SKE security enhancement: OpenSSH removal
Section titled “SKE security enhancement: OpenSSH removal”To align with cloud-native security best practices and further harden your clusters, STACKIT Kubernetes Engine is updating its node configuration.
Currently, nodes provisioned by STACKIT run the OpenSSH daemon, even though there is no supported method to use it. To reduce the OS-level attack surface and enforce immutable infrastructure practices, the OpenSSH daemon will be permanently disabled on all nodes during scheduled cluster maintenance starting November 5, 2026.
If you have a specific requirement to keep the OpenSSH daemon active on your nodes, please open a service request via the Help Center. Please note that this is only a temporary exception, and the daemon will eventually be disabled across all clusters.
Otherwise, no action is required, and your workloads will continue running without interruption.