NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1414 by repository stars
Last release today
07 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Rarely documented
notes for 13 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
643 releases · first in 2024
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per month.
Nothing published for this version
`b9cabbd95` feat: add deprecation notification for non-ImageFactory machines
Welcome to the v1.7.0-beta.0 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
Audit logs are now browsable directly in the Omni UI, making it easier to review audit events without CLI access.
Configuration validation errors are now presented in a human-readable format, making it easier to diagnose and fix configuration issues.
All Talos nodes can now be accessed directly via their SideroLink endpoint, removing the need to route through the load balancer for Talos API calls. Allowing direct access to worker nodes when control plane nodes are unavailable.
Omni now supports syncing Kubernetes manifests directly to managed clusters. Manifests can be defined in cluster templates, allowing declarative management of Kubernetes resources alongside cluster configuration.
omnictl edit CommandA new omnictl edit command has been added, allowing users to edit Omni resources interactively from the CLI.
The workload proxy now supports an empty subdomain configuration and a new useOmniSubdomain option, providing more flexibility in how workload proxy URLs are structured.
<details><summary>61 commits</summary> <p>
9b09e8b0c fix: apply --force-context-name on initial kubeconfig creation3251d1429 fix: batch SQLite cleanup deletes to reduce write lock contentionb6e3280a6 chore: bump go to v1.26.29201358b2 chore: bump dependencies and rekrese4760526f feat: support omnictl edit command78bfa12a3 chore: collect metrics on the initial Collect call to avoid empty data43be52c7b chore: bump sqlite metrics collector timeout and interval5db4dbfa0 test: lock prepared for Omni upgrade cluster, then check pending changes76d0c6a22 chore: extract sqlite metrics collector into a separate goroutine683058540 chore(frontend): bump yaml to 2.8.3f0dd48f37 feat(frontend): place machine labels on new line for cluster scale/created10f1f1c6 fix: log errors from the metrics endpoint handler5edcef1fb refactor(frontend): drop the views/cluster folder65c6b8047 refactor(frontend): drop the components/common foldercc71b5b52 refactor(frontend): drop the views/omni folder0e66352fb fix: fix stale writes of MachineRequestStatus in infra provider lib2bb49a954 fix(frontend): fix useclusterpermissions not reacting to cluster changes1bbe869bb fix: clean up stale identity last active resources on identity removala366efb97 fix: add missing cluster relations to resource typesff5d9beb5 test: add e2e tests for key expiration6efb0f2f0 feat: support Kubernetes manifests in the cluster templates73f3079fc fix(frontend): hide machine tutorial card if we have machinesfe7c1beba fix(frontend): fix ui error on cluster all nodes pagee46d9420b fix(frontend): prevent invalid auth states in frontendb720fc307 fix(frontend): prevent saving unconfirmed keys2a863fcf5 chore: rewrite cluster workload proxy controller to use manifests7cb5ba3c2 feat(frontend): introduce browsable audit logs in the frontend2b39af725 refactor(frontend): abort useresource get/list queries on unmountc6f2413dd fix: enable Teardown audit logs26798512e chore: bump deps, rekres, Talos 1.12.6, Kubernetes 1.35.344c0d0e21 feat: update omnictl version warning text72dfad7db feat: update github issue templates53f94596a fix(frontend): address login race conditionsada036083 feat: add a way to sync Kubernetes manifests in Omnid6f50a7f2 fix: disable client IP reporting in embedded discovery service3b2f6daa6 feat(frontend): refactor watch to allow watch singletons outside of components027ff314c fix(frontend): respect embedded discovery checkbox in cluster createb9cabbd95 feat: add deprecation notification for non-ImageFactory machines21a087024 chore(frontend): bump monaco-editor to 0.55.17699f5e7b chore(frontend): bump frontend deps5b29817fc fix: restore resolved node address fallback56b6a90fb feat: make config validation errors human-readable9052ebc2b fix: allow Talos API read and copy methodscfb18f364 chore: rewrite machine status link as qcontrollerc7f60c0c6 feat: access all Talos nodes directly via their SideroLink endpoint311f75ce5 feat(frontend): remove cookie consent banner2977f0538 feat: allow empty subdomain for workload proxyd5862a27b fix(frontend): prevent flashing no access during logine85ab384c fix: correct SQLite size metrics to include indexes and freelist621d3f449 fix: fix panics in diff algorithms90d73211e fix: use dynamic SQLite pool1fc2e01f7 fix: track load balancer port allocations in-memorye35ff83f0 fix: load balancer health status diff and stopped status race25926b5d4 feat: add useOmniSubdomain option for workload proxyd18e95800 refactor(frontend): make currentuser and permissions reactiveac35cdd44 refactor(frontend): migrate to file based routing211bbc23e chore: export the SQLite memory allocator statsdf236c3da fix: remove Election.Resign call to fix data race with Campaign913d72463 fix: add omnictl backward compatibility with older Omni servers936166b24 chore(frontend): bump dependencies, including vite 86370b41c9 test: re-fetch machine IPs in AssertTalosVersion retry loop
</p>
</details><details><summary>1 commit</summary> <p>
6d82f0c fix: bump minimum TLS version to v1.3
</p>
</details><details><summary>4 commits</summary> <p>
f1fdd95 release(v1.0.17): prepare release2267f4c feat: store relative expiration (TTL) instead of absolutef708818 release(v1.0.16): prepare release379016a feat: add option to disable client IP reporting in Hello response
</p>
</details><details><summary>5 commits</summary> <p>
503792d chore: add retry to main kubernetes operations6a00c4f feat: handle CR defined alongside their CRD in the same apply4ff2602 feat: update deprecations to Kuberntes 1.36.0-beta.0691a26b feat: add StateProvider for per-node COSI state in upgrade checks92163c3 fix: set a the context logger
</p>
</details><details><summary>2 commits</summary> <p>
6ec24a7 feat: add per-node Talos client provider for support bundle collection5e0155f fix: add trailing new line when writing to logger
</p>
</details><details><summary>3 commits</summary> <p>
d670c42 chore: bump dependencies8614c71 chore: bump deps80677e0 fix: propagate the headers before the message
</p>
</details><details><summary>1 commit</summary> <p>
9b8a14e chore: bump dependencies
</p>
</details><details><summary>1 commit</summary> <p>
0a1933c chore: bump dependencies
</p>
</details>Previous release can be found at v1.6.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The deprecated flags and config fields that were kept for the SQLite migration period (introduced in v1.4.0) have been removed.
Welcome to the v1.6.0-beta.3 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
The deprecated flags and config fields that were kept for the SQLite migration period (introduced in v1.4.0) have been removed.
If you still have any of the following flags or config keys set, you must remove them before upgrading, as they will cause startup errors:
--audit-log-dir (.logs.audit.path)--secondary-storage-path (.storage.secondary.path)--machine-log-storage-path (.logs.machine.storage.path)--machine-log-storage-enabled (.logs.machine.storage.enabled)--log-storage-path (.logs.machine.storage.path)--embedded-discovery-service-snapshot-path (.services.embeddedDiscoveryService.snapshotsPath)--machine-log-buffer-capacity (.logs.machine.bufferInitialCapacity)--machine-log-buffer-max-capacity (.logs.machine.bufferMaxCapacity)--machine-log-buffer-safe-gap (.logs.machine.bufferSafetyGap)--machine-log-num-compressed-chunks (.logs.machine.storage.numCompressedChunks)The automatic migration code for BoltDB secondary storage, file-based audit logs, file-based discovery service snapshots, and circular buffer machine logs has also been removed. If you are upgrading from a version older than v1.4.0, you must first upgrade to v1.4.x to complete the migrations, then upgrade to this version.
Omni now supports rotating the Talos and Kubernetes Certificate Authorities for managed clusters.
The ClusterStatus resource now includes talos_version and kubernetes_version fields, making cluster version information available programmatically. They are now also shown in the cluster list in the UI.
The UI now shows pending and historical configuration diffs, making it easy to review what changed and when.
<img width="1140" height="549" alt="diffs" src="https://github.com/user-attachments/assets/2b04cb8e-7f32-4f3a-9488-db4142ed38e7" />
A --force flag has been added to the machine destroy command (and a corresponding UI option) to forcibly remove machines that are stuck or unresponsive.
A new Helm chart v2 has been implemented with improved structure and more configurable options. More configuration values are now exposed in the Helm chart, giving operators greater flexibility when deploying Omni.
The installation media flow now uses a wizard-based UI by default, replacing the previous modal dialog. Presets may now also be saved, allowing for future reuse.
<img width="1635" height="863" alt="wizard" src="https://github.com/user-attachments/assets/7f34350a-60f1-4cf2-93cb-e459563cbe72" />
Global size-based cleanup has been added for machine log storage, preventing unbounded disk usage. Configurable options for audit log cleanup have also been added.
The minimum supported Talos version for new clusters has been bumped to 1.8.
Other minor UI improvements part of this release:
The node details page now shows detailed disk information, including disk model, size, and type.
<img width="1145" height="602" alt="disks" src="https://github.com/user-attachments/assets/11199bfc-9359-43b7-8f3f-d7aa225e02c7" />
The node details page now includes a dedicated section listing all PCI devices present on the node.
<img width="1159" height="649" alt="devices" src="https://github.com/user-attachments/assets/73e5b90d-131d-4eaf-91c0-c0b81c1a9b1b" />
It is now possible to reset the unique token for a node, which can be useful for re-enrolling machines.
Generated kubeconfigs now use isolated OIDC token caches, preventing token collisions between different kubeconfig users.
Machines that were previously rejected can now be unrejected from the UI, allowing them to be accepted into Omni.
Rejected machines can also now be deleted directly from the UI.
Omni now implements the SAML logout flow, properly terminating sessions with the SAML identity provider on sign-out.
Metrics for the SQLite state backend have been exposed, along with cleanup counters for better observability.
The upgrade parallelism for machine sets can now be configured via cluster templates and the UI, allowing operators to control how many machines are upgraded concurrently.
Omni now tracks the last activity time for users and service accounts, providing better visibility into account usage.
New ManagementService gRPC endpoints have been added for user operations, enabling programmatic user management.
Operators can now enforce configurable limits on the number of users and service accounts that can be created in Omni.
The Vault Kubernetes authentication mount path is now configurable, supporting non-default Vault configurations.
<details><summary>153 commits</summary> <p>
6d52a697 feat: add hsts header for omni frontend385c512d test: fix ConfigPatching test72cb85a4 feat: add configurable bandwidth rate limiting for SideroLink tunnel49795f0c feat(frontend): display appropriate message for talos apis when booting3a19194f fix: add missing timeout to the backup download calls in secrets ctrl017b0398 fix(frontend): fix cluster details layout for ultrawide and mobilefebba94d test: fix flaky link cleanup test118a2c7c chore(frontend): expose error codes on watches28e85107 fix: calculate diff history and machine config out of applied config7a153579 chore: remove go-jsonschema fork, use upstream v0.22.01e9b733c chore: bump deps, rekres31e13e9e fix: do not release lock on apply config fails91ec5eed fix(frontend): prevent -1 stats on home pagecf8f58e6 fix(frontend): correct config patch routing for cluster machinescec99c31 feat(frontend): replace mount status data with volume status data433fe435 chore: bump default talos version23951c5c fix(frontend): reset support bundle state on close7ed46ba9 feat(frontend): reintroduce apexcharts tree-shakinga566261b feat(frontend): allow specifying date range for audit logs75b77f7f fix: skip schematic comparison for invalid schematic machinesd4ae1460 release(v1.6.0-beta.2): prepare release0b01dfdd fix: use localhost for internal kubeconfig server address8ebaa095 fix(frontend): revert apexcharts tree-shakinga168a96e feat: add info for audit-log filter argsafe41b09 release(v1.6.0-beta.1): prepare releasee2adcb0b fix: close ssa manager after use543cf70b chore: force SSA manifests sync mode for Talos >= 1.136a0da38f chore(frontend): bump dependenciesef3946cf fix: use uncached read for MachineExtensions in SchematicConfiguration1e6be81f refactor: introduce uncached reader/writer package, fix flaky testsbeb7dba8 release(v1.6.0-beta.0): prepare releasea7b8b145 feat(frontend): update selected state of machineset labels943a9ad4 fix(frontend): reset pagination when selectors change05738937 feat: support setting upgrade parallelism in templates and UIa9f2937c feat: add OIDC token cache isolation for generated kubeconfigs8a814d17 feat(frontend): use new resource label colors0cb34323 refactor(frontend): use tailwind classes instead of color variables8a72a8ae refactor(frontend): don't interpolate resource label classesf8a42eeb chore: move graceful upgrades to the lowest level6f0ca32f fix(frontend): truncate machine classes in cluster list5bb4ad9d fix(frontend): fix pending manifests warning sidebar color6d03fc7c feat: track user and service account last activitya6811877 refactor(frontend): create pagecontainer component to manage paddinge7f7a8ee fix(frontend): re-add padding in cluster scoped for error caseed1ebe35 fix: enhance SAML handler startup errora907c311 fix: properly select extensions when they're defined for cluster/ms lvl66dbbdc6 feat(frontend): add instructions for adding machines51747657 chore: update LICENSE2372684a feat(frontend): show pci devices on node details823af623 fix(frontend): fix unintented icon button size overridesb5076c19 feat: implement saml logout flowe57b7f5b chore(frontend): bump storybook dependencies5d13f4ba chore(frontend): add uncategorised vue lint rules415111c7 chore(frontend): update eslint related dependencies05957580 chore(frontend): add lint rule for scoped stylesf361fa73 chore: bump depsba578e60 feat(frontend): move cluster scale pencil edit to a modal7b1de4f0 feat(frontend): show talos and k8s versions in the cluster list5fccd82b feat: add talos_version and kubernetes_version to clusterstatuse3df911d feat: enforce configurable limits on user and service account creationc5b40efb feat(frontend): add collapse/expand toggle to machine set poolsda60807d feat: add ManagementService gRPC endpoints for user operationsf29d769c fix: fetch siderolink url from omnia6bf6667 feat(frontend): add some getting started info for clusters/machinesa4ee4b5e feat(frontend): add no clusters/machines found to home page59881d2e refactor: remove direct dependency on github.com/siderolabs/talos47fb4dd7 feat: allow resetting node unique tokens578f2126 fix(frontend): handle invalid jwt response from backendad6cf5b1 feat: enforce auth_time in auth0 token validation90474045 fix(frontend): keep cluster menu visible and sticky7c0e18c2 feat: introduce machine --force destroy flag and UI option for that4e5c9c57 fix: rename --force flag to --force-etcd-leave, same in the UI1887d863 feat(frontend): show more detailed node disk informationae2f48f0 refactor(frontend): clean up node mounts a bit5bfa167d refactor(frontend): fix node details scrolling and padding8c94b77c chore: bump Talos machinery to the latest main and use 1.12.4 schema6776d127 feat: add global size-based cleanup for machine log storage08c31275 test: migrate machine request set status testsed5b81ce feat(frontend): show nodename and uuid in support bundle modal1abd7ce6 chore: bump default talos version4cb81e43 test: fix flaky nature of ca rotation tests928d568c feat(frontend): add ability to delete pending machines6e8d837d fix: do not check Talos version in the machine set node updates8786ad36 feat(frontend): update machine class condition text78da5820 feat(frontend): provide get started text for first machine classe406321d refactor(frontend): remove watch class usage from machine class01a0b3e6 fix: add required SQLite storage path flag to compose.yamld133b564 fix(frontend): fix multi-doc parsing when creating single node clusters4f6f0707 chore: update readme img2f1f0f78 test: fix flaky unit tests2ecd603c refactor(frontend): fix some minor lint warnings1f237905 fix: compare current and new kernel args more defensivelyd262e03b feat: allow unrejecting machines from the uid67b25f6 fix: track dependendants for searchFor in watchd7d54916 refactor(frontend): remove <watch> from backupslist8f5d64f8 test: add embedded etcd smoke test to helm e2eccc197b2 refactor: replace the old helm chart with the new one69c2759b fix: break the dep loop in the cluster machine config status controllerdbf34e24 refactor(frontend): add type checking for context inclusion52f249db feat: make more things configurable in the helm chartfbf36740 test: add unit and e2e tests to the helm chart04bcff7a fix: unify helm chart services and ingresses, remove JSON schema0c2c5c1c test: use envsubst in tests and do small improvementsbd86ff31 chore: remove deprecated migration flags, config fields, and migration codeafdf123e feat: add support for Kubernetes CA rotation4c9212f6 refactor: remove global runtime registry, inject runtimes to servicesf845af53 feat(frontend): show pending and historical config diffs in ui939a9a08 chore: expose machine request set id in the provision context7d80fede feat: support custom Vault Kubernetes auth mount path30d17dcf chore: update Go to 1.26 in go.mod, rekres, fix linting issuesd1c869a9 chore: bump deps, rekresa89d270c fix: replace gotextdiff with linear-space Myers diff to prevent OOM05e42f9a feat: expose metrics for sqlite state and add cleanup counters868f8ac1 test: reach maintenance mode machines' Talos API through Omni in testsed5efa5d feat(frontend): for frontend auth flow dont require login clickef3e3bc1 test: use automation sa directly in integration tests6102db4e fix: use single shared etcd backup store factory70c9a549 fix: properly generate upgrade diffs for the imported cluster337bbe6c fix: fix memory leak in the config diff compute code69b8e997 feat: update machinery doc links79f85eec feat: add configuration options for audit log cleanup7e4bc18f feat(frontend): refactor confirm modal with reka-ui4009aa42 fix(frontend): import undefined components and add lint rule0a4dab64 refactor(frontend): rename tbutton type to variante4b1f3b5 refactor(frontend): refactor patches, machine class, and node destroy watches9bca00a7 test(installation-media): write e2e test for the wizarda2eedd8d feat(installation-media): replace modal with wizard by defaultf3cdbda7 refactor: remove global config, inject it to servicesed94ce9c fix: update the error for sqlite libraryf61b72f5 refactor(frontend): reimplement tabs using reka-ui4ef8c73b feat: move omni schematic cache to ephemeralb9bd3f90 refactor: migrate all SQLite usage to zombiezen922d8418 feat(frontend): add instructions on how to export cluster templatesb72b00b4 feat: bump minimum talos version to 1.80906bcc2 fix: prevent unwanted upgrades of non-image-factory machines76fd73f6 feat(frontend): add clarification text to backup settingse60b8091 feat(installation-media): remove hover on table rows and make name clickable3a18fdd5 refactor(frontend): remove <watch> from cluster machineseae8f84e fix: handle deletion event on InstallationMediaConfig validation4cc3a3da test: do not check for empty wipe id in static infra provider test3d2dc7b5 feat(frontend): allow embedding youtube videos8f33ee1e fix: pause cluster machine watches until expandedf2f8842a feat(installation-media): use usedownloadimage composable in download preset modalc319d7bc fix: fix schematic generation for machines in agent modee73acfde chore: update dependenciesb83852a9 feat(installation-media): add download progress and omni specific filenames to images197a7fa8 chore(frontend): update dependenciesdc2c9480 fix: check config generation errors before computing redacted configs7e0bec69 feat(installation-media): backend validation for installation media configs1e24fd22 feat: implement helm chart v2c86c2e02 test: add e2e test to validate machine tabs74e4abf8 feat(installation-media): replace edit naming with clone for installation mediac6cc25c7 feat: add support for Talos CA rotation
</p>
</details><details><summary>20 commits</summary> <p>
6d52a697 feat: add hsts header for omni frontend385c512d test: fix ConfigPatching test72cb85a4 feat: add configurable bandwidth rate limiting for SideroLink tunnel49795f0c feat(frontend): display appropriate message for talos apis when booting3a19194f fix: add missing timeout to the backup download calls in secrets ctrl017b0398 fix(frontend): fix cluster details layout for ultrawide and mobilefebba94d test: fix flaky link cleanup test118a2c7c chore(frontend): expose error codes on watches28e85107 fix: calculate diff history and machine config out of applied config7a153579 chore: remove go-jsonschema fork, use upstream v0.22.01e9b733c chore: bump deps, rekres31e13e9e fix: do not release lock on apply config fails91ec5eed fix(frontend): prevent -1 stats on home pagecf8f58e6 fix(frontend): correct config patch routing for cluster machinescec99c31 feat(frontend): replace mount status data with volume status data433fe435 chore: bump default talos version23951c5c fix(frontend): reset support bundle state on close7ed46ba9 feat(frontend): reintroduce apexcharts tree-shakinga566261b feat(frontend): allow specifying date range for audit logs75b77f7f fix: skip schematic comparison for invalid schematic machines
</p>
</details><details><summary>2 commits</summary> <p>
9c06846 feat: change the way excluded addresses are specifiedf71a14a feat: add advertised filters to discovery data
</p>
</details><details><summary>2 commits</summary> <p>
854400f feat: bump discovery API to v0.1.80a4c6fd chore: update dependencies and rekres
</p>
</details><details><summary>4 commits</summary> <p>
d5fdcb8 release(v1.0.15): prepare releaseb9a9ae9 feat: update dependencies8863fd8 release(v1.0.14): prepare releasee0c8062 chore: rekres and update dependencies
</p>
</details><details><summary>1 commit</summary> <p>
47fce68 feat: support Go 1.26, rekres
</p>
</details><details><summary>10 commits</summary> <p>
8364add chore: small improcements to ssa packagea95f3bf chore: add helper functions for CLI applicationsf2c063b test: add integration tests for ssa logic9de92cf refactor: drop k8s.io/utils8e6f068 fix: bring back legacy syncde675a0 fix: stop using custom dialer for Kubernetes cliente7a89c3 refactor: use fluxcd/ssa instead of kubernetes cli-utils for ssa0a235c0 feat: add early support for Kubernetes 1.363bea212 fix: use new Myers diff algorithm604c56b chore: extract common code to the go-kubernetes package
</p>
</details><details><summary>37 commits</summary> <p>
f0c7a7b release(v1.0.3): prepare releasedd92631 docs: correct path to hack/copy-artifacts.shddc1a83 fix: update Talos to fix rpi_5 buildb3d07e5 docs: remove redundant Kubernetes version prerequisite9666795 fix: values.schema.json8a8da46 feat: adjust security context for user namespace modebc631dc fix: values.schema.json8ea6fe9 feat: add user namespace support with Kubernetes version validation324c464 fix: skip initializing TUF if keyless signing is disableda42b9d9 release(v1.0.2): prepare release80d1ba3 fix: pass nameoptions to verify bundle tooeec01d1 release(v1.0.1): prepare releaseec1c0a7 fix: pass insecure to the cosign new bundle verifier14d0f2a release(v1.0.0): prepare releasea90529c feat: add more security contextsec69fe2 fix: extra kernel args for overlaysaa325ee feat: add Helm docs and schema3c18e05 feat: add Sidero google service account email also to verfiers151feb5 fix: docs url42a1c45 feat: add helm to kresac4718a feat: update Talos and pkgs1d6468e feat: add helm e2e to CI2f0499c feat: added e2e tests2eccf98 fix: made changes on the recommendation of copilote27ea36 feat: Added E2E with KUTTL9f6b9e7 feat: Added additional tests4939747 feat: Added helm unittestsdcaa1db feat: added helmchart1f85622 feat: add cloudflare credentials helper852856d fix: installer internal configc8c6576 release(v1.0.0-beta.0): prepare release56bd21b fix: allow Cache-Control header in CORS83f4d91 fix: clarify bootloader selectionc8c5faa feat: allow using image GET/HEAD API by the JS code on any domainse732d90 feat: support acm for secureboot5f103c1 feat: support copying to clipboardc3532c4 feat: update Talos with GRUB and other fixes
</p>
</details><details><summary>3 commits</summary> <p>
296bf9a feat: add logging to the KMS server2d6b082 feat: add TLS support for KMS server4233ecd chore: bump deps, rekres
</p>
</details>Previous release can be found at v1.5.0
Nothing published for this version
The deprecated flags and config fields that were kept for the SQLite migration period (introduced in v1.4.0) have been removed.
Welcome to the v1.6.0-beta.2 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
The deprecated flags and config fields that were kept for the SQLite migration period (introduced in v1.4.0) have been removed.
If you still have any of the following flags or config keys set, you must remove them before upgrading, as they will cause startup errors:
--audit-log-dir (.logs.audit.path)--secondary-storage-path (.storage.secondary.path)--machine-log-storage-path (.logs.machine.storage.path)--machine-log-storage-enabled (.logs.machine.storage.enabled)--log-storage-path (.logs.machine.storage.path)--embedded-discovery-service-snapshot-path (.services.embeddedDiscoveryService.snapshotsPath)--machine-log-buffer-capacity (.logs.machine.bufferInitialCapacity)--machine-log-buffer-max-capacity (.logs.machine.bufferMaxCapacity)--machine-log-buffer-safe-gap (.logs.machine.bufferSafetyGap)--machine-log-num-compressed-chunks (.logs.machine.storage.numCompressedChunks)The automatic migration code for BoltDB secondary storage, file-based audit logs, file-based discovery service snapshots, and circular buffer machine logs has also been removed. If you are upgrading from a version older than v1.4.0, you must first upgrade to v1.4.x to complete the migrations, then upgrade to this version.
Omni now supports rotating the Talos and Kubernetes Certificate Authorities for managed clusters.
The ClusterStatus resource now includes talos_version and kubernetes_version fields, making cluster version information available programmatically. They are now also shown in the cluster list in the UI.
The UI now shows pending and historical configuration diffs, making it easy to review what changed and when.
<img width="1140" height="549" alt="diffs" src="https://github.com/user-attachments/assets/2b04cb8e-7f32-4f3a-9488-db4142ed38e7" />
A --force flag has been added to the machine destroy command (and a corresponding UI option) to forcibly remove machines that are stuck or unresponsive.
A new Helm chart v2 has been implemented with improved structure and more configurable options. More configuration values are now exposed in the Helm chart, giving operators greater flexibility when deploying Omni.
The installation media flow now uses a wizard-based UI by default, replacing the previous modal dialog. Presets may now also be saved, allowing for future reuse.
<img width="1635" height="863" alt="wizard" src="https://github.com/user-attachments/assets/7f34350a-60f1-4cf2-93cb-e459563cbe72" />
Global size-based cleanup has been added for machine log storage, preventing unbounded disk usage. Configurable options for audit log cleanup have also been added.
The minimum supported Talos version for new clusters has been bumped to 1.8.
Other minor UI improvements part of this release:
The node details page now shows detailed disk information, including disk model, size, and type.
<img width="1145" height="602" alt="disks" src="https://github.com/user-attachments/assets/11199bfc-9359-43b7-8f3f-d7aa225e02c7" />
The node details page now includes a dedicated section listing all PCI devices present on the node.
<img width="1159" height="649" alt="devices" src="https://github.com/user-attachments/assets/73e5b90d-131d-4eaf-91c0-c0b81c1a9b1b" />
It is now possible to reset the unique token for a node, which can be useful for re-enrolling machines.
Generated kubeconfigs now use isolated OIDC token caches, preventing token collisions between different kubeconfig users.
Machines that were previously rejected can now be unrejected from the UI, allowing them to be accepted into Omni.
Rejected machines can also now be deleted directly from the UI.
Omni now implements the SAML logout flow, properly terminating sessions with the SAML identity provider on sign-out.
Metrics for the SQLite state backend have been exposed, along with cleanup counters for better observability.
The upgrade parallelism for machine sets can now be configured via cluster templates and the UI, allowing operators to control how many machines are upgraded concurrently.
Omni now tracks the last activity time for users and service accounts, providing better visibility into account usage.
New ManagementService gRPC endpoints have been added for user operations, enabling programmatic user management.
Operators can now enforce configurable limits on the number of users and service accounts that can be created in Omni.
The Vault Kubernetes authentication mount path is now configurable, supporting non-default Vault configurations.
<details><summary>132 commits</summary> <p>
0b01dfdd fix: use localhost for internal kubeconfig server address8ebaa095 fix(frontend): revert apexcharts tree-shakinga168a96e feat: add info for audit-log filter argsafe41b09 release(v1.6.0-beta.1): prepare releasee2adcb0b fix: close ssa manager after use543cf70b chore: force SSA manifests sync mode for Talos >= 1.136a0da38f chore(frontend): bump dependenciesef3946cf fix: use uncached read for MachineExtensions in SchematicConfiguration1e6be81f refactor: introduce uncached reader/writer package, fix flaky testsbeb7dba8 release(v1.6.0-beta.0): prepare releasea7b8b145 feat(frontend): update selected state of machineset labels943a9ad4 fix(frontend): reset pagination when selectors change05738937 feat: support setting upgrade parallelism in templates and UIa9f2937c feat: add OIDC token cache isolation for generated kubeconfigs8a814d17 feat(frontend): use new resource label colors0cb34323 refactor(frontend): use tailwind classes instead of color variables8a72a8ae refactor(frontend): don't interpolate resource label classesf8a42eeb chore: move graceful upgrades to the lowest level6f0ca32f fix(frontend): truncate machine classes in cluster list5bb4ad9d fix(frontend): fix pending manifests warning sidebar color6d03fc7c feat: track user and service account last activitya6811877 refactor(frontend): create pagecontainer component to manage paddinge7f7a8ee fix(frontend): re-add padding in cluster scoped for error caseed1ebe35 fix: enhance SAML handler startup errora907c311 fix: properly select extensions when they're defined for cluster/ms lvl66dbbdc6 feat(frontend): add instructions for adding machines51747657 chore: update LICENSE2372684a feat(frontend): show pci devices on node details823af623 fix(frontend): fix unintented icon button size overridesb5076c19 feat: implement saml logout flowe57b7f5b chore(frontend): bump storybook dependencies5d13f4ba chore(frontend): add uncategorised vue lint rules415111c7 chore(frontend): update eslint related dependencies05957580 chore(frontend): add lint rule for scoped stylesf361fa73 chore: bump depsba578e60 feat(frontend): move cluster scale pencil edit to a modal7b1de4f0 feat(frontend): show talos and k8s versions in the cluster list5fccd82b feat: add talos_version and kubernetes_version to clusterstatuse3df911d feat: enforce configurable limits on user and service account creationc5b40efb feat(frontend): add collapse/expand toggle to machine set poolsda60807d feat: add ManagementService gRPC endpoints for user operationsf29d769c fix: fetch siderolink url from omnia6bf6667 feat(frontend): add some getting started info for clusters/machinesa4ee4b5e feat(frontend): add no clusters/machines found to home page59881d2e refactor: remove direct dependency on github.com/siderolabs/talos47fb4dd7 feat: allow resetting node unique tokens578f2126 fix(frontend): handle invalid jwt response from backendad6cf5b1 feat: enforce auth_time in auth0 token validation90474045 fix(frontend): keep cluster menu visible and sticky7c0e18c2 feat: introduce machine --force destroy flag and UI option for that4e5c9c57 fix: rename --force flag to --force-etcd-leave, same in the UI1887d863 feat(frontend): show more detailed node disk informationae2f48f0 refactor(frontend): clean up node mounts a bit5bfa167d refactor(frontend): fix node details scrolling and padding8c94b77c chore: bump Talos machinery to the latest main and use 1.12.4 schema6776d127 feat: add global size-based cleanup for machine log storage08c31275 test: migrate machine request set status testsed5b81ce feat(frontend): show nodename and uuid in support bundle modal1abd7ce6 chore: bump default talos version4cb81e43 test: fix flaky nature of ca rotation tests928d568c feat(frontend): add ability to delete pending machines6e8d837d fix: do not check Talos version in the machine set node updates8786ad36 feat(frontend): update machine class condition text78da5820 feat(frontend): provide get started text for first machine classe406321d refactor(frontend): remove watch class usage from machine class01a0b3e6 fix: add required SQLite storage path flag to compose.yamld133b564 fix(frontend): fix multi-doc parsing when creating single node clusters4f6f0707 chore: update readme img2f1f0f78 test: fix flaky unit tests2ecd603c refactor(frontend): fix some minor lint warnings1f237905 fix: compare current and new kernel args more defensivelyd262e03b feat: allow unrejecting machines from the uid67b25f6 fix: track dependendants for searchFor in watchd7d54916 refactor(frontend): remove <watch> from backupslist8f5d64f8 test: add embedded etcd smoke test to helm e2eccc197b2 refactor: replace the old helm chart with the new one69c2759b fix: break the dep loop in the cluster machine config status controllerdbf34e24 refactor(frontend): add type checking for context inclusion52f249db feat: make more things configurable in the helm chartfbf36740 test: add unit and e2e tests to the helm chart04bcff7a fix: unify helm chart services and ingresses, remove JSON schema0c2c5c1c test: use envsubst in tests and do small improvementsbd86ff31 chore: remove deprecated migration flags, config fields, and migration codeafdf123e feat: add support for Kubernetes CA rotation4c9212f6 refactor: remove global runtime registry, inject runtimes to servicesf845af53 feat(frontend): show pending and historical config diffs in ui939a9a08 chore: expose machine request set id in the provision context7d80fede feat: support custom Vault Kubernetes auth mount path30d17dcf chore: update Go to 1.26 in go.mod, rekres, fix linting issuesd1c869a9 chore: bump deps, rekresa89d270c fix: replace gotextdiff with linear-space Myers diff to prevent OOM05e42f9a feat: expose metrics for sqlite state and add cleanup counters868f8ac1 test: reach maintenance mode machines' Talos API through Omni in testsed5efa5d feat(frontend): for frontend auth flow dont require login clickef3e3bc1 test: use automation sa directly in integration tests6102db4e fix: use single shared etcd backup store factory70c9a549 fix: properly generate upgrade diffs for the imported cluster337bbe6c fix: fix memory leak in the config diff compute code69b8e997 feat: update machinery doc links79f85eec feat: add configuration options for audit log cleanup7e4bc18f feat(frontend): refactor confirm modal with reka-ui4009aa42 fix(frontend): import undefined components and add lint rule0a4dab64 refactor(frontend): rename tbutton type to variante4b1f3b5 refactor(frontend): refactor patches, machine class, and node destroy watches9bca00a7 test(installation-media): write e2e test for the wizarda2eedd8d feat(installation-media): replace modal with wizard by defaultf3cdbda7 refactor: remove global config, inject it to servicesed94ce9c fix: update the error for sqlite libraryf61b72f5 refactor(frontend): reimplement tabs using reka-ui4ef8c73b feat: move omni schematic cache to ephemeralb9bd3f90 refactor: migrate all SQLite usage to zombiezen922d8418 feat(frontend): add instructions on how to export cluster templatesb72b00b4 feat: bump minimum talos version to 1.80906bcc2 fix: prevent unwanted upgrades of non-image-factory machines76fd73f6 feat(frontend): add clarification text to backup settingse60b8091 feat(installation-media): remove hover on table rows and make name clickable3a18fdd5 refactor(frontend): remove <watch> from cluster machineseae8f84e fix: handle deletion event on InstallationMediaConfig validation4cc3a3da test: do not check for empty wipe id in static infra provider test3d2dc7b5 feat(frontend): allow embedding youtube videos8f33ee1e fix: pause cluster machine watches until expandedf2f8842a feat(installation-media): use usedownloadimage composable in download preset modalc319d7bc fix: fix schematic generation for machines in agent modee73acfde chore: update dependenciesb83852a9 feat(installation-media): add download progress and omni specific filenames to images197a7fa8 chore(frontend): update dependenciesdc2c9480 fix: check config generation errors before computing redacted configs7e0bec69 feat(installation-media): backend validation for installation media configs1e24fd22 feat: implement helm chart v2c86c2e02 test: add e2e test to validate machine tabs74e4abf8 feat(installation-media): replace edit naming with clone for installation mediac6cc25c7 feat: add support for Talos CA rotation
</p>
</details><details><summary>3 commits</summary> <p>
0b01dfdd fix: use localhost for internal kubeconfig server address8ebaa095 fix(frontend): revert apexcharts tree-shakinga168a96e feat: add info for audit-log filter args
</p>
</details><details><summary>2 commits</summary> <p>
9c06846 feat: change the way excluded addresses are specifiedf71a14a feat: add advertised filters to discovery data
</p>
</details><details><summary>2 commits</summary> <p>
854400f feat: bump discovery API to v0.1.80a4c6fd chore: update dependencies and rekres
</p>
</details><details><summary>2 commits</summary> <p>
8863fd8 release(v1.0.14): prepare releasee0c8062 chore: rekres and update dependencies
</p>
</details><details><summary>1 commit</summary> <p>
47fce68 feat: support Go 1.26, rekres
</p>
</details><details><summary>10 commits</summary> <p>
8364add chore: small improcements to ssa packagea95f3bf chore: add helper functions for CLI applicationsf2c063b test: add integration tests for ssa logic9de92cf refactor: drop k8s.io/utils8e6f068 fix: bring back legacy syncde675a0 fix: stop using custom dialer for Kubernetes cliente7a89c3 refactor: use fluxcd/ssa instead of kubernetes cli-utils for ssa0a235c0 feat: add early support for Kubernetes 1.363bea212 fix: use new Myers diff algorithm604c56b chore: extract common code to the go-kubernetes package
</p>
</details><details><summary>37 commits</summary> <p>
f0c7a7b release(v1.0.3): prepare releasedd92631 docs: correct path to hack/copy-artifacts.shddc1a83 fix: update Talos to fix rpi_5 buildb3d07e5 docs: remove redundant Kubernetes version prerequisite9666795 fix: values.schema.json8a8da46 feat: adjust security context for user namespace modebc631dc fix: values.schema.json8ea6fe9 feat: add user namespace support with Kubernetes version validation324c464 fix: skip initializing TUF if keyless signing is disableda42b9d9 release(v1.0.2): prepare release80d1ba3 fix: pass nameoptions to verify bundle tooeec01d1 release(v1.0.1): prepare releaseec1c0a7 fix: pass insecure to the cosign new bundle verifier14d0f2a release(v1.0.0): prepare releasea90529c feat: add more security contextsec69fe2 fix: extra kernel args for overlaysaa325ee feat: add Helm docs and schema3c18e05 feat: add Sidero google service account email also to verfiers151feb5 fix: docs url42a1c45 feat: add helm to kresac4718a feat: update Talos and pkgs1d6468e feat: add helm e2e to CI2f0499c feat: added e2e tests2eccf98 fix: made changes on the recommendation of copilote27ea36 feat: Added E2E with KUTTL9f6b9e7 feat: Added additional tests4939747 feat: Added helm unittestsdcaa1db feat: added helmchart1f85622 feat: add cloudflare credentials helper852856d fix: installer internal configc8c6576 release(v1.0.0-beta.0): prepare release56bd21b fix: allow Cache-Control header in CORS83f4d91 fix: clarify bootloader selectionc8c5faa feat: allow using image GET/HEAD API by the JS code on any domainse732d90 feat: support acm for secureboot5f103c1 feat: support copying to clipboardc3532c4 feat: update Talos with GRUB and other fixes
</p>
</details><details><summary>3 commits</summary> <p>
296bf9a feat: add logging to the KMS server2d6b082 feat: add TLS support for KMS server4233ecd chore: bump deps, rekres
</p>
</details>Previous release can be found at v1.5.0
Nothing published for this version
The deprecated flags and config fields that were kept for the SQLite migration period (introduced in v1.4.0) have been removed.
Welcome to the v1.6.0-beta.1 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
The deprecated flags and config fields that were kept for the SQLite migration period (introduced in v1.4.0) have been removed.
If you still have any of the following flags or config keys set, you must remove them before upgrading, as they will cause startup errors:
--audit-log-dir (.logs.audit.path)--secondary-storage-path (.storage.secondary.path)--machine-log-storage-path (.logs.machine.storage.path)--machine-log-storage-enabled (.logs.machine.storage.enabled)--log-storage-path (.logs.machine.storage.path)--embedded-discovery-service-snapshot-path (.services.embeddedDiscoveryService.snapshotsPath)--machine-log-buffer-capacity (.logs.machine.bufferInitialCapacity)--machine-log-buffer-max-capacity (.logs.machine.bufferMaxCapacity)--machine-log-buffer-safe-gap (.logs.machine.bufferSafetyGap)--machine-log-num-compressed-chunks (.logs.machine.storage.numCompressedChunks)The automatic migration code for BoltDB secondary storage, file-based audit logs, file-based discovery service snapshots, and circular buffer machine logs has also been removed. If you are upgrading from a version older than v1.4.0, you must first upgrade to v1.4.x to complete the migrations, then upgrade to this version.
Omni now supports rotating the Talos and Kubernetes Certificate Authorities for managed clusters.
The ClusterStatus resource now includes talos_version and kubernetes_version fields, making cluster version information available programmatically. They are now also shown in the cluster list in the UI.
The UI now shows pending and historical configuration diffs, making it easy to review what changed and when.
<img width="1140" height="549" alt="diffs" src="https://github.com/user-attachments/assets/2b04cb8e-7f32-4f3a-9488-db4142ed38e7" />
A --force flag has been added to the machine destroy command (and a corresponding UI option) to forcibly remove machines that are stuck or unresponsive.
A new Helm chart v2 has been implemented with improved structure and more configurable options. More configuration values are now exposed in the Helm chart, giving operators greater flexibility when deploying Omni.
The installation media flow now uses a wizard-based UI by default, replacing the previous modal dialog. Presets may now also be saved, allowing for future reuse.
<img width="1635" height="863" alt="wizard" src="https://github.com/user-attachments/assets/7f34350a-60f1-4cf2-93cb-e459563cbe72" />
Global size-based cleanup has been added for machine log storage, preventing unbounded disk usage. Configurable options for audit log cleanup have also been added.
The minimum supported Talos version for new clusters has been bumped to 1.8.
Other minor UI improvements part of this release:
The node details page now shows detailed disk information, including disk model, size, and type.
<img width="1145" height="602" alt="disks" src="https://github.com/user-attachments/assets/11199bfc-9359-43b7-8f3f-d7aa225e02c7" />
The node details page now includes a dedicated section listing all PCI devices present on the node.
<img width="1159" height="649" alt="devices" src="https://github.com/user-attachments/assets/73e5b90d-131d-4eaf-91c0-c0b81c1a9b1b" />
It is now possible to reset the unique token for a node, which can be useful for re-enrolling machines.
Generated kubeconfigs now use isolated OIDC token caches, preventing token collisions between different kubeconfig users.
Machines that were previously rejected can now be unrejected from the UI, allowing them to be accepted into Omni.
Rejected machines can also now be deleted directly from the UI.
Omni now implements the SAML logout flow, properly terminating sessions with the SAML identity provider on sign-out.
Metrics for the SQLite state backend have been exposed, along with cleanup counters for better observability.
The upgrade parallelism for machine sets can now be configured via cluster templates and the UI, allowing operators to control how many machines are upgraded concurrently.
Omni now tracks the last activity time for users and service accounts, providing better visibility into account usage.
New ManagementService gRPC endpoints have been added for user operations, enabling programmatic user management.
Operators can now enforce configurable limits on the number of users and service accounts that can be created in Omni.
The Vault Kubernetes authentication mount path is now configurable, supporting non-default Vault configurations.
<details><summary>128 commits</summary> <p>
e2adcb0b fix: close ssa manager after use543cf70b chore: force SSA manifests sync mode for Talos >= 1.136a0da38f chore(frontend): bump dependenciesef3946cf fix: use uncached read for MachineExtensions in SchematicConfiguration1e6be81f refactor: introduce uncached reader/writer package, fix flaky testsbeb7dba8 release(v1.6.0-beta.0): prepare releasea7b8b145 feat(frontend): update selected state of machineset labels943a9ad4 fix(frontend): reset pagination when selectors change05738937 feat: support setting upgrade parallelism in templates and UIa9f2937c feat: add OIDC token cache isolation for generated kubeconfigs8a814d17 feat(frontend): use new resource label colors0cb34323 refactor(frontend): use tailwind classes instead of color variables8a72a8ae refactor(frontend): don't interpolate resource label classesf8a42eeb chore: move graceful upgrades to the lowest level6f0ca32f fix(frontend): truncate machine classes in cluster list5bb4ad9d fix(frontend): fix pending manifests warning sidebar color6d03fc7c feat: track user and service account last activitya6811877 refactor(frontend): create pagecontainer component to manage paddinge7f7a8ee fix(frontend): re-add padding in cluster scoped for error caseed1ebe35 fix: enhance SAML handler startup errora907c311 fix: properly select extensions when they're defined for cluster/ms lvl66dbbdc6 feat(frontend): add instructions for adding machines51747657 chore: update LICENSE2372684a feat(frontend): show pci devices on node details823af623 fix(frontend): fix unintented icon button size overridesb5076c19 feat: implement saml logout flowe57b7f5b chore(frontend): bump storybook dependencies5d13f4ba chore(frontend): add uncategorised vue lint rules415111c7 chore(frontend): update eslint related dependencies05957580 chore(frontend): add lint rule for scoped stylesf361fa73 chore: bump depsba578e60 feat(frontend): move cluster scale pencil edit to a modal7b1de4f0 feat(frontend): show talos and k8s versions in the cluster list5fccd82b feat: add talos_version and kubernetes_version to clusterstatuse3df911d feat: enforce configurable limits on user and service account creationc5b40efb feat(frontend): add collapse/expand toggle to machine set poolsda60807d feat: add ManagementService gRPC endpoints for user operationsf29d769c fix: fetch siderolink url from omnia6bf6667 feat(frontend): add some getting started info for clusters/machinesa4ee4b5e feat(frontend): add no clusters/machines found to home page59881d2e refactor: remove direct dependency on github.com/siderolabs/talos47fb4dd7 feat: allow resetting node unique tokens578f2126 fix(frontend): handle invalid jwt response from backendad6cf5b1 feat: enforce auth_time in auth0 token validation90474045 fix(frontend): keep cluster menu visible and sticky7c0e18c2 feat: introduce machine --force destroy flag and UI option for that4e5c9c57 fix: rename --force flag to --force-etcd-leave, same in the UI1887d863 feat(frontend): show more detailed node disk informationae2f48f0 refactor(frontend): clean up node mounts a bit5bfa167d refactor(frontend): fix node details scrolling and padding8c94b77c chore: bump Talos machinery to the latest main and use 1.12.4 schema6776d127 feat: add global size-based cleanup for machine log storage08c31275 test: migrate machine request set status testsed5b81ce feat(frontend): show nodename and uuid in support bundle modal1abd7ce6 chore: bump default talos version4cb81e43 test: fix flaky nature of ca rotation tests928d568c feat(frontend): add ability to delete pending machines6e8d837d fix: do not check Talos version in the machine set node updates8786ad36 feat(frontend): update machine class condition text78da5820 feat(frontend): provide get started text for first machine classe406321d refactor(frontend): remove watch class usage from machine class01a0b3e6 fix: add required SQLite storage path flag to compose.yamld133b564 fix(frontend): fix multi-doc parsing when creating single node clusters4f6f0707 chore: update readme img2f1f0f78 test: fix flaky unit tests2ecd603c refactor(frontend): fix some minor lint warnings1f237905 fix: compare current and new kernel args more defensivelyd262e03b feat: allow unrejecting machines from the uid67b25f6 fix: track dependendants for searchFor in watchd7d54916 refactor(frontend): remove <watch> from backupslist8f5d64f8 test: add embedded etcd smoke test to helm e2eccc197b2 refactor: replace the old helm chart with the new one69c2759b fix: break the dep loop in the cluster machine config status controllerdbf34e24 refactor(frontend): add type checking for context inclusion52f249db feat: make more things configurable in the helm chartfbf36740 test: add unit and e2e tests to the helm chart04bcff7a fix: unify helm chart services and ingresses, remove JSON schema0c2c5c1c test: use envsubst in tests and do small improvementsbd86ff31 chore: remove deprecated migration flags, config fields, and migration codeafdf123e feat: add support for Kubernetes CA rotation4c9212f6 refactor: remove global runtime registry, inject runtimes to servicesf845af53 feat(frontend): show pending and historical config diffs in ui939a9a08 chore: expose machine request set id in the provision context7d80fede feat: support custom Vault Kubernetes auth mount path30d17dcf chore: update Go to 1.26 in go.mod, rekres, fix linting issuesd1c869a9 chore: bump deps, rekresa89d270c fix: replace gotextdiff with linear-space Myers diff to prevent OOM05e42f9a feat: expose metrics for sqlite state and add cleanup counters868f8ac1 test: reach maintenance mode machines' Talos API through Omni in testsed5efa5d feat(frontend): for frontend auth flow dont require login clickef3e3bc1 test: use automation sa directly in integration tests6102db4e fix: use single shared etcd backup store factory70c9a549 fix: properly generate upgrade diffs for the imported cluster337bbe6c fix: fix memory leak in the config diff compute code69b8e997 feat: update machinery doc links79f85eec feat: add configuration options for audit log cleanup7e4bc18f feat(frontend): refactor confirm modal with reka-ui4009aa42 fix(frontend): import undefined components and add lint rule0a4dab64 refactor(frontend): rename tbutton type to variante4b1f3b5 refactor(frontend): refactor patches, machine class, and node destroy watches9bca00a7 test(installation-media): write e2e test for the wizarda2eedd8d feat(installation-media): replace modal with wizard by defaultf3cdbda7 refactor: remove global config, inject it to servicesed94ce9c fix: update the error for sqlite libraryf61b72f5 refactor(frontend): reimplement tabs using reka-ui4ef8c73b feat: move omni schematic cache to ephemeralb9bd3f90 refactor: migrate all SQLite usage to zombiezen922d8418 feat(frontend): add instructions on how to export cluster templatesb72b00b4 feat: bump minimum talos version to 1.80906bcc2 fix: prevent unwanted upgrades of non-image-factory machines76fd73f6 feat(frontend): add clarification text to backup settingse60b8091 feat(installation-media): remove hover on table rows and make name clickable3a18fdd5 refactor(frontend): remove <watch> from cluster machineseae8f84e fix: handle deletion event on InstallationMediaConfig validation4cc3a3da test: do not check for empty wipe id in static infra provider test3d2dc7b5 feat(frontend): allow embedding youtube videos8f33ee1e fix: pause cluster machine watches until expandedf2f8842a feat(installation-media): use usedownloadimage composable in download preset modalc319d7bc fix: fix schematic generation for machines in agent modee73acfde chore: update dependenciesb83852a9 feat(installation-media): add download progress and omni specific filenames to images197a7fa8 chore(frontend): update dependenciesdc2c9480 fix: check config generation errors before computing redacted configs7e0bec69 feat(installation-media): backend validation for installation media configs1e24fd22 feat: implement helm chart v2c86c2e02 test: add e2e test to validate machine tabs74e4abf8 feat(installation-media): replace edit naming with clone for installation mediac6cc25c7 feat: add support for Talos CA rotation
</p>
</details><details><summary>5 commits</summary> <p>
e2adcb0b fix: close ssa manager after use543cf70b chore: force SSA manifests sync mode for Talos >= 1.136a0da38f chore(frontend): bump dependenciesef3946cf fix: use uncached read for MachineExtensions in SchematicConfiguration1e6be81f refactor: introduce uncached reader/writer package, fix flaky tests
</p>
</details><details><summary>2 commits</summary> <p>
9c06846 feat: change the way excluded addresses are specifiedf71a14a feat: add advertised filters to discovery data
</p>
</details><details><summary>2 commits</summary> <p>
854400f feat: bump discovery API to v0.1.80a4c6fd chore: update dependencies and rekres
</p>
</details><details><summary>2 commits</summary> <p>
8863fd8 release(v1.0.14): prepare releasee0c8062 chore: rekres and update dependencies
</p>
</details><details><summary>1 commit</summary> <p>
47fce68 feat: support Go 1.26, rekres
</p>
</details><details><summary>10 commits</summary> <p>
8364add chore: small improcements to ssa packagea95f3bf chore: add helper functions for CLI applicationsf2c063b test: add integration tests for ssa logic9de92cf refactor: drop k8s.io/utils8e6f068 fix: bring back legacy syncde675a0 fix: stop using custom dialer for Kubernetes cliente7a89c3 refactor: use fluxcd/ssa instead of kubernetes cli-utils for ssa0a235c0 feat: add early support for Kubernetes 1.363bea212 fix: use new Myers diff algorithm604c56b chore: extract common code to the go-kubernetes package
</p>
</details><details><summary>37 commits</summary> <p>
f0c7a7b release(v1.0.3): prepare releasedd92631 docs: correct path to hack/copy-artifacts.shddc1a83 fix: update Talos to fix rpi_5 buildb3d07e5 docs: remove redundant Kubernetes version prerequisite9666795 fix: values.schema.json8a8da46 feat: adjust security context for user namespace modebc631dc fix: values.schema.json8ea6fe9 feat: add user namespace support with Kubernetes version validation324c464 fix: skip initializing TUF if keyless signing is disableda42b9d9 release(v1.0.2): prepare release80d1ba3 fix: pass nameoptions to verify bundle tooeec01d1 release(v1.0.1): prepare releaseec1c0a7 fix: pass insecure to the cosign new bundle verifier14d0f2a release(v1.0.0): prepare releasea90529c feat: add more security contextsec69fe2 fix: extra kernel args for overlaysaa325ee feat: add Helm docs and schema3c18e05 feat: add Sidero google service account email also to verfiers151feb5 fix: docs url42a1c45 feat: add helm to kresac4718a feat: update Talos and pkgs1d6468e feat: add helm e2e to CI2f0499c feat: added e2e tests2eccf98 fix: made changes on the recommendation of copilote27ea36 feat: Added E2E with KUTTL9f6b9e7 feat: Added additional tests4939747 feat: Added helm unittestsdcaa1db feat: added helmchart1f85622 feat: add cloudflare credentials helper852856d fix: installer internal configc8c6576 release(v1.0.0-beta.0): prepare release56bd21b fix: allow Cache-Control header in CORS83f4d91 fix: clarify bootloader selectionc8c5faa feat: allow using image GET/HEAD API by the JS code on any domainse732d90 feat: support acm for secureboot5f103c1 feat: support copying to clipboardc3532c4 feat: update Talos with GRUB and other fixes
</p>
</details><details><summary>3 commits</summary> <p>
296bf9a feat: add logging to the KMS server2d6b082 feat: add TLS support for KMS server4233ecd chore: bump deps, rekres
</p>
</details>Previous release can be found at v1.5.0
Nothing published for this version
The deprecated flags and config fields that were kept for the SQLite migration period (introduced in v1.4.0) have been removed.
Welcome to the v1.6.0-beta.0 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
The deprecated flags and config fields that were kept for the SQLite migration period (introduced in v1.4.0) have been removed.
If you still have any of the following flags or config keys set, you must remove them before upgrading, as they will cause startup errors:
--audit-log-dir (.logs.audit.path)--secondary-storage-path (.storage.secondary.path)--machine-log-storage-path (.logs.machine.storage.path)--machine-log-storage-enabled (.logs.machine.storage.enabled)--log-storage-path (.logs.machine.storage.path)--embedded-discovery-service-snapshot-path (.services.embeddedDiscoveryService.snapshotsPath)--machine-log-buffer-capacity (.logs.machine.bufferInitialCapacity)--machine-log-buffer-max-capacity (.logs.machine.bufferMaxCapacity)--machine-log-buffer-safe-gap (.logs.machine.bufferSafetyGap)--machine-log-num-compressed-chunks (.logs.machine.storage.numCompressedChunks)The automatic migration code for BoltDB secondary storage, file-based audit logs, file-based discovery service snapshots, and circular buffer machine logs has also been removed. If you are upgrading from a version older than v1.4.0, you must first upgrade to v1.4.x to complete the migrations, then upgrade to this version.
Omni now supports rotating the Talos and Kubernetes Certificate Authorities for managed clusters.
The ClusterStatus resource now includes talos_version and kubernetes_version fields, making cluster version information available programmatically. They are now also shown in the cluster list in the UI.
The UI now shows pending and historical configuration diffs, making it easy to review what changed and when.
<img width="1140" height="549" alt="diffs" src="https://github.com/user-attachments/assets/2b04cb8e-7f32-4f3a-9488-db4142ed38e7" />
A --force flag has been added to the machine destroy command (and a corresponding UI option) to forcibly remove machines that are stuck or unresponsive.
A new Helm chart v2 has been implemented with improved structure and more configurable options. More configuration values are now exposed in the Helm chart, giving operators greater flexibility when deploying Omni.
The installation media flow now uses a wizard-based UI by default, replacing the previous modal dialog. Presets may now also be saved, allowing for future reuse.
<img width="1635" height="863" alt="wizard" src="https://github.com/user-attachments/assets/7f34350a-60f1-4cf2-93cb-e459563cbe72" />
Global size-based cleanup has been added for machine log storage, preventing unbounded disk usage. Configurable options for audit log cleanup have also been added.
The minimum supported Talos version for new clusters has been bumped to 1.8.
Other minor UI improvements part of this release:
The node details page now shows detailed disk information, including disk model, size, and type.
<img width="1145" height="602" alt="disks" src="https://github.com/user-attachments/assets/11199bfc-9359-43b7-8f3f-d7aa225e02c7" />
The node details page now includes a dedicated section listing all PCI devices present on the node.
<img width="1159" height="649" alt="devices" src="https://github.com/user-attachments/assets/73e5b90d-131d-4eaf-91c0-c0b81c1a9b1b" />
It is now possible to reset the unique token for a node, which can be useful for re-enrolling machines.
Generated kubeconfigs now use isolated OIDC token caches, preventing token collisions between different kubeconfig users.
Machines that were previously rejected can now be unrejected from the UI, allowing them to be accepted into Omni.
Rejected machines can also now be deleted directly from the UI.
Omni now implements the SAML logout flow, properly terminating sessions with the SAML identity provider on sign-out.
Metrics for the SQLite state backend have been exposed, along with cleanup counters for better observability.
The upgrade parallelism for machine sets can now be configured via cluster templates and the UI, allowing operators to control how many machines are upgraded concurrently.
Omni now tracks the last activity time for users and service accounts, providing better visibility into account usage.
New ManagementService gRPC endpoints have been added for user operations, enabling programmatic user management.
Operators can now enforce configurable limits on the number of users and service accounts that can be created in Omni.
The Vault Kubernetes authentication mount path is now configurable, supporting non-default Vault configurations.
<details><summary>122 commits</summary> <p>
a7b8b145 feat(frontend): update selected state of machineset labels943a9ad4 fix(frontend): reset pagination when selectors change05738937 feat: support setting upgrade parallelism in templates and UIa9f2937c feat: add OIDC token cache isolation for generated kubeconfigs8a814d17 feat(frontend): use new resource label colors0cb34323 refactor(frontend): use tailwind classes instead of color variables8a72a8ae refactor(frontend): don't interpolate resource label classesf8a42eeb chore: move graceful upgrades to the lowest level6f0ca32f fix(frontend): truncate machine classes in cluster list5bb4ad9d fix(frontend): fix pending manifests warning sidebar color6d03fc7c feat: track user and service account last activitya6811877 refactor(frontend): create pagecontainer component to manage paddinge7f7a8ee fix(frontend): re-add padding in cluster scoped for error caseed1ebe35 fix: enhance SAML handler startup errora907c311 fix: properly select extensions when they're defined for cluster/ms lvl66dbbdc6 feat(frontend): add instructions for adding machines51747657 chore: update LICENSE2372684a feat(frontend): show pci devices on node details823af623 fix(frontend): fix unintented icon button size overridesb5076c19 feat: implement saml logout flowe57b7f5b chore(frontend): bump storybook dependencies5d13f4ba chore(frontend): add uncategorised vue lint rules415111c7 chore(frontend): update eslint related dependencies05957580 chore(frontend): add lint rule for scoped stylesf361fa73 chore: bump depsba578e60 feat(frontend): move cluster scale pencil edit to a modal7b1de4f0 feat(frontend): show talos and k8s versions in the cluster list5fccd82b feat: add talos_version and kubernetes_version to clusterstatuse3df911d feat: enforce configurable limits on user and service account creationc5b40efb feat(frontend): add collapse/expand toggle to machine set poolsda60807d feat: add ManagementService gRPC endpoints for user operationsf29d769c fix: fetch siderolink url from omnia6bf6667 feat(frontend): add some getting started info for clusters/machinesa4ee4b5e feat(frontend): add no clusters/machines found to home page59881d2e refactor: remove direct dependency on github.com/siderolabs/talos47fb4dd7 feat: allow resetting node unique tokens578f2126 fix(frontend): handle invalid jwt response from backendad6cf5b1 feat: enforce auth_time in auth0 token validation90474045 fix(frontend): keep cluster menu visible and sticky7c0e18c2 feat: introduce machine --force destroy flag and UI option for that4e5c9c57 fix: rename --force flag to --force-etcd-leave, same in the UI1887d863 feat(frontend): show more detailed node disk informationae2f48f0 refactor(frontend): clean up node mounts a bit5bfa167d refactor(frontend): fix node details scrolling and padding8c94b77c chore: bump Talos machinery to the latest main and use 1.12.4 schema6776d127 feat: add global size-based cleanup for machine log storage08c31275 test: migrate machine request set status testsed5b81ce feat(frontend): show nodename and uuid in support bundle modal1abd7ce6 chore: bump default talos version4cb81e43 test: fix flaky nature of ca rotation tests928d568c feat(frontend): add ability to delete pending machines6e8d837d fix: do not check Talos version in the machine set node updates8786ad36 feat(frontend): update machine class condition text78da5820 feat(frontend): provide get started text for first machine classe406321d refactor(frontend): remove watch class usage from machine class01a0b3e6 fix: add required SQLite storage path flag to compose.yamld133b564 fix(frontend): fix multi-doc parsing when creating single node clusters4f6f0707 chore: update readme img2f1f0f78 test: fix flaky unit tests2ecd603c refactor(frontend): fix some minor lint warnings1f237905 fix: compare current and new kernel args more defensivelyd262e03b feat: allow unrejecting machines from the uid67b25f6 fix: track dependendants for searchFor in watchd7d54916 refactor(frontend): remove <watch> from backupslist8f5d64f8 test: add embedded etcd smoke test to helm e2eccc197b2 refactor: replace the old helm chart with the new one69c2759b fix: break the dep loop in the cluster machine config status controllerdbf34e24 refactor(frontend): add type checking for context inclusion52f249db feat: make more things configurable in the helm chartfbf36740 test: add unit and e2e tests to the helm chart04bcff7a fix: unify helm chart services and ingresses, remove JSON schema0c2c5c1c test: use envsubst in tests and do small improvementsbd86ff31 chore: remove deprecated migration flags, config fields, and migration codeafdf123e feat: add support for Kubernetes CA rotation4c9212f6 refactor: remove global runtime registry, inject runtimes to servicesf845af53 feat(frontend): show pending and historical config diffs in ui939a9a08 chore: expose machine request set id in the provision context7d80fede feat: support custom Vault Kubernetes auth mount path30d17dcf chore: update Go to 1.26 in go.mod, rekres, fix linting issuesd1c869a9 chore: bump deps, rekresa89d270c fix: replace gotextdiff with linear-space Myers diff to prevent OOM05e42f9a feat: expose metrics for sqlite state and add cleanup counters868f8ac1 test: reach maintenance mode machines' Talos API through Omni in testsed5efa5d feat(frontend): for frontend auth flow dont require login clickef3e3bc1 test: use automation sa directly in integration tests6102db4e fix: use single shared etcd backup store factory70c9a549 fix: properly generate upgrade diffs for the imported cluster337bbe6c fix: fix memory leak in the config diff compute code69b8e997 feat: update machinery doc links79f85eec feat: add configuration options for audit log cleanup7e4bc18f feat(frontend): refactor confirm modal with reka-ui4009aa42 fix(frontend): import undefined components and add lint rule0a4dab64 refactor(frontend): rename tbutton type to variante4b1f3b5 refactor(frontend): refactor patches, machine class, and node destroy watches9bca00a7 test(installation-media): write e2e test for the wizarda2eedd8d feat(installation-media): replace modal with wizard by defaultf3cdbda7 refactor: remove global config, inject it to servicesed94ce9c fix: update the error for sqlite libraryf61b72f5 refactor(frontend): reimplement tabs using reka-ui4ef8c73b feat: move omni schematic cache to ephemeralb9bd3f90 refactor: migrate all SQLite usage to zombiezen922d8418 feat(frontend): add instructions on how to export cluster templatesb72b00b4 feat: bump minimum talos version to 1.80906bcc2 fix: prevent unwanted upgrades of non-image-factory machines76fd73f6 feat(frontend): add clarification text to backup settingse60b8091 feat(installation-media): remove hover on table rows and make name clickable3a18fdd5 refactor(frontend): remove <watch> from cluster machineseae8f84e fix: handle deletion event on InstallationMediaConfig validation4cc3a3da test: do not check for empty wipe id in static infra provider test3d2dc7b5 feat(frontend): allow embedding youtube videos8f33ee1e fix: pause cluster machine watches until expandedf2f8842a feat(installation-media): use usedownloadimage composable in download preset modalc319d7bc fix: fix schematic generation for machines in agent modee73acfde chore: update dependenciesb83852a9 feat(installation-media): add download progress and omni specific filenames to images197a7fa8 chore(frontend): update dependenciesdc2c9480 fix: check config generation errors before computing redacted configs7e0bec69 feat(installation-media): backend validation for installation media configs1e24fd22 feat: implement helm chart v2c86c2e02 test: add e2e test to validate machine tabs74e4abf8 feat(installation-media): replace edit naming with clone for installation mediac6cc25c7 feat: add support for Talos CA rotation
</p>
</details><details><summary>2 commits</summary> <p>
9c06846 feat: change the way excluded addresses are specifiedf71a14a feat: add advertised filters to discovery data
</p>
</details><details><summary>2 commits</summary> <p>
854400f feat: bump discovery API to v0.1.80a4c6fd chore: update dependencies and rekres
</p>
</details><details><summary>2 commits</summary> <p>
8863fd8 release(v1.0.14): prepare releasee0c8062 chore: rekres and update dependencies
</p>
</details><details><summary>1 commit</summary> <p>
47fce68 feat: support Go 1.26, rekres
</p>
</details><details><summary>9 commits</summary> <p>
a95f3bf chore: add helper functions for CLI applicationsf2c063b test: add integration tests for ssa logic9de92cf refactor: drop k8s.io/utils8e6f068 fix: bring back legacy syncde675a0 fix: stop using custom dialer for Kubernetes cliente7a89c3 refactor: use fluxcd/ssa instead of kubernetes cli-utils for ssa0a235c0 feat: add early support for Kubernetes 1.363bea212 fix: use new Myers diff algorithm604c56b chore: extract common code to the go-kubernetes package
</p>
</details><details><summary>37 commits</summary> <p>
f0c7a7b release(v1.0.3): prepare releasedd92631 docs: correct path to hack/copy-artifacts.shddc1a83 fix: update Talos to fix rpi_5 buildb3d07e5 docs: remove redundant Kubernetes version prerequisite9666795 fix: values.schema.json8a8da46 feat: adjust security context for user namespace modebc631dc fix: values.schema.json8ea6fe9 feat: add user namespace support with Kubernetes version validation324c464 fix: skip initializing TUF if keyless signing is disableda42b9d9 release(v1.0.2): prepare release80d1ba3 fix: pass nameoptions to verify bundle tooeec01d1 release(v1.0.1): prepare releaseec1c0a7 fix: pass insecure to the cosign new bundle verifier14d0f2a release(v1.0.0): prepare releasea90529c feat: add more security contextsec69fe2 fix: extra kernel args for overlaysaa325ee feat: add Helm docs and schema3c18e05 feat: add Sidero google service account email also to verfiers151feb5 fix: docs url42a1c45 feat: add helm to kresac4718a feat: update Talos and pkgs1d6468e feat: add helm e2e to CI2f0499c feat: added e2e tests2eccf98 fix: made changes on the recommendation of copilote27ea36 feat: Added E2E with KUTTL9f6b9e7 feat: Added additional tests4939747 feat: Added helm unittestsdcaa1db feat: added helmchart1f85622 feat: add cloudflare credentials helper852856d fix: installer internal configc8c6576 release(v1.0.0-beta.0): prepare release56bd21b fix: allow Cache-Control header in CORS83f4d91 fix: clarify bootloader selectionc8c5faa feat: allow using image GET/HEAD API by the JS code on any domainse732d90 feat: support acm for secureboot5f103c1 feat: support copying to clipboardc3532c4 feat: update Talos with GRUB and other fixes
</p>
</details><details><summary>3 commits</summary> <p>
296bf9a feat: add logging to the KMS server2d6b082 feat: add TLS support for KMS server4233ecd chore: bump deps, rekres
</p>
</details>Previous release can be found at v1.5.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Welcome to the v1.5.0-beta.2 release of Omni! *This is a pre-release of Omni*
Welcome to the v1.5.0-beta.2 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
Omni now collects audit logs for operations performed on all user-managed resources, improving security and traceability.
Omni can now generate its own configuration directly from the defined schema. The config merge algorithms were also improved: now the config preserves the default values properly when some sections are overwritten by the user provided config.
The following etcd commands are now usable with Omni managed clusters:
talosctl etcd downgrade validate
talosctl etcd downgrade enable
talosctl etcd downgrade cancel
talosctl etcd forfeit leadership
Added the ability to switch gRPC tunnel modes for connected machines.
Added a dedicated omnictl jointoken omni-endpoint to streamline node registration.
Added support for managing kernel arguments directly within cluster templates.
The built-in code editor for the machine configs now supports different configuration schemas for each Talos version. So the config will be always validated against the currently running Talos version schema.
omnictl Directory SupportThe omnictl sync/apply can now process directories, simplifying bulk resource applications.
The WireGuard endpoint (services.siderolink.wireGuard.endpoint / --siderolink-wireguard-bind-addr) is now respected. Previously, Omni always bound to all interfaces regardless of this setting. Default remains 0.0.0.0:50180.
<details><summary>120 commits</summary> <p>
2aabc02a6 chore: rekres3a7c92784 chore: rekres to disable helm doc generation stepc241820e7 fix: apply AccessPolicy rules on gRPC proxy for Talos backend587356b31 fix: stop generating node unique token in NodeUniqueTokenStatus85ff13f95 feat(installation-media): add step validation to installation media wizard0b33cf8ed feat(installation-media): select defaults for each form step8f1eb588d refactor(frontend): extract route.name into a computed ref0d5d7da62 feat: allow multiple --config-path flags for config merging056d5e4e1 fix: bind wireguard to configured address instead of all interfaces7376edafc fix(installation-media): fix bug when setting arch to amd64c3c483d76 fix(installation-media): clarify bootloader section9bcd356c4 fix: don't submit empty machine labels to create schematic46de2c3aa chore: enable no-explicit-any in frontend and fix errorsd20fd8f0e chore: rekres and generate-frontendbc7725f76 feat(installation-media): implement edit preset functionality77a32346b refactor(installation-media): move form state to its own composablefe713e94c release(v1.5.0-beta.1): prepare release497883423 test: fix failing workload proxy testsa5795c2fa feat: add config descriptions in schema, use them in flags883fadfea feat(installation-media): add review page for installation mediadb1b969b7 refactor(frontend): refactor config patch editd12c92c0a feat(installation-media): allow skipping/jumping between steps993097ae2 fix: fix tmenuitem to not lose reactivity from props98ef83ee4 fix: fix config patches encryption when encryption is disabledaafc74f95 chore: update packagesc87c952ee refactor(frontend): rekres and use request error from fetch.pb.ts0f8a3d6c6 test(e2e): add an e2e test for exposed services680c79482 chore: enable noImplicitAny for typescriptfd82327c2 release(v1.5.0-beta.0): prepare release587bffe8a fix: fix regressions on service api url generation28a2b87d7 feat: create sequential stage controller5cfa4ccbe fix(frontend): fix loading of machine config6a256ac68 fix: open OIDC plugin link in a new tab8b39d5f12 refactor(frontend): refactor patches watchesca61be7e3 chore: remove unused vite-plugin-node-polyfills50901c1ad chore: bump lodash91c8bff46 feat: generate omni config from schema6c2206835 refactor(frontend): refactor nodeoverview watches698dd1465 fix: always show features section in cluster overviewd8df9c11d test: wait for 1 minute for cluster to be destroyedd3ae77c0c chore: bump copyright to 20263804184d1 fix(frontend): keep correct auth flow for cli/workload21a89ae7f docs: update CONTRIBUTING.md2e90fad37 feat: add ominctl jointoken omni-endpoint7919ba7e3 feat(frontend): constrain machine label widthb9a049a31 feat(frontend): close tooltips even if hovered onb12333478 chore: add environment to chromatic.yml9783f4c50 feat(installation-media): change installation media wizard to be route based41506f72f chore: move graceful config rollout logic to the lowest controller level8e4c6e863 test: regression test for machine class scalingb3e430bdf test: add e2e for creating and scaling clusters using machine classes0de90a231 feat: support different config schemas for the code editor72557577a refactor: add a majorMinorVersion function to parse versions into major.minorf18ec16a8 refactor(frontend): refactor some watches to useresourcewatchcb45c1b4d fix: prevent ClusterMachine creation when Machine is not allocatedf56551abc chore: move some tests from e2e upgrades e2e test to misc upgrades test82d9bc5b1 fix: solve new machines not joining omni if they are part of a cluster2d5e58cba chore: rekres and bump deps8f6d01707 chore: bump node to 24.13e7a2fa396 fix(frontend): fix incorrect cluster query checking for disk_encryptionc6aaff0f9 refactor: make namespace implicit in auth package85d099489 chore: separate integration-tests1483aacbd refactor(frontend): expose all vars from watch in watch composablec6b29e52f test: add talemu fixtures and split into talemu + qemu tests87e073f93 fix(frontend): fix lost reactivity on cluster overview pagedff8e1f64 feat: make namespace implicit in k8s and oidc package NewResource functions897db4fb1 test: fix another test flake in redacted machine config tests4db838196 test: remove machine.install.extraKernelArgs from infra machines79ef09b38 test: add an e2e test for destroying a cluster0bea7ecd7 test: fix the flake in redacted machine config test1ac3dd90f feat(installation-media): implement ui for listing saved presetsed77c84c3 fix(frontend): support disabled links for buttons4bf2e0de9 test: fix flaky ECDSA signature generation in TestPlainSignature9514df576 feat: collect audit logs for operations on user managed resourcesde6e2c66f refactor: make namespace implicit in omni resourcesfb08dcaa2 feat(frontend): add extra information to userpilot9503f850c refactor: make namespace implicit in siderolink resources0902357fa fix: correctly filter out tearing down nodes with no finalizers03b76d5ad feat(installation-media): add a button to clear wizard state66e243a23 refactor(installation-media): add metal id const and use gets where possibleef2d931aa chore: rekres and bump deps950ca1b0a refactor(installation-media): extract schematic generation and download links389f04659 feat(frontend): add polymorphic buttons2b53945c7 fix: use uncached reader for imported cluster secrets, fix its test55fd33db3 refactor: make namespace implicit in system & virtual resources0be460205 test: improve test stability87f966ab3 feat: clean up orphaned machine logs from sqlite844207df0 feat(installation-media): implement ui for saving presets01bf66385 feat: support kernel args management in cluster templates8eb0b50d3 chore!: set minimum talos version to 1.7.0535d733ea chore: drop migrations older than v1.1.0e400dd53c fix(frontend): allow selecting all download options for omnictl9726c6bb0 chore(frontend): update dependenciesad027a33b fix(frontend): align cluster machines properly when mixing with classes030ccc8af chore: update slack linksc91658a96 fix: set secureboot for image correctly from download modal865a0b9db fix(frontend): handle missing talos version when upgrading k8s5c98d44bd chore: implement InstallationMediaConfig resourcee2afe7c7a feat: allow omnictl to handle directoriesb433207a9 fix(installation-media): prevent double schematic creation for sbc flowed44eabac fix: ignore labeled MachineSetNodes in the UI same way as for CLIa9ca74be4 chore: bump API version to 2 as old CLI is no longer 100% compatible36c20175e fix: ignore labeled MachineSetNodes in the export and sync CLI cmds6a00bfdf7 fix: run more aggressive compaction for sqlite/metrics40a98bc0b fix: get rid of an exception in the UserInfo3bf0b0046 chore(frontend): update storybook to 10.1.10068093f46 fix: implement size-based machine logs cleanup332599461 fix: prevent audit logs migration from getting stuckd5f6ebf33 fix(installation-media): parse yaml for overlay options before JSON stringifyingdee6d8cae chore: make omnictl download go directly to the image factoryf52e3396d test: refactor TalosUpgradeStatusController tests1d9fbd023 docs: update license link and badge in README48999514b feat: allow Talos APIs for etcd maintenance7ffe5a4db feat(installation-media): allow submitting bootloader to schematic requestd3e4884ba chore: add new fields to the CreateSchematic Omni APIaa6acff63 chore: support resource list based filtering in the DependencyGraph4a973f9fd chore(installation-media): move doc links into icons with tooltipsc1f43fd61 chore(installation-media): remove links for uki, kernel image, initramfs imagee6b18ee18 feat(installation-media): implement final confirmation step for wizardee926cd9e feat: add a way to switch gRPC tunnel mode for the connected machines
</p>
</details><details><summary>16 commits</summary> <p>
2aabc02a6 chore: rekres3a7c92784 chore: rekres to disable helm doc generation stepc241820e7 fix: apply AccessPolicy rules on gRPC proxy for Talos backend587356b31 fix: stop generating node unique token in NodeUniqueTokenStatus85ff13f95 feat(installation-media): add step validation to installation media wizard0b33cf8ed feat(installation-media): select defaults for each form step8f1eb588d refactor(frontend): extract route.name into a computed ref0d5d7da62 feat: allow multiple --config-path flags for config merging056d5e4e1 fix: bind wireguard to configured address instead of all interfaces7376edafc fix(installation-media): fix bug when setting arch to amd64c3c483d76 fix(installation-media): clarify bootloader section9bcd356c4 fix: don't submit empty machine labels to create schematic46de2c3aa chore: enable no-explicit-any in frontend and fix errorsd20fd8f0e chore: rekres and generate-frontendbc7725f76 feat(installation-media): implement edit preset functionality77a32346b refactor(installation-media): move form state to its own composable
</p>
</details><details><summary>4 commits</summary> <p>
ec0e3ae chore: expose more ssa optionsad2fccd feat: add SSA and pruning supportc53fcf6 chore: rekres with latest changes6cf115c feat: provide compatibility for Kubernetes 1.35
</p>
</details><details><summary>29 commits</summary> <p>
b5ba663 fix: avoid pulling Talos core in schematic pkgb2b0cc8 fix: update cosign to v3.0.4fca99d0 chore: update docs/developing.md49f4226 chore: separate kres integration-test variables190aa22 fix: add missing libarchive dependency37bd795 fix: image-factory rootless99cbfd7 fix: don't enforce bundle verifiedcf3e56a chore: bump talos8723b02 fix: drop sbc board supportf0150c4 feat: use rootless Image Factoryf57218f feat: refactor configuration of image factorye440ce7 fix: support new cosign bundle format5eb1775 feat: introduce Enterprise Image Factoryfa266e0 release(v0.9.0): prepare release6799661 feat: show booter command in final wizardfb22bce feat: support selecting bootloadere881e4b feat: bump depsd1bec57 feat: implement schematic GET APIf1dad9d feat: better test matrixbc4f959 fix: remove secureboot talosctl presetdb5e4dc feat: add a prompt about using talosctl cluster create qemu2c5037c chore: bump deps1559666 feat: replace hardcoded artifact image constants with CLI-configurable valuesc27ee27 fix: return 400 when an invalid image name is requested58125d4 feat: support proxying external installer registryd782950 feat: support serving TLS froom Image Factory743fe7f feat: support disable cosign signature verification3a20123 chore: rekres with parallel jobs241963f chore(ci): use runner groups
</p>
</details>Previous release can be found at v1.4.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Welcome to the v1.5.0-beta.1 release of Omni! *This is a pre-release of Omni*
Welcome to the v1.5.0-beta.1 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
Omni now collects audit logs for operations performed on all user-managed resources, improving security and traceability.
Omni can now generate its own configuration directly from the defined schema. The config merge algorithms were also improved: now the config preserves the default values properly when some sections are overwritten by the user provided config.
The following etcd commands are now usable with Omni managed clusters:
talosctl etcd downgrade validate
talosctl etcd downgrade enable
talosctl etcd downgrade cancel
talosctl etcd forfeit leadership
Added the ability to switch gRPC tunnel modes for connected machines.
Added a dedicated omnictl jointoken omni-endpoint to streamline node registration.
Added support for managing kernel arguments directly within cluster templates.
The built-in code editor for the machine configs now supports different configuration schemas for each Talos version. So the config will be always validated against the currently running Talos version schema.
omnictl Directory SupportThe omnictl sync/apply can now process directories, simplifying bulk resource applications.
<details><summary>103 commits</summary> <p>
497883423 test: fix failing workload proxy testsa5795c2fa feat: add config descriptions in schema, use them in flags883fadfea feat(installation-media): add review page for installation mediadb1b969b7 refactor(frontend): refactor config patch editd12c92c0a feat(installation-media): allow skipping/jumping between steps993097ae2 fix: fix tmenuitem to not lose reactivity from props98ef83ee4 fix: fix config patches encryption when encryption is disabledaafc74f95 chore: update packagesc87c952ee refactor(frontend): rekres and use request error from fetch.pb.ts0f8a3d6c6 test(e2e): add an e2e test for exposed services680c79482 chore: enable noImplicitAny for typescriptfd82327c2 release(v1.5.0-beta.0): prepare release587bffe8a fix: fix regressions on service api url generation28a2b87d7 feat: create sequential stage controller5cfa4ccbe fix(frontend): fix loading of machine config6a256ac68 fix: open OIDC plugin link in a new tab8b39d5f12 refactor(frontend): refactor patches watchesca61be7e3 chore: remove unused vite-plugin-node-polyfills50901c1ad chore: bump lodash91c8bff46 feat: generate omni config from schema6c2206835 refactor(frontend): refactor nodeoverview watches698dd1465 fix: always show features section in cluster overviewd8df9c11d test: wait for 1 minute for cluster to be destroyedd3ae77c0c chore: bump copyright to 20263804184d1 fix(frontend): keep correct auth flow for cli/workload21a89ae7f docs: update CONTRIBUTING.md2e90fad37 feat: add ominctl jointoken omni-endpoint7919ba7e3 feat(frontend): constrain machine label widthb9a049a31 feat(frontend): close tooltips even if hovered onb12333478 chore: add environment to chromatic.yml9783f4c50 feat(installation-media): change installation media wizard to be route based41506f72f chore: move graceful config rollout logic to the lowest controller level8e4c6e863 test: regression test for machine class scalingb3e430bdf test: add e2e for creating and scaling clusters using machine classes0de90a231 feat: support different config schemas for the code editor72557577a refactor: add a majorMinorVersion function to parse versions into major.minorf18ec16a8 refactor(frontend): refactor some watches to useresourcewatchcb45c1b4d fix: prevent ClusterMachine creation when Machine is not allocatedf56551abc chore: move some tests from e2e upgrades e2e test to misc upgrades test82d9bc5b1 fix: solve new machines not joining omni if they are part of a cluster2d5e58cba chore: rekres and bump deps8f6d01707 chore: bump node to 24.13e7a2fa396 fix(frontend): fix incorrect cluster query checking for disk_encryptionc6aaff0f9 refactor: make namespace implicit in auth package85d099489 chore: separate integration-tests1483aacbd refactor(frontend): expose all vars from watch in watch composablec6b29e52f test: add talemu fixtures and split into talemu + qemu tests87e073f93 fix(frontend): fix lost reactivity on cluster overview pagedff8e1f64 feat: make namespace implicit in k8s and oidc package NewResource functions897db4fb1 test: fix another test flake in redacted machine config tests4db838196 test: remove machine.install.extraKernelArgs from infra machines79ef09b38 test: add an e2e test for destroying a cluster0bea7ecd7 test: fix the flake in redacted machine config test1ac3dd90f feat(installation-media): implement ui for listing saved presetsed77c84c3 fix(frontend): support disabled links for buttons4bf2e0de9 test: fix flaky ECDSA signature generation in TestPlainSignature9514df576 feat: collect audit logs for operations on user managed resourcesde6e2c66f refactor: make namespace implicit in omni resourcesfb08dcaa2 feat(frontend): add extra information to userpilot9503f850c refactor: make namespace implicit in siderolink resources0902357fa fix: correctly filter out tearing down nodes with no finalizers03b76d5ad feat(installation-media): add a button to clear wizard state66e243a23 refactor(installation-media): add metal id const and use gets where possibleef2d931aa chore: rekres and bump deps950ca1b0a refactor(installation-media): extract schematic generation and download links389f04659 feat(frontend): add polymorphic buttons2b53945c7 fix: use uncached reader for imported cluster secrets, fix its test55fd33db3 refactor: make namespace implicit in system & virtual resources0be460205 test: improve test stability87f966ab3 feat: clean up orphaned machine logs from sqlite844207df0 feat(installation-media): implement ui for saving presets01bf66385 feat: support kernel args management in cluster templates8eb0b50d3 chore!: set minimum talos version to 1.7.0535d733ea chore: drop migrations older than v1.1.0e400dd53c fix(frontend): allow selecting all download options for omnictl9726c6bb0 chore(frontend): update dependenciesad027a33b fix(frontend): align cluster machines properly when mixing with classes030ccc8af chore: update slack linksc91658a96 fix: set secureboot for image correctly from download modal865a0b9db fix(frontend): handle missing talos version when upgrading k8s5c98d44bd chore: implement InstallationMediaConfig resourcee2afe7c7a feat: allow omnictl to handle directoriesb433207a9 fix(installation-media): prevent double schematic creation for sbc flowed44eabac fix: ignore labeled MachineSetNodes in the UI same way as for CLIa9ca74be4 chore: bump API version to 2 as old CLI is no longer 100% compatible36c20175e fix: ignore labeled MachineSetNodes in the export and sync CLI cmds6a00bfdf7 fix: run more aggressive compaction for sqlite/metrics40a98bc0b fix: get rid of an exception in the UserInfo3bf0b0046 chore(frontend): update storybook to 10.1.10068093f46 fix: implement size-based machine logs cleanup332599461 fix: prevent audit logs migration from getting stuckd5f6ebf33 fix(installation-media): parse yaml for overlay options before JSON stringifyingdee6d8cae chore: make omnictl download go directly to the image factoryf52e3396d test: refactor TalosUpgradeStatusController tests1d9fbd023 docs: update license link and badge in README48999514b feat: allow Talos APIs for etcd maintenance7ffe5a4db feat(installation-media): allow submitting bootloader to schematic requestd3e4884ba chore: add new fields to the CreateSchematic Omni APIaa6acff63 chore: support resource list based filtering in the DependencyGraph4a973f9fd chore(installation-media): move doc links into icons with tooltipsc1f43fd61 chore(installation-media): remove links for uki, kernel image, initramfs imagee6b18ee18 feat(installation-media): implement final confirmation step for wizardee926cd9e feat: add a way to switch gRPC tunnel mode for the connected machines
</p>
</details><details><summary>11 commits</summary> <p>
49788342 test: fix failing workload proxy testsa5795c2f feat: add config descriptions in schema, use them in flags883fadfe feat(installation-media): add review page for installation mediadb1b969b refactor(frontend): refactor config patch editd12c92c0 feat(installation-media): allow skipping/jumping between steps993097ae fix: fix tmenuitem to not lose reactivity from props98ef83ee fix: fix config patches encryption when encryption is disabledaafc74f9 chore: update packagesc87c952e refactor(frontend): rekres and use request error from fetch.pb.ts0f8a3d6c test(e2e): add an e2e test for exposed services680c7948 chore: enable noImplicitAny for typescript
</p>
</details><details><summary>4 commits</summary> <p>
ec0e3ae chore: expose more ssa optionsad2fccd feat: add SSA and pruning supportc53fcf6 chore: rekres with latest changes6cf115c feat: provide compatibility for Kubernetes 1.35
</p>
</details><details><summary>29 commits</summary> <p>
b5ba663 fix: avoid pulling Talos core in schematic pkgb2b0cc8 fix: update cosign to v3.0.4fca99d0 chore: update docs/developing.md49f4226 chore: separate kres integration-test variables190aa22 fix: add missing libarchive dependency37bd795 fix: image-factory rootless99cbfd7 fix: don't enforce bundle verifiedcf3e56a chore: bump talos8723b02 fix: drop sbc board supportf0150c4 feat: use rootless Image Factoryf57218f feat: refactor configuration of image factorye440ce7 fix: support new cosign bundle format5eb1775 feat: introduce Enterprise Image Factoryfa266e0 release(v0.9.0): prepare release6799661 feat: show booter command in final wizardfb22bce feat: support selecting bootloadere881e4b feat: bump depsd1bec57 feat: implement schematic GET APIf1dad9d feat: better test matrixbc4f959 fix: remove secureboot talosctl presetdb5e4dc feat: add a prompt about using talosctl cluster create qemu2c5037c chore: bump deps1559666 feat: replace hardcoded artifact image constants with CLI-configurable valuesc27ee27 fix: return 400 when an invalid image name is requested58125d4 feat: support proxying external installer registryd782950 feat: support serving TLS froom Image Factory743fe7f feat: support disable cosign signature verification3a20123 chore: rekres with parallel jobs241963f chore(ci): use runner groups
</p>
</details>Previous release can be found at v1.4.0
Nothing published for this version
Welcome to the v1.5.0-beta.0 release of Omni! *This is a pre-release of Omni*
Welcome to the v1.5.0-beta.0 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
Omni now collects audit logs for operations performed on all user-managed resources, improving security and traceability.
Omni can now generate its own configuration directly from the defined schema. The config merge algorithms were also improved: now the config preserves the default values properly when some sections are overwritten by the user provided config.
The following etcd commands are now usable with Omni managed clusters:
talosctl etcd downgrade validate
talosctl etcd downgrade enable
talosctl etcd downgrade cancel
talosctl etcd forfeit leadership
Added the ability to switch gRPC tunnel modes for connected machines.
Added a dedicated omnictl jointoken omni-endpoint to streamline node registration.
Added support for managing kernel arguments directly within cluster templates.
The built-in code editor for the machine configs now supports different configuration schemas for each Talos version. So the config will be always validated against the currently running Talos version schema.
omnictl Directory SupportThe omnictl sync/apply can now process directories, simplifying bulk resource applications.
<details><summary>91 commits</summary> <p>
587bffe8 fix: fix regressions on service api url generation28a2b87d feat: create sequential stage controller5cfa4ccb fix(frontend): fix loading of machine config6a256ac6 fix: open OIDC plugin link in a new tab8b39d5f1 refactor(frontend): refactor patches watchesca61be7e chore: remove unused vite-plugin-node-polyfills50901c1a chore: bump lodash91c8bff4 feat: generate omni config from schema6c220683 refactor(frontend): refactor nodeoverview watches698dd146 fix: always show features section in cluster overviewd8df9c11 test: wait for 1 minute for cluster to be destroyedd3ae77c0 chore: bump copyright to 20263804184d fix(frontend): keep correct auth flow for cli/workload21a89ae7 docs: update CONTRIBUTING.md2e90fad3 feat: add ominctl jointoken omni-endpoint7919ba7e feat(frontend): constrain machine label widthb9a049a3 feat(frontend): close tooltips even if hovered onb1233347 chore: add environment to chromatic.yml9783f4c5 feat(installation-media): change installation media wizard to be route based41506f72 chore: move graceful config rollout logic to the lowest controller level8e4c6e86 test: regression test for machine class scalingb3e430bd test: add e2e for creating and scaling clusters using machine classes0de90a23 feat: support different config schemas for the code editor72557577 refactor: add a majorMinorVersion function to parse versions into major.minorf18ec16a refactor(frontend): refactor some watches to useresourcewatchcb45c1b4 fix: prevent ClusterMachine creation when Machine is not allocatedf56551ab chore: move some tests from e2e upgrades e2e test to misc upgrades test82d9bc5b fix: solve new machines not joining omni if they are part of a cluster2d5e58cb chore: rekres and bump deps8f6d0170 chore: bump node to 24.13e7a2fa39 fix(frontend): fix incorrect cluster query checking for disk_encryptionc6aaff0f refactor: make namespace implicit in auth package85d09948 chore: separate integration-tests1483aacb refactor(frontend): expose all vars from watch in watch composablec6b29e52 test: add talemu fixtures and split into talemu + qemu tests87e073f9 fix(frontend): fix lost reactivity on cluster overview pagedff8e1f6 feat: make namespace implicit in k8s and oidc package NewResource functions897db4fb test: fix another test flake in redacted machine config tests4db83819 test: remove machine.install.extraKernelArgs from infra machines79ef09b3 test: add an e2e test for destroying a cluster0bea7ecd test: fix the flake in redacted machine config test1ac3dd90 feat(installation-media): implement ui for listing saved presetsed77c84c fix(frontend): support disabled links for buttons4bf2e0de test: fix flaky ECDSA signature generation in TestPlainSignature9514df57 feat: collect audit logs for operations on user managed resourcesde6e2c66 refactor: make namespace implicit in omni resourcesfb08dcaa feat(frontend): add extra information to userpilot9503f850 refactor: make namespace implicit in siderolink resources0902357f fix: correctly filter out tearing down nodes with no finalizers03b76d5a feat(installation-media): add a button to clear wizard state66e243a2 refactor(installation-media): add metal id const and use gets where possibleef2d931a chore: rekres and bump deps950ca1b0 refactor(installation-media): extract schematic generation and download links389f0465 feat(frontend): add polymorphic buttons2b53945c fix: use uncached reader for imported cluster secrets, fix its test55fd33db refactor: make namespace implicit in system & virtual resources0be46020 test: improve test stability87f966ab feat: clean up orphaned machine logs from sqlite844207df feat(installation-media): implement ui for saving presets01bf6638 feat: support kernel args management in cluster templates8eb0b50d chore!: set minimum talos version to 1.7.0535d733e chore: drop migrations older than v1.1.0e400dd53 fix(frontend): allow selecting all download options for omnictl9726c6bb chore(frontend): update dependenciesad027a33 fix(frontend): align cluster machines properly when mixing with classes030ccc8a chore: update slack linksc91658a9 fix: set secureboot for image correctly from download modal865a0b9d fix(frontend): handle missing talos version when upgrading k8s5c98d44b chore: implement InstallationMediaConfig resourcee2afe7c7 feat: allow omnictl to handle directoriesb433207a fix(installation-media): prevent double schematic creation for sbc flowed44eaba fix: ignore labeled MachineSetNodes in the UI same way as for CLIa9ca74be chore: bump API version to 2 as old CLI is no longer 100% compatible36c20175 fix: ignore labeled MachineSetNodes in the export and sync CLI cmds6a00bfdf fix: run more aggressive compaction for sqlite/metrics40a98bc0 fix: get rid of an exception in the UserInfo3bf0b004 chore(frontend): update storybook to 10.1.10068093f4 fix: implement size-based machine logs cleanup33259946 fix: prevent audit logs migration from getting stuckd5f6ebf3 fix(installation-media): parse yaml for overlay options before JSON stringifyingdee6d8ca chore: make omnictl download go directly to the image factoryf52e3396 test: refactor TalosUpgradeStatusController tests1d9fbd02 docs: update license link and badge in README48999514 feat: allow Talos APIs for etcd maintenance7ffe5a4d feat(installation-media): allow submitting bootloader to schematic requestd3e4884b chore: add new fields to the CreateSchematic Omni APIaa6acff6 chore: support resource list based filtering in the DependencyGraph4a973f9f chore(installation-media): move doc links into icons with tooltipsc1f43fd6 chore(installation-media): remove links for uki, kernel image, initramfs imagee6b18ee1 feat(installation-media): implement final confirmation step for wizardee926cd9 feat: add a way to switch gRPC tunnel mode for the connected machines
</p>
</details><details><summary>4 commits</summary> <p>
ec0e3ae chore: expose more ssa optionsad2fccd feat: add SSA and pruning supportc53fcf6 chore: rekres with latest changes6cf115c feat: provide compatibility for Kubernetes 1.35
</p>
</details><details><summary>29 commits</summary> <p>
b5ba663 fix: avoid pulling Talos core in schematic pkgb2b0cc8 fix: update cosign to v3.0.4fca99d0 chore: update docs/developing.md49f4226 chore: separate kres integration-test variables190aa22 fix: add missing libarchive dependency37bd795 fix: image-factory rootless99cbfd7 fix: don't enforce bundle verifiedcf3e56a chore: bump talos8723b02 fix: drop sbc board supportf0150c4 feat: use rootless Image Factoryf57218f feat: refactor configuration of image factorye440ce7 fix: support new cosign bundle format5eb1775 feat: introduce Enterprise Image Factoryfa266e0 release(v0.9.0): prepare release6799661 feat: show booter command in final wizardfb22bce feat: support selecting bootloadere881e4b feat: bump depsd1bec57 feat: implement schematic GET APIf1dad9d feat: better test matrixbc4f959 fix: remove secureboot talosctl presetdb5e4dc feat: add a prompt about using talosctl cluster create qemu2c5037c chore: bump deps1559666 feat: replace hardcoded artifact image constants with CLI-configurable valuesc27ee27 fix: return 400 when an invalid image name is requested58125d4 feat: support proxying external installer registryd782950 feat: support serving TLS froom Image Factory743fe7f feat: support disable cosign signature verification3a20123 chore: rekres with parallel jobs241963f chore(ci): use runner groups
</p>
</details>Previous release can be found at v1.4.0
Your coding agent can read these notes before it upgrades. Set up the MCP server →