Last Week In Kubernetes Development

Archives
Subscribe
September 30, 2026

LWKD: Week Ending September 27, 2026

Week Ending September 27, 2026

Developer News

Two security advisories were published on September 24: CVE-2026-2270 (rated Medium, 5.9) describes a confused deputy attack in the StatefulSet controller that lets a user with namespace-scoped write permissions on StatefulSet and ControllerRevision objects create a cross-namespace pod, and CVE-2026-76654 (rated Medium, 5.8) describes an NTLM coercion vulnerability on Windows nodes when a pod's subPath is a symbolic link to an attacker-controlled UNC network share; both are fixed in the September patch releases (v1.34.12, v1.35.9, v1.36.5, v1.37.1) covered in the Release Schedule below.

SIG Cluster Lifecycle has a leadership change: Vince Prignano (@vincepri) is stepping down as chair, and existing Tech Lead Fabrizio Pandini (@fabriziopandini) will assume the chair role in addition to his Tech Lead responsibilities. The change is under a one-week lazy consensus period.

The CfP for Kubecon Europe 2027 is already open, and closes October 11th. This includes Maintainer Track sessions and Lightning Talks for SIGs.

Election Update

Voting closes on October 2. If you are an Kubernetes Org Member, and have not cast your ballot yet, please vote right away.

Release Schedule

Next Deadline: Enhancements Freeze, September 29 (AoE) / September 30 at 12:00 UTC

The Kubernetes v1.38 release cycle heads into its Enhancements Freeze this week. Following KEP Readiness, 11 enhancements were removed from the v1.38 milestone, leaving 89 tracked out of the 100 that had opted in. Any KEP that still wants to join v1.38 and isn't already tracked now needs an approved exception. Please reach out in the #sig-release channel in Slack with any questions.

Kubernetes v1.38.0-alpha.1 has been built and pushed using Go 1.27.1. See the release notes and the GitHub release.

Patch releases v1.37.1, v1.36.5, v1.35.9, and v1.34.12 are now available. These releases bump to Go 1.26.8 and include a handful of bug fixes.

Featured PRs

142218: DRA ResourceSlice controller: optionally refuse to publish capacities and attributes with driver domain

pohly added an option for the DRA ResourceSlice controller to avoid publishing capacities and attributes associated with a driver domain. ResourceSlices are used by DRA drivers to publish device information that the scheduler uses during allocation and placement. This change gives drivers more control over which resource metadata is exposed through ResourceSlices while preserving the ability to publish the devices themselves. The work builds on the ResourceSlice and structured-parameter design described in KEP-4381.

142478: DRA Device Binding Conditions: graduate to GA

ttsuubasa graduated DRA Device Binding Conditions to General Availability under KEP-5007. Device Binding Conditions allow the scheduler to wait for network- or fabric-attached devices to become ready before binding a Pod. This avoids binding a workload to a node before the required device attachment has completed and allows failed attachment attempts to be reported back to scheduling. The graduation makes this workflow stable for DRA drivers and workloads that depend on devices requiring external preparation.

KEP of the Week

KEP-6361: Leader Election Recovery

Kubernetes controller managers use a Lease to ensure only one replica reconciles resources at a time. Today, if the leader cannot renew its Lease before RenewDeadline during a temporary API server or etcd outage, it exits. Restarting forces its controllers to rebuild their cached view of the cluster, extending the interruption after the API becomes available again.

The proposal adds a transport-level write gate to controller clients. When the manager stops leading, the gate rejects new writes and cancels writes in flight while reads and watches continue, keeping caches warm. The election loop keeps trying to renew the same Lease; if it succeeds before another replica takes over, the gate reopens and reconciliation resumes without a restart. A configurable recovery deadline can limit these attempts, and the former leader exits if another replica takes over. The Lease API and election protocol remain unchanged.

alvaroaleman, jpbetz, and michaelasp authored the KEP with SIG API Machinery. Proposed on September 14, it was merged on September 25. The enhancement issue tracks the work, and discussion is in the SIG API Machinery thread.

KEP 6361 is implementable and targets Alpha in Kubernetes v1.38 behind the disabled-by-default LeaderElectionRecovery feature gate.

Other Merges

  • Fixed a regression in v1.38 where resource quantities written by a v1.37 or older apiserver with a decimal exponent outside the int32 range could not be decoded, failing reads of the whole collection.
  • validation-gen: +k8s:minimum and +k8s:maximum support time.Duration fields with quoted Go duration strings, such as +k8s:minimum="1s". Integer payloads on time.Duration fields are now rejected.
  • SelfSignedCertKeyOptions in k8s.io/client-go/util/cert accepts a KeyGenerator, allowing self-signed certificates to be generated with a key algorithm other than RSA. The default remains a 2048-bit RSA key.
  • Added resource version to pod binding API
  • Fixed a bug where NoExecute device taints (DeviceTaintRule) did not evict pods using DRA-backed extended resources (pod.Status.ExtendedResourceClaimStatus)
  • resource.Quantity: calling String or encoding a quantity is now guaranteed to not mutate the instance
  • client-go: restrict CA key encipherment usage to RSA keys. Key encipherment usage is no longer included for non RSA keys in self signed CA certificates generated from client-go
  • Fixed an issue where a Job recreated with the same name as a recently deleted Job could remain unreconciled because it inherited pending Pod expectations from the previous Job
  • kubectl describe node: per-pod resource percentages no longer print -9223372036854775808% on nodes that have not reported allocatable resources, and the "Allocated resources" totals now use the same resource accounting as the per-pod rows
  • Added resource version to eviction api
  • LimitRanger no longer re-validates the resource requests and limits a pod resize leaves unchanged. Only the values a resize changes are checked against the LimitRange, so an existing pod is no longer rejected on resize by a constraint it already violates
  • Fixed false fractional-byte warnings for integer resource quantities larger than the int64 range
  • Out-of-tree kube-scheduler plugins using the NominatedPodsForNode method must now pass logger klog.Logger as the first argument
  • Added support for using PKCS#10 signing requests signed with ML-DSA keys in CertificateSigningRequest, gated by the CertificateSigningRequestMLDSA feature-gate
  • kubeadm: added support for the ML-DSA encryption algorithm. "ML-DSA-44", "ML-DSA-65" and "ML-DSA-87" are now allowed values for ClusterConfiguration.EncryptionAlgorithm for new clusters using the v1beta4 and the still disabled (WIP) v1 API
  • Fixed DRA kubelet plugin helper rolling updates for drivers with long valid names by shortening automatic DRA service socket paths when needed
  • The documentation of Node.status.volumesAttached[].devicePath now states the platform-specific semantics: on Linux it is the host block-device node, on Windows it carries the CSI VolumeID
  • Fixed a race in client-go MutationCache indexed lookups that could temporarily hide a recently created replacement object
  • Both distribute-cpus-across-cores=true and align-by-socket=true options were enabled, even when a single socket had sufficient capacity
  • Fixed a bug where kubelet logged --manifest-url-header credential values (e.g., Authorization tokens) to runtime logs at startup. Only header key names are now logged
  • kube-apiserver: added the alpha ManagedFieldsOptOut feature gate (off by default)
  • kube-apiserver: Requests to unknown /apis/... paths and final delegation 404s now return a JSON Status object with Content-Type: application/json instead of a plain-text "404 page not found" body
  • Fixed a bug where kubelet device manager may assign the same device ID to multiple pods simultaneously

Promotions

  • DRADeviceTaints and DRADeviceTaintRules to GA

Deprecated

  • Removed the deprecated WindowsHostNetwork feature gate (KEP-3503, withdrawn). The gate no longer guarded any code paths
  • Removed the SeparateTaintEvictionController feature gate from kube-controller-manager. Remove this gate from existing --feature-gates configuration before upgrading

Version Updates

  • Bumped golang.org/x modules and mdlayher/socket to their current releases
  • Bumped grpc to v1.84.0, lifted its pin, and bumped the etcd modules to v3.7.2

Subprojects and Dependency Updates

  • containerd v2.4.1: Fixes CVE-2026-53493, leaked tasks after failed container start, and container creation when SELinux relabeling is unsupported; also v2.3.6, v2.2.9, v2.0.13, v1.7.36
  • prometheus v3.15.0: Deprecates --log.level in favor of runtime.log_level, adds Unix Domain Socket scraping, stabilizes XOR2 float chunk encoding, and adds zstd scrape support
  • etcd v3.7.2: new patch release with cherry-picks of bugfixes, see CHANGELOG; also v3.6.15 and v3.5.34
  • vertical-pod-autoscaler v1.8.0: new minor release brings improved unboosting for the alpha CPU Startup Boost feature, improved API validation, configurable status leases and several other changes
  • vertical-pod-autoscaler v1.7.2: new patch release with various small bug fixes

Shoutouts

No shoutouts this week. Want to thank someone for special efforts to improve Kubernetes? Tag them in the #shoutouts channel.

Don't miss what's next. Subscribe to Last Week In Kubernetes Development:
Older → LWKD: Week Ending September 20, 2026
Powered by Buttondown, the easiest way to start and grow your newsletter.