Warning
Upstream ingress-nginx Retirement & Transition to Traefik
Because ingress-nginx was retired upstream as of March 2026, Traefik is now the default for new clusters starting in v1.36 (existing clusters will keep their current ingress upon upgrade to avoid breakage). This transition brings the following structural changes:
- Airgapped Environments: The
rke2-images-coretarball now contains Traefik images instead ofingress-nginx. The standalonerke2-images-traefiktarball has been removed. Users who must continue usingingress-nginxwill now need to manually provide therke2-images-ingress-nginxtarball. - Future Removal: The
ingress-nginxchart will not receive any additional updates and will be completely removed in v1.37 for community users. - Prime Customers: Please refer to the official product documentation for specific Prime considerations.
This release upgrades Traefik chart to v40.x which includes a breaking change for the ingress-nginx migration: the provider name changes from kubernetesIngressNginx to kubernetesIngressNGINX. Check https://github.com/traefik/traefik-helm-chart/releases/tag/v40.0.0 for more details
This release updates Kubernetes to v1.36.5.
Important Note
If your server (control-plane) nodes were not started with the --token CLI flag or config file key, a randomized token was generated during initial cluster startup. This key is used both for joining new nodes to the cluster, and for encrypting cluster bootstrap data within the datastore. Ensure that you retain a copy of this token, as is required when restoring from backup.
You may retrieve the token value from any server already joined to the cluster:
cat /var/lib/rancher/rke2/server/tokenChanges since v1.36.4+rke2r1:
- Update multus to version v4.3.0.10 (#11152)
- Bump Traefik chart version to get latest gateway-api crds (#11143)
- Consume gateway-api v1.6.1
- Bump Traefik 3.7.13 (#11180)
- Bump Traefik to v3.7.13 (grpc CVE fix) (#11200)
- Cnis update for 2026-09 release (#11207)
- Rke2-snapshot-controller: bump image to v8.6.0-build20260909 (#11222)
- Update hardened core, coredns, vsphere, metric images (#11233)
- Bump k3s and etcd (#11241)
- Bump klipper-helm to v0.13.3-build20260909 (#11250)
- Bump rke2-cloud-provider version for 2026-09 release cycle (#11259)
- Update ingress-nginx to chart 4.15.110 / image v1.15.1-prime12 (#11254)
- Update Cilium chart to 1.20.200 (#11267)
- Update multus chart to v4.3.102 (#11289)
- Update to v1.36.5-rke2r1 and Go 1.26.8 (#11299)
- Charts: Bump Harvester CSI Driver to 0.1.32 (#11279)
- Bump Harvester CSI Driver to v0.2.10 and add optional controller pod security context support; default behavior is unchanged.
- Update CoreDNS chart to 1.47.101 (#11293)
- Update CoreDNS chart to 1.47.102 (#11304)
- Bump k3s 2026-Sept (#11317)
Charts Versions
| Component | Version |
|---|---|
| rke2-cilium | 1.20.200 |
| rke2-canal | v3.32.2-build2026090900 |
| rke2-calico | v3.32.200 |
| rke2-calico-crd | v3.32.200 |
| rke2-coredns | 1.47.102 |
| rke2-ingress-nginx | 4.15.110 |
| rke2-metrics-server | 3.14.001 |
| rke2-multus | v4.3.102 |
| rancher-vsphere-csi | 3.7.3-rancher300 |
| rancher-vsphere-cpi | 1.16.200 |
| harvester-cloud-provider | 0.2.1500 |
| harvester-csi-driver | 0.1.3200 |
| rke2-snapshot-controller | 5.2.004 |
| rke2-snapshot-controller-crd | 5.2.004 |
| rke2-traefik | 40.1.013 |
| rke2-traefik-crd | 40.1.013 |
Packaged Component Versions
| Component | Version |
|---|---|
| Kubernetes | v1.36.5 |
| Etcd | v3.6.14-k3s3 |
| Containerd | v2.3.4-k3s1 |
| Runc | v1.4.3 |
| Metrics-server | v0.9.0 |
| CoreDNS | v1.14.7 |
| Ingress-Nginx | v1.14.5-hardened2 |
| Helm-controller | v0.17.9 |
| Traefik | v3.7.13 |
Available CNIs
| Component | Version | FIPS Compliant |
|---|---|---|
| Canal (Default) | Flannel v0.28.9 Calico v3.32.2 | Yes |
| Calico | v3.32.2 | No |
| Cilium | v1.20.2 | No |
| Multus | v4.3.1 | No |
Helpful Links
As always, we welcome and appreciate feedback from our community of users. Please feel free to:
- Open issues here
- Join our Slack channel
- Check out our documentation for guidance on how to get started.