Home / Companies / Sysdig / Blog / Post Details
Content Deep Dive

Kubernetes 1.35 - New security features

Blog post from Sysdig

Post Details
Company
Date Published
Author
Víctor Jiménez Cerrada
Word Count
3,196
Company Posts That Month
10
Language
English
Hacker News Points
-
Post removed?
No
Summary

Kubernetes 1.35 introduces significant changes to enhance security and streamline operations, including 17 updates that involve new validations, deprecations, and expanded support for user namespaces. Key changes include the default disabling of cgroup v1 support in favor of the more advanced cgroup v2, aimed at improving resource management and isolation. The update also enhances image pull credential verification to prevent unauthorized access, especially in multi-tenant clusters, and transitions from the SPDY protocol to WebSockets for more secure and efficient command execution. Additionally, the release introduces features like constrained impersonation to limit user permissions during impersonation, allows HostNetwork pods to use user namespaces for better security, and offers new mechanisms for managing Kubernetes component flags for diagnostics. The update also focuses on improving certificate management with a PodCertificateRequest API, separating user preferences from cluster configurations, and removing deprecated dependencies like gogo protobuf to bolster security and performance.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 49 1,540 251 91 +19%
Secrets Management 5 1,206 193 82 -5%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.