Skip to content

OCPBUGS-89242: Update RHCOS-release-4.20 bootimage metadata to 9.6.20260616-0#10641

Open
coreosbot-releng wants to merge 417 commits into
openshift:release-4.20from
coreosbot-releng:bootimage-bump-9.6.20260616-0
Open

OCPBUGS-89242: Update RHCOS-release-4.20 bootimage metadata to 9.6.20260616-0#10641
coreosbot-releng wants to merge 417 commits into
openshift:release-4.20from
coreosbot-releng:bootimage-bump-9.6.20260616-0

Conversation

@coreosbot-releng

Copy link
Copy Markdown

Update data/data/coreos/rhcos.json to 9.6.20260616-0

Bootimage bump of 4.20 done for container-selinux-2.237.0-5.el9_6 https://redhat.atlassian.net/browse/OCPBUGS-88740

plume cosa2stream --target data/data/coreos/rhcos.json                 \n    --distro rhcos --no-signatures --name rhel-9.6                     \n    --url https://rhcos.mirror.openshift.com/art/storage/prod/streams  \n    x86_64=9.6.20260616-0                                       \n    aarch64=9.6.20260616-0                                      \n    s390x=9.6.20260616-0                                        \n    ppc64le=9.6.20260616-0

patrickdillon and others added 30 commits November 11, 2025 16:19
Upgrading from capi v1beta1 -> v1beta2 will take a not
insignificant amount of work. I have captured that work in
https://issues.redhat.com/browse/CORS-3563
and set nolint to disable the linters from failing on this package.
OCPBUGS-61167: pkg/types/valication: explain overlapping internal subnets better
CORS-4082, CORS-4086: Azure UserProvisionedDNS: Update bootstrap, master and worker ignition files
CORS-4262: update openshift/api & capi v1.11
When using a pre-existing network, save CIDR blocks for the virtual
network and subnets

https://issues.redhat.com/browse/OCPBUGS-59105
Service endpoints are no longer needed in favor of the PSCEndpoint.
A new policy was added to the ImageDigestSource configuration that
allows the user to specify policy when there is a failure pulling
an image from the source.

Update the image registry configuration on the bootstrap host with
this SourcePolicy.
Update the image registry configuration with the newly added
Image source policy field that specifies the fallback policy
when image pull fails.
With the introduction of the fallback source policy when Image
source and mirrors are specified, image registry configuration
for ABI should be update to include that.
…13-0

The changes done here will update the RHCOS 4.21 bootimage metadata and
address the following issues:

OCPBUGS-61669: [4.21] [OCP 4.18] coreos-boot-disk link not working with
  multipath on early boot

This change was generated using:

plume cosa2stream \
    --target data/data/coreos/rhcos.json \
    --distro rhcos \
    --no-signatures \
    --name rhel-9.6 \
    --url https://rhcos.mirror.openshift.com/art/storage/prod/streams \
    x86_64=9.6.20251113-0        \
    aarch64=9.6.20251113-0       \
    s390x=9.6.20251113-0         \
    ppc64le=9.6.20251113-0

Signed-off-by: Tiago Bueno <tiago.bueno@gmail.com>
OCPBUGS-65585: Update the RHCOS 4.21 bootimage metadata to 9.6.20251113-0
Signed-off-by: Dmitry Tantsur <dtantsur@protonmail.com>
Signed-off-by: Dmitry Tantsur <dtantsur@protonmail.com>
Signed-off-by: Dmitry Tantsur <dtantsur@protonmail.com>
TRT-2424: Revert "Update the RHCOS 4.21 bootimage metadata to 9.6.20251113-0"
NO-ISSUE: Generate the agent systemd diagrams from the unit files
CORS-4282: Remove the installer gcp service endpoints.
…59105

OCPBUGS-59105: pkg/asset/manifests/azure: save cidr blocks
Register the InfraEnv (using late binding) when the interactive GUI is
enabled.
Pulling in the internalDNSRecords field from
openshift/api#2460
** Firewall rules seem to be an issue on destroy with load balancers. The load
balancers may have resource names created with a name such as a9123-xxxxx-xxxx.
These resources are only discovered once, and it is possible when a failure occurs
that the destroy process will skip finding these resources later. Now the firewall
rules will be found using the name OR target tags. When the name does not appear
to be part of the cluster (including the cluster id), then the target tags should
be searched to determine if they are part of the cluster. This should handle the
load balancer resources too.
jhixson74 and others added 16 commits April 6, 2026 12:51
- When using a managed identity, don't use shared key credentials
- SAS urls are not supported in this case, so just return the blob URL

https://issues.redhat.com/browse/OCPBUGS-37587
Removing the option to add shared key credentials to make way for
better cred authentications.
Creating SAS url for ignition blobs using user
delegated credentials.
Since this needs to be backported to earlier versions, adding a
field to disallow shared access key if necessary.

Made the field negative type field to have the default be enabled for
shared key access for earlier versions.
…nt-pull-secret-to-ui-container

OCPBUGS-82439: [release-4.21] Mount pullsecret manifest to UI container
The newer API versions of the vpc contains some breaking changes for
SecurityGroupRuleProtocol. Some older SDKs was patched to handle additional
protocol values introduced in newer API versions, ensuring older SDK
releases do not fail when reading security group or network ACL rules
created with expanded protocol support. The latest release of v0.10 of
the cluster-api-provider-ibmcloud uses one of the patched SDKs.
This update allows the installer to continue functioning with the changes.
SDK Compatibility Patch - Protocol Handling
The SDK was patched to handle additional protocol values introduced in
newer API versions, ensuring older SDK releases do not fail when reading
security group or network ACL rules created with expanded protocol support.
[release-4.21] OCPBUGS-84225: ibmcloud: bump vpc-go-sdk and capibm
OCPBUGS-82068: Azure: Sign blob container using user delegated creds
OCPBUGS-77787 - [4.21] bootimage needs a coreos update to support GNR-D hardware
OCPBUGS-77048 - [4.21] RHCOS SNO does not boot after install; wrong device uuid in GRUB
OCPBUGS-69682 - [4.21] Kernel panic when using vrf and srv6 instrumented with FRR in RHCOS

```
plume cosa2stream --target data/data/coreos/rhcos.json                 \
    --distro rhcos --no-signatures --name rhel-9.6                     \
    --url https://rhcos.mirror.openshift.com/art/storage/prod/streams  \
    x86_64=9.6.20260520-0                                       \
    aarch64=9.6.20260520-0                                      \
    s390x=9.6.20260520-0                                        \
    ppc64le=9.6.20260520-0
```
…mp-9.6.20260520-0

OCPBUGS-77049: Update RHCOS-release-4.21 bootimage metadata to 9.6.20260520-0
OCPBUGS-81986: Bump go-jose/v4 to 4.1.4
@openshift-ci-robot openshift-ci-robot added jira/severity-moderate Referenced Jira bug's severity is moderate for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. labels Jun 19, 2026
@openshift-ci-robot

Copy link
Copy Markdown
Contributor

@coreosbot-releng: This pull request references Jira Issue OCPBUGS-89242, which is invalid:

  • release note text must be set and not match the template OR release note type must be set to "Release Note Not Required". For more information you can reference the OpenShift Bug Process.
  • expected Jira Issue OCPBUGS-89242 to depend on a bug targeting a version in 4.21.0, 4.21.z and in one of the following states: VERIFIED, RELEASE PENDING, CLOSED (ERRATA), CLOSED (CURRENT RELEASE), CLOSED (DONE), CLOSED (DONE-ERRATA), but no dependents were found

Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.

The bug has been updated to refer to the pull request using the external bug tracker.

Details

In response to this:

Update data/data/coreos/rhcos.json to 9.6.20260616-0

Bootimage bump of 4.20 done for container-selinux-2.237.0-5.el9_6 https://redhat.atlassian.net/browse/OCPBUGS-88740

plume cosa2stream --target data/data/coreos/rhcos.json                 \n    --distro rhcos --no-signatures --name rhel-9.6                     \n    --url https://rhcos.mirror.openshift.com/art/storage/prod/streams  \n    x86_64=9.6.20260616-0                                       \n    aarch64=9.6.20260616-0                                      \n    s390x=9.6.20260616-0                                        \n    ppc64le=9.6.20260616-0

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci-robot openshift-ci-robot added the jira/invalid-bug Indicates that a referenced Jira bug is invalid for the branch this PR is targeting. label Jun 19, 2026
@coderabbitai

coderabbitai Bot commented Jun 19, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 6b89b6c4-a9ab-4e9c-b7e3-c826aa8a408e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@openshift-ci openshift-ci Bot requested review from PeaceRebel and aaradhak June 19, 2026 17:26
@openshift-ci openshift-ci Bot added the needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. label Jun 19, 2026
@openshift-ci

openshift-ci Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

Hi @coreosbot-releng. Thanks for your PR.

I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Tip

We noticed you've done this a few times! Consider joining the org to skip this step and gain /lgtm and other bot rights. We recommend asking approvers on your previous PRs to sponsor you.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Bootimage-bump done to keep rhel-9.6 in sync with 4.20 bootimage bump - https://redhat.atlassian.net/browse/OCPBUGS-89242

```
plume cosa2stream --target data/data/coreos/rhcos.json                 \
    --distro rhcos --no-signatures --name rhel-9.6                     \
    --url https://rhcos.mirror.openshift.com/art/storage/prod/streams  \
    x86_64=9.6.20260616-0                                       \
    aarch64=9.6.20260616-0                                      \
    s390x=9.6.20260616-0                                        \
    ppc64le=9.6.20260616-0
```
@coreosbot-releng coreosbot-releng force-pushed the bootimage-bump-9.6.20260616-0 branch from 1d3f441 to f96182b Compare June 19, 2026 17:29
@openshift-ci openshift-ci Bot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Jun 19, 2026
@openshift-ci

openshift-ci Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

PR needs rebase.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci

openshift-ci Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign rna-afk for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

jira/invalid-bug Indicates that a referenced Jira bug is invalid for the branch this PR is targeting. jira/severity-moderate Referenced Jira bug's severity is moderate for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD.

Projects

None yet

Development

Successfully merging this pull request may close these issues.