CCE has passed the Certified Kubernetes Conformance Program and is a certified Kubernetes offering. CCE now supports Kubernetes 1.35 cluster features. This section describes the updates in Kubernetes 1.35.
In Kubernetes 1.35, this feature has graduated to GA. The PreferSameNode policy is added, which allows service traffic to be preferentially forwarded to the endpoints on the same node as the client. The PreferClose policy is deprecated and replaced with PreferSameNode. For details, see PreferSameZone and PreferSameNode Traffic Distribution.
In Kubernetes 1.35, the support for the managedBy field for Jobs has graduated to GA. This feature introduces the .spec.managedBy field for Jobs. You can use this field to allow an external controller (such as Kueue or MultiKueue) to take full responsibility for the synchronization logic and status update of a Job. For details, see Job Managed By Goes GA.
In Kubernetes 1.35, Pod generation has graduated to GA. This feature leverages metadata.generation that automatically increments the value when the pod spec is updated. Additionally, the status.observedGeneration field is added, which is reported by kubelet to identify the observed pod configuration version. For details, see Pod Generation.
In Kubernetes 1.35, this feature has graduated to GA. The max-allowable-numa-nodes policy option is added for Topology Manager. It allows users to specify the maximum number of NUMA nodes. Before this option is added, the maximum number of NUMA nodes that Topology Manager allows is 8. With more than 8 NUMA nodes, high-end CPUs and AI acceleration chips can be used. For details, see TopologyManager NUMA Node Limit Configuration.
In Kubernetes 1.35, Node Topology Downward API has graduated to Beta. This feature uses the built-in PodTopologyLabels admission controller to synchronize standard topology labels of nodes to pods. Containers can directly obtain topology information such as regions, AZs, and host names through the downward API without requiring privileged init containers. For details, see Node Topology Labels via Downward API.
In Kubernetes 1.35, this feature has graduated to beta. This feature moves the Storage Version Migrator (SVM) from an external component to kube-controller-manager, providing a standard StorageVersionMigration API. For details, see Move Storage Version Migrator in-tree.
In Kubernetes 1.35, this feature has graduated to beta. This feature allows dynamic modification of the CSINode.Spec.Drivers[*].Allocatable.Count field. When volume mounting fails due to insufficient capacity, the capacity information is automatically corrected to prevent the scheduler from suspending pods based on outdated data. For details, see Mutable CSINode Allocatable Property.
In Kubernetes 1.35, the opportunistic batching is added to the scheduler. This feature reuses scheduling results through pod scheduling signatures to improve the efficiency of scheduling batches of similar pods. For details, see Opportunistic batching.
In Kubernetes 1.35, this feature has graduated to beta. The maxUnavailable field is added to the StatefulSet rolling update policies to specify the maximum number of unavailable pods during an update (either as a number or a percentage). For details, see Implement maxUnavailable in StatefulSet.
In Kubernetes 1.35, KYAML has graduated to beta. The KYAML output format (-o kyaml), compatible with the standard YAML parsers, is added to kubectl. For details, see Introducing KYAML, a safer, less ambiguous YAML subset/encoding.
In Kubernetes 1.35, this feature has graduated to beta. This feature adds the tolerance configuration item to the native HPA scaling policies. For details, see Configurable tolerance for HPA.
In Kubernetes 1.35, this feature has graduated to beta. This feature enables user namespace isolation using the pod.spec.hostUsers field, improving pod security isolation. For details, see Support User Namespaces.
In Kubernetes 1.35, this feature adds image volumes for pods, so users can directly mount OCI images or artifacts as read-only volumes. To use this feature, containerd must be v2.1 or later. For details, see OCI VolumeSource.
In Kubernetes 1.35, this feature has graduated to beta. This feature enables kubelet to cache image pull credentials and enforce access permission verification. It checks whether a pod has permission to use existing images on the node based on the value (IfNotPresent or Never) of imagePullPolicy. For details, see Ensure Secret Pulled Images.
In Kubernetes 1.35, this feature has graduated to beta. This feature adds the restartPolicy and restartPolicyRules configurations for containers. These configurations can override the pod-level restart policy. For details, see Container Restart Rules.
In Kubernetes 1.35, the serviceAccountTokenInSecrets field in the CSI driver spec can be set to true. This enables service account tokens to be passed through a dedicated Secrets field of the CSI request instead of the volume_context field, preventing sensitive token leakage. For details, see CSI driver opt-in for service account tokens via secrets field.
In Kubernetes 1.35, this feature has graduated to beta. The .status.terminatingReplicas field is added for Deployments and ReplicaSets to count the number of terminating pods. For details, see Consider Terminating Pods in Deployments.
In Kubernetes 1.35, the JobManagedBy feature has been upgraded to GA. The feature gate is locked to be true and will be removed in later versions.
During a version maintenance period, CCE periodically updates Kubernetes 1.35 with enhanced functions.
For details about cluster version updates, see Patch Versions.
For more details about the performance comparison and functional enhancements between Kubernetes 1.35 and other versions, see Kubernetes 1.35 Release Notes.