Skip to content

chore(deps): update dependency k3s-io/k3s to v1.37.1+k3s1 - #121

Merged
Stensel8 merged 1 commit into
mainfrom
renovate/kubernetes-installer-deps
Oct 1, 2026
Merged

Stensel8 merged 1 commit into
mainfrom
renovate/kubernetes-installer-deps

Conversation

@renovate

@renovate renovate Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
k3s-io/k3s patch v1.37.0+k3s1 → v1.37.1+k3s1

Release Notes

k3s-io/k3s (k3s-io/k3s)

v1.37.1+k3s1: v1.37.1+k3s1

Compare Source

This release updates Kubernetes to v1.37.1, and fixes a number of issues.

For more details on what's new, see the Kubernetes release notes.

Changes since v1.37.0+k3s1:

  • Backports for 2026-09 (#​14631)
    • Fix restore from compressed etcd snapshot #​14528
    • Enable seccomp in riscv64 builds #​14529
    • Use ginkgo CLI to run tests #​14531
    • Bump k3s-io/api to v0.2.0 #​14570
    • Servicelb multiple lbpools #​14547
    • Close minio.Object after read #​14580
    • Bump k3s-io/apis again #​14589
    • Fix --flannel-cni-conf not reaching the embedded flannel #​14598
    • Check-config: suppress colors when stdout is not a terminal #​14595
    • Fix deploy controller not re-applying manifests when mtime is pinned to the epoch #​14568
    • Bump etcd to v3.7.1-k3s3 for nonblocking logging support #​14628
    • Bump kine to v0.17.1 #​14627
  • Bump helm-controller (#​14684)
  • Bump k3s-io/kubernetes and Go references (#​14695)
  • Bump cadvisor to v0.60.5-k3s1 (#​14698)
  • Reject anonymous access to supervisor router (spegel/pprof/metrics) (#​14701)
  • Improve CA hash validation (#​14705)

Embedded Component Versions

Component Version
Kubernetes v1.37.1
Kine v0.17.1
SQLite 3.53.4
Etcd v3.7.1-k3s3
Containerd v2.3.4-k3s1
Runc v1.4.2
Flannel v0.28.4
Metrics-server v0.9.0
Traefik v3.7.13
CoreDNS v1.14.7
Helm-controller v0.17.9
Local-path-provisioner v0.0.37

Helpful Links

As always, we welcome and appreciate feedback from our community of users. Please feel free to:


Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Summary by CodeRabbit

  • Updates
    • The default K3s release is now v1.37.1+k3s1. An explicitly configured version continues to take precedence.

@renovate
renovate Bot requested a review from Stensel8 as a code owner October 1, 2026 17:40
@renovate renovate Bot added the dependencies label Oct 1, 2026
@renovate
renovate Bot enabled auto-merge (squash) October 1, 2026 17:40
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 234bc518-6313-481d-9bb7-a34fa81ed958

📥 Commits

Reviewing files that changed from the base of the PR and between 3407490 and 4d1355c.

📒 Files selected for processing (1)
  • kubernetes/k3s_installer.sh

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The K3s installer’s default version changes to v1.37.1+k3s1. An existing K3S_VERSION value continues to override the default.

Changes

K3s version selection

Layer / File(s) Summary
Update default K3s version
kubernetes/k3s_installer.sh
The default changes from v1.37.0+k3s1 to v1.37.1+k3s1. An existing K3S_VERSION value continues to take precedence.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~2 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 4d135

The default advances to v1.37.1+k3s1, while K3S_VERSION can still select another release. No actionable merge risk was established, so the change appears ready for normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 4d135

The change preserves explicit version overrides, installation permissions, and existing-install safeguards. No introduced security defect was demonstrated, but the new release's authentication behavior and compatibility with existing clusters were not independently verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The selected release runs with host-level privilege and participates as a cluster control plane or enrolled worker. Consequently, a release-level security regression could affect the installed host and its cluster authority. Actual deployment, tenant, and fleet exposure is not established; the existing-install guard limits automatic propagation through this wrapper.

Trust Boundaries and Controls

  • observed — Installation is root-gated and executes code fetched over HTTPS from the same upstream installer endpoint. This privileged upstream trust relationship already exists; the patch changes the selected release without adding a local authority grant or new download endpoint.
  • observed — The worker reachability probe disables TLS certificate verification for /ping. It is a pre-existing reachability check, not evidence that the delegated node join authenticates the server correctly or incorrectly; the upstream join implementation is outside the hydrated source.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains the dependency update and includes release notes, but it does not use the repository template or include the required Summary, Type of change, and Checklist sections. Add the repository template sections. Include a brief summary, select chore under Type of change, and complete the checklist.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the maintenance change and the exact K3s version update.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@Stensel8
Stensel8 merged commit 53a40b8 into main Oct 1, 2026
9 of 10 checks passed
@Stensel8
Stensel8 deleted the renovate/kubernetes-installer-deps branch October 1, 2026 17:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant