Skip to content

Products

Featured Pages

Developer Tools

For partners

Latest Updates

  • changedruntime

    Improved Kubernetes API server load balancing and strict RFC compliance

    Section titled “Improved Kubernetes API server load balancing and strict RFC compliance”

    We are updating our ingress mechanism to make use of improved Kubernetes API server load balancing in the STACKIT Kubernetes Engine (SKE). We will begin rolling out this update gradually across all clusters starting September 15, 2026. This update significantly benefits the overall stability of SKE and decreases the response times from the API servers under high load.

    To achieve this improved load balancing, the new ingress mechanism strictly enforces RFC compliance. This means that misconfigured clients—specifically those where the Server Name Indication (SNI) does not match the Host or :authority HTTP header—will be rejected with a 421 Misdirected Request error. Previously, these clients might have worked because the former L4 load balancers did not take HTTP headers into consideration.

    As we roll out this change gradually across our production environments, non-compliant clients will receive a 421 Misdirected Request error when attempting to access the API server. To ensure a smooth transition and minimize disruption, we are proactively monitoring our logs for these 421 Misdirected Request errors. If we detect that your cluster is affected during the rollout, our support team will:

    1. Temporarily apply a compatibility fix on our end to restore your traffic flow.

    2. Open a support ticket to notify you, providing your project ID and cluster details.

    3. Inform you of the temporary nature of this fix and provide a strict deadline to update your non-compliant clients before the compatibility mode is permanently removed.

    To learn how to make sure your clients stay compatible, refer to our how-to guide “Ensure RFC-compliant API requests to your SKE cluster”.

  • announcementsecurity

    STACKIT Secrets Manager AppRole authentication is now in Public Preview

    Section titled “STACKIT Secrets Manager AppRole authentication is now in Public Preview”

    We are excited to announce that AppRole authentication for the STACKIT Secrets Manager has reached Public Preview as of August 31, 2026. You can now use AppRole to authenticate applications and automated workloads.

    AppRole lets applications and automated workloads authenticate with a Role-ID and Secret-ID instead of a username and password, and exchange them for a Vault-compatible token—making it easier to manage credentials for automated access to your secrets.

    Public Preview scope

    • API: Full support for creating and managing AppRoles and Secret-IDs, and for authenticating with AppRole, on the stable v1 API. Explore our documentation to learn how to configure and use AppRoles.
  • deprecatedruntime

    Kubernetes version 1.34 is getting deprecated in SKE

    Section titled “Kubernetes version 1.34 is getting deprecated in SKE”

    Kubernetes minor version 1.34 reaches the end of its official maintenance support on 27 October 2026.

    This version will be removed from SKE on 14 October 2026 at 8 AM UTC. Starting with the date of removal, all clusters that are still using 1.34 will be automatically upgraded to 1.35 during the cluster’s maintenance time window.

    In order to keep your cluster up-to-date, we synchronize the version lifecycle with the upstream Kubernetes lifecycle. Therefore, we expire Kubernetes minor versions on the patchday prior the End-of-Life (EOL) dates with Kubernetes.

    Documentation for applying minor or patch updates is available in the official STACKIT Kubernetes Engine documentation. Additional guidance on the release process can be found in the STACKIT Kubernetes Engine Version Updates.

    For more detailed information, refer to:

    Our Help Center is always at your disposal if you have any questions.