The Cloud Native Computing Foundation released Kubernetes 1.37, codenamed Garhwal, with 67 enhancements focused on platform stability, security, and AI/ML workloads. The release promotes the Metrics API, resilient watch-cache initialization, and pod certificates to stable availability, while moving rootless Kubelet operation to beta, reducing the privilege requirements of node-level Kubernetes components.
Kubernetes 1.37 also introduces alpha support for pod checkpoint and restore, an effort supported by the Kubernetes Checkpoint/Restore Working Group, alongside workload-aware scheduler preemption and StatefulSet Recreate rollouts. The release includes 27 alpha features, 23 beta graduations, 16 stable graduations, and one deprecation or removal.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Kubernetes 1.37 introduces alpha support for workload-aware scheduler preemption during in-place pod resizing, pod-level checkpoint and restore, and a StatefulSet Recreate rollout strategy. The checkpoint feature allows kubelet to save and restore pods, including running-container memory and process trees for debugging or security analysis.
The Cloud Native Computing Foundation announced Kubernetes 1.37, codenamed “Garhwal,” emphasizing stability, security, and AI/ML workload optimization. The release includes 67 enhancements, with the Metrics API, resilient watchcache initialization, and pod certificates reaching general availability or stable status, while rootless Kubelet advances to beta.
Kubernetes announced the formation of a Checkpoint/Restore Working Group.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.