Skip to content

Releases: Azure/AKS

Release 2026-09-04

Choose a tag to compare

@AllenWen-at-Azure AllenWen-at-Azure released this 09 Sep 05:19
034e301

Release Notes - 2026-09-04

Monitor the release status by regions at AKS-Release-Tracker. This release is titled v20260904.

Announcements of upcoming changes and retirements

  • Starting September 30, 2026, AKS will automatically migrate deprecated Availability Sets (VMAS) clusters to Virtual Machines node pools through the auto-upgrader. To control the migration timing, migrate before that date by using az aks update --migrate-vmas-to-vms.
  • Azure Linux with OS Guard for Azure Kubernetes Service (AKS) (preview) will be retired on December 10, 2026. Please transition to Azure Container Linux by that date. From now to December 9, 2026, you can continue to use Azure Linux with OS Guard (preview) without disruption. On December 10, 2026, AKS will no longer produce new Azure Linux with OS Guard node images or provide security patches, and you will not be able to create new node pools with Azure Linux with OS Guard. On March 10, 2027, AKS will remove all existing Azure Linux with OS Guard node images, which will cause scaling and remediation (reimage and redeploy) operations to fail.

Release notes

Kubernetes versions

  • Kubernetes Version 1.37 Preview is being rolled out.
  • Kubernetes patch versions 1.36.3, 1.35.7, and 1.34.10 are now available.

Features

Preview features

  • Existing clusters can now be converted to use a managed system node pool in supported regions after registering the required preview feature.
  • Node pools with an in-progress blue-green upgrade can now switch safely to the rolling upgrade strategy.
  • On-Demand Monitor, a new Cluster Health Monitor capability for node health checks and remediation, is available in preview.
  • AKS Hyperscale Configuration is now available in public preview. It lets customers running large AI, high-performance computing (HPC), batch processing, and enterprise workloads preprovision control plane capacity with H2, H4, and H8 scaling profiles. These profiles provide predictable Kubernetes API responsiveness, pod scheduling throughput, and cluster state management during scale-out, recovery, and traffic spikes.

Behavioral changes

  • The AKS release status site now includes Windows Server 2025 and no longer lists Windows Server 2019 or Windows Server, version 23H2 because AKS no longer produces VHDs for those versions. The AKS release status site now shows only the default VHD for each Windows version.
  • Starting with Kubernetes 1.37, LocalDNS is enabled automatically when the cluster networking configuration supports it. Clusters using bring-your-own CNI, network policy configurations that aren't supported, or an existing custom DNS configuration aren't changed.
  • AKS now rejects updates that attempt to remove IPv6 from an existing dual-stack cluster. Dual-stack to single-stack migration isn't supported.
  • New clusters using an HTTP proxy or Custom Certificate Authority now reject CA certificate content larger than 35 KB, preventing node bootstrap data from exceeding platform limits. Existing clusters aren't affected.
  • Managed namespace creation now rejects names beginning with the reserved kube- or aks-istio- prefixes. This prevents naming conflicts with system-reserved namespaces and reduces the risk of customers accidentally interfering with Kubernetes or AKS-managed components.
  • When the Azure Policy add-on is enabled in AKS, Azure Policy's Kubernetes-native validation path is now enabled by default across regions.
  • Static Egress Gateway nodes now deregister from the load balancer before a node-image upgrade reimages them, reducing the risk of interrupted egress traffic.
  • AKS will return a validation error if you try to enable KMS encryption-at-rest for Kubernetes secrets handled by K8s API with customer managed key on 1.37 cluster with versioned Key Vault key IDs. This feature requires specification of versionless Azure Key Vault key ID.
  • On Kubernetes 1.37 and later, Azure Monitor managed service for Prometheus (ama-metrics) uses namespace-scoped access to Kubernetes secrets for PodMonitor and ServiceMonitor configurations. If your ServiceMonitor or PodMonitor uses basicAuth, bearerToken, or any other configuration that references Kubernetes secrets, you must configure namespace-scoped secrets access before upgrading your cluster to Kubernetes 1.37.

Bug fixes

  • Fixed an issue where the Microsoft Defender for Containers collector could prevent CSI volumes from detaching, leaving volumes terminating and blocking dependent pods from scheduling.
  • Fixed missing Windows node metrics caused by an incorrect exporter port configuration.

Component updates

  • Gatekeeper has been updated to v3.23.1, fixing excessive Validating Admission Policy reconciliation requests.
  • Managed Gateway API on Kubernetes 1.37 now uses the Gateway API v1.6.1 standard-channel CRD bundle, adding the graduated TCPRoute and UDPRoute resources.
  • Istio-based service mesh add-on revisions have been updated with security patches for ISTIO-SECURITY-2026-006:
  • Azure CSI drivers have been updated:
    • Azure File CSI driver to v1.33.10 on AKS 1.33, v1.34.9 on AKS 1.34, and v1.35.8 on AKS 1.35 and later.
    • Azure Disk CSI driver to v1.33.11 on AKS 1.33, v1.33.12 on AKS 1.34, and v1.34.6 on AKS 1.35 and later.
    • Azure Blob CSI driver to v1.27.10 on AKS 1.34 and later.
  • Cloud Provider Azure components have been updated to v1.33.17-2 and v1.36.5-2, including cloud-controller-manager, cloud-node-manager, and health-probe-proxy. The Kubernetes 1.36 cloud controller manager also includes Service Gateway support.
  • Cilium, Hubble Relay, and Advanced Container Networking Services FQDN policy images have been updated:
  • App Routing updated to version 0.2.28 with ingress-nginx bumped to v1.13.10-10 with additional validation for custom log formats.
  • AKS Windows images:
  • AKS Azure Linux images:
  • AKS Azure Container Linux images:
  • AKS Ubuntu images:
    • Ubuntu 22.04 - [202608.06.1](vhd-notes/aks-ubuntu/AKSUbuntu-2204/202608.06...
Read more

AppNet 2026-08-19

Choose a tag to compare

@SanyaKochhar SanyaKochhar released this 31 Aug 20:35
edf52ad

AppNet Release Notes - 2026-08-19

Azure Kubernetes Application Network (AppNet) — initial release notes covering changes since March 2026. AppNet is in public preview.

Announcements and retirements

  • The following AppNet versions have been retired and are no longer supported. If using self-managed upgrade mode, upgrade to a currently supported version (see Component updates) following the AppNet upgrade guide.
  • AppNet is now available in public preview in additional Azure regions, including Central US, East US, East US 2, Japan East, North Central US, North Europe, South India, Southeast Asia, West Central US, West US 2, and West US 3.

Bug fixes

  • AppNet now validates cluster prerequisites at member-join time and returns a clear, actionable error when a cluster is missing a required add-on (Microsoft Entra / AAD or the Managed Gateway API) or is running an AKS Kubernetes version below the minimum supported version, instead of failing opaquely later.
  • Clusters using AKS managed Gateway API no longer hit a CRD ownership conflict when joining a mesh; AppNet defers to the add-on-provided Gateway API CRDs.
  • Moving AppNet resources across resource groups or subscriptions is now blocked, as these move operations are not supported for AppNet.
  • Fixed an issue where the AppNet Managed Control Plane could fail to start after an intermediate certificate authority rotation, which could disrupt the entire mesh. Certificate rotation is now handled reliably.
  • Fixed an issue where multicluster east-west gateways were missing a required network label, causing cross-cluster traffic to fail.
  • Fixed an issue where member clusters using Microsoft Entra (managed identity) authentication were rejected on update, which had blocked member updates and version upgrades.
  • Fixed leftover mesh resources being orphaned on a member cluster after it left the mesh; these are now cleaned up.
  • Fixed member deletion being stuck in a retry loop when the underlying cluster had already been removed; already-deleted resources are now treated as a success.
  • Fixed an issue where AppNet Managed Control Plane diagnostic logs were missing from customer Log Analytics workspaces.
  • Fixed an issue where member join would retry when the cluster had a customer-fixable configuration error; it now fails fast and returns the validation error so it can be corrected.
  • Fixed an issue where failed AppLink and member operations returned a generic error instead of the specific reason; actionable failures, such as joining a cluster already connected to another AppLink, now explain what went wrong and how to resolve it.

Component updates

Release 2026-08-07

Choose a tag to compare

@allyford allyford released this 11 Aug 22:09
4e01af7

Release Notes - 2026-08-07

Monitor the release status by regions at AKS-Release-Tracker. This release is titled v20260807.

Release notes

Features

Preview features

  • Prepared Image Specification (PIS) is now available in public preview. PIS allows you to create preconfigured node images with your required container images and node customizations already applied, helping to reduce node startup times.
  • Customers using preview API version 2026-01-02-preview or later can associate a Capacity Reservation Group with an existing node pool. Zonal node pools perform a rolling cordon, drain, and reboot; non-zero regional pools must still be scaled to zero first.

Behavioral changes

  • For AKS clusters running Kubernetes 1.37 or later, SSH node access configuration changes now trigger an immediate node reimage. Use Node Disruption Policy to block the reimage or schedule it during a maintenance window.
  • For AKS clusters running Kubernetes 1.37 or later, changes to IMDS restriction, network-isolated bootstrap profile, or cluster outbound type now trigger an immediate node reimage. Use Node Disruption Policy to control when the reimage is allowed.
  • VMSS rolling upgrade concurrency for percentage-based maxSurge, maxUnavailable, and maxBlockedNodes is now calculated from current VMSS capacity and capped to the remaining VMs to upgrade, making partial upgrades match the remaining upgrade work. For more details see the documentation on rolling upgrade behaviors.
  • Updating a cluster from service principal authentication to managed identity now triggers node reimages across node pools. Configure Node Disruption Policy to control when reimages that can disrupt workloads are allowed.
  • AKS upgrade validation now rejects node pool upgrades where current pool size plus effective surge would exceed the VMSS 1,000-instance limit, preventing mid-upgrade Azure Compute failures. See 'Configure rolling upgrade settings' for more details.
  • Istio Gateway API deployments now set automountServiceAccountToken to false, improving the default security posture and unblocking environments with Azure Policies that require pods to disable service account token auto-mounting.
  • AKS now validates GPU MIG instance profile slice width against VM SKU capacity, preventing unsupported MIG profiles from being accepted on lower-capacity GPU SKUs.
  • The Application Gateway for Containers ALB add-on is now aligned with AKS minor versions. AKS automatically selects the compatible ALB controller image during cluster upgrades, reducing controller and feature-flag incompatibilities.
  • AKS now rejects Entra ID SSH configuration on AzureContainerLinux node pools because the extension is incompatible with immutable OS nodes and can make nodes unreachable.

Bug fixes

  • Fixed an AKS Automatic issue where App Routing on Kubernetes 1.36+ clusters could incorrectly default to NGINX instead of Istio/Gateway API mode during cluster creation.

Component updates

  • Node Auto Provisioning has been updated to Karpenter provider Azure v1.14.0, adding support for the Balanced consolidation policy to reduce node churn during consolidation.
  • Azure Policy add-on components were updated: Gatekeeper was bumped to 3.23.0, and Azure Policy add-on was bumped to 1.17.0.
  • Azure File CSI Driver has been upgraded to v1.34.7 on AKS 1.34 and v1.35.6 on AKS 1.35 and 1.36.
  • Azure Blob CSI Driver has been upgraded to v1.26.16 on AKS 1.33 and v1.27.9 on AKS 1.34 and later.
  • Azure Disk CSI Driver has been upgraded to v1.33.11 on AKS 1.34 and v1.34.5 on AKS 1.35 and 1.36.
  • Azure Monitor managed service for Prometheus add-on was updated to the 07-27-2026 release, including collector image updates and kube-state-metrics v2.19.1-2.
  • Container Insights has been upgraded to 3.6.0.
  • AKS Azure Linux images:
  • AKS Azure Container Linux images:
  • AKS Ubuntu images:

Release 2026-07-17

Choose a tag to compare

@alvinli222 alvinli222 released this 24 Jul 18:39
6c24387

Release Notes - 2026-07-17

Monitor the release status by regions at AKS-Release-Tracker. This release is titled v20260717.

Announcements of upcoming changes and retirements

  • On September 14, 2026, the preview property enableCustomCATrust will retire. After that date, the enableCustomCATrust=true node pool level field will no longer enable Custom Certificate Authority (CA). To avoid failures during scaling and certificate updates, update the impacted clusters and node pools and remove the preview property (--disable-custom-ca-trust).
  • AKS no longer supports creating node pools with Windows Server Annual Channel for Containers. Existing WSAnnual node pools are unaffected. For more information, see Windows Annual Channel retirement.
  • AKS no longer supports creating node pools or clusters with Flatcar Container Linux for AKS. Existing node pools are unaffected. For more information, see Flatcar preview retirement.
  • Customers using NVadsA10v5 or NCadsA10v4 node pools should verify they are running AKS node image version 202606.08.1 or later to maintain compatibility with updated NVIDIA v18.x host drivers. Clusters running older node images may encounter host/guest GPU driver compatibility issues and move into an unsupported configuration. For upgrade guidance, see the AKS node image upgrade documentation. See Github issue for more information.

Release notes

Kubernetes versions

Features

  • Artifact Streaming is now generally available. The feature allows you to stream container images from Azure Container Registry (ACR) to Azure Kubernetes Service (AKS). AKS only pulls the necessary layers for initial pod startup, reducing the time it takes to deploy your workloads.
  • Secure TLS bootstrapping is now enabled by default in westcentralus and eastasia. See regional updates on AKS GitHub Issues.
  • Secure Boot is now supported when using GPUs with Azure Linux OS.
  • Trusted Launch (vTPM and Secure Boot) can now be enabled and disabled on existing Linux node pools.

Preview features

  • Node Disruption Policy is now available in public preview. Node Disruption Policy lets you control when reimage-triggering operations are allowed so disruptive changes happen during windows you define.
  • Automatic zone placement is now available in public preview. Automatic zone placement in AKS dynamically selects the best set of availability zones for a node pool. You don't need to specify the zones manually for each region and VM SKU combination.
  • Prepared Image Specification is now available in preview. With AKS Prepared Image Specification, you can create preconfigured node images that include required container images and customizations ahead of time, enabling new nodes to start in a ready-to-run state.
  • Full caching mode for Ephemeral OS disks is now available in public preview. Full caching mode caches the entire operating system locally on the node, so that AKS can continue running even when remote storage is unavailable, significantly improving node resiliency while also delivering faster OS disk performance.

Behavioral changes

  • Starting with Kubernetes 1.37 (expected to be available in October 2026), Windows Server 2025 is the default and recommended OS SKU for new Windows node pools when no OS SKU is specified. For more information, see Windows best practices.
  • For Node Auto Provisioning enabled clusters, AKS now sets kubernetes.azure.com/mode: user on the default NodePool to help prevent pending system workloads from causing user node scale-up.
  • Node Auto-Provisioning enabled clusters now use an In-VM spot rebalancing signal, which allows for an improved spot eviction notification and proactive spot replacement.
  • AKS now rejects kube-proxy nftables mode at request time on clusters running Kubernetes versions older than 1.33, instead of accepting the request and silently falling back to iptables.
  • AKS now accepts mixed-case networkPlugin values for supported network plugin options during cluster creation.
  • The until field in upgrade override settings can now be set to any future date; AKS no longer rejects values more than 30 days in the future.
  • CNI Overlay Dual-Stack on Windows no longer requires a preview feature registration.

Bug fixes

  • Fixed an issue where API Server Authorized IP Ranges using only service tags were not enforced on API Server VNet Integration clusters.
  • Fixed Container Insights onboarding through AzureMonitorProfile so re-enabling Container Insights uses AAD auth and blocks unsafe Log Analytics Workspace changes under legacy auth.
  • Fixed an issue where clusters with an existing kube-proxy configuration object could not be updated unless KubeProxyConfigurationPreview was registered, even when the update did not change kube-proxy configuration.
  • Fixed App Routing Istio manifest values so resource requests and limits are populated correctly.
  • Fixed Static Egress Gateway VMSS model reconciliation so secondary egress IP configurations are preserved.
  • Re-enabled Cilium source IP verification on Cilium v1.17+ to restore dataplane anti-spoofing protection.
  • Fixed AKS support for Istio 1.30 mutating webhook configuration updates on Automatic clusters.
  • Fixed Node Auto Provisioning issue where load balancer deletion could block node provisioning.
  • Fixed Node Auto Provisioning to normalize CSI empty-zone topology value to regional zone "0".

Component updates

  • Istio revision asm-1-30 is now available with the Istio-based service mesh add-on. See supported Istio revisions for details.
  • Istio-based service mesh add-on revisions asm-1-28, asm-1-29, and asm-1-30 include security fixes for ISTIO-SECURITY-2026-005. Action required: restart your Istio workload pods to trigger re-injection of the newer istio-proxy patch version.
  • Istio-based service mesh add-on revisions have been updated:
  • Cilium, Hubble, and ACNS security agent images have been updated:
  • containerd has been updated from 1.7.32 to 1.7.33, including security fixes for CVE-2026-53488, CVE-2026-47262, and CVE-2026-34986.
  • Azure Monitor for Containers has been updated to 3.4.0.
  • Azure Karpenter Provider has been updated to v1.14.0.
  • Azure File CSI driver images have been updated to v1.35.5 on AKS 1.35 and 1.36.
  • App Routing operator has been updated to v0.2.26.
  • Updated Cluster Autoscaler images from v1.33.4 to v1.33.5, v1.34.3 to v1.34.4, and v1.35.0 to v1.35.1 for Kubernetes versions 1.33, 1.34, and 1.35, respectively.
  • kube-proxy image mcr.microsoft.com/oss/v2/kubernetes/kube-proxy has been updated:
  • kube-scheduler image mcr.microsoft.com/oss/v2/kubernetes/kube-scheduler has been updated across Kubernetes 1.34, 1.35, and 1.36 patch tags.
  • CoreDNS images have been updated (see CoreDNS upstream releases):
    • v1.11.3-30 to `v1.11...
Read more

Release - 2026-06-19

Choose a tag to compare

@shashankbarsin shashankbarsin released this 25 Jun 19:32
d77f611

Release Notes - 2026-06-19

Monitor the release status by regions at AKS-Release-Tracker. Vulnerabilities addressed by AKS releases can be tracked at CVE API viewer.

Announcements

  • Windows Server 2022 retirement has been extended. Please note the following updates: Windows Server 2022 retires on June 30, 2028. After that date, AKS will no longer produce new node images or provide security patches. After that date, you will not be able to create new node pools with Windows Server 2022 on any Kubernetes version. All existing node pools with Windows Server 2022 will be unsupported. Windows Server 2022 is not supported in Kubernetes version 1.37 and above. Starting on June 30, 2029, AKS will remove all existing node images for Windows Server 2022, meaning that scaling operations will fail. For more information on this retirement, see the Retirement GitHub issue.
  • Azure Service Mesh add-on revision asm-1-30 (estimated to release in early July) introduces the following changes to default behavior:
    • The default proxy redirection mechanism on new installations will change from privileged init containers to Istio CNI for revisions asm-1-30 and above. Clusters upgrading to asm-1-30 will not be impacted. Read more about Istio CNI. To retain the existing proxy redirection mechanism on new installations, see the instructions to disable Istio CNI.
    • Starting with asm-1-30, Istio ingress, egress, and gateway pods will have a weighted preference of 100 for nodes labeled azureservicemesh/istio.replica.preferred (previously 50) and 50 for AKS system nodes labeled kubernetes.azure.com/mode: system (previously 100).

Kubernetes versions

Features

Behavioral changes

Bug fixes

  • Fixed an issue where the aks-istio-system namespace was not exempted from the Azure Policy add-on when using application routing with the Gateway API in Istio mode. The namespace is now exempted, so the two features can be used together in the same cluster.
  • Fixed a bug where Multiple Standard Load Balancers rejected valid domain-prefixed label keys (for example, kubernetes.io/os) in node selectors. Label selector validation now follows standard Kubernetes semantics.

Component updates

  • The Istio-based service mesh add-on revisions asm-1-29 and asm-1-28 have been upgraded to patches 1.29.4 and 1.28.8, which address CVE-2026-47774. Restart your workload pods to trigger re-injection of the updated istio-proxy sidecar. For more information, see the Istio add-on upgrade guide.
  • Azure File CSI Driver has been upgraded to v1.35.4 on AKS 1.35 and 1.36.
  • Azure Blob Storage CSI driver has been upgraded to v1.26.14 on AKS 1.33 and v1.27.7 on AKS 1.34+. This update also fixes a regression where blob containers with a $ in the name (for example, $web) could not be accessed.
  • Azure CNI Powered by Cilium has been updated:
    • Cilium, Hubble, and ACNS images to v1.17.15 for Kubernetes 1.32.
    • Cilium, Hubble, and ACNS images to v1.16.19 for Kubernetes 1.31.
  • Cloud Provider Azure components (cloud-controller-manager, cloud-node-manager, and health-probe-proxy) have been updated to the June 18, 2026 release: v1.33.14 on AKS 1.33, v1.34.11 on AKS 1.34, v1.35.6 on AKS 1.35, and v1.36.2 on AKS 1.36.
  • AKS Windows images:
  • AKS Azure Linux images:
  • AKS Ubuntu images:

Release 2026-05-29

Choose a tag to compare

@dyu1208 dyu1208 released this 04 Jun 22:30
67669da

Release Notes - 2026-05-29

Monitor the release status by regions at AKS-Release-Tracker. Vulnerabilities addressed by AKS releases can be tracked at CVE API viewer.

Announcements of upcoming changes and retirements

  • Revision asm-1-27 of the Istio-based service mesh add-on has been deprecated. Please upgrade to revision 1.28 or later following the Istio add-on upgrade guide.
  • Windows Server Annual Channel for Containers retired on AKS on May 15, 2026. 5B is the last image that AKS will produce for Windows Server Annual Channel. After 5B, AKS will no longer produce new Windows Server Annual Channel node images or provide security patches. You will not be able to create new node pools with Windows Server Annual Channel. On May 15, 2027, AKS will remove all existing Windows Annual Channel node images, which will cause scaling and remediation (reimage and redeploy) operations to fail. Customers must migrate their Windows Server Annual Channel node pools to Long Term Servicing Channel (LTSC) by following the migration guide.
  • Windows Server 2019 retired on March 1, 2026 and its preview feature flag has been removed. You can expect the following impact: AKS no longer produces new node images or provides security patches. All existing node pools with Windows Server 2019 are unsupported. You will not be able to create new node pools in k8s 1.33+. Starting on April 1, 2027, AKS will remove all existing node images for Windows Server 2019, meaning that scaling operations will fail. For more information, see aka.ms/aks/ws2019-retirement-github.
  • Starting on June 8, 2026, AKS no longer supports Flatcar Container Linux for Azure Kubernetes Service (AKS) (preview). At that point, AKS will no longer produce new Flatcar Container Linux node images or provide security patches, and you'll be unable to create new node pools with Flatcar Container Linux. On September 8, 2026, AKS will remove all existing Flatcar Container Linux node images, causing scaling and remediation (reimage and redeploy) operations to fail. Migrate existing Flatcar Container Linux for AKS node pools to Azure Container Linux for AKS.
  • Managed system node pools are now generally available for AKS Automatic. New AKS Automatic clusters preconfigure managed system node pools by default. If you have an existing Automatic cluster without managed system node pools, you should recreate the cluster and migrate the workloads.
    • New AKS Automatic clusters now preconfigure LocalDNS mode to Required by default, including new node pools added to existing Automatic clusters. Existing node pools are unchanged.
    • Users with the Azure Kubernetes Service Contributor or Contributor role (with Microsoft.ContainerService/deploymentSafeguards/write permission) can now edit the excludedNamespaces field for deployment safeguards on Automatic clusters, controlling which policies apply to specific namespaces.
    • Deployment safeguards in Enforce mode and Pod Security Standards set to Baseline now allow pods on Automatic clusters to read the /var/log and /hostfs hostPath volumes (read-only), supporting log exporter scenarios.
    • Since AKS manages the system node pool on your behalf, AKS applies multiple layers of security restrictions:
      • New AKS Automatic clusters with managed system node pools now block customer-supplied SSH keys. Existing Automatic clusters with managed system node pools keep their existing keys but can't add new ones; clusters without managed system node pools are unaffected.
      • AKS Automatic clusters enforce a ValidatingAdmissionPolicy that blocks Services from setting spec.externalIPs, in line with the upstream deprecation of Service externalIPs. The policy applies immediately to Automatic clusters with managed system node pools, and to Automatic clusters without managed system node pools starting in Kubernetes 1.36.
      • AKS Automatic clusters with managed system node pools deny kubectl port-forward for objects and pods running on the managed system node pool.
      • AKS Automatic clusters with managed system node pools block read access to secrets in the kube-system namespace, except for known trusted identities. This mitigates the risk of attackers using the node bootstrap token to deploy pods on managed system node pools.
      • AKS Automatic clusters with managed system node pools enforce stricter authorization on MutatingAdmissionPolicyBinding resources by blocking unauthorized mutation operations (create, update, patch, delete).
      • For AKS versions prior to 1.36, AKS Automatic clusters with managed system node pools block all mutating admission resources (MutatingWebhookConfiguration, MutatingAdmissionPolicy, and MutatingAdmissionPolicyBinding) to reduce risk from unsafe mutations. Starting in AKS 1.36, Automatic clusters with managed system node pools allow a controlled subset of mutating admission configurations, provided they do not target the following sensitive resources: nodes, persistentvolumes, certificatesigningrequests, and tokenreviews.

Release notes

Kubernetes versions

Features

  • Windows Server 2025 is now generally available. You no longer need to register a feature flag to create Windows Server 2025 node pools. Windows Server 2025 node pools can be created in Kubernetes version 1.32+ with a minimum GA CLI version of 2.87.0.
  • Azure Container Linux is generally available (GA) as an OS option on AKS starting AKS v1.34. You can deploy ACL node pools in a new AKS cluster or add ACL node pools to your existing clusters. AKS also supports migrating existing node pools to ACL using in-place OS SKU migration or by creating new ACL node pools. For detailed migration steps, considerations, and rollback instructions, see Migrate existing nodes to ACL.
  • Azure Policy add-on now generates ValidatingAdmissionPolicies (VAP) for all customers. This enforces CEL-based policies inside the API server process for minimal latency and enables fail-closed enforcement.
  • AKS end of support notifications are now available. AKS automatically notifies you when your cluster's Kubernetes version is approaching or has passed its end of support date. Alerts are sent two weeks before end of support, one week before end of support, and then weekly after the support date passes—no monitoring add-on or maintenance window configuration required. Notifications are published to Azure Resource Graph and can be surfaced via email alerts or real-time Event Grid webhooks.

Preview features

  • Azure Linux 3.0 confidential VM (CVM) is now available in preview in Fairfax (US Gov) regions. Register the AzureLinuxCVMPreview feature to enable it.
  • In-place node pool resize is now available in preview. Resize the VM size of an existing VMSS-based node pool in place via az aks nodepool update --node-vm-size, without manually creating and migrating to a new node pool.
  • Automatic Pod Disruption Budget management is now available in preview. The AKS extension automatically creates PDBs for deployments without PDBs and temporarily scales up replicas to unblock node drain when a PDB would prevent eviction, then scales back down—reducing the need for manual interventi...
Read more

Release 2026-04-28

Choose a tag to compare

@alvinli222 alvinli222 released this 04 May 20:09
9c9791c

Release Notes - 2026-04-28

Monitor the release status by regions at AKS-Release-Tracker. Vulnerabilities addressed by AKS releases can be tracked at CVE API viewer.

Announcements

  • AKS-2026-0003: A Linux kernel algif_aead local privilege escalation vulnerability (CVE-2026-31431) lets a pod escalate to root on the underlying node — including non-root pods with no special capabilities. Affects AKS nodes running Ubuntu 20.04 FIPS, Ubuntu 22.04, Ubuntu 24.04, and Azure Linux 3.0. Azure Linux 2.0 (Mariner) and Windows nodes aren't affected. The mitigation is globally deployed in node image versions 202604.13.0 and 202604.24.0. New nodes and any node that goes through a node image upgrade are automatically protected. Existing nodes aren't patched in place — upgrade the node image, or, if your pool is already on 202604.24.0, apply the mitigation DaemonSet from the advisory immediately. See the AKS security bulletin for full details.
  • The Kubernetes SIG Network and the Security Response Committee announced the upcoming retirement of the Ingress NGINX project, with maintenance ending in March 2026. Application routing add-on users: Production workloads remain fully supported through November 2026. Migrate to the application routing Gateway API implementation for a Gateway API-based ingress traffic management experience.
  • On Long Term Support clusters, Premium-tier billing for a cluster begins only after the cluster's Kubernetes minor version exits community support and enters the long-term support window. Until then, the cluster continues to be billed at its existing tier rate. See the Long Term Support for more information.

Kubernetes Version

  • New Kubernetes patch versions are now available: 1.35.2, 1.35.3, 1.34.5, 1.34.6, 1.33.9, and 1.33.10.
  • AKS Kubernetes Long Term Support (LTS) version 1.29 is deprecated. Please upgrade your clusters to a supported version. Refer to AKS Support Calendar for more information.
  • AKS Kubernetes version 1.32 is now available only through Long Term Support. Use an LTS support plan for clusters that need to remain on 1.32, or upgrade to a supported standard-support Kubernetes version.

For deprecation, rollouts and patch timelines by region, please check the AKS-Release-Tracker.

Preview Features

  • Added preview support for AKS-managed NAT Gateway V2 outbound type in supported public Azure regions. Regions where StandardV2 NAT Gateway is not yet available remain excluded.
  • Customers can now preview customization of the default kube-reserved and hard eviction kubelet configuration through the existing custom node preview feature registration starting with the 2026-03-02-preview API.
  • Customers can now view the VM SKUs supported on AKS and available in their Azure subscription with the AKS List Available VM SKUs API, to create their clusters and/or add node pools.
  • AKS-managed GPU metrics are now supported by default in Azure Managed Prometheus and Dashboards with Grafana in Azure Monitor.
  • Customers can now set both MaxUnavailable and MaxSurge values to surge during node pool upgrades based on available capacity with Capacity Based Surge. With both configurations enabled, the MaxSurge value will be attempted first. If MaxSurge value is not available due to quota or capacity, a surge of 1 node will be attempted. If a surge of 1 is not available, MaxUnavailable configuration will be attempted for an in-place upgrade.

Features

  • Gateway API-based ingress for the application routing add-on is now generally available. The Kubernetes SIG Network and the Security Response Committee announced the upcoming retirement of the Ingress NGINX project, with maintenance ending in March 2026. Application routing add-on users: Production workloads remain fully supported through November 2026. Migrate to the application routing Gateway API implementation for a Gateway API-based ingress traffic management experience.
  • AKS Automatic clusters with managed system node pools can now migrate to AKS Standard clusters in additional regions after adding a system node pool.
  • Users can now configure spec.minReadySeconds in the Application Routing Gateway Parameters ConfigMap. This helps applications that need extra initialization time after passing their initial health check and can reduce disruption during rolling upgrades. See the related AKS GitHub issue.

Bug Fixes

  • Fixed an issue in the Istio-based service mesh add-on where the CRD installer could pull busybox from an unintended registry in AGC environments. This also removes non-Job Helm hooks from related resources to avoid a CRD installer race condition.
  • Fixed empty PUT reconcile failures with CustomRouteTableInvalidUpdateAttempt on clusters using bring-your-own route tables.
  • Added validation to prevent enabling Artifact Streaming with Pod Sandboxing, which is not supported.
  • Added AKS Automatic managed system node pool protection that blocks ClusterRoleBinding create or update requests when the roleRef targets configured privileged ClusterRoles, reducing the risk of privilege escalation through service account impersonation.

Behavioral Changes

Component Updates

Read more

Release 2026-04-02

Choose a tag to compare

@shashankbarsin shashankbarsin released this 09 Apr 02:49
b7dc6da

Release Notes - 2026-04-02

Monitor the release status by regions at AKS-Release-Tracker. Vulnerabiltiies addressed by AKS releases can be tracked at CVE API viewer.

Announcements

  • Starting on June 30, 2027, Azure Kubernetes Service (AKS) no longer supports or provides security updates for Ubuntu 22.04. To avoid disruptions, transition to Ubuntu 24.04 or later by that date. Between now and June 30, 2027, you can continue to use Ubuntu 22.04 on AKS without disruption. If you don't migrate by June 30, 2027, you won't be able to create new node pools, AKS won't produce new node images, and you'll no longer receive security patches for existing node pools. If you want to enable long-term support (LTS) with Kubernetes version 1.33 or later, first update your node pools to Ubuntu 24.04. On April 30, 2028, AKS will remove Ubuntu 22.04 node images and existing code, causing scaling and remediation operations to fail. For more information, see aka.ms/aks/ubuntu2204-retirement-github.
  • Starting on April 1, 2027, the node pool tag, aks-disable-kubelet-serving-certificate-rotation=true will no longer be supported. New node pools can be created with the node pool tag, but AKS will not respect the node pool tag. For new node pools, that means that they will be created with Kubelet Serving Certificate Rotation (KSCR) enabled, despite the node pool tag. For existing node pools, this means that KSCR will be automatically enabled on their next reimage operation. For updates about this retirement, see AKS GitHub Issue.
  • Teleport (preview) on AKS has now been removed by Azure Container Registry and by AKS. Please migrate to Artifact Streaming (preview) on AKS or update your node pools to set --aks-custom-headers EnableACRTeleport=false. Existing node pools with Teleport (preview) enabled may experience breakage and node provisioning failures. For more information, see aka.ms/aks/teleport-retirement.
  • Check out What's new with Microsoft in open source and Kubernetes at KubeCon + CloudNativeCon Europe 2026 for the recent announcements at KubeCon + CloudNativeCon Europe 2026.

Kubernetes Version

For deprecation, rollouts and patch timelines by region, please check the AKS-Release-Tracker.

Preview Features

  • Added support for AKS-managed NAT Gateway V2 outbound in supported public Azure regions, with automatic exclusion in sovereign clouds and regions where StandardV2 NAT Gateway isn't yet available.

Features

  • Customers using Standard_NC80ads_H100_v5 VM sizes can now configure MIG (multi-instance GPU) profiles on their agent pools, enabling partitioning of H100 GPUs into smaller instances (MIG1g, MIG2g, MIG3g, MIG4g, MIG7g) for better GPU utilization and multi-tenancy scenarios.
  • A preinstalled Premium SSD v2 StorageClass is now available on AKS 1.35 clusters in supported regions, providing sensible defaults for Premium SSD v2 adoption without requiring custom StorageClasses.
  • API Server VNET Integration is now available in malaysiasouth.
  • Vertical Pod Autoscaler (VPA) now supports the Recreate update mode.
  • Users can now customize the termination grace period on Istio-based service mesh gateway proxy pods.
  • Disable HTTP Proxy is now generally available. It's enabled by default for new clusters and can be disabled for existing AKS clusters. Once you disable HTTP proxy on a cluster, the proxy configuration is saved in the database but the proxy variables are removed from the pods and nodes.
  • AKS Managed API Server Guard is now generally available. It acts as a last-resort safeguard for the kube-apiserver during extreme load.

Bug Fixes

  • Fixed a bug in the AKS-managed nodes/proxy ValidatingAdmissionPolicy on AKS Automatic clusters where RBAC rules containing only nonResourceURLs were incorrectly denied.
  • A new ValidatingAdmissionPolicy has been added to AKS Automatic clusters to prevent creation or mutation of Kubernetes Service objects (such as clusterIP, externalIPs, or loadBalancerIP) that could redirect traffic to the Azure WireServer IP address, mitigating a potential remote code execution risk.
  • Fixed an issue in the AKS Istio add-on that could prevent CRD installer pods from scheduling on nodes tainted with CriticalAddonsOnly and cni.istio.io/ready=false, improving installation and upgrade reliability.

Behavioral Changes

  • Starting with Kubernetes 1.34, clusters using Azure CNI Powered by Cilium include a new AKS-managed cilium-fluent-bit component to improve Cilium supportability.
  • The noProxy validation for HTTP proxy configuration has been relaxed. The updated validation only runs upon changes to the noProxy field and uses a less strict regex, unblocking customers with non-standard noProxy entries.
  • When using HTTP Proxy, you can't add more than 20 Trusted CA Certificates. See HTTP Proxy limitations for more information.

Component Updates

  • Node Auto Provisioning has been updated to Karpenter Azure provider v1.10.1.
  • Azure Monitor Metrics (ama-metrics) has been updated to the release-03-05-2026.
  • Azure File CSI driver has been updated to v1.33.8 (AKS 1.33), v1.34.4 (AKS 1.34), and v1.35.1 (AKS 1.35).
  • Azure Blob CSI driver has been updated to v1.26.10 (AKS 1.33) and v1.27.3 (AKS 1.34/1.35).
  • Microsoft Defender for Containers sensor has been upgraded to v0.9.52 on AKS >= 1.35 and to v0.8.49 on AKS < 1.35. See release notes for v0.9.52 and v0.8.49. The following Defender for Containers components were also updated:
  • Cloud-provider-azure has been updated to v1.35.0 with cloud-controller-manager v1.35.1-1 and cloud-node-manager v1.35.1-1.
  • Cluster autoscaler v1.35.0 is now available on AKS version 1.35.
  • Cilium agent and operator images have been updated to v1.17.9...
Read more

Release Notes - 2026-03-05

Choose a tag to compare

@kaarthis kaarthis released this 11 Mar 23:12
d0efd81

Monitor the release status by regions at AKS-Release-Tracker.

Announcements

  • Azure Kubernetes Service support for Flatcar Container Linux for AKS (preview) will be retired on 8 June 2026, transition to a supported alternative by that date. From now to 7 June 2026, you can continue to use Flatcar Container Linux for AKS (preview) on Azure Kubernetes Service without disruption. Starting on 8 June 2026, Azure Kubernetes Service will no longer support Flatcar Container Linux for AKS (preview). You will no longer be able to create new node pools. AKS will not produce new node images and will no longer provide security patches for existing node pools. AKS will remove Flatcar Container Linux for AKS (preview) node images and existing code on 8 September 2026, meaning that scaling and remediation operations will fail.
  • Azure Linux has expanded GPU support to include NVIDIA A100, H100, and H200 VMs. Find the full list of supported GPUs with Azure Linux on AKS here.

Kubernetes Version

  • AKS Kubernetes version 1.35 is now generally available and being rolled out across regions. Please refer to the components breaking changes for more information.
  • AKS Kubernetes version 1.32 reaches the end of standard support on April 30, 2026. Please upgrade your clusters to a supported version. Refer to the AKS Support Calendar, version support policy for more information.
  • New Kubernetes patch versions are now available: 1.32.11, 1.33.7, 1.34.3.
  • AKS Kubernetes Long Term Support (LTS) version 1.28 is deprecated. Please upgrade your clusters to a supported version. Refer to AKS Support Calendar for more information.

For deprecation, rollouts and patch timelines by region, please check the AKS-Release-Tracker.

Preview Features

  • Azure Monitor Profile OTLP gRPC support is now available in public preview, enabling OpenTelemetry Protocol gRPC endpoints for Azure Monitor metrics collection.
  • ACNS preview feature is now supported on dual-stack clusters.
  • Node Auto Provisioning has been updated to Karpenter Azure provider v1.7.2. This release adds a new alpha resource NodeOverlay for controlling node priorities and supports two new scheduling labels: kubernetes.azure.com/scalesetpriority and kubernetes.azure.com/os-sku.

Features

Behavioral Changes

  • AKS Automatic clusters now enforce multiple layers of defense against remote code execution via nodes/proxy permissions:
    • A ValidatingAdmissionPolicy (VAP) restricts creation or updates of ClusterRole and Role objects granting nodes/proxy, except for approved system users and groups.
    • An authorization policy denies nodes/proxy by default. Approved system users, groups, and kube-system service accounts are exempt.
  • On clusters where ACNS performance is used to enable eBPF host routing, nodes will be labeled with kubernetes.azure.com/ebpf-host-routing=true. This is done by a node image upgrade.
  • Service tags for API server authorized IP ranges are now supported for AKS clusters with API server VNet integration.
  • AKS now supports configuring Standard V2 Azure NAT Gateway as a user‑assigned NAT gateway for outbound (egress) traffic.

Component Updates

Release 2026-02-08

Choose a tag to compare

@kaysieyu kaysieyu released this 17 Feb 21:29
2c84848

Release Notes 2026-02-08

Monitor the release status by regions at AKS-Release-Tracker.

Announcements

  • Windows Server 2019 is scheduled for retirement on March 1, 2026. Please transition to Windows Server 2022+ by that date. After that date, AKS will no longer produce new node images or provide security patches for Windows Server 2019. After that date, you will not be able to create new node pools with Windows Server 2019 on any Kubernetes version. All existing node pools with Windows Server 2019 will be unsupported. Windows Server 2019 is not supported in Kubernetes versions >= 1.33. Starting on April 1, 2027, AKS will remove all existing node images for Windows Server 2019 which will result in failure of scaling and remediation (reimage and redeploy) operations.
  • Windows Server Annual Channel (Preview) on AKS will be retired on May 15, 2026, please transition to the Long Term Servicing Channel (LTSC) by that date. From now to May 15, 2026 you can continue to use Windows Server Annual Channel (Preview) without disruption. On May 15, 2026, AKS will no longer produce new Windows Server Annual Channel node images or provide security patches. You will not be able to create new node pools with Windows Server Annual Channel. On May 15, 2027, AKS will remove all existing Windows Server Annual Channel node images, which will cause scaling and remediation (reimage and redeploy) operations to fail.

Kubernetes Version

  • AKS Kubernetes patch versions 1.34.2, 1.33.6, and 1.32.10 are now available. Refer to version support policy and upgrading a cluster for more information.
  • AKS Kubernetes version 1.35 preview is rolling out to multiple regions and is expected to complete by early March.

Preview Features

  • Managed GPU profiles are now available in public preview via API version 2026-01-02-preview.
  • Blue-green node pool upgrade is now available in public preview via API version 2025-08-02-preview and Azure CLI version 2.64.0 or higher.
  • Node pool version rollback is now available in public preview via API version 2025-08-02-preview and Azure CLI version 2.64.0 or higher.

Features

Behavioral Changes

  • Nodes are now annotated with a kubernetes.azure.com/security-patch-timestamp annotation during a security VHD reboot upgrade. This gives you a unified way to verify when the last security patch was applied to each node. Refer to Autoupgrade Node OS Image FAQs for more information.
  • By default, AKS no longer creates or updates Network Security Groups on subnets it delegates for Application Gateway for Containers, improving reliability in policy-managed environments.
  • To protect against potential security concern of remote code execution via nodes/proxy get permission, AKS Automatic has added multiple layers of defense:
    1. A ValidatingAdmissionPolicy(VAP) that restrict the use of the Kubernetes nodes/proxy permission. One policy blocks creation or updates of ClusterRole and Role objects granting nodes/proxy, except for approved system users and groups.
    2. An authorization policy that denies nodes/proxy by default. This prevents exploitation even if a user has already been granted nodes/proxy permission through existing RBAC bindings. Approved system users, groups, and kube-system service accounts are exempt.
  • AKS Deployment Safeguards no longer Deny missing startup, liveness, and readiness probe requirements on AKS Automatic clusters. The policy has been changed to warn only. Learn more.
  • Gateway API CRDs can now be enabled directly without first requiring a supported gateway implementation such as the Managed Istio service mesh add-on to be enabled on the cluster.

Component Updates

Read more