Sitelet https://github.com/kubernetes/kops/pull/18683
Skip to content

containerd: default to 2.3.4 / runc 1.4.3 - #18683

Merged
kubernetes-prow[bot] merged 6 commits into
kubernetes:masterfrom
hakman:containerd-min-2.1-default-2.3.4
Aug 13, 2026
Merged

kubernetes-prow[bot] merged 6 commits into
kubernetes:masterfrom
hakman:containerd-min-2.1-default-2.3.4

Conversation

@hakman

@hakman hakman commented Aug 13, 2026

Copy link
Copy Markdown
Member

This prepares the containerd stack for kOps 1.37, driven by the upstream EOL calendar: containerd 1.6, 1.7, and 2.1 are already end of life, 2.2 reaches EOL in November 2026, and 2.0 reaches EOL in March 2027, all within the kOps 1.37 support window. The only supported lines with image volume support are 2.2 and 2.3 (LTS, supported to April 2028).

  • Raise the minimum supported containerd version from 1.3.4 to 2.1.0. Versions below that now fail validation. A single bump avoids breaking 2.0 pinners twice, and with the floor at 2.1, every etcd-manager on Kubernetes >= 1.33 uses image volumes; the kops-utils-cp copy path now only serves Kubernetes 1.32 and can be removed in kOps 1.38.
  • Bump the default to containerd 2.3.4 with runc 1.4.3. 2.3.4 is the first usable 2.3.x release: 2.3.0 through 2.3.3 fail RunPodSandbox when the sandbox image is pinned by digest, which kops emits by default (CRI: tag+digest sandbox image breaks RunPodSandbox containerd/containerd#13529, fixed by cri: auto-add prefix for pause image containerd/containerd#13513 and verified against 2.3.4).
  • Remove code that only served containerd 1.x: the v2 config schema builder (the v3 schema is emitted unconditionally; config version 4 from containerd 2.3 is not used because 2.1/2.2 reject it and 2.3 migrates v3 on load), the pre-1.6 tarball layout fallbacks in nodeup, and the cri-containerd-cni bundle URL.
  • Add well-known asset hashes for containerd 2.3.x, runc 1.4.3, and the latest Kubernetes patch releases (1.33.13, 1.34.10, 1.35.7, 1.36.3).

/cc @rifelpet @ameukam

@kubernetes-prow
kubernetes-prow Bot requested review from ameukam and rifelpet August 13, 2026 05:22
@kubernetes-prow kubernetes-prow Bot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. area/api area/documentation area/nodeup labels Aug 13, 2026
@ameukam

ameukam commented Aug 13, 2026

Copy link
Copy Markdown
Member

/lgtm
(from the beach with love)

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Aug 13, 2026
@hakman

hakman commented Aug 13, 2026

Copy link
Copy Markdown
Member Author

Thanks @ameukam, enjoy the beach! 😎
/approve

@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: hakman

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 13, 2026
@kubernetes-prow
kubernetes-prow Bot merged commit 8892516 into kubernetes:master Aug 13, 2026
40 checks passed
@hakman
hakman deleted the containerd-min-2.1-default-2.3.4 branch August 13, 2026 07:50
rifelpet added a commit to rifelpet/test-infra that referenced this pull request Aug 16, 2026
Adds cos129 and cos129arm64, pinned to cos-129-19506-299-116, tested
against kops latest and 1.36. This follows the convention the other
recently added distros use: a new image is only exercised on the newer
kops branches.

At the same time, stop testing cos121 on kops latest and 1.36. kops
master now requires containerd 2.1.0 or newer (kubernetes/kops#18683),
while cos121 is pinned to containerd 2.0.7 because COS 121 cannot run
2.1+, so every cos121 job on kops latest fails at cluster creation:

  Error: spec.containerd.version: Invalid value: "2.0.7": unsupported
  legacy version; containerd 2.1.0 or newer is required

The 1.36 jobs still pass, since the release branch does not carry that
floor; dropping them as well is an age-out decision.

Note that dropping the newer branches requires passing None to
drop_unsupported_versions, because None is the entry that maps to
"latest kops" -- filtering only on version strings would have left
cos121 on latest, the broken combination, while removing the 1.36 jobs
that still work.

Also register the kops-distro-cos129 testgrid dashboard, in both the
dashboard group and the dashboard list, so the new jobs' annotations
resolve.

No kops changes are needed. ContainerOS is a single version-agnostic
distribution there: util/pkg/distributions/identify.go matches any "cos-"
prefix and DistributionContainerOS carries no version, so every COS
behavior in nodeup keys off that one constant.

Net effect is 78 job additions and 72 removals. The remaining line churn
in the generated files is cron reassignment for jobs whose position
shifted, not a change to those jobs.
alien1403 pushed a commit to alien1403/test-infra that referenced this pull request Aug 19, 2026
Adds cos129 and cos129arm64, pinned to cos-129-19506-299-116, tested
against kops latest and 1.36. This follows the convention the other
recently added distros use: a new image is only exercised on the newer
kops branches.

At the same time, stop testing cos121 on kops latest and 1.36. kops
master now requires containerd 2.1.0 or newer (kubernetes/kops#18683),
while cos121 is pinned to containerd 2.0.7 because COS 121 cannot run
2.1+, so every cos121 job on kops latest fails at cluster creation:

  Error: spec.containerd.version: Invalid value: "2.0.7": unsupported
  legacy version; containerd 2.1.0 or newer is required

The 1.36 jobs still pass, since the release branch does not carry that
floor; dropping them as well is an age-out decision.

Note that dropping the newer branches requires passing None to
drop_unsupported_versions, because None is the entry that maps to
"latest kops" -- filtering only on version strings would have left
cos121 on latest, the broken combination, while removing the 1.36 jobs
that still work.

Also register the kops-distro-cos129 testgrid dashboard, in both the
dashboard group and the dashboard list, so the new jobs' annotations
resolve.

No kops changes are needed. ContainerOS is a single version-agnostic
distribution there: util/pkg/distributions/identify.go matches any "cos-"
prefix and DistributionContainerOS carries no version, so every COS
behavior in nodeup keys off that one constant.

Net effect is 78 job additions and 72 removals. The remaining line churn
in the generated files is cron reassignment for jobs whose position
shifted, not a change to those jobs.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/api area/documentation area/nodeup cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants