Supported Kubernetes distributions
The following are the supported Kubernetes platform versions for the Kubernetes connector (Posture Management). The table shows the latest version that is supported. We support n-3 versions of each supported Kubernetes environment.
Kubernetes environment
Notes
Managed clusters
Amazon Elastic Kubernetes Service (EKS)
Microsoft Azure Kubernetes Service (AKS)
Google Kubernetes Engine (GKE)
Managed OpenShift
Managed Openshift clusters, including ROSA (Red Hat OpenShift on AWS), are supported.
Self-Managed
We support every CNCF-certified Kubernetes solution. We've tested our solution on:
Self-managed vanilla/on-premise Kubernetes clusters.
Self-managed OpenShift Kubernetes clusters.
Rancher Distributions (RKE and RKE2).
The following are the Kubernetes platforms that are supported with Cortex XDR agents (Real-time protection).
This table shows the Kubernetes platform versions that have been compatibility tested. The table shows the latest version that has been tested. All versions that are not EOL, up to the latest version are supported.
Linux Kubernetes Platform
Version
Unmanaged Kubernetes (k8s)
1.30
Amazon Elastic Kubernetes Service (EKS)
1.33
BottleRocket OS x86_64
User mode agent only
BottleRocket OS aarch64
User mode agent only
Microsoft Azure Kubernetes Service (AKS)
1.33
CBL-mariner 2 x86_64
Google Kubernetes Engine (GKE)
1.33
Google Container-Optimized OS (COS)^(*) x86_64
User mode agent only
Google Kubernetes Engine (GKE) Autopilot
Oracle Kubernetes Engine (OKE)
1.33
Red Hat Openshift Container Platform (OCP)
4.16
RHCOS^(*) x86_64
User mode agent only
SUSE Rancher Kubernetes Engine 2 (RKE2)
1.28
Talos
1.8.3
Note
In Google Container-Optimized OS release 100 and earlier, where the FANOTIFY EXEC flag is not supported, the Kernel configuration may be partial for the user mode agent to properly function. In such cases, the agent will fallback to asynchronous mode.
In RHCOS version 4.12 and earlier, the Kernel configuration may be partial for the user mode agent to properly function. In such cases, the agent will fallback to asynchronous mode.
Last updated
Was this helpful?
