NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #1037 most downloaded on crates.io
Kubernetes client
Last release 2 months ago
22 Jul 2026
Ships fairly regularly
a new release about every 2 months
Rarely documented
notes for 11 of 58 stable releases
2 versions withdrawn
withdrawn after publishing
5 years old
60 releases · first in 2021
One column per quarter.
Maintenance release for 4.0.0. Fixes, and https proxy. MSRV 1.89. All PRs here .
Maintenance release for 4.0.0. Fixes, and https proxy. MSRV 1.89. All PRs here.
CommitError's error message by @iniw in #2020Display messages at client, core, runtime by @doxxx93 in #2021Sync bound in Controller::reconcile_all_on by @bojidar-bg in #2029ObjectMeta per event in trigger_owners by @doxxx93 in #2039CustomResourceDefinition in derived crd() by @doxxx93 in #2042Full Changelog: 4.0.0...4.2.0
deserialization changed from serde-yaml to serde-saphyr to get rid of the long-deprecated dependency. #1975
As per the release schedule to match up with the latest Kubernetes ハル release.
Lots of fixes and improvements. Thanks to everyone who contributed!
v1_36 support via k8s-openapi 0.28Please upgrade k8s-openapi along with kube to avoid conflicts.
A new optional crate kube-cel is being re-exported through kube::core::cel via #1954
Kubernetes CRDs support CEL validation rules via x-kubernetes-validations, and were supported from 3.0 via KubeSchema, but these rules could only be evaluated server-side by the API server.
The new crate allows evaluating these rules locally using rules matching the upstream Kubernetes CEL libraries.
While low-level, a higher-level CEL validator integrates with CustomResource via #[kube(cel)] from #2011 and can be used as;
#[derive(CustomResource, Serialize, Deserialize, Clone, KubeSchema)]
#[kube(group = "example.com", version = "v1", kind = "Foo", namespaced)]
#[kube(cel, validation = "self.spec.replicas >= 0")] // cel trigger + validation rule
struct FooSpec { replicas: i32 }
let foo = Foo::new("test", FooSpec { replicas: -1 });
foo.validate_cel()?; // new impl; checks creation rules
new_foo.validate_cel_update(&old_foo)?; // new impl; checks transition rulesSee examples/crd_derive_cel.rs for more details.
This is available under the kube/cel feature, courtesy of @doxxx93.
A lot of improvements to config handling;
Kubeconfig fields in #1965Kubeconfig future key compatibility for new fields by adding catch-all other key via #1964serde-yaml to serde-saphyr to get rid of the long-deprecated dependency. #1975Better timeout and retry handling to better deal with flaky network conditions, and busy or initializing apiservers.
watcher level timeouts in #1945 (see #1798 for context)RetryPolicy - now enabled by default in #2007.tls-server-name with openssl-tls via #1993yaml output from exec plugins via #2003ws task leak and drop, and a deadlock on join() via #1978watcher automatically uses the metadata_ api methods when called with PartialObjectMeta<K> via #1952
metadata_watcher in favor of an explicit change from Api::<K> to Api::<PartialObjectMeta<K>>)wait::conditions::is_created as a counter to is_deleted #2000Store::state_filtered and Store::state_filter_selector to allow more efficient slicing of the locked cache via #2002 + #1998AdmissionRequest::to_cel_request() for VAP CEL bridging by @doxxx93 in #1991Store::state_with and Store::state_filtered by @Alvov1 in #1998wait::conditions::is_created helper by @orangecms in #2000RetryPolicy::server_retry by default for Client by @Danil-Grigorev in #2007Full Changelog: 3.1.0...4.0.0
Maintenance release with fixes for schemas/validation, client exec blocking and proxy handling, as well as some smaller new features listed below. Int
Maintenance release with fixes for schemas/validation, client exec blocking and proxy handling, as well as some smaller new features listed below. Internal changes and documentation improvements listed in the milestone.
Rule by @Immortal-Beyond-Oblivion in #1947Full Changelog: 3.0.1...3.1.0
Bugfix release for schemas, admission, and docs. Minor internal improvements listed in the milestone . Important fixes below.
Bugfix release for schemas, admission, and docs. Minor internal improvements listed in the milestone. Important fixes below.
AdmissionResponse created via invalid call by @Magicloud in #1905OptionalEnum transform skipping schemas with description by @doxxx93 in #1908additionalProperties: false from schema by @doxxx93 in #1920Full Changelog: 3.0.0...3.0.1
This creates a small breaking change for users matching on specific Error::Api codes;
As per the new release schedule to match up with the new Kubernetes release.
Lots of additions, fixes and improvements. Thanks to everyone who contributed so heavily over the holidays! Happy new year.
v1_35 support via k8s-openapi 0.27Please upgrade k8s-openapi along with kube to avoid conflicts.
jiff replaces chronoMatching k8s-openapi's change, kube has also swapped out chrono. The biggest impact of this is for interacting with timestamps in metadata, but it also updates 2 smaller public interfaces in LogParams, Client::with_valid_until. See controller-rs#217 for an example change.
ErrorResponse has been replaced with StatusErrorResponse served as a partial metav1/Status replacement which ended up hiding error information to users. These structs have merged, more information is available on errors, and a type alias with a deprecation warning is in place for ErrorResponse which will be removed in a later version.
This creates a small breaking change for users matching on specific Error::Api codes;
.map_err(|error| match error {
- kube::Error::Api(kube::error::ErrorResponse { code: 403, .. }) => {
- Error::UnauthorizedToPatch(obj)
- }
+ kube::Error::Api(s) if s.is_forbidden() => Error::UnauthorizedToPatch(obj),
other => Error::Other(other),
})?;This prevents unbounded memory for controllers, particularly affecting ones watching quickly rotating objects with generated names (e.g. pods). By default the TTL is 1h. It can be configured via new PredicateConfig parameter. To use the default;
- .predicate_filter(predicates::resource_version);
+ .predicate_filter(predicates::resource_version, Default::default());Change in #1836. This helped expose and fix a bug in watches with streaming_lists now fixed in #1882.
Some subresource write methods were public with inconsistent signatures that required less ergonomic use than any other write methods. They took a Vec<u8> for the post body, now they take a &K: Serialize or the actual subresource.
There affect Api::create_subresource, Api::replace_subresource, Api::replace_status, Api::replace_scale. In essence this generally means you do not have to wrap raw objects in json! and serde_json::to_vec for these calls and lean more on rust's typed objects rather than json! blobs which has some footguns for subresources.
- let o = foos.replace_status("qux", &pp, serde_json::to_vec(&object)?).await?;
+ let o = foos.replace_status("qux", &pp, &object).await?;See some more shifts in examples in the implementaion; #1884
Speeds up api discovery significantly by using the newer api with much less round-tripping.
To opt-in change Discovery::run() to Discovery::run_aggregated()
Changes; #1876 + #1873 + #1889
RetryPolicy opt-inAllows custom clients (for now) to enable exponential backoff'd retries for retryable errors by exposing a tower::retry::Policy for a tower::retry::Layer. See the new custom_client_retry example for details.
Enabled by a clonable body + the new RetryPolicy based on mirrord's solution*.
While this is mostly for internal ergonomics, we would like to highlight this also simplifies the Condition implementors which had to deal with a lot of options;
pub fn is_job_completed() -> impl Condition<Job> {
|obj: Option<&Job>| {
- if let Some(job) = &obj {
- if let Some(s) = &job.status {
- if let Some(conds) = &s.conditions {
- if let Some(pcond) = conds.iter().find(|c| c.type_ == "Complete") {
- return pcond.status == "True";
- }
- }
- }
+ if let Some(job) = &obj
+ && let Some(s) = &job.status
+ && let Some(conds) = &s.conditions
+ && let Some(pcond) = conds.iter().find(|c| c.type_ == "Complete")
+ {
+ return pcond.status == "True";Resize subresource impl for Pod - #1851#[kube(attr="...") to allow custom attrs on derives - #1850Resize subresource for Pod by @hugoponthieu in #1851try_clone method for kube_client::client::Body when it's Kind::Once by @meowjesty in #1867predicate_filter by @doxxx93 in #1838chrono with jiff by @ngergs in #1868k8s-openapi for Kubernetes 1.35 by @clux in #1898Full Changelog: 2.0.1...3.0.0
Fixes an accidental inclusion of a constraint added to Api::log_stream introduced in the 2.0.0 Rust 2024 upgrade.
Fixes an accidental inclusion of a constraint added to Api::log_stream introduced in the 2.0.0 Rust 2024 upgrade.
Full Changelog: 2.0.0...2.0.1
Kubernetes v1_34 support via k8s-openapi 0.26
v1_34 support via k8s-openapi 0.26Please upgrade k8s-openapi along with kube to avoid conflicts.
A fairly significant upgrade in #1780. Our external facing API should be unchanged, although some schemars public import paths have changed. Note that if you are implementing schemars traits directly, then see the upstream schemars/migrating (and maybe consider using KubeSchema for relevant schema overrides).
Please upgrade schemars along with kube for this version to avoid conflicts.
Minimum versions: MSRV 1.85.0 (for edition 2024), MK8SV: 1.30 (unchanged).
This version is contains fixes, dependency clearups, and dependency updates. Noteworthy additions are TryFrom impls for Kubeconfig users in #1801, and a namespace accessor in Api in #1788
A new semver major for unstable, public facing dependency updates. As per the new release cycle, it is aligned with the Kubernetes release.
TryFrom conversions for Kubeconfig -> Config -> Client by @Danil-Grigorev in #1801hyper-socks2 with hyper-util client-proxy feature by @tottoto in #1795Full Changelog: 1.1.0...2.0.0
Missing attribute bugfix + extra standard derives on core::conversion structs.
Missing attribute bugfix + extra standard derives on core::conversion structs.
Full Changelog: 1.0.0...1.1.0
This is a somewhat symbolic gesture, because semver-breaking changes are still hard to avoid with a large set of sub-1.0 dependencies we need to bump,…
It's been a long time coming, but time has come to draw the line in the sand. No alphas, no betas. Hope it finds you all well. Thanks to everyone who has contributed over the years.
This is a somewhat symbolic gesture, because semver-breaking changes are still hard to avoid with a large set of sub-1.0 dependencies we need to bump, as well as managing the large api surface of Kubernetes.
Therefore, the plan is to align our breaking changes and major bumps with Kubernetes versions / k8s-openapi versions for now, and this should allow our other releases to stream in. See #1688 for more information.
v1_33 support via k8s-openapi 0.25Please upgrade k8s-openapi along with kube to avoid conflicts.
New minimum versions: MSRV 1.82.0, MK8SV: 1.30*
The CELSchema alternate derive for JsonSchema has been renamed to KubeSchema to indicate the increased functionality.
In addition to being able to inject CEL rules for validations, it can now also inject x-kubernetes properties such as merge-strategy via #1750, handle #[validate] attributes #1749, and pass validation rules as string literals #1754 :
#[derive(CustomResource, Serialize, Deserialize, Debug, PartialEq, Clone, KubeSchema)]
#[kube(...properties)
struct DocumentSpec {
/// New merge strategy support
#[x_kube(merge_strategy = ListMerge::Set)]
x_kubernetes_set: Vec<String>,
/// CEL Validation now lives on x_kube and supports literal Rules:
#[x_kube(validation = "!has(self.variantOne) || self.variantOne.int > 22")]
complex_enum: ComplexEnum,
}See kube.rs docs on validation for more info. Huge thanks to @Danil-Grigorev.
hyper-util/tracing feature flag by @cratelyn in #1734x-kubernetes-* schema extensions by @Danil-Grigorev in #1750k8s-openapi to 0.25.0 by @clux in #1756CELSchema by @Danil-Grigorev in #1747CELSchema by @Danil-Grigorev in #1749Full Changelog: 0.99.0...1.0.0
CustomResource derive; typed attributes for #[kube(scale)] and #[kube(deprecated)] in #1656 + #1697
backoff (unmaintained) replaced with backon in #1653
default_backoff natively, or through Controller.ExponentialBackoff from backon::ExponentialBuilder into WatchStreamExt::backoffjson-patch bumped and uses re-exported jsonptr for less version clashes #1718rand dependency no longer explicit as only rng is under ws feature via tungstenite's client::generate_key #1691ring (still maintained) now optional for rustls-tls feature (for alternate aws-lc-rs) #1717v5.channel.k8s.io streaming ws protocol to allow closing streams properly (kubernetes.io blog) #1693CustomResource derive; typed attributes for #[kube(scale)] and #[kube(deprecated)] in #1656 + #1697Client::with_valid_until to handle short lived local client certs #1707conditions that can be awaited #1710Api::get_metadata_opt_with by @sebsoto in #1708Client::with_valid_until for client cert expiry by @goenning in #1707ExponentialBackoff public by @gdeleon2 in #1716backoff with backon by @flavio in #1653rand to 0.9 by @clux in #1686rand dependency in favor of tungstenite fn by @clux in #1691json-patch to 4 use bundled jsonptr to 0.7 by @clux in #1718CustomResource derive; allow status attribute to take a path by @clux in #1704Full Changelog: 0.98.0...0.99.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Compare
Compare
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →