# PMK Release 5.14 Release Notes

## Release Summary

The Platform9 Managed Kubernetes (PMK) version 5.14 release is now generally available with active support for Kubernetes **v1.33**

## PMK 5.14.0 Release Highlights (Released 2025-08-25)

#### New Features

<mark style="color:green;">`Added`</mark> Added active support for Kubernetes **1.33**

#### Feature Updates

<mark style="color:green;">`Added`</mark> Improvements to **Cilium CNI**

<mark style="color:green;">`Added`</mark> Updated libraries/ module dependencies to fix CVEs

#### Deprecations, Feature Removal and EOL information

{% hint style="danger" %}
**Kubernetes 1.30 and lower EoL**

* All clusters must be upgraded to at **least Kubernetes v1.31** before upgrading from **PMK 5.13.x to PMK 5.14**
* **Kubernetes v1.30** and lower versions are marked as *End of Life* on **PMK 5.14**
  {% endhint %}

{% hint style="warning" %}
**Kubernetes 1.31 Deprecated**

* **Kubernetes v1.31** is marked as deprecated.

* New clusters should be created on **Kubernetes v1.32** or above. However, you can continue to create new clusters on Kubernetes v1.31 or above.
  {% endhint %}

* There are no Operating Systems deprecations in PMK **5.14** release. Check the PMK support matrix here: [Managed Kubernetes Support Matrix](https://docs.platform9.com/managed-kubernetes/5.14/support/support/managed-kubernetes-support-matrix)

#### Bug Fixes

<mark style="color:orange;">`Fixed`</mark> Removed the `-cloud-provider` flag for API server to support k8s 1.33 for AWS clusters

#### Known Issues

<mark style="color:blue;">`Known Issue`</mark> All existing and new AWS clusters in PMK must be configured with an `is_update`flag and restricted security group rules. Without this cluster updates (such as AMI updated) and upgrades may fail. Please reach out to Platform9 support for this configuration.

<mark style="color:blue;">`Known Issue`</mark> During PMK cluster upgrades, `pf9-kube` package uninstallation may be incomplete if workload containers are not stopped and removed. Please reach out to Platform9 support if this occurs.

<mark style="color:blue;">`Known Issue`</mark> On Rocky Linux 9 (tested on 9.2 and 9.4), Platform9's `pf9-kube` package installs `iptables-services` as a dependency. With recent updates to the upstream repositories, installation will fail due to a missing dependency on `iptables-legacy-*` packages.

<mark style="color:blue;">`Known Issue`</mark> (On Rocky Linux 9) Users will need to install the legacy packages by running `dnf install iptables` or `dnf install iptables-utils` on workload cluster nodes. Since this is a recent upstream change, a solution will be provided in upcoming releases by packaging the required packages along with `pf9-kube` package.

<mark style="color:blue;">`Known Issue`</mark> AWS clusters using flannel CNI need to be updated to use port 2379 instead of 4001 from1.22 version onwards. Workaround is to go to the "Edit cluster" option on the UI and clicked on "Update cluster" without making any changes. This adds the 2379 ingress rule to the master ELB.

<mark style="color:blue;">`Known Issue`</mark> When a detach operation is performed on a master node in a multi master cluster, it takes approximately 30 minutes to complete all the detach operations and perform cleanup on the node. Therefore, if you want to reattach this node to any other cluster, you need to wait for the nodelet to stop all the phases and perform cleanup before attempting to reattach the node.

<mark style="color:blue;">`Known Issue`</mark> In some scenarios, after a node is removed from the qbert clusters, nodelet fails to cleanup the data. Workaround is to check and remove the `/var/opt/pf9/kube`directory if present, even after the node is deauthorized.

<mark style="color:blue;">`Known Issue`</mark> Cluster upgrade attempt is blocked on UI post a cluster upgrade failure due to nodes being in a converging/not converged state.

<mark style="color:blue;">`Known Issue`</mark> Kubelet authorization mode is marked set to AlwaysAllow instead of Webhook.

<mark style="color:blue;">`Known Issue`</mark> PMK Cloud provider created directly in Sunpike cannot be used to create qbert clusters. Qbert cloud providers will work to create both qbert and sunpike clusters. But cloud providers created directly in sunpike CANNOT be used to create qbert clusters. Please use the appropriate one based on your needs.

### Package Updates

#### PMK 5.14.0 Latest Kubernetes Components List

<table data-header-hidden><thead><tr><th></th><th width="187"></th><th></th><th></th></tr></thead><tbody><tr><td><strong>Component</strong></td><td><strong>Kubernetes 1.33</strong></td><td><strong>Kubernetes 1.32</strong></td><td><strong>Kubernetes 1.31</strong></td></tr><tr><td>KUBERNETES BUILD VERSION</td><td>1.33.3-pmk.<strong>46</strong> <mark style="color:green;"><strong><code>updated</code></strong></mark></td><td>1.32.3-pmk.<strong>55</strong> <mark style="color:green;"><strong><code>updated</code></strong></mark></td><td>1.31.9-pmk.<strong>136</strong> <mark style="color:green;"><strong><code>updated</code></strong></mark></td></tr><tr><td>CONTAINERD</td><td>1.7.27</td><td>1.7.27</td><td>1.7.27</td></tr><tr><td>RUNC</td><td>1.1.12</td><td>1.1.12</td><td>1.1.12</td></tr><tr><td>CORE-DNS</td><td>1.11.1</td><td>1.11.1</td><td>1.11.1</td></tr><tr><td>METRICS SERVER</td><td>0.6.4</td><td>0.6.4</td><td>0.6.4</td></tr><tr><td>METAL LB</td><td>0.14.9</td><td>0.14.9</td><td>0.14.9</td></tr><tr><td>KUBERNETES DASHBOARD</td><td>2.7.0</td><td>2.7.0</td><td>2.7.0</td></tr><tr><td>CLUSTER AUTO-SCALER AWS</td><td>1.28.0</td><td>1.28.0</td><td>1.28.0</td></tr><tr><td>FLANNEL CNI</td><td>0.24.2</td><td>0.24.2</td><td>0.24.2</td></tr><tr><td>CALICO CNI</td><td>3.27.5</td><td>3.27.5</td><td>3.27.5</td></tr><tr><td><strong>CILIUM CNI </strong><mark style="color:green;"><strong><code>new</code></strong></mark></td><td>1.17.2</td><td>1.17.2</td><td>1.17.2</td></tr><tr><td><strong>CILIUM CLI</strong> <mark style="color:green;"><strong><code>new</code></strong></mark></td><td>0.18.3</td><td>0.18.3</td><td>0.18.3</td></tr><tr><td>ETCD</td><td>3.5.12</td><td>3.5.12</td><td>3.5.12</td></tr><tr><td>CNI PLUGINS</td><td>1.4.0</td><td>1.4.0</td><td>1.4.0</td></tr><tr><td>KUBEVIRT</td><td>1.0.0</td><td>1.0.0</td><td>1.0.0</td></tr><tr><td>KUBEVIRT CDI</td><td>1.57.0</td><td>1.57.0</td><td>1.57.0</td></tr><tr><td>ADVANCED NETWORKING OPERATOR (LUIGI)</td><td>0.5.8</td><td>0.5.8</td><td>0.5.8</td></tr><tr><td>MONITORING - PROMETHEUS OPERATOR</td><td>0.68.2</td><td>0.68.2</td><td>0.68.2</td></tr><tr><td>PROFILE AGENT</td><td>2.0.2</td><td>2.0.2</td><td>2.0.2</td></tr><tr><td>METAL3</td><td>1.1.1</td><td>1.1.1</td><td>1.1.1</td></tr></tbody></table>

## PMK 5.14.1 Release Highlights (Released 2025-10-16)

#### Feature Updates

<mark style="color:green;">`Added`</mark> Catapult monitoring supports namespace-scoped filtering. Configure monitored namespaces using the `ksm-namespace-allowlist` configmap to reduce alert noise.

<mark style="color:green;">`Added`</mark> Management plane monitoring now exports certificate and token Time-To-Live (TTL) metrics, enabling proactive alerting on certificate expiration.

<mark style="color:green;">`Added`</mark> Increased default volume size for the Terraform script for AWS instance.

<mark style="color:green;">`Added`</mark> Increased memory and CPU limits and requests for the `socat` container under `rabbitmq` pod.

#### Bug Fixes

<mark style="color:orange;">`Fixed`</mark> Fixed cert-manager installation conflicts during cluster upgrades. The luigi-addon operator now detects existing cert-manager deployments and skips installation to prevent errors.

<mark style="color:orange;">`Fixed`</mark> The master node attachment and secondary volume mounting failures on AWS Nitro-based instances by correcting Terraform boot.sh script for NVMe device compatibility and increasing default volumes to 150GB and 180GB.

<mark style="color:orange;">`Fixed`</mark> Increased memory limits and requests for PMK components to prevent out-of-memory errors and container evictions.

<mark style="color:orange;">`Fixed`</mark> Resolved Out of Memory (OOM) errors causing Sunpike pod restarts by increasing memory limits for sunpike-apiserver and sunpike-kine to 400Mi, and sunpike-conductor limit to 1000Mi with request at 500Mi.

### Package Updates

#### PMK 5.14.1 Latest Kubernetes Components List

| **Component**                                                   | **Kubernetes 1.33**                                               | **Kubernetes 1.32**                                               | **Kubernetes 1.31**                                                |
| --------------------------------------------------------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------- | ------------------------------------------------------------------ |
| KUBERNETES BUILD VERSION                                        | 1.33.3-pmk.**49** <mark style="color:green;">**`updated`**</mark> | 1.32.3-pmk.**63** <mark style="color:green;">**`updated`**</mark> | 1.31.9-pmk.**144** <mark style="color:green;">**`updated`**</mark> |
| CONTAINERD                                                      | 1.7.27                                                            | 1.7.27                                                            | 1.7.27                                                             |
| RUNC                                                            | 1.1.12                                                            | 1.1.12                                                            | 1.1.12                                                             |
| CORE-DNS                                                        | 1.11.1                                                            | 1.11.1                                                            | 1.11.1                                                             |
| METRICS SERVER                                                  | 0.6.4                                                             | 0.6.4                                                             | 0.6.4                                                              |
| METAL LB                                                        | 0.14.9                                                            | 0.14.9                                                            | 0.14.9                                                             |
| KUBERNETES DASHBOARD                                            | 2.7.0                                                             | 2.7.0                                                             | 2.7.0                                                              |
| CLUSTER AUTO-SCALER AWS                                         | 1.28.0                                                            | 1.28.0                                                            | 1.28.0                                                             |
| FLANNEL CNI                                                     | 0.24.2                                                            | 0.24.2                                                            | 0.24.2                                                             |
| CALICO CNI                                                      | 3.27.5                                                            | 3.27.5                                                            | 3.27.5                                                             |
| **CILIUM CNI&#x20;**<mark style="color:green;">**`new`**</mark> | 1.17.2                                                            | 1.17.2                                                            | 1.17.2                                                             |
| **CILIUM CLI** <mark style="color:green;">**`new`**</mark>      | 0.18.3                                                            | 0.18.3                                                            | 0.18.3                                                             |
| ETCD                                                            | 3.5.12                                                            | 3.5.12                                                            | 3.5.12                                                             |
| CNI PLUGINS                                                     | 1.4.0                                                             | 1.4.0                                                             | 1.4.0                                                              |
| KUBEVIRT                                                        | 1.0.0                                                             | 1.0.0                                                             | 1.0.0                                                              |
| KUBEVIRT CDI                                                    | 1.57.0                                                            | 1.57.0                                                            | 1.57.0                                                             |
| ADVANCED NETWORKING OPERATOR (LUIGI)                            | 0.5.8                                                             | 0.5.8                                                             | 0.5.8                                                              |
| MONITORING - PROMETHEUS OPERATOR                                | 0.68.2                                                            | 0.68.2                                                            | 0.68.2                                                             |
| PROFILE AGENT                                                   | 2.0.2                                                             | 2.0.2                                                             | 2.0.2                                                              |
| METAL3                                                          | 1.1.1                                                             | 1.1.1                                                             | 1.1.1                                                              |
