NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #589 by repository stars
Last release 2 days ago
02 Oct 2026
Ships on a steady schedule
a new release about every 9 days
Rarely documented
notes for 13 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
5 years old
1110 releases · first in 2021
One column per quarter.
Nothing published for this version
Nothing published for this version
Bump github.com/moby/spdystream to 0.5.1 [ CVE-2026-35469 ] ( #4049 , @xrstf )
LogicalClusterInactiveAnnotationKey (core.kcp.io/inactive) and a respecitve phase to mark logical clusters as inactiveinternal.kcp.io/inactive, replaced with LogicalClusterInactiveAnnotationKeykcp_backend_rq_body_bytes, kcp_backend_rs_body_bytes, kcp_listener_tls_connection_error metrics to front-proxy. (#4192, @xrstf)kcp_workspace_count metric (#4095, @xrstf)kubectl kcp quickstart command to bootstrap a kcp environment with workspaces, APIResourceSchemas, APIExports, and APIBindings in a single command (#4024, @nuromirg)core.kcp.io/shard annotation with the value being the name of the shard they are scheduled on (#4171, @ntnn)NO_GORUN is set sdk/testing allows setting the paths to prebuilt binaries by setting KCP_ASSET_$name in the environment to the path of the prebuilt binary; $name is the capitalized executable name with dashes replacing underscores (e.g. kcp-front-proxy is looked up with KCP_ASSET_KCP_FRONT_PROXY) (#4179, @ntnn)/services/... requests keep impersonation headers request-scoped. (#4009, @officialasishkumar)Nothing published for this version
Nothing published for this version
Add an optional --header-file flag to apigen used to append boilerplate to the generated YAML files ( #4247 , @kcp-ci-bot )
--header-file flag to apigen used to append boilerplate to the generated YAML files (#4247, @kcp-ci-bot)Unauthorized in sharded deployments, a regression introduced by the fix for GHSA-c8w2-fgvx-vhv4. Enabling mounts now requires configuring the front-proxy with --requestheader-client-ca-file and each shard with --mount-proxy-client-cert-file/--mount-proxy-client-key-file. (#4241, @xmudrii)Nothing published for this version
Full Changelog : v0.31.3...v0.31.4
Full Changelog: v0.31.3...v0.31.4
[release-0.31] fix(rbac): allow external-logical-cluster-admin to create SubjectAcce… by @kcp-ci-bot in #4157
Full Changelog: v0.31.2...v0.31.3
Added kcp-front-proxy, cache-server, virtual-workspaces, crd-puller and sharded-test-server to the release artifacts ( #4083 , @kcp-ci-bot )
Nothing has changed.
Nothing has changed.
Nothing has changed.
Bump github.com/moby/spdystream to 0.5.1 [ CVE-2026-35469 ] ( #4057 , @kcp-ci-bot )
/services/... requests keep impersonation headers request-scoped. (#4009, @officialasishkumar)Nothing has changed.
Nothing has changed.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
🐞 VW proxy impersonation isolation — #4009 ( @officialasishkumar ) Security fix: the shared ReverseProxy in VW was being mutated concurrently, causing…
🚀 Rebase to Kubernetes 1.35.1 — #3842 (@xmudrii)
Foundation upgrade to Kubernetes 1.35.1 + Go 1.25.7. XL change touching the entire codebase — API adaptations, test adjustments, separate etcd lifecycle context to prevent shutdown blocking.
🔒 Cross-shard service account lookup — #3973 (@ntnn)
Enables service account validation across shards via a TTL cache. Removes the previous same-shard requirement for SAs. Drops the GlobalServiceAccount feature gate (now always-on).
⚙️ APIResourceSchema Virtual Workspace — #3881 (@mjudeikis)
New virtual workspace enabling providers to access consumer workspace schemas — key for kube-bind.io integration. Requires GlobalServiceAccounts and cross-workspace RBAC.
🔑 defaultSelector for PermissionClaim on APIExport — #3884 (@mjudeikis)
API change: providers can specify default permission claim selectors on APIExport that automatically apply when APIBindings are auto-created via WorkspaceType. Replaces a cache-replication approach (#3859) that had O(workspaces × bindings) scalability concerns.
🛟 Extract Virtual Workspace framework to staging repo — #3959 (@xmudrii)
Moves pkg/virtual/framework and pkg/virtual/options into github.com/kcp-dev/virtual-workspace-framework. External VW developers no longer need to vendor the entire kcp core repo. Also moves OpenAPI defs to SDK and crdpuller to the new repo.
🏋️ Load testing framework & infrastructure — #3796, #3866, #3895 (@SimonTheLeg)
Three-part effort: concept doc, k8s infra setup, and the framework itself. Inspired by clusterloader2, uses Go iterators for tuning sets, supports scenarios like "10,000 empty workspaces" with P99 stats.
🐛 Etcd key poisoning fix — #4011 (@mjudeikis)
Critical data integrity fix: unresolved workspace paths were poisoning etcd keys with malformed cluster names. Adds 404 handling and defense-in-depth filtering.
🔨 CLI permission claims management — #3956 (@rxinui) + #3946 (@ghdrope)
New kcp claims accept / kcp claims reject subcommands plus --accept-all-permission-claims / --reject-all-permission-claims flags on kubectl kcp bind. Significant UX improvement for API consumers.
🎁 SSA (Server-Side Apply) committer — #4002 (@swastik959)
Introduces Server-Side Apply support for controllers, fixing race conditions where JSON Merge Patch would lose concurrent condition updates.
🐞 VW proxy impersonation isolation — #4009 (@officialasishkumar)
Security fix: the shared ReverseProxy in VW was being mutated concurrently, causing impersonation header leakage between requests. Each request now gets an isolated proxy instance.
defaultSelector field to PermissionClaim on APIExport. When APIBindings are auto-created via WorkspaceType.defaultAPIBindings, the selector is now taken from the APIExport's defaultSelector instead of defaulting to matchAll: true. Existing APIExports without defaultSelector retain the previous matchAll: true behavior. (#3884, @mjudeikis)/readyz now uses NewInformerSyncHealthz/livez now uses PingHealthz (#3935, @nuromirg)kcp claims accept and kcp claims reject (#3956, @rxinui)pkg/virtual/framework and pkg/virtual/options packages into a dedicated staging repository (github.com/kcp-dev/virtual-workspace-framework
cluster/{cluster} - it was not resolved, and so WorkspaceAuthorizationConfiguration was not run if used inside FrontProxy, but forwarded to VirtualWorkspace without checking. As a result, if one has misconfigured VirtualWorkspace, it might receive traffic intended for another recipient. (#3857, @mjudeikis)--shard-virtual-workspace-url, --shard-virtual-workspace-ca-file, --shard-client-key-file, --shard-client-cert-file not being taken into account when disabling the in-process kcp virtual workspaces server on a shard. (#3955, @xrstf)/clusters/<path>/... on a shard could cause resources to be written to etcd under a key segment containing the raw workspace path instead of the logical cluster name, producing orphaned rows invisible to the normal API read path. The shard now returns 404 for unresolvable workspace paths, and a new defense-in-depth filter rejects any request whose context carries a path-shaped cluster name before it can reach storage. (#4011, @mjudeikis)/services/... requests keep impersonation headers request-scoped. (#4009, @officialasishkumar)--external-hostname, determined based on --shard-base-url or --bind-address instead (#3832, @ntnn)--shard-external-url for virtual-workspace (#3849, @ntnn)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →