LWKD logo

Last Week in Kubernetes Development

Stay up-to-date on Kubernetes development in 15 minutes a week.

Subscribe
Mastodon
BlueSky
RSS

View LWKD on GitHub

Week Ending October 04, 2026

Developer News

A new security advisory, CVE-2026-19444 (kubectl cp path traversal on Windows allows arbitrary file writes), was published on September 28; a malicious tar archive can cause kubectl cp on Windows to write files outside the intended destination.

Shu Muto (@shu-mutou) has moved to SIG UI emeritus, following the earlier SIG UI leadership transitions covered in prior editions.

WG Node Identity has added a dedicated Slack channel for its working group discussions.

SIG ContribEx has added vetting criteria for the #announcements Slack channel to clarify what messages are appropriate for posting there.

Election Update

The 2026 Kubernetes Steering Committee election results were announced at the public Steering meeting on October 7: Michael McCune, Janet Kuo, and Priyanka Saggu were elected to the three open seats for two-year terms. 308 of 1547 eligible voters cast ballots, for a turnout of 19.91%.

Release Schedule

Next Deadline: Docs: Open placeholder PRs, October 29

The Kubernetes v1.38 Enhancements Freeze began September 30. Of 102 enhancements opted in, 86 are being tracked and 16 were removed from the milestone.

October patch releases are targeted for October 13.

142693: Add CSIControllerGetNodeInfo feature gate and driverRegistrations field

torredil added the alpha CSIControllerGetNodeInfo feature gate and the driverRegistrations field to CSINode as part of KEP-6011. The change enables CSI node registration to split node-side identity reporting from controller-side discovery of topology and volume attachment limits. This allows CSI drivers to obtain information that may require cloud API access from the controller rather than requiring those credentials on worker nodes. The controller-side flow also enables more accurate volume capacity tracking using VolumeAttachment information while preserving the existing node-side registration flow for drivers that do not opt in.

142789: KEP-[6283]: use kubernetes.io/kube-apiserver-serving CTB to mount kube-apiserver trust

stlaz introduced a feature gate, as part of KEP-6283, to switch ServiceAccount token volume trust from the kube-root-ca.crt ConfigMap to the kubernetes.io/kube-apiserver-serving ClusterTrustBundle. This provides a newer mechanism for making the kube-apiserver serving CA available to workloads using automatically mounted ServiceAccount token volumes, while allowing the existing behavior to remain available behind the feature gate.

KEP of the Week

KEP-4412: Projected Service Account Tokens for Kubelet Image Credential Providers

Private image pulls commonly use imagePullSecrets stored in the Kubernetes API or credentials supplied to the kubelet for an entire node. KEP-4412 lets a configured credential provider receive a short-lived ServiceAccount token bound to the Pod and scoped to an audience. The plugin can exchange it for registry credentials or return it directly as a pull credential. This lets image access follow the workload’s identity without requiring a long-lived pull Secret in the cluster.

Before an image pull, kubelet requests the token and passes it to the plugin with selected ServiceAccount annotations. Administrators opt a provider in through tokenAttributes and set cacheType to key cached credentials per token or per ServiceAccount. The API server restricts which token audiences a node may request. Because the container runtime receives credentials only when a pull starts, a pull longer than their lifetime can fail, and lazy image streaming is not supported.

aramase and mainred authored the KEP with SIG Auth and SIG Node. The feature reached Alpha in v1.33 and Beta in v1.34. The KEP is targeting GA in v1.38 and the GA update merged on September 29 documents test evidence, operational limits, and the plan to lock its two feature gates on; the enhancement issue tracks the work.

Other Merges

Promotions

Deprecated

Version Updates

Shoutouts

Last Week In Kubernetes Development (LWKD) is a product of multiple contributors participating in Kubernetes SIG Contributor Experience. All original content is licensed Creative Commons Share-Alike, although linked content and images may be differently licensed. LWKD does collect some information on readers, see our privacy notice for details.

You may contribute to LWKD by submitting pull requests or issues on the LWKD github repo.