Sitelet https://github.com/kubernetes/kops/pull/18513
Skip to content

Automated cherry pick of ##18479: Upgrade Karpenter to v1.13.0 ##18486: Register Karpenter nodes with karpenter.sh/unregistered taint ##18487: Add missing EC2 read permissions to Karpenter IAM policy ##18497: Add managed Karpenter EC2NodeClass and NodePool - #18513

Merged
kubernetes-prow[bot] merged 9 commits into
kubernetes:release-1.36from
hakman:automated-cherry-pick-of-##18479-##18486-##18487-##18497-upstream-release-1.36
Jun 26, 2026

Conversation

@hakman

@hakman hakman commented Jun 26, 2026

Copy link
Copy Markdown
Member

Cherry pick of ##18479 ##18486 ##18487 ##18497 on release-1.36.

##18479: Upgrade Karpenter to v1.13.0
##18486: Register Karpenter nodes with karpenter.sh/unregistered taint
##18487: Add missing EC2 read permissions to Karpenter IAM policy
##18497: Add managed Karpenter EC2NodeClass and NodePool

For details on the cherry pick process, see the cherry pick requests page.

What type of PR is this?


hakman added 9 commits June 26, 2026 20:47
Signed-off-by: Ciprian Hacman <ciprian@hakman.dev>
…depool

The karpenter.sh/provisioner-name label is a Karpenter v1alpha5 relic. Since
v1beta1/v1, Karpenter applies karpenter.sh/nodepool to the nodes it provisions.
Update the controller's anti-self-scheduling affinity to match Karpenter's own
v1 label (also the upstream chart default), and stop setting the obsolete
provisioner-name label on Karpenter-managed nodes.

Signed-off-by: Ciprian Hacman <ciprian@hakman.dev>
kOps supports Kubernetes 1.31+, where node-role.kubernetes.io/master no longer
exists (removed in 1.24/1.25) and kOps only labels control-plane nodes with
node-role.kubernetes.io/control-plane. The second nodeSelectorTerm keyed on the
master label can never match, so the control-plane term alone suffices.

Signed-off-by: Ciprian Hacman <ciprian@hakman.dev>
Adopt the same kustomize-based generation as the Azure CCM/CSI addons: the
upstream chart is pulled via a kustomization.yaml helmChart, kops customizations
(image, dnsPolicy, feature gates) are declarative patches, and the manifest is
regenerated with regenerate.sh. This replaces the manual 'helm template' command
plus hand-applied customizations, which required a 3-way merge to preserve on
every version bump. Controller replicas are now fixed at 1, matching the other
kustomize-generated addons.

Signed-off-by: Ciprian Hacman <ciprian@hakman.dev>
Signed-off-by: Ciprian Hacman <ciprian@hakman.dev>
Signed-off-by: Ciprian Hacman <ciprian@hakman.dev>
Signed-off-by: Ciprian Hacman <ciprian@hakman.dev>
Signed-off-by: Ciprian Hacman <ciprian@hakman.dev>
Signed-off-by: Ciprian Hacman <ciprian@hakman.dev>
@kubernetes-prow kubernetes-prow Bot added this to the v1.36 milestone Jun 26, 2026
@kubernetes-prow
kubernetes-prow Bot requested review from olemarkus and zetaab June 26, 2026 17:47
@kubernetes-prow kubernetes-prow Bot added area/addons area/api area/documentation size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. area/provider/aws Issues or PRs related to aws provider cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. labels Jun 26, 2026
@hakman

hakman commented Jun 26, 2026

Copy link
Copy Markdown
Member Author

/cc @rifelpet

@kubernetes-prow
kubernetes-prow Bot requested a review from rifelpet June 26, 2026 17:48
@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Jun 26, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: rifelpet

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jun 26, 2026
@kubernetes-prow
kubernetes-prow Bot merged commit 6b8ea50 into kubernetes:release-1.36 Jun 26, 2026
18 checks passed
social4hyq pushed a commit to social4hyq/homebrew-core that referenced this pull request Sep 20, 2026
kops 1.36.0

Created-by: HarmonybrewBot
Commit-by: HarmonybrewBot
Merged-by: HarmonybrewBot
Description: Created by `brew bump`

---

Created with `brew bump-formula-pr`.<details>
  <summary>release notes</summary>
  <pre>See the full [kOps 1.36 release notes](https://kops.sigs.k8s.io/releases/1.36-notes/) for details, including breaking changes and deprecations.

