Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion features.md
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,6 @@
| HyperShiftOnlyDynamicResourceAllocation| <span style="background-color: #519450">Enabled</span> | | <span style="background-color: #519450">Enabled</span> | | <span style="background-color: #519450">Enabled</span> | | <span style="background-color: #519450">Enabled</span> | |
| ImageModeStatusReporting| | | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | | | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> |
| IngressComponentRouteLabels| | | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | | | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> |
| IngressControllerMultipleHAProxyVersions| | | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | | | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> |
| IrreconcilableMachineConfig| | | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | | | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> |
| KMSEncryption| | | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | | | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> |
| MachineAPIMigration| | | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | | | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> |
Expand Down Expand Up @@ -108,6 +107,7 @@
| GatewayAPIWithoutOLM| <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> |
| ImageStreamImportMode| <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> |
| IngressControllerDynamicConfigurationManager| <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> |
| IngressControllerMultipleHAProxyVersions| <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> |
| InsightsConfig| <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> |
| InsightsOnDemandDataGather| <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> |
| KMSv1| <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> | <span style="background-color: #519450">Enabled</span> |
Expand Down
2 changes: 1 addition & 1 deletion features/features.go
Original file line number Diff line number Diff line change
Expand Up @@ -679,7 +679,7 @@ var (
contactPerson("miciah").
productScope(ocpSpecific).
enhancementPR("https://github.com/openshift/enhancements/pull/1965").
enable(inDevPreviewNoUpgrade(), inTechPreviewNoUpgrade()).
enable(inDefault(), inOKD(), inDevPreviewNoUpgrade(), inTechPreviewNoUpgrade()).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remediation recommended

1. 5.0-only value exposed 🐞 Bug ≡ Correctness

IngressControllerMultipleHAProxyVersions is now enabled for the Default and OKD feature sets without
any OpenShift major-version constraint, which makes spec.haproxyVersion accept "3.2" even on
payloads that target major version 4. This contradicts the API documentation that describes HAProxy
3.2 as introduced in OpenShift 5.0 and can let OpenShift 4.x clusters pass API validation with a
value that may not be supported by that release’s ingress payload/operator logic.
Agent Prompt
### Issue description
The feature gate `IngressControllerMultipleHAProxyVersions` is now enabled in `Default` and `OKD` for all generated OpenShift major versions, but the API type/doc explicitly describes HAProxy `3.2` as an OpenShift 5.0 introduction. This means OpenShift major version 4 payloads will advertise and validate a value (`"3.2"`) that is documented as 5.0-only.

### Issue Context
- The feature-gate payloads are annotated for major versions `4,5,6,7,8,9,10`.
- The `HAProxyVersion` type is enum-constrained to `"2.8";"3.2"`.
- The `haproxyVersion` field description states HAProxy 3.2 is the OpenShift 5.0 default.

### Fix Focus Areas
- features/features.go[677-683]

### How to fix
Update the feature gate registration to only enable this gate in `Default`/`OKD` for OpenShift major version >= 5 (e.g., by adding `inVersion(5, greaterThanOrEqual)` to the enable options for `inDefault()` and `inOKD()`), or otherwise make the exposed/validated values release-aware so major version 4 payloads do not validate/advertise `"3.2"` as a supported setting.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

mustRegister()

FeatureGateMinimumKubeletVersion = newFeatureGate("MinimumKubeletVersion").
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -924,6 +924,32 @@ spec:
required:
- type
type: object
haproxyVersion:
description: |-
haproxyVersion specifies the HAProxy version to use for this
IngressController.

OpenShift 5.0 introduces HAProxy 3.2 as its default version and supports
HAProxy 2.8 from OpenShift 4.22 for migration purposes. When an OpenShift
release introduces a new default HAProxy version, that HAProxy version
becomes available as a pinnable value in subsequent OpenShift releases,
providing a smooth migration path for administrators who want to defer
HAProxy upgrades.

Valid values for OpenShift 5.0:
- Unset (default): Uses HAProxy 3.2 (the default for OpenShift 5.0)
- "3.2": Explicitly pins HAProxy 3.2 for preservation during cluster
upgrades to future OpenShift releases
- "2.8": Uses HAProxy 2.8 from OpenShift 4.22 (migration support, will
be dropped in the next OpenShift release)

If a specific HAProxy version is set and would become unsupported in a
target cluster upgrade, a preflight check will block the cluster upgrade
until this field is updated to unset or a supported version.
enum:
- "2.8"
- "3.2"
type: string
httpCompression:
description: |-
httpCompression defines a policy for HTTP traffic compression.
Expand Down Expand Up @@ -2561,6 +2587,20 @@ spec:
domain:
description: domain is the actual domain in use.
type: string
effectiveHAProxyVersion:
description: |-
effectiveHAProxyVersion reports the HAProxy version currently in use by
this IngressController. This reflects the resolved value of the
spec.haproxyVersion field. When omitted, the effective value has not yet
been resolved by the operator or the feature is not enabled for this cluster.

