[sig-node] Code Freeze Exception Request for KEP-5996

8 views
Skip to first unread message

Vera Qin

unread,
Jul 21, 2026, 8:58:15 PM (10 days ago) Jul 21
to releas...@kubernetes.io, kubernetes-...@googlegroups.com, sig-...@kubernetes.io
Hello Release Team,

I would like to request a 4 calendar day code freeze exception for the following enhancement.

Enhancement name: KEP-5996 Support defaultPodSysctls in Kubelet

Enhancement status: alpha

SIG: Node

Additional time needed: 4 calendar days

Reason this enhancement is critical for this milestone:
KEP-5996 introduces native support for default Pod-level sysctls, providing a crucial mechanism for workload fine-tuning (such as net.* or kernel.* parameters). This capability will highly benefit users running specialized workloads that require kernel-level parameter tuning out-of-the-box, without sacrificing Pod isolation or relying on privileged init containers. Besides, introducing the off-by-default alpha feature in 1.37 allows us to gather essential community feedback, keeping the SIG-Node roadmap for safe and customizable kernel tunings on track.

Risks from adding code late:

The inherent risk of adding this code late is the potential for unforeseen regressions in the Kubelet's Pod admission pipeline where sysctls are bound. However, this risk is minimal and heavily mitigated because:

  • The logic is completely shielded by the off-by-default feature gate, so it does not affect existing clusters or workloads.
  • The changes are localized to Kubelet's sysctl handling layer and do not modify core orchestration logic.
Risks from cutting enhancement:
Cutting or postponing this enhancement delays a highly demanded feature, forcing users to prolong their reliance on suboptimal workarounds. These workarounds typically involve node-level configuration hacks that lower security boundaries and apply settings too broadly. Furthermore, delaying this feature slows down downstream adopters and managed Kubernetes services that have expressed interest in surfacing granular sysctl tuning to their users. 

Thank you for your consideration,
Vera Qin
Reply all
Reply to author
Forward
0 new messages