## Highlights

* **Kubernetes 1.36 support** and completion of the move away from the in-tree cloud providers
* **Reworked addon management**: `kops-channels` now runs as a static pod on control-plane nodes; the standalone `channels` binary is no longer distributed
* **Hybrid bootstrap for gossip clusters**: workers bootstrap directly against the API load balancer, easing migration off gossip DNS, which is deprecated
* **Karpenter refresh**: Karpenter v1.13.0 with kOps-managed `EC2NodeClass` and `NodePool` objects per instance group
* **etcd-manager improvements**: recovery of members with replaced data disks, membership changes resilient to unreachable members, a distroless image, and faster single-member cluster startup
* **Expanded Azure support**: cloud-controller-manager, Azure Disk CSI driver, and experimental Terraform target
* **Hetzner Cluster Autoscaler support** and groundwork for Linode (Akamai) as a new cloud provider
* **Component updates**: containerd v2.2.4, etcd-manager v3.0.20260707 with etcd 3.5.31/3.6.12, AWS Load Balancer Controller v3.3.0, Cilium tunables, CoreDNS v1.14.2, cluster-autoscaler v1.36.0
* **Removed**: support for Kubernetes 1.30, etcd 3.4, Amazon Linux 2, Ubuntu 20.04, and Debian 10

## What's Changed
* Automated cherry pick of #18467: aws: Reconcile target group health check changes on existing target groups by @hakman in kubernetes/kops#18469
* Automated cherry pick of #18484: gce: emit kops.k8s.io/instancegroup node label by @rifelpet in kubernetes/kops#18488
* Automated cherry pick of #18478: nodeup: load ip_set module and disable firewalld on RHEL10 by @rifelpet in kubernetes/kops#18492
* Automated cherry pick of #18498: Remove namespace from DO ClusterRole by @rifelpet in kubernetes/kops#18499
* Automated cherry pick of #18511: Allow setting missing slice elements from the command line by @hakman in kubernetes/kops#18512
* Automated cherry pick of ##18479: Upgrade Karpenter to v1.13.0 
##18486: Register Karpenter nodes with karpenter.sh/unregistered taint
##18487: Add missing EC2 read permissions to Karpenter IAM policy
##18497: Add managed Karpenter EC2NodeClass and NodePool by @hakman in kubernetes/kops#18513
* Automated cherry pick of #18522: azure: Scope nodes-to-API NSG rules to the NAT gateway public IP by @hakman in kubernetes/kops#18523
* Automated cherry pick of #18527: azure: Bump azuredisk-csi-driver to v1.34.4 by @hakman in kubernetes/kops#18528
* Automated cherry pick of #18529: azure: Bump azure-cloud-controller-manager to v1.36.2 by @hakman in kubernetes/kops#18531
* Automated cherry pick of #18533: azure: Grant control-plane VMSS Contributor instead of Owner by @hakman in kubernetes/kops#18534
* Automated cherry pick of #18535: coredns: Honor node taints in hostname topologySpreadConstraint by @hakman in kubernetes/kops#18536
* Automated cherry pick of #18538: hetzner: fix Cluster Autoscaler node group membership by @hakman in kubernetes/kops#18539
* Automated cherry pick of #18541: Update cluster-autoscaler to v1.36.0 by @hakman in kubernetes/kops#18542
* Automated cherry pick of #18543: gce: register all zonal MIGs of a multi-zone instance group with cluster-autoscaler by @hakman in kubernetes/kops#18544
* Automated cherry pick of #18546: Update Go to 1.26.5 and bump golang.org/x modules by @hakman in kubernetes/kops#18547
* Cherry pick of #18560: etcd-manager: upgrade to v3.0.20260707 by @hakman in kubernetes/kops#18561
* Automated cherry pick of #18556: feat(api): add storageInitializationTimeout to KubeAPIServerConfig by @hakman in kubernetes/kops#18558
* Cherry pick of #18549: Replace fi.PtrTo with new() builtin by @hakman in kubernetes/kops#18551
* Automated cherry pick of #18567: dns-controller: always apply the addon, empty when unused by @hakman in kubernetes/kops#18573
* Release 1.36.0 by @hakman in kubernetes/kops#18591


**Full Changelog**: https://github.com/kubernetes/kops/compare/v1.36.0-beta.1...v1.36.0</pre>
  <p>View the full release notes at <a href="/sitelet?url=https%3A%2F%2Fgithub.com%2Fkubernetes%2Fkops%2Fpull%2F%253Ca%2520href%3D"https://github.com/kubernetes/kops/releases/tag/v1.36.0">https://github.com/kubernetes/kops/releases/tag/v1.36.0</a>.</p">https://github.com/kubernetes/kops/releases/tag/v1.36.0">https://github.com/kubernetes/kops/releases/tag/v1.36.0</a>.</p>
</details>
<hr>

See merge request: Harmonybrew/homebrew-core!14334
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/addons area/api area/documentation area/provider/aws Issues or PRs related to aws provider cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants