NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1414 by repository stars
Last release 4 days ago
02 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Rarely documented
notes for 12 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
641 releases · first in 2024
Nothing published for this version
Nothing published for this version
A new cluster security page lists the vulnerabilities of the images a running cluster uses, together with the upgrade paths that clear them, and the s…
Welcome to the v1.10.0-beta.0 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
The audit log read API gains a follow mode. After serving the backlog the stream stays open and delivers new events as they are written, in insertion order. Followed events carry their ids, and a stream can start from an id received earlier, so a consumer resumes exactly where it left off. The start position can also be given as a timestamp. A follow stream ends cleanly after a bounded time rather than staying open indefinitely, and the client continues from the last id it received. omnictl performs that reconnect automatically. omnictl audit-log gains a --follow flag to tail the log live and a --since flag to start from a relative time in either mode. Reading the audit log now produces an audit log event of its own, recording who read it, the time range requested and the filters used, and the new event type can itself be filtered on.
Reading the audit log required the Admin role, so anything that consumes audit events also had to hold user management and full administrative access to every managed Kubernetes cluster. The new Auditor role grants read access plus the audit log and nothing else. It is matched by exact role rather than by rank, so an Operator, which outranks an Auditor, still cannot read the audit log. It can be assigned to users and service accounts, but not through access policies or SAML label rules, which now reject roles that are not meant to be assigned that way.
A new cluster security page lists the vulnerabilities of the images a running cluster uses, together with the upgrade paths that clear them, and the scan details can be filtered by severity. Vulnerability scanning requires the Image Factory Enterprise. Against the public factory the page reports that scanning is unavailable instead of showing results.
Config patches can no longer set the Kubernetes certificate authority or the service account signing key, which Omni generates and owns. This holds for every cluster, not only for clusters on the new Talos 1.14 document layout, and it covers the v1alpha1 fields as well as the Talos 1.14 documents that carry the same material. An already stored patch keeps working while it stays unchanged. Changing one that sets either of them is rejected, so such a patch has to be corrected before it can be edited again.
A config patch can now be disabled. It is retained as a resource but is never applied.
Talos 1.14 replaces the single discovery endpoint with a configuration that can register a machine with more than one discovery service at once, and Omni now removes a departing machine's affiliate from every endpoint it used. A cluster used to pick either the public discovery service or the embedded one. For clusters created with Talos 1.14 or newer it can now also use both at the same time.
Machines running Talos Enterprise now get an omni.sidero.dev/enterprise label, and machines running Talos in FIPS mode get an omni.sidero.dev/fips label carrying either enabled or strict. Like the other labels Omni manages, they cannot be removed by the user, and they are cleared when a machine reverts to a regular build. Both values are read over the Talos API and watched for changes, since they follow the installed image. Older Talos versions do not report them, so machines running those get no labels.
Machine names are shown the same way everywhere, using the hostname with the machine UUID as a fallback, and the machine stage is dimmed while a machine is unhealthy, with the last known status still shown. The home page replaces the radial bars with segmented ones and splits the machine stats into connection and allocation, which used to be mixed together, and it now also shows the ongoing operations that were previously only in the top-right dropdown. The CPU usage chart stacks its system and user areas and labels them as percentages, and the Kubernetes manifests status is drawn as a graph. In the disk view, unallocated space is striped so it reads apart from allocated space, and volumes Omni does not recognize cycle through distinct colors. Errors from machine service queries appear inline on the page instead of as a toast, with retries and backoff, and an unreachable Talos API is reported as not ready yet rather than as a generic failure. The config editor can toggle word wrap from its context menu, and $patch: delete is accepted everywhere the patch validation allows it. On an Auth0 instance the very first user lands on the signup page instead of the login page, and PXE boot is hidden when Omni runs against the Image Factory Enterprise.
An infrastructure provider id must now be a valid DNS label, so lowercase letters, digits and dashes only. Ids with uppercase letters, underscores or spaces used to be accepted and caused failures further along. They are rejected at creation now.
The UI and the CLI now show the version of an infrastructure provider.
Machines on Talos 1.13 or newer are installed through the Talos lifecycle API, which takes the install disk as an explicit argument. Omni passed the automatically picked default there, so a disk chosen through the UI or a cluster template was ignored and Talos could be installed to a different disk than the one selected. Omni now reads the install disk from the machine's effective configuration, where the selection is already applied on top of the default.
Talos installers from 1.14 report a distinct exit code per failure instead of one generic code, and Omni now reads them. A failure caused by invalid input or an unsupported operation cannot succeed until the machine configuration or the install options change, so Omni records the reason on the machine and stops retrying. Everything else stays retryable, including the single exit code that pre-1.14 installers report for every failure.
Kubernetes upgrades no longer pre-pull the kube-proxy image, on any cluster. Clusters that use a kube-proxy replacement such as Cilium turn kube-proxy off, and pre-pulling an image they never run consumed bandwidth needlessly.
Rather than disabling the KubeSpan tab for a cluster that does not have KubeSpan enabled, Omni now shows a quick start page there with a short explanation, a link to the docs, the config patch it would apply, and a button that applies it. The suggested patch matches what the cluster supports, so a cluster on multi-document configs is offered the newer form. The page warns about the network overhead, which matters most on larger clusters. The KubeSpan status view also tells offline peers apart by shape and line style on top of color, which helps with red and green color blindness.
On machines running Talos 1.13 or newer, Omni installs and upgrades through Talos's LifecycleService and runs the sequence itself: pull the installer, install or upgrade to disk, forfeit etcd leadership on control planes, cordon and drain the node, then reboot. Same-minor installs on maintenance machines take this explicit path now, instead of letting a config apply trigger the install, and cluster creation and scale-up bring a maintenance-mode machine to the cluster's Talos version when the two differ by a minor version. Machines on older Talos keep using the classic path, and each machine's running version and schematic decide which one it takes.
Every Omni instance now answers at /logout, whatever its authentication type. SAML and OIDC instances were already served by the backend, and Auth0 instances now have a page that performs the logout, so the same URL ends a session everywhere.
omni_machine_logs_ingested_bytes_total counts the bytes of machine log messages written to storage. Two gauges that were being kept up to date but never registered are now exposed on the Prometheus endpoint as well, one for the number of CPU cores across all machines and one for the number of active virtual state watches.
Omni can now run against two image factories, a primary and a secondary, which makes it possible to migrate from one to the other. They are configured under registries.factories.primary and registries.factories.secondary, each taking a URL, a PXE URL, and Image Factory Enterprise credentials. The flat imageFactoryBaseURL, imageFactoryPXEBaseURL, imageFactoryUsername and imageFactoryPassword options are deprecated in favor of the primary block. They still work on their own, but once the primary block carries a URL they are ignored completely, so credentials meant for one factory are never sent to another.
The node audit skip cluster feature, which exempts a Kubernetes node carrying the omni.sidero.dev/node-audit-skip annotation from the node audit, can now be turned on from the cluster create page and the cluster overview, and set in cluster templates.
On Talos 1.14 and newer, resetting a machine also wipes the container runtime, kubelet, etcd and log volumes, on top of the state and ephemeral partitions it wiped before. Machines on earlier Talos versions still have only those two wiped.
Search terms, filters and sort order are now part of the URL, so a narrowed-down view survives a reload and can be shared as a link.
Support bundles now also carry in-flight machine update state and the inputs Omni uses to generate machine configurations.
Talos 1.14 moves cluster identity, certificate authorities, encryption secrets and Talos API access rules out of the single v1alpha1 document into documents of their own, and Omni understands the new layout. Kubernetes component images for upgrades are patched in the shape the cluster's version contract calls for, Kubernetes CA rotation writes the accepted CA wherever the generated configuration keeps it, and the Talos API access restriction follows its own document. The frontend validates patches against the 1.14 schema and generates 1.14 variants of the patches it writes.
<details><summary>183 commits</summary> <p>
acc9edb2 feat: classify installer exit codes and skip retrying permanent ones18bafff4 fix(frontend): adjust toast text for machine removal02bb8277 fix(frontend): unselect removed machines in machine listd3419f71 test: make the install disk selection test deterministicee6b16d8 test: reserve integration test machines against concurrent allocationeb532093 feat(frontend): improve legibility for unallocated and user partitions2c4940ae fix: drop noisy WireGuard handshake warnings for offline peers89d41856 feat: for talos 1.14 machine reset also wipe cri, kubelet, etcd, loge040a4b6 fix(frontend): use cluster config version for version contract in scale5d948964 fix(frontend): also check version contract in cluster scaledbc458e8 feat(frontend): allow $patch: delete in all places0b5cafaf chore: bump dependencies9e062ebc fix: forbid cluster CA and service account key in config patches3a4771fa feat: rotate the Kubernetes CA on Talos 1.14 multi-doc configs6d67db2a feat: rework discovery service configuration for Talos 1.141cdfd703 fix: track namespaced cluster-scoped manifests as applied7765bab3 feat: validate multi-doc config patches2f4f0f38 feat(frontend): add talos 1.14 variants for frontend generated patches4dcd206a feat: expose more version contract fields202769d7 fix(frontend): use dvh instead of vh for heightd02e7043 feat(frontend): add talos 1.14 schema9cad2579 chore: bump talos machinery03ad541a fix: respect the user's install disk selection in maintenance installsf31cbce0 feat(frontend): redesign manifests status to a graph view126b6b72 refactor(frontend): refactor kubespan canvas to vue-flow4546b096 fix(frontend): trim cluster machine status last_config_error messaged04a0123 feat: for kubespan quick start use correct patch for the clusterd34ecf49 feat(client): allow disabling the transparent watch retry72b942c3 feat: add Auditor role for reading the audit log0a64c818 feat: label Talos Enterprise machinesf7329696 feat: multiple image factories support7873fda7 chore: apply CA, Registry configs before install/upgrade calls53b3c825 feat: support enableNodeAuditSkip in cluster templatesb2b2b205 fix: verify maintenance install/upgrade against the live machine7bc77666 chore: change virtual ImageFactoryAuth resource to be persistent72ffae83 fix(frontend): fix incorrect action on patch delete92215fb7 fix(frontend): preserve whitespace in alerts4edaf8a4 fix: dont include failed/evicted pods for k8s usage dataf5cb97b2 fix(frontend): constrain monitor charts to a fixed size regardless of stateb5cff35b fix(frontend): constrain extensions modals to a fixed size6cea6257 fix(frontend): dont try load auth0 if we arent using auth0 in userinfobed3482d fix(frontend): don't call machineservice.events for maintenance talos on <1.13582730ce chore: bump depsfb2ae3f7 fix: allow SAMLLabelRule to downgrade user role to None7b06af51 fix: mark machines installed when the lifecycle install completes2557f645 chore: rekres73e415be chore(frontend): bump deps87ca0cdf fix(frontend): prevent jumping when select up/down arrows disappear071f1b29 feat: allow disabling config patches526e1c63 feat: support following the audit log over the management APId0824edf fix: support the new discovery service endpoints list of Talos 1.1447b66fdf feat: show infra provider versions in ui and clie23a8f7d feat: do not pre-pull the kube-proxy image on Kubernetes upgradese19f19d1 fix: use initial versions from inputedcc2569 feat: build version aware Kubernetes component patches for upgradesd0642877 feat(frontend): hide pxe boot option for enterprise3187ffad test: fix Omni upgrade workload proxy DNS4e8cc051 fix: ignore not-found errors when deleting an infra provider1476e538 chore: bump talos machinery to v1.14.0-alpha.29d4cfa66 feat(frontend): dim machine stage status when machine is not healthy89eca085 test: run browser e2e tests off the host networkd6bfcee9 feat: serve the frontend dev server through the main endpoint66a7ba2f fix: allow removing the bootstrap spec once the cluster is bootstrappedf75c63db feat: install same-minor maintenance machines via LifecycleServiceff510298 fix: expose the machines cores and virtual state watches metricsdf72b2c3 test: use dex oidc instead of auth0 as default for e2e tests7fcee51e test: poll for minio to come up instead of just sleeping54819dfa test(frontend): remove testing of actual iso download110cf83c refactor: proxy frontend dev server routes using prod flowd62f8c86 chore(frontend): update factory staging url for dev5a751477 feat(frontend): add a /logout route for auth0 logouts9e3f2903 fix(frontend): skip 0 length bars in home segmented charts15b1667d feat(frontend): handle machine services errors gracefullyf161c437 refactor(frontend): make watch failed errors more informative7a2477b4 fix: update kube-service-exposer to v0.4.0d0d7d76d feat: introduce the new metric that counts total number of cores53194783 feat: use LifecycleService for maintenance machine upgradesdb679539 fix: dont clear sa expiration when no keys are left74cb7078 fix: correct boot ID and Talos version tracking for maintenance installs3eab1cc1 fix(frontend): remove an unused @click actionf3f9cd67 refactor(frontend): make all detached scopes lazily loaded2be41995 chore(frontend): bump frontend deps000b1620 fix: honor current machine set update limits2dfe2e5a chore: bump oras-go to 2.6.216265a1a feat(frontend): add word wrap to monaco context menu0a37d509 refactor(frontend): don't create new editor and model instance for schema changes80021712 chore(frontend): add stories for CodeEditore2f57398 fix(frontend): make CodeEditor props reactive561d2582 feat: log audit log access in the audit log0fee0fc3 fix: properly propagate errors coming from the machine lifecycle APIb5450ebf fix: don't treat unset S3 endpoint as an empty overridedaa12686 test(frontend): adjust fake-indexeddb usage which broke in node 24.180618b901 chore(frontend): bump node to 24.185419d707 feat(frontend): show ongoing operations on the home page2afd2223 feat(frontend): use segmented bars for home page stats8b637dc8 chore(frontend): write stories for home page contentdf33497e chore: bump dependenciesa47e7128 feat: add machine log ingestion byte-rate metric7bc30eb0 chore: rekres and bump Go to 1.26.5e05e3285 feat: manage Talos install and upgrade via LifecycleService2ddeca05 fix(frontend): remove power icon from machines paged0535ada feat: expose node audit skip cluster feature809baa68 feat(frontend): persist search and filters as query stringsee432246 refactor(frontend): rename filterLabel to selectLabel in ItemLabelab95b0c3 refactor(frontend): refactor LabelsInput to use v-modele6fa2f14 refactor(frontend): replace removeLabel prop with remove emit5e9ccbd1 refactor(frontend): replace onClear prop with clear emit14ef6113 feat: send initial instance user to signup page84f151fe fix(frontend): handle aborted requests in useMachineServices7e0cf44c feat(frontend): add a quickstart page for kubespan8e8a4675 feat(frontend): standardize machine display in omni2d561020 fix(frontend): prevent item list flash during connection drops655c2ae4 refactor(frontend): move itemID into useResourceWatch8373f536 refactor(frontend): lift interfaces from watch to composable7fb66d5b refactor(frontend): merge watch items into composable37b19c40 refactor(frontend): lift remaining parts of watch class to composable0e7bb6ae refactor(frontend): lift item handlers up to watch composable640014ec refactor(frontend): inline watch callbacks588d21e2 refactor(frontend): remove unnecessary setDescending funcc655f002 refactor(frontend): migrate watch tests to useresourcewatch tests4e4cd5f8 refactor(frontend): move watch.setup into useresourcewatch81c8c2a4 refactor(frontend): merge watchfunc and watch classes together104a8b2a fix(frontend): prevent copying double newlines in machine logsc48c9b92 refactor(frontend): migrate machine set config edit modal to new modal system2adcefe4 refactor(frontend): migrate create extensions modal to new modal systemc435a8f6 refactor(frontend): migrate config patch edit modal to new modal systeme7c34066 refactor(frontend): migrate save preset modal to new modal systema7762559 refactor(frontend): hide primary action when maintenance lifecycle complete971145cc refactor(frontend): migrate download preset modal to new modal systemf9360c2e refactor(frontend): remove unused machine template extensions modal8ee92b37 refactor(frontend): migrate service account renew to new modal system022c458f refactor(frontend): migrate service account create to new modal system7747a322 refactor(frontend): migrate role edit to new modal systemfb9d41f1 refactor(frontend): migrate user destroy to new modal system384a5347 refactor(frontend): migrate user create to new modal systemd6940108 refactor(frontend): migrate machine remove to new modal systeme0626db8 refactor(frontend): migrate machine class destroy to new modal systemdb554082 refactor(frontend): migrate machine set destroy to new modal systeme26d569a refactor(frontend): migrate export cluster template to new modal systemdd5b6255 refactor(frontend): migrate config patch destroy to new modal system7f1bf664 refactor(frontend): migrate infra provider delete to new modal system9bdbeace refactor(frontend): migrate infra provider setup to new modal systemb94b299b refactor(frontend): migrate download omnictl to new modal system542124bc refactor(frontend): migrate node shutdown to new modal systemfe09adc2 refactor(frontend): migrate node destroy cancel to new modal systemd1b56338 refactor(frontend): migrate node destroy to new modal system02f0d112 refactor(frontend): migrate node reboot to new modal system3ddc040e test: fix flaky audit log and service account status testse330092a feat: add pending updates and config gen options to support bundle49c8e725 fix: update COSI runtime to fix hanging TeardownAndDestroy callsc91ce1a5 fix: align config outdated status in ui and clifde089bb refactor(frontend): refactor untaint single node modal to new system094b2591 feat(frontend): add content-class support to confirm modald193dce9 chore: expose user roles in the public package to be used by scripts33aa3fa2 refactor(frontend): replace ua-parser-js with bowser6b2da674 chore(frontend): drop yaml dependency and move openpgp to dependencies27c6aa07 chore: rekres for js sbomed793b6b feat(frontend): add filtering to scan details modal6ef286f2 feat(frontend): add a cluster security page for vulns99a76d47 refactor(frontend): extract components from scan details modal034640bb refactor(frontend): extract business logic from scan details modal2cf7801d refactor(frontend): make use resource list default to empty array120563a3 feat(frontend): stack CPU usage chart areas and format with %77dcbe90 chore: add stories for monitor viewae93d3f9 fix(frontend): only show process args in command columne690d624 fix(frontend): allow in-minor patch upgrades in update kubernetes on Omnib30472e6 refactor: use ImageServiceClient for pulling images1c20cc94 chore: bump helm to v4 in zstd-dict5f4f27df fix: recover a machine from a reverted reboot-requiring config patcheadd5b57 fix(frontend): allow force-destroy when MachineSetNode is already gonefd4e5da4 test(frontend): fix some flaky tests in e2e-talemu1882db15 feat: install/upgrade maintenance-mode Talos during cluster create/scale-up84180bd0 fix: advertise reachable machine API address in cluster-import test937ce3a6 fix: keep maintenance Talos clients until machine leaves maintenancea7b87871 refactor: derive extension list from the raw schematic manifest961a20c6 fix: move timeout for factory requests to controllerse63d4e45 test: drop non-existent preset delete error expectation6f26c409 chore: enrich SBOM with Go module licenses1b337b24 fix: tolerate NotFound on installation media preset deletec2533013 test: stabilize image-factory schematic across CI runs984ba009 feat(frontend): add more visual distinction for offline kubespan peers51cc468d fix: prevent removal of node unique tokens that still have a link88c77c61 fix: validate infra provider name as DNS-1123 label
</p>
</details><details><summary>13 commits</summary> <p>
f03ed02 release(v1.1.0): prepare release373430a feat(stats): add cached /stats endpoint0dc4741 chore: bump prometheus, grpc, and otel deps1479df2 chore: bump net to v0.57.0709d4b9 chore: bump net pkg to v0.55.0 (security)0ce4779 chore: bump sync pkg to v0.22.09628da0 chore: update go.mod deps99b6268 chore: rekres48cf9df chore: bump go to latest 1.26d315a3f chore: fmtf905881 chore: rekres73b90df feat: add support for x-forwaded-for header35804da chore: bump dependencies
</p>
</details><details><summary>1 commit</summary> <p>
c526410 fix: skip unknown-key check for types with custom YAML unmarshaler
</p>
</details><details><summary>3 commits</summary> <p>
0caf1f2 feat: add Kubernetes 1.37 compatibility822b7a2 feat: add nodedrain package for client-side cordon and drain260bc0a fix: update authorization config apiVersion for K8s >= 1.32
</p>
</details><details><summary>21 commits</summary> <p>
efab38f release(v1.4.0): prepare release9c64235 feat: add schematic owner validationca87d23 fix: add single-flight around schematic factoryd45b5ac docs: link to Image Factory Enterprise docs page490a993 chore: bump pkgs revision to match talos v1.14.0-alpha.2f9ff935 chore: bump go pkgs12cd647 feat: add llms.txt for better LLM usagef65960f fix: audit file defaultsf26e5e2 feat: add audit log for authenticated requestsbeff6e2 feat: support registry namespace prefix for core artifacts8c489d0 chore: update dependencies026f8a8 feat: extra extensions (enterprise only)915ef76 chore: add insecure flag to dev config3bccbe1 fix: handle single arch images6b1c855 refactor: prepare for more than one artifact registrybee4fe3 feat: narrow sbom cache key to extension list onlye0e4a44 refactor: abstract versioned cache3359f6c feat: add secureboot enrollKeys schematic option805c51c feat: add per-request correlation ID to logs8cee96d feat: assert pxe cache in tests4ec0789 feat: bump go-conainerregistry
</p>
</details>Previous release can be found at v1.9.0
One column per month.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The installation media wizard's confirmation page now shows SBOM and VEX links plus the vulnerability scan and modal, the same as the Image Factory. T…
Welcome to the v1.9.0-beta.1 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
Cluster templates now support health check jobs that gate Talos upgrades. Omni creates the jobs when a Talos upgrade is running and re-runs them on an interval until they succeed, re-creating a job whenever it fails. The checks run before each node upgrade in the upgrade status controller, and if any defined health check fails Omni drops the available upgrade quota to zero, blocking further upgrades until the checks pass. You can read more about this feature on the docs.
Installation media can now carry an embedded machine configuration, so a machine applies it on first boot before it ever reaches Omni. You can set it from the frontend or with omnictl when creating installation media, and Omni stores it on the schematic request alongside the rest of the media config. The option is exposed only where the underlying stack reports support for it, through a new supports_embedded_config quirk.
You can now throttle etcd writes by payload size, with separate budgets for end users, infra providers, and internal callers. It is off by default and turns on via storage.rateLimits.etcd.*. Four new Prometheus series report throttle wait time, admitted writes, rejected writes, and rejected bytes, labeled by class. The failure counters also carry a reason of timeout or oversize.
Extension names on installation media configs, machine request sets, and extensions configurations are now validated against the Talos extensions catalog for the relevant Talos version. Unknown names, duplicates, and oversized lists are rejected, and when no Talos version is set the default version's catalog is used so the names still get checked. Names without a namespace are looked up under siderolabs/, so older clients that send the documented short form keep working. The omnictl installation media create command now resolves short or partial extension names to canonical form before sending, replacing the client-side catalog check it used to do.
A new graphical view shows KubeSpan peer status for a cluster machine.
A round of UI improvements across Omni. The home screen has a reworked "Welcome to Omni" card. An unhealthy infrastructure provider shows its error on hover, the machine details panel shows the SMBIOS serial number, and kernel args editing moved into a modal. Config diffs have a sort-order toggle, version pickers sort newest first and scroll to the current selection, and Talos and Kubernetes update calls now report their errors. The disks view got several cleanups, pods sort by status, power-state icons have tooltips, Omni shows a loading indicator when it is slow to start, and the rewritten log viewer scrolls to the bottom reliably. Machine patches no longer offer the cluster-machine patch option and surface an error when a machine is not part of a cluster.
The Helm chart has a new service.wireguard.loadBalancerIP value for setting a static load balancer IP on the WireGuard Kubernetes Service. It is rendered only when the WireGuard service type is LoadBalancer.
Two new config options, registries.imageFactoryUsername and registries.imageFactoryPassword, let Omni authenticate to the Image Factory Enterprise with HTTP basic auth.
The frontend now shows the status of a cluster's synced Kubernetes manifests.
Log ingestion now uses a per-machine token bucket, so one noisy machine can no longer overwhelm the log store. It is off by default to keep backwards compatibility.
Omni can now apply machine-level config patches while a machine is still in maintenance mode, not just after it joins a cluster. The patches go on top of the configuration the machine already runs, next to the SideroLink documents Omni manages, and Omni will not apply a document that installs Talos and pulls the machine out of maintenance. Omni also keeps whatever configuration a machine connects with as a low-priority, user-owned patch. So a machine that arrives with its own config (say a TrustedRootsConfig document) keeps it, and your own patches still win.
A new streaming management API installs or upgrades Talos on machines booted in maintenance mode. It comes with omnictl install and upgrade subcommands and frontend modals that stream installer progress live. This feature uses Talos's LifecycleService API, which became available in v1.13.0. So it works with any Talos version starting from v1.13.0.
The installation media wizard's confirmation page now shows SBOM and VEX links plus the vulnerability scan and modal, the same as the Image Factory. This shows up only when you use the Image Factory Enterprise.
The Kubernetes node audit deletes nodes that no ClusterMachine backs. You can now skip it for individual nodes, which helps with virtual nodes such as VirtualKubelet. A node is skipped only when it has the omni.sidero.dev/node-audit-skip annotation and the cluster owner has turned on the matching cluster feature, so a workload cannot annotate its own way out of the audit.
omnictl cluster statusThe omnictl cluster status tree now prints each machine's Kubernetes node name in parentheses after its UUID, so you can match a machine to the upgrade status lines that reference node names. A "Locked" indicator shows up whenever a machine is locked.
Talos PlatformMetadata tags (for example EC2 instance tags) now appear as editable, removable machine labels in Omni. Omni fills them in once, when the machine first joins, and your own custom labels win on any key conflict.
When Omni changes a machine's schematic, it now touches only the fields it manages (extensions and kernel args) and leaves the rest alone, instead of rebuilding the schematic from scratch. It reads the full schematic from the machine or the Image Factory and stores it as is.
Omni releases now ship an SBOM built from the Go modules as a release artifact, and Sidero Labs signs the published container images during release.
Each Omni release now declares the latest Talos minor version it can support end to end. Cluster create and update, the maintenance upgrade API, the upgrade status computation, and every version picker in the UI all read this same cap, so you can no longer pick a Talos version newer than the running Omni supports.
<details><summary>118 commits</summary> <p>
f472356d7 release(v1.9.0-beta.1): prepare release8bea9d98d feat(frontend): add expandable code editor for extra overlay options4121e730f feat(frontend): add expandable code editor for embedded machine config22318022d feat(frontend): add more default editor options and remove default class00e99c4d5 refactor(frontend): refactor code editor to use v-model454daba78 chore: bump default talos version to 1.13.5cb74aa700 feat: support embedded machine config in installation media CLI86af10d45 fix: get rid of the race in the UUID conflict resolution flow55bda4979 refactor: only log schematic id when ensuringc2b067a1f feat(frontend): allow specifying embedded machine config for installation media574daf6d5 feat: add embedded_machine_config to create schematic request1a8c85b88 feat: add embedded_machine_config to installation media config spec687e56ae1 feat: add supports_embedded_config quirk to virtual resources2fa8855c6 feat: validate Talos extensions against the catalog807fe47a7 feat: register destroy controllers for user-managed resource typesc3c511acb chore: bump containerd to 1.7.33af44779ae chore(frontend): bump dependencies17b2b30ec fix: prevent API requests from hanging after idle periods240c48323 feat(frontend): remove cluster machine patch option from machine patches498e8c0b4 feat(frontend): show error if machine not part of clustera66f1ae3a feat(frontend): use machine status link snapshot for recent machines phase0f853e1bb release(v1.9.0-beta.0): prepare release060a4c759 chore: bump deps and default versions43bf5856e test: run integration-qemu against the image factory enterprise4b49029cb feat: support machine config patches in maintenance modeb9e407174 fix: stabilize flaky talemu e2e EULA setup and preset downloads448ed9a69 docs: update LICENSEb44f92efe fix: ignore the embedded-config meta extensione32307d8e fix: allow empty list of extensions in cluster templatesb08c34ac8 feat: implement advanced healthchecks for the cluster1c125d3f4 chore: add Oguz to sops-encrypted secrets recipients9a736342d fix: properly handle invalid UTF-8 strings in the machine statusesd77ee0495 fix: properly handle empty provider data in the common modulec55173efc feat: validate Talos version on installation media config243f046e0 fix(frontend): display correct units for byte valuesd9eebd7c4 fix(frontend): reset monitor chart on watch change7f02f41f3 chore(frontend): bump frontend dependencies27ef3dd03 feat: install/upgrade Talos in maintenance mode18131edfd feat(frontend): change machine tutorial into a welcome card4fdc07191 feat(frontend): adjust action buttons on getting started card987b3ec18 feat: reject control characters in join token names8bfc6c17d fix(frontend): fix incorrect pxe boot urlead9840b7 feat: validate user-supplied request IDs and kernel args1ebde6a44 feat: validate bootstrap snapshot path on machine sets1ff045796 feat: allow opt-in skip of Kubernetes node audit50dcd264c feat: validate resource metadata at the state layer086a1964c feat: preserve schematic contents1ab0c4e32 feat(frontend): display infrastructure provider error when unhealthy5c67c7c9b fix: read machine uncached when deciding whether to reset it098dac2c3 refactor: remove unused fields, fix print columns/comments of resourcesa29fba498 fix: use correct help string in the omnictl jointoken delete command9505aabec feat(frontend): add kubespan status viewd19768879 refactor: replace injectable clocks with real timeb5be9a779 fix: prune expired public keys with finalizers or no owner64b02f4f6 feat: cap Talos upgrade targets at the latest supported releasea1367d90e feat: per-machine log ingestion rate limitbc0e5273b refactor: move state validations into their own package33909b1b9 fix: keep exposed services reachable after a health check flap84649427b feat(helm): support loadBalancerIP for WireGuard service4db447046 fix: release config update slot while a machine waits to upgradee63ea1f0e feat: add PostHog analytics to the Omni frontend5b5203660 chore: bump major go dependencies48a7f9394 fix: persist config status when update lock is contended59d9079c7 refactor(frontend): remove last cases of any in codebase665371f3a refactor: drop unused field in create schematic gRPC requestc2f52d799 fix: prevent deadlock between machine upgrade and config update861594332 feat: nest omnictl, talosctl, scans under apif144020c0 feat(frontend): show vulnerability items on installation media wizard68afcd086 chore: rekresb3e038f8d feat(frontend): generate talos types for frontend0610a4088 refactor(frontend): type tlist items4afaf514b refactor(frontend): drop watchjoin998e803ec chore: bump go-kubernetes libraryccbc50bda feat(omnictl): show node name and locked status in cluster status3edf383b6 chore: bump deps, rekres, Talos 1.13.3, Kubernetes 1.36.1429708f84 feat(frontend): show join tokens in saved presets listc857af939 feat(frontend): enable field-sizing content for kernel argsf62e044aa feat(frontend): show errors for all update talos/k8s issues7ddd63b1a feat(frontend): sort upgrade modal versions descending and scroll to selectedffcbf3342 refactor(frontend): refactor update talos + k8s to new modals9248b762b test: mock clock in saml testd18726e9c fix: lower minimum discovered Kubernetes version2dd7c8807 test: pick previous Omni upgrade version from the release line2bfe8c08a chore: rekres and bump frontend deps3b9399fba fix: do not downgrade nodes header to single node15ad495ad test: bump Talos to 1.13.325f5de5c6 feat(frontend): allow changing config diff sort order0f060a449 feat(frontend): add improvements to disks viewe297c4d47 fix: hack/compose dlv tools install1704f0047 chore(hack): add delve debugger support30d5d2868 test: use up-to-date way to set node labels on the nodes in the tests72dfce9e5 fix(frontend): remove lingering test code028a57e84 feat(frontend): move editing logic for kernel args into a modal76ee6332f feat(frontend): add tooltips to power state329922816 feat: refactor logviewer to tanstack virtual1fafd3781 chore: bump dependencies988bc9e81 chore: add missing syft version to kres065db6960 test(integration): bump readiness timeout durationsfc362b5fc feat: expose ec2 tags as machine labels6d61a546e feat: add sign-images target to sign omni container image34473a7f5 feat: generate SBOM as a release artifactfa2f11fc0 fix: fetch versions from registry with auth0a2641c6c chore: bump deps to patch GO-2026-5027ddfa70a9c feat: add per-class etcd write-bytes rate limiting69e4fe255 feat(frontend): add some feedback when omni is loading5246ba332 fix: ensure infra providers with new common module support the old Omni9ae983308 feat(frontend): sort pods by status on pods listc8daa7805 fix(frontend): fix incorrect permissions-policy header7484972df feat(frontend): load robot fonts from npmbb442ab7e feat: add teardown RPCs and tighten state API accessc1126b471 chore: fix linter issues120be2f10 chore: rekres to secure slack workflows686249525 fix: dont clean clients with active watches679ca3014 feat: support basic auth against the image factory2ce7140ec feat: introduce UI for showing Kubernetes manifests status of clustersc990a0820 feat(frontend): change service finished state style to gray1b9177ee8 feat(frontend): show smbios serial info on machine details panel9dd6cb490 refactor: drop compose 'version' (from hack)
</p>
</details><details><summary>21 commits</summary> <p>
f472356d release(v1.9.0-beta.1): prepare release8bea9d98 feat(frontend): add expandable code editor for extra overlay options4121e730 feat(frontend): add expandable code editor for embedded machine config22318022 feat(frontend): add more default editor options and remove default class00e99c4d refactor(frontend): refactor code editor to use v-model454daba7 chore: bump default talos version to 1.13.5cb74aa70 feat: support embedded machine config in installation media CLI86af10d4 fix: get rid of the race in the UUID conflict resolution flow55bda497 refactor: only log schematic id when ensuringc2b067a1 feat(frontend): allow specifying embedded machine config for installation media574daf6d feat: add embedded_machine_config to create schematic request1a8c85b8 feat: add embedded_machine_config to installation media config spec687e56ae feat: add supports_embedded_config quirk to virtual resources2fa8855c feat: validate Talos extensions against the catalog807fe47a feat: register destroy controllers for user-managed resource typesc3c511ac chore: bump containerd to 1.7.33af44779a chore(frontend): bump dependencies17b2b30e fix: prevent API requests from hanging after idle periods240c4832 feat(frontend): remove cluster machine patch option from machine patches498e8c0b feat(frontend): show error if machine not part of clustera66f1ae3 feat(frontend): use machine status link snapshot for recent machines phase
</p>
</details><details><summary>1 commit</summary> <p>
07009e7 chore: bump deps, update gopenpgp to v3
</p>
</details><details><summary>2 commits</summary> <p>
cc8c2c9 fix: return the apply results in a consistent order131a2bd fix: handle cluster-scoped resources with a ns correctly
</p>
</details><details><summary>2 commits</summary> <p>
59d47af feat: rewrite support bundle library around client provider8dd4326 feat: support encryption of the support bundle using age
</p>
</details><details><summary>26 commits</summary> <p>
425e59e release(v1.3.3): prepare releaseb5d3d92 fix: vulnerability scans with extensions916bcf6 feat: update go-vex9920386 feat: update Image Factory with Talos 1.14.0-alpha.1d49e952 feat: allow excluding Talos releases147a3e8 feat: add scan report to factory client2887e78 feat: add support for embedding machine configuration660ac01 release(v1.3.2): prepare release38183fc fix: update golang.org/x/net9f6aee8 fix: make PXE copyable on SecureBootd7377c5 refactor: migrate to Tailwind CSS classes1e86750 fix: update golang.org/x/* packages33c79e4 test: move from kuttl to chainsawba34dab feat: move SPDX cache to enterprise optionscd137ed chore: disable authentication for local development4ea792f fix: build profile with versionfcf9d57 release(v1.3.1): prepare release1d216c7 docs: update the developing documentation4a60270 fix(config): validate early and sort SPDX deterministically41d3947 release(v1.3.0): prepare releaseae3ed04 feat: add enterprise features with Helm chart support3fb0f96 feat(enterprise): add vulnerability scanning endpoint92209b6 feat: return normalized schematic on creationba2a46d feat(enterprise): implement VEX endpoint9b40156 feat: show schematic-id url parameter on the final wizard step114bb60 fix(spdx): use configured external URL in document namespace
</p>
</details>Previous release can be found at v1.8.0
Nothing published for this version
Nothing published for this version
The installation media wizard's confirmation page now shows SBOM and VEX links plus the vulnerability scan and modal, the same as the Image Factory. T…
Welcome to the v1.9.0-beta.0 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
You can now throttle etcd writes by payload size, with separate budgets for end users, infra providers, and internal callers. It is off by default and turns on via storage.rateLimits.etcd.*. Four new Prometheus series report throttle wait time, admitted writes, rejected writes, and rejected bytes, labeled by class. The failure counters also carry a reason of timeout or oversize.
A new graphical view shows KubeSpan peer status for a cluster machine.
A round of UI improvements across Omni. The home screen has a reworked "Welcome to Omni" card. An unhealthy infrastructure provider shows its error on hover, the machine details panel shows the SMBIOS serial number, and kernel args editing moved into a modal. Config diffs have a sort-order toggle, version pickers sort newest first and scroll to the current selection, and Talos and Kubernetes update calls now report their errors. The disks view got several cleanups, pods sort by status, power-state icons have tooltips, Omni shows a loading indicator when it is slow to start, and the rewritten log viewer scrolls to the bottom reliably.
The Helm chart has a new service.wireguard.loadBalancerIP value for setting a static load balancer IP on the WireGuard Kubernetes Service. It is rendered only when the WireGuard service type is LoadBalancer.
Two new config options, registries.imageFactoryUsername and registries.imageFactoryPassword, let Omni authenticate to the Image Factory Enterprise with HTTP basic auth.
The frontend now shows the status of a cluster's synced Kubernetes manifests.
Log ingestion now uses a per-machine token bucket, so one noisy machine can no longer overwhelm the log store. It is off by default to keep backwards compatibility.
Omni can now apply machine-level config patches while a machine is still in maintenance mode, not just after it joins a cluster. The patches go on top of the configuration the machine already runs, next to the SideroLink documents Omni manages, and Omni will not apply a document that installs Talos and pulls the machine out of maintenance. Omni also keeps whatever configuration a machine connects with as a low-priority, user-owned patch. So a machine that arrives with its own config (say a TrustedRootsConfig document) keeps it, and your own patches still win.
A new streaming management API installs or upgrades Talos on machines booted in maintenance mode. It comes with omnictl install and upgrade subcommands and frontend modals that stream installer progress live. This feature uses Talos's LifecycleService API, which became available in v1.13.0. So it works with any Talos version starting from v1.13.0.
The installation media wizard's confirmation page now shows SBOM and VEX links plus the vulnerability scan and modal, the same as the Image Factory. This shows up only when you use the Image Factory Enterprise.
The Kubernetes node audit deletes nodes that no ClusterMachine backs. You can now skip it for individual nodes, which helps with virtual nodes such as VirtualKubelet. A node is skipped only when it has the omni.sidero.dev/node-audit-skip annotation and the cluster owner has turned on the matching cluster feature, so a workload cannot annotate its own way out of the audit.
omnictl cluster statusThe omnictl cluster status tree now prints each machine's Kubernetes node name in parentheses after its UUID, so you can match a machine to the upgrade status lines that reference node names. A "Locked" indicator shows up whenever a machine is locked.
Talos PlatformMetadata tags (for example EC2 instance tags) now appear as editable, removable machine labels in Omni. Omni fills them in once, when the machine first joins, and your own custom labels win on any key conflict.
When Omni changes a machine's schematic, it now touches only the fields it manages (extensions and kernel args) and leaves the rest alone, instead of rebuilding the schematic from scratch. It reads the full schematic from the machine or the Image Factory and stores it as is.
Omni releases now ship an SBOM built from the Go modules as a release artifact, and Sidero Labs signs the published container images during release.
Each Omni release now declares the latest Talos minor version it can support end to end. Cluster create and update, the maintenance upgrade API, the upgrade status computation, and every version picker in the UI all read this same cap, so you can no longer pick a Talos version newer than the running Omni supports.
<details><summary>96 commits</summary> <p>
060a4c759 chore: bump deps and default versions43bf5856e test: run integration-qemu against the image factory enterprise4b49029cb feat: support machine config patches in maintenance modeb9e407174 fix: stabilize flaky talemu e2e EULA setup and preset downloads448ed9a69 docs: update LICENSEb44f92efe fix: ignore the embedded-config meta extensione32307d8e fix: allow empty list of extensions in cluster templatesb08c34ac8 feat: implement advanced healthchecks for the cluster1c125d3f4 chore: add Oguz to sops-encrypted secrets recipients9a736342d fix: properly handle invalid UTF-8 strings in the machine statusesd77ee0495 fix: properly handle empty provider data in the common modulec55173efc feat: validate Talos version on installation media config243f046e0 fix(frontend): display correct units for byte valuesd9eebd7c4 fix(frontend): reset monitor chart on watch change7f02f41f3 chore(frontend): bump frontend dependencies27ef3dd03 feat: install/upgrade Talos in maintenance mode18131edfd feat(frontend): change machine tutorial into a welcome card4fdc07191 feat(frontend): adjust action buttons on getting started card987b3ec18 feat: reject control characters in join token names8bfc6c17d fix(frontend): fix incorrect pxe boot urlead9840b7 feat: validate user-supplied request IDs and kernel args1ebde6a44 feat: validate bootstrap snapshot path on machine sets1ff045796 feat: allow opt-in skip of Kubernetes node audit50dcd264c feat: validate resource metadata at the state layer086a1964c feat: preserve schematic contents1ab0c4e32 feat(frontend): display infrastructure provider error when unhealthy5c67c7c9b fix: read machine uncached when deciding whether to reset it098dac2c3 refactor: remove unused fields, fix print columns/comments of resourcesa29fba498 fix: use correct help string in the omnictl jointoken delete command9505aabec feat(frontend): add kubespan status viewd19768879 refactor: replace injectable clocks with real timeb5be9a779 fix: prune expired public keys with finalizers or no owner64b02f4f6 feat: cap Talos upgrade targets at the latest supported releasea1367d90e feat: per-machine log ingestion rate limitbc0e5273b refactor: move state validations into their own package33909b1b9 fix: keep exposed services reachable after a health check flap84649427b feat(helm): support loadBalancerIP for WireGuard service4db447046 fix: release config update slot while a machine waits to upgradee63ea1f0e feat: add PostHog analytics to the Omni frontend5b5203660 chore: bump major go dependencies48a7f9394 fix: persist config status when update lock is contended59d9079c7 refactor(frontend): remove last cases of any in codebase665371f3a refactor: drop unused field in create schematic gRPC requestc2f52d799 fix: prevent deadlock between machine upgrade and config update861594332 feat: nest omnictl, talosctl, scans under apif144020c0 feat(frontend): show vulnerability items on installation media wizard68afcd086 chore: rekresb3e038f8d feat(frontend): generate talos types for frontend0610a4088 refactor(frontend): type tlist items4afaf514b refactor(frontend): drop watchjoin998e803ec chore: bump go-kubernetes libraryccbc50bda feat(omnictl): show node name and locked status in cluster status3edf383b6 chore: bump deps, rekres, Talos 1.13.3, Kubernetes 1.36.1429708f84 feat(frontend): show join tokens in saved presets listc857af939 feat(frontend): enable field-sizing content for kernel argsf62e044aa feat(frontend): show errors for all update talos/k8s issues7ddd63b1a feat(frontend): sort upgrade modal versions descending and scroll to selectedffcbf3342 refactor(frontend): refactor update talos + k8s to new modals9248b762b test: mock clock in saml testd18726e9c fix: lower minimum discovered Kubernetes version2dd7c8807 test: pick previous Omni upgrade version from the release line2bfe8c08a chore: rekres and bump frontend deps3b9399fba fix: do not downgrade nodes header to single node15ad495ad test: bump Talos to 1.13.325f5de5c6 feat(frontend): allow changing config diff sort order0f060a449 feat(frontend): add improvements to disks viewe297c4d47 fix: hack/compose dlv tools install1704f0047 chore(hack): add delve debugger support30d5d2868 test: use up-to-date way to set node labels on the nodes in the tests72dfce9e5 fix(frontend): remove lingering test code028a57e84 feat(frontend): move editing logic for kernel args into a modal76ee6332f feat(frontend): add tooltips to power state329922816 feat: refactor logviewer to tanstack virtual1fafd3781 chore: bump dependencies988bc9e81 chore: add missing syft version to kres065db6960 test(integration): bump readiness timeout durationsfc362b5fc feat: expose ec2 tags as machine labels6d61a546e feat: add sign-images target to sign omni container image34473a7f5 feat: generate SBOM as a release artifactfa2f11fc0 fix: fetch versions from registry with auth0a2641c6c chore: bump deps to patch GO-2026-5027ddfa70a9c feat: add per-class etcd write-bytes rate limiting69e4fe255 feat(frontend): add some feedback when omni is loading5246ba332 fix: ensure infra providers with new common module support the old Omni9ae983308 feat(frontend): sort pods by status on pods listc8daa7805 fix(frontend): fix incorrect permissions-policy header7484972df feat(frontend): load robot fonts from npmbb442ab7e feat: add teardown RPCs and tighten state API accessc1126b471 chore: fix linter issues120be2f10 chore: rekres to secure slack workflows686249525 fix: dont clean clients with active watches679ca3014 feat: support basic auth against the image factory2ce7140ec feat: introduce UI for showing Kubernetes manifests status of clustersc990a0820 feat(frontend): change service finished state style to gray1b9177ee8 feat(frontend): show smbios serial info on machine details panel9dd6cb490 refactor: drop compose 'version' (from hack)
</p>
</details><details><summary>1 commit</summary> <p>
07009e7 chore: bump deps, update gopenpgp to v3
</p>
</details><details><summary>2 commits</summary> <p>
cc8c2c9 fix: return the apply results in a consistent order131a2bd fix: handle cluster-scoped resources with a ns correctly
</p>
</details><details><summary>2 commits</summary> <p>
59d47af feat: rewrite support bundle library around client provider8dd4326 feat: support encryption of the support bundle using age
</p>
</details><details><summary>26 commits</summary> <p>
425e59e release(v1.3.3): prepare releaseb5d3d92 fix: vulnerability scans with extensions916bcf6 feat: update go-vex9920386 feat: update Image Factory with Talos 1.14.0-alpha.1d49e952 feat: allow excluding Talos releases147a3e8 feat: add scan report to factory client2887e78 feat: add support for embedding machine configuration660ac01 release(v1.3.2): prepare release38183fc fix: update golang.org/x/net9f6aee8 fix: make PXE copyable on SecureBootd7377c5 refactor: migrate to Tailwind CSS classes1e86750 fix: update golang.org/x/* packages33c79e4 test: move from kuttl to chainsawba34dab feat: move SPDX cache to enterprise optionscd137ed chore: disable authentication for local development4ea792f fix: build profile with versionfcf9d57 release(v1.3.1): prepare release1d216c7 docs: update the developing documentation4a60270 fix(config): validate early and sort SPDX deterministically41d3947 release(v1.3.0): prepare releaseae3ed04 feat: add enterprise features with Helm chart support3fb0f96 feat(enterprise): add vulnerability scanning endpoint92209b6 feat: return normalized schematic on creationba2a46d feat(enterprise): implement VEX endpoint9b40156 feat: show schematic-id url parameter on the final wizard step114bb60 fix(spdx): use configured external URL in document namespace
</p>
</details>Previous release can be found at v1.8.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
omnictl cluster template has breaking changes: it now restricts including files outside of the current directory. If using files in the parent dirs, o…
Welcome to the v1.8.0-beta.1 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
As Omni is now using --join-tokens-mode=legacyAllowed by default it won't start if there are any nodes running Talos below 1.6 connected to the instance.
If you want to keep using Omni with the outdated Talos you will need to set the flag to legacy. But of course we strongly recommend you to update Talos ASAP.
omnictl cluster template has breaking changes: it now restricts including files outside of the current directory.
If using files in the parent dirs, old behavior can be enabled by using --allowed-dir.
Audit logs gain a generic search box and sortable columns in the UI, plus CLI filters for event_type, resource_type, resource_id, cluster_id, and actor.
New omni_etcd_operations_total and omni_etcd_resource_bytes_total Prometheus counters track etcd writes, split by operation (create/update/teardown/destroy), actor (internal/user/service account/infra provider), actor ID, and resource type. Byte sizes are captured from the actual on-disk payload via a new WithObserver hook in state-etcd.
The frontend now shows disks and devices on the machines and individual machine pages.
The installation media wizard's Talos version text has been updated for clarity.
The logs tab now allows switching between log sources directly inside the tab.
The frontend allows quickly switching between machines within a cluster from the machine detail view.
Omni notifications are now shown in the UI as dismissible banners.
The cluster machine page gains a copy-UUID button, the machines list page can toggle between hostnames and UUIDs (with the preference saved), and machine and cluster machine pages gain kernel args tabs for editing kernel arguments inline instead of through a modal.
The frontend now allows re-saving a previously generated Omni support bundle without regenerating it.
A new support modal in the frontend exposes links to GitHub issues, support channels, documentation, community resources, and office hours.
A new helmvaluesgen tool, run on make generate, updates the config: section of the Helm chart's values.yaml from Omni's config schema, applying chart-specific overrides for defaults, omissions, and descriptions.
Omni no longer proxies legacy installation media download requests to the Talos Image Factory. Such requests are now rejected with a message asking users to upgrade omnictl, which downloads installation media directly from the factory.
Infra provider Image Factory requests can now be proxied through Omni via a new schematic creation API that accepts raw YAML. This is useful when Omni holds authentication for the Image Factory or when multiple Image Factory endpoints need to be supported.
A new controller tears down ImportedClusterSecrets once their content has been copied into ClusterSecrets and marked Imported=true, so imported bootstrap material does not linger in the state after a successful import.
Infra providers now use the Image Factory endpoint configured in Omni's features state (sourced from args/config) instead of a hardcoded default. The configured factory URL is exposed on the provider.
InstallationMediaConfig now accepts empty strings for talosVersion and joinToken, which resolve to the current stable version and default token at download time. The create wizard exposes "Automatic" options for these fields, and the download modal shows version/token/arch pickers for all presets.
Users with the reader role can now read join tokens. Reader had access to it before through Talos logs, so making the access more consistent. More fine grained access will come with RBAC v2 later on.
The omni-kube-service-exposer.sidero.dev/port annotation now accepts a comma-separated list of host-port or host-port:service-port entries, each producing its own ExposedService URL. Label, icon, and prefix annotations gain per-host-port suffixed variants (e.g. label-30080). Existing single-port exposed services keep their URLs across the upgrade.
Omni's log level and log format are now configurable via flags and config.
A new Error field on ClusterMachineRequestStatus surfaces provision step failures so users can see why a request is stuck without scraping logs. Errors are now persisted on both failure and requeue paths.
omnictl media Command GroupA new omnictl media preset {create,list,delete} command group manages InstallationMediaConfig presets from the CLI, and omnictl media download <preset> downloads from them. Preset validation runs against the server's CloudPlatformConfig, SBCConfig, and TalosExtensions resources at create time. The legacy omnictl download is preserved but deprecated.
The frontend now uses plain browser download links for factory image downloads instead of intercepting them.
Machines that are shut down now appear as "Powered Off" in the UI instead of being stuck in "Shutting Down" with a greyed-out unreachable state. Static infra providers honor the shutdown until the machine goes through a deallocation cycle, instead of automatically powering it back on. The CLI gains omnictl machine shutdown and omnictl machine power-on commands.
Service account key listings now include per-key creation timestamps and last-active times. omnictl serviceaccount list shows KEY CREATED and KEY LAST ACTIVE columns alongside the existing SA-level LAST ACTIVE. A new PublicKeyLastActive resource backs this tracking, and the activity interceptor records last-used timestamps per signing key fingerprint.
omnictl serviceaccount create OutputThe output of omnictl serviceaccount create is now commented out by default, making it friendlier for piping into .env files and shell automation.
Omni now tracks machines running Talos versions approaching or past end of support relative to MinTalosVersion, emits two new notifications (approaching end of support, end of support reached), and exposes Prometheus metrics for both.
talosctl From Factorytalosctl binaries are now downloaded directly from the Talos Image Factory instead of GitHub.
By default, cluster templates can only include files from the same directory as the template file. This prevents malicious templates from including arbitrary files like /etc/passwd. The previous behavior can be restored with --allowed-dir.
Inline fields for manifests and config patches now accept three forms: a single inline map (for backward compatibility), a list of inline maps, or raw bytes (which may contain multiple YAML documents). omnictl cluster template export now exports patches and manifests as raw bytes so multi-document values round-trip correctly.
omnictl cluster template commands now resolve patch and Kubernetes manifest includes relative to the template YAML file, rather than the current working directory of omnictl.
<details><summary>81 commits</summary> <p>
b5e5e86e refactor: update minio env names5a894a21 chore: update helm README with new install instructions4fe2a67f chore: rekres, bump deps and default versions6fab9972 release(v1.8.0-beta.0): prepare releaseac81e59f feat: collect ClusterKubernetesManifestStatus in the support bundles64a1d536 fix: wrong role promotion for some etcd APIs7cc7e181 test: fix workload proxy integration test for upgrade scenario2c8b1789 feat: add per-actor etcd write metrics49322f05 feat: use plain download links for image downloads01742e71 feat: add log level and format configuration7fb5b164 chore: bump depscab06214 feat(frontend): allow switching logs inside logs tabc890ecec refactor(frontend): move node logs logic into machinelogscontainer75cdb09f refactor(frontend): extra machine service list into a composable9f1bb2fa docs: add COSI resource operations in API usage examples13c3f289 fix: add more input validations to management APIced79da6 fix: consume SAML sessions once7b72ac64 chore(frontend): bump dependenciesed7738b3 fix: do not panic is ssa apply with multi-version CRDse08e566d feat: destroy imported cluster secrets after bundle is consumedd01a6f66 fix(frontend): keep machine details open when switching25fa9e14 fix: change ImportedClusterSecrets access level to operator39ee2f01 feat: proxy image factory requests done by the providers through Omnie7aee25c test(frontend): add e2e tests for join tokens in frontende6be461c fix(frontend): add apexcharts formatter workaroundba6205f5 fix(frontend): fix apexcharts broken tooltips and initial stateaddf6624 feat: add omnictl media command group with preset support110be565 feat: expose provision step errors on machine request status699ebf70 fix(frontend): fix revoking/deleting join tokens1f4f2afa feat: allow exposing a Kubernetes service on multiple host ports75e881fc feat: resolve patches/kubernetes manifests relative to the templates dire9b71f0b fix(frontend): only show machine patches for currently visible machinea524554c fix(frontend): fix editing labels on machine classc14ee101 refactor(frontend): refactor all but the last tlist use of watch.setup56cce45e chore(frontend): bump node to 24.15.07989c3c0 test: fix data race in machine service mockc141613d fix: fix the storm of PendingUpdateStatus create/destroya43407d0 feat: generate config section of helm chart values from config schema0cdb5a58 feat: support raw bytes in the inline fields for manifests/patches14b83e12 feat: set infra provider factory endpoint to the one configured in omniefbd089f feat(frontend): add qol machine updates to omni frontend2fe716d2 chore: enable go linting for build tags, fix linting errors718d61a6 chore(frontend): bump dependenciesd3592671 feat: download talosctl directly from factoryb2671d08 refactor(frontend): create downloadfile helperdc9baca8 refactor(frontend): refactor downloadtalosctl modal to new modal system06d8140d feat: add join token/talos version placeholders in installation media5f4b9761 fix: bring back election campaign resign code in the etcd state03c4e1d9 fix: stop logging Kubernetes read checksdc3b974d fix: remove workload proxy deployment when disabled on the account65af568b fix: skip allocating nodes for deleted/tearing down MachineRequestsf9dd8491 feat: introduce powered off machine state and power on support921389a5 fix(frontend): fix eula handling to prevent being stuck on /eula725f41d4 fix: properly display service account expiration time in the UIc5a43105 feat(frontend): add support modal to omni66383890 feat(frontend): show disks and devices in machines/machine page1e31079e fix(frontend): fix indeterminate state for update extensions modal6d7e4f45 feat(frontend): allow quickly switching between cluster machinesc98b1187 fix(frontend): clear page state when keys are clearedf89955b4 refactor(frontend): remove last use of <watch> componentbe67f710 feat: allow reader access to join tokenf2211688 chore: bump deps475e3660 feat: add Talos version end-of-support notifications and metrics302e9175 feat: comment serviceaccount create output967c229e chore: rekres to update to new kres schemaedbb621a chore: bump stripe-go to v85cc0adefc fix(frontend): select default join token in installation media wizard0987fa9e chore: prepare omni with talos v1.13.0-rc73a06f89 chore: bump talos machinery78544a85 feat: restrict directories for included files in the cluster templatesa3fd0b1c feat(frontend): allow re-saving omni support bundle5c4a6b57 feat: remove image factory proxyingdc5e289c feat(frontend): show notifications in the frontend9fd6e9e1 fix(frontend): open external eula link in a new tab8c23f72e chore: bump deps2e9d00a6 chore: make Omni use join tokens mode legacyAllowed by default488b020b feat: add more filters to audit logs590ea2e3 feat: add per-key creation and last-active tracking for service accounts44b0d636 chore: bump deps186f02b4 chore(frontend): bump frontend dependencies57216254 feat(frontend): update talos version text on installation media wizard
</p>
</details><details><summary>3 commits</summary> <p>
b5e5e86e refactor: update minio env names5a894a21 chore: update helm README with new install instructions4fe2a67f chore: rekres, bump deps and default versions
</p>
</details><details><summary>2 commits</summary> <p>
38c182f fix: normalize the changeset to be keyed without apiVersionca35008 feat: update k8s api to 0.36.0
</p>
</details><details><summary>22 commits</summary> <p>
ccffefc release(v1.2.0): prepare release4abeff4 feat: add /talosctl/:version endpoint to list downloadable talosctls405b488 feat(i18n): add french localec6ad082 feat(registry): resolve latest tag to stable version471706d chore: drop update to talos main tests403cd5a fix: centralize schematic ownership enforcementf1cceee feat: implement authentication support81f9312 release(v1.1.0): prepare release1b834b7 feat: add SHA-256 and SHA-512 checksum frontende775c36 feat: upgrade tailwind to v4bb27d39 feat: update Talos to v1.13.0-rc.02a59890 fix: gsa signer pull during verifyfbc302f fix: support insecure registries for signature bundles8e7d10e feat: add support for google service account signing74afd80 fix: set correct Content-Type when downloading images8372fe8 feat: add SPDX frontendb379bf2 feat: switch schematic cache to LRU and negative TTL0450038 chore: remove deuplicate k8s-down ci step470cb2f chore: switch to large runners713fc6e fix: memory usage when building images0a25274 fix: excessive memory usage0f9eb22 feat: update machinery doc links
</p>
</details>Previous release can be found at v1.7.0
omnictl cluster template has breaking changes: it now restricts including files outside of the current directory. If using files in the parent dirs, o…
Welcome to the v1.8.0-beta.0 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
As Omni is now using --join-tokens-mode=legacyAllowed by default it won't start if there are any nodes running Talos below 1.6 connected to the instance.
If you want to keep using Omni with the outdated Talos you will need to set the flag to legacy. But of course we strongly recommend you to update Talos ASAP.
omnictl cluster template has breaking changes: it now restricts including files outside of the current directory.
If using files in the parent dirs, old behavior can be enabled by using --allowed-dir.
Audit logs gain a generic search box and sortable columns in the UI, plus CLI filters for event_type, resource_type, resource_id, cluster_id, and actor.
New omni_etcd_operations_total and omni_etcd_resource_bytes_total Prometheus counters track etcd writes, split by operation (create/update/teardown/destroy), actor (internal/user/service account/infra provider), actor ID, and resource type. Byte sizes are captured from the actual on-disk payload via a new WithObserver hook in state-etcd.
The frontend now shows disks and devices on the machines and individual machine pages.
The installation media wizard's Talos version text has been updated for clarity.
The logs tab now allows switching between log sources directly inside the tab.
The frontend allows quickly switching between machines within a cluster from the machine detail view.
Omni notifications are now shown in the UI as dismissible banners.
The cluster machine page gains a copy-UUID button, the machines list page can toggle between hostnames and UUIDs (with the preference saved), and machine and cluster machine pages gain kernel args tabs for editing kernel arguments inline instead of through a modal.
The frontend now allows re-saving a previously generated Omni support bundle without regenerating it.
A new support modal in the frontend exposes links to GitHub issues, support channels, documentation, community resources, and office hours.
A new helmvaluesgen tool, run on make generate, updates the config: section of the Helm chart's values.yaml from Omni's config schema, applying chart-specific overrides for defaults, omissions, and descriptions.
Omni no longer proxies legacy installation media download requests to the Talos Image Factory. Such requests are now rejected with a message asking users to upgrade omnictl, which downloads installation media directly from the factory.
Infra provider Image Factory requests can now be proxied through Omni via a new schematic creation API that accepts raw YAML. This is useful when Omni holds authentication for the Image Factory or when multiple Image Factory endpoints need to be supported.
A new controller tears down ImportedClusterSecrets once their content has been copied into ClusterSecrets and marked Imported=true, so imported bootstrap material does not linger in the state after a successful import.
Infra providers now use the Image Factory endpoint configured in Omni's features state (sourced from args/config) instead of a hardcoded default. The configured factory URL is exposed on the provider.
InstallationMediaConfig now accepts empty strings for talosVersion and joinToken, which resolve to the current stable version and default token at download time. The create wizard exposes "Automatic" options for these fields, and the download modal shows version/token/arch pickers for all presets.
Users with the reader role can now read join tokens. Reader had access to it before through Talos logs, so making the access more consistent. More fine grained access will come with RBAC v2 later on.
The omni-kube-service-exposer.sidero.dev/port annotation now accepts a comma-separated list of host-port or host-port:service-port entries, each producing its own ExposedService URL. Label, icon, and prefix annotations gain per-host-port suffixed variants (e.g. label-30080). Existing single-port exposed services keep their URLs across the upgrade.
Omni's log level and log format are now configurable via flags and config.
A new Error field on ClusterMachineRequestStatus surfaces provision step failures so users can see why a request is stuck without scraping logs. Errors are now persisted on both failure and requeue paths.
omnictl media Command GroupA new omnictl media preset {create,list,delete} command group manages InstallationMediaConfig presets from the CLI, and omnictl media download <preset> downloads from them. Preset validation runs against the server's CloudPlatformConfig, SBCConfig, and TalosExtensions resources at create time. The legacy omnictl download is preserved but deprecated.
The frontend now uses plain browser download links for factory image downloads instead of intercepting them.
Machines that are shut down now appear as "Powered Off" in the UI instead of being stuck in "Shutting Down" with a greyed-out unreachable state. Static infra providers honor the shutdown until the machine goes through a deallocation cycle, instead of automatically powering it back on. The CLI gains omnictl machine shutdown and omnictl machine power-on commands.
Service account key listings now include per-key creation timestamps and last-active times. omnictl serviceaccount list shows KEY CREATED and KEY LAST ACTIVE columns alongside the existing SA-level LAST ACTIVE. A new PublicKeyLastActive resource backs this tracking, and the activity interceptor records last-used timestamps per signing key fingerprint.
omnictl serviceaccount create OutputThe output of omnictl serviceaccount create is now commented out by default, making it friendlier for piping into .env files and shell automation.
Omni now tracks machines running Talos versions approaching or past end of support relative to MinTalosVersion, emits two new notifications (approaching end of support, end of support reached), and exposes Prometheus metrics for both.
talosctl From Factorytalosctl binaries are now downloaded directly from the Talos Image Factory instead of GitHub.
By default, cluster templates can only include files from the same directory as the template file. This prevents malicious templates from including arbitrary files like /etc/passwd. The previous behavior can be restored with --allowed-dir.
Inline fields for manifests and config patches now accept three forms: a single inline map (for backward compatibility), a list of inline maps, or raw bytes (which may contain multiple YAML documents). omnictl cluster template export now exports patches and manifests as raw bytes so multi-document values round-trip correctly.
omnictl cluster template commands now resolve patch and Kubernetes manifest includes relative to the template YAML file, rather than the current working directory of omnictl.
<details><summary>78 commits</summary> <p>
c3ea048fd release(v1.8.0-beta.0): prepare releaseac81e59f8 feat: collect ClusterKubernetesManifestStatus in the support bundles64a1d5360 fix: wrong role promotion for some etcd APIs7cc7e1815 test: fix workload proxy integration test for upgrade scenario2c8b17899 feat: add per-actor etcd write metrics49322f05e feat: use plain download links for image downloads01742e71e feat: add log level and format configuration7fb5b164d chore: bump depscab06214c feat(frontend): allow switching logs inside logs tabc890ececa refactor(frontend): move node logs logic into machinelogscontainer75cdb09fc refactor(frontend): extra machine service list into a composable9f1bb2fa3 docs: add COSI resource operations in API usage examples13c3f2897 fix: add more input validations to management APIced79da6c fix: consume SAML sessions once7b72ac644 chore(frontend): bump dependenciesed7738b33 fix: do not panic is ssa apply with multi-version CRDse08e566dc feat: destroy imported cluster secrets after bundle is consumedd01a6f668 fix(frontend): keep machine details open when switching25fa9e141 fix: change ImportedClusterSecrets access level to operator39ee2f01e feat: proxy image factory requests done by the providers through Omnie7aee25c7 test(frontend): add e2e tests for join tokens in frontende6be461c9 fix(frontend): add apexcharts formatter workaroundba6205f54 fix(frontend): fix apexcharts broken tooltips and initial stateaddf66249 feat: add omnictl media command group with preset support110be565c feat: expose provision step errors on machine request status699ebf70e fix(frontend): fix revoking/deleting join tokens1f4f2afa5 feat: allow exposing a Kubernetes service on multiple host ports75e881fca feat: resolve patches/kubernetes manifests relative to the templates dire9b71f0ba fix(frontend): only show machine patches for currently visible machinea524554c7 fix(frontend): fix editing labels on machine classc14ee1019 refactor(frontend): refactor all but the last tlist use of watch.setup56cce45e1 chore(frontend): bump node to 24.15.07989c3c03 test: fix data race in machine service mockc141613d4 fix: fix the storm of PendingUpdateStatus create/destroya43407d09 feat: generate config section of helm chart values from config schema0cdb5a58c feat: support raw bytes in the inline fields for manifests/patches14b83e129 feat: set infra provider factory endpoint to the one configured in omniefbd089ff feat(frontend): add qol machine updates to omni frontend2fe716d2c chore: enable go linting for build tags, fix linting errors718d61a6b chore(frontend): bump dependenciesd3592671e feat: download talosctl directly from factoryb2671d08d refactor(frontend): create downloadfile helperdc9baca82 refactor(frontend): refactor downloadtalosctl modal to new modal system06d8140d7 feat: add join token/talos version placeholders in installation media5f4b97616 fix: bring back election campaign resign code in the etcd state03c4e1d9b fix: stop logging Kubernetes read checksdc3b974d0 fix: remove workload proxy deployment when disabled on the account65af568b3 fix: skip allocating nodes for deleted/tearing down MachineRequestsf9dd84915 feat: introduce powered off machine state and power on support921389a59 fix(frontend): fix eula handling to prevent being stuck on /eula725f41d4e fix: properly display service account expiration time in the UIc5a431057 feat(frontend): add support modal to omni66383890b feat(frontend): show disks and devices in machines/machine page1e31079e4 fix(frontend): fix indeterminate state for update extensions modal6d7e4f454 feat(frontend): allow quickly switching between cluster machinesc98b1187e fix(frontend): clear page state when keys are clearedf89955b43 refactor(frontend): remove last use of <watch> componentbe67f710f feat: allow reader access to join tokenf22116882 chore: bump deps475e3660d feat: add Talos version end-of-support notifications and metrics302e9175a feat: comment serviceaccount create output967c229e1 chore: rekres to update to new kres schemaedbb621aa chore: bump stripe-go to v85cc0adefca fix(frontend): select default join token in installation media wizard0987fa9e8 chore: prepare omni with talos v1.13.0-rc73a06f892 chore: bump talos machinery78544a855 feat: restrict directories for included files in the cluster templatesa3fd0b1c4 feat(frontend): allow re-saving omni support bundle5c4a6b576 feat: remove image factory proxyingdc5e289c1 feat(frontend): show notifications in the frontend9fd6e9e14 fix(frontend): open external eula link in a new tab8c23f72e0 chore: bump deps2e9d00a66 chore: make Omni use join tokens mode legacyAllowed by default488b020b2 feat: add more filters to audit logs590ea2e37 feat: add per-key creation and last-active tracking for service accounts44b0d636e chore: bump deps186f02b45 chore(frontend): bump frontend dependencies572162547 feat(frontend): update talos version text on installation media wizard
</p>
</details><details><summary>2 commits</summary> <p>
38c182f fix: normalize the changeset to be keyed without apiVersionca35008 feat: update k8s api to 0.36.0
</p>
</details><details><summary>22 commits</summary> <p>
ccffefc release(v1.2.0): prepare release4abeff4 feat: add /talosctl/:version endpoint to list downloadable talosctls405b488 feat(i18n): add french localec6ad082 feat(registry): resolve latest tag to stable version471706d chore: drop update to talos main tests403cd5a fix: centralize schematic ownership enforcementf1cceee feat: implement authentication support81f9312 release(v1.1.0): prepare release1b834b7 feat: add SHA-256 and SHA-512 checksum frontende775c36 feat: upgrade tailwind to v4bb27d39 feat: update Talos to v1.13.0-rc.02a59890 fix: gsa signer pull during verifyfbc302f fix: support insecure registries for signature bundles8e7d10e feat: add support for google service account signing74afd80 fix: set correct Content-Type when downloading images8372fe8 feat: add SPDX frontendb379bf2 feat: switch schematic cache to LRU and negative TTL0450038 chore: remove deuplicate k8s-down ci step470cb2f chore: switch to large runners713fc6e fix: memory usage when building images0a25274 fix: excessive memory usage0f9eb22 feat: update machinery doc links
</p>
</details>Previous release can be found at v1.7.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →