Skip to main content

v1.34.X

Upgrade Notice

Before upgrading from earlier releases, be sure to read the Kubernetes Urgent Upgrade Notes.

VersionRelease dateKubernetesEtcdContainerdRuncMetrics-serverCoreDNSIngress-NginxHelm-controllerCanal (Default)CalicoCiliumMultus
v1.34.6+rke2r3Apr 08 2026v1.34.6v3.6.7-k3s1v2.2.2-k3s1v1.4.1v0.8.1v1.14.2v1.14.5-hardened1v0.16.17Flannel v0.28.2
Calico v3.31.4
v3.31.4v1.19.1v4.2.4
v1.34.6+rke2r1Mar 28 2026v1.34.6v3.6.7-k3s1v2.2.2-k3s1v1.4.1v0.8.1v1.14.2v1.14.5-hardened1v0.16.17Flannel v0.28.2
Calico v3.31.4
v3.31.4v1.19.1v4.2.4
v1.34.5+rke2r1Mar 05 2026v1.34.5v3.6.7-k3s1v2.1.5-k3s1v1.4.0v0.8.1v1.14.1v1.14.3-hardened3v0.16.17Flannel v0.28.1
Calico v3.31.3
v3.31.3v1.19.1v4.2.3
v1.34.4+rke2r1Feb 13 2026v1.34.4v3.6.7-k3s1v2.1.5-k3s1v1.4.0v0.8.1v1.14.1v1.14.3-hardened2v0.16.17Flannel v0.28.1
Calico v3.31.3
v3.31.3v1.19.0v4.2.3
v1.34.3+rke2r3Feb 04 2026v1.34.3v3.6.7-k3s1v2.1.5-k3s1v1.4.0v0.8.0v1.14.1v1.14.3-hardened1v0.16.17Flannel v0.28.0
Calico v3.31.3
v3.31.3v1.18.6v4.2.3
v1.34.3+rke2r1Dec 18 2025v1.34.3v3.6.6-k3s1v2.1.5-k3s1v1.4.0v0.8.0v1.13.1v1.13.5-hardened2v0.16.17Flannel v0.27.4
Calico v3.31.2
v3.31.2v1.18.4v4.2.3
v1.34.2+rke2r1Nov 20 2025v1.34.2v3.6.5-k3s1v2.1.5-k3s1v1.3.3v0.8.0v1.13.1v1.13.4-hardened1v0.16.16Flannel v0.27.4
Calico v3.30.3
v3.30.4v1.18.3v4.2.3
v1.34.1+rke2r1Sep 17 2025v1.34.1v3.6.4-k3s3v2.1.4-k3s2v1.3.1v0.8.0v1.12.3v1.12.6-hardened1v0.16.13Flannel v0.27.3
Calico v3.30.3
v3.30.3 v1.18.1v4.2.2

Release v1.34.6+rke2r3

This release updates Kubernetes to v1.34.6.

Important Note

If your server (control-plane) nodes were not started with the --token CLI flag or config file key, a randomized token was generated during initial cluster startup. This key is used both for joining new nodes to the cluster, and for encrypting cluster bootstrap data within the datastore. Ensure that you retain a copy of this token, as is required when restoring from backup.

You may retrieve the token value from any server already joined to the cluster:

cat /var/lib/rancher/rke2/server/token

Changes since v1.34.6+rke2r1:

Charts Versions

ComponentVersion
rke2-cilium1.19.101
rke2-canalv3.31.4-build2026032700
rke2-calicov3.31.400
rke2-calico-crdv3.31.400
rke2-coredns1.45.205
rke2-ingress-nginx4.14.503
rke2-metrics-server3.13.007
rancher-vsphere-csi3.5.0-rancher200
rancher-vsphere-cpi1.12.100
harvester-cloud-provider0.2.1100
harvester-csi-driver0.1.2500
rke2-snapshot-controller4.2.002
rke2-snapshot-controller-crd4.2.002
rke2-snapshot-validation-webhook0.0.0
rke2-traefik39.0.502
rke2-traefik-crd39.0.502

Release v1.34.6+rke2r1

This release updates Kubernetes to v1.34.6.

Important Note

If your server (control-plane) nodes were not started with the --token CLI flag or config file key, a randomized token was generated during initial cluster startup. This key is used both for joining new nodes to the cluster, and for encrypting cluster bootstrap data within the datastore. Ensure that you retain a copy of this token, as is required when restoring from backup.

You may retrieve the token value from any server already joined to the cluster:

cat /var/lib/rancher/rke2/server/token

Changes since v1.34.5+rke2r1:

  • Add prime configuration (#9877)
  • Bump ingresses 2026 March (#9892)
  • Bump snapshot crd for groupsnapshot v1beta2 (#9903)
    • Update to multus chart v4.2.403 (#9911)
    • Update to CoreDNS chart 1.45.205 (#9919)
  • Update PSA namespace exceptions (#9928)
  • Bump flannel with newer busybox image (#9936)
  • Version bumps and backports for 2026-03 (#9939)
    • Update to canal v3.31.4-build2026031000 (#9951)
  • Bump runc to v1.4.1 (#9956)
  • Pass PRIME_REGISTRY env var to make ci steps (#9964)
  • Add PRIME_REGISTRY passthrough to in-docker-XXXXX targets (#9974)
  • Bump K3s version (#9987)
  • Update to v1.34.6 (#9992)
  • Bump ingress nginx to 1.14.5 (#10005)
  • Pin GH Actions to commit sha (#10018)
  • Add Install Trivy step (#10025)

Charts Versions

ComponentVersion
rke2-cilium1.19.101
rke2-canalv3.31.4-build2026032700
rke2-calicov3.31.400
rke2-calico-crdv3.31.400
rke2-coredns1.45.205
rke2-ingress-nginx4.14.501
rke2-metrics-server3.13.007
rancher-vsphere-csi3.5.0-rancher200
rancher-vsphere-cpi1.12.100
harvester-cloud-provider0.2.1100
harvester-csi-driver0.1.2500
rke2-snapshot-controller4.2.002
rke2-snapshot-controller-crd4.2.002
rke2-snapshot-validation-webhook0.0.0
rke2-traefik39.0.502
rke2-traefik-crd39.0.502

Release v1.34.5+rke2r1

This release updates Kubernetes to v1.34.5.

Important Note

If your server (control-plane) nodes were not started with the --token CLI flag or config file key, a randomized token was generated during initial cluster startup. This key is used both for joining new nodes to the cluster, and for encrypting cluster bootstrap data within the datastore. Ensure that you retain a copy of this token, as is required when restoring from backup.

You may retrieve the token value from any server already joined to the cluster:

cat /var/lib/rancher/rke2/server/token

Changes since v1.34.4+rke2r1:

  • Ingress-Nginx to Traefik Docker Test (#9736)
  • Prevent a node transform from agent/server to server/agent (#9779)
  • Fix package dev broken after dapper removal from rke2-packaging (#9805)
  • Bump Traefik to v3.6.9 (#9821)
  • Update to v1.34.5 and Go v1.24.13 (#9811)
  • Bump k3s for etcd bootstrap fix (#9794)
  • Bump ETCD version to v3.6.7-k3s1-20260227 (#9825)
  • Chore: Bump ingress-nginx 2026-Feb (#9830)
  • Backports for 2026-02 BONUS RELEASE (#9841)
  • Bump crictl, runc and containerd to build20260303 (#9851)

Charts Versions

ComponentVersion
rke2-cilium1.19.100
rke2-canalv3.31.3-build2026020600
rke2-calicov3.31.300
rke2-calico-crdv3.31.300
rke2-coredns1.45.201
rke2-ingress-nginx4.14.303
rke2-metrics-server3.13.007
rancher-vsphere-csi3.5.0-rancher200
rancher-vsphere-cpi1.12.100
harvester-cloud-provider0.2.1100
harvester-csi-driver0.1.2500
rke2-snapshot-controller4.2.001
rke2-snapshot-controller-crd4.2.001
rke2-snapshot-validation-webhook0.0.0
rke2-traefik39.0.002
rke2-traefik-crd39.0.002

Release v1.34.4+rke2r1

This release updates Kubernetes to v1.34.4.

Important Note

If your server (control-plane) nodes were not started with the --token CLI flag or config file key, a randomized token was generated during initial cluster startup. This key is used both for joining new nodes to the cluster, and for encrypting cluster bootstrap data within the datastore. Ensure that you retain a copy of this token, as is required when restoring from backup.

You may retrieve the token value from any server already joined to the cluster:

cat /var/lib/rancher/rke2/server/token

Changes since v1.34.3+rke2r3:

  • Bump k3s + Bulk Backports 2026-02 (#9655)
    • Update to CoreDNS chart 1.45.201 (#9645)
  • Remove cloud-config arg from kubelet for windows (#9674)
  • CNI bumps for the Feb 2026 release (#9680)
    • Update Kubernetes Metrics Server chart 3.13.007 (#9688)
  • Bump ingress-nginx to v1.14.3-hardened2 (#9697)
  • Update K8s to v1.34.4 and Go to v1.24.12 (#9702)
  • Bump k3s/rke2-ccm/klipper-lb/klipper-helm (#9713)

Charts Versions

ComponentVersion
rke2-cilium1.19.001
rke2-canalv3.31.3-build2026020600
rke2-calicov3.31.300
rke2-calico-crdv3.31.300
rke2-coredns1.45.201
rke2-ingress-nginx4.14.302
rke2-metrics-server3.13.007
rancher-vsphere-csi3.5.0-rancher200
rancher-vsphere-cpi1.12.100
harvester-cloud-provider0.2.1100
harvester-csi-driver0.1.2500
rke2-snapshot-controller4.2.001
rke2-snapshot-controller-crd4.2.001
rke2-snapshot-validation-webhook0.0.0
rke2-traefik39.0.000
rke2-traefik-crd39.0.000

Release v1.34.3+rke2r3

This release updates Kubernetes to v1.34.3.

Important Note

If your server (control-plane) nodes were not started with the --token CLI flag or config file key, a randomized token was generated during initial cluster startup. This key is used both for joining new nodes to the cluster, and for encrypting cluster bootstrap data within the datastore. Ensure that you retain a copy of this token, as is required when restoring from backup.

You may retrieve the token value from any server already joined to the cluster:

cat /var/lib/rancher/rke2/server/token

Changes since v1.34.3+rke2r1:

  • Remove dapper + use crane (#9443)
  • Bump calico chart to v3.31.300 (#9459)
  • CNI bump Jan 2026 (#9473)
  • Bump Ingresses - 2026 Jan (#9481)
  • Bulk Backports - 2026 Jan (#9493)
  • Rke2-coredns: Use k8s-style "IANA" names (RFC 6335) (#9504)
  • K3s bump and backports for 2026-01 (#9514)
  • Adjust Windows directory creation order (#9526)
  • Bump Traefik version to v3.6.7 (#9550)
  • Update chart and container image versions (#9559)
  • Add e2e test for Calico in eBPF mode (#9567)
  • Bump etcd to v3.6.7 (#9579)
  • Update to v1.34.3-rke2r3 (#9596)
  • Fix release arm64 (#9601)
  • Backport: Increase timeouts in calico eBPF e2e tests (#9606)
  • Fix manifest and sync-prime steps (#9610)
  • Revert accidental hardcode of klipper-helm tag (#9624)
  • Bump K3s version for etcd reconcile fix (#9629)
  • Bump ingress-nginx to v1.14.3-hardened1 (#9634)

Charts Versions

ComponentVersion
rke2-cilium1.18.601
rke2-canalv3.31.3-build2026011900
rke2-calicov3.31.300
rke2-calico-crdv3.31.300
rke2-coredns1.45.008
rke2-ingress-nginx4.14.301
rke2-metrics-server3.13.006
rancher-vsphere-csi3.5.0-rancher200
rancher-vsphere-cpi1.12.100
harvester-cloud-provider0.2.1100
harvester-csi-driver0.1.2500
rke2-snapshot-controller4.2.000
rke2-snapshot-controller-crd4.2.000
rke2-snapshot-validation-webhook0.0.0
rke2-traefik38.0.201
rke2-traefik-crd38.0.201

Release v1.34.3+rke2r1

This release updates Kubernetes to v1.34.3.

Important Note

If your server (control-plane) nodes were not started with the --token CLI flag or config file key, a randomized token was generated during initial cluster startup. This key is used both for joining new nodes to the cluster, and for encrypting cluster bootstrap data within the datastore. Ensure that you retain a copy of this token, as is required when restoring from backup.

You may retrieve the token value from any server already joined to the cluster:

cat /var/lib/rancher/rke2/server/token

Changes since v1.34.2+rke2r1:

  • Remove NetworkManager check for nm-cloud.service (#9292)
  • Bump rke2-multus to v4.2.303 (#9326)
  • Bump rke2-coredns to 1.45.002 (#9333)
  • Update CNI to the latest versions (#9353)
  • Update to multus chart version v4.2.305 (#9357)
    • Update to CoreDNS chart 1.45.003 and Kubernetes Metrics Server chart 3.13.004 (#9368)
  • Update to v1.34.3 and Go v1.24.11 (#9388)
  • Bump traefik version (#9386)
  • Backports for 2025-12 (#9377)
  • Bump ingress-nginx and vsphere-csi (#9391)
  • Bump kine to v0.14.9 (#9406)
  • Bump klipper-helm to v0.9.12 (#9400)
  • Revert "Remove FlannelBackend from config" (#9421)

Charts Versions

ComponentVersion
rke2-cilium1.18.401
rke2-canalv3.31.2-build2025120500
rke2-calicov3.31.200
rke2-calico-crdv3.31.200
rke2-coredns1.45.003
rke2-ingress-nginx4.13.500
rke2-metrics-server3.13.004
rancher-vsphere-csi3.5.0-rancher200
rancher-vsphere-cpi1.12.100
harvester-cloud-provider0.2.1100
harvester-csi-driver0.1.2500
rke2-snapshot-controller4.0.003
rke2-snapshot-controller-crd4.0.003
rke2-snapshot-validation-webhook0.0.0

Release v1.34.2+rke2r1

This release updates Kubernetes to v1.34.2.

Important Note

If your server (control-plane) nodes were not started with the --token CLI flag or config file key, a randomized token was generated during initial cluster startup. This key is used both for joining new nodes to the cluster, and for encrypting cluster bootstrap data within the datastore. Ensure that you retain a copy of this token, as is required when restoring from backup.

You may retrieve the token value from any server already joined to the cluster:

cat /var/lib/rancher/rke2/server/token

Changes since v1.34.1+rke2r1:

  • Bump harvester-cloud-provider chart to v0.2.11 with app image tag v0.2.5 (#8957)
  • Update traefik to v3.5.1, use new hardened image (#8970)
  • Bump rke2-ingress-nginx to v1.13.3-hardened1 (#8998)
  • Container runtime endpoint description and Docker warning (#8985)
  • Add calico envoy-proxy and envoy-ratelimit images (#9022)
  • Move dualstack to larger docker runners to prevent eviction failures (#9030)
  • Charts: Bump Harvester CSI driver 0.1.25 (#9038)
      • Support CSI Snapshot
  • Bump k3s (#9043)
  • Update to cilium v1.18.2 (#9075)
  • October 2025 bumps for canal, flannel and multus (#9100)
  • Update to CoreDNS chart 1.44.300 and Kubernetes Metrics Server chart 3.13.002 (#9089)
  • Bump images for go1.24.9 rebuild (#9103)
  • Add new kubeapiserver argument for cis-1.11 benchmark (#9118)
  • Bump traefik and ingress-nginx (#9127)
  • Bump helm-controller/klipper-helm (#9135)
  • Tests: update e2e tests to use images from the rancher org (#9158)
  • Bump k3s and backport uninstall fix (#9174)
  • Bump traefik to v3.5.4 and ingress-nginx to v1.13.4 (#9187)
  • Bump runc to v1.3.3 (#9192)
  • Improve PR Trivy Scanning Reports (#9238)
  • More backports for 2025-11 (#9244)
    • Update to multus chart version v4.2.300 (#9252)
  • Bump k3s and helm-controller (#9263)
  • Update k8s and Go (#9273)
  • Fix race condition with Calico startup on Windows (#9279)
  • Release race condition (#9294)

Charts Versions

ComponentVersion
rke2-cilium1.18.300
rke2-canalv3.30.3-build2025101500
rke2-calicov3.30.401
rke2-calico-crdv3.30.401
rke2-coredns1.44.300
rke2-ingress-nginx4.13.400
rke2-metrics-server3.13.002
rancher-vsphere-csi3.5.0-rancher100
rancher-vsphere-cpi1.12.100
harvester-cloud-provider0.2.1100
harvester-csi-driver0.1.2500
rke2-snapshot-controller4.0.003
rke2-snapshot-controller-crd4.0.003
rke2-snapshot-validation-webhook0.0.0

Release v1.34.1+rke2r1

This release updates Kubernetes to v1.34.1.

Important Note

If your server (control-plane) nodes were not started with the --token CLI flag or config file key, a randomized token was generated during initial cluster startup. This key is used both for joining new nodes to the cluster, and for encrypting cluster bootstrap data within the datastore. Ensure that you retain a copy of this token, as is required when restoring from backup.

You may retrieve the token value from any server already joined to the cluster:

cat /var/lib/rancher/rke2/server/token

Changes since v1.33.4+rke2r1:

  • Bump aquasecurity/trivy-action from 0.32.0 to 0.33.0 (#8841)
  • Bump cni charts and coredns (#8843)
  • Update k8s to v1.34, go to v1.24.6 (#8860)
  • Bump ingress-nginx v1v1.30.14+rke2r4.12.6-hardened1 (#8868)
  • Bump CNI chart latest version (#8887)
  • Update metrics-server chart 3.13.001 (#8903)
  • Update CoreDNS chart 1.43.302 (#8907)
  • Update to v1.34.1 and Go v1.24.6 (#8919)
  • Remove cloud-config arg from kubelet (#8927)
  • Bump vsphere cpi chart (#8938)

Charts Versions

ComponentVersion
rke2-cilium1.18.103
rke2-canalv3.30.3-build2025090900
rke2-calicov3.30.300
rke2-calico-crdv3.30.300
rke2-coredns1.43.302
rke2-ingress-nginx4.12.600
rke2-metrics-server3.13.001
rancher-vsphere-csi3.5.0-rancher100
rancher-vsphere-cpi1.12.100
harvester-cloud-provider0.2.1000
harvester-csi-driver0.1.2400
rke2-snapshot-controller4.0.003
rke2-snapshot-controller-crd4.0.003
rke2-snapshot-validation-webhook0.0.0