Skip to main content

Kubernetes 1.36

Supported
Latest
Released
Latest Cluster Stack
1-36-v7
Last Updated
Support Ends
Latest release: 1-36-v7

All Cluster Stack 1.36 Releases

  1. 1-36-v7

    1-36-v7
    Latest

    No vulnerabilities Last scanned yesterday

    Security

    • Security: node-image kernel updated to 6.18.54 and OS packages refreshed — Intel microcode 20260925, Linux firmware 20260916, containerd 2.3.6, crun 1.30.1, runc 1.5.2, open-iscsi 2.1.13, PAM 1.7.3, expat 2.8.5, libtirpc 1.3.8, and the CA bundle.

    Update

    • Platform: Kubernetes 1.36.4 to 1.36.5.
    • Networking: Cilium 1.20.2 (agent, operator, envoy).
    • Compute: NVIDIA driver 595.104.02.
    • Time zone data updated to 2026d.
    17 component updates
    NameVersion
    ca_bundle2026-09-25 from 2026-08-13
    cilium1.20.2 from 1.20.1
    cilium_envoyv1.37.6-1789133542-cbec91f666af0bf742da986d43832932dbb26b82 from v1.37.5-1786810558-766ccfb37260a43e9d228837aa84ce3faf9f64e7
    cilium_operator1.20.2 from 1.20.1
    containerd2.3.6 from 2.3.4
    crun1.30.1 from 1.29.1
    expat2.8.5 from 2.8.4
    intel_microcode20260925 from 20260812
    kernel6.18.54 from 6.18.49
    kubernetes1.36.5 from 1.36.4
    libtirpc1.3.8 from 1.3.7
    linux_firmware20260916 from 20260810
    nvidia_driver595.104.02 from 595.91.07
    open_iscsi2.1.13 from 2.1.12
    pam1.7.3 from 1.7.2
    runc1.5.2 from 1.5.1
    tzdata2026d from 2026c
  2. 1-36-v6

    1-36-v6

    No critical or high vulnerabilities Last scanned yesterday

    Fix

    • GPU nodes: node image now ships the NVIDIA GSP firmware, so Turing and newer cards (RTX 4000 SFF Ada, RTX 6000 Ada, RTX PRO 4000 Blackwell, RTX PRO 6000 Blackwell i.e. every Hetzner GEX server) initialize correctly and show up as allocatable nvidia.com/gpu devices.
  3. 1-36-v5

    1-36-v5

    No critical or high vulnerabilities Last scanned yesterday

    Security

    • Security: node-image OS packages refreshed — kernel 6.18.49, OpenSSL 3.5.8, expat 2.8.4, QEMU guest agent 11.0.4.

    Fix

    • Storage: Hetzner CSI driver 2.23.0 — fixes a crash when listing volumes in a project that already has volumes.
    • Networking: syself-node 0.1.6 — in case a control plane is down, connections from kubelets to other other - healthy - control planes stay open.
    • Compute (bare metal): the receive page size on Broadcom NICs is now always initialised, fixing a driver-level networking issue.
    6 component updates
    NameVersion
    expat2.8.4 from 2.8.3
    hcloud-csi-driverv2.23.0 from v2.22.1
    kernel6.18.49 from 6.18.45
    openssl3.5.8 from 3.5.7
    qemu_ga11.0.4 from 11.0.3
    syself-nodev0.1.6 from v0.1.5

Syself New Features And Changes

Syself Kubernetes 1.36 introduces the next generation of Syself cluster stacks, built around a new from-source Syself Linux node image. It adds stronger supply-chain evidence, tighter security defaults, and a more reliable cluster lifecycle across Hetzner cloud and bare-metal.

Read full release note
Syself Linux node image

Syself Linux Node Image

An immutable, reproducible node image built from source, the same on every server you run.

Read more

KubeGate Integration

KubeGate is Syself's own policy layer in front of the Kubernetes API server. It checks every request, so API access is controlled and auditable.

Read more

Syself Tunnel

A secure reverse tunnel between nodes and the control plane. The API server reaches kubelets and pods through it, so nodes never open extra ports to the outside.

Read more

Faster provision time

We cut down the provisioning time for a single server from 6 min to 3 min.

Read more

Syself Resilience Proxy

Keeps worker nodes connected to Kubernetes when the control-plane load balancer fails. It reroutes kubelet traffic to a healthy control-plane node on its own, with no one paged.

Read more

Enhanced Audit Coverage

Captures security-relevant activity across the operating system, the Kubernetes API, and the API access layer. It records the real client identity behind each action, so the audit trail is accurate and hard to tamper with.

Read more

Syself Health

The on-node Syself agent that monitors node health, reports node problems, and keeps node metadata available for Syself networking services.

Read more

GPU Support Improvements

Reworked NVIDIA device plugin handling and GPU detection, so GPU nodes boot the node image cleanly.

Syself Log Collector

Collecting relevant node logs, service state, and debugging context directly from the Syself Linux node.

What Kubernetes 1.36 Shipped

What upstream Kubernetes shipped in this minor, now integrated and tested inside the Cluster Stack.

Read full release
In-Place Pod Resizing
Adjust a Pod's CPU and memory budget without a restart, so no redeploy and no dropped connections.
Pod-Level Resource Budgets
Set requests and limits once for the whole Pod, so sidecars and main containers share headroom instead of each reserving their own.
Resize Jobs Before They Run
Update CPU and memory requests on a suspended Job, then unsuspend. No more delete-and-recreate to fit your quota.
User Namespaces Now Stable
One field in your Pod spec maps container root to an unprivileged host user, so a breakout gains nothing.
Unprivileged Container Builds
ProcMount goes stable. Combined with user namespaces, nested container workloads no longer need a privileged Pod.
Hardware Faults in Pod Status
Device health surfaces directly in your Pod status, separating a failing device from a failing container image.
  1. Kubernetes 1.36 Cluster Stack 1-36-v7
  2. Kubernetes 1.35 Cluster Stack 1-35-v6
  3. Kubernetes 1.34 Cluster Stack 1-34-v12

From Cluster Stack 1-34-v1, the update path leads to 1-34-v12, and the upgrade path continues to 1-36-v7.

Automated Updates and Upgrades

Every change to a cluster's Kubernetes version comes through a Cluster Stack release, never a patch to a running node. An update keeps the cluster on the same Kubernetes minor version; an upgrade moves it to a newer one. Both run a tested, automated path.

Updates carry maintenance work: security patches, bug fixes, and component bumps that do not change how Kubernetes behaves.

Upgrades are where new Kubernetes behavior lands, along with new Syself features, API changes, and the larger compatibility shifts between minor versions.

Explore Tested Upgrade Paths
  • Cloud servers are replaced, bare-metal ones are reprovisioned
  • Kubernetes, the components, and the node image move together
  • Every node runs a tested stack version

Go deeper on how Cluster Stacks are built, how clusters move between versions, and how Syself runs them day to day.

See All