Releases: Azure/AKS
Release list
Release 2026-09-04
Release Notes - 2026-09-04
Monitor the release status by regions at AKS-Release-Tracker. This release is titled
v20260904.
Announcements of upcoming changes and retirements
- Starting September 30, 2026, AKS will automatically migrate deprecated Availability Sets (VMAS) clusters to Virtual Machines node pools through the auto-upgrader. To control the migration timing, migrate before that date by using
az aks update --migrate-vmas-to-vms. - Azure Linux with OS Guard for Azure Kubernetes Service (AKS) (preview) will be retired on December 10, 2026. Please transition to Azure Container Linux by that date. From now to December 9, 2026, you can continue to use Azure Linux with OS Guard (preview) without disruption. On December 10, 2026, AKS will no longer produce new Azure Linux with OS Guard node images or provide security patches, and you will not be able to create new node pools with Azure Linux with OS Guard. On March 10, 2027, AKS will remove all existing Azure Linux with OS Guard node images, which will cause scaling and remediation (reimage and redeploy) operations to fail.
Release notes
Kubernetes versions
- Kubernetes Version 1.37 Preview is being rolled out.
- Kubernetes patch versions
1.36.3,1.35.7, and1.34.10are now available.
Features
- Autoscaling for Virtual Machines node pools is now generally available, including multi-SKU autoscaling.
Preview features
- Existing clusters can now be converted to use a managed system node pool in supported regions after registering the required preview feature.
- Node pools with an in-progress blue-green upgrade can now switch safely to the rolling upgrade strategy.
- On-Demand Monitor, a new Cluster Health Monitor capability for node health checks and remediation, is available in preview.
- AKS Hyperscale Configuration is now available in public preview. It lets customers running large AI, high-performance computing (HPC), batch processing, and enterprise workloads preprovision control plane capacity with H2, H4, and H8 scaling profiles. These profiles provide predictable Kubernetes API responsiveness, pod scheduling throughput, and cluster state management during scale-out, recovery, and traffic spikes.
Behavioral changes
- The AKS release status site now includes Windows Server 2025 and no longer lists Windows Server 2019 or Windows Server, version 23H2 because AKS no longer produces VHDs for those versions. The AKS release status site now shows only the default VHD for each Windows version.
- Starting with Kubernetes 1.37, LocalDNS is enabled automatically when the cluster networking configuration supports it. Clusters using bring-your-own CNI, network policy configurations that aren't supported, or an existing custom DNS configuration aren't changed.
- AKS now rejects updates that attempt to remove IPv6 from an existing dual-stack cluster. Dual-stack to single-stack migration isn't supported.
- New clusters using an HTTP proxy or Custom Certificate Authority now reject CA certificate content larger than 35 KB, preventing node bootstrap data from exceeding platform limits. Existing clusters aren't affected.
- Managed namespace creation now rejects names beginning with the reserved
kube-oraks-istio-prefixes. This prevents naming conflicts with system-reserved namespaces and reduces the risk of customers accidentally interfering with Kubernetes or AKS-managed components. - When the Azure Policy add-on is enabled in AKS, Azure Policy's Kubernetes-native validation path is now enabled by default across regions.
- Static Egress Gateway nodes now deregister from the load balancer before a node-image upgrade reimages them, reducing the risk of interrupted egress traffic.
- AKS will return a validation error if you try to enable KMS encryption-at-rest for Kubernetes secrets handled by K8s API with customer managed key on 1.37 cluster with versioned Key Vault key IDs. This feature requires specification of versionless Azure Key Vault key ID.
- On Kubernetes 1.37 and later, Azure Monitor managed service for Prometheus (ama-metrics) uses namespace-scoped access to Kubernetes secrets for PodMonitor and ServiceMonitor configurations. If your ServiceMonitor or PodMonitor uses basicAuth, bearerToken, or any other configuration that references Kubernetes secrets, you must configure namespace-scoped secrets access before upgrading your cluster to Kubernetes 1.37.
Bug fixes
- Fixed an issue where the Microsoft Defender for Containers collector could prevent CSI volumes from detaching, leaving volumes terminating and blocking dependent pods from scheduling.
- Fixed missing Windows node metrics caused by an incorrect exporter port configuration.
Component updates
- Gatekeeper has been updated to
v3.23.1, fixing excessive Validating Admission Policy reconciliation requests. - Managed Gateway API on Kubernetes 1.37 now uses the Gateway API v1.6.1 standard-channel CRD bundle, adding the graduated
TCPRouteandUDPRouteresources. - Istio-based service mesh add-on revisions have been updated with security patches for ISTIO-SECURITY-2026-006:
asm-1-29tov1.29.7asm-1-30tov1.30.4- Restart workload pods to trigger reinjection of the updated
istio-proxysidecar. For more information, see the Istio add-on upgrade guide.
- Azure CSI drivers have been updated:
- Cloud Provider Azure components have been updated to
v1.33.17-2andv1.36.5-2, includingcloud-controller-manager,cloud-node-manager, andhealth-probe-proxy. The Kubernetes 1.36 cloud controller manager also includes Service Gateway support. - Cilium, Hubble Relay, and Advanced Container Networking Services FQDN policy images have been updated:
- App Routing updated to version 0.2.28 with ingress-nginx bumped to
v1.13.10-10with additional validation for custom log formats. - AKS Windows images:
- Windows Server 2022 - 20348.5499.260812.
- Windows Server 2025 - 26100.33296.260812.
- AKS Azure Linux images:
- v3.0 - 202608.06.1.
- v3.0 - 202608.14.0.
- v3.0 - 202608.20.0.
- v3.0 - 202608.26.0.
- AKS Azure Container Linux images:
- ACLv3 - 202608.06.1.
- ACLv3 - 202608.14.0.
- ACLv3 - 202608.20.0.
- ACLv3 - 202608.26.0.
- AKS Ubuntu images:
- Ubuntu 22.04 - [202608.06.1](vhd-notes/aks-ubuntu/AKSUbuntu-2204/202608.06...
AppNet 2026-08-19
AppNet Release Notes - 2026-08-19
Azure Kubernetes Application Network (AppNet) — initial release notes covering changes since March 2026. AppNet is in public preview.
Announcements and retirements
- The following AppNet versions have been retired and are no longer supported. If using self-managed upgrade mode, upgrade to a currently supported version (see Component updates) following the AppNet upgrade guide.
- AppNet 1.0 (Istio 1.25)
- AppNet 1.1 (Istio 1.26)
- AppNet 1.2 (Istio 1.27)
- AppNet is now available in public preview in additional Azure regions, including Central US, East US, East US 2, Japan East, North Central US, North Europe, South India, Southeast Asia, West Central US, West US 2, and West US 3.
Bug fixes
- AppNet now validates cluster prerequisites at member-join time and returns a clear, actionable error when a cluster is missing a required add-on (Microsoft Entra / AAD or the Managed Gateway API) or is running an AKS Kubernetes version below the minimum supported version, instead of failing opaquely later.
