github.com/siderolabs/omni
v1.10.4
#1323 most downloaded on Go modules
siderolabs/omni
What this package is like to depend on
Last release 5 days ago
18 Aug 2026
Ships on a steady schedule
a new release about every 9 days
Rarely documented
notes for 7 of 122 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
533 releases · first in 2024
272 releases in the last 12 months
see the full history below
Release timeline
533 releases · Feb 2024 to Aug 2026Releases
latest 60 of 533-
v1.10.418 Aug 2026Release notes
Open source →Omni 1.10.4 (2026-08-18)
Welcome to the v1.10.4 release of Omni!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.Revoking Kubernetes Access Tokens
Admins can now list the keys which sign the Kubernetes access tokens and delete them using omnictl. Deleting a key immediately invalidates all the tokens signed by it, such as the long-lived service account kubeconfigs, without a restart. Deleting the most recent key is safe: a replacement is generated automatically when the next token is issued. The key deletions are recorded in the audit log.
Contributors
- Utku Ozdemir
Changes
2 commits615998ab9release(v1.10.4): prepare releasebc586e4f7feat: allow listing and deleting the Kubernetes token signing keys
Dependency Changes
This release has no dependency changes
Previous release can be found at v1.10.3
Release notes
Open source →Welcome to the v1.10.4 release of Omni!
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
Revoking Kubernetes Access Tokens
Admins can now list the keys which sign the Kubernetes access tokens and delete them using omnictl. Deleting a key immediately invalidates all the tokens signed by it, such as the long-lived service account kubeconfigs, without a restart. Deleting the most recent key is safe: a replacement is generated automatically when the next token is issued. The key deletions are recorded in the audit log.
Contributors
- Utku Ozdemir
Changes
<details><summary>1 commit</summary> <p>
bc586e4ffeat: allow listing and deleting the Kubernetes token signing keys </p> </details>
Dependency Changes
This release has no dependency changes
Previous release can be found at v1.10.3
-
v1.10.314 Aug 2026Release notes
Open source →Omni 1.10.3 (2026-08-14)
Welcome to the v1.10.3 release of Omni!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.Contributors
- Edward Sammut Alessi
Changes
2 commits39bcff396release(v1.10.3): prepare release8bce1ddbdfix(frontend): check for navigation in preload error events
Dependency Changes
This release has no dependency changes
Previous release can be found at v1.10.2
Release notes
Open source →Welcome to the v1.10.3 release of Omni!
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
Contributors
- Edward Sammut Alessi
Changes
<details><summary>1 commit</summary> <p>
8bce1ddbdfix(frontend): check for navigation in preload error events </p> </details>
Dependency Changes
This release has no dependency changes
Previous release can be found at v1.10.2
-
v1.10.214 Aug 2026Release notes
Open source →Omni 1.10.2 (2026-08-14)
Welcome to the v1.10.2 release of Omni!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.Contributors
- Edward Sammut Alessi
- Oguz Kilcan
Changes
3 commits0a932d3dfrelease(v1.10.2): prepare release93fb429b4chore: rekres and bump go024fe1e4cfix(frontend): fix incorrect machine route params
Dependency Changes
This release has no dependency changes
Previous release can be found at v1.10.1
Release notes
Open source →Welcome to the v1.10.2 release of Omni!
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
Contributors
- Edward Sammut Alessi
- Oguz Kilcan
Changes
<details><summary>2 commits</summary> <p>
93fb429b4chore: rekres and bump go024fe1e4cfix(frontend): fix incorrect machine route params </p> </details>
Dependency Changes
This release has no dependency changes
Previous release can be found at v1.10.1
-
v1.10.112 Aug 2026Release notes
Open source →Omni 1.10.1 (2026-08-12)
Welcome to the v1.10.1 release of Omni!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.Contributors
- Edward Sammut Alessi
- Oguz Kilcan
- Artem Chernyshev
- Utku Ozdemir
Changes
15 commits0fbf63143release(v1.10.1): prepare releasea694edefbfix(frontend): fix reset wizard7aa7a7e45fix: compress diffs in the machine pending updates and diff historydd1b1dd97fix: force re-authentication at the IdP so logout takes effectb5303320afix: keep a machine's tunnel peer address stable across provisions1005ec0d6fix(frontend): return no-cache for index.htmlc9ba2048bfix: don't sign users out of Omni on Kubernetes OIDC logout3b82989e1fix(frontend): add missing credentials to security pagesa2058e200chore(frontend): bump dependencies8a8fd2a1btest(frontend): add edit patch e2e test4d1ed5bb5fix(frontend): fix patch edit dropping fields80b2e8586fix: backfill the image factory host of machines enrolled before 1.10f28cdc77afix: bound the machine config diff by bytes, not just lines0e1259283fix(frontend): be more defensive about signup errors6b91ddb67fix: log out of Omni and the IdP when /logout is opened directly
Dependency Changes
This release has no dependency changes
Previous release can be found at v1.10.0
Release notes
Open source →Welcome to the v1.10.1 release of Omni!
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
Contributors
- Edward Sammut Alessi
- Oguz Kilcan
- Artem Chernyshev
- Utku Ozdemir
Changes
<details><summary>14 commits</summary> <p>
a694edeffix(frontend): fix reset wizard7aa7a7e4fix: compress diffs in the machine pending updates and diff historydd1b1dd9fix: force re-authentication at the IdP so logout takes effectb5303320fix: keep a machine's tunnel peer address stable across provisions1005ec0dfix(frontend): return no-cache for index.htmlc9ba2048fix: don't sign users out of Omni on Kubernetes OIDC logout3b82989efix(frontend): add missing credentials to security pagesa2058e20chore(frontend): bump dependencies8a8fd2a1test(frontend): add edit patch e2e test4d1ed5bbfix(frontend): fix patch edit dropping fields80b2e858fix: backfill the image factory host of machines enrolled before 1.10f28cdc77fix: bound the machine config diff by bytes, not just lines0e125928fix(frontend): be more defensive about signup errors6b91ddb6fix: log out of Omni and the IdP when /logout is opened directly </p> </details>
Dependency Changes
This release has no dependency changes
Previous release can be found at v1.10.0
-
v1.10.007 Aug 2026Release notes
Open source →Welcome to the v1.10.0 release of Omni!
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
Following the Audit Log
The audit log read API gains a follow mode. After serving the backlog the stream stays open and delivers new events as they are written, in insertion order. Followed events carry their ids, and a stream can start from an id received earlier, so a consumer resumes exactly where it left off. The start position can also be given as a timestamp. A follow stream ends cleanly after a bounded time rather than staying open indefinitely, and the client continues from the last id it received.
omnictlperforms that reconnect automatically.omnictl audit-loggains a--followflag to tail the log live and a--sinceflag to start from a relative time in either mode. Reading the audit log now produces an audit log event of its own, recording who read it, the time range requested and the filters used, and the new event type can itself be filtered on.Auditor Role
Reading the audit log required the Admin role, so anything that consumes audit events also had to hold user management and full administrative access to every managed Kubernetes cluster. The new Auditor role grants read access plus the audit log and nothing else. It is matched by exact role rather than by rank, so an Operator, which outranks an Auditor, still cannot read the audit log. It can be assigned to users and service accounts, but not through access policies or SAML label rules, which now reject roles that are not meant to be assigned that way.
Cluster Security Page
A new cluster security page lists the vulnerabilities of the images a running cluster uses, together with the upgrade paths that clear them, and the scan details can be filtered by severity. Vulnerability scanning requires the Image Factory Enterprise. Against the public factory the page reports that scanning is unavailable instead of showing results.
Kubernetes CA and Service Account Key Rejected in Config Patches
Config patches can no longer set the Kubernetes certificate authority or the service account signing key, which Omni generates and owns. This holds for every cluster, not only for clusters on the new Talos 1.14 document layout, and it covers the v1alpha1 fields as well as the Talos 1.14 documents that carry the same material. An already stored patch keeps working while it stays unchanged. Changing one that sets either of them is rejected, so such a patch has to be corrected before it can be edited again.
Disabling Config Patches
A config patch can now be disabled. It is retained as a resource but is never applied.
Discovery Service Configuration Reworked
Talos 1.14 replaces the single discovery endpoint with a configuration that can register a machine with more than one discovery service at once, and Omni now removes a departing machine's affiliate from every endpoint it used. A cluster used to pick either the public discovery service or the embedded one. For clusters created with Talos 1.14 or newer it can now also use both at the same time.
Talos Enterprise and FIPS Machine Labels
Machines running Talos Enterprise now get an
omni.sidero.dev/enterpriselabel, and machines running Talos in FIPS mode get anomni.sidero.dev/fipslabel carrying eitherenabledorstrict. Like the other labels Omni manages, they cannot be removed by the user, and they are cleared when a machine reverts to a regular build. Both values are read over the Talos API and watched for changes, since they follow the installed image. Older Talos versions do not report them, so machines running those get no labels.Frontend Quality-of-Life Improvements
Machine names are shown the same way everywhere, using the hostname with the machine UUID as a fallback, and the machine stage is dimmed while a machine is unhealthy, with the last known status still shown. The home page replaces the radial bars with segmented ones and splits the machine stats into connection and allocation, which used to be mixed together, and it now also shows the ongoing operations that were previously only in the top-right dropdown. The CPU usage chart stacks its system and user areas and labels them as percentages, and the Kubernetes manifests status is drawn as a graph. In the disk view, unallocated space is striped so it reads apart from allocated space, and volumes Omni does not recognize cycle through distinct colors. Errors from machine service queries appear inline on the page instead of as a toast, with retries and backoff, and an unreachable Talos API is reported as not ready yet rather than as a generic failure. The config editor can toggle word wrap from its context menu, and
$patch: deleteis accepted everywhere the patch validation allows it. On an Auth0 instance the very first user lands on the signup page instead of the login page, and PXE boot is hidden when Omni runs against the Image Factory Enterprise. A node's last configuration error is now shown on every one of its tabs, not just the overview, and Talos and Kubernetes version dropdowns list versions newest first. The machine delete confirmation lists hostnames instead of raw UUIDs. Removing machines is named consistently: deleting a machine or a pending machine is "Delete", removing one from a cluster is "Remove", and the destructive machine option reads "Force Delete" instead of "Force Destroy".Infrastructure Provider Names Validated as DNS Labels
An infrastructure provider id must now be a valid DNS label, so lowercase letters, digits and dashes only. Ids with uppercase letters, underscores or spaces used to be accepted and caused failures further along. They are rejected at creation now.
Infra Provider Versions in the UI and CLI
The UI and the CLI now show the version of an infrastructure provider.
Install Disk Selection Respected on Maintenance Installs
Machines on Talos 1.13 or newer are installed through the Talos lifecycle API, which takes the install disk as an explicit argument. Omni passed the automatically picked default there, so a disk chosen through the UI or a cluster template was ignored and Talos could be installed to a different disk than the one selected. Omni now reads the install disk from the machine's effective configuration, where the selection is already applied on top of the default.
Permanent Install Failures Stop Retrying
Talos installers from 1.14 report a distinct exit code per failure instead of one generic code, and Omni now reads them. A failure caused by invalid input or an unsupported operation cannot succeed until the machine configuration or the install options change, so Omni records the reason on the machine and stops retrying. Everything else stays retryable, including the single exit code that pre-1.14 installers report for every failure.
No kube-proxy Pre-Pull on Kubernetes Upgrades
Kubernetes upgrades no longer pre-pull the kube-proxy image, on any cluster. Clusters that use a kube-proxy replacement such as Cilium turn kube-proxy off, and pre-pulling an image they never run consumed bandwidth needlessly.
KubeSpan Quick Start
Rather than disabling the KubeSpan tab for a cluster that does not have KubeSpan enabled, Omni now shows a quick start page there with a short explanation, a link to the docs, the config patch it would apply, and a button that applies it. The suggested patch matches what the cluster supports, so a cluster on multi-document configs is offered the newer form. The page warns about the network overhead, which matters most on larger clusters. The KubeSpan status view also tells offline peers apart by shape and line style on top of color, which helps with red and green color blindness.
Installs and Upgrades Through Talos's LifecycleService
On machines running Talos 1.13 or newer, Omni installs and upgrades through Talos's LifecycleService and runs the sequence itself: pull the installer, install or upgrade to disk, forfeit etcd leadership on control planes, cordon and drain the node, then reboot. Same-minor installs on maintenance machines take this explicit path now, instead of letting a config apply trigger the install, and cluster creation and scale-up bring a maintenance-mode machine to the cluster's Talos version when the two differ by a minor version. Machines on older Talos keep using the classic path, and each machine's running version and schematic decide which one it takes.
Logout URL
Every Omni instance now answers at
/logout, whatever its authentication type. SAML and OIDC instances were already served by the backend, and Auth0 instances now have a page that performs the logout, so the same URL ends a session everywhere.New and Newly Exposed Metrics
omni_machine_logs_ingested_bytes_totalcounts the bytes of machine log messages written to storage. Two gauges that were being kept up to date but never registered are now exposed on the Prometheus endpoint as well, one for the number of CPU cores across all machines and one for the number of active virtual state watches.Multiple Image Factories
Omni can now run against two image factories, a primary and a secondary, which makes it possible to migrate from one to the other. They are configured under
registries.factories.primaryandregistries.factories.secondary, each taking a URL, a PXE URL, and Image Factory Enterprise credentials. The flatimageFactoryBaseURL,imageFactoryPXEBaseURL,imageFactoryUsernameandimageFactoryPasswordoptions are deprecated in favor of the primary block. They still work on their own, but once the primary block carries a URL they are ignored completely, so credentials meant for one factory are never sent to another.Node Audit Skip Configurable in the UI and Cluster Templates
The node audit skip cluster feature, which exempts a Kubernetes node carrying the
omni.sidero.dev/node-audit-skipannotation from the node audit, can now be turned on from the cluster create page and the cluster overview, and set in cluster templates.Machine Reset Wipes More Volumes on Talos 1.14
On Talos 1.14 and newer, resetting a machine also wipes the container runtime, kubelet, etcd and log volumes, on top of the state and ephemeral partitions it wiped before. Machines on earlier Talos versions still have only those two wiped.
More Reliable SAML Single Logout
Single logout on a SAML instance could silently fail to reach the identity provider. The cookie tracking the logout was cleared as soon as the logout request was built rather than once the identity provider confirmed it, so any repeated request to
/logout, including the browser's own retries, found nothing left to send and the identity provider session survived. A logout response delivered over the HTTP-Redirect binding, rather than as a POST, also failed to parse and left the user on the forbidden page even though the identity provider had already completed the logout; that binding is now handled on its own endpoint.Search, Filter and Sort Kept in the URL
Search terms, filters and sort order are now part of the URL, so a narrowed-down view survives a reload and can be shared as a link.
Richer Support Bundles
Support bundles now also carry in-flight machine update state and the inputs Omni uses to generate machine configurations.
Talos 1.14 Configuration Support
Talos 1.14 moves cluster identity, certificate authorities, encryption secrets and Talos API access rules out of the single v1alpha1 document into documents of their own, and Omni understands the new layout. Kubernetes component images for upgrades are patched in the shape the cluster's version contract calls for, Kubernetes CA rotation writes the accepted CA wherever the generated configuration keeps it, and the Talos API access restriction follows its own document. The frontend validates patches against the 1.14 schema and generates 1.14 variants of the patches it writes.
Contributors
- Edward Sammut Alessi
- Oguz Kilcan
- Utku Ozdemir
- Mateusz Urbanek
- Maja Bojarska
- Artem Chernyshev
- Andrey Smirnov
- Orzelius
- Noel Georgi
- Justin Garrison
- Mark Glants
- Mickaël Canévet
- Nguyen Duc Quynh
- Olli Hauer
- Rowan Voermans
- Sting Alleman
- Tim Jones
Changes
<details><summary>192 commits</summary> <p>
5d2b007bcchore: bump default versions0a63295b4fix: make SAML single logout survive retries and redirect binding0b59f8beefeat(frontend): show config errors on all node pages7e97185f3feat(frontend): sort talos/k8s versions newest firste9214cc36fix(frontend): adjust kubespan quick start text06b49581afeat(frontend): use hostnames for machine list in delete modalbe310e386feat(frontend): normalise the delete/remove text for machinesfd41f737afeat: encrypt support bundles by default924420ddarelease(v1.10.0-beta.0): prepare releaseacc9edb2efeat: classify installer exit codes and skip retrying permanent ones18bafff42fix(frontend): adjust toast text for machine removal02bb82775fix(frontend): unselect removed machines in machine listd3419f711test: make the install disk selection test deterministicee6b16d84test: reserve integration test machines against concurrent allocationeb5320932feat(frontend): improve legibility for unallocated and user partitions2c4940aedfix: drop noisy WireGuard handshake warnings for offline peers89d418568feat: for talos 1.14 machine reset also wipe cri, kubelet, etcd, loge040a4b61fix(frontend): use cluster config version for version contract in scale5d9489643fix(frontend): also check version contract in cluster scaledbc458e82feat(frontend): allow $patch: delete in all places0b5cafaf3chore: bump dependencies9e062ebc5fix: forbid cluster CA and service account key in config patches3a4771fabfeat: rotate the Kubernetes CA on Talos 1.14 multi-doc configs6d67db2a6feat: rework discovery service configuration for Talos 1.141cdfd703cfix: track namespaced cluster-scoped manifests as applied7765bab36feat: validate multi-doc config patches2f4f0f382feat(frontend): add talos 1.14 variants for frontend generated patches4dcd206a5feat: expose more version contract fields202769d74fix(frontend): use dvh instead of vh for heightd02e70432feat(frontend): add talos 1.14 schema9cad25799chore: bump talos machinery03ad541a4fix: respect the user's install disk selection in maintenance installsf31cbce00feat(frontend): redesign manifests status to a graph view126b6b721refactor(frontend): refactor kubespan canvas to vue-flow4546b0968fix(frontend): trim cluster machine status last_config_error messaged04a01230feat: for kubespan quick start use correct patch for the clusterd34ecf498feat(client): allow disabling the transparent watch retry72b942c38feat: add Auditor role for reading the audit log0a64c8185feat: label Talos Enterprise machinesf73296960feat: multiple image factories support7873fda7achore: apply CA, Registry configs before install/upgrade calls53b3c825cfeat: support enableNodeAuditSkip in cluster templatesb2b2b2050fix: verify maintenance install/upgrade against the live machine7bc776663chore: change virtual ImageFactoryAuth resource to be persistent72ffae831fix(frontend): fix incorrect action on patch delete92215fb7efix(frontend): preserve whitespace in alerts4edaf8a41fix: dont include failed/evicted pods for k8s usage dataf5cb97b2efix(frontend): constrain monitor charts to a fixed size regardless of stateb5cff35bffix(frontend): constrain extensions modals to a fixed size6cea62574fix(frontend): dont try load auth0 if we arent using auth0 in userinfobed3482d1fix(frontend): don't call machineservice.events for maintenance talos on <1.13582730ce9chore: bump depsfb2ae3f74fix: allow SAMLLabelRule to downgrade user role to None7b06af519fix: mark machines installed when the lifecycle install completes2557f6451chore: rekres73e415becchore(frontend): bump deps87ca0cdf9fix(frontend): prevent jumping when select up/down arrows disappear071f1b295feat: allow disabling config patches526e1c635feat: support following the audit log over the management APId0824edf0fix: support the new discovery service endpoints list of Talos 1.1447b66fdf3feat: show infra provider versions in ui and clie23a8f7d7feat: do not pre-pull the kube-proxy image on Kubernetes upgradese19f19d14fix: use initial versions from inputedcc25692feat: build version aware Kubernetes component patches for upgradesd0642877bfeat(frontend): hide pxe boot option for enterprise3187ffad3test: fix Omni upgrade workload proxy DNS4e8cc051efix: ignore not-found errors when deleting an infra provider1476e5389chore: bump talos machinery to v1.14.0-alpha.29d4cfa666feat(frontend): dim machine stage status when machine is not healthy89eca085dtest: run browser e2e tests off the host networkd6bfcee97feat: serve the frontend dev server through the main endpoint66a7ba2fdfix: allow removing the bootstrap spec once the cluster is bootstrappedf75c63db6feat: install same-minor maintenance machines via LifecycleServiceff510298bfix: expose the machines cores and virtual state watches metricsdf72b2c32test: use dex oidc instead of auth0 as default for e2e tests7fcee51e2test: poll for minio to come up instead of just sleeping54819dfa2test(frontend): remove testing of actual iso download110cf83c2refactor: proxy frontend dev server routes using prod flowd62f8c866chore(frontend): update factory staging url for dev5a751477dfeat(frontend): add a /logout route for auth0 logouts9e3f29030fix(frontend): skip 0 length bars in home segmented charts15b1667d7feat(frontend): handle machine services errors gracefullyf161c4377refactor(frontend): make watch failed errors more informative7a2477b42fix: update kube-service-exposer to v0.4.0d0d7d76dbfeat: introduce the new metric that counts total number of cores531947830feat: use LifecycleService for maintenance machine upgradesdb6795395fix: dont clear sa expiration when no keys are left74cb7078efix: correct boot ID and Talos version tracking for maintenance installs3eab1cc10fix(frontend): remove an unused @click actionf3f9cd675refactor(frontend): make all detached scopes lazily loaded2be419957chore(frontend): bump frontend deps000b16206fix: honor current machine set update limits2dfe2e5aechore: bump oras-go to 2.6.216265a1a8feat(frontend): add word wrap to monaco context menu0a37d5090refactor(frontend): don't create new editor and model instance for schema changes800217124chore(frontend): add stories for CodeEditore2f573985fix(frontend): make CodeEditor props reactive561d2582dfeat: log audit log access in the audit log0fee0fc30fix: properly propagate errors coming from the machine lifecycle APIb5450ebfbfix: don't treat unset S3 endpoint as an empty overridedaa126862test(frontend): adjust fake-indexeddb usage which broke in node 24.180618b9015chore(frontend): bump node to 24.185419d7071feat(frontend): show ongoing operations on the home page2afd22236feat(frontend): use segmented bars for home page stats8b637dc86chore(frontend): write stories for home page contentdf33497e2chore: bump dependenciesa47e7128cfeat: add machine log ingestion byte-rate metric7bc30eb08chore: rekres and bump Go to 1.26.5e05e3285dfeat: manage Talos install and upgrade via LifecycleService2ddeca05ffix(frontend): remove power icon from machines paged0535ada4feat: expose node audit skip cluster feature809baa687feat(frontend): persist search and filters as query stringsee432246drefactor(frontend): rename filterLabel to selectLabel in ItemLabelab95b0c3brefactor(frontend): refactor LabelsInput to use v-modele6fa2f14erefactor(frontend): replace removeLabel prop with remove emit5e9ccbd12refactor(frontend): replace onClear prop with clear emit14ef61130feat: send initial instance user to signup page84f151fe7fix(frontend): handle aborted requests in useMachineServices7e0cf44c2feat(frontend): add a quickstart page for kubespan8e8a46757feat(frontend): standardize machine display in omni2d5610204fix(frontend): prevent item list flash during connection drops655c2ae4frefactor(frontend): move itemID into useResourceWatch8373f536frefactor(frontend): lift interfaces from watch to composable7fb66d5bdrefactor(frontend): merge watch items into composable37b19c408refactor(frontend): lift remaining parts of watch class to composable0e7bb6ae9refactor(frontend): lift item handlers up to watch composable640014ecdrefactor(frontend): inline watch callbacks588d21e2crefactor(frontend): remove unnecessary setDescending funcc655f002frefactor(frontend): migrate watch tests to useresourcewatch tests4e4cd5f85refactor(frontend): move watch.setup into useresourcewatch81c8c2a40refactor(frontend): merge watchfunc and watch classes together104a8b2abfix(frontend): prevent copying double newlines in machine logsc48c9b923refactor(frontend): migrate machine set config edit modal to new modal system2adcefe4drefactor(frontend): migrate create extensions modal to new modal systemc435a8f69refactor(frontend): migrate config patch edit modal to new modal systeme7c340668refactor(frontend): migrate save preset modal to new modal systema7762559drefactor(frontend): hide primary action when maintenance lifecycle complete971145cc1refactor(frontend): migrate download preset modal to new modal systemf9360c2e9refactor(frontend): remove unused machine template extensions modal8ee92b377refactor(frontend): migrate service account renew to new modal system022c458ferefactor(frontend): migrate service account create to new modal system7747a322crefactor(frontend): migrate role edit to new modal systemfb9d41f13refactor(frontend): migrate user destroy to new modal system384a5347arefactor(frontend): migrate user create to new modal systemd69401087refactor(frontend): migrate machine remove to new modal systeme0626db83refactor(frontend): migrate machine class destroy to new modal systemdb5540826refactor(frontend): migrate machine set destroy to new modal systeme26d569adrefactor(frontend): migrate export cluster template to new modal systemdd5b62550refactor(frontend): migrate config patch destroy to new modal system7f1bf6646refactor(frontend): migrate infra provider delete to new modal system9bdbeace7refactor(frontend): migrate infra provider setup to new modal systemb94b299b4refactor(frontend): migrate download omnictl to new modal system542124bcfrefactor(frontend): migrate node shutdown to new modal systemfe09adc22refactor(frontend): migrate node destroy cancel to new modal systemd1b56338drefactor(frontend): migrate node destroy to new modal system02f0d1129refactor(frontend): migrate node reboot to new modal system3ddc040e1test: fix flaky audit log and service account status testse330092a2feat: add pending updates and config gen options to support bundle49c8e725ffix: update COSI runtime to fix hanging TeardownAndDestroy callsc91ce1a50fix: align config outdated status in ui and clifde089bberefactor(frontend): refactor untaint single node modal to new system094b25913feat(frontend): add content-class support to confirm modald193dce9echore: expose user roles in the public package to be used by scripts33aa3fa26refactor(frontend): replace ua-parser-js with bowser6b2da6745chore(frontend): drop yaml dependency and move openpgp to dependencies27c6aa078chore: rekres for js sbomed793b6b0feat(frontend): add filtering to scan details modal6ef286f27feat(frontend): add a cluster security page for vulns99a76d479refactor(frontend): extract components from scan details modal034640bberefactor(frontend): extract business logic from scan details modal2cf7801dcrefactor(frontend): make use resource list default to empty array120563a38feat(frontend): stack CPU usage chart areas and format with %77dcbe90bchore: add stories for monitor viewae93d3f96fix(frontend): only show process args in command columne690d624bfix(frontend): allow in-minor patch upgrades in update kubernetes on Omnib30472e6crefactor: use ImageServiceClient for pulling images1c20cc949chore: bump helm to v4 in zstd-dict5f4f27df3fix: recover a machine from a reverted reboot-requiring config patcheadd5b57dfix(frontend): allow force-destroy when MachineSetNode is already gonefd4e5da46test(frontend): fix some flaky tests in e2e-talemu1882db158feat: install/upgrade maintenance-mode Talos during cluster create/scale-up84180bd0ffix: advertise reachable machine API address in cluster-import test937ce3a61fix: keep maintenance Talos clients until machine leaves maintenancea7b87871crefactor: derive extension list from the raw schematic manifest961a20c60fix: move timeout for factory requests to controllerse63d4e455test: drop non-existent preset delete error expectation6f26c4098chore: enrich SBOM with Go module licenses1b337b249fix: tolerate NotFound on installation media preset deletec2533013ctest: stabilize image-factory schematic across CI runs984ba0090feat(frontend): add more visual distinction for offline kubespan peers51cc468dbfix: prevent removal of node unique tokens that still have a link88c77c618fix: validate infra provider name as DNS-1123 label </p> </details>
Changes since v1.10.0-beta.0
<details><summary>8 commits</summary> <p>
5d2b007bcchore: bump default versions0a63295b4fix: make SAML single logout survive retries and redirect binding0b59f8beefeat(frontend): show config errors on all node pages7e97185f3feat(frontend): sort talos/k8s versions newest firste9214cc36fix(frontend): adjust kubespan quick start text06b49581afeat(frontend): use hostnames for machine list in delete modalbe310e386feat(frontend): normalise the delete/remove text for machinesfd41f737afeat: encrypt support bundles by default </p> </details>
Changes from siderolabs/discovery-service
<details><summary>13 commits</summary> <p>
f03ed02release(v1.1.0): prepare release373430afeat(stats): add cached /stats endpoint0dc4741chore: bump prometheus, grpc, and otel deps1479df2chore: bump net to v0.57.0709d4b9chore: bump net pkg to v0.55.0 (security)0ce4779chore: bump sync pkg to v0.22.09628da0chore: update go.mod deps99b6268chore: rekres48cf9dfchore: bump go to latest 1.26d315a3fchore: fmtf905881chore: rekres73b90dffeat: add support for x-forwaded-for header35804dachore: bump dependencies </p> </details>
Changes from siderolabs/gen
<details><summary>1 commit</summary> <p>
c526410fix: skip unknown-key check for types with custom YAML unmarshaler </p> </details>
Changes from siderolabs/go-kubernetes
<details><summary>3 commits</summary> <p>
0caf1f2feat: add Kubernetes 1.37 compatibility822b7a2feat: add nodedrain package for client-side cordon and drain260bc0afix: update authorization config apiVersion for K8s >= 1.32 </p> </details>
Changes from siderolabs/go-talos-support
<details><summary>1 commit</summary> <p>
18af7d6feat: update dependencies and support recipients </p> </details>
Changes from siderolabs/image-factory
<details><summary>21 commits</summary> <p>
efab38frelease(v1.4.0): prepare release9c64235feat: add schematic owner validationca87d23fix: add single-flight around schematic factoryd45b5acdocs: link to Image Factory Enterprise docs page490a993chore: bump pkgs revision to match talos v1.14.0-alpha.2f9ff935chore: bump go pkgs12cd647feat: add llms.txt for better LLM usagef65960ffix: audit file defaultsf26e5e2feat: add audit log for authenticated requestsbeff6e2feat: support registry namespace prefix for core artifacts8c489d0chore: update dependencies026f8a8feat: extra extensions (enterprise only)915ef76chore: add insecure flag to dev config3bccbe1fix: handle single arch images6b1c855refactor: prepare for more than one artifact registrybee4fe3feat: narrow sbom cache key to extension list onlye0e4a44refactor: abstract versioned cache3359f6cfeat: add secureboot enrollKeys schematic option805c51cfeat: add per-request correlation ID to logs8cee96dfeat: assert pxe cache in tests4ec0789feat: bump go-conainerregistry </p> </details>
Dependency Changes
- github.com/auth0/go-jwt-middleware/v3 v3.2.0 -> v3.3.0
- github.com/aws/aws-sdk-go-v2 v1.42.0 -> v1.43.2
- github.com/aws/aws-sdk-go-v2/config v1.32.25 -> v1.32.33
- github.com/aws/aws-sdk-go-v2/credentials v1.19.24 -> v1.19.32
- github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager v0.3.7 new
- github.com/aws/aws-sdk-go-v2/service/s3 v1.104.0 -> v1.106.2
- github.com/aws/smithy-go v1.27.2 -> v1.27.6
- github.com/coreos/go-oidc/v3 v3.19.0 -> v3.20.0
- github.com/cosi-project/runtime v1.16.1 -> v1.16.2
- github.com/fluxcd/cli-utils v1.2.1 -> v1.2.2
- github.com/fluxcd/pkg/ssa v0.76.0 -> v0.77.0
- github.com/go-logr/logr v1.4.3 -> v1.4.4
- github.com/google/go-containerregistry v0.21.7 -> v0.21.8
- github.com/johannesboyne/gofakes3 4c385a1f6a73 -> v1.2.0
- github.com/mattn/go-shellwords v1.0.13 -> v1.0.14
- github.com/prometheus/client_golang v1.23.2 -> v1.24.1
- github.com/prometheus/common v0.69.0 -> v0.70.1
- github.com/siderolabs/discovery-service v1.0.17 -> v1.1.0
- github.com/siderolabs/gen v0.8.6 -> v0.8.7
- github.com/siderolabs/go-kubernetes v0.2.39 -> v0.2.41
- github.com/siderolabs/go-talos-support v0.3.0 -> v0.3.1
- github.com/siderolabs/image-factory v1.3.3 -> v1.4.0
- github.com/siderolabs/omni/client v1.8.1 -> v1.9.3
- github.com/siderolabs/talos/pkg/machinery v1.14.0-alpha.1 -> v1.14.0-beta.1
- github.com/zitadel/oidc/v3 v3.47.5 -> v3.48.1
- go.etcd.io/bbolt v1.4.3 -> v1.5.0
- go.etcd.io/etcd/client/pkg/v3 v3.6.12 -> v3.7.1
- go.etcd.io/etcd/client/v3 v3.6.12 -> v3.7.1
- go.etcd.io/etcd/pkg/v3 v3.7.1 new
- go.etcd.io/etcd/server/v3 v3.6.12 -> v3.7.1
- go.yaml.in/yaml/v4 v4.0.0-rc.4 -> v4.0.0-rc.6
- golang.org/x/crypto v0.53.0 -> v0.54.0
- golang.org/x/net v0.56.0 -> v0.57.0
- golang.org/x/sync v0.21.0 -> v0.22.0
- golang.org/x/text v0.38.0 -> v0.40.0
- golang.org/x/tools v0.46.0 -> v0.48.0
- google.golang.org/grpc v1.81.1 -> v1.83.0
- k8s.io/api v0.36.2 -> v0.36.3
- k8s.io/apimachinery v0.36.2 -> v0.36.3
- k8s.io/client-go v0.36.2 -> v0.36.3
Previous release can be found at v1.9.0
-
v1.10.0-beta.0.0.20260818182222-ee0704f79d0718 Aug 2026 pre-releaseNothing published for this version
-
v1.10.0-beta.0.0.20260818084146-0051462aac6318 Aug 2026 pre-releaseNothing published for this version
-
v1.10.0-beta.0.0.20260814133638-f2aeaa851a8e14 Aug 2026 pre-releaseNothing published for this version
-
v1.10.0-beta.0.0.20260814074331-4c283a3bfcff14 Aug 2026 pre-releaseNothing published for this version
-
v1.10.0-beta.0.0.20260813102735-0f029dcec8ba13 Aug 2026 pre-releaseNothing published for this version
-
v1.10.0-beta.0.0.20260812150027-dbff80519cf712 Aug 2026 pre-releaseNothing published for this version
-
v1.10.0-beta.0.0.20260812131340-0970a6db2c4c12 Aug 2026 pre-releaseNothing published for this version
-
v1.10.0-beta.0.0.20260812124608-cc23658b073212 Aug 2026 pre-releaseNothing published for this version
-
v1.10.0-beta.0.0.20260812115117-47845eb51c8912 Aug 2026 pre-releaseNothing published for this version
-
v1.10.0-beta.0.0.20260812113236-194c629cf40e12 Aug 2026 pre-releaseNothing published for this version
-
v1.10.0-beta.0.0.20260812110958-899128ec588d12 Aug 2026 pre-releaseNothing published for this version
-
v1.10.0-beta.0.0.20260811104404-2c70b154142a11 Aug 2026 pre-releaseNothing published for this version
-
v1.10.0-beta.0.0.20260810154917-dc6fa2246f8e10 Aug 2026 pre-releaseNothing published for this version
-
v1.10.0-beta.0.0.20260807143307-0a45ef09553407 Aug 2026 pre-releaseNothing published for this version
-
v1.10.0-beta.004 Aug 2026 pre-releaseRelease notes
Open source →Welcome to the v1.10.0-beta.0 release of Omni!
This is a pre-release of OmniPlease try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
Following the Audit Log
The audit log read API gains a follow mode. After serving the backlog the stream stays open and delivers new events as they are written, in insertion order. Followed events carry their ids, and a stream can start from an id received earlier, so a consumer resumes exactly where it left off. The start position can also be given as a timestamp. A follow stream ends cleanly after a bounded time rather than staying open indefinitely, and the client continues from the last id it received.
omnictlperforms that reconnect automatically.omnictl audit-loggains a--followflag to tail the log live and a--sinceflag to start from a relative time in either mode. Reading the audit log now produces an audit log event of its own, recording who read it, the time range requested and the filters used, and the new event type can itself be filtered on.Auditor Role
Reading the audit log required the Admin role, so anything that consumes audit events also had to hold user management and full administrative access to every managed Kubernetes cluster. The new Auditor role grants read access plus the audit log and nothing else. It is matched by exact role rather than by rank, so an Operator, which outranks an Auditor, still cannot read the audit log. It can be assigned to users and service accounts, but not through access policies or SAML label rules, which now reject roles that are not meant to be assigned that way.
Cluster Security Page
A new cluster security page lists the vulnerabilities of the images a running cluster uses, together with the upgrade paths that clear them, and the scan details can be filtered by severity. Vulnerability scanning requires the Image Factory Enterprise. Against the public factory the page reports that scanning is unavailable instead of showing results.
Kubernetes CA and Service Account Key Rejected in Config Patches
Config patches can no longer set the Kubernetes certificate authority or the service account signing key, which Omni generates and owns. This holds for every cluster, not only for clusters on the new Talos 1.14 document layout, and it covers the v1alpha1 fields as well as the Talos 1.14 documents that carry the same material. An already stored patch keeps working while it stays unchanged. Changing one that sets either of them is rejected, so such a patch has to be corrected before it can be edited again.
Disabling Config Patches
A config patch can now be disabled. It is retained as a resource but is never applied.
Discovery Service Configuration Reworked
Talos 1.14 replaces the single discovery endpoint with a configuration that can register a machine with more than one discovery service at once, and Omni now removes a departing machine's affiliate from every endpoint it used. A cluster used to pick either the public discovery service or the embedded one. For clusters created with Talos 1.14 or newer it can now also use both at the same time.
Talos Enterprise and FIPS Machine Labels
Machines running Talos Enterprise now get an
omni.sidero.dev/enterpriselabel, and machines running Talos in FIPS mode get anomni.sidero.dev/fipslabel carrying eitherenabledorstrict. Like the other labels Omni manages, they cannot be removed by the user, and they are cleared when a machine reverts to a regular build. Both values are read over the Talos API and watched for changes, since they follow the installed image. Older Talos versions do not report them, so machines running those get no labels.Frontend Quality-of-Life Improvements
Machine names are shown the same way everywhere, using the hostname with the machine UUID as a fallback, and the machine stage is dimmed while a machine is unhealthy, with the last known status still shown. The home page replaces the radial bars with segmented ones and splits the machine stats into connection and allocation, which used to be mixed together, and it now also shows the ongoing operations that were previously only in the top-right dropdown. The CPU usage chart stacks its system and user areas and labels them as percentages, and the Kubernetes manifests status is drawn as a graph. In the disk view, unallocated space is striped so it reads apart from allocated space, and volumes Omni does not recognize cycle through distinct colors. Errors from machine service queries appear inline on the page instead of as a toast, with retries and backoff, and an unreachable Talos API is reported as not ready yet rather than as a generic failure. The config editor can toggle word wrap from its context menu, and
$patch: deleteis accepted everywhere the patch validation allows it. On an Auth0 instance the very first user lands on the signup page instead of the login page, and PXE boot is hidden when Omni runs against the Image Factory Enterprise.Infrastructure Provider Names Validated as DNS Labels
An infrastructure provider id must now be a valid DNS label, so lowercase letters, digits and dashes only. Ids with uppercase letters, underscores or spaces used to be accepted and caused failures further along. They are rejected at creation now.
Infra Provider Versions in the UI and CLI
The UI and the CLI now show the version of an infrastructure provider.
Install Disk Selection Respected on Maintenance Installs
Machines on Talos 1.13 or newer are installed through the Talos lifecycle API, which takes the install disk as an explicit argument. Omni passed the automatically picked default there, so a disk chosen through the UI or a cluster template was ignored and Talos could be installed to a different disk than the one selected. Omni now reads the install disk from the machine's effective configuration, where the selection is already applied on top of the default.
Permanent Install Failures Stop Retrying
Talos installers from 1.14 report a distinct exit code per failure instead of one generic code, and Omni now reads them. A failure caused by invalid input or an unsupported operation cannot succeed until the machine configuration or the install options change, so Omni records the reason on the machine and stops retrying. Everything else stays retryable, including the single exit code that pre-1.14 installers report for every failure.
No kube-proxy Pre-Pull on Kubernetes Upgrades
Kubernetes upgrades no longer pre-pull the kube-proxy image, on any cluster. Clusters that use a kube-proxy replacement such as Cilium turn kube-proxy off, and pre-pulling an image they never run consumed bandwidth needlessly.
KubeSpan Quick Start
Rather than disabling the KubeSpan tab for a cluster that does not have KubeSpan enabled, Omni now shows a quick start page there with a short explanation, a link to the docs, the config patch it would apply, and a button that applies it. The suggested patch matches what the cluster supports, so a cluster on multi-document configs is offered the newer form. The page warns about the network overhead, which matters most on larger clusters. The KubeSpan status view also tells offline peers apart by shape and line style on top of color, which helps with red and green color blindness.
Installs and Upgrades Through Talos's LifecycleService
On machines running Talos 1.13 or newer, Omni installs and upgrades through Talos's LifecycleService and runs the sequence itself: pull the installer, install or upgrade to disk, forfeit etcd leadership on control planes, cordon and drain the node, then reboot. Same-minor installs on maintenance machines take this explicit path now, instead of letting a config apply trigger the install, and cluster creation and scale-up bring a maintenance-mode machine to the cluster's Talos version when the two differ by a minor version. Machines on older Talos keep using the classic path, and each machine's running version and schematic decide which one it takes.
Logout URL
Every Omni instance now answers at
/logout, whatever its authentication type. SAML and OIDC instances were already served by the backend, and Auth0 instances now have a page that performs the logout, so the same URL ends a session everywhere.New and Newly Exposed Metrics
omni_machine_logs_ingested_bytes_totalcounts the bytes of machine log messages written to storage. Two gauges that were being kept up to date but never registered are now exposed on the Prometheus endpoint as well, one for the number of CPU cores across all machines and one for the number of active virtual state watches.Multiple Image Factories
Omni can now run against two image factories, a primary and a secondary, which makes it possible to migrate from one to the other. They are configured under
registries.factories.primaryandregistries.factories.secondary, each taking a URL, a PXE URL, and Image Factory Enterprise credentials. The flatimageFactoryBaseURL,imageFactoryPXEBaseURL,imageFactoryUsernameandimageFactoryPasswordoptions are deprecated in favor of the primary block. They still work on their own, but once the primary block carries a URL they are ignored completely, so credentials meant for one factory are never sent to another.Node Audit Skip Configurable in the UI and Cluster Templates
The node audit skip cluster feature, which exempts a Kubernetes node carrying the
omni.sidero.dev/node-audit-skipannotation from the node audit, can now be turned on from the cluster create page and the cluster overview, and set in cluster templates.Machine Reset Wipes More Volumes on Talos 1.14
On Talos 1.14 and newer, resetting a machine also wipes the container runtime, kubelet, etcd and log volumes, on top of the state and ephemeral partitions it wiped before. Machines on earlier Talos versions still have only those two wiped.
Search, Filter and Sort Kept in the URL
Search terms, filters and sort order are now part of the URL, so a narrowed-down view survives a reload and can be shared as a link.
Richer Support Bundles
Support bundles now also carry in-flight machine update state and the inputs Omni uses to generate machine configurations.
Talos 1.14 Configuration Support
Talos 1.14 moves cluster identity, certificate authorities, encryption secrets and Talos API access rules out of the single v1alpha1 document into documents of their own, and Omni understands the new layout. Kubernetes component images for upgrades are patched in the shape the cluster's version contract calls for, Kubernetes CA rotation writes the accepted CA wherever the generated configuration keeps it, and the Talos API access restriction follows its own document. The frontend validates patches against the 1.14 schema and generates 1.14 variants of the patches it writes.
Contributors
- Edward Sammut Alessi
- Oguz Kilcan
- Utku Ozdemir
- Mateusz Urbanek
- Maja Bojarska
- Artem Chernyshev
- Andrey Smirnov
- Orzelius
- Noel Georgi
- Justin Garrison
- Mark Glants
- Mickaël Canévet
- Nguyen Duc Quynh
- Olli Hauer
- Rowan Voermans
- Sting Alleman
- Tim Jones
Changes
<details><summary>183 commits</summary> <p>
acc9edb2feat: classify installer exit codes and skip retrying permanent ones18bafff4fix(frontend): adjust toast text for machine removal02bb8277fix(frontend): unselect removed machines in machine listd3419f71test: make the install disk selection test deterministicee6b16d8test: reserve integration test machines against concurrent allocationeb532093feat(frontend): improve legibility for unallocated and user partitions2c4940aefix: drop noisy WireGuard handshake warnings for offline peers89d41856feat: for talos 1.14 machine reset also wipe cri, kubelet, etcd, loge040a4b6fix(frontend): use cluster config version for version contract in scale5d948964fix(frontend): also check version contract in cluster scaledbc458e8feat(frontend): allow $patch: delete in all places0b5cafafchore: bump dependencies9e062ebcfix: forbid cluster CA and service account key in config patches3a4771fafeat: rotate the Kubernetes CA on Talos 1.14 multi-doc configs6d67db2afeat: rework discovery service configuration for Talos 1.141cdfd703fix: track namespaced cluster-scoped manifests as applied7765bab3feat: validate multi-doc config patches2f4f0f38feat(frontend): add talos 1.14 variants for frontend generated patches4dcd206afeat: expose more version contract fields202769d7fix(frontend): use dvh instead of vh for heightd02e7043feat(frontend): add talos 1.14 schema9cad2579chore: bump talos machinery03ad541afix: respect the user's install disk selection in maintenance installsf31cbce0feat(frontend): redesign manifests status to a graph view126b6b72refactor(frontend): refactor kubespan canvas to vue-flow4546b096fix(frontend): trim cluster machine status last_config_error messaged04a0123feat: for kubespan quick start use correct patch for the clusterd34ecf49feat(client): allow disabling the transparent watch retry72b942c3feat: add Auditor role for reading the audit log0a64c818feat: label Talos Enterprise machinesf7329696feat: multiple image factories support7873fda7chore: apply CA, Registry configs before install/upgrade calls53b3c825feat: support enableNodeAuditSkip in cluster templatesb2b2b205fix: verify maintenance install/upgrade against the live machine7bc77666chore: change virtual ImageFactoryAuth resource to be persistent72ffae83fix(frontend): fix incorrect action on patch delete92215fb7fix(frontend): preserve whitespace in alerts4edaf8a4fix: dont include failed/evicted pods for k8s usage dataf5cb97b2fix(frontend): constrain monitor charts to a fixed size regardless of stateb5cff35bfix(frontend): constrain extensions modals to a fixed size6cea6257fix(frontend): dont try load auth0 if we arent using auth0 in userinfobed3482dfix(frontend): don't call machineservice.events for maintenance talos on <1.13582730cechore: bump depsfb2ae3f7fix: allow SAMLLabelRule to downgrade user role to None7b06af51fix: mark machines installed when the lifecycle install completes2557f645chore: rekres73e415bechore(frontend): bump deps87ca0cdffix(frontend): prevent jumping when select up/down arrows disappear071f1b29feat: allow disabling config patches526e1c63feat: support following the audit log over the management APId0824edffix: support the new discovery service endpoints list of Talos 1.1447b66fdffeat: show infra provider versions in ui and clie23a8f7dfeat: do not pre-pull the kube-proxy image on Kubernetes upgradese19f19d1fix: use initial versions from inputedcc2569feat: build version aware Kubernetes component patches for upgradesd0642877feat(frontend): hide pxe boot option for enterprise3187ffadtest: fix Omni upgrade workload proxy DNS4e8cc051fix: ignore not-found errors when deleting an infra provider1476e538chore: bump talos machinery to v1.14.0-alpha.29d4cfa66feat(frontend): dim machine stage status when machine is not healthy89eca085test: run browser e2e tests off the host networkd6bfcee9feat: serve the frontend dev server through the main endpoint66a7ba2ffix: allow removing the bootstrap spec once the cluster is bootstrappedf75c63dbfeat: install same-minor maintenance machines via LifecycleServiceff510298fix: expose the machines cores and virtual state watches metricsdf72b2c3test: use dex oidc instead of auth0 as default for e2e tests7fcee51etest: poll for minio to come up instead of just sleeping54819dfatest(frontend): remove testing of actual iso download110cf83crefactor: proxy frontend dev server routes using prod flowd62f8c86chore(frontend): update factory staging url for dev5a751477feat(frontend): add a /logout route for auth0 logouts9e3f2903fix(frontend): skip 0 length bars in home segmented charts15b1667dfeat(frontend): handle machine services errors gracefullyf161c437refactor(frontend): make watch failed errors more informative7a2477b4fix: update kube-service-exposer to v0.4.0d0d7d76dfeat: introduce the new metric that counts total number of cores53194783feat: use LifecycleService for maintenance machine upgradesdb679539fix: dont clear sa expiration when no keys are left74cb7078fix: correct boot ID and Talos version tracking for maintenance installs3eab1cc1fix(frontend): remove an unused @click actionf3f9cd67refactor(frontend): make all detached scopes lazily loaded2be41995chore(frontend): bump frontend deps000b1620fix: honor current machine set update limits2dfe2e5achore: bump oras-go to 2.6.216265a1afeat(frontend): add word wrap to monaco context menu0a37d509refactor(frontend): don't create new editor and model instance for schema changes80021712chore(frontend): add stories for CodeEditore2f57398fix(frontend): make CodeEditor props reactive561d2582feat: log audit log access in the audit log0fee0fc3fix: properly propagate errors coming from the machine lifecycle APIb5450ebffix: don't treat unset S3 endpoint as an empty overridedaa12686test(frontend): adjust fake-indexeddb usage which broke in node 24.180618b901chore(frontend): bump node to 24.185419d707feat(frontend): show ongoing operations on the home page2afd2223feat(frontend): use segmented bars for home page stats8b637dc8chore(frontend): write stories for home page contentdf33497echore: bump dependenciesa47e7128feat: add machine log ingestion byte-rate metric7bc30eb0chore: rekres and bump Go to 1.26.5e05e3285feat: manage Talos install and upgrade via LifecycleService2ddeca05fix(frontend): remove power icon from machines paged0535adafeat: expose node audit skip cluster feature809baa68feat(frontend): persist search and filters as query stringsee432246refactor(frontend): rename filterLabel to selectLabel in ItemLabelab95b0c3refactor(frontend): refactor LabelsInput to use v-modele6fa2f14refactor(frontend): replace removeLabel prop with remove emit5e9ccbd1refactor(frontend): replace onClear prop with clear emit14ef6113feat: send initial instance user to signup page84f151fefix(frontend): handle aborted requests in useMachineServices7e0cf44cfeat(frontend): add a quickstart page for kubespan8e8a4675feat(frontend): standardize machine display in omni2d561020fix(frontend): prevent item list flash during connection drops655c2ae4refactor(frontend): move itemID into useResourceWatch8373f536refactor(frontend): lift interfaces from watch to composable7fb66d5brefactor(frontend): merge watch items into composable37b19c40refactor(frontend): lift remaining parts of watch class to composable0e7bb6aerefactor(frontend): lift item handlers up to watch composable640014ecrefactor(frontend): inline watch callbacks588d21e2refactor(frontend): remove unnecessary setDescending funcc655f002refactor(frontend): migrate watch tests to useresourcewatch tests4e4cd5f8refactor(frontend): move watch.setup into useresourcewatch81c8c2a4refactor(frontend): merge watchfunc and watch classes together104a8b2afix(frontend): prevent copying double newlines in machine logsc48c9b92refactor(frontend): migrate machine set config edit modal to new modal system2adcefe4refactor(frontend): migrate create extensions modal to new modal systemc435a8f6refactor(frontend): migrate config patch edit modal to new modal systeme7c34066refactor(frontend): migrate save preset modal to new modal systema7762559refactor(frontend): hide primary action when maintenance lifecycle complete971145ccrefactor(frontend): migrate download preset modal to new modal systemf9360c2erefactor(frontend): remove unused machine template extensions modal8ee92b37refactor(frontend): migrate service account renew to new modal system022c458frefactor(frontend): migrate service account create to new modal system7747a322refactor(frontend): migrate role edit to new modal systemfb9d41f1refactor(frontend): migrate user destroy to new modal system384a5347refactor(frontend): migrate user create to new modal systemd6940108refactor(frontend): migrate machine remove to new modal systeme0626db8refactor(frontend): migrate machine class destroy to new modal systemdb554082refactor(frontend): migrate machine set destroy to new modal systeme26d569arefactor(frontend): migrate export cluster template to new modal systemdd5b6255refactor(frontend): migrate config patch destroy to new modal system7f1bf664refactor(frontend): migrate infra provider delete to new modal system9bdbeacerefactor(frontend): migrate infra provider setup to new modal systemb94b299brefactor(frontend): migrate download omnictl to new modal system542124bcrefactor(frontend): migrate node shutdown to new modal systemfe09adc2refactor(frontend): migrate node destroy cancel to new modal systemd1b56338refactor(frontend): migrate node destroy to new modal system02f0d112refactor(frontend): migrate node reboot to new modal system3ddc040etest: fix flaky audit log and service account status testse330092afeat: add pending updates and config gen options to support bundle49c8e725fix: update COSI runtime to fix hanging TeardownAndDestroy callsc91ce1a5fix: align config outdated status in ui and clifde089bbrefactor(frontend): refactor untaint single node modal to new system094b2591feat(frontend): add content-class support to confirm modald193dce9chore: expose user roles in the public package to be used by scripts33aa3fa2refactor(frontend): replace ua-parser-js with bowser6b2da674chore(frontend): drop yaml dependency and move openpgp to dependencies27c6aa07chore: rekres for js sbomed793b6bfeat(frontend): add filtering to scan details modal6ef286f2feat(frontend): add a cluster security page for vulns99a76d47refactor(frontend): extract components from scan details modal034640bbrefactor(frontend): extract business logic from scan details modal2cf7801drefactor(frontend): make use resource list default to empty array120563a3feat(frontend): stack CPU usage chart areas and format with %77dcbe90chore: add stories for monitor viewae93d3f9fix(frontend): only show process args in command columne690d624fix(frontend): allow in-minor patch upgrades in update kubernetes on Omnib30472e6refactor: use ImageServiceClient for pulling images1c20cc94chore: bump helm to v4 in zstd-dict5f4f27dffix: recover a machine from a reverted reboot-requiring config patcheadd5b57fix(frontend): allow force-destroy when MachineSetNode is already gonefd4e5da4test(frontend): fix some flaky tests in e2e-talemu1882db15feat: install/upgrade maintenance-mode Talos during cluster create/scale-up84180bd0fix: advertise reachable machine API address in cluster-import test937ce3a6fix: keep maintenance Talos clients until machine leaves maintenancea7b87871refactor: derive extension list from the raw schematic manifest961a20c6fix: move timeout for factory requests to controllerse63d4e45test: drop non-existent preset delete error expectation6f26c409chore: enrich SBOM with Go module licenses1b337b24fix: tolerate NotFound on installation media preset deletec2533013test: stabilize image-factory schematic across CI runs984ba009feat(frontend): add more visual distinction for offline kubespan peers51cc468dfix: prevent removal of node unique tokens that still have a link88c77c61fix: validate infra provider name as DNS-1123 label </p> </details>
Changes from siderolabs/discovery-service
<details><summary>13 commits</summary> <p>
f03ed02release(v1.1.0): prepare release373430afeat(stats): add cached /stats endpoint0dc4741chore: bump prometheus, grpc, and otel deps1479df2chore: bump net to v0.57.0709d4b9chore: bump net pkg to v0.55.0 (security)0ce4779chore: bump sync pkg to v0.22.09628da0chore: update go.mod deps99b6268chore: rekres48cf9dfchore: bump go to latest 1.26d315a3fchore: fmtf905881chore: rekres73b90dffeat: add support for x-forwaded-for header35804dachore: bump dependencies </p> </details>
Changes from siderolabs/gen
<details><summary>1 commit</summary> <p>
c526410fix: skip unknown-key check for types with custom YAML unmarshaler </p> </details>
Changes from siderolabs/go-kubernetes
<details><summary>3 commits</summary> <p>
0caf1f2feat: add Kubernetes 1.37 compatibility822b7a2feat: add nodedrain package for client-side cordon and drain260bc0afix: update authorization config apiVersion for K8s >= 1.32 </p> </details>
Changes from siderolabs/image-factory
<details><summary>21 commits</summary> <p>
efab38frelease(v1.4.0): prepare release9c64235feat: add schematic owner validationca87d23fix: add single-flight around schematic factoryd45b5acdocs: link to Image Factory Enterprise docs page490a993chore: bump pkgs revision to match talos v1.14.0-alpha.2f9ff935chore: bump go pkgs12cd647feat: add llms.txt for better LLM usagef65960ffix: audit file defaultsf26e5e2feat: add audit log for authenticated requestsbeff6e2feat: support registry namespace prefix for core artifacts8c489d0chore: update dependencies026f8a8feat: extra extensions (enterprise only)915ef76chore: add insecure flag to dev config3bccbe1fix: handle single arch images6b1c855refactor: prepare for more than one artifact registrybee4fe3feat: narrow sbom cache key to extension list onlye0e4a44refactor: abstract versioned cache3359f6cfeat: add secureboot enrollKeys schematic option805c51cfeat: add per-request correlation ID to logs8cee96dfeat: assert pxe cache in tests4ec0789feat: bump go-conainerregistry </p> </details>
Dependency Changes
- github.com/auth0/go-jwt-middleware/v3 v3.2.0 -> v3.3.0
- github.com/aws/aws-sdk-go-v2 v1.42.0 -> v1.43.2
- github.com/aws/aws-sdk-go-v2/config v1.32.25 -> v1.32.33
- github.com/aws/aws-sdk-go-v2/credentials v1.19.24 -> v1.19.32
- github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager v0.3.7 new
- github.com/aws/aws-sdk-go-v2/service/s3 v1.104.0 -> v1.106.2
- github.com/aws/smithy-go v1.27.2 -> v1.27.6
- github.com/coreos/go-oidc/v3 v3.19.0 -> v3.20.0
- github.com/cosi-project/runtime v1.16.1 -> v1.16.2
- github.com/fluxcd/cli-utils v1.2.1 -> v1.2.2
- github.com/fluxcd/pkg/ssa v0.76.0 -> v0.77.0
- github.com/go-logr/logr v1.4.3 -> v1.4.4
- github.com/google/go-containerregistry v0.21.7 -> v0.21.8
- github.com/johannesboyne/gofakes3 4c385a1f6a73 -> v1.2.0
- github.com/mattn/go-shellwords v1.0.13 -> v1.0.14
- github.com/prometheus/client_golang v1.23.2 -> v1.24.1
- github.com/prometheus/common v0.69.0 -> v0.70.1
- github.com/siderolabs/discovery-service v1.0.17 -> v1.1.0
- github.com/siderolabs/gen v0.8.6 -> v0.8.7
- github.com/siderolabs/go-kubernetes v0.2.39 -> v0.2.41
- github.com/siderolabs/image-factory v1.3.3 -> v1.4.0
- github.com/siderolabs/omni/client v1.8.1 -> v1.9.3
- github.com/siderolabs/talos/pkg/machinery v1.14.0-alpha.1 -> v1.14.0-beta.1
- github.com/zitadel/oidc/v3 v3.47.5 -> v3.48.1
- go.etcd.io/bbolt v1.4.3 -> v1.5.0
- go.etcd.io/etcd/client/pkg/v3 v3.6.12 -> v3.7.1
- go.etcd.io/etcd/client/v3 v3.6.12 -> v3.7.1
- go.etcd.io/etcd/pkg/v3 v3.7.1 new
- go.etcd.io/etcd/server/v3 v3.6.12 -> v3.7.1
- go.yaml.in/yaml/v4 v4.0.0-rc.4 -> v4.0.0-rc.6
- golang.org/x/crypto v0.53.0 -> v0.54.0
- golang.org/x/net v0.56.0 -> v0.57.0
- golang.org/x/sync v0.21.0 -> v0.22.0
- golang.org/x/text v0.38.0 -> v0.40.0
- golang.org/x/tools v0.46.0 -> v0.48.0
- google.golang.org/grpc v1.81.1 -> v1.83.0
- k8s.io/api v0.36.2 -> v0.36.3
- k8s.io/apimachinery v0.36.2 -> v0.36.3
- k8s.io/client-go v0.36.2 -> v0.36.3
Previous release can be found at v1.9.0
-
v1.9.316 Jul 2026Nothing published for this version
-
v1.9.216 Jul 2026Nothing published for this version
-
v1.9.102 Jul 2026Nothing published for this version
-
v1.9.025 Jun 2026Nothing published for this version
-
v1.9.0-beta.1.0.20260729155718-f31cbce0032c29 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260729124326-d04a012309e529 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260729115545-d34ecf49816b29 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260728221112-0a64c818501528 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260727121546-7873fda7aa9e27 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260724185746-53b3c825c48124 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260724093126-72ffae83171b24 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260723121807-582730ce940c23 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260721120301-47b66fdf394a21 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260721112609-e23a8f7d71d121 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260720124257-edcc256921e820 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260717141052-1476e5389b4d17 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260717132753-9d4cfa66606e17 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260717115409-89eca085d39917 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260716153611-ff510298b80b16 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260716104655-9e3f2903006316 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260715163052-d0d7d76db5c615 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260702125353-104a8b2abe5a02 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260701150613-e330092a2c7301 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260701144727-49c8e725f6a101 Jul 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260626130436-5f4f27df331526 Jun 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.1.0.20260625231033-84180bd0fd7f25 Jun 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.123 Jun 2026 pre-releaseRelease notes
Open source →Welcome to the v1.9.0-beta.1 release of Omni!
This is a pre-release of OmniPlease try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
Cluster Health Check Jobs
Cluster templates now support health check jobs that gate Talos upgrades. Omni creates the jobs when a Talos upgrade is running and re-runs them on an interval until they succeed, re-creating a job whenever it fails. The checks run before each node upgrade in the upgrade status controller, and if any defined health check fails Omni drops the available upgrade quota to zero, blocking further upgrades until the checks pass. You can read more about this feature on the docs.
Embedded Machine Config for Installation Media
Installation media can now carry an embedded machine configuration, so a machine applies it on first boot before it ever reaches Omni. You can set it from the frontend or with
omnictlwhen creating installation media, and Omni stores it on the schematic request alongside the rest of the media config. The option is exposed only where the underlying stack reports support for it, through a newsupports_embedded_configquirk.Per-Class etcd Write Rate Limiting
You can now throttle etcd writes by payload size, with separate budgets for end users, infra providers, and internal callers. It is off by default and turns on via
storage.rateLimits.etcd.*. Four new Prometheus series report throttle wait time, admitted writes, rejected writes, and rejected bytes, labeled by class. The failure counters also carry a reason of timeout or oversize.Talos Extension Names Validated Against the Catalog
Extension names on installation media configs, machine request sets, and extensions configurations are now validated against the Talos extensions catalog for the relevant Talos version. Unknown names, duplicates, and oversized lists are rejected, and when no Talos version is set the default version's catalog is used so the names still get checked. Names without a namespace are looked up under
siderolabs/, so older clients that send the documented short form keep working. Theomnictl installation media createcommand now resolves short or partial extension names to canonical form before sending, replacing the client-side catalog check it used to do.KubeSpan Status View
A new graphical view shows KubeSpan peer status for a cluster machine.
Frontend Quality-of-Life Improvements
A round of UI improvements across Omni. The home screen has a reworked "Welcome to Omni" card. An unhealthy infrastructure provider shows its error on hover, the machine details panel shows the SMBIOS serial number, and kernel args editing moved into a modal. Config diffs have a sort-order toggle, version pickers sort newest first and scroll to the current selection, and Talos and Kubernetes update calls now report their errors. The disks view got several cleanups, pods sort by status, power-state icons have tooltips, Omni shows a loading indicator when it is slow to start, and the rewritten log viewer scrolls to the bottom reliably. Machine patches no longer offer the cluster-machine patch option and surface an error when a machine is not part of a cluster.
Static loadBalancerIP for the WireGuard Service in Helm
The Helm chart has a new
service.wireguard.loadBalancerIPvalue for setting a static load balancer IP on the WireGuard Kubernetes Service. It is rendered only when the WireGuard service type isLoadBalancer.Support for Image Factory Enterprise
Two new config options,
registries.imageFactoryUsernameandregistries.imageFactoryPassword, let Omni authenticate to the Image Factory Enterprise with HTTP basic auth.Kubernetes Manifests Status in the UI
The frontend now shows the status of a cluster's synced Kubernetes manifests.
Per-Machine Log Ingestion Rate Limit
Log ingestion now uses a per-machine token bucket, so one noisy machine can no longer overwhelm the log store. It is off by default to keep backwards compatibility.
Machine Config Patches in Maintenance Mode
Omni can now apply machine-level config patches while a machine is still in maintenance mode, not just after it joins a cluster. The patches go on top of the configuration the machine already runs, next to the SideroLink documents Omni manages, and Omni will not apply a document that installs Talos and pulls the machine out of maintenance. Omni also keeps whatever configuration a machine connects with as a low-priority, user-owned patch. So a machine that arrives with its own config (say a TrustedRootsConfig document) keeps it, and your own patches still win.
Install and Upgrade Talos in Maintenance Mode
A new streaming management API installs or upgrades Talos on machines booted in maintenance mode. It comes with
omnictlinstall and upgrade subcommands and frontend modals that stream installer progress live. This feature uses Talos's LifecycleService API, which became available in v1.13.0. So it works with any Talos version starting from v1.13.0.SBOM, VEX, and Vulnerability Scan on the Installation Media Wizard
The installation media wizard's confirmation page now shows SBOM and VEX links plus the vulnerability scan and modal, the same as the Image Factory. This shows up only when you use the Image Factory Enterprise.
Opt-In Skip of Kubernetes Node Audit
The Kubernetes node audit deletes nodes that no ClusterMachine backs. You can now skip it for individual nodes, which helps with virtual nodes such as VirtualKubelet. A node is skipped only when it has the
omni.sidero.dev/node-audit-skipannotation and the cluster owner has turned on the matching cluster feature, so a workload cannot annotate its own way out of the audit.Node Names and Locked Status in
omnictl cluster statusThe
omnictl cluster statustree now prints each machine's Kubernetes node name in parentheses after its UUID, so you can match a machine to the upgrade status lines that reference node names. A "Locked" indicator shows up whenever a machine is locked.Platform Tags Exposed as Machine Labels
Talos PlatformMetadata tags (for example EC2 instance tags) now appear as editable, removable machine labels in Omni. Omni fills them in once, when the machine first joins, and your own custom labels win on any key conflict.
Schematic Contents Preserved on Update
When Omni changes a machine's schematic, it now touches only the fields it manages (extensions and kernel args) and leaves the rest alone, instead of rebuilding the schematic from scratch. It reads the full schematic from the machine or the Image Factory and stores it as is.
Signed Images and SBOM Release Artifacts
Omni releases now ship an SBOM built from the Go modules as a release artifact, and Sidero Labs signs the published container images during release.
Talos Upgrade Targets Capped at the Latest Supported Release
Each Omni release now declares the latest Talos minor version it can support end to end. Cluster create and update, the maintenance upgrade API, the upgrade status computation, and every version picker in the UI all read this same cap, so you can no longer pick a Talos version newer than the running Omni supports.
Contributors
- Edward Sammut Alessi
- Utku Ozdemir
- Mateusz Urbanek
- Oguz Kilcan
- Artem Chernyshev
- Maja Bojarska
- Noel Georgi
- Andrey Smirnov
- Orzelius
- 0hlov3
- Bo Bobson
- Matthew Sanabria
- Sterling Koch
- Steve Francis
- fsgh42
Changes
<details><summary>118 commits</summary> <p>
f472356d7release(v1.9.0-beta.1): prepare release8bea9d98dfeat(frontend): add expandable code editor for extra overlay options4121e730ffeat(frontend): add expandable code editor for embedded machine config22318022dfeat(frontend): add more default editor options and remove default class00e99c4d5refactor(frontend): refactor code editor to use v-model454daba78chore: bump default talos version to 1.13.5cb74aa700feat: support embedded machine config in installation media CLI86af10d45fix: get rid of the race in the UUID conflict resolution flow55bda4979refactor: only log schematic id when ensuringc2b067a1ffeat(frontend): allow specifying embedded machine config for installation media574daf6d5feat: add embedded_machine_config to create schematic request1a8c85b88feat: add embedded_machine_config to installation media config spec687e56ae1feat: add supports_embedded_config quirk to virtual resources2fa8855c6feat: validate Talos extensions against the catalog807fe47a7feat: register destroy controllers for user-managed resource typesc3c511acbchore: bump containerd to 1.7.33af44779aechore(frontend): bump dependencies17b2b30ecfix: prevent API requests from hanging after idle periods240c48323feat(frontend): remove cluster machine patch option from machine patches498e8c0b4feat(frontend): show error if machine not part of clustera66f1ae3afeat(frontend): use machine status link snapshot for recent machines phase0f853e1bbrelease(v1.9.0-beta.0): prepare release060a4c759chore: bump deps and default versions43bf5856etest: run integration-qemu against the image factory enterprise4b49029cbfeat: support machine config patches in maintenance modeb9e407174fix: stabilize flaky talemu e2e EULA setup and preset downloads448ed9a69docs: update LICENSEb44f92efefix: ignore the embedded-config meta extensione32307d8efix: allow empty list of extensions in cluster templatesb08c34ac8feat: implement advanced healthchecks for the cluster1c125d3f4chore: add Oguz to sops-encrypted secrets recipients9a736342dfix: properly handle invalid UTF-8 strings in the machine statusesd77ee0495fix: properly handle empty provider data in the common modulec55173efcfeat: validate Talos version on installation media config243f046e0fix(frontend): display correct units for byte valuesd9eebd7c4fix(frontend): reset monitor chart on watch change7f02f41f3chore(frontend): bump frontend dependencies27ef3dd03feat: install/upgrade Talos in maintenance mode18131edfdfeat(frontend): change machine tutorial into a welcome card4fdc07191feat(frontend): adjust action buttons on getting started card987b3ec18feat: reject control characters in join token names8bfc6c17dfix(frontend): fix incorrect pxe boot urlead9840b7feat: validate user-supplied request IDs and kernel args1ebde6a44feat: validate bootstrap snapshot path on machine sets1ff045796feat: allow opt-in skip of Kubernetes node audit50dcd264cfeat: validate resource metadata at the state layer086a1964cfeat: preserve schematic contents1ab0c4e32feat(frontend): display infrastructure provider error when unhealthy5c67c7c9bfix: read machine uncached when deciding whether to reset it098dac2c3refactor: remove unused fields, fix print columns/comments of resourcesa29fba498fix: use correct help string in theomnictl jointoken deletecommand9505aabecfeat(frontend): add kubespan status viewd19768879refactor: replace injectable clocks with real timeb5be9a779fix: prune expired public keys with finalizers or no owner64b02f4f6feat: cap Talos upgrade targets at the latest supported releasea1367d90efeat: per-machine log ingestion rate limitbc0e5273brefactor: move state validations into their own package33909b1b9fix: keep exposed services reachable after a health check flap84649427bfeat(helm): support loadBalancerIP for WireGuard service4db447046fix: release config update slot while a machine waits to upgradee63ea1f0efeat: add PostHog analytics to the Omni frontend5b5203660chore: bump major go dependencies48a7f9394fix: persist config status when update lock is contended59d9079c7refactor(frontend): remove last cases of any in codebase665371f3arefactor: drop unused field in create schematic gRPC requestc2f52d799fix: prevent deadlock between machine upgrade and config update861594332feat: nest omnictl, talosctl, scans under apif144020c0feat(frontend): show vulnerability items on installation media wizard68afcd086chore: rekresb3e038f8dfeat(frontend): generate talos types for frontend0610a4088refactor(frontend): type tlist items4afaf514brefactor(frontend): drop watchjoin998e803ecchore: bump go-kubernetes libraryccbc50bdafeat(omnictl): show node name and locked status in cluster status3edf383b6chore: bump deps, rekres, Talos 1.13.3, Kubernetes 1.36.1429708f84feat(frontend): show join tokens in saved presets listc857af939feat(frontend): enable field-sizing content for kernel argsf62e044aafeat(frontend): show errors for all update talos/k8s issues7ddd63b1afeat(frontend): sort upgrade modal versions descending and scroll to selectedffcbf3342refactor(frontend): refactor update talos + k8s to new modals9248b762btest: mock clock in saml testd18726e9cfix: lower minimum discovered Kubernetes version2dd7c8807test: pick previous Omni upgrade version from the release line2bfe8c08achore: rekres and bump frontend deps3b9399fbafix: do not downgrade nodes header to single node15ad495adtest: bump Talos to 1.13.325f5de5c6feat(frontend): allow changing config diff sort order0f060a449feat(frontend): add improvements to disks viewe297c4d47fix: hack/compose dlv tools install1704f0047chore(hack): add delve debugger support30d5d2868test: use up-to-date way to set node labels on the nodes in the tests72dfce9e5fix(frontend): remove lingering test code028a57e84feat(frontend): move editing logic for kernel args into a modal76ee6332ffeat(frontend): add tooltips to power state329922816feat: refactor logviewer to tanstack virtual1fafd3781chore: bump dependencies988bc9e81chore: add missing syft version to kres065db6960test(integration): bump readiness timeout durationsfc362b5fcfeat: expose ec2 tags as machine labels6d61a546efeat: add sign-images target to sign omni container image34473a7f5feat: generate SBOM as a release artifactfa2f11fc0fix: fetch versions from registry with auth0a2641c6cchore: bump deps to patch GO-2026-5027ddfa70a9cfeat: add per-class etcd write-bytes rate limiting69e4fe255feat(frontend): add some feedback when omni is loading5246ba332fix: ensure infra providers with new common module support the old Omni9ae983308feat(frontend): sort pods by status on pods listc8daa7805fix(frontend): fix incorrect permissions-policy header7484972dffeat(frontend): load robot fonts from npmbb442ab7efeat: add teardown RPCs and tighten state API accessc1126b471chore: fix linter issues120be2f10chore: rekres to secure slack workflows686249525fix: dont clean clients with active watches679ca3014feat: support basic auth against the image factory2ce7140ecfeat: introduce UI for showing Kubernetes manifests status of clustersc990a0820feat(frontend): change service finished state style to gray1b9177ee8feat(frontend): show smbios serial info on machine details panel9dd6cb490refactor: drop compose 'version' (from hack) </p> </details>
Changes since v1.9.0-beta.0
<details><summary>21 commits</summary> <p>
f472356drelease(v1.9.0-beta.1): prepare release8bea9d98feat(frontend): add expandable code editor for extra overlay options4121e730feat(frontend): add expandable code editor for embedded machine config22318022feat(frontend): add more default editor options and remove default class00e99c4drefactor(frontend): refactor code editor to use v-model454daba7chore: bump default talos version to 1.13.5cb74aa70feat: support embedded machine config in installation media CLI86af10d4fix: get rid of the race in the UUID conflict resolution flow55bda497refactor: only log schematic id when ensuringc2b067a1feat(frontend): allow specifying embedded machine config for installation media574daf6dfeat: add embedded_machine_config to create schematic request1a8c85b8feat: add embedded_machine_config to installation media config spec687e56aefeat: add supports_embedded_config quirk to virtual resources2fa8855cfeat: validate Talos extensions against the catalog807fe47afeat: register destroy controllers for user-managed resource typesc3c511acchore: bump containerd to 1.7.33af44779achore(frontend): bump dependencies17b2b30efix: prevent API requests from hanging after idle periods240c4832feat(frontend): remove cluster machine patch option from machine patches498e8c0bfeat(frontend): show error if machine not part of clustera66f1ae3feat(frontend): use machine status link snapshot for recent machines phase </p> </details>
Changes from siderolabs/go-api-signature
<details><summary>1 commit</summary> <p>
07009e7chore: bump deps, update gopenpgp to v3 </p> </details>
Changes from siderolabs/go-kubernetes
<details><summary>2 commits</summary> <p>
cc8c2c9fix: return the apply results in a consistent order131a2bdfix: handle cluster-scoped resources with a ns correctly </p> </details>
Changes from siderolabs/go-talos-support
<details><summary>2 commits</summary> <p>
59d47affeat: rewrite support bundle library around client provider8dd4326feat: support encryption of the support bundle using age </p> </details>
Changes from siderolabs/image-factory
<details><summary>26 commits</summary> <p>
425e59erelease(v1.3.3): prepare releaseb5d3d92fix: vulnerability scans with extensions916bcf6feat: update go-vex9920386feat: update Image Factory with Talos 1.14.0-alpha.1d49e952feat: allow excluding Talos releases147a3e8feat: add scan report to factory client2887e78feat: add support for embedding machine configuration660ac01release(v1.3.2): prepare release38183fcfix: update golang.org/x/net9f6aee8fix: make PXE copyable on SecureBootd7377c5refactor: migrate to Tailwind CSS classes1e86750fix: update golang.org/x/* packages33c79e4test: move from kuttl to chainsawba34dabfeat: move SPDX cache to enterprise optionscd137edchore: disable authentication for local development4ea792ffix: build profile with versionfcf9d57release(v1.3.1): prepare release1d216c7docs: update the developing documentation4a60270fix(config): validate early and sort SPDX deterministically41d3947release(v1.3.0): prepare releaseae3ed04feat: add enterprise features with Helm chart support3fb0f96feat(enterprise): add vulnerability scanning endpoint92209b6feat: return normalized schematic on creationba2a46dfeat(enterprise): implement VEX endpoint9b40156feat: show schematic-id url parameter on the final wizard step114bb60fix(spdx): use configured external URL in document namespace </p> </details>
Dependency Changes
- github.com/ProtonMail/go-crypto v1.4.1 new
- github.com/ProtonMail/gopenpgp/v3 v3.4.1 new
- github.com/auth0/go-jwt-middleware/v3 v3.2.0 new
- github.com/aws/aws-sdk-go-v2 v1.41.7 -> v1.42.0
- github.com/aws/aws-sdk-go-v2/config v1.32.17 -> v1.32.25
- github.com/aws/aws-sdk-go-v2/credentials v1.19.16 -> v1.19.24
- github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.22.18 -> v1.22.28
- github.com/aws/aws-sdk-go-v2/service/s3 v1.101.0 -> v1.104.0
- github.com/aws/smithy-go v1.25.1 -> v1.27.2
- github.com/coreos/go-oidc/v3 v3.18.0 -> v3.19.0
- github.com/cosi-project/runtime v1.16.0 -> v1.16.1
- github.com/cosi-project/state-etcd v0.6.0 -> v0.7.0
- github.com/felixge/httpsnoop v1.0.4 -> v1.1.0
- github.com/fluxcd/cli-utils v1.2.0 -> v1.2.1
- github.com/fluxcd/pkg/ssa v0.74.0 -> v0.76.0
- github.com/golang-jwt/jwt/v5 v5.3.1 new
- github.com/google/go-containerregistry v0.21.5 -> v0.21.7
- github.com/grpc-ecosystem/go-grpc-middleware/v2 v2.3.3 new
- github.com/prometheus/client_model v0.6.2 new
- github.com/prometheus/common v0.67.5 -> v0.69.0
- github.com/russellhaering/goxmldsig v1.6.0 new
- github.com/siderolabs/go-api-signature v0.3.12 -> v0.3.13
- github.com/siderolabs/go-kubernetes v0.2.37 -> v0.2.39
- github.com/siderolabs/go-talos-support v0.2.1 -> v0.3.0
- github.com/siderolabs/image-factory v1.2.0 -> v1.3.3
- github.com/siderolabs/omni/client v1.6.5 -> v1.8.1
- github.com/siderolabs/talos/pkg/machinery v1.13.2 -> v1.14.0-alpha.1
- github.com/stripe/stripe-go/v85 v85.1.0 -> v85.2.0
- go.etcd.io/etcd/client/pkg/v3 v3.6.11 -> v3.6.12
- go.etcd.io/etcd/client/v3 v3.6.11 -> v3.6.12
- go.etcd.io/etcd/server/v3 v3.6.11 -> v3.6.12
- golang.org/x/crypto v0.51.0 -> v0.53.0
- golang.org/x/net v0.54.0 -> v0.56.0
- golang.org/x/sync v0.20.0 -> v0.21.0
- golang.org/x/text v0.37.0 -> v0.38.0
- golang.org/x/tools v0.45.0 -> v0.46.0
- golang.zx2c4.com/wireguard f333402bd9cb -> ecfc5a8d5446
- google.golang.org/grpc v1.81.0 -> v1.81.1
- k8s.io/api v0.36.0 -> v0.36.2
- k8s.io/apimachinery v0.36.0 -> v0.36.2
- k8s.io/client-go v0.36.0 -> v0.36.2
- sigs.k8s.io/controller-runtime v0.24.0 -> v0.24.1
Previous release can be found at v1.8.0
-
v1.9.0-beta.0.0.20260619212954-17b2b30ecb9019 Jun 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.0.0.20260619161350-498e8c0b421719 Jun 2026 pre-releaseNothing published for this version
-
v1.9.0-beta.019 Jun 2026 pre-releaseRelease notes
Open source →Welcome to the v1.9.0-beta.0 release of Omni!
This is a pre-release of OmniPlease try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
Per-Class etcd Write Rate Limiting
You can now throttle etcd writes by payload size, with separate budgets for end users, infra providers, and internal callers. It is off by default and turns on via
storage.rateLimits.etcd.*. Four new Prometheus series report throttle wait time, admitted writes, rejected writes, and rejected bytes, labeled by class. The failure counters also carry a reason of timeout or oversize.KubeSpan Status View
A new graphical view shows KubeSpan peer status for a cluster machine.
Frontend Quality-of-Life Improvements
A round of UI improvements across Omni. The home screen has a reworked "Welcome to Omni" card. An unhealthy infrastructure provider shows its error on hover, the machine details panel shows the SMBIOS serial number, and kernel args editing moved into a modal. Config diffs have a sort-order toggle, version pickers sort newest first and scroll to the current selection, and Talos and Kubernetes update calls now report their errors. The disks view got several cleanups, pods sort by status, power-state icons have tooltips, Omni shows a loading indicator when it is slow to start, and the rewritten log viewer scrolls to the bottom reliably.
Static loadBalancerIP for the WireGuard Service in Helm
The Helm chart has a new
service.wireguard.loadBalancerIPvalue for setting a static load balancer IP on the WireGuard Kubernetes Service. It is rendered only when the WireGuard service type isLoadBalancer.Support for Image Factory Enterprise
Two new config options,
registries.imageFactoryUsernameandregistries.imageFactoryPassword, let Omni authenticate to the Image Factory Enterprise with HTTP basic auth.Kubernetes Manifests Status in the UI
The frontend now shows the status of a cluster's synced Kubernetes manifests.
Per-Machine Log Ingestion Rate Limit
Log ingestion now uses a per-machine token bucket, so one noisy machine can no longer overwhelm the log store. It is off by default to keep backwards compatibility.
Machine Config Patches in Maintenance Mode
Omni can now apply machine-level config patches while a machine is still in maintenance mode, not just after it joins a cluster. The patches go on top of the configuration the machine already runs, next to the SideroLink documents Omni manages, and Omni will not apply a document that installs Talos and pulls the machine out of maintenance. Omni also keeps whatever configuration a machine connects with as a low-priority, user-owned patch. So a machine that arrives with its own config (say a TrustedRootsConfig document) keeps it, and your own patches still win.
Install and Upgrade Talos in Maintenance Mode
A new streaming management API installs or upgrades Talos on machines booted in maintenance mode. It comes with
omnictlinstall and upgrade subcommands and frontend modals that stream installer progress live. This feature uses Talos's LifecycleService API, which became available in v1.13.0. So it works with any Talos version starting from v1.13.0.SBOM, VEX, and Vulnerability Scan on the Installation Media Wizard
The installation media wizard's confirmation page now shows SBOM and VEX links plus the vulnerability scan and modal, the same as the Image Factory. This shows up only when you use the Image Factory Enterprise.
Opt-In Skip of Kubernetes Node Audit
The Kubernetes node audit deletes nodes that no ClusterMachine backs. You can now skip it for individual nodes, which helps with virtual nodes such as VirtualKubelet. A node is skipped only when it has the
omni.sidero.dev/node-audit-skipannotation and the cluster owner has turned on the matching cluster feature, so a workload cannot annotate its own way out of the audit.Node Names and Locked Status in
omnictl cluster statusThe
omnictl cluster statustree now prints each machine's Kubernetes node name in parentheses after its UUID, so you can match a machine to the upgrade status lines that reference node names. A "Locked" indicator shows up whenever a machine is locked.Platform Tags Exposed as Machine Labels
Talos PlatformMetadata tags (for example EC2 instance tags) now appear as editable, removable machine labels in Omni. Omni fills them in once, when the machine first joins, and your own custom labels win on any key conflict.
Schematic Contents Preserved on Update
When Omni changes a machine's schematic, it now touches only the fields it manages (extensions and kernel args) and leaves the rest alone, instead of rebuilding the schematic from scratch. It reads the full schematic from the machine or the Image Factory and stores it as is.
Signed Images and SBOM Release Artifacts
Omni releases now ship an SBOM built from the Go modules as a release artifact, and Sidero Labs signs the published container images during release.
Talos Upgrade Targets Capped at the Latest Supported Release
Each Omni release now declares the latest Talos minor version it can support end to end. Cluster create and update, the maintenance upgrade API, the upgrade status computation, and every version picker in the UI all read this same cap, so you can no longer pick a Talos version newer than the running Omni supports.
Contributors
- Edward Sammut Alessi
- Utku Ozdemir
- Mateusz Urbanek
- Oguz Kilcan
- Artem Chernyshev
- Maja Bojarska
- Noel Georgi
- Andrey Smirnov
- Orzelius
- 0hlov3
- Bo Bobson
- Matthew Sanabria
- Sterling Koch
- Steve Francis
- fsgh42
Changes
<details><summary>96 commits</summary> <p>
060a4c759chore: bump deps and default versions43bf5856etest: run integration-qemu against the image factory enterprise4b49029cbfeat: support machine config patches in maintenance modeb9e407174fix: stabilize flaky talemu e2e EULA setup and preset downloads448ed9a69docs: update LICENSEb44f92efefix: ignore the embedded-config meta extensione32307d8efix: allow empty list of extensions in cluster templatesb08c34ac8feat: implement advanced healthchecks for the cluster1c125d3f4chore: add Oguz to sops-encrypted secrets recipients9a736342dfix: properly handle invalid UTF-8 strings in the machine statusesd77ee0495fix: properly handle empty provider data in the common modulec55173efcfeat: validate Talos version on installation media config243f046e0fix(frontend): display correct units for byte valuesd9eebd7c4fix(frontend): reset monitor chart on watch change7f02f41f3chore(frontend): bump frontend dependencies27ef3dd03feat: install/upgrade Talos in maintenance mode18131edfdfeat(frontend): change machine tutorial into a welcome card4fdc07191feat(frontend): adjust action buttons on getting started card987b3ec18feat: reject control characters in join token names8bfc6c17dfix(frontend): fix incorrect pxe boot urlead9840b7feat: validate user-supplied request IDs and kernel args1ebde6a44feat: validate bootstrap snapshot path on machine sets1ff045796feat: allow opt-in skip of Kubernetes node audit50dcd264cfeat: validate resource metadata at the state layer086a1964cfeat: preserve schematic contents1ab0c4e32feat(frontend): display infrastructure provider error when unhealthy5c67c7c9bfix: read machine uncached when deciding whether to reset it098dac2c3refactor: remove unused fields, fix print columns/comments of resourcesa29fba498fix: use correct help string in theomnictl jointoken deletecommand9505aabecfeat(frontend): add kubespan status viewd19768879refactor: replace injectable clocks with real timeb5be9a779fix: prune expired public keys with finalizers or no owner64b02f4f6feat: cap Talos upgrade targets at the latest supported releasea1367d90efeat: per-machine log ingestion rate limitbc0e5273brefactor: move state validations into their own package33909b1b9fix: keep exposed services reachable after a health check flap84649427bfeat(helm): support loadBalancerIP for WireGuard service4db447046fix: release config update slot while a machine waits to upgradee63ea1f0efeat: add PostHog analytics to the Omni frontend5b5203660chore: bump major go dependencies48a7f9394fix: persist config status when update lock is contended59d9079c7refactor(frontend): remove last cases of any in codebase665371f3arefactor: drop unused field in create schematic gRPC requestc2f52d799fix: prevent deadlock between machine upgrade and config update861594332feat: nest omnictl, talosctl, scans under apif144020c0feat(frontend): show vulnerability items on installation media wizard68afcd086chore: rekresb3e038f8dfeat(frontend): generate talos types for frontend0610a4088refactor(frontend): type tlist items4afaf514brefactor(frontend): drop watchjoin998e803ecchore: bump go-kubernetes libraryccbc50bdafeat(omnictl): show node name and locked status in cluster status3edf383b6chore: bump deps, rekres, Talos 1.13.3, Kubernetes 1.36.1429708f84feat(frontend): show join tokens in saved presets listc857af939feat(frontend): enable field-sizing content for kernel argsf62e044aafeat(frontend): show errors for all update talos/k8s issues7ddd63b1afeat(frontend): sort upgrade modal versions descending and scroll to selectedffcbf3342refactor(frontend): refactor update talos + k8s to new modals9248b762btest: mock clock in saml testd18726e9cfix: lower minimum discovered Kubernetes version2dd7c8807test: pick previous Omni upgrade version from the release line2bfe8c08achore: rekres and bump frontend deps3b9399fbafix: do not downgrade nodes header to single node15ad495adtest: bump Talos to 1.13.325f5de5c6feat(frontend): allow changing config diff sort order0f060a449feat(frontend): add improvements to disks viewe297c4d47fix: hack/compose dlv tools install1704f0047chore(hack): add delve debugger support30d5d2868test: use up-to-date way to set node labels on the nodes in the tests72dfce9e5fix(frontend): remove lingering test code028a57e84feat(frontend): move editing logic for kernel args into a modal76ee6332ffeat(frontend): add tooltips to power state329922816feat: refactor logviewer to tanstack virtual1fafd3781chore: bump dependencies988bc9e81chore: add missing syft version to kres065db6960test(integration): bump readiness timeout durationsfc362b5fcfeat: expose ec2 tags as machine labels6d61a546efeat: add sign-images target to sign omni container image34473a7f5feat: generate SBOM as a release artifactfa2f11fc0fix: fetch versions from registry with auth0a2641c6cchore: bump deps to patch GO-2026-5027ddfa70a9cfeat: add per-class etcd write-bytes rate limiting69e4fe255feat(frontend): add some feedback when omni is loading5246ba332fix: ensure infra providers with new common module support the old Omni9ae983308feat(frontend): sort pods by status on pods listc8daa7805fix(frontend): fix incorrect permissions-policy header7484972dffeat(frontend): load robot fonts from npmbb442ab7efeat: add teardown RPCs and tighten state API accessc1126b471chore: fix linter issues120be2f10chore: rekres to secure slack workflows686249525fix: dont clean clients with active watches679ca3014feat: support basic auth against the image factory2ce7140ecfeat: introduce UI for showing Kubernetes manifests status of clustersc990a0820feat(frontend): change service finished state style to gray1b9177ee8feat(frontend): show smbios serial info on machine details panel9dd6cb490refactor: drop compose 'version' (from hack) </p> </details>
Changes from siderolabs/go-api-signature
<details><summary>1 commit</summary> <p>
07009e7chore: bump deps, update gopenpgp to v3 </p> </details>
Changes from siderolabs/go-kubernetes
<details><summary>2 commits</summary> <p>
cc8c2c9fix: return the apply results in a consistent order131a2bdfix: handle cluster-scoped resources with a ns correctly </p> </details>
Changes from siderolabs/go-talos-support
<details><summary>2 commits</summary> <p>
59d47affeat: rewrite support bundle library around client provider8dd4326feat: support encryption of the support bundle using age </p> </details>
Changes from siderolabs/image-factory
<details><summary>26 commits</summary> <p>
425e59erelease(v1.3.3): prepare releaseb5d3d92fix: vulnerability scans with extensions916bcf6feat: update go-vex9920386feat: update Image Factory with Talos 1.14.0-alpha.1d49e952feat: allow excluding Talos releases147a3e8feat: add scan report to factory client2887e78feat: add support for embedding machine configuration660ac01release(v1.3.2): prepare release38183fcfix: update golang.org/x/net9f6aee8fix: make PXE copyable on SecureBootd7377c5refactor: migrate to Tailwind CSS classes1e86750fix: update golang.org/x/* packages33c79e4test: move from kuttl to chainsawba34dabfeat: move SPDX cache to enterprise optionscd137edchore: disable authentication for local development4ea792ffix: build profile with versionfcf9d57release(v1.3.1): prepare release1d216c7docs: update the developing documentation4a60270fix(config): validate early and sort SPDX deterministically41d3947release(v1.3.0): prepare releaseae3ed04feat: add enterprise features with Helm chart support3fb0f96feat(enterprise): add vulnerability scanning endpoint92209b6feat: return normalized schematic on creationba2a46dfeat(enterprise): implement VEX endpoint9b40156feat: show schematic-id url parameter on the final wizard step114bb60fix(spdx): use configured external URL in document namespace </p> </details>
Dependency Changes
- github.com/ProtonMail/go-crypto v1.4.1 new
- github.com/ProtonMail/gopenpgp/v3 v3.4.1 new
- github.com/auth0/go-jwt-middleware/v3 v3.2.0 new
- github.com/aws/aws-sdk-go-v2 v1.41.7 -> v1.42.0
- github.com/aws/aws-sdk-go-v2/config v1.32.17 -> v1.32.25
- github.com/aws/aws-sdk-go-v2/credentials v1.19.16 -> v1.19.24
- github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.22.18 -> v1.22.28
- github.com/aws/aws-sdk-go-v2/service/s3 v1.101.0 -> v1.104.0
- github.com/aws/smithy-go v1.25.1 -> v1.27.2
- github.com/coreos/go-oidc/v3 v3.18.0 -> v3.19.0
- github.com/cosi-project/runtime v1.16.0 -> v1.16.1
- github.com/cosi-project/state-etcd v0.6.0 -> v0.7.0
- github.com/felixge/httpsnoop v1.0.4 -> v1.1.0
- github.com/fluxcd/cli-utils v1.2.0 -> v1.2.1
- github.com/fluxcd/pkg/ssa v0.74.0 -> v0.76.0
- github.com/golang-jwt/jwt/v5 v5.3.1 new
- github.com/google/go-containerregistry v0.21.5 -> v0.21.7
- github.com/grpc-ecosystem/go-grpc-middleware/v2 v2.3.3 new
- github.com/prometheus/client_model v0.6.2 new
- github.com/prometheus/common v0.67.5 -> v0.69.0
- github.com/russellhaering/goxmldsig v1.6.0 new
- github.com/siderolabs/go-api-signature v0.3.12 -> v0.3.13
- github.com/siderolabs/go-kubernetes v0.2.37 -> v0.2.39
- github.com/siderolabs/go-talos-support v0.2.1 -> v0.3.0
- github.com/siderolabs/image-factory v1.2.0 -> v1.3.3
- github.com/siderolabs/omni/client v1.6.5 -> v1.8.1
- github.com/siderolabs/talos/pkg/machinery v1.13.2 -> v1.14.0-alpha.1
- github.com/stripe/stripe-go/v85 v85.1.0 -> v85.2.0
- go.etcd.io/etcd/client/pkg/v3 v3.6.11 -> v3.6.12
- go.etcd.io/etcd/client/v3 v3.6.11 -> v3.6.12
- go.etcd.io/etcd/server/v3 v3.6.11 -> v3.6.12
- golang.org/x/crypto v0.51.0 -> v0.53.0
- golang.org/x/net v0.54.0 -> v0.56.0
- golang.org/x/sync v0.20.0 -> v0.21.0
- golang.org/x/text v0.37.0 -> v0.38.0
- golang.org/x/tools v0.45.0 -> v0.46.0
- golang.zx2c4.com/wireguard f333402bd9cb -> ecfc5a8d5446
- google.golang.org/grpc v1.81.0 -> v1.81.1
- k8s.io/api v0.36.0 -> v0.36.2
- k8s.io/apimachinery v0.36.0 -> v0.36.2
- k8s.io/client-go v0.36.0 -> v0.36.2
- sigs.k8s.io/controller-runtime v0.24.0 -> v0.24.1
Previous release can be found at v1.8.0
-
v1.8.205 Jun 2026Nothing published for this version
-
v1.8.129 May 2026Nothing published for this version
-
v1.8.021 May 2026Nothing published for this version
-
v1.8.0-beta.1.0.20260616181556-d77ee049529916 Jun 2026 pre-releaseNothing published for this version
-
v1.8.0-beta.1.0.20260605102248-4db44704692105 Jun 2026 pre-releaseNothing published for this version
-
v1.8.0-beta.1.0.20260529113325-2bfe8c08a1cf29 May 2026 pre-releaseNothing published for this version
-
v1.8.0-beta.1.0.20260526080537-fa2f11fc0a6426 May 2026 pre-releaseNothing published for this version
-
v1.8.0-beta.1.0.20260521103036-9ae98330814321 May 2026 pre-releaseNothing published for this version
-
v1.8.0-beta.1.0.20260521094219-c8daa7805fc321 May 2026 pre-releaseNothing published for this version
-
v1.8.0-beta.118 May 2026 pre-releaseRelease notes
Open source →Welcome to the v1.8.0-beta.1 release of Omni!
This is a pre-release of OmniPlease try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
Urgent Upgrade Notes (No, really, you MUST read this before you upgrade)
As Omni is now using
--join-tokens-mode=legacyAllowedby default it won't start if there are any nodes running Talos below 1.6 connected to the instance. If you want to keep using Omni with the outdated Talos you will need to set the flag tolegacy. But of course we strongly recommend you to update Talos ASAP.omnictl cluster templatehas breaking changes: it now restricts including files outside of the current directory. If using files in the parent dirs, old behavior can be enabled by using--allowed-dir.Additional Audit Log Filters
Audit logs gain a generic search box and sortable columns in the UI, plus CLI filters for
event_type,resource_type,resource_id,cluster_id, andactor.Per-Actor etcd Write Metrics
New
omni_etcd_operations_totalandomni_etcd_resource_bytes_totalPrometheus counters track etcd writes, split by operation (create/update/teardown/destroy), actor (internal/user/service account/infra provider), actor ID, and resource type. Byte sizes are captured from the actual on-disk payload via a newWithObserverhook instate-etcd.Disks and Devices on Machine Pages
The frontend now shows disks and devices on the machines and individual machine pages.
Talos Version Text on Installation Media Wizard
The installation media wizard's Talos version text has been updated for clarity.
Switching Logs Inside the Logs Tab
The logs tab now allows switching between log sources directly inside the tab.
Quick Switching Between Cluster Machines
The frontend allows quickly switching between machines within a cluster from the machine detail view.
In-UI Notifications
Omni notifications are now shown in the UI as dismissible banners.
Frontend Quality-of-Life Improvements for Machines
The cluster machine page gains a copy-UUID button, the machines list page can toggle between hostnames and UUIDs (with the preference saved), and machine and cluster machine pages gain kernel args tabs for editing kernel arguments inline instead of through a modal.
Re-Saving the Omni Support Bundle
The frontend now allows re-saving a previously generated Omni support bundle without regenerating it.
Support Modal
A new support modal in the frontend exposes links to GitHub issues, support channels, documentation, community resources, and office hours.
Helm Chart Values Generated From Config Schema
A new
helmvaluesgentool, run onmake generate, updates theconfig:section of the Helm chart'svalues.yamlfrom Omni's config schema, applying chart-specific overrides for defaults, omissions, and descriptions.Legacy Installation Media Proxying Removed
Omni no longer proxies legacy installation media download requests to the Talos Image Factory. Such requests are now rejected with a message asking users to upgrade
omnictl, which downloads installation media directly from the factory.Image Factory Proxy for Infra Providers
Infra provider Image Factory requests can now be proxied through Omni via a new schematic creation API that accepts raw YAML. This is useful when Omni holds authentication for the Image Factory or when multiple Image Factory endpoints need to be supported.
Imported Cluster Secrets Cleanup
A new controller tears down
ImportedClusterSecretsonce their content has been copied intoClusterSecretsand markedImported=true, so imported bootstrap material does not linger in the state after a successful import.Infra Provider Factory Endpoint
Infra providers now use the Image Factory endpoint configured in Omni's features state (sourced from args/config) instead of a hardcoded default. The configured factory URL is exposed on the provider.
Installation Media Placeholders
InstallationMediaConfig now accepts empty strings for
talosVersionandjoinToken, which resolve to the current stable version and default token at download time. The create wizard exposes "Automatic" options for these fields, and the download modal shows version/token/arch pickers for all presets.Reader Access to Join Tokens
Users with the reader role can now read join tokens. Reader had access to it before through Talos logs, so making the access more consistent. More fine grained access will come with RBAC v2 later on.
Multi-Port Workload Proxy
The
omni-kube-service-exposer.sidero.dev/portannotation now accepts a comma-separated list ofhost-portorhost-port:service-portentries, each producing its own ExposedService URL. Label, icon, and prefix annotations gain per-host-port suffixed variants (e.g.label-30080). Existing single-port exposed services keep their URLs across the upgrade.Configurable Log Level and Format
Omni's log level and log format are now configurable via flags and config.
Provision Step Errors on Machine Requests
A new
Errorfield onClusterMachineRequestStatussurfaces provision step failures so users can see why a request is stuck without scraping logs. Errors are now persisted on both failure and requeue paths.omnictl mediaCommand GroupA new
omnictl media preset {create,list,delete}command group manages InstallationMediaConfig presets from the CLI, andomnictl media download <preset>downloads from them. Preset validation runs against the server's CloudPlatformConfig, SBCConfig, and TalosExtensions resources at create time. The legacyomnictl downloadis preserved but deprecated.Plain Download Links for Images
The frontend now uses plain browser download links for factory image downloads instead of intercepting them.
Powered Off Machine State
Machines that are shut down now appear as "Powered Off" in the UI instead of being stuck in "Shutting Down" with a greyed-out unreachable state. Static infra providers honor the shutdown until the machine goes through a deallocation cycle, instead of automatically powering it back on. The CLI gains
omnictl machine shutdownandomnictl machine power-oncommands.Per-Key Creation and Last-Active Tracking for Service Accounts
Service account key listings now include per-key creation timestamps and last-active times.
omnictl serviceaccount listshowsKEY CREATEDandKEY LAST ACTIVEcolumns alongside the existing SA-levelLAST ACTIVE. A newPublicKeyLastActiveresource backs this tracking, and the activity interceptor records last-used timestamps per signing key fingerprint.Commented
omnictl serviceaccount createOutputThe output of
omnictl serviceaccount createis now commented out by default, making it friendlier for piping into.envfiles and shell automation.Talos Version End-of-Support Notifications
Omni now tracks machines running Talos versions approaching or past end of support relative to
MinTalosVersion, emits two new notifications (approaching end of support, end of support reached), and exposes Prometheus metrics for both.Download
talosctlFrom Factorytalosctlbinaries are now downloaded directly from the Talos Image Factory instead of GitHub.Cluster Template Include Directory Restrictions
By default, cluster templates can only include files from the same directory as the template file. This prevents malicious templates from including arbitrary files like
/etc/passwd. The previous behavior can be restored with--allowed-dir.Raw Bytes Support in Template Inline Fields
Inline fields for manifests and config patches now accept three forms: a single inline map (for backward compatibility), a list of inline maps, or raw bytes (which may contain multiple YAML documents).
omnictl cluster template exportnow exports patches and manifests as raw bytes so multi-document values round-trip correctly.Template Includes Resolved Relative to Template File
omnictl cluster templatecommands now resolve patch and Kubernetes manifest includes relative to the template YAML file, rather than the current working directory ofomnictl.Contributors
- Edward Sammut Alessi
- Utku Ozdemir
- Artem Chernyshev
- Oguz Kilcan
- Andrey Smirnov
- Noel Georgi
- Mateusz Urbanek
- Justin Garrison
- Maja Bojarska
- Orzelius
- Quentin Joly
- Spencer Smith
Changes
<details><summary>81 commits</summary> <p>
b5e5e86erefactor: update minio env names5a894a21chore: update helm README with new install instructions4fe2a67fchore: rekres, bump deps and default versions6fab9972release(v1.8.0-beta.0): prepare releaseac81e59ffeat: collectClusterKubernetesManifestStatusin the support bundles64a1d536fix: wrong role promotion for some etcd APIs7cc7e181test: fix workload proxy integration test for upgrade scenario2c8b1789feat: add per-actor etcd write metrics49322f05feat: use plain download links for image downloads01742e71feat: add log level and format configuration7fb5b164chore: bump depscab06214feat(frontend): allow switching logs inside logs tabc890ececrefactor(frontend): move node logs logic into machinelogscontainer75cdb09frefactor(frontend): extra machine service list into a composable9f1bb2fadocs: add COSI resource operations in API usage examples13c3f289fix: add more input validations to management APIced79da6fix: consume SAML sessions once7b72ac64chore(frontend): bump dependenciesed7738b3fix: do not panic is ssa apply with multi-version CRDse08e566dfeat: destroy imported cluster secrets after bundle is consumedd01a6f66fix(frontend): keep machine details open when switching25fa9e14fix: change ImportedClusterSecrets access level to operator39ee2f01feat: proxy image factory requests done by the providers through Omnie7aee25ctest(frontend): add e2e tests for join tokens in frontende6be461cfix(frontend): add apexcharts formatter workaroundba6205f5fix(frontend): fix apexcharts broken tooltips and initial stateaddf6624feat: add omnictl media command group with preset support110be565feat: expose provision step errors on machine request status699ebf70fix(frontend): fix revoking/deleting join tokens1f4f2afafeat: allow exposing a Kubernetes service on multiple host ports75e881fcfeat: resolve patches/kubernetes manifests relative to the templates dire9b71f0bfix(frontend): only show machine patches for currently visible machinea524554cfix(frontend): fix editing labels on machine classc14ee101refactor(frontend): refactor all but the last tlist use of watch.setup56cce45echore(frontend): bump node to 24.15.07989c3c0test: fix data race in machine service mockc141613dfix: fix the storm ofPendingUpdateStatuscreate/destroya43407d0feat: generate config section of helm chart values from config schema0cdb5a58feat: support raw bytes in the inline fields for manifests/patches14b83e12feat: set infra provider factory endpoint to the one configured in omniefbd089ffeat(frontend): add qol machine updates to omni frontend2fe716d2chore: enable go linting for build tags, fix linting errors718d61a6chore(frontend): bump dependenciesd3592671feat: download talosctl directly from factoryb2671d08refactor(frontend): create downloadfile helperdc9baca8refactor(frontend): refactor downloadtalosctl modal to new modal system06d8140dfeat: add join token/talos version placeholders in installation media5f4b9761fix: bring back election campaign resign code in the etcd state03c4e1d9fix: stop logging Kubernetes read checksdc3b974dfix: remove workload proxy deployment when disabled on the account65af568bfix: skip allocating nodes for deleted/tearing downMachineRequestsf9dd8491feat: introduce powered off machine state and power on support921389a5fix(frontend): fix eula handling to prevent being stuck on /eula725f41d4fix: properly display service account expiration time in the UIc5a43105feat(frontend): add support modal to omni66383890feat(frontend): show disks and devices in machines/machine page1e31079efix(frontend): fix indeterminate state for update extensions modal6d7e4f45feat(frontend): allow quickly switching between cluster machinesc98b1187fix(frontend): clear page state when keys are clearedf89955b4refactor(frontend): remove last use of <watch> componentbe67f710feat: allow reader access to join tokenf2211688chore: bump deps475e3660feat: add Talos version end-of-support notifications and metrics302e9175feat: comment serviceaccount create output967c229echore: rekres to update to new kres schemaedbb621achore: bump stripe-go to v85cc0adefcfix(frontend): select default join token in installation media wizard0987fa9echore: prepare omni with talos v1.13.0-rc73a06f89chore: bump talos machinery78544a85feat: restrict directories for included files in the cluster templatesa3fd0b1cfeat(frontend): allow re-saving omni support bundle5c4a6b57feat: remove image factory proxyingdc5e289cfeat(frontend): show notifications in the frontend9fd6e9e1fix(frontend): open external eula link in a new tab8c23f72echore: bump deps2e9d00a6chore: make Omni use join tokens modelegacyAllowedby default488b020bfeat: add more filters to audit logs590ea2e3feat: add per-key creation and last-active tracking for service accounts44b0d636chore: bump deps186f02b4chore(frontend): bump frontend dependencies57216254feat(frontend): update talos version text on installation media wizard </p> </details>
Changes since v1.8.0-beta.0
<details><summary>3 commits</summary> <p>
b5e5e86erefactor: update minio env names5a894a21chore: update helm README with new install instructions4fe2a67fchore: rekres, bump deps and default versions </p> </details>
Changes from siderolabs/go-kubernetes
<details><summary>2 commits</summary> <p>
38c182ffix: normalize the changeset to be keyed without apiVersionca35008feat: update k8s api to 0.36.0 </p> </details>
Changes from siderolabs/image-factory
<details><summary>22 commits</summary> <p>
ccffefcrelease(v1.2.0): prepare release4abeff4feat: add /talosctl/:version endpoint to list downloadable talosctls405b488feat(i18n): add french localec6ad082feat(registry): resolve latest tag to stable version471706dchore: drop update to talos main tests403cd5afix: centralize schematic ownership enforcementf1cceeefeat: implement authentication support81f9312release(v1.1.0): prepare release1b834b7feat: add SHA-256 and SHA-512 checksum frontende775c36feat: upgrade tailwind to v4bb27d39feat: update Talos to v1.13.0-rc.02a59890fix: gsa signer pull during verifyfbc302ffix: support insecure registries for signature bundles8e7d10efeat: add support for google service account signing74afd80fix: set correct Content-Type when downloading images8372fe8feat: add SPDX frontendb379bf2feat: switch schematic cache to LRU and negative TTL0450038chore: remove deuplicate k8s-down ci step470cb2fchore: switch to large runners713fc6efix: memory usage when building images0a25274fix: excessive memory usage0f9eb22feat: update machinery doc links </p> </details>
Dependency Changes
- github.com/aws/aws-sdk-go-v2 v1.41.5 -> v1.41.7
- github.com/aws/aws-sdk-go-v2/config v1.32.14 -> v1.32.17
- github.com/aws/aws-sdk-go-v2/credentials v1.19.14 -> v1.19.16
- github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.22.12 -> v1.22.18
- github.com/aws/aws-sdk-go-v2/service/s3 v1.98.0 -> v1.101.0
- github.com/aws/smithy-go v1.24.3 -> v1.25.1
- github.com/coreos/go-oidc/v3 v3.17.0 -> v3.18.0
- github.com/cosi-project/runtime v1.14.1 -> v1.16.0
- github.com/cosi-project/state-etcd v0.5.3 -> v0.6.0
- github.com/fluxcd/cli-utils v0.37.2-flux.1 -> v1.2.0
- github.com/fluxcd/pkg/ssa v0.70.0 -> v0.74.0
- github.com/fsnotify/fsnotify v1.9.0 -> v1.10.1
- github.com/google/go-containerregistry v0.21.4 -> v0.21.5
- github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 -> v2.29.0
- github.com/mattn/go-shellwords v1.0.12 -> v1.0.13
- github.com/siderolabs/go-kubernetes v0.2.36 -> v0.2.37
- github.com/siderolabs/image-factory v1.0.3 -> v1.2.0
- github.com/siderolabs/omni/client v1.6.1 -> v1.6.5
- github.com/siderolabs/talos/pkg/machinery v1.13.0-rc.0 -> v1.13.2
- github.com/stripe/stripe-go/v85 v85.1.0 new
- github.com/zitadel/oidc/v3 v3.46.0 -> v3.47.5
- go.etcd.io/etcd/client/pkg/v3 v3.6.10 -> v3.6.11
- go.etcd.io/etcd/client/v3 v3.6.10 -> v3.6.11
- go.etcd.io/etcd/server/v3 v3.6.10 -> v3.6.11
- go.uber.org/zap v1.27.1 -> v1.28.0
- golang.org/x/crypto v0.49.0 -> v0.51.0
- golang.org/x/net v0.52.0 -> v0.54.0
- golang.org/x/text v0.35.0 -> v0.37.0
- golang.org/x/tools v0.43.0 -> v0.45.0
- google.golang.org/grpc v1.80.0 -> v1.81.0
- k8s.io/api v0.35.3 -> v0.36.0
- k8s.io/apimachinery v0.35.3 -> v0.36.0
- k8s.io/client-go v0.35.3 -> v0.36.0
- sigs.k8s.io/controller-runtime v0.23.3 -> v0.24.0
Previous release can be found at v1.7.0