Week 41, Oct 5-11, 2026

This week: 64 releases, 162 news items.

👋 Welcome

This week in Cloud Native saw a range of project updates, with numerous patch releases across container runtimes, networking, and security tools. Major news focused on the expanding role of AI agents in development, security, and operations, alongside preparations for upcoming KubeCon and ArgoCon events.

🚀 Notable Releases

Application Frameworks

CI/CD

  • Flux 2 v2.9.6 - Stops helm-controller from reapplying chart CRDs when server-side apply is enabled and recovers HelmReleases with drifted Ready=Unknown conditions. source-controller normalizes Azure Blob listing ETags to prevent re-downloads of unchanged containers and evicts stale Helm repository index entries from the cache.

Configuration

  • Cloud Custodian 0.9.53.0 - Adds AWS updates including excluding AWS-managed KMS and Route53 resources from actions, a deployments filter for Bedrock custom models, and a route resource for API Gateway v2 authorization type filtering.
  • Kustomize kyaml/v0.21.2 - Marks ValidatingAdmissionPolicy resources as cluster-scoped and updates Go version to 1.25.7, along with other dependency bumps.
  • Kustomize kustomize/v5.8.2 - Adds kustomize edit add configuration and kustomize edit remove component commands. The built-in OpenAPI schema is now loaded from a pre-compiled bundle embedded in the binary.
  • Kustomize cmd/config/v0.21.2 - Updates Go version to 1.25.7 and bumps various dependencies including go-git, x/crypt, otel lib, kube-openapi, and go.yaml.in/yaml/v2.
  • Kustomize api/v0.21.2 - Adds labels to volumeClaimTemplates in StatefulSets when includeVolumeClaimTemplates is true, accounts for delimiters in structured data replacements, marks ValidatingAdmissionPolicy resources as cluster-scoped, and rejects ambiguous resource paths with inner “..” to prevent misresolution.

Container Runtime

  • CRI-O v1.37.2 - This is a patch release.
  • CRI-O v1.36.7 - This is a patch release.
  • CRI-O v1.35.10 - This is a patch release.
  • CRI-O v1.34.15 - This is a patch release.
  • Lima v2.2.1 - Contains bug fixes and dependency updates, including improvements to rsync option parsing, guest error string quoting in time sync logs, and handling of PID files.
  • Podman v6.1.3 - Addresses CVE-2026-94603, which could disable sandboxing when running checkpoint images. Support for checkpoint images in podman run has been removed due to security concerns.
  • Podman v5.8.8 - Addresses CVE-2026-94603, which could disable sandboxing when running checkpoint images. Support for checkpoint images in podman run has been removed due to security concerns.

Database

  • Vitess v24.0.4 - The lz4 compression engine now uses the pierrec/lz4/v4 library, fixing broken block decoding on amd64. Backups remain restorable across versions, and the --compression-level interpretation has changed.
  • Vitess v23.0.7 - The lz4 compression engine now uses the pierrec/lz4/v4 library, fixing broken block decoding on amd64. Backups remain restorable across versions, and the --compression-level interpretation has changed.

Edge

  • K3s v1.37.1+k3s1 - Updates Kubernetes to v1.37.1 and includes backports for 2026-09, fixing etcd snapshot restoration, enabling seccomp in riscv64 builds, and updating ginkgo usage.
  • K3s v1.36.5+k3s1 - Updates Kubernetes to v1.36.5 and bumps image versions for coredns, gateway-api, and traefik.
  • K3s v1.35.9+k3s1 - Updates Kubernetes to v1.35.9 and warns of a breaking change in the Traefik chart upgrade to v40.x, where the provider name changes from kubernetesIngressNginx to kubernetesIngressNGINX.
  • K3s v1.34.12+k3s1 - Updates Kubernetes to v1.34.12 and warns of a breaking change in the Traefik chart upgrade to v40.x, where the provider name changes from kubernetesIngressNginx to kubernetesIngressNGINX.

Networking

  • Envoy v1.39.2 - Fixes CVE-2026-35189 in BoringSSL, addressing excessive memory allocation when parsing certificates. Debian bullseye (11) packaging has been removed.
  • Envoy v1.38.5 - Fixes CVE-2026-35189 in BoringSSL, addressing excessive memory allocation when parsing certificates. Debian bullseye (11) packaging has been removed. The BoringSSL FIPS build does not receive this patch.
  • Envoy v1.37.7 - Fixes CVE-2026-35189 in BoringSSL, addressing excessive memory allocation when parsing certificates. Debian bullseye (11) packaging has been removed. The BoringSSL FIPS build does not receive this patch.
  • Envoy v1.36.11 - Fixes CVE-2026-35189 in BoringSSL, addressing excessive memory allocation when parsing certificates. Debian bullseye (11) packaging has been removed. The FIPS build is not patched.
  • Kube-OVN v1.16.10 - Fixes per-port DHCP option preservation during subnet reconciliation, prevents duplicate logical switch/router creation, addresses security-group preservation issues, suppresses ARP/ND floods, resolves stale load balancer mappings, and improves VPC Egress Gateway validation.
  • Kube-OVN v1.16.9 - Fixes VIP reconciliation for switch load balancer VIPs, improves external-gateway node handling, addresses VMI protection, and backports full-mask tunnel address selection for IPv6 tunnel endpoints.
  • Kube-OVN v1.15.30 - Updates containerd to v2.2.9 and backports full-mask tunnel address selection for IPv6 tunnel endpoints.
  • Kube-OVN v1.14.47 - Updates containerd to v2.2.9, backports full-mask tunnel address selection for IPv6 tunnel endpoints, and uses the OVN branch for release-1.14 base images.

Observability

  • OpenTelemetry Collector v0.162.0 - Introduces breaking changes where generated processor lifecycle tests assert context propagation by default (can be disabled), and renames the queuebatch processor to queue_batch. An enhancement adds the otelcol_memorylimiter_refused_requests metric.
  • Prometheus v3.13.4 - Includes security fixes by bumping google.golang.org/grpc to v1.83.1 to address HTTP/2 DATA frame fragmentation memory exhaustion (GO-2026-6348) and updating vulnerable npm dependencies in the UI. Bug fixes include ignoring unknown WAL record types in Agent mode, fixing corruption of float native histograms in Federation, and resolving failing scrapes of protobuf float histograms.
  • Inspektor Gadget v0.56.2 - Fixes a bug in container-collection by bounding the owner reference enrichment loop.

Orchestration

  • Volcano v1.15.3 - Prevents an int64 overflow in aggregate DRA device counts from bypassing the capacity plugin’s quota check. Also prevents stale PodGroup annotation updates from being applied to recreated Pods and skips not-ready placeholder nodes during incremental agent-scheduler snapshot updates.
  • Volcano v1.14.6 - Prevents stale PodGroup annotation updates from being applied to recreated Pods and skips not-ready placeholder nodes during incremental agent-scheduler snapshot updates.
  • Volcano v1.13.5 - Prevents stale PodGroup annotation updates from being applied to recreated Pods.

Scheduling

  • Kubernetes Descheduler v0.37.0 - Updates the Helm chart, fixes eviction metrics for background evictions, and removes unnecessary pods delete permission from the ClusterRole.

Security

  • Open Policy Agent v1.21.1 - Fixes a compiler regression from v1.21.0 where comprehensions using some … in or every nested in object or set literals were wrongly treated as ground, leading to errors or panics.
  • Keycloak 26.8.0 - Adds capabilities for issuing and verifying digital wallet credentials with OID4VCI and OID4VP. Introduces a SCIM API for automated user provisioning and supports stateless mode for multi-cluster deployments without an external cache.
  • Keycloak 26.7.5 - Includes a security fix for CVE-2026-16103, which addresses an incomplete fix for a CIBA brute-force lockout bypass vulnerability.
  • Kubescape v4.0.15 - Bumps the regolibrary to v2.0.36, refactors getReadableID, and updates CI dependencies.
  • Trivy v0.75.0 - This is a new minor release with general updates.

Storage

  • Rook v1.20.8 - A patch release focusing on bug fixes and feature additions to the Ceph operator. Improvements include running OSD prepare pods on the host network, adding default httproute backend parameters, making util.retry context aware, making RGW pool references immutable, and allowing missing lifecycle notification events.
  • Longhorn v1.13.0 - Introduces live upgrade for the V2 Data Engine, allowing V2 volumes to remain attached during Longhorn upgrades, provided cluster prerequisites are met. This release also adds full interrupt mode.

📰 This Week in Cloud Native

The Cloud Native community is preparing for KubeCon + CloudNativeCon North America 2026, with several announcements highlighting dedicated tracks and events. These include OpenTofu Day, focusing on provisioning infrastructure around Kubernetes, and various “journey” guides for application developers, infrastructure engineers, SREs, and contributors, indicating a broad range of topics covering different roles within the ecosystem. ArgoCon North America 2026 is also looking towards the future of Continuous Delivery with “CD 4.0”.

A significant theme this week involved the integration and implications of AI agents across the cloud native landscape. Discussions covered AI’s impact on security, with concerns that AI is accelerating exploits and that traditional vulnerability management systems may not keep pace. AWS introduced the Dogwood Local Engine, an open-source governance language for agents, and demonstrated an AI-powered EKS migration assessment agent using Amazon Bedrock AgentCore. Dynatrace’s acquisition of Arize highlights a shift towards new forms of observability tailored for agents. Microsoft also announced updates to Copilot Code Reviews for Azure Repos and the general availability of GitHub-hosted agents with Pay-as-you-Go pricing in Azure Pipelines. CloudBees has also stated an AI-first pivot for enterprise DevOps.

In Kubernetes and Infrastructure, articles explored the use cases for lightweight Kubernetes distributions like K3s compared to full K8s. Amazon EKS users received guidance on fixing pod distribution drift using the Kubernetes descheduler, and athenahealth shared how Amazon EKS Hybrid Nodes helped modernize healthcare workloads. Policy enforcement remains a focus, with a CNCF blog post advocating for “guardrails, not gates” in platform teams. AWS also expanded its cloud offerings, including new capabilities for Amazon Aurora PostgreSQL to directly query historical data from S3, improved Lambda function latency with scalable network bandwidth, and simplified AMI discovery with SSM Parameter Store.

💬 Community Buzz

Discussions on Hacker News this week frequently revolved around AI agents, covering topics such as their security implications, development tools (including inference engines and coding agents), and integration into various platforms. Kubernetes also generated interest, with new projects like KubeZap for declarative workflow automation and Ramen as a self-hosted multi-zone MCP server. The use of Docker and its underlying technologies, including microVMs and alternatives like rcdesktop, was also discussed. Additionally, there were conversations about the impact of AI on programming careers, the OVH dedicated server price increase, and various open-source tools for development and observability.

📊 Numbers of the Week

  • Total stable releases: 49 across 19 projects
  • Top 3 projects by commits this week:
    1. kubernetes/kubernetes — 184 commits
    2. keycloak/keycloak — 117 commits
    3. envoyproxy/envoy — 106 commits
  • Top 3 projects by merged pull requests this week:
    1. keycloak/keycloak — 142 merged PRs
    2. envoyproxy/envoy — 133 merged PRs
    3. kubernetes/kubernetes — 93 merged PRs

📚 View all articles from this week →