Catalog / Kubernetes

1.37.0

2 months agosecurityaddedfixedOriginal notes

Changelog since v1.36.0

Urgent Upgrade Notes

(No, really, you MUST read this before you upgrade)

  • ACTION REQUIRED: Graduated the SELinuxMount feature gate to GA. The feature is enabled by default in v1.37, which may break existing workloads in clusters with SELinux enabled. Please see the Kubernetes blog post to identify potentially problematic workloads in a v1.36 cluster and how to fix them or opt out of SELinuxMount changes before upgrading to v1.37. Admins of clusters without SELinux enabled can ignore this release note. (#139956, @jsafrane) [SIG API Machinery, Apps and Node]
  • ACTION REQUIRED: Converted the DisruptionMode enum field to a struct to support future extensibility. Promoted the scheduling.k8s.io API group from v1alpha2 to v1alpha3 and dropped v1alpha2 entirely. Remove all v1alpha2 objects from the kube-apiserver before performing the cluster update. (#138572, @dom4ha) [SIG API Machinery, Apps, CLI, Etcd, Node, Scheduling and Testing]
  • ACTION REQUIRED: Fixed eventRecordQPS handling in kubelet configuration to treat 0 as unlimited (no rate limit), aligning behavior with the documentation. Users relying on the previous default behavior should explicitly set a non-zero value (for example, 50). (#117119, @HirazawaUi) [SIG API Machinery, Auth and Node]
  • ACTION REQUIRED: Updated the kubelet to log its effective configuration at startup. Because these logs can expose configuration details, cluster administrators should restrict the nodes/logs ClusterRole to trusted users. This is largely a reminder of an existing best practice, since most effective configuration values can already be inferred from other log messages or kubelet behavior. (#139837, @SergeyKanzhelev) [SIG Node]

Changes by Kind

Dependency

  • Updated google.golang.org/grpc to v1.82.1, which adds a server-side limit on HTTP/2 control frame flooding. It also removes the GRPC_GO_EXPERIMENTAL_DISABLE_STRICT_PATH_CHECKING environment variable, so strict path checking is always on. (#140740, @dims) [SIG API Machinery, Architecture, Auth, CLI, Cloud Provider, Network, Node and Scheduling]
  • Updated the kubelet's embedded cAdvisor to use the leaner github.com/google/cadvisor/lib module, which removes three long-deprecated or legacy surfaces:
    • Deprecated cAdvisor flags are no longer accepted and the kubelet will fail to start if any are set (only --housekeeping-interval is kept): --application-metrics-count-limit, --boot-id-file, --container-hints, --containerd, --containerd-namespace, --enable-load-reader, --event-storage-age-limit, --event-storage-event-limit, --global-housekeeping-interval, --log-cadvisor-usage, --machine-id-file, --storage-driver-user, --storage-driver-password, --storage-driver-host, --storage-driver-db, --storage-driver-table, --storage-driver-secure, --storage-driver-buffer-duration. Remove these from your kubelet configuration.
    • cAdvisor application/custom metrics are no longer collected: the userDefinedMetrics field in /stats/summary and the custom container_application_* families in /metrics/cadvisor.
    • The /metrics/cadvisor series container_cpu_load_average_10s, container_cpu_load_d_average_10s, and container_tasks_state are no longer exported. (#139870, @dims) [SIG API Machinery, Auth, Instrumentation, Network, Node and Testing]
  • Updated the default etcd version to v3.7.0-rc.0. (#139427, @Jefftree) [SIG API Machinery, Cloud Provider, Cluster Lifecycle, Etcd and Testing]
  • Updated the default etcd version to v3.7.0. (#140333, @Jefftree) [SIG API Machinery, Auth, Cloud Provider, Cluster Lifecycle, Etcd, Node, Scheduling and Testing]
  • Updated the etcd client library to v3.6.10. (#138393, @humblec) [SIG API Machinery, Architecture, Auth, CLI, Cloud Provider, Cluster Lifecycle, Etcd, Instrumentation, Network, Node, Scheduling and Storage]

Deprecation

  • Changed kubeadm to explicitly set KubeProxyConfiguration.mode to iptables when KubeProxyConfiguration is not provided or when the mode field is empty. In v1.37, kube-proxy will warn if the field is not explicitly set as part of the planned transition to nftables as the default mode in a future release. (#139777, @neolit123) [SIG Cluster Lifecycle]
  • Deprecated the ignored --filename/-f flag on kubectl run. (#138671, @Suknna) [SIG CLI]
  • Locked the deprecated DeclarativeValidationTakeover feature gate to its default value; it can no longer be set. (#139212, @yongruilin) [SIG API Machinery]
  • kubeadm: Added a (delayed) warning that kube-proxy's ipvs mode is deprecated since v1.35 and users on newer Linux kernels should be using the nftables mode instead, which became GA in v1.33. For older kernel versions, users can use iptables, which is still the default. (#139067, @neolit123) [SIG Cluster Lifecycle]

API Change

  • Added Alpha support for DRA device compatibility groups, guarded by the DRADeviceCompatibilityGroups feature gate (disabled by default). DRA drivers can declare opaque compatibilityGroups on each device.consumesCounters[] entry of a ResourceSlice, and the scheduler only co-allocates devices drawing from the same counter set when their declared groups intersect. This moves detection of incompatible co-allocation from preparation-time failure to scheduling-time rejection. (#139795, @omeryahud) [SIG API Machinery, Node, Scheduling and Testing]
  • Added Alpha support for binding service account tokens to webhook configurations with attestations, behind the APIServerWebhookAuthenticationToken feature gate. This enables API servers to authenticate to admission webhooks with scoped tokens. (#140113, @pmengelbert) [SIG API Machinery, Apps, Auth and Testing]
  • Added Alpha support for defining the file owner of atomically written volume files, behind the AtomicWriteVolumeUserFields feature gate (disabled by default). (#139764, @gavinkflam) [SIG API Machinery, Apps, Auth, Storage and Testing]
  • Added CompositePodGroup support to the building block APIs and the workloadbuilder library. (#140717, @helayoty) [SIG API Machinery, Apps, Auth, Scheduling and Testing]
  • Added Workload-aware scheduling (WAS) support to the Job controller by integrating it with the workloadbuilder library and the Workload building block APIs. (#140188, @helayoty) [SIG API Machinery, Apps, Auth, Network, Node, Scheduling, Storage and Testing]
  • Added CheckpointPod and RestorePod RPCs to the CRI v1 RuntimeService API for Pod-level checkpoint and restore. (#140366, @rst0git) [SIG Node, Testing and Windows]
  • Added a PreemptionPolicy field to PodGroup, allowing users to control how kube-scheduler preempts Pods that belong to a PodGroup during workload-aware preemption. (#139240, @ania-borowiec) [SIG Scheduling]
  • Added a protocol field to httpGet probes so that liveness, readiness, and startup probes can run over HTTP/2 cleartext (H2C). (#139429, @amritansh1502) [SIG API Machinery, Apps, Node and Testing]
  • Added a defense-in-depth check to the NodeRestriction admission plugin for PodCertificateRequests. A node can only create a PodCertificateRequest referring to a particular signer name if the Pod actually mounts a podCertificate projected volume source that refers to that signer name, or if an authorization check for the user (with verb=request-podcertificate-signer and resource=<signerName>) succeeds. (#140006, @ahmedtd) [SIG Auth and Testing]
  • Added a second Alpha of DRA resource availability visibility (KEP-5677), behind the DRAResourcePoolStatus feature gate (disabled by default). The ResourcePoolStatusRequest controller counts partitionable and consumable devices correctly, counting each device once, ignoring AdminAccess, and treating taints as unavailable. Optional fields describe partition and shareable availability. These accounting fixes change the numbers reported in v1.36. (#140170, @nmn3m) [SIG API Machinery, Apps, Auth, Node and Testing]
  • Added an opt-in userspace TCP proxy to the nftables kube-proxy backend to serve localhost NodePort Services on IPv4 and IPv6. (#138427, @AustinAbro321) [SIG Instrumentation, Network and Testing]
  • Added dry-run support to unsafe corrupt object deletion, letting administrators test deletion operations safely before running them. (#134037, @ibihim) [SIG API Machinery and Testing]
  • Added generated declarative validation functions for Go consumers of the DRA device metadata v1alpha1 API. (#140687, @alaypatel07) [SIG Node]
  • Added scheduler support for preempting lower-priority Pods to make room for Deferred in-place Pod resizes of higher-priority Pods when the InPlacePodVerticalScalingSchedulerPreemption Alpha feature gate is enabled. (#140000, @natasha41575) [SIG API Machinery, Apps, Node, Scheduling, Storage and Testing]
  • Added support for derived attributes in DRA, allowing claims to define virtual attributes using CEL expressions and use them in device constraints. This enables co-allocation of devices across different domains, for example GPUs and NICs on the same NUMA node, even if their drivers publish physical attributes differently. (#140029, @gauravkghildiyal) [SIG API Machinery, Node, Scheduling and Testing]
  • Added support for dynamically resizing memory-backed volumes behind the Alpha InPlacePodVerticalScalingMemoryBackedVolumes feature gate. (#139425, @natasha41575) [SIG API Machinery, Apps, Autoscaling, CLI, Node, Scheduling, Storage and Testing]
  • Added support for selecting ResourceSlices by pool name with the field selector spec.pool.name. (#138456, @yaroslavborbat) [SIG API Machinery, Node and Testing]
  • Added support for setting Unix permission bits (0000-01777) through the mode field on emptyDir volume directories at creation time. (#140244, @nispriha) [SIG API Machinery, Apps, Node, Storage and Testing]
  • Added support for specifying bind mount options (noexec, nodev, nosuid) per container volume mount. (#140013, @nispriha) [SIG API Machinery, Apps, Autoscaling, Node, Scheduling and Testing]
  • Added the API changes required for reporting volume health. (#140194, @gnufied) [SIG API Machinery, Apps, Architecture, Auth, Etcd, Instrumentation, Node, Storage and Testing]
  • Added the CompositePodGroup API to scheduling.k8s.io/v1alpha3. (#139596, @jdzikowski) [SIG API Machinery, Apps, Auth, Etcd, Node, Scheduling and Testing]
  • Added the Recreate update strategy for StatefulSet, mirroring the Deployment Recreate strategy by deleting all Pods, waiting for them to terminate completely, and then creating Pods according to the podManagementPolicy field. (#137187, @galal-hussein) [SIG Apps and Testing]
  • Added the --concurrent-disruption-syncs flag to kube-controller-manager to configure the number of concurrent disruption controller workers. (#140014, @xigang) [SIG API Machinery, Apps, Auth and Testing]
  • Added the .spec.evictionResponders Pod field, along with the EvictionRequest and Eviction resources. A set of requesters and responders can use these to coordinate graceful eviction of Pods. (#137050, @atiratree) [SIG API Machinery, Apps, Architecture, Auth, CLI, Etcd and Testing]
  • Added the DefaultPodSysctls kubelet configuration field for default Pod sysctls on Linux nodes, behind the Alpha DefaultPodSysctls feature gate (disabled by default). (#140052, @VeraQin) [SIG Node and Testing]
  • Added the DisruptionMode and PreemptionPolicy fields to the Workload and CompositePodGroup APIs to support workload-aware preemption for CompositePodGroups. (#140634, @tosi3k) [SIG API Machinery, Auth, Etcd, Node, Scheduling and Testing]
  • Added the GracefulNodeShutdownInProgress, DrainInProgress, Drained, MaintenancePlanned, and MaintenanceInProgress Node lifecycle conditions. (#139993, @rthallisey) [SIG Apps and Node]
  • Added the PodGroupPostFilter extension point to the scheduling framework, replacing the internal hardcoding for WorkloadAwarePreemption with a configurable extension point for PodGroups. (#139674, @GFilipek) [SIG Scheduling and Testing]
  • Added the PreemptionPolicy field to PodGroupTemplate to define the policy for workload-aware preemption. (#140312, @ania-borowiec) [SIG API Machinery, Apps, Scheduling and Testing]
  • Added the SchedulerPreQueueingHints feature gate (Alpha, disabled by default). When enabled, scheduler plugins can provide a PreQueueingHintFn that narrows the set of Pods evaluated on cluster events, improving scheduling throughput. The DRA plugin implements this to optimize ResourceClaimTemplate-based workloads. (#138916, @geetasg) [SIG API Machinery, Apps, Architecture, Auth, CLI, Cloud Provider, Instrumentation, Network, Node, Scheduling, Storage, Testing and Windows]
  • Added the core machinery for Conditional Authorization, which enables authorizers to allow requests conditionally based on the request's content, rather than only allowing or denying them outright. (#137513, @luxas) [SIG API Machinery, Auth, Node and Testing]
  • Allowed HorizontalPodAutoscaler conditions to optionally include the observedGeneration at the time the condition was recorded. (#138653, @adrianmoisey) [SIG API Machinery, Apps, Autoscaling and Testing]
  • Changed the kube-apiserver CBOR encoder to encode collections item by item instead of all at once. (#138808, @chenk008) [SIG API Machinery, Apps, Auth, Autoscaling, CLI, Cloud Provider, Cluster Lifecycle, Contributor Experience, Instrumentation, Network, Node, Release, Scalability, Scheduling, Storage, Testing and Windows]
  • DRA: Added Alpha support for DRAOptionalNodeOperations (the SkipNodeOperations field in ResourceSlice and ResourceClaim), which allows skipping node-level preparation and cleanup operations. (#139933, @troychiu) [SIG API Machinery, Autoscaling, Instrumentation, Node, Release, Scheduling and Testing]
  • Fixed CEL cost estimation for metadata.name and metadata.generateName in CRDs to correctly account for the default maximum length of 253 characters, unless additional validations are defined on those metadata fields. (#139573, @jpbetz) [SIG API Machinery]
  • Fixed DRA CapacityRequestPolicyRange to support fractional quantities in milli-scale. (#140161, @sunya-ch) [SIG API Machinery, Node and Scheduling]
  • Fixed Pod status validation for reported Linux container user UIDs to accept values above 2147483647 and up to the unsigned 32-bit UID limit. (#138574, @Kunalbehbud) [SIG Apps and Node]
  • Fixed a v1.34+ regression handling containers with environment values set from Secret API objects containing binary non-utf8 data. (#139168, @liggitt) [SIG Architecture, Node and Testing]
  • Fixed a bug in DRA consumable capacity where the DistinctAttribute constraint was not correctly enforced for each device when a request allocated multiple devices. (#140600, @GunaKKIBM) [SIG API Machinery, Apps, CLI, Etcd, Network, Node, Release, Scheduling and Testing]
  • Fixed the overestimation of a Pod's resource footprint during resize operations for multi-container Pods. (#140047, @natasha41575) [SIG Node and Scheduling]
  • Graduated Pod Certificates to GA, with the PodCertificateRequest feature gate enabled by default. The PKIXPublicKey and ProofOfPossession fields, deprecated in PodCertificateRequest v1beta1, are removed from the v1 API. Update clients that still set these fields before upgrading. (#139579, @yt2985) [SIG API Machinery, Apps, Architecture, Auth, Etcd, Node, Scheduling and Testing]
  • Graduated Pod hostname overrides to GA. The HostnameOverride feature gate is locked to enabled. (#139116, @HirazawaUi) [SIG API Machinery, Apps, Node and Testing]
  • Graduated the ClusterTrustBundle and ClusterTrustBundleProjection feature gates to GA and enabled them by default. (#139437, @stlaz) [SIG API Machinery, Apps, Architecture, Auth, Etcd, Node, Storage and Testing]
  • Improved CEL error messages in Dynamic Resource Allocation to provide guidance when accessing non-existent device attributes. Error messages link to documentation on handling optional fields using orValue() and has(). (#136709, @gzb1128) [SIG API Machinery, Node and Scheduling]
  • Moved the NodeSyncPeriod field from KubeCloudSharedConfiguration to CloudControllerManagerConfiguration.NodeLifecycleController.NodeMonitorPeriod. (#137964, @niewysoki) [SIG API Machinery, Apps, Cloud Provider, Instrumentation and Node]
  • Promoted DRA Workload resource claims to Beta. The DRAWorkloadResourceClaims feature gate remains disabled by default. (#140334, @nojnhuh) [SIG API Machinery, Apps, Etcd, Node, Scheduling and Testing]
  • Promoted kubelet volume metrics (storage_operation_duration_seconds, volume_operation_total_seconds) from Alpha to Beta stability, providing stronger API and label stability guarantees for metric consumers. (#136189, @bhope) [SIG Instrumentation and Storage]
  • Promoted the DRA Device Taints and Tolerations feature to GA, making it available via the resource.k8s.io/v1 API. (#138676, @pohly) [SIG API Machinery, Apps, Architecture, Auth, Etcd, Node, Scheduling, Storage and Testing]
  • Promoted the DRA extended resource feature to GA in v1.37. (#138488, @yliaog) [SIG API Machinery, Apps, Node, Scheduling and Testing]
  • Promoted the DRA metadata API to Beta. DRA driver authors that enable the feature must explicitly select which versions to support in their metadata output. (#140722, @pohly) [SIG Node and Testing]
  • Promoted the DRAResourceHealth kubelet gRPC API to v1; the schema is unchanged from v1alpha1. DRAPlugin.WatchHealthStatus is a mandatory method on the DRAPlugin interface in the k8s.io/dynamic-resource-allocation/kubeletplugin helper, replacing the optional versioned gRPC interface. This is a one-time Go API break: existing drivers must add the method to compile. Drivers without health support return ErrHealthNotSupported from it, or disable the service with HealthService(false). The helper serves both v1 and v1alpha1 by default, so drivers report health on kubelet v1.36 and older without extra configuration. The kubelet prefers v1 and, for three releases of transition, still consumes v1alpha1 from drivers that shipped before v1 existed. The v1alpha1 DRAResourceHealth API is deprecated and is planned to be removed in v1.40. The kubelet only opens the device health stream for plugins that advertise the service. (#139477, @harche) [SIG Node and Testing]
  • Promoted the HPAConfigurableTolerance feature gate to GA. (#140107, @jm-franc) [SIG API Machinery, Apps, Autoscaling and Testing]
  • Promoted the KubeletInUserNamespace feature gate to Beta. (#134639, @AkihiroSuda) [SIG API Machinery, Apps, Node and Testing]
  • Promoted the MemoryQoS feature gate to Beta. memoryThrottlingFactor defaults to nil, and memory.high is not set unless explicitly configured. (#140007, @QiWang19) [SIG Node and Testing]
  • Promoted the NodeDeclaredFeatures feature gate to GA. (#139763, @pravk03) [SIG Apps, Autoscaling, Node, Scheduling and Testing]
  • Promoted the PersistentVolumeClaimUnusedSinceTime feature gate to Beta in v1.37 and enabled it by default. PersistentVolumeClaims report the Unused condition, indicating how long a PersistentVolumeClaim has been unused to help identify candidates for cleanup. (#139620, @RomanBednar) [SIG Apps]
  • Promoted the StorageVersionMigration feature gate to GA. The storagemigration.k8s.io/v1 API group is enabled by default. (#138560, @michaelasp) [SIG API Machinery, Apps, Architecture, Auth, Etcd and Testing]
  • Promoted the VolumeLimitScaling feature gate, which adds the preventPodSchedulingIfMissing field to CSIDriver to prevent Pod scheduling on nodes missing a required CSI driver, to Beta. (#140612, @gnufied) [SIG API Machinery, Storage and Testing]
  • Promoted the metrics.k8s.io API from v1beta1 to v1 without changes. (#139223, @tico88612) [SIG Instrumentation]
  • Promoted the core Workload-Aware Scheduling (WAS) API types Workload and PodGroup to scheduling.k8s.io/v1beta1. Remove all v1alpha2 objects from the kube-apiserver before upgrading from v1.36 to v1.37. (#140184, @tosi3k) [SIG API Machinery, Apps, Auth, Etcd, Node, Scheduling and Testing]
  • Relaxed container security context validation so that updates to Pods may set allowPrivilegeEscalation together with CAP_SYSADMIN. Pod creation still rejects this combination. (#138834, @haircommander) [SIG Apps]
  • Removed the GangScheduling and WorkloadAwarePreemption feature gates. Use the GenericWorkload feature gate to enable core workload-aware scheduling functionality. (#139520, @macsko) [SIG API Machinery, Node, Scheduling and Testing]
  • Removed the generally available feature gate AnyVolumeDataSource, which was locked and enabled since v1.33. (#135336, @carlory) [SIG API Machinery, Apps, Storage and Testing]
  • Removed the unused PodStatusResult type from the Kubernetes API. This type had no REST endpoint and has been unused since 2015. (#136271, @adityasharmawork) [SIG API Machinery, Apps, Node and Testing]
  • Renamed signal enum keys in cri-api, which are prefixed with SIGNAL_ in the api.proto definition, to avoid conflicts with C++ macros. The wire format is unchanged. (#139251, @SergeyKanzhelev) [SIG Apps, Node and Testing]
  • Renamed the PodGroup condition PodGroupScheduled to PodGroupInitiallyScheduled to clarify that the condition is set only after a PodGroup is first scheduled successfully and may not reflect the PodGroup's current scheduling state. (#139743, @antekjb) [SIG API Machinery, Scheduling and Testing]
  • Switched the json tag for inlined TypeMeta fields in the API Go types from ",inline" to "". inline was not a recognized json serializer option and did not modify marshal or unmarshal behavior. (#138260, @liggitt) [SIG API Machinery, Apps, Architecture, Auth, CLI, Cloud Provider, Cluster Lifecycle, Etcd, Instrumentation, Network, Node, Scheduling, Storage and Testing]
  • Updated CDI spec version selection to be dynamic, preventing the generation of incompatible CDI specifications. (#137699, @alaypatel07) [SIG Apps, Node, Scheduling and Testing]
  • Updated Pod-level resource handling so that Pod resources determine QoS only when they include a resource request or limit. Empty Pod resources ({}, {requests:{}}, or {limits:{}}) no longer affect QoS calculation. (#137150, @KevinTMtz) [SIG Apps, CLI, Node and Scheduling]
  • Updated PodGroup and PodGroupTemplate to allow modifying minCount after creation. Changes to a PodGroupTemplate do not affect existing PodGroups. (#139279, @antekjb) [SIG API Machinery, Scheduling and Testing]
  • Updated the Alpha DRANodeAllocatableResources feature:
    • ResourceSlice mappings and PodStatus support direct allocations, for DRA drivers modeling CPU, memory, and hugepages as a resource, and overhead allocations, for accelerator host overhead.
    • The kubelet accounts for DRA allocated resources when configuring Pod and container cgroups, OOM scores, and Memory QoS thresholds.
    • Standard resource requests and limits can be resized in place for Pods that use DRA claims.
    • The scheduler supports unreferenced Pod-level claims, enforces resource limits with DRA, and enforces claim sharing rules, allowing claim sharing across Pods for overhead allocations.
    • Validation enforces constraints for the updated API and uses node declared features to confirm that target nodes have the NodeAllocatableDRA feature gate enabled. (#140009, @pravk03) [SIG API Machinery, Apps, Auth, Autoscaling, Node, Scheduling and Testing]
  • Updated the PodGroup API to replace PodGroupTemplateRef with WorkloadRef, a simpler and more direct way to reference the workload a PodGroup belongs to. (#140080, @dom4ha) [SIG API Machinery, Apps, Etcd, Node, Scheduling and Testing]
  • client-go: Removed nearly all context.TODO calls by introducing APIs where the caller passes in the context. Log calls use the logger provided by the caller when available. (#129125, @pohly) [SIG API Machinery, Apps, Architecture, Auth, CLI, Cloud Provider, Instrumentation, Network, Node, Storage and Testing]
  • kubelet: Added TLS support for gRPC container probes (behind a feature gate). (#137762, @amritansh1502) [SIG API Machinery, Apps, Node and Testing]

Feature

  • Added Beta support for compressed responses to WatchList requests. When a client sends Accept-Encoding: gzip, the API server returns a gzip compressed response. This behavior is enabled by default and can be disabled using the WatchListCompression feature gate. Regular watch requests are unaffected. (#140140, @p0lyn0mial) [SIG API Machinery]
  • Added GROUP, SCOPE, VERSIONS, and CREATED AT columns to kubectl get crd output, alongside the existing NAME column. The new columns provide additional information about the Custom Resource Definitions (CRDs) in a more concise and organized manner, making it easier for users to understand the details of their CRDs at a glance. (#131599, @jaehanbyun) [SIG API Machinery]
  • Added PodGroup methods to PodGroupManager and SharedLister, allowing scheduler plugins to obtain a consistent PodGroup state. (#140077, @macsko) [SIG Node, Scheduling and Testing]
  • Added Prometheus metrics for Windows kube-proxy (winkernel) load balancer operation failures: kubeproxy_sync_proxy_rules_winkernel_lb_create_failures_total, kubeproxy_sync_proxy_rules_winkernel_lb_update_failures_total, and kubeproxy_sync_proxy_rules_winkernel_lb_delete_failures_total. Each metric includes ip_family, lb_type, and error labels for fine-grained failure observability. (#137767, @princepereira) [SIG Instrumentation, Network and Windows]
  • Added ServiceName, PodManagementPolicy, and PersistentVolumeClaimRetentionPolicy to kubectl describe statefulset output. (#137547, @kfess) [SIG CLI]
  • Added AnnotatedEventf method to the new events API (EventRecorder and EventRecorderLogger interfaces in client-go/tools/events), enabling callers to attach custom annotations to events at creation time. (#138103, @adri1197) [SIG API Machinery and Node]
  • Added cpu_ids and memory fields at the pod level to the PodResources v1 API to report total allocated pod resources, while only returning contai

These notes run past the length kept in the archive. The rest is on the publisher’s page.