SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
Kubernetes 1.37: the hardening you did not ask for is the part you have to test
Sysdig counts 19 security-relevant changes in the release. The ones that arrive switched on, led by SELinuxMount at stable, are the ones that can break a running cluster.
The Watch · Security desk
What happened
- Sysdig's roundup counts 19 security-relevant items among the 67 enhancements in Kubernetes 1.37.
- iptables kube-proxy users start seeing a warning in 1.37, ahead of nftables becoming the default in 1.40.
- Static Pods can no longer reference Secrets or ConfigMaps, and the gate that governed that behaviour is gone.
Why it matters
- constraint A mount now carries one SELinux label, so a shared volume that worked because files were relabelled individually has to be redesigned rather than configured around.
- decision The kube-proxy deadline is a tooling decision as much as a networking one: detection that reads iptables state has three releases to learn nftables.
- exposure Four API additions at stable widen what any authorised reader learns about node capabilities and device health, which makes RBAC scope the control that carries the weight.
- cost The upgrade testing bill falls entirely on changes nobody requested, while the new controls this release offers stay off until someone opts in.
The mechanism behind the SELinux change decides whether it can hurt you. Kubernetes used to walk a PersistentVolume and relabel files recursively; with the `context` mount option, the security context is applied to the whole volume at mount time instead [5]. That is faster, and it also means a mount carries one label. Which is exactly the failure Sysdig names: Pods with different SELinux labels, or different privilege levels, sharing the same volume [7]. At stable, there is no gate to sit behind while you think about it, and the optimisation applies to all eligible volumes [6].
Look at which items in this release arrive switched on. The three net-new features detailed in the roundup are alpha with gates defaulting to false: TLS for gRPC probes [14], a permission `mode` for emptyDir volumes between 0000 and 01777 [3], and Pod-level checkpoint and restore [15]. All three cost nothing until somebody enables them [16]. The changes that need pre-upgrade testing are the ones without a switch: SELinuxMount at stable [6], and the static Pod fix whose `PreventStaticPodAPIReferences` gate has been deleted along with the bug [11].
Sysdig's 19 out of 67 enhancements works out to a little over a quarter of the release touching security in some way [17], though that count is generous by construction. It includes a block of enhancements whose only security property is that they publish more data: resource health status, DRA claim status, the metrics.k8s.io definition and Node Declared Features all land at stable, and Sysdig's own note is that the extra detail helps attackers understand your infrastructure too, so review who can read the API [12][13].
On how settled the alpha end of this is: the emptyDir stickyBit entry is listed with a feature gate named `FOO` [3]. Placeholder naming is a reasonable guide to how much of your attention that one has earned this cycle.
kube-proxy is the item with a real calendar. The nftables backend has been stable since 1.33, becomes the default in 1.40, and 1.37 starts warning anyone still defaulting to iptables [8] - three minor releases of notice [18]. The migration work is not the flag; it is that anything parsing iptables rules or config, detection tooling included, has to read nftables instead [10]. Anyone on ipvs has less room, since that mode has begun deprecation [9].
One gap worth flagging: authentication by default on webhooks is named in Sysdig's opening summary of the 19 changes [2], but it is not among the itemised entries in the published material [19]. Planning for that one means reading the KEP, not the roundup.
What to watch
- Whether operators find a supported way to keep the old recursive relabelling behaviour for shared volumes now that SELinuxMount is stable.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence58
- Adoption30
- Hype gap+10
- Incentives68
- Confidence54
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Sysdig identified 19 changes in Kubernetes 1.37 with security implications.
- [2]
Sysdig's summary says the 19 security-relevant changes span new security features to mount volumes, improvements on snapshots, authentication by default on webhooks, and more.
- [3]
KEP #5502 (sig-storage) adds stickyBit support for emptyDir volumes, net new to alpha, default false, with the feature gate listed as FOO; it allows an EmptyDirVolumeSource permission mode between 0000 and 01777 instead of the default 0777.
- [4]
Kubernetes 1.37 has been released, bringing 67 enhancements.
- [5]
KEP #1710 (sig-storage) speeds up mounting of PersistentVolumes when using SELinux: by using the context option at mount time, Kubernetes applies the security context to the entire volume rather than recursively changing the context on the files.
- [6]
In Kubernetes 1.37, SELinuxMount, the last bit of enhancement #1710, graduates to stable, meaning the optimisation will be applied to all eligible volumes.
- [7]
Sysdig warns this may cause issues in rare cases where Pods with different SELinux labels, or with different privilege levels, share the same volume.
- [8]
KEP #5343 (sig-network) makes nftables the default kube-proxy backend and is net new to alpha in 1.37; the nftables backend mode has been considered stable since 1.33 and will be the default in 1.40, and in 1.37 users will start seeing a warning if they currently use iptables as a default.
- [9]
In this release the kube-proxy ipvs mode is taking its first steps towards deprecation (#5495).
- [10]
Sysdig advises that anyone making the kube-proxy transition now should make sure their security tools are covering the new config files.
- [11]
Per #140226, a bug where static Pods could reference Secrets or ConfigMaps is fixed, and the related PreventStaticPodAPIReferences feature gate has been removed.
- [12]
Kubernetes 1.37 exposes new data through APIs, including at stable: Resource Health Status in Pod Status for Device Plugin and DRA (#4680), DRA Resource Claim Status with standardized network interface data (#4817), the metrics.k8s.io API definition (#5207), and Node Declared Features, formerly Node Capabilities (#5328).
- [13]
Sysdig notes the extra API data may also help attackers understand your infrastructure better, and recommends reviewing who has access to the API so they only access the data they need.
- [14]
KEP #4939 (sig-node) adds support for TLS credentials in gRPC probes, net new to alpha, feature gate GRPCContainerProbeTLS, default false; previously operators worked around this using an exec probe.
- [15]
KEP #5823 (sig-node) adds Pod-level checkpoint/restore, net new to alpha, feature gate PodLevelCheckpointRestore, default false; the existing kubelet Checkpoint API only creates stateful copies of a running container.
- [16]
All three net-new features itemised in the roundup ship as alpha with feature gates defaulting to false, so none of them changes behaviour unless an administrator enables it.
- [17]
The 19 security-relevant changes represent about 28 percent of the release's 67 enhancements.
- [18]
The gap between the iptables warning in 1.37 and nftables becoming the default in 1.40 is three minor releases.
- [19]
Authentication by default on webhooks appears in the roundup's summary sentence but not among its itemised entries, which cover SELinux mounts, kube-proxy backends, static Pods, new API data exposure, and three alpha additions.
Sources
1 independent publisher whose own reporting we read for this story.
- webflow.sysdig.comKubernetes 1.37 - New security features
1 article · August 25, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
Entities
- KubernetesFollow
- SysdigFollow
- Falco FeedsFollow
- FalcoFollow
- kube-proxyFollow
- kubeletFollow
- nftablesFollow
- iptablesFollow
- IPVSFollow
- SELinuxFollow
- KEP #1710 (Speed up recursive SELinux label change)Follow
- KEP #5343 (Make nftables the default kube-proxy backend)Follow
- KEP #5823 (Pod-level checkpoint/restore)Follow
- KEP #4939 (TLS credentials in gRPC probe)Follow
- Dynamic Resource Allocation (DRA)Follow