Skip to content
CAI
Software that uses CAICheck a score

kubernetes/minikube

64.4

Adequate · 24 September 2026

90.3k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is Minikube, a tool for running local Kubernetes clusters on various host operating systems and virtualization drivers. It manages the lifecycle of these clusters, including bootstrapping the control plane, configuring container runtimes, and installing a wide array of optional addons for networking, storage, and monitoring. The codebase also handles the construction of the underlying virtual machine or container images, ensuring compatibility across different architectures and environments.

How it got here

2016–2019 — KIC driver and architectural modernization

101 changes.

This period focused on introducing the Kubernetes-in-Containers (KIC) driver to enable VM-less cluster execution, alongside a comprehensive refactoring of the codebase into modular packages for drivers, bootstrapping, and configuration. The work also standardized logging, enhanced error handling, and expanded support for multiple container runtimes and Linux package formats.

2020–2022 — ISO rebuild and driver expansion

70 changes.

This period focused on rebuilding the Minikube ISO for x86\_64 and aarch64 architectures with Linux 6.6 and modern container runtimes, while introducing new drivers like QEMU2 and SSH. It also expanded the ecosystem with numerous addons, a native Podman driver, and robust infrastructure for automated benchmarking, testing, and documentation generation.

2023–2026 — macOS virtualization and driver consolidation

44 changes.

This period focused on expanding macOS support by introducing new virtualization drivers (vfkit, krunkit) and consolidating external dependencies like libmachine, VMware, and Parallels into the internal codebase. It also included significant infrastructure improvements for ARM64 ISO builds, CI testing via Prow, and the addition of various Kubernetes addons and benchmarking tools.

Features

Add Ambassador addon for managing Ambassador Edge Stack installations

This change introduces the Ambassador addon, providing the necessary Kubernetes manifests to install and manage the Ambassador Operator and its Custom Resource Definitions (CRDs). The deployment includes the operator's ServiceAccount, RBAC roles, and a Deployment configured to pull images with the \IfNotPresent\ policy. It also defines an \AmbassadorInstallation\ CR that allows users to specify installation options, such as choosing between the Open Source (OSS) and Edge Stack (AES) flavors via the \installOSS\ flag, and setting update windows.

deploy/addons/ambassador · high confidence

Add Arch Linux package build files for Minikube

Added PKGBUILD and .SRCINFO files to enable building the Minikube binary as an Arch Linux package. The package depends on net-tools and offers optional dependencies for kubectl-bin, virtualbox, and docker-machine-kvm, downloading the pre-built Linux binary from Google Storage.

installers/linux/archlinux · high confidence

Add BuildKit v0.33.0 package for aarch64 Minikube ISO

This change introduces the BuildKit container build engine (version v0.33.0) to the aarch64 architecture of the Minikube ISO. The package includes the buildkitd daemon, buildctl CLI, and runc, configured to run as a systemd socket-activated service. It is set up to use the containerd worker with the 'k8s.io' namespace, enabling native container image building capabilities within the aarch64 Minikube environment.

deploy/iso/minikube-iso/arch/aarch64/package/buildkit-bin-aarch64 · high confidence

Add CPU usage benchmarks for idle and auto-pause scenarios

New benchmarking scripts and documentation have been added to the \hack/benchmark/cpu\_usage\ directory to measure and compare CPU overhead across local Kubernetes tools (minikube, kind, k3d, Docker). The suite is split into two distinct modes: \idle\_only\, which measures average CPU usage during the first five minutes of operation, and \auto\_pause\, which specifically benchmarks the CPU savings achieved when minikube's control plane auto-pause feature is enabled versus disabled. Each mode includes shell scripts to orchestrate the tests, Go code to generate bar chart visualizations from the results, and README files explaining the methodology and usage.

_hack/benchmark/cpu\usage · high confidence

Add CSI hostpath driver addon with configurable registries

The csi-hostpath-driver addon now deploys the v1.6.0 hostpath CSI driver, enabling persistent and ephemeral inline volumes via a new StorageClass (csi-hostpath-sc) and CSIDriver resource. The deployment manifests (attacher, plugin, resizer, snapshotter) are now Go templates that support custom image registries through .CustomRegistries and .Registries fields, with imagePullPolicy set to IfNotPresent. The addon includes RBAC configurations for external sidecars (attacher, provisioner, resizer, snapshotter, health-monitor) and a dedicated service account for the hostpath plugin.

deploy/addons/csi-hostpath-driver · high confidence

Add EFK (Elasticsearch, Fluentd, Kibana) logging addon

This change introduces the EFK logging stack as a new Minikube addon. It deploys Elasticsearch for log storage, Fluentd for log collection and parsing from various system sources (containers, kubelet, etcd, etc.), and Kibana for visualization. The Kibana interface is exposed via a NodePort service on port 30003. The deployment manifests are templated to support custom image registries and repositories.

deploy/addons/efk · high confidence

Add GCP Cloud Trace integration for minikube start

Users can now enable distributed tracing for the \minikube start\ workflow by setting the \MINIKUBE\_GCP\_PROJECT\_ID\ environment variable. This change introduces a new \pkg/trace\ package that initializes an OpenTelemetry tracer provider and exports spans to Google Cloud Trace, allowing users to visualize the start process steps in the Cloud Trace UI.

pkg/trace · high confidence

Add Headlamp Kubernetes dashboard addon

This change introduces the Headlamp addon, providing a new Kubernetes dashboard interface. The deployment includes a dedicated namespace, a NodePort service exposing the dashboard on port 80, a deployment configured to run the Headlamp container, a service account for identity, and a ClusterRoleBinding granting cluster-admin privileges to the Headlamp service account.

deploy/addons/headlamp · high confidence

Add Helm v4.2.3 to the aarch64 Minikube ISO

The aarch64 Minikube ISO now includes the Helm v4.2.3 binary by default. This change adds the necessary Buildroot configuration and build scripts to download, verify, and install the Helm CLI tool into the ISO image, enabling users to manage Kubernetes applications directly from the ISO environment on ARM64 hardware.

deploy/iso/minikube-iso/arch/aarch64/package/helm-bin-aarch64 · high confidence

Add Homebrew Cask formula for Minikube on macOS

Users can now install Minikube on macOS via Homebrew Cask. A new template file (minikube.rb.tmpl) defines the cask, specifying the download URL from Google Storage, a dependency on the kubernetes-cli formula, and a zap command to clean up the \~/.minikube directory upon removal.

installers/darwin · high confidence

Add KubeVirt addon for VM workloads

The KubeVirt addon is now available, allowing users to run Virtual Machine workloads on Minikube. It installs KubeVirt version v1.9.0 and automatically configures software emulation if the host CPU lacks hardware virtualization support (svm/vmx). The addon uses a dedicated installer pod and manages the KubeVirt Custom Resource directly.

deploy/addons/kubevirt · high confidence

Add Kubernetes Bootcamp sample application image

A new Docker image for the Kubernetes Bootcamp sample application has been added to the deploy/images/kubernetes-bootcamp directory. The image is built from node:25-slim, installs curl, and runs a simple Node.js HTTP server on port 8080 that responds with the hostname and request count, enabling users to deploy and test basic Kubernetes workloads.

deploy/images/kubernetes-bootcamp · high confidence

Add Logviewer addon for cluster log access

Introduces the Logviewer addon, which deploys a Kubernetes Service and Deployment to expose container logs via a NodePort on port 3000. The addon configures a ServiceAccount with ClusterRole permissions to read namespace metadata and mounts host paths for container logs, supporting configurable image registries and an IfNotPresent pull policy.

deploy/addons/logviewer · high confidence

Add MetalLB addon for Layer 2 load balancing

This change introduces the MetalLB addon, providing a Layer 2 load balancer implementation for Kubernetes clusters that lack a native cloud provider load balancer. The deployment manifests create the \metallb-system\ namespace, configure ServiceAccounts, RBAC roles, and DaemonSets for the controller and speaker components. It includes a configurable ConfigMap (\metallb-config.yaml.tmpl\) allowing users to define the IP address pool range via \LoadBalancerStartIP\ and \LoadBalancerEndIP\. Additionally, the addon conditionally applies a \LegacyPodSecurityPolicy\ for Kubernetes versions prior to 1.25 to ensure compatibility with older clusters while maintaining security constraints for the speaker component.

deploy/addons/metallb · high confidence

Add Minikube logo assets and license to images directory

The \images\ directory now includes a \logo\ subdirectory containing the Minikube brand assets. This adds the primary SVG logo (\logo.svg\), a white variant (\logo\_white.svg\), and versions including the product name (\logo\_with\_name.svg\ and \logo\_white\_with\_name.svg\). A \LICENSE\ file is also included, specifying that the logo files are licensed under either Apache-2.0 or CC-BY-4.0.

images · high confidence

Add Podman container engine to the Minikube ISO

The Minikube ISO now includes Podman (version 3.4.7) as a built-in container runtime, alongside its dependencies runc, crun, and conmon. This addition enables users to run containers directly on the ISO using Podman, with a default CNI bridge network configuration installed at /etc/cni/net.d/87-podman-bridge.conflist and systemd socket activation configured for the podman service.

deploy/iso/minikube-iso/package/podman · high confidence

Add Podman driver with rootless support and version validation

Minikube now includes a native Podman driver, available by default on Linux and as an experimental option on macOS and Windows. The driver enforces a minimum Podman version of 4.9.0 and automatically handles sudo requirements on Linux, offering a rootless mode via the 'rootless' configuration setting to avoid password prompts. It supports standard KIC features such as custom listen addresses, subnets, and exposed ports, while providing specific error guidance for common issues like missing sudo privileges or non-running services.

pkg/minikube/registry/drvs/podman · high confidence

Add Prow installer scripts for containerd, Docker, Go, and test tools

New shell scripts have been added to the Prow installer directory to automate the setup of the CI environment. These scripts handle the installation of containerd (with SystemdCgroup enabled), Docker, specific versions of Go and kubectl, and test utilities like gotestsum (v1.13.0) and gopogh (v0.29.0).

hack/prow/installer · high confidence

Add Prow integration test runners for KVM, None, and vfkit drivers

The Prow CI system now includes dedicated integration test runners for multiple driver and runtime combinations, expanding test coverage beyond the previous scope. New Go-based testers in the \tester\ package enable validation for the KVM2 driver with Docker, containerd, and CRI-O runtimes on Linux x86\_64, the None driver with Docker and containerd on Linux x86\_64, Docker on Linux ARM64, and the vfkit driver with Docker on macOS ARM64. These changes introduce specific test execution logic for each environment, ensuring that Minikube's integration tests run correctly across these diverse virtualization and container runtime configurations in the continuous integration pipeline.

hack/prow/minitest/tester · high confidence

Add Prow minikube integration test deployer infrastructure

The \hack/prow/minitest/deployer\ directory now contains the Go implementation for provisioning test environments in Prow CI. This includes a \MiniTestDeployer\ interface and concrete implementations for Docker containers, GCP virtual machines, and macOS instances, all utilizing Boskos for resource acquisition. The code provides the necessary logic to spin up these environments, establish SSH connectivity, and synchronize files, enabling the new minikube integration tests to run against isolated infrastructure.

hack/prow/minitest/deployer · high confidence

Add RPM packaging template for minikube

Added a new RPM spec file template (minikube.spec) in the installers/linux/rpm directory, defining the package metadata, build steps, and file installation for the minikube binary. This enables the creation of RPM packages for Linux distributions.

installers/linux/rpm · high confidence

Add SSH agent process management for Minikube profiles

Minikube now includes a new capability to automatically start and stop an ssh-agent process for each profile. The system launches the agent, parses its output to capture the socket path and process ID, and persists these details in the profile configuration. It also provides logic to detect if the agent is already running using the gopsutil library and can cleanly terminate the process when stopping, ensuring keys are managed via a dedicated agent per profile.

pkg/minikube/sshagent · high confidence

Add Volcano addon for Kubernetes workload scheduling

Introduces a new Volcano addon that deploys the Volcano batch scheduling system into the \volcano-system\ namespace. This includes the necessary Kubernetes resources such as namespaces, service accounts, RBAC roles, admission webhooks, and controller deployments to enable advanced scheduling capabilities for batch workloads.

deploy/addons/volcano · high confidence

Add VolumeSnapshot addon with GA v1 API support

The volumesnapshots addon now includes the necessary Kubernetes manifests to enable CSI-based volume snapshots, featuring the snapshot controller deployment, RBAC rules, and a VolumeSnapshotClass. The CustomResourceDefinitions for VolumeSnapshot, VolumeSnapshotContent, and VolumeSnapshotClass have been upgraded to the stable v1 API (snapshot.storage.k8s.io/v1), ensuring compatibility with external-snapshotter v4.x. The addon also supports configurable image registries via templates and sets the image pull policy to IfNotPresent.

deploy/addons/volumesnapshots · high confidence

Add Yakd dashboard addon

The deploy/addons/yakd location now includes the Kubernetes manifests required to install the Yakd dashboard addon. This adds a dedicated namespace, service account, ClusterRoleBinding, Deployment, and NodePort Service, enabling users to deploy and access the Yakd dashboard within their cluster.

deploy/addons/yakd · high confidence

Add aarch64 Docker binary package to the Minikube ISO

This change introduces a new Buildroot package definition for the Docker binaries (docker, dockerd, docker-init, docker-proxy) specifically for the aarch64 architecture within the Minikube ISO build. The package is configured to download and install Docker version 28.5.2 from the official static release site, includes a daemon configuration file (daemon.json) setting the cgroup driver to systemd and storage driver to overlay2, and installs necessary systemd socket and sysctl configuration files to enable Docker on ARM64 nodes.

deploy/iso/minikube-iso/arch/aarch64/package/docker-bin-aarch64 · high confidence

Add aarch64 ISO build configuration for Minikube

This change introduces the board-specific configuration files required to build the Minikube ISO for the aarch64 architecture. It includes the kernel defconfig with support for BPF, networking, and virtualization features, along with GRUB boot configuration files that set the default console for various virtualization drivers (VirtualBox, QEMU, vfkit/krunkit). The entry also provides the genimage configuration for the EFI boot partition, post-build/image scripts to assemble the ISO using xorriso, and user/permission definitions for the resulting image.

deploy/iso/minikube-iso/board/minikube/aarch64 · high confidence

Add aarch64 configuration template for Minikube ISO

A new configuration template file (Config.in.tmpl) has been added for the aarch64 architecture within the Minikube ISO deployment path. This file sources the main Minikube package configuration and the specific aarch64 package configuration, enabling the build system to correctly assemble the ISO image for ARM64 devices.

deploy/iso/minikube-iso/arch/aarch64 · high confidence

Add aarch64 containerd package with version 2.3.5 and Minikube-specific configuration

This change introduces the containerd binary package for the aarch64 architecture, building version 2.3.5. It installs the containerd binaries and applies a Minikube-specific configuration (\config.toml\) that sets the CRI sandbox image to \registry.k8s.io/pause:3.6\, uses the \overlayfs\ snapshotter, and configures the CNI plugin paths. The package also installs a systemd service unit that integrates with Minikube's environment and automount services, and includes a preset file to disable the containerd service by default.

deploy/iso/minikube-iso/arch/aarch64/package/containerd-bin-aarch64 · high confidence

Add aarch64 cri-dockerd package to Minikube ISO

The Minikube ISO build now includes a dedicated package for cri-dockerd on aarch64 architectures. This change introduces the necessary Buildroot configuration, systemd service and socket files, and a build script to install the pre-compiled v0.4.3 binary from GitHub, enabling container runtime support for ARM64 users.

deploy/iso/minikube-iso/arch/aarch64/package/cri-dockerd-aarch64 · high confidence

Add aarch64 package configuration for Minikube ISO

The Minikube ISO build now includes a dedicated configuration file for the aarch64 architecture, enabling the inclusion of essential container and Kubernetes tools such as buildkit, CNI plugins, containerd, cri-dockerd, crictl, Docker, Docker Buildx, Helm, and nerdctl for this platform.

deploy/iso/minikube-iso/arch/aarch64/package · high confidence

Add auto-pause webhook to inject reverse-proxy environment variables

The auto-pause hook now runs as a Kubernetes mutating admission webhook that intercepts Pod and Deployment creation and update events. For each affected workload, it injects the KUBERNETES\_SERVICE\_HOST and KUBERNETES\_SERVICE\_PORT environment variables (pointing to the auto-pause reverse proxy) into every container, enabling inner-cluster requests to be redirected through the proxy. The webhook registers itself via a MutatingWebhookConfiguration, uses TLS with generated certificates, and skips resources labeled with auto-pause-skip.

cmd/auto-pause/auto-pause-hook · high confidence

Add automated time-to-k8s benchmarking with CPU utilization metrics

The time-to-k8s benchmark tool now includes CPU utilization and CPU time metrics alongside the existing deployment timing data. The benchmark script (time-to-k8s.sh) runs the benchmark for minikube, kind, and k3d, and the Go-based report generator (chart.go, cpu.go, page.go) produces public-facing charts and markdown tables for both running time and CPU usage, which are published to the documentation site.

hack/benchmark/time-to-k8s · high confidence

Add crictl v1.35.0 for aarch64 in Minikube ISO

The Minikube ISO build now includes the crictl command-line tool (v1.35.0) for aarch64 architectures. This addition ensures that ARM64-based Minikube nodes have access to the container runtime interface client utility, aligning with the broader crio update to v1.35.

deploy/iso/minikube-iso/arch/aarch64/package/crictl-bin-aarch64 · high confidence

Add docker-buildx plugin to aarch64 ISO

The aarch64 ISO build now includes the docker-buildx CLI plugin (version v0.37.1) by default. The build system downloads the pre-built binary for linux-arm64 and installs it as a Docker CLI plugin at /usr/libexec/docker/cli-plugins/docker-buildx, enabling extended build capabilities on ARM64 systems without requiring a source build.

deploy/iso/minikube-iso/arch/aarch64/package/docker-buildx-aarch64 · high confidence

Add experimental Krunkit driver for macOS arm64

Minikube now includes a new experimental driver named 'krunkit' for macOS arm64 machines, enabling GPU acceleration via the Krunkit hypervisor. This driver is registered in the driver registry with experimental priority and supports parallel start capabilities. It automatically configures deterministic MAC addresses and validates VirtioFS mount strings for shared directories. Users must have the 'krunkit' binary installed (via 'brew tap slp/krunkit && brew install krunkit') and the 'vment-helper' utility configured for networking to use this driver.

pkg/minikube/registry/drvs/krunkit · high confidence

Add gVisor addon support with enable/disable lifecycle and download validation

This change introduces the core logic for the gVisor addon in minikube, allowing users to enable and disable the gVisor sandbox runtime. The new \pkg/gvisor\ package provides \Enable()\ and \Disable()\ functions that manage the containerd configuration (backing up and restoring \config.toml\), download the \runsc\ and \containerd-shim-runsc\ binaries from Google Cloud Storage, and restart the containerd service. It also includes validation to ensure downloads succeed (failing on non-200 HTTP status codes) and adds tests to verify that failed downloads do not corrupt existing binaries or save error pages.

pkg/gvisor · high confidence

Add go9p 9P2000 client and go-dockerclient tar utilities

This change introduces the go9p library (a 9P2000 file protocol client implementation) and the go-dockerclient tar utilities into the third\_party directory. The go9p package provides the core client logic for connecting to 9P file servers, including authentication, file operations (read, write, create, remove, stat), and directory walking, along with necessary protocol definitions and packing/unpacking functions. The go-dockerclient additions include a LICENSE file and a tar.go file that provides utilities for creating tar streams from build contexts, handling .dockerignore files, and validating context directories, which are essential for Docker build operations.

_third\party · high confidence

Add hyperkit driver for macOS (non-arm64)

The hyperkit driver is now available for use on macOS systems running on Intel processors (darwin, !arm64). This new standalone binary registers the hyperkit driver with libmachine, allowing users to select hyperkit as a VM driver. The driver supports version reporting, including the hyperkit version and the git commit ID, which aids in debugging and version tracking. It is explicitly disabled for arm64 architectures.

cmd/drivers · high confidence

Add image-build benchmark infrastructure and chart generation

Introduces a new benchmarking workflow in hack/benchmark/image-build that runs minikube image benchmarks (using the minikube-image-benchmark submodule) and generates visual charts from the results. The new generate-chart.go tool reads CSV benchmark data and past JSON records to produce PNG charts, while publish-chart.sh orchestrates the benchmark execution and uploads the resulting charts and records to an S3 bucket (s3://time-to-k8s/image-benchmark).

hack/benchmark/image-build · high confidence

Add internal Parallels Desktop driver for macOS

The Parallels Desktop driver has been moved from the external libmachine repository into the internal minikube package (pkg/drivers/parallels). On macOS, this provides full support for creating and managing Parallels VMs with configurable CPU, memory, disk, and nested virtualization settings. On non-macOS platforms, the driver is present but returns a "not supported" error, ensuring consistent build behavior across all operating systems.

pkg/drivers/parallels · high confidence

Add krunkit driver supporting GPU acceleration on macOS

Introduces a new krunkit machine driver for macOS, enabling users to run Kubernetes clusters with GPU acceleration support. This driver leverages the krunkit virtualization framework and integrates with existing minikube infrastructure, including common driver utilities, DHCP lease handling, and virtiofs mount support.

pkg/drivers/krunkit · high confidence

Add kubetail addon (v0.13.3)

The kubetail addon is now available in Minikube, providing cluster-wide log tailing capabilities. This deployment installs the kubetail-system namespace and includes the CLI, cluster-agent, cluster-api, and dashboard components, all tagged with version 0.13.3. Users can enable this addon to monitor logs across multiple pods and nodes in their cluster.

deploy/addons/kubetail · high confidence

Add metrics-server addon

This change introduces the metrics-server as a new addon, deploying the necessary Kubernetes resources (Deployment, Service, RBAC, and APIService) to enable cluster-level metrics collection. The deployment is configured with a 60-second metric resolution, uses the 'IfNotPresent' image pull policy, and supports custom image registries via template variables.

deploy/addons/metrics-server · high confidence

Add minikube-hostpath dynamic storage provisioner

Introduces a new dynamic storage provisioner for minikube that automatically creates PersistentVolumes backed by host paths. The provisioner organizes volume directories by PVC namespace and name, sets permissions to 0777, and manages lifecycle via identity-based annotations to ensure safe deletion.

pkg/storage · high confidence

Add minitest integration test runner for Prow

Introduces a new minitest runner in hack/prow/minitest that orchestrates integration tests within the Prow CI environment. The tool supports multiple deployment strategies, including Boskos for GCP resource management and Docker for local testing, and executes specific integration scenarios such as KVM with Docker, containerd, and CRI-O on Linux AMD64, None mode tests, Docker on ARM64, and vfkit on macOS ARM64.

hack/prow/minitest · high confidence

Add nerdctl binary package for aarch64 ISO builds

The Minikube ISO build system now includes nerdctl (version 2.3.5) for aarch64 architectures. This change adds the necessary Buildroot package configuration, source hashes for multiple versions, and the build script to install the nerdctl binary into the target ISO image, making the container CLI tool available to users running Minikube on ARM64 hardware.

deploy/iso/minikube-iso/arch/aarch64/package/nerdctl-bin-aarch64 · high confidence

Add optional scheduled VM shutdown capability

The Minikube ISO now includes an optional 'scheduled-stop' feature that allows the virtual machine to automatically power off after a user-defined delay. This is implemented via a new systemd service (\minikube-scheduled-stop.service\) and a shell script installed to \/usr/sbin/minikube-scheduled-stop\. The service reads a sleep duration from \/var/lib/minikube/scheduled-stop/environment\ and executes \systemctl poweroff\ after that period. The feature is enabled by default in the build configuration (\BR2\_PACKAGE\_SCHEDULED\_STOP\) but the systemd service is disabled by default until a user explicitly schedules a stop, ensuring it does not interfere with normal operation.

deploy/iso/minikube-iso/package/scheduled-stop · high confidence

Add public chart generation for Docker and VirtualBox benchmarks with containerd support

The time-to-k8s benchmark tool now generates public charts for Docker and VirtualBox drivers, including new support for the containerd container runtime. This change introduces benchmark configuration files for all four combinations (Docker/containerd, Docker/Docker, VirtualBox/containerd, VirtualBox/Docker), a Go utility to parse benchmark CSVs and generate daily and weekly trend charts, and a shell script to orchestrate the benchmark run, chart generation, and upload of results and images to an S3 bucket.

hack/benchmark/time-to-k8s/public-chart · high confidence

Add registry-aliases addon for custom domain resolution

The new \registry-aliases\ addon allows users to push and pull container images from the Minikube internal registry using custom domain names (e.g., \example.org\, \test.com\). It installs a DaemonSet to update the node's \/etc/hosts\ file and a Job to patch CoreDNS with rewrite rules, ensuring that in-cluster workloads and the Minikube node can resolve these aliases to the internal registry service.

deploy/addons/registry-aliases · high confidence

Add runc-master package to Minikube ISO build

The Minikube ISO build system now includes a new 'runc-master' package, allowing users to opt-in to a newer version of runc (v1.5.1) than the default Buildroot version. This addition provides access to the latest container runtime features and fixes from the opencontainers/runc project, built dynamically for the target architecture (amd64 or arm64) and integrated into the ISO via Buildroot configuration.

deploy/iso/minikube-iso/package/crun-latest, deploy/iso/minikube-iso/package/runc-master · high confidence

Add script to generate minikube help text and documentation

A new Go script (hack/help\_text/gen\_help\_text.go) has been added to automatically generate Markdown documentation and Bash completion files for the minikube CLI. This tool uses the Cobra library to traverse the command tree and outputs the resulting help text and completion scripts to the ../out/docs directory, streamlining the maintenance of user-facing documentation.

_hack/help\text · high confidence

Add tool to filter test flake data for the last 90 days

Added a new Go utility and accompanying shell script in the Jenkins hack directory to process Minikube test flake data. The tool reads a source CSV file, filters entries to include only those from the last 90 days, and writes the result to a target CSV, which is then uploaded to Google Cloud Storage. This enables more focused analysis of recent test instability by excluding older historical data.

_hack/jenkins/test-flake-chart/process\_last\90 · high confidence

Added Azure infrastructure templates for Windows Hyper-V CI testing

New Bicep files (vm.bicep and vm.bicepparam) have been added to the hack/windows-ci-image directory to define the Azure resource group, virtual network, and virtual machine required for running functional tests on Windows Hyper-V in Azure. These templates configure a Standard SKU public IP, allow RDP and SSH access, and reference an Azure Shared Image Gallery image via environment variables, enabling the CI pipeline to provision the necessary Windows test environment.

hack/windows-ci-image · high confidence

Added dedicated single-page layouts for gvisor, helm-tiller, ingress-dns, and istio addons

New layout templates have been added for the gvisor, helm-tiller, ingress-dns, and istio addon documentation pages. These templates define the main content wrapper with specific top padding (20px for gvisor, helm-tiller, and istio; 60px for ingress-dns) to ensure consistent visual spacing for these individual addon pages.

deploy/addons/layouts · high confidence

Added internal code extraction utility for translation strings

A new command-line tool has been added to scan the minikube codebase (specifically the cmd and pkg directories) for translatable strings. This utility identifies calls to the translation function and outputs the collected strings into JSON files within a translations directory, supporting the project's internationalization efforts. It is designed to be run from the project root and includes checks to ensure it is not executed from within the cmd directory or if required error mapping files are missing.

cmd/extract · high confidence

Added legacy database population script

A new Go utility (\hack/legacy\_fill\_db/filldb.go\) has been added to populate the legacy flakiness database. This tool fetches test result JSONs from a Google Cloud Storage bucket, partitions the workload across 64 concurrent workers, and uses the \gopogh\ CLI tool to insert the data into a PostgreSQL database via Cloud SQL, including logic to skip already-existing entries and handle rate limits.

_hack/legacy\_fill\db · high confidence

Added pause/unpause file management for API server status

The minikube pause package now provides functions to create and remove a 'paused' file within the cluster, allowing the system to signal whether the API server is paused or unpaused. This mechanism helps ensure the API server displays the correct status during pause and unpause operations.

pkg/minikube/pause · high confidence

Addons now support AMD GPUs and configurable NVIDIA driver versions

The GPU addon templates have been updated to include a new \amd-gpu-device-plugin\ for AMD hardware on Linux amd64, alongside a restructured NVIDIA setup. The NVIDIA driver installer now uses a configurable version (set to 510.60.02 in the template) and a dedicated installer image, while the device plugin has been renamed to \nvidia-gpu-device-plugin\. All GPU-related DaemonSets now support custom image registries via the \.CustomRegistries\ and \.ImageRepository\ template variables, allowing users to override default image sources.

deploy/addons/gpu · high confidence

Audit logging for Minikube commands

Minikube now records an audit trail of executed commands, including the command name, arguments, profile, user, version, and start/end times, stored as CloudEvents in a JSON log file. The system limits the log to a configurable number of entries (defaulting to 1000) and excludes specific commands like 'status', 'version', 'logs', 'generate-docs', 'profile', and 'delete --purge' from being logged. Users can view the last N entries of this audit log as a formatted ASCII table via the new report functionality, and can opt out of audit logging entirely using the --skip-audit flag.

pkg/minikube/audit · high confidence

Automated CI host cleanup and reboot scripts for Linux and macOS

New cron-based scripts have been added to automatically clean up CI host resources and reboot machines when idle. The Linux script (cleanup\_and\_reboot\_Linux.sh) performs comprehensive cleanup of minikube, Docker, and KVM resources for jenkins and root users, updates the system, and reboots. The macOS script (cleanup\_and\_reboot\_Darwin.sh) handles Docker cleanup, clears DHCP leases, runs software updates, and reboots. A separate script (cleanup\_go\_modules.sh) periodically clears the Go module cache.

hack/jenkins/cron · high confidence

Automated GitHub Actions runner cleanup and reboot

Added scripts to automatically clean up Docker resources and reboot GitHub Actions self-hosted runners. The \install\_cleanup.sh\ script configures a cron job to run \cleanup.sh\ hourly and sets up a reboot trigger to clear state files, ensuring runners remain in a clean state after maintenance.

_hack/gh\actions · high confidence

Automated documentation generation for commands, error codes, and integration tests

The \pkg/generate\ package now provides a comprehensive system for automatically generating documentation. It creates Markdown files for all non-hidden CLI commands, including custom shell code blocks and aliases. It also generates a dedicated error codes and strings reference by parsing Go source files, and produces a list of integration test cases by extracting structured comments (such as \docs:\, \docs(special):\, and \docs(skip):\) from test files. Additionally, the system rewrites OS-dependent flag descriptions (like \--driver\ and \--mount-string\) to ensure the generated docs are accurate and deterministic across different environments.

pkg/generate · high confidence

Automated kernel hash update helper for ISO builds

Added a new shell script, \update-kernel-hash.sh\, to the \hack/iso\ directory to streamline the process of updating Linux kernel hashes for ISO images. This tool automatically fetches the SHA256 checksum for a specified kernel version from kernel.org and updates the corresponding entry in the \linux.hash\ file used by the Buildroot-based ISO build system, ensuring that hash verification remains accurate when kernel versions are bumped.

hack/iso · high confidence

Automated kicbase release and package listing tooling

The hack/kicbase\_version directory now includes a Go script (release\_kicbase\_version.go) that automates the process of promoting a snapshot kicbase image to a stable release by stripping the version suffix, tagging the image, and pushing it to Google Cloud Container Registry, Docker Hub, and GitHub Packages. Additionally, a new os-package-list.txt file has been added to capture the list of installed operating system packages within the kicbase image, providing a reproducible snapshot of the base environment's dependencies.

_hack/kicbase\version · high confidence

Automated persistent storage mounting for Minikube ISO

The Minikube ISO now includes a new 'automount' package that automatically detects and formats external data disks labeled 'boot2docker-data' (or unpartitioned disks with the specific magic header) at boot. This process creates bind mounts for critical directories—including /var/lib/docker, /var/lib/kubelet, /var/lib/containerd, /var/lib/buildkit, /var/lib/containers, /var/log, /var/tmp, /data, /tmp/hostpath\_pv, /tmp/hostpath-provisioner, /var/lib/minikube, /var/lib/toolbox, and /var/lib/minishift—ensuring that container state, logs, and persistent volumes survive reboots. The automation is handled by a systemd oneshot service that runs after udev settles and before Docker starts.

deploy/iso/minikube-iso/package/automount · high confidence

Automated version update scripts for Kicbase and ISO components

The \hack/update\ directory now includes a comprehensive suite of automated scripts to keep underlying container runtime and infrastructure dependencies current. These new tools automatically fetch the latest stable versions from upstream repositories (such as GitHub releases and Docker Hub) and apply them to the project's build files. Specifically, the update covers critical components including containerd, cri-dockerd, CNI plugins, crun, buildkit, docker, docker-buildx, calico, cilium, and crictl. The automation also handles the Debian base image for Kicbase, ensuring that the ISO and container images are built with the most recent, supported versions of these tools without manual intervention.

hack/update · high confidence

Enable gVisor sandboxed container runtime addon

Users can now enable the gVisor addon to run pods with untrusted workloads in a sandboxed environment. This change introduces the necessary Kubernetes manifests (RuntimeClass and Pod) and documentation to configure the gVisor runtime handler. Enabling the addon via 'minikube addons enable gvisor' deploys the gVisor controller pod and registers the runtime class, allowing users to specify 'runtimeClassName: gvisor' in their pod specifications to leverage the sandboxed runtime.

deploy/addons/gvisor · high confidence

Enable gvisor addon in minikube

Users can now enable the gvisor addon in minikube. This change introduces a new command-line tool at cmd/gvisor that calls the gvisor.Enable() function to activate the feature, replacing previous implementation details like using chroot for containerd restarts.

cmd/gvisor · high confidence

Extracted DHCP lease parsing and WaitForLease utility

The DHCP lease lookup logic has been extracted into a new \pkg/drivers/common/dhcp\ package. This introduces a \WaitForLease\ function that polls the DHCP leases file for a given MAC address, automatically tripling the timeout when running inside a nested VM. The underlying parser now correctly handles DUID entries (hw\_address type 'ff') by skipping them without breaking the parsing of subsequent Ethernet entries, and supports variable-size MAC address formats found on macOS.

pkg/drivers/common/dhcp · high confidence

Initial German and Greek translation files added

Minikube now includes initial localization support for German (de.json) and Greek (el.json), providing translated user-facing messages, help text, and error strings for these languages.

translations · high confidence

Initial deployment of Kong Ingress Controller addon

Adds the initial configuration files for the Kong Ingress Controller addon, including the Kubernetes Namespace, CustomResourceDefinitions (such as IngressClassParameters and KongClusterPlugin), and the controller deployment template. This enables users to install and manage the Kong Ingress Controller within the cluster.

deploy/addons/kong · high confidence

Initial release of the Linux .deb installer for minikube

A new Debian package (.deb) installer has been added for minikube, allowing users to install the tool on Debian-based Linux distributions. The package configuration defines minikube as an optional base package, sets the architecture dynamically, and includes a recommendation for VirtualBox to support local Kubernetes cluster creation.

installers/linux/deb · high confidence

Initial support for localized console messages

Minikube now detects the user's system locale and translates console output messages into the user's preferred language. The new \pkg/minikube/translate\ package loads language-specific JSON files (e.g., \en.json\, \fr.json\) embedded in the binary, falling back to American English if a translation is missing or the locale cannot be determined. This allows non-English speaking users to see Minikube's status and error messages in their native language.

pkg/minikube/translate · high confidence

Inspektor Gadget addon deployment manifest added

The deployment configuration for the Inspektor Gadget addon is now provided via a new Helm-style template file (ig-deployment.yaml.tmpl). This file defines the complete Kubernetes resource set required to run the gadget operator, including the Namespace, ServiceAccount, RBAC ClusterRoles/ClusterRoleBindings, and the DaemonSet that runs the gadgettracermanager container. Users deploying this addon will now have these resources generated from the template, ensuring consistent installation of the gadget monitoring stack.

deploy/addons/inspektor-gadget · high confidence

Introduce Dockerized minikube ISO build environment

Adds a new Dockerfile and Buildroot external tree configuration to the minikube-iso location, establishing a containerized build environment based on Ubuntu 24.04. This setup provides the necessary toolchain (including gcc-multilib for x86\_64) and caching directories (ccache, gocache) to build the minikube ISO using Buildroot, replacing previous ad-hoc or host-dependent build methods.

deploy/iso/minikube-iso · high confidence

Introduce GCP Authentication Addon with mutating webhook

Adds the GCP authentication addon, which deploys a namespace, service, and deployment to handle GCP credential injection. The addon uses a mutating webhook to automatically inject GCP credentials into pods, supporting both real credentials via host-mounted files and mock credentials for testing via the MOCK\_GOOGLE\_TOKEN environment variable. It also includes a certificate generation job and RBAC rules to manage the webhook configuration securely.

deploy/addons/gcp-auth · high confidence

Introduce KIC driver for running Kubernetes in containers

This change adds the KIC (Kubernetes In Containers) driver, allowing minikube to run the cluster inside a container using the kicbase image (v0.0.51) instead of a virtual machine. The driver supports both Docker and Podman runtimes, enabling features such as static IP assignment, custom network configuration, GPU passthrough, and host port forwarding. It also includes logic to handle preloaded image tarballs and manages container lifecycle operations like creation, deletion, and status reporting.

pkg/drivers/kic · high confidence

Introduce OCI driver infrastructure with cgroup, CLI runner, and network management

The \pkg/drivers/kic/oci\ package now provides the core infrastructure for the KIC driver, including Linux-specific cgroup detection for memory limits, a centralized CLI runner for executing Docker and Podman commands with slow-execution warnings, and comprehensive network creation and inspection logic. This change adds support for both Docker and Podman runtimes, handling platform-specific details such as rootless mode detection, gateway IP resolution, and port forwarding, while introducing specific error types for better failure diagnostics.

pkg/drivers/kic/oci · high confidence

Introduce QEMU2 driver with socket\_vmnet networking and serial logging

The QEMU driver has been forked into a new 'qemu2' implementation that replaces the legacy user networking with socket\_vmnet for improved network stability and performance. This change introduces new configuration flags for socket\_vmnet paths, adds support for creating extra disks on VMs, and enables serial log capture for better debugging. Additionally, the driver now includes specific handling for macOS hardware acceleration detection and provides clearer user advice when firewall or permission issues block the network.

pkg/drivers/qemu · high confidence

Introduce SSH driver for remote host management

The SSH driver has been added to allow Minikube to manage Kubernetes clusters on existing remote hosts via SSH, replacing the previous generic driver implementation. This driver handles SSH key validation, imports keys into the machine store, and automatically adds the user to the Docker group when the Docker container runtime is selected. It also provides core lifecycle methods such as creating, starting, stopping, and checking the state of the remote host.

pkg/drivers/ssh · high confidence

Introduce SSH utility package for VM connectivity

Added a new sshutil package that provides core SSH client creation and host verification capabilities for connecting to Minikube VMs. The NewSSHClient function establishes SSH connections using driver-provided host details, automatically falling back to the default \~/.ssh/id\_rsa key if no specific key path is configured, and includes retry logic to handle transient connection failures. Additionally, the package introduces a KnownHost function to verify whether a remote host is present in the known\_hosts file, supporting both plain and hashed hostname lookups to ensure secure and reliable remote command execution.

pkg/minikube/sshutil · high confidence

Introduce auto-pause addon with HAProxy-based API server interception

The auto-pause addon now deploys a local HAProxy proxy (auto-pause-proxy) that intercepts Kubernetes API server traffic on port 6443. Using a custom Lua script (unpause.lua), the proxy checks whether the cluster is paused and blocks or allows requests accordingly, while an env-inject webhook deployment handles environment variable injection for inner-cluster requests. The service is configured via auto-pause.service.tmpl to run with a configurable container runtime and pause interval, and the entire addon is built using a Go 1.26.5-based Dockerfile for the hook component.

deploy/addons/auto-pause · high confidence

Introduce auto-pause binary for automatic container pausing

A new auto-pause command-line tool has been added to automatically pause and unpause Kubernetes containers based on inactivity. The binary starts an HTTP server on port 8080 that accepts requests to trigger an unpause; if no unpause request is received within a configurable interval (defaulting to one minute), the tool pauses containers in the 'kube-system' namespace. It supports selecting the container runtime via the --container-runtime flag and checks the current pause state on startup.

cmd/auto-pause · high confidence

Introduce automated flake rate tracking and GitHub issue management

This change adds a new suite of scripts and tools in \hack/jenkins/test-flake-chart\ to automatically collect test data, compute flake rates, and manage GitHub issues for failing tests. The system includes \collect\_data\_manual.sh\ and \upload\_tests.sh\ to gather and store test summaries in GCS, \compute\_flake\_rate.go\ to calculate flake percentages and average durations, and \compute\_flake\_rate.sh\ to orchestrate the analysis and automatically create, update, or close GitHub issues based on configurable thresholds. The \flake\_chart.html\ and \flake\_chart.js\ files provide a web interface for visualizing flake rates and test durations over time, with support for sorting and filtering by environment and test name.

hack/jenkins/test-flake-chart · high confidence

Introduce centralized version management package

A new \pkg/version\ package has been added to centralize version information for the application. This package exposes functions to retrieve the current minikube version, the git commit ID used for the build, the ISO version, and the storage provisioner version. These values are designed to be injected at compile time via linker flags, allowing users to accurately identify the specific build and its associated component versions.

pkg/version · high confidence

Introduce minikube tunnel for local LoadBalancer service access

The \minikube tunnel\ command is now available, allowing users to access Kubernetes services of type LoadBalancer locally. This feature introduces a tunnel agent that manages host routing rules (via \ip route\ on Linux, \route\ on macOS/FreeBSD) to direct traffic for the cluster's service CIDR to the minikube VM. It also includes a LoadBalancer emulator that patches service status fields to expose the local gateway IP as the ingress address, and a persistent registry to track active tunnel instances and prevent conflicts. The implementation is cross-platform, with specific routing and DNS resolver logic for macOS, Linux, and FreeBSD, and includes comprehensive tests for the registry, patcher, and route management.

pkg/minikube/tunnel · high confidence

Introduce mkcmp binary for comparing minikube performance

Added the mkcmp tool, which compares the performance of two minikube binaries by running 'minikube start' three times for each and outputting a Markdown comparison table. The tool accepts binary paths or PR references (e.g., pr://400) and is primarily used by the pr-bot to comment on PRs with performance data.

cmd/performance/mkcmp · high confidence

Introduce mustload package for robust cluster loading and health verification

The new \pkg/minikube/mustload\ package centralizes the logic for loading minikube clusters, providing functions like \Running\ and \Healthy\ that verify the control plane's status and API server availability before returning a usable cluster controller. This change improves error handling by offering specific, user-friendly exit messages for scenarios such as missing profiles, non-running nodes, or unreachable API servers, and adds a partial test to validate the cluster loading mechanism.

pkg/minikube/mustload · high confidence

Introduce performance comparison tool for minikube binaries

The \pkg/minikube/perf\ package now provides a tool to compare the startup performance of two minikube binaries, such as a pull request build versus the current HEAD. It supports downloading binaries directly from GCS using a \pr://\ prefix, timing \minikube start\ and \minikube addons enable ingress\ commands across various driver and runtime combinations (e.g., docker/containerd), and reporting the results in a structured table that highlights significant performance regressions.

pkg/minikube/perf · high confidence

Introduce structured profile and cluster configuration models

Minikube now uses dedicated Go structs (Profile, ClusterConfig, KubernetesConfig, Node) to manage cluster settings, replacing the previous flat map-based configuration. This change enables robust validation of profile names, supports multi-node cluster topologies with distinct control-plane and worker nodes, and allows persistent storage of advanced options such as custom addon images, registries, and extra configuration flags. The new structure also introduces profile lifecycle management (create, list, delete) and ensures that critical settings like the driver, container runtime, and Kubernetes version are explicitly tracked and validated.

pkg/minikube/config · high confidence

Introduction of the QEMU2 driver with platform-specific optimizations

A new QEMU2 driver is registered in the driver registry, supporting both amd64 and arm64 architectures with distinct configuration defaults. On macOS, the driver dynamically resolves QEMU firmware paths based on the architecture (Intel vs. Apple Silicon) and applies specific CPU and machine type settings, including conditional high-memory handling for older QEMU versions. On Windows, the driver is marked as experimental, while on other platforms it is enabled by default. The implementation also introduces support for custom firmware paths and utilizes deterministic MAC addresses for VM instances.

pkg/minikube/registry/drvs/qemu2 · high confidence

Introduction of the storage provisioner command

A new main entry point for the storage provisioner has been added at cmd/storage-provisioner/main.go. This executable initializes the host path provisioner, ensuring the /tmp directory exists and then starting the storage provisioner logic using the klog library for logging.

cmd/storage-provisioner · high confidence

KVM driver restructured with architecture-specific domain definitions and new capabilities

The KVM driver implementation in pkg/drivers/kvm has been reorganized to support multiple architectures and new hardware features. The driver now uses separate build-tagged files (domain\_definition\_x86.go for amd64 and domain\_definition\_arm64.go for aarch64) to define distinct libvirt domain XML templates, enabling proper support for ARM64 systems with UEFI boot and SCSI CD-ROMs. Additionally, the driver now supports GPU passthrough for NVIDIA devices, the creation of extra virtual disks, and the simulation of NUMA nodes, all of which are configurable via the driver's new fields and integrated into the respective domain XML templates.

pkg/drivers/kvm · high confidence

Kicbase image now supports scheduled container stop and host path automounting

The kicbase base image now includes built-in support for automatically stopping the container after a period of inactivity and for mounting host paths. A new \minikube-scheduled-stop\ systemd service and script allow the container to power off automatically after a configurable sleep duration, while a \minikube-automount\ service ensures that specific host directories (such as \/var/data\ and \/var/hostpath\_pv\) are bind-mounted into the container at startup. These additions are implemented via new systemd unit files and entrypoint scripts within the \deploy/kicbase\ directory.

deploy/kicbase · high confidence

NVIDIA Device Plugin DaemonSet configuration added

The deployment manifest for the NVIDIA Device Plugin has been added as a new DaemonSet resource. This configuration deploys the plugin into the kube-system namespace with system-node-critical priority to ensure availability, mounts the host's device-plugin directory, and configures the container to drop all capabilities and prevent privilege escalation for improved security.

deploy/addons/nvidia-device-plugin · high confidence

New CNI manager package with support for Bridge, Calico, Cilium, Flannel, and KindNet

Minikube now includes a dedicated CNI management package that allows users to select specific Container Networking Interface plugins via the --cni flag. The package introduces managers for Bridge (defaulting to single-node KIC setups), KindNet (defaulting for multi-node or non-docker CRI environments), Calico, Cilium, and Flannel, along with support for custom manifests. It also implements logic to automatically choose the appropriate CNI based on the driver, container runtime, and Kubernetes version, while ensuring compatibility features such as removing appArmor profiles for older Kubernetes versions in Cilium and handling PodDisruptionBudget API versions in Calico.

pkg/minikube/cni · high confidence

New Dev Container configuration for Minikube development

Developers can now launch the project in a GitHub Codespace or local Dev Container with a pre-configured environment for Minikube. The setup includes Docker-in-Docker, kubectl, Helm, Minikube, and Go, along with convenient shell aliases for common Kubernetes commands.

.devcontainer · high confidence

New GitHub release asset utilities

Added a new \pkg/minikube/download/gh\ package that provides helper functions for interacting with the GitHub API, specifically to retrieve release assets by tag and extract their SHA-256 digests. This includes support for optional authentication via the \GITHUB\_TOKEN\ environment variable to improve API rate limits, and unit tests covering digest extraction and error handling for missing assets or digests.

pkg/minikube/download/gh · high confidence

New PR bot for automated performance analysis

A new command-line tool located at cmd/performance/pr-bot has been added to automate performance testing on pull requests. The bot runs in a loop every 10 minutes, identifying open pull requests labeled with 'OkToTest', checking for new commits, and executing the 'mkcmp' performance comparison tool. Upon completion, it posts the resulting performance analysis directly as a comment on the relevant pull request.

cmd/performance/pr-bot · high confidence

New Prow integration test infrastructure and image build targets

This change introduces a comprehensive set of new scripts and Makefile targets in the \hack/prow\ directory to support automated integration testing and image publishing in the Prow CI environment. It adds specific integration test runners for various driver and runtime combinations (Docker, KVM, None) across Linux x86/ARM64 and macOS ARM64, utilizing a shared \common.sh\ for environment setup and dependency installation. Additionally, it provides Makefile targets (\prow.mk\, \prow\_images.mk\) to build and push key Minikube images (kicbase, gvisor, storage-provisioner, kube-registry-proxy, kubernetes-bootcamp) to the staging registry using Docker Buildx for multi-platform support, along with Boskos configuration files for cloud resource management.

hack/prow · high confidence

New addons and registry mirror support

This update introduces several new addons including InAccel FPGA Operator, Rancher Local Path Provisioner, Headlamp, Kubeflow, Yakd, Kubetail, and Cloud Spanner Emulator. It also adds an Aliyun mirror configuration to map standard container images to Alibaba Cloud registries for improved access in restricted networks. Additionally, addon assets are now embedded using Go's embed.FS for more efficient bundling.

deploy/addons · high confidence

New automation scripts for release, conformance, and contributor tracking

The hack directory now includes several new shell scripts to streamline release engineering and community management. \release\_notes.sh\ automates the generation of release notes by fetching recent changes and thanking contributors, reviewers, and triage members. \tag\_release.sh\ handles the creation and pushing of version tags. \conformance\_tests.sh\ automates running Kubernetes conformance tests using Sonobuoy and generates the necessary artifacts for CNCF certification. \update\_contributions.sh\ and \yearly-leaderboard.sh\ automate the generation of contributor leaderboards for specific releases and yearly periods, respectively. Additional utility scripts include \build\_auto\_pause.sh\ for building the auto-pause binary, \cover.sh\ for generating code coverage reports, and \generate\_licenses.sh\ for collecting third-party license information.

hack · high confidence

New changelog generator tool for release notes

A new Go-based changelog generator has been added to the \hack/changelog\ directory. This tool fetches pull requests between two git references from GitHub, classifies them into groups (such as Bug fixes, Addons, Drivers, or Improvements) based on configurable title prefixes, contained keywords, and labels, and outputs a formatted changelog. It supports skipping specific prefixes (like CI or docs), allows sorting of groups, and uses the \go-github\ library (v85) to handle API interactions, including pagination for large commit lists.

hack/changelog · high confidence

New download package with locking, progress tracking, and mirror support

Minikube introduces a dedicated download package that centralizes the retrieval of Kubernetes binaries, ISOs, container images, preload tarballs, and drivers. This change adds file-level locking to prevent concurrent downloads of the same resource, implements progress reporting via both terminal progress bars and structured JSON output, and supports downloading from GitHub releases with Google Cloud Storage as a fallback. It also introduces an Aliyun mirror configuration for users in regions where that source is preferred, and ensures binaries are skipped when the --no-kubernetes flag is set.

pkg/minikube/download · high confidence

New environment detection and Docker Hub rate-limit checking capabilities

Minikube now includes a dedicated detection package that automatically identifies the host's cgroup driver version (v1 or v2) on Linux to ensure proper container runtime configuration, checks for 9p filesystem support, and detects specific environments such as WSL, Google Cloud Shell, GitHub Actions, and macOS 13+. It also adds logic to prevent running the amd64 binary on Apple Silicon (M1) via emulation and verifies the installation paths for socket\_vmnet on macOS. Additionally, users can now check their remaining Docker Hub pull rate limits before attempting to pull images, helping to avoid unexpected failures due to rate limiting.

pkg/minikube/detect · high confidence

New kapi package provides Kubernetes API helper utilities

A new \pkg/kapi\ package has been introduced to centralize Kubernetes API interaction logic, moving functions like \Client\, \ClientConfig\, and \KubectlBinaryPath\ out of other packages to prevent cyclic import dependencies. This package exposes helper functions for waiting on pod and deployment states (\WaitForPods\, \WaitForDeploymentToStabilize\, \WaitForService\) and scaling deployments with retry logic (\ScaleDeployment\), utilizing \klog\ for logging and standard Kubernetes client-go interfaces.

pkg/kapi · high confidence

New kubeconfig package for context and endpoint management

The \pkg/minikube/kubeconfig\ package introduces dedicated functions for managing Kubernetes contexts and cluster endpoints. It adds \GetCurrentContext\, \SetCurrentContext\, and \UnsetCurrentContext\ to control the active context, with \UnsetCurrentContext\ now safely only clearing the context if the specified profile matches the current one. The package also provides \UpdateEndpoint\ and \VerifyEndpoint\ to repair missing or invalid cluster settings and update server addresses in the kubeconfig file. Additionally, it introduces an \Extension\ struct to store metadata like provider and version in the kubeconfig, and implements file locking for safe concurrent updates.

pkg/minikube/kubeconfig · high confidence

New kverify package for granular cluster health checks

The bootstrapper now includes a new \kverify\ package that provides detailed, component-specific health checks for the Kubernetes cluster. This adds support for waiting on the default service account, verifying node readiness and pressure conditions (disk, memory, PID, network), and ensuring specific system pods and applications are running. It also introduces cgroup v2 support for checking the API server's frozen state and allows users to control which components are waited for during startup via the \--wait\ flag.

pkg/minikube/bootstrapper/bsutil/kverify · high confidence

New macOS vfkit driver for virtualization.framework

Minikube now includes a new driver for macOS that leverages Apple's Virtualization.framework (vfkit), offering an alternative to the existing hyperkit and qemu drivers. This driver supports shared networking via vmnet-helper, allows for Rosetta support in guest VMs, and integrates with common driver features like deterministic MAC addresses and virtiofs mounts.

pkg/drivers/vfkit · high confidence

New macOS vfkit driver with shared networking and Rosetta support

Minikube now includes a new vfkit driver for macOS, registered as the preferred driver on Darwin systems. This driver supports shared networking via the vmnet-helper, allows Virtiofs mounts for host directory sharing, and includes support for Apple Rosetta 2 emulation. It also uses deterministic MAC addresses and requires the vfkit binary to be installed via Homebrew.

pkg/minikube/registry/drvs/vfkit · high confidence

New metrics collection script for monitoring minikube start performance

Added a new Go-based metrics script in hack/metrics that automates the measurement of minikube start times across different container runtimes (docker, containerd, crio). The script downloads the latest minikube binary, runs start commands in a loop, and exports latency data to Google Cloud Monitoring and Cloud Trace via the OpenTelemetry API. It supports custom labeling via a --label flag and allows specifying a temporary file path for the minikube binary via a --file flag, enabling automated performance tracking and regression prevention.

hack/metrics · high confidence

New minikube config subcommands for managing addons and settings

The \minikube config\ command now includes several new subcommands to manage cluster configuration and addons. Users can list available addons and their status with \minikube config addons list\ (supporting \--output json\ and \--docs\ flags), enable or disable specific addons via \minikube config addons enable\ and \minikube config addons disable\, and configure addon-specific settings interactively or via a config file using \minikube config addons configure\. Additionally, \minikube config defaults\ allows users to view valid default values for configuration properties in plain text, JSON, or YAML format. The \minikube config get\ command remains available for retrieving individual configuration values.

cmd/minikube/cmd/config · high confidence

New network package for subnet inspection and reservation

A new \pkg/network\ package has been introduced to centralize network parameter inspection and subnet management. It provides the \Inspect\ function to derive network details (CIDR, gateway, broadcast, client IP ranges) from an IP address, and \FreeSubnet\ to locate an available private subnet, incorporating logic to handle subnet reservation and race conditions via file locking. The package also includes \IsBuiltinQEMU\ to identify QEMU-based builtin networks and \ParseAddr\ for robust address parsing, supported by unit tests for subnet finding and address validation.

pkg/network · high confidence

New performance monitoring bot for PR comparisons

Added a new performance monitoring package (pkg/perf/monitor) that enables an automated bot to compare minikube builds. The bot authenticates with GitHub using the GITHUB\_ACCESS\_TOKEN environment variable, identifies open pull requests labeled 'ok-to-test' in the kubernetes/minikube repository, and runs a comparison tool (mkcmp) between the PR's build and the master branch. It then posts the results as comments on the relevant pull requests.

pkg/perf · high confidence

New process management library with cross-platform process detection and control

The \pkg/minikube/process\ package now provides a unified interface for managing subprocesses, replacing the previous implementation. It introduces functions to write and read PID files, check if a specific process (identified by PID and executable name) exists, and safely terminate or kill processes. The implementation uses \gopsutil/v4\ for cross-platform process inspection and includes platform-specific optimizations (using \os.FindProcess\ and signal checks on Unix, and \OpenProcess\ on Windows) to ensure robust process existence checks. Comprehensive tests verify behavior for existing, non-existing, and unresponsive processes.

pkg/minikube/process · high confidence

New prune-translations tool to remove stale translation keys

A new command-line tool has been added at cmd/prune-translations that automatically removes translation keys from language JSON files when those keys are no longer present in the source strings.txt file. This helps keep translation files clean and consistent with the current codebase by deleting obsolete entries while preserving valid ones.

cmd/prune-translations · high confidence

New retry utility package with improved logging and backoff

A new \pkg/util/retry\ package has been added, providing \Local\ and \Expo\ functions for retrying operations with exponential backoff. This implementation upgrades the underlying \cenkalti/backoff\ library to v7 and introduces a logging mechanism that deduplicates identical error messages to reduce log noise, while also flagging persistent errors as potentially stuck after a configurable threshold.

pkg/util/retry · high confidence

New storage class management utilities

Added a new \pkg/minikube/storageclass\ package that provides functions to manage Kubernetes storage class annotations. This includes \DisableDefaultStorageClass\ to mark a specific storage class as non-default, and \SetDefaultStorageClass\ to ensure only one specified storage class is marked as the default among all available classes. The package also includes a helper to retrieve the storage v1 client interface and comes with unit tests covering success and error scenarios for these operations.

pkg/minikube/storageclass · high confidence

New style package for consistent terminal output and low-fi fallbacks

A new \pkg/minikube/style\ package centralizes terminal styling, providing ANSI color codes (green, red, reset) and a comprehensive set of emoji-based prefixes for various status messages (e.g., success, failure, provisioning). It introduces a \LowPrefix\ mechanism that automatically falls back to 7-bit compatible text prefixes (like \\* \ or \! \) for terminals that do not support emojis, ensuring consistent readability across different environments. The package also defines configuration options for spinner behavior and sub-step visibility, allowing for more structured and visually distinct command-line output.

pkg/minikube/style · high confidence

New sysinit package for unified service management across init systems

A new \pkg/minikube/sysinit\ package has been added to provide a unified abstraction for managing services on both systemd and OpenRC-based VMs. This change introduces a \Manager\ interface that automatically detects the host's init system and routes commands accordingly. For systemd, it now sets \SYSTEMCTL\_SKIP\_SYSV=1\ to prevent interaction with SysV scripts, adds journalctl logs to error messages for better debugging, and explicitly prevents enabling the \kubelet\ service to avoid race conditions. For OpenRC, it implements service start, stop, restart, and status checks, along with a shim script to emulate systemd restart behavior. This allows Minikube to handle service lifecycle consistently regardless of the underlying init system.

pkg/minikube/sysinit · high confidence

New tool to report test flakiness from GCP storage

Added a new Go-based utility in \hack/jenkins/test-flake-chart/report\_flakes\ that fetches test summaries and pre-calculated flake rates from Google Cloud Storage (GCS) and generates a Markdown comment. The tool reads a list of environments, retrieves per-environment test results (pass/fail/skip counts and durations) from the \minikube-builds\ GCS bucket, and combines them with historical flake rates from the \minikube-flake-rate\ bucket to produce a sorted table of failing tests ranked by their flake rate, helping users identify unstable tests in pull requests.

_hack/jenkins/test-flake-chart/report\flakes · high confidence

New translation string extraction tool for localization

Added the \pkg/minikube/extract\ package, a new internal tool that scans the minikube Go source code to identify and extract translatable strings. This tool supports extracting standard user-facing messages, command-line help text, and specific 'Advice' strings from error handling maps (such as \known\_issues.go\). It filters out non-translatable content like URLs, code snippets, and internal identifiers, then outputs the collected strings to JSON files to facilitate the localization of the minikube CLI interface into multiple languages.

pkg/minikube/extract · high confidence

New unified container runtime management package

Minikube introduces a new \pkg/minikube/cruntime\ package that centralizes the management of container runtimes (Docker, containerd, and CRI-O) behind a common interface. This change standardizes how Minikube handles runtime-specific operations such as configuration generation, image loading, and container lifecycle management, while also adding support for pausing and unpausing containers across CRI runtimes. Additionally, a new \pkg/minikube/docker\ package manages Docker reference stores to ensure image tags are correctly preserved after preloading.

pkg/minikube/cruntime · high confidence

New update notification system with beta release support and Aliyun mirror

Minikube now includes a dedicated update notification package that checks for new versions by fetching release data from Google Cloud Storage (releases-v2.json) or an Aliyun mirror. The system supports opt-in notifications for beta releases, allowing users to receive alerts for pre-release versions via a separate configuration flag. Users are provided with clear instructions on how to disable these notifications using minikube config commands, and the update check respects user preferences for non-interactive and JSON output modes.

pkg/minikube/notify · high confidence

New utility functions for certificate generation, IP calculation, and size parsing

The \pkg/util\ package now includes new capabilities for managing cluster resources and security. It introduces \ServiceClusterIP\ and \DNSIP\ functions to automatically calculate the first IP and DNS IP (x.x.x.10) from a service CIDR, and \CalculateSizeInMB\ to parse human-readable size strings (e.g., '1g', '1024mb') into megabytes using binary suffixes. Additionally, \GenerateCACert\ and \GenerateSignedCert\ provide utilities for creating and signing X.509 certificates, with the CA certificate's \NotBefore\ set 24 hours in the past to avoid time drift issues. These changes are accompanied by unit tests for the new functions.

pkg/util · high confidence

New virtiofs mount validation and setup logic for macOS

Added a new \pkg/drivers/common/virtiofs\ package (Darwin-only) that parses, validates, and configures virtiofs shared directories. Users can now specify host-to-guest mount paths (e.g., \/host:/guest\), which are validated to ensure both paths are absolute, the host path exists and is a directory, and it does not contain the comma separator used by underlying tools. The package also provides a \SetupMounts\ function that executes SSH commands to create the guest mount point and mount the virtiofs filesystem, with corresponding tests added to verify parsing and validation logic.

pkg/drivers/common/virtiofs · high confidence

Scheduled stop daemonization now supports Unix and Windows platforms

The scheduled stop feature now properly daemonizes the process to ensure the cluster shuts down at the specified time, regardless of the user's terminal session. On Unix systems, the process is backgrounded using godaemon and its PID is tracked in a file for cleanup. On Windows, the implementation leverages a systemd-like service (minikube-scheduled-stop) running inside the VM/container, configured with the sleep duration via an environment file. The logic also ensures that the scheduled stop configuration is only saved to the profile if the daemonization succeeds, and it explicitly skips scheduling for the 'none' driver which does not support this backgrounding mechanism.

pkg/minikube/schedule · high confidence

Structured JSON event logging for minikube operations

The minikube output system now emits structured JSON events based on the CloudEvents specification for key lifecycle actions, including step progress, downloads, warnings, info, and errors. This change introduces a new \register\ package that tracks execution steps (such as 'Initial Minikube Setup', 'Configuring CNI', and 'Deleting') and formats them into JSON payloads containing step names, indices, and messages. Users can now consume machine-readable logs for automation or monitoring, with support for recording these events to a file via \SetEventLogPath\ and configuring the output destination.

pkg/minikube/out/register · high confidence

Support for Ingress and LoadBalancer services on macOS with Docker driver

The KIC tunnel implementation now supports tunneling for Kubernetes Ingress resources and LoadBalancer-type Services when using the Docker driver on macOS. This change introduces a new ServiceTunnel for direct service access and enhances the SSHTunnel to reconcile Ingress resources, allowing users to access these resources locally. The implementation uses random local ports for service tunnels to avoid privilege requirements and handles sudo prompts for privileged ports on non-Windows systems, while providing specific warnings for Windows users regarding port access limitations.

pkg/minikube/tunnel/kic · high confidence

VirtualBox driver now supports macOS Apple Silicon (darwin/arm64) with version checks

The VirtualBox driver registration in the minikube registry now includes specific support for macOS on Apple Silicon. The driver probes the installed VirtualBox version and enforces a minimum requirement of version 7.1 for darwin/arm64, returning a clear error if an older version is detected. It also issues a recommendation to upgrade to 7.2+ for stability. Additionally, the driver automatically disables shared folders (NoShare) on darwin/arm64 because the minikube ISO lacks the necessary VirtualBox Guest Additions for that architecture.

pkg/minikube/registry/drvs/virtualbox · high confidence

VirtualBox driver refactored to support macOS host-only networking on Apple Silicon

The VirtualBox driver in \pkg/drivers/virtualbox\ has been restructured to support darwin/arm64 by introducing a new \hostOnlyNet\ abstraction that uses the VirtualBox 7.1+ \hostonlynet\ API instead of the legacy \hostonlyif\ interface. This change adds new files (\network\_hostonlynet.go\, \network\_hostonlynet\_test.go\) to manage modern host-only networks, updates the main driver (\virtualbox.go\) and network logic (\network.go\) to utilize this new API, and includes comprehensive unit tests for the new networking and disk creation logic.

pkg/drivers/virtualbox · high confidence

Architecture

Extracted command runner interface and implementations into a dedicated package

The command execution logic has been refactored into a new \pkg/minikube/command\ package, introducing a unified \Runner\ interface with methods for running commands (\RunCmd\, \StartCmd\, \WaitCmd\) and managing files (\Copy\, \CopyFrom\, \Remove\). This change consolidates previously scattered execution logic into specific implementers: \SSHRunner\ for remote SSH execution, \execRunner\ for local command execution, and \kicRunner\ for running commands inside the KIC container. A \FakeCommandRunner\ is also provided for testing, ensuring consistent command output handling across all execution paths.

pkg/minikube/command · high confidence

Internalize libmachine from docker/machine

The \pkg/libmachine\ package has been internalized from the external \docker/machine\ repository into the minikube codebase. This change introduces the full set of machine management components—including authentication, certificate bootstrapping, driver interfaces, and RPC plugin communication—directly under \pkg/libmachine\, allowing minikube to maintain its own version of the machine logic without depending on the upstream docker-machine project.

pkg/libmachine · high confidence

Refactor bootstrapper utilities into the bsutil package

The bootstrapper logic has been reorganized into the new \pkg/minikube/bootstrapper/bsutil\ package, consolidating previously scattered functionality into focused modules. This includes \binaries.go\ for managing Kubernetes binary transfers, \kubeadm.go\ for generating kubeadm configuration files with support for multiple API versions (v1beta1 through v1beta4), \kubelet.go\ for generating systemd unit files, \extraconfig.go\ for handling component-specific extra arguments, and \featuregates.go\ for parsing feature gate configurations. The refactoring also introduces version-specific option handling in \versions.go\ and adds comprehensive unit tests for these components to ensure correct behavior across different Kubernetes versions.

pkg/minikube/bootstrapper/bsutil · high confidence

Restructure x86\_64 ISO build with architecture-specific package definitions

The x86\_64 ISO build configuration has been reorganized into a dedicated architecture-specific directory structure. This change introduces new Buildroot package definitions for core container runtime components (buildkit, containerd, cri-dockerd, crictl, docker, docker-buildx, nerdctl) and system tools (cni-plugins, helm, hyperv-daemons, vbox-mount-service). Each component now has its own configuration, hash, and build script files, allowing for independent version management and clearer separation of concerns within the ISO build process.

_deploy/iso/minikube-iso/arch/x86\64 · high confidence

Behavioural changes

Add Hyper-V driver implementation to minikube

The Hyper-V driver, previously located in the docker/machine repository, has been moved into minikube under pkg/drivers/hyperv. This change introduces the core driver logic (hyperv.go) and PowerShell helper utilities (powershell.go) required to manage Hyper-V virtual machines, including configuration flags for CPU, memory, disk size, and virtual switch selection, as well as checks for Hyper-V availability and administrator privileges.

pkg/drivers/hyperv · high confidence

Add-on system refactored to support custom images, registries, and Helm charts

The \pkg/minikube/assets\ package has been restructured to provide a more flexible add-on management system. The \Addon\ struct now includes dedicated fields for \Images\, \Registries\, and \HelmChart\, allowing users to specify custom container images, override image registries, and deploy add-ons via Helm charts. This change introduces logic to persist custom image and registry settings per profile, ensuring that user overrides are maintained across restarts. Additionally, support for Aliyun mirrors has been added to automatically resolve and substitute image references for users in restricted network environments.

pkg/minikube/assets · high confidence

Added placeholder for boot2docker directory in Minikube ISO rootfs

The Minikube ISO build process now ensures the existence of the /var/lib/boot2docker directory in the root filesystem overlay for both aarch64 and x86\_64 architectures. This is achieved by adding empty .keep files to these paths, preventing the directory from being omitted during the ISO creation if it is otherwise empty.

_deploy/iso/minikube-iso/board/minikube/aarch64/rootfs-overlay/var, deploy/iso/minikube-iso/board/minikube/x86\64/rootfs-overlay/var · high confidence

Addon management logic reorganized into dedicated package

The addon enablement and configuration logic has been moved from the main application into the new \pkg/addons\ package. This change introduces a structured \Addon\ definition in \config.go\ that separates validation, setting, and callback functions, allowing for more modular handling of individual addons. The core \addons.go\ file now manages the lifecycle of these addons, including pre- and post-start messages for specific addons like Headlamp and Traefik, and handles deprecation warnings for addons such as EFK and the old NVIDIA GPU plugin. Additionally, specific addon behaviors are isolated in their own files (e.g., \addons\_gcpauth.go\ for GCP authentication, \addons\_autopause.go\ for auto-pause, and \addons\_storage\_classes.go\ for storage class management), and a new \helm.go\ module provides utilities for installing and managing Helm charts within the guest environment.

pkg/addons · high confidence

Auto-enables control-plane load balancing in HA clusters

The HA cluster configuration now automatically enables kube-vip's control-plane load balancing feature when the underlying environment supports it (specifically when IPVS kernel modules are available and kube-proxy is not using IPVS mode). This reduces manual configuration steps for users setting up multi-control-plane clusters, as the system detects the necessary prerequisites and configures the load balancer accordingly.

pkg/minikube/cluster/ha · high confidence

Automatic unblocking of bootpd on macOS with socket\_vmnet

Minikube now detects when the macOS built-in firewall blocks the bootpd process (required for QEMU2 with socket\_vmnet) and automatically adds and unblocks it. The implementation handles macOS 15+ firewall states and respects the --interactive=false flag by using sudo -n for non-interactive execution, falling back to password prompts if necessary.

pkg/minikube/firewall · high confidence

Boilerplate checking tool rewritten in Go with new file-type support

The boilerplate checking utility in hack/boilerplate has been rewritten from Python to Go, introducing a new executable (boilerplate.go) that validates file headers for Go, Python, shell, Makefile, and Dockerfile formats. This change adds specific boilerplate templates for Dockerfiles and Makefiles, enables a verbose mode for debugging, and updates the fix.sh script to leverage the new Go tool for automatically correcting missing or incorrect license headers across these file types.

hack/boilerplate · high confidence

CRI-O container runtime upgraded to v1.35.0 with updated configuration and systemd integration

The CRI-O container runtime included in the Minikube ISO has been upgraded from v1.29.1 to v1.35.0, bringing the latest upstream features and security fixes. This update includes a new Buildroot package definition (\crio-bin.mk\) that installs the static binaries for both amd64 and arm64 architectures, along with updated configuration files (\crio.conf\, \02-crio.conf\) that enforce the \systemd\ cgroup manager and standard socket paths. The ISO now also installs a dedicated systemd service unit (\crio.service\) that ensures CRI-O starts after \minikube-automount.service\, and includes necessary supporting configuration files like \policy.json\ and \registries.conf\ to handle image signing and registry search defaults.

deploy/iso/minikube-iso/package/crio-bin · high confidence

Centralize VM guest path constants

The vmpath package now provides a centralized set of constants defining standard directories within the Minikube VM, such as /etc/kubernetes/addons, /var/lib/minikube, and /etc/ssl/certs. This change consolidates previously scattered path definitions into a single source of truth, ensuring consistent directory usage across the codebase for addons, manifests, ephemeral data, and certificates.

pkg/minikube/vmpath · high confidence

Centralized Kubernetes image version management for the bootstrapper

The bootstrapper now uses a centralized image management system that automatically resolves correct image tags for Kubernetes components (kube-apiserver, etcd, coredns, pause) based on the target version, falling back to the latest known minor version or kubeadm metadata if a specific tag is missing. This ensures that minikube pulls the exact images required by the requested Kubernetes release, including updated defaults for newer versions (e.g., pause 3.9, etcd 3.5.7-0) and correct repository prefixes (registry.k8s.io). It also standardizes CNI plugin images (Calico v3.32.2, kindnetd v20260820) and the storage provisioner, ensuring consistency across different mirror configurations.

pkg/minikube/bootstrapper/images · high confidence

Centralized browser URL opening with Linux fallback

The browser package now provides a centralized OpenURL function that attempts to open the default system browser. On Linux systems, it includes a fallback mechanism: if the xdg-open utility is not found, it prints the URL using styled output instead of failing, ensuring users can still access the link even in minimal environments.

pkg/minikube/browser · high confidence

Centralized path management and legacy certificate migration

The new localpath package centralizes all minikube directory and file path resolution, including the MINIKUBE\_HOME environment variable logic, profile paths, and machine paths. It introduces per-profile client certificates (client.crt/key) while automatically detecting and migrating legacy v1.5.x certificates from the root .minikube directory to the new profile structure. The package also adds support for storing transient status in event logs, outputs the last start log during minikube logs, and includes Windows-specific path sanitization for Docker image references and drive letter handling.

pkg/minikube/localpath · high confidence

Consolidated driver registry and platform-specific support lists

The driver detection and selection logic has been consolidated into the \pkg/minikube/driver\ package, introducing a unified registry that manages driver availability, health status, and priority across platforms. This change introduces new supported drivers including \podman\, \vfkit\, and \krunkit\, while adding aliases such as \kvm\ for \kvm2\ and \native\ for \none\. Platform-specific support lists are now defined in dedicated files (\driver\_darwin.go\, \driver\_linux.go\, \driver\_windows.go\, \driver\_freebsd.go\), ensuring that the correct set of drivers (e.g., \HyperKit\ on macOS x86, \VFKit\/\Krunkit\ on macOS ARM64) is presented to the user. The system now explicitly handles driver health, rejecting unhealthy drivers and deprioritizing discouraged ones during auto-selection, and standardizes endpoint resolution for control plane access across different driver types.

pkg/minikube/driver · high confidence

Deterministic MAC addresses and macOS 26+ vmnet-helper support

The vmnet driver now generates deterministic MAC addresses for virtual machines based on their names, ensuring consistent network identities across restarts. On macOS 26 and later, the vmnet-helper process runs as an unprivileged user (no longer requiring sudo) and is located via Homebrew paths, while older macOS versions continue to use the legacy installation path. Validation is also skipped in download-only mode to prevent unnecessary checks.

pkg/drivers/common/vmnet · high confidence

Docker driver version validation and status checks

The Docker driver now enforces a minimum Docker Engine version of 18.09.0 and recommends 20.10.0, while explicitly blocking the known problematic Docker Desktop 4.16.0 on macOS. It also prevents using an amd64 minikube binary on arm64 machines and provides specific error codes and fix instructions for issues like missing Docker installation, version mismatches, and daemon info failures.

pkg/minikube/registry/drvs/docker · high confidence

Enable arm64 host builds and update Go/Linux hashes

The ISO build process now supports building on arm64 hosts by patching the Go bootstrap configuration to include aarch64, preventing missing Docker components in the resulting image. Additionally, the build system has been updated with SHA256 hashes for Go versions 1.23.7, 1.25.5, 1.26.2, 1.26.4, and 1.26.5, as well as Linux kernel 6.6.152, to ensure integrity verification for these dependencies.

deploy/iso/minikube-iso/patches · high confidence

Enhanced minikube logs with problem detection and expanded source coverage

The \minikube logs\ command now automatically detects and reports known failure patterns (such as eviction errors, TLS issues, and RBAC misconfigurations) by scanning the last 400 lines of logs from key components like kube-apiserver, etcd, coredns, and kube-proxy. It also includes logs from enabled addons (dashboard, ingress, storage-provisioner, gcp-auth) and displays host/guest distro information. Errors and warnings are now output to stderr, and the command supports outputting to a file via the \--file\ flag and auditing via the \--audit\ flag.

pkg/minikube/logs · high confidence

Forked kubeadm constants and feature gate logic into third\_party

The kubeadm constants and feature gate implementation have been forked into the third\_party directory. This includes new files for platform-specific constants (such as the Docker CRI socket path for Unix and Windows) and a comprehensive feature gate system that manages Kubernetes version compatibility for features like IPv6DualStack, PublicKeysECDSA, and RootlessControlPlane. This change establishes the local foundation for kubeadm's configuration and feature management within this codebase.

_third\party/kubeadm · high confidence

Hyper-V driver registration and health checks

The Hyper-V driver is now registered in the driver registry with a preferred priority and an 8-second probe timeout. The driver includes a health check that verifies Hyper-V availability using Get-CimInstance (with a fallback to Get-Wmiobject) and ensures the user has Administrator or Hyper-V Administrator privileges, providing specific fix instructions if checks fail.

pkg/minikube/registry/drvs/hyperv · high confidence

HyperKit driver deprecated and version-checked on macOS

The HyperKit driver is now registered with a Deprecated priority, meaning it will not be selected by default for new clusters on macOS. Additionally, the driver now enforces a minimum version check (0.20190201); if the installed hyperkit binary is older, the status check fails with a specific error and suggests running 'brew upgrade hyperkit'.

pkg/minikube/registry/drvs/hyperkit · high confidence

Hyperkit driver installation logic moved to auxdriver package with deprecation warning

The logic for downloading, validating, and fixing permissions for the Hyperkit driver has been extracted into the new \pkg/minikube/driver/auxdriver\ package (specifically \install.go\ and \version.go\). This change introduces a warning message informing users that the Hyperkit driver will be removed in the next minikube release and suggests switching to Docker, QEMU, or vfkit. The installation process now explicitly checks for a minimum driver version (1.37.0 is treated as the last release) and validates the driver's presence and version via the \--version\ command before proceeding.

pkg/minikube/driver/auxdriver · high confidence

Hyperkit driver refactored with CGO stubs and improved process detection

The hyperkit driver has been restructured to split CGO-dependent functionality (specifically MAC address resolution via go-vmnet) into separate stub and implementation files, allowing builds without CGO. The driver now uses gopsutil to detect the hyperkit process state, improving reliability by correctly identifying stale PIDs and handling crashes. Additionally, the driver supports extra disks, NFS sharing, and includes version/git-commit information for better diagnostics.

pkg/drivers/hyperkit · high confidence

ISO updated to v1.38.0

The Minikube ISO has been updated to version 1.38.0, bringing in the latest kernel and buildroot improvements for the virtual machine environment.

(repo-wide) · high confidence

Improved error handling and node lifecycle management in minikube start

The node start process now provides more specific, user-friendly advice when fatal errors occur, such as Docker Desktop being configured for Windows containers, insufficient CPU resources, or incompatible container runtime versions. Additionally, the node addition and deletion workflows have been refined: adding a node now ensures unique machine names across profiles and handles provisioning and starting in a single flow, while deleting a node performs a more robust teardown sequence including draining, resetting the node via kubeadm, and deleting it from the cluster with retry logic to handle leader elections in HA setups. The start process also introduces a new Provisioner interface to encapsulate OS-specific join logic, improving how nodes join the cluster with retry and reset capabilities on Linux.

pkg/minikube/node · high confidence

Improved error handling and user guidance for container runtime failures

The machine package now provides actionable advice when the Docker or Podman daemon is unhealthy or the minikube container exits unexpectedly. A new \advice.go\ module detects these specific errors and suggests steps such as pruning unused images, restarting the daemon, or recreating the cluster. Additionally, the \delete.go\ module has been updated to automatically clean up orphaned KIC containers that lack a minikube config file, preventing stale resources from blocking future operations.

pkg/minikube/machine · high confidence

Improved proxy environment handling and Kubernetes transport configuration

The proxy package now correctly passes proxy environment variables to the Docker engine and handles case-insensitive proxy environment variables (e.g., http\_proxy vs HTTP\_PROXY). It also ensures that the Kubernetes client configuration does not use a proxy by stripping proxy settings from the HTTP transport, even when the transport is wrapped by other RoundTripper implementations. Additionally, the package now supports excluding specific IPs or CIDR blocks from proxy settings via the NO\_PROXY environment variable.

pkg/minikube/proxy · high confidence

Ingress controller deployment template updated for compatibility and runtime support

The ingress deployment template has been updated to support Kubernetes versions prior to v1.19 and to work correctly with the CRIO container runtime. This includes conditionally enabling hostNetwork and ClusterFirstWithHostNet for CRIO environments, setting the ingress webhook port to 8444 for CRIO (versus 8443 otherwise), and adjusting RBAC rules to support older API versions (v1beta1). The template also removes deprecated annotations like 'allow-snippet-annotations' and fixes the leader election configmap resource name to ensure stable operation across different cluster configurations.

deploy/addons/ingress · medium confidence

Ingress-DNS addon now supports custom registries and updated RBAC

The ingress-dns addon template has been updated to allow the container image to be pulled from a custom registry by respecting the \CustomRegistries.IngressDNS\, \ImageRepository\, and \Registries.IngressDNS\ configuration fields, with the pull policy set to \IfNotPresent\. Additionally, the Kubernetes RBAC resources have been migrated to the stable \rbac.authorization.k8s.io/v1\ API version to ensure compatibility with newer Kubernetes clusters.

deploy/addons/ingress-dns · high confidence

Internal VMware driver implementation added

The VMware driver has been copied from the external docker/machine repository into the internal minikube package (pkg/drivers/vmware). This change introduces the core driver files (config, driver, vmrun, vmx) and platform-specific implementations for macOS, Linux, and Windows, enabling minikube to manage VMware-based virtual machines using its own internal codebase rather than relying on the external library.

pkg/drivers/vmware · high confidence

Introduce dedicated Buildroot and Ubuntu provisioners with improved certificate handling

The provision package now includes specific provisioners for Buildroot and Ubuntu hosts, replacing the previous generic logic. These provisioners generate tailored systemd unit files for Docker, including support for the DOCKER\_RAMDISK environment variable on rootfs filesystems and explicit ulimit settings. Additionally, the certificate generation process has been updated to automatically include 'minikube' and the machine name in the server certificate's Subject Alternative Names (SANs), ensuring reliable TLS connectivity for these host types.

pkg/provision · high confidence

Introduce dedicated error handling and cross-platform path logic in the kubeadm bootstrapper

The kubeadm bootstrapper now includes a dedicated error definitions file (errors.go) that introduces specific error types, such as FailFastError and ErrNoExecLinux, to provide clearer diagnostics when kubeadm binaries are not executable or initialization times out. Additionally, the bootstrapper implementation has been updated to use the standard library path package instead of filepath, ensuring that generated paths remain valid and do not produce malformed Windows-style paths on non-Windows systems or when running in cross-platform environments.

pkg/minikube/bootstrapper/kubeadm · high confidence

Introduce dedicated run options struct

The minikube run package now defines a dedicated CommandOptions struct to hold command-line flags such as NonInteractive and DownloadOnly, replacing the previous reliance on global viper configuration checks for these settings.

pkg/minikube/run · medium confidence

Introduce minikube-based nginx proxy for Kubernetes registry

The kube-registry-proxy image is rebuilt using an nginx-based approach (nginx:1.29.4-alpine-slim) with a custom boot script that configures the proxy via environment variables (REGISTRY\_HOST, REGISTRY\_PORT) and waits for the upstream registry to become available using wget. This replaces the previous implementation, aligning the proxy with the minikube codebase and ensuring compatibility with the alpine-slim base image by avoiding curl.

deploy/images/kube-registry-proxy · high confidence

Introduces structured exit handling with known-issue matching and JSON support

The new \pkg/minikube/exit\ package replaces the previous ad-hoc exit logic with a structured approach that categorizes errors by reason, automatically matches fatal errors against known issues to provide specific advice, and supports structured JSON output for programmatic consumption. Users will see more consistent error reporting, including specific advice for known problems and appropriate exit codes, while shell integrations receive silent output to avoid breaking scripts.

pkg/minikube/exit · high confidence

Isolate minikube delete to current profile resources

The delete operation now strictly targets resources belonging to the current profile by filtering containers, volumes, and networks via the profile label. This prevents accidental deletion of infrastructure shared with or belonging to other profiles, addressing a previous issue where networks from other profiles were inadvertently removed during deletion.

pkg/minikube/delete · high confidence

KVM2 driver status check now validates libvirt group membership and uses domcapabilities

The kvm2 driver's health check now explicitly verifies that the current user belongs to the libvirt group before attempting to run virsh commands, preventing slow timeouts and providing a clear permission error if access is denied. Additionally, the driver detection command has switched from virt-host-validate to virsh domcapabilities for more accurate behavior, and the LIBVIRT\_DEFAULT\_URI environment variable is now explicitly set during these checks to ensure consistent connection behavior.

pkg/minikube/registry/drvs/kvm2 · high confidence

Kubernetes Dashboard addon updated to v2.1.0 with metrics scraper and improved security

The Kubernetes Dashboard addon has been upgraded to version 2.1.0, introducing the dashboard-metrics-scraper component for better performance monitoring. The deployment now runs the dashboard and scraper containers as non-root users with read-only root filesystems to enhance security. Additionally, the dashboard is configured with the --disable-settings-authorizer flag to prevent 403 forbidden errors when accessing settings, and it uses kubectl proxy for exposure instead of a NodePort service.

deploy/addons/dashboard · high confidence

Minikube ISO defconfigs updated to Linux 6.6.152 with systemd-coredump and EFI GRUB support

The Buildroot defconfigs for the Minikube ISO (both aarch64 and x86\_64) have been updated to use Linux kernel version 6.6.152. The configuration now includes systemd-coredump to enable crash stack traces and updates the x86\_64 build to use EFI-based GRUB2 configuration. Additionally, the aarch64 defconfig is newly introduced in this location, standardizing the build settings for ARM64 architectures alongside the existing x86\_64 setup.

deploy/iso/minikube-iso/configs · high confidence

Minikube ISO rootfs configuration and tooling overhaul

The Minikube ISO rootfs overlay has been restructured to improve networking stability, debugging capabilities, and user tooling. Networking is hardened with sysctl tweaks for MTU probing and reverse-path filtering (specifically for Cilium/LXC), DNSSEC is explicitly disabled to prevent resolution failures, and IPv6 is disabled by default. Debugging is enhanced by configuring systemd-journald to volatile storage and enabling systemd-coredump for crash stack traces. A new 'toolbox' utility is added, allowing users to spawn a Fedora-based development environment via systemd-nspawn. Additionally, the SSH daemon configuration is updated to support modern algorithms (ssh-rsa) and higher session limits, while sudoers and fstab are configured to support the new initramfs-based boot process.

_deploy/iso/minikube-iso/board/minikube/x86\64/rootfs-overlay · high confidence

Minikube ISO rootfs configuration and tooling updates

The Minikube ISO rootfs overlay has been restructured to include explicit configuration files for networking, system services, and user tools. Key changes include adding sysctl settings to disable IPv6, increase inotify limits for Kubevirt VMs, and enable TCP MTU probing to prevent network hangs with Docker. DNSSEC validation is explicitly disabled via systemd-resolved to address compatibility issues. The SSH daemon configuration has been updated to allow the ssh-rsa algorithm and increase session limits. Additionally, the ISO now includes a 'toolbox' script for launching Fedora-based development containers, configures systemd-networkd for DHCP on eth1 and eth\*, sets journald to volatile storage, and provides a custom init script for the rootfs overlay.

deploy/iso/minikube-iso/board/minikube/aarch64/rootfs-overlay · high confidence

New common driver package with improved ISO extraction and SSH waiting

The \pkg/drivers/common\ package introduces shared utilities for internal machine drivers, including robust ISO file extraction that automatically handles case-insensitive paths (e.g., finding \bzimage\ in uppercase ISOs) via the \go-diskfs\ library, and an optimized SSH availability check that eliminates unnecessary sleep delays during host startup.

pkg/drivers/common · high confidence

None driver now supports running as a regular user with on-demand sudo

The none driver has been updated to allow execution by non-root users. It now checks for sudo permissions during the status probe and will prompt for sudo access on demand if the user is not root, rather than requiring root privileges from the start. Additionally, the driver is now restricted to Linux platforms via build tags and is registered with a discouraged priority to indicate it provides no isolation.

pkg/minikube/registry/drvs/none · high confidence

None driver supports dynamic container runtime configuration

The none driver now supports dynamic container runtime configuration via JSON unmarshaling, allowing the runtime (e.g., containerd, docker) to be specified in the driver's configuration. This change also introduces a new \cruntime.Manager\ abstraction for managing container lifecycles, improving the reliability of stop and kill operations by gracefully stopping containers before force-killing them, and updates the state detection logic to correctly identify running hosts based on the API server status.

pkg/drivers/none · high confidence

Parallel driver health probing with health-aware prioritization

The driver registry in pkg/minikube/registry now probes all available drivers in parallel with per-driver timeouts, significantly reducing the time spent waiting for driver status checks during startup. The registry introduces a health-aware prioritization system where drivers that fail health checks are automatically downgraded to an 'Unhealthy' priority, ensuring that only healthy drivers are considered for default selection. Additionally, the registry now supports driver aliases, allowing users to reference drivers by alternative names, and provides detailed rejection reasons and improvement suggestions for drivers that are not selected.

pkg/minikube/registry · high confidence

Parallels driver is now built-in and deprecated

The Parallels driver is now included directly in the minikube binary, removing the requirement for users to install a separate external driver binary. However, this built-in driver is marked as deprecated and will not be selected by default, encouraging users to migrate to supported alternatives.

pkg/minikube/registry/drvs/parallels · high confidence

Portainer addon updated to version 2.27.7 with HTTPS support

The Portainer addon has been upgraded from version 2.15.1 to 2.27.7. This update introduces an HTTPS endpoint on port 9443 (NodePort 30779) alongside the existing HTTP port, enabling secure access to the Portainer interface. The configuration also includes updated labels reflecting the new version and ensures the service account has cluster-admin privileges for full cluster management capabilities.

deploy/addons/portainer · high confidence

Redesign of the Minikube ISO build configuration for x86\_64

The build configuration for the Minikube ISO on x86\_64 has been restructured to use a new set of board-specific files. This includes a new \genimage.cfg\ to define the EFI boot image, updated GRUB and isolinux configuration files to streamline the boot process, and a new \linux\_x86\_64\_defconfig\ that enables modern kernel features such as eBPF support, nftables, and VirtioFS. Additionally, the build scripts (\post-build.sh\ and \post-image.sh\) have been updated to handle the new EFI image structure, and the default user configuration now explicitly sets up the \docker\ user with necessary group memberships.

_deploy/iso/minikube-iso/board/minikube/x86\64 · high confidence

Refactor Jenkins CI into modular, reusable integration test scripts

The Jenkins CI infrastructure in hack/jenkins has been restructured from a collection of scattered, monolithic scripts into a modular architecture centered around a shared common.sh (and common.ps1 for Windows) entry point. This new common script handles environment setup, dependency installation (Go, Docker, kubectl, gopogh, gotestsum), and standardized test execution, while specific driver and OS combinations (e.g., linux\_integration\_tests\_docker.sh, cloud\_shell\_functional\_tests\_docker.sh) now act as thin wrappers that configure variables and source the common logic. Additionally, new helper scripts like build\_changelog.sh and investigate\_disk\_usage.sh have been added to automate changelog generation from merged PRs and diagnose build node storage issues, respectively. This change improves maintainability and consistency across the CI pipeline by reducing code duplication and centralizing setup logic.

hack/jenkins · high confidence

Refactor cluster package into focused modules

The monolithic cluster package has been split into separate files to improve maintainability and testability. This change introduces dedicated modules for cluster bootstrapping (cluster.go), IP address resolution across various drivers (ip.go), 9p filesystem mounting (mount.go), cluster pause/unpause operations (pause.go), and status reporting (status.go). Users benefit from more robust error handling in mount and status commands, as well as clearer separation of concerns in the underlying codebase.

pkg/minikube/cluster · high confidence

Refactor service package to use EndpointSlices and improve URL output

The service package has been refactored to replace the deprecated core Endpoints API with the discovery/v1 EndpointSlice API for resolving service targets, ensuring compatibility with modern Kubernetes versions. Additionally, the \minikube service\ command now includes port names in its output alongside URLs, providing clearer context for which port corresponds to which service endpoint.

pkg/minikube/service · high confidence

Refactored certificate management and bootstrapper interface

The bootstrapper package has been restructured to centralize certificate handling and standardize the cluster lifecycle interface. The new \Bootstrapper\ interface explicitly defines methods for cluster operations such as \StartCluster\, \DeleteCluster\, and \UpdateNode\, replacing previous ad-hoc implementations. Certificate logic has been consolidated into \certs.go\, introducing shared CA generation, profile-specific cert generation, and automatic renewal of expired kubeadm certificates. Additionally, the \SetupCerts\ function now correctly handles the copying of essential certificates (like service account keys) from the primary control-plane node to secondary nodes in high-availability setups, and ensures kubeconfig files are generated and persisted for control-plane nodes.

pkg/minikube/bootstrapper · high confidence

Refactored image caching and retrieval logic using go-containerregistry

The image package has been restructured to replace the Docker CLI with the go-containerregistry library for image operations. This change introduces a new cache mechanism that saves images to local tarballs (via \SaveToDir\) and retrieves them using \go-containerregistry\, improving consistency and reducing external dependencies. The refactoring includes new helper functions for handling image tags and digests, better error handling for missing images, and support for platform-specific image retrieval. Users will benefit from more reliable image caching and loading, especially in environments where Docker CLI integration was previously required or problematic.

pkg/minikube/image · high confidence

Registry addon now includes a proxy DaemonSet and updated deployment templates

The registry addon has been updated to include a new \registry-proxy\ DaemonSet (defined in \registry-proxy.yaml.tmpl\) that runs on each node to proxy requests to the central registry, alongside a refactored main registry Deployment (\registry-rc.yaml.tmpl\) and Service (\registry-svc.yaml\). The proxy container exposes host port 5000 and targets the registry service, while the main registry deployment now uses \apps/v1\ API version, sets \imagePullPolicy\ to \IfNotPresent\, and enables storage deletion. These changes improve registry accessibility and reliability across the cluster nodes.

deploy/addons/registry · high confidence

Registry-creds addon now uses Deployment and supports Azure Container Registry

The registry-creds addon has been updated to use a Kubernetes Deployment instead of a ReplicationController, ensuring better lifecycle management. It now supports Azure Container Registry (ACR) by injecting ACR credentials (password, URL, client ID) via environment variables, in addition to existing AWS ECR, Docker Private Registry, and GCR support. The container image is now configurable via template variables (CustomRegistries, ImageRepository, Registries) and defaults to pulling images with the IfNotPresent policy.

deploy/addons/registry-creds · high confidence

Replaces external mutex library with internal flock-based file locking

The lock utility now uses the gofrs/flock library for file-based locking instead of the previous juju/mutex implementation. This change introduces per-user isolation for lock directories (using UID on Unix or home directory hash on Windows) to prevent conflicts in shared temporary directories, and provides new WriteFile and AppendToFile functions that automatically acquire locks to ensure safe concurrent access to files.

pkg/util/lock · high confidence

SSH driver is now opt-in and discouraged by default

The SSH driver has been renamed from 'generic' and is now registered in the driver registry with a default value of false and a priority of 'Discouraged'. This means the SSH driver will no longer be selected automatically when no other driver is specified; users must explicitly choose it. Additionally, the driver now validates that the provided SSH IP address is not localhost or 127.0.0.1, preventing misconfiguration, and correctly resolves SSH keys starting with a tilde to absolute paths.

pkg/minikube/registry/drvs/ssh · high confidence

Standardize logging infrastructure and redirect standard logs to klog

The minikube entry point now implements a unified logging bridge that redirects Go's standard \log\ output and libmachine driver logs into the \klog\ system. This ensures consistent log formatting and allows users to leverage existing klog configuration for log management. The change also introduces logic to generate unique log file names based on command arguments and the current user to prevent collisions, and filters out logs containing environment variables to protect sensitive information.

cmd/minikube · high confidence

Standardized Jenkins installer scripts for CI dependencies

The Jenkins installer scripts in hack/jenkins/installers have been replaced with a new set of dedicated, version-pinned scripts for each tool. Go is now installed via explicit version checks and downloads (v1.26.5) rather than generic package managers, with support for both Linux and macOS (PowerShell). The GitHub CLI (gh) installer now downloads a specific binary (v2.101.0) and handles authentication, while gotestsum and gopogh are installed via go install with pinned versions (v1.13.0 and v0.29.0 respectively). Docker and kubectl installation is now handled by a dedicated script that also adds the jenkins user to the docker group. CNI plugins are installed via a specific script (v1.9.1), and cron jobs for cleanup are installed using gsutil to sync configuration from GCS. This change ensures consistent, reproducible environments for CI nodes by removing reliance on system package managers for these specific tools.

hack/jenkins/installers · high confidence

Storage provisioner addon now uses IfNotPresent image pull policy and configurable registries

The storage-provisioner addon has been updated to use the \IfNotPresent\ image pull policy, which may reduce network traffic and startup time by reusing locally cached images. Additionally, the container image is now configurable via custom registries, allowing users to override the default image source through the \.CustomRegistries.StorageProvisioner\ or \.Images.StorageProvisioner\ template variables.

deploy/addons/olm, deploy/addons/storage-provisioner · high confidence

Structured JSON output and reason-based error reporting for console interactions

The \pkg/minikube/out\ package now supports structured JSON output via the \--output=json\ flag, allowing users to parse machine-readable logs and errors. When JSON mode is active, console output is suppressed in favor of structured events, including detailed error reasons with exit codes, advice, and related issue URLs. This change also introduces a new \reason\-based error handling system that provides consistent, localized error messages with suggestions and documentation links, replacing ad-hoc error printing with a standardized, stylized output mechanism.

pkg/minikube/out · high confidence

Structured error handling and exit codes for minikube

Minikube now uses a structured error-handling system that assigns specific, stable exit codes and actionable advice to various failure scenarios. This change introduces a new \reason\ package that categorizes errors (e.g., resource limits, host configuration, driver issues) and matches them against known issues using regular expressions, providing users with clear, context-aware guidance and links to relevant documentation or GitHub issues when failures occur.

pkg/minikube/reason · high confidence

Unified shell environment generation with tcsh support and robust detection

The shell environment generation logic has been consolidated into a new \pkg/minikube/shell\ package, replacing the previous \libmachine\ dependency. This change introduces native support for the \tcsh\ shell in the \docker-env\ subcommand and ensures that usage hints are correctly generated for all supported shells (bash, fish, powershell, cmd, emacs, and tcsh). Additionally, shell detection is now more resilient: it no longer errors when the \SHELL\ environment variable is unset (defaulting to \bash\ on non-Windows systems) and explicitly suppresses usage hints when \shell=none\ is selected, preventing confusing output for users who do not intend to source environment variables.

pkg/minikube/shell · high confidence

Update Buildroot configuration to include latest container runtimes

The ISO build configuration has been updated to integrate the latest versions of key container runtimes and tools. Specifically, the configuration now sources definitions for \crio-bin\, \crun-latest\, \automount\, \scheduled-stop\, \podman\, and \runc-master\. This ensures the Minikube ISO includes the most recent stable releases of these components, improving compatibility and feature support for containerized workloads.

deploy/iso/minikube-iso/package · high confidence

Update default Kubernetes version to v1.37.0 and refresh supported version list

The default Kubernetes version for new minikube clusters has been updated to v1.37.0, with the newest supported version also set to v1.37.0 and the oldest supported version set to v1.28.0. The list of valid Kubernetes versions has been refreshed to include the latest releases and pre-releases (v1.37.0, v1.36.x, v1.35.x, etc.), and the associated kubeadm images (coredns, etcd, pause) have been updated to match the new default version.

pkg/minikube/constants · high confidence

Updated Istio Operator addon to version 1.5.0

The Istio provisioner addon has been upgraded from version 1.4.0 to 1.5.0. This update includes migrating the CustomResourceDefinition for IstioOperator from the deprecated v1beta1 API to the stable v1 API, ensuring compatibility with current Kubernetes standards. Additionally, the addon now supports a configurable global image registry, allowing users to override the default Docker Hub prefix and manage image pull policies more flexibly.

deploy/addons/istio-provisioner · high confidence

Updated kubeadm configuration templates for Kubernetes v1.13 through v1.31

Minikube's bootstrapper now uses updated kubeadm configuration templates (v1beta1 through v1beta4) to support Kubernetes versions from v1.13 to v1.31. These changes ensure correct API versions and configuration structures for each release, including specific adjustments such as adding the \unix://\ prefix to CRI sockets in v1beta3+, setting \proxy-refresh-interval=70000\ for etcd in v1beta2+, and handling the \resolvConf\ regression in v1beta3+. Additionally, the v1beta4 template (for Kubernetes v1.31+) adopts the new list-based syntax for \kubeletExtraArgs\ and \extraArgs\.

pkg/minikube/bootstrapper/bsutil/ktmpl · high confidence

Updated list of supported VM drivers

The registry of available virtual machine drivers has been updated to include the new krunkit, vfkit, podman, qemu2, and ssh drivers, while the obsolete vmwarefusion driver has been removed. This change ensures that the minikube CLI recognizes and can initialize these specific driver implementations.

pkg/minikube/registry/drvs · high confidence

VMware driver registered as deprecated with explicit vmrun requirement

The VMware driver is now registered in the internal driver registry with a Deprecated priority, meaning it will not be selected by default and users must explicitly choose it. The driver registration now explicitly checks for the presence of the vmrun binary during status probing and provides a direct link to the VMware driver documentation if vmrun is missing, ensuring users are guided to install the necessary VMware tools before attempting to use this driver.

pkg/minikube/registry/drvs/vmware · high confidence

Website now automatically detects the user's operating system and adjusts documentation tabs accordingly

The documentation site now automatically detects the user's operating system and defaults the documentation tabs to the relevant platform-specific instructions. This change removes the need for manual tab selection for most users, ensuring that Windows, macOS, and Linux users immediately see the commands and configuration steps appropriate for their environment.

site · high confidence

Fixes

Fix NVIDIA GPU support with KVM driver by installing kernel module symvers

The ISO build process now correctly installs the kernel module symbol versioning file (Module.symvers) into the target directory. This change ensures that NVIDIA GPU drivers can properly resolve symbols when built against the KVM kernel, fixing compatibility issues that previously prevented the GPU driver from loading or functioning correctly in virtualized environments.

deploy/iso/minikube-iso/linux · high confidence

Windows installer now uses PowerShell to manage PATH environment variable

The Windows installer (minikube.nsi) has been updated to delegate PATH modification to a new PowerShell script (update\_path.ps1) during both installation and uninstallation. This change addresses a limitation in NSIS where the built-in environment variable update function truncates paths that are too long, ensuring that the Minikube installation directory is correctly added to or removed from the system PATH without data loss.

installers/windows · high confidence

Test coverage

Added integration tests for download-only, offline, and Traefik addon scenarios; Added test fixtures for the extract package; Added test infrastructure mocks and utilities; Automated release integrity validation for Minikube binaries; Updated kubeconfig test fixtures for validation.

Dependencies

Routine dependency updates across 12 manifests

This release updates dependencies across 12 manifests, including bumps to Kubernetes libraries (k8s.io/\), Docker packages (github.com/docker/docker, github.com/docker/cli), Google Cloud APIs (google.golang.org/api, cloud.google.com/go/storage), and various Go standard library and utility packages (golang.org/x/\, github.com/shirou/gopsutil). These updates ensure compatibility with the latest upstream releases and incorporate security and bug fixes from the underlying libraries.

(dependencies) · medium confidence

Update cni-plugins to v1.9.1 for aarch64 ISO builds

The Container Network Interface (CNI) plugins bundled in the Minikube ISO for aarch64 architectures have been updated from v1.9.0 to v1.9.1. This change ensures that the latest stable version of the plugins (including bridge, portmap, host-local, and others) is available for container networking within the Kicbase environment.

deploy/iso/minikube-iso/arch/aarch64/package/cni-plugins-latest-aarch64 · high confidence

Upgrade gopsutil to v4

The minikube CLI now uses gopsutil v4 for host system information retrieval, replacing the previous version. This update may alter the behavior of commands that rely on host metrics, such as memory or CPU checks, and requires users to ensure their host environment is compatible with the new library version.

cmd/minikube/cmd · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 63 → 64 (+1.7)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 78 → 86 (+8.0)
  • Architecture 97 → 96 (-1.2)
  • Maturity 56 → 56 (-0.3)
  • Readiness 65 → 66 (+0.4)
  • Security 64 → 70 (+6.6)

Resolved (132)

  • Coverage not included — suite not readable by the collector
  • Critical IaC: KSV-0041 (deploy/addons/kubeflow/kubeflow.yaml)
  • Critical IaC: KSV-0046 (deploy/addons/kubeflow/kubeflow.yaml)
  • Critical IaC: KSV-0050 (deploy/addons/kubeflow/kubeflow.yaml)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (cmd/minikube/cmd/config/configure.go)
  • Duplicated block (10 lines × 2) (hack/jenkins/release_update_releases_json.go)
  • Duplicated block (10 lines × 2) (hack/update/buildkit_version/buildkit_version.go)
  • Duplicated block (10 lines × 2) (pkg/drivers/kvm/network.go)
  • Duplicated block (10 lines × 2) (pkg/drivers/qemu/qemu.go)
  • Duplicated block (10 lines × 2) (pkg/minikube/command/ssh_runner.go)
  • Duplicated block (10 lines × 2) (pkg/minikube/image/cache.go)
  • Duplicated block (10 lines × 2) (pkg/minikube/machine/build_images.go)
  • Duplicated block (10 lines × 2) (pkg/minikube/node/start.go)
  • Duplicated block (10 lines × 2) (pkg/minikube/schedule/daemonize_windows.go)
  • Duplicated block (10 lines × 3) (hack/update/amd_device_gpu_plugin_version/amd_device_gpu_plugin_version.go)
  • Duplicated block (10 lines × 3) (pkg/drivers/qemu/qemu.go)
  • Duplicated block (10 lines × 3) (pkg/drivers/qemu/qemu.go)
  • Duplicated block (10 lines × 6) (hack/update/cni_plugins_version/cni_plugins_version.go)
  • Duplicated block (11 lines × 2) (hack/update/cni_plugins_version/cni_plugins_version.go)
  • …and 112 more

New (1823)

  • CI installs an unverified third-party binary (.github/workflows/functional_test.yml)
  • CI installs an unverified third-party binary (.github/workflows/functional_test.yml)
  • ClassTooLong: Bootstrapper (pkg/minikube/bootstrapper/kubeadm/kubeadm.go)
  • ClassTooLong: Driver (pkg/drivers/parallels/parallels_darwin.go)
  • ClassTooLong: Driver (pkg/drivers/qemu/qemu.go)
  • ClassTooLong: Driver (pkg/drivers/virtualbox/virtualbox.go)
  • Critical IaC: KSV-0041 (deploy/addons/kubeflow/kubeflow.yaml)
  • Critical IaC: KSV-0041 (deploy/addons/kubeflow/kubeflow.yaml)
  • Critical IaC: KSV-0041 (deploy/addons/kubeflow/kubeflow.yaml)
  • Critical IaC: KSV-0041 (deploy/addons/kubeflow/kubeflow.yaml)
  • Critical IaC: KSV-0041 (deploy/addons/kubeflow/kubeflow.yaml)
  • Critical IaC: KSV-0041 (deploy/addons/kubeflow/kubeflow.yaml)
  • Critical IaC: KSV-0041 (deploy/addons/kubeflow/kubeflow.yaml)
  • Critical IaC: KSV-0041 (deploy/addons/kubeflow/kubeflow.yaml)
  • Critical IaC: KSV-0041 (deploy/addons/kubeflow/kubeflow.yaml)
  • Critical IaC: KSV-0041 (deploy/addons/kubeflow/kubeflow.yaml)
  • Critical IaC: KSV-0041 (deploy/addons/kubeflow/kubeflow.yaml)
  • Critical IaC: KSV-0041 (deploy/addons/kubeflow/kubeflow.yaml)
  • Critical IaC: KSV-0041 (deploy/addons/kubeflow/kubeflow.yaml)
  • Critical IaC: KSV-0041 (deploy/addons/kubeflow/kubeflow.yaml)
  • …and 1803 more

Changes since last survey

  • 300 commits — 273 feature/other, 27 fixes

By area

  • (repo) — 116 commits
  • (root) — 50 commits
  • pkg/minikube — 24 commits
  • hack/go.mod — 19 commits
  • .github/workflows — 15 commits
  • cmd/minikube — 12 commits
  • deploy/iso — 10 commits
  • deploy/minikube — 8 commits
  • hack/jenkins — 8 commits
  • site/content — 7 commits
  • hack/kicbase_version — 6 commits
  • hack/update — 4 commits
  • test/integration — 4 commits
  • translations/pt-BR.json — 3 commits
  • deploy/kicbase — 2 commits
  • pkg/drivers — 2 commits
  • pkg/gvisor — 2 commits
  • deploy/addons — 1 commit
  • hack/iso — 1 commit
  • hack/release_notes.sh — 1 commit

Notable commits

  • fix: Merge pull request #23527 from nirs/fix-iso-test-memory
  • fix: Merge pull request #23586 from locker95/fix/registry-addon-major-tag
  • fix: Merge pull request #23602 from nirs/fix-release-notes
  • fix: Merge pull request #23623 from troychiu/fix-release-sanity-test
  • fix: Merge pull request #23637 from amanmaurya92/fix-23154-kvm-test-timeout
  • fix: Merge pull request #23648 from marwan562/fix/23640-dep-bumps-crypto-getter
  • fix: Merge pull request #23652 from rishiraj38/fix-hugo-security-allowcontent
  • fix: Merge pull request #23655 from locker95/fix/debian-slim-platforms
  • fix: Merge pull request #23657 from marwan562/fix/23628-remove-qemu-smoke-matrix
  • fix: Merge pull request #23658 from locker95/fix/nerdctl-bin-amd64-version
  • fix: Merge pull request #23663 from rishiraj38/fix-parallels-debugf-format-verb
  • fix: Merge pull request #23677 from SinghAman21/fix/node-status-on-deleting
  • fix: Merge pull request #23682 from Tushar12222/bugfix/driver-probing-too-slow
  • fix: Merge pull request #23687 from SinghAman21/fix/status-nodes-507-range-copy-23683
  • fix: Merge pull request #23710 from marwan562/fix/23709-gvisor-tarball
  • fix: Merge pull request #23744 from sh011/fix/23742-replace-bookworm-with-trixie
  • fix: Merge pull request #23756 from Roslaan001/fix/lock-appendtofile-fd-leak
  • fix: Merge pull request #23767 from Jeffrin2005/fix/remove-duplicate-klog-stop-warning
  • fix: Merge pull request #23769 from Jeffrin2005/fix/node-stop-invalid-node-error-message
  • fix: Merge pull request #23774 from Jeffrin2005/fix/pause_unpause
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

kubernetes/minikube was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 84597a58ae06ecf70388cb777f5bcaa17301e458 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.