Skip to content
CAI
Software that uses CAICheck a score

k3s-io/k3s

66.3

Adequate · 6 August 2026

29.5k

lines of production code

Go

primary language

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

K3s is a lightweight, fully-featured Kubernetes distribution designed for edge, IoT, and resource-constrained environments. It provides a unified binary that manages the entire control plane and node agent lifecycle, including containerd, CNI, and etcd. The system supports advanced operational capabilities such as rootless execution, dual-stack networking, and automated certificate and secrets encryption management. It also includes robust tooling for cluster diagnostics, snapshotting, and integration with external networks like Tailscale.

How it got here

2019 — CLI and agent refactoring

46 changes.

This period focused on restructuring the K3s CLI into a multi-call binary and consolidating agent startup logic into platform-specific modules. The work involved removing legacy agent components, introducing rootless execution support, and updating dependencies to Kubernetes v1.36.3.

2020–2022 — Architecture modernization and test expansion

47 changes.

This period focused on modernizing the codebase by introducing pluggable interfaces for managed clusters, etcd, and node configuration, while centralizing control-plane dependencies and proxy logic. Significant effort was also dedicated to expanding test coverage, adding integration and end-to-end tests for features like secrets encryption, certificate rotation, and dual-stack networking.

2023–2025 — Test coverage expansion and infrastructure hardening

52 changes.

This period focused on significantly expanding test coverage across Docker, E2E, and integration environments, while introducing new features for token management, VPN integration, and certificate monitoring. The codebase also saw architectural improvements, including centralized metrics, HTTPS handling, and structured logging, alongside a shift to Go-based test suites.

2026 — etcd store abstraction and scale testing

6 changes.

This period focused on introducing local and remote etcd store abstractions to improve resilience during bootstrap and node restarts. The team also expanded test coverage by adding integration tests for the Nix snapshotter, large-scale cluster stability, and SELinux configuration across multiple Linux distributions.

Features

Add Linux cgroup validation and Windows stub for cgroup detection

The cgroups package now includes a new Linux implementation (cgroups\_linux.go) that validates cgroup availability for both cgroup v1 and v2, checking for required controllers like cpu, memory, and cpuset, and detects the cgroup mode to determine kubelet and runtime roots. A Windows stub (cgroups\_windows.go) is also added, providing empty implementations for Validate and CheckCgroups to support Windows builds. This change introduces new logic for cgroup validation and detection on Linux while providing a no-op implementation for Windows.

pkg/cgroups · high confidence

Add RPM packaging for k3s

The package/rpm directory now contains the necessary files to build and install k3s via RPM. This includes a new install.sh script that handles the installation of the k3s binary, systemd service files, and configuration, along with a k3s.spec file that defines the RPM package structure, dependencies, and post-installation steps to enable the k3s services. Additionally, a repo-setup.sh script is provided to configure the Rancher YUM repository for package management.

package/rpm · high confidence

Add Tailscale VPN integration with control server and extra arguments support

Users can now configure Tailscale as the VPN provider, including setting a custom control server URL and passing extra CLI flags to the Tailscale binary. The system will detect if Tailscale is already running and skip redundant startup commands, while also providing a generic interface for retrieving VPN status and advertised routes.

pkg/vpn · high confidence

Add basic authentication support via password file or header

Users can now authenticate using HTTP Basic Authentication by providing a CSV file of usernames and passwords, or by sending a Basic Auth header. The new \pkg/authenticator\ module wires together basic auth, client certificate authentication, and password file-based authentication, allowing the server to validate credentials from multiple sources simultaneously.

pkg/authenticator/basicauth · high confidence

Add certificate expiration monitoring and warning events

The certmonitor package now includes a new controller that periodically checks the expiration status of node and CA certificates. It registers a Prometheus metric to track remaining certificate lifetime and emits Kubernetes events: a warning event if certificates are expiring within the configured warning period, and a one-time OK event on startup if all certificates are healthy. This provides users with proactive alerts about certificate expiration and automatic rotation triggers.

pkg/certmonitor · high confidence

Add certificate file mapping for all K3s services

A new utility in pkg/util/services now maps each internal service (such as api-server, controller-manager, scheduler, and supervisor) to its corresponding certificate and key file paths. This provides a centralized, reliable way to identify which certificate files belong to which component, supporting operations like certificate rotation and expiry checking. Unit tests verify the correct file paths for server and agent services.

pkg/util/services · high confidence

Add certificate inspection and rotation commands

Users can now run 'k3s certificate check' to inspect the status of all certificates, with output in text, table, JSON, or YAML formats, and 'k3s certificate rotate-ca' to update CA certificates in the datastore. The check command reports expiration dates, remaining time, and warnings for certificates nearing expiry.

pkg/cli/cert · high confidence

Add cri-dockerd as a container runtime backend for the --docker flag

The agent now supports cri-dockerd as a container runtime backend when the --docker flag is used. This adds platform-specific configuration (Linux and Windows stubs), a main runner that launches the cri-dockerd process with dynamic arguments (e.g., CNI dirs, pause image, dual-stack support), and a build-tag-gated no-op for builds where cri-dockerd is disabled. Users can now run K3s with Docker via the cri-dockerd shim, with logging and configuration options exposed via the agent config and environment variables.

pkg/agent/cridockerd · high confidence

Add diagnostics and certificate management utilities

Added new scripts in contrib/util to support cluster diagnostics and certificate lifecycle management. The diagnostics.sh script collects system, application, and Kubernetes logs, encrypts them with AES-256-CBC, and uploads them to a Google Cloud Storage bucket for secure analysis. Additionally, generate-custom-ca-certs.sh and rotate-default-ca-certs.sh provide tools for bootstrapping and rotating Certificate Authority certificates, while fetch-diags.sh handles the secure retrieval and decryption of uploaded diagnostic archives.

contrib/util · high confidence

Add etcd snapshot CLI commands for save, delete, and list operations

Users can now manage etcd snapshots directly from the command line. The new \etcd-snapshot\ subcommands allow users to save new snapshots, delete existing ones, and list available snapshots. The implementation supports both local storage and S3-compatible backends, with configurable timeouts, compression, and retention policies. The CLI communicates with the server's \/db/snapshot\ endpoint, handling authentication via token and providing clear error messages when operations fail or when snapshots are not found.

