Jenkins pipelines
The previous CI system. Still running for pipelines that have not migrated, and switching off for good at the end of March 2027.
38 pipelines still to migrate before the March 2027 shutdown
Runs the paved road: clusters, CI runners, deployment tooling and the guardrails that keep production safe to change.
The previous CI system. Still running for pipelines that have not migrated, and switching off for good at the end of March 2027.
38 pipelines still to migrate before the March 2027 shutdown
Cluster-wide upgrade to Kubernetes 1.31. Workloads still using removed beta APIs will stop working when their cluster is upgraded.
Production clusters upgrade from 1 October — Ingress v1beta1 is removed
Blocks commits containing credentials before they reach a remote branch, and flags secrets already in history so they can be rotated.
Push protection is on for the 20 busiest repositories
The supported way to run CI here: autoscaling self-hosted runners with access to internal networks, artifact caching and deployment credentials.
Secret scanning and push protection
If a push is blocked, the message names the file and line. Rotate the credential first, then remove it from the commit — do not just force-push over it, because the secret is already in the reflog.
Rolling out to the remaining repositories through October and November.
Production upgrades run in three waves starting 1 October. Any workload
still declaring networking.k8s.io/v1beta1 Ingress objects will fail to
deploy once its cluster is upgraded.
Run kubectl deprecations --context <your-cluster> to see whether you are
affected. The migration guide has the before-and-after manifests.
What you need to do
kubectl deprecations --context <your-cluster> against every cluster your team owns.networking.k8s.io/v1, using the before-and-after manifests.We will contact owning teams individually from October. If your pipeline is on the list and you think it should simply be deleted, tell us — that is often the right answer for pipelines nobody has run this year.
Staging has been stable for two weeks. This is the window to catch problems before the production waves begin.
Secret scanning and push protection
No pushes are blocked yet. Findings go to the owning team's channel so you can start rotating without a deadline hanging over you.
Self-hosted GitHub Actions runners
Capacity has been stable through three months of rollout. New repositories created from the golden path templates get runner access automatically.