AKS on Azure Stack HCI and Windows Server 2023-10-30 Update
We are pleased to announce that with this release we update the AKS HCI management cluster to Kubernetes version 1.26.6. This update enables us to set the basis for supporting futures versions of Kubernetes for your workload clusters. See the complete set of versions for each module in the GitHub release page.
Here is a description of what is included in this release:
Security Updates
- Kubernetes CVE-2023-2728: Bypassing enforce mountable secrets policy imposed by the ServiceAccount admission plugin.
A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service account's secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with ephemeral containers.
- Gogoprotobuf CVE-2021-3121: An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue.
New Features
- See a list of Kubernetes new features.
Bug Fixes
- Azure Arc onboarding prechecks were improved to handle transitory restricted network bandwidth. When setting up AKS hybrid, the Azure Arc agents are on-boarded so that the deployment is projected to the user subscription in Azure. During this process there are several pre-checks run by the Arc agents, if there are network issues these tests may fail. This fix makes the pre-checks more resilient to network problems.
- See a list of Kubernetes bug fixes.
As always, you can try AKS on Azure Stack HCI or Windows Server any time even if you do not have the hardware handy using our eval guide to set up AKS on a Windows Server Azure VM.
Once you have downloaded and installed the AKS on Azure Stack HCI or Windows Server Update – you can report any issues you encounter, follow our plans, and check out recently released updates through the AKS hybrid roadmap in GitHub.
We look forward to hearing from you all!
Cheers,
AKS Hybrid Team
Published on:
Learn moreRelated posts
Find and fix app issues - Azure Copilot Observability Agent
Cut through alert noise and move from detection to root cause using the Azure Copilot Observability Agent. It autonomously investigates incide...
Azure Functions MCP Extension: What’s New at Build 2026
A roundup of what shipped in the Azure Functions MCP extension since preview: resource and prompt triggers, MCP Apps, built-in MCP authenticat...
Secure Boot certificate updates for Linux on Azure virtual machines
Microsoft has published new guidance for managing Secure Boot certificate updates for Linux on Azure virtual machines, including Trusted Launc...
Soluzione Earns Microsoft Solutions Partner Designation for Digital & App Innovation (Azure)
Soluzione is pleased to announce that it has earned the Microsoft Solutions Partner designation for Digital & App Innovation (Azure). This...
Azure SDK Release (May 2026)
Azure SDK releases every month. In this post, you'll find this month's highlights and release notes. The post Azure SDK Release (May 2026) app...
How to Use Deep Agents with Azure Cosmos DB – Plan, act, and verify against operational data
Deep Agents is an agent harness built on LangGraph, for agents that need to work through a task over many steps instead of a single LLM call. ...
Retirement of Azure DevOps issuer in Workload identity federation service connections
We are announcing the deprecation of the Azure DevOps issuer in workload identity federation (WIF) service connections, with planned retiremen...