Skip to content

Rebase release-4.21 to Kubernetes v1.34.11 - #2755

Open
redhat-chai-bot wants to merge 36 commits into
openshift:release-4.21from
redhat-chai-bot:rebase-v1.34.11
Open

Rebase release-4.21 to Kubernetes v1.34.11#2755
redhat-chai-bot wants to merge 36 commits into
openshift:release-4.21from
redhat-chai-bot:rebase-v1.34.11

Conversation

@redhat-chai-bot

Copy link
Copy Markdown

Summary

Rebase openshift/kubernetes:release-4.21 from Kubernetes v1.34.9 to v1.34.11.

Upstream release: https://github.com/kubernetes/kubernetes/releases/tag/v1.34.11

Rebase details

  • Upstream tag v1.34.11 was merged into the release-4.21 branch
  • Vendor directory and go.mod/go.sum updated via hack/update-vendor.sh and make update
  • Hyperkube image rebuilt

How to verify

git fetch origin pull/<PR_NUMBER>/head:pr-rebase-4.21
git log --oneline pr-rebase-4.21 | head -20

Confirm v1.34.11 tag merge is present and vendor is consistent.


AI-generated. Review for accuracy.

@jubittajohn requested in Slack thread

yongruilin and others added 30 commits March 11, 2026 23:23
Add a mutex to protect the global policyRefreshInterval. This prevents a data race during tests where SetPolicyRefreshIntervalForTests writes to the variable while a background goroutine reads it.
Move isLearner and isStarted variables to the outer var block of
MemberPromote so their values are accessible after the poll loop.
After the poll, if isLearner is false the member was already promoted,
so return nil early without issuing a redundant promote call.
Signed-off-by: Siyuan Zhang <sizhang@google.com>
When manageJob() needs to create replacement pods but defers creation
because a pod-failure backoff is still active, it returned a hardcoded
active=0 to the caller. Because no pods were actually created or deleted,
this left Status.Active=0 while Status.Ready still reflected the running
pods. The apiserver correctly rejects such updates ("cannot set more
ready pods than active") with a 422, which blocks flushing uncounted
terminated pods, removing finalizers, and updating job status, leaving
pods stuck Terminating with stale status.

Return the real active count from both backoff early-returns instead,
since the deferral does not change the number of active pods.

Issue: kubernetes#139428
(cherry picked from commit 2fe49b0)
…c996af

Pins google.golang.org/protobuf to HEAD commit f2248ac996afc39b3df0777cdcc269f6ade50b07
(v1.36.12-0.20260120151049-f2248ac996af) which includes fixes for dead code
elimination issues surfaced by Go 1.26's reflect changes.

Xref: golang/protobuf#1704
Xref: kubernetes#137445
Signed-off-by: Davanum Srinivas <davanum@gmail.com>
During kubeadm join, the mandatory kubeadm-config ConfigMap fetch uses
GetConfigMapWithShortRetry, which has a 350ms polling budget. When the
API server is slow to respond, the single GET attempt blocks for up to
10 seconds (the client timeout), exhausting the polling budget with no
retry. Since this call site has no fallback, the join fails.

Add a shortConfigMapGet parameter to getInitConfigurationFromCluster
and FetchInitConfigurationFromCluster. When false, the kubeadm-config
ConfigMap is fetched using KubernetesAPICallTimeout (default 1 minute,
user-configurable) with retries, matching the pattern used by
getAPIEndpointFromPodAnnotation. When true, the existing
GetConfigMapWithShortRetry is used for callers like kubeadm reset that
don't need a long retry.

Signed-off-by: Damiano Donati <damiano.donati@gmail.com>
…-of-139667-release-1.34

Automated cherry pick of kubernetes#139667: fix(kubeadm): use KubernetesAPICallTimeout for mandatory kubeadm-config fetch during join
…-of-#137451-upstream-release-1.34

Automated cherry pick of kubernetes#137451: Update google.golang.org/protobuf to v1.36.12-0.20260120151049-f2248ac996af to prevent file size explosion in go 1.26
…ck-of-#139964-upstream-release-1.34

[1.34] Automated cherry pick of kubernetes#139964: Restore string JSON encoding of cri-api KeyValue
…-pick-of-#139842-upstream-release-1.34

Automated cherry pick of kubernetes#139842: kubeadm: treat already promoted learner as successful
…-pick-of-#138584-upstream-release-1.34

Automated cherry pick of kubernetes#138584: [chore] test/compatibility_lifecycle: resolve feature names from variables
…erry-pick-of-#139457-upstream-release-1.34

Fix job controller reporting active=0 during pod creation backoff [1.34]
…-pick-of-#134829-upstream-release-1.34

Automated cherry pick of kubernetes#134829: test: Fix data race on policy refresh interval
…ck-of-#138390-origin-release-1.34

Automated cherry pick of kubernetes#138390: kubeadm: skip promote call when etcd member is already a voting member
…bles

Signed-off-by: Nabarun Pal <pal.nabarun95@gmail.com>
…ck-of-#139121-upstream-release-1.34

Automated cherry pick of kubernetes#139121: kubelet: defer CRI fallback removal to 1.38
…-pick-of-#140163-upstream-release-1.34

Automated cherry pick of kubernetes#140163: kubelet: stop logging missing optional container annotations
[release-1.34] Bump images and versions to golang 1.25.12 and update distroless-iptables
@openshift-ci-robot openshift-ci-robot added the backports/unvalidated-commits Indicates that not all commits come to merged upstream PRs. label Aug 21, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@redhat-chai-bot: the contents of this pull request could not be automatically validated.

The following commits could not be validated and must be approved by a top-level approver:

Comment /validate-backports to re-evaluate validity of the upstream PRs, for example when they are merged upstream.

@coderabbitai

coderabbitai Bot commented Aug 21, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 6d306cac-9e0d-4dc8-9a71-e0e96677d0a3

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@openshift-merge-bot

Copy link
Copy Markdown

Pipeline controller notification
This repo is configured to use the pipeline controller. Second-stage tests will be triggered either automatically or after lgtm label is added, depending on the repository configuration. The pipeline controller will automatically detect which contexts are required and will utilize /test Prow commands to trigger the second stage.

For optional jobs, comment /test ? to see a list of all defined jobs. To trigger manually all jobs from second stage use /pipeline required command.

This repository is configured in: LGTM mode

@openshift-ci
openshift-ci Bot requested review from jacobsee and rphillips August 21, 2026 15:53
@openshift-ci openshift-ci Bot added the vendor-update Touching vendor dir or related files label Aug 21, 2026
@openshift-ci

openshift-ci Bot commented Aug 21, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: redhat-chai-bot
Once this PR has been reviewed and has the lgtm label, please assign jubittajohn for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci

openshift-ci Bot commented Aug 21, 2026

Copy link
Copy Markdown

@redhat-chai-bot: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/verify 18d565b link true /test verify
ci/prow/unit 18d565b link true /test unit
ci/prow/okd-scos-images 18d565b link true /test okd-scos-images
ci/prow/integration 18d565b link true /test integration
ci/prow/images 18d565b link true /test images
ci/prow/artifacts 18d565b link true /test artifacts

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backports/unvalidated-commits Indicates that not all commits come to merged upstream PRs. vendor-update Touching vendor dir or related files

Projects

None yet

Development

Successfully merging this pull request may close these issues.