Kubernetes v1.37.0-beta.0 is live!

12 views
Skip to first unread message

Agustina Barbetta

unread,
Jul 20, 2026, 7:31:45 PM (2 days ago) Jul 20
to kubernetes-announce, dev
Kubernetes Community,

Kubernetes v1.37.0-beta.0 has been built and pushed using Golang version 1.26.5.

The release notes have been updated in CHANGELOG-1.37.md, with a pointer to them on GitHub:


v1.37.0-beta.0

Downloads for v1.37.0-beta.0

Source Code

filename sha512 hash
kubernetes.tar.gz f9d5a3e658affdbb2a238fccd85c8761386302ee46d262b4440fd2813f4676bac02f3549c09f29b9a598905d461ab559d41a349ce8c2fb3528e8760bd5969ffc
kubernetes-src.tar.gz 2e2ac730f6f5a2d63986e2939d353f10c10c44293e6cd0de53bcb2796ca7f89d3b0cf8363063241ddf1f1ef997f9e01433ba4e98e04886b2c9c9fa363361faff

Client Binaries

filename sha512 hash
kubernetes-client-darwin-amd64.tar.gz bb36f64627b9b851cf3bba0ce60d3577578c4757140e027085e02f13e30a9cc1a13fb90c29083b6ba1b4da1f4e2e698f70d0fdf0ff11827ce34b8b112646959f
kubernetes-client-darwin-arm64.tar.gz 725cf0cae1295786726be1c8b461248923afdcdedb8b83c4a457da3355dff66e7205c57ad9f721fde143e9f0f4b59fd4c4fd628e347f3ce2e55fc2fb2d08dbe0
kubernetes-client-linux-386.tar.gz 307bcdab8a705384e1d5868d4aed8c318b72010f62818cc68812c51fb00f2e49ff3497f3a64cd56269cd669908525156cacc2076dd8d1d5c4892b137ccb740da
kubernetes-client-linux-amd64.tar.gz b880a28e51d2ea2b253ae8e82e6f94072db7cadec88235ee06fcec989de09d06ad0ff3263c470d21406f0ee527d92b00131a82695860ec2e609d7619fe239af2
kubernetes-client-linux-arm.tar.gz 5bb4f9b63109a893c6a72b636be467a2c46dc90a5e7ff5d39e34aaa8950d6519bd8c371295f4819e66ff4cc120878afca03ee70360597bdd861a5882d3b66d18
kubernetes-client-linux-arm64.tar.gz f490a05e9234ccc2d8237d877849796e8b60b7c0184d8c4eea117dabc719407a732b3081bee5771540df7ff41f463a780f7f9f13f54ed036904220339569e709
kubernetes-client-linux-ppc64le.tar.gz 6b066f0837355174a3399f8c2552a34e67fa6d410a21e094ab444074fc263f82a5c890735576f79fc726d3fd3c9ba031fc463ace962d2ead6e2a5a03cf5065be
kubernetes-client-linux-s390x.tar.gz aa8f6f9179a24eb1557840c23c5240210cd8c2125e700aa3293de45f90e2e2c971042e051a060c33b5bdf6bb656bbb8de38686ddb1aac53d210439602f46939e
kubernetes-client-windows-386.tar.gz 661a31a0ed6f21f739dcb18444c19b64c7716ea87e273d56c7e19bbb17ceb29994943bb7f636c6728bb609061b039ad113a11d8f3808e947dc728cd28d0c8794
kubernetes-client-windows-amd64.tar.gz 1370fe6493054554d4951569203fc9230f9f30c4843a111089792378f1f6932f2203b65b3338e43a3729cb428813d24462e9b25554e0f8a7bea2e67bd2a91189
kubernetes-client-windows-arm64.tar.gz 6419aa5600a0fe4f8860ed7f126369aa5feed2860fa5b1cfdcb990df99154c00512dcd4c4198b343f5e1475f2d78fd59657b9f905e5bcf3f7e9724a42402fbcc

Server Binaries

filename sha512 hash
kubernetes-server-linux-amd64.tar.gz a74d754bfa7e69493cdf1a0357306e8a5e5107f7eaff0c560677eff5fcb56d9a39192dbc227fc14148c7f48b61993c063bf90fcbd191a43455d2d85aa0a0f4ef
kubernetes-server-linux-arm64.tar.gz 6d5961b97bba55d2a927acaba7fd327fc9a3916f1625e79b1a32229d3a8db669616b9adb0ba0a058e9ab1c8809893a20edee4355d6c5f4c8c670acd38de41b71
kubernetes-server-linux-ppc64le.tar.gz d9956ea921a70bc1c75bb32b9390c3158a69e772ffbbf9f5bd3954975038c018b9bbd4417a8da59e0cbe0a9629b259ae3644e7ab73837e40d61495c620bee037
kubernetes-server-linux-s390x.tar.gz 2441f5906fd18c072977082a1706292ca3431935e85ba3a65d0aa629afec4b5a470981f98ceb914d70759cd8560c5be695c176a40c776e0e9c946967f9a10380

Node Binaries

filename sha512 hash
kubernetes-node-linux-amd64.tar.gz da044a30d92e9a3c15ee678a9e10a36b09188a117e6fccd67a3f993ee514f7a07e52a2768c02a90f7f9f8e78e8398b6033aa60628a126df48ece559dfef95381
kubernetes-node-linux-arm64.tar.gz 31adffb8b051e742bbd8fcb54687aa9abbc6af4da597f9a6f589720beebfa091939fca81959b3c44c413ecdb3b5f549a7a7751df82f7085d156611332656011c
kubernetes-node-linux-ppc64le.tar.gz 9a2d99718bc226b0ab6e47bfae3980d7e41678bb6c0eeb1d5fb8069f0f07a1229825b63bb979a19662c2efc07677cdc2df9b7fdbd255c9a8910c797f980e50c1
kubernetes-node-linux-s390x.tar.gz b30bd77b2b72fd3ab4778242deddd55bfb580973adbf3bfecaed46e816824cdf536c201e60132036e409fbd653c12e79168871018427215a002f28fc591fd60e
kubernetes-node-windows-amd64.tar.gz 0a404926c1017b06e3c7dd1c429031a3c51b0001256bfa77777a1c7198103938b814a54d76c93097abccf3276515ce0fc262354e7dd54ba67d2796e4d8e2e6a2

Container Images

All container images are available as manifest lists and support the described architectures. It is also possible to pull a specific architecture directly by adding the "-$ARCH" suffix to the container image name.

name architectures
registry.k8s.io/conformance:v1.37.0-beta.0 amd64, arm64, ppc64le, s390x
registry.k8s.io/kube-apiserver:v1.37.0-beta.0 amd64, arm64, ppc64le, s390x
registry.k8s.io/kube-controller-manager:v1.37.0-beta.0 amd64, arm64, ppc64le, s390x
registry.k8s.io/kube-proxy:v1.37.0-beta.0 amd64, arm64, ppc64le, s390x
registry.k8s.io/kube-scheduler:v1.37.0-beta.0 amd64, arm64, ppc64le, s390x
registry.k8s.io/kubectl:v1.37.0-beta.0 amd64, arm64, ppc64le, s390x

Changelog since v1.37.0-alpha.3

Changes by Kind

Dependency

  • Updated the default etcd version to 3.7.0 (#140333, @Jefftree) [SIG API Machinery, Auth, Cloud Provider, Cluster Lifecycle, Etcd, Node, Scheduling and Testing]

API Change

  • Add PreemptionPolicy field to PodGroupTemplate to define policy for workload-aware preemption (#140312, @ania-borowiec) [SIG API Machinery, Apps, Scheduling and Testing]
  • Add a new Recreate update strategy for StatefulSets, mirroring Deployments' Recreate strategy, which deletes all pods and waits for full termination before creating new pods according to podManagementPolicy. (#137187, @galal-hussein) [SIG Apps and Testing]
  • Added --concurrent-disruption-syncs to kube-controller-manager to configure the number of concurrent disruption controller workers. (#140014, @xigang) [SIG API Machinery, Apps, Auth and Testing]
  • Added the CompositePodGroup API into scheduling.k8s.io/v1alpha3. (#139596, @jdzikowski) [SIG API Machinery, Apps, Auth, Etcd, Node, Scheduling and Testing]
  • DRA consumable capacity: when a request allocated multiple devices, the DistinctAttribute constraint was not checked properly for each device. (#140600, @GunaKKIBM) [SIG API Machinery, Apps, CLI, Etcd, Network, Node, Release, Scheduling and Testing]
  • Fix DRA CapacityRequestPolicyRange to support fractional quantities in milli-scale. (#140161, @sunya-ch) [SIG API Machinery, Node and Scheduling]
  • Fix the overestimation of the pod's resource footprint for multi-container pods undergoing a resize. (#140047, @natasha41575) [SIG Node and Scheduling]
  • Fixed pod status validation for reported Linux container user UIDs so values above 2147483647 and up to the unsigned 32-bit UID limit are accepted. (#138574, @Kunalbehbud) [SIG Apps and Node]
  • Introduce new Node Lifecycle Conditions (#139993, @rthallisey) [SIG Apps and Node]
  • Introduces PodGroupPostFilter extension point to the scheduling framework. This replaces internal hardcoding for WorkloadAwarePreemption with a proper, configurable extension point for operating on PodGroups. (#139674, @GFilipek) [SIG Scheduling and Testing]
  • Kep-5304: make cdi spec version dynamic to avoid incompatible spec generation (#137699, @alaypatel07) [SIG Apps, Node, Scheduling and Testing]
  • Pod-level resources only determine the QoS when they include a resource request or limit. Empty pod-level resources ({}, {requests:{}}, or {limits:{}}) no longer affect QoS calculation. (#137150, @KevinTMtz) [SIG Apps, CLI, Node and Scheduling]
  • Promoted the HPAConfigurableTolerance feature gate to GA. (#140107, @jm-franc) [SIG API Machinery, Apps, Autoscaling and Testing]
  • Promoted the PersistentVolumeClaimUnusedSinceTime feature gate to beta in v1.37 (enabled by default). PersistentVolumeClaims now report an Unused condition indicating how long a PVC has been unused, helping identify candidates for cleanup. (#139620, @RomanBednar) [SIG Apps]
  • The ClusterTrustBundle and ClusterTrustBundleProjection features move to stable and enabled by default, along with the ClusterTrustBundle API. (#139437, @stlaz) [SIG API Machinery, Apps, Architecture, Auth, Etcd, Node, Storage and Testing]
  • The metrics.k8s.io API is promoted from v1beta1 to v1 without any modifications (#139223, @tico88612) [SIG Instrumentation]
  • The unsafe corrupt object deletion feature now supports dry-run mode, allowing administrators to test deletion operations safely before execution. (#134037, @ibihim) [SIG API Machinery and Testing]
  • When the alpha feature gate InPlacePodVertifcalScalingSchedulerPreemption is enabled, the scheduler preempts lower-priority pods to make room for the Deferred in-place pod resizes of higher-priority pods. (#140000, @natasha41575) [SIG API Machinery, Apps, Node, Scheduling, Storage and Testing]

Feature

  • Added a --max-depth flag to kubectl explain --recursive to limit the depth of nested fields displayed in the output. (#138809, @shady0503) [SIG CLI and Testing]

  • Added metrics related to workload preemption in alpha stability behind WorkloadAwarePreemption feature gate. (#139373, @brejman) [SIG Instrumentation and Scheduling]

  • Added validation to PodGroup scheduling which, if the feature gate PodGroupPreemptionPolicy is enabled, ensures that preemption policies of the evaluated pods match the priority of the PodGroup. (#140359, @ania-borowiec) [SIG Scheduling and Testing]

  • Admission webhooks now skip the auth/authz virtual resources (e.g. tokenreviews, subjectaccessreviews) that ValidatingAdmissionPolicy/MutatingAdmissionPolicy already exclude, via the new ExcludeAdmissionWebhookVirtualResources feature gate (beta, on by default; opt out to restore the old behavior). (#140019, @BenTheElder) [SIG API Machinery and Testing]

  • After successful scheduling of a podgroup, its remaining unscheduled pods are requeued directly to active queue rather than backoff queue. These pods preserve their old timestamp so they have precedence in scheduling unless a higher priority entity comes in between. (#139613, @iomarsayed) [SIG Scheduling and Testing]

  • Bump coredns to 1.14.6 (#140497, @yashsingh74) [SIG Cloud Provider and Cluster Lifecycle]

  • DRA: Add resource.kubernetes.io/numaNode as a standard device attribute with sysfs-based helper functions for DRA drivers (KEP-6072). (#139929, @johnahull) [SIG Node]

  • Enhanced Pod-by-Pod preemption to support PodGroups as preemption victims. (#137981, @vshkrabkov) [SIG Scheduling and Testing]

  • Graduate scheduler metrics scheduler_plugin_execution_duration_seconds and scheduler_scheduling_algorithm_duration_seconds from ALPHA to BETA stability. (#138176, @abhay1999) [SIG Instrumentation, Scheduling and Testing]

  • Gradute NativeHistograms feature to beta (#140124, @richabanker) [SIG Architecture and Instrumentation]

  • Kubernetes is now built with Go 1.26.5 (#140576, @palnabarun) [SIG Release and Testing]

  • PostFilter plugins are no longer run during PodGroup cycle for pods from PodGroup. Instead the PodGroupPostFilter is run if the whole PodGroup is unschedulable. (#140412, @Argh4k) [SIG Scheduling and Testing]

  • The EtcdRangeStream feature gate is now enabled by default (Beta). (#140085, @Jefftree) [SIG API Machinery]

  • The ManifestBasedAdmissionControlConfig feature is now beta and enabled by default. (#140559, @BenTheElder) [SIG API Machinery]

  • We are adding two new metrics:

    "queued_entities": This metric tracks the current entities (individual pods or podgroups) in queues (active, backoff, etc..) of scheduler.

    "queue_incoming_entities_total": This metric tracks total number of entities (individual pods or podgroups) added to scheduling queues (active, backoff, etc..). (#139840, @iomarsayed) [SIG Instrumentation, Network and Scheduling]

  • When workload aware preemption finds a placement for the PodGroup, the status of the PodGroup will contain "pod group preemption found a placement for podgroup, preempting <victim_count> victims" message. (#140311, @Argh4k) [SIG Scheduling and Testing]

  • Workload-Aware Preemption now runs only one scheduling attempt, on a cluster with all potential victims removed. This can lead to a suboptimal preemption victims choice at the cost of significant performance improvement. (#139980, @Argh4k) [SIG Scheduling and Testing]

Documentation

  • Kube-proxy: Corrected the --metrics-bind-address flag documentation by removing the incorrect claim that setting it to an empty string disables the metrics server. (#138940, @kairosci) [SIG Network]

Bug or Regression

  • DRA consumable capacity: fixed a scheduler bug where a ResourceSlice with a device capacity requirement stored as a high-precision decimal (a fine-grained fractional value, or a value above the int64 range) could have that ResourceSlice mutated in place in the informer cache during allocation, which could then make allocation fail incorrectly for subsequent pods. (#140702, @weizhoublue) [SIG Node]
  • DRA drivers might not have re-created ResourcSlices that were deleted by someone else, depending on timing (driver updates, then someone else shortly afterwards deletes them). (#140063, @pohly) [SIG API Machinery, Apps, Node and Testing]
  • DRA partitionable devices: if a DRA driver published counters which were outside of the normal int64 range, the counters in the informer cache got mutated and allocation may have failed incorrectly for future pods. (#140518, @weizhoublue) [SIG Node]
  • Fix bug in CEL where quantity.Add would mutate the receiver. (#140556, @jpbetz) [SIG API Machinery]
  • Fix: Prevent CEL Admission Panics on Three-Key Typed Map Lists (#140386, @weizhoublue) [SIG API Machinery]
  • Fixed CEL for "set" and "map" lists: equality (==) no longer matches lists containing duplicates, and concatenation (+) now correctly applies set/map merge semantics to appended elements. (#140293, @jpbetz) [SIG API Machinery]
  • Fixed DRA scheduling bugs where the structured allocator mis-counted a device's shared counters while exploring candidates: it could keep a counter reserved after rejecting or backtracking a candidate, or drop a shared device's in-use marker so a later share was charged the counter twice. Either way the allocator could treat a counter set as exhausted and leave a pod pending on a node that could satisfy it. This affected the allocator used by the default feature configuration. (#140431, @thc1006) [SIG Node]
  • Fixed kubectl cluster-info dump --output-directory creating world-readable dump files. Files are now created with mode 0600 and kubectl-created directories with mode 0700, since dumped pod logs can contain sensitive data. (#140189, @ashvinctrl) [SIG CLI and Security]
  • Fixed a DRA scheduling bug where the structured allocator keyed its shared-counter caches by pool name alone, so two drivers publishing a pool with the same name on a node could use each other's counter definitions and incorrectly accept or reject device allocations in the second driver's pool. (#140435, @thc1006) [SIG Node]
  • Fixed a bug where burstable pod memory.low (soft protection) was ineffective because the parent cgroup lacked ancestor coverage required by the kernel's hierarchical protection model (#140267, @sohankunkerkar) [SIG Node and Testing]
  • Fixed a case where Pods from PodGroup that evaluated successfully during the pod group cycle that eventually failed would have NNN set from this evaluation instead of from Pod Group preemption. (#140590, @Argh4k) [SIG Scheduling]
  • Fixed a concurrent map read/write data race condition in handleSchedulingFailure during scheduling failure handling. (#140623, @SparshGarg999) [SIG Scheduling]
  • Fixed a panic (integer divide by zero) and incorrect validation in ResourceSlice admission when a DRA consumable-capacity validRange step, min, max or default is negative or larger than 9223372036854775807. (#140666, @thc1006) [SIG Node]
  • Fixed a panic in the kube-controller-manager that could crash it when a StorageVersionMigration targeted a resource not present in the RESTMapper (for example, a CRD deleted while its migration was pending). (#140586, @zwindler) [SIG API Machinery and Apps]
  • Fixed kube-apiserver hanging forever on SIGTERM when its identity Lease cannot be created (e.g. hostname longer than 63 bytes). (#140241, @camilamacedo86) [SIG API Machinery]
  • Fixes a regression in the retry of deferred resizes that occurred due to a change in the way a pod resource footprint is calculated. (#140646, @natasha41575) [SIG Node and Scheduling]
  • KEP-5491: Fixed a bug where DRAListTypeAttributes feature gate enabled could fail to allocate devices even when a valid combination exists. This occurred when the allocator needed to backtrack during allocation of multiple devices with a matchAttribute constraint using list-type attribute values. (#140325, @everpeace) [SIG Node and Scheduling]
  • Kube-proxy now exits when the watched Node's IPs change or when the Node object is deleted, allowing it to restart with updated node networking state. (#138183, @abishekgiri) [SIG Network]
  • Kubectl run: error messages for invalid --restart and --image-pull-policy values now list the accepted values (#138188, @ogormans-deptstack) [SIG CLI]
  • Kubelet/DRA: fixed a race where PrepareResources could attach a pod to a ResourceClaim that was concurrently being unprepared, leaving the pod running with unprepared devices. (#140527, @bart0sh) [SIG Node]
  • Kubelet: fixed device health updates being applied to the wrong pod's status when device plugins for different resources expose devices with identical IDs. Affected pods now reflect device health changes immediately instead of waiting for the next periodic pod sync. (#140323, @harche) [SIG Node]
  • The scheduler is less likely to get stuck scheduling large PodGroups when member Pods transiently fail to bind to Nodes (as is common when many Pods share the same ResourceClaim). (#140478, @nojnhuh) [SIG Scheduling]
  • Updated the version of the nft binary in the kube-proxy image to nftables 1.0.6.1, to fix problems resyncing kube-proxy in nftables mode on systems containing rules created by recent versions of nftables. (#140405, @danwinship) [SIG Testing]

Other (Cleanup or Flake)

  • DRA: when a Pod is a member of a PodGroup, the ResourceClaim controller will no longer create ResourceClaims from ResourceClaimTemplates referenced by the Pod unless the DRAWorkloadResourceClaims feature gate is enabled. This prevents the controller from generating a ResourceClaim for the individual Pod in case it was intended to be generated for the PodGroup. (#138363, @nojnhuh) [SIG API Machinery, Apps, Node, Scheduling and Testing]
  • Improve memory usage of kube-proxy by dropping the .metadata.managedFields field that kube-proxy doesn't require. (#140056, @adrianmoisey) [SIG Network]
  • MutatingAdmissionPolicy and MutatingAdmissionPolicyBinding are now stored in etcd as admissionregistration.k8s.io/v1 (#137375, @Jefftree) [SIG API Machinery, Etcd and Testing]
  • Server-side apply now correctly drops status changes when tracking field owership for PodGroup, PodCompositeGroup and PodCertificateRequest. (#140654, @jpbetz) [SIG API Machinery, Auth, Scheduling and Testing]

Dependencies

Added

Changed

Removed

Nothing has changed.



Contributors, the CHANGELOG-1.37.md has been bootstrapped with v1.37.0-beta.0 release notes and you may edit now as needed.



Published by your Kubernetes Release Managers.

Reply all
Reply to author
Forward
0 new messages