Skip to main content

hetzner-apalla-1-36-v5

Supported
Latest

Last updated

Release Notes

Security

  • Security: node-image OS packages refreshed — kernel 6.18.49, OpenSSL 3.5.8, expat 2.8.4, QEMU guest agent 11.0.4.

Fix

  • Storage: Hetzner CSI driver 2.23.0 — fixes a crash when listing volumes in a project that already has volumes.
  • Networking: syself-node 0.1.6 — in case a control plane is down, connections from kubelets to other other - healthy - control planes stay open.
  • Compute (bare metal): the receive page size on Broadcom NICs is now always initialised, fixing a driver-level networking issue.

What’s Included in This Stack

Components packages and containers running on that node.

  • etcdctl etcdctl, the command-line client for administering the etcd key-value store. 3.6.8 CLI
    • 14
      • C 0
      • H 0
      • M 0
      • L 0
    • T 14
    Open all CVEs for etcdctl
  • etcd_image Container image of etcd, the key-value store backing the Kubernetes control plane. 3.6.8-0 Container
  • kube_apiserver The Kubernetes API server — the front door and central hub of the control plane. 1.36.4 Container
  • kube_controller_manager Runs the core Kubernetes controllers that reconcile cluster state to the desired spec. 1.36.4 Container
  • kube_scheduler Assigns newly created pods to the most suitable nodes in the cluster. 1.36.4 Container
  • kubegate Syself Kubegate: secure access to the cluster's control plane. v0.0.7 Container
  • kernel The Linux kernel — the core of the OS that runs every container and drives the hardware. 6.18.49 from 6.18.45 Kernel
    • 1480
      • C 0
      • H 0
      • M 0
      • L 0
    • T 1480
    Open all CVEs for kernel
  • intel_microcode Intel CPU microcode applied at boot to patch processor errata and hardware security issues. 20260812 Firmware
    • 11
      • C 0
      • H 0
      • M 0
      • L 0
    • T 11
    Open all CVEs for intel_microcode
  • linux_firmware Vendor firmware blobs the kernel loads for network, storage and other hardware devices. 20260810 Firmware
    • 5
      • C 0
      • H 0
      • M 0
      • L 0
    • T 5
    Open all CVEs for linux_firmware
  • grub The GRUB bootloader that loads and starts the Linux kernel when the node powers on. 2.14 CLI
    • 8
      • C 0
      • H 0
      • M 0
      • L 0
    • T 8
    Open all CVEs for grub
  • glibc The GNU C library — the core system library nearly every program links against. 2.43 Library
    • 21
      • C 0
      • H 0
      • M 0
      • L 0
    • T 21
    Open all CVEs for glibc
  • libgcc GCC runtime support library providing low-level routines that compiled programs depend on. 14.2.0-19 Library
    • 1
      • C 0
      • H 0
      • M 0
      • L 0
    • T 1
    Open all CVEs for libgcc
  • zlib Widely used data compression library (DEFLATE/gzip) linked by many system components. 1.3.2 Library
    • 2
      • C 0
      • H 0
      • M 0
      • L 0
    • T 2
    Open all CVEs for zlib
  • zstd Zstandard compression library offering fast, high-ratio compression used across the system. 1.5.7 Library
  • libxcrypt Modern password-hashing library providing the crypt() functions used for local logins. 4.4.38 Library

What’s a Cluster Stack?

A Cluster Stack pins everything your cluster runs to one tested release: the Kubernetes version, the node image, and the in-cluster components like CNI and DNS. Syself builds and tests them together, so your team never has to check hundreds of moving parts by hand.

Each stack fits the provider, node role, and hardware it runs on. Syself also tests the upgrade paths between Cluster Stack releases, so a cluster moves forward safely over time.

  • Tested Together

    Syself tests the Kubernetes version, the node image, the in-cluster components, and every upgrade path together, then ships them as one release.

  • Applied Per Node

    Each Cluster Stack fits the infrastructure it runs on. The provisioner installs only what a node needs for its role and its hardware, nothing more.

  • Continuously Maintained

    Syself tracks versions, vulnerabilities, fixes, and upgrade paths. Releases on the same minor keep behavior stable; a new minor adds new Kubernetes features.

Go deeper on how Cluster Stacks are built, how clusters move between versions, and how Syself runs them day to day.

See All