4.22 version information and update actions

Review information about version 4.22 of Red Hat OpenShift on IBM Cloud. This version is based on Kubernetes version 1.35.

Looking for general information about updating clusters, or information on a different version? See Red Hat Red Hat OpenShift on IBM Cloud version information and the version 4.22 release notes.

This badge indicates Kubernetes version 1.35 certification for Red Hat OpenShift on IBM Cloud
Kubernetes version 1.35 certification badge

Red Hat OpenShift on IBM Cloud is a Certified Kubernetes product for version 1.35 under the CNCF Kubernetes Software Conformance Certification program. Kubernetes® is a registered trademark of The Linux Foundation in the United States and other countries, and is used pursuant to a license from The Linux Foundation.

Release timeline

The following table includes the expected release timeline for version 4.22. You can use this information for planning purposes, such as to estimate the general time that the version might become unsupported.

Dates that are marked with a dagger (†) are tentative and subject to change.

Release history for Red Hat OpenShift on IBM Cloud version 4.22.
Supported? Red Hat OpenShift / Kubernetes version Release date Unsupported date
Supported 4.22 / 1.35 28 September 2026 30 June 2028†

Preparing to update

Review changes that you might need to make when you update a cluster to version 4.22. This information summarizes updates that are likely to have an impact on deployed apps when you update.

The Satellite Location Sizing Requirements for hosting Red Hat OpenShift on IBM Cloud version 4.22 clusters are now the same regardless of the location being RHEL non-CoreOS or RHEL CoreOS based. The requirements for the location nodes should now follow those for CoreOS-enabled locations.

Portworx does not yet support Red Hat OpenShift on IBM Cloud version 4.22 clusters. Do not update your cluster to version 4.22 if Portworx is installed.

Starting with version 4.22, the cluster control plane is served over port 443 instead of a dynamically assigned node port (20000–32767 range). Traffic is routed using hostname-based routing through four purpose-built hostnames: <cluster>.api.<region-domain>, <cluster>.oauth.<region-domain>, <cluster>.tunnel.<region-domain>, and <cluster>.ignition.private.<region-domain>. The .api. and .oauth. hostnames are available over both the public and private service endpoints; the .tunnel. and .ignition.private. hostnames are private-only. This change affects not only kubectl/oc client traffic but also worker-to-control-plane traffic (kubelet API, Konnectivity, and RHCOS ignition). This change is available starting in the following regions: Montreal (ca-mon), Chennai (in-che), and Mumbai (in-mum). Support for additional regions is coming soon. For more information, see Cluster control plane reachable over port 443.

Update before master

The following table shows the actions that you must take before you update the cluster master.

For clusters that run version 4.22 or later, you can use the oc adm upgrade status command to check the update status of your cluster master during a master version update. For more information, see Viewing cluster upgrade status with the oc adm upgrade status command.

Changes to make before you update the master to Red Hat OpenShift 4.22
Type Description
Port 443 for cluster control plane The cluster control plane is now served over port 443 instead of a dynamically assigned node port (20000–32767 range). Four hostnames are used: <cluster>.api.<region-domain>, <cluster>.oauth.<region-domain>, <cluster>.tunnel.<region-domain>, and <cluster>.ignition.private.<region-domain>. The .tunnel. and .ignition.private. hostnames are private-only. This affects kubectl/oc clients, oc login, the web console, and worker-to-control-plane traffic (kubelet, Konnectivity, and RHCOS ignition). Action required: Update any firewall, security group, or egress allowlist rules that reference the old high-numbered control plane port to allow outbound HTTPS on port 443 to all four hostnames. If you use the public service endpoint, download a fresh kubeconfig by running ibmcloud ks cluster config or manually update the port in your existing kubeconfig to 443. If you use IP-based allowlists, update them to use the current Akamai IPP IP ranges, as the public service endpoint DNS records now resolve to Akamai IP Protect frontend addresses. For more information, see Understanding networking for ROKS clusters and Cluster control plane reachable over port 443.
Preparing to update OpenShift For more information, review the Preparing to update to OpenShift Container Platform 4.22 for possible actions required. The etcd backup, version selection, and SDN removal upgrade preparation actions do not apply to Red Hat OpenShift on IBM Cloud clusters since etcd backups and version selection actions are handled for you, and Calico is used instead of SDN.
Deprecated and removed OpenShift features For more information, review the OpenShift Container Platform version 4.22 deprecated and removed features for possible actions required.
Upgrade does not require administrator acknowledgement There are no API removals in this release.
Known OpenShift issues For more information, review the OpenShift Container Platform version 4.22 known issues for possible actions required.
Upgrade requires OpenShift cluster version currency A cluster master upgrade will be cancelled if the OpenShift cluster version status indicates that an update is already in progress. See Why does OpenShift show the cluster version is not up to date? for details.
Upgrade requires resolution to OpenShift cluster version upgradeable conditions A cluster master upgrade will be cancelled if the OpenShift cluster version Upgradeable status condition indicates that the cluster is not upgradeable. To determine if the cluster is upgradeable, see Checking the Upgradeable status of your cluster.

Checking the Upgradeable status of your cluster

Run the following command to check the Upgradeable status of your cluster.

oc get clusterversion version -o json | jq '.status.conditions[] | select(.type == "Upgradeable")'

Example output where the Upgradeable status is False.

{
  "lastTransitionTime": "2024-11-17T19:29:34Z",
  "message": "Cluster operator operator-lifecycle-manager should not be upgraded between minor versions: ClusterServiceVersions blocking cluster upgrade: default/test is incompatible with OpenShift minor versions greater than 4.16",
  "reason": "IncompatibleOperatorsInstalled",
  "status": "False",
  "type": "Upgradeable"
}

If the Upgradeable status is False, the condition information provides instructions that must be followed before upgrading.