NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1244 by repository stars
Last release 9 days ago
28 Sep 2026
Ships fairly regularly
a new release about every 4 weeks
Some releases are documented
notes for 18 of 35 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
1029 releases · first in 2018
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
install-config.yml is now install-config.yaml to align with our usual YAML extension. install-config.yml is deprecated, and support for it will be rem…
create cluster invocations
(which we saw sometimes on all platforms).config.openshift.io as a DNS custom resource.install-config.yml is now install-config.yaml to align with our
usual YAML extension. install-config.yml is deprecated, and
support for it will be removed completely in the next release.
On AWS, we now use a select widget for the base-domain wizard prompt, making it easier to choose an existing public zone.
On AWS, Route 53 rate limits during cluster destroy are now less
disruptive, reducing the AWS request load in busy accounts.
On OpenStack, the HAProxy configuration no longer hard-codes the cluster name and base domain.
On OpenStack, the 0.7.0 fix for:
FATAL Expected HTTP response code [202 204] when accessing [DELETE https://osp-xxxxx:13696/v2.0/routers/52093478-dcf1-4bcc-9a2c-dbb1e42da880], but got 409 instead
{"NeutronError": {"message": "Router 52093478-dcf1-4bcc-9a2c-dbb1e42da880 still has ports", "type": "RouterInUse", "detail": ""}}
was incorrect and has been reverted. We'll land a real fix for this issue in future work.
On OpenStack, the service VM from 0.7.0 now has a floating IP address.
All libvirt functionality is behind TAGS=libvirt now. Previously
installer builds with TAGS=libvirt_destroy included all libvirt
functionality, while builds without that tag would include create cluster but not destroy cluster functionality. With the change,
all users using the installer with libvirt clusters will need to set
the new build tag.
Lots of doc and internal cleanup and minor fixes.
tectonicClusterID tag which was
deprecated in 0.7.0 has been removed.Nothing published for this version
Nothing published for this version
Nothing published for this version
On AWS and OpenStack, the installer and subsequent cluster will now tag resources it creates with openshiftClusterID. tectonicClusterID is deprecated.
We now validate install-config when loading it during staged installs. Previously we only validated that input when it was entered into the wizard or via environment variables. This also leads to some changes in which values are considered valid:
auths property). Previously we only required pull secrets to
be valid JSON.ParseAuthorizedKey][ssh.ParseAuthorizedKey]. Previously we
had our own logic that was not as well developed.We've added images/installer/Dockerfile.ci.rhel7 for building
installer images on a RHEL base.
On AWS, we now create [an S3 endpoint][aws-s3-endpoint] for the VPC.
We've added OpenStack documentation.
admin
privileges, but only for 30 minutes. Now it has role bindings that
allow it to create and receive automatic approval for certificate
signing requests, but it does not have additional privileges beyond
that.openshiftClusterID.
tectonicClusterID is deprecated.clouds entry is marshalled into
the openstack-creds secret. Previously we had injected the host's
entire cloud configuration.bootstrap-complete event.Fixed OpenShift manifest loading during staged installs. The installer had been ignoring changes to those files since 0.4.0.
Fixed you must pass a pointer as the target of a Write operation
errors introduced in 0.6.0 for the AWS access key ID prompt.
When create cluster times out waiting for the Kubernetes API, we
now exit immediately. Previously we'd wait through another 30
minutes of failed event-listener connections before failing this
case. We've also fixed similar timeout detection for the code that
waits for the OpenShift console route.
On OpenStack, we've fixed a bug in router deletion:
FATAL Expected HTTP response code [202 204] when accessing [DELETE https://osp-xxxxx:13696/v2.0/routers/52093478-dcf1-4bcc-9a2c-dbb1e42da880], but got 409 instead
{"NeutronError": {"message": "Router 52093478-dcf1-4bcc-9a2c-dbb1e42da880 still has ports", "type": "RouterInUse", "detail": ""}}
On libvirt, we've fixed a bug introduced in 0.6.0 and are now back to removing the bootstrap node from round-robin DNS when we destroy the bootstrap resources.
OPENSHIFT_INSTALL_* environment variables are
gone. Instead, users who want to skip the wizard are encouraged to
provide their own
install-config.Nothing published for this version
We now push a kubeadmin user (with an internally-generated password) into the cluster for the new [bootstrap identity provider][bootstrap-identity-pro
kubeadmin user (with an internally-generated
password) into the cluster for the new [bootstrap identity
provider][bootstrap-identity-provider]. This gives users a way to
access the web console, Prometheus, etc. without needing to
configure a full-fledged identity provider or install oc. The
create cluster subcommand now blocks until the web-console route
is available and then exits after printing instructions for using
the new credentials.admin structure has been removed.build.sh now checks to make sure you have a new enough go,
instead of erroring out partway through the build.AWS_DEFAULT_REGION and in other
usual places when picking a default for the region prompt. You
still have to set OPENSHIFT_INSTALL_AWS_REGION if you want to skip
the prompt entirely.kubeadmin user and bootstrap identity provider.openshift-web-console namespace is gone. The new console
is in the openshift-console namespace.…to configure itself without referencing the deprecated cluster-config-v1 resource.
cluster-config-v1 resource.account.coreos.com. Users
will need to update their pull secrets.bootstrap-complete event, the installer exits
with a non-zero exit code. We had ignored watcher timeouts in 0.4.0
due to concerns about watcher robustness, but the current watcher
code has been reliable in our continuous integration testing.quay.io/coreos/bootkube dependency has been
replaced by the new [cluster-bootstrap][] image, which is referenced
from the release image.AWSMachineProviderConfig][cluster-api-provider-aws-012575c1-AWSMachineProviderConfig],
so this change is currently limited to masters created by the
installer.The .openshift_install.log addition from 0.4.0 removed Terraform
output from --log-level=debug. We've fixed that in 0.5.0; now
.openshift_install.log will always contain the full Terraform
output, while standard error returns to containing the Terraform
output if and only if --log-level=debug or higher.
On AWS teardown, errors retrieving tags for S3 buckets and Route 53 zones are no longer fatal. This allows the teardown code to continue it's exponential backoff and try to remove the bucket or zone later. It avoids some resource leaks we were seeing due to AWS rate limiting on those tag lookups as many simultaneous CI jobs searched for Route 53 zones with their cluster's tags. We'll still hit those rate limits, but they no longer cause us to give up on reaping resources.
On AWS, we've removed some unused data blocks, fixing occasional errors like:
data.aws_route_table.worker.1: Your query returned no results.
On OpenStack, similar retry-during-teardown changes were made for removing ports and for removing subnets from routers.
On libvirt, Terraform no longer errors out when launching clusters configured for more than one master, fixing a bug from 0.4.0.
Nothing published for this version
Nothing published for this version
Nothing published for this version
We push a ClusterVersion custom resource. The old CVOConfig is still being pushed, but it is deprecated.
create subcommand
(e.g. openshift-install create cluster instead of the old
openshift-install cluster). This makes them easier to distinguish
from other openshift-install subcommands and also mirrors the
approach taken by destroy in 0.3.0.manifest-templates target has been added to create,
allowing users to edit templates and have descendant assets
generated from their altered templates during a staged
install.destroy support.${INSTALL_DIR}/.openshift_install.log for most
operations, giving access to the logs for troubleshooting even if
you neglected to run with --log-level=debug.The create cluster subcommand now waits for the
bootstrap-complete event and automatically removes the bootstrap
assets after receiving it. This means that after create cluster
returns successfully, the cluster has its production control plane
and topology (although there may still be operators working through
their initialization). The bootstrap-complete event was new in
0.3.0, and it is now pushed at the appropriate time (it was too
early in 0.3.0). The destroy bootstrap subcommand is still
available, to allow users to manually trigger bootstrap deletion if
the automatic removal fails for whatever reason.
On AWS, bootstrap deletion now also removes the S3 bucket used for the bootstrap node's Ignition configuration.
Asset state is preserved even while moving backwards through a staged install. For example:
openshift-install --dir=example create ignition-configs
openshift-install --dir=example create install-config
now preserves the full state including the generated Ignition
configuration. In 0.3.0, the install-config call would have
removed the Ignition configuration and other downstream assets
from the stored state.
Some asset state is removed by successful destroy cluster runs.
This reduces the change of contaminating future cluster creation
with assets left over from a previous cluster, but users are still
encouraged to remove state between clusters to
avoid accidentally contaminating the subsequent cluster's state.
etcd discovery now happens via SRV records. On libvirt, this
requires a new Terraform provider, so users with older providers
should install a newer
version.
This also allows all masters to use a single Ignition file.
On AWS, the API and service load balancers have been changed from [classic load balancers][aws-elb] to [network load balancers][aws-nlb]. This should avoid [some latency issues we were seeing with classic load balancers][aws-elb-latency], and network load balancers are cheaper.
On AWS, master Machine entries now include load balancer
references, ensuring that new masters created by [the AWS
cluster-API provider][cluster-api-provider-aws] will be attached to
the load balancers.
On AWS and OpenStack, the default network CIDRs have changed to
172.30.0.0/16 for services and 10.128.0.0/14 for the cluster, to
be consistent with previous versions of OpenStack.
The bootstrap kubelet is no longer part of the production cluster. This reduces complexity and keeps production pods off of the temporary bootstrap node.
[The cluster-version operator][cluster-version-operator] now runs in a static pod on the bootstrap node until the production control plane comes up. This breaks a cyclic dependency between the production API server and operators.
The bootstrap control plane now waits for some core pods to come up before exiting.
[The machine-API operator][machine-api-operator] now reads the
install-config from the cluster-config-v1 config-map, instead of
from an operator-specific configuration.
AWS AMIs and libvirt images are now pulled from the new [RHCOS pipeline][rhcos-pipeline].
Updated the security contact information for CoreOS -> Red Hat.
We push a ClusterVersion custom resource. The old CVOConfig is
still being pushed, but it is deprecated.
OpenStack credentials are loaded from standard system paths.
On AWS and OpenStack, ports 9000-9999 are now open for host network services.
Lots of doc and internal cleanup and minor fixes.
destroy cluster is now more robust, removing resources with
either the tectonicClusterID or kubernetes.io/cluster/<name>: owned tags. It also removes pending instances as well (it used to
only remove running instances).destroy cluster is now more precise, only removing
resources which are prefixed by the cluster name.create ignition-configs) no longer
suffer from a worker.ign dependency cycle, which had been
clobbering manual bootstrap.ign changes.--dir, avoiding remove ...: no such file or directory errors during staged
installs.destroy bootstrap
no longer raises invalid cross-device link./usr/local/bin, avoiding
SELinux violations on RHEL 8.tectonic-system namespace
have been removed.OPENSHIFT_INSTALL_LIBVIRT_IMAGE environment
variable, but too many users were breaking their cluster by pointing
the installer at an outdated RHCOS, so we removed the prompt to make
that knob less obvious..gz suffix handling for images. The new
RHCOS pipeline supports Content-Encoding: gzip, so the
suffix-based hack is no longer necessary.destroy-cluster command, which was deprecated in favor of
destroy cluster in 0.3.0, has been removed.openshift-install have been
removed. Use the target subcommands of create instead
(e.g. openshift-install create cluster instead of
openshift-install cluster).Nothing published for this version
Nothing published for this version
For consistency, the old destroy-cluster has been deprecated in favor of openshift-install destroy cluster.
Asset state is loaded from the install directory, allowing for a staged install.
A new openshift-install destroy bootstrap command destroys the
bootstrap resources. Ideally, this would be safe to run after the
new bootstrap-complete event is pushed to the kube-system
namespace, but there is currently a bug causing that event to be
pushed too early. For now, you're on your own figuring out when to
call this command.
For consistency, the old destroy-cluster has been deprecated in
favor of openshift-install destroy cluster.
The installer creates worker MachineSets, instead of leaving that to
[the machine-API operator][machine-api-operator].
The installer creates master Machines and tags masters to be
picked up by the [AWS cluster-API
provider][cluster-api-provider-aws].
AWS_PROFILE environment variable
when launching AWS clusters.Asset state is preserved between invocations, allowing for a staged install like:
Asset state is preserved between invocations, allowing for a staged install like:
$ openshift-install --dir=example install-config
$ openshift-install --dir=example cluster
which creates a cluster using the same data given in the install-config (including the same random cluster ID, etc.).
[The kube-apiserver][kube-apiserver-operator] and [kube-controller-manager][kube-controller-manager-operator] operators are called to render additional cluster manifests.
etcd is now available as a service in the kube-system namespace,
and the new service is labeled so [Prometheus][] will scrape it.
The service-serving-cert-signer-signing-key secret is now
available in the openshift-service-cert-signer namespace, which
gives [the service-serving cert signer][service-serving-cert-signer]
the keys it needs to mint and manage certificates for Kubernetes
services.
The etcd-serving certificate is now passed through to [the kube-controller-manager operator][kube-controller-manager-operator].
We disable some components which [the cluster-version operator][cluster-version-operator] would otherwise install but which conflict with the legacy tectonic-operators.
The new openshift-install graph outputs the asset graph in [the
DOT language][dot].
openshift-install version now outputs the Terraform version as
well as the installer version.
--log-level is less than debug.-no-color and -input=false.cluster target now includes both launching the cluster and
populating metadata.json, regardless of whether the terraform
invocation succeeds. This allows destroy-cluster to cleanup
cluster resources even when the terraform invocation fails.$XDG_CACHE_HOME/openshift-install/libvirt/image. The previous
implementation unzipped, when necessary, for every launched cluster,
which was slow. And the previous implementation added one unzipped
image to /tmp per cluster launch, which consumed more disk space.machine-config-operator-images config-map. Now [the
cluster-version operator][cluster-version-operator] pulls these from
[the machine-config images][machine-config-operator].machine-api app-version from the tectonic-system namespace.The openshift-install command. This moves us to the new install-config approach with asset generation in Go instead of in Terraform. Terraform is stil
The openshift-install command. This moves us to the new
install-config approach with asset
generation in Go instead of in
Terraform. Terraform is still used to push the assets out to
resources on the backing platform (AWS, libvirt, or OpenStack), but
that push happens in a single Terraform invocation instead of in
multiple steps. This makes installation faster, because more
resources can be created in parallel. openshift-install also
dispenses with the distribution tarball; all required assets except
for a terraform binary are distributed in the openshift-install
binary.
The configuration and command-line interface are quite different, so
previous tectonic users are encouraged to start from scratch when
getting acquainted with openshift-install. AWS users should look
here. Libvirt users should look
here. The new openshift-install also
includes an interactive configuration generator, so you can launch the
installer and follow along as it guides you through the process.
The tectonic command and tarball distribution are gone. Please use
the new openshift-install command instead.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →