OSSEVA FOR ETCD
etcd 3.4 ended on 1 June 2026. Your control plane still runs it.
etcd holds every object in a Kubernetes cluster, the leader lock for Patroni-managed PostgreSQL, Vitess topology and APISIX routes. It is rarely upgraded on its own schedule, so it drifts behind. OSSeva patched builds for etcd 3.4 and older are available now, with backup and restore you can prove works.
Trusted globally by enterprises




Why now
etcd is the Raft-based coordination layer under your platform
etcd is a strongly consistent key/value store replicated with Raft. Kubernetes uses it as the backing store for all cluster data. Patroni can hold its PostgreSQL leader key there, Vitess offers etcd2 as a topology service, and APISIX uses etcd as its configuration store. A problem in etcd is a problem in every one of those systems at once.
3.4 is end of life, and the Kubernetes docs still mention it
etcd 3.4.45, released on 1 June 2026, was the final patch for 3.4 and marked its end of support. The project now patches 3.5, 3.6 and 3.7. The Kubernetes guide to operating etcd still lists 3.4.29+ and 3.5.11+ as the minimum recommended production versions, so clusters built from it can sit on a line that no longer gets fixes. etcd is Apache 2.0 licensed, so there is no licence cliff, only a support one.
The next upgrade is not a drop-in swap
etcd 3.6 removed the --enable-v2 flag, so anything still using the v2 API has to move first. Patroni's etcd section uses protocol version 2, and its docs warn that v2 keys are invisible to v3, so switching to the etcd3 section is not a config edit. etcd also will not start on a data directory written by a newer version. A tested snapshot is the only safe rollback.
Versions covered
All versions below receive active CVE patches from OSSeva. Version numbers in monospace are exact release identifiers.
| Version | Status | Active CVEs |
|---|---|---|
| 3.3.x and older(Community EOL. OSSeva patched) | EOL | Clean |
| 3.4.x(Final release 3.4.45, 1 Jun 2026. OSSeva patched) | EOL | Clean |
| 3.5.x(Upstream maintained (3.5.34). No end date announced) | Extended | Clean |
| 3.6.x(Upstream maintained (3.6.15)) | Current | Clean |
| 3.7.x(GA 8 Jul 2026. Upstream maintained (3.7.2)) | Current | Clean |
What you get
Three tiers — pick the level of engagement that matches your team's operational needs and compliance requirements.
OSSeva Patch
Patched, signed builds for etcd 3.4 and older, available today.
- Security backports for etcd 3.4 and older lines, same data format
- Rebuilt on a supported Go toolchain with patched gRPC and dependencies
- etcd, etcdctl and etcdutl binaries covered
- Binary / Docker / package delivery
- Signed artifacts (GPG)
- Backup and restore drill
- 24/7 managed operations
OSSeva Assure
Patch plus a cluster audit, a restore drill and an upgrade plan.
- Everything in Patch
- Member, quorum and failure-domain review
- TLS, authentication and client exposure audit
- Snapshot backup design and a timed restore drill
- SOC 2 / HIPAA attestation package
- Upgrade plan to 3.5 or later, including v2 API dependencies
- 24/7 managed operations
OSSeva Operate
Full MSP: 24/7 cluster monitoring, 15-min SLA, named engineers.
- Everything in Assure
- 24/7 leader changes, fsync latency and database size monitoring
- 15-minute P1 incident response SLA
- Named senior distributed systems engineer
- Scheduled snapshots, defragmentation and compaction
- Rolling upgrade execution with quorum preserved
- Patroni and Kubernetes etcd migrations run end to end
All tiers priced per cluster/application — not per core. Contact for pricing →
How it installs
OSSeva artifacts arrive via your existing package infrastructure. Pull the patched version the same way you pull upstream today — just from the OSSeva registry.
# VERSION column shows the server version of each member
etcdctl --endpoints=$ENDPOINTS endpoint status -w table
# kubeadm clusters run etcd as a static pod in kube-system
kubectl -n kube-system get pods -l component=etcd \
-o jsonpath='{range .items[*]}{.spec.containers[0].image}{"\n"}{end}'
# Patroni: 'etcd:' means the v2 API, 'etcd3:' means v3
grep -E '^(etcd|etcd3):' /etc/patroni/patroni.yml# Snapshot a live member (all supported versions)
etcdctl --endpoints=$ENDPOINT snapshot save snapshot.db
# Check it. etcdutl ships with 3.5 and later;
# on 3.4 use 'etcdctl snapshot status' instead
etcdutl snapshot status snapshot.db -w table
# Restore into a fresh data directory. This starts a new logical
# cluster, so every member restores from the same snapshot.
etcdutl snapshot restore snapshot.db --data-dir /var/lib/etcd-restored# Patched 3.4 build, same on-disk format as upstream 3.4
docker pull artifacts.osseva.io/etcd:v3.4.45-osseva-1Migrate from Unsupported community etcd 3.4 and older
OSSeva ships patched etcd builds on the line you already run, so the data directory, API versions and client behaviour stay the same while the cluster becomes secure. The move to 3.5 or later is then planned around the systems above it, with v2 API users found first, a tested snapshot taken and quorum preserved at every step.
Pricing model
OSSeva for etcd is priced per cluster, not per member or per client.
Frequently asked questions
Is etcd 3.4 end of life?
Yes. etcd 3.4.45, released on 1 June 2026, was the final patch for the 3.4 line and marked its end of support. 3.4 was first released in August 2019. The project currently patches 3.5, 3.6 and 3.7, with 3.7.0 reaching GA on 8 July 2026. No end date has been announced for 3.5.
How do I back up and restore etcd?
Take a snapshot from a live member with etcdctl snapshot save, then check it with etcdutl snapshot status (etcdctl snapshot status on 3.4). Restore with etcdutl snapshot restore into a new data directory. A restore creates a new logical cluster with new member and cluster IDs, so every member must restore from the same snapshot. The Assure tier includes a timed restore drill, because an untested backup is not a backup.
Which etcd version does Kubernetes need?
The Kubernetes guide to operating etcd lists 3.4.29+ and 3.5.11+ as the minimum recommended versions for production. Meeting that minimum on 3.4 no longer means receiving fixes, because 3.4 reached end of life on 1 June 2026. OSSeva patches self-managed control plane etcd on 3.4 and plans the move to a maintained line.
Can a Patroni cluster on etcd's v2 API move to etcd 3.6?
Not directly. etcd 3.6 removed the --enable-v2 flag. Patroni's etcd section talks to etcd over protocol version 2, and its docs warn that v2 and v3 keys are not visible to each other, so changing the section to etcd3 is not enough. The DCS has to be moved as a planned maintenance step before the etcd upgrade.
Does OSSeva cover etcd under Vitess and APISIX?
Yes. Vitess can use etcd2 as its topology service and APISIX stores its configuration in etcd in the traditional deployment mode. OSSeva patches and operates the etcd cluster under both, and maps which systems share a cluster before any member is touched.
Ready to get etcd patched and supported?
Start with a 45-minute discovery call. We confirm your version coverage, scope the engagement, and have you onboarded within your first quarter.