Catalog / Kubernetes

1.33.6

Kubernetes v1.33.6

11 months agofixedchangedremovedOriginal notes

Changelog since v1.33.5

Changes by Kind

Feature

  • Kubernetes is now built using Go 1.24.9
    • update setcap and debian-base to bookworm-v1.0.6 (#134613, @cpanato) [SIG Architecture, Cloud Provider, Etcd, Release, Storage and Testing]

Bug or Regression

  • Bump system-validators to v1.9.2: remove version-specific cgroup kernel config checks to avoid false failures on cgroup v2 systems when v1-only configs are missing. (#134086, @pacoxu) [SIG Cluster Lifecycle]
  • Extends the nodeports scheduling plugin to consider hostPorts used by restartable init containers. (#133390, @SergeyKanzhelev) [SIG Scheduling and Testing]
  • Fix Windows kube-proxy (winkernel) issue where stale RemoteEndpoints remained when a Deployment was referenced by multiple Services due to premature clearing of the terminatedEndpoints map. (#135171, @princepereira) [SIG Network and Windows]
  • Fix Windows kube-proxy to prevent intermittent deletion of ClusterIP load balancers in HNS when internalTrafficPolicy=Local, ensuring stable service connectivity. (#134032, @princepereira) [SIG Network and Windows]
  • Fix the bug which could result in Job status updates failing with the error: status.startTime: Required value: startTime cannot be removed for unsuspended job The error could be raised after a Job is resumed, if started and suspended previously. (#135129, @dejanzele) [SIG Apps and Testing]
  • Fix: The requests for a config FromClass in the status of a ResourceClaim were not referenced. (#135105, @LionelJouin) [SIG Node]
  • Fixed a bug in kube-proxy nftables mode (GA as of 1.33) that fails to determine if traffic originates from a local source on the node. The issue was caused by using the wrong meta iif instead of iifname for name based matches. (#134099, @aroradaman) [SIG Network]
  • Fixed a bug in kube-proxy nftables mode (GA as of 1.33) that fails to determine if traffic originates from a local source on the node. The issue was caused by using the wrong meta iif instead of iifname for name based matches. (#134117, @jack4it) [SIG Network]
  • Fixed a startup probe race condition that caused main containers to remain stuck in "Initializing" state when sidecar containers with startup probes failed initially but succeeded on restart in pods with restartPolicy=Never. (#134801, @yuanwang04) [SIG Node and Testing]
  • Fixed race-condition in service allocation logic which leads to spurious IPAddressWrongReference warnings impacting performance (#133954, @aroradaman) [SIG Network]
  • Fixes spammy incorrect "Ignoring same-zone topology hints for service since no hints were provided for zone" messages in the kube-proxy logs. (#133527, @danwinship) [SIG Network]
  • Kube-controller-manager: Fixes a 1.33 regression in daemonset handling of orphaned pods (#134652, @liggitt) [SIG Apps]
  • Kube-controller-manager: Resolves potential issues handling pods with incorrect uids in their ownerReference (#134662, @liggitt) [SIG Apps]
  • Kube-proxy in nftables mode now allows pods on nodes without local service endpoints to access LoadBalancer Service ExternalIPs (with externalTrafficPolicy: Local). Previously, such traffic was dropped. This change brings nftables mode in line with iptables and IPVS modes, allowing traffic to be forwarded to available endpoints elsewhere in the cluster. (#133969, @aroradaman) [SIG Network]
  • Kubeadm: avoid panicing if the user has malformed the kubeconfig in the cluster-info config map to not include a valid current context. Include proper validation at the appropriate locations and throw errors instead. (#134724, @neolit123) [SIG Cluster Lifecycle]
  • Kubeadm: ensured waiting for apiserver uses a local client that doesn't reach to the control plane endpoint and instead reaches directly to the local API server endpoint. (#134269, @neolit123) [SIG Cluster Lifecycle]
  • Kubeadm: fixed a bug where the node registration information for a given node was not fetched correctly during "kubeadm upgrade node" and the node name can end up being incorrect in cases where the node name is not the same as the host name. (#134363, @neolit123) [SIG Cluster Lifecycle]
  • Kubeadm: fixes a preflight check that can fail hostname construction in IPV6 setups (#134590, @liggitt) [SIG API Machinery, Auth, Cloud Provider, Cluster Lifecycle and Testing]
  • Reduce event spam during volume operation errors in Portworx in-tree driver (#135192, @gohilankit) [SIG Storage]

Other (Cleanup or Flake)

  • Kubeadm: updated the supported etcd version to v3.5.24 for the skewed control plane version v1.33. (#135018, @hakman) [SIG Cloud Provider, Cluster Lifecycle and Etcd]
  • Kubernetes is now built using Go 1.24.7 (#134197, @cpanato) [SIG Release and Testing]
  • The test is intended to verify pod scheduling with an anti-affinity scenario, but it uses the wrong pod template. This affects functional correctness. (#134262, @sats-23) [SIG Testing]

Dependencies

Added

Nothing has changed.

Changed

  • k8s.io/system-validators: v1.9.1 → v1.9.2

Removed

Nothing has changed.