diff --git a/go.mod b/go.mod
index f77413eab8d8..4738e0301425 100644
--- a/go.mod
+++ b/go.mod
@@ -65,10 +65,10 @@ require (
github.com/opencontainers/go-digest v1.0.0
github.com/openshift-eng/openshift-tests-extension v0.0.0-20260626105913-1f81f3df939a
github.com/openshift-kni/commatrix v0.0.5-0.20251111204857-e5a931eff73f
- github.com/openshift/api v0.0.0-20260717133910-57eb58a15422
+ github.com/openshift/api v0.0.0-20260817165856-9fda5179a7f7
github.com/openshift/apiserver-library-go v0.0.0-20260303173613-cd3676268d31
github.com/openshift/build-machinery-go v0.0.0-20250530140348-dc5b2804eeee
- github.com/openshift/client-go v0.0.0-20260720094807-fbc45213df28
+ github.com/openshift/client-go v0.0.0-20260818144019-860af65a7cbc
github.com/openshift/library-go v0.0.0-20260303171201-5d9eb6295ff6
github.com/ovn-org/ovn-kubernetes/go-controller v0.0.0-20250118001652-a8b9c3c31417
github.com/pborman/uuid v1.2.0
diff --git a/go.sum b/go.sum
index 6b0b7a15def3..470870b3d968 100644
--- a/go.sum
+++ b/go.sum
@@ -878,14 +878,14 @@ github.com/openshift-eng/openshift-tests-extension v0.0.0-20260626105913-1f81f3d
github.com/openshift-eng/openshift-tests-extension v0.0.0-20260626105913-1f81f3df939a/go.mod h1:pHOS9c6BjZv91OkkHyIHAOWnYhxwcxWQkyYGEvPyUCE=
github.com/openshift-kni/commatrix v0.0.5-0.20251111204857-e5a931eff73f h1:E72Zoc+JImPehBrXkgaCbIDbSFuItvyX6RCaZ0FQE5k=
github.com/openshift-kni/commatrix v0.0.5-0.20251111204857-e5a931eff73f/go.mod h1:cDVdp0eda7EHE6tLuSeo4IqPWdAX/KJK+ogBirIGtsI=
-github.com/openshift/api v0.0.0-20260717133910-57eb58a15422 h1:XIUxnjPKf+qjoOGrdjow458H9hgA4sx3QKACCt+Fy58=
-github.com/openshift/api v0.0.0-20260717133910-57eb58a15422/go.mod h1:pyVjK0nZ4sRs4fuQVQ4rubsJdahI1PB94LnQ8sGdvxo=
+github.com/openshift/api v0.0.0-20260817165856-9fda5179a7f7 h1:uFNuAmnV94fsPpmFuO2yDz0N3xy1+L5N802hPoNHVVw=
+github.com/openshift/api v0.0.0-20260817165856-9fda5179a7f7/go.mod h1:pyVjK0nZ4sRs4fuQVQ4rubsJdahI1PB94LnQ8sGdvxo=
github.com/openshift/apiserver-library-go v0.0.0-20260303173613-cd3676268d31 h1:oYPQMrkzyk002L5aN8I2tkUHTEu9lsVrc1qiJmHJdXU=
github.com/openshift/apiserver-library-go v0.0.0-20260303173613-cd3676268d31/go.mod h1:mnTsMMTtXSPBQzqBp5HXBjLvliveKenRADFQy9m5jc0=
github.com/openshift/build-machinery-go v0.0.0-20250530140348-dc5b2804eeee h1:+Sp5GGnjHDhT/a/nQ1xdp43UscBMr7G5wxsYotyhzJ4=
github.com/openshift/build-machinery-go v0.0.0-20250530140348-dc5b2804eeee/go.mod h1:8jcm8UPtg2mCAsxfqKil1xrmRMI3a+XU2TZ9fF8A7TE=
