The whole kubernetes node just learned to run as a regular user. v1.37, announced september 4,…
the whole kubernetes node just learned to run as a regular user. v1.37, announced september 4, promotes rootless kubelet to beta so the kubelet, cri and oci runtimes, cni and kube-proxy all run without root.
container breakout gets a smaller blast radius.
Context
The Kubernetes blog post of September 4, 2026 by Akihiro Suda says the KubeletInUserNamespace feature gate (KEP-2033, rootless mode) is promoted to beta in v1.37, so the kubelet, CRI and OCI runtimes, CNI plugins and kube-proxy can run as a non-root user on the host using a Linux user namespace. The gate is on by default at beta, but enabling it does not put the kubelet into a user namespace automatically and nothing changes for existing rootful clusters. Nodes report runningInUserNamespace, and node conformance end-to-end tests run on a rootless cluster in CI. The user namespace has to be created outside Kubernetes, for example with Rootless Docker, and the docs list prerequisites such as cgroup v2 and systemd with a user session.
The beta gate being on does not activate a user namespace, and setup, cgroup, systemd and driver limits remain, since the fake root inside the namespace may break compatibility with specific CNI and CSI drivers. The blog says user namespaces do not mitigate kernel vulnerabilities and should be combined with hardening such as seccomp, so no kernel vulnerability mitigation is claimed. The smaller blast radius is the project's stated rationale and not a measured result. The v1.37 release itself is dated August 26 in an index snippet, and September 4 is the blog date. Pod user namespaces, which keep node components as root, are a different feature. The whole kubernetes node just learned to run as a regular user is the author's framing.
Watch next
- The path to GA.
Sources
- Kubernetes blog: v1.37 rootless beta (September 4, 2026)kubernetes.io
- Kubernetes docs: kubelet in a user namespacekubernetes.io
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 22 September 2026 at 13:58 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →