1.37.0
Changelog since v1.36.0
Urgent Upgrade Notes
(No, really, you MUST read this before you upgrade)
- ACTION REQUIRED: Graduated the
SELinuxMountfeature gate to GA. The feature is enabled by default inv1.37, which may break existing workloads in clusters with SELinux enabled. Please see the Kubernetes blog post to identify potentially problematic workloads in av1.36cluster and how to fix them or opt out ofSELinuxMountchanges before upgrading tov1.37. Admins of clusters without SELinux enabled can ignore this release note. (#139956, @jsafrane) [SIG API Machinery, Apps and Node] - ACTION REQUIRED: Converted the
DisruptionModeenum field to a struct to support future extensibility. Promoted thescheduling.k8s.ioAPI group fromv1alpha2tov1alpha3and droppedv1alpha2entirely. Remove allv1alpha2objects from thekube-apiserverbefore performing the cluster update. (#138572, @dom4ha) [SIG API Machinery, Apps, CLI, Etcd, Node, Scheduling and Testing] - ACTION REQUIRED: Fixed
eventRecordQPShandling inkubeletconfiguration to treat 0 as unlimited (no rate limit), aligning behavior with the documentation. Users relying on the previous default behavior should explicitly set a non-zero value (for example, 50). (#117119, @HirazawaUi) [SIG API Machinery, Auth and Node] - ACTION REQUIRED: Updated the
kubeletto log its effective configuration at startup. Because these logs can expose configuration details, cluster administrators should restrict thenodes/logsClusterRole to trusted users. This is largely a reminder of an existing best practice, since most effective configuration values can already be inferred from other log messages orkubeletbehavior. (#139837, @SergeyKanzhelev) [SIG Node]
Changes by Kind
Dependency
- Updated
google.golang.org/grpctov1.82.1, which adds a server-side limit on HTTP/2 control frame flooding. It also removes theGRPC_GO_EXPERIMENTAL_DISABLE_STRICT_PATH_CHECKINGenvironment variable, so strict path checking is always on. (#140740, @dims) [SIG API Machinery, Architecture, Auth, CLI, Cloud Provider, Network, Node and Scheduling] - Updated the
kubelet's embeddedcAdvisorto use the leanergithub.com/google/cadvisor/libmodule, which removes three long-deprecated or legacy surfaces:- Deprecated
cAdvisorflags are no longer accepted and thekubeletwill fail to start if any are set (only--housekeeping-intervalis kept):--application-metrics-count-limit,--boot-id-file,--container-hints,--containerd,--containerd-namespace,--enable-load-reader,--event-storage-age-limit,--event-storage-event-limit,--global-housekeeping-interval,--log-cadvisor-usage,--machine-id-file,--storage-driver-user,--storage-driver-password,--storage-driver-host,--storage-driver-db,--storage-driver-table,--storage-driver-secure,--storage-driver-buffer-duration. Remove these from yourkubeletconfiguration. cAdvisorapplication/custom metrics are no longer collected: theuserDefinedMetricsfield in/stats/summaryand the customcontainer_application_*families in/metrics/cadvisor.- The
/metrics/cadvisorseriescontainer_cpu_load_average_10s,container_cpu_load_d_average_10s, andcontainer_tasks_stateare no longer exported. (#139870, @dims) [SIG API Machinery, Auth, Instrumentation, Network, Node and Testing]
- Deprecated
- Updated the default etcd version to
v3.7.0-rc.0. (#139427, @Jefftree) [SIG API Machinery, Cloud Provider, Cluster Lifecycle, Etcd and Testing] - Updated the default etcd version to
v3.7.0. (#140333, @Jefftree) [SIG API Machinery, Auth, Cloud Provider, Cluster Lifecycle, Etcd, Node, Scheduling and Testing] - Updated the etcd client library to
v3.6.10. (#138393, @humblec) [SIG API Machinery, Architecture, Auth, CLI, Cloud Provider, Cluster Lifecycle, Etcd, Instrumentation, Network, Node, Scheduling and Storage]
Deprecation
- Changed
kubeadmto explicitly setKubeProxyConfiguration.modeto iptables whenKubeProxyConfigurationis not provided or when themodefield is empty. Inv1.37,kube-proxywill warn if the field is not explicitly set as part of the planned transition to nftables as the default mode in a future release. (#139777, @neolit123) [SIG Cluster Lifecycle] - Deprecated the ignored
--filename/-fflag onkubectl run. (#138671, @Suknna) [SIG CLI] - Locked the deprecated
DeclarativeValidationTakeoverfeature gate to its default value; it can no longer be set. (#139212, @yongruilin) [SIG API Machinery] kubeadm: Added a (delayed) warning thatkube-proxy's ipvs mode is deprecated sincev1.35and users on newer Linux kernels should be using the nftables mode instead, which became GA inv1.33. For older kernel versions, users can use iptables, which is still the default. (#139067, @neolit123) [SIG Cluster Lifecycle]
API Change
- Added Alpha support for DRA device compatibility groups, guarded by the
DRADeviceCompatibilityGroupsfeature gate (disabled by default). DRA drivers can declare opaquecompatibilityGroupson eachdevice.consumesCounters[]entry of a ResourceSlice, and the scheduler only co-allocates devices drawing from the same counter set when their declared groups intersect. This moves detection of incompatible co-allocation from preparation-time failure to scheduling-time rejection. (#139795, @omeryahud) [SIG API Machinery, Node, Scheduling and Testing] - Added Alpha support for binding service account tokens to webhook configurations with attestations, behind the
APIServerWebhookAuthenticationTokenfeature gate. This enables API servers to authenticate to admission webhooks with scoped tokens. (#140113, @pmengelbert) [SIG API Machinery, Apps, Auth and Testing] - Added Alpha support for defining the file owner of atomically written volume files, behind the
AtomicWriteVolumeUserFieldsfeature gate (disabled by default). (#139764, @gavinkflam) [SIG API Machinery, Apps, Auth, Storage and Testing] - Added CompositePodGroup support to the building block APIs and the
workloadbuilderlibrary. (#140717, @helayoty) [SIG API Machinery, Apps, Auth, Scheduling and Testing] - Added Workload-aware scheduling (WAS) support to the Job controller by integrating it with the
workloadbuilderlibrary and the Workload building block APIs. (#140188, @helayoty) [SIG API Machinery, Apps, Auth, Network, Node, Scheduling, Storage and Testing] - Added
CheckpointPodandRestorePodRPCs to the CRIv1RuntimeService API for Pod-level checkpoint and restore. (#140366, @rst0git) [SIG Node, Testing and Windows] - Added a
PreemptionPolicyfield to PodGroup, allowing users to control howkube-schedulerpreempts Pods that belong to a PodGroup during workload-aware preemption. (#139240, @ania-borowiec) [SIG Scheduling] - Added a
protocolfield tohttpGetprobes so that liveness, readiness, and startup probes can run over HTTP/2 cleartext (H2C). (#139429, @amritansh1502) [SIG API Machinery, Apps, Node and Testing] - Added a defense-in-depth check to the
NodeRestrictionadmission plugin for PodCertificateRequests. A node can only create a PodCertificateRequest referring to a particular signer name if the Pod actually mounts apodCertificateprojected volume source that refers to that signer name, or if an authorization check for the user (withverb=request-podcertificate-signerandresource=<signerName>) succeeds. (#140006, @ahmedtd) [SIG Auth and Testing] - Added a second Alpha of DRA resource availability visibility (KEP-5677), behind the
DRAResourcePoolStatusfeature gate (disabled by default). The ResourcePoolStatusRequest controller counts partitionable and consumable devices correctly, counting each device once, ignoring AdminAccess, and treating taints as unavailable. Optional fields describe partition and shareable availability. These accounting fixes change the numbers reported inv1.36. (#140170, @nmn3m) [SIG API Machinery, Apps, Auth, Node and Testing] - Added an opt-in userspace TCP proxy to the nftables
kube-proxybackend to serve localhost NodePort Services on IPv4 and IPv6. (#138427, @AustinAbro321) [SIG Instrumentation, Network and Testing] - Added dry-run support to unsafe corrupt object deletion, letting administrators test deletion operations safely before running them. (#134037, @ibihim) [SIG API Machinery and Testing]
- Added generated declarative validation functions for Go consumers of the DRA device metadata
v1alpha1API. (#140687, @alaypatel07) [SIG Node] - Added scheduler support for preempting lower-priority Pods to make room for
Deferredin-place Pod resizes of higher-priority Pods when theInPlacePodVerticalScalingSchedulerPreemptionAlpha feature gate is enabled. (#140000, @natasha41575) [SIG API Machinery, Apps, Node, Scheduling, Storage and Testing] - Added support for derived attributes in DRA, allowing claims to define virtual attributes using CEL expressions and use them in device constraints. This enables co-allocation of devices across different domains, for example GPUs and NICs on the same NUMA node, even if their drivers publish physical attributes differently. (#140029, @gauravkghildiyal) [SIG API Machinery, Node, Scheduling and Testing]
- Added support for dynamically resizing memory-backed volumes behind the Alpha
InPlacePodVerticalScalingMemoryBackedVolumesfeature gate. (#139425, @natasha41575) [SIG API Machinery, Apps, Autoscaling, CLI, Node, Scheduling, Storage and Testing] - Added support for selecting ResourceSlices by pool name with the field selector
spec.pool.name. (#138456, @yaroslavborbat) [SIG API Machinery, Node and Testing] - Added support for setting Unix permission bits (0000-01777) through the
modefield on emptyDir volume directories at creation time. (#140244, @nispriha) [SIG API Machinery, Apps, Node, Storage and Testing] - Added support for specifying bind mount options (
noexec,nodev,nosuid) per container volume mount. (#140013, @nispriha) [SIG API Machinery, Apps, Autoscaling, Node, Scheduling and Testing] - Added the API changes required for reporting volume health. (#140194, @gnufied) [SIG API Machinery, Apps, Architecture, Auth, Etcd, Instrumentation, Node, Storage and Testing]
- Added the CompositePodGroup API to
scheduling.k8s.io/v1alpha3. (#139596, @jdzikowski) [SIG API Machinery, Apps, Auth, Etcd, Node, Scheduling and Testing] - Added the Recreate update strategy for StatefulSet, mirroring the Deployment Recreate strategy by deleting all Pods, waiting for them to terminate completely, and then creating Pods according to the
podManagementPolicyfield. (#137187, @galal-hussein) [SIG Apps and Testing] - Added the
--concurrent-disruption-syncsflag tokube-controller-managerto configure the number of concurrent disruption controller workers. (#140014, @xigang) [SIG API Machinery, Apps, Auth and Testing] - Added the
.spec.evictionRespondersPod field, along with the EvictionRequest and Eviction resources. A set of requesters and responders can use these to coordinate graceful eviction of Pods. (#137050, @atiratree) [SIG API Machinery, Apps, Architecture, Auth, CLI, Etcd and Testing] - Added the
DefaultPodSysctlskubeletconfiguration field for default Pod sysctls on Linux nodes, behind the AlphaDefaultPodSysctlsfeature gate (disabled by default). (#140052, @VeraQin) [SIG Node and Testing] - Added the
DisruptionModeandPreemptionPolicyfields to the Workload and CompositePodGroup APIs to support workload-aware preemption for CompositePodGroups. (#140634, @tosi3k) [SIG API Machinery, Auth, Etcd, Node, Scheduling and Testing] - Added the
GracefulNodeShutdownInProgress,DrainInProgress,Drained,MaintenancePlanned, andMaintenanceInProgressNode lifecycle conditions. (#139993, @rthallisey) [SIG Apps and Node] - Added the
PodGroupPostFilterextension point to the scheduling framework, replacing the internal hardcoding forWorkloadAwarePreemptionwith a configurable extension point for PodGroups. (#139674, @GFilipek) [SIG Scheduling and Testing] - Added the
PreemptionPolicyfield to PodGroupTemplate to define the policy for workload-aware preemption. (#140312, @ania-borowiec) [SIG API Machinery, Apps, Scheduling and Testing] - Added the
SchedulerPreQueueingHintsfeature gate (Alpha, disabled by default). When enabled, scheduler plugins can provide aPreQueueingHintFnthat narrows the set of Pods evaluated on cluster events, improving scheduling throughput. The DRA plugin implements this to optimize ResourceClaimTemplate-based workloads. (#138916, @geetasg) [SIG API Machinery, Apps, Architecture, Auth, CLI, Cloud Provider, Instrumentation, Network, Node, Scheduling, Storage, Testing and Windows] - Added the core machinery for Conditional Authorization, which enables authorizers to allow requests conditionally based on the request's content, rather than only allowing or denying them outright. (#137513, @luxas) [SIG API Machinery, Auth, Node and Testing]
- Allowed HorizontalPodAutoscaler conditions to optionally include the
observedGenerationat the time the condition was recorded. (#138653, @adrianmoisey) [SIG API Machinery, Apps, Autoscaling and Testing] - Changed the
kube-apiserverCBOR encoder to encode collections item by item instead of all at once. (#138808, @chenk008) [SIG API Machinery, Apps, Auth, Autoscaling, CLI, Cloud Provider, Cluster Lifecycle, Contributor Experience, Instrumentation, Network, Node, Release, Scalability, Scheduling, Storage, Testing and Windows] - DRA: Added Alpha support for
DRAOptionalNodeOperations(theSkipNodeOperationsfield in ResourceSlice and ResourceClaim), which allows skipping node-level preparation and cleanup operations. (#139933, @troychiu) [SIG API Machinery, Autoscaling, Instrumentation, Node, Release, Scheduling and Testing] - Fixed CEL cost estimation for
metadata.nameandmetadata.generateNamein CRDs to correctly account for the default maximum length of 253 characters, unless additional validations are defined on those metadata fields. (#139573, @jpbetz) [SIG API Machinery] - Fixed DRA
CapacityRequestPolicyRangeto support fractional quantities in milli-scale. (#140161, @sunya-ch) [SIG API Machinery, Node and Scheduling] - Fixed Pod status validation for reported Linux container user UIDs to accept values above 2147483647 and up to the unsigned 32-bit UID limit. (#138574, @Kunalbehbud) [SIG Apps and Node]
- Fixed a
v1.34+ regression handling containers with environment values set from Secret API objects containing binary non-utf8 data. (#139168, @liggitt) [SIG Architecture, Node and Testing] - Fixed a bug in DRA consumable capacity where the
DistinctAttributeconstraint was not correctly enforced for each device when a request allocated multiple devices. (#140600, @GunaKKIBM) [SIG API Machinery, Apps, CLI, Etcd, Network, Node, Release, Scheduling and Testing] - Fixed the overestimation of a Pod's resource footprint during resize operations for multi-container Pods. (#140047, @natasha41575) [SIG Node and Scheduling]
- Graduated Pod Certificates to GA, with the PodCertificateRequest feature gate enabled by default. The
PKIXPublicKeyandProofOfPossessionfields, deprecated in PodCertificateRequestv1beta1, are removed from thev1API. Update clients that still set these fields before upgrading. (#139579, @yt2985) [SIG API Machinery, Apps, Architecture, Auth, Etcd, Node, Scheduling and Testing] - Graduated Pod hostname overrides to GA. The
HostnameOverridefeature gate is locked to enabled. (#139116, @HirazawaUi) [SIG API Machinery, Apps, Node and Testing] - Graduated the
ClusterTrustBundleandClusterTrustBundleProjectionfeature gates to GA and enabled them by default. (#139437, @stlaz) [SIG API Machinery, Apps, Architecture, Auth, Etcd, Node, Storage and Testing] - Improved CEL error messages in Dynamic Resource Allocation to provide guidance when accessing non-existent device attributes. Error messages link to documentation on handling optional fields using
orValue()andhas(). (#136709, @gzb1128) [SIG API Machinery, Node and Scheduling] - Moved the
NodeSyncPeriodfield fromKubeCloudSharedConfigurationtoCloudControllerManagerConfiguration.NodeLifecycleController.NodeMonitorPeriod. (#137964, @niewysoki) [SIG API Machinery, Apps, Cloud Provider, Instrumentation and Node] - Promoted DRA Workload resource claims to Beta. The
DRAWorkloadResourceClaimsfeature gate remains disabled by default. (#140334, @nojnhuh) [SIG API Machinery, Apps, Etcd, Node, Scheduling and Testing] - Promoted
kubeletvolume metrics (storage_operation_duration_seconds,volume_operation_total_seconds) from Alpha to Beta stability, providing stronger API and label stability guarantees for metric consumers. (#136189, @bhope) [SIG Instrumentation and Storage] - Promoted the DRA Device Taints and Tolerations feature to GA, making it available via the
resource.k8s.io/v1API. (#138676, @pohly) [SIG API Machinery, Apps, Architecture, Auth, Etcd, Node, Scheduling, Storage and Testing] - Promoted the DRA extended resource feature to GA in
v1.37. (#138488, @yliaog) [SIG API Machinery, Apps, Node, Scheduling and Testing] - Promoted the DRA metadata API to Beta. DRA driver authors that enable the feature must explicitly select which versions to support in their metadata output. (#140722, @pohly) [SIG Node and Testing]
- Promoted the DRAResourceHealth
kubeletgRPC API tov1; the schema is unchanged fromv1alpha1.DRAPlugin.WatchHealthStatusis a mandatory method on theDRAPlugininterface in thek8s.io/dynamic-resource-allocation/kubeletpluginhelper, replacing the optional versioned gRPC interface. This is a one-time Go API break: existing drivers must add the method to compile. Drivers without health support returnErrHealthNotSupportedfrom it, or disable the service withHealthService(false). The helper serves bothv1andv1alpha1by default, so drivers report health onkubeletv1.36and older without extra configuration. Thekubeletprefersv1and, for three releases of transition, still consumesv1alpha1from drivers that shipped beforev1existed. Thev1alpha1DRAResourceHealth API is deprecated and is planned to be removed inv1.40. Thekubeletonly opens the device health stream for plugins that advertise the service. (#139477, @harche) [SIG Node and Testing] - Promoted the
HPAConfigurableTolerancefeature gate to GA. (#140107, @jm-franc) [SIG API Machinery, Apps, Autoscaling and Testing] - Promoted the
KubeletInUserNamespacefeature gate to Beta. (#134639, @AkihiroSuda) [SIG API Machinery, Apps, Node and Testing] - Promoted the
MemoryQoSfeature gate to Beta.memoryThrottlingFactordefaults to nil, andmemory.highis not set unless explicitly configured. (#140007, @QiWang19) [SIG Node and Testing] - Promoted the
NodeDeclaredFeaturesfeature gate to GA. (#139763, @pravk03) [SIG Apps, Autoscaling, Node, Scheduling and Testing] - Promoted the
PersistentVolumeClaimUnusedSinceTimefeature gate to Beta inv1.37and enabled it by default. PersistentVolumeClaims report theUnusedcondition, indicating how long a PersistentVolumeClaim has been unused to help identify candidates for cleanup. (#139620, @RomanBednar) [SIG Apps] - Promoted the
StorageVersionMigrationfeature gate to GA. Thestoragemigration.k8s.io/v1API group is enabled by default. (#138560, @michaelasp) [SIG API Machinery, Apps, Architecture, Auth, Etcd and Testing] - Promoted the
VolumeLimitScalingfeature gate, which adds thepreventPodSchedulingIfMissingfield to CSIDriver to prevent Pod scheduling on nodes missing a required CSI driver, to Beta. (#140612, @gnufied) [SIG API Machinery, Storage and Testing] - Promoted the
metrics.k8s.ioAPI fromv1beta1tov1without changes. (#139223, @tico88612) [SIG Instrumentation] - Promoted the core Workload-Aware Scheduling (WAS) API types Workload and PodGroup to
scheduling.k8s.io/v1beta1. Remove allv1alpha2objects from thekube-apiserverbefore upgrading fromv1.36tov1.37. (#140184, @tosi3k) [SIG API Machinery, Apps, Auth, Etcd, Node, Scheduling and Testing] - Relaxed container security context validation so that updates to Pods may set
allowPrivilegeEscalationtogether withCAP_SYSADMIN. Pod creation still rejects this combination. (#138834, @haircommander) [SIG Apps] - Removed the
GangSchedulingandWorkloadAwarePreemptionfeature gates. Use theGenericWorkloadfeature gate to enable core workload-aware scheduling functionality. (#139520, @macsko) [SIG API Machinery, Node, Scheduling and Testing] - Removed the generally available feature gate
AnyVolumeDataSource, which was locked and enabled sincev1.33. (#135336, @carlory) [SIG API Machinery, Apps, Storage and Testing] - Removed the unused
PodStatusResulttype from the Kubernetes API. This type had no REST endpoint and has been unused since 2015. (#136271, @adityasharmawork) [SIG API Machinery, Apps, Node and Testing] - Renamed signal enum keys in
cri-api, which are prefixed withSIGNAL_in theapi.protodefinition, to avoid conflicts with C++ macros. The wire format is unchanged. (#139251, @SergeyKanzhelev) [SIG Apps, Node and Testing] - Renamed the PodGroup condition
PodGroupScheduledtoPodGroupInitiallyScheduledto clarify that the condition is set only after a PodGroup is first scheduled successfully and may not reflect the PodGroup's current scheduling state. (#139743, @antekjb) [SIG API Machinery, Scheduling and Testing] - Switched the json tag for inlined
TypeMetafields in the API Go types from",inline"to"".inlinewas not a recognized json serializer option and did not modify marshal or unmarshal behavior. (#138260, @liggitt) [SIG API Machinery, Apps, Architecture, Auth, CLI, Cloud Provider, Cluster Lifecycle, Etcd, Instrumentation, Network, Node, Scheduling, Storage and Testing] - Updated CDI spec version selection to be dynamic, preventing the generation of incompatible CDI specifications. (#137699, @alaypatel07) [SIG Apps, Node, Scheduling and Testing]
- Updated Pod-level resource handling so that Pod resources determine QoS only when they include a resource request or limit. Empty Pod resources (
{},{requests:{}}, or{limits:{}}) no longer affect QoS calculation. (#137150, @KevinTMtz) [SIG Apps, CLI, Node and Scheduling] - Updated PodGroup and PodGroupTemplate to allow modifying
minCountafter creation. Changes to a PodGroupTemplate do not affect existing PodGroups. (#139279, @antekjb) [SIG API Machinery, Scheduling and Testing] - Updated the Alpha
DRANodeAllocatableResourcesfeature:- ResourceSlice mappings and PodStatus support direct allocations, for DRA drivers modeling CPU, memory, and hugepages as a resource, and overhead allocations, for accelerator host overhead.
- The
kubeletaccounts for DRA allocated resources when configuring Pod and container cgroups, OOM scores, and Memory QoS thresholds. - Standard resource requests and limits can be resized in place for Pods that use DRA claims.
- The scheduler supports unreferenced Pod-level claims, enforces resource limits with DRA, and enforces claim sharing rules, allowing claim sharing across Pods for overhead allocations.
- Validation enforces constraints for the updated API and uses node declared features to confirm that target nodes have the
NodeAllocatableDRAfeature gate enabled. (#140009, @pravk03) [SIG API Machinery, Apps, Auth, Autoscaling, Node, Scheduling and Testing]
- Updated the PodGroup API to replace
PodGroupTemplateRefwithWorkloadRef, a simpler and more direct way to reference the workload a PodGroup belongs to. (#140080, @dom4ha) [SIG API Machinery, Apps, Etcd, Node, Scheduling and Testing] client-go: Removed nearly allcontext.TODOcalls by introducing APIs where the caller passes in the context. Log calls use the logger provided by the caller when available. (#129125, @pohly) [SIG API Machinery, Apps, Architecture, Auth, CLI, Cloud Provider, Instrumentation, Network, Node, Storage and Testing]kubelet: Added TLS support for gRPC container probes (behind a feature gate). (#137762, @amritansh1502) [SIG API Machinery, Apps, Node and Testing]
Feature
- Added Beta support for compressed responses to
WatchListrequests. When a client sendsAccept-Encoding: gzip, the API server returns a gzip compressed response. This behavior is enabled by default and can be disabled using theWatchListCompressionfeature gate. Regularwatchrequests are unaffected. (#140140, @p0lyn0mial) [SIG API Machinery] - Added GROUP, SCOPE, VERSIONS, and CREATED AT columns to
kubectl get crdoutput, alongside the existing NAME column. The new columns provide additional information about the Custom Resource Definitions (CRDs) in a more concise and organized manner, making it easier for users to understand the details of their CRDs at a glance. (#131599, @jaehanbyun) [SIG API Machinery] - Added PodGroup methods to
PodGroupManagerandSharedLister, allowing scheduler plugins to obtain a consistent PodGroup state. (#140077, @macsko) [SIG Node, Scheduling and Testing] - Added Prometheus metrics for Windows kube-proxy (winkernel) load balancer operation failures:
kubeproxy_sync_proxy_rules_winkernel_lb_create_failures_total,kubeproxy_sync_proxy_rules_winkernel_lb_update_failures_total, andkubeproxy_sync_proxy_rules_winkernel_lb_delete_failures_total. Each metric includesip_family,lb_type, anderrorlabels for fine-grained failure observability. (#137767, @princepereira) [SIG Instrumentation, Network and Windows] - Added ServiceName, PodManagementPolicy, and PersistentVolumeClaimRetentionPolicy to
kubectl describe statefulsetoutput. (#137547, @kfess) [SIG CLI] - Added
AnnotatedEventfmethod to the new events API (EventRecorderandEventRecorderLoggerinterfaces inclient-go/tools/events), enabling callers to attach custom annotations to events at creation time. (#138103, @adri1197) [SIG API Machinery and Node] - Added
cpu_idsandmemoryfields at the pod level to thePodResourcesv1 API to report total allocated pod resources, while only returning contai
These notes run past the length kept in the archive. The rest is on the publisher’s page.