-github.com/openshift/client-go v0.0.0-20260720094807-fbc45213df28 h1:7umi+uA/Bm1PAEXduwzfQRsMZ8WR0/LHh9YXezJnxaA=
-github.com/openshift/client-go v0.0.0-20260720094807-fbc45213df28/go.mod h1:dOrynOHvh9q01db+7+Eu8O0do1FTrAUQSnI9tzJhO8Y=
+github.com/openshift/client-go v0.0.0-20260818144019-860af65a7cbc h1:CBh9auSrUo+N2gIP/uf5lNn9WfYiHRo7yNql9CNP8PE=
+github.com/openshift/client-go v0.0.0-20260818144019-860af65a7cbc/go.mod h1:KlQTifDju+xKbhiWzjcM3SMYpMfJw2Xb0jNzFW30/F4=
github.com/openshift/kubernetes v0.0.0-20260305123649-d18f3f005eaa h1:4TK07egSJrny442x0Kl0HgzXgt2lnCKTKHF3sbL2U3E=
github.com/openshift/kubernetes v0.0.0-20260305123649-d18f3f005eaa/go.mod h1:1r2FIoYrPU0110cjYlWAwNcbiqRPLWAgmZK4d0YeEZw=
github.com/openshift/kubernetes/staging/src/k8s.io/api v0.0.0-20260305123649-d18f3f005eaa h1:ifOqAFthJWnT1HS6Sq2AcLQWNSJ1+XEiyA9eo+PIcR0=
diff --git a/vendor/github.com/openshift/api/features.md b/vendor/github.com/openshift/api/features.md
index 97062fde68e9..f35301ac2921 100644
--- a/vendor/github.com/openshift/api/features.md
+++ b/vendor/github.com/openshift/api/features.md
@@ -21,7 +21,6 @@
| NewOLMConfigAPI| | | | Enabled | | | | Enabled |
| NewOLMOwnSingleNamespace| | | | Enabled | | | | Enabled |
| NewOLMPreflightPermissionChecks| | | | Enabled | | | | Enabled |
-| NoRegistryClusterInstall| | | | Enabled | | | | Enabled |
| ProvisioningRequestAvailable| | | Enabled | Enabled | | | | |
| VSphereMultiVCenterDay2| | | Enabled | Enabled | | | | |
| AWSClusterHostedDNS| | | Enabled | Enabled | | | Enabled | Enabled |
@@ -77,6 +76,7 @@
| NewOLM| | Enabled | | Enabled | | Enabled | | Enabled |
| NewOLMWebhookProviderOpenshiftServiceCA| | Enabled | | Enabled | | Enabled | | Enabled |
| NoOverlayMode| | | Enabled | Enabled | | | Enabled | Enabled |
+| NoRegistryClusterInstall| | Enabled | | Enabled | | Enabled | | Enabled |
| NutanixMultiSubnets| | | Enabled | Enabled | | | Enabled | Enabled |
| OSStreams| | | Enabled | Enabled | | | Enabled | Enabled |
| OVNObservability| | | Enabled | Enabled | | | Enabled | Enabled |
diff --git a/vendor/github.com/openshift/api/features/features.go b/vendor/github.com/openshift/api/features/features.go
index 30523fa067ca..4fa3616a727d 100644
--- a/vendor/github.com/openshift/api/features/features.go
+++ b/vendor/github.com/openshift/api/features/features.go
@@ -822,7 +822,7 @@ var (
contactPerson("andfasano").
productScope(ocpSpecific).
enhancementPR("https://github.com/openshift/enhancements/pull/1821").
- enable(inClusterProfile(SelfManaged), inTechPreviewNoUpgrade(), inDevPreviewNoUpgrade()).
+ enable(inDefault(), inOKD(), inClusterProfile(SelfManaged), inTechPreviewNoUpgrade(), inDevPreviewNoUpgrade()).
mustRegister()
FeatureGateAWSClusterHostedDNSInstall = newFeatureGate("AWSClusterHostedDNSInstall").
diff --git a/vendor/github.com/openshift/api/operator/v1/types_ingress.go b/vendor/github.com/openshift/api/operator/v1/types_ingress.go
index 0c5cf919e15b..e197a05cdc6c 100644
--- a/vendor/github.com/openshift/api/operator/v1/types_ingress.go
+++ b/vendor/github.com/openshift/api/operator/v1/types_ingress.go
@@ -385,6 +385,25 @@ type IngressControllerSpec struct {
// +kubebuilder:default:="Continue"
// +default="Continue"
ClosedClientConnectionPolicy IngressControllerClosedClientConnectionPolicy `json:"closedClientConnectionPolicy,omitempty"`
+
+ // haproxyVersion specifies the HAProxy version to use for this
+ // IngressController.
+ //
+ // This field is available in OpenShift 4.22 as an API-only backport with no
+ // operator implementation. Setting this field on OpenShift 4.22 allows
+ // administrators to pin HAProxy 2.8 before upgrading to OpenShift 5.0, where
+ // the operator will honor this setting.
+ //
+ // Valid values for OpenShift 4.22:
+ // - Unset (default): Uses HAProxy 2.8 (the default for OpenShift 4.22)
+ // - "2.8": Explicitly pins HAProxy 2.8 for preservation during cluster
+ // upgrade to OpenShift 5.0
+ //
+ // On OpenShift 4.22, this field has no effect on the running IngressController.
+ // It only preserves the administrator's intent for the OpenShift 5.0 upgrade.
+ //
+ // +optional
+ HAProxyVersion HAProxyVersion `json:"haproxyVersion,omitempty"`
}
// httpCompressionPolicy turns on compression for the specified MIME types.
@@ -2285,3 +2304,15 @@ const (
// server's response regardless of the client having closed the connection.
IngressControllerClosedClientConnectionPolicyContinue IngressControllerClosedClientConnectionPolicy = "Continue"
)
+
+// HAProxyVersion is a string representing a HAProxy minor version in "X.Y"
+// format. The allowed values are constrained by enum validation and vary by
+// OpenShift release.
+//
+// +kubebuilder:validation:Enum="2.8"
+type HAProxyVersion string
+
+const (
+ // HAProxyVersion28 represents HAProxy 2.8, shipped with OpenShift 4.22.
+ HAProxyVersion28 HAProxyVersion = "2.8"
+)
diff --git a/vendor/github.com/openshift/api/operator/v1/zz_generated.swagger_doc_generated.go b/vendor/github.com/openshift/api/operator/v1/zz_generated.swagger_doc_generated.go
index c3ed726028de..ebc52b6ad7c8 100644
--- a/vendor/github.com/openshift/api/operator/v1/zz_generated.swagger_doc_generated.go
+++ b/vendor/github.com/openshift/api/operator/v1/zz_generated.swagger_doc_generated.go
@@ -1082,6 +1082,7 @@ var map_IngressControllerSpec = map[string]string{
"httpCompression": "httpCompression defines a policy for HTTP traffic compression. By default, there is no HTTP compression.",
"idleConnectionTerminationPolicy": "idleConnectionTerminationPolicy maps directly to HAProxy's idle-close-on-response option and controls whether HAProxy keeps idle frontend connections open during a soft stop (router reload).\n\nAllowed values for this field are \"Immediate\" and \"Deferred\". The default value is \"Immediate\".\n\nWhen set to \"Immediate\", idle connections are closed immediately during router reloads. This ensures immediate propagation of route changes but may impact clients sensitive to connection resets.\n\nWhen set to \"Deferred\", HAProxy will maintain idle connections during a soft reload instead of closing them immediately. These connections remain open until any of the following occurs:\n\n - A new request is received on the connection, in which\n case HAProxy handles it in the old process and closes\n the connection after sending the response.\n\n - HAProxy's `timeout http-keep-alive` duration expires.\n By default this is 300 seconds, but it can be changed\n using httpKeepAliveTimeout tuning option.\n\n - The client's keep-alive timeout expires, causing the\n client to close the connection.\n\nSetting Deferred can help prevent errors in clients or load balancers that do not properly handle connection resets. Additionally, this option allows you to retain the pre-2.4 HAProxy behaviour: in HAProxy version 2.2 (OpenShift versions < 4.14), maintaining idle connections during a soft reload was the default behaviour, but starting with HAProxy 2.4, the default changed to closing idle connections immediately.\n\nImportant Consideration:\n\n - Using Deferred will result in temporary inconsistencies\n for the first request on each persistent connection\n after a route update and router reload. This request\n will be processed by the old HAProxy process using its\n old configuration. Subsequent requests will use the\n updated configuration.\n\nOperational Considerations:\n\n - Keeping idle connections open during reloads may lead\n to an accumulation of old HAProxy processes if\n connections remain idle for extended periods,\n especially in environments where frequent reloads\n occur.\n\n - Consider monitoring the number of HAProxy processes in\n the router pods when Deferred is set.\n\n - You may need to enable or adjust the\n `ingress.operator.openshift.io/hard-stop-after`\n duration (configured via an annotation on the\n IngressController resource) in environments with\n frequent reloads to prevent resource exhaustion.",
"closedClientConnectionPolicy": "closedClientConnectionPolicy controls how the IngressController behaves when the client closes the TCP connection while the TLS handshake or HTTP request is in progress. This option maps directly to HAProxy’s \"abortonclose\" option.\n\nValid values are: \"Abort\" and \"Continue\". The default value is \"Continue\".\n\nWhen set to \"Abort\", the router will stop processing the TLS handshake if it is in progress, and it will not send an HTTP request to the backend server if the request has not yet been sent when the client closes the connection.\n\nWhen set to \"Continue\", the router will complete the TLS handshake if it is in progress, or send an HTTP request to the backend server and wait for the backend server's response, regardless of whether the client has closed the connection.\n\nSetting \"Abort\" can help free CPU resources otherwise spent on TLS computation for connections the client has already closed, and can reduce request queue size, thereby reducing the load on saturated backend servers.\n\nImportant Considerations:\n\n - The default policy (\"Continue\") is HTTP-compliant, and requests\n for aborted client connections will still be served.\n Use the \"Continue\" policy to allow a client to send a request\n and then immediately close its side of the connection while\n still receiving a response on the half-closed connection.\n\n - When clients use keep-alive connections, the most common case for premature\n closure is when the user wants to cancel the transfer or when a timeout\n occurs. In that case, the \"Abort\" policy may be used to reduce resource consumption.\n\n - Using RSA keys larger than 2048 bits can significantly slow down\n TLS computations. Consider using the \"Abort\" policy to reduce CPU usage.",
+ "haproxyVersion": "haproxyVersion specifies the HAProxy version to use for this IngressController.\n\nThis field is available in OpenShift 4.22 as an API-only backport with no operator implementation. Setting this field on OpenShift 4.22 allows administrators to pin HAProxy 2.8 before upgrading to OpenShift 5.0, where the operator will honor this setting.\n\nValid values for OpenShift 4.22: - Unset (default): Uses HAProxy 2.8 (the default for OpenShift 4.22) - \"2.8\": Explicitly pins HAProxy 2.8 for preservation during cluster\n upgrade to OpenShift 5.0\n\nOn OpenShift 4.22, this field has no effect on the running IngressController. It only preserves the administrator's intent for the OpenShift 5.0 upgrade.",
}
func (IngressControllerSpec) SwaggerDoc() map[string]string {
diff --git a/vendor/github.com/openshift/client-go/operator/applyconfigurations/operator/v1/ingresscontrollerspec.go b/vendor/github.com/openshift/client-go/operator/applyconfigurations/operator/v1/ingresscontrollerspec.go
index 9874c3b63bb3..8907a8c75ce3 100644
--- a/vendor/github.com/openshift/client-go/operator/applyconfigurations/operator/v1/ingresscontrollerspec.go
+++ b/vendor/github.com/openshift/client-go/operator/applyconfigurations/operator/v1/ingresscontrollerspec.go
@@ -285,6 +285,22 @@ type IngressControllerSpecApplyConfiguration struct {
// - Using RSA keys larger than 2048 bits can significantly slow down
// TLS computations. Consider using the "Abort" policy to reduce CPU usage.
ClosedClientConnectionPolicy *operatorv1.IngressControllerClosedClientConnectionPolicy `json:"closedClientConnectionPolicy,omitempty"`
+ // haproxyVersion specifies the HAProxy version to use for this
+ // IngressController.
+ //
+ // This field is available in OpenShift 4.22 as an API-only backport with no
+ // operator implementation. Setting this field on OpenShift 4.22 allows
+ // administrators to pin HAProxy 2.8 before upgrading to OpenShift 5.0, where
+ // the operator will honor this setting.
+ //
+ // Valid values for OpenShift 4.22:
+ // - Unset (default): Uses HAProxy 2.8 (the default for OpenShift 4.22)
+ // - "2.8": Explicitly pins HAProxy 2.8 for preservation during cluster
+ // upgrade to OpenShift 5.0
+ //
+ // On OpenShift 4.22, this field has no effect on the running IngressController.
+ // It only preserves the administrator's intent for the OpenShift 5.0 upgrade.
+ HAProxyVersion *operatorv1.HAProxyVersion `json:"haproxyVersion,omitempty"`
}
// IngressControllerSpecApplyConfiguration constructs a declarative configuration of the IngressControllerSpec type for use with
@@ -444,3 +460,11 @@ func (b *IngressControllerSpecApplyConfiguration) WithClosedClientConnectionPoli
b.ClosedClientConnectionPolicy = &value
return b
}
+
+// WithHAProxyVersion sets the HAProxyVersion field in the declarative configuration to the given value
+// and returns the receiver, so that objects can be built by chaining "With" function invocations.
+// If called multiple times, the HAProxyVersion field is set to the value of the last call.
+func (b *IngressControllerSpecApplyConfiguration) WithHAProxyVersion(value operatorv1.HAProxyVersion) *IngressControllerSpecApplyConfiguration {
+ b.HAProxyVersion = &value
+ return b
+}
diff --git a/vendor/modules.txt b/vendor/modules.txt
index 8ca92f975f55..9a5abd693ba6 100644
--- a/vendor/modules.txt
+++ b/vendor/modules.txt
@@ -1573,7 +1573,7 @@ github.com/openshift-kni/commatrix/pkg/matrix-diff
github.com/openshift-kni/commatrix/pkg/mcp
github.com/openshift-kni/commatrix/pkg/types
github.com/openshift-kni/commatrix/pkg/utils
-# github.com/openshift/api v0.0.0-20260717133910-57eb58a15422
+# github.com/openshift/api v0.0.0-20260817165856-9fda5179a7f7
## explicit; go 1.25.0
github.com/openshift/api
github.com/openshift/api/annotations
@@ -1686,7 +1686,7 @@ github.com/openshift/build-machinery-go/make/targets/golang
github.com/openshift/build-machinery-go/make/targets/openshift
github.com/openshift/build-machinery-go/make/targets/openshift/operator
github.com/openshift/build-machinery-go/scripts
-# github.com/openshift/client-go v0.0.0-20260720094807-fbc45213df28
+# github.com/openshift/client-go v0.0.0-20260818144019-860af65a7cbc
## explicit; go 1.25.0
github.com/openshift/client-go/apiserver/applyconfigurations/apiserver/v1
github.com/openshift/client-go/apiserver/applyconfigurations/internal