Kubernetes 1.37: what to check before upgrading

Published 2 October 2026 · Updated 2 October 2026

In short. Kubernetes 1.37 was released on 26 August 2026. Before upgrading, check SELinuxMount being enabled by default, the removed scheduling.k8s.io/v1alpha2 API and the new meaning of eventRecordQPS=0. Support for 1.34 ends on 27 October 2026: if you are on that version, plan now.

Kubernetes 1.37 (“Garhwal”) was released on 26 August 2026; patch 1.37.1 followed on 15 September. Source: release announcement and releases page.

Support calendar

Version End of maintenance End of support (EOL)
1.34 27 August 2026 (already under way) 27 October 2026
1.35 28 December 2026 28 February 2027
1.36 28 April 2027 28 June 2027
1.37 28 August 2027 28 October 2027

Source: patch releases, accessed on 2 October 2026. A cluster on 1.34 has only a few weeks of margin.

The four mandatory actions

From the 1.37 CHANGELOG, “Urgent Upgrade Notes” section:

  1. SELinuxMount is GA and enabled by default. It can break workloads on clusters running SELinux. Identify the problematic workloads on a 1.36 cluster before upgrading, following the blog post on the change. Without SELinux, no action is needed.
  2. scheduling.k8s.io/v1alpha2 is removed. Delete all objects of that version from the API server before upgrading.
  3. eventRecordQPS=0 now means “no limit”. If you relied on the previous behaviour, set a non-zero value.
  4. The kubelet writes its effective configuration to the logs at startup. Restrict the ClusterRole that grants access to node logs to those who need it.

Removals and deprecations to check

  • The GangScheduling and WorkloadAwarePreemption feature gates are removed (use GenericWorkload), as is the AnyVolumeDataSource gate.
  • The ipvs mode of kube-proxy has been deprecated since 1.35; nftables has been GA since 1.33. kubeadm now explicitly writes iptables mode if none is specified.
  • Pod Certificates are GA: the PKIXPublicKey and ProofOfPossession fields are removed from v1.
  • Workload and PodGroup move to scheduling.k8s.io/v1beta1, with renamed fields: relevant if you use them.
  • Pods with empty resources ({}) no longer affect the QoS class calculation.
  • ingress-nginx has not received fixes since March 2026: see the Gateway API migration checklist.
  • Service externalIPs: the deprecation has been announced since 1.36; the exact version of removal has not been verified, so do not assume it has happened without checking again.

What you gain

Among other things, metrics.k8s.io/v1, StorageVersionMigration, in-place resizing for init containers and the DRA extensions for external resources become GA. The kubelet rootless mode and scaling to zero replicas with the HPA are in beta. Full lists are in the CHANGELOG.

Upgrade checklist

  1. Take an etcd snapshot and test the restore.
  2. Upgrade a test cluster first, with the same components (CNI, runtime, network controllers, add-ons).
  3. Re-read the “Urgent Upgrade Notes” section and the feature gates you use.
  4. Check the skew policy between control plane, kubelet and kubectl.
  5. Plan the rollback before touching the production cluster.

What has not been verified

Minimum container runtime versions, network plugin compatibility and the required Gateway API version were not found in primary sources for this note: check them in the documentation of your components.

For an upgrade plan tested on your own cluster, see Kubernetes and cloud native platforms.

Need a hand?

If you want to apply these points to your case, tell me in a few lines.

Let's talk