Will future K3s releases enforce a strict containerd version match across all nodes during upgrades?
0 reputation · 31 Aug 2021, 02:57 UTC
0 reputation · 31 Aug 2021, 02:57 UTC
The goal is to determine whether a standard K3s upgrade automatically upgrades the bundled containerd version on existing agent nodes, or whether the containerd binary remains unchanged unless the operator explicitly triggers an upgrade via specific install flags.
Constraints include the tight coupling of K3s to a specific containerd version, the possibility of version skew between server and agent nodes, and kernel version mismatches that can exacerbate incompatibilities. The current documentation leaves the decision to enforce a strict containerd version match across all nodes as an operator‑driven choice, and it remains unresolved whether future releases will make this enforcement mandatory. Does the standard K3s upgrade script automatically upgrade containerd on agent nodes without additional flags? What conditions must be satisfied for a future K3s release to enforce a strict containerd version match across all nodes?
29275 reputation · 31 Aug 2021, 13:43 UTC
No – the current K3s upgrade mechanism does not enforce that every node runs the exact same containerd version.
Rancher’s public roadmap and community discussions indicate a preference for flexibility: they provide a compatibility matrix and recommend uniform versions for best stability, but they have not announced plans to make containerd version matching a requirement during upgrades.
pkg/upgrade/upgrade.go) for logic that compares containerd versions across nodes; absence of such checks indicates no enforcement.Note: If you are using an external containerd installation (not the K3s‑bundled binary), the upgrade behavior differs and you should confirm which containerd is being managed.
Use comments to ask for clarification. Post a solution as an answer.
29,275 reputation · 31 Aug 2021, 08:02 UTC
It is important to distinguish between the bundled containerd provided by K3s and an external containerd installation. When using the default K3s installation, the install.sh script replaces the K3s binary on each node, which inherently updates the bundled containerd version. This happens automatically during a standard upgrade without additional flags.
To verify the current runtime version on any node (assuming K3s v1.28+), execute:
k3s --version
The output will explicitly list the bundled containerd:// version, allowing you to confirm if the agent node has successfully transitioned to the new release version.