NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #934 by repository stars
Last release 14 days ago
22 Sep 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
5 years old
705 releases · first in 2021
One column per quarter.
Backporting dependency bumps to fix vulnerabilities #8118
| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu 20.04 | ✔ | ✔ | ✔ | — | ✔ |
| Ubuntu 22.04 | ✔ | ✔ | ✔ | — | — |
| Bottlerocket 1.19.2 | ✔ | * | — | — | — |
| RHEL 8.x | ✔ | ✔ | ✔ | ✔ | — |
| RHEL 9.x | — | — | ✔ | ✔ | — |
* EKS Anywhere issue regarding deprecation of Bottlerocket bare metal variants
v1-25-eks-37 to v1-25-eks-39v1-26-eks-33 to v1-26-eks-35v1-27-eks-27 to v1-27-eks-29v1-28-eks-20 to v1-28-eks-22v1-29-eks-9 to v1-29-eks-11\* EKS Anywhere issue regarding deprecation of Bottlerocket bare metal variants
| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu 20.04 | ✔ | ✔ | ✔ | — | ✔ |
| Ubuntu 22.04 | ✔ | ✔ | ✔ | — | — |
| Bottlerocket 1.19.2 | ✔ | * | — | — | — |
| RHEL 8.x | ✔ | ✔ | ✔ | ✔ | — |
| RHEL 9.x | — | — | ✔ | ✔ | — |
* EKS Anywhere issue regarding deprecation of Bottlerocket bare metal variants
v0.4.2 to v0.4.3\* EKS Anywhere issue regarding deprecation of Bottlerocket bare metal variants
| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu 20.04 | ✔ | ✔ | ✔ | — | ✔ |
| Ubuntu 22.04 | ✔ | ✔ | ✔ | — | — |
| Bottlerocket 1.19.2 | ✔ | * | — | — | — |
| RHEL 8.x | ✔ | ✔ | ✔ | ✔ | — |
| RHEL 9.x | — | — | ✔ | ✔ | — |
* EKS Anywhere issue regarding deprecation of Bottlerocket bare metal variants
v1-25-eks-35 to v1-25-eks-37v1-26-eks-31 to v1-26-eks-33v1-27-eks-25 to v1-27-eks-27v1-28-eks-18 to v1-28-eks-20v1-29-eks-7 to v1-29-eks-9Bumped golang.org/x/net that has a fix for vulnerability GO-2024-2687
| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu 20.04 | ✔ | ✔ | ✔ | — | ✔ |
| Ubuntu 22.04 | ✔ | ✔ | ✔ | — | — |
| Bottlerocket 1.19.2 | ✔ | * | — | — | — |
| RHEL 8.x | ✔ | ✔ | ✔ | ✔ | — |
| RHEL 9.x | — | — | ✔ | ✔ | — |
* EKS Anywhere issue regarding deprecation of Bottlerocket bare metal variants
\* EKS Anywhere issue regarding deprecation of Bottlerocket bare metal variants
| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu 20.04 | ✔ | ✔ | ✔ | — | ✔ |
| Ubuntu 22.04 | ✔ | ✔ | ✔ | — | — |
| Bottlerocket 1.19.2 | ✔ | * | — | — | — |
| RHEL 8.x | ✔ | ✔ | ✔ | ✔ | — |
| RHEL 9.x | — | — | ✔ | ✔ | — |
* EKS Anywhere issue regarding deprecation of Bottlerocket bare metal variants
v1-25-eks-34 to v1-25-eks-35v1-26-eks-30 to v1-26-eks-31v1-27-eks-24 to v1-27-eks-25v1-28-eks-17 to v1-28-eks-18v1-29-eks-6 to v1-29-eks-7\* EKS Anywhere issue regarding deprecation of Bottlerocket bare metal variants
| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu 20.04 | ✔ | ✔ | ✔ | — | ✔ |
| Ubuntu 22.04 | ✔ | ✔ | ✔ | — | — |
| Bottlerocket 1.19.2 | ✔ | * | — | — | — |
| RHEL 8.x | ✔ | ✔ | ✔ | ✔ | — |
| RHEL 9.x | — | — | ✔ | ✔ | — |
* EKS Anywhere issue regarding deprecation of Bottlerocket bare metal variants
v1-25-eks-32 to v1-25-eks-34v1-26-eks-28 to v1-26-eks-30v1-27-eks-22 to v1-27-eks-24v1-28-eks-15 to v1-28-eks-17v1-29-eks-4 to v1-29-eks-6public.ecr.aws/eks-anywhere/eks-anywhere-packages-bundles:v1-29-158\* EKS Anywhere issue regarding deprecation of Bottlerocket bare metal variants
| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu 20.04 | ✔ | ✔ | ✔ | — | ✔ |
| Ubuntu 22.04 | ✔ | ✔ | ✔ | — | — |
| Bottlerocket 1.19.0 | ✔ | * | — | — | — |
| RHEL 8.x | ✔ | ✔ | ✔ | ✔ | — |
| RHEL 9.x | — | — | ✔ | ✔ | — |
* EKS Anywhere issue regarding deprecation of Bottlerocket bare metal variants
etcd count in clusters with external etcd deployments (#7127)etcd support for Nutanix (#7550)upgrade management-components command which upgrades management components independently of cluster components (#7238)upgrade plan management-components command which provides new release versions for the next management components upgrade (#7447)maxUnhealthy count configurable for control plane and worker machines (#7281)maxSurge and maxUnavailable configuration support to all providersv1-25-eks-30 to v1-25-eks-32v1-26-eks-26 to v1-26-eks-28v1-27-eks-20 to v1-27-eks-22v1-28-eks-13 to v1-28-eks-15v1-29-eks-4v0.1.26 to v0.1.27v1.5.2 to v1.6.1v1.7.4 to v1.8.5v1.2.3 to v1.3.1v2.0.0 to v2.2.3v0.6.0 to v0.7.0v0.1.19 to v0.1.24v0.20.0 to v0.22.0MachineHealthCheck-related CLI flagsNothing published for this version
EKS Anywhere v0.18.7 Admin AMI with CVE fixes for Amazon Linux 2
| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu 20.04 | ✔ | ✔ | ✔ | — | ✔ |
| Ubuntu 22.04 | ✔ | ✔ | ✔ | — | — |
| Bottlerocket 1.19.0 | ✔ | ✔ | — | — | — |
| RHEL 8.7 | ✔ | ✔ | ✔ | ✔ | — |
| RHEL 9.x | — | — | ✔ | — | — |
runc v1.1.10 to v1.1.12 (CVE-2024-21626)
runcv1.15.1 to 1.19.0v1.1.10 to v1.1.12 (CVE-2024-21626)v1.7.11 to v.1.7.12| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu 20.04 | ✔ | ✔ | ✔ | — | ✔ |
| Ubuntu 22.04 | ✔ | ✔ | ✔ | — | — |
| Bottlerocket 1.19.0 | ✔ | ✔ | — | — | — |
| RHEL 8.x | ✔ | ✔ | ✔ | ✔ | — |
| RHEL 9.x | — | — | ✔ | — | — |
New EKS Anywhere Admin AMI with CVE fixes for Amazon Linux 2
| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu 20.04 | ✔ | ✔ | ✔ | — | ✔ |
| Ubuntu 22.04 | ✔ | ✔ | ✔ | — | — |
| Bottlerocket 1.15.1 | ✔ | ✔ | — | — | — |
| RHEL 8.7 | ✔ | ✔ | ✔ | ✔ | — |
| RHEL 9.x | — | — | ✔ | — | — |
Nutanix: Enable api-server audit logging for Nutanix
| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu 20.04 | ✔ | ✔ | ✔ | — | ✔ |
| Ubuntu 22.04 | ✔ | ✔ | ✔ | — | — |
| Bottlerocket 1.15.1 | ✔ | ✔ | — | — | — |
| RHEL 8.7 | ✔ | ✔ | ✔ | ✔ | — |
| RHEL 9.x | — | — | ✔ | — | — |
Etcdadm: Renew client certificates when nodes rollover (etcdadm/#56)
v1.25.15 to v1.25.16v1.26.10 to v1.26.11v1.27.7 to v1.27.8v1.28.3 to v1.28.4v1.0.15 to v1.0.16| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu 20.04 | ✔ | ✔ | ✔ | — | ✔ |
| Ubuntu 22.04 | ✔ | ✔ | ✔ | — | — |
| Bottlerocket 1.15.1 | ✔ | ✔ | — | — | — |
| RHEL 8.7 | ✔ | ✔ | ✔ | ✔ | — |
| RHEL 9.x | — | — | ✔ | — | — |
Security: Patch malicious tarballs directory traversal vulnerability
no_proxy inputs when both Red Hat Satellite and Proxy is used in image-builder. (#2664)kube-vip deployment when TinkerbellDatacenterConfig.skipLoadBalancerDeployment is set to true. (#6990)| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu 20.04 | ✔ | ✔ | ✔ | — | ✔ |
| Ubuntu 22.04 | ✔ | ✔ | ✔ | — | — |
| Bottlerocket 1.15.1 | ✔ | ✔ | — | — | — |
| RHEL 8.7 | ✔ | ✔ | ✔ | ✔ | — |
| RHEL 9.x | — | — | ✔ | — | — |
Etcdadm Bootstrap Provider: v1.0.9 to v1.0.10
v1.25.14 to v1.25.15v1.26.9 to v1.26.10v1.27.6 to v1.27.7v1.28.2 to v1.28.3v1.0.9 to v1.0.10v1.0.14 to v1.0.15v0.4.9-rc7 to v0.4.9-rc8v0.3.12 to v0.3.13| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu 20.04 | ✔ | ✔ | ✔ | — | ✔ |
| Ubuntu 22.04 | ✔ | ✔ | ✔ | — | — |
| Bottlerocket 1.15.1 | ✔ | ✔ | — | — | — |
| RHEL 8.7 | ✔ | ✔ | ✔ | ✔ | — |
| RHEL 9.x | — | — | ✔ | — | — |
| | vSphere | Bare Metal | Nutanix | CloudStack | Snow |
| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu | 20.04 | 20.04 | 20.04 | Not supported | 20.04 |
| 22.04 | 22.04 | 22.04 | Not supported | Not supported | |
| Bottlerocket | 1.15.1 | 1.15.1 | Not supported | Not supported | Not supported |
| RHEL | 8.7 | 8.7 | 9.x, 8.7 | 8.7 | Not supported |
v1-24-eks-26 to v1-24-eks-27v1-25-eks-22 to v1-25-eks-23v1-26-eks-18 to v1-26-eks-19v1-27-eks-12 to v1-27-eks-13v1-28-eks-26v0.4.9-rc6 to v0.4.9-rc7v0.1.26 to v0.1.27v1.5.2Nothing published for this version
CNI reconciler now properly pulls images from registry mirror instead of public ECR in airgapped environments: #7170
| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu 20.04 | ✔ | ✔ | ✔ | — | ✔ |
| Ubuntu 22.04 | ✔ | ✔ | ✔ | — | — |
| Bottlerocket 1.14.3 | ✔ | ✔ | — | — | — |
| RHEL 8.7 | ✔ | ✔ | _ | ✔ | — |
Cluster API Provider CloudStack: v0.4.9-rc7 to v0.4.9-rc8
v0.4.9-rc7 to v0.4.9-rc8| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu 20.04 | ✔ | ✔ | ✔ | — | ✔ |
| Ubuntu 22.04 | ✔ | ✔ | ✔ | — | — |
| Bottlerocket 1.14.3 | ✔ | ✔ | — | — | — |
| RHEL 8.7 | ✔ | ✔ | _ | ✔ | — |
| | vSphere | Bare Metal | Nutanix | CloudStack | Snow |
| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu | 20.04 | 20.04 | 20.04 | Not supported | 20.04 |
| 22.04 | 22.04 | 22.04 | Not supported | Not supported | |
| Bottlerocket | 1.14.3 | 1.14.3 | Not supported | Not supported | Not supported |
| RHEL | 8.7 | 8.7 | Not supported | 8.7 | Not supported |
kube-apiserver on baremetal provider (#6779).| | vSphere | Bare Metal | Nutanix | CloudStack | Snow |
| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu | 20.04 | 20.04 | 20.04 | Not supported | 20.04 |
| 22.04 | 22.04 | 22.04 | Not supported | Not supported | |
| Bottlerocket | 1.14.3 | 1.14.3 | Not supported | Not supported | Not supported |
| RHEL | 8.7 | 8.7 | Not supported | 8.7 | Not supported |
| | vSphere | Bare Metal | Nutanix | CloudStack | Snow |
| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu | 20.04 | 20.04 | 20.04 | Not supported | 20.04 |
| 22.04 | 22.04 | 22.04 | Not supported | Not supported | |
| Bottlerocket | 1.14.0 | 1.14.0 | Not supported | Not supported | Not supported |
| RHEL | 8.7 | 8.7 | Not supported | 8.7 | Not supported |
writefile action to ensure Bottlerocket configs write content or error (#2441)etcdcluster.cluster.x-k8s.io/healthcheck-retries annotation (aws/etcdadm-controller#44)| | vSphere | Bare Metal | Nutanix | CloudStack | Snow |
| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu | 20.04 | 20.04 | 20.04 | Not supported | 20.04 |
| 22.04 | 22.04 | 22.04 | Not supported | Not supported | |
| Bottlerocket | 1.14.0 | 1.14.0 | Not supported | Not supported | Not supported |
| RHEL | 8.7 | 8.7 | Not supported | 8.7 | Not supported |
VSpherMachinesConfig #6591The bundlesRef field in the cluster spec is now deprecated in favor of the new eksaVersion field. This field will be deprecated in three versions.
| vSphere | Bare Metal | Nutanix | CloudStack | Snow | |
|---|---|---|---|---|---|
| Ubuntu | 20.04 | 20.04 | 20.04 | Not supported | 20.04 |
| 22.04 | 22.04 | 22.04 | Not supported | Not supported | |
| Bottlerocket | 1.14.0 | 1.14.0 | Not supported | Not supported | Not supported |
| RHEL | 8.7 | 8.7 | Not supported | 8.7 | Not supported |
Note: We have updated the image-builder docs to include the latest enhancements. Please refer to the image-builder docs for more details.
ControlPlaneInitialized, ControlPlaneReady, DefaultCNIConfigured, WorkersReady, and Ready conditions.observedGeneration field.failureReason field.egressMasqueradeInterfaces option in Cilium CNI via EKS Anywhere cluster spec #6018--skip-validations=vsphere-user-privilegev1.6.1 to v1.7.0v0.4.9-rc5 to v0.4.9-rc6v1.2.1 to v1.2.3Cilium: v1.11.15 to v1.12.11
Note: If you are using the vSphere provider with the Redhat OS family, there is a known issue with VMWare and the new Cilium version that only affects our Redhat variants. To prevent this from affecting your upgrade from EKS Anywhere v0.16 to v0.17, we are adding a temporary daemonset to disable UDP offloading on the nodes before upgrading Cilium. After your cluster is upgraded, the daemonset will be deleted. This note is strictly informational as this change requires no additional effort from the user.
eksaVersion field in the cluster spec is added for better representing CLI version and dependencies in EKS-A cluster #5847<Provider>DatacenterConfig is missing apiVersion field #6096Option A
# Does not persist across reboots.
sudo ip rule add from all fwmark 0x200/0xf00 lookup 2004 pref 9
sudo ip rule add from all fwmark 0xa00/0xf00 lookup 2005 pref 10
sudo ip rule add from all lookup local pref 100
Option B
# Does persist across reboots.
# Add these values /etc/systemd/networkd.conf
[Network]
ManageForeignRoutes=no
ManageForeignRoutingPolicyRules=no
eksaVersion field. This field will be deprecated in three versions.Nothing published for this version
Bump up the worker count for etcdadm-controller from 1 to 10 #34
Fix support for having management cluster and workload cluster in different namespaces #6414
During management cluster upgrade, if the backup of CAPI objects of all workload clusters attached to the management cluster fails before upgrade star
CLI: Ensure importing packages and bundles honors the insecure flag #6056
Nothing published for this version
Add warning to deprecate disableCSI through CLI (#5918). Refer to the deprecation section in the vSphere provider documentation for more information.
Nothing published for this version
Add validation for tinkerbell ip for workload cluster to match management cluster
Added bundles-override to package cli commands
| | vSphere | Baremetal | Nutanix | Cloudstack | Snow |
| vSphere | Baremetal | Nutanix | Cloudstack | Snow | |
|---|---|---|---|---|---|
| Ubuntu | 20.04 | 20.04 | 20.04 | Not supported | 20.04 |
| Bottlerocket | 1.13.1 | 1.13.1 | Not supported | Not supported | Not supported |
| RHEL | 8.7 | 8.7 | Not supported | 8.7 | Not supported |
| | vSphere | Baremetal | Nutanix | Cloudstack | Snow |
| vSphere | Baremetal | Nutanix | Cloudstack | Snow | |
|---|---|---|---|---|---|
| Ubuntu | 20.04 | 20.04 | 20.04 | Not supported | 20.04 |
| Bottlerocket | 1.13.1 | 1.13.1 | Not supported | Not supported | Not supported |
| RHEL | 8.7 | 8.7 | Not supported | 8.7 | Not supported |
v1.11.10 to version v1.11.15| | vSphere | Baremetal | Nutanix | Cloudstack | Snow |
| vSphere | Baremetal | Nutanix | Cloudstack | Snow | |
|---|---|---|---|---|---|
| Ubuntu | 20.04 | 20.04 | 20.04 | Not supported | 20.04 |
| Bottlerocket | 1.13.1 | 1.13.1 | Not supported | Not supported | Not supported |
| RHEL | 8.7 | 8.7 | Not supported | 8.7 | Not supported |
CredentialsRef to NutanixDatacenterConfig to specify Nutanix credentials for workload clusters (#5114)cloneMode for different VSphereMachineConfig (#4634)v1.13.0 to v1.13.1v0.4.0v0.10.1v0.2.1v0.8.02.5.1 to 2.7.12.39.1 to 2.41.00.13.5 to 0.13.73.3.0 to 3.5.1Fix clustermanager no-timeouts option
Fix kubectl get call to point to full API name
--no-timeouts flag in create and upgrade commands to disable timeout for all wait operations
--no-timeouts flag in create and upgrade commands to disable timeout for all wait operations--aws-region flag to copy packages command.
--aws-region flag to copy packages command.v0.1.22 to v0.1.24.Enabled support for Kubernetes version 1.25
support for authenticated pulls from registry mirror
Add support for EKS Anywhere on AWS Snow
Multi-region support for all supported curated packages
eksctl anywhere upgrade plan commandWorkload clusters full lifecycle API support for vSphere and Docker
v1.11.10cluster command error (#1703 implemented by #4289)--unhealthy-machine-timeout (#3918 implemented by #4123)maxSurge and maxUnavailable parametersv2.39.1v0.23.0 upgraded from v0.21.1v3.3.0 upgraded from v3.0.0v0.13.7 upgraded from v0.13.5Add support for Kubernetes 1.24 (CloudStack support to come in future releases)#3491
Setting minimum wait time for nodes and machinedeployments (#3868, fixes #3822)
Certificates signed with SHA-1 are not supported anymore for Registry Mirror. Users with a registry mirror and providing a custom CA cert will need to
create cluster command) and existing clusters (upgrade cluster command).--source option was removed from several package commands. Use either --kube-version for registry or --cluster for cluster.Add validate session permission for vsphere
Enable kube-rbac-proxy on CloudStack cluster controller's metrics port
Add a preflight check to validate vSphere user's permissions #2744
DiskOffering in CloudStackMachineConfig optionalAdd --insecure flag to import/download images commands #2878
--insecure flag to import/download images commands #2878Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →