ACK release notes for Kubernetes 1.34

Updated at:

Alibaba Cloud Container Service for Kubernetes Kubernetes 1.34 brings new default node images, DRA GA, and kubelet TLS hardening.

Component versions

Supported core component versions for ACK clusters.

Core component

Version

Kubernetes

1.34.1-aliyun.1, 1.34.3-aliyun.1, and 1.34.10-aliyun.1

etcd

v3.5.21

containerd

2.1.6

CoreDNS

v1.11.3.5-5321daf49-aliyun

CSI

For latest versions of csi-plugin and csi-provisioner, see csi-plugin and csi-provisioner release notes.

CNI

Flannel v0.15.1.23-33d25c1-aliyun

Terway and TerwayControlplane: v1.15.0 or later

Major changes

  • From version 1.34, new node pools default to Alibaba Cloud Linux 3 Container-optimized unless you specify an OS image.

  • From version 1.34, in new clusters with the Terway network plugin and DataPath V2, kube-proxy no longer runs on Terway-active nodes. DataPath V2 uses eBPF to accelerate network access in shared ENI mode.

    This change applies only to newly created clusters.

  • From version 1.34, in ACK managed Pro clusters, serverTLSBootstrap and RotateKubeletServerCertificate are enabled by default for new standard and managed node pools.

    This enables automatic rotation and cluster-CA validation of kubelet server certificates, enhancing node security.

  • From version 1.34, the kubelet server no longer supports the TLS_RSA_WITH_AES_256_GCM_SHA384 and TLS_RSA_WITH_AES_128_GCM_SHA256 cipher suites. For upgraded clusters, this applies to new nodes only.

  • From version 1.34, you can no longer mark a node asunschedulableduring registration, and the set as unschedulable node pool option no longer takes effect. See kubelet: remove --register-schedulable flag #122384.

    Use node taints instead to prevent scheduling on newly registered nodes. Do not use node.kubernetes.io/unschedulable as the taint key.

    # Add a NoSchedule taint
    kubectl taint nodes <node-name> key=value:NoSchedule
    
    # Remove the taint
    kubectl taint nodes <node-name> key=value:NoSchedule-

Feature updates

  • The core functionality of Dynamic Resource Allocation (DRA) has graduated to General Availability (GA) and is enabled by default. Workloads specify device attributes to request resources; the scheduler places pods on matching nodes, and the device driver and kubelet configure access.

    Other DRA features have graduated to Beta and are enabled by default, allowing administrators to access in-use devices with limited permissions for monitoring and diagnostics, configure device allocation options at request time, and enable kubelet reporting on DRA resources.

  • The kubelet now supports short-term credentials for container image repository authentication, avoiding long-term credential risks. See Service Account Token Integration for Image Pulls Graduates to Beta.

  • The pod replacement policy for Jobs has graduated to GA. By default, replacements start when the old pod begins terminating, risking resource conflicts. Configure.spec.podReplacementPolicyto delay replacement until the old pod fully terminates, avoiding contention and unnecessary scaling.

  • RecoverVolumeExpansionFailure has graduated to GA. If a volume expansion fails due to an oversized PVC capacity request, reduce the request to recover.

  • Volume Attributes Classes has graduated to GA and is enabled by default. Define common volume parameters in aVolumeAttributesClassobject and reference it from a PVC to apply them.

  • The kubelet now refuses to start a static pod if referenced API objects, such as Secrets, ConfigMaps, PVCs, or ServiceAccounts, do not exist, preventing pods from entering an undefined state due to missing dependencies.

  • Optimizations for kube-apiserver stability and performance:

  • Version 1.34.3-aliyun.1 fixes an issue where DRA pods get stuck inTerminatingstate during deletion. See #133920.

New features

  • PodLevelResources has graduated to Beta. Set resource requests and limits at the pod level instead of per container, capping total consumption at pod limits. See Pod Level Resource Specifications.

    This feature is not supported on Windows nodes.
  • kubectl now supports a.kubercfile for user preferences by default. Unlike credential-bearingkubeconfig, it stores only non-sensitive client-side configurations. See Introduce kuberc.

  • ExternalServiceAccountTokenSigner has graduated to Beta, introducing the ExternalJWTSigner gRPC service for signing ServiceAccount tokens with an external key management solution instead of a local static key.

  • SchedulerAsyncAPICalls has graduated to Beta, enabling asynchronous API calls in kube-scheduler by default.

    This reduces scheduling latency from blocking API calls, prevents thread stalls from slow responses, and speeds up retries for unschedulable pods. See Asynchronous API calls during scheduling.

  • WindowsGracefulNodeShutdown has graduated to Beta and now supports graceful node shutdown on Windows nodes.

  • PreferSameTrafficDistribution has graduated to Beta. Set a Service's.spec.trafficDistributiontoPreferSameZoneorPreferSameNode to prioritize zone-local or node-local endpoints.PreferCloseis deprecated. See Traffic Distribution.

  • kubeletPSI has graduated to Beta, exposing Pressure Stall Information (PSI) metrics in the Summary API and as Prometheus metrics. See PSI Metrics for Kubernetes Graduates to Beta.

  • The CPU manager static policy now supports prefer-align-cpus-by-uncorecache to optimize workloads on processors with disaggregated uncore cache. See Introducing CPU Manager Static Policy Option for Uncore Cache Alignment.

References

Full Kubernetes 1.34 changelog: CHANGELOG-1.34 and Kubernetes v1.34: Of Wind Will (O' WaW)