Stay up-to-date on Kubernetes development in 15 minutes a week.
A new security advisory, CVE-2026-19444 (kubectl cp path traversal on Windows allows arbitrary file writes), was published on September 28; a malicious tar archive can cause kubectl cp on Windows to write files outside the intended destination.
Shu Muto (@shu-mutou) has moved to SIG UI emeritus, following the earlier SIG UI leadership transitions covered in prior editions.
WG Node Identity has added a dedicated Slack channel for its working group discussions.
SIG ContribEx has added vetting criteria for the #announcements Slack channel to clarify what messages are appropriate for posting there.
The 2026 Kubernetes Steering Committee election results were announced at the public Steering meeting on October 7: Michael McCune, Janet Kuo, and Priyanka Saggu were elected to the three open seats for two-year terms. 308 of 1547 eligible voters cast ballots, for a turnout of 19.91%.
Next Deadline: Docs: Open placeholder PRs, October 29
The Kubernetes v1.38 Enhancements Freeze began September 30. Of 102 enhancements opted in, 86 are being tracked and 16 were removed from the milestone.
October patch releases are targeted for October 13.
torredil added the alpha CSIControllerGetNodeInfo feature gate and the driverRegistrations field to CSINode as part of KEP-6011. The change enables CSI node registration to split node-side identity reporting from controller-side discovery of topology and volume attachment limits. This allows CSI drivers to obtain information that may require cloud API access from the controller rather than requiring those credentials on worker nodes. The controller-side flow also enables more accurate volume capacity tracking using VolumeAttachment information while preserving the existing node-side registration flow for drivers that do not opt in.
stlaz introduced a feature gate, as part of KEP-6283, to switch ServiceAccount token volume trust from the kube-root-ca.crt ConfigMap to the kubernetes.io/kube-apiserver-serving ClusterTrustBundle. This provides a newer mechanism for making the kube-apiserver serving CA available to workloads using automatically mounted ServiceAccount token volumes, while allowing the existing behavior to remain available behind the feature gate.
Private image pulls commonly use imagePullSecrets stored in the Kubernetes API or credentials supplied to the kubelet for an entire node. KEP-4412 lets a configured credential provider receive a short-lived ServiceAccount token bound to the Pod and scoped to an audience. The plugin can exchange it for registry credentials or return it directly as a pull credential. This lets image access follow the workload’s identity without requiring a long-lived pull Secret in the cluster.
Before an image pull, kubelet requests the token and passes it to the plugin with selected ServiceAccount annotations. Administrators opt a provider in through tokenAttributes and set cacheType to key cached credentials per token or per ServiceAccount. The API server restricts which token audiences a node may request. Because the container runtime receives credentials only when a pull starts, a pull longer than their lifetime can fail, and lazy image streaming is not supported.
aramase and mainred authored the KEP with SIG Auth and SIG Node. The feature reached Alpha in v1.33 and Beta in v1.34. The KEP is targeting GA in v1.38 and the GA update merged on September 29 documents test evidence, operational limits, and the plan to lock its two feature gates on; the enhancement issue tracks the work.
kubectl kuberc set leaving a stale credential plugin allowlist when the policy is changed to AllowAll or DenyAll, which caused kubectl to failkubectl label now prints messages about nonexistent labels to stderr instead of stdout, so they no longer break JSON or YAML outputtaint_eviction_controller_pod_deletion_duration_seconds metric, which recorded nanoseconds scaled by 1e9 instead of secondsa/b/c, is now rejectedspec.attachRequired, which was previously reported as spec.attachedRequired — a field that does not exist in the APIstatus.reservedFor for allocated claims that remain in use by other consumersnodeSelector with more than one node selector term, as it already does for the slice-level nodeSelectorkubectl kuberc view when no kuberc file exists and the user declines to generate a default onednsPolicy: Default no longer inherit scoped IPv6 link-local nameservers from the node resolver configuration unless the pod uses the host network namespaceequality.Semantic.DeepDerivative for slices by rejecting prefix-only matchesLast Week In Kubernetes Development (LWKD) is a product of multiple contributors participating in Kubernetes SIG Contributor Experience. All original content is licensed Creative Commons Share-Alike, although linked content and images may be differently licensed. LWKD does collect some information on readers, see our privacy notice for details.
You may contribute to LWKD by submitting pull requests or issues on the LWKD github repo.