Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
102 commits
Select commit Hold shift + click to select a range
38378d5
Bugfix: calculate request latency properly in audit log filter
Dec 9, 2025
6b56734
Update knftables to v0.0.21
danwinship Mar 6, 2026
93de120
pkg/proxy/nftables: fix kube-proxy crash with newer nftables versions
kairosci Feb 11, 2026
4c04292
Update CHANGELOG/CHANGELOG-1.35.md for v1.35.3
k8s-release-robot Mar 18, 2026
570f471
kubelet: fix sidecar restart after kubelet restart
george-angel Mar 13, 2026
a886e95
Merge pull request #137807 from danwinship/automated-cherry-pick-of-#…
k8s-ci-robot Mar 19, 2026
b0ec348
KEP-961: demote maxUnavailable feature in statefulset to off by default
soltysh Mar 19, 2026
9a39e5c
Fix union validation ratcheting when oldObj is nil
yongruilin Mar 18, 2026
863ed56
Add nil OldValue test coverage for union doc_tests
yongruilin Mar 18, 2026
7b708cc
Add DRA test for device attribute with no value set
yongruilin Mar 18, 2026
3d39627
Use IsZero instead of IsNil for union ratcheting check
yongruilin Mar 18, 2026
b6ee759
Add slice and map union member support with tests
yongruilin Mar 19, 2026
d8a562b
Fix backport differences for 1.35 (remove WithOrigin and MarkAlpha)
lalitc375 Mar 20, 2026
e54bba5
Merge pull request #137885 from HirazawaUi/automated-cherry-pick-of-#…
k8s-ci-robot Mar 20, 2026
a09ab89
Merge pull request #136281 from chaochn47/automated-cherry-pick-of-#1…
k8s-ci-robot Mar 26, 2026
9d8bbea
Fix device plugin admission failure after container restart
saschagrunert Nov 27, 2025
91a1e8b
e2e: node: podresources: fix expectations for Get() and terminated pods
ffromani Feb 18, 2026
1d5e94e
podresources: filter out inactive pods in Get()
ffromani Feb 18, 2026
46ba1c3
Deflake TestPodSubresourceAuth by waiting for effective permissions b…
liggitt Mar 31, 2026
69dd59d
podStartSLOduration excludes init container runtime and image pulling…
alimaazamat May 23, 2025
e23757c
Merge pull request #138137 from liggitt/automated-cherry-pick-of-#138…
k8s-ci-robot Apr 9, 2026
82a705c
Merge pull request #137927 from lalitc375/cherry-pick-137864
k8s-ci-robot Apr 9, 2026
a0ce4b9
Merge pull request #137926 from soltysh/automated-cherry-pick-of-#137…
k8s-ci-robot Apr 9, 2026
97ccbdf
Bump images and versions to go 1.25.9 and distroless iptables
xmudrii Apr 9, 2026
c9622e9
Merge pull request #138304 from xmudrii/update-go-1.35
k8s-ci-robot Apr 9, 2026
c889751
Merge pull request #138042 from zxqlxy/automated-cherry-pick-of-#1354…
k8s-ci-robot Apr 9, 2026
e87f6b9
update go.opentelemetry.io/otel to v1.41.0
dashpole Apr 13, 2026
1687aa8
Update github.com/moby/spdystream from v0.5.0 to v0.5.1
dims Apr 13, 2026
0f1efab
Merge pull request #138348 from dashpole/update_prop_35
k8s-ci-robot Apr 14, 2026
9382886
Merge pull request #138356 from dims/update-moby-spdystream-v0.5.1-1.35
k8s-ci-robot Apr 14, 2026
7b8c6cf
Release commit for Kubernetes v1.35.4
k8s-release-robot Apr 15, 2026
31d47ca
Update CHANGELOG/CHANGELOG-1.35.md for v1.35.4
k8s-release-robot Apr 15, 2026
55f12e8
scheduler: fix inFlightPods leak when pod is recreated during schedul…
MaybeSam05 Apr 12, 2026
bf14155
scheduler: skip requeueing recreated pods on scheduling failure
MaybeSam05 Apr 13, 2026
6953afb
scheduler: address recreated pod review feedback
MaybeSam05 Apr 14, 2026
799beb9
kubeadm: skip promote call when etcd member is already a voting member
wgkingk Apr 15, 2026
1a7f0b3
Escape path inside the container
soltysh Mar 10, 2026
7b57a4b
Merge pull request #138434 from Argh4k/automated-cherry-pick-of-#1383…
k8s-ci-robot Apr 22, 2026
feb7fa1
Evaluate etcd cluster health using quorum
ahrtr Apr 15, 2026
6d314b2
Add a (*Client) addEndpoint method
ahrtr Apr 17, 2026
ec18059
Merge pull request #138539 from ahrtr/automated-cherry-pick-of-#13840…
k8s-ci-robot Apr 23, 2026
d550d45
Delete remote endpoint if it has same ip as local endpoint in the sys…
princepereira Mar 23, 2026
943d941
Delete remote endpoint if it has same ip as local endpoint in the sys…
princepereira Mar 24, 2026
faa8112
kube-proxy: don't do full periodic syncs on large cluster mode
aojea Apr 24, 2026
f792796
kubeadm: use the localAPIEndpoint for all API calls in 'init'
neolit123 Apr 17, 2026
a69783a
Merge pull request #138602 from princepereira/automated-cherry-pick-o…
k8s-ci-robot May 5, 2026
935bba3
Merge pull request #138683 from neolit123/automated-cherry-pick-of-#1…
k8s-ci-robot May 5, 2026
ddbb265
Merge pull request #138636 from aojea/automated-cherry-pick-of-#13857…
k8s-ci-robot May 6, 2026
7909267
kubeadm: skip LocalAPIEndpoint defaulting on worker join
clwluvw Apr 29, 2026
1c60082
Merge pull request #138803 from neolit123/automated-cherry-pick-of-#1…
k8s-ci-robot May 8, 2026
41b5310
Merge pull request #138153 from alimaazamat/automated-cherry-pick-of-…
k8s-ci-robot May 8, 2026
7777c57
Merge pull request #138501 from soltysh/automated-cherry-pick-of-#138…
k8s-ci-robot May 8, 2026
b9ffe7c
kubeadm: use dedicated ClusterRole for apiserver kubelet client
micahhausler Feb 16, 2026
f0a869d
Merge pull request #138959 from neolit123/automated-cherry-pick-of-#1…
k8s-ci-robot May 11, 2026
bf604dc
test/compatibility_lifecycle: resolve feature names from variables
siyuanfoundation Apr 24, 2026
6636cbc
Release commit for Kubernetes v1.35.5
k8s-release-robot May 12, 2026
90640ec
Update CHANGELOG/CHANGELOG-1.35.md for v1.35.5
k8s-release-robot May 12, 2026
350f793
DRA: fix AllocationModeAll with consumed counters
takonomura May 8, 2026
9f52f4d
controller/selinuxwarning: Pre-parse SELinux label
tchap Feb 24, 2026
fd08821
controller/selinuxwarning/cache: Add reverse index
tchap Feb 24, 2026
4a0532b
Cache selinux conflicts
gnufied May 11, 2026
b596e7b
Restore ability to plumb binary data through envvar values
liggitt May 19, 2026
f1ce76d
feat(volume): add IsRemount to MounterArgs
aramase May 13, 2026
df562ae
fix(csi): preserve mount dir on NodePublish error during remount
aramase May 13, 2026
77292b8
fix(endpoint): avoid panic on services with empty IPFamilies
rahulbabu95 Apr 22, 2026
a74c5bf
Fix DRA scoring bug with mixed allocated and unallocated claims
johnbelamaric May 12, 2026
d2212b8
kubeadm: fix dry-run CA copy paths in init certs
ErikJiang May 28, 2026
d44082b
Fix wrong marking of errors
lalitc375 Jun 3, 2026
79ce171
Merge pull request #139193 from liggitt/env-binary-1.35
k8s-ci-robot Jun 8, 2026
607d6c1
Merge pull request #139137 from gnufied/manual-cherry-pick-selinux-me…
k8s-ci-robot Jun 8, 2026
e8003b4
Merge pull request #139234 from rahulbabu95/automated-cherry-pick-of-…
k8s-ci-robot Jun 8, 2026
3fd20ce
Merge pull request #139362 from nojnhuh/automated-cherry-pick-of-#139…
k8s-ci-robot Jun 8, 2026
f5419c1
Merge pull request #138989 from pohly/automated-cherry-pick-of-#13888…
k8s-ci-robot Jun 8, 2026
508ff96
Merge pull request #139229 from aramase/automated-cherry-pick-of-#139…
k8s-ci-robot Jun 8, 2026
4eb3220
Merge pull request #139509 from lalitc375/automated-cherry-pick-of-#1…
k8s-ci-robot Jun 8, 2026
ccae5e3
Merge pull request #139447 from HirazawaUi/automated-cherry-pick-of-#…
k8s-ci-robot Jun 8, 2026
5ccf8f4
Bump images and versions to go 1.25.11 and distroless iptables
cpanato Jun 9, 2026
6b479f6
Merge pull request #139588 from cpanato/update-go-images-rel135
k8s-ci-robot Jun 9, 2026
dd84374
Fix job controller reporting active=0 during pod creation backoff
akhilsingh-git Jun 3, 2026
fc0e7a6
Release commit for Kubernetes v1.35.6
k8s-release-robot Jun 11, 2026
923d2d9
Update CHANGELOG/CHANGELOG-1.35.md for v1.35.6
k8s-release-robot Jun 11, 2026
4c89481
Update google.golang.org/protobuf to v1.36.12-0.20260120151049-f2248a…
dims Mar 5, 2026
463e908
kubeadm: use KubernetesAPICallTimeout for mandatory kubeadm-config fetch
damdo Jun 17, 2026
4b3619c
Merge pull request #139809 from damdo/automated-cherry-pick-of-139667…
k8s-ci-robot Jun 17, 2026
cfad4b5
kubeadm: treat already promoted learner as successful
jihyun-huh Jun 18, 2026
64f72b7
Restore string JSON encoding of cri-api KeyValue
liggitt Jun 23, 2026
8b1184f
Make utf8 replacement char test pass on Go 1.27
liggitt Jun 24, 2026
c371666
Merge pull request #139666 from kmala/automated-cherry-pick-of-#13745…
kubernetes-prow[bot] Jun 25, 2026
2165452
Fix vet error
liggitt Feb 17, 2026
7a90faf
Merge pull request #139966 from liggitt/automated-cherry-pick-of-#139…
kubernetes-prow[bot] Jul 1, 2026
860b2bb
Merge pull request #140030 from kmala/release-1.35
kubernetes-prow[bot] Jul 2, 2026
6a68e67
Merge pull request #139751 from akhilsingh-git/automated-cherry-pick-…
kubernetes-prow[bot] Jul 3, 2026
44b56f8
Merge pull request #139909 from jihyun-huh/automated-cherry-pick-of-#…
kubernetes-prow[bot] Jul 3, 2026
13fcb37
Merge pull request #138492 from wgkingk/automated-cherry-pick-of-#138…
kubernetes-prow[bot] Jul 3, 2026
14e26b5
Merge pull request #138976 from stmcginnis/automated-cherry-pick-of-#…
kubernetes-prow[bot] Jul 3, 2026
ff899e0
stop logging missing optional container annotations
HirazawaUi Jul 1, 2026
68bd319
Bump images and versions to golang 1.25.12 and update distroless-ipta…
palnabarun Jul 15, 2026
c4d272d
Merge pull request #140321 from HirazawaUi/automated-cherry-pick-of-#…
kubernetes-prow[bot] Jul 18, 2026
d5eba19
Merge pull request #140585 from palnabarun/bump-go-1.35
kubernetes-prow[bot] Jul 18, 2026
96cb9ab
Release commit for Kubernetes v1.35.7
k8s-release-robot Jul 22, 2026
b7e63cc
Merge tag 'v1.35.7' into rebase-release-4.23-v1.35.7
redhat-chai-bot Jul 27, 2026
44b455a
UPSTREAM: <drop>: hack/update-vendor.sh, make update and update image
redhat-chai-bot Jul 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion .go-version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.25.7
1.25.12
559 changes: 500 additions & 59 deletions CHANGELOG/CHANGELOG-1.35.md

Large diffs are not rendered by default.

31 changes: 30 additions & 1 deletion LICENSES/vendor/go.opentelemetry.io/otel/LICENSE

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

31 changes: 30 additions & 1 deletion LICENSES/vendor/go.opentelemetry.io/otel/metric/LICENSE

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

31 changes: 30 additions & 1 deletion LICENSES/vendor/go.opentelemetry.io/otel/sdk/LICENSE

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

31 changes: 30 additions & 1 deletion LICENSES/vendor/go.opentelemetry.io/otel/trace/LICENSE

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion build/build-image/cross/VERSION
Original file line number Diff line number Diff line change
@@ -1 +1 @@
v1.35.0-go1.25.7-bullseye.0
v1.35.0-go1.25.12-bullseye.0
4 changes: 2 additions & 2 deletions build/common.sh
Original file line number Diff line number Diff line change
Expand Up @@ -80,8 +80,8 @@ readonly REMOTE_OUTPUT_BINPATH="${REMOTE_OUTPUT_SUBPATH}/bin"
readonly REMOTE_OUTPUT_GOPATH="${REMOTE_OUTPUT_SUBPATH}/go"

# These are the default versions (image tags) for their respective base images.
readonly __default_distroless_iptables_version=v0.8.8
readonly __default_go_runner_version=v2.4.0-go1.25.7-bookworm.0
readonly __default_distroless_iptables_version=v0.8.14
readonly __default_go_runner_version=v2.4.0-go1.25.12-bookworm.0
readonly __default_setcap_version=bookworm-v1.0.6

# The default image for all binaries which are dynamically linked.
Expand Down
6 changes: 3 additions & 3 deletions build/dependencies.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -122,7 +122,7 @@ dependencies:
# should also be updated, but go-runner is much harder to exploit and has
# far less relevancy to go updates for Kubernetes more generally.
- name: "registry.k8s.io/kube-cross: dependents"
version: v1.35.0-go1.25.7-bullseye.0
version: v1.35.0-go1.25.12-bullseye.0
refPaths:
- path: build/build-image/cross/VERSION

Expand Down Expand Up @@ -170,15 +170,15 @@ dependencies:
match: registry\.k8s\.io\/build-image\/debian-base:[a-zA-Z]+\-v((([0-9]+)\.([0-9]+)\.([0-9]+)(?:-([0-9a-zA-Z-]+(?:\.[0-9a-zA-Z-]+)*))?)(?:\+([0-9a-zA-Z-]+(?:\.[0-9a-zA-Z-]+)*))?)

- name: "registry.k8s.io/distroless-iptables: dependents"
version: v0.8.8
version: v0.8.14
refPaths:
- path: build/common.sh
match: __default_distroless_iptables_version=
- path: test/utils/image/manifest.go
match: configs\[DistrolessIptables\] = Config{list\.BuildImageRegistry, "distroless-iptables", "v([0-9]+)\.([0-9]+)\.([0-9]+)"}

- name: "registry.k8s.io/go-runner: dependents"
version: v2.4.0-go1.25.7-bookworm.0
version: v2.4.0-go1.25.12-bookworm.0
refPaths:
- path: build/common.sh
match: __default_go_runner_version=
Expand Down
2 changes: 1 addition & 1 deletion cmd/kubeadm/app/cmd/certs.go
Original file line number Diff line number Diff line change
Expand Up @@ -350,7 +350,7 @@ func getInternalCfg(cfgPath string, client kubernetes.Interface, cfg kubeadmapiv
getNodeRegistration := true
getAPIEndpoint := staticpodutil.IsControlPlaneNode()
getComponentConfigs := true
internalcfg, err := configutil.FetchInitConfigurationFromCluster(client, printer, logPrefix, getNodeRegistration, getAPIEndpoint, getComponentConfigs)
internalcfg, err := configutil.FetchInitConfigurationFromCluster(client, printer, logPrefix, getNodeRegistration, getAPIEndpoint, getComponentConfigs, true)
if err == nil {
printer.Println() // add empty line to separate the FetchInitConfigurationFromCluster output from the command output
// certificate renewal or expiration checking doesn't depend on a running cluster, which means the CertificatesDir
Expand Down
58 changes: 30 additions & 28 deletions cmd/kubeadm/app/cmd/init.go
Original file line number Diff line number Diff line change
Expand Up @@ -19,11 +19,9 @@ package cmd
import (
"fmt"
"io"
"net"
"os"
"path/filepath"
"slices"
"strconv"

"github.com/spf13/cobra"
flag "github.com/spf13/pflag"
Expand Down Expand Up @@ -93,6 +91,7 @@ type initData struct {
skipTokenPrint bool
dryRun bool
kubeconfig *clientcmdapi.Config
kubeconfigOriginal *clientcmdapi.Config
kubeconfigDir string
kubeconfigPath string
ignorePreflightErrors sets.Set[string]
Expand Down Expand Up @@ -463,6 +462,9 @@ func (d *initData) CertificateDir() string {
}

// KubeConfig returns a kubeconfig after loading it from KubeConfigPath().
// If the default kubeconfig path is used (admin.conf), instead of constructing
// a kubeconfig that points to the control plane endpoint, make it point to the localAPIEndpoint.
// This would allow 'kubeadm init' to only talk to the local kube-apiserver instance.
func (d *initData) KubeConfig() (*clientcmdapi.Config, error) {
if d.kubeconfig != nil {
return d.kubeconfig, nil
Expand All @@ -473,10 +475,26 @@ func (d *initData) KubeConfig() (*clientcmdapi.Config, error) {
if err != nil {
return nil, err
}
d.kubeconfigOriginal = d.kubeconfig.DeepCopy()

if d.kubeconfigPath == kubeadmconstants.GetAdminKubeConfigPath() {
kubeconfigutil.PointKubeConfigToLocalAPIEndpoint(d.kubeconfig, &d.Cfg().LocalAPIEndpoint)
}

return d.kubeconfig, nil
}

// KubeConfigOriginal returns the original kubeconfig loaded from file, without any modifications.
func (d *initData) KubeConfigOriginal() (*clientcmdapi.Config, error) {
if d.kubeconfigOriginal == nil {
if _, err := d.KubeConfig(); err != nil {
return nil, err
}
}

return d.kubeconfigOriginal, nil
}

// KubeConfigDir returns the Kubernetes configuration directory or the temporary directory if DryRun is true.
func (d *initData) KubeConfigDir() string {
if d.dryRun {
Expand Down Expand Up @@ -521,8 +539,12 @@ func (d *initData) OutputWriter() io.Writer {

// getDryRunClient creates a fake client that answers some GET calls in order to be able to do the full init flow in dry-run mode.
func getDryRunClient(d *initData) (clientset.Interface, error) {
kubeconfig, err := d.KubeConfig()
if err != nil {
return nil, err
}
dryRun := apiclient.NewDryRun()
if err := dryRun.WithKubeConfigFile(d.KubeConfigPath()); err != nil {
if err := dryRun.WithKubeConfig(kubeconfig); err != nil {
return nil, err
}
dryRun.WithDefaultMarshalFunction().
Expand Down Expand Up @@ -550,7 +572,11 @@ func (d *initData) Client() (clientset.Interface, error) {
// and if the bootstrapping was not already done
if !d.adminKubeConfigBootstrapped && isDefaultKubeConfigPath {
// Call EnsureAdminClusterRoleBinding() to obtain a working client from admin.conf.
d.client, err = kubeconfigphase.EnsureAdminClusterRoleBinding(kubeadmconstants.KubernetesDir, nil)
d.client, err = kubeconfigphase.EnsureAdminClusterRoleBinding(
kubeadmconstants.KubernetesDir,
&d.Cfg().LocalAPIEndpoint,
nil,
)
if err != nil {
return nil, errors.Wrapf(err, "could not bootstrap the admin user in file %s", kubeadmconstants.AdminKubeConfigFileName)
}
Expand All @@ -571,30 +597,6 @@ func (d *initData) Client() (clientset.Interface, error) {
return d.client, nil
}

// WaitControlPlaneClient returns a basic client used for the purpose of waiting
// for control plane components to report 'ok' on their respective health check endpoints.
// It uses the admin.conf as the base, but modifies it to point at the local API server instead
// of the control plane endpoint.
func (d *initData) WaitControlPlaneClient() (clientset.Interface, error) {
config, err := clientcmd.LoadFromFile(d.KubeConfigPath())
if err != nil {
return nil, err
}
for _, v := range config.Clusters {
v.Server = fmt.Sprintf("https://%s",
net.JoinHostPort(
d.Cfg().LocalAPIEndpoint.AdvertiseAddress,
strconv.Itoa(int(d.Cfg().LocalAPIEndpoint.BindPort)),
),
)
}
client, err := kubeconfigutil.ToClientSet(config)
if err != nil {
return nil, err
}
return client, nil
}

// Tokens returns an array of token strings.
func (d *initData) Tokens() []string {
tokens := []string{}
Expand Down
2 changes: 1 addition & 1 deletion cmd/kubeadm/app/cmd/join.go
Original file line number Diff line number Diff line change
Expand Up @@ -715,7 +715,7 @@ func fetchInitConfiguration(client clientset.Interface) (*kubeadmapi.InitConfigu
getNodeRegistration := false
getAPIEndpoint := false
getComponentConfigs := true
initConfiguration, err := configutil.FetchInitConfigurationFromCluster(client, nil, "preflight", getNodeRegistration, getAPIEndpoint, getComponentConfigs)
initConfiguration, err := configutil.FetchInitConfigurationFromCluster(client, nil, "preflight", getNodeRegistration, getAPIEndpoint, getComponentConfigs, false)
if err != nil {
return nil, errors.Wrap(err, "unable to fetch the kubeadm-config ConfigMap")
}
Expand Down
Loading