Kubernetes v1.35 sets failCgroupV1 to true by default, so the kubelet will not start on a node still running cgroup v1. Teams below v1.35 now decide before upgrading between migrating every Linux node and carrying a temporary override the project plans to remove.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence68
buildOne report1 publisher Admission control and RBAC decide who may fetch a Secret object. Neither is in the path once the kubelet has copied the value into a container, and an agent runtime is where that gap gets expensive.
Reality
- Evidence68
- Adoption15
- Hype gap+12
- Incentives45
- Confidence62
buildOne report1 publisher Kubernetes 1.37 shipped on 26 August 2026 with the containerd CRI fallback still working, because a pull request merged three months earlier moved the removal to 1.38. Two of the guides link to that pull request.
Reality
- Evidence52
- Adoption18
- Hype gap+30
- Incentives55
- Confidence45
The v1.37 GA puts X.509 delivery and refresh inside Kubelet, but the authority that actually signs those certificates is still integration work, which is why no adjacent tooling comes out of the plan this quarter.
Reality
- Evidence60
- Adoption20
- Hype gap+18
- Incentives62
- Confidence55
buildOne report1 publisher Tunable CrashLoopBackOff is now GA on GKE, with a per-node-pool maximum restart period anywhere from 1 to 300 seconds. It retires the privileged DaemonSets teams were using to rewrite kubelet config on accelerator nodes.
Reality
- Evidence48
- Adoption18
- Hype gap+18
- Incentives78
- Confidence44
buildOne report1 publisher KEP-3257 adds a ClusterTrustBundle object and a kubelet projected volume source, which lets a signer publish its roots without running a controller that holds create-ConfigMap permission in every namespace.
Publishers:kubernetes.dev
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+18
- Incentives55
- Confidence62
buildOne report1 publisher KEP-4317 pairs a pod-scoped certificate request with a projected volume, so the kubelet provisions the key and kube-apiserver enforces node restriction. What is left for a signer to do is the CA work.
Publishers:kubernetes.dev
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence55
buildOne report1 publisher The word healthcheck names three different behaviours depending on which layer reads it, and the layer where it means nothing for routing is the one most production traffic goes through. Portability was the assumption.
Reality
- Evidence56
- Adoption
- Insufficient
- Hype gap+12
- Incentives28
- Confidence57
Sysdig counts 19 security-relevant changes in the release. The ones that arrive switched on, led by SELinuxMount at stable, are the ones that can break a running cluster.
Reality
- Evidence58
- Adoption30
- Hype gap+10
- Incentives68
- Confidence54
buildOne report1 publisher In-place Pod resizing is GA and the kubelet can now issue pod certificates itself, but the fix for feature skew between control plane and nodes is still alpha. Read the removals list first.
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+14
- Incentives62
- Confidence68
buildOne report1 publisher An ngrok post ports more than 100,000 lines of Kubernetes Go to TypeScript to demonstrate restart loops and dropped requests. The instructive case is the one a correct probe does not prevent.
Publishers:ngrok.com
Reality
- Evidence54
- Adoption
- Insufficient
- Hype gap+14
- Incentives58
- Confidence48