Oct
v4.3 Update 2 - SaaS¶
8 Oct, 2026
Upstream Kubernetes for Bare Metal and VMs¶
Kubernetes v1.37¶
New Rafay MKS clusters based on upstream Kubernetes can now be provisioned with Kubernetes v1.37. Existing clusters managed by the controller can be upgraded in-place to Kubernetes v1.37.
Note
For new clusters Kubernetes v1.37 requires etcd 3.7.0, which is supported from platform version 1.5.0. The UI defaults to the latest platform version (1.6.0), which includes etcd 3.7.0. This platform requirement does not apply when upgrading existing clusters in-place to Kubernetes v1.37.
Kubernetes patch versions¶
This release adds the following latest Kubernetes patch versions:
- v1.36.4 — Kubernetes 1.36
- v1.35.8 — Kubernetes 1.35
- v1.34.11 — Kubernetes 1.34
- v1.33.12 — Kubernetes 1.33
By default, the console shows these latest active patch versions. Rafay recommends them for new clusters and upgrades.
Older patch versions remain available when Show deprecated Kubernetes patch versions is enabled in the cluster provisioning UI.
Platform versions¶
This release adds the following platform versions. v1.6.0 is the latest and is selected by default when creating a cluster in the UI.
- v1.6.0 (default) — Adds a Node Settings component (starting at v1.0.0) that version-controls node configuration changes. Later node optimizations and configuration updates will ship through this component.
- v1.5.0 — Updates etcd to 3.7.0, which is required to create new Kubernetes v1.37 clusters.
- v1.4.0 — Includes an etcd version 3.6.14 update for clusters that need a newer etcd. This is only required if users would wish to update their existing etcd version to this version.
- v1.3.2 — Includes Cluster Utils bug fixes for improved stability.
Bug Fixes¶
The following bug fixes are included in this release:
| Bug ID | Description |
|---|---|
| RC-54520 | AKS: Fixed an intermittent issue where rctl apply for v3 clusters failed with a 404 / "cluster Apply failed" error |
| RC-55016 | GKE: Fixed an issue where a node pool update could remain stuck in the Pending or Retry state |
| RC-50441 | RCTL: Fixed an issue where rctl apply unpublished a namespace when the YAML used the v2 schema or was missing v3 placement |
| RC-55450 | SAML: Fixed an issue with IdP domain verification email |
| RC-45093 | MKS: Fixed an issue where addon dependencies were not honored when provisioning a new cluster with CNI via blueprint |
v4.3 Update 1 - SaaS¶
1 Oct, 2026
Google GKE¶
GKE Metadata Server¶
GKE node pools can now enable the GKE Metadata Server (workloadMetadataMode) in Day 0 and as a Day-2 operation. This option is configured at the node pool level and requires Workload Identity to be enabled on the cluster. Configure it in the node pool Node Security section, or via API, RCTL and Terraform.
Benefit
Workloads on the node pool can securely access Google Cloud services using Workload Identity, without the need to manage service account key files.
Bug Fixes¶
The following bug fixes are included in this release:
| Bug ID | Description |
|---|---|
| RC-54071 | GKE: Fixed an issue where a node pool could be deleted from a cluster that had only one node pool |
| RC-54523 | EKS: Fixed an issue where IAM service account creation failed |