NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1414 by repository stars
Last release today
07 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Rarely documented
notes for 13 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
643 releases · first in 2024
42a6dd708 feat: allow upgrading one deprecated Talos to another one in maintenance
Welcome to the v1.12.4 release of Omni!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.
The local resource service, which served Omni resources on a local listener, is removed. Consumers should reach Omni through its regular API with a service account instead. Its services.localResourceService settings and flags have no effect.
f9d1743a5 release(v1.12.4): prepare releasea1265ba7a fix: return only the unauthenticated error for an unsigned request69c79f273 fix: redact config secrets and clear the stored OIDC client secret3b0446c85 fix: forward only known headers to the Kubernetes apiserver4dfee714f fix: remove conflicting join token renew alias6eddd8c08 fix: require a confirmed key for workload proxy access18ac5ee9d fix: make a resource's cluster label agree with its target3b2a95383 fix: extract the cluster ID from label query terms correctly42a6dd708 feat: allow upgrading one deprecated Talos to another one in maintenance999446893 fix: do not allocate machines with outdated schematics into a cluster3526d6614 fix: reject unknown Talos versions on the talosctl downloads endpoint7d5c9bf5c feat: remove the local resource service33d8d5b7e fix: resolve node headers only for the runtime that uses themd9e69d606 fix: read local resource server stream metadata from its own contextdcfa43a27 fix: verify the caller before reporting a resolution failure29958ee1a fix: check access before rejecting a request that names several nodese38d71c06 fix: record the outcome of Talos access in the audit log6f7d8c83e fix: parse the role of a public key request before any lookup2982aa994 fix: return only the access error for a denied requestfcf4c8568 fix: return the same error for a missing and an inaccessible target668469919 chore: bump otel libraries to close a vuln47322b255 fix(frontend): add v prefix to installer image tagThis release has no dependency changes
Previous release can be found at v1.12.3
One column per month.
Welcome to the v1.12.3 release of Omni!
Welcome to the v1.12.3 release of Omni!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.
74b0bd683 release(v1.12.3): prepare release78d0cc7a1 fix(frontend): make some style fixes on cluster list9d7af1d54 feat(frontend): add a resource browser to the UIa9a16e0c9 fix(frontend): check kubespanlink instead of kubespanconfigaa217700e feat(frontend): add enterprise labels to maintenance modalsThis release has no dependency changes
Previous release can be found at v1.12.2
Welcome to the v1.12.2 release of Omni!
Welcome to the v1.12.2 release of Omni!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.
020bfffc1 release(v1.12.2): prepare release26fdb97e5 fix: keep the cached Talos clients alive while they are in usec7f88c92a fix: reject unknown omnictl config contexts318674380 fix: do not report k8s manifests as deleting when Omni does not own them607d07bb4 fix(frontend): show enterprise label for cluster on overview259aa95ce fix: forbid changing roles to or from InfraProvider5678d3a89 fix: honor context override in omnictl config infoThis release has no dependency changes
Previous release can be found at v1.12.1
Welcome to the v1.12.2 release of Omni!
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
<details><summary>6 commits</summary> <p>
26fdb97e fix: keep the cached Talos clients alive while they are in usec7f88c92 fix: reject unknown omnictl config contexts31867438 fix: do not report k8s manifests as deleting when Omni does not own them607d07bb fix(frontend): show enterprise label for cluster on overview259aa95c fix: forbid changing roles to or from InfraProvider5678d3a8 fix: honor context override in omnictl config info
</p>
</details>This release has no dependency changes
Previous release can be found at v1.12.1
Welcome to the v1.12.1 release of Omni!
Welcome to the v1.12.1 release of Omni!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.
97e51eafd release(v1.12.1): prepare release60deeecce test: drop MinIO usage in the tests663e550b7 feat(frontend): show a message that cluster security UI requires enterprisea0e2c0e84 feat(frontend): add enterprise label to cluster overviewd3c2eb3db feat: copy enterprise label to more resources62ac3b806 feat(frontend): handle not found scan reports in ui5a2a27e06 fix: allow image removal API6fb7e330d fix(frontend): make security docs link _blankddddf4729 feat(frontend): group talos versions by minor0b9eef767 feat(frontend): add enterprise label to talos select listsdfa4b52ee refactor(frontend): extract all select components into individual files87c525a61 refactor(frontend): create a singular talos version select component0270ead84 fix: remove incomplete installation media downloadsed531d7fd refactor: normalize factory urls at input onlyb35962912 feat(frontend): add loading state for image download links17086d6f9 fix: keep the untouched machines out of a canceled Talos upgradeThis release has no dependency changes
Previous release can be found at v1.12.0
scan : the vulnerability scan report.
Welcome to the v1.12.0 release of Omni!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.
Omni can now authenticate to the image factory with an API token. The token is read from a file, so it can be rotated without a restart. Basic auth is still supported for self-hosted factories using htpasswd.
For such a factory, Omni creates a machine token and puts it into the registry auth config of every machine, so that the machines can pull images from the factory.
The token file is configured under registries.factories.<primary|secondary> in the config file:
registries:
factories:
primary:
url: https://factory.example.com
tokenFile: /run/secrets/factory-tokenThe equivalent flags are --primary-factory-token-file and --secondary-factory-token-file.
The new omnictl security command fetches the security artifacts of a Talos schematic from the enterprise image factory:
scan: the vulnerability scan report.sbom: the SPDX SBOM.vex: the VEX document.It takes either a cluster ID, covering every schematic and architecture the cluster runs, or an explicit combination of Talos version, architecture and schematic. The scan output also shows the available Talos upgrade paths and the vulnerability diff for each of them.
These artifacts are only available on the enterprise image factory, so the command requires Omni to be configured with one.
cd616f1cd release(v1.12.0): prepare release6192a1450 feat: add security scans to omnictl6cdda713c fix: revert stabilizing the tunnel peer address across provisionsc4a37d55e test: run the enterprise image factory tests against the staging factoryc832a504f feat: make the lifetime of the image factory machine tokens configurable70814f39c refactor(frontend): make frontend obtain artifact targets from backendd525fda6c feat: implement ClusterArtifactTargets rpc callccc80d254 feat: add ClusterArtifactTargets rpc methodaf65853e0 release(v1.12.0-beta.0): prepare release723666686 fix: restore the extra parameters of the sqlite connection string08695407d fix: read the node unique token uncached in the cleanup controller9ddfa5246 feat: authenticate to the image factory with an API token800bcac19 test: use ECDSA service account keys for the clusters in the testscd8598724 fix: generate the registry auth document by the running Talos versionacc0c4f40 chore: bump delve version in compose6692b2c0b fix: ensure the schematic on the target factory before an install8c7699a77 fix: run the sqlite database with the NORMAL synchronous moded8a281c42 chore(frontend): bump deps49861a25e fix: reuse the node unique token already written to the machine74003273c chore: bump deps, rekres, Talos 1.13.100a6d296fd test: poll for Vault readiness instead of sleeping in the testsd411b2554 test: increase the timeout of the node label check46e112ac4 chore(frontend): remove factory urls from csp8cbf034be fix: keep the machine extensions consistent across extensions configurations0a22ac7af fix(frontend): distinguish initial log fetch failures4c833c7e1 fix: apply the registry mirrors to machines in maintenance modeedcad2769 fix: retry the installer image pull in the maintenance lifecycle API
cd616f1cd release(v1.12.0): prepare release6192a1450 feat: add security scans to omnictl6cdda713c fix: revert stabilizing the tunnel peer address across provisionsc4a37d55e test: run the enterprise image factory tests against the staging factoryc832a504f feat: make the lifetime of the image factory machine tokens configurable70814f39c refactor(frontend): make frontend obtain artifact targets from backendd525fda6c feat: implement ClusterArtifactTargets rpc callccc80d254 feat: add ClusterArtifactTargets rpc method
44d6398 feat: support Go 1.27
4520b38 fix(enterprise): evaluate VEX against Talos kernela27dfe6 feat: enforce public API with OpenAPI773ba3c fix(ui): gate token create modal on the in-flight POST2e149c8 fix(auth0): drop Bearer challenge from 401 response9f82dde fix: rename registryClientRefreshInterval to refreshIntervalf4f79db feat(enterprise): repo-per-org token storage, url-safe stored tokensf4e4d01 feat(enterprise): expose actor profiles for token creation UI8a77753 feat(enterprise): replace scope enum with route-defined capability scopes4d9710f feat(enterprise): add CLI-only admin token scope4286666 feat(enterprise): unify download and node tokens as scoped API tokens4becd5d release(v1.6.1): prepare releasee5ff748 fix: pull in Talos for the SBC/GRUB/EFI fixPrevious release can be found at v1.11.0
Welcome to the v1.12.0 release of Omni!
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
Omni can now authenticate to the image factory with an API token. The token is read from a file, so it can be rotated without a restart. Basic auth is still supported for self-hosted factories using htpasswd.
For such a factory, Omni creates a machine token and puts it into the registry auth config of every machine, so that the machines can pull images from the factory.
The token file is configured under registries.factories.<primary|secondary> in the config file:
registries:
factories:
primary:
url: https://factory.example.com
tokenFile: /run/secrets/factory-token
The equivalent flags are --primary-factory-token-file and --secondary-factory-token-file.
The new omnictl security command fetches the security artifacts of a Talos schematic from the enterprise image factory:
scan: the vulnerability scan report.sbom: the SPDX SBOM.vex: the VEX document.It takes either a cluster ID, covering every schematic and architecture the cluster runs, or an explicit combination of Talos version, architecture and schematic. The scan output also shows the available Talos upgrade paths and the vulnerability diff for each of them.
