LWKD: Week Ending September 27, 2026
Week Ending September 27, 2026
Developer News
Two security advisories were published on September 24: CVE-2026-2270 (rated Medium, 5.9) describes a confused deputy attack in the StatefulSet controller that lets a user with namespace-scoped write permissions on StatefulSet and ControllerRevision objects create a cross-namespace pod, and CVE-2026-76654 (rated Medium, 5.8) describes an NTLM coercion vulnerability on Windows nodes when a pod's subPath is a symbolic link to an attacker-controlled UNC network share; both are fixed in the September patch releases (v1.34.12, v1.35.9, v1.36.5, v1.37.1) covered in the Release Schedule below.
SIG Cluster Lifecycle has a leadership change: Vince Prignano (@vincepri) is stepping down as chair, and existing Tech Lead Fabrizio Pandini (@fabriziopandini) will assume the chair role in addition to his Tech Lead responsibilities. The change is under a one-week lazy consensus period.
The CfP for Kubecon Europe 2027 is already open, and closes October 11th. This includes Maintainer Track sessions and Lightning Talks for SIGs.
Election Update
Voting closes on October 2. If you are an Kubernetes Org Member, and have not cast your ballot yet, please vote right away.
Release Schedule
Next Deadline: Enhancements Freeze, September 29 (AoE) / September 30 at 12:00 UTC
The Kubernetes v1.38 release cycle heads into its Enhancements Freeze this week. Following KEP Readiness, 11 enhancements were removed from the v1.38 milestone, leaving 89 tracked out of the 100 that had opted in. Any KEP that still wants to join v1.38 and isn't already tracked now needs an approved exception. Please reach out in the #sig-release channel in Slack with any questions.
Kubernetes v1.38.0-alpha.1 has been built and pushed using Go 1.27.1. See the release notes and the GitHub release.
Patch releases v1.37.1, v1.36.5, v1.35.9, and v1.34.12 are now available. These releases bump to Go 1.26.8 and include a handful of bug fixes.
Featured PRs
142218: DRA ResourceSlice controller: optionally refuse to publish capacities and attributes with driver domain
pohly added an option for the DRA ResourceSlice controller to avoid publishing capacities and attributes associated with a driver domain. ResourceSlices are used by DRA drivers to publish device information that the scheduler uses during allocation and placement. This change gives drivers more control over which resource metadata is exposed through ResourceSlices while preserving the ability to publish the devices themselves. The work builds on the ResourceSlice and structured-parameter design described in KEP-4381.
142478: DRA Device Binding Conditions: graduate to GA
ttsuubasa graduated DRA Device Binding Conditions to General Availability under KEP-5007. Device Binding Conditions allow the scheduler to wait for network- or fabric-attached devices to become ready before binding a Pod. This avoids binding a workload to a node before the required device attachment has completed and allows failed attachment attempts to be reported back to scheduling. The graduation makes this workflow stable for DRA drivers and workloads that depend on devices requiring external preparation.
KEP of the Week
KEP-6361: Leader Election Recovery
Kubernetes controller managers use a Lease to ensure only one replica reconciles resources at a time. Today, if the leader cannot renew its Lease before RenewDeadline during a temporary API server or etcd outage, it exits. Restarting forces its controllers to rebuild their cached view of the cluster, extending the interruption after the API becomes available again.
The proposal adds a transport-level write gate to controller clients. When the manager stops leading, the gate rejects new writes and cancels writes in flight while reads and watches continue, keeping caches warm. The election loop keeps trying to renew the same Lease; if it succeeds before another replica takes over, the gate reopens and reconciliation resumes without a restart. A configurable recovery deadline can limit these attempts, and the former leader exits if another replica takes over. The Lease API and election protocol remain unchanged.
alvaroaleman, jpbetz, and michaelasp authored the KEP with SIG API Machinery. Proposed on September 14, it was merged on September 25. The enhancement issue tracks the work, and discussion is in the SIG API Machinery thread.
KEP 6361 is implementable and targets Alpha in Kubernetes v1.38 behind the disabled-by-default LeaderElectionRecovery feature gate.
Other Merges
- Fixed a regression in v1.38 where resource quantities written by a v1.37 or older apiserver with a decimal exponent outside the int32 range could not be decoded, failing reads of the whole collection.
- validation-gen:
+k8s:minimumand+k8s:maximumsupporttime.Durationfields with quoted Go duration strings, such as+k8s:minimum="1s". Integer payloads ontime.Durationfields are now rejected. SelfSignedCertKeyOptionsink8s.io/client-go/util/certaccepts aKeyGenerator, allowing self-signed certificates to be generated with a key algorithm other than RSA. The default remains a 2048-bit RSA key.- Added resource version to pod binding API
- Fixed a bug where
NoExecutedevice taints (DeviceTaintRule) did not evict pods using DRA-backed extended resources (pod.Status.ExtendedResourceClaimStatus) - resource.Quantity: calling String or encoding a quantity is now guaranteed to not mutate the instance
- client-go: restrict CA key encipherment usage to RSA keys. Key encipherment usage is no longer included for non RSA keys in self signed CA certificates generated from client-go
- Fixed an issue where a Job recreated with the same name as a recently deleted Job could remain unreconciled because it inherited pending Pod expectations from the previous Job
- kubectl describe node: per-pod resource percentages no longer print -9223372036854775808% on nodes that have not reported allocatable resources, and the "Allocated resources" totals now use the same resource accounting as the per-pod rows
- Added resource version to eviction api
- LimitRanger no longer re-validates the resource requests and limits a pod resize leaves unchanged. Only the values a resize changes are checked against the LimitRange, so an existing pod is no longer rejected on resize by a constraint it already violates
- Fixed false fractional-byte warnings for integer resource quantities larger than the int64 range
- Out-of-tree kube-scheduler plugins using the
NominatedPodsForNodemethod must now passlogger klog.Loggeras the first argument - Added support for using PKCS#10 signing requests signed with ML-DSA keys in CertificateSigningRequest, gated by the CertificateSigningRequestMLDSA feature-gate
- kubeadm: added support for the ML-DSA encryption algorithm. "ML-DSA-44", "ML-DSA-65" and "ML-DSA-87" are now allowed values for ClusterConfiguration.EncryptionAlgorithm for new clusters using the v1beta4 and the still disabled (WIP) v1 API
- Fixed DRA kubelet plugin helper rolling updates for drivers with long valid names by shortening automatic DRA service socket paths when needed
- The documentation of
Node.status.volumesAttached[].devicePathnow states the platform-specific semantics: on Linux it is the host block-device node, on Windows it carries the CSI VolumeID - Fixed a race in client-go MutationCache indexed lookups that could temporarily hide a recently created replacement object
- Both
distribute-cpus-across-cores=trueandalign-by-socket=trueoptions were enabled, even when a single socket had sufficient capacity - Fixed a bug where kubelet logged
--manifest-url-headercredential values (e.g., Authorization tokens) to runtime logs at startup. Only header key names are now logged - kube-apiserver: added the alpha
ManagedFieldsOptOutfeature gate (off by default) - kube-apiserver: Requests to unknown
/apis/...paths and final delegation 404s now return a JSONStatusobject withContent-Type: application/jsoninstead of a plain-text "404 page not found" body - Fixed a bug where kubelet device manager may assign the same device ID to multiple pods simultaneously
Promotions
Deprecated
- Removed the deprecated
WindowsHostNetworkfeature gate (KEP-3503, withdrawn). The gate no longer guarded any code paths - Removed the
SeparateTaintEvictionControllerfeature gate fromkube-controller-manager. Remove this gate from existing--feature-gatesconfiguration before upgrading
Version Updates
- Bumped golang.org/x modules and mdlayher/socket to their current releases
- Bumped grpc to v1.84.0, lifted its pin, and bumped the etcd modules to v3.7.2
Subprojects and Dependency Updates
- containerd v2.4.1: Fixes CVE-2026-53493, leaked tasks after failed container start, and container creation when SELinux relabeling is unsupported; also v2.3.6, v2.2.9, v2.0.13, v1.7.36
- prometheus v3.15.0: Deprecates --log.level in favor of runtime.log_level, adds Unix Domain Socket scraping, stabilizes XOR2 float chunk encoding, and adds zstd scrape support
- etcd v3.7.2: new patch release with cherry-picks of bugfixes, see CHANGELOG; also v3.6.15 and v3.5.34
- vertical-pod-autoscaler v1.8.0: new minor release brings improved unboosting for the alpha CPU Startup Boost feature, improved API validation, configurable status leases and several other changes
- vertical-pod-autoscaler v1.7.2: new patch release with various small bug fixes
Shoutouts
No shoutouts this week. Want to thank someone for special efforts to improve Kubernetes? Tag them in the #shoutouts channel.