What kubernetes/kubernetes shipped
Written by FoxPlug from public releases; not affiliated with Kubernetes. An automatic summary of the public release, pull request and commit data of github.com/kubernetes/kubernetes. Kubernetes did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- kubeadm now supports ML-DSA-44, ML-DSA-65, and ML-DSA-87 encryption algorithms for new clusters using ClusterConfiguration. Pull request #142037
- konnectivity network proxy updated to v0.37.0 with CVE fixes and improvements to connection handling and agent data-plane communication. Pull request #142400
- CertificateSigningRequests now support ML-DSA with updates to cluster-signing flags and a new CertificateSigningRequestMLDSA feature gate. Pull request #142196
- Clients can now omit metadata.managedFields from API responses by adding drop=metadata.managedFields to the Accept header behind the ManagedFieldsAlpha feature gate. Pull request #139561
- CompositePodGroup.Spec.SchedulingPolicy.Gang.MinGroupCount is now mutable across v1alpha3 and v1beta1 versions for dynamic workload resizing. Pull request #141023
- Watch validation added using minimal and maximal revision tracking to ensure watches return consistent event tuples. Pull request #142381
- validation-gen now supports time.Duration bounds in +k8s:minimum and +k8s:maximum annotations with quoted Go duration strings. Pull request #142368
- Callers can now choose the self-signed key algorithm in client-go/util/cert.GenerateSelfSignedCertKeyWithOptions. Pull request #142350
- DRA ResourceSlice controller can now optionally refuse to publish capacities and attributes with driver domain to prevent conflicts. Pull request #142218
- Kubernetes v1.34.12 released. Release
Why it matters
This week brings support for post-quantum cryptography through ML-DSA integration across kubeadm and certificate signing, improving security for future threats. The addition of server-side opt-out for managedFields and mutable workload scheduling parameters addresses operational needs for API efficiency and dynamic resource management. Multiple performance and correctness improvements across watch validation, caching, and device management strengthen the core platform.
Changelog entry
- kubeadm: add ML-DSA-44, ML-DSA-65, and ML-DSA-87 support to ClusterConfiguration.EncryptionAlgorithm Pull request #142037
- kube-apiserver: update konnectivity network proxy to v0.37.0 with CVE fixes and performance improvements Pull request #142400
- certificates: add ML-DSA support to CertificateSigningRequests with CertificateSigningRequestMLDSA feature gate Pull request #142196
- api: support drop=metadata.managedFields in Accept header to omit managedFields from responses Pull request #139561
- scheduling: make CompositePodGroup.Spec.SchedulingPolicy.Gang.MinGroupCount mutable Pull request #141023
- apiserver: add watch validation using revision tracking Pull request #142381
- validation-gen: support time.Duration in +k8s:minimum/maximum annotations Pull request #142368
- DRA: include extended resource claims in pod claim iteration and taint eviction Pull request #142289
- kubelet/devicemanager: preserve in-flight device reservations across rebuilds Pull request #137534
- api: document platform-specific semantics of Node.status.volumesAttached[].devicePath Pull request #141861
This week: ML-DSA post-quantum cryptography support in kubeadm and certificates, managedFields opt-out for API responses, mutable workload scheduling, watch validation improvements, and four patch releases.
Kubernetes shipped significant updates this week: post-quantum cryptography support via ML-DSA for kubeadm and certificate signing; server-side control over metadata.managedFields in API responses; mutable workload group sizing for dynamic scheduling; improved watch validation; and refinements to device management and performance. Four patch releases (v1.34.12, v1.35.9, v1.36.5, v1.37.1) are available.
Week of September 14, 2026
What shipped
- IP/CIDR Validation feature graduates to GA, removing the feature gate requirement. Pull request #141979
- PodCertificateRequest and pod certificate projections now support ML-DSA algorithms for signing PKCS#10 CSRs. Pull request #142108
- kubectl explain command gains shell autocompletion support. Pull request #140058
- HPA now correctly excludes pod overhead from pod-level resource request calculations. Pull request #142154
- ResourceQuota validation no longer incorrectly rejects updates that preserve previously stored values. Pull request #142163
- StatefulSet restore from ControllerRevision now preserves only the .spec field to prevent unintended modifications. Pull request #142159
- Pod sorting by creation time now uses UID as a tie-breaker to ensure deterministic ordering. Pull request #141211
- Kubelet no longer incorrectly inherits probe state from replaced containers after restart. Pull request #141487
- LimitRanger no longer applies min/max checks to unchanged PersistentVolumeClaim requests on update. Pull request #142170
- Pod resize end-to-end tests now properly wait for resize actuation before continuing. Pull request #142106
Why it matters
Multiple bug fixes address correctness issues in resource management, scheduling, and validation that could affect production workloads. New features like kubectl autocompletion and ML-DSA support expand functionality for operators and security use cases.
Changelog entry
- IP/CIDR Validation feature gate removed as feature graduates to GA Pull request #141979
- Added ML-DSA algorithm support to PodCertificateRequest and pod certificate projections Pull request #142108
- kubectl explain command now supports shell autocompletion Pull request #140058
- Fixed HPA pod-level resource request calculations to exclude pod overhead Pull request #142154
- Fixed ResourceQuota validation to accept stored values during updates Pull request #142163
- StatefulSet now restores only .spec from ControllerRevision to prevent unintended field modifications Pull request #142159
- Added UID tie-breaker to PodsByCreationTime sort for deterministic ordering Pull request #141211
- Kubelet no longer inherits probe state from replaced containers after restart Pull request #141487
- LimitRanger skips min/max checks on unchanged PersistentVolumeClaim requests during updates Pull request #142170
- Fixed container memory resize validation error message reporting wrong variable Pull request #141100
This week: IP/CIDR Validation reaches GA, pod overhead handling fixed in HPA, kubectl explain gains autocompletion, plus fixes for resource validation and StatefulSet restoration.
Notable updates to Kubernetes this week include IP/CIDR Validation graduating to GA, improvements to pod resource calculations in HPA that now properly exclude overhead, shell autocompletion for kubectl explain, and critical bug fixes for ResourceQuota validation and StatefulSet restoration from ControllerRevision.