Last Week In Kubernetes Development

Archives
Subscribe
September 25, 2026

LWKD: Week Ending September 20, 2026

Week Ending September 20, 2026

Developer News

Sebastian Florek (@floreks) has moved to SIG UI emeritus, following Kahiro Okina's appointment as a SIG UI Lead covered in last week's edition.

The Maintainer Summit NA 2026 schedule is now available, with sessions on SIG Node, SIG Apps, SIG Architecture, and Kubernetes localization; the event runs November 8 in Salt Lake City, and a KubeCon + CloudNativeCon NA ticket is required.

Election Update

This is your last week to vote. The Steering Committee election voting will remain open through October 1, with exception requests due by September 29. If you are marked as not eligible despite your contributions, please request an exception.

Release Schedule

Next Deadline: KEP Readiness Deadline, September 22-23

The Kubernetes v1.38 release cycle has reached its KEP Readiness Deadline. Enhancement owners should confirm their opt-in status now; the Enhancements Freeze follows on September 29 (AoE) / September 30 at 12:00 UTC. Please reach out in the #sig-release channel in Slack with any questions.

September patch releases were delayed by one week to September 23rd.

Featured PRs

142339: DRA: expose the allocator's constraint mechanism to callers

KunWuLuan exposed the DRA allocator’s constraint mechanism to its callers. This allows DRA-aware components to inspect and use allocator constraints when determining whether resource claims can be satisfied together. The change provides a clearer interface between the allocator, kube-scheduler, and device-management integrations, and lays groundwork for more informed placement decisions for workloads that require multiple or constrained resources.

142218: DRA ResourceSlice controller: optionally refuse to publish capacities and attributes with driver domain

pohly added an option for the DRA ResourceSlice controller to avoid publishing capacities and attributes associated with a driver domain. ResourceSlices are used by DRA drivers to publish device information that the scheduler uses for allocation and placement. This change gives drivers more control over which resource details are exposed through ResourceSlices while preserving the ability to publish the resources themselves, improving support for drivers with domain-specific or sensitive resource metadata.

KEP of the Week

KEP-6247: Kubelet Systemd Watchdog Diagnostic Guardrails

On Linux nodes, kubelet can use the systemd watchdog to run health checks and send periodic heartbeats through SdNotify(). If those heartbeats stop, systemd can restart kubelet, but the resulting failure can be difficult to diagnose. This KEP adds default-visible structured logs for watchdog checker and SdNotify() errors, plus one summary when existing notification retries are exhausted.

The proposal preserves the existing watchdog control flow, timing, retry count, backoff, socket behavior, and cancellation. The KubeletWatchdogDiagnostics feature gate controls the new diagnostic output and is disabled by default, so operators can enable the additional evidence during investigations without changing watchdog behavior. The work follows the kubelet watchdog discussion in kubernetes/kubernetes#135449 and intentionally adds no Kubernetes API, kubelet configuration fields, metrics, events, or NodeConditions.

googs1025 is developing the provisional KEP with SIG Node. The KEP is proposed in kubernetes/enhancements#6248 and targets Alpha in v1.38.

Other Merges

  • ResourceQuota updates no longer fail validation on a spec.hard, status.hard or status.used value that the object already holds.
  • LimitRanger no longer rejects an update of a PersistentVolumeClaim because of a request that the update leaves unchanged, even when that request is outside the LimitRange minimum or maximum.
  • Fixed issue where HorizontalPodAutoscaler incorrectly included pod overhead in the request calculation for pods using pod-level resources.
  • client-go: add support for ML-DSA keys from the crypto/mldsa package of Go 1.27
  • kube-proxy no longer tries to set the nf_conntrack_max sysctl if its value is already higher than the value kube-proxy wants it to be.
  • CEL cost estimation for CRD validation rules using URL accessor functions (getScheme, getHostname, getHost, getPort, getEscapedPath, getQuery) now propagates the result size bound from the input URL.
  • Fixed duplicate initialization of serviceaccounts REST storage when ServiceAccountIssuer is configured
  • kubectl now prints a warning when creating or updating a DeviceTaintRule whose deviceSelector is present but empty, since that selector matches every device from every driver in the cluster.
  • Fix: silently dropped DNS resolution latency metric in restclient
  • Fixed issue where a container that was recreated while the kubelet could not reach the API server was reported Ready after a kubelet restart, before its own readiness probe had run.
  • Conformance test Pods, completes the lifecycle of a Pod and the PodStatus now cover resetting the PodReadyToStartContainers condition.
  • kubelet: fixed wrong variable in container memory resize validation
  • Added auto complete support to kubectl explain
  • Fixed kubectl describe service printing "+ 0 more..." after the endpoint list when exactly three ready endpoints are followed by not-ready endpoints.
  • kubectl debug: The sysadmin profile now auto-detects Windows nodes and configures debug pods as Windows Host Process Containers with NT AUTHORITY\SYSTEM access.

Promotions

  • KEP-4858 "IP/CIDR Validation improvements" is now GA

Deprecated

  • The DynamicResourceAllocation feature gate, which has been locked to default on since v1.35, has been removed

Version Updates

  • Kubernetes is now built using Go 1.27.1
  • Updated go-jose and go-oidc packages to latest versions
  • cadvisor bumped to v0.60.6.

Subprojects and Dependency Updates

  • containerd v2.4.0: remove restore in CreateContainer, remove deprecated CRI/tracing config options, enable mount manager for image mounts in CRI
  • containerd API v1.12.0: align with containerd 2.4.0, deprecate task API address/version fields in runc options
  • cri-o v1.37.0: fix CVE-2026-15809, add conmon-rs v1.0.1 support, remove insecure_registries config option
  • prometheus v3.15.0-rc.0: deprecate --log.level in favor of runtime.log_level, add Unix Domain Socket scrape support, stabilize XOR2 float chunk encoding
  • nerdctl v2.4.0: adopt Docker v29 default images output, add --mount type=image, add Docker v25 recursive read-only mount support

Shoutouts

No shoutouts this week. Want to thank someone for special efforts to improve Kubernetes? Tag them in the #shoutouts channel.

Don't miss what's next. Subscribe to Last Week In Kubernetes Development:
← Newer LWKD: Week Ending September 27, 2026 Older → LWKD: Week Ending September 13, 2026
Powered by Buttondown, the easiest way to start and grow your newsletter.