---
title: "Upgrade Calico on OpenShift 4"
description: "Upgrade Calico Open Source on OpenShift 4 by reapplying the manifests for the new release."
product: "Calico Open Source"
version: "3.33 (latest)"
section: "Installing and upgrading"
canonical_url: "https://docs.tigera.io/calico/latest/operations/upgrading/openshift-upgrade"
---

# Upgrade Calico on OpenShift 4

## About upgrading Calico

Before you start, review the [upgrade notes](https://docs.tigera.io/calico/latest/operations/upgrading/upgrade-notes.md) for changes in each release that need your attention.

This page covers upgrading to v3.33 from the two previous Calico releases.

It applies to an existing Calico cluster on OpenShift 4.

## Upgrading Calico on OpenShift 4

Apply the updated manifests.

```bash
oc apply --server-side --force-conflicts -f https://raw.githubusercontent.com/projectcalico/calico/v3.33.0/manifests/tigera-operator-ocp-upgrade.yaml
```

Optional: To enable the flow logs API and Calico Whisker (introduced in version 3.30), apply the `Goldmane` and `Whisker` custom resources.

```bash
kubectl apply -f - <<EOF
apiVersion: operator.tigera.io/v1
kind: Goldmane
metadata:
  name: default
---
apiVersion: operator.tigera.io/v1
kind: Whisker
metadata:
  name: default
EOF
```

You can now monitor the upgrade progress with the following command:

```bash
watch oc get tigerastatus
```

## Migrating to auto host endpoints

> **WARNING:**
>
> Auto host endpoints have an allow-all profile attached which allows all traffic in the absence of network policy. This may result in unexpected behavior and data.

In order to migrate existing all-interfaces host endpoints to Calico-managed auto host endpoints:

1. Add any labels on existing all-interfaces host endpoints to their corresponding OpenShift nodes. Calico manages labels on automatic host endpoints by syncing labels from their nodes. Any labels on existing all-interfaces host endpoints should be added to their respective nodes. For example, if your existing all-interface host endpoint for node **node1** has the label **environment: dev**, then you must add that same label to its node:

   ```bash
   oc label node node1 environment=dev
   ```

2. Enable auto host endpoints by following the [enable automatic host endpoints how-to guide](https://docs.tigera.io/calico/latest/network-policy/hosts/kubernetes-nodes.md#enable-automatic-host-endpoints). Note that automatic host endpoints are created with a profile attached that allows all traffic in the absence of network policy.

   ```bash
   calicoctl patch kubecontrollersconfiguration default --patch ={"spec": {"controllers": {"node": {"hostEndpoint": {"autoCreate": "Enabled"}}}}}
   ```

3. Delete old all-interfaces host endpoints. You can distinguish host endpoints managed by Calico from others in several ways. First, automatic host endpoints have the label **projectcalico.org/created-by: calico-kube-controllers**. Secondly, automatic host endpoints' name have the suffix **-auto-hep**.

   ```bash
   calicoctl delete hostendpoint <old_hostendpoint_name>
   ```
