Release Notes - 2026-09-04
Monitor the release status by regions at AKS-Release-Tracker. This release is titled
v20260904.
Announcements of upcoming changes and retirements
- Starting September 30, 2026, AKS will automatically migrate deprecated Availability Sets (VMAS) clusters to Virtual Machines node pools through the auto-upgrader. To control the migration timing, migrate before that date by using
az aks update --migrate-vmas-to-vms. - Azure Linux with OS Guard for Azure Kubernetes Service (AKS) (preview) will be retired on December 10, 2026. Please transition to Azure Container Linux by that date. From now to December 9, 2026, you can continue to use Azure Linux with OS Guard (preview) without disruption. On December 10, 2026, AKS will no longer produce new Azure Linux with OS Guard node images or provide security patches, and you will not be able to create new node pools with Azure Linux with OS Guard. On March 10, 2027, AKS will remove all existing Azure Linux with OS Guard node images, which will cause scaling and remediation (reimage and redeploy) operations to fail.
Release notes
Kubernetes versions
- Kubernetes Version 1.37 Preview is being rolled out.
- Kubernetes patch versions
1.36.3,1.35.7, and1.34.10are now available.
Features
- Autoscaling for Virtual Machines node pools is now generally available, including multi-SKU autoscaling.
Preview features
- Existing clusters can now be converted to use a managed system node pool in supported regions after registering the required preview feature.
- Node pools with an in-progress blue-green upgrade can now switch safely to the rolling upgrade strategy.
- On-Demand Monitor, a new Cluster Health Monitor capability for node health checks and remediation, is available in preview.
Behavioral changes
- The AKS release status site now includes Windows Server 2025 and no longer lists Windows Server 2019 or Windows Server, version 23H2 because AKS no longer produces VHDs for those versions. The AKS release status site now shows only the default VHD for each Windows version.
- Starting with Kubernetes 1.37, LocalDNS is enabled automatically when the cluster networking configuration supports it. Clusters using bring-your-own CNI, network policy configurations that aren't supported, or an existing custom DNS configuration aren't changed.
- AKS now rejects updates that attempt to remove IPv6 from an existing dual-stack cluster. Dual-stack to single-stack migration isn't supported.
- New clusters using an HTTP proxy or Custom Certificate Authority now reject CA certificate content larger than 35 KB, preventing node bootstrap data from exceeding platform limits. Existing clusters aren't affected.
- Managed namespace creation now rejects names beginning with the reserved
kube-oraks-istio-prefixes. This prevents naming conflicts with system-reserved namespaces and reduces the risk of customers accidentally interfering with Kubernetes or AKS-managed components. - When the Azure Policy add-on is enabled in AKS, Azure Policy's Kubernetes-native validation path is now enabled by default across regions.
- Static Egress Gateway nodes now deregister from the load balancer before a node-image upgrade reimages them, reducing the risk of interrupted egress traffic.
- AKS will return a validation error if you try to enable KMS encryption-at-rest for Kubernetes secrets handled by K8s API with customer managed key on 1.37 cluster with versioned Key Vault key IDs. This feature requires specification of versionless Azure Key Vault key ID.
Bug fixes
- Fixed an issue where the Microsoft Defender for Containers collector could prevent CSI volumes from detaching, leaving volumes terminating and blocking dependent pods from scheduling.
- Fixed missing Windows node metrics caused by an incorrect exporter port configuration.
Component updates
- Gatekeeper has been updated to
v3.23.1, fixing excessive Validating Admission Policy reconciliation requests. - Managed Gateway API on Kubernetes 1.37 now uses the Gateway API v1.6.1 standard-channel CRD bundle, adding the graduated
TCPRouteandUDPRouteresources. - Istio-based service mesh add-on revisions have been updated with security patches for ISTIO-SECURITY-2026-006:
asm-1-29tov1.29.7asm-1-30tov1.30.4- Restart workload pods to trigger reinjection of the updated
istio-proxysidecar. For more information, see the Istio add-on upgrade guide.
- Azure CSI drivers have been updated:
- Cloud Provider Azure components have been updated to
v1.33.17-2andv1.36.5-2, includingcloud-controller-manager,cloud-node-manager, andhealth-probe-proxy. The Kubernetes 1.36 cloud controller manager also includes Service Gateway support. - Cilium, Hubble Relay, and Advanced Container Networking Services FQDN policy images have been updated:
- App Routing updated to version 0.2.28 with ingress-nginx bumped to
v1.13.10-10with additional validation for custom log formats. - AKS Windows images:
- Windows Server 2022 - 20348.5499.260812.
- Windows Server 2025 - 26100.33296.260812.
- AKS Azure Linux images:
- v3.0 - 202608.06.1.
- v3.0 - 202608.14.0.
- v3.0 - 202608.20.0.
- v3.0 - 202608.26.0.
- AKS Azure Container Linux images:
- ACLv3 - 202608.06.1.
- ACLv3 - 202608.14.0.
- ACLv3 - 202608.20.0.
- ACLv3 - 202608.26.0.
- AKS Ubuntu images:
- Ubuntu 22.04 - 202608.06.1.
- Ubuntu 22.04 - 202608.14.0.
- Ubuntu 22.04 - 202608.20.0.
- Ubuntu 22.04 - 202608.26.0.
- Ubuntu 24.04 - 202608.06.1.
- Ubuntu 24.04 - 202608.14.0.
- Ubuntu 24.04 - 202608.20.0.
- Ubuntu 24.04 - 202608.26.0.