End of life

etcd 3.4 end of life

etcd 3.4 reached end of life on 1 June 2026 with 3.4.45, which SIG-etcd called the final patch update for the line. No further 3.4 patches will be issued. The project now patches 3.5, 3.6 and 3.7, and the latest releases on those branches shipped on 22 September 2026. etcd 3.4 was first released in August 2019.

End of life
1 June 2026
Released
Aug 2019
Final release
3.4.45
Successor
etcd 3.5, 3.6 or 3.7

Date published by etcd project blog: final update for v3.4. We do not publish a lifecycle date we cannot source.

What actually stops on 1 June 2026

  • Patch releases on the 3.4 branch. 3.4.45, on 1 June 2026, was the last.
  • Go toolchain rebuilds. 3.4.45 was built with Go 1.25.10, while the September 2026 releases for 3.5, 3.6 and 3.7 are built with Go 1.26.8.
  • Dependency security updates, such as the gorilla/websocket update that shipped in 3.5.34 and 3.6.15.

What actually breaks in the upgrade

3.4 to 3.5 is rolling, unless auth is on

The etcd guide describes 3.4 to 3.5 as a zero-downtime rolling upgrade in the general case. The exception matters: if the cluster has authentication enabled, a rolling upgrade from 3.4 is not supported, because 3.5 changes the format of auth-related WAL entries.

Plan 3.6 at the same time

The 3.6 guide requires every member to run 3.5.32 or later first, and the --enable-v2 flag must be unset. If the v2 API was ever enabled on any member, the v2store has to be checked with etcdutl check v2store and cleaned up before the upgrade.

Logging flags change

3.5 deprecates --logger=capnslog and makes zap the default, and --log-output becomes --log-outputs. Configuration management and log shipping built around 3.4 flags need updating before the first member moves.

Your options, costed honestly

Including the ones that do not involve buying anything from us.

OptionWhat it isEffortCostOur view
Rolling upgrade to 3.5, then 3.6 or 3.7Replace members one at a time, following the project's upgrade guides.Days per clusterEngineering timeThe right destination. Auth-enabled clusters need a planned window.
Stop at 3.5Still patched today, with no announced end date.DaysEngineering timeThe written policy covers two branches and three are patched now, so 3.5 is the next line at risk.
OSSeva extended support on 3.4Patched 3.4 builds while the upgrade is scheduled.Drop-inSubscriptionKeeps a 3.4 cluster patched when a product pins it or the auth upgrade needs downtime.

What OSSeva does for etcd 3.4

OSSeva patches this line

OSSeva patches etcd 3.4 now. Signed 3.4 builds carry backported security fixes and dependency updates, on the Patch, Assure and Operate tiers, and OSSeva runs the rolling upgrade to 3.5 and 3.6 when the cluster is ready to move.

etcd extended support

What your auditor will say

PCI DSS v4 Requirement 6.3.3

etcd holds the state of the systems built on it. For Kubernetes that includes Secrets, which the Kubernetes documentation says are stored unencrypted in etcd unless encryption at rest is configured.

SOC 2 CC7.1

Auditors ask for evidence that production systems receive security fixes. A data store with no upstream patches since June 2026 needs another source of fixes or a documented compensating control.

Compliance library

etcd 3.4: common questions

Is etcd 3.4 end of life?

Yes. SIG-etcd released 3.4.45 on 1 June 2026 as the final patch update for the line and said no further patches will be issued.

Which etcd versions are supported?

3.5, 3.6 and 3.7. The latest releases are 3.7.2, 3.6.15 and 3.5.34, all published on 22 September 2026. No end date has been announced for 3.5.

Can I upgrade etcd 3.4 straight to 3.6?

The project publishes its upgrade guides one minor version at a time, and the 3.6 guide requires every member to be on 3.5.32 or later first. Plan it as two rolling upgrades: 3.4 to 3.5, then 3.5 to 3.6.

Does etcd use ZooKeeper?

No. etcd uses the Raft consensus algorithm, which is why it is one of the stores teams move ZooKeeper workloads to. Patroni, for example, can use either etcd or ZooKeeper as its configuration store.

Still running etcd 3.4?

Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.