PackageTrack
Sign in Get early access

github.com/siderolabs/omni

v1.10.4 #1323 most downloaded on Go modules siderolabs/omni

What this package is like to depend on

Last release 5 days ago

18 Aug 2026

Ships on a steady schedule

a new release about every 9 days

Rarely documented

notes for 7 of 122 stable releases

Nothing withdrawn

no release was ever pulled

2 years old

533 releases · first in 2024

272 releases in the last 12 months

see the full history below

Release timeline

533 releases · Feb 2024 to Aug 2026
2025 2026
Release Pre-release

Releases

latest 60 of 533
  1. v1.10.4 18 Aug 2026
    Release notes

    Omni 1.10.4 (2026-08-18)

    Welcome to the v1.10.4 release of Omni!

    Please try out the release binaries and report any issues at
    https://github.com/siderolabs/omni/issues.

    Revoking Kubernetes Access Tokens

    Admins can now list the keys which sign the Kubernetes access tokens and delete them using omnictl. Deleting a key immediately invalidates all the tokens signed by it, such as the long-lived service account kubeconfigs, without a restart. Deleting the most recent key is safe: a replacement is generated automatically when the next token is issued. The key deletions are recorded in the audit log.

    Contributors

    • Utku Ozdemir

    Changes

    2 commits

    • 615998ab9 release(v1.10.4): prepare release
    • bc586e4f7 feat: allow listing and deleting the Kubernetes token signing keys

    Dependency Changes

    This release has no dependency changes

    Previous release can be found at v1.10.3

    Open source →
    Release notes

    Welcome to the v1.10.4 release of Omni!

    Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.

    Revoking Kubernetes Access Tokens

    Admins can now list the keys which sign the Kubernetes access tokens and delete them using omnictl. Deleting a key immediately invalidates all the tokens signed by it, such as the long-lived service account kubeconfigs, without a restart. Deleting the most recent key is safe: a replacement is generated automatically when the next token is issued. The key deletions are recorded in the audit log.

    Contributors

    • Utku Ozdemir

    Changes

    <details><summary>1 commit</summary> <p>

    • bc586e4f feat: allow listing and deleting the Kubernetes token signing keys </p> </details>

    Dependency Changes

    This release has no dependency changes

    Previous release can be found at v1.10.3

    Open source →
  2. v1.10.3 14 Aug 2026
    Release notes

    Omni 1.10.3 (2026-08-14)

    Welcome to the v1.10.3 release of Omni!

    Please try out the release binaries and report any issues at
    https://github.com/siderolabs/omni/issues.

    Contributors

    • Edward Sammut Alessi

    Changes

    2 commits

    • 39bcff396 release(v1.10.3): prepare release
    • 8bce1ddbd fix(frontend): check for navigation in preload error events

    Dependency Changes

    This release has no dependency changes

    Previous release can be found at v1.10.2

    Open source →
    Release notes

    Welcome to the v1.10.3 release of Omni!

    Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.

    Contributors

    • Edward Sammut Alessi

    Changes

    <details><summary>1 commit</summary> <p>

    • 8bce1ddbd fix(frontend): check for navigation in preload error events </p> </details>

    Dependency Changes

    This release has no dependency changes

    Previous release can be found at v1.10.2

    Open source →
  3. v1.10.2 14 Aug 2026
    Release notes

    Omni 1.10.2 (2026-08-14)

    Welcome to the v1.10.2 release of Omni!

    Please try out the release binaries and report any issues at
    https://github.com/siderolabs/omni/issues.

    Contributors

    • Edward Sammut Alessi
    • Oguz Kilcan

    Changes

    3 commits

    • 0a932d3df release(v1.10.2): prepare release
    • 93fb429b4 chore: rekres and bump go
    • 024fe1e4c fix(frontend): fix incorrect machine route params

    Dependency Changes

    This release has no dependency changes

    Previous release can be found at v1.10.1

    Open source →
    Release notes

    Welcome to the v1.10.2 release of Omni!

    Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.

    Contributors

    • Edward Sammut Alessi
    • Oguz Kilcan

    Changes

    <details><summary>2 commits</summary> <p>

    • 93fb429b4 chore: rekres and bump go
    • 024fe1e4c fix(frontend): fix incorrect machine route params </p> </details>

    Dependency Changes

    This release has no dependency changes

    Previous release can be found at v1.10.1

    Open source →
  4. v1.10.1 12 Aug 2026
    Release notes

    Omni 1.10.1 (2026-08-12)

    Welcome to the v1.10.1 release of Omni!

    Please try out the release binaries and report any issues at
    https://github.com/siderolabs/omni/issues.

    Contributors

    • Edward Sammut Alessi
    • Oguz Kilcan
    • Artem Chernyshev
    • Utku Ozdemir

    Changes

    15 commits

    • 0fbf63143 release(v1.10.1): prepare release
    • a694edefb fix(frontend): fix reset wizard
    • 7aa7a7e45 fix: compress diffs in the machine pending updates and diff history
    • dd1b1dd97 fix: force re-authentication at the IdP so logout takes effect
    • b5303320a fix: keep a machine's tunnel peer address stable across provisions
    • 1005ec0d6 fix(frontend): return no-cache for index.html
    • c9ba2048b fix: don't sign users out of Omni on Kubernetes OIDC logout
    • 3b82989e1 fix(frontend): add missing credentials to security pages
    • a2058e200 chore(frontend): bump dependencies
    • 8a8fd2a1b test(frontend): add edit patch e2e test
    • 4d1ed5bb5 fix(frontend): fix patch edit dropping fields
    • 80b2e8586 fix: backfill the image factory host of machines enrolled before 1.10
    • f28cdc77a fix: bound the machine config diff by bytes, not just lines
    • 0e1259283 fix(frontend): be more defensive about signup errors
    • 6b91ddb67 fix: log out of Omni and the IdP when /logout is opened directly

    Dependency Changes

    This release has no dependency changes

    Previous release can be found at v1.10.0

    Open source →
    Release notes

    Welcome to the v1.10.1 release of Omni!

    Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.

    Contributors

    • Edward Sammut Alessi
    • Oguz Kilcan
    • Artem Chernyshev
    • Utku Ozdemir

    Changes

    <details><summary>14 commits</summary> <p>

    • a694edef fix(frontend): fix reset wizard
    • 7aa7a7e4 fix: compress diffs in the machine pending updates and diff history
    • dd1b1dd9 fix: force re-authentication at the IdP so logout takes effect
    • b5303320 fix: keep a machine's tunnel peer address stable across provisions
    • 1005ec0d fix(frontend): return no-cache for index.html
    • c9ba2048 fix: don't sign users out of Omni on Kubernetes OIDC logout
    • 3b82989e fix(frontend): add missing credentials to security pages
    • a2058e20 chore(frontend): bump dependencies
    • 8a8fd2a1 test(frontend): add edit patch e2e test
    • 4d1ed5bb fix(frontend): fix patch edit dropping fields
    • 80b2e858 fix: backfill the image factory host of machines enrolled before 1.10
    • f28cdc77 fix: bound the machine config diff by bytes, not just lines
    • 0e125928 fix(frontend): be more defensive about signup errors
    • 6b91ddb6 fix: log out of Omni and the IdP when /logout is opened directly </p> </details>

    Dependency Changes

    This release has no dependency changes

    Previous release can be found at v1.10.0

    Open source →
  5. v1.10.0 07 Aug 2026
    Release notes

    Welcome to the v1.10.0 release of Omni!

    Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.

    Following the Audit Log

    The audit log read API gains a follow mode. After serving the backlog the stream stays open and delivers new events as they are written, in insertion order. Followed events carry their ids, and a stream can start from an id received earlier, so a consumer resumes exactly where it left off. The start position can also be given as a timestamp. A follow stream ends cleanly after a bounded time rather than staying open indefinitely, and the client continues from the last id it received. omnictl performs that reconnect automatically. omnictl audit-log gains a --follow flag to tail the log live and a --since flag to start from a relative time in either mode. Reading the audit log now produces an audit log event of its own, recording who read it, the time range requested and the filters used, and the new event type can itself be filtered on.

    Auditor Role

    Reading the audit log required the Admin role, so anything that consumes audit events also had to hold user management and full administrative access to every managed Kubernetes cluster. The new Auditor role grants read access plus the audit log and nothing else. It is matched by exact role rather than by rank, so an Operator, which outranks an Auditor, still cannot read the audit log. It can be assigned to users and service accounts, but not through access policies or SAML label rules, which now reject roles that are not meant to be assigned that way.

    Cluster Security Page

    A new cluster security page lists the vulnerabilities of the images a running cluster uses, together with the upgrade paths that clear them, and the scan details can be filtered by severity. Vulnerability scanning requires the Image Factory Enterprise. Against the public factory the page reports that scanning is unavailable instead of showing results.

    Kubernetes CA and Service Account Key Rejected in Config Patches

    Config patches can no longer set the Kubernetes certificate authority or the service account signing key, which Omni generates and owns. This holds for every cluster, not only for clusters on the new Talos 1.14 document layout, and it covers the v1alpha1 fields as well as the Talos 1.14 documents that carry the same material. An already stored patch keeps working while it stays unchanged. Changing one that sets either of them is rejected, so such a patch has to be corrected before it can be edited again.

    Disabling Config Patches

    A config patch can now be disabled. It is retained as a resource but is never applied.

    Discovery Service Configuration Reworked

    Talos 1.14 replaces the single discovery endpoint with a configuration that can register a machine with more than one discovery service at once, and Omni now removes a departing machine's affiliate from every endpoint it used. A cluster used to pick either the public discovery service or the embedded one. For clusters created with Talos 1.14 or newer it can now also use both at the same time.

    Talos Enterprise and FIPS Machine Labels

    Machines running Talos Enterprise now get an omni.sidero.dev/enterprise label, and machines running Talos in FIPS mode get an omni.sidero.dev/fips label carrying either enabled or strict. Like the other labels Omni manages, they cannot be removed by the user, and they are cleared when a machine reverts to a regular build. Both values are read over the Talos API and watched for changes, since they follow the installed image. Older Talos versions do not report them, so machines running those get no labels.

    Frontend Quality-of-Life Improvements

    Machine names are shown the same way everywhere, using the hostname with the machine UUID as a fallback, and the machine stage is dimmed while a machine is unhealthy, with the last known status still shown. The home page replaces the radial bars with segmented ones and splits the machine stats into connection and allocation, which used to be mixed together, and it now also shows the ongoing operations that were previously only in the top-right dropdown. The CPU usage chart stacks its system and user areas and labels them as percentages, and the Kubernetes manifests status is drawn as a graph. In the disk view, unallocated space is striped so it reads apart from allocated space, and volumes Omni does not recognize cycle through distinct colors. Errors from machine service queries appear inline on the page instead of as a toast, with retries and backoff, and an unreachable Talos API is reported as not ready yet rather than as a generic failure. The config editor can toggle word wrap from its context menu, and $patch: delete is accepted everywhere the patch validation allows it. On an Auth0 instance the very first user lands on the signup page instead of the login page, and PXE boot is hidden when Omni runs against the Image Factory Enterprise. A node's last configuration error is now shown on every one of its tabs, not just the overview, and Talos and Kubernetes version dropdowns list versions newest first. The machine delete confirmation lists hostnames instead of raw UUIDs. Removing machines is named consistently: deleting a machine or a pending machine is "Delete", removing one from a cluster is "Remove", and the destructive machine option reads "Force Delete" instead of "Force Destroy".

    Infrastructure Provider Names Validated as DNS Labels

    An infrastructure provider id must now be a valid DNS label, so lowercase letters, digits and dashes only. Ids with uppercase letters, underscores or spaces used to be accepted and caused failures further along. They are rejected at creation now.

    Infra Provider Versions in the UI and CLI

    The UI and the CLI now show the version of an infrastructure provider.

    Install Disk Selection Respected on Maintenance Installs

    Machines on Talos 1.13 or newer are installed through the Talos lifecycle API, which takes the install disk as an explicit argument. Omni passed the automatically picked default there, so a disk chosen through the UI or a cluster template was ignored and Talos could be installed to a different disk than the one selected. Omni now reads the install disk from the machine's effective configuration, where the selection is already applied on top of the default.

    Permanent Install Failures Stop Retrying

    Talos installers from 1.14 report a distinct exit code per failure instead of one generic code, and Omni now reads them. A failure caused by invalid input or an unsupported operation cannot succeed until the machine configuration or the install options change, so Omni records the reason on the machine and stops retrying. Everything else stays retryable, including the single exit code that pre-1.14 installers report for every failure.

    No kube-proxy Pre-Pull on Kubernetes Upgrades

    Kubernetes upgrades no longer pre-pull the kube-proxy image, on any cluster. Clusters that use a kube-proxy replacement such as Cilium turn kube-proxy off, and pre-pulling an image they never run consumed bandwidth needlessly.

    KubeSpan Quick Start

    Rather than disabling the KubeSpan tab for a cluster that does not have KubeSpan enabled, Omni now shows a quick start page there with a short explanation, a link to the docs, the config patch it would apply, and a button that applies it. The suggested patch matches what the cluster supports, so a cluster on multi-document configs is offered the newer form. The page warns about the network overhead, which matters most on larger clusters. The KubeSpan status view also tells offline peers apart by shape and line style on top of color, which helps with red and green color blindness.

    Installs and Upgrades Through Talos's LifecycleService

    On machines running Talos 1.13 or newer, Omni installs and upgrades through Talos's LifecycleService and runs the sequence itself: pull the installer, install or upgrade to disk, forfeit etcd leadership on control planes, cordon and drain the node, then reboot. Same-minor installs on maintenance machines take this explicit path now, instead of letting a config apply trigger the install, and cluster creation and scale-up bring a maintenance-mode machine to the cluster's Talos version when the two differ by a minor version. Machines on older Talos keep using the classic path, and each machine's running version and schematic decide which one it takes.

    Logout URL

    Every Omni instance now answers at /logout, whatever its authentication type. SAML and OIDC instances were already served by the backend, and Auth0 instances now have a page that performs the logout, so the same URL ends a session everywhere.

    New and Newly Exposed Metrics

    omni_machine_logs_ingested_bytes_total counts the bytes of machine log messages written to storage. Two gauges that were being kept up to date but never registered are now exposed on the Prometheus endpoint as well, one for the number of CPU cores across all machines and one for the number of active virtual state watches.

    Multiple Image Factories

    Omni can now run against two image factories, a primary and a secondary, which makes it possible to migrate from one to the other. They are configured under registries.factories.primary and registries.factories.secondary, each taking a URL, a PXE URL, and Image Factory Enterprise credentials. The flat imageFactoryBaseURL, imageFactoryPXEBaseURL, imageFactoryUsername and imageFactoryPassword options are deprecated in favor of the primary block. They still work on their own, but once the primary block carries a URL they are ignored completely, so credentials meant for one factory are never sent to another.

    Node Audit Skip Configurable in the UI and Cluster Templates

    The node audit skip cluster feature, which exempts a Kubernetes node carrying the omni.sidero.dev/node-audit-skip annotation from the node audit, can now be turned on from the cluster create page and the cluster overview, and set in cluster templates.

    Machine Reset Wipes More Volumes on Talos 1.14

    On Talos 1.14 and newer, resetting a machine also wipes the container runtime, kubelet, etcd and log volumes, on top of the state and ephemeral partitions it wiped before. Machines on earlier Talos versions still have only those two wiped.

    More Reliable SAML Single Logout

    Single logout on a SAML instance could silently fail to reach the identity provider. The cookie tracking the logout was cleared as soon as the logout request was built rather than once the identity provider confirmed it, so any repeated request to /logout, including the browser's own retries, found nothing left to send and the identity provider session survived. A logout response delivered over the HTTP-Redirect binding, rather than as a POST, also failed to parse and left the user on the forbidden page even though the identity provider had already completed the logout; that binding is now handled on its own endpoint.

    Search, Filter and Sort Kept in the URL

    Search terms, filters and sort order are now part of the URL, so a narrowed-down view survives a reload and can be shared as a link.

    Richer Support Bundles

    Support bundles now also carry in-flight machine update state and the inputs Omni uses to generate machine configurations.

    Talos 1.14 Configuration Support

    Talos 1.14 moves cluster identity, certificate authorities, encryption secrets and Talos API access rules out of the single v1alpha1 document into documents of their own, and Omni understands the new layout. Kubernetes component images for upgrades are patched in the shape the cluster's version contract calls for, Kubernetes CA rotation writes the accepted CA wherever the generated configuration keeps it, and the Talos API access restriction follows its own document. The frontend validates patches against the 1.14 schema and generates 1.14 variants of the patches it writes.

    Contributors

    • Edward Sammut Alessi
    • Oguz Kilcan
    • Utku Ozdemir
    • Mateusz Urbanek
    • Maja Bojarska
    • Artem Chernyshev
    • Andrey Smirnov
    • Orzelius
    • Noel Georgi
    • Justin Garrison
    • Mark Glants
    • Mickaël Canévet
    • Nguyen Duc Quynh
    • Olli Hauer
    • Rowan Voermans
    • Sting Alleman
    • Tim Jones

    Changes

    <details><summary>192 commits</summary> <p>

    • 5d2b007bc chore: bump default versions
    • 0a63295b4 fix: make SAML single logout survive retries and redirect binding
    • 0b59f8bee feat(frontend): show config errors on all node pages
    • 7e97185f3 feat(frontend): sort talos/k8s versions newest first
    • e9214cc36 fix(frontend): adjust kubespan quick start text
    • 06b49581a feat(frontend): use hostnames for machine list in delete modal
    • be310e386 feat(frontend): normalise the delete/remove text for machines
    • fd41f737a feat: encrypt support bundles by default
    • 924420dda release(v1.10.0-beta.0): prepare release
    • acc9edb2e feat: classify installer exit codes and skip retrying permanent ones
    • 18bafff42 fix(frontend): adjust toast text for machine removal
    • 02bb82775 fix(frontend): unselect removed machines in machine list
    • d3419f711 test: make the install disk selection test deterministic
    • ee6b16d84 test: reserve integration test machines against concurrent allocation
    • eb5320932 feat(frontend): improve legibility for unallocated and user partitions
    • 2c4940aed fix: drop noisy WireGuard handshake warnings for offline peers
    • 89d418568 feat: for talos 1.14 machine reset also wipe cri, kubelet, etcd, log
    • e040a4b61 fix(frontend): use cluster config version for version contract in scale
    • 5d9489643 fix(frontend): also check version contract in cluster scale
    • dbc458e82 feat(frontend): allow $patch: delete in all places
    • 0b5cafaf3 chore: bump dependencies
    • 9e062ebc5 fix: forbid cluster CA and service account key in config patches
    • 3a4771fab feat: rotate the Kubernetes CA on Talos 1.14 multi-doc configs
    • 6d67db2a6 feat: rework discovery service configuration for Talos 1.14
    • 1cdfd703c fix: track namespaced cluster-scoped manifests as applied
    • 7765bab36 feat: validate multi-doc config patches
    • 2f4f0f382 feat(frontend): add talos 1.14 variants for frontend generated patches
    • 4dcd206a5 feat: expose more version contract fields
    • 202769d74 fix(frontend): use dvh instead of vh for height
    • d02e70432 feat(frontend): add talos 1.14 schema
    • 9cad25799 chore: bump talos machinery
    • 03ad541a4 fix: respect the user's install disk selection in maintenance installs
    • f31cbce00 feat(frontend): redesign manifests status to a graph view
    • 126b6b721 refactor(frontend): refactor kubespan canvas to vue-flow
    • 4546b0968 fix(frontend): trim cluster machine status last_config_error message
    • d04a01230 feat: for kubespan quick start use correct patch for the cluster
    • d34ecf498 feat(client): allow disabling the transparent watch retry
    • 72b942c38 feat: add Auditor role for reading the audit log
    • 0a64c8185 feat: label Talos Enterprise machines
    • f73296960 feat: multiple image factories support
    • 7873fda7a chore: apply CA, Registry configs before install/upgrade calls
    • 53b3c825c feat: support enableNodeAuditSkip in cluster templates
    • b2b2b2050 fix: verify maintenance install/upgrade against the live machine
    • 7bc776663 chore: change virtual ImageFactoryAuth resource to be persistent
    • 72ffae831 fix(frontend): fix incorrect action on patch delete
    • 92215fb7e fix(frontend): preserve whitespace in alerts
    • 4edaf8a41 fix: dont include failed/evicted pods for k8s usage data
    • f5cb97b2e fix(frontend): constrain monitor charts to a fixed size regardless of state
    • b5cff35bf fix(frontend): constrain extensions modals to a fixed size
    • 6cea62574 fix(frontend): dont try load auth0 if we arent using auth0 in userinfo
    • bed3482d1 fix(frontend): don't call machineservice.events for maintenance talos on <1.13
    • 582730ce9 chore: bump deps
    • fb2ae3f74 fix: allow SAMLLabelRule to downgrade user role to None
    • 7b06af519 fix: mark machines installed when the lifecycle install completes
    • 2557f6451 chore: rekres
    • 73e415bec chore(frontend): bump deps
    • 87ca0cdf9 fix(frontend): prevent jumping when select up/down arrows disappear
    • 071f1b295 feat: allow disabling config patches
    • 526e1c635 feat: support following the audit log over the management API
    • d0824edf0 fix: support the new discovery service endpoints list of Talos 1.14
    • 47b66fdf3 feat: show infra provider versions in ui and cli
    • e23a8f7d7 feat: do not pre-pull the kube-proxy image on Kubernetes upgrades
    • e19f19d14 fix: use initial versions from input
    • edcc25692 feat: build version aware Kubernetes component patches for upgrades
    • d0642877b feat(frontend): hide pxe boot option for enterprise
    • 3187ffad3 test: fix Omni upgrade workload proxy DNS
    • 4e8cc051e fix: ignore not-found errors when deleting an infra provider
    • 1476e5389 chore: bump talos machinery to v1.14.0-alpha.2
    • 9d4cfa666 feat(frontend): dim machine stage status when machine is not healthy
    • 89eca085d test: run browser e2e tests off the host network
    • d6bfcee97 feat: serve the frontend dev server through the main endpoint
    • 66a7ba2fd fix: allow removing the bootstrap spec once the cluster is bootstrapped
    • f75c63db6 feat: install same-minor maintenance machines via LifecycleService
    • ff510298b fix: expose the machines cores and virtual state watches metrics
    • df72b2c32 test: use dex oidc instead of auth0 as default for e2e tests
    • 7fcee51e2 test: poll for minio to come up instead of just sleeping
    • 54819dfa2 test(frontend): remove testing of actual iso download
    • 110cf83c2 refactor: proxy frontend dev server routes using prod flow
    • d62f8c866 chore(frontend): update factory staging url for dev
    • 5a751477d feat(frontend): add a /logout route for auth0 logouts
    • 9e3f29030 fix(frontend): skip 0 length bars in home segmented charts
    • 15b1667d7 feat(frontend): handle machine services errors gracefully
    • f161c4377 refactor(frontend): make watch failed errors more informative
    • 7a2477b42 fix: update kube-service-exposer to v0.4.0
    • d0d7d76db feat: introduce the new metric that counts total number of cores
    • 531947830 feat: use LifecycleService for maintenance machine upgrades
    • db6795395 fix: dont clear sa expiration when no keys are left
    • 74cb7078e fix: correct boot ID and Talos version tracking for maintenance installs
    • 3eab1cc10 fix(frontend): remove an unused @click action
    • f3f9cd675 refactor(frontend): make all detached scopes lazily loaded
    • 2be419957 chore(frontend): bump frontend deps
    • 000b16206 fix: honor current machine set update limits
    • 2dfe2e5ae chore: bump oras-go to 2.6.2
    • 16265a1a8 feat(frontend): add word wrap to monaco context menu
    • 0a37d5090 refactor(frontend): don't create new editor and model instance for schema changes
    • 800217124 chore(frontend): add stories for CodeEditor
    • e2f573985 fix(frontend): make CodeEditor props reactive
    • 561d2582d feat: log audit log access in the audit log
    • 0fee0fc30 fix: properly propagate errors coming from the machine lifecycle API
    • b5450ebfb fix: don't treat unset S3 endpoint as an empty override
    • daa126862 test(frontend): adjust fake-indexeddb usage which broke in node 24.18
    • 0618b9015 chore(frontend): bump node to 24.18
    • 5419d7071 feat(frontend): show ongoing operations on the home page
    • 2afd22236 feat(frontend): use segmented bars for home page stats
    • 8b637dc86 chore(frontend): write stories for home page content
    • df33497e2 chore: bump dependencies
    • a47e7128c feat: add machine log ingestion byte-rate metric
    • 7bc30eb08 chore: rekres and bump Go to 1.26.5
    • e05e3285d feat: manage Talos install and upgrade via LifecycleService
    • 2ddeca05f fix(frontend): remove power icon from machines page
    • d0535ada4 feat: expose node audit skip cluster feature
    • 809baa687 feat(frontend): persist search and filters as query strings
    • ee432246d refactor(frontend): rename filterLabel to selectLabel in ItemLabel
    • ab95b0c3b refactor(frontend): refactor LabelsInput to use v-model
    • e6fa2f14e refactor(frontend): replace removeLabel prop with remove emit
    • 5e9ccbd12 refactor(frontend): replace onClear prop with clear emit
    • 14ef61130 feat: send initial instance user to signup page
    • 84f151fe7 fix(frontend): handle aborted requests in useMachineServices
    • 7e0cf44c2 feat(frontend): add a quickstart page for kubespan
    • 8e8a46757 feat(frontend): standardize machine display in omni
    • 2d5610204 fix(frontend): prevent item list flash during connection drops
    • 655c2ae4f refactor(frontend): move itemID into useResourceWatch
    • 8373f536f refactor(frontend): lift interfaces from watch to composable
    • 7fb66d5bd refactor(frontend): merge watch items into composable
    • 37b19c408 refactor(frontend): lift remaining parts of watch class to composable
    • 0e7bb6ae9 refactor(frontend): lift item handlers up to watch composable
    • 640014ecd refactor(frontend): inline watch callbacks
    • 588d21e2c refactor(frontend): remove unnecessary setDescending func
    • c655f002f refactor(frontend): migrate watch tests to useresourcewatch tests
    • 4e4cd5f85 refactor(frontend): move watch.setup into useresourcewatch
    • 81c8c2a40 refactor(frontend): merge watchfunc and watch classes together
    • 104a8b2ab fix(frontend): prevent copying double newlines in machine logs
    • c48c9b923 refactor(frontend): migrate machine set config edit modal to new modal system
    • 2adcefe4d refactor(frontend): migrate create extensions modal to new modal system
    • c435a8f69 refactor(frontend): migrate config patch edit modal to new modal system
    • e7c340668 refactor(frontend): migrate save preset modal to new modal system
    • a7762559d refactor(frontend): hide primary action when maintenance lifecycle complete
    • 971145cc1 refactor(frontend): migrate download preset modal to new modal system
    • f9360c2e9 refactor(frontend): remove unused machine template extensions modal
    • 8ee92b377 refactor(frontend): migrate service account renew to new modal system
    • 022c458fe refactor(frontend): migrate service account create to new modal system
    • 7747a322c refactor(frontend): migrate role edit to new modal system
    • fb9d41f13 refactor(frontend): migrate user destroy to new modal system
    • 384a5347a refactor(frontend): migrate user create to new modal system
    • d69401087 refactor(frontend): migrate machine remove to new modal system
    • e0626db83 refactor(frontend): migrate machine class destroy to new modal system
    • db5540826 refactor(frontend): migrate machine set destroy to new modal system
    • e26d569ad refactor(frontend): migrate export cluster template to new modal system
    • dd5b62550 refactor(frontend): migrate config patch destroy to new modal system
    • 7f1bf6646 refactor(frontend): migrate infra provider delete to new modal system
    • 9bdbeace7 refactor(frontend): migrate infra provider setup to new modal system
    • b94b299b4 refactor(frontend): migrate download omnictl to new modal system
    • 542124bcf refactor(frontend): migrate node shutdown to new modal system
    • fe09adc22 refactor(frontend): migrate node destroy cancel to new modal system
    • d1b56338d refactor(frontend): migrate node destroy to new modal system
    • 02f0d1129 refactor(frontend): migrate node reboot to new modal system
    • 3ddc040e1 test: fix flaky audit log and service account status tests
    • e330092a2 feat: add pending updates and config gen options to support bundle
    • 49c8e725f fix: update COSI runtime to fix hanging TeardownAndDestroy calls
    • c91ce1a50 fix: align config outdated status in ui and cli
    • fde089bbe refactor(frontend): refactor untaint single node modal to new system
    • 094b25913 feat(frontend): add content-class support to confirm modal
    • d193dce9e chore: expose user roles in the public package to be used by scripts
    • 33aa3fa26 refactor(frontend): replace ua-parser-js with bowser
    • 6b2da6745 chore(frontend): drop yaml dependency and move openpgp to dependencies
    • 27c6aa078 chore: rekres for js sbom
    • ed793b6b0 feat(frontend): add filtering to scan details modal
    • 6ef286f27 feat(frontend): add a cluster security page for vulns
    • 99a76d479 refactor(frontend): extract components from scan details modal
    • 034640bbe refactor(frontend): extract business logic from scan details modal
    • 2cf7801dc refactor(frontend): make use resource list default to empty array
    • 120563a38 feat(frontend): stack CPU usage chart areas and format with %
    • 77dcbe90b chore: add stories for monitor view
    • ae93d3f96 fix(frontend): only show process args in command column
    • e690d624b fix(frontend): allow in-minor patch upgrades in update kubernetes on Omni
    • b30472e6c refactor: use ImageServiceClient for pulling images
    • 1c20cc949 chore: bump helm to v4 in zstd-dict
    • 5f4f27df3 fix: recover a machine from a reverted reboot-requiring config patch
    • eadd5b57d fix(frontend): allow force-destroy when MachineSetNode is already gone
    • fd4e5da46 test(frontend): fix some flaky tests in e2e-talemu
    • 1882db158 feat: install/upgrade maintenance-mode Talos during cluster create/scale-up
    • 84180bd0f fix: advertise reachable machine API address in cluster-import test
    • 937ce3a61 fix: keep maintenance Talos clients until machine leaves maintenance
    • a7b87871c refactor: derive extension list from the raw schematic manifest
    • 961a20c60 fix: move timeout for factory requests to controllers
    • e63d4e455 test: drop non-existent preset delete error expectation
    • 6f26c4098 chore: enrich SBOM with Go module licenses
    • 1b337b249 fix: tolerate NotFound on installation media preset delete
    • c2533013c test: stabilize image-factory schematic across CI runs
    • 984ba0090 feat(frontend): add more visual distinction for offline kubespan peers
    • 51cc468db fix: prevent removal of node unique tokens that still have a link
    • 88c77c618 fix: validate infra provider name as DNS-1123 label </p> </details>

    Changes since v1.10.0-beta.0

    <details><summary>8 commits</summary> <p>

    • 5d2b007bc chore: bump default versions
    • 0a63295b4 fix: make SAML single logout survive retries and redirect binding
    • 0b59f8bee feat(frontend): show config errors on all node pages
    • 7e97185f3 feat(frontend): sort talos/k8s versions newest first
    • e9214cc36 fix(frontend): adjust kubespan quick start text
    • 06b49581a feat(frontend): use hostnames for machine list in delete modal
    • be310e386 feat(frontend): normalise the delete/remove text for machines
    • fd41f737a feat: encrypt support bundles by default </p> </details>

    Changes from siderolabs/discovery-service

    <details><summary>13 commits</summary> <p>

    • f03ed02 release(v1.1.0): prepare release
    • 373430a feat(stats): add cached /stats endpoint
    • 0dc4741 chore: bump prometheus, grpc, and otel deps
    • 1479df2 chore: bump net to v0.57.0
    • 709d4b9 chore: bump net pkg to v0.55.0 (security)
    • 0ce4779 chore: bump sync pkg to v0.22.0
    • 9628da0 chore: update go.mod deps
    • 99b6268 chore: rekres
    • 48cf9df chore: bump go to latest 1.26
    • d315a3f chore: fmt
    • f905881 chore: rekres
    • 73b90df feat: add support for x-forwaded-for header
    • 35804da chore: bump dependencies </p> </details>

    Changes from siderolabs/gen

    <details><summary>1 commit</summary> <p>

    • c526410 fix: skip unknown-key check for types with custom YAML unmarshaler </p> </details>

    Changes from siderolabs/go-kubernetes

    <details><summary>3 commits</summary> <p>

    • 0caf1f2 feat: add Kubernetes 1.37 compatibility
    • 822b7a2 feat: add nodedrain package for client-side cordon and drain
    • 260bc0a fix: update authorization config apiVersion for K8s >= 1.32 </p> </details>

    Changes from siderolabs/go-talos-support

    <details><summary>1 commit</summary> <p>

    • 18af7d6 feat: update dependencies and support recipients </p> </details>

    Changes from siderolabs/image-factory

    <details><summary>21 commits</summary> <p>

    • efab38f release(v1.4.0): prepare release
    • 9c64235 feat: add schematic owner validation
    • ca87d23 fix: add single-flight around schematic factory
    • d45b5ac docs: link to Image Factory Enterprise docs page
    • 490a993 chore: bump pkgs revision to match talos v1.14.0-alpha.2
    • f9ff935 chore: bump go pkgs
    • 12cd647 feat: add llms.txt for better LLM usage
    • f65960f fix: audit file defaults
    • f26e5e2 feat: add audit log for authenticated requests
    • beff6e2 feat: support registry namespace prefix for core artifacts
    • 8c489d0 chore: update dependencies
    • 026f8a8 feat: extra extensions (enterprise only)
    • 915ef76 chore: add insecure flag to dev config
    • 3bccbe1 fix: handle single arch images
    • 6b1c855 refactor: prepare for more than one artifact registry
    • bee4fe3 feat: narrow sbom cache key to extension list only
    • e0e4a44 refactor: abstract versioned cache
    • 3359f6c feat: add secureboot enrollKeys schematic option
    • 805c51c feat: add per-request correlation ID to logs
    • 8cee96d feat: assert pxe cache in tests
    • 4ec0789 feat: bump go-conainerregistry </p> </details>

    Dependency Changes

    • github.com/auth0/go-jwt-middleware/v3 v3.2.0 -> v3.3.0
    • github.com/aws/aws-sdk-go-v2 v1.42.0 -> v1.43.2
    • github.com/aws/aws-sdk-go-v2/config v1.32.25 -> v1.32.33
    • github.com/aws/aws-sdk-go-v2/credentials v1.19.24 -> v1.19.32
    • github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager v0.3.7 new
    • github.com/aws/aws-sdk-go-v2/service/s3 v1.104.0 -> v1.106.2
    • github.com/aws/smithy-go v1.27.2 -> v1.27.6
    • github.com/coreos/go-oidc/v3 v3.19.0 -> v3.20.0
    • github.com/cosi-project/runtime v1.16.1 -> v1.16.2
    • github.com/fluxcd/cli-utils v1.2.1 -> v1.2.2
    • github.com/fluxcd/pkg/ssa v0.76.0 -> v0.77.0
    • github.com/go-logr/logr v1.4.3 -> v1.4.4
    • github.com/google/go-containerregistry v0.21.7 -> v0.21.8
    • github.com/johannesboyne/gofakes3 4c385a1f6a73 -> v1.2.0
    • github.com/mattn/go-shellwords v1.0.13 -> v1.0.14
    • github.com/prometheus/client_golang v1.23.2 -> v1.24.1
    • github.com/prometheus/common v0.69.0 -> v0.70.1
    • github.com/siderolabs/discovery-service v1.0.17 -> v1.1.0
    • github.com/siderolabs/gen v0.8.6 -> v0.8.7
    • github.com/siderolabs/go-kubernetes v0.2.39 -> v0.2.41
    • github.com/siderolabs/go-talos-support v0.3.0 -> v0.3.1
    • github.com/siderolabs/image-factory v1.3.3 -> v1.4.0
    • github.com/siderolabs/omni/client v1.8.1 -> v1.9.3
    • github.com/siderolabs/talos/pkg/machinery v1.14.0-alpha.1 -> v1.14.0-beta.1
    • github.com/zitadel/oidc/v3 v3.47.5 -> v3.48.1
    • go.etcd.io/bbolt v1.4.3 -> v1.5.0
    • go.etcd.io/etcd/client/pkg/v3 v3.6.12 -> v3.7.1
    • go.etcd.io/etcd/client/v3 v3.6.12 -> v3.7.1
    • go.etcd.io/etcd/pkg/v3 v3.7.1 new
    • go.etcd.io/etcd/server/v3 v3.6.12 -> v3.7.1
    • go.yaml.in/yaml/v4 v4.0.0-rc.4 -> v4.0.0-rc.6
    • golang.org/x/crypto v0.53.0 -> v0.54.0
    • golang.org/x/net v0.56.0 -> v0.57.0
    • golang.org/x/sync v0.21.0 -> v0.22.0
    • golang.org/x/text v0.38.0 -> v0.40.0
    • golang.org/x/tools v0.46.0 -> v0.48.0
    • google.golang.org/grpc v1.81.1 -> v1.83.0
    • k8s.io/api v0.36.2 -> v0.36.3
    • k8s.io/apimachinery v0.36.2 -> v0.36.3
    • k8s.io/client-go v0.36.2 -> v0.36.3

    Previous release can be found at v1.9.0

    Open source →
  6. v1.10.0-beta.0.0.20260818182222-ee0704f79d07 18 Aug 2026 pre-release

    Nothing published for this version

  7. v1.10.0-beta.0.0.20260818084146-0051462aac63 18 Aug 2026 pre-release

    Nothing published for this version

  8. v1.10.0-beta.0.0.20260814133638-f2aeaa851a8e 14 Aug 2026 pre-release

    Nothing published for this version

  9. v1.10.0-beta.0.0.20260814074331-4c283a3bfcff 14 Aug 2026 pre-release

    Nothing published for this version

  10. v1.10.0-beta.0.0.20260813102735-0f029dcec8ba 13 Aug 2026 pre-release

    Nothing published for this version

  11. v1.10.0-beta.0.0.20260812150027-dbff80519cf7 12 Aug 2026 pre-release

    Nothing published for this version

  12. v1.10.0-beta.0.0.20260812131340-0970a6db2c4c 12 Aug 2026 pre-release

    Nothing published for this version

  13. v1.10.0-beta.0.0.20260812124608-cc23658b0732 12 Aug 2026 pre-release

    Nothing published for this version

  14. v1.10.0-beta.0.0.20260812115117-47845eb51c89 12 Aug 2026 pre-release

    Nothing published for this version

  15. v1.10.0-beta.0.0.20260812113236-194c629cf40e 12 Aug 2026 pre-release

    Nothing published for this version

  16. v1.10.0-beta.0.0.20260812110958-899128ec588d 12 Aug 2026 pre-release

    Nothing published for this version

  17. v1.10.0-beta.0.0.20260811104404-2c70b154142a 11 Aug 2026 pre-release

    Nothing published for this version

  18. v1.10.0-beta.0.0.20260810154917-dc6fa2246f8e 10 Aug 2026 pre-release

    Nothing published for this version

  19. v1.10.0-beta.0.0.20260807143307-0a45ef095534 07 Aug 2026 pre-release

    Nothing published for this version

  20. v1.10.0-beta.0 04 Aug 2026 pre-release
    Release notes

    Welcome to the v1.10.0-beta.0 release of Omni!
    This is a pre-release of Omni

    Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.

    Following the Audit Log

    The audit log read API gains a follow mode. After serving the backlog the stream stays open and delivers new events as they are written, in insertion order. Followed events carry their ids, and a stream can start from an id received earlier, so a consumer resumes exactly where it left off. The start position can also be given as a timestamp. A follow stream ends cleanly after a bounded time rather than staying open indefinitely, and the client continues from the last id it received. omnictl performs that reconnect automatically. omnictl audit-log gains a --follow flag to tail the log live and a --since flag to start from a relative time in either mode. Reading the audit log now produces an audit log event of its own, recording who read it, the time range requested and the filters used, and the new event type can itself be filtered on.

    Auditor Role

    Reading the audit log required the Admin role, so anything that consumes audit events also had to hold user management and full administrative access to every managed Kubernetes cluster. The new Auditor role grants read access plus the audit log and nothing else. It is matched by exact role rather than by rank, so an Operator, which outranks an Auditor, still cannot read the audit log. It can be assigned to users and service accounts, but not through access policies or SAML label rules, which now reject roles that are not meant to be assigned that way.

    Cluster Security Page

    A new cluster security page lists the vulnerabilities of the images a running cluster uses, together with the upgrade paths that clear them, and the scan details can be filtered by severity. Vulnerability scanning requires the Image Factory Enterprise. Against the public factory the page reports that scanning is unavailable instead of showing results.

    Kubernetes CA and Service Account Key Rejected in Config Patches

    Config patches can no longer set the Kubernetes certificate authority or the service account signing key, which Omni generates and owns. This holds for every cluster, not only for clusters on the new Talos 1.14 document layout, and it covers the v1alpha1 fields as well as the Talos 1.14 documents that carry the same material. An already stored patch keeps working while it stays unchanged. Changing one that sets either of them is rejected, so such a patch has to be corrected before it can be edited again.

    Disabling Config Patches

    A config patch can now be disabled. It is retained as a resource but is never applied.

    Discovery Service Configuration Reworked

    Talos 1.14 replaces the single discovery endpoint with a configuration that can register a machine with more than one discovery service at once, and Omni now removes a departing machine's affiliate from every endpoint it used. A cluster used to pick either the public discovery service or the embedded one. For clusters created with Talos 1.14 or newer it can now also use both at the same time.

    Talos Enterprise and FIPS Machine Labels

    Machines running Talos Enterprise now get an omni.sidero.dev/enterprise label, and machines running Talos in FIPS mode get an omni.sidero.dev/fips label carrying either enabled or strict. Like the other labels Omni manages, they cannot be removed by the user, and they are cleared when a machine reverts to a regular build. Both values are read over the Talos API and watched for changes, since they follow the installed image. Older Talos versions do not report them, so machines running those get no labels.

    Frontend Quality-of-Life Improvements

    Machine names are shown the same way everywhere, using the hostname with the machine UUID as a fallback, and the machine stage is dimmed while a machine is unhealthy, with the last known status still shown. The home page replaces the radial bars with segmented ones and splits the machine stats into connection and allocation, which used to be mixed together, and it now also shows the ongoing operations that were previously only in the top-right dropdown. The CPU usage chart stacks its system and user areas and labels them as percentages, and the Kubernetes manifests status is drawn as a graph. In the disk view, unallocated space is striped so it reads apart from allocated space, and volumes Omni does not recognize cycle through distinct colors. Errors from machine service queries appear inline on the page instead of as a toast, with retries and backoff, and an unreachable Talos API is reported as not ready yet rather than as a generic failure. The config editor can toggle word wrap from its context menu, and $patch: delete is accepted everywhere the patch validation allows it. On an Auth0 instance the very first user lands on the signup page instead of the login page, and PXE boot is hidden when Omni runs against the Image Factory Enterprise.

    Infrastructure Provider Names Validated as DNS Labels

    An infrastructure provider id must now be a valid DNS label, so lowercase letters, digits and dashes only. Ids with uppercase letters, underscores or spaces used to be accepted and caused failures further along. They are rejected at creation now.

    Infra Provider Versions in the UI and CLI

    The UI and the CLI now show the version of an infrastructure provider.

    Install Disk Selection Respected on Maintenance Installs

    Machines on Talos 1.13 or newer are installed through the Talos lifecycle API, which takes the install disk as an explicit argument. Omni passed the automatically picked default there, so a disk chosen through the UI or a cluster template was ignored and Talos could be installed to a different disk than the one selected. Omni now reads the install disk from the machine's effective configuration, where the selection is already applied on top of the default.

    Permanent Install Failures Stop Retrying

    Talos installers from 1.14 report a distinct exit code per failure instead of one generic code, and Omni now reads them. A failure caused by invalid input or an unsupported operation cannot succeed until the machine configuration or the install options change, so Omni records the reason on the machine and stops retrying. Everything else stays retryable, including the single exit code that pre-1.14 installers report for every failure.

    No kube-proxy Pre-Pull on Kubernetes Upgrades

    Kubernetes upgrades no longer pre-pull the kube-proxy image, on any cluster. Clusters that use a kube-proxy replacement such as Cilium turn kube-proxy off, and pre-pulling an image they never run consumed bandwidth needlessly.

    KubeSpan Quick Start

    Rather than disabling the KubeSpan tab for a cluster that does not have KubeSpan enabled, Omni now shows a quick start page there with a short explanation, a link to the docs, the config patch it would apply, and a button that applies it. The suggested patch matches what the cluster supports, so a cluster on multi-document configs is offered the newer form. The page warns about the network overhead, which matters most on larger clusters. The KubeSpan status view also tells offline peers apart by shape and line style on top of color, which helps with red and green color blindness.

    Installs and Upgrades Through Talos's LifecycleService

    On machines running Talos 1.13 or newer, Omni installs and upgrades through Talos's LifecycleService and runs the sequence itself: pull the installer, install or upgrade to disk, forfeit etcd leadership on control planes, cordon and drain the node, then reboot. Same-minor installs on maintenance machines take this explicit path now, instead of letting a config apply trigger the install, and cluster creation and scale-up bring a maintenance-mode machine to the cluster's Talos version when the two differ by a minor version. Machines on older Talos keep using the classic path, and each machine's running version and schematic decide which one it takes.

    Logout URL

    Every Omni instance now answers at /logout, whatever its authentication type. SAML and OIDC instances were already served by the backend, and Auth0 instances now have a page that performs the logout, so the same URL ends a session everywhere.

    New and Newly Exposed Metrics

    omni_machine_logs_ingested_bytes_total counts the bytes of machine log messages written to storage. Two gauges that were being kept up to date but never registered are now exposed on the Prometheus endpoint as well, one for the number of CPU cores across all machines and one for the number of active virtual state watches.

    Multiple Image Factories

    Omni can now run against two image factories, a primary and a secondary, which makes it possible to migrate from one to the other. They are configured under registries.factories.primary and registries.factories.secondary, each taking a URL, a PXE URL, and Image Factory Enterprise credentials. The flat imageFactoryBaseURL, imageFactoryPXEBaseURL, imageFactoryUsername and imageFactoryPassword options are deprecated in favor of the primary block. They still work on their own, but once the primary block carries a URL they are ignored completely, so credentials meant for one factory are never sent to another.

    Node Audit Skip Configurable in the UI and Cluster Templates

    The node audit skip cluster feature, which exempts a Kubernetes node carrying the omni.sidero.dev/node-audit-skip annotation from the node audit, can now be turned on from the cluster create page and the cluster overview, and set in cluster templates.

    Machine Reset Wipes More Volumes on Talos 1.14

    On Talos 1.14 and newer, resetting a machine also wipes the container runtime, kubelet, etcd and log volumes, on top of the state and ephemeral partitions it wiped before. Machines on earlier Talos versions still have only those two wiped.

    Search, Filter and Sort Kept in the URL

    Search terms, filters and sort order are now part of the URL, so a narrowed-down view survives a reload and can be shared as a link.

    Richer Support Bundles

    Support bundles now also carry in-flight machine update state and the inputs Omni uses to generate machine configurations.

    Talos 1.14 Configuration Support

    Talos 1.14 moves cluster identity, certificate authorities, encryption secrets and Talos API access rules out of the single v1alpha1 document into documents of their own, and Omni understands the new layout. Kubernetes component images for upgrades are patched in the shape the cluster's version contract calls for, Kubernetes CA rotation writes the accepted CA wherever the generated configuration keeps it, and the Talos API access restriction follows its own document. The frontend validates patches against the 1.14 schema and generates 1.14 variants of the patches it writes.

    Contributors

    • Edward Sammut Alessi
    • Oguz Kilcan
    • Utku Ozdemir
    • Mateusz Urbanek
    • Maja Bojarska
    • Artem Chernyshev
    • Andrey Smirnov
    • Orzelius
    • Noel Georgi
    • Justin Garrison
    • Mark Glants
    • Mickaël Canévet
    • Nguyen Duc Quynh
    • Olli Hauer
    • Rowan Voermans
    • Sting Alleman
    • Tim Jones

    Changes

    <details><summary>183 commits</summary> <p>

    • acc9edb2 feat: classify installer exit codes and skip retrying permanent ones
    • 18bafff4 fix(frontend): adjust toast text for machine removal
    • 02bb8277 fix(frontend): unselect removed machines in machine list
    • d3419f71 test: make the install disk selection test deterministic
    • ee6b16d8 test: reserve integration test machines against concurrent allocation
    • eb532093 feat(frontend): improve legibility for unallocated and user partitions
    • 2c4940ae fix: drop noisy WireGuard handshake warnings for offline peers
    • 89d41856 feat: for talos 1.14 machine reset also wipe cri, kubelet, etcd, log
    • e040a4b6 fix(frontend): use cluster config version for version contract in scale
    • 5d948964 fix(frontend): also check version contract in cluster scale
    • dbc458e8 feat(frontend): allow $patch: delete in all places
    • 0b5cafaf chore: bump dependencies
    • 9e062ebc fix: forbid cluster CA and service account key in config patches
    • 3a4771fa feat: rotate the Kubernetes CA on Talos 1.14 multi-doc configs
    • 6d67db2a feat: rework discovery service configuration for Talos 1.14
    • 1cdfd703 fix: track namespaced cluster-scoped manifests as applied
    • 7765bab3 feat: validate multi-doc config patches
    • 2f4f0f38 feat(frontend): add talos 1.14 variants for frontend generated patches
    • 4dcd206a feat: expose more version contract fields
    • 202769d7 fix(frontend): use dvh instead of vh for height
    • d02e7043 feat(frontend): add talos 1.14 schema
    • 9cad2579 chore: bump talos machinery
    • 03ad541a fix: respect the user's install disk selection in maintenance installs
    • f31cbce0 feat(frontend): redesign manifests status to a graph view
    • 126b6b72 refactor(frontend): refactor kubespan canvas to vue-flow
    • 4546b096 fix(frontend): trim cluster machine status last_config_error message
    • d04a0123 feat: for kubespan quick start use correct patch for the cluster
    • d34ecf49 feat(client): allow disabling the transparent watch retry
    • 72b942c3 feat: add Auditor role for reading the audit log
    • 0a64c818 feat: label Talos Enterprise machines
    • f7329696 feat: multiple image factories support
    • 7873fda7 chore: apply CA, Registry configs before install/upgrade calls
    • 53b3c825 feat: support enableNodeAuditSkip in cluster templates
    • b2b2b205 fix: verify maintenance install/upgrade against the live machine
    • 7bc77666 chore: change virtual ImageFactoryAuth resource to be persistent
    • 72ffae83 fix(frontend): fix incorrect action on patch delete
    • 92215fb7 fix(frontend): preserve whitespace in alerts
    • 4edaf8a4 fix: dont include failed/evicted pods for k8s usage data
    • f5cb97b2 fix(frontend): constrain monitor charts to a fixed size regardless of state
    • b5cff35b fix(frontend): constrain extensions modals to a fixed size
    • 6cea6257 fix(frontend): dont try load auth0 if we arent using auth0 in userinfo
    • bed3482d fix(frontend): don't call machineservice.events for maintenance talos on <1.13
    • 582730ce chore: bump deps
    • fb2ae3f7 fix: allow SAMLLabelRule to downgrade user role to None
    • 7b06af51 fix: mark machines installed when the lifecycle install completes
    • 2557f645 chore: rekres
    • 73e415be chore(frontend): bump deps
    • 87ca0cdf fix(frontend): prevent jumping when select up/down arrows disappear
    • 071f1b29 feat: allow disabling config patches
    • 526e1c63 feat: support following the audit log over the management API
    • d0824edf fix: support the new discovery service endpoints list of Talos 1.14
    • 47b66fdf feat: show infra provider versions in ui and cli
    • e23a8f7d feat: do not pre-pull the kube-proxy image on Kubernetes upgrades
    • e19f19d1 fix: use initial versions from input
    • edcc2569 feat: build version aware Kubernetes component patches for upgrades
    • d0642877 feat(frontend): hide pxe boot option for enterprise
    • 3187ffad test: fix Omni upgrade workload proxy DNS
    • 4e8cc051 fix: ignore not-found errors when deleting an infra provider
    • 1476e538 chore: bump talos machinery to v1.14.0-alpha.2
    • 9d4cfa66 feat(frontend): dim machine stage status when machine is not healthy
    • 89eca085 test: run browser e2e tests off the host network
    • d6bfcee9 feat: serve the frontend dev server through the main endpoint
    • 66a7ba2f fix: allow removing the bootstrap spec once the cluster is bootstrapped
    • f75c63db feat: install same-minor maintenance machines via LifecycleService
    • ff510298 fix: expose the machines cores and virtual state watches metrics
    • df72b2c3 test: use dex oidc instead of auth0 as default for e2e tests
    • 7fcee51e test: poll for minio to come up instead of just sleeping
    • 54819dfa test(frontend): remove testing of actual iso download
    • 110cf83c refactor: proxy frontend dev server routes using prod flow
    • d62f8c86 chore(frontend): update factory staging url for dev
    • 5a751477 feat(frontend): add a /logout route for auth0 logouts
    • 9e3f2903 fix(frontend): skip 0 length bars in home segmented charts
    • 15b1667d feat(frontend): handle machine services errors gracefully
    • f161c437 refactor(frontend): make watch failed errors more informative
    • 7a2477b4 fix: update kube-service-exposer to v0.4.0
    • d0d7d76d feat: introduce the new metric that counts total number of cores
    • 53194783 feat: use LifecycleService for maintenance machine upgrades
    • db679539 fix: dont clear sa expiration when no keys are left
    • 74cb7078 fix: correct boot ID and Talos version tracking for maintenance installs
    • 3eab1cc1 fix(frontend): remove an unused @click action
    • f3f9cd67 refactor(frontend): make all detached scopes lazily loaded
    • 2be41995 chore(frontend): bump frontend deps
    • 000b1620 fix: honor current machine set update limits
    • 2dfe2e5a chore: bump oras-go to 2.6.2
    • 16265a1a feat(frontend): add word wrap to monaco context menu
    • 0a37d509 refactor(frontend): don't create new editor and model instance for schema changes
    • 80021712 chore(frontend): add stories for CodeEditor
    • e2f57398 fix(frontend): make CodeEditor props reactive
    • 561d2582 feat: log audit log access in the audit log
    • 0fee0fc3 fix: properly propagate errors coming from the machine lifecycle API
    • b5450ebf fix: don't treat unset S3 endpoint as an empty override
    • daa12686 test(frontend): adjust fake-indexeddb usage which broke in node 24.18
    • 0618b901 chore(frontend): bump node to 24.18
    • 5419d707 feat(frontend): show ongoing operations on the home page
    • 2afd2223 feat(frontend): use segmented bars for home page stats
    • 8b637dc8 chore(frontend): write stories for home page content
    • df33497e chore: bump dependencies
    • a47e7128 feat: add machine log ingestion byte-rate metric
    • 7bc30eb0 chore: rekres and bump Go to 1.26.5
    • e05e3285 feat: manage Talos install and upgrade via LifecycleService
    • 2ddeca05 fix(frontend): remove power icon from machines page
    • d0535ada feat: expose node audit skip cluster feature
    • 809baa68 feat(frontend): persist search and filters as query strings
    • ee432246 refactor(frontend): rename filterLabel to selectLabel in ItemLabel
    • ab95b0c3 refactor(frontend): refactor LabelsInput to use v-model
    • e6fa2f14 refactor(frontend): replace removeLabel prop with remove emit
    • 5e9ccbd1 refactor(frontend): replace onClear prop with clear emit
    • 14ef6113 feat: send initial instance user to signup page
    • 84f151fe fix(frontend): handle aborted requests in useMachineServices
    • 7e0cf44c feat(frontend): add a quickstart page for kubespan
    • 8e8a4675 feat(frontend): standardize machine display in omni
    • 2d561020 fix(frontend): prevent item list flash during connection drops
    • 655c2ae4 refactor(frontend): move itemID into useResourceWatch
    • 8373f536 refactor(frontend): lift interfaces from watch to composable
    • 7fb66d5b refactor(frontend): merge watch items into composable
    • 37b19c40 refactor(frontend): lift remaining parts of watch class to composable
    • 0e7bb6ae refactor(frontend): lift item handlers up to watch composable
    • 640014ec refactor(frontend): inline watch callbacks
    • 588d21e2 refactor(frontend): remove unnecessary setDescending func
    • c655f002 refactor(frontend): migrate watch tests to useresourcewatch tests
    • 4e4cd5f8 refactor(frontend): move watch.setup into useresourcewatch
    • 81c8c2a4 refactor(frontend): merge watchfunc and watch classes together
    • 104a8b2a fix(frontend): prevent copying double newlines in machine logs
    • c48c9b92 refactor(frontend): migrate machine set config edit modal to new modal system
    • 2adcefe4 refactor(frontend): migrate create extensions modal to new modal system
    • c435a8f6 refactor(frontend): migrate config patch edit modal to new modal system
    • e7c34066 refactor(frontend): migrate save preset modal to new modal system
    • a7762559 refactor(frontend): hide primary action when maintenance lifecycle complete
    • 971145cc refactor(frontend): migrate download preset modal to new modal system
    • f9360c2e refactor(frontend): remove unused machine template extensions modal
    • 8ee92b37 refactor(frontend): migrate service account renew to new modal system
    • 022c458f refactor(frontend): migrate service account create to new modal system
    • 7747a322 refactor(frontend): migrate role edit to new modal system
    • fb9d41f1 refactor(frontend): migrate user destroy to new modal system
    • 384a5347 refactor(frontend): migrate user create to new modal system
    • d6940108 refactor(frontend): migrate machine remove to new modal system
    • e0626db8 refactor(frontend): migrate machine class destroy to new modal system
    • db554082 refactor(frontend): migrate machine set destroy to new modal system
    • e26d569a refactor(frontend): migrate export cluster template to new modal system
    • dd5b6255 refactor(frontend): migrate config patch destroy to new modal system
    • 7f1bf664 refactor(frontend): migrate infra provider delete to new modal system
    • 9bdbeace refactor(frontend): migrate infra provider setup to new modal system
    • b94b299b refactor(frontend): migrate download omnictl to new modal system
    • 542124bc refactor(frontend): migrate node shutdown to new modal system
    • fe09adc2 refactor(frontend): migrate node destroy cancel to new modal system
    • d1b56338 refactor(frontend): migrate node destroy to new modal system
    • 02f0d112 refactor(frontend): migrate node reboot to new modal system
    • 3ddc040e test: fix flaky audit log and service account status tests
    • e330092a feat: add pending updates and config gen options to support bundle
    • 49c8e725 fix: update COSI runtime to fix hanging TeardownAndDestroy calls
    • c91ce1a5 fix: align config outdated status in ui and cli
    • fde089bb refactor(frontend): refactor untaint single node modal to new system
    • 094b2591 feat(frontend): add content-class support to confirm modal
    • d193dce9 chore: expose user roles in the public package to be used by scripts
    • 33aa3fa2 refactor(frontend): replace ua-parser-js with bowser
    • 6b2da674 chore(frontend): drop yaml dependency and move openpgp to dependencies
    • 27c6aa07 chore: rekres for js sbom
    • ed793b6b feat(frontend): add filtering to scan details modal
    • 6ef286f2 feat(frontend): add a cluster security page for vulns
    • 99a76d47 refactor(frontend): extract components from scan details modal
    • 034640bb refactor(frontend): extract business logic from scan details modal
    • 2cf7801d refactor(frontend): make use resource list default to empty array
    • 120563a3 feat(frontend): stack CPU usage chart areas and format with %
    • 77dcbe90 chore: add stories for monitor view
    • ae93d3f9 fix(frontend): only show process args in command column
    • e690d624 fix(frontend): allow in-minor patch upgrades in update kubernetes on Omni
    • b30472e6 refactor: use ImageServiceClient for pulling images
    • 1c20cc94 chore: bump helm to v4 in zstd-dict
    • 5f4f27df fix: recover a machine from a reverted reboot-requiring config patch
    • eadd5b57 fix(frontend): allow force-destroy when MachineSetNode is already gone
    • fd4e5da4 test(frontend): fix some flaky tests in e2e-talemu
    • 1882db15 feat: install/upgrade maintenance-mode Talos during cluster create/scale-up
    • 84180bd0 fix: advertise reachable machine API address in cluster-import test
    • 937ce3a6 fix: keep maintenance Talos clients until machine leaves maintenance
    • a7b87871 refactor: derive extension list from the raw schematic manifest
    • 961a20c6 fix: move timeout for factory requests to controllers
    • e63d4e45 test: drop non-existent preset delete error expectation
    • 6f26c409 chore: enrich SBOM with Go module licenses
    • 1b337b24 fix: tolerate NotFound on installation media preset delete
    • c2533013 test: stabilize image-factory schematic across CI runs
    • 984ba009 feat(frontend): add more visual distinction for offline kubespan peers
    • 51cc468d fix: prevent removal of node unique tokens that still have a link
    • 88c77c61 fix: validate infra provider name as DNS-1123 label </p> </details>

    Changes from siderolabs/discovery-service

    <details><summary>13 commits</summary> <p>

    • f03ed02 release(v1.1.0): prepare release
    • 373430a feat(stats): add cached /stats endpoint
    • 0dc4741 chore: bump prometheus, grpc, and otel deps
    • 1479df2 chore: bump net to v0.57.0
    • 709d4b9 chore: bump net pkg to v0.55.0 (security)
    • 0ce4779 chore: bump sync pkg to v0.22.0
    • 9628da0 chore: update go.mod deps
    • 99b6268 chore: rekres
    • 48cf9df chore: bump go to latest 1.26
    • d315a3f chore: fmt
    • f905881 chore: rekres
    • 73b90df feat: add support for x-forwaded-for header
    • 35804da chore: bump dependencies </p> </details>

    Changes from siderolabs/gen

    <details><summary>1 commit</summary> <p>

    • c526410 fix: skip unknown-key check for types with custom YAML unmarshaler </p> </details>

    Changes from siderolabs/go-kubernetes

    <details><summary>3 commits</summary> <p>

    • 0caf1f2 feat: add Kubernetes 1.37 compatibility
    • 822b7a2 feat: add nodedrain package for client-side cordon and drain
    • 260bc0a fix: update authorization config apiVersion for K8s >= 1.32 </p> </details>

    Changes from siderolabs/image-factory

    <details><summary>21 commits</summary> <p>

    • efab38f release(v1.4.0): prepare release
    • 9c64235 feat: add schematic owner validation
    • ca87d23 fix: add single-flight around schematic factory
    • d45b5ac docs: link to Image Factory Enterprise docs page
    • 490a993 chore: bump pkgs revision to match talos v1.14.0-alpha.2
    • f9ff935 chore: bump go pkgs
    • 12cd647 feat: add llms.txt for better LLM usage
    • f65960f fix: audit file defaults
    • f26e5e2 feat: add audit log for authenticated requests
    • beff6e2 feat: support registry namespace prefix for core artifacts
    • 8c489d0 chore: update dependencies
    • 026f8a8 feat: extra extensions (enterprise only)
    • 915ef76 chore: add insecure flag to dev config
    • 3bccbe1 fix: handle single arch images
    • 6b1c855 refactor: prepare for more than one artifact registry
    • bee4fe3 feat: narrow sbom cache key to extension list only
    • e0e4a44 refactor: abstract versioned cache
    • 3359f6c feat: add secureboot enrollKeys schematic option
    • 805c51c feat: add per-request correlation ID to logs
    • 8cee96d feat: assert pxe cache in tests
    • 4ec0789 feat: bump go-conainerregistry </p> </details>

    Dependency Changes

    • github.com/auth0/go-jwt-middleware/v3 v3.2.0 -> v3.3.0
    • github.com/aws/aws-sdk-go-v2 v1.42.0 -> v1.43.2
    • github.com/aws/aws-sdk-go-v2/config v1.32.25 -> v1.32.33
    • github.com/aws/aws-sdk-go-v2/credentials v1.19.24 -> v1.19.32
    • github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager v0.3.7 new
    • github.com/aws/aws-sdk-go-v2/service/s3 v1.104.0 -> v1.106.2
    • github.com/aws/smithy-go v1.27.2 -> v1.27.6
    • github.com/coreos/go-oidc/v3 v3.19.0 -> v3.20.0
    • github.com/cosi-project/runtime v1.16.1 -> v1.16.2
    • github.com/fluxcd/cli-utils v1.2.1 -> v1.2.2
    • github.com/fluxcd/pkg/ssa v0.76.0 -> v0.77.0
    • github.com/go-logr/logr v1.4.3 -> v1.4.4
    • github.com/google/go-containerregistry v0.21.7 -> v0.21.8
    • github.com/johannesboyne/gofakes3 4c385a1f6a73 -> v1.2.0
    • github.com/mattn/go-shellwords v1.0.13 -> v1.0.14
    • github.com/prometheus/client_golang v1.23.2 -> v1.24.1
    • github.com/prometheus/common v0.69.0 -> v0.70.1
    • github.com/siderolabs/discovery-service v1.0.17 -> v1.1.0
    • github.com/siderolabs/gen v0.8.6 -> v0.8.7
    • github.com/siderolabs/go-kubernetes v0.2.39 -> v0.2.41
    • github.com/siderolabs/image-factory v1.3.3 -> v1.4.0
    • github.com/siderolabs/omni/client v1.8.1 -> v1.9.3
    • github.com/siderolabs/talos/pkg/machinery v1.14.0-alpha.1 -> v1.14.0-beta.1
    • github.com/zitadel/oidc/v3 v3.47.5 -> v3.48.1
    • go.etcd.io/bbolt v1.4.3 -> v1.5.0
    • go.etcd.io/etcd/client/pkg/v3 v3.6.12 -> v3.7.1
    • go.etcd.io/etcd/client/v3 v3.6.12 -> v3.7.1
    • go.etcd.io/etcd/pkg/v3 v3.7.1 new
    • go.etcd.io/etcd/server/v3 v3.6.12 -> v3.7.1
    • go.yaml.in/yaml/v4 v4.0.0-rc.4 -> v4.0.0-rc.6
    • golang.org/x/crypto v0.53.0 -> v0.54.0
    • golang.org/x/net v0.56.0 -> v0.57.0
    • golang.org/x/sync v0.21.0 -> v0.22.0
    • golang.org/x/text v0.38.0 -> v0.40.0
    • golang.org/x/tools v0.46.0 -> v0.48.0
    • google.golang.org/grpc v1.81.1 -> v1.83.0
    • k8s.io/api v0.36.2 -> v0.36.3
    • k8s.io/apimachinery v0.36.2 -> v0.36.3
    • k8s.io/client-go v0.36.2 -> v0.36.3

    Previous release can be found at v1.9.0

    Open source →
  21. v1.9.3 16 Jul 2026

    Nothing published for this version

  22. v1.9.2 16 Jul 2026

    Nothing published for this version

  23. v1.9.1 02 Jul 2026

    Nothing published for this version

  24. v1.9.0 25 Jun 2026

    Nothing published for this version

  25. v1.9.0-beta.1.0.20260729155718-f31cbce0032c 29 Jul 2026 pre-release

    Nothing published for this version

  26. v1.9.0-beta.1.0.20260729124326-d04a012309e5 29 Jul 2026 pre-release

    Nothing published for this version

  27. v1.9.0-beta.1.0.20260729115545-d34ecf49816b 29 Jul 2026 pre-release

    Nothing published for this version

  28. v1.9.0-beta.1.0.20260728221112-0a64c8185015 28 Jul 2026 pre-release

    Nothing published for this version

  29. v1.9.0-beta.1.0.20260727121546-7873fda7aa9e 27 Jul 2026 pre-release

    Nothing published for this version

  30. v1.9.0-beta.1.0.20260724185746-53b3c825c481 24 Jul 2026 pre-release

    Nothing published for this version

  31. v1.9.0-beta.1.0.20260724093126-72ffae83171b 24 Jul 2026 pre-release

    Nothing published for this version

  32. v1.9.0-beta.1.0.20260723121807-582730ce940c 23 Jul 2026 pre-release

    Nothing published for this version

  33. v1.9.0-beta.1.0.20260721120301-47b66fdf394a 21 Jul 2026 pre-release

    Nothing published for this version

  34. v1.9.0-beta.1.0.20260721112609-e23a8f7d71d1 21 Jul 2026 pre-release

    Nothing published for this version

  35. v1.9.0-beta.1.0.20260720124257-edcc256921e8 20 Jul 2026 pre-release

    Nothing published for this version

  36. v1.9.0-beta.1.0.20260717141052-1476e5389b4d 17 Jul 2026 pre-release

    Nothing published for this version

  37. v1.9.0-beta.1.0.20260717132753-9d4cfa66606e 17 Jul 2026 pre-release

    Nothing published for this version

  38. v1.9.0-beta.1.0.20260717115409-89eca085d399 17 Jul 2026 pre-release

    Nothing published for this version

  39. v1.9.0-beta.1.0.20260716153611-ff510298b80b 16 Jul 2026 pre-release

    Nothing published for this version

  40. v1.9.0-beta.1.0.20260716104655-9e3f29030063 16 Jul 2026 pre-release

    Nothing published for this version

  41. v1.9.0-beta.1.0.20260715163052-d0d7d76db5c6 15 Jul 2026 pre-release

    Nothing published for this version

  42. v1.9.0-beta.1.0.20260702125353-104a8b2abe5a 02 Jul 2026 pre-release

    Nothing published for this version

  43. v1.9.0-beta.1.0.20260701150613-e330092a2c73 01 Jul 2026 pre-release

    Nothing published for this version

  44. v1.9.0-beta.1.0.20260701144727-49c8e725f6a1 01 Jul 2026 pre-release

    Nothing published for this version

  45. v1.9.0-beta.1.0.20260626130436-5f4f27df3315 26 Jun 2026 pre-release

    Nothing published for this version

  46. v1.9.0-beta.1.0.20260625231033-84180bd0fd7f 25 Jun 2026 pre-release

    Nothing published for this version

  47. v1.9.0-beta.1 23 Jun 2026 pre-release
    Release notes

    Welcome to the v1.9.0-beta.1 release of Omni!
    This is a pre-release of Omni

    Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.

    Cluster Health Check Jobs

    Cluster templates now support health check jobs that gate Talos upgrades. Omni creates the jobs when a Talos upgrade is running and re-runs them on an interval until they succeed, re-creating a job whenever it fails. The checks run before each node upgrade in the upgrade status controller, and if any defined health check fails Omni drops the available upgrade quota to zero, blocking further upgrades until the checks pass. You can read more about this feature on the docs.

    Embedded Machine Config for Installation Media

    Installation media can now carry an embedded machine configuration, so a machine applies it on first boot before it ever reaches Omni. You can set it from the frontend or with omnictl when creating installation media, and Omni stores it on the schematic request alongside the rest of the media config. The option is exposed only where the underlying stack reports support for it, through a new supports_embedded_config quirk.

    Per-Class etcd Write Rate Limiting

    You can now throttle etcd writes by payload size, with separate budgets for end users, infra providers, and internal callers. It is off by default and turns on via storage.rateLimits.etcd.*. Four new Prometheus series report throttle wait time, admitted writes, rejected writes, and rejected bytes, labeled by class. The failure counters also carry a reason of timeout or oversize.

    Talos Extension Names Validated Against the Catalog

    Extension names on installation media configs, machine request sets, and extensions configurations are now validated against the Talos extensions catalog for the relevant Talos version. Unknown names, duplicates, and oversized lists are rejected, and when no Talos version is set the default version's catalog is used so the names still get checked. Names without a namespace are looked up under siderolabs/, so older clients that send the documented short form keep working. The omnictl installation media create command now resolves short or partial extension names to canonical form before sending, replacing the client-side catalog check it used to do.

    KubeSpan Status View

    A new graphical view shows KubeSpan peer status for a cluster machine.

    Frontend Quality-of-Life Improvements

    A round of UI improvements across Omni. The home screen has a reworked "Welcome to Omni" card. An unhealthy infrastructure provider shows its error on hover, the machine details panel shows the SMBIOS serial number, and kernel args editing moved into a modal. Config diffs have a sort-order toggle, version pickers sort newest first and scroll to the current selection, and Talos and Kubernetes update calls now report their errors. The disks view got several cleanups, pods sort by status, power-state icons have tooltips, Omni shows a loading indicator when it is slow to start, and the rewritten log viewer scrolls to the bottom reliably. Machine patches no longer offer the cluster-machine patch option and surface an error when a machine is not part of a cluster.

    Static loadBalancerIP for the WireGuard Service in Helm

    The Helm chart has a new service.wireguard.loadBalancerIP value for setting a static load balancer IP on the WireGuard Kubernetes Service. It is rendered only when the WireGuard service type is LoadBalancer.

    Support for Image Factory Enterprise

    Two new config options, registries.imageFactoryUsername and registries.imageFactoryPassword, let Omni authenticate to the Image Factory Enterprise with HTTP basic auth.

    Kubernetes Manifests Status in the UI

    The frontend now shows the status of a cluster's synced Kubernetes manifests.

    Per-Machine Log Ingestion Rate Limit

    Log ingestion now uses a per-machine token bucket, so one noisy machine can no longer overwhelm the log store. It is off by default to keep backwards compatibility.

    Machine Config Patches in Maintenance Mode

    Omni can now apply machine-level config patches while a machine is still in maintenance mode, not just after it joins a cluster. The patches go on top of the configuration the machine already runs, next to the SideroLink documents Omni manages, and Omni will not apply a document that installs Talos and pulls the machine out of maintenance. Omni also keeps whatever configuration a machine connects with as a low-priority, user-owned patch. So a machine that arrives with its own config (say a TrustedRootsConfig document) keeps it, and your own patches still win.

    Install and Upgrade Talos in Maintenance Mode

    A new streaming management API installs or upgrades Talos on machines booted in maintenance mode. It comes with omnictl install and upgrade subcommands and frontend modals that stream installer progress live. This feature uses Talos's LifecycleService API, which became available in v1.13.0. So it works with any Talos version starting from v1.13.0.

    SBOM, VEX, and Vulnerability Scan on the Installation Media Wizard

    The installation media wizard's confirmation page now shows SBOM and VEX links plus the vulnerability scan and modal, the same as the Image Factory. This shows up only when you use the Image Factory Enterprise.

    Opt-In Skip of Kubernetes Node Audit

    The Kubernetes node audit deletes nodes that no ClusterMachine backs. You can now skip it for individual nodes, which helps with virtual nodes such as VirtualKubelet. A node is skipped only when it has the omni.sidero.dev/node-audit-skip annotation and the cluster owner has turned on the matching cluster feature, so a workload cannot annotate its own way out of the audit.

    Node Names and Locked Status in omnictl cluster status

    The omnictl cluster status tree now prints each machine's Kubernetes node name in parentheses after its UUID, so you can match a machine to the upgrade status lines that reference node names. A "Locked" indicator shows up whenever a machine is locked.

    Platform Tags Exposed as Machine Labels

    Talos PlatformMetadata tags (for example EC2 instance tags) now appear as editable, removable machine labels in Omni. Omni fills them in once, when the machine first joins, and your own custom labels win on any key conflict.

    Schematic Contents Preserved on Update

    When Omni changes a machine's schematic, it now touches only the fields it manages (extensions and kernel args) and leaves the rest alone, instead of rebuilding the schematic from scratch. It reads the full schematic from the machine or the Image Factory and stores it as is.

    Signed Images and SBOM Release Artifacts

    Omni releases now ship an SBOM built from the Go modules as a release artifact, and Sidero Labs signs the published container images during release.

    Talos Upgrade Targets Capped at the Latest Supported Release

    Each Omni release now declares the latest Talos minor version it can support end to end. Cluster create and update, the maintenance upgrade API, the upgrade status computation, and every version picker in the UI all read this same cap, so you can no longer pick a Talos version newer than the running Omni supports.

    Contributors

    • Edward Sammut Alessi
    • Utku Ozdemir
    • Mateusz Urbanek
    • Oguz Kilcan
    • Artem Chernyshev
    • Maja Bojarska
    • Noel Georgi
    • Andrey Smirnov
    • Orzelius
    • 0hlov3
    • Bo Bobson
    • Matthew Sanabria
    • Sterling Koch
    • Steve Francis
    • fsgh42

    Changes

    <details><summary>118 commits</summary> <p>

    • f472356d7 release(v1.9.0-beta.1): prepare release
    • 8bea9d98d feat(frontend): add expandable code editor for extra overlay options
    • 4121e730f feat(frontend): add expandable code editor for embedded machine config
    • 22318022d feat(frontend): add more default editor options and remove default class
    • 00e99c4d5 refactor(frontend): refactor code editor to use v-model
    • 454daba78 chore: bump default talos version to 1.13.5
    • cb74aa700 feat: support embedded machine config in installation media CLI
    • 86af10d45 fix: get rid of the race in the UUID conflict resolution flow
    • 55bda4979 refactor: only log schematic id when ensuring
    • c2b067a1f feat(frontend): allow specifying embedded machine config for installation media
    • 574daf6d5 feat: add embedded_machine_config to create schematic request
    • 1a8c85b88 feat: add embedded_machine_config to installation media config spec
    • 687e56ae1 feat: add supports_embedded_config quirk to virtual resources
    • 2fa8855c6 feat: validate Talos extensions against the catalog
    • 807fe47a7 feat: register destroy controllers for user-managed resource types
    • c3c511acb chore: bump containerd to 1.7.33
    • af44779ae chore(frontend): bump dependencies
    • 17b2b30ec fix: prevent API requests from hanging after idle periods
    • 240c48323 feat(frontend): remove cluster machine patch option from machine patches
    • 498e8c0b4 feat(frontend): show error if machine not part of cluster
    • a66f1ae3a feat(frontend): use machine status link snapshot for recent machines phase
    • 0f853e1bb release(v1.9.0-beta.0): prepare release
    • 060a4c759 chore: bump deps and default versions
    • 43bf5856e test: run integration-qemu against the image factory enterprise
    • 4b49029cb feat: support machine config patches in maintenance mode
    • b9e407174 fix: stabilize flaky talemu e2e EULA setup and preset downloads
    • 448ed9a69 docs: update LICENSE
    • b44f92efe fix: ignore the embedded-config meta extension
    • e32307d8e fix: allow empty list of extensions in cluster templates
    • b08c34ac8 feat: implement advanced healthchecks for the cluster
    • 1c125d3f4 chore: add Oguz to sops-encrypted secrets recipients
    • 9a736342d fix: properly handle invalid UTF-8 strings in the machine statuses
    • d77ee0495 fix: properly handle empty provider data in the common module
    • c55173efc feat: validate Talos version on installation media config
    • 243f046e0 fix(frontend): display correct units for byte values
    • d9eebd7c4 fix(frontend): reset monitor chart on watch change
    • 7f02f41f3 chore(frontend): bump frontend dependencies
    • 27ef3dd03 feat: install/upgrade Talos in maintenance mode
    • 18131edfd feat(frontend): change machine tutorial into a welcome card
    • 4fdc07191 feat(frontend): adjust action buttons on getting started card
    • 987b3ec18 feat: reject control characters in join token names
    • 8bfc6c17d fix(frontend): fix incorrect pxe boot url
    • ead9840b7 feat: validate user-supplied request IDs and kernel args
    • 1ebde6a44 feat: validate bootstrap snapshot path on machine sets
    • 1ff045796 feat: allow opt-in skip of Kubernetes node audit
    • 50dcd264c feat: validate resource metadata at the state layer
    • 086a1964c feat: preserve schematic contents
    • 1ab0c4e32 feat(frontend): display infrastructure provider error when unhealthy
    • 5c67c7c9b fix: read machine uncached when deciding whether to reset it
    • 098dac2c3 refactor: remove unused fields, fix print columns/comments of resources
    • a29fba498 fix: use correct help string in the omnictl jointoken delete command
    • 9505aabec feat(frontend): add kubespan status view
    • d19768879 refactor: replace injectable clocks with real time
    • b5be9a779 fix: prune expired public keys with finalizers or no owner
    • 64b02f4f6 feat: cap Talos upgrade targets at the latest supported release
    • a1367d90e feat: per-machine log ingestion rate limit
    • bc0e5273b refactor: move state validations into their own package
    • 33909b1b9 fix: keep exposed services reachable after a health check flap
    • 84649427b feat(helm): support loadBalancerIP for WireGuard service
    • 4db447046 fix: release config update slot while a machine waits to upgrade
    • e63ea1f0e feat: add PostHog analytics to the Omni frontend
    • 5b5203660 chore: bump major go dependencies
    • 48a7f9394 fix: persist config status when update lock is contended
    • 59d9079c7 refactor(frontend): remove last cases of any in codebase
    • 665371f3a refactor: drop unused field in create schematic gRPC request
    • c2f52d799 fix: prevent deadlock between machine upgrade and config update
    • 861594332 feat: nest omnictl, talosctl, scans under api
    • f144020c0 feat(frontend): show vulnerability items on installation media wizard
    • 68afcd086 chore: rekres
    • b3e038f8d feat(frontend): generate talos types for frontend
    • 0610a4088 refactor(frontend): type tlist items
    • 4afaf514b refactor(frontend): drop watchjoin
    • 998e803ec chore: bump go-kubernetes library
    • ccbc50bda feat(omnictl): show node name and locked status in cluster status
    • 3edf383b6 chore: bump deps, rekres, Talos 1.13.3, Kubernetes 1.36.1
    • 429708f84 feat(frontend): show join tokens in saved presets list
    • c857af939 feat(frontend): enable field-sizing content for kernel args
    • f62e044aa feat(frontend): show errors for all update talos/k8s issues
    • 7ddd63b1a feat(frontend): sort upgrade modal versions descending and scroll to selected
    • ffcbf3342 refactor(frontend): refactor update talos + k8s to new modals
    • 9248b762b test: mock clock in saml test
    • d18726e9c fix: lower minimum discovered Kubernetes version
    • 2dd7c8807 test: pick previous Omni upgrade version from the release line
    • 2bfe8c08a chore: rekres and bump frontend deps
    • 3b9399fba fix: do not downgrade nodes header to single node
    • 15ad495ad test: bump Talos to 1.13.3
    • 25f5de5c6 feat(frontend): allow changing config diff sort order
    • 0f060a449 feat(frontend): add improvements to disks view
    • e297c4d47 fix: hack/compose dlv tools install
    • 1704f0047 chore(hack): add delve debugger support
    • 30d5d2868 test: use up-to-date way to set node labels on the nodes in the tests
    • 72dfce9e5 fix(frontend): remove lingering test code
    • 028a57e84 feat(frontend): move editing logic for kernel args into a modal
    • 76ee6332f feat(frontend): add tooltips to power state
    • 329922816 feat: refactor logviewer to tanstack virtual
    • 1fafd3781 chore: bump dependencies
    • 988bc9e81 chore: add missing syft version to kres
    • 065db6960 test(integration): bump readiness timeout durations
    • fc362b5fc feat: expose ec2 tags as machine labels
    • 6d61a546e feat: add sign-images target to sign omni container image
    • 34473a7f5 feat: generate SBOM as a release artifact
    • fa2f11fc0 fix: fetch versions from registry with auth
    • 0a2641c6c chore: bump deps to patch GO-2026-5027
    • ddfa70a9c feat: add per-class etcd write-bytes rate limiting
    • 69e4fe255 feat(frontend): add some feedback when omni is loading
    • 5246ba332 fix: ensure infra providers with new common module support the old Omni
    • 9ae983308 feat(frontend): sort pods by status on pods list
    • c8daa7805 fix(frontend): fix incorrect permissions-policy header
    • 7484972df feat(frontend): load robot fonts from npm
    • bb442ab7e feat: add teardown RPCs and tighten state API access
    • c1126b471 chore: fix linter issues
    • 120be2f10 chore: rekres to secure slack workflows
    • 686249525 fix: dont clean clients with active watches
    • 679ca3014 feat: support basic auth against the image factory
    • 2ce7140ec feat: introduce UI for showing Kubernetes manifests status of clusters
    • c990a0820 feat(frontend): change service finished state style to gray
    • 1b9177ee8 feat(frontend): show smbios serial info on machine details panel
    • 9dd6cb490 refactor: drop compose 'version' (from hack) </p> </details>

    Changes since v1.9.0-beta.0

    <details><summary>21 commits</summary> <p>

    • f472356d release(v1.9.0-beta.1): prepare release
    • 8bea9d98 feat(frontend): add expandable code editor for extra overlay options
    • 4121e730 feat(frontend): add expandable code editor for embedded machine config
    • 22318022 feat(frontend): add more default editor options and remove default class
    • 00e99c4d refactor(frontend): refactor code editor to use v-model
    • 454daba7 chore: bump default talos version to 1.13.5
    • cb74aa70 feat: support embedded machine config in installation media CLI
    • 86af10d4 fix: get rid of the race in the UUID conflict resolution flow
    • 55bda497 refactor: only log schematic id when ensuring
    • c2b067a1 feat(frontend): allow specifying embedded machine config for installation media
    • 574daf6d feat: add embedded_machine_config to create schematic request
    • 1a8c85b8 feat: add embedded_machine_config to installation media config spec
    • 687e56ae feat: add supports_embedded_config quirk to virtual resources
    • 2fa8855c feat: validate Talos extensions against the catalog
    • 807fe47a feat: register destroy controllers for user-managed resource types
    • c3c511ac chore: bump containerd to 1.7.33
    • af44779a chore(frontend): bump dependencies
    • 17b2b30e fix: prevent API requests from hanging after idle periods
    • 240c4832 feat(frontend): remove cluster machine patch option from machine patches
    • 498e8c0b feat(frontend): show error if machine not part of cluster
    • a66f1ae3 feat(frontend): use machine status link snapshot for recent machines phase </p> </details>

    Changes from siderolabs/go-api-signature

    <details><summary>1 commit</summary> <p>

    • 07009e7 chore: bump deps, update gopenpgp to v3 </p> </details>

    Changes from siderolabs/go-kubernetes

    <details><summary>2 commits</summary> <p>

    • cc8c2c9 fix: return the apply results in a consistent order
    • 131a2bd fix: handle cluster-scoped resources with a ns correctly </p> </details>

    Changes from siderolabs/go-talos-support

    <details><summary>2 commits</summary> <p>

    • 59d47af feat: rewrite support bundle library around client provider
    • 8dd4326 feat: support encryption of the support bundle using age </p> </details>

    Changes from siderolabs/image-factory

    <details><summary>26 commits</summary> <p>

    • 425e59e release(v1.3.3): prepare release
    • b5d3d92 fix: vulnerability scans with extensions
    • 916bcf6 feat: update go-vex
    • 9920386 feat: update Image Factory with Talos 1.14.0-alpha.1
    • d49e952 feat: allow excluding Talos releases
    • 147a3e8 feat: add scan report to factory client
    • 2887e78 feat: add support for embedding machine configuration
    • 660ac01 release(v1.3.2): prepare release
    • 38183fc fix: update golang.org/x/net
    • 9f6aee8 fix: make PXE copyable on SecureBoot
    • d7377c5 refactor: migrate to Tailwind CSS classes
    • 1e86750 fix: update golang.org/x/* packages
    • 33c79e4 test: move from kuttl to chainsaw
    • ba34dab feat: move SPDX cache to enterprise options
    • cd137ed chore: disable authentication for local development
    • 4ea792f fix: build profile with version
    • fcf9d57 release(v1.3.1): prepare release
    • 1d216c7 docs: update the developing documentation
    • 4a60270 fix(config): validate early and sort SPDX deterministically
    • 41d3947 release(v1.3.0): prepare release
    • ae3ed04 feat: add enterprise features with Helm chart support
    • 3fb0f96 feat(enterprise): add vulnerability scanning endpoint
    • 92209b6 feat: return normalized schematic on creation
    • ba2a46d feat(enterprise): implement VEX endpoint
    • 9b40156 feat: show schematic-id url parameter on the final wizard step
    • 114bb60 fix(spdx): use configured external URL in document namespace </p> </details>

    Dependency Changes

    • github.com/ProtonMail/go-crypto v1.4.1 new
    • github.com/ProtonMail/gopenpgp/v3 v3.4.1 new
    • github.com/auth0/go-jwt-middleware/v3 v3.2.0 new
    • github.com/aws/aws-sdk-go-v2 v1.41.7 -> v1.42.0
    • github.com/aws/aws-sdk-go-v2/config v1.32.17 -> v1.32.25
    • github.com/aws/aws-sdk-go-v2/credentials v1.19.16 -> v1.19.24
    • github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.22.18 -> v1.22.28
    • github.com/aws/aws-sdk-go-v2/service/s3 v1.101.0 -> v1.104.0
    • github.com/aws/smithy-go v1.25.1 -> v1.27.2
    • github.com/coreos/go-oidc/v3 v3.18.0 -> v3.19.0
    • github.com/cosi-project/runtime v1.16.0 -> v1.16.1
    • github.com/cosi-project/state-etcd v0.6.0 -> v0.7.0
    • github.com/felixge/httpsnoop v1.0.4 -> v1.1.0
    • github.com/fluxcd/cli-utils v1.2.0 -> v1.2.1
    • github.com/fluxcd/pkg/ssa v0.74.0 -> v0.76.0
    • github.com/golang-jwt/jwt/v5 v5.3.1 new
    • github.com/google/go-containerregistry v0.21.5 -> v0.21.7
    • github.com/grpc-ecosystem/go-grpc-middleware/v2 v2.3.3 new
    • github.com/prometheus/client_model v0.6.2 new
    • github.com/prometheus/common v0.67.5 -> v0.69.0
    • github.com/russellhaering/goxmldsig v1.6.0 new
    • github.com/siderolabs/go-api-signature v0.3.12 -> v0.3.13
    • github.com/siderolabs/go-kubernetes v0.2.37 -> v0.2.39
    • github.com/siderolabs/go-talos-support v0.2.1 -> v0.3.0
    • github.com/siderolabs/image-factory v1.2.0 -> v1.3.3
    • github.com/siderolabs/omni/client v1.6.5 -> v1.8.1
    • github.com/siderolabs/talos/pkg/machinery v1.13.2 -> v1.14.0-alpha.1
    • github.com/stripe/stripe-go/v85 v85.1.0 -> v85.2.0
    • go.etcd.io/etcd/client/pkg/v3 v3.6.11 -> v3.6.12
    • go.etcd.io/etcd/client/v3 v3.6.11 -> v3.6.12
    • go.etcd.io/etcd/server/v3 v3.6.11 -> v3.6.12
    • golang.org/x/crypto v0.51.0 -> v0.53.0
    • golang.org/x/net v0.54.0 -> v0.56.0
    • golang.org/x/sync v0.20.0 -> v0.21.0
    • golang.org/x/text v0.37.0 -> v0.38.0
    • golang.org/x/tools v0.45.0 -> v0.46.0
    • golang.zx2c4.com/wireguard f333402bd9cb -> ecfc5a8d5446
    • google.golang.org/grpc v1.81.0 -> v1.81.1
    • k8s.io/api v0.36.0 -> v0.36.2
    • k8s.io/apimachinery v0.36.0 -> v0.36.2
    • k8s.io/client-go v0.36.0 -> v0.36.2
    • sigs.k8s.io/controller-runtime v0.24.0 -> v0.24.1

    Previous release can be found at v1.8.0

    Open source →
  48. v1.9.0-beta.0.0.20260619212954-17b2b30ecb90 19 Jun 2026 pre-release

    Nothing published for this version

  49. v1.9.0-beta.0.0.20260619161350-498e8c0b4217 19 Jun 2026 pre-release

    Nothing published for this version

  50. v1.9.0-beta.0 19 Jun 2026 pre-release
    Release notes

    Welcome to the v1.9.0-beta.0 release of Omni!
    This is a pre-release of Omni

    Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.

    Per-Class etcd Write Rate Limiting

    You can now throttle etcd writes by payload size, with separate budgets for end users, infra providers, and internal callers. It is off by default and turns on via storage.rateLimits.etcd.*. Four new Prometheus series report throttle wait time, admitted writes, rejected writes, and rejected bytes, labeled by class. The failure counters also carry a reason of timeout or oversize.

    KubeSpan Status View

    A new graphical view shows KubeSpan peer status for a cluster machine.

    Frontend Quality-of-Life Improvements

    A round of UI improvements across Omni. The home screen has a reworked "Welcome to Omni" card. An unhealthy infrastructure provider shows its error on hover, the machine details panel shows the SMBIOS serial number, and kernel args editing moved into a modal. Config diffs have a sort-order toggle, version pickers sort newest first and scroll to the current selection, and Talos and Kubernetes update calls now report their errors. The disks view got several cleanups, pods sort by status, power-state icons have tooltips, Omni shows a loading indicator when it is slow to start, and the rewritten log viewer scrolls to the bottom reliably.

    Static loadBalancerIP for the WireGuard Service in Helm

    The Helm chart has a new service.wireguard.loadBalancerIP value for setting a static load balancer IP on the WireGuard Kubernetes Service. It is rendered only when the WireGuard service type is LoadBalancer.

    Support for Image Factory Enterprise

    Two new config options, registries.imageFactoryUsername and registries.imageFactoryPassword, let Omni authenticate to the Image Factory Enterprise with HTTP basic auth.

    Kubernetes Manifests Status in the UI

    The frontend now shows the status of a cluster's synced Kubernetes manifests.

    Per-Machine Log Ingestion Rate Limit

    Log ingestion now uses a per-machine token bucket, so one noisy machine can no longer overwhelm the log store. It is off by default to keep backwards compatibility.

    Machine Config Patches in Maintenance Mode

    Omni can now apply machine-level config patches while a machine is still in maintenance mode, not just after it joins a cluster. The patches go on top of the configuration the machine already runs, next to the SideroLink documents Omni manages, and Omni will not apply a document that installs Talos and pulls the machine out of maintenance. Omni also keeps whatever configuration a machine connects with as a low-priority, user-owned patch. So a machine that arrives with its own config (say a TrustedRootsConfig document) keeps it, and your own patches still win.

    Install and Upgrade Talos in Maintenance Mode

    A new streaming management API installs or upgrades Talos on machines booted in maintenance mode. It comes with omnictl install and upgrade subcommands and frontend modals that stream installer progress live. This feature uses Talos's LifecycleService API, which became available in v1.13.0. So it works with any Talos version starting from v1.13.0.

    SBOM, VEX, and Vulnerability Scan on the Installation Media Wizard

    The installation media wizard's confirmation page now shows SBOM and VEX links plus the vulnerability scan and modal, the same as the Image Factory. This shows up only when you use the Image Factory Enterprise.

    Opt-In Skip of Kubernetes Node Audit

    The Kubernetes node audit deletes nodes that no ClusterMachine backs. You can now skip it for individual nodes, which helps with virtual nodes such as VirtualKubelet. A node is skipped only when it has the omni.sidero.dev/node-audit-skip annotation and the cluster owner has turned on the matching cluster feature, so a workload cannot annotate its own way out of the audit.

    Node Names and Locked Status in omnictl cluster status

    The omnictl cluster status tree now prints each machine's Kubernetes node name in parentheses after its UUID, so you can match a machine to the upgrade status lines that reference node names. A "Locked" indicator shows up whenever a machine is locked.

    Platform Tags Exposed as Machine Labels

    Talos PlatformMetadata tags (for example EC2 instance tags) now appear as editable, removable machine labels in Omni. Omni fills them in once, when the machine first joins, and your own custom labels win on any key conflict.

    Schematic Contents Preserved on Update

    When Omni changes a machine's schematic, it now touches only the fields it manages (extensions and kernel args) and leaves the rest alone, instead of rebuilding the schematic from scratch. It reads the full schematic from the machine or the Image Factory and stores it as is.

    Signed Images and SBOM Release Artifacts

    Omni releases now ship an SBOM built from the Go modules as a release artifact, and Sidero Labs signs the published container images during release.

    Talos Upgrade Targets Capped at the Latest Supported Release

    Each Omni release now declares the latest Talos minor version it can support end to end. Cluster create and update, the maintenance upgrade API, the upgrade status computation, and every version picker in the UI all read this same cap, so you can no longer pick a Talos version newer than the running Omni supports.

    Contributors

    • Edward Sammut Alessi
    • Utku Ozdemir
    • Mateusz Urbanek
    • Oguz Kilcan
    • Artem Chernyshev
    • Maja Bojarska
    • Noel Georgi
    • Andrey Smirnov
    • Orzelius
    • 0hlov3
    • Bo Bobson
    • Matthew Sanabria
    • Sterling Koch
    • Steve Francis
    • fsgh42

    Changes

    <details><summary>96 commits</summary> <p>

    • 060a4c759 chore: bump deps and default versions
    • 43bf5856e test: run integration-qemu against the image factory enterprise
    • 4b49029cb feat: support machine config patches in maintenance mode
    • b9e407174 fix: stabilize flaky talemu e2e EULA setup and preset downloads
    • 448ed9a69 docs: update LICENSE
    • b44f92efe fix: ignore the embedded-config meta extension
    • e32307d8e fix: allow empty list of extensions in cluster templates
    • b08c34ac8 feat: implement advanced healthchecks for the cluster
    • 1c125d3f4 chore: add Oguz to sops-encrypted secrets recipients
    • 9a736342d fix: properly handle invalid UTF-8 strings in the machine statuses
    • d77ee0495 fix: properly handle empty provider data in the common module
    • c55173efc feat: validate Talos version on installation media config
    • 243f046e0 fix(frontend): display correct units for byte values
    • d9eebd7c4 fix(frontend): reset monitor chart on watch change
    • 7f02f41f3 chore(frontend): bump frontend dependencies
    • 27ef3dd03 feat: install/upgrade Talos in maintenance mode
    • 18131edfd feat(frontend): change machine tutorial into a welcome card
    • 4fdc07191 feat(frontend): adjust action buttons on getting started card
    • 987b3ec18 feat: reject control characters in join token names
    • 8bfc6c17d fix(frontend): fix incorrect pxe boot url
    • ead9840b7 feat: validate user-supplied request IDs and kernel args
    • 1ebde6a44 feat: validate bootstrap snapshot path on machine sets
    • 1ff045796 feat: allow opt-in skip of Kubernetes node audit
    • 50dcd264c feat: validate resource metadata at the state layer
    • 086a1964c feat: preserve schematic contents
    • 1ab0c4e32 feat(frontend): display infrastructure provider error when unhealthy
    • 5c67c7c9b fix: read machine uncached when deciding whether to reset it
    • 098dac2c3 refactor: remove unused fields, fix print columns/comments of resources
    • a29fba498 fix: use correct help string in the omnictl jointoken delete command
    • 9505aabec feat(frontend): add kubespan status view
    • d19768879 refactor: replace injectable clocks with real time
    • b5be9a779 fix: prune expired public keys with finalizers or no owner
    • 64b02f4f6 feat: cap Talos upgrade targets at the latest supported release
    • a1367d90e feat: per-machine log ingestion rate limit
    • bc0e5273b refactor: move state validations into their own package
    • 33909b1b9 fix: keep exposed services reachable after a health check flap
    • 84649427b feat(helm): support loadBalancerIP for WireGuard service
    • 4db447046 fix: release config update slot while a machine waits to upgrade
    • e63ea1f0e feat: add PostHog analytics to the Omni frontend
    • 5b5203660 chore: bump major go dependencies
    • 48a7f9394 fix: persist config status when update lock is contended
    • 59d9079c7 refactor(frontend): remove last cases of any in codebase
    • 665371f3a refactor: drop unused field in create schematic gRPC request
    • c2f52d799 fix: prevent deadlock between machine upgrade and config update
    • 861594332 feat: nest omnictl, talosctl, scans under api
    • f144020c0 feat(frontend): show vulnerability items on installation media wizard
    • 68afcd086 chore: rekres
    • b3e038f8d feat(frontend): generate talos types for frontend
    • 0610a4088 refactor(frontend): type tlist items
    • 4afaf514b refactor(frontend): drop watchjoin
    • 998e803ec chore: bump go-kubernetes library
    • ccbc50bda feat(omnictl): show node name and locked status in cluster status
    • 3edf383b6 chore: bump deps, rekres, Talos 1.13.3, Kubernetes 1.36.1
    • 429708f84 feat(frontend): show join tokens in saved presets list
    • c857af939 feat(frontend): enable field-sizing content for kernel args
    • f62e044aa feat(frontend): show errors for all update talos/k8s issues
    • 7ddd63b1a feat(frontend): sort upgrade modal versions descending and scroll to selected
    • ffcbf3342 refactor(frontend): refactor update talos + k8s to new modals
    • 9248b762b test: mock clock in saml test
    • d18726e9c fix: lower minimum discovered Kubernetes version
    • 2dd7c8807 test: pick previous Omni upgrade version from the release line
    • 2bfe8c08a chore: rekres and bump frontend deps
    • 3b9399fba fix: do not downgrade nodes header to single node
    • 15ad495ad test: bump Talos to 1.13.3
    • 25f5de5c6 feat(frontend): allow changing config diff sort order
    • 0f060a449 feat(frontend): add improvements to disks view
    • e297c4d47 fix: hack/compose dlv tools install
    • 1704f0047 chore(hack): add delve debugger support
    • 30d5d2868 test: use up-to-date way to set node labels on the nodes in the tests
    • 72dfce9e5 fix(frontend): remove lingering test code
    • 028a57e84 feat(frontend): move editing logic for kernel args into a modal
    • 76ee6332f feat(frontend): add tooltips to power state
    • 329922816 feat: refactor logviewer to tanstack virtual
    • 1fafd3781 chore: bump dependencies
    • 988bc9e81 chore: add missing syft version to kres
    • 065db6960 test(integration): bump readiness timeout durations
    • fc362b5fc feat: expose ec2 tags as machine labels
    • 6d61a546e feat: add sign-images target to sign omni container image
    • 34473a7f5 feat: generate SBOM as a release artifact
    • fa2f11fc0 fix: fetch versions from registry with auth
    • 0a2641c6c chore: bump deps to patch GO-2026-5027
    • ddfa70a9c feat: add per-class etcd write-bytes rate limiting
    • 69e4fe255 feat(frontend): add some feedback when omni is loading
    • 5246ba332 fix: ensure infra providers with new common module support the old Omni
    • 9ae983308 feat(frontend): sort pods by status on pods list
    • c8daa7805 fix(frontend): fix incorrect permissions-policy header
    • 7484972df feat(frontend): load robot fonts from npm
    • bb442ab7e feat: add teardown RPCs and tighten state API access
    • c1126b471 chore: fix linter issues
    • 120be2f10 chore: rekres to secure slack workflows
    • 686249525 fix: dont clean clients with active watches
    • 679ca3014 feat: support basic auth against the image factory
    • 2ce7140ec feat: introduce UI for showing Kubernetes manifests status of clusters
    • c990a0820 feat(frontend): change service finished state style to gray
    • 1b9177ee8 feat(frontend): show smbios serial info on machine details panel
    • 9dd6cb490 refactor: drop compose 'version' (from hack) </p> </details>

    Changes from siderolabs/go-api-signature

    <details><summary>1 commit</summary> <p>

    • 07009e7 chore: bump deps, update gopenpgp to v3 </p> </details>

    Changes from siderolabs/go-kubernetes

    <details><summary>2 commits</summary> <p>

    • cc8c2c9 fix: return the apply results in a consistent order
    • 131a2bd fix: handle cluster-scoped resources with a ns correctly </p> </details>

    Changes from siderolabs/go-talos-support

    <details><summary>2 commits</summary> <p>

    • 59d47af feat: rewrite support bundle library around client provider
    • 8dd4326 feat: support encryption of the support bundle using age </p> </details>

    Changes from siderolabs/image-factory

    <details><summary>26 commits</summary> <p>

    • 425e59e release(v1.3.3): prepare release
    • b5d3d92 fix: vulnerability scans with extensions
    • 916bcf6 feat: update go-vex
    • 9920386 feat: update Image Factory with Talos 1.14.0-alpha.1
    • d49e952 feat: allow excluding Talos releases
    • 147a3e8 feat: add scan report to factory client
    • 2887e78 feat: add support for embedding machine configuration
    • 660ac01 release(v1.3.2): prepare release
    • 38183fc fix: update golang.org/x/net
    • 9f6aee8 fix: make PXE copyable on SecureBoot
    • d7377c5 refactor: migrate to Tailwind CSS classes
    • 1e86750 fix: update golang.org/x/* packages
    • 33c79e4 test: move from kuttl to chainsaw
    • ba34dab feat: move SPDX cache to enterprise options
    • cd137ed chore: disable authentication for local development
    • 4ea792f fix: build profile with version
    • fcf9d57 release(v1.3.1): prepare release
    • 1d216c7 docs: update the developing documentation
    • 4a60270 fix(config): validate early and sort SPDX deterministically
    • 41d3947 release(v1.3.0): prepare release
    • ae3ed04 feat: add enterprise features with Helm chart support
    • 3fb0f96 feat(enterprise): add vulnerability scanning endpoint
    • 92209b6 feat: return normalized schematic on creation
    • ba2a46d feat(enterprise): implement VEX endpoint
    • 9b40156 feat: show schematic-id url parameter on the final wizard step
    • 114bb60 fix(spdx): use configured external URL in document namespace </p> </details>

    Dependency Changes

    • github.com/ProtonMail/go-crypto v1.4.1 new
    • github.com/ProtonMail/gopenpgp/v3 v3.4.1 new
    • github.com/auth0/go-jwt-middleware/v3 v3.2.0 new
    • github.com/aws/aws-sdk-go-v2 v1.41.7 -> v1.42.0
    • github.com/aws/aws-sdk-go-v2/config v1.32.17 -> v1.32.25
    • github.com/aws/aws-sdk-go-v2/credentials v1.19.16 -> v1.19.24
    • github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.22.18 -> v1.22.28
    • github.com/aws/aws-sdk-go-v2/service/s3 v1.101.0 -> v1.104.0
    • github.com/aws/smithy-go v1.25.1 -> v1.27.2
    • github.com/coreos/go-oidc/v3 v3.18.0 -> v3.19.0
    • github.com/cosi-project/runtime v1.16.0 -> v1.16.1
    • github.com/cosi-project/state-etcd v0.6.0 -> v0.7.0
    • github.com/felixge/httpsnoop v1.0.4 -> v1.1.0
    • github.com/fluxcd/cli-utils v1.2.0 -> v1.2.1
    • github.com/fluxcd/pkg/ssa v0.74.0 -> v0.76.0
    • github.com/golang-jwt/jwt/v5 v5.3.1 new
    • github.com/google/go-containerregistry v0.21.5 -> v0.21.7
    • github.com/grpc-ecosystem/go-grpc-middleware/v2 v2.3.3 new
    • github.com/prometheus/client_model v0.6.2 new
    • github.com/prometheus/common v0.67.5 -> v0.69.0
    • github.com/russellhaering/goxmldsig v1.6.0 new
    • github.com/siderolabs/go-api-signature v0.3.12 -> v0.3.13
    • github.com/siderolabs/go-kubernetes v0.2.37 -> v0.2.39
    • github.com/siderolabs/go-talos-support v0.2.1 -> v0.3.0
    • github.com/siderolabs/image-factory v1.2.0 -> v1.3.3
    • github.com/siderolabs/omni/client v1.6.5 -> v1.8.1
    • github.com/siderolabs/talos/pkg/machinery v1.13.2 -> v1.14.0-alpha.1
    • github.com/stripe/stripe-go/v85 v85.1.0 -> v85.2.0
    • go.etcd.io/etcd/client/pkg/v3 v3.6.11 -> v3.6.12
    • go.etcd.io/etcd/client/v3 v3.6.11 -> v3.6.12
    • go.etcd.io/etcd/server/v3 v3.6.11 -> v3.6.12
    • golang.org/x/crypto v0.51.0 -> v0.53.0
    • golang.org/x/net v0.54.0 -> v0.56.0
    • golang.org/x/sync v0.20.0 -> v0.21.0
    • golang.org/x/text v0.37.0 -> v0.38.0
    • golang.org/x/tools v0.45.0 -> v0.46.0
    • golang.zx2c4.com/wireguard f333402bd9cb -> ecfc5a8d5446
    • google.golang.org/grpc v1.81.0 -> v1.81.1
    • k8s.io/api v0.36.0 -> v0.36.2
    • k8s.io/apimachinery v0.36.0 -> v0.36.2
    • k8s.io/client-go v0.36.0 -> v0.36.2
    • sigs.k8s.io/controller-runtime v0.24.0 -> v0.24.1

    Previous release can be found at v1.8.0

    Open source →
  51. v1.8.2 05 Jun 2026

    Nothing published for this version

  52. v1.8.1 29 May 2026

    Nothing published for this version

  53. v1.8.0 21 May 2026

    Nothing published for this version

  54. v1.8.0-beta.1.0.20260616181556-d77ee0495299 16 Jun 2026 pre-release

    Nothing published for this version

  55. v1.8.0-beta.1.0.20260605102248-4db447046921 05 Jun 2026 pre-release

    Nothing published for this version

  56. v1.8.0-beta.1.0.20260529113325-2bfe8c08a1cf 29 May 2026 pre-release

    Nothing published for this version

  57. v1.8.0-beta.1.0.20260526080537-fa2f11fc0a64 26 May 2026 pre-release

    Nothing published for this version

  58. v1.8.0-beta.1.0.20260521103036-9ae983308143 21 May 2026 pre-release

    Nothing published for this version

  59. v1.8.0-beta.1.0.20260521094219-c8daa7805fc3 21 May 2026 pre-release

    Nothing published for this version

  60. v1.8.0-beta.1 18 May 2026 pre-release
    Release notes

    Welcome to the v1.8.0-beta.1 release of Omni!
    This is a pre-release of Omni

    Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.

    Urgent Upgrade Notes (No, really, you MUST read this before you upgrade)

    As Omni is now using --join-tokens-mode=legacyAllowed by default it won't start if there are any nodes running Talos below 1.6 connected to the instance. If you want to keep using Omni with the outdated Talos you will need to set the flag to legacy. But of course we strongly recommend you to update Talos ASAP.

    omnictl cluster template has breaking changes: it now restricts including files outside of the current directory. If using files in the parent dirs, old behavior can be enabled by using --allowed-dir.

    Additional Audit Log Filters

    Audit logs gain a generic search box and sortable columns in the UI, plus CLI filters for event_type, resource_type, resource_id, cluster_id, and actor.

    Per-Actor etcd Write Metrics

    New omni_etcd_operations_total and omni_etcd_resource_bytes_total Prometheus counters track etcd writes, split by operation (create/update/teardown/destroy), actor (internal/user/service account/infra provider), actor ID, and resource type. Byte sizes are captured from the actual on-disk payload via a new WithObserver hook in state-etcd.

    Disks and Devices on Machine Pages

    The frontend now shows disks and devices on the machines and individual machine pages.

    Talos Version Text on Installation Media Wizard

    The installation media wizard's Talos version text has been updated for clarity.

    Switching Logs Inside the Logs Tab

    The logs tab now allows switching between log sources directly inside the tab.

    Quick Switching Between Cluster Machines

    The frontend allows quickly switching between machines within a cluster from the machine detail view.

    In-UI Notifications

    Omni notifications are now shown in the UI as dismissible banners.

    Frontend Quality-of-Life Improvements for Machines

    The cluster machine page gains a copy-UUID button, the machines list page can toggle between hostnames and UUIDs (with the preference saved), and machine and cluster machine pages gain kernel args tabs for editing kernel arguments inline instead of through a modal.

    Re-Saving the Omni Support Bundle

    The frontend now allows re-saving a previously generated Omni support bundle without regenerating it.

    Support Modal

    A new support modal in the frontend exposes links to GitHub issues, support channels, documentation, community resources, and office hours.

    Helm Chart Values Generated From Config Schema

    A new helmvaluesgen tool, run on make generate, updates the config: section of the Helm chart's values.yaml from Omni's config schema, applying chart-specific overrides for defaults, omissions, and descriptions.

    Legacy Installation Media Proxying Removed

    Omni no longer proxies legacy installation media download requests to the Talos Image Factory. Such requests are now rejected with a message asking users to upgrade omnictl, which downloads installation media directly from the factory.

    Image Factory Proxy for Infra Providers

    Infra provider Image Factory requests can now be proxied through Omni via a new schematic creation API that accepts raw YAML. This is useful when Omni holds authentication for the Image Factory or when multiple Image Factory endpoints need to be supported.

    Imported Cluster Secrets Cleanup

    A new controller tears down ImportedClusterSecrets once their content has been copied into ClusterSecrets and marked Imported=true, so imported bootstrap material does not linger in the state after a successful import.

    Infra Provider Factory Endpoint

    Infra providers now use the Image Factory endpoint configured in Omni's features state (sourced from args/config) instead of a hardcoded default. The configured factory URL is exposed on the provider.

    Installation Media Placeholders

    InstallationMediaConfig now accepts empty strings for talosVersion and joinToken, which resolve to the current stable version and default token at download time. The create wizard exposes "Automatic" options for these fields, and the download modal shows version/token/arch pickers for all presets.

    Reader Access to Join Tokens

    Users with the reader role can now read join tokens. Reader had access to it before through Talos logs, so making the access more consistent. More fine grained access will come with RBAC v2 later on.

    Multi-Port Workload Proxy

    The omni-kube-service-exposer.sidero.dev/port annotation now accepts a comma-separated list of host-port or host-port:service-port entries, each producing its own ExposedService URL. Label, icon, and prefix annotations gain per-host-port suffixed variants (e.g. label-30080). Existing single-port exposed services keep their URLs across the upgrade.

    Configurable Log Level and Format

    Omni's log level and log format are now configurable via flags and config.

    Provision Step Errors on Machine Requests

    A new Error field on ClusterMachineRequestStatus surfaces provision step failures so users can see why a request is stuck without scraping logs. Errors are now persisted on both failure and requeue paths.

    omnictl media Command Group

    A new omnictl media preset {create,list,delete} command group manages InstallationMediaConfig presets from the CLI, and omnictl media download <preset> downloads from them. Preset validation runs against the server's CloudPlatformConfig, SBCConfig, and TalosExtensions resources at create time. The legacy omnictl download is preserved but deprecated.

    Plain Download Links for Images

    The frontend now uses plain browser download links for factory image downloads instead of intercepting them.

    Powered Off Machine State

    Machines that are shut down now appear as "Powered Off" in the UI instead of being stuck in "Shutting Down" with a greyed-out unreachable state. Static infra providers honor the shutdown until the machine goes through a deallocation cycle, instead of automatically powering it back on. The CLI gains omnictl machine shutdown and omnictl machine power-on commands.

    Per-Key Creation and Last-Active Tracking for Service Accounts

    Service account key listings now include per-key creation timestamps and last-active times. omnictl serviceaccount list shows KEY CREATED and KEY LAST ACTIVE columns alongside the existing SA-level LAST ACTIVE. A new PublicKeyLastActive resource backs this tracking, and the activity interceptor records last-used timestamps per signing key fingerprint.

    Commented omnictl serviceaccount create Output

    The output of omnictl serviceaccount create is now commented out by default, making it friendlier for piping into .env files and shell automation.

    Talos Version End-of-Support Notifications

    Omni now tracks machines running Talos versions approaching or past end of support relative to MinTalosVersion, emits two new notifications (approaching end of support, end of support reached), and exposes Prometheus metrics for both.

    Download talosctl From Factory

    talosctl binaries are now downloaded directly from the Talos Image Factory instead of GitHub.

    Cluster Template Include Directory Restrictions

    By default, cluster templates can only include files from the same directory as the template file. This prevents malicious templates from including arbitrary files like /etc/passwd. The previous behavior can be restored with --allowed-dir.

    Raw Bytes Support in Template Inline Fields

    Inline fields for manifests and config patches now accept three forms: a single inline map (for backward compatibility), a list of inline maps, or raw bytes (which may contain multiple YAML documents). omnictl cluster template export now exports patches and manifests as raw bytes so multi-document values round-trip correctly.

    Template Includes Resolved Relative to Template File

    omnictl cluster template commands now resolve patch and Kubernetes manifest includes relative to the template YAML file, rather than the current working directory of omnictl.

    Contributors

    • Edward Sammut Alessi
    • Utku Ozdemir
    • Artem Chernyshev
    • Oguz Kilcan
    • Andrey Smirnov
    • Noel Georgi
    • Mateusz Urbanek
    • Justin Garrison
    • Maja Bojarska
    • Orzelius
    • Quentin Joly
    • Spencer Smith

    Changes

    <details><summary>81 commits</summary> <p>

    • b5e5e86e refactor: update minio env names
    • 5a894a21 chore: update helm README with new install instructions
    • 4fe2a67f chore: rekres, bump deps and default versions
    • 6fab9972 release(v1.8.0-beta.0): prepare release
    • ac81e59f feat: collect ClusterKubernetesManifestStatus in the support bundles
    • 64a1d536 fix: wrong role promotion for some etcd APIs
    • 7cc7e181 test: fix workload proxy integration test for upgrade scenario
    • 2c8b1789 feat: add per-actor etcd write metrics
    • 49322f05 feat: use plain download links for image downloads
    • 01742e71 feat: add log level and format configuration
    • 7fb5b164 chore: bump deps
    • cab06214 feat(frontend): allow switching logs inside logs tab
    • c890ecec refactor(frontend): move node logs logic into machinelogscontainer
    • 75cdb09f refactor(frontend): extra machine service list into a composable
    • 9f1bb2fa docs: add COSI resource operations in API usage examples
    • 13c3f289 fix: add more input validations to management API
    • ced79da6 fix: consume SAML sessions once
    • 7b72ac64 chore(frontend): bump dependencies
    • ed7738b3 fix: do not panic is ssa apply with multi-version CRDs
    • e08e566d feat: destroy imported cluster secrets after bundle is consumed
    • d01a6f66 fix(frontend): keep machine details open when switching
    • 25fa9e14 fix: change ImportedClusterSecrets access level to operator
    • 39ee2f01 feat: proxy image factory requests done by the providers through Omni
    • e7aee25c test(frontend): add e2e tests for join tokens in frontend
    • e6be461c fix(frontend): add apexcharts formatter workaround
    • ba6205f5 fix(frontend): fix apexcharts broken tooltips and initial state
    • addf6624 feat: add omnictl media command group with preset support
    • 110be565 feat: expose provision step errors on machine request status
    • 699ebf70 fix(frontend): fix revoking/deleting join tokens
    • 1f4f2afa feat: allow exposing a Kubernetes service on multiple host ports
    • 75e881fc feat: resolve patches/kubernetes manifests relative to the templates dir
    • e9b71f0b fix(frontend): only show machine patches for currently visible machine
    • a524554c fix(frontend): fix editing labels on machine class
    • c14ee101 refactor(frontend): refactor all but the last tlist use of watch.setup
    • 56cce45e chore(frontend): bump node to 24.15.0
    • 7989c3c0 test: fix data race in machine service mock
    • c141613d fix: fix the storm of PendingUpdateStatus create/destroy
    • a43407d0 feat: generate config section of helm chart values from config schema
    • 0cdb5a58 feat: support raw bytes in the inline fields for manifests/patches
    • 14b83e12 feat: set infra provider factory endpoint to the one configured in omni
    • efbd089f feat(frontend): add qol machine updates to omni frontend
    • 2fe716d2 chore: enable go linting for build tags, fix linting errors
    • 718d61a6 chore(frontend): bump dependencies
    • d3592671 feat: download talosctl directly from factory
    • b2671d08 refactor(frontend): create downloadfile helper
    • dc9baca8 refactor(frontend): refactor downloadtalosctl modal to new modal system
    • 06d8140d feat: add join token/talos version placeholders in installation media
    • 5f4b9761 fix: bring back election campaign resign code in the etcd state
    • 03c4e1d9 fix: stop logging Kubernetes read checks
    • dc3b974d fix: remove workload proxy deployment when disabled on the account
    • 65af568b fix: skip allocating nodes for deleted/tearing down MachineRequests
    • f9dd8491 feat: introduce powered off machine state and power on support
    • 921389a5 fix(frontend): fix eula handling to prevent being stuck on /eula
    • 725f41d4 fix: properly display service account expiration time in the UI
    • c5a43105 feat(frontend): add support modal to omni
    • 66383890 feat(frontend): show disks and devices in machines/machine page
    • 1e31079e fix(frontend): fix indeterminate state for update extensions modal
    • 6d7e4f45 feat(frontend): allow quickly switching between cluster machines
    • c98b1187 fix(frontend): clear page state when keys are cleared
    • f89955b4 refactor(frontend): remove last use of <watch> component
    • be67f710 feat: allow reader access to join token
    • f2211688 chore: bump deps
    • 475e3660 feat: add Talos version end-of-support notifications and metrics
    • 302e9175 feat: comment serviceaccount create output
    • 967c229e chore: rekres to update to new kres schema
    • edbb621a chore: bump stripe-go to v85
    • cc0adefc fix(frontend): select default join token in installation media wizard
    • 0987fa9e chore: prepare omni with talos v1.13.0-rc
    • 73a06f89 chore: bump talos machinery
    • 78544a85 feat: restrict directories for included files in the cluster templates
    • a3fd0b1c feat(frontend): allow re-saving omni support bundle
    • 5c4a6b57 feat: remove image factory proxying
    • dc5e289c feat(frontend): show notifications in the frontend
    • 9fd6e9e1 fix(frontend): open external eula link in a new tab
    • 8c23f72e chore: bump deps
    • 2e9d00a6 chore: make Omni use join tokens mode legacyAllowed by default
    • 488b020b feat: add more filters to audit logs
    • 590ea2e3 feat: add per-key creation and last-active tracking for service accounts
    • 44b0d636 chore: bump deps
    • 186f02b4 chore(frontend): bump frontend dependencies
    • 57216254 feat(frontend): update talos version text on installation media wizard </p> </details>

    Changes since v1.8.0-beta.0

    <details><summary>3 commits</summary> <p>

    • b5e5e86e refactor: update minio env names
    • 5a894a21 chore: update helm README with new install instructions
    • 4fe2a67f chore: rekres, bump deps and default versions </p> </details>

    Changes from siderolabs/go-kubernetes

    <details><summary>2 commits</summary> <p>

    • 38c182f fix: normalize the changeset to be keyed without apiVersion
    • ca35008 feat: update k8s api to 0.36.0 </p> </details>

    Changes from siderolabs/image-factory

    <details><summary>22 commits</summary> <p>

    • ccffefc release(v1.2.0): prepare release
    • 4abeff4 feat: add /talosctl/:version endpoint to list downloadable talosctls
    • 405b488 feat(i18n): add french locale
    • c6ad082 feat(registry): resolve latest tag to stable version
    • 471706d chore: drop update to talos main tests
    • 403cd5a fix: centralize schematic ownership enforcement
    • f1cceee feat: implement authentication support
    • 81f9312 release(v1.1.0): prepare release
    • 1b834b7 feat: add SHA-256 and SHA-512 checksum frontend
    • e775c36 feat: upgrade tailwind to v4
    • bb27d39 feat: update Talos to v1.13.0-rc.0
    • 2a59890 fix: gsa signer pull during verify
    • fbc302f fix: support insecure registries for signature bundles
    • 8e7d10e feat: add support for google service account signing
    • 74afd80 fix: set correct Content-Type when downloading images
    • 8372fe8 feat: add SPDX frontend
    • b379bf2 feat: switch schematic cache to LRU and negative TTL
    • 0450038 chore: remove deuplicate k8s-down ci step
    • 470cb2f chore: switch to large runners
    • 713fc6e fix: memory usage when building images
    • 0a25274 fix: excessive memory usage
    • 0f9eb22 feat: update machinery doc links </p> </details>

    Dependency Changes

    • github.com/aws/aws-sdk-go-v2 v1.41.5 -> v1.41.7
    • github.com/aws/aws-sdk-go-v2/config v1.32.14 -> v1.32.17
    • github.com/aws/aws-sdk-go-v2/credentials v1.19.14 -> v1.19.16
    • github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.22.12 -> v1.22.18
    • github.com/aws/aws-sdk-go-v2/service/s3 v1.98.0 -> v1.101.0
    • github.com/aws/smithy-go v1.24.3 -> v1.25.1
    • github.com/coreos/go-oidc/v3 v3.17.0 -> v3.18.0
    • github.com/cosi-project/runtime v1.14.1 -> v1.16.0
    • github.com/cosi-project/state-etcd v0.5.3 -> v0.6.0
    • github.com/fluxcd/cli-utils v0.37.2-flux.1 -> v1.2.0
    • github.com/fluxcd/pkg/ssa v0.70.0 -> v0.74.0
    • github.com/fsnotify/fsnotify v1.9.0 -> v1.10.1
    • github.com/google/go-containerregistry v0.21.4 -> v0.21.5
    • github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 -> v2.29.0
    • github.com/mattn/go-shellwords v1.0.12 -> v1.0.13
    • github.com/siderolabs/go-kubernetes v0.2.36 -> v0.2.37
    • github.com/siderolabs/image-factory v1.0.3 -> v1.2.0
    • github.com/siderolabs/omni/client v1.6.1 -> v1.6.5
    • github.com/siderolabs/talos/pkg/machinery v1.13.0-rc.0 -> v1.13.2
    • github.com/stripe/stripe-go/v85 v85.1.0 new
    • github.com/zitadel/oidc/v3 v3.46.0 -> v3.47.5
    • go.etcd.io/etcd/client/pkg/v3 v3.6.10 -> v3.6.11
    • go.etcd.io/etcd/client/v3 v3.6.10 -> v3.6.11
    • go.etcd.io/etcd/server/v3 v3.6.10 -> v3.6.11
    • go.uber.org/zap v1.27.1 -> v1.28.0
    • golang.org/x/crypto v0.49.0 -> v0.51.0
    • golang.org/x/net v0.52.0 -> v0.54.0
    • golang.org/x/text v0.35.0 -> v0.37.0
    • golang.org/x/tools v0.43.0 -> v0.45.0
    • google.golang.org/grpc v1.80.0 -> v1.81.0
    • k8s.io/api v0.35.3 -> v0.36.0
    • k8s.io/apimachinery v0.35.3 -> v0.36.0
    • k8s.io/client-go v0.35.3 -> v0.36.0
    • sigs.k8s.io/controller-runtime v0.23.3 -> v0.24.0

    Previous release can be found at v1.7.0

    Open source →

Every package, every release, already written down.

The archive is open and free. Watching your own project is what we are building next.

Browse the archive