v1.33.X
Upgrade Notice
Before upgrading from earlier releases, be sure to read the Kubernetes Urgent Upgrade Notes. |
Version | Release date | Kubernetes | Etcd | Containerd | Runc | Metrics-server | CoreDNS | Ingress-Nginx | Helm-controller | Canal (Default) | Calico | Cilium | Multus |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Aug 23 2025 |
|||||||||||||
Jul 25 2025 |
|||||||||||||
Jun 27 2025 |
|||||||||||||
May 21 2025 |
|||||||||||||
May 07 2025 |
Release v1.33.4+rke2r1
This release updates Kubernetes to v1.33.4.
Important Note
If your server (control-plane) nodes were not started with the --token
CLI flag or config file key, a randomized token was generated during initial cluster startup. This key is used both for joining new nodes to the cluster, and for encrypting cluster bootstrap data within the datastore. Ensure that you retain a copy of this token, as is required when restoring from backup.
You may retrieve the token value from any server already joined to the cluster:
cat /var/lib/rancher/rke2/server/token
Changes since v1.33.3+rke2r1
-
Add.utils test (#8651) - backport 1.33 (#8662)
-
CNI Bumps for Aug 25 release (#8695)
-
Bump rke2-coredns to 1.43.100 (#8721)
-
Update to cilium v1.18.000 (#8716)
-
Bump ingress-nginx to v1.12.4-hardened6 (#8732)
-
Update Kubernetes Metrics Server chart 3.13.000 (#8741)
-
Separate pod template generation and static pod execution code (#8746)
-
Add prime ribs index upload and cache invalidation (#8711)
-
Bump k3s (#8749)
-
Bump K3s version for certificate startup check fix (#8762)
-
Update K8s to v1.33.4 and Go to v1.24.5 (#8773)
-
Fix missing ECM config (#8778)
-
Fix uploader authentication (#8783)
-
Bump k3s for metric and event fixes (#8785)
-
Bump ingress-nginx to hardened7 (#8789)
-
Bump coredns chart and image (#8736) (#8795)
-
Fix static pod cleanup (#8806)
Charts Versions
Component | Version |
---|---|
rke2-cilium |
|
rke2-canal |
|
rke2-calico |
|
rke2-calico-crd |
|
rke2-coredns |
|
rke2-ingress-nginx |
|
rke2-metrics-server |
|
rancher-vsphere-csi |
|
rancher-vsphere-cpi |
|
harvester-cloud-provider |
|
harvester-csi-driver |
|
rke2-snapshot-controller |
|
rke2-snapshot-controller-crd |
|
rke2-snapshot-validation-webhook |
Release v1.33.3+rke2r1
This release updates Kubernetes to v1.33.3.
Important Note
If your server (control-plane) nodes were not started with the --token
CLI flag or config file key, a randomized token was generated during initial cluster startup. This key is used both for joining new nodes to the cluster, and for encrypting cluster bootstrap data within the datastore. Ensure that you retain a copy of this token, as is required when restoring from backup.
You may retrieve the token value from any server already joined to the cluster:
cat /var/lib/rancher/rke2/server/token
Changes since v1.33.2+rke2r1
-
Update Canal chart to latest version (#8529)
-
Prepend defaults to extra kube args (#8513)
-
Bump multus and whereabouts chart (#8536)
-
Update Kubernetes Metrics Server chart 3.12.203 (#8555)
-
Change structure and set namespace for ctr command (#8545)
-
Bump ingress-nginx to v1.12.4-hardened1 (#8568)
-
Charts: Bump Harvester CSI driver 0.1.24 (#8507)
-
Support online resize
-
Support external storage
-
-
Allow for zypper remove 104 code on uninstall (#8579)
-
Fix snapshot controller backwards compatibility (#8591)
-
-
Update flannel chart v0.27.100 (#8601)
-
Backports for 2025-07 (#8606)
-
Update K8s to
v1.33.3
(#8625) -
Bump ingress-nginx to hardened2 (#8632)
-
Update to cilium
v1.17.6
(#8643)
Charts Versions
Component | Version |
---|---|
rke2-cilium |
|
rke2-canal |
|
rke2-calico |
|
rke2-calico-crd |
|
rke2-coredns |
|
rke2-ingress-nginx |
|
rke2-metrics-server |
|
rancher-vsphere-csi |
|
rancher-vsphere-cpi |
|
harvester-cloud-provider |
|
harvester-csi-driver |
|
rke2-snapshot-controller |
|
rke2-snapshot-controller-crd |
|
rke2-snapshot-validation-webhook |
Release v1.33.2+rke2r1
This release updates Kubernetes to v1.33.2.
Important Note
If your server (control-plane) nodes were not started with the --token
CLI flag or config file key, a randomized token was generated during initial cluster startup. This key is used both for joining new nodes to the cluster, and for encrypting cluster bootstrap data within the datastore. Ensure that you retain a copy of this token, as is required when restoring from backup.
You may retrieve the token value from any server already joined to the cluster:
cat /var/lib/rancher/rke2/server/token
Changes since v1.33.1+rke2r1
-
June 2025 CNI bumps (#8328)
-
Windows: Allow for silent/non confirmation use of uninstall.ps1 (#8342)
-
Testing Overhaul Backports (#8364)
-
Bump canal, flannel and cilium charts (#8359) (#8382)
-
Bump multus and whereabouts (#8360) (#8387)
-
Support profile: etcd (#8371)
-
Bump for etcd, containerd, cloud provider, runc and crictl (#8407)
-
Backports for 2025-06 (#8417)
-
Update Kubernetes Metrics Server chart 3.12.2 (#8421)
-
Update CoreDNS chart 1.42.3 (#8425)
-
Bump ingress-nginx to v1.12.2 and hardened-dns-node for CVE fixes (#8403)
-
Bump K3s version (#8434)
-
June K8s
v1.33.2
patch (#8446) -
Update runc to the newest image (#8471)
Charts Versions
Component | Version |
---|---|
rke2-cilium |
|
rke2-canal |
|
rke2-calico |
|
rke2-calico-crd |
|
rke2-coredns |
|
rke2-ingress-nginx |
|
rke2-metrics-server |
|
rancher-vsphere-csi |
|
rancher-vsphere-cpi |
|
harvester-cloud-provider |
|
harvester-csi-driver |
|
rke2-snapshot-controller |
|
rke2-snapshot-controller-crd |
|
rke2-snapshot-validation-webhook |
Release vhttps://github.com/rancher/rke2/releases/tag/v1.33.1+rke2r1[v1.33.1+rke2r1]
This release updates Kubernetes to v1.33.1.
Important Note
If your server (control-plane) nodes were not started with the --token
CLI flag or config file key, a randomized token was generated during initial cluster startup. This key is used both for joining new nodes to the cluster, and for encrypting cluster bootstrap data within the datastore. Ensure that you retain a copy of this token, as is required when restoring from backup.
You may retrieve the token value from any server already joined to the cluster:
cat /var/lib/rancher/rke2/server/token
Changes since v1.33.0+rke2r1
-
Upload prime ribs assets (#8172)
-
Feat: bump harvester-cloud-provider to v0.2.10 (#8183)
-
Backports for 2025-05 (#8195)
-
Udpate calico chart to v3.30.0 and Canal image (#8201)
-
Bump nginx version (#8178)
-
Update to Kubernetes Metrics Server 3.12.201 (#8210)
-
Update to flannel v0.26.700 (#8218)
-
Update cilium and multus to cni-plugins v1.7.1 (#8226)
-
Upgrade nginx chart (#8231)
-
Update to flannel v0.26.701 and canal v3.30.0-build2025051500 (#8257)
-
Update to CoreDNS 1.42.000 (#8265)
-
Update k8s to v1.33.1 (#8241)
-
Fix race conditions in startup readiness checks (#8275)
-
Fix secrets syntax (#8283)
Charts Versions
Component | Version |
---|---|
rke2-cilium |
|
rke2-canal |
|
rke2-calico |
|
rke2-calico-crd |
|
rke2-coredns |
|
rke2-ingress-nginx |
|
rke2-metrics-server |
|
rancher-vsphere-csi |
|
rancher-vsphere-cpi |
|
harvester-cloud-provider |
|
harvester-csi-driver |
|
rke2-snapshot-controller |
|
rke2-snapshot-controller-crd |
|
rke2-snapshot-validation-webhook |
Release v1.33.0+rke2r1
This release updates Kubernetes to v1.33.0.
Important Note
If your server (control-plane) nodes were not started with the --token
CLI flag or config file key, a randomized token was generated during initial cluster startup. This key is used both for joining new nodes to the cluster, and for encrypting cluster bootstrap data within the datastore. Ensure that you retain a copy of this token, as is required when restoring from backup.
You may retrieve the token value from any server already joined to the cluster:
cat /var/lib/rancher/rke2/server/token
Charts Versions
Component | Version |
---|---|
rke2-cilium |
|
rke2-canal |
|
rke2-calico |
|
rke2-calico-crd |
|
rke2-coredns |
|
rke2-ingress-nginx |
|
rke2-metrics-server |
|
rancher-vsphere-csi |
|
rancher-vsphere-cpi |
|
harvester-cloud-provider |
|
harvester-csi-driver |
|
rke2-snapshot-controller |
|
rke2-snapshot-controller-crd |
|
rke2-snapshot-validation-webhook |