Chapter 2. Release notes


You can review the following release notes to learn about changes in the Windows Machine Config Operator (WMCO) version 10.19.2.

Issued: 15 April 2026

You can review the following release notes to learn about the bug fixes provided in this release of the Windows Machine Config Operator (WMCO).

The components of the WMCO 10.19.2 were released in RHBA-2026:8345.

2.1.1.1. Bug fixes

  • Before this update, the hybridOverlay service was not using the trusted CA bundle when connecting to OpenShift Container Platform, because the --k8s-cacert option was missing from the service command. Because of this, users could encounter trust issues or failures when the hybridOverlay service attempted to communicate securely with OpenShift Container Platform clusters by using custom or internal CAs. With this release, the hybridOverlay service command now includes the --k8s-cacert flag that points to the trusted CA bundle. As a result, the hybridOverlay service uses the trusted CA bundle for secure communication, preventing trust issues and ensuring compatibility with the cluster. (OCPBUGS-65856)

You can review the following release notes to learn about changes in previous versions of the Custom Metrics Autoscaler Operator.

For the current version, see Red Hat OpenShift support for Windows Containers release notes.

Issued: 11 November 2025

You can review the following release notes to learn about the bug fixes provided in this release of the Windows Machine Config Operator (WMCO).

2.2.1.1. Bug fixes

  • Before this update, the hybridOverlay service was not using the trusted CA bundle when connecting to Kubernetes because the hybridOverlay service command was missing the --k8s-cacert option. As a consequence, users could have encountered trust issues or failures when the hybridOverlay service attempted to communicate securely with Kubernetes clusters using custom or internal CAs. With this release, the hybridOverlay service command now includes the --k8s-cacert flag pointing to the trusted CA bundle. As a result, the hybridOverlay service uses the trusted CA bundle for secure communication, preventing trust issues and ensuring compatibility with the cluster.
  • Before this update, the WMCO neglected to close SSH connections when finishing node reconciliation. As a consequence, after adding a new Windows node to a cluster, the node SSH server would eventually refuse new connections due to being overwhelmed, causing node management issues. With this release, the WMCO now properly closes SSH connections. As a result, the node SSH servers no longer refuse new connections due to this problem. (OCPBUGS-60775)
  • Before this update, if an internally used config map needed to be deleted and re-created, a nil error was dereferenced when logging the event. As a consequence, the WMCO pod panicked and restarted. With this release, the error handling logic has been reworked. As a result, the Operator pod no longer panics. (OCPBUGS-60792)
  • Before this update, during secret reconciliations, secret change data was being added to the logs on each reconciliation loop. As a result, this secret change data was persisting, causing the logs to grow in size with unrelated data. With this release, only the current secret change data is being logged, reducing the size and complexity of the logs. (OCPBUGS-61832)

The components of the WMCO 10.19.0 were released in RHSA-2025:14048.

2.2.2.1. New features and improvements

WMCO kubelet configuration changes

With this release, the WMCO now sets the following values in the KubeletConfig custom resource (CR):

  • The system-reserved parameter on new Windows nodes is now set to 2GiB of memory for system processes by default, as recommended in the Kubernetes documentation. (WINC-1373)
  • The enforceNodeAllocatable on new Windows nodes is now set to none by default. Previously, the value was set to [] to avoid a known issue. Both settings disable the enforcement of node allocatable resource limits. (WINC-926)
  • The evictionHard parameters, imagefs.available and nodefs.available, are now set to 15% and 10% respectively by default, as recommended in the Kubernetes documentation. (WINC-1374)

The KubeletConfig object configures the kubelet service, which runs on each node in the cluster to ensure that containers in a pod are running.

WMCO kubelet configuration changes
For disconnected clusters, the Windows AMI that you are using must have the EC2LaunchV2 agent version 2.0.2107 or later installed. Previously, the minimum required EC2LaunchV2 agent version was 2.0.1643. For more information, see the Install the latest version of EC2Launch v2 in the AWS documentation.

2.2.2.2. Bug fixes

  • Before this update, when using the optional_namespaces parameter in an ImageTagMirrorSet CR, Windows nodes could fail to pull the specified image, resulting in a image not found error. With this release, the optional_namespace parameter works as expected. (OCPBUGS-47696)
  • Before this update, Windows Server 2019 nodes did not have a running an SSH server because of network instability. As a result, you were unable to SSH into that node. With this release, the WMCO installs the SSH server node creation. As a result, you can SSH into the Windows nodes as expected. (OCPBUGS-56131)
  • Before this update, because an Endpoint_IP variable was not resolving, the Windows Instance Config Daemon (WICD) repeatedly reported an Endpoint_IP error. With this release, retries are added to ensure that the Endpoint_IP is created before continuing. As a result, the error message is no longer reported. (OCPBUGS-1721)

2.2.2.3. Known issues

  • Some Windows 2019 Bring-Your-Own-Host (BYOH) Window instances could enter a non-ready state after upgrading to 4.19. Red Hat has not been able to reproduce the issue outside the testing environment, and advises caution when upgrading. If you experience this situation, restart the non-ready instance. (OCPBUGS-47696)

2.3. Windows Machine Config Operator prerequisites

The following information details the supported platform versions, Windows Server versions, and networking configurations for the Windows Machine Config Operator (WMCO). See the vSphere documentation for any information that is relevant to only that platform.

2.3.1. WMCO supported installation method

The WMCO fully supports installing Windows nodes into installer-provisioned infrastructure (IPI) clusters. This is the preferred OpenShift Container Platform installation method.

For user-provisioned infrastructure (UPI) clusters, the WMCO supports installing Windows nodes only into a UPI cluster installed with the platform: none field set in the install-config.yaml file (bare-metal or provider-agnostic) and only for the BYOH (Bring Your Own Host) use case. UPI is not supported for any other platform.

The following table lists the Windows Server versions that are supported by WMCO 10-19.0, based on the applicable platform. Windows Server versions not listed are not supported and attempting to use them will cause errors. To prevent these errors, use only an appropriate version for your platform.

Expand
PlatformSupported Windows Server version

Amazon Web Services (AWS)

  • Windows Server 2022, OS Build 20348.681 or later [1]
  • Windows Server 2019, version 1809

Microsoft Azure

  • Windows Server 2022, OS Build 20348.681 or later
  • Windows Server 2019, version 1809

VMware vSphere

Windows Server 2022, OS Build 20348.681 or later

Google Cloud

Windows Server 2022, OS Build 20348.681 or later

Nutanix

Windows Server 2022, OS Build 20348.681 or later

Bare metal or provider agnostic

  • Windows Server 2022, OS Build 20348.681 or later
  • Windows Server 2019, version 1809
  1. For disconnected clusters, the Windows AMI must have the EC2LaunchV2 agent version 2.0.2107 or later installed. For more information, see the Install the latest version of EC2Launch v2 in the AWS documentation.

2.3.3. Supported networking

Hybrid networking with OVN-Kubernetes is the only supported networking configuration. See the additional resources below for more information on this functionality. The following tables outline the type of networking configuration and Windows Server versions to use based on your platform. You must specify the network configuration when you install the cluster.

Note
  • The WMCO does not support OVN-Kubernetes without hybrid networking or OpenShift SDN.
  • Dual NIC is not supported on WMCO-managed Windows instances.
Expand
Table 2.1. Platform networking support
PlatformSupported networking

Amazon Web Services (AWS)

Hybrid networking with OVN-Kubernetes

Microsoft Azure

Hybrid networking with OVN-Kubernetes

VMware vSphere

Hybrid networking with OVN-Kubernetes with a custom VXLAN port

Google Cloud

Hybrid networking with OVN-Kubernetes

Nutanix

Hybrid networking with OVN-Kubernetes

Bare metal or provider agnostic

Hybrid networking with OVN-Kubernetes

Expand
Table 2.2. Hybrid OVN-Kubernetes Windows Server support
Hybrid networking with OVN-KubernetesSupported Windows Server version

Default VXLAN port

  • Windows Server 2022, OS Build 20348.681 or later
  • Windows Server 2019, version 1809

Custom VXLAN port

Windows Server 2022, OS Build 20348.681 or later

Note the following limitations when working with Windows nodes managed by the WMCO (Windows nodes):

  • The following OpenShift Container Platform features are not supported on Windows nodes:

    • Image builds
    • OpenShift Pipelines
    • OpenShift Service Mesh
    • OpenShift monitoring of user-defined projects
    • OpenShift Serverless
    • Horizontal Pod Autoscaling
    • Vertical Pod Autoscaling
    • Hosted Control Planes
  • The following Red Hat features are not supported on Windows nodes:

  • Dual NIC is not supported on WMCO-managed Windows instances.
  • Windows nodes do not support workloads created by using deployment configs. You can use a deployment or other method to deploy workloads.
  • Red Hat OpenShift support for Windows Containers does not support adding Windows nodes to a cluster through a trunk port. The only supported networking configuration for adding Windows nodes is through an access port that carries traffic for the VLAN.
  • Red Hat OpenShift support for Windows Containers does not support any Windows operating system language other than English (United States).
  • Due to a limitation within the Windows operating system, clusterNetwork CIDR addresses of class E, such as 240.0.0.0, are not compatible with Windows nodes.
  • Kubernetes has identified the following node feature limitations :

    • Huge pages are not supported for Windows containers.
    • Privileged containers are not supported for Windows containers.
  • Kubernetes has identified several API compatibility issues.
Red Hat logoGithubredditYoutubeTwitter

Learn

Try, buy, & sell

Communities

About Red Hat Documentation

We help Red Hat users innovate and achieve their goals with our products and services with content they can trust. Explore our recent updates.

Making open source more inclusive

Red Hat is committed to replacing problematic language in our code, documentation, and web properties. For more details, see the Red Hat Blog.

About Red Hat

We deliver hardened solutions that make it easier for enterprises to work across platforms and environments, from the core datacenter to the network edge.

Theme

© 2026 Red Hat
Back to top