Skip to content

Commit 044e620

Browse files
Merge pull request #6368 from pmtk/dns-pod-kube-rbac-proxy-fix-args
NO-ISSUE: Add DNS' core-rbac-proxy args and template TLS Cipher Suites & Min Version
2 parents 8a16d85 + 6d4927a commit 044e620

27 files changed

Lines changed: 221 additions & 5332 deletions

Makefile.version.aarch64.var

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
OCP_VERSION := 4.22.0-0.nightly-arm64-2026-03-16-023946
1+
OCP_VERSION := 4.22.0-0.nightly-arm64-2026-03-17-075144

Makefile.version.x86_64.var

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
OCP_VERSION := 4.22.0-0.nightly-2026-03-15-203841
1+
OCP_VERSION := 4.22.0-0.nightly-2026-03-17-104634

assets/components/multus/kustomization.aarch64.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
images:
33
- name: multus-cni-microshift
44
newName: quay.io/openshift-release-dev/ocp-v4.0-art-dev
5-
digest: sha256:346179a6e0b2b56a4f1ba1a0085bdb58cd9ef1ac3514018d1f3351e48e81b275
5+
digest: sha256:50e5e48edb99e4c89d03c0edcfc58ffbc3081d2b5b189431b6d6e8b565c749a0
66
- name: containernetworking-plugins-microshift
77
newName: quay.io/openshift-release-dev/ocp-v4.0-art-dev
8-
digest: sha256:40c1962394cb18ec4ea81eb0a301f76330fb7c4b0b27eaf5eded647b9e86b90e
8+
digest: sha256:81ee1fcc06b556e5ba7fd737137e500bbf249006d022593958c67324d8ce74e6

assets/components/multus/kustomization.x86_64.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
images:
33
- name: multus-cni-microshift
44
newName: quay.io/openshift-release-dev/ocp-v4.0-art-dev
5-
digest: sha256:a0d4399c420679b4b33edd4554c44ab825585d4efccca2291c20a627df8b09c6
5+
digest: sha256:51f90ebc8bc3eb0d031cfc41a3720fffd5d3eaad4a31141bfee675b1f8d567ce
66
- name: containernetworking-plugins-microshift
77
newName: quay.io/openshift-release-dev/ocp-v4.0-art-dev
8-
digest: sha256:9a9e34cc3ccad8eba2b490c787113d20acacbb36a1b601783d3d41199e8cc6e7
8+
digest: sha256:11f416d27af7b4c42a7ca5aba11afd5c57a919e8e142e5f4959b0d503dbfa327
Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
{
22
"release": {
3-
"base": "4.22.0-0.nightly-arm64-2026-03-16-023946"
3+
"base": "4.22.0-0.nightly-arm64-2026-03-17-075144"
44
},
55
"images": {
6-
"multus-cni-microshift": "quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:346179a6e0b2b56a4f1ba1a0085bdb58cd9ef1ac3514018d1f3351e48e81b275",
7-
"containernetworking-plugins-microshift": "quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:40c1962394cb18ec4ea81eb0a301f76330fb7c4b0b27eaf5eded647b9e86b90e"
6+
"multus-cni-microshift": "quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:50e5e48edb99e4c89d03c0edcfc58ffbc3081d2b5b189431b6d6e8b565c749a0",
7+
"containernetworking-plugins-microshift": "quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:81ee1fcc06b556e5ba7fd737137e500bbf249006d022593958c67324d8ce74e6"
88
}
99
}
Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
{
22
"release": {
3-
"base": "4.22.0-0.nightly-2026-03-15-203841"
3+
"base": "4.22.0-0.nightly-2026-03-17-104634"
44
},
55
"images": {
6-
"multus-cni-microshift": "quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:a0d4399c420679b4b33edd4554c44ab825585d4efccca2291c20a627df8b09c6",
7-
"containernetworking-plugins-microshift": "quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:9a9e34cc3ccad8eba2b490c787113d20acacbb36a1b601783d3d41199e8cc6e7"
6+
"multus-cni-microshift": "quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:51f90ebc8bc3eb0d031cfc41a3720fffd5d3eaad4a31141bfee675b1f8d567ce",
7+
"containernetworking-plugins-microshift": "quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:11f416d27af7b4c42a7ca5aba11afd5c57a919e8e142e5f4959b0d503dbfa327"
88
}
99
}

assets/components/openshift-dns/dns/daemonset.yaml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ spec:
2424
readOnly: true
2525
- mountPath: /tmp
2626
name: tmp-dir
27-
{{- if .HostsEnabled }}
27+
{{- if .HostsEnabled }}
2828
- mountPath: /tmp/hosts
2929
name: hosts
3030
readOnly: true
@@ -63,13 +63,6 @@ spec:
6363
readOnlyRootFilesystem: true
6464
image: '{{ .ReleaseImage.coredns }}'
6565
- name: kube-rbac-proxy
66-
args:
67-
- --logtostderr
68-
- --secure-listen-address=:9154
69-
- --tls-cipher-suites=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
70-
- --upstream=http://127.0.0.1:9153/
71-
- --tls-cert-file=/etc/tls/private/tls.crt
72-
- --tls-private-key-file=/etc/tls/private/tls.key
7366
ports:
7467
- containerPort: 9154
7568
name: metrics
@@ -87,6 +80,13 @@ spec:
8780
securityContext:
8881
readOnlyRootFilesystem: true
8982
image: '{{ .ReleaseImage.kube_rbac_proxy }}'
83+
args:
84+
- --secure-listen-address=:9154
85+
- --tls-cipher-suites={{ .TLSCipherSuites }}
86+
- --tls-min-version={{ .TLSMinVersion }}
87+
- --upstream=http://127.0.0.1:9153/
88+
- --tls-cert-file=/etc/tls/private/tls.crt
89+
- --tls-private-key-file=/etc/tls/private/tls.key
9090
imagePullPolicy: IfNotPresent
9191
dnsPolicy: Default
9292
volumes:

assets/optional/operator-lifecycle-manager/kustomization.aarch64.yaml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -2,26 +2,26 @@
22
images:
33
- name: quay.io/operator-framework/olm
44
newName: quay.io/openshift-release-dev/ocp-v4.0-art-dev
5-
digest: sha256:2117f6b445a949a484722170568f69b64ad35c728eb23a20f439e6dbbbf0c6ab
5+
digest: sha256:e1fa426d6a06aaeb7a8922e09bceaf92e124dbfd40d018484ea0272c2d3d40ec
66
- name: quay.io/operator-framework/configmap-operator-registry
77
newName: quay.io/openshift-release-dev/ocp-v4.0-art-dev
8-
digest: sha256:ede57976518d8de0e2b466e1529a8acffe1bc2a9e59f65766362fae0bef88ada
8+
digest: sha256:d4a73641d8d2f9e84ccc5bbe5529c2a45d57378dab0c3bdb5df6ab933231683e
99
- name: quay.io/openshift/origin-kube-rbac-proxy
1010
newName: quay.io/openshift-release-dev/ocp-v4.0-art-dev
11-
digest: sha256:404e91fe9b4e8281891e017be366b9a7eb312a2cfd35df45c4e97442f000d897
11+
digest: sha256:3808a275427e399c43f7b769542f32e15320c8984dd7b44e372ba4f8b06696db
1212

1313
patches:
1414
- patch: |-
1515
- op: add
1616
path: /spec/template/spec/containers/0/env/-
1717
value:
1818
name: OPERATOR_REGISTRY_IMAGE
19-
value: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:ede57976518d8de0e2b466e1529a8acffe1bc2a9e59f65766362fae0bef88ada
19+
value: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:d4a73641d8d2f9e84ccc5bbe5529c2a45d57378dab0c3bdb5df6ab933231683e
2020
- op: add
2121
path: /spec/template/spec/containers/0/env/-
2222
value:
2323
name: OLM_IMAGE
24-
value: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:2117f6b445a949a484722170568f69b64ad35c728eb23a20f439e6dbbbf0c6ab
24+
value: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:e1fa426d6a06aaeb7a8922e09bceaf92e124dbfd40d018484ea0272c2d3d40ec
2525
target:
2626
kind: Deployment
2727
labelSelector: app=catalog-operator

assets/optional/operator-lifecycle-manager/kustomization.x86_64.yaml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -2,26 +2,26 @@
22
images:
33
- name: quay.io/operator-framework/olm
44
newName: quay.io/openshift-release-dev/ocp-v4.0-art-dev
5-
digest: sha256:c8b30a999339e0d278e12459cc6e9717fef134c31bf8d197f2decd58e69a3ce1
5+
digest: sha256:b2c9e33a9bb2272fe959221d82a335dd3258b6fd703ab3c6bb795634f1d5685d
66
- name: quay.io/operator-framework/configmap-operator-registry
77
newName: quay.io/openshift-release-dev/ocp-v4.0-art-dev
8-
digest: sha256:37a44a613e53626d6adf4556219701e16455fb71603eca7865d464ffcb0d73ed
8+
digest: sha256:52c91cf06f1971592b333f9350a8227e2b3d7c0cd1f38205f49ef1728db1fa64
99
- name: quay.io/openshift/origin-kube-rbac-proxy
1010
newName: quay.io/openshift-release-dev/ocp-v4.0-art-dev
11-
digest: sha256:2ead40d6af5a9159a3452c2aeeb347bcc63064f7cc4858e789473581c7e0158b
11+
digest: sha256:198863a1d295199013dbaf0d58077027af91abecf2af32968f7103368a0d2785
1212

1313
patches:
1414
- patch: |-
1515
- op: add
1616
path: /spec/template/spec/containers/0/env/-
1717
value:
1818
name: OPERATOR_REGISTRY_IMAGE
19-
value: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:37a44a613e53626d6adf4556219701e16455fb71603eca7865d464ffcb0d73ed
19+
value: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:52c91cf06f1971592b333f9350a8227e2b3d7c0cd1f38205f49ef1728db1fa64
2020
- op: add
2121
path: /spec/template/spec/containers/0/env/-
2222
value:
2323
name: OLM_IMAGE
24-
value: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:c8b30a999339e0d278e12459cc6e9717fef134c31bf8d197f2decd58e69a3ce1
24+
value: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:b2c9e33a9bb2272fe959221d82a335dd3258b6fd703ab3c6bb795634f1d5685d
2525
target:
2626
kind: Deployment
2727
labelSelector: app=catalog-operator
Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
{
22
"release": {
3-
"base": "4.22.0-0.nightly-arm64-2026-03-16-023946"
3+
"base": "4.22.0-0.nightly-arm64-2026-03-17-075144"
44
},
55
"images": {
6-
"operator-lifecycle-manager": "quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:2117f6b445a949a484722170568f69b64ad35c728eb23a20f439e6dbbbf0c6ab",
7-
"operator-registry": "quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:ede57976518d8de0e2b466e1529a8acffe1bc2a9e59f65766362fae0bef88ada",
8-
"kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:404e91fe9b4e8281891e017be366b9a7eb312a2cfd35df45c4e97442f000d897"
6+
"operator-lifecycle-manager": "quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:e1fa426d6a06aaeb7a8922e09bceaf92e124dbfd40d018484ea0272c2d3d40ec",
7+
"operator-registry": "quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:d4a73641d8d2f9e84ccc5bbe5529c2a45d57378dab0c3bdb5df6ab933231683e",
8+
"kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:3808a275427e399c43f7b769542f32e15320c8984dd7b44e372ba4f8b06696db"
99
}
1010
}

0 commit comments

Comments
 (0)