NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #741 by repository stars
Last release 2 days ago
06 Oct 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 56 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
647 releases · first in 2018
chore: bump to go 1.26.6 by @zac-nixon in #3865
Full Changelog: v1.23.1...v1.23.2
To manually apply this release:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.23.2/config/master/aws-k8s-cni.yaml
Note that the following regions use different manifests:
us-gov-east-1:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.23.2/config/master/aws-k8s-cni-us-gov-east-1.yaml
us-gov-west-1:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.23.2/config/master/aws-k8s-cni-us-gov-west-1.yaml
cn:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.23.2/config/master/aws-k8s-cni-cn.yaml
To apply this release using helm:
Follow the installation instructions in https://github.com/aws/amazon-vpc-cni-k8s/blob/v1.23.2/charts/aws-vpc-cni/README.md#installing-the-chart
Verify the update:
$ kubectl describe daemonset aws-node -n kube-system | grep Image | cut -d "/" -f 2-3
amazon-k8s-cni-init:v1.23.2
amazon-k8s-cni:v1.23.2
amazon/aws-network-policy-agent:v1.4.3
One column per quarter.
DescribeSubnets call for ENI subnet discovery fails (#3843, @cdirubbio)sagemaker:AttachClusterNodeNetworkInterface API for HyperPod nodes (#3874, @AshwinS27)aws-dependencies group with 11 updates (aws-sdk-go-v2 services, smithy-go) (#3850)k8s-dependencies group with 4 updates (#3866)other-deps group with 2 updates (docker/setup-qemu-action, docker/setup-buildx-action) (#3870)google.golang.org/grpc from 1.83.1 to 1.83.2 (#3867)github.com/containernetworking/plugins from 1.9.0 to 1.9.1 (#3851)google.golang.org/protobuf to 1.36.12 (#3853)helm.sh/helm/v4 from 4.2.2 to 4.3.0 (#3852)aws-actions/configure-aws-credentials from 6.2.3 to 6.2.4 (#3860)test: pin busybox and curl image by @Issacwww in #3820
Full Changelog: v1.23.0...v1.23.1
To manually apply this release:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.23.1/config/master/aws-k8s-cni.yaml
Note that the following regions use different manifests:
us-gov-east-1:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.23.1/config/master/aws-k8s-cni-us-gov-east-1.yaml
us-gov-west-1:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.23.1/config/master/aws-k8s-cni-us-gov-west-1.yaml
cn:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/refs/heads/v1.23.1/config/master/aws-k8s-cni-cn.yaml
To apply this release using helm:
Follow the installation instructions in https://github.com/aws/amazon-vpc-cni-k8s/blob/v1.23.1/charts/aws-vpc-cni/README.md#installing-the-chart
Verify the update:
$ kubectl describe daemonset aws-node -n kube-system | grep Image | cut -d "/" -f 2-3
amazon-k8s-cni-init:v1.23.1
amazon-k8s-cni:v1.23.1
amazon/aws-network-policy-agent:v1.4.2
NodeIPv4, NodeIPv6, and InstanceID from ipamd instead of querying IMDS (#3827, @viveksb007)Region to NetworkPolicyAgentConfigReply so the agent can resolve its region without calling IMDS (#3829, @viveksb007)getENIMetadata) (#3681, @cdirubbio)primaryIP map entry when an ENI is freed in tryFreeENI (#3727)podMonitor.scrapeTimeout in the PodMonitor template (#3804, @OdaloV)github.com/go-logr/logr from 1.4.3 to 1.4.4 (#3817)aws-dependencies group with 11 updates (aws-sdk-go-v2 services, vpc-resource-controller, smithy-go) (#3815)github.com/apparentlymart/go-cidr from 1.1.0 to 1.1.1 (#3816)oras.land/oras-go/v2 from 2.6.1 to 2.6.2 (#3828)github.com/aws/amazon-vpc-cni-k8s (test/agent) from 1.22.3 to 1.22.4 (#3814)actions/stale from 10.4.0 to 11.0.0 (#3812)aws-actions/configure-aws-credentials from 6.2.2 to 6.2.3 (#3794)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Warning If you have Network Policy enabled, Amazon VPC CNI v1.23.0 must be paired with Network Policy Agent v1.4.1. This release moves communication w
Warning
If you have Network Policy enabled, Amazon VPC CNI v1.23.0 must be paired with Network Policy Agent v1.4.1. This release moves communication with IPAMD from TCP to a Unix domain socket, which earlier Network Policy Agent versions do not support. Upgrade both components together to maintain Network Policy functionality.
VPC CNI v1.23.0 also moves the aws-node liveness and readiness probes from TCP port 50051 to unix:///var/run/aws-node/ipamd.sock.The v1.23.0 Helm chart and installation manifests include the updated probe configuration. Self-managed users should use the v1.23.0 chart or manifests and update any custom livenessProbe or readinessProbe overrides that still target :50051; otherwise, aws-node may fail its health checks and restart or remain unready.
If customer wants to rollback from this version, they must rollback to version v1.22.4, if they use Network Policy feature.
Full Changelog: v1.22.4...v1.23.0
To manually apply this release:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.23.0/config/master/aws-k8s-cni.yaml
Note that the following regions use different manifests:
us-gov-east-1:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.23.0/config/master/aws-k8s-cni-us-gov-east-1.yaml
us-gov-west-1:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.23.0/config/master/aws-k8s-cni-us-gov-west-1.yaml
cn:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/refs/heads/v1.23.0/config/master/aws-k8s-cni-cn.yaml
To apply this release using helm:
Follow the installation instructions in https://github.com/aws/amazon-vpc-cni-k8s/blob/v1.23.0/charts/aws-vpc-cni/README.md#installing-the-chart
Verify the update:
$ kubectl describe daemonset aws-node -n kube-system | grep Image | cut -d "/" -f 2-3
amazon-k8s-cni-init:v1.23.0
amazon-k8s-cni:v1.23.0
amazon/aws-network-policy-agent:v1.4.1
[!WARNING] This release must be run with Network Policy Agent
v1.4.1. #3739 moves the IPAMD gRPC server from a TCP port to a Unix domain socket, so the Network Policy Agent must be onv1.4.1to connect over the socket.
Warning If you have Network Policy enabled , this release is not backward compatible. The Network Policy Agent's internal pod identifier format has ch
Warning
If you have Network Policy enabled, this release is not backward compatible. The Network Policy Agent's internal pod identifier format has changed. Existing enforcement state is migrated automatically on upgrade, but if you later downgrade, enforcement will not apply to pods created before the rollback until their nodes are replaced. If you do not use Network Policy, this change does not affect you.
Full Changelog: v1.22.3...v1.22.4
To manually apply this release:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.22.4/config/master/aws-k8s-cni.yaml
Note that the following regions use different manifests:
us-gov-east-1:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.22.4/config/master/aws-k8s-cni-us-gov-east-1.yaml
us-gov-west-1:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.22.4/config/master/aws-k8s-cni-us-gov-west-1.yaml
cn:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/refs/heads/v1.22.4/config/master/aws-k8s-cni-cn.yaml
To apply this release using helm:
Follow the installation instructions in https://github.com/aws/amazon-vpc-cni-k8s/blob/v1.22.4/charts/aws-vpc-cni/README.md#installing-the-chart
Verify the update:
$ kubectl describe daemonset aws-node -n kube-system | grep Image | cut -d "/" -f 2-3
amazon-k8s-cni-init:v1.22.4
amazon-k8s-cni:v1.22.4
amazon/aws-network-policy-agent:v1.4.0
Nothing published for this version
This release updates the Amazon VPC CNI images to an Amazon Linux 2023 (AL2023)-based image.
This release updates the Amazon VPC CNI images to an Amazon Linux 2023 (AL2023)-based image.
Warning
If you are using Sagemaker HyperPod on Amazon EKS, please upgrade to version v1.22.4 as v1.22.0-v1.22.3 contain an issue with Enhanced Subnet Discovery on HyperPod.
Full Changelog: v1.22.2...v1.22.3
To manually apply this release:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.22.3/config/master/aws-k8s-cni.yaml
Note that the following regions use different manifests:
us-gov-east-1:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.22.3/config/master/aws-k8s-cni-us-gov-east-1.yaml
us-gov-west-1:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.22.3/config/master/aws-k8s-cni-us-gov-west-1.yaml
cn:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/refs/heads/v1.22.3/config/master/aws-k8s-cni-cn.yaml
To apply this release using helm:
Follow the installation instructions in https://github.com/aws/amazon-vpc-cni-k8s/blob/v1.22.3/charts/aws-vpc-cni/README.md#installing-the-chart
Verify the update:
$ kubectl describe daemonset aws-node -n kube-system | grep Image | cut -d "/" -f 2-3
amazon-k8s-cni-init:v1.22.3
amazon-k8s-cni:v1.22.3
amazon/aws-network-policy-agent:v1.3.7
⚠️ Warning: VPC CNI v1.22.2 reverts the Security Group discovery feature initially introduced in the previous version, v1.22.1.
Warning
If you are using Sagemaker HyperPod on Amazon EKS, please upgrade to version v1.22.4 as v1.22.0-v1.22.3 contain an issue with Enhanced Subnet Discovery on HyperPod.
Full Changelog: v1.22.1...v1.22.2
To manually apply this release:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.22.2/config/master/aws-k8s-cni.yaml
Note that the following regions use different manifests:
us-gov-east-1:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.22.2/config/master/aws-k8s-cni-us-gov-east-1.yaml
us-gov-west-1:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/v1.22.2/config/master/aws-k8s-cni-us-gov-west-1.yaml
cn:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/refs/heads/v1.22.2/config/master/aws-k8s-cni-cn.yaml
To apply this release using helm:
Follow the installation instructions in https://github.com/aws/amazon-vpc-cni-k8s/blob/v1.22.2/charts/aws-vpc-cni/README.md#installing-the-chart
Verify the update:
$ kubectl describe daemonset aws-node -n kube-system | grep Image | cut -d "/" -f 2-3
amazon-k8s-cni-init:v1.22.2
amazon-k8s-cni:v1.22.2
amazon/aws-network-policy-agent:v1.3.5
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Amazon VPC CNI v1.22.1 introduces enhanced subnet discovery, allowing customers to separate pod and node subnets and apply dedicated security groups t
Amazon VPC CNI v1.22.1 introduces enhanced subnet discovery, allowing customers to separate pod and node subnets and apply dedicated security groups to pods on secondary ENIs.
Warning
If you are using Sagemaker HyperPod on Amazon EKS, please upgrade to version v1.22.4 as v1.22.0-v1.22.3 contain an issue with Enhanced Subnet Discovery on HyperPod.
The enhanced subnet discovery feature (enabled by default with ENABLE_SUBNET_DISCOVERY=true) requires ec2:DescribeSubnets and ec2:DescribeSecurityGroups permissions.
Without these permissions, aws-node will fail to start (#3704, #3705).
Who needs to take action:
ec2:DescribeSubnets or ec2:DescribeSecurityGroupsAdd the following to your CNI IAM policy:
{
"Effect": "Allow",
"Action": [
"ec2:DescribeSubnets",
"ec2:DescribeSecurityGroups"
],
"Resource": "*"
}Note: The AWS managed policy
AmazonEKS_CNI_Policyalready includes both permissions. If you are using the managed policy on an IPv4 cluster, no action is needed.
Alternatively, if you do not need subnet discovery, you can set ENABLE_SUBNET_DISCOVERY=false to disable the feature and avoid the new permission requirement.
VPC CNI now supports advanced subnet selection for secondary ENIs:
kubernetes.io/role/cni=1 to include them for pod ENI allocationkubernetes.io/role/cni=0 to exclude them (including the node's primary subnet)kubernetes.io/role/cni=1 to apply custom security groups to ENIs in secondary subnetscni.networking.k8s.aws/cluster/<cluster-name> tags to scope subnets to specific clusters in multi-cluster VPCsThis feature is enabled by default via ENABLE_SUBNET_DISCOVERY=true.
cni.networking.k8s.aws/cluster/ and fix primary subnet exclusion logic (#3647, @haouc)Full Changelog: v1.21.2...v1.22.1
To manually apply this release:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/release-1.22/config/master/aws-k8s-cni.yaml
Note that the following regions use different manifests:
us-gov-east-1:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/release-1.22/config/master/aws-k8s-cni-us-gov-east-1.yaml
us-gov-west-1:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/release-1.22/config/master/aws-k8s-cni-us-gov-west-1.yaml
cn:
kubectl apply -f https://raw.githubusercontent.com/aws/amazon-vpc-cni-k8s/refs/heads/release-1.22/config/master/aws-k8s-cni-cn.yaml
To apply this release using helm:
Follow the installation instructions in https://github.com/aws/amazon-vpc-cni-k8s/blob/release-1.22/charts/aws-vpc-cni/README.md#installing-the-chart
Verify the update:
$ kubectl describe daemonset aws-node -n kube-system | grep Image | cut -d "/" -f 2-3
amazon-k8s-cni-init:v1.22.1
amazon-k8s-cni:v1.22.1
amazon/aws-network-policy-agent:v1.3.5
kubernetes.io/role/cni=0 and include subnets with kubernetes.io/role/cni=1kubernetes.io/role/cni=1 to apply them to ENIs in discovered subnetscni.networking.k8s.aws/cluster/<cluster-name> tag for multi-cluster VPC environmentscni=0, new ENIs are created only in secondary subnetsNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →