Skip to content

Products

Featured Pages

Developer Tools

For partners

Latest Updates

  • announcementruntime

    SKE patchday October 2026 – Remove Docker from Flatcar

    Section titled “SKE patchday October 2026 – Remove Docker from Flatcar”

    With the upcoming October patch day, we are adjusting the Flatcar OS images provided in STACKIT Kubernetes Engine (SKE) by removing Docker.

    Docker has been deprecated and removed as the container runtime in SKE for more than two years. By removing it, we ensure the OS footprint remains small and remove unneeded dependencies that could potentially introduce security vulnerabilities.

    Key Dates:

    • October 14, 2026: A new preview Flatcar OS version (the latest stable release available in October) will be added to SKE. This version will not contain Docker.
    • November, 11, 2026: The Flatcar version without Docker will be promoted to the supported OS version. If you have auto updates enabled, your Kubernetes worker nodes will automatically update to this version.

    What you need to do

    Test your SKE workloads beforehand using the new preview Flatcar version once it becomes available on October 14, 2026. Testing is highly recommended to ensure your configurations function exactly as expected before the automatic upgrade takes place in November.

    Our Help Center is always at your disposal if you have any questions.

  • changedruntime

    Improved Kubernetes API server load balancing and strict RFC compliance

    Section titled “Improved Kubernetes API server load balancing and strict RFC compliance”

    We are updating our ingress mechanism to make use of improved Kubernetes API server load balancing in the STACKIT Kubernetes Engine (SKE). We will begin rolling out this update gradually across all clusters starting September 15, 2026. This update significantly benefits the overall stability of SKE and decreases the response times from the API servers under high load.

    To achieve this improved load balancing, the new ingress mechanism strictly enforces RFC compliance. This means that misconfigured clients—specifically those where the Server Name Indication (SNI) does not match the Host or :authority HTTP header—will be rejected with a 421 Misdirected Request error. Previously, these clients might have worked because the former L4 load balancers did not take HTTP headers into consideration.

    As we roll out this change gradually across our production environments, non-compliant clients will receive a 421 Misdirected Request error when attempting to access the API server. To ensure a smooth transition and minimize disruption, we are proactively monitoring our logs for these 421 Misdirected Request errors. If we detect that your cluster is affected during the rollout, our support team will:

    1. Temporarily apply a compatibility fix on our end to restore your traffic flow.

    2. Open a support ticket to notify you, providing your project ID and cluster details.

    3. Inform you of the temporary nature of this fix and provide a strict deadline to update your non-compliant clients before the compatibility mode is permanently removed.

    To learn how to make sure your clients stay compatible, refer to our how-to guide “Ensure RFC-compliant API requests to your SKE cluster”.

  • announcementsecurity

    STACKIT Secrets Manager AppRole authentication is now in Public Preview

    Section titled “STACKIT Secrets Manager AppRole authentication is now in Public Preview”

    We are excited to announce that AppRole authentication for the STACKIT Secrets Manager has reached Public Preview as of August 31, 2026. You can now use AppRole to authenticate applications and automated workloads.

    AppRole lets applications and automated workloads authenticate with a Role-ID and Secret-ID instead of a username and password, and exchange them for a Vault-compatible token—making it easier to manage credentials for automated access to your secrets.

    Public Preview scope

    • API: Full support for creating and managing AppRoles and Secret-IDs, and for authenticating with AppRole, on the stable v1 API. Explore our documentation to learn how to configure and use AppRoles.