Examples for OpenShift 5.0:
- "3.2": Using HAProxy 3.2
- "2.8": Using HAProxy 2.8
enum:
- "2.8"
- "3.2"
type: string
endpointPublishingStrategy:
description: endpointPublishingStrategy is the actual strategy in
use.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -924,6 +924,32 @@ spec:
required:
- type
type: object
haproxyVersion:
description: |-
haproxyVersion specifies the HAProxy version to use for this
IngressController.

OpenShift 5.0 introduces HAProxy 3.2 as its default version and supports
HAProxy 2.8 from OpenShift 4.22 for migration purposes. When an OpenShift
release introduces a new default HAProxy version, that HAProxy version
becomes available as a pinnable value in subsequent OpenShift releases,
providing a smooth migration path for administrators who want to defer
HAProxy upgrades.

Valid values for OpenShift 5.0:
- Unset (default): Uses HAProxy 3.2 (the default for OpenShift 5.0)
- "3.2": Explicitly pins HAProxy 3.2 for preservation during cluster
upgrades to future OpenShift releases
- "2.8": Uses HAProxy 2.8 from OpenShift 4.22 (migration support, will
be dropped in the next OpenShift release)

If a specific HAProxy version is set and would become unsupported in a
target cluster upgrade, a preflight check will block the cluster upgrade
until this field is updated to unset or a supported version.
enum:
- "2.8"
- "3.2"
type: string
httpCompression:
description: |-
httpCompression defines a policy for HTTP traffic compression.
Expand Down Expand Up @@ -2561,6 +2587,20 @@ spec:
domain:
description: domain is the actual domain in use.
type: string
effectiveHAProxyVersion:
description: |-
effectiveHAProxyVersion reports the HAProxy version currently in use by
this IngressController. This reflects the resolved value of the
spec.haproxyVersion field. When omitted, the effective value has not yet
been resolved by the operator or the feature is not enabled for this cluster.

Examples for OpenShift 5.0:
- "3.2": Using HAProxy 3.2
- "2.8": Using HAProxy 2.8
enum:
- "2.8"
- "3.2"
type: string
endpointPublishingStrategy:
description: endpointPublishingStrategy is the actual strategy in
use.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -161,9 +161,6 @@
{
"name": "IngressComponentRouteLabels"
},
{
"name": "IngressControllerMultipleHAProxyVersions"
},
{
"name": "IrreconcilableMachineConfig"
},
Expand Down Expand Up @@ -340,6 +337,9 @@
{
"name": "IngressControllerDynamicConfigurationManager"
},
{
"name": "IngressControllerMultipleHAProxyVersions"
},
{
"name": "InsightsConfig"
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -163,9 +163,6 @@
{
"name": "IngressComponentRouteLabels"
},
{
"name": "IngressControllerMultipleHAProxyVersions"
},
{
"name": "IrreconcilableMachineConfig"
},
Expand Down Expand Up @@ -342,6 +339,9 @@
{
"name": "IngressControllerDynamicConfigurationManager"
},
{
"name": "IngressControllerMultipleHAProxyVersions"
},
{
"name": "InsightsConfig"
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -164,9 +164,6 @@
{
"name": "IngressComponentRouteLabels"
},
{
"name": "IngressControllerMultipleHAProxyVersions"
},
{
"name": "IrreconcilableMachineConfig"
},
Expand Down Expand Up @@ -331,6 +328,9 @@
{
"name": "IngressControllerDynamicConfigurationManager"
},
{
"name": "IngressControllerMultipleHAProxyVersions"
},
{
"name": "InsightsConfig"
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -166,9 +166,6 @@
{
"name": "IngressComponentRouteLabels"
},
{
"name": "IngressControllerMultipleHAProxyVersions"
},
{
"name": "IrreconcilableMachineConfig"
},
Expand Down Expand Up @@ -333,6 +330,9 @@
{
"name": "IngressControllerDynamicConfigurationManager"
},
{
"name": "IngressControllerMultipleHAProxyVersions"
},
{
"name": "InsightsConfig"
},
Expand Down