Stay up-to-date on Kubernetes development in 15 minutes a week.
Two security advisories were published on September 24: CVE-2026-2270 (rated Medium, 5.9) describes a confused deputy attack in the StatefulSet controller that lets a user with namespace-scoped write permissions on StatefulSet and ControllerRevision objects create a cross-namespace pod, and CVE-2026-76654 (rated Medium, 5.8) describes an NTLM coercion vulnerability on Windows nodes when a pod’s subPath is a symbolic link to an attacker-controlled UNC network share; both are fixed in the September patch releases (v1.34.12, v1.35.9, v1.36.5, v1.37.1) covered in the Release Schedule below.
SIG Cluster Lifecycle has a leadership change: Vince Prignano (@vincepri) is stepping down as chair, and existing Tech Lead Fabrizio Pandini (@fabriziopandini) will assume the chair role in addition to his Tech Lead responsibilities. The change is under a one-week lazy consensus period.
The CfP for Kubecon Europe 2027 is already open, and closes October 11th. This includes Maintainer Track sessions and Lightning Talks for SIGs.
Voting closes on October 2. If you are an Kubernetes Org Member, and have not cast your ballot yet, please vote right away.
Next Deadline: Enhancements Freeze, September 29 (AoE) / September 30 at 12:00 UTC
The Kubernetes v1.38 release cycle heads into its Enhancements Freeze this week. Following KEP Readiness, 11 enhancements were removed from the v1.38 milestone, leaving 89 tracked out of the 100 that had opted in. Any KEP that still wants to join v1.38 and isn’t already tracked now needs an approved exception. Please reach out in the #sig-release channel in Slack with any questions.
Kubernetes v1.38.0-alpha.1 has been built and pushed using Go 1.27.1. See the release notes and the GitHub release.
Patch releases v1.37.1, v1.36.5, v1.35.9, and v1.34.12 are now available. These releases bump to Go 1.26.8 and include a handful of bug fixes.
pohly added an option for the DRA ResourceSlice controller to avoid publishing capacities and attributes associated with a driver domain. ResourceSlices are used by DRA drivers to publish device information that the scheduler uses during allocation and placement. This change gives drivers more control over which resource metadata is exposed through ResourceSlices while preserving the ability to publish the devices themselves. The work builds on the ResourceSlice and structured-parameter design described in KEP-4381.
ttsuubasa graduated DRA Device Binding Conditions to General Availability under KEP-5007. Device Binding Conditions allow the scheduler to wait for network- or fabric-attached devices to become ready before binding a Pod. This avoids binding a workload to a node before the required device attachment has completed and allows failed attachment attempts to be reported back to scheduling. The graduation makes this workflow stable for DRA drivers and workloads that depend on devices requiring external preparation.
Kubernetes controller managers use a Lease to ensure only one replica reconciles resources at a time. Today, if the leader cannot renew its Lease before RenewDeadline during a temporary API server or etcd outage, it exits. Restarting forces its controllers to rebuild their cached view of the cluster, extending the interruption after the API becomes available again.
The proposal adds a transport-level write gate to controller clients. When the manager stops leading, the gate rejects new writes and cancels writes in flight while reads and watches continue, keeping caches warm. The election loop keeps trying to renew the same Lease; if it succeeds before another replica takes over, the gate reopens and reconciliation resumes without a restart. A configurable recovery deadline can limit these attempts, and the former leader exits if another replica takes over. The Lease API and election protocol remain unchanged.
alvaroaleman, jpbetz, and michaelasp authored the KEP with SIG API Machinery. Proposed on September 14, it was merged on September 25. The enhancement issue tracks the work, and discussion is in the SIG API Machinery thread.
KEP 6361 is implementable and targets Alpha in Kubernetes v1.38 behind the disabled-by-default LeaderElectionRecovery feature gate.
+k8s:minimum and +k8s:maximum support time.Duration fields with quoted Go duration strings, such as +k8s:minimum="1s". Integer payloads on time.Duration fields are now rejected.SelfSignedCertKeyOptions in k8s.io/client-go/util/cert accepts a KeyGenerator, allowing self-signed certificates to be generated with a key algorithm other than RSA. The default remains a 2048-bit RSA key.NoExecute device taints (DeviceTaintRule) did not evict pods using DRA-backed extended resources (pod.Status.ExtendedResourceClaimStatus)NominatedPodsForNode method must now pass logger klog.Logger as the first argumentNode.status.volumesAttached[].devicePath now states the platform-specific semantics: on Linux it is the host block-device node, on Windows it carries the CSI VolumeIDdistribute-cpus-across-cores=true and align-by-socket=true options were enabled, even when a single socket had sufficient capacity--manifest-url-header credential values (e.g., Authorization tokens) to runtime logs at startup. Only header key names are now loggedManagedFieldsOptOut feature gate (off by default)/apis/... paths and final delegation 404s now return a JSON Status object with Content-Type: application/json instead of a plain-text “404 page not found” bodyWindowsHostNetwork feature gate (KEP-3503, withdrawn). The gate no longer guarded any code pathsSeparateTaintEvictionController feature gate from kube-controller-manager. Remove this gate from existing --feature-gates configuration before upgradingNo shoutouts this week. Want to thank someone for special efforts to improve Kubernetes? Tag them in the #shoutouts channel.
Last Week In Kubernetes Development (LWKD) is a product of multiple contributors participating in Kubernetes SIG Contributor Experience. All original content is licensed Creative Commons Share-Alike, although linked content and images may be differently licensed. LWKD does collect some information on readers, see our privacy notice for details.
You may contribute to LWKD by submitting pull requests or issues on the LWKD github repo.