What Shipped in Kubernetes 1.36 for Windows
Kubernetes 1.36 brings several concrete Windows improvements. Kube-proxy fixes introduced in 1.36 were also back-ported to 1.35. The container image platform logic gained enhancements for better image selection. Windows Server 2025 now has a dedicated pause image and full test-grid coverage. NodeLogQuery, first introduced as alpha in 1.27, graduates to GA in 1.36 with its feature gate locked to true, letting operators pull logs from any Windows or Linux node through kubectl alone.
HyperV Isolated Containers: What They Are and How to Enable Them
Process-isolated containers share the host kernel. HyperV isolated containers each run inside a microVM with a separate kernel, which matters for multi-tenant workloads where container escapes would be a real risk. The feature works on Windows Server 2019 and later, though 2022 and 2025 images are recommended. Nested virtualization must be enabled on any public cloud host. Containerd 1.7 or newer is required. No Kubernetes code changes are needed. Configure containerd with a sandbox isolation handler, create a matching RuntimeClass, and set the runtime class name on pods.
K0S Demo: A Windows Cluster in 5 Minutes
Tom Vitizk showed a live cluster built on a stock Amazon EC2 Windows Server 2022 image with no prior configuration. The K0S setup needs only SSH addresses for a Linux control-plane node and a Windows worker node. Running k0sctl installs K0S on both nodes simultaneously, downloads dependencies, and starts the control plane. The full process took about 5 minutes. A single-pod deployment exposed over a node port confirmed the Windows workload was running, with live worker stats visible through a QR-code-accessible URL.
Features Planned for Future Releases
Windows graceful shutdown (KEP 2000 counterpart) targets beta in a future release once the Linux side reaches beta. Windows CPU and memory affinity work tracks KEP 4885. Sidecar containers on Windows port stack and EMOS pool per runtime class are aimed at 1.38 and beyond. Most of these already have code merged upstream. What remains is shepherding them through beta requirements to reach stable. Contributors who want to help can pick up any of these KEPs directly.
Community, Leadership Changes, and How to Get Involved
Arvind is stepping down as SIG-Windows co-chair. JR Valdes takes that role. Yan Lang Jang joins as a new tech lead, and Mark Rosetti moves from co-chair to tech lead. The group holds weekly meetings on Tuesdays. All meetings are recorded and published on YouTube. The Kubernetes Slack SIG-Windows channel is the fastest way to get help, including for K0S deployments on bare hardware. Contributors who can test KEPs or write docs are welcome.
Q&A
How can someone get help running the K0S Windows setup on their own hardware? Join the Kubernetes Slack SIG-Windows channel and reach out directly to Tom or the maintainers. ▶ 20:54
Does SIG-Windows cooperate with public cloud providers like Microsoft AKS? Yes. Mark Rosetti works for Microsoft, and all test infrastructure runs on Azure through AKS. ▶ 21:37
What is the minimum needed to join a Windows node to a cluster using the K0S method? An IP address, a username and password, and SSH enabled on the Windows host. ▶ 22:32
Notable Quotes
it took me around about 5 minutes to deploy all of this. So it’s not not really hard actually. Tom Vitizk · ▶ 14:26
this is very very much a barebones virtual machine, just a b the the standard EC2 image that you can grab from, um, Amazon Web Services and we didn’t do anything with it. Tom Vitizk · ▶ 13:23
for Tom’s demo, basically the only thing you need is an IP address and username and password and SSH enabled in the in the Windows host. Claudiu Belu · ▶ 22:32
Key Takeaways
- NodeLogQuery reaches GA in 1.36, enabled by default on all node types.
- HyperV isolated containers need only a containerd config change and a RuntimeClass, with no Kubernetes core modifications.
- A bare Windows Server 2022 EC2 node joins a K0S cluster in roughly 5 minutes using only SSH credentials.
About the Speaker(s)
Claudiu Belu is a Senior Cloud Engineer at Cloudbase Solutions. He has focused on cloud-related open source projects for several years and serves as one of SIG-Windows’ Tech Leads in the Kubernetes project.