- Clusters using AKS managed Gateway API no longer hit a CRD ownership conflict when joining a mesh; AppNet defers to the add-on-provided Gateway API CRDs.
- Moving AppNet resources across resource groups or subscriptions is now blocked, as these move operations are not supported for AppNet.
- Fixed an issue where the AppNet Managed Control Plane could fail to start after an intermediate certificate authority rotation, which could disrupt the entire mesh. Certificate rotation is now handled reliably.
- Fixed an issue where multicluster east-west gateways were missing a required network label, causing cross-cluster traffic to fail.
- Fixed an issue where member clusters using Microsoft Entra (managed identity) authentication were rejected on update, which had blocked member updates and version upgrades.
- Fixed leftover mesh resources being orphaned on a member cluster after it left the mesh; these are now cleaned up.
- Fixed member deletion being stuck in a retry loop when the underlying cluster had already been removed; already-deleted resources are now treated as a success.
- Fixed an issue where AppNet Managed Control Plane diagnostic logs were missing from customer Log Analytics workspaces.
- Fixed an issue where member join would retry when the cluster had a customer-fixable configuration error; it now fails fast and returns the validation error so it can be corrected.
- Fixed an issue where failed AppLink and member operations returned a generic error instead of the specific reason; actionable failures, such as joining a cluster already connected to another AppLink, now explain what went wrong and how to resolve it.
Component updates
- AppNet 1.3 has been updated to Istio 1.28.10.
- AppNet 1.4 has been updated to Istio 1.29.6.
- AppNet 1.5 (Istio 1.30) is now available, using Istio 1.30.3.
Release 2026-08-07
Release Notes - 2026-08-07
Monitor the release status by regions at AKS-Release-Tracker. This release is titled
v20260807.
Release notes
Features
- Node Auto Provisioning can now be enabled on clusters with restricted
publicNetworkAccess, including private API server VNet-integrated clusters using UDR, as long as the existing AKS-wide networking guardrails pass. - Automatic availability zone placement is now enabled globally. Customers can create new VMSS or VirtualMachines node pools with
availabilityZones=["auto"], and existing VMSS node pools can be updated toavailabilityZones=["auto"]after rollout completes. - AKS now allows control-plane only upgrades to AKS Long Term Support (LTS) as long as the version skew policy is satisfied. This allows user to more safely upgrade into LTS by first upgrading the control plane, validating functionality, and then upgrading node pools.
- AKS Node pool Rollback is now generally available. AKS node pool version rollback lets you restore a node pool to its previous Kubernetes version and node image after an upgrade issue, minimizing downtime and maintaining business continuity.
- Encryption in Transit and use workload identity to access Azure Files storage are now generally available for the Azure File CSI driver.
Preview features
- Prepared Image Specification (PIS) is now available in public preview. PIS allows you to create preconfigured node images with your required container images and node customizations already applied, helping to reduce node startup times.
- Customers using preview API version
2026-01-02-previewor later can associate a Capacity Reservation Group with an existing node pool. Zonal node pools perform a rolling cordon, drain, and reboot; non-zero regional pools must still be scaled to zero first.
Behavioral changes
- For AKS clusters running Kubernetes 1.37 or later, SSH node access configuration changes now trigger an immediate node reimage. Use Node Disruption Policy to block the reimage or schedule it during a maintenance window.
- For AKS clusters running Kubernetes 1.37 or later, changes to IMDS restriction, network-isolated bootstrap profile, or cluster outbound type now trigger an immediate node reimage. Use Node Disruption Policy to control when the reimage is allowed.
- VMSS rolling upgrade concurrency for percentage-based
maxSurge,maxUnavailable, andmaxBlockedNodesis now calculated from current VMSS capacity and capped to the remaining VMs to upgrade, making partial upgrades match the remaining upgrade work. For more details see the documentation on rolling upgrade behaviors. - Updating a cluster from service principal authentication to managed identity now triggers node reimages across node pools. Configure Node Disruption Policy to control when reimages that can disrupt workloads are allowed.
- AKS upgrade validation now rejects node pool upgrades where current pool size plus effective surge would exceed the VMSS 1,000-instance limit, preventing mid-upgrade Azure Compute failures. See 'Configure rolling upgrade settings' for more details.
- Istio Gateway API deployments now set
automountServiceAccountTokentofalse, improving the default security posture and unblocking environments with Azure Policies that require pods to disable service account token auto-mounting. - AKS now validates GPU MIG instance profile slice width against VM SKU capacity, preventing unsupported MIG profiles from being accepted on lower-capacity GPU SKUs.
- The Application Gateway for Containers ALB add-on is now aligned with AKS minor versions. AKS automatically selects the compatible ALB controller image during cluster upgrades, reducing controller and feature-flag incompatibilities.
- AKS now rejects Entra ID SSH configuration on AzureContainerLinux node pools because the extension is incompatible with immutable OS nodes and can make nodes unreachable.
Bug fixes
- Fixed an AKS Automatic issue where App Routing on Kubernetes 1.36+ clusters could incorrectly default to NGINX instead of Istio/Gateway API mode during cluster creation.
Component updates
- Node Auto Provisioning has been updated to Karpenter provider Azure
v1.14.0, adding support for theBalancedconsolidation policy to reduce node churn during consolidation. - Azure Policy add-on components were updated: Gatekeeper was bumped to
3.23.0, and Azure Policy add-on was bumped to1.17.0. - Azure File CSI Driver has been upgraded to
v1.34.7on AKS 1.34 andv1.35.6on AKS 1.35 and 1.36. - Azure Blob CSI Driver has been upgraded to
v1.26.16on AKS 1.33 andv1.27.9on AKS 1.34 and later. - Azure Disk CSI Driver has been upgraded to
v1.33.11on AKS 1.34 andv1.34.5on AKS 1.35 and 1.36. - Azure Monitor managed service for Prometheus add-on was updated to the 07-27-2026 release, including collector image updates and kube-state-metrics
v2.19.1-2. - Container Insights has been upgraded to
3.6.0. - AKS Azure Linux images:
- v3.0 - 202607.20.0.
- v3.0 - 202607.29.0.
- AKS Azure Container Linux images:
- ACLv3 - 202607.20.0.
- ACLv3 - 202607.29.0.
- AKS Ubuntu images:
- Ubuntu 22.04 - 202607.20.0.
- Ubuntu 22.04 - 202607.29.0.
- Ubuntu 24.04 - 202607.20.0.
- Ubuntu 24.04 - 202607.29.0.
Release 2026-07-17
Release Notes - 2026-07-17
Monitor the release status by regions at AKS-Release-Tracker. This release is titled
v20260717.
Announcements of upcoming changes and retirements
- On September 14, 2026, the preview property enableCustomCATrust will retire. After that date, the
enableCustomCATrust=truenode pool level field will no longer enable Custom Certificate Authority (CA). To avoid failures during scaling and certificate updates, update the impacted clusters and node pools and remove the preview property (--disable-custom-ca-trust). - AKS no longer supports creating node pools with Windows Server Annual Channel for Containers. Existing WSAnnual node pools are unaffected. For more information, see Windows Annual Channel retirement.
- AKS no longer supports creating node pools or clusters with Flatcar Container Linux for AKS. Existing node pools are unaffected. For more information, see Flatcar preview retirement.
- Customers using NVadsA10v5 or NCadsA10v4 node pools should verify they are running AKS node image version 202606.08.1 or later to maintain compatibility with updated NVIDIA v18.x host drivers. Clusters running older node images may encounter host/guest GPU driver compatibility issues and move into an unsupported configuration. For upgrade guidance, see the AKS node image upgrade documentation. See Github issue for more information.
Release notes
Kubernetes versions
- Kubernetes patch versions 1.36.2, 1.35.6, 1.34.9, and 1.33.13 are now available.
- Kubernetes version 1.30 is now deprecated. Upgrade to a supported Kubernetes version, or opt into long-term support (LTS) to continue receiving updates.
- Kubernetes version 1.33 is now available only under long-term support (LTS).
Features
- Artifact Streaming is now generally available. The feature allows you to stream container images from Azure Container Registry (ACR) to Azure Kubernetes Service (AKS). AKS only pulls the necessary layers for initial pod startup, reducing the time it takes to deploy your workloads.
- Secure TLS bootstrapping is now enabled by default in
westcentralusandeastasia. See regional updates on AKS GitHub Issues. - Secure Boot is now supported when using GPUs with Azure Linux OS.
- Trusted Launch (vTPM and Secure Boot) can now be enabled and disabled on existing Linux node pools.
Preview features
- Node Disruption Policy is now available in public preview. Node Disruption Policy lets you control when reimage-triggering operations are allowed so disruptive changes happen during windows you define.
- Automatic zone placement is now available in public preview. Automatic zone placement in AKS dynamically selects the best set of availability zones for a node pool. You don't need to specify the zones manually for each region and VM SKU combination.
- Prepared Image Specification is now available in preview. With AKS Prepared Image Specification, you can create preconfigured node images that include required container images and customizations ahead of time, enabling new nodes to start in a ready-to-run state.
- Full caching mode for Ephemeral OS disks is now available in public preview. Full caching mode caches the entire operating system locally on the node, so that AKS can continue running even when remote storage is unavailable, significantly improving node resiliency while also delivering faster OS disk performance.
Behavioral changes
- Starting with Kubernetes 1.37 (expected to be available in October 2026), Windows Server 2025 is the default and recommended OS SKU for new Windows node pools when no OS SKU is specified. For more information, see Windows best practices.
- For Node Auto Provisioning enabled clusters, AKS now sets
kubernetes.azure.com/mode: useron the default NodePool to help prevent pending system workloads from causing user node scale-up. - Node Auto-Provisioning enabled clusters now use an In-VM spot rebalancing signal, which allows for an improved spot eviction notification and proactive spot replacement.
- AKS now rejects kube-proxy
nftablesmode at request time on clusters running Kubernetes versions older than 1.33, instead of accepting the request and silently falling back toiptables. - AKS now accepts mixed-case
networkPluginvalues for supported network plugin options during cluster creation. - The
untilfield in upgrade override settings can now be set to any future date; AKS no longer rejects values more than 30 days in the future. - CNI Overlay Dual-Stack on Windows no longer requires a preview feature registration.
Bug fixes
- Fixed an issue where API Server Authorized IP Ranges using only service tags were not enforced on API Server VNet Integration clusters.
- Fixed Container Insights onboarding through AzureMonitorProfile so re-enabling Container Insights uses AAD auth and blocks unsafe Log Analytics Workspace changes under legacy auth.
- Fixed an issue where clusters with an existing kube-proxy configuration object could not be updated unless
KubeProxyConfigurationPreviewwas registered, even when the update did not change kube-proxy configuration. - Fixed App Routing Istio manifest values so resource requests and limits are populated correctly.
- Fixed Static Egress Gateway VMSS model reconciliation so secondary egress IP configurations are preserved.
- Re-enabled Cilium source IP verification on Cilium v1.17+ to restore dataplane anti-spoofing protection.
- Fixed AKS support for Istio 1.30 mutating webhook configuration updates on Automatic clusters.
- Fixed Node Auto Provisioning issue where load balancer deletion could block node provisioning.
- Fixed Node Auto Provisioning to normalize CSI empty-zone topology value to regional zone "0".
Component updates
- Istio revision
asm-1-30is now available with the Istio-based service mesh add-on. See supported Istio revisions for details. - Istio-based service mesh add-on revisions
asm-1-28,asm-1-29, andasm-1-30include security fixes for ISTIO-SECURITY-2026-005. Action required: restart your Istio workload pods to trigger re-injection of the neweristio-proxypatch version. - Istio-based service mesh add-on revisions have been updated:
- Cilium, Hubble, and ACNS security agent images have been updated:
- Kubernetes 1.32 images to
v1.17.17-260701 - Kubernetes 1.34 images to
v1.18.11-260622 - Kubernetes 1.36 images to
v1.19.5-260714
- Kubernetes 1.32 images to
- containerd has been updated from
1.7.32to1.7.33, including security fixes for CVE-2026-53488, CVE-2026-47262, and CVE-2026-34986. - Azure Monitor for Containers has been updated to
3.4.0. - Azure Karpenter Provider has been updated to
v1.14.0. - Azure File CSI driver images have been updated to
v1.35.5on AKS 1.35 and 1.36. - App Routing operator has been updated to
v0.2.26. - Updated Cluster Autoscaler images from v1.33.4 to v1.33.5, v1.34.3 to v1.34.4, and v1.35.0 to v1.35.1 for Kubernetes versions 1.33, 1.34, and 1.35, respectively.
- kube-proxy image
mcr.microsoft.com/oss/v2/kubernetes/kube-proxyhas been updated:v1.36.2-4tov1.36.2-5v1.33.7-14tov1.33.7-15
- kube-scheduler image
mcr.microsoft.com/oss/v2/kubernetes/kube-schedulerhas been updated across Kubernetes 1.34, 1.35, and 1.36 patch tags. - CoreDNS images have been updated (see CoreDNS upstream releases):
v1.11.3-30to `v1.11...
Release - 2026-06-19
Release Notes - 2026-06-19
Monitor the release status by regions at AKS-Release-Tracker. Vulnerabilities addressed by AKS releases can be tracked at CVE API viewer.
Announcements
- Windows Server 2022 retirement has been extended. Please note the following updates: Windows Server 2022 retires on June 30, 2028. After that date, AKS will no longer produce new node images or provide security patches. After that date, you will not be able to create new node pools with Windows Server 2022 on any Kubernetes version. All existing node pools with Windows Server 2022 will be unsupported. Windows Server 2022 is not supported in Kubernetes version 1.37 and above. Starting on June 30, 2029, AKS will remove all existing node images for Windows Server 2022, meaning that scaling operations will fail. For more information on this retirement, see the Retirement GitHub issue.
- Azure Service Mesh add-on revision
asm-1-30(estimated to release in early July) introduces the following changes to default behavior:- The default proxy redirection mechanism on new installations will change from privileged init containers to Istio CNI for revisions
asm-1-30and above. Clusters upgrading toasm-1-30will not be impacted. Read more about Istio CNI. To retain the existing proxy redirection mechanism on new installations, see the instructions to disable Istio CNI. - Starting with
asm-1-30, Istio ingress, egress, and gateway pods will have a weighted preference of 100 for nodes labeledazureservicemesh/istio.replica.preferred(previously 50) and 50 for AKS system nodes labeledkubernetes.azure.com/mode: system(previously 100).
- The default proxy redirection mechanism on new installations will change from privileged init containers to Istio CNI for revisions
Kubernetes versions
- Kubernetes version 1.36 is now generally available and supported as a Long Term Support (LTS) version. You no longer need to enable a preview to create or upgrade clusters to 1.36.
Features
- FIPS is now supported on Ubuntu 22.04 node pools with FIPS 140-3 compliance in the 2026-05-29 release. You can migrate to Ubuntu 22.04 FIPS by upgrading existing FIPS node pools to k8s 1.35+ with 'Ubuntu' OS SKU, or by updating existing FIPS node pools in k8s 1.25+ to 'Ubuntu2204' os sku. You can now enable FIPS and Trusted Launch in the same node pools when using Ubuntu on AKS.
- AKS now supports the NVIDIA RTX PRO 6000 Blackwell Server Edition GPU VM sizes as managed GPUs. These SKUs use the NVIDIA GRID driver and are supported on Ubuntu node pools.
- Confidential VMs (CVM) with Azure Linux is now generally available.
Behavioral changes
- On AKS Automatic clusters running Kubernetes 1.36 or later, you can now disable the default application routing add-on with Gateway API to use the Istio-based service mesh add-on with Istio CNI, either at cluster create time or afterward.
- Deployment Safeguards in Enforce mode now apply default resource requests to DaemonSets and Jobs when those requests are missing, in addition to Deployments and StatefulSets. This includes AKS Automatic clusters.
- You can now configure custom Prometheus metric scraping and log collection on AKS Automatic clusters that use a managed system node pool.
- AKS now automatically derives the IPv6 pod CIDR from the pod subnet when you create a dual-stack Azure CNI static block allocation (VnetScale) cluster, so you no longer need to pass the pod CIDR explicitly.
- Windows gMSA now validates for CoreDNS conflicts. AKS rejects enabling gMSA, or changing its root domain name, when the cluster's
coredns-customConfigMap already defines a server block for the same domain. This prevents a duplicate zone that would crash CoreDNS and disrupt cluster-wide DNS. - AKS now rejects enabling FIPS (
--enable-fips-image) on Pod Sandboxing (Kata) workload runtime node pools. The Kata node image doesn't carry FIPS compliance, so the request now fails at the API with a clear error instead of silently providing no FIPS enforcement. - You can now create Pod Sandboxing (Kata) node pools on
Standard_DadsV7-series VM sizes, which were previously rejected by nested-virtualization validation. - You can now migrate an AKS Automatic cluster that uses a managed system node pool to the AKS Base SKU.
Bug fixes
- Fixed an issue where the
aks-istio-systemnamespace was not exempted from the Azure Policy add-on when using application routing with the Gateway API in Istio mode. The namespace is now exempted, so the two features can be used together in the same cluster. - Fixed a bug where Multiple Standard Load Balancers rejected valid domain-prefixed label keys (for example,
kubernetes.io/os) in node selectors. Label selector validation now follows standard Kubernetes semantics.
Component updates
- The Istio-based service mesh add-on revisions
asm-1-29andasm-1-28have been upgraded to patches1.29.4and1.28.8, which address CVE-2026-47774. Restart your workload pods to trigger re-injection of the updatedistio-proxysidecar. For more information, see the Istio add-on upgrade guide. - Azure File CSI Driver has been upgraded to
v1.35.4on AKS 1.35 and 1.36. - Azure Blob Storage CSI driver has been upgraded to
v1.26.14on AKS 1.33 andv1.27.7on AKS 1.34+. This update also fixes a regression where blob containers with a$in the name (for example,$web) could not be accessed. - Azure CNI Powered by Cilium has been updated:
- Cloud Provider Azure components (
cloud-controller-manager,cloud-node-manager, andhealth-probe-proxy) have been updated to the June 18, 2026 release:v1.33.14on AKS 1.33,v1.34.11on AKS 1.34,v1.35.6on AKS 1.35, andv1.36.2on AKS 1.36. - AKS Windows images:
- Windows Server 2022 - 20348.5256.260610.
- Windows Server 2025 - 26100.32995.260610.
- AKS Azure Linux images:
- v3.0 - 202606.08.1.
- AKS Ubuntu images:
- Ubuntu 22.04 - 202606.08.1.
- Ubuntu 24.04 - 202606.08.1.
Release 2026-05-29
Release Notes - 2026-05-29
Monitor the release status by regions at AKS-Release-Tracker. Vulnerabilities addressed by AKS releases can be tracked at CVE API viewer.
Announcements of upcoming changes and retirements
- Revision
asm-1-27of the Istio-based service mesh add-on has been deprecated. Please upgrade to revision 1.28 or later following the Istio add-on upgrade guide. - Windows Server Annual Channel for Containers retired on AKS on May 15, 2026. 5B is the last image that AKS will produce for Windows Server Annual Channel. After 5B, AKS will no longer produce new Windows Server Annual Channel node images or provide security patches. You will not be able to create new node pools with Windows Server Annual Channel. On May 15, 2027, AKS will remove all existing Windows Annual Channel node images, which will cause scaling and remediation (reimage and redeploy) operations to fail. Customers must migrate their Windows Server Annual Channel node pools to Long Term Servicing Channel (LTSC) by following the migration guide.
- Windows Server 2019 retired on March 1, 2026 and its preview feature flag has been removed. You can expect the following impact: AKS no longer produces new node images or provides security patches. All existing node pools with Windows Server 2019 are unsupported. You will not be able to create new node pools in k8s 1.33+. Starting on April 1, 2027, AKS will remove all existing node images for Windows Server 2019, meaning that scaling operations will fail. For more information, see aka.ms/aks/ws2019-retirement-github.
- Starting on June 8, 2026, AKS no longer supports Flatcar Container Linux for Azure Kubernetes Service (AKS) (preview). At that point, AKS will no longer produce new Flatcar Container Linux node images or provide security patches, and you'll be unable to create new node pools with Flatcar Container Linux. On September 8, 2026, AKS will remove all existing Flatcar Container Linux node images, causing scaling and remediation (reimage and redeploy) operations to fail. Migrate existing Flatcar Container Linux for AKS node pools to Azure Container Linux for AKS.
- Managed system node pools are now generally available for AKS Automatic. New AKS Automatic clusters preconfigure managed system node pools by default. If you have an existing Automatic cluster without managed system node pools, you should recreate the cluster and migrate the workloads.
- New AKS Automatic clusters now preconfigure LocalDNS mode to
Requiredby default, including new node pools added to existing Automatic clusters. Existing node pools are unchanged. - Users with the Azure Kubernetes Service Contributor or Contributor role (with
Microsoft.ContainerService/deploymentSafeguards/writepermission) can now edit theexcludedNamespacesfield for deployment safeguards on Automatic clusters, controlling which policies apply to specific namespaces. - Deployment safeguards in Enforce mode and Pod Security Standards set to Baseline now allow pods on Automatic clusters to read the
/var/logand/hostfshostPath volumes (read-only), supporting log exporter scenarios. - Since AKS manages the system node pool on your behalf, AKS applies multiple layers of security restrictions:
- New AKS Automatic clusters with managed system node pools now block customer-supplied SSH keys. Existing Automatic clusters with managed system node pools keep their existing keys but can't add new ones; clusters without managed system node pools are unaffected.
- AKS Automatic clusters enforce a ValidatingAdmissionPolicy that blocks Services from setting
spec.externalIPs, in line with the upstream deprecation of Service externalIPs. The policy applies immediately to Automatic clusters with managed system node pools, and to Automatic clusters without managed system node pools starting in Kubernetes 1.36. - AKS Automatic clusters with managed system node pools deny
kubectl port-forwardfor objects and pods running on the managed system node pool. - AKS Automatic clusters with managed system node pools block read access to secrets in the
kube-systemnamespace, except for known trusted identities. This mitigates the risk of attackers using the node bootstrap token to deploy pods on managed system node pools. - AKS Automatic clusters with managed system node pools enforce stricter authorization on MutatingAdmissionPolicyBinding resources by blocking unauthorized mutation operations (create, update, patch, delete).
- For AKS versions prior to 1.36, AKS Automatic clusters with managed system node pools block all mutating admission resources (MutatingWebhookConfiguration, MutatingAdmissionPolicy, and MutatingAdmissionPolicyBinding) to reduce risk from unsafe mutations. Starting in AKS 1.36, Automatic clusters with managed system node pools allow a controlled subset of mutating admission configurations, provided they do not target the following sensitive resources: nodes, persistentvolumes, certificatesigningrequests, and tokenreviews.
- New AKS Automatic clusters now preconfigure LocalDNS mode to
Release notes
Kubernetes versions
- Kubernetes Version 1.36 Preview is being rolled out.
- Kubernetes patch versions 1.35.4, 1.34.7, and 1.33.11 are now available. These builds use Go 1.25.9, which includes fixes for the following CVEs (CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32282, CVE-2026-32283, CVE-2026-32288, CVE-2026-32289).
- Kubernetes patch versions 1.35.5, 1.34.8, and 1.33.12 are now available.
Features
- Windows Server 2025 is now generally available. You no longer need to register a feature flag to create Windows Server 2025 node pools. Windows Server 2025 node pools can be created in Kubernetes version 1.32+ with a minimum GA CLI version of 2.87.0.
- Azure Container Linux is generally available (GA) as an OS option on AKS starting AKS v1.34. You can deploy ACL node pools in a new AKS cluster or add ACL node pools to your existing clusters. AKS also supports migrating existing node pools to ACL using in-place OS SKU migration or by creating new ACL node pools. For detailed migration steps, considerations, and rollback instructions, see Migrate existing nodes to ACL.
- Azure Policy add-on now generates ValidatingAdmissionPolicies (VAP) for all customers. This enforces CEL-based policies inside the API server process for minimal latency and enables fail-closed enforcement.
- AKS end of support notifications are now available. AKS automatically notifies you when your cluster's Kubernetes version is approaching or has passed its end of support date. Alerts are sent two weeks before end of support, one week before end of support, and then weekly after the support date passes—no monitoring add-on or maintenance window configuration required. Notifications are published to Azure Resource Graph and can be surfaced via email alerts or real-time Event Grid webhooks.
Preview features
- Azure Linux 3.0 confidential VM (CVM) is now available in preview in Fairfax (US Gov) regions. Register the
AzureLinuxCVMPreviewfeature to enable it. - In-place node pool resize is now available in preview. Resize the VM size of an existing VMSS-based node pool in place via
az aks nodepool update --node-vm-size, without manually creating and migrating to a new node pool. - Automatic Pod Disruption Budget management is now available in preview. The AKS extension automatically creates PDBs for deployments without PDBs and temporarily scales up replicas to unblock node drain when a PDB would prevent eviction, then scales back down—reducing the need for manual interventi...
Release 2026-04-28
Release Notes - 2026-04-28
Monitor the release status by regions at AKS-Release-Tracker. Vulnerabilities addressed by AKS releases can be tracked at CVE API viewer.
Announcements
- AKS-2026-0003: A Linux kernel algif_aead local privilege escalation vulnerability (CVE-2026-31431) lets a pod escalate to root on the underlying node — including non-root pods with no special capabilities. Affects AKS nodes running Ubuntu 20.04 FIPS, Ubuntu 22.04, Ubuntu 24.04, and Azure Linux 3.0. Azure Linux 2.0 (Mariner) and Windows nodes aren't affected. The mitigation is globally deployed in node image versions 202604.13.0 and 202604.24.0. New nodes and any node that goes through a node image upgrade are automatically protected. Existing nodes aren't patched in place — upgrade the node image, or, if your pool is already on 202604.24.0, apply the mitigation DaemonSet from the advisory immediately. See the AKS security bulletin for full details.
- The Kubernetes SIG Network and the Security Response Committee announced the upcoming retirement of the Ingress NGINX project, with maintenance ending in March 2026. Application routing add-on users: Production workloads remain fully supported through November 2026. Migrate to the application routing Gateway API implementation for a Gateway API-based ingress traffic management experience.
- On Long Term Support clusters, Premium-tier billing for a cluster begins only after the cluster's Kubernetes minor version exits community support and enters the long-term support window. Until then, the cluster continues to be billed at its existing tier rate. See the Long Term Support for more information.
Kubernetes Version
- New Kubernetes patch versions are now available:
1.35.2,1.35.3,1.34.5,1.34.6,1.33.9, and1.33.10. - AKS Kubernetes Long Term Support (LTS) version
1.29is deprecated. Please upgrade your clusters to a supported version. Refer to AKS Support Calendar for more information. - AKS Kubernetes version
1.32is now available only through Long Term Support. Use an LTS support plan for clusters that need to remain on1.32, or upgrade to a supported standard-support Kubernetes version.
For deprecation, rollouts and patch timelines by region, please check the AKS-Release-Tracker.
Preview Features
- Added preview support for AKS-managed NAT Gateway V2 outbound type in supported public Azure regions. Regions where StandardV2 NAT Gateway is not yet available remain excluded.
- Customers can now preview customization of the default
kube-reservedand hard eviction kubelet configuration through the existing custom node preview feature registration starting with the 2026-03-02-preview API. - Customers can now view the VM SKUs supported on AKS and available in their Azure subscription with the AKS List Available VM SKUs API, to create their clusters and/or add node pools.
- AKS-managed GPU metrics are now supported by default in Azure Managed Prometheus and Dashboards with Grafana in Azure Monitor.
- Customers can now set both MaxUnavailable and MaxSurge values to surge during node pool upgrades based on available capacity with Capacity Based Surge. With both configurations enabled, the MaxSurge value will be attempted first. If MaxSurge value is not available due to quota or capacity, a surge of 1 node will be attempted. If a surge of 1 is not available, MaxUnavailable configuration will be attempted for an in-place upgrade.
Features
- Gateway API-based ingress for the application routing add-on is now generally available. The Kubernetes SIG Network and the Security Response Committee announced the upcoming retirement of the Ingress NGINX project, with maintenance ending in March 2026. Application routing add-on users: Production workloads remain fully supported through November 2026. Migrate to the application routing Gateway API implementation for a Gateway API-based ingress traffic management experience.
- AKS Automatic clusters with managed system node pools can now migrate to AKS Standard clusters in additional regions after adding a system node pool.
- Users can now configure
spec.minReadySecondsin the Application Routing Gateway Parameters ConfigMap. This helps applications that need extra initialization time after passing their initial health check and can reduce disruption during rolling upgrades. See the related AKS GitHub issue.
Bug Fixes
- Fixed an issue in the Istio-based service mesh add-on where the CRD installer could pull busybox from an unintended registry in AGC environments. This also removes non-Job Helm hooks from related resources to avoid a CRD installer race condition.
- Fixed empty PUT reconcile failures with
CustomRouteTableInvalidUpdateAttempton clusters using bring-your-own route tables. - Added validation to prevent enabling Artifact Streaming with Pod Sandboxing, which is not supported.
- Added AKS Automatic managed system node pool protection that blocks
ClusterRoleBindingcreate or update requests when theroleReftargets configured privilegedClusterRoles, reducing the risk of privilege escalation through service account impersonation.
Behavioral Changes
- Starting on AKS
1.36, new AKS Automatic clusters will be preconfigured with Kubernetes Gateway API via the application routing add-on instead of Managed NGINX ingress with the application routing add-on due to the upstream Ingress NGINX retirement. Existing clusters are not changed. Creating Automatic clusters with explicit--enable-app-routingcontinues to enable NGINX, while explicit--enable-app-routing-istioenables Gateway API without NGINX. - Mesh Membership now requires the Managed Gateway API add-on to be enabled with
StandardorInferenceExtensioninstallation before a cluster can join an Azure Kubernetes Application Network. Attempts to create a mesh membership without the required Gateway API add-on return a400 Bad Requesterror. For more information, see aka.ms/managed-gateway-api. - When using HTTP Proxy, you cannot add more than 20 Trusted CA certificates. See HTTP Proxy limitations for more information.
- AKS is rolling out kube-proxy reduced privileges for Kubernetes
1.30and later.kube-proxyuses theNET_ADMINandSYS_RESOURCELinux capabilities instead ofprivileged: true. Kubernetes1.29and earlier are unaffected. - Fleet-managed resources are now deployed through managed namespace ClusterResourcePlacement selection so fleet-managed resources can be rolled out separately from customer workloads.
Component Updates
- Azure Policy add-on has been updated to
1.16.1. Gatekeeper has been updated to 3.20.1-8 with CVE fixes. - Istio-based service mesh add-on revisions have been updated:
asm-1-27to1.27.9-2,asm-1-28to1.28.6-1, andasm-1-29to1.29.2-1. Revisionasm-1-29is now available, andasm-1-26is deprecated. For more information, see Istio add-on patch upgrades. - Azure Monitor Container Insights has been updated to 3.3.0.
- Node Auto Provisioning has been updated to Karpenter Azure provider v1.10.2. This release sets Artifact Streaming uniformly disable...
Release 2026-04-02
Release Notes - 2026-04-02
Monitor the release status by regions at AKS-Release-Tracker. Vulnerabiltiies addressed by AKS releases can be tracked at CVE API viewer.
Announcements
- Starting on June 30, 2027, Azure Kubernetes Service (AKS) no longer supports or provides security updates for Ubuntu 22.04. To avoid disruptions, transition to Ubuntu 24.04 or later by that date. Between now and June 30, 2027, you can continue to use Ubuntu 22.04 on AKS without disruption. If you don't migrate by June 30, 2027, you won't be able to create new node pools, AKS won't produce new node images, and you'll no longer receive security patches for existing node pools. If you want to enable long-term support (LTS) with Kubernetes version 1.33 or later, first update your node pools to Ubuntu 24.04. On April 30, 2028, AKS will remove Ubuntu 22.04 node images and existing code, causing scaling and remediation operations to fail. For more information, see aka.ms/aks/ubuntu2204-retirement-github.
- Starting on April 1, 2027, the node pool tag,
aks-disable-kubelet-serving-certificate-rotation=truewill no longer be supported. New node pools can be created with the node pool tag, but AKS will not respect the node pool tag. For new node pools, that means that they will be created with Kubelet Serving Certificate Rotation (KSCR) enabled, despite the node pool tag. For existing node pools, this means that KSCR will be automatically enabled on their next reimage operation. For updates about this retirement, see AKS GitHub Issue. - Teleport (preview) on AKS has now been removed by Azure Container Registry and by AKS. Please migrate to Artifact Streaming (preview) on AKS or update your node pools to set
--aks-custom-headers EnableACRTeleport=false. Existing node pools with Teleport (preview) enabled may experience breakage and node provisioning failures. For more information, see aka.ms/aks/teleport-retirement. - Check out What's new with Microsoft in open source and Kubernetes at KubeCon + CloudNativeCon Europe 2026 for the recent announcements at KubeCon + CloudNativeCon Europe 2026.
Kubernetes Version
- New Kubernetes patch versions are now available:
1.35.1,1.34.4,1.33.8. - AKS Kubernetes version
1.32is deprecated. Please upgrade your clusters to a supported version. Refer to AKS Support Calendar for more information. - AKS Kubernetes Long Term Support (LTS) version
1.29is deprecated. Please upgrade your clusters to a supported version. Refer to AKS Support Calendar for more information.
For deprecation, rollouts and patch timelines by region, please check the AKS-Release-Tracker.
Preview Features
- Added support for AKS-managed NAT Gateway V2 outbound in supported public Azure regions, with automatic exclusion in sovereign clouds and regions where StandardV2 NAT Gateway isn't yet available.
Features
- Customers using
Standard_NC80ads_H100_v5VM sizes can now configure MIG (multi-instance GPU) profiles on their agent pools, enabling partitioning of H100 GPUs into smaller instances (MIG1g, MIG2g, MIG3g, MIG4g, MIG7g) for better GPU utilization and multi-tenancy scenarios. - A preinstalled Premium SSD v2 StorageClass is now available on AKS 1.35 clusters in supported regions, providing sensible defaults for Premium SSD v2 adoption without requiring custom StorageClasses.
- API Server VNET Integration is now available in malaysiasouth.
- Vertical Pod Autoscaler (VPA) now supports the
Recreateupdate mode. - Users can now customize the termination grace period on Istio-based service mesh gateway proxy pods.
- Disable HTTP Proxy is now generally available. It's enabled by default for new clusters and can be disabled for existing AKS clusters. Once you disable HTTP proxy on a cluster, the proxy configuration is saved in the database but the proxy variables are removed from the pods and nodes.
- AKS Managed API Server Guard is now generally available. It acts as a last-resort safeguard for the kube-apiserver during extreme load.
Bug Fixes
- Fixed a bug in the AKS-managed
nodes/proxyValidatingAdmissionPolicy on AKS Automatic clusters where RBAC rules containing onlynonResourceURLswere incorrectly denied. - A new ValidatingAdmissionPolicy has been added to AKS Automatic clusters to prevent creation or mutation of Kubernetes Service objects (such as
clusterIP,externalIPs, orloadBalancerIP) that could redirect traffic to the Azure WireServer IP address, mitigating a potential remote code execution risk. - Fixed an issue in the AKS Istio add-on that could prevent CRD installer pods from scheduling on nodes tainted with CriticalAddonsOnly and cni.istio.io/ready=false, improving installation and upgrade reliability.
Behavioral Changes
- Starting with Kubernetes 1.34, clusters using Azure CNI Powered by Cilium include a new AKS-managed
cilium-fluent-bitcomponent to improve Cilium supportability. - The
noProxyvalidation for HTTP proxy configuration has been relaxed. The updated validation only runs upon changes to thenoProxyfield and uses a less strict regex, unblocking customers with non-standardnoProxyentries. - When using HTTP Proxy, you can't add more than 20 Trusted CA Certificates. See HTTP Proxy limitations for more information.
Component Updates
- Node Auto Provisioning has been updated to Karpenter Azure provider v1.10.1.
- Azure Monitor Metrics (ama-metrics) has been updated to the release-03-05-2026.
- Azure File CSI driver has been updated to v1.33.8 (AKS 1.33), v1.34.4 (AKS 1.34), and v1.35.1 (AKS 1.35).
- Azure Blob CSI driver has been updated to v1.26.10 (AKS 1.33) and v1.27.3 (AKS 1.34/1.35).
- Microsoft Defender for Containers sensor has been upgraded to v0.9.52 on AKS >= 1.35 and to v0.8.49 on AKS < 1.35. See release notes for v0.9.52 and v0.8.49. The following Defender for Containers components were also updated:
- security-publisher updated from 1.1.57 to 1.1.59.
- low-level-collector updated from 2.1.109 to 2.1.110 (AKS >= 1.35) and from 2.0.242 to 2.0.243 (AKS 1.29–1.34).
- CVEs remediated: CVE-2025-15558, CVE-2026-24051, CVE-2026-33186, CVE-2026-25679, CVE-2026-27142, and CVE-2026-27139.
- Cloud-provider-azure has been updated to v1.35.0 with cloud-controller-manager v1.35.1-1 and cloud-node-manager v1.35.1-1.
- Cluster autoscaler v1.35.0 is now available on AKS version 1.35.
- Cilium agent and operator images have been updated to v1.17.9...
Release Notes - 2026-03-05
Monitor the release status by regions at AKS-Release-Tracker.
Announcements
- Azure Kubernetes Service support for Flatcar Container Linux for AKS (preview) will be retired on 8 June 2026, transition to a supported alternative by that date. From now to 7 June 2026, you can continue to use Flatcar Container Linux for AKS (preview) on Azure Kubernetes Service without disruption. Starting on 8 June 2026, Azure Kubernetes Service will no longer support Flatcar Container Linux for AKS (preview). You will no longer be able to create new node pools. AKS will not produce new node images and will no longer provide security patches for existing node pools. AKS will remove Flatcar Container Linux for AKS (preview) node images and existing code on 8 September 2026, meaning that scaling and remediation operations will fail.
- Azure Linux has expanded GPU support to include NVIDIA A100, H100, and H200 VMs. Find the full list of supported GPUs with Azure Linux on AKS here.
Kubernetes Version
- AKS Kubernetes version
1.35is now generally available and being rolled out across regions. Please refer to the components breaking changes for more information. - AKS Kubernetes version
1.32reaches the end of standard support on April 30, 2026. Please upgrade your clusters to a supported version. Refer to the AKS Support Calendar, version support policy for more information. - New Kubernetes patch versions are now available:
1.32.11,1.33.7,1.34.3. - AKS Kubernetes Long Term Support (LTS) version
1.28is deprecated. Please upgrade your clusters to a supported version. Refer to AKS Support Calendar for more information.
For deprecation, rollouts and patch timelines by region, please check the AKS-Release-Tracker.
Preview Features
- Azure Monitor Profile OTLP gRPC support is now available in public preview, enabling OpenTelemetry Protocol gRPC endpoints for Azure Monitor metrics collection.
- ACNS preview feature is now supported on dual-stack clusters.
- Node Auto Provisioning has been updated to Karpenter Azure provider v1.7.2. This release adds a new alpha resource
NodeOverlayfor controlling node priorities and supports two new scheduling labels:kubernetes.azure.com/scalesetpriorityandkubernetes.azure.com/os-sku.
Features
- Application Monitoring auto-instrumentation is now generally available.
- Azure Linux now supports the AI Toolchain Operator (KAITO) add-on for running AI and ML workloads on AKS.
- Private IP support in Static Egress Gateway is now generally available.
Behavioral Changes
- AKS Automatic clusters now enforce multiple layers of defense against remote code execution via
nodes/proxypermissions:- A ValidatingAdmissionPolicy (VAP) restricts creation or updates of ClusterRole and Role objects granting
nodes/proxy, except for approved system users and groups. - An authorization policy denies
nodes/proxyby default. Approved system users, groups, and kube-system service accounts are exempt.
- A ValidatingAdmissionPolicy (VAP) restricts creation or updates of ClusterRole and Role objects granting
- On clusters where ACNS performance is used to enable eBPF host routing, nodes will be labeled with
kubernetes.azure.com/ebpf-host-routing=true. This is done by a node image upgrade. - Service tags for API server authorized IP ranges are now supported for AKS clusters with API server VNet integration.
- AKS now supports configuring Standard V2 Azure NAT Gateway as a user‑assigned NAT gateway for outbound (egress) traffic.
Component Updates
- Cilium has been updated from v1.18.2 to v1.18.6 to address CVEs: CVE-2025-64715 and CVE-2026-26963.
- Retina has been updated to v1.0.3 to address CVE-2013-3900.
- Retina Enterprise has been updated to v0.1.16.
- Konnectivity has been updated to v0.32.1 with bug fixes and dependency updates.
- Microsoft Defender for Containers sensor has been upgraded to v0.9.51 on AKS >= 1.35 and to v0.8.48 on AKS < 1.35. See release notes. The following defender for containers components were updated:
- Inspektor Gadget upgraded from v0.41.1 to v0.41.2.
- Fluent Bit updated from 4.1.1 to 4.2.2.
- Multiple CVEs remediated as part of this change, listed below:
- CVE-2025-68121
- CVE-2024-25621
- CVE-2025-68156
- CVE-2025-52881
- CVE-2025-58183
- CVE-2025-61726
- CVE-2025-61728
- CVE-2025-61729
- CVE-2025-61730
- CVE-2025-64329
- CVE-2026-24137
- CVE-2025-47914
- CVE-2025-58181
- CVE-2025-47912
- CVE-2025-58185
- CVE-2025-58186
- CVE-2025-58187
- CVE-2025-58188
- CVE-2025-58189
- CVE-2025-61723
- CVE-2025-61724
- CVE-2025-61725
- CVE-2025-61727
- Cluster autoscaler images have been updated with CVE fixes across all supported Kubernetes versions: v1.29.5-aks-5, v1.30.7-aks-5, v1.31.5-aks-7, v1.32.3-aks-7, v1.33.1-aks-7, v1.34.1-aks-4.
- Container Insights has been updated to 3.1.35.
- AKS Azure Linux images:
- v3.0 - 202603.04.0.
- AKS Ubuntu images:
- Ubuntu 22.04 - 202603.04.0.
- Ubuntu 24.04 - 202603.04.0.
Release 2026-02-08
Release Notes 2026-02-08
Monitor the release status by regions at AKS-Release-Tracker.
Announcements
- Windows Server 2019 is scheduled for retirement on March 1, 2026. Please transition to Windows Server 2022+ by that date. After that date, AKS will no longer produce new node images or provide security patches for Windows Server 2019. After that date, you will not be able to create new node pools with Windows Server 2019 on any Kubernetes version. All existing node pools with Windows Server 2019 will be unsupported. Windows Server 2019 is not supported in Kubernetes versions >= 1.33. Starting on April 1, 2027, AKS will remove all existing node images for Windows Server 2019 which will result in failure of scaling and remediation (reimage and redeploy) operations.
- Windows Server Annual Channel (Preview) on AKS will be retired on May 15, 2026, please transition to the Long Term Servicing Channel (LTSC) by that date. From now to May 15, 2026 you can continue to use Windows Server Annual Channel (Preview) without disruption. On May 15, 2026, AKS will no longer produce new Windows Server Annual Channel node images or provide security patches. You will not be able to create new node pools with Windows Server Annual Channel. On May 15, 2027, AKS will remove all existing Windows Server Annual Channel node images, which will cause scaling and remediation (reimage and redeploy) operations to fail.
Kubernetes Version
- AKS Kubernetes patch versions
1.34.2,1.33.6, and1.32.10are now available. Refer to version support policy and upgrading a cluster for more information. - AKS Kubernetes version
1.35preview is rolling out to multiple regions and is expected to complete by early March.
Preview Features
- Managed GPU profiles are now available in public preview via API version
2026-01-02-preview. - Blue-green node pool upgrade is now available in public preview via API version
2025-08-02-previewand Azure CLI version2.64.0or higher. - Node pool version rollback is now available in public preview via API version
2025-08-02-previewand Azure CLI version2.64.0or higher.
Features
- API Server VNET Integration is now available in eastus2, eastus3, and belgiumcentral.
- HTTP Proxy and Custom Certificate Authority (CA) are now supported in Node Auto-provisioning (NAP) enabled clusters. Visit HTTP Proxy documentation and Custom CA documentation to enable these features.
Behavioral Changes
- Nodes are now annotated with a
kubernetes.azure.com/security-patch-timestampannotation during a security VHD reboot upgrade. This gives you a unified way to verify when the last security patch was applied to each node. Refer to Autoupgrade Node OS Image FAQs for more information. - By default, AKS no longer creates or updates Network Security Groups on subnets it delegates for Application Gateway for Containers, improving reliability in policy-managed environments.
- To protect against potential security concern of remote code execution via nodes/proxy get permission, AKS Automatic has added multiple layers of defense:
- A ValidatingAdmissionPolicy(VAP) that restrict the use of the Kubernetes nodes/proxy permission. One policy blocks creation or updates of ClusterRole and Role objects granting nodes/proxy, except for approved system users and groups.
- An authorization policy that denies nodes/proxy by default. This prevents exploitation even if a user has already been granted nodes/proxy permission through existing RBAC bindings. Approved system users, groups, and kube-system service accounts are exempt.
- AKS Deployment Safeguards no longer Deny missing startup, liveness, and readiness probe requirements on AKS Automatic clusters. The policy has been changed to warn only. Learn more.
- Gateway API CRDs can now be enabled directly without first requiring a supported gateway implementation such as the Managed Istio service mesh add-on to be enabled on the cluster.
Component Updates
- Konnectivity has been updated to v0.31.4-6 to resolve CVEs: CVE-2025-61729, CVE-2025-61727
- Karpenter has been updated to v1.6.8 to enforce stricter DNS forwarding rules.
- Azure Blob CSI driver has been updated to v1.26.9 (k8s >= 1.32) and v1.27.2 (k8s >= 1.34).
- AKS Windows images:
- Server 2019 – 17763.8276.260120.
- Server 2019 – 17763.8389.260210.
- Server 2022 – 20348.4648.260120.
- Server 2022 – 20348.4773.260210.
- Server 2025 – 26100.32230.260120.
- Server 2025 – 26100.32370.260210.
- AKS Azure Linux images:
- v3.0 - 202512.18.0.
- v3.0 - 202601.07.0.
- v3.0 - 202601.13.0.
- v3.0 - 202601.27.0.
- AKS Ubuntu images:
- Ubuntu 22.04 - 202512.18.0.
- Ubuntu 22.04 - 202601.07.0.
- Ubuntu 22.04 - 202601.13.0.
- Ubuntu 22.04 - 202601.27.0.
- Ubuntu 24.04 - 202512.18.0.
- Ubuntu 24.04 - 202601.07.0.
- Ubuntu 24.04 - 202601.13.0.
- Ubuntu 24.04 - 202601.27.0.
- Managed Prometheus add-on has been updated to v6.24.2.
- The following control plane components have been updated to address security vulnerabilities:
- etcd has been updated to v3.5.22‑5 across all supported AKS versions.
- kube-apiserver/kube-controller-manager/kube-scheduler has been updated to v1.34.0-5 on AKS v1.34.0 and v1.34.1-4 on AKS v1.34.1.
- kubectl has been updated to v1.34.0-6 on AKS v1.34.0 and v1.34.1-5 on AKS v1.34.1.
- ACNS has been updated to v1.16.16 for Kubernetes v1.31 to resolve CVEs: CVE-2025-22874, CVE-2025-47907, CVE-2025-47912, CVE-2025-58183, CVE-2025-58185, CVE-2025-58186, CVE-2025-58187, CVE-2025-58188, CVE-2025-58189, CVE-2025-61723, CVE-2025-61724, CVE-2025-61725, CVE-2025-0913, CVE-2025-4673, CVE-2025-47906, CVE-2025-6297, CVE-2023-4039, CVE-2025-8058, CVE-2025-9230
- Updated Cilium to v1.17.9 for Kubernetes v1.32 and v1.33 to resolve CVEs: CVE-2025-22874, [CVE-2025-47907](https://nvd.ni...