Stack Signal.
Technical news & guides across AI, programming and the open-source world
SUNDAY, OCTOBER 11, 2026 · 75 articles · RSS

DevOps & Self-HostingOct 11, 2026772 words
How-To Guide

Kubernetes v1.37 'Garhwal': Metrics API goes GA, scale-to-zero lands, and the deprecations operators can't ignore

Kubernetes v1.37 "Garhwal" adds up to a quieter, leaner control plane

On Wednesday, 26 August 2026, the Kubernetes project shipped v1.37 "Garhwal" — named for the Garhwal Himalayan region of northern India. It brings 67 enhancements: 16 to Stable, 23 to Beta, 27 entering Alpha, and one deprecation/removal. The first patch, 1.37.1, landed in mid-September.

There isn't one showboat feature. The news is that the project finally cleaned up APIs it had leaned on for years, dialed down how and where the kubelet runs, and started winding down two older subsystems. None of it is loud. All of it changes how you operate a cluster.

The metrics API is finally Stable

The headline is the graduation of metrics.k8s.io to Stable (GA) after nearly nine years in Beta. The API supplies CPU and memory usage for nodes and Pods — it's what powers kubectl top and the Horizontal Pod Autoscaler. It entered Alpha in v1.6, went Beta in v1.8, and has been effectively frozen and production-proven since.

What changed in v1.37 is only the API version, not the data: metrics.k8s.io/v1 has the same resources and fields as v1beta1. Your metrics implementation (typically metrics-server) must serve the new version and register an APIService so the aggregated endpoint appears; kubectl top prefers v1 and falls back to v1beta1. No feature gate needed.

Scale-to-zero autoscaling is now core

Right next to it: HPA scale-to-zero reached Beta and is enabled by default. You can now set minReplicas: 0 on a HorizontalPodAutoscaler that reads an object or external metric — a queue length, not CPU — and the last idle Pod is removed instead of parked. That's a real cost change for batch processors, queue consumers, and anything with bursty traffic; the savings are biggest when every replica reserves expensive resources like dedicated CPUs or GPUs.

The trade-off is cold start: the HPA has to observe the metric, schedule a Pod, and boot the app. The controller records a ScaledToZero status condition so later reconciliation knows the zero was intentional, not a manual pause. Keep that warm-cool logic in mind for customer-facing services — cold starts there are a feature only occasionally.

A rootless kubelet goes Beta

Security-minded teams get a first-class hardening path. Kubelet in User Namespace (rootless mode) graduated to Beta: the kubelet, CRI/OCI runtimes, CNI plugins, and even kube-proxy can run unprivileged on the host while behaving as root inside a Linux user namespace. The KubeletInUserNamespace feature gate is on by default (it merely lets the kubelet ignore the sysctl and /dev/kmsg permission errors it would otherwise hit — enabling the gate does not itself change how existing rootful clusters run). The payoff is a smaller blast radius: a container escape lands in an unprivileged namespace rather than on a root-owned process that can reconfigure the node.

It's not a flip of a switch. Privileged DaemonSets, host-path mounts, observability and security agents that assumed host root all need an audit — and the audit is far cheaper while the feature is optional Beta than after it becomes the default.

Storage and scheduling catch up

Two more useful betas: PVC "last used" tracking (PersistentVolumeClaimUnusedSinceTime) now enabled by default adds an Unused condition that reports how long a claim has been idle, so you can stop paying for stranded volumes. And gang scheduling reached Beta with workload-aware preemption and PodGroup queueing — all-or-nothing pod groups that matter for AI and batch workloads that can't make progress on a partial set of replicas.

SELinuxMount reached GA: volume relabeling now uses the kernel's native -o context mount option instead of a slow recursive filesystem walk.

The deprecations you can't ignore

Three changes need a look before you upgrade:

  • kube-proxy ipvs mode is being retired. It was introduced in v1.8 to dodge iptables bottlenecks, but it still leans on iptables underneath. kube-proxy now warns on startup; ipvs is expected to be disabled by default in v1.40 and removed by v1.43. The path forward is the newer nftables backend.
  • cgroup v1 is being phased out. cgroup v2 is the default, and since v1.35 the kubelet fails to initialize on cgroup v1 nodes unless you set failCgroupV1: false — a stopgap, not a strategy.
  • Static Pods can no longer reference Secrets or ConfigMaps. The bug that let them read API resources directly is fixed, and the PreventStaticPodAPIReferences gate is gone. Any static manifest relying on secretRef/configMapRef will fail to start.

Kubernetes v1.37 is a subtle release with sharp edges. Upgrade for the GA metrics API and the promised savings of scale-to-zero — just budget time for the ipvs, cgroup, and static-pod cleanups first.