Azure AKS

notes:
  • AKS Roadmap: https://aka.ms/aks/roadmap
  • AKS Blog: https://aka.ms/aks/blog
  • AKS Release Notes: https://aka.ms/aks/release-notes
  • AKS Community YouTube: https://www.youtube.com/@theakscommunity
  • AKS Public Community Channel: https://twitter.com/theakscommunity Updates about the service, including new features and new Azure regions: (AKS feed in Azure Updates)[https://azure.microsoft.com/updates/?product=kubernetes-service]
Release list
2025-10-12
2025-09-21
2025-08-29
2025-08-08
2025-07-20
2025-06-17
2025-05-19
6m+
2025-04-27
6m+
2025-04-06
6m+
2025-03-16
6m+
2025-02-20
6m+
2025-01-30
6m+
2025-01-06
6m+
2024-10-25
1y+
2024-10-06
1y+
2024-09-18
1y+
2024-08-27
1y+
2024-08-05
1y+
2024-07-16
1y+
2024-06-27
1y+
Release notes:

Release 2025-07-20

Monitor the release status by region at AKS-Release-Tracker. This release is titled v20250720.

Announcements

Release notes

  • Features

  • Preview Features

  • Bug Fixes

    • Fixed issue where AKS evicted pods that had already been manually relocated, causing upgrade failures. This fix adds a node consistency check to ensure the pod is still on the original node before retrying eviction.
  • Behavior Changes

    • The delete-machines API will only delete machines from the system nodepool if the system addon PDBs are respected.
    • AKS will now reject invalid OsSku enums during cluster creation, node pool creation, and node pool update. Previously AKS would default to Ubuntu. Unspecified OsSku with OsType Linux will still default to Ubuntu. For more information on supported OsSku options, see documentation for Azure CLI and the AKS API.
    • Application routing component Pods are now annotated with kubernetes.azure.com/set-kube-service-host-fqdn to automatically have the API server's domain name injected into the pod instead of the cluster IP, to enable communication to the API server. This is useful in cases where the cluster egress is via a layer 7 firewall.
    • Advanced Container Networking Services (ACNS) pods now run with priorityClassName: system-node-critical, preventing eviction under node resource pressure and improving cluster security posture.
    • Add node anti-affinity for FIPS-enabled nodes for retina-agent when pod-level metrics are enabled.
  • Component Updates

    • Windows node images
    • AKS Azure Linux v2 image has been updated to 202507.15.0.
    • AKS Azure Linux v3 image has been updated to 202507.15.0.
    • AKS Ubuntu 22.04 node image has been updated to 202507.15.0.
    • AKS Ubuntu 24.04 node image has been updated to 202507.15.0.
    • Application Insights addon image is updated to 1.0.0-beta.7 to expose container port 4000 for scraping Prometheus metrics.
    • Application routing operator is updated to v0.2.7 for all supported Kubernetes versions.
    • Azure Network Policy Manager (NPM) image version is updated to v1.6.29 to resolve iptables-legacy command issues and bump Ubuntu to 24.04 with CVE fixes.
    • Azure Disk CSI driver versions are upgraded to v1.31.11, v1.32.8, v1.33.2 on AKS versions 1.31, 1.32, 1.33 respectively.
    • Cloud Controller Manager has been upgraded to v1.33.1, v1.32.6, v1.31.7 and v1.30.13.
    • Retina Basic image is updated to v0.0.36 on Linux and Windows.
    • Retina Enterprise has been updated to v0.1.11 to resolve several CVEs.
    • Azure Monitor managed service for Prometheus addon is updated to the latest release 06-19-2025.
    • Microsoft Defender for Cloud security-publisher image updated to 1.0.243 to address CVE-2023-4039 and CVE-2024-13176.
    • Microsoft Defender for Cloud old-file-cleaner image updated to 1.0.243 to address CVE-2025-0913 and CVE-2025-4673.
    • Image Cleaner eraser image is updated to v1.4.0-4.
    • Bumped Azure Cloud Controller Manager to v1.33.1, v1.32.6, v1.31.7, and v1.30.13.
    • Tigera operator is updated from v.1.38.0 to v1.38.2 to support Calico v3.30.1.
    • Calico has been upgraded with the v3.30.2.
    • Vertical Pod Autoscaler (VPA) addon images are now built with Dalec starting from AKS version 1.27.
    • Cluster Autoscaler is upgraded to v1.33.0 with Dalec-built image.
    • Azure Policy Addon is upgraded to v1.13.0 with enhanced EUDB request routing.
    • secrets-store-csi-driver is upgraded to v1.5.1
    • Workload identity image is updated to v1.5.1 with CVE fixes.
    • Istio revision asm-1-26 is now available for the Istio-based service mesh add-on. To adopt the new revision, follow the canary upgrade guidance. Other updates:
    • Istio-based service mesh add-on now supports the following annotations: service.beta.kubernetes.io/azure-allowed-ip-ranges, service.beta.kubernetes.io/azure-load-balancer-disable-tcp-reset, service.beta.kubernetes.io/azure-pip-ip-tags, service.beta.kubernetes.io/azure-load-balancer-tcp-idle-timeout for Istio ingress gateways.

Copyright © 2023 - All right reserved by Yadoc SAS