pkg/cli/etcdsnapshot · high confidence

Add etcd snapshot metrics

A new Go file pkg/util/metrics/metrics.go is introduced, defining a helper function ObserveWithStatus that records a Prometheus histogram observation with a 'success' or 'error' status label based on an error argument. This enables tracking etcd snapshot durations and outcomes via Prometheus metrics.

pkg/util/metrics · medium confidence

Add file locking utility for Unix and non-Unix platforms

The \pkg/flock\ package has been added, providing file locking capabilities. For Unix-based systems (Linux, macOS, FreeBSD, OpenBSD, NetBSD, and DragonFly), the \flock\_unix.go\ file implements \Acquire\, \AcquireShared\, and \Release\ functions using \golang.org/x/sys/unix\. For non-Unix systems, \flock\_other.go\ provides stub implementations that return no-op results. Additionally, \flock\_unix\_test.go\ includes unit tests for the Unix-specific locking behavior.

pkg/flock · high confidence

Add k3s token CLI commands

The k3s CLI now includes a new 'token' subcommand with support for creating, deleting, generating, listing, and rotating bootstrap tokens. This allows users to manage authentication tokens directly via the command line, including rotating the server token and generating new bootstrap tokens for node registration.

pkg/cli/token · high confidence

Add k3s-specific ctr CLI wrapper

A new \pkg/ctr\ package was added to provide a \ctr\ command-line interface that automatically configures the containerd socket path to \/run/k3s/containerd/containerd.sock\ and sets the default namespace to \k8s.io\. This allows users to interact with the k3s-managed containerd instance using the standard \ctr\ tooling without manual configuration.

pkg/ctr · high confidence

Add password file-based user authentication

The \pkg/authenticator/passwordfile\ package now provides a \PasswordAuthenticator\ that reads user credentials from a CSV file. The authenticator parses each line for password, username, and optional groups, storing the password as a hash for secure verification. This enables users to authenticate against a local password file, with the system logging a warning if duplicate usernames are found.

pkg/authenticator/passwordfile · high confidence

Add project governance, contributor guidelines, and community documentation

The repository now includes formal project governance and community structure documentation. A new GOVERNANCE.md file defines the project's values, maintainer roles, and voting procedures. A comprehensive CONTRIBUTING.md guide outlines the development workflow, code conventions, and AI usage policies. Additionally, a MAINTAINERS.md file lists the current project maintainers, and an ADOPTERS.md file catalogs organizations using K3s. These additions provide clear guidelines for community participation and project management.

(repo-wide) · high confidence

Add rootless port mapping controller

A new controller in the rootlessports package now manages port forwarding for services in rootless mode. On Linux, it registers a handler that monitors Kubernetes services and configures the rootlesskit port manager to bind host ports to child namespace ports for TCP and UDP protocols. On Windows, the controller is a stub that panics, indicating that rootless port mapping is not supported on that platform.

pkg/rootlessports · high confidence

Add scrypt-based password hashing implementation

The package pkg/authenticator/hash now provides a new scrypt-based hashing implementation. This includes a Hasher interface, an SCrypt struct with configurable parameters (N, R, P, KeyLen, SaltLen), and methods to create and verify hashes. A fuzz test has been added to verify the robustness of the VerifyHash function against malformed or invalid inputs.

pkg/authenticator/hash · high confidence

Add shell completion support for Bash and Zsh

Users can now generate shell completion scripts for Bash and Zsh using the new \k3s completion\ command. Running the command with the \-i\ flag will automatically append the necessary completion configuration to the user's \.bashrc\ or \.zshrc\ files, enabling tab-completion for k3s commands in those shells.

pkg/cli/completion · high confidence

Add signal handling utility for graceful shutdown

A new \pkg/signals\ package has been introduced to manage process signals for graceful shutdown. It registers handlers for SIGTERM and SIGINT (or OS-specific equivalents like \os.Interrupt\ on Windows), returning a context that is cancelled when a shutdown signal is received. If a second signal is received, the application terminates immediately. This provides a standardized way for the application to handle shutdown requests.

pkg/signals · high confidence

Add structured logging via logr/logrus bridge

A new logger utility has been added to the codebase, providing a bridge between the logr and logrus libraries. This introduces a LogrusSink implementation that maps logr verbosity levels to logrus log levels and supports structured logging with key-value pairs. The change also includes a helper function to inject a logger into the Go context, enabling consistent logging across the application.

pkg/util/logger · high confidence

Add support for k3s token command

The k3s CLI now includes a new 'token' subcommand, implemented in the pkg/kubeadm package. This adds the ability to manage bootstrap tokens for node authentication and cluster joining, mirroring functionality from the upstream kubeadm tooling. The implementation includes new types for BootstrapToken and BootstrapTokenString, along with utility functions to convert between token objects and Kubernetes Secrets, allowing users to generate, inspect, and manage bootstrap tokens directly via the k3s CLI.

pkg/kubeadm · high confidence

Added crictl CLI integration

Users can now access the crictl command-line tool through the K3s CLI. This change introduces a new 'crictl' subcommand that wraps the external sigs.k8s.io/cri-tools/crictl package, allowing users to interact with container runtimes directly from the K3s interface.

pkg/cli/crictl · high confidence

Added data directory verification for file integrity

A new \dataverify\ package has been introduced to validate the integrity of a data directory. It provides functions to verify SHA-256 checksums against a \.sha256sums\ file and validates symbolic links against a \.links\ file, logging errors for any mismatches.

pkg/dataverify · high confidence

Added gotests templates for automated Go test generation

The contrib/gotests\_templates directory now includes a new set of Go template files (call, function, header, inline, inputs, message, and results) that define the structure for automatically generating unit tests for Go functions and methods. These templates provide a scaffold for test cases, including setup/teardown hooks, argument struct generation, and assertion logic, allowing users to generate test files with pre-filled test cases.

_contrib/gotests\templates · high confidence

Agent now loads required kernel modules and configures sysctls for network connectivity

The agent now automatically loads essential kernel modules (such as nf\_conntrack, br\_netfilter, and iptable\_nat) and configures corresponding sysctls (including net/ipv4/conf/all/forwarding and bridge-nf-call-iptables) to ensure proper network functionality. This setup is conditional: IPv6 modules and sysctls are only applied when IPv6 is enabled, and bridge filter sysctls are only set when the bridge filter flag is true, allowing administrators to manage these settings manually if needed. A Windows-specific stub is also provided.

pkg/agent/syssetup · high confidence

Automated airgap image list generation and volume test

The airgap workflow now uses a new script (generate-list.sh) to automatically extract the current set of required container images from the k3s binary, producing an updated image-list.txt. Additionally, a volume-test.yaml is added to verify local-path-provisioner functionality in airgap environments.

scripts/airgap · high confidence

Automated staging dependency updates via new Updatecli scripts

Three new shell scripts have been added to the updatecli/scripts directory to automate the process of bumping Kubernetes staging dependencies. The 'bump-staging-deps.sh' script updates go.mod entries to the latest available -k3sN tags, 'check-staging-tags-ready.sh' validates that required tags exist before proceeding, and 'run-go-mod-update.sh' executes the Go module updates. These scripts enable the Updatecli automation to keep the project's internal Kubernetes staging dependencies in sync with upstream releases.

updatecli/scripts · high confidence

Bootstrap data serialization and deserialization

The bootstrap package now provides functions to serialize control runtime bootstrap data to and from disk as JSON. Specifically, \ReadFromDisk\ reads certificate and key files from disk into a JSON structure, while \WriteToDiskFromStorage\ writes the contents of a reader to the paths derived from the bootstrap configuration, including file permissions and timestamps. A helper function \ObjToMap\ is also added to convert objects to a map representation. Tests are added to verify the \ObjToMap\ function handles valid and invalid inputs correctly.

pkg/bootstrap · high confidence

CLI commands for secrets encryption management

The \k3s secrets-encrypt\ CLI commands (enable, disable, status, prepare, rotate) are now implemented in \pkg/cli/secretsencrypt/secrets\_encrypt.go\. This change introduces the command-line interface for managing secrets encryption, allowing users to enable or disable encryption, check the current status, and perform rotation or preparation steps via the CLI.

pkg/cli/secretsencrypt · high confidence

Centralized control-plane dependency and certificate path management

The control-plane daemon's dependency and certificate path management has been consolidated into a new \deps\ package. This change introduces a centralized \CreateRuntimeCertFiles\ function that defines all certificate, key, and kubeconfig file paths for the control plane, alongside a \GenServerDeps\ function to handle certificate generation and legacy cleanup. The refactoring also adds unit tests for the \addSANs\ helper function, ensuring consistent handling of Subject Alternative Names in certificates.

pkg/daemons/control/deps · high confidence

Introduce CRI connection and wait utilities

Added new CRI (Container Runtime Interface) helper functions to the agent. The \Connection\ function establishes a gRPC connection to a CRI socket, automatically prepending the correct platform-specific prefix (Unix for Linux, npipe for Windows) and verifying the runtime is responsive. The \WaitForService\ function provides a retry loop to wait for the CRI service to become available, improving startup reliability.

pkg/agent/cri · high confidence

Introduce dedicated config file argument parser

The \pkg/configfilearg\ package now provides a standalone, framework-agnostic parser for K3s configuration files. This new \Parser\ and its \DefaultParser\ handle reading the primary config file and \.d\ drop-in directories, supporting value appending for slice flags and filtering invalid flags per command. The \MustFindString\ helper allows safe retrieval of config values while respecting override flags like \--help\ or \--version\. Comprehensive unit tests verify parsing logic, drop-in file handling, and environment variable overrides.

pkg/configfilearg · high confidence

Introduce internal types for etcd snapshot management

Added a new \types.go\ file in \pkg/etcd/snapshot\ that defines the internal \File\ and \S3Config\ structs used to represent etcd snapshots and their S3 configuration. This change introduces the data structures and conversion logic (\FromETCDSnapshotFile\, \ToETCDSnapshotFile\) that map between the internal snapshot representation and the external \ETCDSnapshotFile\ API objects, enabling the snapshot subsystem to handle both local and S3-based storage backends.

pkg/etcd/snapshot · high confidence

Introduce k3s cloud provider implementation for node and load balancer management

The k3s cloud provider has been implemented in the \pkg/cloudprovider\ package, providing the \cloudprovider.Interface\ for managing node status and service load balancers. This includes the \InstancesV2\ implementation for node metadata (internal/external IPs, DNS, hostname, and topology labels) and the \LoadBalancer\ interface for managing the \svclb\ DaemonSet. The implementation supports dual-stack IP families, respects the \ExternalTrafficPolicy\ for local traffic routing, and allows configuration of the load balancer image, namespace, and pod priority class. Tests have been added for the instance metadata and load balancer filtering logic.

pkg/cloudprovider · high confidence

Introduce local and remote etcd store abstractions

Added new \store\ package providing \ReadWriteCloser\ and \ReadCloser\ interfaces for interacting with etcd data. The implementation includes a \RemoteStore\ wrapper around the etcd client for remote operations, and a \TemporaryStore\ that creates a local copy of the etcd database files for safe, isolated access. These changes support improved resilience during datastore bootstrap and control-plane node restarts by enabling local data access without a running etcd server.

pkg/etcd/store · high confidence

Introduce local load balancer with persistent state and proxy support

The agent's load balancer has been refactored to persist its configuration to disk, allowing it to remember the list of backend servers across restarts. The implementation now supports HTTP and SOCKS5 proxies for agent connections, configurable via environment variables. Additionally, Prometheus metrics are exposed to monitor server health states, connection counts, and dial durations.

pkg/agent/loadbalancer · high confidence

Introduce passwd package for managing node credentials and roles

Added a new \pkg/passwd\ package that provides a structured way to read, update, and write node password and role information. The \Read\ function parses CSV-based password files, handling missing files gracefully and validating that records contain at least two columns. The \EnsureUser\ method updates or creates user entries, supporting both explicit passwords and automatic generation of random tokens for new users. The \Write\ method persists changes to disk using a temporary file and atomic rename to ensure filesystem compatibility. A comprehensive test suite (\passwd\_test.go\) validates reading, updating, and edge cases like K10 token prefix stripping.

pkg/passwd · medium confidence

Introduce rootless mode for K3s

Added a new rootless execution mode that allows K3s to run as a non-root user. This includes mounting necessary directories (logs, CNI, kubelet, etc.) into a user-specific state directory, configuring port forwarding via a built-in or slirp4netns driver, and validating required kernel sysctls. The implementation is restricted to Linux; attempting to use rootless mode on Windows will result in a panic.

pkg/rootless · high confidence

Introduce version package with configurable program name

A new \pkg/version\ package is added, defining variables for the program name (defaulting to 'k3s'), its uppercase variant, the version string, and the git commit hash. The program name is exposed as a variable, allowing it to be changed at compile time rather than being hardcoded.

pkg/version · high confidence

Introduces a new API proxy layer with local load-balancing for supervisor and API server connections

A new \apiproxy.go\ file introduces a \Proxy\ interface and implementation in \pkg/agent/proxy\ that manages connections to the supervisor and API server. When load-balancing is enabled, the proxy starts local load-balancers on static ports (one below each other) to route traffic, returning the local load-balancer URLs instead of the actual server addresses. This allows agents to connect to local load-balancers rather than directly to remote servers, supporting features like health checks and IPv6. The proxy also handles fallback addresses and port configuration for both supervisor and API server endpoints.

pkg/agent/proxy · high confidence

Introduces a pluggable driver interface for managed cluster components

A new \Driver\ interface is introduced in \pkg/cluster/managed/drivers.go\, defining a pluggable architecture for managed cluster backends. The interface specifies methods for initialization, lifecycle management (Start, Reset, Restore), snapshotting, and member management. The file also includes a global registry (\RegisterDriver\, \Registered\) to manage multiple driver implementations, allowing the system to support different storage or database backends through a unified interface.

pkg/cluster/managed · medium confidence

Introduces a unified executor interface for managing node components

The system now uses a centralized \Executor\ interface to manage the lifecycle of Kubernetes components (API server, scheduler, controller manager, etc.) and node services (containerd, CNI). This change encapsulates the execution logic, allowing different drivers to implement the interface, which facilitates the transition to an embedded architecture where components like the cloud controller manager and etcd are managed internally rather than as separate processes. Users benefit from more robust component startup and shutdown sequencing, including proper context passing and wait-group handling to prevent premature exits.

pkg/daemons/executor · high confidence

New API and utility helpers for API server readiness and RBAC checks

The pkg/util package introduces new utility functions to manage API server readiness and RBAC validation. WaitForAPIServerReady and APIServerReadyChan now poll the /readyz endpoint with a configurable timeout and context support, ensuring components wait for the API server before starting. WaitForRBACReady and CheckRBAC provide polling mechanisms to verify RBAC permissions using SelfSubjectAccessReview or SubjectAccessReview. Additionally, GetRESTConfig and GetClientSet simplify Kubernetes client initialization with default timeouts and rate limits, while SendError and SendErrorWithID standardize error responses and logging. These changes improve startup reliability and error handling in the control plane.

pkg/util · high confidence

New authentication and authorization middleware components

Added new middleware functions for authentication and authorization in the server's HTTP handler chain. The \auth\ package now provides \HasRole\ and \IsLocalOrHasRole\ for role-based access control, and \Delegated\ for Kubernetes-style client certificate and SubjectAccessReview-based authentication. Additionally, a \MaxInFlight\ middleware was added to limit concurrent requests, and a \RequestInfo\ middleware was introduced to enrich request context with verb, resource, and GVK information.

pkg/server/auth · high confidence

New deploy controller for manifest management

A new deploy controller has been introduced to manage the lifecycle of Kubernetes manifests. The controller watches for file changes and applies them to the cluster, supporting features such as disabling specific manifests, handling symlinks for logical path preservation, and using the \wrangler\ library for apply operations. The implementation includes a \Stage\ function that embeds and processes manifest files, and a \WatchFiles\ function that triggers periodic checks for updates. Tests verify that symlinked directories are followed correctly and that regular manifests remain removable when disabled.

pkg/deploy · high confidence

New file and string utility functions

Added new utility functions to the agent's util package: a WriteFile helper that creates parent directories and writes content to a file, and a CopyFile function that copies files with optional handling for missing source files. Additionally, a case-insensitive suffix check function (HasSuffixI) was added to the strings utility.

pkg/agent/util · medium confidence

Node configuration and environment variables are now stored as annotations

The nodeconfig package introduces new annotations to store the node's CLI arguments and environment variables, enabling other components to detect configuration changes. Sensitive values (such as tokens, datastore endpoints, and secret keys) are redacted with asterisks in the stored annotations. Additionally, labels are added or removed based on the egress selector mode to indicate supported functionality.

pkg/nodeconfig · high confidence

Refactor cluster bootstrap and TLS handling into dedicated modules

The cluster initialization logic has been refactored into separate modules: bootstrap.go handles loading and saving bootstrap data to the datastore, encrypt.go implements AES-GCM encryption for sensitive cluster configuration, and https.go manages the dynamic TLS listener and certificate generation. A new address\_controller.go introduces a node controller that dynamically updates the allowed TLS Subject Alternative Names (SANs) based on active control-plane and etcd nodes, filtering out invalid addresses. Additionally, a profile.go module is added to expose the Go pprof debugging endpoints on the supervisor port.

pkg/cluster · high confidence

Server CLI configuration and startup logic consolidated into a single entry point

The server command's entry point and configuration mapping have been consolidated into a new file at pkg/cli/server/server.go. This change centralizes how the server CLI parses arguments and maps them to the internal server configuration, including datastore (etcd/S3) settings, TLS/SSL parameters, feature flags (e.g., disable agent, disable CCM), and network settings (advertise IP, flannel backend). This refactoring simplifies the CLI interface and ensures consistent initialization of the server components.

pkg/cli/server · high confidence

Support etcd S3 configuration via Kubernetes Secret

Users can now store sensitive S3 backup configuration (access keys, endpoints, CA bundles, etc.) in a Kubernetes Secret rather than using CLI flags or config files. The system reads these settings from a specified secret, allowing for more secure and flexible S3 snapshot management. This change introduces new files (config\_secret.go, s3.go) that handle secret retrieval and client initialization, along with corresponding unit tests.

pkg/etcd/s3 · high confidence

Removals

Removal of legacy agent and CLI components

The agent subsystem has been removed, including the Go implementation files for configuration, containerd, flannel, proxy, syssetup, and tunnel management. The corresponding CLI commands for running the agent and kubectl wrapper have also been deleted. This eliminates the previous mechanism for initializing and managing the node agent, network (flannel), and system setup, indicating a shift away from the prior agent-based architecture.

(repo-wide) · high confidence

Removal of version package

The version package, which previously exposed the application's version and git commit hash, has been removed from the codebase.

version · high confidence

Architecture

Refactor embedded executor into a dedicated package

The embedded executor implementation has been moved from \pkg/executor\ into a new \pkg/executor/embed\ package, separating the embedded runtime logic from the main executor interface. This change also includes platform-specific implementations for Linux and Windows, and extracts the embedded etcd startup logic into \pkg/executor/embed/etcd\.

pkg/executor · high confidence

Relocate server request handlers into a dedicated package

The HTTP request handlers for the K3s server have been moved from the \pkg/server\ package into a new \pkg/server/handlers\ package. This refactoring groups related HTTP handlers—such as those for certificates, secrets encryption, and token rotation—into a single, organized location, improving code structure and maintainability without changing the external API or behavior.

pkg/server/handlers · high confidence

Behavioural changes

Added zstd-based tarball extraction utility

The package now supports extracting zstd-compressed tarballs, replacing the previous gzip-based approach. The new implementation includes memory limits for the zstd decoder and validates file paths to prevent directory traversal issues.

pkg/untar · medium confidence

Agent configuration retrieval and node authentication refactored

The agent configuration retrieval logic has been refactored to use jittered polling with exponential backoff when fetching node configuration from the server, improving stability during startup. Node authentication has been updated to include the node name and IP in the request headers, and the system now falls back to basic or bearer authentication if node identity authentication is rejected. Additionally, platform-specific containerd and CRI-Dockerd configurations are now applied via OS-specific files (config\_linux.go, config\_windows.go), and unit tests have been added to validate resolv.conf parsing and containerd QoS class configuration.

pkg/agent/config · high confidence

Agent startup and configuration logic consolidated into new run files

The agent startup sequence is now implemented in new platform-specific files (run.go, run\_linux.go, run\_windows.go) that handle container runtime initialization, network setup, and crictl configuration. This refactors how the agent bootstraps, validates network configuration (including dual-stack and IPv6 support), and manages the transition from deprecated pointer libraries and raw ListWatch calls to modern helpers.

pkg/agent · medium confidence

Centralized HTTPS router and listener management for the agent

The agent's HTTPS handling is now managed through a centralized router and listener setup in the \pkg/agent/https\ package. This change introduces a \Start\ function that creates a new HTTPS listener and applies authentication/authorization filters, while also supporting the wrapping of existing handlers. This provides a consistent entry point for HTTPS traffic to the agent.

pkg/agent/https · medium confidence

Centralized data directory resolution with rootless support

The pkg/datadir package now defines default paths for data and configuration, using version.Program to construct paths like /var/lib/rancher/k3s and ${HOME}/.rancher/k3s. The Resolve and LocalHome functions implement logic to select between privileged (system) and unprivileged (home) directories based on permissions, enabling rootless operation.

pkg/datadir · medium confidence

Centralized metrics registration and HTTP endpoint

The metrics subsystem has been refactored to use a shared Prometheus registry (DefaultRegisterer) and a unified HTTP /metrics endpoint. On startup, the application automatically registers metrics from the load balancer, etcd snapshot manager, remote dialer, and lasso, ensuring all these components expose their metrics through the same registry. The metrics server is now started by binding the /metrics path to the standard Prometheus handler, replacing the previous per-component or ad-hoc registration patterns.

pkg/metrics · medium confidence

Conditional compilation for static asset staging

The static package now supports conditional compilation via build tags. A new 'nostage' build tag allows users to disable the staging of static assets entirely, which is useful for environments where embedding or writing these files is unnecessary or undesirable. When the 'no\_stage' tag is not present, the system stages static files from the embedded filesystem to the specified data directory, maintaining the existing behavior for standard builds.

pkg/static · high confidence

Expanded daemon configuration schema with new control and agent settings

The configuration types in \pkg/daemons/config/types.go\ have been significantly expanded to support new cluster networking, storage, and runtime options. The \Node\ struct now includes fields for egress selector mode, embedded registry, and containerd/cri-dockerd configurations. A new \EtcdS3\ struct defines parameters for S3-compatible etcd snapshot storage, while the \Agent\ struct gains fields for dual-stack CIDRs, node IPs/DNS, image credentials, and TLS settings. These changes enable users to configure advanced networking, storage backends, and runtime behaviors directly through the daemon's configuration.

pkg/daemons/config · high confidence

Flannel networking agent refactored with dual-stack and backend support

The Flannel networking agent has been refactored to support dual-stack (IPv4/IPv6) configurations and multiple backends including VXLAN, host-gateway, IPsec, and Wireguard. The implementation now uses a \netMode\ type to determine network configuration, enabling IPv6 masquerading and IPv6-only setups. The CNI configuration is generated dynamically based on the node's cluster CIDRs, and the agent waits for the PodCIDR assignment before starting. Additionally, the codebase has been updated to use modern Go practices, such as \context\ for error handling and \renameio\ for atomic file writes on Linux, while falling back to standard \os.WriteFile\ on Windows.

pkg/agent/flannel · high confidence

Improved kubeconfig permission handling and Windows support

The kubectl wrapper now detects the kubeconfig path from the --kubeconfig flag and the KUBECONFIG environment variable. On Windows, it strips the first argument to support multi-call binary execution. Additionally, the wrapper checks if the kubeconfig file is world-readable and issues a warning if it is not, suggesting the use of --write-kubeconfig-mode or --write-kubeconfig-group to fix permissions.

pkg/kubectl · high confidence

Integrate containerd v2 with platform-specific snapshotter support

The embedded containerd runtime has been upgraded to v2, introducing new built-in support for Linux snapshotter plugins including overlayfs, btrfs, devmapper, zfs, fuse-overlayfs, and nix-snapshotter on Linux, while providing stubs for Windows and non-Linux platforms. This change updates the containerd integration layer to register these snapshotter plugins and expose utility functions to detect their availability, enabling users to leverage advanced storage backends for container images and containers.

pkg/containerd · high confidence

Introduce custom HTTP router with middleware support

Added a new HTTP router implementation in pkg/util/mux that wraps the standard library's http.ServeMux to provide middleware support. This change replaces the previous reliance on the github.com/gorilla/mux library, shifting to a custom routing solution that allows applying middlewares to matched routes.

pkg/util/mux · high confidence

Introduce new CLI entry points for the agent and kubectl

The agent CLI entry point has been refactored into a new file (pkg/cli/agent/agent.go) that handles process title concealment, cgroup v2 evacuation, logging initialization, and signal context setup before delegating to the core agent logic. Additionally, a new kubectl CLI entry point (pkg/cli/kubectl/kubectl.go) has been added to wrap the kubectl main function. These changes restructure how the agent and kubectl commands are invoked from the CLI, introducing new behaviors around process title hiding, cgroup management, and signal handling.

pkg/cli/agent · medium confidence

Major CLI refactoring and command restructuring

The CLI has been refactored to use the Urfave CLI v2 framework, which restructures the command hierarchy and introduces new subcommands for managing certificates (k3s certificate check/rotate/rotate-ca), tokens (k3s token create/delete/generate/list/rotate), and secrets encryption (k3s secrets-encrypt status/enable/disable/prepare/rotate/reencrypt/rotate-keys). Additionally, shell completion is now handled via a dedicated k3s completion command supporting Bash and Zsh, and the etcd-snapshot command now includes save, delete, list, and prune subcommands with S3 backup support. The agent and server subcommands have been reorganized to expose more configuration flags for networking, runtime, and node settings.

pkg/cli/cmds · high confidence

Migrate CLI implementation to UrfaveCLI v2

The \ctr\ CLI command handler has been updated to use the Urfave CLI v2 library, replacing the previous implementation. This change updates the underlying framework for parsing command-line arguments and managing the \ctr\ subcommand within the K3s CLI interface.

pkg/cli/ctr · high confidence

Migrate containerd configuration template to version 3

The containerd configuration template has been updated to version 3, introducing support for additional runtime classes (crun, wasm, nvidia), SELinux, and systemd cgroup settings. The template now handles private registry configurations, snapshotter options (including Stargz and Nix), and CNI directory settings. Windows-specific handling for named pipe addresses and path escaping has also been refined.

pkg/agent/templates · medium confidence

Multi-call binary and standalone CLI wrappers for K3s commands

The K3s CLI is restructured into a multi-call binary (k3s) that dispatches to subcommands, alongside standalone wrappers for specific tools (agent, server, cert, token, etcd-snapshot, secrets-encrypt, crictl, ctr, kubectl). This change introduces a new \--prefer-bundled-bin\ flag that allows users to prefer bundled binaries over host-installed ones, and adds shell completion support. The multi-call binary also handles symlink aliases for external CLIs and manages data directory resolution.

cmd · high confidence

Network policy controller now waits for node readiness and taint removal before starting

The network policy controller will now wait for the node to become Ready and for the external cloud provider taint to be removed before starting. This prevents the controller from crashing or failing to initialize when the node is still in an uninitialized or not-yet-ready state, improving startup reliability.

pkg/agent/netpol · high confidence

Node host entries are now managed via a dedicated controller

The node controller has been refactored to use a dedicated handler that watches for node creation and removal events, updating the CoreDNS ConfigMap with the node's internal IP addresses and hostname. This change introduces a cache-based watch on the CoreDNS ConfigMap to avoid repeated API server calls, and ensures that node host entries are correctly synced or removed when nodes are added or deleted.

pkg/node · high confidence

Node password authentication now uses Kubernetes Secrets with a dedicated controller

The node password validation logic has been refactored to store and verify passwords in Kubernetes Secrets of type 'k3s-io/node-password' rather than relying on local files or in-memory state. A new controller in pkg/nodepassword manages these secrets, handling creation, migration of legacy secrets, and cleanup of orphaned entries. This change introduces a new dependency on the 'wrangler' library for controller management and updates the authentication flow to require the node password informer to be synced before using the cache, improving reliability during cluster startup and preventing race conditions.

pkg/nodepassword · high confidence

Platform-specific privileged checks for permissions

The permissions utility now implements platform-specific logic for the IsPrivileged function. On non-Windows systems, it checks if the process is running as root (UID 0). On Windows, it verifies that the process is a member of the BUILTIN\\Administrators group. This ensures that privilege checks are correctly enforced across different operating systems.

pkg/util/permissions · medium confidence

Redesigned Spegel integration with deferred store and bootstrapper interfaces

The embedded registry (Spegel) integration has been refactored to use new bootstrapper interfaces that prevent the node from advertising itself as an upstream registry. A deferred OCI store implementation is introduced to delay the connection to the containerd backend, and the registry mirror configuration now correctly injects TLS settings and updates node annotations and labels to support peer-to-peer image distribution.

pkg/spegel · high confidence

Refactor agent startup to use kubelet config files instead of CLI arguments

The agent daemon now generates and writes kubelet configuration files (drop-ins) rather than passing all settings as CLI flags. This change introduces OS-specific implementations (agent\_linux.go and agent\_windows.go) that build the kubelet configuration map and arguments, while the main agent.go orchestrates the startup sequence using these generated configs. Users may see changes in how kubelet is configured, particularly regarding the handling of --config and --config-dir flags which are now copied into managed drop-in directories.

pkg/daemons/agent · high confidence

Refactor client access logic into dedicated files

The client access package has been reorganized by splitting the previous monolithic implementation into separate files for token handling (token.go) and kubeconfig generation (kubeconfig.go). This change introduces new public APIs for parsing and validating cluster join tokens, as well as generating client kubeconfig files, while maintaining the same underlying functionality for connecting to the K3s server.

pkg/clientaccess · high confidence

Refactor etcd management into dedicated controllers and handlers

The monolithic etcd management logic has been split into dedicated controllers and handlers to improve modularity and testability. A new API addresses controller (\apiaddresses\_controller.go\) watches Kubernetes EndpointSlices to update the etcd datastore with API server addresses. A member controller (\member\_controller.go\) handles the addition and removal of etcd cluster members based on node annotations. A metadata controller (\metadata\_controller.go\) manages node labels and annotations for etcd nodes. The snapshot functionality has been separated into a dedicated controller (\snapshot\_controller.go\) that syncs snapshot metadata to a ConfigMap, and a handler (\snapshot\_handler.go\) that exposes snapshot operations (save, list, prune, delete) via HTTP. Additionally, a simple gRPC resolver (\resolver.go\) is introduced to bypass etcd's internal resolver for better failover handling, and snapshot metrics (\snapshotmetrics/snapshotmetrics.go\) are added to track performance. These changes restructure the \pkg/etcd\ package to separate concerns, making the codebase easier to maintain and test.

pkg/etcd · high confidence

Refactor network proxy implementation to use custom error handling

The network proxy logic in \pkg/daemons/control/proxy\ has been refactored to use a custom \errors\ package (\github.com/k3s-io/k3s/pkg/util/errors\) for error handling, specifically replacing the use of \github.com/pkg/errors\ which was removed as a dependency. The \Proxy\ function now manages bidirectional data piping between two connections, handling errors via a dedicated channel and logging warnings for non-EOF errors. This change aligns with the broader project goal of removing the archived \github.com/pkg/errors\ dependency.

pkg/daemons/control/proxy · medium confidence

Refactor secrets encryption configuration handling

The secrets encryption configuration logic has been refactored into a new \config.go\ file, introducing structured handling for AES-CBC and SecretBox providers, along with identity (no-encryption) states. This change consolidates the logic for reading, writing, and managing encryption keys and providers, supporting the enable/disable and rotation workflows for secrets encryption.

pkg/secretsencrypt · medium confidence

Refactor server initialization and controller lifecycle management

The server package has been refactored to improve the initialization and lifecycle management of controllers. A new \Context\ struct and \NewContext\ constructor centralize the creation of Kubernetes and Wrangler client factories, replacing the previous scattered initialization logic. The \StartServer\ function now explicitly manages the startup sequence: it waits for the API server to be ready, runs startup hooks, stages files, and then starts the controllers. This change introduces a more robust lifecycle management for controllers, ensuring that components like the node password controller and leader-elected controllers are started in the correct order and with proper context cancellation. The \Config\ struct has been updated to include \StartupHooks\ and \Controllers\ fields, allowing for more flexible and modular server configuration.

pkg/server · high confidence

Refactored agent tunnel to use EndpointSlices and support EgressSelector modes

The agent tunnel implementation has been refactored to watch Kubernetes EndpointSlices instead of Endpoints, improving reliability and performance. The tunnel now supports EgressSelector modes (Cluster and Pod) to control which traffic is routed through the tunnel, and includes logic to wait for RBAC permissions before starting watches. Additionally, the tunnel respects the configured Kubelet port and address, and handles IPv6 addresses correctly when building proxy addresses.

pkg/agent/tunnel · medium confidence

Refactored containerd agent configuration and image loading

The containerd agent's configuration and image loading logic has been refactored into new, platform-specific files. On Linux, the agent now supports cgroup v2, systemd cgroups, SELinux, and a wider range of container runtimes (crun, nvidia, and various WASM shims). On Windows, the agent configures the Windows container runtime and disables unsupported features like overlayfs. Both platforms now use a templated config generation system (config-v3.toml.tmpl) and a new \watcher.go\ to monitor the images directory for automatic image imports and pre-pulling. The \command.go\ and \config.go\ files handle process management and config writing, while \runtimes.go\ discovers available runtimes via PATH.

pkg/agent/containerd · high confidence

Refactored tunnel server and control-plane startup logic

The tunnel server implementation was refactored to support egress proxy mode, tracking node and pod IP addresses via a CIDR trie for routing. The control-plane startup logic was restructured: the \Server\ function now delegates to \cfg.Cluster.Start\ and uses a delayed context cancellation, while the \Prepare\ function handles tunnel and authenticator setup. A new \TunnelServer\ struct manages the remotedialer server and watches for node/pod changes to update the routing table. Unit tests were added for the server startup logic.

pkg/daemons/control · high confidence

Removal of TLS listener config storage implementation

The file pkg/tls/storage.go, which previously handled the persistence and retrieval of TLS listener configuration via a Kubernetes Custom Resource (ListenerConfig), has been deleted. This removes the local storage mechanism for TLS state, indicating a shift away from using this specific Kubernetes resource for managing TLS configuration.

pkg/tls · high confidence

Removal of generated k3s.cattle.io/v1 API types

The generated Go types and controllers for the k3s.cattle.io/v1 API, including the ListenerConfig resource and its associated deep copy, client, and lifecycle adapter files, have been removed from the codebase. This eliminates the previously available API surface for managing ListenerConfig objects in the k3s.cattle.io group.

types/apis · high confidence

Removed obsolete codegen entry point

The main.go file in the types/codegen directory has been deleted. This file previously served as the entry point for generating types using the Norman generator, relying on the k3s.cattle.io/v1 API schema. Its removal indicates that this specific code generation process is no longer required or has been superseded by a different approach.

types/codegen · high confidence

Replace go-bindata with Go native embed

The project has migrated from the external go-bindata library to Go's native embed package. This change updates the data loading mechanism in pkg/data to use the built-in embed functionality, which simplifies the codebase and removes the dependency on the previous binding tool.

pkg/data · high confidence

Replaces go-bindata with Go's native embed package

The project has migrated from the external go-bindata library to Go's built-in embed package for handling embedded static assets. This change updates the internal API for accessing embedded files, ensuring compatibility with modern Go tooling and linting requirements while maintaining the same functional interface for retrieving asset data and file names.

pkg/util/bindata · high confidence

Restructured build and release scripts

The build system was restructured to support the K3s project. Legacy scripts for a different product (Rio) were removed, and new scripts were added to handle K3s-specific build tasks, including versioning, artifact validation, image scanning, and airgap packaging. The \version.sh\ script was replaced with a more robust \version.sh\ that extracts versions from Go modules. The \build\ script was updated to compile K3s binaries and their dependencies. The \ci\ script was updated to run the new \binary\_size\_check.sh\ and \download\ scripts. The \package\ script was updated to use the new \package-airgap\ and \package-cli\ scripts. The \validate\ script was updated to run \go mod tidy\ and \go mod verify\.

scripts · high confidence

Test coverage

Add CA certificate verification test for Docker environments; Add Docker conformance test suite; Add Docker scale test for large CNCF runners; Add Docker-based E2E tests for service traffic policies and firewall rules; Add Docker-based dual-stack integration test; Add Docker-based end-to-end tests for token management; Add E2E split-server test suite; Add E2E startup test suite for K3s cluster validation; Add E2E test suite for Tailscale integration; Add E2E tests for WebAssembly workloads; Add Ginkgo-based Docker skew test suite; Add Go-based e2e test suite for Docker-based etcd clusters; Add Rocky Linux 8 install test; Add T4 Docker test suite and test helpers; Add end-to-end test for node-external-ip configuration; Add end-to-end tests for etcd snapshotting to S3; Add end-to-end tests for private registry functionality; Add end-to-end tests for the embedded registry mirror; Add hardened Docker test suite for network policy verification; Add integration test for CA certificate rotation; Add integration test for dual-stack networking; Add integration tests for etcd snapshot management; Add integration tests for server startup scenarios; Added Docker-based snapshot restore test suite; Added Docker-based upgrade test suite for K3s; Added E2E test infrastructure and scripts; Added Fedora-based install test infrastructure; Added Go-based e2e test suite for Docker lazy pull functionality; Added Longhorn integration tests; Added SELinux RPM installation tests for SUSE and SLE Micro distributions; Added Terraform infrastructure for k3s performance testing; Added Vagrant-based install tests for openSUSE Leap and MicroOS; Added automated install test for Ubuntu 24.04; Added end-to-end test for Multus CNI integration; Added end-to-end test for custom CA certificate rotation; Added end-to-end tests for Btrfs snapshotter support; Added end-to-end tests for dual-stack (IPv4/IPv6) cluster configurations; Added end-to-end tests for secrets encryption; Added end-to-end tests for secrets encryption key rotation and lifecycle; Added end-to-end tests for the auto-import feature; Added install tests for CentOS 9 and Rocky Linux 9; Added integration test for Nix snapshotter; Added integration test for certificate rotation; Added integration test for custom etcd arguments; Added integration test for etcd snapshot restore; Added integration test for flannel-backend=none configuration; Added integration tests for K3s kube-\* server flags; Added integration tests for local storage functionality; Added integration tests for secrets encryption lifecycle; Added mock implementations for testing; Added performance test automation scripts; Added rootless E2E test suite; Added test fixture for etcd member zip; Consolidate test utility functions and add testing documentation; Convert Docker-based end-to-end tests to Go; E2E test infrastructure and utilities; New E2E test suite for cluster validation; New integration test infrastructure and flannel-ipv6-masq test.

Dependencies

Update Go dependencies and Kubernetes version to v1.36.3

The project's Go dependencies have been updated, most notably upgrading the Kubernetes version to 1.36.3-k3s1 and Go to 1.26.5. This update includes bumps to core components such as containerd v2.3.2, runc v1.4.2, etcd v3.6.14, and kine v0.16.3, alongside various other library updates to maintain compatibility and security.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 66.

Lenses

  • Code Health 64
  • Architecture 100
  • Maturity 74
  • Readiness 75
  • Security 61

Changes since last survey

  • 300 commits — 248 feature/other, 52 fixes

By area

  • (root) — 89 commits
  • .github/workflows — 67 commits
  • pkg/agent — 14 commits
  • pkg/cli — 13 commits
  • pkg/etcd — 11 commits
  • scripts/airgap — 11 commits
  • (repo) — 10 commits
  • manifests/traefik.yaml — 10 commits
  • tests/e2e — 9 commits
  • updatecli/updatecli.d — 8 commits
  • manifests/coredns.yaml — 6 commits
  • tests/docker — 5 commits
  • pkg/cloudprovider — 4 commits
  • pkg/daemons — 4 commits
  • tests/integration — 4 commits
  • pkg/executor — 3 commits
  • pkg/server — 3 commits
  • pkg/util — 3 commits
  • .github/actions — 2 commits
  • .github/dependabot.yml — 2 commits

Notable commits

  • fix: Bump containerd with the fix for []byte Get tag from k3s-io/containerd
  • fix: Bump cri-api and containerd for upstream env string fix
  • fix: Bump golang.org/x/net to v0.55.0 to fix [CVE redacted] (#14203)
  • fix: Bump helm-controller for job race fix
  • fix: Bump kine for NATS conformance fixes
  • fix: Bump kine for list/watch revision fixes
  • fix: Bump kine for t4 fixes
  • fix: Bump klipper-helm image for revision check fix
  • fix: Bump spegel to v0.7.1 for libp2p-kad-dht panic fix
  • fix: Download script fix to not be based for /v to use a better pattern for versions
  • fix: Fix [CVE redacted]: Update docker/docker to v25.0.13 (#13473)
  • fix: Fix S3 test
  • fix: Fix SANs added from comma-separated node-external-ip list
  • fix: Fix VPN node IP not being applied to kubelet (#13457)
  • fix: Fix atomic write in WriteSubnetFile
  • fix: Fix cloud-controller-manager exiting due to missing core RBAC
  • fix: Fix coverage reports for e2e and integration tests
  • fix: Fix cron to run everyday at 6PM UTC (#14041)
  • fix: Fix deprecated updatecli apply command
  • fix: Fix docker dualstack test
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

k3s-io/k3s was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a11ae4edfceef9148fd3ebc318ef1da7b88aa566 — the exact code this score is about.
  • Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer latest.