Loading...
Loading...
On Kubernetes 1.35 or later, Veeam Kasten for Kubernetes worker pods fail with ImagePullBackOff errors when the cluster uses a private container registry. These pods run in the application namespace and have no image pull credentials. The following operations are affected: Backup and restore of applications protected by a Kanister blueprint Backup of volumes not attached to a running workload Execution hooks whose blueprint creates a pod Generic Storage Backup operations Kanister times out after approximately 15 minutes per attempt.
This issue occurs because Kubernetes 1.35 enables the KubeletEnsureSecretPulledImages feature gate by default. Every pod must now present valid registry credentials to pull an image, and cached images no longer bypass authentication. Veeam Kasten for Kubernetes runs certain worker pods in the application namespace. The image pull secret (by default, k10-ecr) exists only in the kasten-io namespace. Those worker pods have no imagePullSecrets and reference no service account credentials, so they cannot authenticate against a private registry. On Kubernetes 1.34 and earlier, cached images did not require re-authentication. This masked the missing credentials.
Copy the image pull secret into each protected namespace, then attach it to the default service account of that namespace. Both steps are required. A secret that exists in the namespace but is not referenced by the service account has no effect. Prerequisites kubectl access to the cluster Permission to create secrets and patch service accounts in the target namespace The name of the image pull secret used during Veeam Kasten for Kubernetes installation (default: k10-ecr) Procedure 1. Set variables for the target namespace and secret name. If a name other than k10-ecr was provided to global.imagePullSecret during installation, replace the value accordingly:
This is a documented workaround. A product-side fix is tracked internally. Clusters that use a public registry are not affected. For more information on private registry configuration, see the Air-Gapped Installation section of the Veeam Kasten documentation. For details on the upstream Kubernetes change, see KEP-2535 (KubeletEnsureSecretPulledImages).
Click on a version to see all relevant bugs
Veeam Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.