #5578 MGMT-15980 : added missing Create op to infraenvs Webhook (#5569) #5569 Update RHTAP references (#5573) #5573  
NO-ISSUE: use kubectl 1.28.2 (#5572) #5572  
Update RHTAP references (#5570) #5570  
MGMT-15949 : fix missing ImageSetRef validation (#5552) #5552 Revert “NO-ISSUE: Set default ENABLE_SKIP_MCO_REBOOT: false (#5560)” (#5566) #5560  
MGMT-15572 Hold installation when reconcile-pause annotation is set on cluster deployment (#5549) #5549  
NO-ISSUE: Fix console output in ZTP jobs (#5562) #5562  
NO-ISSUE: add console output for ztp (#5550) #5550  
Bump OCP versions: 4.14 (#5559) #5559  
MGMT-15796 : set CloudControllerManager to External for OCI (#5548) #5548 NO-ISSUE: Set default ENABLE_SKIP_MCO_REBOOT: false (#5560) #5560  
Bump OCP versions: 4.12, 4.14, 4.13 (#5546) #5546  
Update RHTAP references (#5539) #5539  
MGMT-15950 : Fix DNS wilcard domain validation (#5544) #5544 WIP: Add assisted images service short URL routes (#5543) #5543  
Update RHTAP references (#5538) #5538  
MGMT-15738 : Support for E2E test, make sure we have an infraenv for adding a node to the local cluster. (#5477) #5477 Bump OCP versions: 4.13, 4.11 (#5537) #5537  
MGMT-14409 : generate short image URL (#5523) #5523 MGMT-15762 : fix odf validation failing where is one small disk (#5529) #5529 Update RHTAP references (#5520) #5520  
Bump OCP versions: 4.12, 4.14 (#5528) #5528  
NO-ISSUE: fail upload if response is not 2XX (#5522) #5522  
Bump OCP versions: 4.14 (#5525) #5525  
NO-ISSUE: fix docker-ce-cli package missing (#5499) #5499  
NO-ISSUE: Add versions file to onprem event upload (#5514) #5514  
MGMT-15699 : Service changes for avoiding MCO reboot (#5453) #5453 Update RHTAP references (#5517) #5517  
MGMT-15598 : Add a parameter to manifest list to disable filter (#5498) #5498 Bump OCP versions: 4.12 (#5515) #5515  
Update RHTAP references (#5513) #5513  
Bump OCP versions: 4.14 (#5512) #5512  
NO-ISSUE: Fix email domain for event uploader (#5511) #5511  
Update RHTAP references (#5510) #5510  
Update RHTAP references (#5508) #5508  
Bump OCP versions: 4.12, 4.13 (#5506) #5506  
MGMT-15808 : change base image to stream9 (#5497) #5497 MGMT-15559 : Change detached annotation condition in non-converged flow (#5445) #5445 MGMT-15732 : Fix unbound variable (#5493) #5493 Update RHTAP references (#5492) #5492  
Bump OCP versions: 4.14, 4.11 (#5496) #5496  
Update RHTAP references (#5470) #5470  
MGMT-15715 : Allow handling multi-document YAML custom manifests (#5480) #5480 MGMT-15732 : Add extra flag var for hypershift install (#5469) #5469 XMGMT-15704 : Bugfix for local cluster import (#5484) #5484 NO-ISSUE: update RHTAP deprecated image check (#5488) #5488  
Bump OCP versions: 4.12, 4.13 (#5483) #5483  
MGMT-15653 : Fix DNS regex validation (#5482) #5482 MGMT-15716 : notify events when updating cluster status (#5476) #5476 MGMT-15503 : Update operator bundle channel (#5474) #5474 Bump OCP versions: 4.14 (#5472) #5472  
MGMT-15306 : Fix UpdateCluster for requests that include VIPS and UMA (#5462) #5462 Full changelog  
OCPBUGS-35894 : Fix race to mark node Joined (#859) #859 MGMT-16843 : Use hostnamectl to replace illegal hostname (#851) #851 MGMT-17593 : Bump x/net to at least v0.24.0 to mitigate CVE-2023-45288 (#833) #833 MGMT-17549 : Bump runc version to 1.1.12 to Mitigate CVE-2024-21626 (#827) #827 MGMT-17541 : Replace broken golangci reference (#824) #824 MGMT-16843 : Ensure valid hostname during install (#791) #791 OCPBUGS-25718 : Do not remove uninitialized taints if vSphere (#785) #785 NO-ISSUE: Bump the go-dependencies group with 2 updates (#756) #756  
NO-ISSUE: Bump the go-dependencies group with 2 updates (#755) #755  
OCPBUGS-20049 : Remove uninitialized taint for agent-based installs (#739) #739 MGMT-16258 : Partitions naming convetion is different for various disk types (#752) #752 NO-ISSUE: Bump the go-dependencies group with 2 updates (#751) #751  
Updating ose-agent-installer-orchestrator images to be consistent with ART (#719) #719  
MGMT-15926 : Delete failed OLM jobs and subscription install plans in all cases during initialization check, not only in case of not found error (#748) #748 NO-ISSUE: Add my github account as an OWNER for this repository (#749) #749  
NO-ISSUE: Bump the go-dependencies group with 2 updates (#747) #747  
MGMT-15902 : Trigger event that notifies the number of reboots once the node installation is completed (#744) #744 NO-ISSUE: Bump the go-dependencies group with 1 update (#745) #745  
NO-ISSUE: Bump github.com/google/uuid from 1.3.1 to 1.4.0 (#743) #743  
NO-ISSUE: Bump github.com/operator-framework/api from 0.17.7 to 0.18.0 (#742) #742  
MGMT-16039 : upgrade to golang 1.20 (#741) #741 NO-ISSUE: Bump the go-dependencies group with 7 updates (#738) #738  
OCPBUGS-16482 : Update dependencies to remove goproxy dependency (#701) #701 MGMT-15984 : Assisted installer doesn’t freeze and unmount file systems used for overwriting os image (#737) #737 NO-ISSUE: Bump golang.org/x/sync from 0.1.0 to 0.4.0 (#731) #731  
Updating ose-agent-installer-csr-approver images to be consistent with ART (#718) #718  
MGMT-15710 : Assisted installer changes for avoiding MCO reboot (#713) #713 MGMT-15810 : fix image missing nsenter executable (#729) #729 MGMT-15810 : change base image to stream9 (#725) #725 NO-ISSUE: fix dependabot ingored packages (#724) #724  
Full changelog  
OCPBUGS-33404 : Make removable disks eligible (#718) #718 MGMT-17593 : Bump x/net to at least v0.24.0 to mitigate CVE-2023-45288 (#704) #704 MGMT-17549 : Bump runc version to 1.1.12 to Mitigate CVE-2024-21626 (#699) #699 MGMT-17541 : Replace broken golangci reference (#695) #695 MGMT-16335 : set HasUUID on appliance mock disk (#634) #634 NO-ISSUE: Bump the go-dependencies group with 3 updates (#635) #635  
NO-ISSUE: Add Eran Ifrach account and mine as owners (#633) #633  
NO-ISSUE: Bump the go-dependencies group with 2 updates (#630) #630  
MGMT-15860 : add strictfipsruntime to build (#629) #629 NO-ISSUE: Bump the go-dependencies group with 1 update (#626) #626  
OCPBUGS-16483 : Update apimachinery dependency to remove goproxy dep (#590) #590 MGMT-15271 : Get cmdline and set IBM in vendor (#624) #624 NO-ISSUE: Bump the go-dependencies group with 2 updates (#623) #623  
NO-ISSUE: Bump the go-dependencies group with 2 updates (#621) #621  
MGMT-16039 : upgrade to golang 1.20 (#619) #619 MGMT-16011 : Reduce agent image size (#617) #617 NO-ISSUE: Bump the go-dependencies group with 1 update (#618) #618  
MGMT-15900 : Add enable-skip-mco-reboot flag to assisted installer install command (#614) #614 NO-ISSUE: Bump the go-dependencies group with 3 updates (#612) #612  
NO-ISSUE: add adriengentil as approver (#611) #611  
NO-ISSUE: Bump the go-dependencies group with 2 updates (#608) #608  
MGMT-15809 : change base image to stream9 (#604) #604 Updating ose-agent-installer-node-agent images to be consistent with ART (#603) #603  
OCPBUGS-16482 : bump golangci-lint to v1.53.1 (#591) #591 NO-ISSUE: fix lint target and code (#605) #605  
MGMT-15653 : Update domain validation from assisted-service changes (#599) #599 Full changelog  
OCPBUGS-25355 : setting TLSSecurityProfile with no minTLSVersion crashes controller #82 OCPBUGS-25161 : Add annotation to CSI driver Pod preventing eviction from the cluster-autoscaler #76 OCPBUGS-25233 : CVE-2023-47108: bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp to v0.46 #77 STOR-1402 , STOR-1453 : update libraries and specify TLS_MIN_VERSION #72 OCPBUGS-22541 : CVE-2023-45142: bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp to v0.45.0 #70 OCPBUGS-22357 : CVE-2023-44487: bump github.com/openshift/library-go to master #69 OCPBUGS-21593 : CVE-2023-44487: bump golang.org/x/net to v0.17.0 #62 STOR-1276 : Enable support for mounting volumes with SELinux context #57 OCPBUGS-19111 : Updating ose-alibaba-disk-csi-driver-operator images to be consistent with ART #61 Full changelog  
OCPBUGS-33043 : Explicitly reserve 1 attachment for the root disk #222 OCPBUGS-30621 : remove legacy directory and duplicate Dockerfile.*.test files #201 OCPBUGS-30621 : move test manifest to top-level directory #195 OCPBUGS-26195 : Create RBAC objects first #93 OCPBUGS-25995 : Add selinux #91 OCPBUGS-25355 : setting TLSSecurityProfile with no minTLSVersion crashes controller #90 OCPBUGS-25161 : Add annotation to CSI driver Pod preventing eviction from the cluster-autoscaler #82 OCPBUGS-25234 : CVE-2023-47108: bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp to v0.46 #83 STOR-1500 : Switch to the new operator #69 Updating ose-aws-ebs-csi-driver-operator-container image to be consistent with ART #75  
STOR-1402 , STOR-1453 : update libraries and specify TLS_MIN_VERSION #71 STOR-1400 : Add support for Batch DescribeVolume #74 STOR-1400 : Sync sidecar arguments with upstream #72 STOR-1500 : Add log for the new operator #70 Pull the latest AWS EBS operator #67  
Fix vendoring of golang.org/x/net #68  
hack: remove existing path from .gitignore #65  
Drop Guest prefix from client names #64  
Update all generated assets in a single run #63  
Verify generated assets in make verify #62  
Move operator config into pkg/drivers #61  
Add AWS EBS CSI driver operator starter #58  
OCPBUGS-21593 : CVE-2023-44487: bump golang.org/x/net to v0.17.0 #59 STOR-1455 : Add asset generator #53 Delegate to aws-ebs-csi-driver-operator for tests and verify #57  
Add aws ebs operator legacy #56  
Add ci-operator config #54  
Clean the repository, it will be reused for all CSI driver operators #52  
Obsolete the operator #51  
Fix hostpath image sample to support dynamic registration #47  
Add kubelet-registration-path flag to csi-driver-registrar #44  
Fix golint error #45  
Output error message when failed to get CSIDriverDeployment and requeued #46  
Add -nometadata to go-bindata to stop updating generated files by every build #43  
Disable automatic installation of the operator in OpenShift #41  
Pass SecurityContext to sidecar containers #40  
Move EBS deployment sample to the right place #39  
Use correct context timeouts #38  
Add EBS sample deployment file #37  
Add leader election to the operator #36  
Embed git version into the operator binary #35  
Generate bindata during build #34  
Add more unit tests #33  
Add controller unit tests #32  
Fix deletion of non-namespaced objects #31  
Fix e2e test #30  
Add e2e test #29  
Update to operator-sdk 0.1.1 #28  
Fix liveness probe version #27  
ADd a RHEL7 dockerfile and standardize format #26  
Documentation update #23  
Add unit test for validation #14  
Fix status.conditions json name #11  
Add CRD printer columns #12  
Add configuration of liveness probe. #9  
Increase resync period #10  
Add /var/lib/kubelet HostPath directory to node drivers #8  
Fix role bindings #7  
Add liveness probe. #6  
Fix operator images #5  
Add OpenShift manifests to operator image #4  
Use label selector for informers. #3  
Use constants where appropriate #2  
Add initial operator #1  
And 26 elided commits (e.g. from squash or rebase merges) 
Full changelog  
OCPBUGS-25355 : setting TLSSecurityProfile with no minTLSVersion crashes controller #121 OCPBUGS-25161 : Add annotation to CSI driver Pod preventing eviction from the cluster-autoscaler #114 OCPBUGS-25237 : CVE-2023-47108: bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp to v0.46 #115 STOR-1402 , STOR-1453 : update libraries and specify TLS_MIN_VERSION #110 OCPBUGS-22560 : CVE-2023-45142: bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp to v0.45.0 #107 STOR-1276 : Enable support for mounting volumes with SELinux context #93 OCPBUGS-22357 : CVE-2023-44487: bump github.com/openshift/library-go to master #106 OCPBUGS-21593 : CVE-2023-44487: bump golang.org/x/net to v0.17.0 #100 update readme #99  
simplify workload identity feature enablement #92  
update readme #94  
OCPBUGS-19172 : Updating ose-azure-disk-csi-driver-operator images to be consistent with ART #98 Full changelog  
OCPBUGS-33038 : add token audience for Azure File #103 OCPBUGS-25355 : setting TLSSecurityProfile with no minTLSVersion crashes controller #95 OCPBUGS-25161 : Add annotation to CSI driver Pod preventing eviction from the cluster-autoscaler #89 OCPBUGS-25238 : CVE-2023-47108: bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp to v0.46 #90 STOR-1402 , STOR-1453 : update libraries and specify TLS_MIN_VERSION #84 OCPBUGS-22562 : CVE-2023-45142: bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp to v0.45.0 #82 OCPBUGS-22357 : CVE-2023-44487: bump github.com/openshift/library-go to master #81 OCPBUGS-21593 : CVE-2023-44487: bump golang.org/x/net to v0.17.0 #75 update readme #70  
simplify workload identity feature enablement #69  
OCPBUGS-19170 : Updating azure-file-csi-driver-operator images to be consistent with ART #74 Full changelog  
OCPBUGS-37067 : update RHCOS 4.15 bootimage metadata to 415.92.202407091355-0 #8746 OCPBUGS-33354 , OCPBUGS-33402 : Use assisted-image-service for ignition editing #8635 : OCPBUGS-36400: PowerVS: add ibmcloud plugins #8687  
OCPBUGS-36225 : Make vSphere default ResourcePool formatting not contain double slash. #8664 OCPBUGS-35131 , OCPBUGS-35141 , OCPBUGS-35144 : [CVE-2023-48795] Bump golang.org/x/crypto to v0.21.0 #8646 OCPBUGS-35359 : GCP: Prevent cluster installation with mismatched worker assets and worker replicas #8581 OCPBUGS-35502 : [release-4.15] azure: bump profile used for network #8607 OCPBUGS-35586 : [release-4.15] bump github.com/containers/image for CVE fix #8621 OCPBUGS-31387 : If host is offline or disconnected don’t check ver #8208 OCPBUGS-35355 : baremetal: Don’t always enable provisioning-interface.service #8580 OCPBUGS-35032 : [release-4.15] aws: terraform: add spot instance support for masters #8540 OCPBUGS-35059 : images: change libvirt-installer base #8550 OCPBUGS-33672 : add quota support to ca-west-1 #8412 OCPBUGS-33454 : go.mod: bump aws-sdk-go for ca-west-1 support #8381 OCPBUGS-33205 : Gcp bootstraping release 4.15 #8339 OCPBUGS-33542 : images: do not force terraform-providers to be statically linked #8392 OCPBUGS-29929 : GCP Destroy cleanup correct zones/records #8062 OCPBUGS-32383 : sdk/aws: add ssh security group rule for compute #8282 OCPBUGS-32690 : AWS: bump CCO for permission fix #8302 OCPBUGS-32264 : always save serial logs if they were gathered #8274 OCPBUGS-30944 : Don’t run libvirt validations in agent installer #8167 NO-ISSUE: test fix to support slightly different nmstate error messages #8285  
OCPBUGS-32259 : escape ‘%’ in proxy settings #8272 OCPBUGS-32355 : Updated libvirt installer to include multi-arch yq and symlink for backwards compatibility #8277 OCPBUGS-31335 : openstack: Honour worker server group policy #8202 : OCPBUGS-31590: GCP: Skip populating Private/Public Zones within DNS manifest #8220  
OCPBUGS-30922 : coreos-installer iso kargs show broken on Agent ISO #8163 OCPBUGS-30822 : Validate control plane replicas #8143 OCPBUGS-31274 : IBMCloud: Restrict CIS and DNS Service lookup #8197 OCPBUGS-30605 : upi: aws: fix typo in worker templates #8125 Bug OCPBUGS-31284: OpenStack: enable 30000:32767 nodePort IPv6 traffic #8199  
OCPBUGS-31087 : Fix vsi image missing #8186 OCPBUGS-30098 : feat: add check for SNO bootstrap condition #8089 OCPBUGS-30601 : update RHCOS 4.15 bootimage metadata to 415.92.202402201450-0 #8122 OCPBUGS-30854 : Power VS: Fix wait_for_workspace #8159 OCPBUGS-29964 : fix Azure API SKU calls timing out #8086 OCPBUGS-30792 : Enable deploy by Service ID on PowerVS #8138 OCPBUGS-30577 : Authn with platform-services-go-sdk for PowerVS #8118 OCPBUGS-30148 : fix “OpenShiftSDN deprecated” error message #8094 OCPBUGS-30011 : PowerVS: remove IBM-Cloud/bluemix-go/api/account/accountv2 in 4.15 #8076 OCPBUGS-29768 : Power VS: Add sleep to allow workspace to configure PER #8052 Bug OCPBUGS-29726: OpenStack: Fix dualstack with external load-balancer #8050  
OCPBUGS-29495 : gcp: better error msg when service accnt missing #8024 Bug OCPBUGS-29458: OpenStack: fix controlPlanePort validation #8019  
OCPBUGS-29236 : Fixed control plane machine set handling of static IPs when AddressesFromPools is not in use. #7996 OCPBUGS-28841 : PowerVS: Add dal12 region #7977 OCPBUGS-29955 : PowerVS: Add debugging to ServiceInstanceNameToGUID #8065 OCPBUGS-29585 : PowerVS: handle composite_instance #8032 OCPBUGS-29620 : Power VS: Fix service instance list #8035 OCPBUGS-29523 : Bump terraform-provider-ibm to v1.61.0 #8026 OCPBUGS-29436 : PowerVS Fix next start search #8013 OCPBUGS-29442 : update RHCOS 4.15 bootimage metadata to 415.92.202402130021-0 #8016 OCPBUGS-29219 : GCP: Skip validation of public and private zones for terraform vars #7994 OCPBUGS-29201 : Copy GCP manifests within MCO bootstrap to the correct location #7993 OCPBUGS-28822 : aws-edge-zones preventing err before discovering #7973 OCPBUGS-29117 : IBMCloud: Handle disk delete errors #7984 OCPBUGS-26036 : ic: aws: add iam:TagInstanceProfile permission requirement #7866 OCPBUGS-28779 : update tested Azure Arm64 instance type on 4.15 #7971 OCPBUGS-28546 : [release-4.15] Bump containerd for vulnerability fix #7957 OCPBUGS-27346 : Warn that FeatureSet is not supported #7922 OCPBUGS-27417 : baremetal: gather all recently refactored services #7928 OCPBUGS-27380 : set the –cluster-profile flag for openshift/api rendering #7955 OCPBUGS-27894 : duplicate failure domains in CMPS #7951 OCPBUGS-27329 : remove retired serial NCv2 from azure tested instance type list on x86 #7921 OCPBUGS-27850 : PowerVS: COS region configurable #7948 OCPBUGS-27814 : [release-4.15] CORS-2950: Remove openshift-sdn as an install-time option #7935 OCPBUGS-25251 : Changed OKD/FCOS workaround to also support Agent-based Installer #7830 OCPBUGS-27299 : Power VS: Add eu-de-1, eu-de-2, sao04, and wdc07 as supported zones #7913 OCPBUGS-26515 : preserve category name when trying to find tag category #7885 OCPBUGS-27311 : Fix depreciated typo #7912 OCPBUGS-26495 : Fix typo in CloudCredential validation #7916 CORS-3166 : GCP: Add load balancer info to cluster infra #7903 OCPBUGS-27188 : Redact platform passwords in agent-gather output #7910 CORS-3168 : build: only rebuild terraform providers if needed #7853 OCPBUGS-27148 : baremetal: correct external_http_url for v6-only BMCs #7906 CORS-3166 : GCP: Update DNSType within GCP PlatformStatus based on UserProvisionedDNS #7882 OCPBUGS-26495 : Add cloud credential capability validation #7890 OCPBUGS-26511 : Bump default channel to 4.15 #7883 OCPBUGS-26051 : aws: validate instance arch #7868 OCPBUGS-25990 : Fixes for the OpensStack UPI playbooks. #7863 OCPBUGS-24679 : Modify the terraform variables to support Nutanix Failure Domains #7813 OCPBUGS-25463 : IBMCloud: Set IBM TF visibility based on URLs #7844 OCPBUGS-25216 : ic: azure: fix retrieving marketplace image #7829 OCPBUGS-25192 : Revert “Merge pull request #7642 from AnnaZivkovic/azure_duplicate_im… #7827 CORS-2934 : IBMCloud: Update MAPI for BYOK #7812 METAL-803 : Update vendoring for baremetal-operator #7809 no-jira: Fix base image reference #7810  
CORS-2952 : GCP Set “ClusterHostedDNS” in the Infra CR based on the value of userProvisionedDNS #7796 CORS-2813 : Pass LB ConfigMap manifest as a parameter to MCO instance during bootstrap #7662 OCPBUGS-23140 , OCPBUGS-23305 : Soften VIP validations for external load-balancer #7803 AGENT-739 : Support for install-config baremetal host BMC fields #7645 AGENT-729 : Support generic platform name for external platform #7585 MULTIARCH-4042 : Reuse existing Transit Gateway in target Workspace, or create anew #7592 OCPBUGS-23473 : update RHCOS 4.15 bootimage metadata to 415.92.202311241643-0 #7770 AGENT-615 : Split create-cluster-and-infraenv.service #7364 no-jira: image: infra-providers: use base image instead of builder #7800  
no-jira: hack: drop hardcoded -j8 in make invocations. #7799  
OCPBUGS-23458 : force destroy bootstrap ign #7791 OSASINFRA-3261 : OpenStack: support dualstack in UPI #7727 MULTIARCH-2678 : Patch for Agent Based Installer to support s390x as supported architecture. #7712 SPLAT-1218 : AWS BYO VPC support for Wavelength Zones #7652 CORS-2525 : Azure: remove storage account with bootstrap destroy #7642 AGENT-337 : Set VIPs directly in api, instead of install-config override #7574 OCPVE-648 : gomod: bump api version with CloudCredential cap #7466 CORS-2852 : cmd/create: ensure proper cleanup on exit #7693 OCPBUGS-9066 : Retry image download on failure #7106 NO-ISSUE: Remove dead code from ‘networking’ asset #7798  
PowerVS: MULTIARCH-4030: Reintroduce serviceInstanceGUID install option #7795  
OCPBUGS-24191 : set vmType in azure cloud config #7793 no-jira: pkg/asset: safety nets to keep installer from crashing #7792  
CORS-2934 : IBMCloud: Add support for BYOK #7738 OCPBUGS-23539 : Keep Machine manifests out of OpenShift Manifests asset #7753 CORS-3020 : IBMCloud: Bump IBM TF provider #7784 MIXEDARCH-310 : Enable the use of the multi payload for agent installer #7595 CORS-2775 : ic: azure: remove deprecated errors package #7778 SPLAT-1126 : aws/clusterNetworkMTU config to change the MTU for overlay network #7765 CORS-2785 : images: decouple installer and installer-artifacts #7782 MULTIARCH-3793 : Power VS: Add mad and wdc assupported region #7773 CORS-2852 : Generate Cluster API Machine Manifests #7771 CORS-2854 : azure: Allow users to set visibility to components #7547 OCPBUGS-24008 : Remove sno_arm.txt integration test #7718 OCPBUGS-23947 : set client options when interacting with azure api #7768 CORS-2978 : enable AWS SDK Installation through feature gates #7715 CORS-2798 : GCP: User Configured DNS solution to update the bootstrap node with the Load Balancer Information #7631 CORS-2845 : azure: Enable storage account encryption #7520 SPLAT-1277 : unrevert PR 7418; implement vSphere control plane machinesets #7780 OSASINFRA-3303 : OpenStack: remove generation of trunks name #7772 AGENT-670 : Add assisted-db data to agent-gather #7719 SPLAT-1160 : AWS - Support Wavelength Zones with edge pool #7369 Skip cluster config #7666  
OCPBUGS-24031 : Bump Fedora CoreOS to latest stable #7779 no-jira:  destroy: azure: store session in the destroy object #7777  
CORS-2975 : Add support for il-central-1 in AWS #7740 CORS-2428 : terraform: add build information to binaries #7763 OCPBUGS-24026 : Add owner for user provided client CA bundle #7749 SPLAT-1272 : Support Nutanix Failure Domains #7730 CORS-2775 : destroy: azure: remove deprecated errors package #7761 no-jira: cmd/openshift-install: Remove “migrate” command #7601  
no-jira: go.mod: remove unused terraform-providers-nutanix import #7762  
CORS-2835 : pkg/infrastructure: remove ARO build tag #7745 OCPBUGS-21777 : baremetal: populate customDeploy in advance #7674 CORS-2933 : IBMCloud: Basic service endpoint override #7632 CORS-2852 : Introduce Cluster API Infrastructure manifest generation #7672 OCPBUGS-22840 : ic/azure: validate field Plan when for marketplace images #7721 CORS-2604 : tag user-provided azure vnet #7611 MULTIARCH-3964 : Power VS: Control SMT level with machineconfig #7704 no-jira: destroy/azure: fix dropped negation from error comparison #7758  
no-jira: destroy/azure: avoid cancelling main context #7750  
OCPCLOUD-2130 : Fix Failuredomains check on manifests test #7617 OSASINFRA-3295 : OpenStack: fix client used to list flavors #7723 OSASINFRA-3294 : OpenStack: fix script to update bootstrap ignition shim #7743 no-jira: images: rename terraform- > infrastructure-providers #7716  
OCPBUGS-23376 : vSphere - when using RP network path is incorrect #7737 no-jira: Stop rendering networks.config CRD #7732  
OCPBUGS-22453 : Fixed systemd-resolved’s split dns config in OKD/FCOS #7634 SPLAT-1218 : upi/AWS: Templates to provision resources in Wavelength #7722 AGENT-337 : Support both VIP and VIPs in AgentClusterInstall #7724 OSASINFRA-3229 : Remove support for Kuryr #7675 CORS-2830 : Provision AWS Infrastructure with SDK #7676 MULTIARCH-4009 : Prepare for varying SysTypes for new datacenters #7717 MULTIARCH-3789 : Power VS: Remove cloud connection support #7696 CORS-2876 : images/installer-altinfra: initial Dockerfile #7711 Bug OCPBUGS-19462: OpenStack: Fix dual-stack machines Spec to contain network #7694  
MULTIARCH-3965 : Check if PER is enabled in the target PowerVS workspace #7683 OSASINFRA-3280 : openstack: document etcd on local disk #7664 OCPBUGS-23170 : Revert #7418 “SPLAT-1141: implement vSphere control plane machinesets” #7708 MULTIARCH-2590 : PowerVS create service instance #7695 SPLAT-1141 : implement vSphere control plane machinesets #7418 CORS-2428 : images: add Dockerfile for a terraform-providers image #7687 OSASINFRA-3237 : move controlPlanePort API to GA #7570 CORS-2835 : use build tags to produce installer with alternate infrastructure providers #7656 CORS-2877 : Install Config Feature Gate Validation #7413 OCPBUGS-22772 : return Terraform statefile on error #7671 NO-JIRA: destroy/aws: replaced deprecated sets syntax #7680  
OCPBUGS-19398 : IBMCloud: Add eu-es region #7668 OCPBUGS-22830 : fix google cli verson to 447.0.0 #7663 OCPBUGS-22113 : Do not generate azure-cloud-provider in manual mode for aro builds #7608 OCPBUGS-22757 : update RHCOS 4.15 bootimage metadata to 415.92.202310310037-0 #7654 CORS-2852 : Introduce pkg/clusterapi, system, and local control plane #7630 OCPBUGS-20403 : OpenStack: add SG rules for compact clusters on UPI #7576 OCPBUGS-17866 : check GOOGLE_APPLICATION_CREDENTIALS env var #6863 OCPBUGS-22773 : PowerVS: fix removeFromLoadBalancers #7653 OCPBUGS-13664 : Add KMS encryption keys if provided #7650 Bug OCPBUGS-22298: OpenStack: Fix IPv6 address configuration for bootstrap #7638  
OCPBUGS-18387 : Add Azure ConfidentialVM capability and DiskEncryptionSet validations #7469 OCPBUGS-22489 : destroy: gcp: fix destroying regional disks #7643 OCPBUGS-22058 : Bump versions for golang modules to accommodate fixes for CVE-2023-39325 & CVE-2023-44487 #7590 OCPBUGS-18986 : Skip the deletion of instance profiles marked shared #7537 hack/go-lint: update golanci-lint to v1.53.1 #7635  
OCPBUGS-22655 : Bump Fedora CoreOS to latest stable #7644 bootkube.sh: drop final mention of machine-os-content #7636  
update tested x86 instance type on 4.14 #7639  
OCPBUGS-4038 : bootstrap: Skip gatewayd units only on OKD agent-installer #7629 CORS-2852 : Build and package Cluster API and providers #7620 AGENT-713 : Use BM hosts in install-config if not defined in agent-config #7531 MIXEDARCH-353 : Add yq-v4 to the upi-installer image for CI and copy yq3 from a previous stage’s manifest-list image #7567 openstack: dual stack UPI - create security group rules for IPv6 #7552  
OCPVE-740 : bump openshift/api #7613 AGENT-718 : Add vSphere credentials to install-config overrides #7593 Revert #7428 “OCPBUGS-13664: Add KMS encryption keys if provided” #7625  
OCPBUGS-10906 : check extracted base iso coreos version is in sync #7030 OCPBUGS-4038 : bootstrap: Enable gatewayd units only on RHCOS #7580 OCPBUGS-21720 : images/libvirt/Dockerfile.ci: Use centos stream instead centos:7 #6813 CORS-2836 : Refactor Stages, encapsulate terraform #7488 OCPBUGS-20356 : update RHCOS 4.15 bootimage metadata to 415.92.202310170229-0 #7616 OCPBUGS-20364 : azure: validation: validate defaultMachinePlatform #7584 OCPBUGS-20525 : aws: use security groups from defaultMachinePlatform #7589 OCPBUGS-13664 : Add KMS encryption keys if provided #7428 OCPBUGS-5471 : Try to select rendezvousIP among non-worker hosts #7443 OCPBUGS-21781 : Rectify GCP label key validation check #7596 Revert skipping integration test agent sno arm #7561  
OCPBUGS-20350 : vSphere,segfault on version check #7575 OCPBUGS-19093 : skip agent-tui on OCI #7512 OCPVE-675 : feat: bump api to add OLM capability #7495 Enforcing the serial execution of the integration tests #7591  
images: Cleanup CI Dockerfiles #7507  
OCPBUGS-20440 : Warn about host and target compatibility #7582 OCPBUGS-19444 : Use changes to AgentClusterInstall during loading #7506 OpenStack: Adapt nodePorts range 0.0.0.0/0 sg rules #7577  
Remove unused method #7438  
PowerVS: MULTIARCH-3791 Remove cloud connection reuse functionality #7564  
OCPBUGS-19552 : Fixed DNS issues in OKD/FCOS due to split dns in systemd-resolved #7516 docs: Described process of adding vGPU capable nodes. #6606  
OCPBUGS-19086 : Check if nmstatectl executable exists in the system #7492 OCPBUGS-16666 : Change where AdditionalTrustBundle is set #7485 OCPBUGS-18455 : Unable to disable external CCM for platform external #7533 OCPBUGS-18552 : Truncate vlan names defined in nmstate if > 15 chars #7486 OpenStack: enable IPv6 primary dual-stack cluster #7259  
OCPBUGS-20110 : Add an unit test - at least one interface must be defined for each node #7555 OSASINFRA-3199 : Configure User-Agent for OpenStack API calls #7548 OCPBUGS-17757 : check credentials type to handle different gcp authentication methods #7422 Docs: Fix openstack command for image update in upi installation #7556  
PowerVS: MULTIARCH-3790 Remove zones that only have CCs with exceptions #7563  
PowerVS: Remove deprecated errors package #7544  
Disable pxe sno arm integration test #7557  
Inefficient wait for all clusteroperators #7535  
OCPBUGS-15844 : Enable FIPS in agent ISO #7540 OCPBUGS-20058 : Use updated ansible-core for Openstack image #7549 OWNERS: Remove obsolete agent reviewers #7545  
OCPBUGS-5728 : Log “agent wait-for” commands to .openshift_install.log #7452 OCPBUGS-19092 : Enable serial console for external OCI platform #7511 OCPBUGS-18690 : ic: azure: validate NVMe-only family types #7500 CORS-2479 : agent: Ensure registries.conf is world readable #6745 add jbtrystram to coreOS approvers and reviewers #7464  
OCPBUGS-19093 , OCPBUGS-19688 : Allow agent-tui to use serial console #7526 Tweaks to validateRendezvousIPNotWorker #7437  
OCPBUGS-18986 : Tag aws instance profiles. #7510 OCPBUGS-19376 : GCP default value for service account #7519 MULTIARCH-3701 : Enable ppc64le for agent installer #7366 pkg/asset/installconfig/powervs: fix dropped error #7419  
OCPBUGS-19699 : Remove warning about CPUPartitioning #7527 OCPBUGS-18187 : Increase bootstrap timeout for vSphere platform by 30 mins #7518 OCPBUGS-18830 : AWS terraform bootstrap destroy will not refresh state #7491 OCPBUGS-12707 : always write AWS cloud.conf #7514 AGENT-710 : Use invoker for bootstrap template generation #7508 OCPBUGS-18876 : Pass CPUPartitioning via install-config overrides if set #7513 OpenStack: fix IPv6 docs #7482  
OCPBUGS-18945 : update RHCOS 4.15 bootimage metadata to 415.92.202309161058-0 #7499 LICENSE: Update #7502  
OCPBUGS-19286 : Updating ose-installer-artifacts images to be consistent with ART #7496 SPLAT-1170 : enable cloud controller manager type to be defined #7457 OpenStack: Set external network for cloud-provider #7411  
OCPBUGS-17724 : Graceful fail for AWS getUser on destroy #7429 AGENT: publish services diagrams #7323  
OCPBUGS-19149 : Updating ose-baremetal-installer images to be consistent with ART #7494 OCPBUGS-19130 : Updating ose-installer images to be consistent with ART #7493 OCPBUGS-17218 : Warn when firewall rull missing. #7417 OSASINFRA-3236 : deps: Bump gophercloud to v1.6.0 #7208 OCPBUGS-19037 : Handle agent tui failure gracefully #7490 OCPBUGS-19017 : Add Net capabilities to dnsmasq container #7487 OCPBUGS-18113 : Do not set FailureDomains on CPMS when in a single zone Azure region #7448 AGENT-702 : Generate minimal ISO for external platform #7450 OCPBUGS-18304 : for vsphere ipi add cluster domain to the uploaded vm configs so that… #7451 Implement workaround to allow SNO installations for OKD/FCOS #7445  
Full changelog  
OCPBUGS-33547 : update azure and ash tolerations on node manager #343 Bug OCPBUGS-32246: Allow to patch events in OpenStack RBAC #339  
OCPBUGS-25751 : Add Snyk file to exclude vendor directory on scan #314 OCPBUGS-26480 , OCPCLOUD-1724 : GCP Credentials req. manifest of CCMO to use new API field #320 OCPBUGS-26210 : Adds CloudConfigTransformer for Azure #319 OCPVE-788 : annotate credentials request manifests #293 Undo TRT-1378: Revert for “OCPCLOUD-2278: Add kube-rbac-proxy container & ensure metrics are only available via HTTPS” #306  
TRT-1378 : Revert #304 “Undo TRT-1374: Revert for \“OCPCLOUD-2278: Add kube-rbac-proxy container & ensure metrics are only available via HTTPS\”” #305 Undo TRT-1374: Revert for “OCPCLOUD-2278: Add kube-rbac-proxy container & ensure metrics are only available via HTTPS” #304  
OCPBUGS-24127 : Updating ose-cluster-cloud-controller-manager-operator-container image to be consistent with ART #302 TRT-1374 : Revert #301 “OCPCLOUD-2278: Add kube-rbac-proxy container & ensure metrics are only available via HTTPS” #303 OCPCLOUD-2278 : Add kube-rbac-proxy container & ensure metrics are only available via HTTPS #301 OCPBUGS-23996 : trust bundle CA controller: add owner annotation for ccm-trusted-ca configmap #300 OCPBUGS-23308 : Set IPFamilyPriority and ExcludeNetworkSubnetCIDR for vSphere IPv6-only #299 OSASINFRA-3289 : OpenStack: Remove Kuryr bits #294 OSASINFRA-3284 : Add Events to OpenStack’s RBAC #292 OCPBUGS-20213 : Add azure cloud config transformer #291 Update OWNERS #290  
OCPBUGS-17652 : apply necessary RBAC for the alibaba cloud controller manager #276 OCPBUGS-18841 : Additional permissions for internal load balancer on STS #287 OCPCLOUD-2188 : Bump k8s packages to v1.28 #285 update readme to stable status #286  
OCPBUGS-19205 : Updating ose-cluster-cloud-controller-manager-operator images to be consistent with ART #278 OCPBUGS-18641 : Set dual-stack IPFamilyPriority for vSphere #279 OCPBUGS-18841 : Ensure subnets read permission for granular roles #281 OCPBUGS-14718 : Add message for CABundleControllerDegradedCondition error #275 Full changelog  
OCPBUGS-36151 : Set required-scc for openshift workloads #420 OCPBUGS-26542 : remove duplicate manifests in image #395 OCPBUGS-28622 : Add required PSa labels #402 Revert “OCPBUGS-19106: Updating ose-cluster-config-operator-container image to be consistent with ART” #388  
OCPBUGS-19106 : Updating ose-cluster-config-operator-container image to be consistent with ART #385 read featuregates from openshift/api #349  
yield CRDs and empty resource rendering to api imge #379  
CNF-10479 : Bump up api to pull mixed cpu allocation feature gate #386 NP-793 : Bump github.com/openshift/api #375 create manifest directory during rendering #382  
SPLAT-1272 : Update for Nutanix failure domains api changes #378 create parent dir for output #381  
Allow split rendering between cluster-config and openshift/api #380  
MON-3480 : Add MetricsServer FeatureGate #377 NO-JIRA: pkg/cmd/render/config: Remove ReadFeatureGateV1OrDie #361  
MCO-813 : add MCN featuregate #368 SPLAT-1127 : bring in vSphere CPMSO API updates #342 OCPBUGS-21781 : Update openshift/api package to latest version #365 OCPBUGS-21744 : bump library-go to include switch to HTTP/1.1 #366 CFE-887 : Bump openshift/api to add DNSNameResolver. #364 Enable ValidatingAdmissionPolicy in TechPreviewNoUpgrade. #358  
OCPBUGS-20164 : Remove Build CRD #360 Remove AdmissionWebhookMatchConditions feature gate #359  
OCPVE-708 : feat: bump(api) #357 OCPCLOUD-1989 : Promote GCP CCM from TPNU to default #319 OCPBUGS-19106 : Updating ose-cluster-config-operator images to be consistent with ART #353 CCO-412 : Bump API to promote azureWorkloadIdentity to defaultFeatures #351 Full changelog  
OCPBUGS-36377 : Set required-scc for openshift workloads #211 OCPBUGS-31599 : create suitable role and roleBinding for csi-snapshot-webhook #203 OCPBUGS-25240 : CVE-2023-47108: bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp to v0.46 #180 OCPBUGS-24099 : Updating ose-cluster-csi-snapshot-controller-operator-container image to be consistent with ART #176 STOR-1402 : Chore: update libraries in all operators [4.15] #175 OCPBUGS-22569 : CVE-2023-45142: bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp to v0.45.0 #173 OCPBUGS-22357 : CVE-2023-44487: bump github.com/openshift/library-go to master #172 OCPBUGS-21593 : CVE-2023-44487: bump golang.org/x/net to v0.17.0 #166 STOR-1443 : Restart webhook Pods if csi-snapshot-webhook-secret changed #157 OCPBUGS-19162 : Updating ose-cluster-csi-snapshot-controller-operator images to be consistent with ART #160 OCPBUGS-3680 : Move readonlyRootFilesystem to the right place #159 Full changelog  
OCPBUGS-34809 : Ensure that the node-identity webhook address contains colons for IPv6 #2396 OCPBUGS-36347 : Create the configmap mtu if not found #2426 OCPBUGS-36499 : [release-4.15] Bump Openshift API and backport configurable subnet knobs (transit / join / masquerade) #2375 OCPBUGS-36367 : update whereabouts crd #2427 OCPBUGS-32989 : Add conditions for ignored-namespaces #2379 OCPBUGS-29739 : Run dhcp-daemon pods as system-node-critical priority #2283 OCPBUGS-34596 : Add ipsec state metric #2389 OCPBUGS-32515 : Fix wait logic for IPsec certificate signing request #2348 OCPBUGS-29092 : Add probes to node-network-identity #2253 OCPBUGS-29654 : Fully disable network-node-identity on ROKS #2314 OCPBUGS-30927 : ensure local networking deployments within hypershift use the client side load balancer to be resilient to control plane node failures #2310 OCPBUGS-30615 : Fix managed cluster detection on ARO #2304 OCPBUGS-29090 : network-node-identity mounts secrets with mode 0640 #2251 OCPBUGS-29390 : ipsec: fix openssl typo #2272 OCPBUGS-29522 : Not set CNO to degraded if API server returns conflict error #2275 OCPBUGS-29654 : [release-4.15] Disable network-node-identity on ROKS #2278 OCPBUGS-29299 : Update ingressconfig_controller to use field Manager #2265 OCPBUGS-28902 : Fix CloudPrivateIPConfig CRD in common #2263 OCPBUGS-29082 , OCPBUGS-29150 : Remove libreswan rpm existence checks #2255 OCPBUGS-28778 : add env var in whereabouts-reconciler daemonset #2242 OCPBUGS-27421 : Only reconcile on Node updates with Label changes #2212 OCPBUGS-27199 : Remove egressip write permissions from ovn-kubernetes-node #2203 OCPBUGS-27174 : network node identity: tolarate all taints #2202 NP-905 , OCPBUGS-28902 : Bump openshift API #2247 OCPBUGS-28904 : [release-4.15] Restrict live migration to standalone managed clusters #2243 NO-JIRA: add kyrtapz as reviewer and approver for release 4.15 #2227  
OCPBUGS-28214 : Not update migration conditions when any MCP is updating #2223 OCPBUGS-27777 : Deploy CNO IPsec MC even if user already have one #2215 OCPBUGS-25652 : fix whereabouts conformance test failures #2168 OCPBUGS-27748 : [release-4.15] Add ConfigMap mount to the whereabouts-reconciler #2214 OCPBUGS-27198 : [release-4.15] Update ovn-k managed control-plane RBAC #2204 OCPBUGS-27286 : Use specific permissions for CNCC in GCP #2190 OCPBUGS-27001 : Keep the live migration annotation consistant with the enhancement doc #2194 OCPBUGS-27186 : Ns ipsec 4.15 #2200 OCPBUGS-25864 : HyperShift, network-node-identity: Check the deployment in the management cluster #2180 OCPBUGS-24036 : remove all managed fields used by old manager #2167 OCPBUGS-25312 , OCPBUGS-25921 : Avoid removal of ipsec-host daemonset when node is NotReady #2181 OCPBUGS-24148 : Updating cluster-network-operator-container image to be consistent with ART #2133 OCPBUGS-22710 : Set enable-multi-external-gateway flag in ovnkube.conf #2158 OCPBUGS-19817 , SDN-4162 : Upgrade IPsec with single daemonset pod #2087 NP-615 : Live migration #2091 OCPBUGS-23161 : Set logging for controller-runtime #2129 SDN-4061 : Remove interconnect upgrade logic, single-zone YAMLs and everything related to OVNK centralized architecture #2101 OCPVE-779 : Annotate credentials request manifests #2105 NP-615 : Bump github.com/openshift/api #2138 SDN-4308 : Update status merge for APBRoute and EgressFirewall. #2132 OCPBUGS-22710 : Add apbroute/status patch rights for ovnkube-node to update status #2139 NETOBSERV-1047 : Add a cluster monitoring dashboard for ovn #1871 OCPBUGS-21924 : Bump library-go #2082 SDN-4101 : Remove HyperShift API dependency, Bump kubernetes dependencies #2128 NO ISSUE: add ownership of the proxy-ca #2111  
OCPBUGS-22869 : hypershift, hosted clusters: enable multi-homing and multi-net features #2113 OCPBUGS-23082 : set automountServiceAccountToken to false for hypershift managed network-node-identity deploy #2100 OCPBUGS-21924 : Bump golang.org/x/net to v0.17.0 #2068 OCPBUGS-18088 , OCPBUGS-18089 : ovnkube: container scripts cleanup [v2] #2060 OCPBUGS-11179 : change CNO to use custom ServiceAccount #2084 two replicas for CM instead of 3 #2052  
OCPBUGS-15817 : Egress router: request at least 100 milliCPU #2077 OCPBUGS-18785 : SDN controller manifest: add node name from downward kapi to sdn controller #2047 OCPBUGS-19370 : Added HCP label to CNO pods #2048 OCPBUGS-15220 : Add zone node preference to multus-admission-controller #1795 multinetworkpolicy: allow Neighbor Discovery Protocol traffic #2010  
OCPBUGS-18569 : hypershift: adjust backoff on infrastructure name retry #1986 OCPBUGS-20533 : Revisit cipher suits for multus-admission-controller’s rbac-proxy #2074 OCPBUGS-10652 : ovnkube: disable conntrack on hybrid overlay VXLAN ports #1819 Make APB External Route namespace selector mandatory for a dynamic hop #1929  
OCPBUGS-20519 : hosted cluster upgrade failure from 4.13 stable to 4.14 #2065 Revert “Merge pull request #2037 from dcbw/db-script-cleanup” #2058  
OCPBUGS-18392 : notify when /etc/openvswitch path changes #1989 OCPBUGS-18088 , OCPBUGS-18089 : ovnkube: container scripts cleanup #2037 Remove ability to deploy with Kuryr #2056  
OCPBUGS-20104 : Don’t run network node identity as root #2051 OCPBUGS-20076 : Multus should determine kubeconfig path #2049 Revert Kuryr MTU fixes #2038  
Fix MTU miscalculation #1778  
OCPBUGS-19918 : get ipsecStatus from host daemonset #2042 Network metrics daemon: change priority class to openshift-user-critical #2044  
OCPBUGS-14819 : HyperShift: Use the local konnectivity proxy when checking proxy readiness #1985 OCPBUGS-19861 : Multus per-node certificates should have 24h duration #2039 OCPBUGS-19418 : Relax conditions to get IC upgrade started #2018 OCPBUGS-18396 : Fix config status MTU migration not being updated #2021 OCPBUGS-19705 : Use port 9108 for ovnkube-control-plane metrics #2031 OCPBUGS-19715 : Do not enable node admission webhook if the CNI is not OVN-Kubernetes #2030 OCPBUGS-17391 : remove prestop hooks for northd, sbdbd and nbdb #1978 OCPBUGS-19625 : Multus per-node certificate request #2009 OCPBUGS-19377 : Kuryr: Fix deriving MTU from previous config #2007 OCPBUGS-19648 : Network identity: node-specific certificate in ovnkube-node, admission webhook #1983 OCPBUGS-19550 : multus: set MULTUS_NODE_NAME to filter pods to local node #2020 OCPBUGS-19018 : use $CPE_NAME to find the OS major version #2003 OCPBUGS-19494 : ipsec: remove preStop from host #2015 OCPBUGS-18114 : Update node selector in various YAMLs #1845 Limit OVN-Kubernetes permissions #1982  
OCPBUGS-18892 : make ipsec.service required #1999 OCPBUGS-19236 : Updating cluster-network-operator images to be consistent with ART #2006 separate libovsdblogs from main ovnkube-master logs #1938  
OCPBUGS-15201 : Disable weak SSH cipher suites #1981 OCPBUGS-18676 : ovnkube: set northd backoff-interval and use a single thread to save CPU #1990 OCPBUGS-17380 : ipsec: fix oopsy from 2e3fc8e7a0 #1996 OCPBUGS-18517 : Kuryr: Set MTU on Bootstrap, not Render phase #1988 Full changelog  
OCPBUGS-36355 : Backport fix for OCPBUGS-30647 (#1095) #1095 OCPBUGS-33929 : Negative net interface name does not reduce queues (#1066) #1066 Add a ‘.snyk’ to silence static code analysis warnings (#1001) #1001  
fix extra-reboot on upgrade with paused mcp worker (#1049) #1049  
fix rendering extra ctrcfgs (#975) #975  
OCPBUGS-31694 : E2E: Workload hints test cases fixes  (#1012) (#1043) #1012 Reduce number of reboots in offline tests (#1014) #1014  
Systemd processes not being moved to cpuset/systemd.slice fix (#1016) #1016  
Scheduler plugin: ignore IRQs (#983) #983  
e2e: when crun is enabled by default skip checking runc config (#1013) #1013  
OCPBUGS-30507 : Add performance real time tuned template (#984) #984 Report duplicate priority only for multiple matching profiles (#965) #965  
hack: fix backport of render-sync.sh (#996) #996  
OCPBUGS-29752 : [release-4.15][manual] backport performance profile owner reference ehnancements (#963) #963 Render: Add MCSelector to missing default MCPs (#959) #959  
Add support to inject owner-ref argument to render command (#966) #966  
OCPBUGS-29376 : Mixed CPUs e2e tests (#952) #952 OCPBUGS-27227 : irqbalance: set banned cpus list to ‘0’ (#953) #953 OCPBUGS-29396 : Labels for e2e testing  (#949) #949 OCPBUGS-29376 : e2e: cgroups: introduce cgroup package (#942) #942 makefile: add target to trigger mixedcpus e2e test (#941) #941  
OCPBUGS-27948 : Tuned rendering and MCP detection improvements (#928) #928 OCPBUGS-25982 : E2E: Add tests for Dynamic ovs pinning (#904) #904 rps: fail silently when rps application failed (#897) #897  
OCPBUGS-25596 : Make MC names deterministic (#888) #888 OCPBUGS-25552 : rps: fix mask update for SR-IOV devices (#886) #886 OCPBUGS-24638 : Do not set default RPS sysctl twice (#869) #869 cpuset-configure: exit gracefully on cgroup v2 (#866) #866  
CNF-7610 : Mixed CPUs plugin deployment support (#853) #853 New MachineConfig render command (#844) #844  
Report duplicate profiles as ERRORs (#864) #864  
CNF-10473 : featuregates: main: add feature gates support for PAO controller (#858) #858 e2e:latency: omit LatencyTestRun env variable (#857) #857  
OCPBUGS-18649 : E2E: PPC Test cases (#708) #708 OCPBUGS-18640 : Fix Racing Machine Configs and add Day 0 Support (#854) #854 Avoid k8s.io/kubernetes as dep (#848) #848  
Remove most //nolint:* overrides (#837) #837  
CNF-10294 : main: remove deprecated multi ns function (#770) #770 OCPBUGS-22519 : bump opentelemetry package (#840) #840 Disable HTTP/2 for webhook and metrics servers (#834) #834  
Remove obsolete protocols and weak ciphers (#827) #827  
OCPBUGS-18662 : rps: trigger udev even per queue (#816) #816 render: change dir path (#824) #824  
Makefile: remote tmp folder on clean target (#823) #823  
Add golangci-lint (#793) #793  
Updating cluster-node-tuning-operator images to be consistent with ART (#795) #795  
fix: add if check for no resource match error (#801) #801  
nto: avoid timeout when there are too many CSV (#731) #731  
Set non-default UserAgent for easier debugging (#807) #807  
Improve co/node-tuning operand version reporting (#792) #792  
Add the k8s reporter to the configuration suite (#815) #815  
OCPBUGS-18783 : e2e: perfprof: enhance the scheduling domain tests (#791) #791 Add kubeconfig path for IBM Managed OpenShift (#810) #810  
Add k8s reporter to e2e tests (#666) #666  
OCPBUGS-19459 : check for object being nil (#804) #804 Memory manager E2E test fixes (#784) #784  
Some unit tests fail with go1.19 as some modules require 1.20 (#794) #794  
e2e: add expected max latancy to hwlatdetec test & rename constant (#719) #719  
OCPBUGS-18662 : e2e:rps: improve logging (#787) #787 Full changelog  
OCPBUGS-24077 : Updating ose-cluster-platform-operators-manager-container image to be consistent with ART #104 manifests: Simplify filenames for default runlevel #101  
Makefile: Drop yq prerequisite from ‘manifests’ target #103  
OCPBUGS-22457 : manifests/0000_50_cluster-platform-operator-manager_07-aggregated-clusteroperator: Drop namespace #100 switch to bingo for dependency management (and bump golangci-lint@v1.51.0) #95  
OCPBUGS-20511 : Bump golang.org/x/net to v0.17.0 #92 OCPBUGS-19118 : Updating ose-cluster-platform-operators-manager images to be consistent with ART #91 Full changelog  
OCPBUGS-34477 : Import from Git allow users to import an app with Build option Pipeline also when no Pipeline is available #13897 OCPBUGS-36971 : ensure correct API version for OperandDetails #14058 OCPBUGS-34912 : Improve Pipeline list page performance #13929 OCPBUGS-33642 : Patch PF dynamic module parser to exclude ‘next’ modules #13849 OCPBUGS-32501 : Pipeline details page Metrics tab crashed due to no custom data #13781 OCPBUGS-34478 : UI inconsistency in topology when application grouping is collapsed #13898 OCPBUGS-34350 : Create Serverless form does not create BuildConfig #13891 OCPBUGS-32029 : Use UserInfo username field when logging out as kubeadmin #13748 OCPBUGS-30208 : Fix asynccache bugs #13807 OCPBUGS-33838 : TaskRuns should not be fetched for Failed PLR’s #13863 OCPBUGS-34703 : fix bug where textarea is not resizable #13913 Revert “OCPBUGS-34550: Dont render ARN mode role field and warning for HyperShift clusters” #13905  
OCPBUGS-33263 : Pipeline list page is crashed when navigating from Search page #13819 OCPBUGS-33166 : Fix NAD always on default namespace #13865 OCPBUGS-31863 : make sure folder is encapsulated with quotas #13737 OCPBUGS-33506 : Fix Pipeline details page with when expression using CEL expression #13835 OCPBUGS-32505 : Add visual connector between VMs and non VMs workloads #13782 OCPBUGS-33548 : restrict Masthead logo to max-height #13839 OCPBUGS-32497 : Improve Create serverless function error message #13778 OCPBUGS-33191 : Hide dev perspective Pipelines nav option if dynamic plugin nav option is enable #13810 OCPBUGS-33058 : fix issues with Edit Route form #13800 OCPBUGS-32187 : Add flag to hide Output tab contributed by pipelines-plugin #13756 OCPBUGS-32716 : Helm Plugin’s Catalog incorrectly renders a single index entry into multiple tiles #13788 OCPBUGS-32506 : setting correct image trigger annotation #13783 OCPBUGS-32933 : change OperatorHub filter FIPS Mode to Designed for FIPS #13796 OCPBUGS-31799 : Improve PipelineRun list view performance #13731 OCPBUGS-32796 : auth: fix OIDC logging out #13793 OCPBUGS-31445 : Upgrade Pipeline trigger resources to v1beta1 #13704 OCPBUGS-31045 : fix for execute inline markdown syntax issue #13681 OCPBUGS-32518 : Add warning about service binding operator will not be supported from 4.15 #13784 OCPBUGS-32391 : Routes created by devfiles do not always use HTTPS #13771 OCPBUGS-32340 : Increased max nodes limit to 200 in topology page #13767 OCPBUGS-32399 : Update devfile library to v2.2.2 #13762 OCPBUGS-32156 : TaskRun status is not displayed near the name #13752 OCPBUGS-31806 : Use bearer-token for local dev with auth #13732 OCPBUGS-31839 : fix bug where paused MCPs were incorrectly unpausing w… #13735 OCPBUGS-31105 : Update to pf5.2 to fix quick starts #13686 OCPBUGS-31476 : Requesting for country codes in localization of openshift - webconsole #13707 OCPBUGS-31046 : Application creation fail when manually entering input scaling value in local setup #13682 OCPBUGS-30916 , OCPBUGS-30917 : PipelineRuns in Console show wrong status or load indefinitely #13672 OCPBUGS-30869 : TaskRun with same name in different project don’t show 2 entries when listing in all namespace #13668 OCPBUGS-31107 : Upload Jar form’s Clear button is not functioning #13688 OCPBUGS-30759 : Fix bugs in Console dynamic plugin SDK webpack code #13678 OCPBUGS-30871 : fix Configure link in AlertmanagerReceiversNotConfigur… #13669 OCPBUGS-29963 : i18n upload/download routine task - chore(i18n): update translations #13670 OCPBUGS-30801 : Switch to service to get the PLR and TR logs from the Tekton results summary API #13663 OCPBUGS-30275 : adjusting documentation links for 4.15 #13648 OCPBUGS-30870 : chore(i18n): update translations: Completed OCP-4.15/Master Branch/Sprint 245 #13641 OCPBUGS-25831 : Date&Time values are not showing as per browser default language #13467 OCPBUGS-29080 : make getGroupVersionKindForResource null safe #13582 OCPBUGS-29781 : Fix operands list endpoint. #13633 OCPBUGS-29812 : Changes to prevent yaml editor crash in version 4.15 #13638 OCPBUGS-29842 : Switch to service from external result route endpoint #13627 OCPBUGS-28889 : VolumeSnapshots data not displayed in PVC >  VolumeSnapshots tab #13570 OCPBUGS-27431 : Add source maps to production builds #13526 OCPBUGS-26481 : Tab VolumeSnapshots crashed on PVC page #13490 OCPBUGS-25984 : Fix config ini format #13475 OCPBUGS-29844 : Enable catalog source badge to truncate for long names #13629 OCPBUGS-29846 : Prevent complete page reload when changing perspective #13631 OCPBUGS-29845 : Page fails to return to the Secrets list after clicking ‘Cancel’ on any Secret creation page #13630 OCPBUGS-29843 : improve empty state message for Machines and MachineSets page #13628 OCPBUGS-29679 : TaskRuns list page is loading constantly for all projects #13618 OCPBUGS-29640 : Output image url link leads to 404 for Shipwright Builds #13615 OCPBUGS-28232 : do not deduplicate ImageManifestVulns in Overview popover #13545 chore(i18n) OCPBUGS-28623: update translations: : Completed OCP-4.15/Master Branch/Sprint 244 #13594  
OCPBUGS-26567 : Fixed some problems in topology Chinese translation text #13498 OCPBUGS-29914 : [release-4.15] Use selfsubjectreview API from frontend #13636 OCPBUGS-29345 : Any namespace after deletion is still visible on UI if it is the default selection in namespace dropdown #13599 OCPBUGS-29096 : Add TaskRun tab in PLR details page using plugin #13584 OCPBUGS-29217 : Revision tab and routes tab in serving details page showing no resource found #13590 OCPBUGS-26411 : Logs for PipelineRuns fetched from the Tekton Results API is not loading #13486 OCPBUGS-28537 : remove “openshift-storage” namespace usage from the console #13548 OCPBUGS-29283 : Error in displaying BuildRun logs in Console #13595 OCPBUGS-28917 : Optimize federation of shared PF5 code for dynamic plugins #13566 OCPBUGS-29022 : fix i18n for Remove volume modal #13575 OCPBUGS-28940 : AUTH-440: fix usersettings identifier creation #13571 OCPBUGS-27012 : update check for the ‘provider’ label on the PackageMa… #13501 AUTH-440 : OIDC: refresh sessions with a refresh token if present #13563 OCPBUGS-28591 : Fixed bug with user feedback where inform the direction of RedHat was not showing up #13551 CONSOLE-3829 , OCPBUGS-27235 : backend: use the k8s SelfSubjectReview API to get info about a user #13514 OCPBUGS-27896 : Add flags checks to hide Pipeline static plugin List and details pages #13536 AUTH-440 : expand options for the OIDC authenticator #13509 OCPBUGS-27909 : fix bug where Expand PVC modal assumes pvc.spec.resou… #13542 OCPBUGS-26439 : Add support for custom segment domains (to load JS and make API calls) #13489 OCPBUGS-27177 : fix bug where Clone PVC modal assumes pvc.spec.resourc… #13508 OCPBUGS-27306 : Copy response code from proxied plugin requests #13518 OCPBUGS-26591 : add additional check to determine if file is binary #13499 OCPBUGS-24812 : Add missing https:// check for an external link #13433 OCPBUGS-26516 : bump helm version to 3.13.2 for OCP 4.15 #13465 OCPBUGS-26041 : fix bug where Update cluster modal will not open #13479 OCPBUGS-26209 : Fix PipelineRun Logs tab navigation #13484 OCPBUGS-25726 : Re-enable and fix pipelines e2e tests #13463 OCPBUGS-25706 : update the checks for showing Archived to Tekton results icon for PLRs and TRs list and details page #13461 OCPBUGS-25707 : fix Observe tab in Topology overview #13462 OCPBUGS-24668 : Follow on logic for only showing VPAs associated with a deployment for a specific project #13447 OCPBUGS-24668 : Only show VPAs that are associated with the selected namespace #13426 OCPBUGS-25324 : fix preferredTab selection on Pipelines page #13443 OCPBUGS-24680 : Backport Add support for Azure Workload Identity / Federated Identity #13428 OCPBUGS-25140 : fix runtime error on Node details Overview when Machin… #13435 OCPBUGS-24678 : Strip ‘Server’ header from proxy response #13427 OCPBUGS-25210 , OCPBUGS-25211 : Fix pipelineRuns loading on repository details page #13439 ODC-7389 : Update OpenShift favicons as well #13420 OCPBUGS-24582 : Updated functions list page to use new hook useParams #13419 OCPBUGS-18401 : add type and text filters to Events integration test #13407 OCPBUGS-13206 : Fix customPythonDeploymentConfig YAML script to create a Pipeline wasn’t working #13149 OCPBUGS-13204 : Fix that customNodeDeployment pipeline YAML script wasn’t working #13148 OCPBUGS-24252 : fix subscription page fields #13416 OCPBUGS-23764 : bump PF dependencies to the latest patch fix #13380 OU-286 : add test-id to panel charts to ease e2e tests when titles change #13340 OCPBUGS-23554 : Fix for monaco editor that happens with yaml is being edited #13414 OCPBUGS-23378 : Set min-width for PF popovers that are being overridden by an inline style #13390 OCPBUGS-23347 : fix vCenter cluster being empty #13209 OCPBUGS-24339 : Do not depend on a global installed lint-staged #13409 OCPBUGS-24399 : Update our overrides css rule to remove list bullet from PF4 ui elements #13406 OCPBUGS-23761 : PatternFly5 update: Fix quick search input background color in dark mode #13398 OCPBUGS-18401 : fix filtering issues on Events #13395 OCPBUGS-23263 : Update i18next-parser dev dependency in console #13330 OCPBUGS-24267 : Cluster configuration fields are not visible #13386 OCPBUGS-22976 : S2I Build Wizard should check for Containerfile in addition to Dockerfile #13378 OCPBUGS-24001 : Fix crash when ArtifactHub Task has no version #13379 OCPBUGS-18371 : Searching for items in quick search is confusing #13381 OCPBUGS-24280 : view sbom link redirection should be based on taskrun annotation #13387 OCPBUGS-24339 : Add note about git hooks and PATH env var to README #13396 OCPBUGS-18542 : Fixed topology package e2e tests #13136 CONSOLE-3852 : remove PatternFly classnames from integration tests #13337 OCPBUGS-24203 : ConsolePlugin metrics must no longer be grouped by the vendor #13383 CONSOLE-3732 : Add option to enable/disable tailing to Pod log viewer #13298 CONSOLE-3705 : Phase 1 of using OpenShift Dynamic Plugin SDK #13188 OCPBUGS-23779 : Fix crash when user clicks on Show tooltips #13382 OCPBUGS-19426 : Edit the secret and add the Chinese in the web-console, garbled characters will be displayed #13333 CONSOLE-3764 : Update husky to v8.0.3 #13320 OCPBUGS-23125 : add access review for impersonate #13345 OCPBUGS-23780 , OCPBUGS-23783 , OCPBUGS-23794 , OCPBUGS-23977 : Bring back the Decorators and Pod Rings around resources in Topology #13376 OCPBUGS-23956 : PatternFly5 update: Remove text decoration for task node on hover #13371 OCPBUGS-23786 : PatternFly5 update: fix code snippet color in quick start in dark mode #13366 OCPBUGS-23770 : After PatternFly5 update: Typology sidebar layout issue #13363 OCPBUGS-23248 : change Alertmanager form to create using matchers inst… #13358 OCPBUGS-23980 : Fix logs streaming auto scroll issue #13377 OCPBUGS-23778 : Apply the correct font-family for the page header action button and menu items. #13375 OCPBUGS-23756 : fix layout of Show tooltips in YAML editor #13374 OCPBUGS-23971 : remove pf-m-grid-md from tables so table headers appea… #13373 OCPBUGS-23927 : fix table layout issue with Identity providers table #13372 OCPBUGS-23769 : PatternFly5 update: fix Topologylist view hover effect #13368 CONSOLE-3793 : add uptime to Node pages #13312 OCPBUGS-23559 : Styling issue in functions list page after PatternFly upgrade #13356 chore(i18n): update translations: : Completed OCP-4.15/Master Branch/Sprint 243 #13253  
OCPBUGS-23923 : fix PipelineRun task logs switcher #13369 OCPBUGS-23775 : After PatternFly5 update: Form error is missing when import a container image #13365 OCPBUGS-23765 : fix dark theme issue for helm release readme modal #13370 ODC-7359 : Fix shipwright build e2e tests #13296 OCPBUGS-23787 : PatternFly5 update: fix Quickstarts catalog item count alignment #13367 OCPBUGS-23776 : After PatternFly5 update: Add page > more button dropdown is too wide #13361 OCPBUGS-23768 : After PatternFly5 update: Navigation: Extra space after divider #13362 OCPBUGS-23912 , OCPBUGS-23918 : Add Vulnerabilities column and signed icon in PAC repository PLR list #13364 ODC-7426 : Deletion of pipeline run after tekton result installation should be user-friendly #13353 OCPBUGS-23388 : Pipeline Name gets changed to “new-pipeline” on the Edit Pipeline YAML/Builder #13344 ODC-7389 : Replace topology graphic with new version for openshift v4.15 #13350 OCPBUGS-23543 : Deployment option is missing in ‘Deploy Image’ #13354 ODC-7428 : Update quick start name and document links for getting started section #13348 OCPBUGS-22778 : Fix for yaml editor that crashes with MCE and ACM plugins enabled #13346 GITOPS-3575 : Added disallowed flag to gitops static plugin #13307 ODC-7419 : Feature new Quickstarts (RHDH on the admin dashboard and Pipelines/Serverless on the dev add page) #13303 CONSOLE-3693 : Upgrade to PFv5 versions #12983 ODC-7425 : Add serverless function icon in Add page group header #13338 OCPBUGS-20016 : account for useK8sWatchResource returning {} like it does f… #13347 ODC-7383 , ODC-7384 , ODC-7385 : Update the PipelineRun and TaskRun details page to use Tekton Results API to load all the info #13328 ODC-7424 : Add e2e tests for vulnerabilities column in pipelinerun list and details page #13335 OCPBUGS-23164 : Cannot Edit Shipwright Build #13341 ODC-7382 , ODC-7395 : add support for tektonresult api to load PipelineRuns #13311 ODC-7421 : Show vulnerability column in the pipelinerun list page #13329 ODC-7424 : add e2e tests for SBOM section and output tab #13325 OCPBUGS-23292 : Webpack-DevServer Hot-Reload Not Working #13331 CONSOLE-3823 : Split auth config to its own module #13261 ODC-7423 : move pipelinerun results to output tab #13323 ODC-7399 : Create getting started content in functions list page #13289 ODC-7422 : Add SBOM link and signed badge in PLR details page #13314 CONSOLE-3618 : Remove frontend multicluster code #13245 CONSOLE-3777 : Update NodeJS v14 to v18 #13213 ODC-7414 : Update Shipwright API from v1alpha1 to v1beta1 #13304 OCPBUGS-20016 : improve labels and annotations modal display and editi… #13295 CONSOLE-3695 : Add details item extension to console dynamic plugin SDK #13240 CONSOLE-3814 : Conditionally render “Users” and “Groups” nav items #13287 OCPBUGS-23110 : Disable Pipelines E2E Tests #13318 CONSOLE-3740 : Address memory issues in CI #13309 CONSOLE-3614 : Remove multicluster code from Bridge #13244 CONSOLE-3822 : Update obsolete deps #13294 OCPBUGS-22930 : remove expandable toggle for conditional update risk d… #13306 OCPBUGS-22749 : Adjust NAD name by using unique-names-generator #13263 CONSOLE-3781 : remove cypress.config comments #13301 CONSOLE-3819 : change Cypress’ default browser to Electron #13300 OCPBUGS-19916 : Fix MachineSetList capacity logic #13259 CNV-30298 : Add UI for OVN Secondary Localnet Network #13293 OCPBUGS-19875 : Fix plugin proxy handler #13272 CONSOLE-3808 : Remove Protactor from console-plugin-sdk #13283 OCPBUGS-22747 : Display “With Data upload form” in Create PVC drop down once #13292 CONSOLE-3811 : remove shared Protractor files #13282 ODC-7409 : Use @kubernetes-models/shipwright types in shipwright-plugin #13267 CONSOLE-3788 : remove local-storage-operator-plugin Protractor tests #13291 CONSOLE-3788 : remove network-attachment-definition-plugin Protractor … #13286 ODC-7386 : Ensure the Import Form gets submitted without errors if BC is not installed while Pipelines is installed #13145 CONSOLE-3788 : migrate console Protractor tests to Cypress #13257 OCPBUGS-22419 : Fix the forms when BC is not installed in the cluster #13241 CONSOLE-3788 : remove cnv console tests #13280 OCPBUGS-10562 : fix operator uninstall test #13214 CONSOLE-3740 : remove references to removed packages #13281 OCPBUGS-22213 : Fix links for CodeEditor component #13274 CONSOLE-3816 : Goodbye! #13255 OCPBUGS-19458 , OU-241 : Remove unused Observe > Metrics page code #13114 OCPBUGS-20295 : clarify Operator installMode error message #13232 CONSOLE-3740 : fix bug where renamed tests weren’t updated #13275 OCPBUGS-22284 : updating doc links for 4.14 GA #13266 OCPBUGS-22199 : Save also the location.search and .hash values in localStorage to restore them after login #13268 OCPBUGS-22213 : Fix links for CodeEditor component #13265 OCPBUGS-19970 : Workloads-AddPage: upload JAR file’s i18n misses #13264 OCPBUGS-16756 : Cluster dropdown items are not marked for i18n when ACM/MCE installed #13238 OCPBUGS-20362 : Delete results.tekton.dev annotations before rerun the pipelineRun #13230 OCPBUGS-9422 : Telemetry- Current page was sometimes not tracked when reloading the current page #13088 CONSOLE-3740 : check that user dropdown is present to verify logged in #13260 CONSOLE-3812 : remove packages/ceph-storage-plugin/integration-tests #13249 CONSOLE-3809 : remove orphaned OLM Protractor views #13248 OCPBUGS-19783 : Channel page shows “Required” message for the default name when navigate to create channel page #13222 OCPBUGS-20229 : Service details page shows revisions and routes from other service also #13221 CONSOLE-3766 : Update i18next-parser dev dependency in console #13197 CONSOLE-3740 : follow-on fixes and cleanup for Cypress upgrade #13242 OCPBUGS-20305 : Extra space is in the translation text(Chinese) of ‘Create rolebinding’ and ‘replicate rolebinding’ #13236 OCPBUGS-19714 : hide page-specific doc links for ROSA and OSD #13229 chore(i18n): update translations: Completed OCP-4.15/Master Branch/Sprint 242 #13201  
OCPBUGS-21616 : Fix empty editor error #13176 ODC-7401 : Remove protractor from dev-console and knative plugins #13247 ODC-7400 : Fix e2e for dev-console, knative, topology, helm and pipeline packages #13231 CONSOLE-3740 : Upgrade Cypress #13070 CONSOLE-3758 : add support for new features annotations while preserv… #13183 ODC-7396 : Add Pipeline metrics tab using plugin #13225 CONSOLE-3084 : frontend/packages/console-shared/src/hooks/useCanClusterUpgrade: Not ROSA #13184 CONSOLE-3675 : Dynamic Demo Plugin: Add dashboard card with chart using QueryBrowser component #13105 OCPBUGS-20270 : Add instructions to the README for running the monitoring plugin locally #13226 OCPBUGS-16736 : use setTimeout to allow model to be created #13195 OCPBUGS-4242 : Fix CSV list and details page managed namespaces for copied CSVs. #13194 OCPBUGS-19970 : Home-Projects-Default-workloads-AddPage: upload JAR file’s i18n misses #13208 OCPBUGS-19966 : Builds - BuildConfigs : i18n misses #13211 OCPBUGS-19437 : API docs content issue (additional fixes) #13198 ODC-7377 , ODC-7378 : Add Revisions, Routes and Pods tab for service details page #13174 CONSOLE-3763 : Update null-loader dev dependency in console #13154 OCPBUGS-7893 : show all the legends for Pipeline metrics in PipelineRun TaskRun Duration chart #13077 OCPBUGS-14322 : fix ResourceLog permissions when impersonating #13196 ODC-7391 : Add a new allowInsecure option to the internet proxy API #13175 OCPBUGS-19743 : Fix Invalid URL crash #13192 OCPBUGS-18267 : 404 - not found will show on Knative-serving Details page #13156 OCPBUGS-17676 : Enable white space retain in resource logs #13101 OCPBUGS-4426 : All Projects’ dropdown”: Roles and RoleBindings “before all” hook for “test Roles detail page breadcrumbs to list page restores #13190 OCPBUGS-8777 : Don’t redirect after logout from login error route #13102 OCPBUGS-9157 : ‘Create Pod’ button should be disabled for normal user … #13040 OCPBUGS-19640 : Dont render ARN mode role field and warning for HyperShift clusters #13191 OCPBUGS-19437 : API docs content issue #13180 OCPBUGS-19546 : Set unlimited line width in YAML editor #13182 OCPBUGS-19413 : Fix demo dynamic plugin dev mode cypress tests #13172 OCPBUGS-19367 : Console should not panic when no response is retrieved for plugin assets #13166 OCPBUGS-19394 : document kebab menu cell props #13177 OCPBUGS-13152 : fetch TaskRuns without selector and reduces the get TaskRuns requests #13065 OCPBUGS-9719 : Correct logout process #10177 OCPBUGS-18832 : change resource icon for FenceAgentRemediationTemplate… #13162 OCPBUGS-18996 : fix issues with refactored “Create StorageClass” form #13153 OCPBUGS-19173 : Updating openshift-enterprise-console images to be consistent with ART #13157 OCPBUGS-11286 : Check if filtered object contains name property #12810 OCPBUGS-18464 : Hide the Builds NavItem if BuildConfig is not installed in the cluster #13141 OCPBUGS-18494 : Upgrade DomainMapping apiVersion to v1beta1 #13133 OCPBUGS-19314 : Hide the DeploymentConfig option in the User Preferences if that resource type isn’t available #13130 OCPBUGS-6515 : address ConsoleExternalLogLink test flake #13110 OCPBUGS-9285 : Remove redundant break line #13109 OCPBUGS-5571 : Update API docs content based on docs review #13108 OCPBUGS-3403 : Fix resource table sorting crash #13103 OCPBUGS-17203 : mock apis for git repo in test serverless function tests #13064 OCPBUGS-19313 : Hide DeploymentConfig option from forms when it’s not installed in the cluster #13129 OCPBUGS-19311 : Unhide the Import From Git Tab on the Add page if Pipelines Operator is installed and BuildConfig is not installed in the cluster #13128 OCPBUGS-18188 : Added React Icon #13111 OCPBUGS-18485 : Monitoring: Fix display of silenced alerts in dev console #13151 OCPBUGS-6513 : Fixed Edit Application form for Knative Services #12832 OCPBUGS-129 : bump @patternfly/react-core to v4.276.11 to pick up Sele… #13092 OCPBUGS-18439 : use active namespace in Create cta href of create action for operator backed #13132 And 4 elided commits (e.g. from squash or rebase merges) 
Full changelog  
OCPBUGS-31599 : add cmdline args to enable group snapshot webhooks #147 OCPBUGS-29336 : cherry-pick:release-4.15: OCPBUGS-29244 Update VolumeSnapshot and VolumeSnapshotContent using JSON patch #143 OCPBUGS-25521 : Updating ose-csi-external-snapshotter-container image to be consistent with ART #134 OCPBUGS-24330 : Updating ose-csi-snapshot-validation-webhook-container image to be consistent with ART #124 OCPBUGS-24338 : Updating ose-csi-external-snapshotter-container image to be consistent with ART #123 OCPBUGS-24329 : Updating ose-csi-snapshot-controller-container image to be consistent with ART #121 OCPBUGS-24244 : Updating ose-csi-external-snapshotter-container image to be consistent with ART #118 OCPBUGS-24160 : Updating ose-csi-snapshot-validation-webhook-container image to be consistent with ART #116 OCPBUGS-24244 : Updating ose-csi-external-snapshotter-container image to be consistent with ART #117 OCPBUGS-24071 : Updating ose-csi-snapshot-controller-container image to be consistent with ART #115 OCPBUGS-23010 : UPSTREAM: 958: Re-queue SnapshotContents that are readyToUse: false #114 OCPBUGS-21593 : CVE-2023-44487: bump golang.org/x/net to v0.17.0 #108 STOR-1404 : Rebase external-snapshotter to v6.3.0 for OCP 4.15 #107 OCPBUGS-19260 : Updating csi-snapshot-validation-webhook images to be consistent with ART #106 OCPBUGS-19223 : Updating ose-csi-external-snapshotter images to be consistent with ART #105 OCPBUGS-19100 : Updating ose-csi-snapshot-controller images to be consistent with ART #104 Full changelog  
Add support for 64k pages with ARM64 (#141) #141  
MGMT-16313 : Add support for C++ build (#137) #137 Revert “Start using rhel-coreos image rather than machine-os-content (#135)” (#136) #135  
Start using rhel-coreos image rather than machine-os-content (#135) #135  
Updating driver-toolkit images to be consistent with ART (#134) #134  
Full changelog  
OCPBUGS-26993 : Increase data source provision timeout #114 OCPBUGS-25355 : setting TLSSecurityProfile with no minTLSVersion crashes controller #108 OCPBUGS-25161 : Add annotation to CSI driver Pod preventing eviction from the cluster-autoscaler #102 OCPBUGS-25242 : CVE-2023-47108: bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp to v0.46 #103 STOR-1402 , STOR-1453 : update libraries and specify TLS_MIN_VERSION #97 OCPBUGS-22600 : CVE-2023-45142: bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp to v0.45.0 #94 STOR-1276 : Enable support for mounting volumes with SELinux context #81 Add clone test for gcp-pd-csi-driver #92  
OCPBUGS-22357 : CVE-2023-44487: bump github.com/openshift/library-go to master #93 OCPBUGS-21593 : CVE-2023-44487: bump golang.org/x/net to v0.17.0 #86 OCPBUGS-19229 : Updating ose-gcp-pd-csi-driver-operator images to be consistent with ART #85 Full changelog  
OCPBUGS-37266 : extract rhel9 MCO binaries for rhel8 based MCO images #4385 OCPBUGS-36606 : enable audit log for oauth-openshift #4320 HOSTEDCP-1714 : Kubernetes API Server Log Verbosity Annotation cherry pick to 4.15 #4178 OCPBUGS-35736 : Complete KAS migration to none endpoint reconciler type #4228 OCPBUGS-35935 : check mgmt cluster for route capability before DeleteIfNeeded for ovn sbdb route #4265 NO-JIRA: chore(deps): update konflux references (release-4.15) #4259  
OCPBUGS-35714 : Generate default worker security group rules based on machineCIDR #4266 NO-JIRA: chore(deps): update konflux references (release-4.15) #4252  
OCPBUGS-32404 : Fix failure to create a second hostedcluster in the same namespace #3907 NO-JIRA: chore(deps): update konflux references to ff44cf3 (release-4.15) #4246  
NO-JIRA: feat(olm): Set packageserver replicas to 2 for IBMCloudPlatform #4231  
chore(deps): update konflux references to 2be7c9c (release-4.15) #4224  
OCPBUGS-34580 : Add TrustedBundles to OAS container #4211 NO-JIRA: hack: make the e2e script generic #4199  
OCPBUGS-33627 : Restrict image registry overrides to control plane components #4131 OCPBUGS-34156 : fix router on 4.14 y-stream upgrade #4077 OCPBUGS-35002 : [release-4.15] HOSTEDCP-1122: Backport etcd defrag controller #4162 NO-JIRA: Update Konflux references to 1025001 (release-4.15) #4180  
NO-JIRA: chore(deps): update konflux references (release-4.15) #4167  
OCPBUGS-34997 : add AWS STS URL to OIDC provider audiences #4157 OCPBUGS-35074 : Fix disconnected metadata inspection for nodepool #4175 HOSTEDCP-1708 : remove liveness and readiness probes that use the metrics #4128 OCPBUGS-34423 : Fixed audit-logs sigterm failing to terminate gracefully #4089 OCPBUGS-33526 : Disable DNS resolving for CNO #4148 OCPBUGS-34904 : remove weak cipher #4156 OCPBUGS-34510 : Reconcile KAS endpoints and endpoint slice #4097 NO-JIRA: test/e2e: fix prometheus serviceaccount handling against 4.16+ #4151  
NO-JIRA: chore(deps): update rhtap references (release-4.15) #4120  
NO-JIRA: chore(deps): update rhtap references (release-4.15) #4072  
OCPBUGS-33510 : Run haproxy to connect to kas from data plane if noproxy settings contain kas #4014 NO-JIRA: chore(deps): update rhtap references to 7cd8020 (release-4.15) #4064  
NO-JIRA: Remove CLI inspection of release image #4056  
HOSTEDCP-1518 : Preserve container resource requests and limits #4032 NO-JIRA: Update RHTAP references (release-4.15) #4041  
OCPBUGS-33118 : Recycler-pod image now points to the OCP Payload reference #3963 OCPBUGS-32220 : Fix disconnected metadata inspection #3881 NO-JIRA: Update RHTAP references to 1f62eaf (release-4.15) #4030  
OCPBUGS-33117 : Reconcile over ICSP/IDMS #3962 NO-JIRA: Update RHTAP references to 2d39df1 (release-4.15) #4022  
HOSTEDCP-1480 : Update TLS cert hash creation with sha512 #4017 HOSTEDCP-1513 : Support hypershift-operator scoping for hostedclusters #3998 Revert “[release-4.15] OCPBUGS-32013: Set OPERATOR_IMAGE environment variable” #3939  
OCPBUGS-33207 : Remove kube-scheduler readiness probe #3955 NO-JIRA: chore(deps): update rhtap references to c6fdbf4 (release-4.15) #3989  
OCPBUGS-25858 : Improve description for agent APIServerAddress CLI flag #3977 OCPBUGS-33224 : disable OCM pull secret controller when imageregistry config managementstate is Removed #3976 NO-JIRA: chore(deps): update rhtap references (release-4.15) #3982  
OCPBUGS-31747 : update desired image even when HCP doesn’t exist yet #3839 NO-JIRA: chore(deps): update rhtap references to e9efe99 (release-4.15) #3974  
OCPBUGS-32229 : disable autoscaler when no nodepool require it #3884 NO-JIRA: chore(deps): update rhtap references (release-4.15) #3967  
HOSTEDCP-1552 : Update RHTAP tekton files for 0.3 -> 0.4 migration #3957 OCPBUGS-31826 : use dnsPolicy: Default for konnectivity-agent in data plane #3845 NO-JIRA: Update RHTAP references (release-4.15) #3935  
OCPBUGS-32715 : Fix OLM intilization args #3923 HOSTEDCP-1519 : [release-4.15] feat(api): Add ingress-controller-load-balancer-scope annotation #3908 NO-JIRA: chore(deps): update rhtap references (release-4.15) #3921  
OCPBUGS-32164 : Fix ICSP and IDMS inclusion as registriesOverrides #3870 NO-JIRA: chore(deps): update rhtap references (release-4.15) #3904  
OCPBUGS-30280 : Switch to use service endpoint for Konnectivity #3692 OCPBUGS-32191 : Kas disable audit cherry pick release 4.15 #3875 OCPBUGS-32114 : Add new permission required in CAPA #3861 NO-JIRA: Update RHTAP references (release-4.15) #3887  
NO-JIRA: [release-4.15] [e2e test framework] Add a flag to add an annotation to HostedCluster #3893  
HOSTEDCP-1524 : [release-4.15] Support additional node selectors for request serving nodes #3883 NO-JIRA: chore(deps): update rhtap references (release-4.15) #3873  
NO-JIRA: chore(deps): update rhtap references (release-4.15) #3868  
OCPBUGS-32013 : Set OPERATOR_IMAGE environment variable #3853 NO-JIRA: chore(deps): update rhtap references (release-4.15) #3857  
NO-JIRA: Update RHTAP references (release-4.15) #3835  
OCPBUGS-31766 : include hostnetwork SCC CPO role for 4.13 and earlier #3840 HOSTEDCP-1438 : [release-4.15] Preserve container resources for more hosted control plane components #3828 OCPBUGS-31324 : Add missing PodSecurityViolation alert #3798 NO-JIRA: Increase stability in autoscaled environments #3777  
OCPBUGS-31471 : Reduce log file size for hypershift apiservers #3816 OCPBUGS-31604 : disable http2 for ignition server and proxy #3825 OCPBUGS-31426 : copy issuerCertificateAuthority configmap into HC openshift-config #3808 OCPBUGS-31265 : inject built-in MCP selector for KubeletConfigs and ContainerRuntimeConfigs #3802 NO-JIRA: Update RHTAP references (release-4.15) #3812  
NO-JIRA: Remove unused ref to hostnetwork in cpo role #3796  
OCPBUGS-31064 : ibmcloud KMS: remove breaking image check and enable KMS v2 support #3774 OCPBUGS-31377 : Manually cherry pick #3782 to 4.15 #3803 OCPBUGS-31326 : fix(ignition): Fix priority class override #3800 OCPBUGS-30804 : honor HC image configuration #3730 ”[release-4.15] OCPBUGS-30164: Ensure cloud resources are destroyed for all platforms when –destroy-cloud-resources is used” #3677  
OCPBUGS-31116 : external OIDC: fix certificateAuthority field in structured auth config #3783 OCPBUGS-30862 : Manual cherry pick 3685&3727 to release 4.15 #3740 NO-JIRA: chore(deps): update rhtap references (release-4.15) #3791  
NO-JIRA: Update RHTAP references (release-4.15) #3785  
OCPBUGS-29881 : feat(ho): Add flag for dedicated request serving isolation #3633 OCPBUGS-30742 : [4.15] HCP deletion can get stuck if CPO is unable to delete the default worker security group #3726 OCPBUGS-30650 : Set KAS config pod security Enforce to privileged #3719 NO-JIRA: Bump CPO API budget to 4000 in EnsureApiBudget #3741  
OCPBUGS-30651 : Remove EnsurePSANotPrivileged #3744 NO-JIRA: Update RHTAP references (release-4.15) #3754  
HOSTEDCP-1488 : Use regionalized STS endpoints in AWS #3747 NO-JIRA: Update RHTAP references (release-4.15) #3738  
OCPBUGS-30581 : [release-4.15] OCPBUGS-30220: Align PSA labels on guest cluster namespaces with standalone OCP #3684 OCPBUGS-30572 : [release-4.15] Update OLM Default Catalog Sources to 4.15 #3696 NO-JIRA: chore(deps): update rhtap references (release-4.15) #3705  
OCPBUGS-30189 : set Konnectivity cipher suites #3673 ”[release-4.15] OCPBUGS-27500: Fix default release image lookup” #3549  
OCPBUGS-30284 : do not set KAS OAuthMetadataFile with Authentication type OIDC #3694 OCPBUGS-30281 : [release-4.15] OCPBUGS-30102: Support to disable machine management components #3670 NO-JIRA: chore(deps): update rhtap references (release-4.15) #3675  
Update RHTAP references (release-4.15) #3645  
HOSTEDCP-1405 : Remove files not needed #3669 CNV-36056 : Expose NodeSelector for KubeVirt VMs in NodePool #3648 OCPBUGS-30088 : rollout kas on auth config change #3653 NO-JIRA: remove PrivateIngressController cleanup #3646  
OCPBUGS-29880 : feat(config): Default RevisionHistoryLimit to 2 for deployments #3632 OCPBUGS-29025 : cpo: honor user provided oauthmetadata configmap passed in Authentication config #3522 OCPBUGS-30029 : sync AuthenticationConfiguration type with o/k 1.28 carry #3644 NO-JIRA: Red Hat Konflux update hypershift-release-mce-25 #3643  
NO-JIRA: Remove specific pull secret watch in HCCO #3606  
OCPBUGS-29850 : control-plane-pki-operator: fix CA used for SRE client credentials #3626 NO-JIRA: PDB backports #3628  
OCPBUGS-29780 : use 2040 for apiserver svc in IBM provider #3595 OCPBUGS-29435 : Use structured authentication config #3607 OCPBUGS-28543 : Include OperatorHubSpec sync with HC when Config is empty #3480 OCPBUGS-29508 : Default NodeUpgradeType on day2 nodepool creation #3582 MULTIARCH-4084 : Reduce the policy access scope to specific instance #3529 NO-JIRA: Approvers update #3579  
OCPBUGS-27149 : Add storage, csisnapshotcontroller and clustercsidrive… #3421 OCPBUGS-29416 : hypershift-operator: don’t create PKI rbac when disabled #3565 OCPBUGS-29418 : control-plane-pki-operator: add a signer for SRE break-glass #3566 OCPBUGS-29089 : Make ControllerAvailabilityPolicy immutable #3533 OCPBUGS-29310 : control-plane-pki-operator: validate CN for CSR #3558 OCPBUGS-29303 : release-4.15: revocation controller backport #3532 OCPBUGS-29020 : reduce external-dns route53 call volume #3521 OCPBUGS-29179 : [4.15] reflect NodePool replica count nil in status #3473 NO-JIRA: remove unneeded code to copy Authentication refs #3537  
OCPBUGS-29029 : Add ValidatingAdmissionPolicy to KAS config #3523 OCPBUGS-28764 : node spread anti-affinity for HA HCP #3495 OCPBUGS-28603 : Remove webhook validations that introduce resource ordering #3515 OCPBUGS-28594 : backport API moves #3482 HOSTEDCP-1272 : Added CLI support to create DualStack clusters using default values #3502 OCPBUGS-27818 : Add GC knobs for KAS #3457 OCPBUGS-27103 : hcco: use manual mode for CCO #3420 NO-JIRA: kubevirt, e2e Add additional network test #3499  
CNV-37394 : Remove ‘–attach-default-network’ from productized cli #3500 OCPBUGS-27380 : indicate cluster profile to render the correct manifests #3465 OCPBUGS-28235 : Required RBAC for network-node-identity is not created when hosted cluster networkType is set to Other. #3467 OCPBUGS-27432 : consider HCP upgradeable if CVO has no upgradable condition #3444 HOSTEDCP-1374 : external OIDC: copy Authentication OIDC client secrets through to guest #3393 OCPBUGS-27076 : availability-prober: wait for infrastructure name to be set #3419 OCPBUGS-27155 : Change KAS bootstrap image to cluster-config-api #3423 OCPBUGS-27071 : Apply Scheduling Configuration for kCCM #3417 OCPBUGS-26600 : set KAS runtime-config in alignment with feature gates #3399 OCPBUGS-26412 : Set new condition on SG deletion. #3381 OCPBUGS-26410 : Disable UWM Telemetry remote writer when MGMT cluster is disconnected #3380 OCPBUGS-26410 : Disable UWM Telemetry writer when telemeter-client cm not exists #3379 OCPBUGS-26223 : hostedcontrolplane: don’t start pki operator when disabled #3376 OCPBUGS-25782 : Added support for OLM Disable default sources on HC creation #3321 CCO-511 : control-plane-operator: reconcile the CCO #3336 NO-JIRA: no-op empty commit publish HO 4.15 to MCE 2.5 #3338  
HOSTEDCP-1257 : control-plane-pki-operator: add a CSR flow for break-glass creds #3324 ACM-8466 : Add Kubernetes SCC V2 options to HO containers #3311 OCPBUGS-19271 : Updating ose-hypershift-container image to be consistent with ART #3247 HOSTEDCP-1336 : bump openshift/api #3282 NO-JIRA: Fix wrong annotation on cluster deletion #3289  
OTA-855 : Enable CVO to evaluate conditional updates on self-managed HyperShift deployed on OpenShift #2807 HOSTEDCP-1318 : correct typo for OAS internal-oauth-disabled flag #3278 NO-JIRA: Bump the golang-dependencies group with 3 updates #3254  
OCPBUGS-23126 : Fix a bug on deletion of a hostedcluster #3234 CNV-35774 : Improve CRD defaulting for HostedCluster and NodePool #3116 HOSTEDCP-1322 : NodeUpgradeType defaulted by provider via CLI #3273 NO-JIRA: cmd/cluster/core/dump: Gather PodDisruptionBudgets too #3263  
CNV-34093 : kubevirt: verify release image falls within supported release window #3184 CNV-29003 : Re-enable NodePoolUpgradeTest for KubeVirt (Replace Only) #3189 OCPBUGS-22459 : Add prestop to konnectiviy server #3250 HOSTEDCP-1318 : pass internal-oauth-disable flag to openshift-apiserver when Auth type is OIDC #3244 OCPBUGS-23397 : Set shutdown-delay-duration to 15s #3204 HOSTEDCP-1234 : Add KMS support on Azure clusters using Azure Key Vault #3183 OCPBUGS-23555 : set respondWithChallenges false on CLI OAuth client #3249 WRKLDS-925 : remove duplicate passing of kubeconfig into route-controller-manager #3220 HOSTEDCP-1256 : control-plane-pki-operator: add an operator for managing PKI #3193 HOSTEDCP-1319 : Fix Dependabot & Group Dependency Updates #3246 OCPBUGS-24062 : fix(cpo): Set restart annotation on network-node-identity #3245 kubevirt, hcp, HOSTEDCP-1311: Add multinet knobs #3235  
HOSTEDCP-1312 : Fixed update-codegen.sh to work locally #3214 OCPBUGS-23555 : add CLI oauthclient #3238 HOSTEDCP-1300 : Bump k8s.io/client-go to v0.28.3 #3191 OCPBUGS-19834 : add watch for HCP pullsecret to HCCO #3237 Update RHTAP references (main) #3230  
HOSTEDCP-1236 : Enable public router+external DNS for azure #3233 OCPBUGS-23921 : Use correct kubeconfig in CCM and remove CCMs access t… #3222 OCPBUGS-22473 : Added OLMCatalogPlacement option to the CLI #3206 OSD-19085 : New hypershift_cluster_cores metric giving the total number of worker cores #3089 OCPBUGS-20246 : Added brackets to IPv6 KAS address on kubeconfig #3207 OCPBUGS-23737 : remove machine-approver probes #3227 OCPBUGS-23350 : Added IPFamilyPolicy to services exposed at the HCP in DualStack mode #3210 OCPBUGS-23466 : Let router use svc ips #3218 HOSTEDCP-1256 : api/hypershift: mark more conditions with list key types #3212 OCPBUGS-23472 : unset ServiceAccount on ignition-server-proxy #3209 OCPBUGS-23528 : Fix error when removing finalizer on cluster destroy #3219 HOSTEDCP-1256 : api/v1beta1: annotate hostedcontrolplane conditions #3211 OCPBUGS-23398 : Fixed AWS KMS Backup container args #3216 HOSTEDCP-1311 : kubevirt, Add support for secondary networks #3066 HOSTEDCP-1256 : expose cert rotation scale parameter #3208 OCPBUGS-23314 : SetLogger for CLI #3199 HOSTEDCP-1237 : Retrieve RHCOS VHD image from release image #3177 HOSTEDCP-1284 : Bumps k8s.io/pod-security-admission to v0.28.3 #3181 CNV-23418 : Validate jsonpatch annotation + add condition on wrong patch #3197 HOSTEDCP-1285 : Kas port svc cleanup #3186 HOSTEDCP-1254 : disable deployment of integrated oauth when authentication type is OIDC and set KAS flags #3151 CNV-23418 : fix the jsonpath annotation implemetation #3201 HOSTEDCP-1305 : Simplify HostedControlPlaneNamespace().Name #2619 OCPBUGS-22912 : Set value of elb tag to 1 instead of true #3198 CNV-30444 : Document recommended MTU settings for KubeVirt HCP #3129 HOSTEDCP-1306 : Bump Golang builder to 1.20 for RHTAP dockerfile #3196 NO-JIRA: chore(deps): update rhtap references #3192  
CNV-23418 : unsupported escape hatch mechanism custom HS/KV vms #3187 HOSTEDCP-1256 : generate typed clients for apis #3179 NO-JIRA: *: Fix “succesfully” -> “successfully” typos #3188  
OCPBUGS-20179 : Stop defining time series for hosted clusters or node pools which do not exist anymore. #2671 HOSTEDCP-1285 : Consume kas Pod port by name #3185 OCPBUGS-23083 : adding permission to CNO RBAC Calico path for network-node-identity deploy #3172 HOSTEDCP-1256 : Update Dependencies #3154 HOSTEDCP-1283 : Fixed Azure nodes not joining #3174 HOSTEDCP-1227 : Retrieve CAPZ image from OCP release image #3074 NO-JIRA: fix formatting for releaseImage log #3156  
HOSTEDCP-1206 : Req serving isolation e2e enxebre #3150 OCPBUGS-23015 : Configure HSTS for kube-apiserver #3088 HOSTEDCP-1281 : Fix a bug in the validating webhook #3164 CNV-33847 : KubeVirt: create the etcd encryption key secret, if missing #3148 HOSTEDCP-1278 : Adjustment cluster-cidr,service-cidr to support dualstack #3161 OCPBUGS-10423 : Update regex validation for nodepool.spec.taints.value #3141 OCPBUGS-20161 : Stop exposing kas on 6443 private route service load balancer #3149 OCPBUGS-16079 : No error for overlapping service network and API IP #3067 OCPBUGS-22868 : Fixed accessTokenInactivityTimeout validation #3157 CNV-34094 : Add validating webhook #3132 Stop defaulting aws private haproxy external port to 6443 #3147  
Remove GITHUB_ACCESS_TOKEN requirement from release notes script #3134  
HOSTEDCP-1215 : Use the same etcd snapshot for all replicas during etcd restore #3081 Bump google.golang.org/grpc from 1.53.0 to 1.56.3 in /hack/tools #3136  
OCPBUGS-20033 : Make the OLMCatalogPlacement field immutable #3113 HOSTEDCP-1113 : Improve NodePool CPU arch & platform check #3072 HOSTEDCP-1253 : bump openshift/api for new authentication config #3135 HOSTEDCP-1229 : Move azure cloud provider to out of tree #3086 contrib: increase HC quota to 40 #3140  
HOSTEDCP-1200 : Remove pod exceptions from EnsureNoCrashingPods #3138 run EnsurePSANotPrivileged for TestCreateCluster only #3137  
OCPBUGS-21776 : Cluster-policy-controller: add missing RBAC for privileged namespaces PSA syncer controller #3115 OCPBUGS-21626 : Validate accessTokenInactivityTimeout >= 300s #3110 OCPBUGS-20246 : Added brackets to the kubeconfig server address when IPv6 #3097 Bump golang.org/x/net from 0.13.0 to 0.17.0 #3092  
OCPBUGS-22195 : Fix label selector check for CAPI provider #3108 Bump golang.org/x/net from 0.9.0 to 0.17.0 in /hack/tools #3093  
Update RHTAP references #3062  
OCPBUGS-21822 : Add ign proxy label selector for LabelTopologyZone PodAntiAffinity #3103 OCPBUGS-19419 change trusted bundle volume mount for CPO #3099  
Disabling unused monitoring services #2730  
OCPBUGS-18341 : change required pod anti-affinity rule to preferred rule #3095 SDN-4062 : Revert “SDN-4042: Increase upgrade rollout timers” #3090 CNV-31891 : Document port 80 is not supported with default ingress for KubeVirt #3079 MULTIARCH-3760 : Rename depricated flag for PowerVS capi deployment #3028 HOSTEDCP-1051 addition of grace period for aws infra destruction #2967  
HOSTEDCP-1232 : Add clusterName label to CAPI kubeconfig secret #3087 OCPBUGS-19957 : Reconcile CNCC secret to CPO namespace #3065 OCPBUGS-20105 : OCPBUGS-20109: Update the scheduler to only accept paired Nodes and check scheduler HCs has two Nodes #3077 OCPBUGS-16189 , OCPBUGS-19746 : Added network validations #3047 CNV-30697 : Dedicated CPU for KubeVirt node pool #3048 Add record rules for kas qps #2858  
Fix a typo in KubeVirt troubleshooting script #3073  
HOSTEDCP-1184 : Document IPv6/IPv4/DualStack deployments for Hypershift in Baremetal #3008 Add aws-ebs-csi-driver-operator to allowed NeedManagementKASAccessLab… #3076  
Upate azure docs #3075  
OCPBUGS-13348 : Hypershift Audit configuration not working (part2). #3014 OCPBUGS-11939 , OCPBUGS-18128 , OCPBUGS-18460 , OCPBUGS-18602 , OCPBUGS-18879 : Support Disconnected HCP #2950 Add private link perms to docs and clarify log message #3063  
OCPBUGS-14819 : Add konnectivity-proxy container to CNO #2974 OCPBUGS-19784 : Update capi agent version for CRD label #3050 KubeVirt platform troubleshooting documentation #3055  
Remove EgressFirewall Creation in HCP namespace #3049  
HOSTEDCP-1212 : Bump Golang to v1.20 #3038 Update RHTAP references (main) #3054  
OCPBUGS-15215 : OAuth template config in HostedCluter.configuration.ouath is not honored in HyperShift #3041 Update RHTAP references (main) #3042  
OCPBUGS-19271 : Updating hypershift images to be consistent with ART #3017 Update kubevirt csi driver deployment with proper timeouts #3044  
OCPBUGS-19516 : Upgrade agent APIs to v1beta1 #3022 [kubevirt platform] Detect Suboptimal MTU and raise HostedCluster Condition accordingly #2976  
OCPBUGS-19674 : Report correct port when API exposed via route #3037 OCPBUGS-13829 : set accesstoken-inactivity-timeout flag to openshift-oauth-apiserver #3025 HOSTEDCP-1209 : set ubi Containerfile labels #3039 Use example versions for KubeVirt platform that are supported #3027  
OCPBUGS-17669 : Remove cluster name validation from HCC #3036 KubeVirt: document VMs logs collection #3031  
Update RHTAP references (main) #3033  
OCPBUGS-19381 : Let NodePools skip min version when SkipReleaseImageValidation is in HC #3024 OCPBUGS-19346 : set default deploymentconfig params on AWS CCM #3021 ACM-7278 : Remove marking pull secret as required in hcp cli #3013 OCPBUGS-19332 : Use impersonated client for fetching the localhost-kubeconfig from ma… #3011 Relax network policy e2e for private #3020  
Dump KubeVirt pod logs #3000  
Update RHTAP references #2995  
OCPBUGS-19014 : Apply private-router network policy only if running OCP 4.14 #3012 Validate KubeVirt platform required versioning #2948  
OCPBUGS-18720 : amend OLM catalogs ImageStream according to annotation #3001 OCPBUGS-17906 : reconcile Authentication global config #3009 feat: add _id label to all hypershift operator metrics #2991  
OCPBUGS-18122 : Rename isUpgradeable to isUpgrading according to its return value #2955 OCPBUGS-18762 : unset ControlPlaneReleaseImage on HCP when ControlPlaneRelease is unset on HC #3004 OCPBUGS-18754 : tuned DS should not use controlPlaneReleaseImage #3003 HYPBLD-99 : enable CGO_ENABLED for building FIPS compliant images #2997 e2e: fixed gomega created from parent test context #2987  
bump HO supported version for 4.15 #2927  
HOSTEDCP-1075 : Document instructions for recovering etcd cluster from lost quorum #2952 And 4 elided commits (e.g. from squash or rebase merges) 
Full changelog  
OCPBUGS-36072 : CVE-2024-6104: bump github.com/hashicorp/go-retryablehttp to v0.7.7 #121 OCPBUGS-33641 : [ibm-vpc] Scheduling issue on IBM Cloud Bare Metal nodes #116 OCPBUGS-25604 : Bump go.opentelemetry.io/contrib/instrumentation/net/http/otelgrpc to v0.46 #103 OCPBUGS-25161 : Add annotation to CSI driver Pod preventing eviction from the cluster-autoscaler #99 STOR-1487 : Provide BYOK encryption support for OpenShift on IBM Cloud VPC #93 OCPBUGS-23862 : OCPBUGS-22603: CVE-2023-45142: bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp to v0.46.0 #88 STOR-1402 : Chore: update libraries in all operators [4.15] #92 STOR-1485 : Support for endpoint override from config #89 OCPBUGS-22924 : Removing unncessary imagePullSecrets #87 STOR-1276 : Enable support for mounting volumes with SELinux context #77 OCPBUGS-22357 : CVE-2023-44487: bump github.com/openshift/library-go to master #86 OCPBUGS-21593 : CVE-2023-44487: bump golang.org/x/net to v0.17.0 #80 OCPBUGS-19215 : Updating ose-ibm-vpc-block-csi-driver-operator images to be consistent with ART #78 Full changelog  
OCPBUGS-36012 : CVE-2024-6104: bump github.com/hashicorp/go-retryablehttp to v0.7.7 #41 Updating ibm-vpc-node-label-updater-container image to be consistent with ART #33  
OCPBUGS-21593 : CVE-2023-44487: bump golang.org/x/net to v0.17.0 #26 OCPBUGS-19217 : Updating ibm-vpc-node-label-updater images to be consistent with ART #25 Full changelog  
Fix typo in link to gathers.json #876  
And 38 elided commits (e.g. from squash or rebase merges) 
Full changelog  
OCPBUGS-36863 : Copy RHEL9 binaries used in HCP #4476 OCPBUGS-35220 : Check both ready and health ingress endpoints #4398 OCPBUGS-30139 : [release-4.15] Use NM’s dns-change event for resolv.conf #4220 OCPBUGS-36769 : daemon: Handle correctly OS Version for 4.1 and 4.2 bootimages #4461 OCPBUGS-36550 : MCD-pull: run after network-online.target in Azure #4454 OCPBUGS-27436 : Fix mirrorSourcePolicy error prompt imagecontentsourcepolicies #4431 OCPBUGS-36258 : daemon/update: disable systemd unit before overwriting #4441 OCPBUGS-32092 : Decrease logs of haproxy #4313 OCPBUGS-35010 : set required-scc for openshift workloads #4393 OCPBUGS-31461 : Remove weights from ingress check script #4290 OCPBUGS-33847 : If multiple hostnames are returned, use the first one for the Node name #4373 OCPBUGS-20152 : Don’t error if the certs.d dir doesn’t exist yet #4358 OCPBUGS-32922 : [release-4.15] add cluster fleet evaluation support to mco #4334 OCPBUGS-28926 : [4.15] crio: update pids limit to be -1 #4163 OCPBUGS-28545 : Delete state files on reboot only #4311 OCPBUGS-31820 : Remove the condition for checking the multiple ovs-if-br-ex profiles #4309 OCPBUGS-27029 : Log network service output to console #4113 OCPBUGS-31646 : fix: resources were in the wrong indentation level #4301 : OCPBUGS-31576: kubelet: restorecon necessary files on kubelet’s prestart #4297  
OCPBUGS-30884 : Prevent OVS-configuration to run before kdump #4259 OCPBUGS-31383 : make verify should use MCO’s kube version #4282 OCPBUGS-30971 : add preferredduringscheduling annotation to kube-rbac-proxy-crio #4264 OCPBUGS-29731 : Delete image openshift/openshift-proxy-pull-test #4199 OCPBUGS-30093 : Mount /run/nodeip-configuration into coredns containers #4229 OCPBUGS-30761 : add static pods for rbacproxy #4252 OCPBUGS-30017 : CRI-O: Add missing Devices annotation to CRI-O configuration #4227 OCPBUGS-29339 : annotate on-prem static pods for workload partitioning #4179 OCPBUGS-29797 : set nodeStatusReportFrequency #4211 OCPBUGS-29166 : ovs-configure: fix vlan_parent calculation #4171 OCPBUGS-29651 : nmstate, configure nmstate to keep service yamls #4192 OCPBUGS-29038 : Add existing kubeletconfig/ctrcfg mc-name-suffix annotation #4166 OCPSTRAT-1062 : [4.15] crio: enable log linking by default in 4.15 #4174 OCPBUGS-29105 : On-prem coredns manifests should not be generated for GCP #4169 OCPBUGS-28909 , OCPBUGS-28910 : Run resolv-prepender entirely async #4161 CORS-3169 : Add support for in-cluster DNS on Cloud Platforms when cloud DNS cannot be used #4155 OCPBUGS-28237 : daemon: allow the user to override drains on IR changes #4148 OCPBUGS-27486 : Add Image Credential Provider flags for Kubelet on AWS #4134 OCPBUGS-27307 : Fix typo in AWS node env unit #4130 OCPBUGS-25424 : Add \n in cert_writer for old cert methods and skip cloudCA validation #4077 OCPBUGS-26240 : Azure Run ovs-configuration.service before dnsmasq.service #4101 OCPBUGS-25948 : kubelet: fix kubelet labels #4090 OCPBUGS-25228 : crio: drop automatic image cleanup on upgrades #4072 OCPBUGS-17877 : daemon: Add support for new nmstate logic #4020 OCPBUGS-21597 : Alleviate confusion over mco_state #4000 OCPBUGS-24012 : Add templates for gc_thresh sysctls #4048 OCPBUGS-24035 : execute cert related processes to ensure proper rotation #4050 MCO-681 , OCPBUGS-20427 : Add Key State Metrics, No datapoint found when querying up certain registered metrics #4052 OCPBUGS-19352 : Fix bootstrap with NTO Operator and duplicate MachineConfigs #3972 COS-2526 : CoreOS: Remove imgid field in coreos aleph #4034 TRT-1377 : Revert #4028 “OCPBUGS-22324: Wait for br-ex up event before node-valid-hostname” #4053 TRT-1375 : Revert #3965 “MCO-681, OCPBUGS-20427: Add Key State Metrics, No datapoint found when querying up certain registered metrics” #4051 MCO-664 : adds on-cluster build dev preview docs #3885 OCPBUGS-24177 : fix race for MCN creation #4049 OCPBUGS-15934 : unit test ctrrcfg uses *resource.Quantity to use *resource.Quantity #4044 OCPBUGS-22324 : Wait for br-ex up event before node-valid-hostname #4028 MCO-681 , OCPBUGS-20427 : Add Key State Metrics, No datapoint found when querying up certain registered metrics #3965 OCPBUGS-24019 : Add ownership annotations to TLS artifacts #4045 MCO-795 : MCO-813: MCO-473: Implement Upgrade-Monitor, FeatureGate, and MachineConfigNode types #4012 OCPBUGS-23255 : Add FIPS information to oldconfig when checking if reboot is needed #4033 OCPBUGS-23484 : kubevirt, Activate nodeip-configuration.service #4039 OCPBUGS-23432 : Use shorter IP label for keepalived VIP #4040 OCPCLOUD-1609 : Fix syntax in vsphere-hostname.yaml for CAPI machines #4037 OCPBUGS-23209 : workaround nmstate bug by configuring ipv{4,6} addresses #4026 OCPBUGS-22200 : Retry fetching OpenStack hostname if it fails #3990 OCPBUGS-22721 : Don’t retry node-ip show in resolv-prepender #4017 MCO-772 : controller: allow custom pool configs to take priority #4015 OCPBUGS-18414 , OCPBUGS-18456 , OCPBUGS-18458 : Configures SSH Keys and Password for core, fixes config drift degradation #3946 Use the bridge interface name for ofport request #3998  
OCPBUGS-7638 : typo s/iface_default_hint_file/default_bridge_file/ #4004 OCPBUGS-16871 : MCO - currentConfig missing on the filesystem #3963 OCPBUGS-20369 : Require a hostname override for AWS #3979 OCPBUGS-21814 : bump library-go and k8s dependencies to most recent version #3988 OCPBUGS-19736 : configure-ovs: handle SIGINT and SIGTERM #3982 Add kernel-64k kernelType #3903  
MCO-593 : Consume MCO API and CRDs from openshift/api #3747 Get the nmstate pinned package from kojihub when building on top of a CentOS base image #3954  
CRI-O: Use 127.0.0.1 for stream server with random port #3853  
OCPBUGS-20499 : gcp-routes: don’t exit on crictl failures #3977 OCPBUGS-7638 : Allow specifying the interface for br-ex #3696 OCPBUGS-20338 : dashboard should detect unknown and not ready for not ready dashboard #3964 OCPBUGS-19722 : Informers are setup with incorrect namespace #3955 OCPBUGS-15087 : templates: Introduce kubelet-dependencies.target #3865 OCPBUGS-17841 : Ensure gcp-routes hack for internalLB hairpin traffic works for SGW #3953 OCPCLOUD-1609 : Set guestinfo.hostname for CAPI VMs on vSphere #3949 OCPBUGS-19708 : Support to append the duplicate kernel arguments to the rendered MC #3947 OCPBUGS-18771 : Consider ingress VIPs when selecting node IP #3943 MCO-424 : Drop machine-os-content references #3364 OCPBUGS-19992 : Add v6-primary dual stack support to VSphere UPI #3670 OCPNODE-1799 : support icsp and idms objects #3898 Improve kubelet error log #3914  
OCPBUGS-18772 : Use image exists in resolv-prepender instead of wc -l #3910 MCO-707 : Strip registry transport from os image URL for comparison #3857 OCPBUGS-15583 : Revert “Revert “fix nodeStatusUpdateFrequency”” #3890 OCPBUGS-17811 : add certificate input to bootstrap mcs #3876 MCO-746 : make buildcontroller tests less flaky #3905 OCPBUGS-18902 : Internal Registry Secrets merge causing excessive API calls #3912 MCO-664 : adds e2e for on-cluster build dev preview #3807 Dockerfile: update local copy to OCP 4.15 image #3922  
OCPBUGS-19365 : Ignore invoking nbctl calls if its SDN #3926 OCPBUGS-15910 : After dual-stack conversion reconcile IPFamilies #3909 OCPBUGS-18800 : fix merged image registry CA behavior #3851 mod: Update rpmostree-client-go #3916  
OCPBUGS-13044 : daemon: always use podman cp to copy extensions container content #3921 OCPBUGS-18906 : Remove dependency on k8s.io/kubernetes packages #3913 OCPBUGS-19097 : Updating openshift-proxy-pull-test images to be consistent with ART #3918 OCPBUGS-18772 : resolv-prepender: avoid pulling baremetalRuntimeCfgImage again #3907 OCPBUGS-19179 : Updating ose-machine-config-operator images to be consistent with ART #3919 OCPBUGS-16905 : install: Recreate and delayed default ServiceAccount deletion #3895 MCO-765 : Examine/Remove memory limits on MCO pods #3915 MCO-731 : Move services machine-config-daemon-pull.service and machine-config-daemon-firstboot.service before ovs-configuration.service #3858 MCO-708 : Extract and merge kernel arguments from /proc/cmdline #3856 configure-ovs-network: Add tun device support #3618  
OCPBUGS-11437 : MCO keeps the pull secret to .orig file once it replaced #3759 Full changelog  
NO-ISSUE: Dummy change to force bumping fcos image to 39.20231101.3.0 #33  
NO-ISSUE: Force updating 4.15 CI images #32  
OCPBUGS-19133 : Updating ose-machine-os-images images to be consistent with ART #30 Full changelog  
OU-417 : throw an error when a custom datasource is not found #118 OU-415 : Add datasource parameter to handle metrics from custom datasources #116 OCPBUGS-32097 : make createdBy mandatory and auto fill with the current user #115 OCPBUGS-31310 : upgrade sanitize-html vulnerable dependency #107 OCPBUGS-27202 : upgrade follow-redirects parent dependency #94 OU-318 : consider all metric keys to display all results on dashboards tables #97 OU-312 : Revert “fix default nginx path to look for static files” #93 OCPBUGS-25643 : On the alert details page, don’t require all alert labels in URL #89 OCPBUGS-24658 : remove regex from console page route path so plugin pages are found #85 OU-298 : fix default nginx path to look for static files #83 OCPBUGS-22104 : disable query link for non metric-based alerts #78 OU-285 : add test-id to panel charts to ease e2e tests when titles change #80 Upgrade Node.js from v16 to v18 in images #79  
OU-261 : Fix “Overwriting current silence” info alert to have padding #74 OU-179 : Fix the root cause of externalLabels not present on alerts #53 Revert “Fix i18n namespace for navigation menu entries” #77  
Fix i18n namespace for navigation menu entries #73  
add ipv6 nginx configuration #76  
OCPBUGS-19233 : Updating monitoring-plugin images to be consistent with ART #75 Full changelog  
Revert art-bot PR#42 #43  
And 5 elided commits (e.g. from squash or rebase merges) 
Full changelog  
OSASINFRA-3290 : Remove Kuryr info gathering #393 machineconfig: always gather MCS-served config #380  
OCPBUGS-20391 : Revert “Add must gather script for network observability” #390 gather_sriov: Fix typos and collect SRIOV cache at /var/lib/cni/sriov #369  
sriov: Clean up ip netns output #387  
OCPBUGS-19280 : Updating ose-must-gather images to be consistent with ART #381 ppc: explicitly add RuntimeClass to gathered resources #386  
OCPBUGS-19761 : Removed workload partitioning annotation from ppc script #385 Full changelog  
Correct 4.16 owners file (#99) #99  
Updating ose-network-metrics-daemon-container image to be consistent with ART (#87) #87  
Added METRIC_TEST_IMAGE var (#86) #86  
Update the k8s dependencies to 1.28.3 (#81) #81  
Updating ose-network-metrics-daemon images to be consistent with ART (#80) #80  
Full changelog  
OCPBUGS-31764 : replace wireshark with wireshark-cli #118 NO-JIRA: Adding bcc to the container #104  
SDN-4189 : Update OVS flows counter to work for cookies with leading 0. #103 OCPBUGS-24385 : Align status and assignee between jira and github #100 OCPBUGS-24276 : Add “networking / network-tools” to list of components #102 SDN-4189 : Fix error when nbdb and sbdb leader are located on different nodes #99 SDN-4189 : Add flow counter script for ACLs #98 SDN-4182 : Script cleanup + track ovnk upstream issues in jira #97 OCPBUGS-22166 : Move commands to the function to avoid them being executed on -h. #93 Update docs to use image-streams instead of quay image #91  
jira-scripts: Add Zenghui, remove Vic #90  
Add Flavio as approver #89  
SDN-3904 : Update scripts in network-tools to reflect the changes in IC model #86 SDN-4047 : Migrate bug-dispath query scripts #88 OCPBUGS-19292 : Updating ose-network-tools images to be consistent with ART #87 Full changelog  
OCPBUGS-34521 : Fix DiskToMirror without internet connection without rebuild catalog (#866) #866 OCPBUGS-33575 : Change default behavior to not rebuild catalogs for V1 (#849) #849 OCPBUGS-31466 : Fix for oc-mirror new defaultChannel override (#846) #846 Bump version to include v5.11.0 of go-git (#819) #819  
OCPBUGS-23550 : Generate both oc-mirror binaries for rhel9 and rhel8 (#804) #804 Fix to ensure operator not found error exits with correct status (#794) #794  
OCPBUGS-27946 : Capability to override default channel (#786) #786 OCPBUGS-27252 : Add Type for CopyImageSchema; Skip graph for IDMS; Fix UpdateService (#780) #780 OCPBUGS-16801 : fix: fixes the bug on catalog when using field archiveSize: 1 (#774) #774 Updating oc-mirror-plugin-container image to be consistent with ART for 4.15 (#776) #776  
OCPBUGS-25346 : - oc-mirror on RHEL9 Host with FIPS enabled (#764) #764 OCPBUGS-24359 : Fix including duplicate blobs in archive (#762) #762 Add generation of updateService.yaml (#759) #759  
OCPBUGS-19429 : Fix cross EUS channel upgrade path calculation (#757) #757 OCPBUGS-23327 : Fix MirrorToDisk of oci catalogs in hidden folders (#756) #756 Fix default port for V2 ‘prepare’ subcommand (#747) #747  
Adding release payload signatures to graph-data container (#742) #742  
OCPBUGS-23339 : fix IDMS custom resource name (#743) #743 remove unnecessary print statement (#745) #745  
OCPBUGS-23309 : Do not panic if port chosen to run local cache is already bound (#744) #744 CFE-994 : cache location separate of working-dir (#741) #741 Integrate Unarchive process to DiskToMirror workflow (#740) #740  
CFE-977 , CFE-991 : archive generation at the end of MirrorToDisk workflow (#739) #739 CFE-981 : Create UnArchiver interface and implementation (#738) #738 CFE-977 , CFE-980 : Introduce Archiver interface and its implementation MirrorArchiver (#734) #734 feat: history file reader and writer (#736) #736  
skipping prune failure if manifest not found (#733) #733  
Package ioutil  is deprecated as of Go 1.16 (#731) #731  
CFE-977 : Implementation of a blob gatherer for images in the local cache (#732) #732 refactorings (#728) #728  
Fix –from being set to default value in mirrorToDisk workflow (#727) #727  
OCPBUGS-22947 : Should not generate graph with prepare subcommand (#725) #725 Cancel community office hours: none for the moment (#726) #726  
CFE-965 : [V2] Enable signature verification (#709) #709 CFE-971 : Generate OSUS graph image - uses go-containerregistry implementation (#722) #722 Pr template change (#719) #719  
CFE-899 , CFE-958 : feat: removes the registry dns (#718) #718 Remove Dockerfile.integration - not used - reduce confusion (#716) #716  
OCPBUGS-21864 : fix: CVE-2023-39325 and CVE-2023-44487 (#712) #712 Introduce subcommand prepare (#702) #702  
Initial implementation of IDMS generation (#707) #707  
Fixes HTTP 401 issues when several catalogs are being mirrored and need to be rendered using operator-registry (#704) #704  
CFE-935 : [V2] Implement a release collector relying on local registry as storage (#690) #690 Fix OCPBUGS-17546: pod catalogsource generated by oc-mirror will crashloopBackOff randomly (#697) #697  
CFE-956 : feat: adds tags on the related images (#695) #695 Updating oc-mirror-plugin images to be consistent with ART (#698) #698  
Update list updates CLI documentation (#687) #687  
CFE-906 : [V2]Enclave support - Separate log file for local storage (#686) #686 CFE-955 : changes owner file (#694) #694 CFE-897 , CFE-907 : feat: add code to call v2 from v1 (#692) #692 Full changelog  
OCPBUGS-29796 : UPSTREAM: 231: make garbage collection a runnable #44 OCPBUGS-27586 , OCPBUGS-27671 : [release-4.15] bump github.com/go-git/go-git/v5 to v5.11.0 #39 NO-ISSUE: Synchronize From Upstream Repositories #33  
NO-ISSUE: UPSTREAM: <drop>: Remove GH activities #35  
OPRUN-3079 : UPSTREAM: <carry>: Drop commitchecker #32 Update to Upstream v0.7.0 #31  
OCPBUGS-20517 : UPSTREAM: <drop>: Bump golang.org/x/net from 0.10.0 to 0.17.0 (#197) #29 OCPBUGS-19117 : UPSTREAM: <carry>: Updating ose-olm-catalogd images to be consistent with ART #28 Full changelog  
OCPBUGS-27591 , OCPBUGS-27676 : [release-4.15] bump github.com/go-git/go-git/v5 to v5.11.0 #68 NO-ISSUE: Synchronize From Upstream Repositories #50  
NO-ISSUE: Synchronize From Upstream Repositories #49  
NO-ISSUE: Synchronize From Upstream Repositories #48  
NO-ISSUE: Synchronize From Upstream Repositories #47  
NO-ISSUE: Synchronize From Upstream Repositories #46  
NO-ISSUE: Synchronize From Upstream Repositories #41  
NO-ISSUE: UPSTREAM: <drop>: Remove GH activities #44  
OPRUN-3081 : UPSTREAM: <carry>: Drop commitchecker #37 OPRUN-3075 : Update to Upstream v0.7.0 #31 OCPBUGS-20505 : Bump golang.org/x/net to v0.17.0 #28 OCPBUGS-19096 : UPSTREAM: <carry>: Updating ose-olm-operator-controller images to be consistent with ART #27 Full changelog  
OCPBUGS-35902 : Bump ovn to 23.09.4-16 #2216 OCPBUGS-36382 : Handle IP fragments in SGW mode #2215 OCPBUGS-33619 : EgressIP: Reload certificates for the grpc heatlhcheck server #2167 OCPBUGS-33623 , OCPBUGS-33624 : Improve CI signal by removing/suppressing signals #2168 OCPBUGS-31814 : ipv6+all protocols conntrack flush #2131 OCPBUGS-34404 : [release-4.15] dns: fix deadlock in case of error #2182 OCPBUGS-33294 : Reuse node-subnet from cache if exists #2163 OCPBUGS-33960 : Egressip garp fix 4.15 #2175 OCPBUGS-30899 : use a forked version of j-keck/arping that fixes a threading issue #2105 OCPBUGS-32426 : [release-4.15] Improves service iptables efficiency on start up #2156 [Release 4.15] OCPBUGS-32986: Bump OVS #2147  
OCPBUGS-27852 : [release-4.15] Full implementation of KEP-1669 ProxyTerminatingEndpoints + ETP=local fix #2025 OCPBUGS-29316 : [release-4.15] Ignore missing live migratable pod annotation on AddNode #2065 OCPBUGS-32202 : [release-4.15] Bump OVN to 23.09.0-139 #2121 OCPBUGS-33020 : drop-forwarding: Add ClusterSubnets to allowed forwarding CIDRs #2141 OCPBUGS-32154 : Custom v4 and v6 transit switch subnets while creating kind cluster #2094 OCPBUGS-31081 : Periodically check the ovnkube-node certificate is not expired #2099 OCPBUGS-31033 : Remove OVN topology version reporting/detection #2098 OCPBUGS-31500 , OCPBUGS-31501 : EIP multi NIC IPv6 support and default route with next hop #2103 OCPBUGS-29599 : Update HostNetworkNamespace address_set for remote zone nodes #2074 OCPBUGS-29185 : Wait for ovnkube controller to start before checking result error. #2064 OCPBUGS-28725 : Update netpol namespace address sets usage to the old ways #2050 OCPBUGS-29230 : [release-4.15] separate the handler sync from the informer sync & remove the full service resync during node tracker startup #2060 OCPBUGS-28818 : Support Permanent Session Affinity #2045 OCPBUGS-28848 : Ignore hybrid-overlay nodes from EgressIP controller #2040 OCPBUGS-29001 : kubevirt, Replace routes on migration #2052 OCPBUGS-27947 : [release-4.15] Fix LGW ETP=Local on IPv6 #2028 OCPBUGS-27255 : Ensure session affinity cleanup on backend removal #2020 OCPBUGS-25938 : CARRY: Updates owners and adds Surya #2005 OCPBUGS-25395 : [release-4.15] Update namespace-owned port group (that used to be managed by multicast) #1998 OCPBUGS-25486 : Fix Egress IP Deletion Handler to Prevent OVN Policy Leaks #1999 OCPBUGS-25700 , OCPBUGS-25701 : Dockerfile: Bump OVN to ovn-23.09.0-91.el9fdp #1994 OCPBUGS-24610 : Updating ose-ovn-kubernetes-container image to be consistent with ART #1963 OCPBUGS-22847 : Downstream merge 12-7-23 #1976 NP-618 , OCPBUGS-22847 , SDN-4124 , SDN-4149 , SDN-4150 : [DownstreamMerge] 1 Dec 2023 #1965 OCPBUGS-24014 : Downstream merge 28th November 2023 #1962 OCPBUGS-21773 : Downstream Merge 22nd November 2023 #1958 NHE-805 , OCPBUGS-19050 , OCPBUGS-22691 , OCPBUGS-22767 , SDN-4173 : [DownstreamMerge] 11 November 2023 #1952 OCPBUGS-16634 , OCPBUGS-19635 , OCPBUGS-20210 : Downstream Merge 24th October 2023 #1942 OCPBUGS-11710 : Downstream Merge 18th Oct 2023 #1939 OCPBUGS-15538 , OCPBUGS-19961 : Downstream merge 2023-10-10 #1935 OCPBUGS-14787 : Dockerfile: stop installing CNI plugins RPM #1702 OCPBUGS-19289 : Updating ose-ovn-kubernetes images to be consistent with ART #1884 OCPBUGS-20178 , OCPBUGS-20238 : Downstream merge 2023-10-09 #1931 OCPBUGS-16217 , OCPBUGS-18071 , OCPBUGS-18598 , OCPBUGS-19698 : DownStream Merge 4th October 2023 #1923 OCPBUGS-19900 : DownStream Merge: 29th-September-2023 #1919 OCPBUGS-18317 : DownStream Merge: 28th-September-2023 #1917 OCPBUGS-18162 , OCPBUGS-19792 , OCPBUGS-19836 : [DownstreamMerge] 9-27-23 #1911 OCPBUGS-17455 , OCPBUGS-17641 , OCPBUGS-18352 , OCPBUGS-18549 , OCPBUGS-19456 : [DownstreamMerge] 9-26-23 #1907 OCPBUGS-19013 : Dockerfile: Copy ovnkube-trace file for RHEL8 platform #1887 OCPBUGS-19501 : Add additonal certificate acceptance condition feature in ovnkube-ide… #1895 Add ovnkube-identity binary to the downstream image #1897  
OCPBUGS-19288 : Updating ovn-kubernetes-microshift images to be consistent with ART #1883 OCPBUGS-19278 : Updating ovn-kubernetes-base images to be consistent with ART #1882 Full changelog  
OCPBUGS-33622 : Fix CVE2023-45288 by bumping x/net to v0.24.0 -4.15 #80 OCPBUGS-25978 : Rebase with upstream: Fix snyk code issue: Path Traversal #71 Updating ose-powervs-block-csi-driver-container image to be consistent with ART #66  
MULTIARCH-4027 : Rebase with upstream: Kubernetes Improper Input Validation vulnerability #65 MULTIARCH-4022 : Rebase with upstream: v0.5.1 changes #63 MULTIARCH-3987 : synk: ignore vendor dir #57 Rebase with upstream: v0.5.0 changes #56  
OCPBUGS-21593 : CVE-2023-44487: bump golang.org/x/net to v0.17.0 #49 Updating ose-powervs-block-csi-driver images to be consistent with ART #47  
cherry-pick: Improve delete device failure logs in driver node #46  
Full changelog  
OCPBUGS-25714 : snyk: ignore vendor dir #59 OCPBUGS-25161 : Add annotation to CSI driver Pod preventing eviction from the cluster-autoscaler #56 UPSTREAM <drop>: OCPBUGS-23628: SAST Scan detected vulnerability in go.uber.org/zap #52  
STOR-1402 : Chore: update libraries in all operators [4.15] #51 OCPBUGS-22628 : Bump otelhttp to >= v0.44.0 #49 OCPBUGS-22357 : CVE-2023-44487: bump github.com/openshift/library-go to master #47 Update OWNERS add yussufsh #43  
OCPBUGS-21593 : CVE-2023-44487: bump golang.org/x/net to v0.17.0 #39 Updating ose-powervs-block-csi-driver-operator images to be consistent with ART #38  
Update the powervs-csi-node to use nodeSelector for ppc64le #37  
Full changelog  
OCPBUGS-26555 : PowerVS: Bump powervs-utils to v0.0.0-20240105123432-7588e9595c17 #72 OCPBUGS-24089 : Updating ose-powervs-machine-controllers-container image to be consistent with ART #66 NO-ISSUE: snyk code scan exclude vendor directory #60  
Fix nil nextURL #59  
OCPBUGS-21878 : CVE-2023-44487 - Bump golang.org/x/net to v0.17.0 - 4.15 #53 Update dependencies and use k8 1.28 #52  
OCPBUGS-19144 : Updating ose-powervs-machine-controllers images to be consistent with ART #51 Full changelog  
OCPBUGS-34831 : fix issuer check during JWT authentication for 4.15 #538 : OCPBUGS-35076: Release Fix CVE go-jose #542  
OCPBUGS-32890 : CVE-2024-28180 bump go-jose to v3.0.3 #531 OCPBUGS-24153 : Updating telemeter-container image to be consistent with ART #496 OCPBUGS-24153 : Force kill jobs after integration v2 test finish #515 RHOBS-956 : Rename subscription_labels to ocm_subscription #495 OCPBUGS-22744 : go.mod: bump go.opentelemetry.io/contrib/instrumentation/net/http/ote… #493 rhelemeter: Parse org and cn with regex #492  
rhelemeter: Validation of incoming metrics #491  
add machine424 and rexagod  to OWNERS #478  
Bump golang 1.20 #490  
OCPBUGS-21636 : Bump golang.org/x/net to v0.17.0 #483 Server: Add support for shipping traces to an otel collector #482  
rhelemeter: support client info file in jsonnet #481  
OCPBUGS-19248 : Updating telemeter images to be consistent with ART #480 Fix: handle authorization server 403 responses #479  
RHOBS-870 : Improve logging #477 RHOBS-855 : rhelemeter: Read client info/data from request #476 Full changelog  
#28746 FIX [release-4.15] OCPBUGS-33023: update egressFWTestE2E image which contains ping binary #28898  
OCPBUGS-36724 : Removes dependency on samples operator images #28927 OCPBUGS-36319 : Only look for thanos connections to platform monitoring stack #28915 OCPBUGS-34949 : test/extended: skip etcd leader change check on hypershift #28919 OCPBUGS-28928 : Add test for UpgradeValidation contention #28820 OCPBUGS-33368 : [release-4.15] monitor test service-type-load-balancer-availability setup fails frequently in 4.14 & 4.15 PowerVS CI jobs #28821 #28776 FIX [release-4.15] OCPBUGS-33368: monitor test fix to wait before connecting to a non-existent dns on PowerVS and IBMCloud platforms #28791  
OCPBUGS-26520 : Kuryr: Ignore Upgradeable=False on operators tests #28512 OCPBUGS-33347 : Provide SCC access via RBAC #28780 OCPBUGS-33541 : Adjust the method of get the apiServer (release-4.15) #28762 OCPBUGS-33473 : [release-4.15] MULTIARCH-4352: Censor private key from pod dump logs #28666 : OCPBUGS-32554: Also rely on oomkilled exit code 137 in build test #28724  
OCPBUGS-31726 : Use centos7 tag instead of latest for cmd images tests #28688 OCPBUGS-30892 : fix panic on non-standard node-role labels #28656 OCPNODE-2101 : add kube-rbac-proxy-crio toleration change #28637 OCPBUGS-30161 : Skip tests for image-registry operator with single replica #28633 OCPBUGS-29927 : Only extract node role from properly formatted node-role label #28615 TRT-1512 : Add debug messages to debug openshift-tests hang #28610 OCPBUGS-27847 : Do not assume there is just a single kubelet systemd service #28545 OCPBUGS-29031 : Replace ‘coreydaley’ with ‘sayan-biswas’ #28573 OCPBUGS-26487 : Increase timeout for pod-network-service #28508 OCPBUGS-27934 : fix panic in service-poller #28550 OCPBUGS-26960 : updated timeout to 3 seconds to account for network timing issues #28519 OCPBUGS-27373 : pathologicalevents: fix regex in LeakyStatefulsetEvents matcher and add test #28549 OCPBUGS-27348 : pkg/monitortests/clusterversionoperator: Add an exception for ingress going Available=False on IngressUnavailable #28531 fix jira components to match actual jira components #28455  
OCPBUGS-27373 : pathologicalevents: Ignore leaky RecreatingTerminatedP… #28533 OCPBUGS-27217 : [4.15] Live migration suite e2e #28524 OCPBUGS-26043 : Adding test case for when exceed openshift.io/image-tags will ban to … #28492 OCPBUGS-25724 : Cherrypick Ruby 3.0 ImageStream Fix #28483 TRT-1408 : Disable TopologyAwareHintsDisabled check whenever NoExecuteTaintManag… #28520 OCPBUGS-26239 : Properly ignore kube guard probe events #28504 OCPBUGS-26206 : Update cluster-monitoring-operator request limits #28506 OCPBUGS-24583 : push violation regression check into the default requirement result #28433 OWNER_ALIASES: update CoreOS team leads #28447  
NOJIRA: collect certificate data: use SkipHashed option #28443  
NO-JIRA: Increase cluster-capi-operator watch count take2 #28424  
OCPNODE-1892 : Conditionally skip tests to help with k8s 1.29 #28436 NO-JIRA: Add test case for namespaced filename in oc process #28440  
API-1524 : ignore stale condition challenge events #28438 TRT-1359 : Ignore azure interaction errors since they are not fatal for our usage #28420 TRT-1347 : Add ability to indicate a monitor test was skipped #28425 NO JIRA: update cert data #28437  
OTA-362 : pkg/monitortests/clusterversionoperator: Fatal unless Available=False in allow-list #27231 OCPNODE-1892 : Update ETCD storage data for k8s 1.29 #28435 OCPBUGS-24290 : cert metadata: generate jsons and markdown for missing metadata viola #28432 NO-JIRA: test/e2e/upgrade/monitor: –abort-at=100 requires a complete update #28402  
eliminate the closed channel race in pod_log_streamer #28426  
OSASINFRA-3291 : Remove Kuryr bits #28397 OCPCLOUD-2256 : Increase cluster-capi-operator watch count #28422 TRT-1329 : Refactor pathological events framework #28399 SO-117 : Removing Ruby 2.7 UBI7-8 tests #28418 trt-1367: Get JobType After Collection Ends #28415  
TRT-1235 : Add ability to specify alerts that should never fire #28411 TRT-1362 : Update disruption/alert test data and fix unit test #28409 make it slightly easy to produce markdown with table of contents #28407  
update the TLS ownership files #28394  
update cert inspect to skip the rest of proxy-CAs #28406  
WRKLDS-908 : test: ignore deprecation warnings in command outputs #28404 collect certificate data: rewrite configmap/secret names #28405  
Certs 11 fix certs after break #28395  
ignore stale condition challenge events #28204  
TRT-1274 : get azure disk metrics and create relevant intervals #28375 Revert “TRT-1339: Revert #28233 “ignore repeated TopologyAwareHintsDisabled events”” #28386  
OCPBUGS-23079 : fix: increase watch count for KubeControllerManagerOperator #28388 OCPBUGS-23102 : Revert “[sig-instrumentation] tests fail due to JSON parsing error.” #28389 OCPBUGS-23084 : expect to not see “git clone” and not just “clone” during a test #28352 TRT-1354 : Add support for intervals to have row differentiators #28376 OCPBUGS-18776 : [sig-instrumentation] tests fail due to JSON parsing error. #28320 “TRT-1342: Trim the intervals for loki serializer to avoid errors during ingest” #28372  
trt-1340: update run-upgrade to use ginkgorunsuiteoptions #28380  
TRT-1339 : Revert #28233 “ignore repeated TopologyAwareHintsDisabled events” #28381 trt-1344: remove msg assertion #28379  
Add test which verifies every certificate has necessary annotations #28305  
OCPBUGS-19527 : retry Prometheus client creation #28323 OCPBUGS-20479 : Add pod sandbox failures to e2e charts #28366 skip revisioned certificates in raw info #28370  
TRT-1340 : Increase cmd support for ExactMonitorTests and DisableMonitorTests #28371 OCPBUGS-22703 : tolerate AWS edge nodes on monitor tests #28363 Revert “OCPBUGS-22413: Use Centos 8 Stream mysql image in tests” #28367  
Skip FailedScheduling intervals when masters are in NodeUpdate #28358  
OCPBUGS-22413 : Use Centos 8 Stream mysql image in tests #28357 Allow the unknown alerts test to fail as it looks stable #28345  
add hack/update-tls-ownership.sh #28359  
Drop not-used pulledInvalidImages method #28330  
start adding raw tls info #28334  
Restore APIServer graceful shutdown windows #28354  
Fix intervals mistakenly showing mass node NotReady #28351  
Remove timelines command reprocessing intervals #28348  
OCPBUGS-22358 : fix: increase upper bounds for samples operator #28353 put back previous Interval Slice algorithm #28344  
OCPBUGS-22276 : Remove all docker.io images due to access denied #28347 Restore Node NotReady intervals #28349  
trt-1320: update trt approvers #28343  
Port remaining clusteroperator monitor intervals to structured #28341  
Improvements and Additions to Alert Testing Stack #28332  
Automated - Update synthetic test data #28237  
prune the system CAs from proxy-ca in rawTLSInfo json #28336  
add test tracking raw cert data #28321  
OCPBUGS-9037 : Require http 1.1 or earlier when using curl #28301 Port Node and Pod State to Structured Intervals #28299  
Extract the cluster operator name from Down/Degraded Alerts #28331  
fix: wrap InitializeReleasePullSpecString in check for HasNoOptionalCapabilities #28329  
Remove some redundant monitor tests #28326  
OCPVE-723 : Add optional olm fixes #28302 Add debug info for interval counts and times #28311  
OCPBUGS-20205 : feat: added support for ImageRegistry capability #28307 OCPBUGS-20024 : Revert “OCPBUGS-13366: ignore repeated TopologyAwareHintsDisabled events” #28233 pkg/monitortests/clusterversionoperator/legacycvomonitortests: Structured condition types #28306  
Bump watch requests for cluster-baremetal-operator #28324  
test/extended/images: update OWNERS #28322  
hs, kubevirt: Wait node readiness before migration #28312  
fix for OCP-11594 to skipped on disconnected env #28316  
SDN-4062 : Revert “SDN-4042: Increase total upgrade time on OVN platforms” #28315 trt-1271: add risk analysis for monitor junit suites #28309  
Revert #28295 “Automating test \“check the quota after import-image with –all option\” in upstrem” #28313  
test/extended: Consolidate hard-coded local image registry dependencies #28308  
Limit intervals to the current phase (addresses loki upload problems) #28294  
Fix bug with disable-monitor #28293  
Remove bug-related annotations #28298  
OPNET-330 : fix DualStackIPv6Primary #28292 Automating test “check the quota after import-image with –all option” in upstrem #28295  
Properly default –from-repository in run-monitor #28285  
OCPBUGS-19909 : Updating parameters for build timing PushImage test #28288 make it possible to select which monitor tests to run #28215  
Revert “Disable EgressIP test temporarily due to OVN-K bug” #28283  
Port the clusteroperator intervals to new structured format #28262  
Revert “Force using mirrored images in disruption tests” #28286  
Bump openshift/kubernetes to get vSphere fix #28278  
Force using mirrored images in disruption tests #28258  
kubevirt: Add live migration tests #27980  
some monitor tests only function on disruptive tests #28251  
wait for the service to have endpoints before starting pollers #28242  
fix PR 28224 #28238  
OCPBUGS-18141 : retry query on MetricsAvailableAfterUpgradeTest setup #28228 Revert “OCPBUGS-18865: add monitortest: in-cluster disruption monitors” #28274  
OCPBUGS-19293 : Updating openshift-enterprise-tests images to be consistent with ART #28264 OCPVE-295 : rteval #28261 add pod log streaming to monitor for etcd so we see all intervals #28243  
OCPBUGS-18865 : add monitortest: in-cluster disruption monitors #28231 AUTH-365 : add PodSecurityViolation to watched alerts #28226 OCPBUGS-14053 : remove exception for MultipleDefaultStorageClasses #28042 remove unnecessary file from cmd folder #27979  
STOR-1425 : Update to Kubernetes 1.28 #28097 Revert “Improvements and fixes for Loki intervals uploader” #28268  
Adding leader election information to timeline #28225  
Improvements and fixes for Loki intervals uploader #28053  
Bring in updates k8s to disable networking test #28256  
When –from-repository use built-in tests only #28253  
[HyperShift/KubeVirt] Raise wait time between pod exec attempts #28249  
Revert fake image injections for k8s 1.28 #28250  
STOR-1425 : Add images coming in k8s 1.28 #28248 OCP-66086 : Automate PSAP NTO Prevent from stalld continually restarting #28157 Bug OCPBUGS-18718 Remove duplicate connection type from disruption name #28245  
OCPVE-295 : fix: add rteval to the test image #28220 STOR-1425 : Add images coming in k8s 1.28 #28200 STOR-1425 : Disable NetworkPolicyStatus tests #28177 And 3 elided commits (e.g. from squash or rebase merges) 
Full changelog  
Source code for this page located on github