Review release notes for Kubernetes versions on standard support - Amazon EKS
Services or capabilities described in AWS documentation might vary by Region. To see the differences applicable to the AWS European Sovereign Cloud Region, see the AWS European Sovereign Cloud User Guide.

Help improve this page

To contribute to this user guide, choose the Edit this page on GitHub link that is located in the right pane of every page.

Review release notes for Kubernetes versions on standard support

Tip

Register for upcoming Amazon EKS workshops.

This topic gives important changes to be aware of for each Kubernetes version in standard support. When upgrading, carefully review the changes that have occurred between the old and new versions for your cluster.

Kubernetes 1.37

Kubernetes 1.37 is now available in Amazon EKS. For more information about Kubernetes 1.37, see the official release announcement.

Important
  • SELinux Mount Labeling Enabled by Default (GA): In Kubernetes 1.37, the SELinuxMount feature is enabled by default. When a Pod sets seLinuxOptions and its volume’s CSI driver sets seLinuxMount: true, the kubelet mounts the volume with mount -o context=<label> instead of relabeling every file. A mount can carry only one SELinux label, so a Pod stays in ContainerCreating if another Pod on the same node already uses the same volume with a different SELinux label, a different seLinuxChangePolicy, or a different privilege level. Nodes without SELinux enabled aren’t affected.

    • Action required: Before upgrading, run kubectl get csidriver -o custom-columns=NAME:.metadata.name,SELINUXMOUNT:.spec.seLinuxMount to find drivers with seLinuxMount: true. For volumes from those drivers, find Pods that set seLinuxOptions and share a volume. Pods that share a volume must use the same seLinuxOptions.level and seLinuxChangePolicy. If a privileged Pod and an unprivileged Pod share a volume, set spec.securityContext.seLinuxChangePolicy: Recursive on the unprivileged Pod. Recursive keeps the previous relabeling behavior; apply it to all Pods that share the volume. For more information, see SELinux Volume Label Changes goes GA (and likely implications in v1.37) and KEP-1710.

  • EKS Auto Mode Consolidation Default: Starting with Kubernetes 1.37, new EKS Auto Mode NodePools that don’t specify consolidationPolicy default to Balanced instead of WhenEmptyOrUnderutilized. Balanced typically results in fewer Pod evictions at roughly the same cost. The built-in general-purpose and system NodePools also use Balanced, and you can’t change this setting on them. For details, see the EKS Auto Mode release notes.

    • Action required: To keep a specific consolidation behavior, set consolidationPolicy explicitly on your own NodePools. If a workload needs the previous behavior, target a NodePool that sets consolidationPolicy: WhenEmptyOrUnderutilized.

  • Dynamic Resource Allocation (DRA) Device Taints and Tolerations (Stable): DRA drivers and cluster administrators can taint devices, such as GPUs, so the scheduler doesn’t allocate them to Pods that don’t tolerate the taint. Using DRA on EKS requires installing a DRA driver, which EKS doesn’t install. The NVIDIA DRA driver is supported with Karpenter static capacity, EKS managed node groups, and self-managed nodes. It isn’t supported with EKS Auto Mode. With EKS Auto Mode, or Karpenter dynamic capacity provisioning, use the NVIDIA device plugin.

  • Horizontal Pod Autoscaler Configurable Tolerance (Stable): You can set a tolerance per HPA, separately for scale up and scale down, instead of relying only on the cluster-wide default of 10%.

  • Horizontal Pod Autoscaler Scale to Zero (Beta): The HPAScaleToZero feature gate is enabled by default in Kubernetes 1.37. An HPA that scales on Object or External metrics can set minReplicas: 0 to scale to zero Pods when idle and back up when demand returns. Object and External metrics require a metrics adapter, which EKS doesn’t install.

  • Kubelet Configuration Changes: The kubelet no longer starts if a deprecated cAdvisor flag is set (except --housekeeping-interval), drops the container_cpu_load_average_10s, container_cpu_load_d_average_10s, and container_tasks_state metrics, and treats eventRecordQPS: 0 as no limit. Previously eventRecordQPS: 0 applied a limit of 5 events per second. EKS-optimized AMIs don’t set the deprecated cAdvisor flags or eventRecordQPS, so their kubelet startup and rate limit are unchanged. The removed metrics affect anyone who scrapes them, on any AMI.

    • Action required: If you use custom AMIs or extra kubelet arguments, remove the deprecated cAdvisor flags, and if you set eventRecordQPS: 0, change it to 5 to keep the previous rate limit. Update any dashboards or alerts that use the removed metrics. For more information, see the kubelet configuration (v1beta1) reference.

  • Kubelet Logs Its Configuration at Startup: The kubelet now logs its full effective configuration at startup. Make sure only trusted users can read node logs. For more information, see kubernetes/kubernetes#139837.

  • NVIDIA Driver 595 for Amazon EC2 G7 Instances: G7 instances require NVIDIA driver 595. The EKS-optimized Amazon Linux 2023 NVIDIA AMIs include driver 595 on all supported versions; the Bottlerocket NVIDIA AMIs include it on Kubernetes 1.37 and later.

For the complete Kubernetes 1.37 changelog, see https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.37.md

Kubernetes 1.36

Kubernetes 1.36 is now available in Amazon EKS. For more information about Kubernetes 1.36, see the official release announcement.

Important
  • gitRepo Volume Removal: The gitRepo volume type is permanently disabled in Kubernetes 1.36 and cannot be re-enabled. The Kubernetes API still accepts Pods with gitRepo volumes, but the kubelet will refuse to run them and return an error.

  • SELinux Volume Labeling Changes (GA): In Kubernetes 1.36, faster SELinux volume labeling defaults to all volumes, using mount -o context instead of recursive file relabeling. Sharing a volume on the same node between privileged and unprivileged Pods, or between Pods with different SELinux labels, may cause issues. The related SELinuxMount behavior that can hold a Pod in ContainerCreating is enabled by default in Kubernetes 1.37, not 1.36. Review the Kubernetes 1.37 section before upgrading.

  • Strict IP/CIDR Validation Enabled by Default: The StrictIPCIDRValidation feature gate is now enabled by default for built-in API kinds. API fields no longer accept IP or CIDR values with extraneous leading zeros (e.g., 010.000.000.005 instead of 10.0.0.5) or CIDR values with ambiguous semantics (e.g., 192.168.0.5/24 instead of 192.168.0.0/24). Existing stored objects are preserved via validation ratcheting, but new creates and updates will be rejected. This does not apply to custom resource kinds.

    • Action required: Review manifests, Helm charts, and automation for IP addresses containing leading zeros or non-canonical CIDR notation. Update them to use canonical formats before upgrading. For more information, see KEP-4858.

  • User Namespaces (Stable): User Namespaces provides defense-in-depth by mapping a container’s root user to a non-privileged user on the host, ensuring that a container breakout grants no administrative power over the node.

  • Resource Health Status (Beta): Reports per-device health in Pod status, allowing operators to determine whether a crash loop is due to an Unhealthy or Unknown device status rather than application issues. Works with both Device Plugins and Dynamic Resource Allocation.

  • Dynamic Resource Allocation Features (Beta): Several DRA features are now enabled by default: Partitionable Devices and Consumable Capacity for more granular sharing of hardware like GPUs, and Device Binding Conditions for thorough device readiness checks before scheduling.

  • Deprecation Notice — Service externalIPs: The externalIPs field in Service .spec is deprecated in Kubernetes 1.36. You will see deprecation warnings when creating or updating Services that use this field. Full removal is planned for Kubernetes 1.43. Customers who use externalIPs should migrate to LoadBalancer Services, NodePort, or Gateway API. For more information, see KEP-5707.

For the complete Kubernetes 1.36 changelog, see https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md

Kubernetes 1.35

Kubernetes 1.35 is now available in Amazon EKS. For more information about Kubernetes 1.35, see the official release announcement.

Important
  • Cgroup v1 Support Removed: Kubernetes 1.35 deprecates cgroup v1 support, meaning the kubelet will refuse to start by default on nodes using cgroup v1.

    • AL2023: AL2023 uses cgroup v2 by default and aligns with Kubernetes upstream behavior.

      • Action required: Customers who manually configured AL2023 to use cgroup v1 must either migrate to cgroups v2 or manually set failCgroupV1: false in kubelet configuration.

    • Bottlerocket: Bottlerocket 1.35 uses cgroup v2 by default, however sets failCgroupV1: false in the kubelet configuration, maintaining backward compatibility.

    • Fargate: Fargate continues to use cgroup v1.

  • Containerd 1.x End of Support: Kubernetes 1.35 is the last release supporting containerd 1.x. You must switch to containerd 2.0 or later before upgrading to the next Kubernetes version.

  • In March 2026, the upstream Kubernetes project will retire Ingress NGINX, a critical infrastructure component for many Kubernetes environments.

    • Action required: EKS customers should evaluate whether they rely on Ingress NGINX and begin planning migration to alternatives such as Gateway API or third-party Ingress controllers, as there will be no further releases for bug fixes, security patches, or updates after retirement. Existing deployments will continue to work, but remaining with Ingress NGINX after retirement leaves your environment vulnerable to security risks, as none of the available alternatives are direct drop-in replacements and will require planning and engineering time. For more information about this Kubernetes announcement, see the official statement from the Kubernetes Steering and Security Response Committees Ingress NGINX retirement.

  • In-Place Pod Resource Updates (Stable): In-Place Pod Resource Updates allows users to adjust CPU and memory resources without restarting Pods or containers. Previously, such modifications required recreating Pods, which could disrupt workloads, particularly for stateful or batch applications. The new in-place functionality allows for smoother, non-disruptive vertical scaling, improves efficiency, and can also simplify development.

  • PreferSameNode Traffic Distribution (Stable): The trafficDistribution field for Services has been updated to provide more explicit control over traffic routing. A new option, PreferSameNode, has been introduced to allow services to strictly prioritize endpoints on the local node when available, falling back to remote endpoints otherwise. This change makes the API more explicit about preferring traffic within the current node.

  • StatefulSet MaxUnavailable (Beta): This feature enables parallel Pod updates by setting maxUnavailable (e.g., 3 or 10%), allowing stateful applications like database clusters to update up to 60% faster than sequential one-at-a-time updates, significantly reducing maintenance windows.

  • Windows Server 2025 Support: EKS 1.35 adds support for Windows Server 2025.

  • Kubelet Flag Removal: The --pod-infra-container-image flag has been removed from kubelet. Custom AMI users must remove this flag from kubelet configuration before upgrading to 1.35.

  • Deprecation Notice - IPVS Mode: IPVS mode in kube-proxy is deprecated and will be removed in a future Kubernetes release. Migrate to nftables mode. For more information, see Running kube-proxy in nftables Mode.

For the complete Kubernetes 1.35 changelog, see https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md

Kubernetes 1.34

Kubernetes 1.34 is now available in Amazon EKS. For more information about Kubernetes 1.34, see the official release announcement.

Important
  • Containerd updated to 2.1 in Version 1.34 for launch.

  • AWS is not releasing an EKS-optimized Amazon Linux 2 AMI for Kubernetes 1.34.

  • AppArmor is deprecated in Kubernetes 1.34.

  • VolumeAttributesClass (VAC) graduates to GA in Kubernetes 1.34, migrating from the beta API (storage.k8s.io/v1beta1) to the stable API (storage.k8s.io/v1).

    • If you use the EBS CSI driver with AWS-managed sidecar containers (from CSI Components on the ECR Gallery), volume modification will continue to work seamlessly on EKS 1.31-1.33 clusters. AWS will patch the sidecars to support beta VAC APIs until the end of EKS 1.33 standard support (July 29, 2026).

    • If you self-manage your CSI sidecar containers, you may need to pin to older sidecar versions on pre-1.34 clusters to maintain VAC functionality.

    • To use GA VolumeAttributesClass features (such as modification rollback), upgrade to EKS 1.34 or later.

  • External JWT Signer for Service Account Tokens is promoted to Beta. When using external signers, the --service-account-extend-token-expiration flag is no longer fully respected. The API server enforces the minimum expiration between the desired extension (1 year) and the external signer’s limit (24 hours).

  • Dynamic Resource Allocation (DRA) Core APIs (GA): Dynamic Resource Allocation has graduated to stable, enabling efficient management of specialized hardware like GPUs through standardized allocation interfaces - simplifying resource management for hardware accelerators and improving utilization of specialized resources.

  • Projected ServiceAccount Tokens for Kubelet (Beta): This enhancement improves security by using short-lived credentials for container image pulls instead of long-lived secrets - reducing the risk of credential exposure and strengthening the overall security posture of your clusters.

  • Pod-level Resource Requests and Limits (Beta): This feature simplifies resource management by allowing shared resource pools for multi-container pods - enabling more efficient resource allocation and utilization for complex applications with multiple containers.

  • Mutable CSI Node Allocatable Count (Beta): The MutableCSINodeAllocatableCount feature gate is enabled by default in EKS 1.34, making the CSINode max attachable volume count attribute mutable and introducing a mechanism to update it dynamically based on user configuration at the CSI driver level. These updates can be triggered either by periodic intervals or by failure detection, enhancing the reliability of stateful pod scheduling by addressing mismatches between reported and actual attachment capacity on nodes.

  • Deprecation Notice - cgroup driver configuration: Manual cgroup driver configuration is being deprecated in favor of automatic detection.

    • Customer impact: If you currently set the --cgroup-driver flag manually in your kubelet configuration, you should prepare to remove this configuration.

    • Required action: Plan to update node bootstrap scripts and custom AMI configurations to remove manual cgroup driver settings before the feature is removed in a future Kubernetes release.

    • For more information, see the cgroup driver documentation.

For the complete Kubernetes 1.34 changelog, see https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md