logo

Kubernetes 1.35 - New security features

ID: c7b0bd35-cec8-50f7-8d4a-78b64f247770

STIX ID: report--c7b0bd35-cec8-50f7-8d4a-78b64f247770

Feed Name: Sysdig Blog

Date Published: 2025-12-02

Date Updated: 2026-05-01

...
...

Kubernetes 1.35 introduces 17 security-related changes, including breaking defaults (cgroup v1 disabled, stricter image pull credential verification, SPDY-to-WebSockets with RBAC 'create' requirement), new alpha features (constrained impersonation, hostNetwork with user namespaces, CSI service account tokens via secrets), and several promotions to beta/stable (pod certificates, user namespaces, OCI image volumes, structured auth config, supplemental groups policy, kubelet config drop-ins), along with removal of gogo protobuf dependencies and diagnostic flagz. Admins should audit RBAC, kubelet certificates and runtimes, registry and image policies, and monitoring thresholds before upgrading to avoid disruptions and strengthen security posture.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.