kOps
Production-grade Kubernetes cluster provisioning and operations
kOps deletes gossip DNS and the protokube binary, and spends the room on Akamai.
◆Recent moves
- 18d ago
Gossip DNS and protokube removed; Akamai becomes a full provider
⚡ SPARKThe narrowing this feed has shown since 1.36 arrives at its largest cut: gossip DNS, the protokube binary that served it, Classic Load Balancer support for the API and Kubernetes 1.31 all come out in one tag, with a migration guide alongside. The same tag builds Akamai into a provider with subnets, instance management and etcd volumes, so the subtraction and the expansion are funded together.
View source ↗ - 2mo ago
Azure attested node identity; AWS and GCE health check reconcile
The reconciliation thread lands on both AWS target groups and GCE HTTP health checks in one tag, so drift in resources kOps already created now gets corrected. Azure switching to the IMDS attested metadata document for node identity is the security-relevant change, and Linode SSH key management is the first step of what becomes the Akamai provider one tag later.
View source ↗ - 3mo ago
Omitted authorization now defaults to RBAC instead of AlwaysAllow
The default change is the item that matters: a cluster spec that omits authorization no longer gets AlwaysAllow. It reads as an early instance of the same instinct that later removes gossip and the Classic Load Balancer — trading a permissive legacy path for a narrower supported one. Addon apply failures also surface through a readiness probe rather than staying silent.
View source ↗ - 3mo ago
Amazon Linux 2 support removed; warm pools take user-defined images
Removing Amazon Linux 2 and updating the distribution matrix around it is the first visible platform subtraction in this window, and it forces migration for anyone still on it. Warm pool instances pulling user-defined images is the useful addition for teams managing their own AMIs.
View source ↗