BuildNot yet confirmed elsewhere1 publisher3 min readPublished
Kubernetes 1.35 lands 60 enhancements, 17 of them stable: treat the upgrade as a compatibility audit
In-place Pod resizing is GA and the kubelet can now issue pod certificates itself, but the fix for feature skew between control plane and nodes is still alpha. Read the removals list first.
The Engineer · Build desk
What happened
- Kubernetes v1.35 ships 60 enhancements: 17 stable, 19 beta and 22 alpha.
- The release announcement also flags deprecations and removals, pointing readers to a separate section rather than listing them in the highlights.
- In-place updates to Pod CPU and memory reached General Availability, so vertical scaling no longer requires restarting Pods or Containers.
- The kubelet can now generate keys, request certificates via PodCertificateRequest and write credential bundles straight into the Pod filesystem.
- A new framework has nodes publish the features they support in .status.declaredFeatures for the scheduler and admission controllers to consume.
Why it matters
- cost The bill for the resize graduation falls on whoever maintains the operators and billing pipelines built on Pods being recreated when resources change, not on the team running the control-plane...
- decision Shops already running cert-manager or SPIFFE/SPIRE now have to decide whether the kubelet owns pod identity or the existing controller keeps it, because there are two viable issuance paths in the...
- exposure Until declaredFeatures is something you would run in anger, a 1.35 control plane over older nodes leaves the mis-scheduling risk sitting with the operator.
- constraint Two thirds of the release stays inert until someone enables it, which narrows the audit to the stable graduations plus whatever the removals list touches.
The node-declaration framework is written up as a feature, but its problem statement reads like a bug report. SIG Node's own description is that when a control plane enables features the nodes do not yet support, which the version skew policy permits, kube-scheduler can place a Pod requiring those features onto an incompatible older node [8]. The remedy is for each node to publish what it supports so the scheduler, admission controllers and third-party components can act on the declaration [9]. In v1.35 that remedy is alpha, filed as KEP 5328 by SIG Node [10][11]. The description of the hazard ships now; the guard rail ships in a state most people will not enable on a production fleet.
The graduation with the widest blast radius is the resize one, and the release note says plainly what it replaces: changing a Pod's CPU or memory used to require recreating the Pod, which disrupted stateful and batch workloads [6]. Any controller that treated a fresh Pod as the signal that resources had changed is now watching for an event that need not fire. So is any chargeback pipeline that samples requests once at admission. Nothing breaks on upgrade. The assumption underneath does.
Certificates are the other place where an existing investment has to be re-decided rather than merely patched. Getting credentials into a Pod previously meant an external controller such as cert-manager or SPIFFE/SPIRE, CRD orchestration and Secret management, with rotation bolted on through sidecars or init containers [12]. The kubelet now generates the key, asks via PodCertificateRequest and writes the bundle into the Pod filesystem [13], while kube-apiserver enforces node restriction at admission time, which the release calls the most common pitfall for third-party signers [14]. The issuance path carries no bearer token [15], and the work is KEP 4317 from SIG Auth [16].
Twenty-eight percent of this release arrives as settled behaviour [18]. The other 41 enhancements sit behind gates until someone turns them on [19], which is why the audit budget belongs to the stable set, to the deprecations and removals the announcement flags without enumerating in its highlights [4], and to behaviour changes that look cosmetic until they are in the data path. The trafficDistribution field for Services is stable with a new PreferSameNode option that strictly prioritises endpoints on the local node and falls back to remote ones [17]. That is a routing change with a name, and it belongs on the same checklist as the API removals.
Three named releases landed in 2025 [2], roughly one every four months [20]. Anyone tracking upstream is running this compatibility exercise three times a year, and the parts that make it expensive are not the alpha features everyone reads about.
What to watch
- The full v1.35 deprecations and removals list, and whether any removed API is called by your operators or CI tooling.
- Whether node-declaration features reach beta in v1.36, which decides how long skew mis-scheduling stays the operator's problem.
- Whether cert-manager and SPIRE integrate with PodCertificateRequest or position against it.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+14
- Incentives62
- Confidence68
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [2]
2025 began with Kubernetes v1.33 (Octarine: The Color of Magic), continued with v1.34 (Of Wind & Will), and closes with v1.35.
- [3]
Kubernetes v1.35 consists of 60 enhancements, including 17 stable, 19 beta and 22 alpha features.
- [4]
The release announcement states there are also some deprecations and removals in this release and tells readers to make sure to read about those; the highlights do not enumerate them.
- [5]
Kubernetes has graduated in-place updates for Pod resources to General Availability, allowing users to adjust CPU and memory resources without restarting Pods or Containers.
- [6]
Previously such modifications required recreating Pods, which could disrupt workloads, particularly for stateful or batch applications.
- [7]
The in-place Pod resource update work was done as part of KEP #1287, led by SIG Node.
- [8]
When control planes enable new features but nodes lag behind, which the Kubernetes skew policy permits, the scheduler can place pods requiring those features onto incompatible older nodes.
- [9]
The node-declaration features framework has a Node report the features it supports, publishing them to the control plane via a new .status.declaredFeatures field, which kube-scheduler, admission controllers and third-party components can use to enforce scheduling and API validation constraints.
- [10]
The node-declaration features framework is an alpha feature in Kubernetes v1.35, active when the new alpha feature is enabled.
- [11]
The node-declaration features work was done as part of KEP #5328, led by SIG Node.
- [12]
Previously, delivering certificates to pods required external controllers (cert-manager, SPIFFE/SPIRE), CRD orchestration and Secret management, with rotation handled by sidecars or init containers.
- [13]
The kubelet now generates keys, requests certificates via PodCertificateRequest, and writes credential bundles directly to the Pod's filesystem.
- [14]
The kube-apiserver enforces node restriction at admission time, which the release describes as eliminating the most common pitfall for third-party signers: accidentally violating node isolation boundaries.
- [15]
The native workload identity feature enables pure mTLS flows with no bearer tokens in the issuance path.
- [16]
The native workload identity work was done as part of KEP #4317, led by SIG Auth.
- [17]
Among the improvements now stable following v1.35, the trafficDistribution field for Services gains a PreferSameNode option that strictly prioritises endpoints on the local node if available, falling back to remote endpoints otherwise.
- [18]
The 17 stable features are 28 percent of the 60 enhancements in v1.35.
- [19]
41 of the 60 enhancements in v1.35, or 68 percent, arrive as beta or alpha rather than stable.
- [20]
Three named Kubernetes releases shipped during 2025, an average of one every four months.
Sources
1 independent publisher whose own reporting we read for this story.
- kubernetes.ioKubernetes v1.35: Timbernetes (The World Tree Release) | Kubernetes
1 article · August 23, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
Entities
- KubernetesFollow
- kubeletFollow
- kube-apiserverFollow
- kube-schedulerFollow
- SIG NodeFollow
- SIG AuthFollow
- cert-managerFollow
- SPIFFE/SPIREFollow