NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1414 by repository stars
Last release today
07 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Rarely documented
notes for 13 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
643 releases · first in 2024
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per month.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Once the migration is complete, you are free to remove the deprecated flags listed below. If they remain, they will be ignored and eventually dropped…
Welcome to the v1.4.0-beta.1 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
This release consolidates Discovery service state, Audit logs, Machine logs, and Secondary resources into a single SQLite storage backend.
1. New Required Flag
You must set the new --sqlite-storage-path (or .storage.sqlite.path) flag. There is no default value, and Omni will not start without it.
2. Audit Logging Changes
A new flag --audit-log-enabled (or .logs.audit.enabled) has been introduced to explicitly enable or disable audit logging.
true.3. Automatic Migration Omni will automatically migrate your existing data (BoltDB, file-based logs) to the new SQLite database on the first startup. To ensure this happens correctly, simply add the new SQLite flag and leave your existing storage flags in place for the first run.
Once the migration is complete, you are free to remove the deprecated flags listed below. If they remain, they will be ignored and eventually dropped in future versions.
4. Deprecated Flags (Kept for Migration) The following flags (and config keys) are deprecated and kept solely to facilitate the automatic migration:
--audit-log-dir (.logs.audit.path)--secondary-storage-path (.storage.secondary.path)--machine-log-storage-path (.logs.machine.storage.path)--machine-log-storage-enabled (.logs.machine.storage.enabled)--embedded-discovery-service-snapshot-path (.services.embeddedDiscoveryService.snapshotsPath)--machine-log-buffer-capacity (.logs.machine.bufferInitialCapacity)--machine-log-buffer-max-capacity (.logs.machine.bufferMaxCapacity)--machine-log-buffer-safe-gap (.logs.machine.bufferSafetyGap)--machine-log-num-compressed-chunks (.logs.machine.storage.numCompressedChunks)5. Removed Flags The following flags have been removed and are no longer supported:
--machine-log-storage-flush-period (.logs.machine.storage.flushPeriod)--machine-log-storage-flush-jitter (.logs.machine.storage.flushJitter)Enabled support for OIDC providers, such as Azure, that do not provide the email_verified claim during authentication.
Added support for dynamically updating SAML label roles on every login via the new update_on_each_login field.
Added support for locks, node deletion, and restore operations when using machine classes.
Platform and SBC information is now pulled from Talos machinery and presented as virtual resources:
MetalPlatformConfig, CloudPlatformConfig, and SBCConfig. They support Get and List operations.
Automated installation options have been added to the CLI section of the homepage, supplementing the existing manual options.
A warning toast is now displayed when downloading kubeconfig to inform users that the OIDC plugin is required before using the file with kubectl.
Various UI improvements including pre-selecting the correct binary for the user's platform, truncating long items in the ongoing tasks list, hiding JSON schema descriptions behind tooltips, and standardizing link styling.
Added the ability to force-delete MachineRequests and InfraMachines managed by Infra providers.
This allows for the cleanup of resources and finalizers even if the underlying provider is unresponsive or deleted.
Omni now prevents downgrading the Talos minor version below the initial version used to create the cluster. This safeguard prevents machine configurations from entering a broken state due to unsupported features in older versions.
<details><summary>114 commits</summary> <p>
914c8c0b feat: add min-commit flag for omnidc351150 chore: update http/2 tunneling text9bf690ef refactor: do SQLite migrations unconditionally, rework the config flags2f2ec76f fix: improve kubeconfig error handling for non-existent clusters2182a175 chore(installation-media): update talos version stories mocksa78b1498 feat(installation-media): use join token label when selecting a tokenba403f92 feat(installation-media): add machine user labels to installation media wizardeb978782 feat(installation-media): add http2 wireguard tunnel to installation media wizard728000c7 refactor: extract ClusterMachineConfigStatusController into a moduled6f0433e feat: offer more talosctl versions to download in omni4d11b75e feat: return schematic yml when creating installation media95a54ecb refactor(frontend): add a helper for getting talosctl downloads7b3ffa2a release(v1.4.0-beta.0): prepare released31f7f86 fix: stop referencing deprecated field on frontend storybookd68562f5 feat: add labels to talos version metric2dd0daac fix(frontend): change incorrect copy toast messagee886bb76 feat: store discovery service state in SQLitefbfbb453 fix: do not filter out rc releases to from pre-release talos versionse27cf264 chore: rekres09ef0432 fix(frontend): prevent an error when downloading support bundlec654237b feat(frontend): show a warning toast about oidc when downloading kubeconfig6eea2cab feat(frontend): add automated install options for cli75cc7778 fix(installation-media): check min_version for providers50b2546f feat(installation-media): support talos 1.12.0 bootloader sectiond9c06640 chore(installation-media): rename external args to extra args6ee38310 feat(installation-media): implement external args stepdd0bdb63 feat: store audit logs in sqlitebc2a5a99 chore: prepare omni with talos v1.12.0-beta.124ed384a fix(installation-media): only list architectures supported by providers64e19ed6 fix(installation-media): correct doc links for sbc & cloud steps9826116e fix(installation-media): adjust secureboot support checkba2e77cc fix: change stripe button to billing60cb92a1 feat: prevent downgrading talos minor version below initial version60dac9d5 feat(frontend): hide descriptions in json schema behind tooltipb9a3e4ee chore(frontend): fix monaco-editor worker on dev serverf0646a67 feat(frontend): change default config patch for talos 1.1231d5a1b6 refactor(installation-media): get cloud providers and sbcs from api672a1c42 refactor(frontend): create composables for resource list & get2804426b feat: store machine logs in sqlite741a86f2 fix(frontend): fix backup interval clamping2e2be883 refactor(frontend): wait for signing keys instead of throwing5e8ef874 feat: allow passing extra parameters to sqlite conn string448fb645 fix: trim whitespaces from the initial label keys and values59f4fff1 fix: properly filter the machines which were already added to a clusterd3a9c663 fix(frontend): update csp for userpilot and refactor init logic20c8c3ab feat(frontend): preselect the correct binary for the user's platform where possible297415de feat(frontend): truncate items inside ongoing tasks list9d30ff55 chore: bump dependenciesedb1603c fix(frontend): prevent logout dropdown menu from shrinking5610e71d refactor(frontend): refactor Tooltip to use reka-ui Tooltipc2ab8ab9 refactor(frontend): replace popper with tooltip in PatchEditcc99091a refactor(frontend): replace popper with tooltip + popover in MachineSetPicker7f6be055 refactor(frontend): replace popper with tooltip in TButtonGroupe91711a2 refactor(frontend): refactor TActionsBox with reka-uia96bd3de fix: restore monaco-editor styles by enabling unsafe-inline7b944d08 fix(frontend): constrain sidebar to a fixed size8b5c29b3 feat: support locks,node delete and restore when using machine classesbc01ae0d feat: pull platforms and SBC information from Talos machinery133fa156 fix(frontend): add nonce to apexcharts and add csp to dev2a690593 chore: rewrite MachineSetNodeController as QController23a3594e fix(frontend): sort talosctl versions correctly and select correct default997e4601 feat(frontend): style all regular links with primary6ca43f37 test: pick UKI and non-UKI machines correctly19a6cd12 feat(installation-media): implement system extensions step52360252 fix: do not clear schematic meta values for non-UKI machinesb284d491 refactor: use template instead of bytes replace for nonce78050045 fix: add nonce for userpilot scripts4bcaea1e feat: centralize Schematic ID computation7397f148 feat(installation-media): implement cloud provider + sbc stepsf6ac435b fix: do not allow downloading deprecated Talos versions in the UI29296971 feat: support dynamically updating SAML label rolesb3fd95cd refactor(frontend): change RadioGroup to use slots for optionsbb879bf6 refactor(frontend): refactor pods list and add stories75f70e4d feat: allow force-deletion of machine requests3e3f5134 feat(installation-media): add machine architecture stepe3ef4daa fix: correct handling extra outputs for cleanup controllere1eaf649 refactor(frontend): switch from openpgp to webcryptoe9ac4a8a fix(frontend): keep use_embedded_discovery_service state when scaling519b46d6 fix: make exposed services also support plain keysa973a7a3 fix: fix typos across the project61d09f81 chore(frontend): update dependenciesdb97e092 chore: bump Kubernetes version to 1.34.2cecb9695 chore: rekres3c744d93 fix(frontend): fix exposed services sidebar not appearing85e0f36b feat: allow force-deletion of infra machinescd40dd5f fix: reduce usage of cached state to avoid stale reads03460a9e test: fix flaky etcd backup tests4d0658bb test: fix flaky MachineUpgradeStatusController teste9586a08 fix: use deterministic order for machine extensions88928fe6 fix: move infra provider ID annotations to labels25ae4a18 refactor(auth): extract interceptor from key generation logicfaf286ab fix: keep existing cluster level system extensions config in the UI606fbc4d fix: ignore MachineSets which reference non-existing clusters7cdd62a8 fix(frontend): remove double scrollbar on machines list6df818b2 chore: make FrontendAuthFlow generatedff1d14e6 refactor(auth): extract identity from key generation logic7468e6ea chore: rekres, make linters happy, bump Go, deps and Talos versionse042332e feat(installation-media): implement talos version step1dec8ed7 feat: allow OIDC providers which do not have email_verified claim119c20da fix: keep ClusterMachineRequestStatus while MachineRequest existscb40d4fb feat: support plain keys in the request signatures60a130ea fix: prevent MachineSetStatus from going into create/destroy loope38b3b9b feat(frontend): add a link generator to installation mediab976e2d2 fix: do not skip creating schematic config in agent moded8d6dc4c fix(frontend): only show label outline if selectede3b53cd9 test: use resource cache in unit tests67ad8f4d feat(frontend): add a split button componente38f0ffe fix: remove KernelArgs resource when a machine is removed1a0174dc test: fix install extra kernel args in infra test971353da chore: add basic logic for light/dark theme3244ac4f fix: update MachineRequestStatus resource when we populate UUID85fa6af8 chore: expose enable-talos-pre-release-versions flag in the FeaturesConfig3e90bc6c fix: prevent stale reads of kernel args in schematic id calculation75a9f3ee feat: use sqlite as secondary resource storage
</p>
</details><details><summary>12 commits</summary> <p>
914c8c0b feat: add min-commit flag for omnidc351150 chore: update http/2 tunneling text9bf690ef refactor: do SQLite migrations unconditionally, rework the config flags2f2ec76f fix: improve kubeconfig error handling for non-existent clusters2182a175 chore(installation-media): update talos version stories mocksa78b1498 feat(installation-media): use join token label when selecting a tokenba403f92 feat(installation-media): add machine user labels to installation media wizardeb978782 feat(installation-media): add http2 wireguard tunnel to installation media wizard728000c7 refactor: extract ClusterMachineConfigStatusController into a moduled6f0433e feat: offer more talosctl versions to download in omni4d11b75e feat: return schematic yml when creating installation media95a54ecb refactor(frontend): add a helper for getting talosctl downloads
</p>
</details><details><summary>5 commits</summary> <p>
a5fccd5 release(v1.0.13): prepare release1d3ea34 feat: add support for custom persistent snapshot store0178eff release(v1.0.12): prepare releaseb7b68e0 chore: update dependencies, Go version2c1239f refactor: use DynamicCertificate from crypto library
</p>
</details><details><summary>1 commit</summary> <p>
4c7388b chore: update Go modules, replace YAML library
</p>
</details><details><summary>2 commits</summary> <p>
8b046e5 fix: do not decode the signature in the plain key from base647e98556 feat: support verifying payload using plain ecdsa keys
</p>
</details><details><summary>1 commit</summary> <p>
8454fe9 feat: add upgrade path for 1.35
</p>
</details><details><summary>2 commits</summary> <p>
abfc570 chore: update dependencies, replace YAML librarye0738a9 fix: set pod name in k8s kube-system log filenames
</p>
</details><details><summary>1 commit</summary> <p>
bd9c491 chore: bump and update dependencies
</p>
</details>Previous release can be found at v1.3.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
`d31f7f86` fix: stop referencing deprecated field on frontend storybook
Welcome to the v1.4.0-beta.0 release of Omni!
This is a pre-release of Omni
Please try out the release binaries and report any issues at https://github.com/siderolabs/omni/issues.
Enabled support for OIDC providers, such as Azure, that do not provide the email_verified claim during authentication.
Added support for dynamically updating SAML label roles on every login via the new update_on_each_login field.
Added support for locks, node deletion, and restore operations when using machine classes.
Platform and SBC information is now pulled from Talos machinery and presented as virtual resources:
MetalPlatformConfig, CloudPlatformConfig, and SBCConfig. They support Get and List operations.
Automated installation options have been added to the CLI section of the homepage, supplementing the existing manual options.
A warning toast is now displayed when downloading kubeconfig to inform users that the OIDC plugin is required before using the file with kubectl.
Various UI improvements including pre-selecting the correct binary for the user's platform, truncating long items in the ongoing tasks list, hiding JSON schema descriptions behind tooltips, and standardizing link styling.
Added the ability to force-delete MachineRequests and InfraMachines managed by Infra providers.
This allows for the cleanup of resources and finalizers even if the underlying provider is unresponsive or deleted.
Discovery service state, audit logs, machine logs, and secondary resources have been migrated to use SQLite storage.
Omni now prevents downgrading the Talos minor version below the initial version used to create the cluster. This safeguard prevents machine configurations from entering a broken state due to unsupported features in older versions.
<details><summary>101 commits</summary> <p>
d31f7f86 fix: stop referencing deprecated field on frontend storybookd68562f5 feat: add labels to talos version metric2dd0daac fix(frontend): change incorrect copy toast messagee886bb76 feat: store discovery service state in SQLitefbfbb453 fix: do not filter out rc releases to from pre-release talos versionse27cf264 chore: rekres09ef0432 fix(frontend): prevent an error when downloading support bundlec654237b feat(frontend): show a warning toast about oidc when downloading kubeconfig6eea2cab feat(frontend): add automated install options for cli75cc7778 fix(installation-media): check min_version for providers50b2546f feat(installation-media): support talos 1.12.0 bootloader sectiond9c06640 chore(installation-media): rename external args to extra args6ee38310 feat(installation-media): implement external args stepdd0bdb63 feat: store audit logs in sqlitebc2a5a99 chore: prepare omni with talos v1.12.0-beta.124ed384a fix(installation-media): only list architectures supported by providers64e19ed6 fix(installation-media): correct doc links for sbc & cloud steps9826116e fix(installation-media): adjust secureboot support checkba2e77cc fix: change stripe button to billing60cb92a1 feat: prevent downgrading talos minor version below initial version60dac9d5 feat(frontend): hide descriptions in json schema behind tooltipb9a3e4ee chore(frontend): fix monaco-editor worker on dev serverf0646a67 feat(frontend): change default config patch for talos 1.1231d5a1b6 refactor(installation-media): get cloud providers and sbcs from api672a1c42 refactor(frontend): create composables for resource list & get2804426b feat: store machine logs in sqlite741a86f2 fix(frontend): fix backup interval clamping2e2be883 refactor(frontend): wait for signing keys instead of throwing5e8ef874 feat: allow passing extra parameters to sqlite conn string448fb645 fix: trim whitespaces from the initial label keys and values59f4fff1 fix: properly filter the machines which were already added to a clusterd3a9c663 fix(frontend): update csp for userpilot and refactor init logic20c8c3ab feat(frontend): preselect the correct binary for the user's platform where possible297415de feat(frontend): truncate items inside ongoing tasks list9d30ff55 chore: bump dependenciesedb1603c fix(frontend): prevent logout dropdown menu from shrinking5610e71d refactor(frontend): refactor Tooltip to use reka-ui Tooltipc2ab8ab9 refactor(frontend): replace popper with tooltip in PatchEditcc99091a refactor(frontend): replace popper with tooltip + popover in MachineSetPicker7f6be055 refactor(frontend): replace popper with tooltip in TButtonGroupe91711a2 refactor(frontend): refactor TActionsBox with reka-uia96bd3de fix: restore monaco-editor styles by enabling unsafe-inline7b944d08 fix(frontend): constrain sidebar to a fixed size8b5c29b3 feat: support locks,node delete and restore when using machine classesbc01ae0d feat: pull platforms and SBC information from Talos machinery133fa156 fix(frontend): add nonce to apexcharts and add csp to dev2a690593 chore: rewrite MachineSetNodeController as QController23a3594e fix(frontend): sort talosctl versions correctly and select correct default997e4601 feat(frontend): style all regular links with primary6ca43f37 test: pick UKI and non-UKI machines correctly19a6cd12 feat(installation-media): implement system extensions step52360252 fix: do not clear schematic meta values for non-UKI machinesb284d491 refactor: use template instead of bytes replace for nonce78050045 fix: add nonce for userpilot scripts4bcaea1e feat: centralize Schematic ID computation7397f148 feat(installation-media): implement cloud provider + sbc stepsf6ac435b fix: do not allow downloading deprecated Talos versions in the UI29296971 feat: support dynamically updating SAML label rolesb3fd95cd refactor(frontend): change RadioGroup to use slots for optionsbb879bf6 refactor(frontend): refactor pods list and add stories75f70e4d feat: allow force-deletion of machine requests3e3f5134 feat(installation-media): add machine architecture stepe3ef4daa fix: correct handling extra outputs for cleanup controllere1eaf649 refactor(frontend): switch from openpgp to webcryptoe9ac4a8a fix(frontend): keep use_embedded_discovery_service state when scaling519b46d6 fix: make exposed services also support plain keysa973a7a3 fix: fix typos across the project61d09f81 chore(frontend): update dependenciesdb97e092 chore: bump Kubernetes version to 1.34.2cecb9695 chore: rekres3c744d93 fix(frontend): fix exposed services sidebar not appearing85e0f36b feat: allow force-deletion of infra machinescd40dd5f fix: reduce usage of cached state to avoid stale reads03460a9e test: fix flaky etcd backup tests4d0658bb test: fix flaky MachineUpgradeStatusController teste9586a08 fix: use deterministic order for machine extensions88928fe6 fix: move infra provider ID annotations to labels25ae4a18 refactor(auth): extract interceptor from key generation logicfaf286ab fix: keep existing cluster level system extensions config in the UI606fbc4d fix: ignore MachineSets which reference non-existing clusters7cdd62a8 fix(frontend): remove double scrollbar on machines list6df818b2 chore: make FrontendAuthFlow generatedff1d14e6 refactor(auth): extract identity from key generation logic7468e6ea chore: rekres, make linters happy, bump Go, deps and Talos versionse042332e feat(installation-media): implement talos version step1dec8ed7 feat: allow OIDC providers which do not have email_verified claim119c20da fix: keep ClusterMachineRequestStatus while MachineRequest existscb40d4fb feat: support plain keys in the request signatures60a130ea fix: prevent MachineSetStatus from going into create/destroy loope38b3b9b feat(frontend): add a link generator to installation mediab976e2d2 fix: do not skip creating schematic config in agent moded8d6dc4c fix(frontend): only show label outline if selectede3b53cd9 test: use resource cache in unit tests67ad8f4d feat(frontend): add a split button componente38f0ffe fix: remove KernelArgs resource when a machine is removed1a0174dc test: fix install extra kernel args in infra test971353da chore: add basic logic for light/dark theme3244ac4f fix: update MachineRequestStatus resource when we populate UUID85fa6af8 chore: expose enable-talos-pre-release-versions flag in the FeaturesConfig3e90bc6c fix: prevent stale reads of kernel args in schematic id calculation75a9f3ee feat: use sqlite as secondary resource storage
</p>
</details><details><summary>5 commits</summary> <p>
a5fccd5 release(v1.0.13): prepare release1d3ea34 feat: add support for custom persistent snapshot store0178eff release(v1.0.12): prepare releaseb7b68e0 chore: update dependencies, Go version2c1239f refactor: use DynamicCertificate from crypto library
</p>
</details><details><summary>1 commit</summary> <p>
4c7388b chore: update Go modules, replace YAML library
</p>
</details><details><summary>2 commits</summary> <p>
8b046e5 fix: do not decode the signature in the plain key from base647e98556 feat: support verifying payload using plain ecdsa keys
</p>
</details><details><summary>1 commit</summary> <p>
8454fe9 feat: add upgrade path for 1.35
</p>
</details><details><summary>2 commits</summary> <p>
abfc570 chore: update dependencies, replace YAML librarye0738a9 fix: set pod name in k8s kube-system log filenames
</p>
</details><details><summary>1 commit</summary> <p>
bd9c491 chore: bump and update dependencies
</p>
</details>Previous release can be found at v1.3.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →