Kubernetes v1.35.9 was published on 23 September 2026 at 19:35 UTC. The change with the widest blast radius is in the scheduler. A ResourceClaim whose device request counts add up past the int range no longer crashes kube-scheduler, and the DRA allocator no longer skips the firstAvailable fallback in that case. The patch also stops kubeadm init from storing a node local resolvConf path, moves a kubelet flag removal from 1.37 to 1.38, rebuilds on Go 1.26.8, and demotes three conformance tests.
The full release notes and downloads are on the GitHub release page. That page does not list the patches. It points at the 1.35 changelog and the kubernetes-announce list. The notes below are the changelog since v1.35.8. v1.35.9 is a stable patch, not a release candidate, beta, or alpha. No dependencies were added, changed, or removed.
Scheduler rejects oversized device counts ¶
A ResourceClaim whose device request counts add up past the int range used to crash the scheduler. The overflow also skipped the firstAvailable fallback in the DRA allocator, so one bad alternative could hide a smaller one that would have fit. #141924 rejects a request over the per claim device limit and names that request in the error. An oversized firstAvailable alternative falls through to a smaller one.
That is a local failure instead of a dead kube-scheduler. The claim stays unschedulable until the count is fixed. Other pods keep getting placed. The changelog does not mention a flag to restore the old behavior, and it names no metric. SIG Node owns the change. Claims that already fit in the int range are unchanged.
kubeadm init leaves resolvConf on the node ¶
kubeadm no longer writes a node specific systemd-resolved resolvConf path into the cluster wide kubelet-config ConfigMap during init. #141629 is the change, under SIG Cluster Lifecycle. The path belongs to the init host. Other nodes may not have the file. Storing it in the shared ConfigMap turned one host into the source of the cluster resolver path.
The changelog sentence is about init only. It does not say a later upgrade rewrites a ConfigMap that already stores the path. If an earlier 1.35 init wrote a node local systemd-resolved path, read the live kubelet-config object. The note does not say this patch deletes that value. A cluster initialized on v1.35.9 should not receive the path.
Kubelet flag removal slips to 1.38 ¶
Removal of the kubelet configuration flags, and the fallback behavior tied to them, moves from 1.37 to 1.38 so the timeline matches containerd v1.7 support. #139268 does not name the flags. If a 1.37 plan assumed they would disappear, move the work to 1.38 and confirm the names in the changelog before you delete config. The slip is more time for containerd v1.7. It does not mean every deprecated kubelet flag moved.
The same pull request changes the kubeadm preflight check ContainerRuntimeVersion. The check tests whether the installed runtime supports the RuntimeConfig gRPC method. When the kubelet is older than 1.38, the result is a warning. On this 1.35 patch a runtime without RuntimeConfig warns. The note does not say kubeadm fails init, and it does not say kubelet refuses to start. SIG Cluster Lifecycle, SIG Node, and SIG Testing are on the entry.
Conformance tests and the Go 1.26.8 build ¶
Three conformance tests added in 1.35 are not interoperable with the static CPU manager. #141602 demotes them to regular end to end tests. SIG Architecture, SIG Node, and SIG Testing are listed. This is classification only. CPU manager policy and kubelet behavior stay as they are. Conformance runs that use the static CPU manager should stop failing those three tests. The tests no longer count as conformance, and they remain end to end tests. The changelog does not name them.
The binaries are built with Go 1.26.8. #142182 records that under features, with SIG Release and Testing. The dependency section is empty, so the Go toolchain for the binaries changed and the module set did not. No config key and no API field ship with the bump. Image tags for the patch include registry.k8s.io/kube-apiserver:v1.35.9, registry.k8s.io/kube-controller-manager:v1.35.9, registry.k8s.io/kube-scheduler:v1.35.9, registry.k8s.io/kube-proxy:v1.35.9, and registry.k8s.io/kubectl:v1.35.9.
Upgrade notes ¶
Inspect kubelet-config if the cluster was initialized before v1.35.9. New inits stop storing a node specific systemd-resolved resolvConf path. The note does not repair an object that already has one.
A ResourceClaim over the per claim device limit, or whose counts add up past the int range, is rejected by name instead of crashing kube-scheduler. A firstAvailable alternative that is too large falls through. Claims that already fit are outside #141924.
ContainerRuntimeVersion warns on kubelet versions older than 1.38 when RuntimeConfig is missing. Plan the unnamed kubelet flag removal for 1.38, with containerd v1.7, not for 1.37. The Go 1.26.8 rebuild does not add or remove dependencies.
Where to get it ¶
- Release page: Kubernetes v1.35.9
- Repository: kubernetes/kubernetes
- Changelog:
CHANGELOG-1.35.md - Announce list:
kubernetes-announce - Tag:
v1.35.9