These artifacts are only available on the enterprise image factory, so the command requires Omni to be configured with one.
<details><summary>26 commits</summary> <p>
6192a145 feat: add security scans to omnictl6cdda713 fix: revert stabilizing the tunnel peer address across provisionsc4a37d55 test: run the enterprise image factory tests against the staging factoryc832a504 feat: make the lifetime of the image factory machine tokens configurable70814f39 refactor(frontend): make frontend obtain artifact targets from backendd525fda6 feat: implement ClusterArtifactTargets rpc callccc80d25 feat: add ClusterArtifactTargets rpc methodaf65853e release(v1.12.0-beta.0): prepare release72366668 fix: restore the extra parameters of the sqlite connection string08695407 fix: read the node unique token uncached in the cleanup controller9ddfa524 feat: authenticate to the image factory with an API token800bcac1 test: use ECDSA service account keys for the clusters in the testscd859872 fix: generate the registry auth document by the running Talos versionacc0c4f4 chore: bump delve version in compose6692b2c0 fix: ensure the schematic on the target factory before an install8c7699a7 fix: run the sqlite database with the NORMAL synchronous moded8a281c4 chore(frontend): bump deps49861a25 fix: reuse the node unique token already written to the machine74003273 chore: bump deps, rekres, Talos 1.13.100a6d296f test: poll for Vault readiness instead of sleeping in the testsd411b255 test: increase the timeout of the node label check46e112ac chore(frontend): remove factory urls from csp8cbf034b fix: keep the machine extensions consistent across extensions configurations0a22ac7a fix(frontend): distinguish initial log fetch failures4c833c7e fix: apply the registry mirrors to machines in maintenance modeedcad276 fix: retry the installer image pull in the maintenance lifecycle API
</p>
</details><details><summary>7 commits</summary> <p>
6192a145 feat: add security scans to omnictl6cdda713 fix: revert stabilizing the tunnel peer address across provisionsc4a37d55 test: run the enterprise image factory tests against the staging factoryc832a504 feat: make the lifetime of the image factory machine tokens configurable70814f39 refactor(frontend): make frontend obtain artifact targets from backendd525fda6 feat: implement ClusterArtifactTargets rpc callccc80d25 feat: add ClusterArtifactTargets rpc method
</p>
</details><details><summary>2 commits</summary> <p>
865fb4f release(v1.1.1): prepare release270f977 feat: rekres and update dependencies
</p>
</details><details><summary>1 commit</summary> <p>
44d6398 feat: support Go 1.27
</p>
</details><details><summary>12 commits</summary> <p>
4520b38 fix(enterprise): evaluate VEX against Talos kernela27dfe6 feat: enforce public API with OpenAPI773ba3c fix(ui): gate token create modal on the in-flight POST2e149c8 fix(auth0): drop Bearer challenge from 401 response9f82dde fix: rename registryClientRefreshInterval to refreshIntervalf4f79db feat(enterprise): repo-per-org token storage, url-safe stored tokensf4e4d01 feat(enterprise): expose actor profiles for token creation UI8a77753 feat(enterprise): replace scope enum with route-defined capability scopes4d9710f feat(enterprise): add CLI-only admin token scope4286666 feat(enterprise): unify download and node tokens as scoped API tokens4becd5d release(v1.6.1): prepare releasee5ff748 fix: pull in Talos for the SBC/GRUB/EFI fix
</p>
</details>Previous release can be found at v1.11.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Omni can now authenticate to the image factory with an API token instead of the deprecated download and node tokens. Configure it with registries.fact…
Welcome to the v1.12.0-beta.0 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.
Omni can now authenticate to the image factory with an API token instead of the deprecated download and node tokens. Configure it with registries.factories.<primary|secondary>.tokenFile (or --primary-factory-token-file), pointing to a file containing the token; Omni watches the file and picks up rotations without a restart. Basic auth is still supported for self-hosted factories using htpasswd.
af65853e0 release(v1.12.0-beta.0): prepare release723666686 fix: restore the extra parameters of the sqlite connection string08695407d fix: read the node unique token uncached in the cleanup controller9ddfa5246 feat: authenticate to the image factory with an API token800bcac19 test: use ECDSA service account keys for the clusters in the testscd8598724 fix: generate the registry auth document by the running Talos versionacc0c4f40 chore: bump delve version in compose6692b2c0b fix: ensure the schematic on the target factory before an install8c7699a77 fix: run the sqlite database with the NORMAL synchronous moded8a281c42 chore(frontend): bump deps49861a25e fix: reuse the node unique token already written to the machine74003273c chore: bump deps, rekres, Talos 1.13.100a6d296fd test: poll for Vault readiness instead of sleeping in the testsd411b2554 test: increase the timeout of the node label check46e112ac4 chore(frontend): remove factory urls from csp8cbf034be fix: keep the machine extensions consistent across extensions configurations0a22ac7af fix(frontend): distinguish initial log fetch failures4c833c7e1 fix: apply the registry mirrors to machines in maintenance modeedcad2769 fix: retry the installer image pull in the maintenance lifecycle API
44d6398 feat: support Go 1.27
4520b38 fix(enterprise): evaluate VEX against Talos kernela27dfe6 feat: enforce public API with OpenAPI773ba3c fix(ui): gate token create modal on the in-flight POST2e149c8 fix(auth0): drop Bearer challenge from 401 response9f82dde fix: rename registryClientRefreshInterval to refreshIntervalf4f79db feat(enterprise): repo-per-org token storage, url-safe stored tokensf4e4d01 feat(enterprise): expose actor profiles for token creation UI8a77753 feat(enterprise): replace scope enum with route-defined capability scopes4d9710f feat(enterprise): add CLI-only admin token scope4286666 feat(enterprise): unify download and node tokens as scoped API tokens4becd5d release(v1.6.1): prepare releasee5ff748 fix: pull in Talos for the SBC/GRUB/EFI fixPrevious release can be found at v1.11.0
bcf658e7f refactor(frontend): drop deprecated getcontext
Welcome to the v1.11.0 release of Omni!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.
The backend API version is bumped, so omnictl and Omni must be upgraded together. omnictl 1.10 fails against Omni 1.11 (and vice versa) with:
client API version mismatch: backend API version 3, client API version 2
In CI and other automation, download omnictl from Omni itself to always get a matching version, e.g., https://<omni-url>/api/omnictl/omnictl-linux-amd64.
Align the UI features on the Cluster scale and Cluster create pages. Support searching by labels on Cluster scaling/create pages.
The install disk is no more set by a config patch. It is now managed by the MachineInstallDiskConfig resource, for all Talos versions.
machine.install.disk are rejected.install.diskSelector field, e.g., disk.serial == "S3EVNX0K123456".Admins can now list the keys that sign Kubernetes access tokens and delete them. Deleting one immediately invalidates every kubeconfig and OIDC token it signed, which is what it takes to pull a long-lived service account kubeconfig out of circulation before it expires.
See documentation for more details.
auth.recoveryAdmin config, or the --recovery-admin flag can be used to elevate a user to Admin on every Omni start.
It also blocks user demotion through SAML label rules. This is the way back in when a SAML rule strips Admin from everyone. Only existing users can be promoted.
973d1dfe7 release(v1.11.0): prepare release50ccd9502 release(v1.11.0-beta.1): prepare release4c61b2687 test: retry the maintenance upgrade right after the install reboot87b704fb0 fix: make the omni log format of omnictl machine-logs workaf6f9c6e4 fix: filter the output in omnictldbf8024c1 fix: handle the META keys Talos 1.14 does not allow to write via the APIa6fa429f4 fix: validate the kubeconfig received from the Omni API23d722ad0 fix: remove documents dropped from config patches in maintenance mode51560db91 fix: recognize the full AMD vendor name in the CPU labeldbd30fd45 feat: report the number of machines by CPU core count2b9494644 feat: use the Linux view of the CPU cores for machine hardware status685ea82f4 fix: update COSI to 1.16.3778192cd5 fix: don't give a UUID-conflicting machine the live machine's address81e0f1364 fix: make the image factory credentials readable only by omni92d72412e release(v1.11.0-beta.0): prepare releasee402ff4ef chore: remove oauth2 client credentials auth for the image factorye460ae71e fix: retry a rejected bootstrap request at the next checkb1341200b feat: authenticate PXE installation media with a download tokenb7b58efe8 feat: download installation media through the boot asset APIe2ad5e43f refactor: rename the boot asset API to installation media URLf573426e4 test: fix a race between manual machine picks and machine classes605a83da9 fix: apply pending updates to unhealthy machines so they can recover9b6d554a3 feat(frontend): use download tokens for installation media2491f1437 fix(frontend): fix filter check in pending machinesfbaa7fb18 feat: regularly reconcile factory access tokens in cosi23cc61d91 feat: add image factory token resource1eecc480a feat: add image factory oauth2 client configa96ef43d2 chore: bump deps and default versions36bd2eccc fix: mark a cluster as bootstrapped only once etcd is running on the node71ee3ad80 test: fix a race in the preserve-features machine config test3794b1177 feat: authenticate boot asset downloads with image factory tokens4bbd713da refactor: move the cluster and metrics controllers into their packagesace063b53 fix: record the image factory host for machines already at target8c003994b test: adapt the integration tests to Talos 1.1478d56b38d chore: prepare Omni for Talos 1.14e37ab210b test: trim redundant legacy manifest group id casesf8b9cfc30 fix: migrate legacy weighted one-time manifest group idsc76cf4b7c test: increase timeouts for sqlitelog cleanup tests9630157c3 fix: correct manifest group ownership comparison20afcdacb fix: drop numeric prefix from manifest group idsd50ea9a57 fix: drop manifest apply-order weighting and fix stale status tracking58d1897a2 feat(frontend): hide machine creation commands not supported by enterprisefc8d3d150 feat(frontend): use cross-browser scroll styling7bc0852b9 feat: proxy security reports through omni1c6369866 fix(frontend): remove credentials from cluster create url8c3f12d72 chore: bump depscbbfd9ffe chore: bump gob024ef98a fix: change incorrect version contract for kubespanb1ea5df26 fix: properly clean up pods of the health check jobscc3717ac6 fix: provide machine id consistently in provision API logsc9d6d489b fix: add missing timeout to the version API call in the identity taskc19abe332 fix: stop a link to an exposed service from starting a login flow80c4a4557 feat: manage the install disk with a first-class resourced0ecc7b3f chore: rekres and bump deps84856105e refactor(frontend): drop luxon in favor of date-fnsb6f64c6b7 chore: bump depsee0704f79 feat: allow listing and deleting the Kubernetes token signing keysd7bef774d feat(frontend): add filename param to image downloadsc574e432d fix: siderolink api label44aa6f524 test: increase test timeoutsd6b8c33e3 test: run talemu suite in both chrome and firefoxa0b13882c test: replace omni.localhost with ci.test8378899c0 test: consolidate all host references to common.sh variables0051462aa feat: serve infra provider boot assets through Omni008d9300e chore: rekres and add gitattributes block18854ce46 refactor(frontend): replace remaining update:xxx locations to v-model270d06711 fix(frontend): fix etcd backup interval not editable3798a6d8d feat: add a recovery admin for SAML lockoutsf2aeaa851 fix(frontend): check for navigation in preload error eventsb56929e10 chore: bump deps4c283a3bf chore: rekres and bump gocfa05aa5a fix(frontend): fix incorrect machine route params0f029dcec feat(frontend): add filtering and pagination to cluster scale91a0e612d feat(frontend): use labels input in cluster create11ecf9522 refactor(frontend): extract label completions query from input76fc80dab test(frontend): fix a typo in test regexbcf658e7f refactor(frontend): drop deprecated getcontext3efa4c63c test: make integration tests pass against a non-CI Omni instance71b3a9e41 test: fix flaky unit tests on overloaded CI runnersdbff80519 refactor(frontend): migrate machines away from tlist4e7e354c0 refactor(frontend): migrate pending machines away from tlistec2028cb3 refactor(frontend): move pagination reset logic into composable0faf1cc1c refactor(frontend): lift filtering logic out of tlistb3845c074 refactor(frontend): lift pagination logic out of tlistec0098668 refactor(frontend): lift sorting logic out of tlistb3967f439 fix(frontend): fix side panel sizing and allow control wrapping5bed0cb85 refactor(frontend): lift sidePanel out of tlistc2f91ee19 refactor(frontend): lift addFilterLabel out of tlist22d0972cd refactor(frontend): use pagination component inside tlist8bcc1ad12 refactor(frontend): use reka-ui for paginationc1ae41c57 refactor(frontend): extract items out of pagination4f299f8a8 refactor(frontend): rename tpagination to paginationa98f5ac0b refactor(frontend): rename arrow-* to chevron-* and use heroicons variants0970a6db2 fix(frontend): fix reset wizardcc23658b0 fix: compress diffs in the machine pending updates and diff history47845eb51 fix: force re-authentication at the IdP so logout takes effect194c629cf fix: keep a machine's tunnel peer address stable across provisions899128ec5 fix(frontend): return no-cache for index.html3e01d4012 fix: don't sign users out of Omni on Kubernetes OIDC logout4fad1c5b9 fix(frontend): add missing credentials to security pages8c802ffd6 test(frontend): add edit patch e2e test240964a2e fix(frontend): fix patch edit dropping fieldsd9c463dcc fix: backfill the image factory host of machines enrolled before 1.102c70b1541 fix: bound the machine config diff by bytes, not just lines7a847f5c2 fix(frontend): be more defensive about signup errorsdc6fa2246 chore(frontend): bump dependencies38299fa8e test: verify upgrade drain honors grace period and aborts on failure0a45ef095 chore: bump default versions4d4e327d3 feat(frontend): use hostnames for machine list in delete modal491d83ea2 feat(frontend): normalise the delete/remove text for machines09a97cd63 feat(frontend): show config errors on all node pages6455ba835 feat(frontend): sort talos/k8s versions newest firsta2b38563e fix(frontend): adjust kubespan quick start textc55f2c2bd fix: never change a machine's tunnel address after registration686be42f7 fix: log out of Omni and the IdP when /logout is opened directly06a07defd fix: make SAML single logout survive retries and redirect binding31e814fa3 test: add e2e-saml test class backed by a local Keycloak IdP
973d1dfe7 release(v1.11.0): prepare release
b54b945 release(v1.6.0): prepare release9244e82 feat: sign installer profile when unified secureboot supported3b58dfa feat(enterprise): add a node tokens page82bd329 feat: add node token methods to the factory client9312d82 feat(enterprise): add self-issued node tokens4691e01 feat: add WithTokenSource to include bearer tokensb115d17 chore(enterprise): drop the Auth0 Management API node-token design6f08ed9 feat(enterprise): extend the download-token issuer to a second audiencec51ac14 feat: accept download token on /pxe/ and forward it7252d87 chore: allow proxying IF through IFf45ec71 fix(enterprise): read the org_id claim from if_org_id43adb19 release(v1.5.1): prepare release5f1f197 feat: update Talos to 1.14.0-rc.2b7908c1 feat(enterprise): add Auth0 Management API client for node tokens36fedd7 feat: add WithBearerToken to include m2m tokene783a3d feat(frontend): preserve whitespace for vuln descriptions18f56f7 chore: make sure check-dirty also checks docs196a447 fix: enforce canonical image references26b95ca feat(enterprise): require auth0 clientID and clientSecret always25561f7 fix: retry put when joining a failed get flightaab14ff feat: add spdx and vex reports to factory clientdc6a9f9 feat(enterprise): theme and translate Auth0 logout/login-error pagesbd13149 release(v1.5.0): prepare released3c693a feat: update talos to v1.14.0-rc.15c9839a feat: use the CI cluster registry cache for integration tests70e0590 feat(enterprise): add auth0 browser loginf5f3128 fix: record the status the client actually received0d2275c feat: make download token TTL configurablea5824c7 docs: complete user-facing API referencedd485bd docs: document endpoint access control6016631 test: fix two flaky checks in the enterprise integration jobf984ad8 chore: let the OIDC test server serve extra routesf297b62 chore: update Talos to the latest version86b0a22 fix: re-identify cached SBOM bundles per schematic77990dc fix: schedule grype db refresh to avoid replica desyncad14c5f feat(enterprise): publish installer build evidencedbcc3c6 feat: add auth0 bearer token authenticationae757b5 chore: bump cosign to v3.1.2, sign via Rekor v2 + TSA615b279 feat(enterprise): serve detached Sigstore bundles for assets5296d4a chore: update grpc librarydee1a57 feat: support JWT download tokensc2339ee feat: support public routes in enterprise pluginsa81f6e9 feat: proxy images through backing registry32a3b08 fix: reuse registry puller for bundle verification
ad296ab chore: rekres, bump deps23030b0 fix: keep a replacement gRPC stream's send queue after cleanup4b69f46 fix: correct the wireguard device error handling5157d0c fix: accept valid short IPv6 packets on filtered devicesPrevious release can be found at v1.10.0
This tag was signed with the committer’s verified signature .
Unix4ever Artem Chernyshev
GPG key ID: 9BAC0E08F5067BB8
Verified Learn about vigilant mode .
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
bcf658e7f refactor(frontend): drop deprecated getcontext
Welcome to the v1.11.0-beta.1 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.
Align the UI features on the Cluster scale and Cluster create pages. Support searching by labels on Cluster scaling/create pages.
Config Patches can no longer be used for setting Talos install disk. Starting from Talos 1.14 installation flow was changed a lot so setting the install disk in the configs will no longer work. Install disk is now defined in a separate resource and works differently for the older Talos versions.
Admins can now list the keys that sign Kubernetes access tokens and delete them. Deleting one immediately invalidates every kubeconfig and OIDC token it signed, which is what it takes to pull a long-lived service account kubeconfig out of circulation before it expires.
See documentation for more details.
auth.recoveryAdmin config, or the --recovery-admin flag can be used to elevate a user to Admin on every Omni start.
It also blocks user demotion through SAML label rules. This is the way back in when a SAML rule strips Admin from everyone. Only existing users can be promoted.
50ccd9502 release(v1.11.0-beta.1): prepare release4c61b2687 test: retry the maintenance upgrade right after the install reboot87b704fb0 fix: make the omni log format of omnictl machine-logs workaf6f9c6e4 fix: filter the output in omnictldbf8024c1 fix: handle the META keys Talos 1.14 does not allow to write via the APIa6fa429f4 fix: validate the kubeconfig received from the Omni API23d722ad0 fix: remove documents dropped from config patches in maintenance mode51560db91 fix: recognize the full AMD vendor name in the CPU labeldbd30fd45 feat: report the number of machines by CPU core count2b9494644 feat: use the Linux view of the CPU cores for machine hardware status685ea82f4 fix: update COSI to 1.16.3778192cd5 fix: don't give a UUID-conflicting machine the live machine's address81e0f1364 fix: make the image factory credentials readable only by omni92d72412e release(v1.11.0-beta.0): prepare releasee402ff4ef chore: remove oauth2 client credentials auth for the image factorye460ae71e fix: retry a rejected bootstrap request at the next checkb1341200b feat: authenticate PXE installation media with a download tokenb7b58efe8 feat: download installation media through the boot asset APIe2ad5e43f refactor: rename the boot asset API to installation media URLf573426e4 test: fix a race between manual machine picks and machine classes605a83da9 fix: apply pending updates to unhealthy machines so they can recover9b6d554a3 feat(frontend): use download tokens for installation media2491f1437 fix(frontend): fix filter check in pending machinesfbaa7fb18 feat: regularly reconcile factory access tokens in cosi23cc61d91 feat: add image factory token resource1eecc480a feat: add image factory oauth2 client configa96ef43d2 chore: bump deps and default versions36bd2eccc fix: mark a cluster as bootstrapped only once etcd is running on the node71ee3ad80 test: fix a race in the preserve-features machine config test3794b1177 feat: authenticate boot asset downloads with image factory tokens4bbd713da refactor: move the cluster and metrics controllers into their packagesace063b53 fix: record the image factory host for machines already at target8c003994b test: adapt the integration tests to Talos 1.1478d56b38d chore: prepare Omni for Talos 1.14e37ab210b test: trim redundant legacy manifest group id casesf8b9cfc30 fix: migrate legacy weighted one-time manifest group idsc76cf4b7c test: increase timeouts for sqlitelog cleanup tests9630157c3 fix: correct manifest group ownership comparison20afcdacb fix: drop numeric prefix from manifest group idsd50ea9a57 fix: drop manifest apply-order weighting and fix stale status tracking58d1897a2 feat(frontend): hide machine creation commands not supported by enterprisefc8d3d150 feat(frontend): use cross-browser scroll styling7bc0852b9 feat: proxy security reports through omni1c6369866 fix(frontend): remove credentials from cluster create url8c3f12d72 chore: bump depscbbfd9ffe chore: bump gob024ef98a fix: change incorrect version contract for kubespanb1ea5df26 fix: properly clean up pods of the health check jobscc3717ac6 fix: provide machine id consistently in provision API logsc9d6d489b fix: add missing timeout to the version API call in the identity taskc19abe332 fix: stop a link to an exposed service from starting a login flow80c4a4557 feat: manage the install disk with a first-class resourced0ecc7b3f chore: rekres and bump deps84856105e refactor(frontend): drop luxon in favor of date-fnsb6f64c6b7 chore: bump depsee0704f79 feat: allow listing and deleting the Kubernetes token signing keysd7bef774d feat(frontend): add filename param to image downloadsc574e432d fix: siderolink api label44aa6f524 test: increase test timeoutsd6b8c33e3 test: run talemu suite in both chrome and firefoxa0b13882c test: replace omni.localhost with ci.test8378899c0 test: consolidate all host references to common.sh variables0051462aa feat: serve infra provider boot assets through Omni008d9300e chore: rekres and add gitattributes block18854ce46 refactor(frontend): replace remaining update:xxx locations to v-model270d06711 fix(frontend): fix etcd backup interval not editable3798a6d8d feat: add a recovery admin for SAML lockoutsf2aeaa851 fix(frontend): check for navigation in preload error eventsb56929e10 chore: bump deps4c283a3bf chore: rekres and bump gocfa05aa5a fix(frontend): fix incorrect machine route params0f029dcec feat(frontend): add filtering and pagination to cluster scale91a0e612d feat(frontend): use labels input in cluster create11ecf9522 refactor(frontend): extract label completions query from input76fc80dab test(frontend): fix a typo in test regexbcf658e7f refactor(frontend): drop deprecated getcontext3efa4c63c test: make integration tests pass against a non-CI Omni instance71b3a9e41 test: fix flaky unit tests on overloaded CI runnersdbff80519 refactor(frontend): migrate machines away from tlist4e7e354c0 refactor(frontend): migrate pending machines away from tlistec2028cb3 refactor(frontend): move pagination reset logic into composable0faf1cc1c refactor(frontend): lift filtering logic out of tlistb3845c074 refactor(frontend): lift pagination logic out of tlistec0098668 refactor(frontend): lift sorting logic out of tlistb3967f439 fix(frontend): fix side panel sizing and allow control wrapping5bed0cb85 refactor(frontend): lift sidePanel out of tlistc2f91ee19 refactor(frontend): lift addFilterLabel out of tlist22d0972cd refactor(frontend): use pagination component inside tlist8bcc1ad12 refactor(frontend): use reka-ui for paginationc1ae41c57 refactor(frontend): extract items out of pagination4f299f8a8 refactor(frontend): rename tpagination to paginationa98f5ac0b refactor(frontend): rename arrow-* to chevron-* and use heroicons variants0970a6db2 fix(frontend): fix reset wizardcc23658b0 fix: compress diffs in the machine pending updates and diff history47845eb51 fix: force re-authentication at the IdP so logout takes effect194c629cf fix: keep a machine's tunnel peer address stable across provisions899128ec5 fix(frontend): return no-cache for index.html3e01d4012 fix: don't sign users out of Omni on Kubernetes OIDC logout4fad1c5b9 fix(frontend): add missing credentials to security pages8c802ffd6 test(frontend): add edit patch e2e test240964a2e fix(frontend): fix patch edit dropping fieldsd9c463dcc fix: backfill the image factory host of machines enrolled before 1.102c70b1541 fix: bound the machine config diff by bytes, not just lines7a847f5c2 fix(frontend): be more defensive about signup errorsdc6fa2246 chore(frontend): bump dependencies38299fa8e test: verify upgrade drain honors grace period and aborts on failure0a45ef095 chore: bump default versions4d4e327d3 feat(frontend): use hostnames for machine list in delete modal491d83ea2 feat(frontend): normalise the delete/remove text for machines09a97cd63 feat(frontend): show config errors on all node pages6455ba835 feat(frontend): sort talos/k8s versions newest firsta2b38563e fix(frontend): adjust kubespan quick start textc55f2c2bd fix: never change a machine's tunnel address after registration686be42f7 fix: log out of Omni and the IdP when /logout is opened directly06a07defd fix: make SAML single logout survive retries and redirect binding31e814fa3 test: add e2e-saml test class backed by a local Keycloak IdP
50ccd9502 release(v1.11.0-beta.1): prepare release4c61b2687 test: retry the maintenance upgrade right after the install reboot87b704fb0 fix: make the omni log format of omnictl machine-logs workaf6f9c6e4 fix: filter the output in omnictldbf8024c1 fix: handle the META keys Talos 1.14 does not allow to write via the APIa6fa429f4 fix: validate the kubeconfig received from the Omni API23d722ad0 fix: remove documents dropped from config patches in maintenance mode51560db91 fix: recognize the full AMD vendor name in the CPU labeldbd30fd45 feat: report the number of machines by CPU core count2b9494644 feat: use the Linux view of the CPU cores for machine hardware status685ea82f4 fix: update COSI to 1.16.3778192cd5 fix: don't give a UUID-conflicting machine the live machine's address81e0f1364 fix: make the image factory credentials readable only by omni
b54b945 release(v1.6.0): prepare release9244e82 feat: sign installer profile when unified secureboot supported3b58dfa feat(enterprise): add a node tokens page82bd329 feat: add node token methods to the factory client9312d82 feat(enterprise): add self-issued node tokens4691e01 feat: add WithTokenSource to include bearer tokensb115d17 chore(enterprise): drop the Auth0 Management API node-token design6f08ed9 feat(enterprise): extend the download-token issuer to a second audiencec51ac14 feat: accept download token on /pxe/ and forward it7252d87 chore: allow proxying IF through IFf45ec71 fix(enterprise): read the org_id claim from if_org_id43adb19 release(v1.5.1): prepare release5f1f197 feat: update Talos to 1.14.0-rc.2b7908c1 feat(enterprise): add Auth0 Management API client for node tokens36fedd7 feat: add WithBearerToken to include m2m tokene783a3d feat(frontend): preserve whitespace for vuln descriptions18f56f7 chore: make sure check-dirty also checks docs196a447 fix: enforce canonical image references26b95ca feat(enterprise): require auth0 clientID and clientSecret always25561f7 fix: retry put when joining a failed get flightaab14ff feat: add spdx and vex reports to factory clientdc6a9f9 feat(enterprise): theme and translate Auth0 logout/login-error pagesbd13149 release(v1.5.0): prepare released3c693a feat: update talos to v1.14.0-rc.15c9839a feat: use the CI cluster registry cache for integration tests70e0590 feat(enterprise): add auth0 browser loginf5f3128 fix: record the status the client actually received0d2275c feat: make download token TTL configurablea5824c7 docs: complete user-facing API referencedd485bd docs: document endpoint access control6016631 test: fix two flaky checks in the enterprise integration jobf984ad8 chore: let the OIDC test server serve extra routesf297b62 chore: update Talos to the latest version86b0a22 fix: re-identify cached SBOM bundles per schematic77990dc fix: schedule grype db refresh to avoid replica desyncad14c5f feat(enterprise): publish installer build evidencedbcc3c6 feat: add auth0 bearer token authenticationae757b5 chore: bump cosign to v3.1.2, sign via Rekor v2 + TSA615b279 feat(enterprise): serve detached Sigstore bundles for assets5296d4a chore: update grpc librarydee1a57 feat: support JWT download tokensc2339ee feat: support public routes in enterprise pluginsa81f6e9 feat: proxy images through backing registry32a3b08 fix: reuse registry puller for bundle verification
ad296ab chore: rekres, bump deps23030b0 fix: keep a replacement gRPC stream's send queue after cleanup4b69f46 fix: correct the wireguard device error handling5157d0c fix: accept valid short IPv6 packets on filtered devicesPrevious release can be found at v1.10.0
Nothing published for this version
bcf658e7f refactor(frontend): drop deprecated getcontext
Welcome to the v1.11.0-beta.0 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.
Align the UI features on the Cluster scale and Cluster create pages. Support searching by labels on Cluster scaling/create pages.
Config Patches can no longer be used for setting Talos install disk. Starting from Talos 1.14 installation flow was changed a lot so setting the install disk in the configs will no longer work. Install disk is now defined in a separate resource and works differently for the older Talos versions.
Admins can now list the keys that sign Kubernetes access tokens and delete them. Deleting one immediately invalidates every kubeconfig and OIDC token it signed, which is what it takes to pull a long-lived service account kubeconfig out of circulation before it expires.
See documentation for more details.
auth.recoveryAdmin config, or the --recovery-admin flag can be used to elevate a user to Admin on every Omni start.
It also blocks user demotion through SAML label rules. This is the way back in when a SAML rule strips Admin from everyone. Only existing users can be promoted.
92d72412e release(v1.11.0-beta.0): prepare releasee402ff4ef chore: remove oauth2 client credentials auth for the image factorye460ae71e fix: retry a rejected bootstrap request at the next checkb1341200b feat: authenticate PXE installation media with a download tokenb7b58efe8 feat: download installation media through the boot asset APIe2ad5e43f refactor: rename the boot asset API to installation media URLf573426e4 test: fix a race between manual machine picks and machine classes605a83da9 fix: apply pending updates to unhealthy machines so they can recover9b6d554a3 feat(frontend): use download tokens for installation media2491f1437 fix(frontend): fix filter check in pending machinesfbaa7fb18 feat: regularly reconcile factory access tokens in cosi23cc61d91 feat: add image factory token resource1eecc480a feat: add image factory oauth2 client configa96ef43d2 chore: bump deps and default versions36bd2eccc fix: mark a cluster as bootstrapped only once etcd is running on the node71ee3ad80 test: fix a race in the preserve-features machine config test3794b1177 feat: authenticate boot asset downloads with image factory tokens4bbd713da refactor: move the cluster and metrics controllers into their packagesace063b53 fix: record the image factory host for machines already at target8c003994b test: adapt the integration tests to Talos 1.1478d56b38d chore: prepare Omni for Talos 1.14e37ab210b test: trim redundant legacy manifest group id casesf8b9cfc30 fix: migrate legacy weighted one-time manifest group idsc76cf4b7c test: increase timeouts for sqlitelog cleanup tests9630157c3 fix: correct manifest group ownership comparison20afcdacb fix: drop numeric prefix from manifest group idsd50ea9a57 fix: drop manifest apply-order weighting and fix stale status tracking58d1897a2 feat(frontend): hide machine creation commands not supported by enterprisefc8d3d150 feat(frontend): use cross-browser scroll styling7bc0852b9 feat: proxy security reports through omni1c6369866 fix(frontend): remove credentials from cluster create url8c3f12d72 chore: bump depscbbfd9ffe chore: bump gob024ef98a fix: change incorrect version contract for kubespanb1ea5df26 fix: properly clean up pods of the health check jobscc3717ac6 fix: provide machine id consistently in provision API logsc9d6d489b fix: add missing timeout to the version API call in the identity taskc19abe332 fix: stop a link to an exposed service from starting a login flow80c4a4557 feat: manage the install disk with a first-class resourced0ecc7b3f chore: rekres and bump deps84856105e refactor(frontend): drop luxon in favor of date-fnsb6f64c6b7 chore: bump depsee0704f79 feat: allow listing and deleting the Kubernetes token signing keysd7bef774d feat(frontend): add filename param to image downloadsc574e432d fix: siderolink api label44aa6f524 test: increase test timeoutsd6b8c33e3 test: run talemu suite in both chrome and firefoxa0b13882c test: replace omni.localhost with ci.test8378899c0 test: consolidate all host references to common.sh variables0051462aa feat: serve infra provider boot assets through Omni008d9300e chore: rekres and add gitattributes block18854ce46 refactor(frontend): replace remaining update:xxx locations to v-model270d06711 fix(frontend): fix etcd backup interval not editable3798a6d8d feat: add a recovery admin for SAML lockoutsf2aeaa851 fix(frontend): check for navigation in preload error eventsb56929e10 chore: bump deps4c283a3bf chore: rekres and bump gocfa05aa5a fix(frontend): fix incorrect machine route params0f029dcec feat(frontend): add filtering and pagination to cluster scale91a0e612d feat(frontend): use labels input in cluster create11ecf9522 refactor(frontend): extract label completions query from input76fc80dab test(frontend): fix a typo in test regexbcf658e7f refactor(frontend): drop deprecated getcontext3efa4c63c test: make integration tests pass against a non-CI Omni instance71b3a9e41 test: fix flaky unit tests on overloaded CI runnersdbff80519 refactor(frontend): migrate machines away from tlist4e7e354c0 refactor(frontend): migrate pending machines away from tlistec2028cb3 refactor(frontend): move pagination reset logic into composable0faf1cc1c refactor(frontend): lift filtering logic out of tlistb3845c074 refactor(frontend): lift pagination logic out of tlistec0098668 refactor(frontend): lift sorting logic out of tlistb3967f439 fix(frontend): fix side panel sizing and allow control wrapping5bed0cb85 refactor(frontend): lift sidePanel out of tlistc2f91ee19 refactor(frontend): lift addFilterLabel out of tlist22d0972cd refactor(frontend): use pagination component inside tlist8bcc1ad12 refactor(frontend): use reka-ui for paginationc1ae41c57 refactor(frontend): extract items out of pagination4f299f8a8 refactor(frontend): rename tpagination to paginationa98f5ac0b refactor(frontend): rename arrow-* to chevron-* and use heroicons variants0970a6db2 fix(frontend): fix reset wizardcc23658b0 fix: compress diffs in the machine pending updates and diff history47845eb51 fix: force re-authentication at the IdP so logout takes effect194c629cf fix: keep a machine's tunnel peer address stable across provisions899128ec5 fix(frontend): return no-cache for index.html3e01d4012 fix: don't sign users out of Omni on Kubernetes OIDC logout4fad1c5b9 fix(frontend): add missing credentials to security pages8c802ffd6 test(frontend): add edit patch e2e test240964a2e fix(frontend): fix patch edit dropping fieldsd9c463dcc fix: backfill the image factory host of machines enrolled before 1.102c70b1541 fix: bound the machine config diff by bytes, not just lines7a847f5c2 fix(frontend): be more defensive about signup errorsdc6fa2246 chore(frontend): bump dependencies38299fa8e test: verify upgrade drain honors grace period and aborts on failure0a45ef095 chore: bump default versions4d4e327d3 feat(frontend): use hostnames for machine list in delete modal491d83ea2 feat(frontend): normalise the delete/remove text for machines09a97cd63 feat(frontend): show config errors on all node pages6455ba835 feat(frontend): sort talos/k8s versions newest firsta2b38563e fix(frontend): adjust kubespan quick start textc55f2c2bd fix: never change a machine's tunnel address after registration686be42f7 fix: log out of Omni and the IdP when /logout is opened directly06a07defd fix: make SAML single logout survive retries and redirect binding31e814fa3 test: add e2e-saml test class backed by a local Keycloak IdP
b54b945 release(v1.6.0): prepare release9244e82 feat: sign installer profile when unified secureboot supported3b58dfa feat(enterprise): add a node tokens page82bd329 feat: add node token methods to the factory client9312d82 feat(enterprise): add self-issued node tokens4691e01 feat: add WithTokenSource to include bearer tokensb115d17 chore(enterprise): drop the Auth0 Management API node-token design6f08ed9 feat(enterprise): extend the download-token issuer to a second audiencec51ac14 feat: accept download token on /pxe/ and forward it7252d87 chore: allow proxying IF through IFf45ec71 fix(enterprise): read the org_id claim from if_org_id43adb19 release(v1.5.1): prepare release5f1f197 feat: update Talos to 1.14.0-rc.2b7908c1 feat(enterprise): add Auth0 Management API client for node tokens36fedd7 feat: add WithBearerToken to include m2m tokene783a3d feat(frontend): preserve whitespace for vuln descriptions18f56f7 chore: make sure check-dirty also checks docs196a447 fix: enforce canonical image references26b95ca feat(enterprise): require auth0 clientID and clientSecret always25561f7 fix: retry put when joining a failed get flightaab14ff feat: add spdx and vex reports to factory clientdc6a9f9 feat(enterprise): theme and translate Auth0 logout/login-error pagesbd13149 release(v1.5.0): prepare released3c693a feat: update talos to v1.14.0-rc.15c9839a feat: use the CI cluster registry cache for integration tests70e0590 feat(enterprise): add auth0 browser loginf5f3128 fix: record the status the client actually received0d2275c feat: make download token TTL configurablea5824c7 docs: complete user-facing API referencedd485bd docs: document endpoint access control6016631 test: fix two flaky checks in the enterprise integration jobf984ad8 chore: let the OIDC test server serve extra routesf297b62 chore: update Talos to the latest version86b0a22 fix: re-identify cached SBOM bundles per schematic77990dc fix: schedule grype db refresh to avoid replica desyncad14c5f feat(enterprise): publish installer build evidencedbcc3c6 feat: add auth0 bearer token authenticationae757b5 chore: bump cosign to v3.1.2, sign via Rekor v2 + TSA615b279 feat(enterprise): serve detached Sigstore bundles for assets5296d4a chore: update grpc librarydee1a57 feat: support JWT download tokensc2339ee feat: support public routes in enterprise pluginsa81f6e9 feat: proxy images through backing registry32a3b08 fix: reuse registry puller for bundle verification
ad296ab chore: rekres, bump deps23030b0 fix: keep a replacement gRPC stream's send queue after cleanup4b69f46 fix: correct the wireguard device error handling5157d0c fix: accept valid short IPv6 packets on filtered devicesPrevious release can be found at v1.10.0
Welcome to the v1.10.6 release of Omni!
Welcome to the v1.10.6 release of Omni!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.
bb8eee1f release(v1.10.6): prepare release7c549374 chore: bump siderolink to v0.3.1792e8440f fix: make the omni log format of omnictl machine-logs work8385d3a2 fix: handle the META keys Talos 1.14 does not allow to write via the APIe8c13956 fix: update COSI to 1.16.3a8a2e61a fix: don't give a UUID-conflicting machine the live machine's address9c91887f fix: record the image factory host for machines already at targetcc33057a chore: bump go80f1bccd fix: siderolink api label
ad296ab chore: rekres, bump deps23030b0 fix: keep a replacement gRPC stream's send queue after cleanup4b69f46 fix: correct the wireguard device error handling5157d0c fix: accept valid short IPv6 packets on filtered devicesPrevious release can be found at v1.10.5
Welcome to the v1.10.5 release of Omni!
Welcome to the v1.10.5 release of Omni!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.
3da514071 release(v1.10.5): prepare release0f61f97fc test: fix talemu version to v1.0.0-6-g9326528f3e43cf2d fix: provide machine id consistently in provision API logs51470e023 fix: add missing timeout to the version API call in the identity taskf74555395 fix: change incorrect version contract for kubespan6c0985051 fix: stop a link to an exposed service from starting a login flow1029e9c37 feat(frontend): add filename param to image downloadsb49f605bc fix(frontend): fix etcd backup interval not editableThis release has no dependency changes
Previous release can be found at v1.10.4
This tag was signed with the committer’s verified signature .
Slessi 👑 Edward Sammut Alessi
GPG key ID: 65558E016966977A
Verified Learn about vigilant mode .
Welcome to the v1.10.4 release of Omni!
Welcome to the v1.10.4 release of Omni!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.
Admins can now list the keys which sign the Kubernetes access tokens and delete them using omnictl. Deleting a key immediately invalidates all the tokens signed by it, such as the long-lived service account kubeconfigs, without a restart. Deleting the most recent key is safe: a replacement is generated automatically when the next token is issued. The key deletions are recorded in the audit log.
615998ab9 release(v1.10.4): prepare releasebc586e4f7 feat: allow listing and deleting the Kubernetes token signing keysThis release has no dependency changes
Previous release can be found at v1.10.3
Welcome to the v1.10.3 release of Omni!
Welcome to the v1.10.3 release of Omni!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.
39bcff396 release(v1.10.3): prepare release8bce1ddbd fix(frontend): check for navigation in preload error eventsThis release has no dependency changes
Previous release can be found at v1.10.2
Welcome to the v1.10.2 release of Omni!
Welcome to the v1.10.2 release of Omni!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.
0a932d3df release(v1.10.2): prepare release93fb429b4 chore: rekres and bump go024fe1e4c fix(frontend): fix incorrect machine route paramsThis release has no dependency changes
Previous release can be found at v1.10.1
Welcome to the v1.10.1 release of Omni!
Welcome to the v1.10.1 release of Omni!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.
0fbf63143 release(v1.10.1): prepare releasea694edefb fix(frontend): fix reset wizard7aa7a7e45 fix: compress diffs in the machine pending updates and diff historydd1b1dd97 fix: force re-authentication at the IdP so logout takes effectb5303320a fix: keep a machine's tunnel peer address stable across provisions1005ec0d6 fix(frontend): return no-cache for index.htmlc9ba2048b fix: don't sign users out of Omni on Kubernetes OIDC logout3b82989e1 fix(frontend): add missing credentials to security pagesa2058e200 chore(frontend): bump dependencies8a8fd2a1b test(frontend): add edit patch e2e test4d1ed5bb5 fix(frontend): fix patch edit dropping fields80b2e8586 fix: backfill the image factory host of machines enrolled before 1.10f28cdc77a fix: bound the machine config diff by bytes, not just lines0e1259283 fix(frontend): be more defensive about signup errors6b91ddb67 fix: log out of Omni and the IdP when /logout is opened directlyThis release has no dependency changes
Previous release can be found at v1.10.0
Welcome to the v1.10.1 release of Omni!
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
<details><summary>14 commits</summary> <p>
a694edef fix(frontend): fix reset wizard7aa7a7e4 fix: compress diffs in the machine pending updates and diff historydd1b1dd9 fix: force re-authentication at the IdP so logout takes effectb5303320 fix: keep a machine's tunnel peer address stable across provisions1005ec0d fix(frontend): return no-cache for index.htmlc9ba2048 fix: don't sign users out of Omni on Kubernetes OIDC logout3b82989e fix(frontend): add missing credentials to security pagesa2058e20 chore(frontend): bump dependencies8a8fd2a1 test(frontend): add edit patch e2e test4d1ed5bb fix(frontend): fix patch edit dropping fields80b2e858 fix: backfill the image factory host of machines enrolled before 1.10f28cdc77 fix: bound the machine config diff by bytes, not just lines0e125928 fix(frontend): be more defensive about signup errors6b91ddb6 fix: log out of Omni and the IdP when /logout is opened directly
</p>
</details>This release has no dependency changes
Previous release can be found at v1.10.0
A new cluster security page lists the vulnerabilities of the images a running cluster uses, together with the upgrade paths that clear them, and the s…
Welcome to the v1.10.0 release of Omni!
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
The audit log read API gains a follow mode. After serving the backlog the stream stays open and delivers new events as they are written, in insertion order. Followed events carry their ids, and a stream can start from an id received earlier, so a consumer resumes exactly where it left off. The start position can also be given as a timestamp. A follow stream ends cleanly after a bounded time rather than staying open indefinitely, and the client continues from the last id it received. omnictl performs that reconnect automatically. omnictl audit-log gains a --follow flag to tail the log live and a --since flag to start from a relative time in either mode. Reading the audit log now produces an audit log event of its own, recording who read it, the time range requested and the filters used, and the new event type can itself be filtered on.
Reading the audit log required the Admin role, so anything that consumes audit events also had to hold user management and full administrative access to every managed Kubernetes cluster. The new Auditor role grants read access plus the audit log and nothing else. It is matched by exact role rather than by rank, so an Operator, which outranks an Auditor, still cannot read the audit log. It can be assigned to users and service accounts, but not through access policies or SAML label rules, which now reject roles that are not meant to be assigned that way.
A new cluster security page lists the vulnerabilities of the images a running cluster uses, together with the upgrade paths that clear them, and the scan details can be filtered by severity. Vulnerability scanning requires the Image Factory Enterprise. Against the public factory the page reports that scanning is unavailable instead of showing results.
Config patches can no longer set the Kubernetes certificate authority or the service account signing key, which Omni generates and owns. This holds for every cluster, not only for clusters on the new Talos 1.14 document layout, and it covers the v1alpha1 fields as well as the Talos 1.14 documents that carry the same material. An already stored patch keeps working while it stays unchanged. Changing one that sets either of them is rejected, so such a patch has to be corrected before it can be edited again.
A config patch can now be disabled. It is retained as a resource but is never applied.
Talos 1.14 replaces the single discovery endpoint with a configuration that can register a machine with more than one discovery service at once, and Omni now removes a departing machine's affiliate from every endpoint it used. A cluster used to pick either the public discovery service or the embedded one. For clusters created with Talos 1.14 or newer it can now also use both at the same time.
Machines running Talos Enterprise now get an omni.sidero.dev/enterprise label, and machines running Talos in FIPS mode get an omni.sidero.dev/fips label carrying either enabled or strict. Like the other labels Omni manages, they cannot be removed by the user, and they are cleared when a machine reverts to a regular build. Both values are read over the Talos API and watched for changes, since they follow the installed image. Older Talos versions do not report them, so machines running those get no labels.
Machine names are shown the same way everywhere, using the hostname with the machine UUID as a fallback, and the machine stage is dimmed while a machine is unhealthy, with the last known status still shown. The home page replaces the radial bars with segmented ones and splits the machine stats into connection and allocation, which used to be mixed together, and it now also shows the ongoing operations that were previously only in the top-right dropdown. The CPU usage chart stacks its system and user areas and labels them as percentages, and the Kubernetes manifests status is drawn as a graph. In the disk view, unallocated space is striped so it reads apart from allocated space, and volumes Omni does not recognize cycle through distinct colors. Errors from machine service queries appear inline on the page instead of as a toast, with retries and backoff, and an unreachable Talos API is reported as not ready yet rather than as a generic failure. The config editor can toggle word wrap from its context menu, and $patch: delete is accepted everywhere the patch validation allows it. On an Auth0 instance the very first user lands on the signup page instead of the login page, and PXE boot is hidden when Omni runs against the Image Factory Enterprise. A node's last configuration error is now shown on every one of its tabs, not just the overview, and Talos and Kubernetes version dropdowns list versions newest first. The machine delete confirmation lists hostnames instead of raw UUIDs. Removing machines is named consistently: deleting a machine or a pending machine is "Delete", removing one from a cluster is "Remove", and the destructive machine option reads "Force Delete" instead of "Force Destroy".
An infrastructure provider id must now be a valid DNS label, so lowercase letters, digits and dashes only. Ids with uppercase letters, underscores or spaces used to be accepted and caused failures further along. They are rejected at creation now.
The UI and the CLI now show the version of an infrastructure provider.
Machines on Talos 1.13 or newer are installed through the Talos lifecycle API, which takes the install disk as an explicit argument. Omni passed the automatically picked default there, so a disk chosen through the UI or a cluster template was ignored and Talos could be installed to a different disk than the one selected. Omni now reads the install disk from the machine's effective configuration, where the selection is already applied on top of the default.
Talos installers from 1.14 report a distinct exit code per failure instead of one generic code, and Omni now reads them. A failure caused by invalid input or an unsupported operation cannot succeed until the machine configuration or the install options change, so Omni records the reason on the machine and stops retrying. Everything else stays retryable, including the single exit code that pre-1.14 installers report for every failure.
Kubernetes upgrades no longer pre-pull the kube-proxy image, on any cluster. Clusters that use a kube-proxy replacement such as Cilium turn kube-proxy off, and pre-pulling an image they never run consumed bandwidth needlessly.
Rather than disabling the KubeSpan tab for a cluster that does not have KubeSpan enabled, Omni now shows a quick start page there with a short explanation, a link to the docs, the config patch it would apply, and a button that applies it. The suggested patch matches what the cluster supports, so a cluster on multi-document configs is offered the newer form. The page warns about the network overhead, which matters most on larger clusters. The KubeSpan status view also tells offline peers apart by shape and line style on top of color, which helps with red and green color blindness.
On machines running Talos 1.13 or newer, Omni installs and upgrades through Talos's LifecycleService and runs the sequence itself: pull the installer, install or upgrade to disk, forfeit etcd leadership on control planes, cordon and drain the node, then reboot. Same-minor installs on maintenance machines take this explicit path now, instead of letting a config apply trigger the install, and cluster creation and scale-up bring a maintenance-mode machine to the cluster's Talos version when the two differ by a minor version. Machines on older Talos keep using the classic path, and each machine's running version and schematic decide which one it takes.
Every Omni instance now answers at /logout, whatever its authentication type. SAML and OIDC instances were already served by the backend, and Auth0 instances now have a page that performs the logout, so the same URL ends a session everywhere.
omni_machine_logs_ingested_bytes_total counts the bytes of machine log messages written to storage. Two gauges that were being kept up to date but never registered are now exposed on the Prometheus endpoint as well, one for the number of CPU cores across all machines and one for the number of active virtual state watches.
Omni can now run against two image factories, a primary and a secondary, which makes it possible to migrate from one to the other. They are configured under registries.factories.primary and registries.factories.secondary, each taking a URL, a PXE URL, and Image Factory Enterprise credentials. The flat imageFactoryBaseURL, imageFactoryPXEBaseURL, imageFactoryUsername and imageFactoryPassword options are deprecated in favor of the primary block. They still work on their own, but once the primary block carries a URL they are ignored completely, so credentials meant for one factory are never sent to another.
The node audit skip cluster feature, which exempts a Kubernetes node carrying the omni.sidero.dev/node-audit-skip annotation from the node audit, can now be turned on from the cluster create page and the cluster overview, and set in cluster templates.
On Talos 1.14 and newer, resetting a machine also wipes the container runtime, kubelet, etcd and log volumes, on top of the state and ephemeral partitions it wiped before. Machines on earlier Talos versions still have only those two wiped.
Single logout on a SAML instance could silently fail to reach the identity provider. The cookie tracking the logout was cleared as soon as the logout request was built rather than once the identity provider confirmed it, so any repeated request to /logout, including the browser's own retries, found nothing left to send and the identity provider session survived. A logout response delivered over the HTTP-Redirect binding, rather than as a POST, also failed to parse and left the user on the forbidden page even though the identity provider had already completed the logout; that binding is now handled on its own endpoint.
Search terms, filters and sort order are now part of the URL, so a narrowed-down view survives a reload and can be shared as a link.
Support bundles now also carry in-flight machine update state and the inputs Omni uses to generate machine configurations.
Talos 1.14 moves cluster identity, certificate authorities, encryption secrets and Talos API access rules out of the single v1alpha1 document into documents of their own, and Omni understands the new layout. Kubernetes component images for upgrades are patched in the shape the cluster's version contract calls for, Kubernetes CA rotation writes the accepted CA wherever the generated configuration keeps it, and the Talos API access restriction follows its own document. The frontend validates patches against the 1.14 schema and generates 1.14 variants of the patches it writes.
<details><summary>192 commits</summary> <p>
5d2b007bc chore: bump default versions0a63295b4 fix: make SAML single logout survive retries and redirect binding0b59f8bee feat(frontend): show config errors on all node pages7e97185f3 feat(frontend): sort talos/k8s versions newest firste9214cc36 fix(frontend): adjust kubespan quick start text06b49581a feat(frontend): use hostnames for machine list in delete modalbe310e386 feat(frontend): normalise the delete/remove text for machinesfd41f737a feat: encrypt support bundles by default924420dda release(v1.10.0-beta.0): prepare releaseacc9edb2e feat: classify installer exit codes and skip retrying permanent ones18bafff42 fix(frontend): adjust toast text for machine removal02bb82775 fix(frontend): unselect removed machines in machine listd3419f711 test: make the install disk selection test deterministicee6b16d84 test: reserve integration test machines against concurrent allocationeb5320932 feat(frontend): improve legibility for unallocated and user partitions2c4940aed fix: drop noisy WireGuard handshake warnings for offline peers89d418568 feat: for talos 1.14 machine reset also wipe cri, kubelet, etcd, loge040a4b61 fix(frontend): use cluster config version for version contract in scale5d9489643 fix(frontend): also check version contract in cluster scaledbc458e82 feat(frontend): allow $patch: delete in all places0b5cafaf3 chore: bump dependencies9e062ebc5 fix: forbid cluster CA and service account key in config patches3a4771fab feat: rotate the Kubernetes CA on Talos 1.14 multi-doc configs6d67db2a6 feat: rework discovery service configuration for Talos 1.141cdfd703c fix: track namespaced cluster-scoped manifests as applied7765bab36 feat: validate multi-doc config patches2f4f0f382 feat(frontend): add talos 1.14 variants for frontend generated patches4dcd206a5 feat: expose more version contract fields202769d74 fix(frontend): use dvh instead of vh for heightd02e70432 feat(frontend): add talos 1.14 schema9cad25799 chore: bump talos machinery03ad541a4 fix: respect the user's install disk selection in maintenance installsf31cbce00 feat(frontend): redesign manifests status to a graph view126b6b721 refactor(frontend): refactor kubespan canvas to vue-flow4546b0968 fix(frontend): trim cluster machine status last_config_error messaged04a01230 feat: for kubespan quick start use correct patch for the clusterd34ecf498 feat(client): allow disabling the transparent watch retry72b942c38 feat: add Auditor role for reading the audit log0a64c8185 feat: label Talos Enterprise machinesf73296960 feat: multiple image factories support7873fda7a chore: apply CA, Registry configs before install/upgrade calls53b3c825c feat: support enableNodeAuditSkip in cluster templatesb2b2b2050 fix: verify maintenance install/upgrade against the live machine7bc776663 chore: change virtual ImageFactoryAuth resource to be persistent72ffae831 fix(frontend): fix incorrect action on patch delete92215fb7e fix(frontend): preserve whitespace in alerts4edaf8a41 fix: dont include failed/evicted pods for k8s usage dataf5cb97b2e fix(frontend): constrain monitor charts to a fixed size regardless of stateb5cff35bf fix(frontend): constrain extensions modals to a fixed size6cea62574 fix(frontend): dont try load auth0 if we arent using auth0 in userinfobed3482d1 fix(frontend): don't call machineservice.events for maintenance talos on <1.13582730ce9 chore: bump depsfb2ae3f74 fix: allow SAMLLabelRule to downgrade user role to None7b06af519 fix: mark machines installed when the lifecycle install completes2557f6451 chore: rekres73e415bec chore(frontend): bump deps87ca0cdf9 fix(frontend): prevent jumping when select up/down arrows disappear071f1b295 feat: allow disabling config patches526e1c635 feat: support following the audit log over the management APId0824edf0 fix: support the new discovery service endpoints list of Talos 1.1447b66fdf3 feat: show infra provider versions in ui and clie23a8f7d7 feat: do not pre-pull the kube-proxy image on Kubernetes upgradese19f19d14 fix: use initial versions from inputedcc25692 feat: build version aware Kubernetes component patches for upgradesd0642877b feat(frontend): hide pxe boot option for enterprise3187ffad3 test: fix Omni upgrade workload proxy DNS4e8cc051e fix: ignore not-found errors when deleting an infra provider1476e5389 chore: bump talos machinery to v1.14.0-alpha.29d4cfa666 feat(frontend): dim machine stage status when machine is not healthy89eca085d test: run browser e2e tests off the host networkd6bfcee97 feat: serve the frontend dev server through the main endpoint66a7ba2fd fix: allow removing the bootstrap spec once the cluster is bootstrappedf75c63db6 feat: install same-minor maintenance machines via LifecycleServiceff510298b fix: expose the machines cores and virtual state watches metricsdf72b2c32 test: use dex oidc instead of auth0 as default for e2e tests7fcee51e2 test: poll for minio to come up instead of just sleeping54819dfa2 test(frontend): remove testing of actual iso download110cf83c2 refactor: proxy frontend dev server routes using prod flowd62f8c866 chore(frontend): update factory staging url for dev5a751477d feat(frontend): add a /logout route for auth0 logouts9e3f29030 fix(frontend): skip 0 length bars in home segmented charts15b1667d7 feat(frontend): handle machine services errors gracefullyf161c4377 refactor(frontend): make watch failed errors more informative7a2477b42 fix: update kube-service-exposer to v0.4.0d0d7d76db feat: introduce the new metric that counts total number of cores531947830 feat: use LifecycleService for maintenance machine upgradesdb6795395 fix: dont clear sa expiration when no keys are left74cb7078e fix: correct boot ID and Talos version tracking for maintenance installs3eab1cc10 fix(frontend): remove an unused @click actionf3f9cd675 refactor(frontend): make all detached scopes lazily loaded2be419957 chore(frontend): bump frontend deps000b16206 fix: honor current machine set update limits2dfe2e5ae chore: bump oras-go to 2.6.216265a1a8 feat(frontend): add word wrap to monaco context menu0a37d5090 refactor(frontend): don't create new editor and model instance for schema changes800217124 chore(frontend): add stories for CodeEditore2f573985 fix(frontend): make CodeEditor props reactive561d2582d feat: log audit log access in the audit log0fee0fc30 fix: properly propagate errors coming from the machine lifecycle APIb5450ebfb fix: don't treat unset S3 endpoint as an empty overridedaa126862 test(frontend): adjust fake-indexeddb usage which broke in node 24.180618b9015 chore(frontend): bump node to 24.185419d7071 feat(frontend): show ongoing operations on the home page2afd22236 feat(frontend): use segmented bars for home page stats8b637dc86 chore(frontend): write stories for home page contentdf33497e2 chore: bump dependenciesa47e7128c feat: add machine log ingestion byte-rate metric7bc30eb08 chore: rekres and bump Go to 1.26.5e05e3285d feat: manage Talos install and upgrade via LifecycleService2ddeca05f fix(frontend): remove power icon from machines paged0535ada4 feat: expose node audit skip cluster feature809baa687 feat(frontend): persist search and filters as query stringsee432246d refactor(frontend): rename filterLabel to selectLabel in ItemLabelab95b0c3b refactor(frontend): refactor LabelsInput to use v-modele6fa2f14e refactor(frontend): replace removeLabel prop with remove emit5e9ccbd12 refactor(frontend): replace onClear prop with clear emit14ef61130 feat: send initial instance user to signup page84f151fe7 fix(frontend): handle aborted requests in useMachineServices7e0cf44c2 feat(frontend): add a quickstart page for kubespan8e8a46757 feat(frontend): standardize machine display in omni2d5610204 fix(frontend): prevent item list flash during connection drops655c2ae4f refactor(frontend): move itemID into useResourceWatch8373f536f refactor(frontend): lift interfaces from watch to composable7fb66d5bd refactor(frontend): merge watch items into composable37b19c408 refactor(frontend): lift remaining parts of watch class to composable0e7bb6ae9 refactor(frontend): lift item handlers up to watch composable640014ecd refactor(frontend): inline watch callbacks588d21e2c refactor(frontend): remove unnecessary setDescending funcc655f002f refactor(frontend): migrate watch tests to useresourcewatch tests4e4cd5f85 refactor(frontend): move watch.setup into useresourcewatch81c8c2a40 refactor(frontend): merge watchfunc and watch classes together104a8b2ab fix(frontend): prevent copying double newlines in machine logsc48c9b923 refactor(frontend): migrate machine set config edit modal to new modal system2adcefe4d refactor(frontend): migrate create extensions modal to new modal systemc435a8f69 refactor(frontend): migrate config patch edit modal to new modal systeme7c340668 refactor(frontend): migrate save preset modal to new modal systema7762559d refactor(frontend): hide primary action when maintenance lifecycle complete971145cc1 refactor(frontend): migrate download preset modal to new modal systemf9360c2e9 refactor(frontend): remove unused machine template extensions modal8ee92b377 refactor(frontend): migrate service account renew to new modal system022c458fe refactor(frontend): migrate service account create to new modal system7747a322c refactor(frontend): migrate role edit to new modal systemfb9d41f13 refactor(frontend): migrate user destroy to new modal system384a5347a refactor(frontend): migrate user create to new modal systemd69401087 refactor(frontend): migrate machine remove to new modal systeme0626db83 refactor(frontend): migrate machine class destroy to new modal systemdb5540826 refactor(frontend): migrate machine set destroy to new modal systeme26d569ad refactor(frontend): migrate export cluster template to new modal systemdd5b62550 refactor(frontend): migrate config patch destroy to new modal system7f1bf6646 refactor(frontend): migrate infra provider delete to new modal system9bdbeace7 refactor(frontend): migrate infra provider setup to new modal systemb94b299b4 refactor(frontend): migrate download omnictl to new modal system542124bcf refactor(frontend): migrate node shutdown to new modal systemfe09adc22 refactor(frontend): migrate node destroy cancel to new modal systemd1b56338d refactor(frontend): migrate node destroy to new modal system02f0d1129 refactor(frontend): migrate node reboot to new modal system3ddc040e1 test: fix flaky audit log and service account status testse330092a2 feat: add pending updates and config gen options to support bundle49c8e725f fix: update COSI runtime to fix hanging TeardownAndDestroy callsc91ce1a50 fix: align config outdated status in ui and clifde089bbe refactor(frontend): refactor untaint single node modal to new system094b25913 feat(frontend): add content-class support to confirm modald193dce9e chore: expose user roles in the public package to be used by scripts33aa3fa26 refactor(frontend): replace ua-parser-js with bowser6b2da6745 chore(frontend): drop yaml dependency and move openpgp to dependencies27c6aa078 chore: rekres for js sbomed793b6b0 feat(frontend): add filtering to scan details modal6ef286f27 feat(frontend): add a cluster security page for vulns99a76d479 refactor(frontend): extract components from scan details modal034640bbe refactor(frontend): extract business logic from scan details modal2cf7801dc refactor(frontend): make use resource list default to empty array120563a38 feat(frontend): stack CPU usage chart areas and format with %77dcbe90b chore: add stories for monitor viewae93d3f96 fix(frontend): only show process args in command columne690d624b fix(frontend): allow in-minor patch upgrades in update kubernetes on Omnib30472e6c refactor: use ImageServiceClient for pulling images1c20cc949 chore: bump helm to v4 in zstd-dict5f4f27df3 fix: recover a machine from a reverted reboot-requiring config patcheadd5b57d fix(frontend): allow force-destroy when MachineSetNode is already gonefd4e5da46 test(frontend): fix some flaky tests in e2e-talemu1882db158 feat: install/upgrade maintenance-mode Talos during cluster create/scale-up84180bd0f fix: advertise reachable machine API address in cluster-import test937ce3a61 fix: keep maintenance Talos clients until machine leaves maintenancea7b87871c refactor: derive extension list from the raw schematic manifest961a20c60 fix: move timeout for factory requests to controllerse63d4e455 test: drop non-existent preset delete error expectation6f26c4098 chore: enrich SBOM with Go module licenses1b337b249 fix: tolerate NotFound on installation media preset deletec2533013c test: stabilize image-factory schematic across CI runs984ba0090 feat(frontend): add more visual distinction for offline kubespan peers51cc468db fix: prevent removal of node unique tokens that still have a link88c77c618 fix: validate infra provider name as DNS-1123 label
</p>
</details><details><summary>8 commits</summary> <p>
5d2b007bc chore: bump default versions0a63295b4 fix: make SAML single logout survive retries and redirect binding0b59f8bee feat(frontend): show config errors on all node pages7e97185f3 feat(frontend): sort talos/k8s versions newest firste9214cc36 fix(frontend): adjust kubespan quick start text06b49581a feat(frontend): use hostnames for machine list in delete modalbe310e386 feat(frontend): normalise the delete/remove text for machinesfd41f737a feat: encrypt support bundles by default
</p>
</details><details><summary>13 commits</summary> <p>
f03ed02 release(v1.1.0): prepare release373430a feat(stats): add cached /stats endpoint0dc4741 chore: bump prometheus, grpc, and otel deps1479df2 chore: bump net to v0.57.0709d4b9 chore: bump net pkg to v0.55.0 (security)0ce4779 chore: bump sync pkg to v0.22.09628da0 chore: update go.mod deps99b6268 chore: rekres48cf9df chore: bump go to latest 1.26d315a3f chore: fmtf905881 chore: rekres73b90df feat: add support for x-forwaded-for header35804da chore: bump dependencies
</p>
</details><details><summary>1 commit</summary> <p>
c526410 fix: skip unknown-key check for types with custom YAML unmarshaler
</p>
</details><details><summary>3 commits</summary> <p>
0caf1f2 feat: add Kubernetes 1.37 compatibility822b7a2 feat: add nodedrain package for client-side cordon and drain260bc0a fix: update authorization config apiVersion for K8s >= 1.32
</p>
</details><details><summary>1 commit</summary> <p>
18af7d6 feat: update dependencies and support recipients
</p>
</details><details><summary>21 commits</summary> <p>
efab38f release(v1.4.0): prepare release9c64235 feat: add schematic owner validationca87d23 fix: add single-flight around schematic factoryd45b5ac docs: link to Image Factory Enterprise docs page490a993 chore: bump pkgs revision to match talos v1.14.0-alpha.2f9ff935 chore: bump go pkgs12cd647 feat: add llms.txt for better LLM usagef65960f fix: audit file defaultsf26e5e2 feat: add audit log for authenticated requestsbeff6e2 feat: support registry namespace prefix for core artifacts8c489d0 chore: update dependencies026f8a8 feat: extra extensions (enterprise only)915ef76 chore: add insecure flag to dev config3bccbe1 fix: handle single arch images6b1c855 refactor: prepare for more than one artifact registrybee4fe3 feat: narrow sbom cache key to extension list onlye0e4a44 refactor: abstract versioned cache3359f6c feat: add secureboot enrollKeys schematic option805c51c feat: add per-request correlation ID to logs8cee96d feat: assert pxe cache in tests4ec0789 feat: bump go-conainerregistry
</p>
</details>Previous release can be found at v1.9.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →