| filename | sha512 hash |
|---|---|
| kubernetes.tar.gz | ef3014768ea305a97865ceef486e704083af78841079cad5c589c02711ac12769f5e949cefa2188c80d28a30884a559befc2239e2adfecdca972d1d211a0cb4f |
| kubernetes-src.tar.gz | 973ce8ba840125da3d1f45205fd53e82bf5c6736517ff1f27d3ecfb951d413e8db30878194177a76bd73912829a9db3e5948437234f23b269b5e05fd0b29ab75 |
| filename | sha512 hash |
|---|---|
| kubernetes-client-darwin-amd64.tar.gz | acb682468b459bfc51fbc823aa5cef7ed6dbd7441bb3f00e1842c7eb59d15a9c0d0c941700f518e8826d0b3e68d54c9607c94186d624d04402d97ba4b716d384 |
| kubernetes-client-darwin-arm64.tar.gz | 066e93a872ea0cef77ab734d7a37ec0ada797da31cd004b29326fc75d4849067ce8a58f11807a4b45643794db4cffa1091820af8c3c476ff9d49c7ce517129b1 |
| kubernetes-client-linux-386.tar.gz | 61aba7c6fef077ddf94e6f63958fd4f1c6062460f47098979e8bedf3b1081478f5905cb72e5a6edcb28f46f8e78965dbf4dbc666be49d2a7ad025b39e74e7369 |
| kubernetes-client-linux-amd64.tar.gz | 291a4d24a400666ec0e3d91fbaae0605de438abf4878ca81e4e8e923beefa8a434ade3a98e8538f654dfe7d32c2038a1610ca6863efe91d2649ea11c28a20a49 |
| kubernetes-client-linux-arm.tar.gz | ac37de6c47ec1e8d8be6e60ef8ca03cd66b6f212b671d619bfa38fe62182c830550d5d6ebe80f4363d2007160ad177c27e7eaab29c2dd5642c4c91f30ce0a347 |
| kubernetes-client-linux-arm64.tar.gz | 643b95ff27f275ee7f8999676c141d9a6199d1a60f19ab425be57e6170abf66a5dd4c3712e10db6e11b104e1e41f1fc2b2366507c477b080061cc0ae1fcd788e |
| kubernetes-client-linux-ppc64le.tar.gz | 2ce8193c228bb8703d2b42c0e354c489a8c2cf73acfa317c8720f7b1deda68f71ff19c27260ac300d5ab1a70958d082fd4146d09be09505694e65c00b23f103b |
| kubernetes-client-linux-s390x.tar.gz | c4124123942178f3371ace92b21e284afd0982d6e2cf8f43db0dc9266a35f5d771d84d829ffa64780213ac7375d0f100463fc990529b28c269527061958098c4 |
| kubernetes-client-windows-386.tar.gz | 9973e72958a27b11a02f74147355f8cc4525d283fc148f7a39c2863bb66601839dbfdb27e0da6477dd0afba7afd6a01138ada0d708dda89518d942eb58d1f44c |
| kubernetes-client-windows-amd64.tar.gz | 6075bd48040a710395ea6df57f3379984291d90f7d2f75f08d3f24e46abc5b716445dc1d7c26cd877439f213f4efea8e2c03fc362a67db86c2c44326bcc6ff43 |
| kubernetes-client-windows-arm64.tar.gz | 17a7d93c0245cdd959845f9c7be95f1f172cae242af09bff03cae161abe828ff2b49cb014b847fff97bdfffd899e78f1a6a0d6c75fd7540c7de5fc9ab7321cef |
| filename | sha512 hash |
|---|---|
| kubernetes-server-linux-amd64.tar.gz | 43a3e68bed60252b588493d07ed85eaa35ff3fec7f9440096fe9af284925f040467d1b31a8948e3035e4738bb689ad6d6fb9208fe77c16b053874d020a3fabd3 |
| kubernetes-server-linux-arm.tar.gz | a8ed49f4a6c57b6e0d4a3dc8705fb5d59c8b77e1cc67564bc3825782922bcc2cf431ed762b97f1fd05b4e63d1bf71a3d43f698aae49db4e670b6a7e99384db0c |
| kubernetes-server-linux-arm64.tar.gz | dfcf3c4e751b9c174dbc667a87b0f561cb9a0ff4c0503439ca57d4e904db775f19be39605a8f553f9fee6af4e6256fea3eedc71a9cd401aa25d836d722b0f695 |
| kubernetes-server-linux-ppc64le.tar.gz | e5d91705c5969a2483314cdb3f80e6b828987036f5fbcf269cce83cbf62b8d73210ec3b469c6e0667432f2f874309622768ecc3df851c9711c4fa51dcaf489e4 |
| kubernetes-server-linux-s390x.tar.gz | 1fcbf0e575752cff6a11c8518658454237953227588c7c73efca1a036c73d30246ce57f0b89095b02ccd536b37be2427ddde918763cf63e6a1e6248f38f41689 |
| filename | sha512 hash |
|---|---|
| kubernetes-node-linux-amd64.tar.gz | b6b36973c45986e61d3ab4440b551b145d6279801e388b08f83c7f0369984bd55979504209d3cc70409ff70b200923c680f00302d3410c973c92f657157a7510 |
| kubernetes-node-linux-arm.tar.gz | dd57bb241b0468ac78d5eb64770e99a9ad14b2cba345cd762e9552e4e58ea50a92eb037ac6e250983fc5bede37459faee7b9c97eccf7eb3dcc2587eb6f280bae |
| kubernetes-node-linux-arm64.tar.gz | b8f339d796644e1bac5e33bb47d14460c012411f28e531a61f3d7b4db939a4722bc8ecafb8193b290b9b4e896b4e52d8332a8e4b010f327b896616614b8695fb |
| kubernetes-node-linux-ppc64le.tar.gz | df52fed23afa5bebaaea2fc18482fc718e6e6643d931416cb62f1efbc8bf2e9ba82f6d3372f82b18c8d0562378dfa82aae621e13cb7a1a80a769d843f9279e1e |
| kubernetes-node-linux-s390x.tar.gz | dc79e44a9a2879d1dea8c22b2b21965c7a0279e54d8c54af899eecb4f14da0b56eb52e11812e663ed9edc94410b2771f38118bf2936aa15bf66011ee04fad03a |
| kubernetes-node-windows-amd64.tar.gz | 4275d4c6ab19433398adf8122923b0dd0a8e1432f966a38f40c9547255e69c952b951e76273b8f3220c777504905480a457a7f0b1a1ed64769f9db0cc9f1b716 |
All container images are available as manifest lists and support the described architectures. It is also possible to pull a specific architecture directly by adding the "-$ARCH" suffix to the container image name.
After its deprecation in v1.20, the dockershim component has been removed from the kubelet. From v1.24 onwards, you will need to either use one of the other supported runtimes (such as containerd or CRI-O) or use cri-dockerd if you are relying on Docker Engine as your container runtime. For more information about ensuring your cluster is ready for this removal, please see this guide.
New beta APIs will not be enabled in clusters by default. Existing beta APIs and new versions of existing beta APIs, will continue to be enabled by default.
Release artifacts are signed using cosign signatures and there is experimental support for verifying image signatures. Signing and verification of release artifacts is part of increasing software supply chain security for the Kubernetes release process.
Kubernetes 1.24 offers beta support for publishing its APIs in the OpenAPI v3 format.
Storage capacity tracking supports exposing currently available storage capacity via CSIStorageCapacity objects and enhances scheduling of pods that use CSI volumes with late binding.
Volume expansion adds support for resizing existing persistent volumes.
This feature adds a new option to PriorityClasses, which can enable or disable pod preemption.
There is work under way to migrate the internals of in-tree storage plugins to call out to CSI Plugins, while maintaining the original API. The Azure Disk and OpenStack Cinder plugins have both been migrated.
With Kubernetes 1.24, the gRPC probes functionality has entered beta and is available by default. You can now configure startup, liveness, and readiness probes for your gRPC app natively within Kubernetes, without exposing an HTTP endpoint or using an extra executable.
Originally released as Alpha in Kubernetes 1.20, the kubelet's support for image credential providers has now graduated to Beta. This allows the kubelet to dynamically retrieve credentials for a container image registry using exec plugins, rather than storing credentials on the node's filesystem.
Kubernetes 1.24 has introduced contextual logging that enables the caller of a function to control all aspects of logging (output formatting, verbosity, additional values and names).
Kubernetes 1.24 introduced a new opt-in feature that allows you to soft-reserve a range for static IP address assignments to Services. With the manual enablement of this feature, the cluster will prefer automatic assignment from the pool of Service IP addresses thereby reducing the risk of collision.
A Service ClusterIP can be assigned:
- dynamically, which means the cluster will automatically pick a free IP within the configured Service IP range.
- statically, which means the user will set one IP within the configured Service IP range.
Service ClusterIP are unique, hence, trying to create a Service with a ClusterIP that has already been allocated will return an error.
- Docker runtime support using dockershim in the kubelet is now completely removed in 1.24. The kubelet used to have a module called dockershim, which implements CRI support for Docker, and it has seen maintenance issues in the Kubernetes community. From 1.24 onwards, please move to a container runtime that is a full-fledged implementation of CRI (v1alpha1 or v1 compliant) as they become available. (#97252, @dims) [sig/network,sig/node,sig/instrumentation,sig/testing,sig/cloud-provider]
- Fixed bug with leads to Node goes
Not-readystate when credentials for vCenter stored in a secret and Zones feature is in use. Zone labels setup moved to KCM component, kubelet skips this step during startup in such case. If credentials stored in cloud-provider config file as plaintext current behaviour does not change and no action required. For proper functioningkube-system:vsphere-legacy-cloud-providershould be allowed to update node object if vCenter credentials stored in secret and Zone feature used. (#101028, @lobziik) [sig/cloud-provider] - The
LegacyServiceAccountTokenNoAutoGenerationfeature gate is beta, and enabled by default. When enabled, Secret API objects containing service account tokens are no longer auto-generated for every ServiceAccount. Use the TokenRequest API to acquire service account tokens, or if a non-expiring token is required, create a Secret API object for the token controller to populate with a service account token by following this guide. (#108309, @zshihang) [sig/api-machinery,sig/auth,sig/apps,sig/testing] - The calculations for Pod topology spread skew now exclude nodes that
don't match the node affinity/selector. This may lead to unschedulable pods if you previously had pods
matching the spreading selector on those excluded nodes (not matching the node affinity/selector),
especially when the
topologyKeyis not node-level. Revisit the node affinity and/or pod selector in the topology spread constraints to avoid this scenario. (#107009, @kerthcet) [sig/scheduling] - Remove the deprecated flag
--experimental-check-node-capabilities-before-mount. With CSI now GA, there is a better alternative. Remove any use of--experimental-check-node-capabilities-before-mountfrom your kubelet scripts or manifests. (#104732, @mengjiao-liu) [sig/storage,sig/node,sig/apps,sig/cloud-provider] kubeadm.k8s.io/v1beta2has been deprecated and will be removed in a future release, possibly in 3 releases (one year). You should start usingkubeadm.k8s.io/v1beta3for new clusters. To migrate your old configuration files on disk you can use thekubeadm config migratecommand. (#107013, @pacoxu) [sig/cluster-lifecycle]- Kubeadm: default the kubeadm configuration to the containerd socket (Unix:
unix:///var/run/containerd/containerd.sock, Windows:npipe:////./pipe/containerd-containerd) instead of the one for Docker. If theInit|JoinConfiguration.nodeRegistration.criSocketfield is empty during cluster creation and multiple sockets are found on the host always throw an error and ask the user to specify which one to use by setting the value in the field. Make sure you update any kubeadm configuration files on disk, to not include the dockershim socket unless you are still using kubelet version < 1.24 with kubeadm >= 1.24. Remove the DockerValidor and ServiceCheck for thedockerservice from kubeadm preflight. Docker is no longer special cased during host validation and ideally this task should be done in the now external cri-dockerd project where the importance of the compatibility matters. Usecrictlfor all communication with CRI sockets for actions like pulling images and obtaining a list of running containers instead of using the docker CLI in the case of Docker. (#107317, @neolit123) [sig/cluster-lifecycle] - The feature gate was mentioned as
csiMigrationRBDwhere it should have beenCSIMigrationRBDto be in parity with other migration plugins. This release correct the same and keep it asCSIMigrationRBD. users who have configured this feature gate ascsiMigrationRBDhas to reconfigure the same toCSIMigrationRBDfrom this release. (#107554, @humblec) [sig/storage] - The experimental dynamic log sanitization feature has been deprecated and removed in the 1.24 release. The feature is no longer available for use. (#107207, @ehashman) [sig/scheduling,sig/instrumentation,sig/security]
- Kubeadm: apply
second stageof the plan to migrate kubeadm away from the usage of the wordmasterin labels and taints. For new clusters, the labelnode-role.kubernetes.io/masterwill no longer be added to control plane nodes, only the labelnode-role.kubernetes.io/control-planewill be added. For clusters that are being upgraded to 1.24 withkubeadm upgrade apply, the command will remove the labelnode-role.kubernetes.io/masterfrom existing control plane nodes. For new clusters, both the old taintnode-role.kubernetes.io/master:NoScheduleand new taintnode-role.kubernetes.io/control-plane:NoSchedulewill be added to control plane nodes. In release 1.20 (first stage), a release note instructed to preemptively tolerate the new taint. For clusters that are being upgraded to 1.24 withkubeadm upgrade apply, the command will add the new taintnode-role.kubernetes.io/control-plane:NoScheduleto existing control plane nodes. Please adapt your infrastructure to these changes. In 1.25 the old taintnode-role.kubernetes.io/master:NoSchedulewill be removed. (#107533, @neolit123) [sig/cluster-lifecycle,sig/testing] - The feature gate was mentioned as
csiMigrationRBDwhere it should have beenCSIMigrationRBDto be in parity with other migration plugins. This release correct the same and keep it asCSIMigrationRBD. users who have configured this feature gate ascsiMigrationRBDhas to reconfigure the same toCSIMigrationRBDfrom this release. (#107554, @humblec) [sig/storage]
- Deprecated
Service.Spec.LoadBalancerIP. This field was under-specified and its meaning varies across implementations. As of Kubernetes v1.24, users are encouraged to use implementation-specific annotations when available. This field may be removed in a future API version. (#107235, @uablrek) [sig/network,sig/apps] - Kube-apiserver: the
--master-countflag and--endpoint-reconciler-type=master-countreconciler are deprecated in favor of the lease reconciler (#108062, @aojea) [sig/api-machinery] - Kube-apiserver: the insecure address flags
--address,--insecure-bind-address,--portand--insecure-port(inert since 1.20) are removed (#106859, @knight42) [sig/api-machinery,sig/cluster-lifecycle,sig/cloud-provider] - Kubeadm: graduated the
UnversionedKubeletConfigMapfeature gate to Beta and enabled the feature by default. This implies that 1) for new clusters kubeadm will start using thekube-system/kubelet-confignaming scheme for the kubelet ConfigMap and RBAC rules, instead of the legacykubelet-config-x.yynaming. 2) during upgrade, kubeadm will only write the new scheme ConfigMap and RBAC objects. To disable the feature you can passUnversionedKubeletConfigMap: falsein the kubeadm config for new clusters. For upgrade on existing clusters you can also override the behavior by patching the ClusterConfiguration object inkube-system/kubeadm-config. More details in the associated KEP. (#108027, @neolit123) [sig/cluster-lifecycle,sig/testing] - Remove
tolerate-unready-endpointsannotation in Service deprecated from 1.11, useService.spec.publishNotReadyAddressesinstead. (#108020, @tossmilestone) [sig/network,sig/apps] - Remove deprecated feature gates
ValidateProxyRedirectsandStreamingProxyRedirects(#106830, @pacoxu) [sig/api-machinery] - Remove insecure serving configuration from cloud-provider package, which is consumed by cloud-controller-managers. (#108953, @nckturner) [sig/testing,sig/cloud-provider]
- The
--pod-infra-container-imagekubelet flag is deprecated and will be removed in future releases (#108045, @hakman) [sig/node] - The
client.authentication.k8s.io/v1alpha1ExecCredential has been removed. If you are using a client-go credential plugin that relies on the v1alpha1 API please contact the distributor of your plugin for instructions on how to migrate to the v1 API. (#108616, @margocrawf) [sig/api-machinery,sig/auth] - The
node.k8s.io/v1alpha1RuntimeClass API is no longer served. Use thenode.k8s.io/v1API version, available since v1.20 (#103061, @SergeyKanzhelev) [sig/node,sig/api-machinery,sig/cli,sig/testing] - The cluster addon for dashboard was removed. To install dashboard, see here. (#107481, @shu-mutou) [sig/testing,sig/cloud-provider]
- The in-tree Azure plugin has been deprecated. The Azure kubelogin plugin serves as an out-of-tree replacement via the kubectl/client-go credential plugin mechanism. Users will now see a warning in the logs regarding this deprecation. (#107904, @sabbey37) [sig/auth]
- The insecure address flags
--addressand--portin kube-controller-manager have had no effect since v1.20 and are removed in v1.24. (#106860, @knight42) [sig/node,sig/api-machinery,sig/testing] - The metadata.clusterName field is deprecated. This field has always been unwritable and always blank, but its presence is confusing, so we will remove it next release. Out of an abundance of caution, this release we have merely changed the name in the go struct to ensure any accidental client uses are found before complete removal. (#108717, @lavalamp) [sig/scheduling,sig/api-machinery,sig/auth,sig/apps,sig/testing]
- VSphere releases less than 7.0u2 are deprecated as of v1.24. Please consider upgrading vSphere to 7.0u2 or above. vSphere CSI Driver requires minimum vSphere 7.0u2.
General Support for vSphere 6.7 will end on October 15, 2022. vSphere 6.7 Update 3 is deprecated in Kubernetes v1.24. Customers are recommended to upgrade vSphere (both ESXi and vCenter) to 7.0u2 or above. vSphere CSI Driver 2.2.3 and higher supports CSI Migration.
Support for these deprecations will be available till October 15, 2022. (#109089, @deepakkinni) [sig/cloud-provider]
- Add 2 new options for kube-proxy running in winkernel mode.
--forward-healthcheck-vip, if specified as true, health check traffic whose destination is service VIP will be forwarded to kube-proxy's healthcheck service.--root-hnsendpoint-namespecifies the name of the hns endpoint for the root network namespace. This option enables the pass-through load balancers like Google's GCLB to correctly health check the backend services. Without this change, the health check packets is dropped, and Windows node will be considered to be unhealthy by those load balancers. (#99287, @anfernee) [sig/network,sig/api-machinery,sig/windows,sig/testing,sig/cloud-provider] - Added CEL runtime cost calculation into CustomerResource validation. CustomerResource validation will fail if runtime cost exceeds the budget. (#108482, @cici37) [sig/api-machinery]
- Added a new metric
webhook_fail_open_countto monitor webhooks that fail to open. (#107171, @ltagliamonte-dd) [sig/api-machinery,sig/instrumentation] - Adds a new Status subresource in Network Policy objects (#107963, @rikatz) [sig/network,sig/api-machinery,sig/apps,sig/testing]
- Adds support for
InterfaceNamePrefixandBridgeInterfaceas arguments to--detect-local-modeoption and also introduces a new optional--pod-interface-name-prefixand--pod-bridge-interfaceflags to kube-proxy. (#95400, @tssurya) [sig/network,sig/api-machinery] - CEL CRD validation expressions may now reference existing object state using the identifier
oldSelf. (#108073, @benluddy) [sig/api-machinery,sig/testing] - CRD deep copies should no longer contain shallow copies of
JSONSchemaProps.XValidations. (#107956, @benluddy) [sig/api-machinery] - CRD writes will generate validation errors if a CEL validation rule references the identifier
oldSelfon a part of the schema that does not support it. (#108013, @benluddy) [sig/api-machinery] - CSIStorageCapacity.storage.k8s.io: The v1beta1 version of this API is deprecated in favor of v1, and will be removed in v1.27. If a CSI driver supports storage capacity tracking, then it must get deployed with a release of external-provisioner that supports the v1 API. (#108445, @pohly) [sig/scheduling,sig/storage,sig/api-machinery,sig/auth,sig/testing,sig/architecture]
- Custom resource requests with
fieldValidation=Strictconsistently requireapiVersionandkind, matching non-strict requests (#109019, @liggitt) [sig/api-machinery] - Feature of
DefaultPodTopologySpreadis graduated to GA (#108278, @kerthcet) [sig/scheduling] - Feature of
NonPreemptingPriorityis graduated to GA (#107432, @denkensk) [sig/scheduling,sig/apps,sig/testing] - Feature of
PodOverheadis graduated to GA (#108441, @pacoxu) [sig/scheduling,sig/node,sig/api-machinery,sig/apps] - Fixed OpenAPI serialization of the x-kubernetes-validations field (#107970, @liggitt) [sig/api-machinery]
- Fixed failed flushing logs in defer function when kubelet cmd exit 1. (#104774, @kerthcet) [sig/scheduling,sig/node]
- Fixes a regression in v1beta1 PodDisruptionBudget handling of
strategic merge patch-type API requests for theselectorfield. Prior to 1.21, these requests would mergematchLabelscontent and replacematchExpressionscontent. In 1.21, patch requests touching theselectorfield started replacing the entire selector. This is consistent with server-side apply and the v1 PodDisruptionBudget behavior, but should not have been changed for v1beta1. (#108138, @liggitt) [sig/auth,sig/apps,sig/testing] - Improve kubectl's user help commands readability (#104736, @lauchokyip) [sig/network,sig/scalability,sig/scheduling,sig/storage,sig/node,sig/api-machinery,sig/cluster-lifecycle,sig/autoscaling,sig/contributor-experience,sig/auth,sig/apps,sig/windows,sig/cli,sig/instrumentation]
- Indexed Jobs graduated to stable. (#107395, @alculquicondor) [sig/apps,sig/testing,sig/architecture]
- Introduce a v1alpha1 networking API for ClusterCIDRConfig (#108290, @sarveshr7) [sig/network,sig/api-machinery,sig/auth,sig/apps,sig/cli,sig/instrumentation,sig/testing,sig/cloud-provider]
- Introduction of a new "sync_proxy_rules_no_local_endpoints_total" proxy metric. This metric represents the number of services with no internal endpoints. The "traffic_policy" label will contain both "internal" or "external". (#108930, @MaxRenaud) [sig/network,sig/scheduling,sig/storage,sig/node,sig/api-machinery,sig/autoscaling,sig/auth,sig/apps,sig/windows,sig/cli,sig/instrumentation,sig/testing,sig/release,sig/architecture]
- JobReadyPods graduates to Beta and it's enabled by default. (#107476, @alculquicondor) [sig/api-machinery,sig/apps,sig/testing]
- Kube-apiserver:
--audit-log-versionand--audit-webhook-versionnow only support the default value ofaudit.k8s.io/v1. The v1alpha1 and v1beta1 audit log versions, deprecated since 1.13, have been removed. (#108092, @carlory) [sig/api-machinery,sig/auth,sig/testing] - Kube-apiserver: the
metadata.selfLinkfield can no longer be populated by kube-apiserver; it was deprecated in 1.16 and has not been populated by default since 1.20+. (#107527, @wojtek-t) [sig/network,sig/scheduling,sig/storage,sig/api-machinery,sig/autoscaling,sig/auth,sig/apps,sig/cli,sig/testing,sig/cloud-provider] - Kubelet external Credential Provider feature is moved to Beta. Credential Provider Plugin and Credential Provider Config API's updated from v1alpha1 to v1beta1 with no API changes. (#108847, @adisky) [sig/node,sig/api-machinery]
- Make STS available replicas optional again. (#109241, @ravisantoshgudimetla) [sig/api-machinery,sig/apps]
- MaxUnavailable for StatefulSets, allows faster RollingUpdate by taking down more than 1 pod at a time. The number of pods you want to take down during a RollingUpdate is configurable using maxUnavailable parameter. (#82162, @krmayankk) [sig/api-machinery,sig/apps]
- Non-graceful node shutdown handling is enabled for stateful workload failovers (#108486, @sonasingh46) [sig/storage,sig/node,sig/apps]
- Omit enum declarations from the static openapi file captured at https://git.k8s.io/kubernetes/api/openapi-spec. This file is used to generate API clients, and use of enums in those generated clients (rather than strings) can break forward compatibility with additional future values in those fields. See https://issue.k8s.io/109177 for details. (#109178, @liggitt) [sig/api-machinery,sig/auth]
- OpenAPI V3 is turned on by default (#109031, @Jefftree) [sig/network,sig/scheduling,sig/storage,sig/node,sig/api-machinery,sig/cluster-lifecycle,sig/autoscaling,sig/auth,sig/apps,sig/cli,sig/instrumentation,sig/testing,sig/architecture,sig/cloud-provider]
- Pod affinity namespace selector and cross-namespace quota graduated to GA. The feature gate
PodAffinityNamespaceSelectoris locked and will be removed in 1.26. (#108136, @ahg-g) [sig/scheduling,sig/api-machinery,sig/apps,sig/testing] - Promote IdentifyPodOS feature to beta. (#107859, @ravisantoshgudimetla) [sig/node,sig/api-machinery,sig/apps,sig/windows,sig/testing]
- Remove a v1alpha1 networking API for ClusterCIDRConfig (#109436, @JamesLaverack) [sig/network,sig/api-machinery,sig/auth,sig/apps,sig/cli,sig/testing]
- Renamed metrics
evictions_numbertoevictions_totaland mark it as stable. The originalevictions_numbermetrics name is marked as "Deprecated" and has been removed in kubernetes 1.23 . (#106366, @cyclinder) [sig/network,sig/scalability,sig/scheduling,sig/storage,sig/node,sig/api-machinery,sig/cluster-lifecycle,sig/auth,sig/apps,sig/windows,sig/cli,sig/instrumentation,sig/testing,sig/release,sig/architecture] - Skip x-kubernetes-validations rules if having fundamental error against the OpenAPIv3 schema. (#108859, @cici37) [sig/api-machinery,sig/testing]
- Support for gRPC probes is now in beta. GRPCContainerProbe feature gate is enabled by default. (#108522, @SergeyKanzhelev) [sig/node,sig/api-machinery,sig/apps,sig/testing]
- Suspend job to GA. The feature gate
SuspendJobis locked and will be removed in 1.26. (#108129, @ahg-g) [sig/apps,sig/testing] - The AnyVolumeDataSource feature is now beta, and the feature gate is enabled by default. In order to provide user feedback on PVCs with data sources, deployers must install the VolumePopulators CRD and the data-source-validator controller. (#108736, @bswartz) [sig/storage,sig/apps,sig/testing]
- The CertificateSigningRequest
spec.expirationSecondsAPI field has graduated to GA. TheCSRDurationfeature gate for the field is now unconditionally enabled and will be removed in 1.26. (#108782, @cfryanr) [sig/api-machinery,sig/auth,sig/apps,sig/instrumentation,sig/testing] - The
ServerSideFieldValidationfeature has graduated to beta and is now enabled by default. Kubectl 1.24 and newer will use server-side validation instead of client-side validation when writing to API servers with the feature enabled. (#108889, @kevindelgado) [sig/api-machinery,sig/cli,sig/testing,sig/architecture] - The
ServiceLBNodePortControlfeature has graduated to GA. The feature gate will be removed in 1.26. (#107027, @uablrek) [sig/network,sig/testing] - The deprecated kube-controller-manager flag '--deployment-controller-sync-period' has been removed, it is not used by the deployment controller. (#107178, @SataQiu) [sig/api-machinery,sig/apps]
- The feature
DynamicKubeletConfighas been removed from the kubelet. (#106932, @SergeyKanzhelev) [sig/node,sig/auth,sig/apps,sig/instrumentation,sig/testing] - The infrastructure for contextual logging is complete (feature gate implemented, JSON backend ready). (#108995, @pohly) [sig/network,sig/scheduling,sig/node,sig/api-machinery,sig/cluster-lifecycle,sig/auth,sig/cli,sig/instrumentation,sig/testing,sig/architecture,sig/cloud-provider]
- This adds an optional
timeZonefield as part of the CronJob spec to support running cron jobs in a specific time zone. (#108032, @deejross) [sig/api-machinery,sig/apps] - Updated the default API priority-and-fairness config to avoid endpoint/configmaps operations from controller-manager to all match leader-election priority level. (#106725, @wojtek-t) [sig/api-machinery]
topologySpreadConstraintsincludesminDomainsfield to limit the minimum number of topology domains. (#107674, @sanposhiho) [sig/scheduling,sig/api-machinery,sig/apps]
-
A new Priority and Fairness metric 'apiserver_flowcontrol_work_estimate_seats_samples' has been added that tracks the estimated seats associated with a request. (#106628, @tkashem) [sig/api-machinery,sig/instrumentation]
-
Add a deprecated cmd flag for the time interval between flushing pods from unschedulable queue to active queue or backoff queue. (#108017, @denkensk) [sig/scheduling]
-
Add one metrics(
kubelet_volume_stats_health_abnormal) of volume health state to kubelet (#105585, @fengzixu) [sig/storage,sig/node,sig/instrumentation,sig/testing] -
Add the metric
container_oom_events_totalto kubelet's cAdvisor metric endpoint. (#108004, @jonkerj) [sig/node] -
Added
SetTransformtoSharedInformerto allow users to transform objects before they are stored. (#107507, @alexzielenski) [sig/api-machinery] -
Added a
proxy-urlflag intokubectl config set-cluster. (#105566, @ardaguclu) [sig/cli] -
Added a metric for measuring end-to-end volume mount timing. (#107006, @gnufied) [sig/storage,sig/node]
-
Added a new Priority and Fairness metric
apiserver_flowcontrol_request_dispatch_no_accommodation_totalto track the number of times a request dispatch attempt results in a no-accommodation status due to lack of available seats. (#106629, @tkashem) [sig/api-machinery,sig/instrumentation] -
Added a path
/header?key=toagnhost netexecallowing one to view what the header value is of the incoming request.Ex:
$ curl -H "X-Forwarded-For: something" 172.17.0.2:8080/header?key=X-Forwarded-For something(#107796, @alexanderConstantinescu) [sig/testing] -
Added completion for
kubectl config set-context. (#106739, @kebe7jun) [sig/cli] -
Added field
add_ambient_capabilitiesto the Capabilities message in the CRI-API. (#104620, @vinayakankugoyal) [sig/node] -
Added label selector flag to all
kubectl rolloutcommands. (#99758, @aramperes) [sig/cli] -
Added more message for no PodSandbox container. (#107116, @yxxhero) [sig/node]
-
Added prune flag into
diffcommand to simulateapply --prune. (#105164, @ardaguclu) [sig/cli,sig/testing] -
Added support for
btrfsresizing (#108561, @RomanBednar) [sig/storage] -
Added support for kubectl commands (
kubectl execandkubectl port-forward) via a SOCKS5 proxy. (#105632, @xens) [sig/storage,sig/api-machinery,sig/cluster-lifecycle,sig/cli,sig/instrumentation,sig/architecture,sig/cloud-provider] -
Adds
OpenAPIV3SchemaInterfacetoDiscoveryClientand its variants for fetching OpenAPI v3 schema documents. (#108992, @alexzielenski) [sig/api-machinery,sig/cluster-lifecycle,sig/cli,sig/instrumentation,sig/architecture,sig/cloud-provider] -
Allow kubectl to manage resources by filename patterns without the shell expanding it first (#102265, @danielrodriguez) [sig/cli]
-
An alpha flag
--subresourceis added to get, patch, edit replace kubectl commands to fetch and update status and scale subresources. (#99556, @nikhita) [sig/api-machinery,sig/cli,sig/testing] -
Apiextensions_openapi_v3_regeneration_count metric (alpha) will be emitted for OpenAPI V3. (#109128, @Jefftree) [sig/api-machinery,sig/instrumentation]
-
Apply ProxyTerminatingEndpoints to all traffic policies (external, internal, cluster, local). (#108691, @andrewsykim) [sig/network,sig/testing]
-
CEL regex patterns in x-kubernetes-valiation rules are compiled when CRDs are created/updated if the pattern is provided as a string constant in the expression. Any regex compile errors are reported as a CRD create/update validation error. (#108617, @jpbetz) [sig/storage,sig/node,sig/api-machinery,sig/cluster-lifecycle,sig/auth,sig/cli,sig/instrumentation,sig/architecture,sig/cloud-provider]
-
CRD
x-kubernetes-validationsrules now support the CEL functions:isSorted,sum,min,max,indexOf,lastIndexOf,findandfindAll. (#108312, @jpbetz) [sig/api-machinery] -
Changes the kubectl
--validateflag from a bool to a string that accepts the values {true, strict, warn, false, ignore} -
true/strict - perform validation and error the request on any invalid fields in the ojbect. It will attempt to perform server-side validation if it is enabled on the apiserver, otherwise it will fall back to client-side validation.
-
warn - perform server-side validation and warn on any invalid fields (but ultimately let the request succeed by dropping any invalid fields from the object). If validation is not available on the server, perform no validation.
-
false/ignore - perform no validation, silently dropping invalid fields from the object. (#108350, @kevindelgado) [sig/node,sig/api-machinery,sig/cli,sig/testing]
-
Client-go metrics: change bucket distribution for
rest_client_request_duration_secondsandrest_client_rate_limiter_duration_secondsfrom [0.001, 0.002, 0.004, 0.008, 0.016, 0.032, 0.064, 0.128, 0.256, 0.512] to [0.005, 0.025, 0.1, 0.25, 0.5, 1.0, 2.0, 4.0, 8.0, 15.0, 30.0, 60.0}] (#106911, @aojea) [sig/api-machinery,sig/instrumentation,sig/architecture] -
Client-go: add new histogram metric to record the size of the requests and responses. (#108296, @aojea) [sig/api-machinery,sig/instrumentation,sig/architecture]
-
CycleState is now optimized for "write once and read many times". (#108724, @sanposhiho) [sig/scheduling]
-
Enabled beta feature HonorPVReclaimPolicy by default. (#109035, @deepakkinni) [sig/storage,sig/apps]
-
Env var for additional cli flags used in the csi-proxy binary when a Windows nodepool is created with
kube-up.sh(#107806, @mauriciopoppe) [sig/windows,sig/cloud-provider] -
Feature of
PreferNominatedNodeis graduated to GA. (#106619, @chendave) [sig/scheduling,sig/testing] -
In text format, log messages that previously used quoting to prevent multi-line output (for example, text="some "quotation", anline break") will now be printed with more readable multi-line output without the escape sequences. (#107103, @pohly) [sig/storage,sig/cluster-lifecycle,sig/auth,sig/cli,sig/instrumentation,sig/cloud-provider]
-
Increase default value of discovery cache TTL for kubectl to 6 hours. (#107141, @mk46) [sig/cli]
-
Introduce policy to allow the HPA to consume the
external.metrics.k8s.ioAPI group. (#104244, @dgrisonnet) [sig/autoscaling,sig/auth,sig/instrumentation] -
Kube-apiserver: Subresources such as
statusandscalenow support tabular output content types. (#103516, @ykakarap) [sig/api-machinery,sig/auth,sig/testing] -
Kube-apiserver: when merging lists, Server Side Apply now prefers the order of the submitted request instead of the existing persisted object. (#107565, @jiahuif) [sig/storage,sig/api-machinery,sig/cluster-lifecycle,sig/auth,sig/cli,sig/instrumentation,sig/testing,sig/cloud-provider]
-
Kubeadm: added support for dry running
kubeadm reset. The new flagkubeadm reset --dry-runis similar to the existing flag forkubeadm init/join/upgradeand allows you to see what changes would be applied. (#107512, @SataQiu) [sig/cluster-lifecycle] -
Kubeadm: added the flag
--experimental-initial-corrupt-checkto etcd static Pod manifests to ensure etcd member data consistency (#109074, @neolit123) [sig/cluster-lifecycle] -
Kubeadm: better surface errors during
kubeadm upgradewhen waiting for the kubelet to restart static pods on control plane nodes (#108315, @Monokaix) [sig/cluster-lifecycle] -
Kubeadm: improve the strict parsing of user YAML/JSON configuration files. Next to printing warnings for unknown and duplicate fields (current state), also print warnings for fields with incorrect case sensitivity - e.g.
controlPlaneEndpoint(valid),ControlPlaneEndpoint(invalid). Instead of only printing warnings duringinitandjoinalso print warnings when downloading the ClusterConfiguration, KubeletConfiguration or KubeProxyConfiguration objects from the cluster. This can be useful if the user has patched these objects in their respective ConfigMaps with mistakes. (#107725, @neolit123) [sig/cluster-lifecycle] -
Kubectl now supports shell completion for the / format for specifying resources. kubectl now provides shell completion for container names following the
--container/-cflag of theexeccommand. kubectl's shell completion now suggests resource types for commands that only apply to pods. (#108493, @marckhouzam) [sig/cli] -
Kubelet: add
kubelet_volume_metric_collection_duration_secondsmetrics for volume disk usage calculation duration (#107201, @pacoxu) [sig/storage,sig/node,sig/instrumentation] -
Kubelet: the following dockershim related flags are also removed along with dockershim
--experimental-dockershim-root-directory,--docker-endpoint,--image-pull-progress-deadline,--network-plugin,--cni-conf-dir,--cni-bin-dir,--cni-cache-dir,--network-plugin-mtu. (#106907, @cyclinder) [sig/node,sig/testing,sig/cloud-provider] -
Kubernetes 1.24 bumped version of golang it is compiled with to go1.18, which introduced significant changes to its garbage collection algorithm. As a result, we observed an increase in memory usage for kube-apiserver in larger an heavily loaded clusters up to ~25% (with the benefit of API call latencies drop by up to 10x on 99th percentiles). If the memory increase is not acceptable for you you can mitigate by setting GOGC env variable (for our tests using GOGC=63 brings memory usage back to original value, although the exact value may depend on usage patterns on your cluster). (#108870, @dims) [sig/testing,sig/release,sig/architecture]
-
Kubernetes 1.24 is built with go1.18, which will no longer validate certificates signed with a SHA-1 hash algorithm by default. See https://golang.org/doc/go1.18#sha1 for more details. If you are using certificates like this in admission or conversion (#109024, @stlaz) [sig/api-machinery,sig/instrumentation]
-
Kubernetes in now built with go1.18rc1 (#107105, @justaugustus) [sig/storage,sig/node,sig/api-machinery,sig/cluster-lifecycle,sig/auth,sig/cli,sig/instrumentation,sig/testing,sig/release,sig/architecture,sig/cloud-provider]
-
Kubernetes is now built with Golang 1.17.4 (#106833, @cpanato) [sig/api-machinery,sig/instrumentation,sig/testing,sig/release,sig/cloud-provider]
-
Kubernetes is now built with Golang 1.17.5. (#106956, @cpanato) [sig/api-machinery,sig/instrumentation,sig/testing,sig/release,sig/cloud-provider]
-
Kubernetes is now built with Golang 1.17.6. (#107612, @palnabarun) [sig/testing,sig/release]
-
Kubernetes is now built with Golang 1.17.7 (#108091, @xmudrii) [sig/testing,sig/release]
-
Kubernetes is now built with Golang 1.18.1 (#109461, @cpanato) [sig/testing,sig/release]
-
Leader Migration is now GA. All new configuration files onwards should use version v1. (#109072, @jiahuif) [sig/cloud-provider]
-
Mark AzureDisk CSI migration as GA (#107681, @andyzhangx) [sig/storage,sig/cloud-provider]
-
Move volume expansion feature to GA (#108929, @gnufied) [sig/storage,sig/node,sig/api-machinery,sig/auth,sig/apps,sig/testing]
-
Moving MixedProtocolLBService from alpha to beta (#109213, @bridgetkromhout) [sig/network]
-
New "field_validation_request_duration_seconds" metric, measures how long requests take, indicating the value of the fieldValidation query parameter and whether or not server-side field validation is enabled on the apiserver (#109120, @kevindelgado) [sig/api-machinery,sig/instrumentation]
-
New feature gate, ServiceIPStaticSubrange, to enable the new strategy in the Service IP allocators, so the IP range is subdivided and dynamic allocated ClusterIP addresses for Services are allocated preferently from the upper range. (#106792, @aojea) [sig/instrumentation]
-
No (#108432, @iXinqi) [SIG Testing and Windows] [sig/windows,sig/testing]
-
OpenAPI definitions served by kube-apiserver now include enum types by default. (#108898, @jiahuif) [sig/api-machinery]
-
OpenStack Cinder CSI migration is now GA and switched on by default, Cinder CSI driver must be installed on clusters on OpenStack for Cinder volumes to work (has been since v1.21). (#107462, @dims) [sig/scheduling,sig/storage]
-
PreFilter extension in the scheduler framework now returns not only status but also PreFilterResult (#108648, @ahg-g) [sig/scheduling,sig/storage,sig/testing]
-
Promoted graceful shutdown based on pod priority to beta (#107986, @wzshiming) [sig/node,sig/instrumentation,sig/testing]
-
Removed feature gate
SetHostnameAsFQDN. (#108038, @mengjiao-liu) [sig/node] -
Removed kube-scheduler insecure flags. You can use
--bind-addressand--secure-portinstead. (#106865, @jonyhy96) [sig/scheduling] -
Removed the
ImmutableEphemeralVolumesfeature gate. (#107152, @mengjiao-liu) [sig/storage,sig/node] -
Set
PodMaxUnschedulableQDurationas 5 min. (#108761, @denkensk) [sig/scheduling] -
Support in-tree PV deletion protection finalizer. (#108400, @deepakkinni) [sig/storage,sig/apps]
-
The
.spec.loadBalancerClassfield for Services is now generally available. (#107979, @XudongLiuHarold) [sig/network,sig/testing,sig/cloud-provider] -
The
NamespaceDefaultLabelNamefeature gate, GA since v1.22, is now removed. (#106838, @mengjiao-liu) [sig/node,sig/apps] -
The
kubectl logswill now warn and default to the first container in a pod. This new behavior brings it in line withkubectl exec. (#105964, @kidlj) [sig/cli] -
The
v1version ofLeaderMigrationConfigurationsupports onlyleasesAPI for leader election. To use formerly supported mechanisms, please continue usingv1beta1. (#108016, @jiahuif) [sig/api-machinery,sig/cloud-provider] -
The kubelet now creates an iptables chain named
KUBE-IPTABLES-HINTin themangletable. Containerized components that need to modify iptables rules in the host network namespace can use the existence of this chain to more-reliably determine whether the system is using iptables-legacy or iptables-nft. (#109059, @danwinship) [sig/network,sig/node] -
The output of
kubectl describe ingressnow includes an IngressClass name if available. (#107921, @mpuckett159) [sig/cli] -
The scheduler prints info logs when the extender returned an error. (
--v>5) (#107974, @sanposhiho) [sig/scheduling] -
The script
cluster/gce/gci/configure.shnow supports downloadingcrictlon ARM64 nodes (#108034, @tstapler) [sig/cloud-provider] -
Turn on
CSIMigrationAzureFileby default on 1.24 (#105070, @andyzhangx) [sig/cloud-provider] -
Update the k8s.io/system-validators library to v1.7.0 (#108988, @neolit123) [sig/cluster-lifecycle]
-
Updated golang.org/x/net to v0.0.0-20211209124913-491a49abca63. (#106949, @cpanato) [sig/storage,sig/node,sig/api-machinery,sig/cluster-lifecycle,sig/auth,sig/cli,sig/instrumentation,sig/cloud-provider]
-
Updates
kubectl kustomizeandkubectl apply -kto Kustomize v4.5.4 (#108994, @KnVerey) [sig/cli] -
When invoked with
-list-images, thee2e.testbinary now also lists the images that might be needed for storage tests. (#108458, @pohly) [sig/testing] -
kubectl config delete-usernow supports completion (#107142, @dimbleby) [sig/cli] -
kubectl create tokencan now be used to request a service account token, and permission to request service account tokens is added to theeditandadminRBAC roles (#107880, @liggitt) [sig/auth,sig/cli,sig/testing] -
kubectl versionnow includes information on the embedded version of Kustomize (#108817, @KnVerey) [sig/cli,sig/testing]
- A node IP provided to kublet via
--node-ipwill now be preferred for when determining the node's primary IP and using the external cloud provider (CCM). (#107750, @stephenfin) [sig/node,sig/cloud-provider] - A static pod that is rapidly updated was failing to start until the Kubelet was restarted. (#107900, @smarterclayton) [sig/node,sig/testing]
- Add one metrics(
kubelet_volume_stats_health_abnormal) of volume health state to kubelet (#108758, @fengzixu) [sig/storage,sig/node,sig/instrumentation,sig/testing] - Added a new label
typetoapiserver_flowcontrol_request_execution_secondsmetric - it has the following values: - 'regular': indicates that it is a non long running request - 'watch': indicates that it is a watch request. (#105517, @tkashem) [sig/api-machinery,sig/instrumentation] - Added a test to guarantee that conformance clusters require at least 2 untainted nodes. (#106313, @aojea) [sig/testing,sig/architecture]
- Adds PV deletion protection finalizer only when PV reclaimPolicy is Delete for dynamically provisioned volumes. (#109205, @deepakkinni) [sig/storage,sig/apps]
- Allowed attached volumes to be mounted quicker by skipping exponential backoff when checking for reported-in-use volumes. (#106853, @gnufied) [sig/storage,sig/node,sig/apps]
- Alowed useful inclusion of
-args $prog_argsin KUBE_TEST_ARGS, when doingmake test-integration. (#107516, @MikeSpreitzer) [sig/testing] - An inefficient lock in EndpointSlice controller metrics cache has been reworked. Network programming latency may be significantly reduced in certain scenarios, especially in clusters with a large number of Services. (#107091, @robscott) [sig/network,sig/scalability,sig/apps]
- Apiserver will now reject connection attempts to
0.0.0.0/::when handling a proxy subresource request. (#107402, @anguslees) [sig/network] - Bug: client-go clientset was not defaulting to the user agent, and was using the default golang agent for all the requests. (#108772, @aojea) [sig/api-machinery,sig/instrumentation]
- Bump
sigs.k8s.io/apiserver-network-proxy/[email protected]to fix a goroutine leak in kube-apiserver when using egress selctor with the gRPC mode. (#108437, @andrewsykim) [sig/api-machinery,sig/auth,sig/cloud-provider] - CEL validation failure returns object type instead of object. (#107090, @cici37) [sig/api-machinery]
- CRI-API: IPs returned by `PodSandboxNetworkStatus`` are ignored by the kubelet for host-network pods. (#106715, @aojea) [sig/node]
- Call
NodeExpandon all nodes in case of RWX volumes (#108693, @gnufied) [sig/storage,sig/node,sig/apps] - Changed node staging path for CSI driver to use a PV agnostic path. Nodes must be drained before updating the kubelet with this change. (#107065, @saikat-royc) [sig/storage,sig/testing]
- Client-go: fixed the paged list calls with
ResourceVersionMatchset would fail once paging is kicked in. (#107311, @fasaxc) [sig/api-machinery] - Correct event registration for multiple scheduler plugins; this fixes a potential significant delay in re-queueing unschedulable pods. (#109442, @ahg-g) [sig/scheduling,sig/testing]
- Etcd: Update to v3.5.3 (#109471, @justaugustus) [sig/api-machinery,sig/cluster-lifecycle,sig/testing,sig/cloud-provider]
- Existing InTree AzureFile PVs which don't have a secret namespace defined will now work properly after enabling CSI migration - the namespace will be obtained from ClaimRef. (#108000, @RomanBednar) [sig/storage,sig/cloud-provider]
- Failure to start a container cannot accidentally result in the pod being considered "Succeeded" in the presence of deletion. (#107845, @smarterclayton) [sig/node]
- Fix a race in the timeout handler that could lead to kube-apiserver crashes (#108455, @Argh4k) [sig/api-machinery]
- Fix container creation errors for pods with cpu requests bigger than 256 cpus (#106570, @odinuge) [sig/node]
- Fix issue where the job controller might not remove the job tracking finalizer from pods when deleting a job, or when the pod is orphan (#108752, @alculquicondor) [sig/apps,sig/testing]
- Fix libct/cg/fs2: fixed GetStats for unsupported hugetlb error on Raspbian Bullseye (#106912, @Letme) [sig/node]
- Fix the bug that the outdated services may be sent to the cloud provider (#107631, @lzhecheng) [sig/network,sig/cloud-provider]
- Fix the overestimated cost of delegated API requests in kube-apiserver API priority & fairness (#109188, @wojtek-t) [sig/api-machinery]
- Fix to allow
fsGroupto be applied for CSI Inline Volumes (#108662, @dobsonj) [sig/storage] - Fixed CSI migration of Azure Disk in-tree StorageClasses with topology requirements in Azure regions that do not have availability zones. (#109154, @jsafrane) [sig/storage]
- Fixed
--retriesfunctionality for negative values inkubectl cp(#108748, @atiratree) [sig/cli] - Fixed
azureDiskparameter lowercase translation issue. (#107429, @andyzhangx) [sig/storage,sig/cloud-provider] - Fixed
azureFilevolumeIDcollision issue in CSI migration. (#107575, @andyzhangx) [sig/storage,sig/cloud-provider] - Fixed a bug in attachdetach controller that didn't properly handle kube-apiserver errors leading to stuck attachments/detachments. (#108167, @jfremy) [sig/apps]
- Fixed a bug that a pod's
.status.nominatedNodeNameis not cleared properly, and thus over-occupied system resources. (#106816, @Huang-Wei) [sig/scheduling,sig/testing] - Fixed a bug that caused credentials in an exec plugin to override the static certificates set in a kubeconfig. (#107410, @margocrawf) [sig/api-machinery,sig/auth,sig/testing]
- Fixed a bug that could cause panic when a
/healthzrequest times out. (#107034, @benluddy) [sig/api-machinery] - Fixed a bug that out-of-tree plugin is misplaced when using scheduler v1beta3 config (#108613, @Huang-Wei) [sig/scheduling,sig/testing]
- Fixed a bug where a partial
EndpointSliceupdate could cause node name information to be dropped from endpoints that were not updated. (#108198, @liggitt) [sig/network] - Fixed a bug where unwanted fields were being returned from a
create --dry-run: uid and, if generateName was used, name. (#107088, @joejulian) [sig/api-machinery,sig/testing] - Fixed a bug where vSphere client connections where not being closed during testing. Leaked vSphere client sessions were causing resource exhaustion during automated testing. (#107337, @derek-pryor) [sig/storage,sig/testing]
- Fixed a panic when using invalid output format in
kubectl create secretcommand. (#107221, @rikatz) [sig/cli] - Fixed a rare race condition handling requests that timeout. (#107452, @liggitt) [sig/api-machinery]
- Fixed a regression in 1.23 that incorrectly pruned data from array items of a custom resource that set
x-kubernetes-preserve-unknown-fields: true. (#107688, @liggitt) [sig/api-machinery] - Fixed a regression in 1.23 where update requests to previously persisted
Serviceobjects that have not been modified since 1.19 can be rejected with an incorrectspec.clusterIPs: Required valueerror. (#107847, @thockin) [sig/network,sig/api-machinery,sig/testing] - Fixed a regression that could incorrectly reject pods with
OutOfCpuerrors if they were rapidly scheduled after other pods were reported as complete in the API. The Kubelet now waits to report the phase of a pod as terminal in the API until all running containers are guaranteed to have stopped and no new containers can be started. Short-lived pods may take slightly longer (~1s) to report Succeeded or Failed after this change. (#108366, @smarterclayton) [sig/node,sig/apps,sig/testing] - Fixed bug in
TopologyManagerfor ensuring aligned allocations on machines with more than 2 NUMA nodes (#108052, @klueska) [sig/node] - Fixed bug in error messaging for basic-auth and ssh secret validations. (#106179, @vivek-koppuru) [sig/auth,sig/apps]
- Fixed detaching CSI volumes from nodes when a CSI driver name has prefix "csi-". (#107025, @jsafrane) [sig/storage]
- Fixed duplicate port opening in kube-proxy when
--nodeport-addressesis empty. (#107413, @tnqn) [sig/network] - Fixed handling of objects with invalid selectors. (#107559, @liggitt) [sig/scheduling,sig/storage,sig/api-machinery,sig/apps]
- Fixed indexer bug that resulted in incorrect index updates if number of index values for a given object was changing during update (#109137, @wojtek-t) [sig/api-machinery]
- Fixed kubectl bug where bash completions don't work if
--contextflag is specified with a value that contains a colon. (#107439, @brianpursley) [sig/cli] - Fixed performance regression in JSON logging caused by syncing stdout every time error was logged. (#107035, @serathius) [sig/scalability,sig/instrumentation]
- Fixed regression in CPUManager that it will release exclusive CPUs in app containers inherited from init containers when the init containers were removed. (#104837, @eggiter) [sig/node]
- Fixed static pod add and removes restarts in certain cases. (#107695, @rphillips) [sig/node]
- Fixed: deleted a non-existent Azure disk issue. (#107406, @andyzhangx) [sig/cloud-provider]
- Fixed: do not return early in the node informer when there is no change of the topology label. (#108149, @nilo19) [sig/cloud-provider]
- Fixed: removed outdated ipv4 route when the corresponding node is deleted. (#106164, @nilo19) [sig/cloud-provider]
- Fixes bug in CronJob Controller V2 where it would lose track of jobs upon job template labels change. (#107997, @d-honeybadger) [sig/apps]
- If drainer has nil for Ctx or Client it will error with
RunCordonOrUncordon. (#105297, @jackfrancis) [sig/cli] - Improved handling of unmount failures when device may be in-use by another container/process. (#107789, @gnufied) [sig/storage]
- Improved logging when volume times out waiting for attach/detach. (#108628, @RomanBednar) [sig/storage]
- Improved the rounding of
PodTopologySpreadscores to offer better scoring when spreading a low number of pods. (#107384, @sanposhiho) [sig/scheduling] - Increase Azure ACR credential provider timeout (#108209, @andyzhangx) [sig/cloud-provider]
- Kube-apiserver: Server Side Apply merge order is reverted to match v1.22 behavior until http://issue.k8s.io/104641 is resolved. (#106660, @liggitt) [sig/storage,sig/api-machinery,sig/cluster-lifecycle,sig/auth,sig/cli,sig/instrumentation,sig/testing,sig/cloud-provider]
- Kube-apiserver: ensures the namespace of objects sent to admission webhooks matches the request namespace. Previously, objects without a namespace set would have the request namespace populated after mutating admission, and objects with a namespace that did not match the request namespace would be rejected after admission. (#94637, @liggitt) [sig/api-machinery,sig/testing]
- Kube-apiserver: removed
apf_fdfrom server logs which could contain data identifying the requesting user (#108631, @jupblb) [sig/api-machinery] - Kube-proxy in iptables mode now only logs the full iptables input at
-v=9rather than-v=5. (#108224, @danwinship) [sig/network] - Kube-proxy will no longer hold service node ports open on the node. Users are still advised not to run any listener on node ports range used by kube-proxy. (#108496, @khenidak) [sig/network]
- Kubeadm: allow the
certs check-expirationcommand to not require the existence of the cluster CA key (ca.key file) when checking the expiration of managed certificates in kubeconfig files. (#106854, @neolit123) [sig/cluster-lifecycle] - Kubeadm: during execution of the
certs check-expirationcommand, treat the etcd CA as external if there is a missing etcd CA key file (etcd/ca.key) and perform the proper validation on certificates signed by the etcd CA. Additionally, make sure that the CA for all entries in the output table is included - for both certificates on disk and in kubeconfig files. (#106891, @neolit123) [sig/cluster-lifecycle] - Kubeadm: fixed a bug related to a warning printed if the
KubeletConfigurationresolvConffield value does not match/run/systemd/resolve/resolv.conf(#107785, @chendave) [sig/cluster-lifecycle] - Kubeadm: fixed a bug when using
kubeadm init --dry-runwith certificate authority files (ca.key/ca.crt) present in/etc/kubernetes/pki) (#108410, @Haleygo) [sig/cluster-lifecycle] - Kubeadm: fixed a bug where Windows nodes fail to join an IPv6 cluster due to preflight errors (#108769, @SataQiu) [sig/cluster-lifecycle]
- Kubeadm: fixed the bug that
kubeadm certs generate-csrcommand does not remove duplicated SANs (#107982, @SataQiu) [sig/cluster-lifecycle] - Kubelet now checks "NoExecute" taint/toleration before accepting pods, except for static pods. (#101218, @gjkim42) [sig/node]
- Metrics Server image bumped to v0.5.2 (#106492, @serathius) [sig/instrumentation,sig/cloud-provider]
- Modified command line errors (for example,
kubectl list->unknown command) that were printed as log message with escaped line breaks instead of a multi-line plain text, making the error hard to read. (#107044, @pohly) [sig/cli,sig/testing] - Modified log messages that were logged with
"v":0in JSON output although they were debug messages with a higher verbosity. (#106978, @pohly) [sig/scheduling,sig/storage,sig/node,sig/api-machinery,sig/cluster-lifecycle,sig/auth,sig/apps,sig/cli,sig/instrumentation,sig/cloud-provider] - No (#107769, @liurupeng) [SIG Cloud Provider and Windows] [sig/windows,sig/cloud-provider]
- NodeRestriction admission: nodes are now allowed to update PersistentVolumeClaim status fields
resizeStatusandallocatedResourceswhen theRecoverVolumeExpansionFailurefeature is enabled. (#107686, @gnufied) [sig/storage,sig/auth] - Only extend token lifetimes when
--service-account-extend-token-expirationis true and the requested token audiences are empty or exactly match all values for--api-audiences. (#105954, @jyotimahapatra) [sig/auth,sig/testing] - Prevent kube-scheduler from nominating a Pod that was already scheduled to a node (#109245, @alculquicondor) [sig/scheduling]
- Prevent unnecessary
EndpointsandEndpointSliceupdates caused byPod ResourceVersionchange (#108078, @tnqn) [sig/network,sig/apps] - Print
<default>as the value in case kubectl describe ingress showsdefault-backend:80when no default backend is present (#108506, @jlsong01) [sig/cli] - Publishing kube-proxy metrics for Windows kernel-mode (#106581, @knabben) [sig/network,sig/windows,sig/instrumentation]
- Re-adds response status and headers on verbose kubectl responses (#108505, @rikatz) [sig/api-machinery,sig/cli]
- Record requests rejected with 429 in the apiserver_request_total metric (#108927, @wojtek-t) [sig/api-machinery,sig/instrumentation]
- Removed validation if AppArmor profiles are loaded on the local node. This should be handled by the container runtime. (#97966, @saschagrunert) [sig/node,sig/auth,sig/security]
- Replace the url label of
rest_client_request_duration_secondsandrest_client_rate_limiter_duration_secondsmetrics with a host label to prevent cardinality explosions and keep only the useful information. This is a breaking change required for security reasons. (#106539, @dgrisonnet) [sig/instrumentation] - Restored
NumPDBViolationsinfo of nodes, whenHTTPExtender ProcessPreemption. This info will be used in subsequent filtering steps -pickOneNodeForPreemption(#105853, @caden2016) [sig/scheduling] - Reverted graceful node shutdown to match 1.21 behavior of setting pods that have not yet successfully completed to "Failed" phase if the GracefulNodeShutdown feature is enabled in kubelet. The GracefulNodeShutdown feature is beta and must be explicitly configured via kubelet config to be enabled in 1.21+. This changes 1.22 and 1.23 behavior on node shutdown to match 1.21. If you do not want pods to be marked terminated on node shutdown in 1.22 and 1.23, disable the GracefulNodeShutdown feature. (#106901, @bobbypage) [sig/node,sig/testing]
- Reverts the CRI API version surfaced by dockershim to v1alpha2 (#106803, @saschagrunert) [sig/network,sig/node]
- Services with "internalTrafficPolicy: Local" now behave more like "externalTrafficPolicy: Local". Also, "internalTrafficPolicy: Local, externalTrafficPolicy: Cluster" is now implemented correctly. (#106497, @danwinship) [sig/network]
- Sets JobTrackingWithFinalizers, a beta feature, as disabled by default, due to unresolved bug kubernetes/kubernetes#109485 (#109487, @alculquicondor) [sig/apps,sig/testing]
- Skip re-allocate logic if pod is already removed to avoid panic (#108831, @waynepeking348) [sig/node]
- The Service field
spec.internalTrafficPolicyis no longer defaulted for Services when the type isExternalName. The field is also dropped on read when the Service type isExternalName. (#104846, @andrewsykim) [sig/network,sig/apps] - The
ServerSideFieldValidationfeature has been reverted to alpha for 1.24. (#109271, @liggitt) [sig/api-machinery,sig/cli,sig/testing] - The
TopologyAwareHintsfeature gate is now enabled by default. This will allow users to opt-in to Topology Aware Hints by setting theservice.kubernetes.io/topology-aware-hintson a Service. This will not affect any Services without that annotation set. (#108747, @robscott) [sig/network] - The deprecated flag
--really-crash-for-testingwas removed. (#101719, @SergeyKanzhelev) [sig/network,sig/node,sig/api-machinery,sig/testing] - The kubelet no longer forcefully closes active connections on heartbeat failures, using the HTTP2 health check mechanism to detect broken connections. Users can force the previous behavior of the kubelet by setting the environment variable DISABLE_HTTP2. (#108107, @aojea) [sig/node,sig/api-machinery]
- This code change fixes the bug that UDP services would trigger unnecessary LoadBalancer updates. The root cause is that a field not working for non-TCP protocols is considered. ref: kubernetes-sigs/cloud-provider-azure#1090 (#107981, @lzhecheng) [sig/cloud-provider]
- Topology translation of in-tree vSphere volume to vSphere CSI. (#108611, @divyenpatel) [sig/storage]
- Updating kubelet permissions check for Windows nodes to see if process is elevated instead of checking if process owner is in Administrators group (#108146, @marosset) [sig/node,sig/windows]
apiserver, if configured to reconcile thekubernetes.defaultservice endpoints, checks if the configured Service IP range matches the apiserver public address IP family, and fails to start if not. (#106721, @aojea) [sig/api-machinery,sig/testing]kubectl versionnow fails when given extra arguments. (#107967, @jlsong01) [sig/cli]
- '
build/dependencies.yaml: remove the dependency on Docker. With the dockershim removal, core Kubernetes no longer has to track the latest validated version of Docker.' (#107607, @neolit123) [sig/node,sig/cluster-lifecycle] - API server's deprecated
--experimental-encryption-provider-configflag is now removed. Adapt your machinery to use the--encryption-provider-configflag that is available since v1.13. (#108423, @ialidzhikov) [sig/api-machinery] - API server's deprecated
--target-ram-mbflag is now removed. (#108457, @ialidzhikov) [sig/scalability,sig/api-machinery,sig/testing,sig/cloud-provider] - Added PreemptionPolicy in PriorityClass describe (#108701, @denkensk) [sig/scheduling,sig/cli]
- Added an e2e test to verify that the cluster is not vulnerable to CVE-2021-29923 when using Services with IPs with leading zeros, note that this test is a necessary but not sufficient condition, all the components in the clusters that consume IPs addresses from the APIs MUST interpret them as decimal or discard them. (#107552, @aojea) [sig/network,sig/testing]
- Added an example for the
kubectl plugin listcommand. (#106600, @bergerhoffer) [sig/cli] - Added details about preemption in the event for scheduling failed. (#107775, @denkensk) [sig/scheduling]
- Allow KUBE_TEST_REPO_LIST to be a remote url (#108429, @dims) [sig/testing,sig/cloud-provider]
- Client-go: if resetting the body fails before a retry, an error is now surfaced to the user. (#109050, @MadhavJivrajani) [sig/api-machinery]
- Deprecate apiserver_dropped_requests_total metric. The same data can be read from apiserver_request_terminations_total metric. (#109018, @wojtek-t) [sig/api-machinery,sig/instrumentation]
- Deprecated types in
k8s.io/apimachinery/util/clock. Please usek8s.io/utils/clockinstead. (#106850, @MadhavJivrajani) [sig/storage,sig/api-machinery,sig/cluster-lifecycle,sig/auth,sig/cli,sig/instrumentation,sig/cloud-provider] - E2e tests wait for
kube-root-ca.crtto be populated in namespaces for use with projected service account tokens, reducing delays starting those test pods and errors in the logs. (#107763, @smarterclayton) [sig/testing] - Endpoints and EndpointSlice controllers no longer populate resourceVersion of targetRef in Endpoints and EndpointSlices (#108450, @tnqn) [sig/network,sig/apps]
- Fixed default config flags for
NewDefaultKubectlCommand. (#107131, @jonnylangefeld) [sig/cli] - Fixed documentation typo in cloud-provider. (#106445, @majst01) [sig/cloud-provider]
- Fixed spelling of implemented in pkg/proxy/apis/config/types.go line 206 (#106453, @davidleitw) [sig/network]
- Improve error message when applying CRDs before the CRD exists in a cluster (#107363, @eddiezane) [sig/cli]
- Improved algorithm for selecting
bestnon-preferred hint in the TopologyManager (#108154, @klueska) [sig/node] - Kube-proxy doesn't set the sysctl
net.ipv4.conf.all.route_localnet=1if no IPv4 loopback address is selected by thenodePortAddressesconfiguration parameter. (#107684, @aojea) [sig/network] - Kubeadm: all warning messages are printed to stderr instead of stdout. (#107467, @SataQiu) [sig/cluster-lifecycle]
- Kubeadm: handled the removal of dockershim related flags for new kubeadm clusters. If kubelet <1.24 is on the host, kubeadm >=1.24 can continue using the built-in dockershim in the kubelet if the user passes the
{Init|Join}Configuration.nodeRegistration.criSocketvalue in the kubeadm configuration to be equal tounix:///var/run/dockershim.sockon Unix ornpipe:////./pipe/dockershimon Windows. If kubelet version >=1.24 is on the host, kubeadm >=1.24 will treat all container runtimes as "remote" using the kubelet flags--container-runtime=remote --container-runtime-endpoint=scheme://some/path. The special management for kubelet <1.24 will be removed in kubeadm 1.25. (#106973, @neolit123) [sig/cluster-lifecycle] - Kubeadm: make sure that
kubeadm init/joinalways use a URL scheme (unix:// on Linux and npipe:// on Windows) when passing a value to the--container-runtime-endpointkubelet flag. This flag's value is taken from the kubeadm configurationcriSocketfield or the--cri-socketCLI flag. Automatically add a missing URL scheme to the user configuration in memory, but warn them that they should also update their configuration on disk manually. Duringkubeadm upgrade apply/nodemutate the/var/lib/kubelet/kubeadm-flags.envfile on disk and thekubeadm.alpha.kubernetes.io/cri-socketannotation Node object if needed. These automatic actions are temporary and will be removed in a future release. In the future the kubelet may not support CRI endpoints without an URL scheme. (#107295, @neolit123) [sig/cluster-lifecycle] - Kubeadm: remove the
IPv6DualStackfeature gate. The feature has been GA and locked to enabled since 1.23. (#106648, @calvin0327) [sig/cluster-lifecycle,sig/testing] - Kubeadm: removed the deprecated
output/v1alpha1API used for machine readable output by some kubeadm commands. In 1.23 kubeadm started using the newer versionoutput/v1alpha2for the same purpose. (#107468, @neolit123) [sig/cluster-lifecycle] - Kubeadm: removed the restriction that the
ca.crtcan only contain one certificate. If there is more than one certificate in theca.crtfile, kubeadm will pick the first one by default. (#107327, @SataQiu) [sig/cluster-lifecycle] - Kubectl stack traces now only print at verbose
-v=99and not-v=6(#108053, @eddiezane) [sig/cli] - Kubectl: restored
--dry-run,--dry-run=true, and--dry-run=falsefor compatibility with pre-1.23 invocations. (#107003, @julianvmodesto) [sig/cli,sig/testing] - Kubelet config validation error messages are updated. (#105360, @shuheiktgw) [sig/node]
- Kubernetes e2e framework will use the url
invalid.registry.k8s.io/invalidinsteadinvalid.com/invalidfor test that use an invalid registry. (#107455, @aojea) [sig/testing] - Marked kubelet
--container-runtime-endpointand--image-service-endpointCLI flags as stable. (#106954, @saschagrunert) [sig/node] - Migrate
volume/csi/csi-client.gologs to structured logging. (#99441, @CKchen0726) [sig/storage] - Migrate statefulset files to structured logging (#106109, @h4ghhh) [sig/apps,sig/instrumentation]
- Refactor kubelet command line for enabling features and "drop
RuntimeClassfeature gate" if present. Note that this feature has been on by default since 1.14 and was GA'ed in 1.20. (#106882, @cyclinder) [sig/node] - Remove deprecated
--serviceaccount,--hostport,--requestsand--limitsfrom kubectl run. (#108820, @mozillazg) [sig/cli] - Remove support for
node-expansionbetweennode-stageandnode-publish(#108614, @gnufied) [sig/storage] - Removed deprecated
generatorandcontainer-portflags (#106824, @lauchokyip) [sig/cli] - Removed kubelet
--non-masquerade-cidrdeprecated CLI flag (#107096, @hakman) [sig/node,sig/cloud-provider] - Rename unschedulableQ to unschedulablePods (#108919, @denkensk) [sig/scheduling,sig/instrumentation,sig/testing]
- SPDY transport in client-go will no longer follow redirects. (#108531, @tallclair) [sig/node,sig/api-machinery]
- ServerResources was deprecated in February 2019 (https://github.com/kubernetes/kubernetes/commit/618050e) and now it's being removed and ServerGroupsAndResources is suggested to be used instead (#107180, @ardaguclu) [sig/api-machinery,sig/apps,sig/cli]
- The API server's deprecated
--deserialization-cache-sizeflag is now removed. (#108448, @ialidzhikov) [sig/api-machinery] - The
--container-runtimekubelet flag is deprecated and will be removed in future releases. (#107094, @adisky) [sig/node] - The
WarningHeadersfeature gate that is GA since v1.22 is unconditionally enabled, and can no longer be specified via the--feature-gatesargument. (#108394, @ialidzhikov) [sig/api-machinery] - The
e2e.testbinary supports a new--kubelet-rootparameter to override the default/var/lib/kubeletpath. CSI storage tests use this. (#108253, @pohly) [sig/storage,sig/node,sig/testing] - The fluentd-elasticsearch addon is no longer included in the cluster directory. It is available from https://github.com/kubernetes-sigs/instrumentation-addons/tree/master/fluentd-elasticsearch. (#107553, @liggitt) [sig/instrumentation,sig/cloud-provider]
- The scheduler framework option
runAllFiltersis removed. (#108829, @kerthcet) [sig/scheduling] - Updated cri-tools to v1.23.0. (#107604, @saschagrunert) [sig/release,sig/cloud-provider]
- Updated runc to 1.1.0 and updated cadvisor to 0.44.0 (#109029, @ehashman) [sig/node,sig/cli,sig/testing]
- Updated runc to 1.1.1 (#109104, @kolyshkin) [sig/node]
- Updated the error message to not use the
--max-resource-write-bytes&--json-patch-max-copy-bytesstring. (#106875, @warmchang) [sig/api-machinery] - Users who look at iptables dumps will see some changes in the naming and structure of rules. (#109060, @thockin) [sig/network,sig/testing]
- Windows Pause no longer has support for SAC releases 1903, 1909, 2004. Windows image support is now Ltcs 2019 (1809), 20H2, LTSC 2022 (#107056, @jsturtevant) [sig/windows]
- [k8s.io/utils/clock]: IntervalClock is now deprecated in favour of SimpleIntervalClock (#108059, @RaghavRoy145) [sig/storage,sig/api-machinery,sig/cluster-lifecycle,sig/auth,sig/cli,sig/instrumentation,sig/architecture,sig/cloud-provider]
kube-addon-managerimage version is bumped to 9.1.6 (#108341, @zshihang) [sig/scalability,sig/testing,sig/cloud-provider]- Add SourceVolumeMode field to VolumeSnapshotContents. Documentation for this alpha feature is pending. (#665, @RaunakShah)
- Update snapshotter module to v6 and client module to v5. Documentation for this alpha feature is pending. ([#670],(kubernetes-csi/external-snapshotter#670), @RaunakShah)
- Deprecate kubectl version long output, will be replaced with kubectl version
--short. Users requiring full output should use--output=yaml|jsoninstead. (#108987, @soltysh) [sig/cli]
- github.com/armon/go-socks5: e753329
- github.com/blang/semver/v4: v4.0.0
- github.com/google/gnostic: v0.5.7-v3refs
- github.com/cespare/xxhash/v2: v2.1.1 → v2.1.2
- github.com/checkpoint-restore/go-criu/v5: v5.0.0 → v5.3.0
- github.com/cilium/ebpf: v0.6.2 → v0.7.0
- github.com/containerd/console: v1.0.2 → v1.0.3
- github.com/containerd/containerd: v1.4.11 → v1.4.12
- github.com/cpuguy83/go-md2man/v2: v2.0.0 → v2.0.1
- github.com/cyphar/filepath-securejoin: v0.2.2 → v0.2.3
- github.com/docker/distribution: v2.7.1+incompatible → v2.8.1+incompatible
- github.com/docker/docker: v20.10.7+incompatible → v20.10.12+incompatible
- github.com/godbus/dbus/v5: v5.0.4 → v5.0.6
- github.com/golang/mock: v1.5.0 → v1.6.0
- github.com/google/cadvisor: v0.43.0 → v0.44.1
- github.com/google/cel-go: v0.9.0 → v0.10.1
- github.com/moby/sys/mountinfo: v0.4.1 → v0.6.0
- github.com/moby/term: 9d4ed18 → 3f7ff69
- github.com/opencontainers/image-spec: v1.0.1 → v1.0.2
- github.com/opencontainers/runc: v1.0.2 → v1.1.1
- github.com/opencontainers/selinux: v1.8.2 → v1.10.0
- github.com/prometheus/client_golang: v1.11.0 → v1.12.1
- github.com/prometheus/common: v0.28.0 → v0.32.1
- github.com/prometheus/procfs: v0.6.0 → v0.7.3
- github.com/russross/blackfriday/v2: v2.0.1 → v2.1.0
- github.com/seccomp/libseccomp-golang: v0.9.1 → 3879420
- github.com/spf13/cobra: v1.2.1 → v1.4.0
- github.com/yuin/goldmark: v1.4.0 → v1.4.1
- go.etcd.io/etcd/api/v3: v3.5.0 → v3.5.1
- go.etcd.io/etcd/client/pkg/v3: v3.5.0 → v3.5.1
- go.etcd.io/etcd/client/v3: v3.5.0 → v3.5.1
- golang.org/x/crypto: 32db794 → 8634188
- golang.org/x/mod: v0.4.2 → 9b9b3d8
- golang.org/x/net: e898025 → cd36cc0
- golang.org/x/oauth2: 2bc19b1 → d3ed0bb
- golang.org/x/sys: f4d4317 → 3681064
- golang.org/x/term: 6886f2d → 03fcf44
- golang.org/x/time: 1f47c86 → 90d013b
- golang.org/x/tools: d4cc65f → 897bd77
- google.golang.org/genproto: fe13028 → 42d7afd
- k8s.io/gengo: 485abfe → c02415c
- k8s.io/klog/v2: v2.30.0 → v2.60.1
- k8s.io/kube-openapi: e816edb → 3ee0da9
- k8s.io/system-validators: v1.6.0 → v1.7.0
- k8s.io/utils: cb0fa31 → 3a6ce19
- sigs.k8s.io/apiserver-network-proxy/konnectivity-client: v0.0.25 → v0.0.30
- sigs.k8s.io/json: c049b76 → 9f7c6b3
- sigs.k8s.io/kustomize/api: v0.10.1 → v0.11.4
- sigs.k8s.io/kustomize/cmd/config: v0.10.2 → v0.10.6
- sigs.k8s.io/kustomize/kustomize/v4: v4.4.1 → v4.5.4
- sigs.k8s.io/kustomize/kyaml: v0.13.0 → v0.13.6
- sigs.k8s.io/structured-merge-diff/v4: v4.1.2 → v4.2.1
- cloud.google.com/go/firestore: v1.1.0
- github.com/armon/go-metrics: f0300d1
- github.com/armon/go-radix: 7fddfc3
- github.com/bgentry/speakeasy: v0.1.0
- github.com/bits-and-blooms/bitset: v1.2.0
- github.com/bketelsen/crypt: v0.0.4
- github.com/containernetworking/cni: v0.8.1
- github.com/fatih/color: v1.7.0
- github.com/googleapis/gnostic: v0.5.5
- github.com/hashicorp/consul/api: v1.1.0
- github.com/hashicorp/consul/sdk: v0.1.1
- github.com/hashicorp/errwrap: v1.0.0
- github.com/hashicorp/go-cleanhttp: v0.5.1
- github.com/hashicorp/go-immutable-radix: v1.0.0
- github.com/hashicorp/go-msgpack: v0.5.3
- github.com/hashicorp/go-multierror: v1.0.0
- github.com/hashicorp/go-rootcerts: v1.0.0
- github.com/hashicorp/go-sockaddr: v1.0.0
- github.com/hashicorp/go-syslog: v1.0.0
- github.com/hashicorp/go-uuid: v1.0.1
- github.com/hashicorp/go.net: v0.0.1
- github.com/hashicorp/golang-lru: v0.5.0
- github.com/hashicorp/hcl: v1.0.0
- github.com/hashicorp/logutils: v1.0.0
- github.com/hashicorp/mdns: v1.0.0
- github.com/hashicorp/memberlist: v0.1.3
- github.com/hashicorp/serf: v0.8.2
- github.com/magiconair/properties: v1.8.5
- github.com/mattn/go-colorable: v0.0.9
- github.com/mattn/go-isatty: v0.0.3
- github.com/miekg/dns: v1.0.14
- github.com/mitchellh/cli: v1.0.0
- github.com/mitchellh/go-homedir: v1.0.0
- github.com/mitchellh/go-testing-interface: v1.0.0
- github.com/mitchellh/gox: v0.4.0
- github.com/mitchellh/iochan: v1.0.0
- github.com/pascaldekloe/goe: 57f6aae
- github.com/pelletier/go-toml: v1.9.3
- github.com/posener/complete: v1.1.1
- github.com/ryanuber/columnize: 9b3edd6
- github.com/sean-/seed: e2103e2
- github.com/shurcooL/sanitized_anchor_name: v1.0.0
- github.com/spf13/cast: v1.3.1
- github.com/spf13/jwalterweatherman: v1.1.0
- github.com/spf13/viper: v1.8.1
- github.com/subosito/gotenv: v1.2.0
- gopkg.in/ini.v1: v1.62.0
| filename | sha512 hash |
|---|---|
| kubernetes.tar.gz | 7915e218b651f9fd7cfa7ab2125e2e72eb92844dc2ab2c1a6c3068dd0db298eea8c7c209a9c97a4b8c55bc34f7365032db2f67bfd873e298afec51083572e39d |
| kubernetes-src.tar.gz | 14497e555b3366560d179fc09c5b8ff57b04573902bb0e1e760e6cf280aab82d6f4b04fcb5c0d400b7425646077d40a7654faff21b44c48c98ceab08d0e7afe0 |
| filename | sha512 hash |
|---|---|
| kubernetes-client-darwin-amd64.tar.gz | 52fba6e9b2ff27b673485661e0c93d163b3317dc034990fc7460cd301ceb28a453616fc5ce8bba6dc9f8031d4f0966976bebaedf96243bcafa5db0d8ba4f8e70 |
| kubernetes-client-darwin-arm64.tar.gz | 4fc2807ada2aa2987f6b84520ca5febbf78d65bea6b58851fdddbf417a59539a0276bcea157e1ae81be0fb87832fea8dbc78b6fdb07fda71920aacddb3705e67 |
| kubernetes-client-linux-386.tar.gz | 347f98f20c5a835aa32cc47960b217ad9b7e4b4254d2479769ae22dc2491b030bc8c1ec406ab502311e978fcd6bb5f53edc1ff8b41b6e0faab9b7cb435d49ece |
| kubernetes-client-linux-amd64.tar.gz | f860dfc209864639791f2133752209ca08f4f7c7d8f65c031c5668160cedfc32a0729e105bf85462dcd8e809c637ce250f433abc3159effcd89e2e20252c1a97 |
| kubernetes-client-linux-arm.tar.gz | f2a819b9e4e35a8741977c41488f8ea75e135d6ea664325259c0e01766c8f2c147682f20f2ba5462de89d3162120babe9c7d2c10e14b0d1fc1e63ad58f784a6d |
| kubernetes-client-linux-arm64.tar.gz | bf28d10570c1cdc7d7901c0a9d5df7258711df39771e1bd2a267ef4dfe54fe9310746492ce49652a9bed92831c99532edf08784316cbdf76c17f2c6a0851c780 |
| kubernetes-client-linux-ppc64le.tar.gz | 3fb29a2a4e0deb5c2e8660ea1f0097e5fc89f283be1f7159b4de80fabc3d76a458add2b50d76e5c432318e44b83f3d7b8fa2527c4f74595bc30031ad6deba431 |
| kubernetes-client-linux-s390x.tar.gz | 157f07f9e410cd2f996ede0b2ce4357b6a55e11f2307401618a855f318bab3d805c6af40d35367dc6b458611debcf011aba883f19dd6fcbff0f46d5e7d8a038b |
| kubernetes-client-windows-386.tar.gz | 9199f7ec5780b6110d0f6209f676c18ab1b38d0bfb8e39e93262b5bbb7e72f6fa4235d55a19e455fdf625dbe3c5687004d002969d1981f209d433d0ba41fda21 |
| kubernetes-client-windows-amd64.tar.gz | 3bc4af50477bebb7d58a82bf1181ad3b5551acae46f5300c7c4c2c434f9a6118d41c346bbe1fd17dc9cdf47a9a042e33f7fab4721c94e95fea847f814988b575 |
| kubernetes-client-windows-arm64.tar.gz | de4af15c041f6b4e3f9841e8a95fd0497ae1e8717fcea26f6015fd7881fabfc4437941713d3c68cfc55d9bd88d6f98cb7e29037fab864d8effe9f3123e12a6d3 |
| filename | sha512 hash |
|---|---|
| kubernetes-server-linux-amd64.tar.gz | 9e3bd58bab7202e54dfeadfd7c8289cf5aef82dcb4e045db4a0a5dce77f47a9362170cf92372c938ba60b51256c33cb409a44ede25b61f076939e1a29738f859 |
| kubernetes-server-linux-arm.tar.gz | 4ab694514d281baf47a61ca76ab08aa8f840d521f6e8d54a842c6692bab7e83e898487bd5cf6bf4aef1589cbd4ad9bf37117d32cdffa5a83a5463b4b3f4d82d6 |
| kubernetes-server-linux-arm64.tar.gz | a20f0950ef6e61d5ca93e0c2c12c09c474de6160be7655f0739e28338872c22814543e6d8f9406e9b3494afcc085273a66d624e9526352895d59d50995e56d21 |
| kubernetes-server-linux-ppc64le.tar.gz | 212916a0ae56b4f9c48b57d2deeaf4582391cef468961f552296261680098779d7cebf9aaf25bfa68a75f97aee45a1d46cb820f300982cbf9ac0d5aff11ad156 |
| kubernetes-server-linux-s390x.tar.gz | 046639871d5a720fdf03365b9da9af934e0b18ca45afe092887d5d84a5bf925850baeafcf437537ab6ac66bdc1a87bb7fd9f82b7649e664c6f6bd9c38114a552 |
| filename | sha512 hash |
|---|---|
| kubernetes-node-linux-amd64.tar.gz | e1460cb62d5794b8e736de0c30ef86b7b0aa3c544d2603f3395f8eaffc7718c4c47881c217a515b218ae69a8af52fbfa1699b233634309f96f7f997e35b43244 |
| kubernetes-node-linux-arm.tar.gz | b662a8be7e9c7545cba7e7cfa689474b544382f8df86a10929234c86d32be9ca843eb01dd35faec367172afb828dc6ac3044483c5852c84ffd5281d86e7fc11f |
| kubernetes-node-linux-arm64.tar.gz | 5e890f3ffddc473f8f20afe9fa8747ef091a60bf4ccddd4d87f94e99c51374bffaf976cab2bc71deb6d8142b967d1cfef50fe96c100d2b4aaecb86d903189311 |
| kubernetes-node-linux-ppc64le.tar.gz | 12f2f16b57abfdaea2c35652c68d60833150a835f11d50a787898d7f178b1bf258c26f14414bbb165e3782e30687e0f373ae82d85e888c701a53d66916a6d432 |
| kubernetes-node-linux-s390x.tar.gz | 5d15a3227aed35d3aa5c7292b44e482ea9c66311d2fa9473c618a64a7c4ebac3ef285b85f2db57e0d1575152dd310efac28b895c7f24191ee297c8cba98c9e65 |
| kubernetes-node-windows-amd64.tar.gz | c09d31a38358fc6e74f6ee77d31e91ebb0f7ec2f8251e4a4c805a7312561d52c30edc68344ac618b73fb3e0326886b639200d52dfd94b4459d8ff9560b9c8a29 |
All container images are available as manifest lists and support the described architectures. It is also possible to pull a specific architecture directly by adding the "-$ARCH" suffix to the container image name.
Nothing has changed.
Nothing has changed.
Nothing has changed.