👋 Welcome
This week brought significant advancements in Kubernetes, with several features graduating or entering alpha in v1.37, focusing on scheduling, monitoring, and node management. The Cloud Native Computing Foundation also announced the graduation of Karmada, highlighting its role in multi-cluster Kubernetes orchestration. Additionally, the intersection of AI and cloud native continued to be a major theme, with discussions around optimizing AI workloads and managing GPU resources.
🚀 Notable Releases
CI/CD
- Argo CD v3.5.3 - Provides updated installation manifests for non-HA and HA setups, with container images signed by cosign.
- Argo CD v3.4.9 - Offers updated installation manifests for non-HA and HA configurations, with container images signed by cosign.
- OpenCost v1.121.2 - Fixes pricing action and debug 403 errors, and includes updates to the public pricing module.
Security
- cert-manager v1.21.2 - Addresses controller and webhook panics, data races, ACME renewal and HTTP-01 solver bugs, and a Gateway API dnsNames bug. Updates Go and dependencies to fix reported security vulnerabilities, and tightens ambient AWS credential use for namespaced Vault Issuers.
- Kyverno v1.19.1 - Bumps Go to 1.26.6 and
x/netto resolve CVE-2026-39821, updates Go to address CVE-2026-56853, fixes missing autogen webhook expansion for NamespacedValidatingPolicy, and applies HTTP blocklist to theapiCall.serviceexecutor. - Kubescape v4.0.14 - Bumps
github.com/mark3labs/mcp-gofrom 0.58.0 to 1.0.0,golang.org/x/cryptofrom 0.55.0 to 0.56.0, andhelm.sh/helm/v3from 3.20.2 to 3.21.4. - OpenFGA v1.20.0 - Adds a
WithServiceNameserver option, allowing embedders to override theserviceNamefield for Prometheus metrics andtelemetry.RPCInfo.Service. - KubeArmor v1.7.5 - Fixes a missing
vmlinux.hin CI. - Kubernetes Secrets Store CSI Driver v1.6.1 - Updates vulnerable image dependencies, prevents secret update hotloops, corrects log format for missing targetpath modification time, bumps Go to 1.26, and upgrades dependencies.
Build Tools
- Dapr Runtime v1.17.14 - Fixes an issue where pluggable pub/sub components delivered messages to the application one at a time, blocking the receive loop.
- Dapr Runtime v1.16.20 - Fixes
daprdnever reconnecting to Placement after failed actor deactivation, actor calls hanging after slow Placement dissemination, and serial message delivery from pluggable pub/sub components. - Dapr Runtime v1.18.4 - Fixes workflows being left permanently PENDING when their start reminder fails during a scheduler restart or fires before creation commit, and when a placement occurs.
- Helm v4.3.0 - A feature release.
- Helm v3.22.0 - A feature release.
- Backstage v1.54.7 - Improves OAuth profile normalization when processing email verification information.
- Backstage v1.49.7 - Improves OAuth profile normalization when processing email verification information.
Registry
- Dragonfly v2.5.2 - Updates password hashing to use
bcrypt.DefaultCost.
Observability
- Prometheus v3.13.3 - Bumps
github.com/klauspost/compressto v1.18.7 andgolang.org/x/cryptoto v0.55.0 for security fixes. Addresses a panic in Docker Swarm service discovery, fixes case-insensitive regex label matchers silently dropping values, and resolves 100% CPU usage on shutdown for scrape manager and alerting. - Inspektor Gadget v0.56.0 - Introduces an experimental Kubernetes multi-tenancy mode that authenticates
kubectl-gadgetrequests via KubernetesTokenReviewand restricts gadget access to RBAC-authorized namespaces.
Configuration
- Baremetal Operator v0.14.0 - Deprecates the BMH Taints field and removes the separate
TryInitcall from the provisioner. New features include a fast Redfish-based inspection mode, a provisioning retry limit, webhooks to validate URLs, and the implementation of the HostClaim controller.
Orchestration
- Capsule v0.14.5 - Fixes an issue to deny empty metadata.
Networking
- Kube-OVN v1.16.4 - Includes dependency and security updates, fixes for dual-stack EIP/SNAT policies, improvements to FRR BGP test reliability, DHCP option parsing fixes, ACL sampling support, and KubeVirt E2E installation updates.
- Kube-OVN v1.15.25 - Includes dependency and security updates, fixes for dual-stack EIP/SNAT policies, improvements to FRR BGP test reliability, DHCP option parsing fixes, and KubeVirt E2E installation updates.
- Kube-OVN v1.14.42 - Includes refreshed image dependencies, DHCP option parsing fixes, and KubeVirt E2E installation updates.
- Kube-OVN kube-ovn-v2-v1.14.42 - Helm chart for Kube-OVN.
- Kube-OVN kube-ovn-v1.14.42 - Helm chart for Kube-OVN.
- Submariner v0.23.2 - No specific changes are detailed in the release notes beyond the version tag.
Service Mesh
- Kuma v2.13.11 - Bumps CoreDNS to v1.14.7, distroless base images, Envoy from 1.36.9 to 1.36.10, and
github.com/cilium/ebpffrom 0.20.0 to 0.22.0. - Kuma v2.12.15 - Bumps CoreDNS to v1.14.7, distroless base images, Envoy from 1.35.13 to 1.36.10,
github.com/cilium/ebpffrom 0.19.0 to 0.22.0, andgithub.com/moby. - Kuma v2.11.19 - Bumps CoreDNS to v1.14.7, distroless base images, Envoy from 1.35.13 to 1.36.10,
github.com/cilium/ebpffrom 0.18.0 to 0.22.0, andgolang.org/x/cr. - Kuma 2.9.20 - Bumps CoreDNS to v1.14.7, Envoy from 1.35.13 to 1.36.10,
github.com/cilium/ebpffrom 0.16.0 to 0.22.0, andgolang.org/x/cryptofrom 0.55.0 to 0.56.0. - Kuma v2.7.30 - Bumps CoreDNS to v1.14.7, Envoy from 1.35.13 to 1.36.10,
github.com/cilium/ebpffrom 0.14.0 to 0.22.0, andgolang.org/x/cryptofrom 0.55.0 to 0.56.0.
Storage
- OpenEBS v4.6.1 - A patch release providing targeted fixes and minor enhancements across its storage engines, including new patch releases for Replicated PV Mayastor (v2.12.1), Local PV LVM (v1.10.1), Local PV ZFS (v2.11.1), and Local PV Rawfile (v0.15.1).
Cluster Management
- Kubernetes Cluster API v1.14.2 - Adds the
--tls-curve-preferencesflag to manager options and includes 4 bug fixes. It supports management clusters from v1.33.x to v1.37.x and workload clusters from v1.31.x to v1.37.x. - Kubernetes Cluster API v1.13.6 - Fixes 5 bugs, including issues with the CRD migrator not using cache and
Options.ClusterFilternot being applied inSetupWithManager. It supports management clusters from v1.32.x to v1.37.x and workload clusters from v1.30.x to v1.37.x.
📰 This Week in Cloud Native
This week, the Cloud Native landscape saw significant updates in Kubernetes core functionality and continued integration with Artificial Intelligence workloads. Kubernetes v1.37 introduced several enhancements, including Native Histograms graduating to Beta, Scheduler Preemption for In-Place Pod Resize entering Alpha, and the introduction of Node Lifecycle Conditions. These updates aim to improve observability, resource management, and overall cluster scheduling capabilities, particularly for dynamic and resource-intensive workloads. Further advancements in workload-aware scheduling were also announced to support complex batch and AI/ML tasks.
The Cloud Native Computing Foundation (CNCF) announced the graduation of Karmada, a multi-cluster, multi-cloud Kubernetes orchestration project, indicating its production maturity. This development is noted as supporting global enterprises scaling AI training and inference across hybrid infrastructure. Relatedly, the CNCF highlighted the increasing cloud native momentum in China, with a report indicating higher cloud native adoption among IIoT developers in the region. Several new Silver members joined the CNCF, with a focus on building cost-efficient infrastructure for scaling AI.
Discussions around AI and cloud native infrastructure continued, with a focus on building reliable foundations for distributed AI training and managing GPU resources in multi-tenant Kubernetes environments. Articles explored strategies for reducing AI inference costs without requiring new hardware and the implications of AI agents on software development lifecycles, including challenges with code sprawl and debugging. AWS announced new capabilities for AI agents, including an open-source inbox for background agents and AI-powered scaffolding for full-stack application development. Netflix is moving towards the open-source Apache Flink Autoscaler for its large-scale streaming jobs, indicating a trend in adopting open-source solutions for managing data processing at scale.
Security and observability topics were also prominent. Guidance was published on Kubernetes disaster recovery based on reproducible failure scenarios, emphasizing the distinction between having backups and achieving successful recovery. The importance of secure, self-service metrics for multi-tenant GPU usage was highlighted, alongside discussions on Kubernetes access via identity providers. Distributed tracing for CI pipelines was presented as a method to gain visibility into workflow performance without modifying workflow files. AWS Lambda introduced a 90-minute function timeout for managed instances, expanding the duration for asynchronous and event source mapping invocations.
💬 Community Buzz
Discussions on Hacker News this week centered on the practical aspects and challenges of AI agents in software development, including their limitations with human syntax, the problem of AI code sprawl, and tools for debugging and testing agent-generated code. The community also discussed the status of various cloud native tools, noting Vagrant’s approach to EOL and the removal of MinIO Docker images. Other topics included new tools for Docker and Kubernetes monitoring, security in multi-cloud environments, and alternative database solutions like EterDB, a PostgreSQL fork designed for incident recovery.
📊 Numbers of the Week
- Total stable releases: 37 across 21 projects
- Top 3 projects by commits this week:
- kubernetes/kubernetes — 202 commits
- envoyproxy/envoy — 141 commits
- cilium/cilium — 141 commits
- Top 3 projects by merged pull requests this week:
- kumahq/kuma — 202 merged PRs
- envoyproxy/envoy — 145 merged PRs
- cilium/cilium — 133 merged PRs