DevOps Elastic Hayway
Document

SUBSCRIBE TO GET FULL ACCESS TO THE E-BOOKS FOR FREE 🎁SUBSCRIBE NOW

Professional Dropdown with Icon

SUBSCRIBE NOW TO GET FREE ACCESS TO EBOOKS

KubernetesLesson 32 / 352 min readUpdated September 11, 2026

Upgrading Kubernetes

Upgrading Kubernetes ensures your cluster remains secure, stable, and compatible with the latest features. This guide explains how to upgrade Kubernetes using kubeadm on Ubuntu 24.04 LTS to the latest supported versions such as 1.31. Follow the process carefully to minimize downtime on production workloads.

Prerequisites

Before starting the upgrade, verify your environment meets all requirements. You need an existing Kubernetes cluster managed by kubeadm, administrative access via kubectl, and root privileges on all nodes. All nodes must run Ubuntu 24.04 LTS with sufficient disk space and network connectivity to registry.k8s.io.

Check current versions

Confirm the exact versions of your control plane components and nodes. Run the following command on the control plane node:

kubectl version --client=true
kubeadm version
kubelet --version

Expected output shows the current API server version and confirms kubeadm and kubelet are installed. Note the minor version difference between components, as upgrades must follow sequential minor version steps.

Backup etcd and configuration

Always create a full backup of etcd before any upgrade. Use the following command to snapshot the etcd data:

sudo ETCDCTL_API=3 etcdctl snapshot save /backup/etcd-snapshot.db 
  --endpoints=https://127.0.0.1:2379 
  --cacert=/etc/kubernetes/pki/etcd/ca.crt 
  --cert=/etc/kubernetes/pki/etcd/server.crt 
  --key=/etc/kubernetes/pki/etcd/server.key

Store the snapshot securely. Also back up the entire /etc/kubernetes directory and any custom manifests.

Step-by-step upgrade process

1. Prepare package repositories

Update the Kubernetes package repository to access version 1.31 packages. Create or update the repository file:

sudo mkdir -p /etc/apt/keyrings
curl -fsSL https://pkgs.k8s.io/core:/stable:/v1.31/deb/Release.key | sudo gpg --dearmor -o /etc/apt/keyrings/kubernetes-apt-keyring.gpg
echo "deb [signed-by=/etc/apt/keyrings/kubernetes-apt-keyring.gpg] https://pkgs.k8s.io/core:/stable:/v1.31/deb/ /" | sudo tee /etc/apt/sources.list.d/kubernetes.list

Refresh the package index:

sudo apt update

2. Unhold current packages

Release version pinning on kubeadm, kubelet, and kubectl:

sudo apt-mark unhold kubeadm kubelet kubectl

3. Upgrade kubeadm

Install the new kubeadm binary first. This component orchestrates the upgrade:

sudo apt install -y kubeadm=1.31.0-1.1

Re-hold the package to prevent accidental updates:

sudo apt-mark hold kubeadm

Verify the new version:

kubeadm version

4. Plan the upgrade

Review the upgrade plan to identify component changes and any required actions:

sudo kubeadm upgrade plan

The output lists the target version, component images from registry.k8s.io, and any deprecated APIs. Resolve warnings before proceeding.

5. Apply control plane upgrade

Upgrade the control plane components in a single operation:

sudo kubeadm upgrade apply v1.31.0

This command updates the API server, controller manager, scheduler, and etcd if necessary. Monitor the output for successful pod restarts and certificate renewals.

6. Upgrade kubelet and kubectl

Install matching versions of kubelet and kubectl:

sudo apt install -y kubelet=1.31.0-1.1 kubectl=1.31.0-1.1
sudo apt-mark hold kubelet kubectl
sudo systemctl restart kubelet

7. Upgrade worker nodes

Repeat the package upgrade steps on each worker node. Then run the node upgrade command from the control plane:

sudo kubeadm upgrade node

Drain and cordon each node before restarting kubelet to avoid workload disruption:

kubectl drain <node-name> --ignore-daemonsets --delete-emptydir-data
sudo systemctl restart kubelet
kubectl uncordon <node-name>

Common Errors

  • Version mismatch between kubeadm and kubelet causing the upgrade to fail.
  • Insufficient disk space on the control plane node during image pulls.
  • etcd backup not performed, leading to data loss risk.
  • Network policies blocking access to registry.k8s.io during component image downloads.
  • Forgetting to unhold packages before running apt install.

Going Further

  • Automate upgrades using Ansible playbooks or Terraform with AWS Launch Templates for node replacement.
  • Implement canary upgrades by adding new nodes at the target version and gradually migrating workloads.
  • Integrate cluster upgrades into CI/CD pipelines with automated testing of critical applications.
  • Monitor upgrade success with Prometheus metrics for API server latency and etcd health.

Conclusion

Following this structured approach allows you to upgrade Kubernetes reliably while maintaining cluster availability. Regular upgrades keep your environment secure and aligned with the latest Kubernetes features. Always test the process in a staging environment first.

FAQ

How often should I upgrade Kubernetes?

Plan minor version upgrades every 3 to 6 months. Stay within the supported skew between control plane and nodes to avoid compatibility issues.

Can I skip minor versions during upgrade?

No. Kubernetes requires sequential minor version upgrades. Skipping versions can cause etcd or API incompatibilities.

What happens if the upgrade fails midway?

Restore from the etcd snapshot created before the upgrade. Re-run kubeadm upgrade apply after fixing the root cause identified in the logs.

Do worker nodes require the same upgrade steps?

Yes. Worker nodes must run the same kubelet and kube-proxy versions as the control plane to maintain cluster stability.

Is zero-downtime upgrade possible?

With multiple control plane replicas and proper draining of nodes, you can achieve near-zero downtime for most workloads during the upgrade process.

Retour parcours Kubernetes — hub de la série et leçons sœurs.

Share your love

Leave a Reply

Your email address will not be published. Required fields are marked *