NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #305 by repository stars
Last release today
01 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Some releases are documented
notes for 17 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
3045 releases · first in 2018
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Welcome to the v1.14.0-alpha.0 release of Talos! *This is a pre-release of Talos*
Welcome to the v1.14.0-alpha.0 release of Talos!
This is a pre-release of Talos
Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues.
The default installer image has been updated to use the Image Factory.
HostDNS configuration was moved from the v1alpha1 config .machine.features.hostDNS field to the new hostDNS in the ResolverConfig document.
Talos now supports Network Time Security (NTS) for secure time synchronization. This feature enhances the security of NTP by providing cryptographic authentication of time sources.
NTS is enabled by default (without any configuration sources) for the default time.cloudflare.com time server
NTS can be enabled for custom time servers via the new useNTS field in the TimeServerConfig document.
Talos now runs etcd and kube-apiserver with a minimum TLS version of 1.3, improving security by leveraging the latest TLS features and cipher suites. Custom settings for cipher suites have been removed, as they are ignored when TLS 1.3 is used, which simplifies configuration and ensures the use of modern, secure defaults.
Linux: 6.18.25 Kubernetes: 1.36.0
Talos is built with Go 1.26.2.
<details><summary>103 commits</summary> <p>
8a037a56e test: fix flaky tests08c81d838 feat: bump kernel to 6.18.25fe40b6e58 fix(ci): fetch empty pr labels837a9ed07 feat: move host DNS config into ResolverConfig96a8ecd1e feat: default to factory installer imagef19eef78b fix: revert add extraArgs from service-account-issuer6821225b6 fix: revert use append instead of prepend in service-account-issuerb43c3a124 feat: add quirk for talosctl factory downloadsdf0b9a8da refactor: make all controller unit-test follow modern patternsc2948cef2 feat: support auth for Image Factory in cluster create560bcf0ca feat: enforce TLS 1.3 minmum version for Kubernetes components3db14309e fix(talosctl): ensure uncordon runs after reboot/upgrade errorsecf2fa855 feat: update Kubernetes to v1.36.071557eadd fix(ci): skip misc jobs not on pull request026313b7c docs: rename security-insights.yml to lowercase for LFX detectiondc4ffd490 fix(ci): fix jobs not interpolating matrix due to condition25e2f37e2 chore: generate comments for fields in resource proto149592fa5 fix: watch kubelet's kubeconfig and time out for cache sync1f315e6e9 feat: update Linux to 6.18.230198eedc2 feat: add NTS (Network Time Security) support for NTP time sync6830a8b97 fix(ci): matrix jobs cleanups71aeb347f test: fix OOM test flake9b9542cc5 test: fix a flake in the manifest sync test863d882b6 test: add image verification for factory.talos.devbba0b4aee chore(ci): nvidia update helm values3399ff4de fix: propagate route table down to the resourcec684ec60e chore: prepare for Talos 1.14 releaseed9545d0d chore(ci): bump gpu operator version4de3e4393 fix(ci): cron triggered workflows212182e6f chore: bump container registry libraryc028db0b8 fix: do not flip machine stage to rebooting during shutdown6ce62d9e8 fix(ci): workflow runs with workflow_run509cd9733 fix: boot entry detection5e3f30188 feat(ci): rework to schedule daily runs after a cron7fa4d3919 fix: zfs extensions test1ef8e630a test: allow more tests to run in FIPS strict modebdcc9321b fix: reduce memory dashboard usage2d177af82 chore: update Syft to v1.42.4+patches0d8362119 fix: return failed precondition on upgrade when not installedbe58eafab fix: wrong slot of encryption key was logged015081c76 feat: update dependencies9fbb7c95d fix: audit trustd code for security986e97fc7 feat: update Flannel to 0.28.4f3817d1d1 chore: update sign images to support image name suffixe776721f3 feat: update Kubernetes 1.36.0-rc.1f6e7346fa fix: encode extra args fields in resources with new id3c7bb80ba chore: bump tools3ba35c9b9 chore(ci): nvidia try UKI boote3e8f01ca chore: bump tools181584a5f fix: handle boot failurec464c7e88 fix: upgrade API in maintenance mode (legacy)b7512d912 feat: update Kubernetes to 1.36.0-rc.04ba11156f refactor: allow overriding out image name suffixc81aa125c fix: panic in reading PCR values6a3ab87c5 feat(ci): add nvidia arm64 matrix21f459aab fix(talosctl): always use default GRPC dial optionsca208e514 fix: validate hostDNS forwarding requires hostDNS to be enabled9fcb9e05b feat: bump go to 1.26.20bfdf7f70 fix: create correct blackhole routes for IPv452b920032 feat: add client-side Kubernetes node drain to reboot and upgrade commands968ec1e0c refactor: propagate NAME properly, allow to set on buildacc69c346 fix: set the minimum TLS version to 1.30cfa6e302 chore: bump some tool dependencies4229bb9d2 feat: add dis-vulncheck toold697f5538 fix: don't set xattrs while decompressing extensions34fb2cbe5 refactor: remove manual shell completion and replace with cobra completion79fa2e300 feat: allow more nvidia and nvme files from extensions414f78a29 feat: allow glibc ld files in etc1bbba4301 feat: update Flannel to v0.28.255815e0fa fix: handle ISOs with zeroes in volume labels7b6ab0c1c feat: add flag to force fallback to legacy upgrade5e24d5265 feat: add resource view to talosctl dashboard649ab7fe4 fix: add os:meta:writer role to the dashboard10cdfa909 fix: drop talosctl install087ced85f fix: unseal with "slow" TPM11ab0a8c5 fix: drop unused type from ExternalVolume schemae2df0f6ce fix: always grow disks919d8c365 chore: drop debug shell783a35851 fix: add metal-agent mode to runtime capabilities37b2221cc docs: add SECURITY-INSIGHTS.yml for OSPS Baseline QA-04.01bed2bd414 feat: add graceful power off support to QEMU VM launcher3400059cc fix: incorrect route source for on-link routesb3dfbf743 feat: bump musl to 1.2.64227921b3 test: fix the PKI mismatch test flakef2bc2dcc6 feat: update NVIDIA production drivers to 595.58.03aa5946dd3 test: fix cron failures for provision-1 & provision-21dd701efa fix: allow blockdevice wipe in maintenance mode786bf00ab feat: add --platform=all support to image cache-createe1f645e3c feat: validate luks headers for tamperingad72c7300 test: improve maintenance API provision tests70cefab6a test: fix the flakes in tests with trusted rootsaacff17f4 test: bump memory for Flannel netpolicy tests9c3459114 feat: update Linux to 6.18.19, CNI to 1.9.1038cb8735 feat: enforce PID check on connections to services over file socketse2b2dd3ea chore: update go-kubernetes library9597714f6 fix: add symlinks nvidia-ctk and nvidia-cdi-hook in /usr/bin8ac47d677 fix: unset rlimits for extension servicesb1a02f368 feat: update Kubernetes to 1.36.0-beta.0362fdc9ec feat: update etcd to 3.6.90a47f40b3 fix(machined): clear stale bond ARP/NS targets on decode86344639f fix: update diff library to v1.0.1eff89d1ed fix: panics in diff algorithms8e1c8a7a9 test: fix the apid test against AWS/GCP
</p>
</details><details><summary>2 commits</summary> <p>
d0b8f82 chore: rekres and bump depsc356eeb fix: fix context conflict detection add New() constructor
</p>
</details><details><summary>3 commits</summary> <p>
d670c42 chore: bump dependencies8614c71 chore: bump deps80677e0 fix: propagate the headers before the message
</p>
</details><details><summary>22 commits</summary> <p>
6a53a93 feat: bump kernel to 6.18.25f567bce feat: disable more stuff in Kconfigffd9790 feat: bump kernel to 6.18.24b7c709a feat: bump depse5e5b3c feat: update Linux to 6.18.231a4cd20 fix: renovate configd0ed6ed feat: update dependencies6ea49c7 fix: support disabling module signature verification6520ec4 feat: update containerd to 2.2.337ce992 feat: enable CONFIG_UHID and CONFIG_INPUT_JOYDEV as modulescddd934 feat: update backportable dependencies32e4077 feat: update OpenSSL2d241e7 feat: update Go to 1.26.2 and small deps updates7f540ce feat: disable dynamic SCS3bef043 feat: update runc to 1.4.2c6e6f10 feat: update Linux to 6.18.21a9e8afa fix: libarchive install prefixe4d0113 feat: update for musl 1.2.69142603 feat: update NVIDIA production to 595.58.0322fa669 feat: update Linux to 6.18.1903680ae feat: update containerd patch verifier rolebdc239e feat: enable CHECKPOINT_RESTORE option
</p>
</details><details><summary>1 commit</summary> <p>
9b8a14e chore: bump dependencies
</p>
</details><details><summary>1 commit</summary> <p>
0a1933c chore: bump dependencies
</p>
</details><details><summary>7 commits</summary> <p>
44ad18c feat: bump depsf3d0dd9 fix: renovate configs4ac4449 feat: update dependencies027744f feat: bump OpenSSL to 3.6.27067f1f feat: update util-linux to 2.41.46cb3e56 feat: update Go to 1.26.29186c5f feat: update musl to 1.2.6
</p>
</details>Previous release can be found at v1.13.0
Welcome to the v1.13.11 release of Talos!
Welcome to the v1.13.11 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
The TimeService/TimeCheck API (talosctl time --check) is no longer available to the os:reader role, as it allows querying
arbitrary time servers from the node. The TimeService/Time API (querying the configured time server) is still available to os:reader.
PTP device paths are now strictly validated both in the machine configuration and in the API: the path should be directly under /dev,
the name should start with ptp (e.g. /dev/ptp0, /dev/ptp_kvm), and the device should be a PTP character device.
Linux: 6.18.54
containerd: 2.2.9
Talos is built with Go 1.26.7
Previous release can be found at v1.13.10
ghcr.io/siderolabs/flannel:0.28.8
registry.k8s.io/coredns/coredns:v1.14.7
registry.k8s.io/etcd:v3.6.14
registry.k8s.io/pause:3.10.1
registry.k8s.io/kube-apiserver:v1.36.3
registry.k8s.io/kube-controller-manager:v1.36.3
registry.k8s.io/kube-scheduler:v1.36.3
registry.k8s.io/kube-proxy:v1.36.3
ghcr.io/siderolabs/kubelet:v1.36.3
registry.k8s.io/networking/kube-network-policies:v1.1.0
ghcr.io/siderolabs/installer:v1.13.11
ghcr.io/siderolabs/installer-base:v1.13.11
ghcr.io/siderolabs/imager:v1.13.11
ghcr.io/siderolabs/talos:v1.13.11
ghcr.io/siderolabs/talosctl-all:v1.13.11
ghcr.io/siderolabs/overlays:v1.13.11
ghcr.io/siderolabs/extensions:v1.13.11
Welcome to the v1.13.10 release of Talos!
Welcome to the v1.13.10 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Linux: 6.18.48
CoreDNS: 1.14.7
Talos is built with Go 1.26.7
Previous release can be found at v1.13.9
ghcr.io/siderolabs/flannel:0.28.8
registry.k8s.io/coredns/coredns:v1.14.7
registry.k8s.io/etcd:v3.6.14
registry.k8s.io/pause:3.10.1
registry.k8s.io/kube-apiserver:v1.36.3
registry.k8s.io/kube-controller-manager:v1.36.3
registry.k8s.io/kube-scheduler:v1.36.3
registry.k8s.io/kube-proxy:v1.36.3
ghcr.io/siderolabs/kubelet:v1.36.3
registry.k8s.io/networking/kube-network-policies:v1.1.0
ghcr.io/siderolabs/installer:v1.13.10
ghcr.io/siderolabs/installer-base:v1.13.10
ghcr.io/siderolabs/imager:v1.13.10
ghcr.io/siderolabs/talos:v1.13.10
ghcr.io/siderolabs/talosctl-all:v1.13.10
ghcr.io/siderolabs/overlays:v1.13.10
ghcr.io/siderolabs/extensions:v1.13.10
Welcome to the v1.13.9 release of Talos!
Welcome to the v1.13.9 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Linux: 6.18.44
containerd: 2.2.7
Kubernetes: 1.36.3
Talos is built with Go 1.26.6.
Previous release can be found at v1.13.8
ghcr.io/siderolabs/flannel:0.28.8
registry.k8s.io/coredns/coredns:v1.14.6
registry.k8s.io/etcd:v3.6.12
registry.k8s.io/pause:3.10.1
registry.k8s.io/kube-apiserver:v1.36.3
registry.k8s.io/kube-controller-manager:v1.36.3
registry.k8s.io/kube-scheduler:v1.36.3
registry.k8s.io/kube-proxy:v1.36.3
ghcr.io/siderolabs/kubelet:v1.36.3
registry.k8s.io/networking/kube-network-policies:v1.1.0
ghcr.io/siderolabs/installer:v1.13.9
ghcr.io/siderolabs/installer-base:v1.13.9
ghcr.io/siderolabs/imager:v1.13.9
ghcr.io/siderolabs/talos:v1.13.9
ghcr.io/siderolabs/talosctl-all:v1.13.9
ghcr.io/siderolabs/overlays:v1.13.9
ghcr.io/siderolabs/extensions:v1.13.9
This tag was signed with the committer’s verified signature .
smira Andrey Smirnov
GPG key ID: 322C6F63F594CE7C
Verified Learn about vigilant mode .
Welcome to the v1.13.9 release of Talos!
Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues.
Linux: 6.18.44 containerd: 2.2.7 Kubernetes: 1.36.3
Talos is built with Go 1.26.6.
<details><summary>6 commits</summary> <p>
9ade215ce feat: update Kubernetes to 1.36.314343cd29 test: save the provision test logsb33e5fce2 fix: support try mode apply without prior config6a8f29591 fix: share IPC namespace with the host for extension servicesb525b8290 fix: size the receive/send buffers for nftables netlink7ac52642c feat: update Go to 1.26.6
</p>
</details><details><summary>5 commits</summary> <p>
f541ca4 feat: bump kernel to 6.18.44a4f2c26 feat: bump kernel to 6.18.4379a7531 feat: update Linux firmware to 2026081089d76bf feat: update backportable dependenciesaf6c08a feat: update Go to 1.26.6
</p>
</details><details><summary>1 commit</summary> <p>
a201d19 feat: update Go to 1.26.6
</p>
</details>Previous release can be found at v1.13.8
Welcome to the v1.13.8 release of Talos!
Welcome to the v1.13.8 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Linux: 6.18.42
CoreDNS: 1.14.6
Flannel: 0.28.8
Talos is built with Go 1.26.5.
Previous release can be found at v1.13.7
ghcr.io/siderolabs/flannel:0.28.8
registry.k8s.io/coredns/coredns:v1.14.6
registry.k8s.io/etcd:v3.6.12
registry.k8s.io/pause:3.10.1
registry.k8s.io/kube-apiserver:v1.36.2
registry.k8s.io/kube-controller-manager:v1.36.2
registry.k8s.io/kube-scheduler:v1.36.2
registry.k8s.io/kube-proxy:v1.36.2
ghcr.io/siderolabs/kubelet:v1.36.2
registry.k8s.io/networking/kube-network-policies:v1.1.0
ghcr.io/siderolabs/installer:v1.13.8
ghcr.io/siderolabs/installer-base:v1.13.8
ghcr.io/siderolabs/imager:v1.13.8
ghcr.io/siderolabs/talos:v1.13.8
ghcr.io/siderolabs/talosctl-all:v1.13.8
ghcr.io/siderolabs/overlays:v1.13.8
ghcr.io/siderolabs/extensions:v1.13.8
Welcome to the v1.13.8 release of Talos!
Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues.
Linux: 6.18.42 CoreDNS: 1.14.6 Flannel: 0.28.8
Talos is built with Go 1.26.5.
<details><summary>13 commits</summary> <p>
76de777df chore: update dependencies77d5fe2cc chore: update pkgsa7db9b227 fix: verify the public key signed images correctlyd76938912 fix: use context without cancelation for etcd locks3a2abc01e fix: redact resource specs in the merge controllers153179702 fix(machined): preserve health when services reach runningfc757545c fix: race with PCR extensions and volume unlock2a51fb18f feat: update Flannel to 0.28.805471d31d feat: update CoreDNS to 1.14.69e0b1caba fix: volume mount race (third attempt) around service restartc5cb36528 fix: ignore insecure-only imager assetsc67b10d29 test: update Calico in canal reset test9eca6ea4a fix: preserve trailing rate-limited trigger events
</p>
</details><details><summary>6 commits</summary> <p>
f677246 chore: update kernel6c5daf2 chore: replace gnu mirror4304e87 feat: bump kernel to 6.18.41e66edeb feat: enable PCF8523 RTC support for arm64b2e51fc feat: bump kernel to 6.18.4033195c5 feat: enable CONFIG_NFT_SOCKET in the kernel
</p>
</details>Previous release can be found at v1.13.7
Welcome to the v1.13.7 release of Talos!
Welcome to the v1.13.7 release of Talos!
Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues.
Linux: 6.18.39 containerd: 2.2.6 Flannel: 0.28.7 CoreDNS: 1.14.4
Talos is built with Go 1.26.5.
<details><summary>18 commits</summary> <p>
fc6f9b173 test: add nginx to the image cache integrationc6c435ba7 test: increase resource inmem buffer to stabilize the tests202dc152a fix: add ca-certificates to talosctl3a14c8d36 fix: vrf sortinga4c1e6eb4 fix: oom podruntime protection57b861657 feat: bump CoreDNS, Flannel58a78fe22 fix: use symlinks for init aliases428872bf4 fix: do proper backoff for NTP Kiss-of-Death responses1d55e281a feat: add iommufd as a kernel module576638def fix: make audit restartable76328f941 fix: avoid image cache mount request churn46f9ac675 feat: bring in ifb.ko module0d752e784 fix: provide correct handler for Ctrl-Alt-Delete sequencefe9d33095 fix: terminate log persistence a bit harder7c8021a3e feat: add --no-reboot flag to upgrade cmda155bad1b fix: do not block volume lifecycle teardown on failed user volumesc63f0789a fix: flaky tests2bf6b7462 feat: bring in Linux 6.18.39, containerd 2.2.6
</p>
</details><details><summary>6 commits</summary> <p>
91fe0a0 feat: update Linux to 6.18.391018556 feat: enable CONFIG_IOMMUFD and CONFIG_VFIO_DEVICE_CDEVd529479 chore: bump nvidia to 580.167.08971fd23 fix: enable CONFIG_IFB as a moduleacece91 feat: update DRBD to 9.3.3b91905c feat: update containerd to 2.2.6
</p>
</details><details><summary>1 commit</summary> <p>
c2844e6 feat: update util-linux to 2.42.2
</p>
</details>Previous release can be found at v1.13.6
Welcome to the v1.13.6 release of Talos!
Welcome to the v1.13.6 release of Talos!
Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues.
Linux: 6.18.38
Talos is built with Go 1.26.5.
<details><summary>14 commits</summary> <p>
9d8e47dd3 chore: update pkgs and tools31552f400 fix: shutdown/reboot via usermode helpersbc0c3f3d3 fix: flaky serviceaccount suite test3e7559258 fix: flaky testsfbe4d900d fix: data race in manifest sync6df3a452b fix: provide cooldown period for the QoS trigger85f8dd63e fix: decode extraArgs list values correctlyc2a56d592 fix: kubelet stuck restarting871440858 chore: bump rekor for GHSA-47q9-m4ww-924m3e37ef8cd fix: handle image cache being disabled466bcd804 fix: align documented image cache partition labeld3cf09bcb fix: image verification with referrerse9609b992 feat: add AMD XGBE driver to initramfsf18efcc4d chore: update deps
</p>
</details><details><summary>1 commit</summary> <p>
c526410 fix: skip unknown-key check for types with custom YAML unmarshaler
</p>
</details><details><summary>7 commits</summary> <p>
d8c80cc chore: update toolchain and tools71874fb feat: bump kernel to 6.18.38a2406a1 feat: bump kernel 6.18.37e410c35 feat: update Linux firmware to 20260622389b8aa fix: patch Linux kernel for tunnel metadata buffer overflow7e4a719 feat: add support for AMD XGBE driver1915c58 feat: enable NF_TABLES_ARP option
</p>
</details><details><summary>1 commit</summary> <p>
c58afd5 chore: bump toolchain
</p>
</details>Previous release can be found at v1.13.5
Welcome to the v1.13.5 release of Talos!
Welcome to the v1.13.5 release of Talos!
Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues.
Linux: 6.18.36 containerd: 2.2.5 runc: 1.4.3
Talos is built with Go 1.26.4.
<details><summary>8 commits</summary> <p>
c5089c655 fix: bump number of open files for etcde0b4d9d75 fix: stop the log persistence and close all files on shutdown23a080dcf fix: honor FailurePauseTimeout when pausing before reboot9adc63a32 fix: correct the link alias conditionb902f9de9 feat: verify go.mod tidiness in generate target765f0a1dc fix: relax LUKS header validationd63aba4c7 feat: update pkgs and Kubernetesf0a5842ab fix: update go.mod and rekres
</p>
</details><details><summary>8 commits</summary> <p>
6b315f7 chore: update zfs to 2.4.3ebf23f3 feat: update Linux to 6.18.367eed62d chore: bump containerd to 2.2.5 (cve patches)8b67bab chore: update nvidia driver lts to 580.167.088cb61b2 feat: bump runcd736aef feat: bump kernel to 6.18.357ede376 fix: avoid page_table_check BUG on time namespace VVAR pagee69debd feat: update tools and rekres
</p>
</details><details><summary>2 commits</summary> <p>
9b78252 feat: update ca-certificates to 2026-05-144d13aff feat: bump OpenSSL to 3.6.3
</p>
</details>Previous release can be found at v1.13.4
Nothing published for this version
Welcome to the v1.13.4 release of Talos!
Welcome to the v1.13.4 release of Talos!
Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues.
Linux: 6.18.34 etcd: v2.6.12 Flannel: v0.28.5
Talos is built with Go 1.26.4.
<details><summary>16 commits</summary> <p>
27d7a1985 fix: handle cluster-scoped resources with a namespace correctlyfe74e00fb chore: update depsf44cafbcd fix: recreate dns server and listeners on host DNS runner restart5ed296b76 fix: marshal kube-scheduler config correctly with int types5992015b0 fix: machine configuration schemasb8dfda7ee fix: mark more resources as sensitiveaad841b7f feat: update Flannel to v0.28.57c0900b85 fix(ci): aws nvidia tests9f5122db7 fix: flaky testcf62af3e2 fix: etcd client leak in the (legacy) Upgrade APId5c3136e0 feat: enforce strict QoS ordering in OOM victim selectionb5ad39e65 feat: update etcd to v3.6.12c83dad3c5 fix: health request server-side577cc6f6c fix: bring in a change to BCM2712_MIP29da68ae2 fix: touch rootfs files with SOURCE_DATE_EPOCHb19a03bc2 fix: ignore cgroups with zero rank in OOM handler
</p>
</details><details><summary>1 commit</summary> <p>
131a2bd fix: handle cluster-scoped resources with a ns correctly
</p>
</details><details><summary>5 commits</summary> <p>
54ec9fc fix: disable PAGE_TABLE_CHECK_ENFORCED in kernel config0d5985a feat: enable USB hiddev for apcupsd support593e34c feat: bump kernel to 6.18.34366f575 fix: enable CONFIG_BCM2712_MIP as built-in in arm64 kernel configb45e84c feat: bump Go to 1.26.4
</p>
</details><details><summary>2 commits</summary> <p>
Previous release can be found at v1.13.3
Welcome to the v1.13.3 release of Talos!
Welcome to the v1.13.3 release of Talos!
Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues.
Linux: 6.18.33 Kubernetes: 1.36.1 containerd: 2.2.4
Talos is built with Go 1.26.3.
<details><summary>18 commits</summary> <p>
f4d451054 feat(ci): rotate credentials01b434870 fix: guard apply config API calla42c37f24 feat(machined): support instance tags on Akamaid62d54ca7 fix: memorymodules resource reportingb673b4be7 fix: bump Go golang.org/x modules19755ad14 feat: add bnxt_re module to the rootfs532bc6baa fix: relax hostname config validation3bbd3ed35 fix: bump Kubernetes to 1.36.1 in one more place472b9d991 feat: update default Kubernetes version to 1.36.16d53ce0d5 chore(ci): fix cloud image upload job name5633c7791 fix: rework how scheduler config is marshaled52f056084 fix: restore some shared (and some lower tier slave) mount propagation9de3c12d9 fix: image verification issue with registry.k8s.io7dc716d85 feat: redact more machine config secrets and audit redactorsd5448c60d chore(ci): try fixing homebrew actionef9f0bf02 docs: drop controlplane endpoint examples7ee3e787b feat: update Linux to 6.18.33e99744bad fix: update containerd to 2.2.4
</p>
</details><details><summary>1 commit</summary> <p>
063f5dc chore: rekres + new testdata
</p>
</details><details><summary>12 commits</summary> <p>
8c18616 feat: pre-generate drbd patches using spatch out of tree82e70a0 feat: update Linux to 6.18.33993d4a6 feat: enable PPP and INFINIBAND_BNXT_RE12d5337 feat: enable more options for CRI-U checkpoint/restorec2e43aa feat: preserve System.map on kernel builds230b4bc chore: update deps847a37e feat: bump kernel 6.18.32d7ae843 feat: update Linux to 6.18.31a26d3c0 feat: update ZFS & NVIDIA LTS94d28c5 feat: update Linux to 6.18.30b3dd525 fix: macb silent TX stall on BCM2712/RP1 (v2 patches from netdev)8bdd5e0 feat: update containerd to 2.2.4
</p>
</details>Previous release can be found at v1.13.2
Welcome to the v1.13.2 release of Talos!
Welcome to the v1.13.2 release of Talos!
Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues.
Etcd: 3.6.11 Linux: 6.18.29
Talos is built with Go 1.26.3.
<details><summary>0 commit</summary> <p>
</p> </details>
This release has no dependency changes
Previous release can be found at v1.13.1
Welcome to the v1.13.1 release of Talos!
Welcome to the v1.13.1 release of Talos!
Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues.
Etcd: 3.6.11 Linux: 6.18.29
Talos is built with Go 1.26.3.
<details><summary>26 commits</summary> <p>
09ead22a3 test: relax kernel-default routing rule assertion817609677 feat: update Go to 1.26.3a5f32abda fix: normalize source name for syft consistencyf8298948a feat: bump in-toto indirect dependencyded9a2d78 feat: update kernel to 6.18.29755628239 fix: handle empty GCP operation errorse7645ba1c fix: clarify documentation for image verification patterne85d01a07 fix: skip reserved routing rule prioritiesc5a81f2cc feat: update etcd to 3.6.1138ca2bca6 fix: add missing kernel modules in rootfsdc30ad327 fix: preserve DHCP DNS serversd8e32fa73 fix: stale discovered volume children80c110c87 fix: re-enable kexec on arm64bd9ac044e fix: provide proper AWS platform metadata549f3c0b4 fix: panic in Kubernetes manifest sync29eb6651d fix(ci): zfs test4b36fc9c2 fix: deadlock in the makefs ext4 with populated sourcefdf4f9f6c fix: do not pick up a system disk from a loop device4ff29cc9f fix(talosctl): protect k8sNames map writes with mutexff53434c9 fix: mount throws EPERM on virtiofs with SELinux16cc0a99c fix: drop explicit platform matcherddb631aba fix: bump go-kmsg to fix the timestamp drift595470849 fix: make lacp active nilable879e31a65 test: fix flaky testsef1d9ffc3 fix: reset the ticker when the KubeSpan is disabled/enabledce89d6727 fix: replace Canal manifest with a more recent one
</p>
</details><details><summary>1 commit</summary> <p>
65e97cb fix: boot time offset calculation
</p>
</details><details><summary>2 commits</summary> <p>
d0b8f82 chore: rekres and bump depsc356eeb fix: fix context conflict detection add New() constructor
</p>
</details><details><summary>2 commits</summary> <p>
38c182f fix: normalize the changeset to be keyed without apiVersionca35008 feat: update k8s api to 0.36.0
</p>
</details><details><summary>11 commits</summary> <p>
969f61c feat: bump kernel to 6.18.294be1aaa feat: bump kernel 6.18.28e49ad17 feat(kernel): backport two PCI bridge realloc fixes from v6.1927cea5f feat: update NVIDIA drivers6c3007f feat: update Linux to 6.18.2792bf093 feat: update Linux to 6.18.26753307b feat: update DRBD to 9.3.2f6066dc docs: list net macb silent TX stall fixes in kernel/build/patches/README.mdfe81e27 fix: macb silent TX stall on BCM2712/RP1 (RFC patches from netdev)dd2bd8a feat: bump kernel to 6.18.254bad9ea feat: update Go to 1.26.3
</p>
</details><details><summary>2 commits</summary> <p>
Previous release can be found at v1.13.0
…variables for Talos components. It replaces and deprecates the previous method of setting environment variables via the .machine.env field.
Welcome to the v1.13.0 release of Talos!
Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues.
Talos now uses a kernel built using Clang compiler, and optimized using ThinLTO. This should bring a small performance improvement, alongside some hardening features, such as BTI on supported ARM systems.
Talos now enables CDI by default and extension/extension services can bring in dynamic
CDI spec files under /run/cdi.
Talos Linux now provides a way to run and attach to the privileged debug container with a user-provided container image. The debug container might be used for troubleshooting and debugging purposes.
A new EnvironmentConfig document has been introduced to allow users to specify environment variables for Talos components.
It replaces and deprecates the previous method of setting environment variables via the .machine.env field.
Multiple values for the same environment variable will replace previous values, with the last one taking precedence.
To remove an environment variable, remove it from the EnvironmentConfig document and restart the node.
Talos now supports virtiofs-based external volumes via the new ExternalVolumeConfig document.
These virtiofs external volumes are not supported when SELinux is running in enforcing mode.
Several Talos configuration fields that previously accepted single string values for extra arguments have been updated to accept slices of strings as well.
This includes fields such as .cluster.apiServer.extraArgs.
BREAKING: If you were relying on the resources EtcdConfigs, KubeletConfigs, ControllerManagerConfigs, SchedulerConfigs or APIServerConfigs, the protobuf format has changed from map<string,string> to map<string,message>.
Talos now supports machine-wide container image signature verification via the new ImageVerificationConfig machine config document.
Any image which gets pulled on the node will be verified against the configured rules, and if no rule matches, it will be pulled without verification.
Talos imager now supports running rootless. --privileged and -v /dev:/dev are no longer required.
Talos Linux provides new APIs to manage container images on the node: listing, pulling, importing and removing images. The new pull API provides pull progress notifications.
The CLI commands talosctl image pull, talosctl image list and talosctl image remove have been updated to interact with the new APIs.
The talosctl images k8s-bundle command now accepts an optional argument to override Talos version.
Talos now exposes install and upgrade operations via the LifecycleService API, enabling programmatic installs and upgrades through a single, consistent interface.
The legacy upgrade API is deprecated; new integrations should migrate to LifecycleService for future compatibility.
Talos now uses inventory backed server-side apply when applying bootstrap manifests (including extraManifests and inlineManifests).
Purging of unneeded manifests is automatically performed.
The switch and inventory backfill is automatic and no action is needed from the user.
Talos Linux now defaults to dynamic Linux kernel preemption model, the default value none matches
previous version, but now with kernel argument preempt= the preemption model can be changed.
See Linux kernel documentation for more information on supported values.
This change only applies to amd64 (x86_64) architecture.
A new KubeSpanConfig document has been introduced to configure KubeSpan settings.
It replaces and deprecates the previous method of configuring KubeSpan via the .machine.network.kubespan field.
The old configuration field will continue to work for backward compatibility.
KubeSpan now supports filtering of advertised networks using the excludeAdvertisedNetworks field in the KubeSpanConfig document.
This allows users to specify a list of CIDRs to exclude from the advertised networks. Please note that routing must be symmetric for any
pair of peers, so if one peer excludes a certain network, the other peer must also exclude it. In other words, for any given pair of peers,
and any pair of their addresses, the traffic should either go through KubeSpan or not, but not one way or the other.
LinkAliasConfig now supports pattern-based alias names using %d format verb (e.g. net%d).
When the alias name contains a %d format verb, the selector is allowed to match multiple links.
Each matched link receives a sequential alias (e.g. net0, net1, ...) based on hardware address order
of the links. Links already aliased by a previous config are automatically skipped.
This enables creating stable aliases from any N links using a single config document,
useful for BondConfig and BridgeConfig member interfaces on varying hardware.
Negative max size represents the amount of space to be left free on the device, rather than the size the volume should consume. For example: * a max size of "-10GiB" means the volume can grow to the available space minus 10GiB. * a max size of "-25%" means the volume can grow to the available space minus 25%.
Talos Linux now supports optionally deploying Flannel CNI with network policy support enabled. The network policy implementation is kube-network-policies.
To enable Flannel CNI with network policy support, use the following machine configuration patch:
cluster:
network:
cni:
name: flannel
flannel:
kubeNetworkPoliciesEnabled: true
(If the cluster is already running, sync the bootstrap manifests after applying the patch to deploy the new CNI configuration.)
Talos switched to using CDI and now supports configuring NVIDIA GPU via the gpu-operator helm chart. See the documentation on upgrade notes for more details on how to configure NVIDIA GPU support in Talos.
Talos now ships with igzip (amd64) and pigz (arm64) to speed up container image decompression.
The TCPProbeConfig configuration document allows to configure TCP probes for network reachability checks. This allows to define a custom connectivity condition.
A new kernel parameter proc_mem.force_override=never has been introduced by default to enhance system security
by preventing unwanted writes to protected process memory via /proc/PID/mem.
If the kernel parameter is removed, default behavior is restored, allowing access only if the process is traced.
Talos disk images are now reproducible. Building the same version of Talos multiple times will yield identical disk images.
Note: VHD and VMDK (Azure and VMware) images are not currently reproducible due to limitations in the underlying image creation tools. Users verifying reproducible images should use raw images, verify checksums, and convert them to VHD/VMDK as needed.
The nameservers configuration in machine configuration now overwrites any previous layers (defaults, platform, etc.) when specified. Previously a smart merge was performed to keep IPv4/IPv6 nameservers from lower layers if the machine configuration specified only one type.
Talos now supports routing rules via the new RoutingRuleConfig machine config document.
talosctl images talos-bundle can ignore reaching to the registryThe talosctl images talos-bundle command now accepts optional --overlays and --extensions flags.
If those are set to false, the command will not attempt to reach out to the container registry to fetch the latest versions and digests of the overlays and extensions.
talosctl upgrades now route through LifecycleService, aligning CLI behavior with the new install/upgrade API and unifying the upgrade path.
This change is transparent to users but standardizes the backend used for upgrades.
Linux: 6.18.24 containerd: 2.2.3 etcd: 3.6.9 CoreDNS: 1.14.2 Kubernetes: 1.36.0 CNI: 1.9.1 Flannel CNI plugin: v1.9.1-flannel1 Flannel: 0.28.4 LVM2: 2_03_38 runc: 1.4.2 systemd: 259.5 cryptsetup: 2.8.3 Tenstorrent: 2.7.0 iptables: 1.8.12 musl: 1.2.6
Talos is built with Go 1.26.2.
Talos now includes udev rules to support hot-adding of CPUs in virtualized environments.
Talos now supports VRF (Virtual Routing and Forwarding) via the new VRFConfig machine config document.
<details><summary>366 commits</summary> <p>
5e2fc260a fix: revert add extraArgs from service-account-issuer17448fcd2 fix: revert use append instead of prepend in service-account-issuer4b9fe000f feat: add quirk for talosctl factory downloadsf62c33113 refactor: make all controller unit-test follow modern patternscd317d533 feat: support auth for Image Factory in cluster create92ca9e16f feat: update Kubernetes to v1.36.0e9afea74d test: fix OOM test flaked34a61c8d fix(talosctl): ensure uncordon runs after reboot/upgrade errorsf9531d352 test: fix a flake in the manifest sync test9f04f2c4e fix: watch kubelet's kubeconfig and time out for cache syncf3bab2baf chore(ci): nvidia update helm valuesd4d018b54 fix: propagate route table down to the resourceffa0bcf61 chore(ci): bump gpu operator version8035e6e49 fix: do not flip machine stage to rebooting during shutdown10606bdfe fix: boot entry detection23393a5ea fix: zfs extensions testa922d1540 fix: return failed precondition on upgrade when not installed252799a00 fix: reduce memory dashboard usage8180cb11c fix: wrong slot of encryption key was loggedb6bcd47e6 feat: update Flannel to 0.28.4370c035ab fix: audit trustd code for security3e1c6fd84 chore: bump container registry librarydacd73313 chore: update sign images to support image name suffix1a519a410 test: allow more tests to run in FIPS strict modecb969aa9f feat: update Linux to 6.18.241f949d9a5 release(v1.13.0-rc.0): prepare release929ab7165 fix(machined): clear stale bond ARP/NS targets on decode730937eee chore: bump tools0f9d4b5b9 feat: update Kubernetes 1.36.0-rc.141e6866fd fix: encode extra args fields in resources with new id5feeab90d chore(ci): nvidia try UKI bootcd88cbd0c chore: bump tools53609713f fix: upgrade API in maintenance mode (legacy)2de7fb60d refactor: allow overriding out image name suffix384b189a5 feat: update Kubernetes to 1.36.0-rc.09b8c1891b fix: panic in reading PCR values67a34a6eb feat(ci): add nvidia arm64 matrixcd73b4a82 feat: bump go to 1.26.277406ec31 fix: validate hostDNS forwarding requires hostDNS to be enabled7d7776dca fix: handle boot failure6dc97e8aa fix(talosctl): always use default GRPC dial optionsdb2c007ee fix: create correct blackhole routes for IPv46f8462849 refactor: propagate NAME properly, allow to set on build6a0ec46b5 feat: add dis-vulncheck tool4c79bd815 chore: bump some tool dependenciescd8d70fb9 fix: set the minimum TLS version to 1.3fe5b849ec refactor: remove manual shell completion and replace with cobra completionfef5ef49e feat: allow more nvidia and nvme files from extensions33b89cff7 feat: allow glibc ld files in etc9be7bc025 fix: don't set xattrs while decompressing extensions9cc735588 feat: add client-side Kubernetes node drain to reboot and upgrade commands128c2c287 feat: update Flannel to v0.28.202d84f582 fix: handle ISOs with zeroes in volume labels70c356bfd feat: add flag to force fallback to legacy upgrade8499579f4 fix: add os:meta:writer role to the dashboarddc59a7e94 fix: drop talosctl installf7be2c598 feat: add resource view to talosctl dashboarda47b76618 fix: unseal with "slow" TPM3c79b432a fix: drop unused type from ExternalVolume schema38d391e9d fix: always grow disksf0c5cb517 fix: add metal-agent mode to runtime capabilities213ecf2a5 release(v1.13.0-beta.1): prepare releaseabc0ddf11 feat: bump musl to 1.2.6fcdfeab2b fix: incorrect route source for on-link routesa8f2a0af7 feat: update NVIDIA production drivers to 595.58.03ccf1e0c27 test: fix the PKI mismatch test flake7a9467306 test: fix cron failures for provision-1 & provision-2797815209 fix: allow blockdevice wipe in maintenance modeefc76f0bf test: fix the flakes in tests with trusted roots7fa16b497 test: bump memory for Flannel netpolicy tests576c26948 feat: add --platform=all support to image cache-createceec42f2a feat: update Linux to 6.18.19, CNI to 1.9.1902c78a17 test: improve maintenance API provision testsa4b0cbc49 feat: validate luks headers for tampering281584b88 chore: update go-kubernetes libraryb86360790 fix: add symlinks nvidia-ctk and nvidia-cdi-hook in /usr/bind82fada75 fix: unset rlimits for extension services76931f409 feat: enforce PID check on connections to services over file socketsdf4e0e7f5 feat: update etcd to 3.6.908ba425e6 feat: update Kubernetes to 1.36.0-beta.01cb2a8b30 fix: update diff library to v1.0.15e171a3de test: fix the apid test against AWS/GCPf98e76f8d fix: panics in diff algorithmsa544aea84 release(v1.13.0-beta.0): prepare releasef36f6ef54 chore: update pkgs and toolsb7d70cf62 feat: unify maintenance and regular APIs13d6b4a03 fix: trim down cosign dependencies5c39a8581 fix: drop aws & azure KMS APIs from the machined build3d059754c fix: accept image cache volume encryption configd2661d253 fix: apparmor parser config files13ef0cfc9 fix: unmount pseudo-late recursivelye9d45671a fix: panic in hardware.SystemInfoControllera728bbd89 fix: validate missing apiVersion in config document decoderc8a674afa fix: pull in a fix for dmesg timestampse7e21fe8e feat: bump dependencies6bb5cf57a feat: implement routing rules supporta0b9d6e77 feat: bump kernel with uhci_hcd driver1f0d2da39 feat: update containerd to 2.2.2cff0f5782 fix(machined): support USERDATA legacy fallback in OpenNebula driver5d3a326c8 feat(machined): add ONEGATE proxy route and deterministic interface iteration for OpenNebula3bec5cc7b feat(machined): inherit IP6_METHOD from METHOD in OpenNebula driver4f4ec9806 fix(machined): align OpenNebula hostname precedence with reference4d0244ddf feat(machined): add IPv6 alias address support for OpenNebula (ETH*_ALIAS*_IP6)5bb896230 feat(machined): support ETH*_IP6_METHOD (static/dhcp/auto/disable) for OpenNebula469db18d3 refactor(machined): extract per-interface IPv4 helper in OpenNebula driverae61f5a5e fix(machined): use ParseFQDN for hostname parsing in OpenNebula7adbbd2f8 feat(machined): support per-interface route metric for OpenNebula (ETH*_METRIC)196658c41 feat(machined): add network alias support for OpenNebula (ETH*_ALIAS*)e96766e81 feat(machined): merge global and per-interface DNS for OpenNebula23c99a3cb feat(machined): add static routes support via ETH*_ROUTES for OpenNebulaad3c59aad fix: prevent stale discovered volumes readsfc9749b9e feat: pull in kernel with preemptible kernelc14179e78 chore(ci): update nvidia test to use gpu-operatorda70cedfd refactor: drop apid file socketee53a18c8 fix: stop pulling wrong platform for images17335107b fix: use non-sensitive resource for health check precondition2fb6f6a16 feat: add symlinks needed by gpu-operatorf2bae55b8 feat: enable container device interface451b13c1b feat: update Linux to 6.18.16a02d578fa feat: add support for mirroring image signatures57599fb87 fix: skip some readiness checks when the CNI is disablede6d8669fb feat: update Go to 1.26.17f2eb4856 feat: add image verification endpoint1e4cd20d2 feat: add talosctl install command and upgrade via LifecycleService275fa351c test: add integration tests for LifecycleService upgrade path15a5ec998 feat: implement new install/upgrade API720a2148a fix: correctly calculate end ranges for nftables sets95287d2db fix: environment suite failures10f49ca91 feat: add trusted roots generation to stdpatches55b872185 fix: use correct dhcp option for unicast dhcp renewal58e006461 feat: update Kubernetes to 1.36.0-alpha.2ebcfafd4e feat: update Linux to 6.18.150ab84c2a1 fix: ignore image digest when doing upgrade-k8sd417d68e0 feat: bring in new ssa logic0bb6413ff fix: do not fail on RO virtiofsbf2cd0a85 feat: update Linux to 6.18.14ad29417ae fix(machined): opennebula: process ETH*_ vars regardless of NETWORK context flagb551cb9b8 feat: allow dashboard mouse supportbfb98a9ca feat: bump kube-network-policy to v1.0.0000c18d53 feat: implement blackhole route configcc636f1dd fix: image cache test fails with 'no space left on device'f0c51b280 feat: implement correct config patching for extraArgs fields1da2b63ab feat: multi-doc support for configuring vrfsc1d0a3360 fix: patch with delete for LinkConfigs59311a792 release(v1.13.0-alpha.2): prepare release009f0d6ca chore: update pkgsba56b0295 feat: include hid-multitouch.ko kernel module in rootfsae29a0dcc feat: update Linux to 6.18.137cf1de279 fix: bring in new version of go-cmd and go-blockdevicec8800b41e fix: update path handling on talosctl cgroups0a7b6eb2c chore: test extensions8b1c974a2 refactor: drop termui-widgets library5baa0028e fix: add owning inventory annotation to talos manifestsd3e793d14 fix: stop Kubernetes client from dynamically reloading the certs6a5a0e3bd feat: support pattern link aliases9758bd4fe feat: update Go to 1.26e00aed0f6 feat: update Kubernetes v1.36.0-alpha.1f20445ad0 chore: improve logging of disk encryption handlingf018fbe7b fix: handle raw encryption keys with \n properlye5b0eb017 fix: hold user volumes root mountpoint8a0e79774 refactor: split locate and provisiona59db0e92 fix: improve OpenStack bare metal network configuration reliability659009ad8 fix: remove stale endpointsdab0d4783 fix: allow static hosts in /etc/hosts without hostname45f214154 feat: update go-kubernetes to use new Myers diff35ad0448c fix: switch to better Myers algorithm implementation0048464be feat: update etcd to v3.6.85df10f260 fix: use mcopy instead of diskfs to populate VFATce53ffa90 fix: disks flag parsing and handling in create qemu command3bd3dd7ca fix: memory overuse in imager VFATf118ee47e fix: read multi-doc machine config with newer talosctl70c6c2154 feat: add filter for KubeSpan advertised networksdaf18abf4 fix: fix talosctl debug in enforcing mode33b5b2565 fix: ignore volumes in wave calculation without provisioninga16392559 feat: add explicit service account support to Talos client4d531884e chore: update dependencies406b8c83c feat: update doc links to docs.siderolabs.com87615f551 feat: implement network policies with Flannel CNI6995bc1b1 chore: update homebrew formula on release7942d5a98 fix: image gc controller config52e8727d0 feat: add IPv6 GRE support9690dbad0 chore: bump tools (including linter)2628eb2ec fix: typo with rpi_5 profile named5ebcd7ca fix: stop building talosctl debug on Windows8b85c7c63 chore: update depsd905035b5 fix: swap volume configuration for min/max sized43a01ccb feat: implement talosctl debug34a31c979 feat: add mount options support for existing volumes1bf95eed1 feat: improve dashboard uptime display055add7ae release(v1.13.0-alpha.1): prepare release900516e68 chore: update image signer938de566e feat: bump kernel388cec727 feat(overlays): add new overlays9f2dd6312 refactor: api testsa90783146 feat: add a helper module to generate standard patches1fec5b23d fix: implement merger for PercentageSize8b245b8f2 feat: implement new image service APIsd90c775b8 chore: rename internal talosctl debug air-gapped2165280d0 refactor: change the way one2many proxying is pickedb1b703dbe chore: move sync logging code to go-kubernetes packagee48c6d7ab fix: allow to expose a port multiple times in Docker410d8cb57 fix: undo CRLF on Windows (talosctl edit)859d3f03c feat: add RPi5 to the list of supported SBCs0bd48bbc6 fix(talosctl): pass --k8s-endpoint flag to rotate-ca kubernetes rotationb9e27ebe7 feat: update Linux kernel with dm-integrity6aa9b0677 fix: skip empty documents on config decoding494492489 fix: always set advertised peer URLs782cc507d fix: open the filesystem as read-only28e61a740 fix: set GRUB prefix correctly on arm64a4f1c5239 feat: update GRUB to 2.14562920701 fix: use node podCIDRs for kubespan advertiseKubernetesNetworks39460365c feat: implement layering for ProbeSpecb5c760f70 feat: add ProbeConfig for network connectivity probes4b274f761 feat: support aws cert manager in imager417209512 fix: fallback to /proc/meminfo for memory modules7f1147bed fix: add warnings to 802.3ad bondddd6b186e refactor: generate GRUB imagesc7aa266ea fix: overwrite resolver config with machine configcf70f05fa fix: oracle platform file format8c7b8f5b7 feat: add support for negative max size77bc3d21f fix: marshal of FailOverMac property38e280c93 fix: make OOM expression a bit less sensitive3d1301640 fix: wipe the first/last 1MiB in addition to wiping by signatures1aa6528ad fix: make OOM controller more precise by considering separate cgroup PSIf7072c050 fix: check if the device is not mounted when wiping743c3b94b fix: use correct containerd import pathf2dd08594 feat: report image pull progress in the console72fe98a06 fix: boot with GRUBd4ed13d93 fix: add talos version to Hetzner Cloud client user agent150c41c30 feat: update Linux to 6.18.501a367891 fix: use append instead of prepend in service-account-issuerd1954278a feat: add extraArgs from service-account-issuer91b88f7f9 feat: support multiple values for extraArgs96e604874 fix: add hostname to endpoints7033275a7 refactor: move BootloaderKind into machinery71adaf0ea fix: sort mirrors and tls configs when generating the machine config34f09a300 feat: add VLAN support to OpenStack platform5127ef7c2 fix: wipe disk by signatures415bfaedb fix: panic in configpatcher when the whole section is missinge5aca71cd fix: fix healthcheck timeout634b71e2d docs: move talosctl pcap example to Example Block818492731 feat: implement KubeSpan multi-document configuration4d0604b9d chore: remove unrelated machineconfige36863470 feat: add it87 hwmon module308c75090 fix: resolve SideroLink Wireguard endpoint on reconnecte4ef494de fix: drop the persist config flag from gen configc3176adcf feat: add EnvironmentConfig documentc839b3880 feat: expose more SSA options in the upgrade-k8s commandb8ff9677e fix: handle correctly incomplete RegistryTLSConfig99f2ddada fix: bond config via platform2449ffea4 fix: allow HostnameConfig to be used with incomplete machine config35fc52087 fix: lock down etcd listen address to IPv4 localhost27253d731 feat: use new xfs config filec9d84ae21 fix: generate OCI-compliant image config7a4b2b33a fix: update VIP config example080efcbda feat: add k8s-version parameter to k8s-bundleb764f5f72 fix: skip sync test when kube-proxy is disabled70e67787d feat: imager: populate filesystems with root owned files7416dca59 fix: print talosctl images to release notesdc2009e47 chore: use context when creating filesystems85f7be6e3 chore: update slack links154952175 fix: disable swap for system servicesd98b415af fix: drop more non-overlay SBC stuff226cd6bc1 fix: do not allocate for the actual disk image file53f5bf8d2 fix: overlay installers10d0cfd93 fix: overlay install in image mode77086694d fix: partition data population4d5657b1a fix: drop SBC board codec4f3f6d3e feat: implement kubernetes server-side applyf12fd2b0a test: bump Image Factory testsc76484e58 release(v1.13.0-alpha.0): prepare releasef0d8a6851 test: skip the source bundle on exact tagc57701d65 fix: remove interactive installer43937c1cd feat: update Linux and systemd72a194df8 feat: add VM CPU hot-add rulesf09ae1e0d fix: probe small images correctly8f2b33799 feat: imager support rootless buildsc7525a97e feat: support creating filesystems from foldere2bffb5ce chore: refactor imager code so it's more clear0fb50dbd0 fix: invalid versions check in talos-bundleb5dd56032 test: upgrade versions in upgrade tests3dfa4d6e4 fix: make upgrade work with SELinux enforcing=1786c8e2ee feat: ship pigz/igzip in rootfs to speed up image decompression48d242918 feat: update containerd to 2.2.1536541afe fix: mount volume mount/unmount race39117d457 feat: update dependenciesf0f420725 fix: bond setting change detection8d6a7a867 feat: update Kubernetes to 1.35.0845a0d09c feat: update etcd 3.6.7, CoreDNS 1.13.2b95912e04 feat: enforce proc_mem.force_override=never by default681f3e84c test: run virtiofs tests only when virtiofsd is running0592ff0cd fix: drop the Omni API URL check on IP addressa4879a5fa feat: update Linux to 6.18.143b43ff18 docs: split talosctl commands into groups6d17c18bf feat: enable Powercap and Intel RAPL884e76662 docs: fix the talosctl cluster create help output6dc31be4f fix: exclude new Virtual IPs configured with new config94905c73e feat(talosctl): support running qemu x86 on Macf871ab241 fix: provide json support in nft binary694f45413 feat: external volumes39feb16d2 fix: update containerd 2.2.0 with cgroups patch82027eb9b fix: bond configuration with new settings121b13b8f fix: disable kexec on arm647eaa725d0 fix: selection of boot entry949bdb90a feat: add Secure Boot to CloudStack platform config798143a88 fix: discard better klog message from Kubernetes client008cd0986 fix: disable kexec in talosctl cluster create on arm64bb62b29ed chore: prepare talos for 1.13c0935030a chore: fork reference docs for 1.13.xe387e48b3 fix: do not override DNS on MacOS1e7e87fb1 fix: rework NFT rules for KubeSpan51bcfb567 feat: rename image default and source bundle585abe944 feat: update Kubernetes to v1.35.0-rc.1f301e3e9b fix: update KubeSpan MSS clamping74c1df6f4 test: propagate MTU size to QEMU in talosctl cluster created347ca1af fix: update CNI plugins to 1.9.0e3f8196b4 chore: update Grype and Syfte1b8ab323 docs: add misssing periodcd04c3dde docs: update release notesfc8ae3249 docs: add omni join token example to create qemu command9fa00773c chore: update go-blockdeviceba13b6786 fix: correct condition to use UKI cmdline in GRUBd2ce3f47f docs: drop machine.network examplecf087c1e0 test: bird2 extension13df94388 fix: adapt SELinuxSuite.TestNoPtrace to new strace version861787c38 fix: mark secureboot as supported for metal04e3e87ad fix: clean up kubelet mounts21057903a fix: clear provisioning data on SideroLink config change0f9f4c05f feat: update Kubernetes to 1.35.0-rc.0d4309d7b1 fix: add a timeout for DNS resolving for NTPdd6c1089c feat: update Linux to 6.18.0e9a30bf9a test: revert add direct connectivity CA rotation testcc95562bc fix: don't disable LACP by defaultc9fe4679b test: add platform acquire/not valid config unit-test5a03a7a20 chore: fix longhorn testa0cfc3527 feat: implement logs persistence51b732bea fix: selection of boot entry18f8ac369 feat: update Kubernetes to 1.35.0-beta.092fa7c5e4 chore: update pkgs for NVIDIA 580.105.08f489299b6 chore: correct condition for running k8s integration testsab149750d](https://github.cNothing published for this version
…variables for Talos components. It replaces and deprecates the previous method of setting environment variables via the .machine.env field.
Welcome to the v1.13.0-rc.0 release of Talos!
This is a pre-release of Talos
Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues.
Talos now uses a kernel built using Clang compiler, and optimized using ThinLTO. This should bring a small performance improvement, alongside some hardening features, such as BTI on supported ARM systems.
Talos now enables CDI by default and extension/extension services can bring in dynamic
CDI spec files under /run/cdi.
Talos Linux now provides a way to run and attach to the privileged debug container with a user-provided container image. The debug container might be used for troubleshooting and debugging purposes.
A new EnvironmentConfig document has been introduced to allow users to specify environment variables for Talos components.
It replaces and deprecates the previous method of setting environment variables via the .machine.env field.
Multiple values for the same environment variable will replace previous values, with the last one taking precedence.
To remove an environment variable, remove it from the EnvironmentConfig document and restart the node.
Talos now supports virtiofs-based external volumes via the new ExternalVolumeConfig document.
These virtiofs external volumes are not supported when SELinux is running in enforcing mode.
Several Talos configuration fields that previously accepted single string values for extra arguments have been updated to accept slices of strings as well.
This includes fields such as .cluster.apiServer.extraArgs.
BREAKING: If you were relying on the resources EtcdConfigs, KubeletConfigs, ControllerManagerConfigs, SchedulerConfigs or APIServerConfigs, the protobuf format has changed from map<string,string> to map<string,message>.
Talos now supports machine-wide container image signature verification via the new ImageVerificationConfig machine config document.
Any image which gets pulled on the node will be verified against the configured rules, and if no rule matches, it will be pulled without verification.
Talos imager now supports running rootless. --privileged and -v /dev:/dev are no longer required.
Talos Linux provides new APIs to manage container images on the node: listing, pulling, importing and removing images. The new pull API provides pull progress notifications.
The CLI commands talosctl image pull, talosctl image list and talosctl image remove have been updated to interact with the new APIs.
The talosctl images k8s-bundle command now accepts an optional argument to override Talos version.
Talos now exposes install and upgrade operations via the LifecycleService API, enabling programmatic installs and upgrades through a single, consistent interface.
The legacy upgrade API is deprecated; new integrations should migrate to LifecycleService for future compatibility.
Talos now uses inventory backed server-side apply when applying bootstrap manifests (including extraManifests and inlineManifests).
Purging of unneeded manifests is automatically performed.
The switch and inventory backfill is automatic and no action is needed from the user.
Talos Linux now defaults to dynamic Linux kernel preemption model, the default value none matches
previous version, but now with kernel argument preempt= the preemption model can be changed.
See Linux kernel documentation for more information on supported values.
This change only applies to amd64 (x86_64) architecture.
A new KubeSpanConfig document has been introduced to configure KubeSpan settings.
It replaces and deprecates the previous method of configuring KubeSpan via the .machine.network.kubespan field.
The old configuration field will continue to work for backward compatibility.
KubeSpan now supports filtering of advertised networks using the excludeAdvertisedNetworks field in the KubeSpanConfig document.
This allows users to specify a list of CIDRs to exclude from the advertised networks. Please note that routing must be symmetric for any
pair of peers, so if one peer excludes a certain network, the other peer must also exclude it. In other words, for any given pair of peers,
and any pair of their addresses, the traffic should either go through KubeSpan or not, but not one way or the other.
LinkAliasConfig now supports pattern-based alias names using %d format verb (e.g. net%d).
When the alias name contains a %d format verb, the selector is allowed to match multiple links.
Each matched link receives a sequential alias (e.g. net0, net1, ...) based on hardware address order
of the links. Links already aliased by a previous config are automatically skipped.
This enables creating stable aliases from any N links using a single config document,
useful for BondConfig and BridgeConfig member interfaces on varying hardware.
Negative max size represents the amount of space to be left free on the device, rather than the size the volume should consume. For example: * a max size of "-10GiB" means the volume can grow to the available space minus 10GiB. * a max size of "-25%" means the volume can grow to the available space minus 25%.
Talos Linux now supports optionally deploying Flannel CNI with network policy support enabled. The network policy implementation is kube-network-policies.
To enable Flannel CNI with network policy support, use the following machine configuration patch:
cluster:
network:
cni:
name: flannel
flannel:
kubeNetworkPoliciesEnabled: true
(If the cluster is already running, sync the bootstrap manifests after applying the patch to deploy the new CNI configuration.)
Talos switched to using CDI and now supports configuring NVIDIA GPU via the gpu-operator helm chart. See the documentation on upgrade notes for more details on how to configure NVIDIA GPU support in Talos.
Talos now ships with igzip (amd64) and pigz (arm64) to speed up container image decompression.
The TCPProbeConfig configuration document allows to configure TCP probes for network reachability checks. This allows to define a custom connectivity condition.
A new kernel parameter proc_mem.force_override=never has been introduced by default to enhance system security
by preventing unwanted writes to protected process memory via /proc/PID/mem.
If the kernel parameter is removed, default behavior is restored, allowing access only if the process is traced.
Talos disk images are now reproducible. Building the same version of Talos multiple times will yield identical disk images.
Note: VHD and VMDK (Azure and VMware) images are not currently reproducible due to limitations in the underlying image creation tools. Users verifying reproducible images should use raw images, verify checksums, and convert them to VHD/VMDK as needed.
The nameservers configuration in machine configuration now overwrites any previous layers (defaults, platform, etc.) when specified. Previously a smart merge was performed to keep IPv4/IPv6 nameservers from lower layers if the machine configuration specified only one type.
Talos now supports routing rules via the new RoutingRuleConfig machine config document.
In API Server, passing extra args with service-account-issuer will append them after default value.
This allows easy migration, e.g. by changing .cluster.controlPlane.endpoint to new value, and keeping the old value in
.cluster.apiServer.extraArgs["service-account-issuer"].
talosctl images talos-bundle can ignore reaching to the registryThe talosctl images talos-bundle command now accepts optional --overlays and --extensions flags.
If those are set to false, the command will not attempt to reach out to the container registry to fetch the latest versions and digests of the overlays and extensions.
talosctl upgrades now route through LifecycleService, aligning CLI behavior with the new install/upgrade API and unifying the upgrade path.
This change is transparent to users but standardizes the backend used for upgrades.
Linux: 6.18.22 containerd: 2.2.3 etcd: 3.6.9 CoreDNS: 1.14.2 Kubernetes: 1.36.0-rc.1 CNI: 1.9.1 Flannel CNI plugin: v1.9.0-flannel1 Flannel: 0.28.2 LVM2: 2_03_38 runc: 1.4.2 systemd: 259.5 cryptsetup: 2.8.3 Tenstorrent: 2.7.0 iptables: 1.8.12 musl: 1.2.6
Talos is built with Go 1.26.2.
Talos now includes udev rules to support hot-adding of CPUs in virtualized environments.
Talos now supports VRF (Virtual Routing and Forwarding) via the new VRFConfig machine config document.
<details><summary>340 commits</summary> <p>
929ab7165 fix(machined): clear stale bond ARP/NS targets on decode730937eee chore: bump tools0f9d4b5b9 feat: update Kubernetes 1.36.0-rc.141e6866fd fix: encode extra args fields in resources with new id5feeab90d chore(ci): nvidia try UKI bootcd88cbd0c chore: bump tools53609713f fix: upgrade API in maintenance mode (legacy)2de7fb60d refactor: allow overriding out image name suffix384b189a5 feat: update Kubernetes to 1.36.0-rc.09b8c1891b fix: panic in reading PCR values67a34a6eb feat(ci): add nvidia arm64 matrixcd73b4a82 feat: bump go to 1.26.277406ec31 fix: validate hostDNS forwarding requires hostDNS to be enabled7d7776dca fix: handle boot failure6dc97e8aa fix(talosctl): always use default GRPC dial optionsdb2c007ee fix: create correct blackhole routes for IPv46f8462849 refactor: propagate NAME properly, allow to set on build6a0ec46b5 feat: add dis-vulncheck tool4c79bd815 chore: bump some tool dependenciescd8d70fb9 fix: set the minimum TLS version to 1.3fe5b849ec refactor: remove manual shell completion and replace with cobra completionfef5ef49e feat: allow more nvidia and nvme files from extensions33b89cff7 feat: allow glibc ld files in etc9be7bc025 fix: don't set xattrs while decompressing extensions9cc735588 feat: add client-side Kubernetes node drain to reboot and upgrade commands128c2c287 feat: update Flannel to v0.28.202d84f582 fix: handle ISOs with zeroes in volume labels70c356bfd feat: add flag to force fallback to legacy upgrade8499579f4 fix: add os:meta:writer role to the dashboarddc59a7e94 fix: drop talosctl installf7be2c598 feat: add resource view to talosctl dashboarda47b76618 fix: unseal with "slow" TPM3c79b432a fix: drop unused type from ExternalVolume schema38d391e9d fix: always grow disksf0c5cb517 fix: add metal-agent mode to runtime capabilities213ecf2a5 release(v1.13.0-beta.1): prepare releaseabc0ddf11 feat: bump musl to 1.2.6fcdfeab2b fix: incorrect route source for on-link routesa8f2a0af7 feat: update NVIDIA production drivers to 595.58.03ccf1e0c27 test: fix the PKI mismatch test flake7a9467306 test: fix cron failures for provision-1 & provision-2797815209 fix: allow blockdevice wipe in maintenance modeefc76f0bf test: fix the flakes in tests with trusted roots7fa16b497 test: bump memory for Flannel netpolicy tests576c26948 feat: add --platform=all support to image cache-createceec42f2a feat: update Linux to 6.18.19, CNI to 1.9.1902c78a17 test: improve maintenance API provision testsa4b0cbc49 feat: validate luks headers for tampering281584b88 chore: update go-kubernetes libraryb86360790 fix: add symlinks nvidia-ctk and nvidia-cdi-hook in /usr/bind82fada75 fix: unset rlimits for extension services76931f409 feat: enforce PID check on connections to services over file socketsdf4e0e7f5 feat: update etcd to 3.6.908ba425e6 feat: update Kubernetes to 1.36.0-beta.01cb2a8b30 fix: update diff library to v1.0.15e171a3de test: fix the apid test against AWS/GCPf98e76f8d fix: panics in diff algorithmsa544aea84 release(v1.13.0-beta.0): prepare releasef36f6ef54 chore: update pkgs and toolsb7d70cf62 feat: unify maintenance and regular APIs13d6b4a03 fix: trim down cosign dependencies5c39a8581 fix: drop aws & azure KMS APIs from the machined build3d059754c fix: accept image cache volume encryption configd2661d253 fix: apparmor parser config files13ef0cfc9 fix: unmount pseudo-late recursivelye9d45671a fix: panic in hardware.SystemInfoControllera728bbd89 fix: validate missing apiVersion in config document decoderc8a674afa fix: pull in a fix for dmesg timestampse7e21fe8e feat: bump dependencies6bb5cf57a feat: implement routing rules supporta0b9d6e77 feat: bump kernel with uhci_hcd driver1f0d2da39 feat: update containerd to 2.2.2cff0f5782 fix(machined): support USERDATA legacy fallback in OpenNebula driver5d3a326c8 feat(machined): add ONEGATE proxy route and deterministic interface iteration for OpenNebula3bec5cc7b feat(machined): inherit IP6_METHOD from METHOD in OpenNebula driver4f4ec9806 fix(machined): align OpenNebula hostname precedence with reference4d0244ddf feat(machined): add IPv6 alias address support for OpenNebula (ETH*_ALIAS*_IP6)5bb896230 feat(machined): support ETH*_IP6_METHOD (static/dhcp/auto/disable) for OpenNebula469db18d3 refactor(machined): extract per-interface IPv4 helper in OpenNebula driverae61f5a5e fix(machined): use ParseFQDN for hostname parsing in OpenNebula7adbbd2f8 feat(machined): support per-interface route metric for OpenNebula (ETH*_METRIC)196658c41 feat(machined): add network alias support for OpenNebula (ETH*_ALIAS*)e96766e81 feat(machined): merge global and per-interface DNS for OpenNebula23c99a3cb feat(machined): add static routes support via ETH*_ROUTES for OpenNebulaad3c59aad fix: prevent stale discovered volumes readsfc9749b9e feat: pull in kernel with preemptible kernelc14179e78 chore(ci): update nvidia test to use gpu-operatorda70cedfd refactor: drop apid file socketee53a18c8 fix: stop pulling wrong platform for images17335107b fix: use non-sensitive resource for health check precondition2fb6f6a16 feat: add symlinks needed by gpu-operatorf2bae55b8 feat: enable container device interface451b13c1b feat: update Linux to 6.18.16a02d578fa feat: add support for mirroring image signatures57599fb87 fix: skip some readiness checks when the CNI is disablede6d8669fb feat: update Go to 1.26.17f2eb4856 feat: add image verification endpoint1e4cd20d2 feat: add talosctl install command and upgrade via LifecycleService275fa351c test: add integration tests for LifecycleService upgrade path15a5ec998 feat: implement new install/upgrade API720a2148a fix: correctly calculate end ranges for nftables sets95287d2db fix: environment suite failures10f49ca91 feat: add trusted roots generation to stdpatches55b872185 fix: use correct dhcp option for unicast dhcp renewal58e006461 feat: update Kubernetes to 1.36.0-alpha.2ebcfafd4e feat: update Linux to 6.18.150ab84c2a1 fix: ignore image digest when doing upgrade-k8sd417d68e0 feat: bring in new ssa logic0bb6413ff fix: do not fail on RO virtiofsbf2cd0a85 feat: update Linux to 6.18.14ad29417ae fix(machined): opennebula: process ETH*_ vars regardless of NETWORK context flagb551cb9b8 feat: allow dashboard mouse supportbfb98a9ca feat: bump kube-network-policy to v1.0.0000c18d53 feat: implement blackhole route configcc636f1dd fix: image cache test fails with 'no space left on device'f0c51b280 feat: implement correct config patching for extraArgs fields1da2b63ab feat: multi-doc support for configuring vrfsc1d0a3360 fix: patch with delete for LinkConfigs59311a792 release(v1.13.0-alpha.2): prepare release009f0d6ca chore: update pkgsba56b0295 feat: include hid-multitouch.ko kernel module in rootfsae29a0dcc feat: update Linux to 6.18.137cf1de279 fix: bring in new version of go-cmd and go-blockdevicec8800b41e fix: update path handling on talosctl cgroups0a7b6eb2c chore: test extensions8b1c974a2 refactor: drop termui-widgets library5baa0028e fix: add owning inventory annotation to talos manifestsd3e793d14 fix: stop Kubernetes client from dynamically reloading the certs6a5a0e3bd feat: support pattern link aliases9758bd4fe feat: update Go to 1.26e00aed0f6 feat: update Kubernetes v1.36.0-alpha.1f20445ad0 chore: improve logging of disk encryption handlingf018fbe7b fix: handle raw encryption keys with \n properlye5b0eb017 fix: hold user volumes root mountpoint8a0e79774 refactor: split locate and provisiona59db0e92 fix: improve OpenStack bare metal network configuration reliability659009ad8 fix: remove stale endpointsdab0d4783 fix: allow static hosts in /etc/hosts without hostname45f214154 feat: update go-kubernetes to use new Myers diff35ad0448c fix: switch to better Myers algorithm implementation0048464be feat: update etcd to v3.6.85df10f260 fix: use mcopy instead of diskfs to populate VFATce53ffa90 fix: disks flag parsing and handling in create qemu command3bd3dd7ca fix: memory overuse in imager VFATf118ee47e fix: read multi-doc machine config with newer talosctl70c6c2154 feat: add filter for KubeSpan advertised networksdaf18abf4 fix: fix talosctl debug in enforcing mode33b5b2565 fix: ignore volumes in wave calculation without provisioninga16392559 feat: add explicit service account support to Talos client4d531884e chore: update dependencies406b8c83c feat: update doc links to docs.siderolabs.com87615f551 feat: implement network policies with Flannel CNI6995bc1b1 chore: update homebrew formula on release7942d5a98 fix: image gc controller config52e8727d0 feat: add IPv6 GRE support9690dbad0 chore: bump tools (including linter)2628eb2ec fix: typo with rpi_5 profile named5ebcd7ca fix: stop building talosctl debug on Windows8b85c7c63 chore: update depsd905035b5 fix: swap volume configuration for min/max sized43a01ccb feat: implement talosctl debug34a31c979 feat: add mount options support for existing volumes1bf95eed1 feat: improve dashboard uptime display055add7ae release(v1.13.0-alpha.1): prepare release900516e68 chore: update image signer938de566e feat: bump kernel388cec727 feat(overlays): add new overlays9f2dd6312 refactor: api testsa90783146 feat: add a helper module to generate standard patches1fec5b23d fix: implement merger for PercentageSize8b245b8f2 feat: implement new image service APIsd90c775b8 chore: rename internal talosctl debug air-gapped2165280d0 refactor: change the way one2many proxying is pickedb1b703dbe chore: move sync logging code to go-kubernetes packagee48c6d7ab fix: allow to expose a port multiple times in Docker410d8cb57 fix: undo CRLF on Windows (talosctl edit)859d3f03c feat: add RPi5 to the list of supported SBCs0bd48bbc6 fix(talosctl): pass --k8s-endpoint flag to rotate-ca kubernetes rotationb9e27ebe7 feat: update Linux kernel with dm-integrity6aa9b0677 fix: skip empty documents on config decoding494492489 fix: always set advertised peer URLs782cc507d fix: open the filesystem as read-only28e61a740 fix: set GRUB prefix correctly on arm64a4f1c5239 feat: update GRUB to 2.14562920701 fix: use node podCIDRs for kubespan advertiseKubernetesNetworks39460365c feat: implement layering for ProbeSpecb5c760f70 feat: add ProbeConfig for network connectivity probes4b274f761 feat: support aws cert manager in imager417209512 fix: fallback to /proc/meminfo for memory modules7f1147bed fix: add warnings to 802.3ad bondddd6b186e refactor: generate GRUB imagesc7aa266ea fix: overwrite resolver config with machine configcf70f05fa fix: oracle platform file format8c7b8f5b7 feat: add support for negative max size77bc3d21f fix: marshal of FailOverMac property38e280c93 fix: make OOM expression a bit less sensitive3d1301640 fix: wipe the first/last 1MiB in addition to wiping by signatures1aa6528ad fix: make OOM controller more precise by considering separate cgroup PSIf7072c050 fix: check if the device is not mounted when wiping743c3b94b fix: use correct containerd import pathf2dd08594 feat: report image pull progress in the console72fe98a06 fix: boot with GRUBd4ed13d93 fix: add talos version to Hetzner Cloud client user agent150c41c30 feat: update Linux to 6.18.501a367891 fix: use append instead of prepend in service-account-issuerd1954278a feat: add extraArgs from service-account-issuer91b88f7f9 feat: support multiple values for extraArgs96e604874 fix: add hostname to endpoints7033275a7 refactor: move BootloaderKind into machinery71adaf0ea fix: sort mirrors and tls configs when generating the machine config34f09a300 feat: add VLAN support to OpenStack platform5127ef7c2 fix: wipe disk by signatures415bfaedb fix: panic in configpatcher when the whole section is missinge5aca71cd fix: fix healthcheck timeout634b71e2d docs: move talosctl pcap example to Example Block818492731 feat: implement KubeSpan multi-document configuration4d0604b9d chore: remove unrelated machineconfige36863470 feat: add it87 hwmon module308c75090 fix: resolve SideroLink Wireguard endpoint on reconnecte4ef494de fix: drop the persist config flag from gen configc3176adcf feat: add EnvironmentConfig documentc839b3880 feat: expose more SSA options in the upgrade-k8s commandb8ff9677e fix: handle correctly incomplete RegistryTLSConfig99f2ddada fix: bond config via platform2449ffea4 fix: allow HostnameConfig to be used with incomplete machine config35fc52087 fix: lock down etcd listen address to IPv4 localhost27253d731 feat: use new xfs config filec9d84ae21 fix: generate OCI-compliant image config7a4b2b33a fix: update VIP config example080efcbda feat: add k8s-version parameter to k8s-bundleb764f5f72 fix: skip sync test when kube-proxy is disabled70e67787d feat: imager: populate filesystems with root owned files7416dca59 fix: print talosctl images to release notesdc2009e47 chore: use context when creating filesystems85f7be6e3 chore: update slack links154952175 fix: disable swap for system servicesd98b415af fix: drop more non-overlay SBC stuff226cd6bc1 fix: do not allocate for the actual disk image file53f5bf8d2 fix: overlay installers10d0cfd93 fix: overlay install in image mode77086694d fix: partition data population4d5657b1a fix: drop SBC board codec4f3f6d3e feat: implement kubernetes server-side applyf12fd2b0a test: bump Image Factory testsc76484e58 release(v1.13.0-alpha.0): prepare releasef0d8a6851 test: skip the source bundle on exact tagc57701d65 fix: remove interactive installer43937c1cd feat: update Linux and systemd72a194df8 feat: add VM CPU hot-add rulesf09ae1e0d fix: probe small images correctly8f2b33799 feat: imager support rootless buildsc7525a97e feat: support creating filesystems from foldere2bffb5ce chore: refactor imager code so it's more clear0fb50dbd0 fix: invalid versions check in talos-bundleb5dd56032 test: upgrade versions in upgrade tests3dfa4d6e4 fix: make upgrade work with SELinux enforcing=1786c8e2ee feat: ship pigz/igzip in rootfs to speed up image decompression48d242918 feat: update containerd to 2.2.1536541afe fix: mount volume mount/unmount race39117d457 feat: update dependenciesf0f420725 fix: bond setting change detection8d6a7a867 feat: update Kubernetes to 1.35.0845a0d09c feat: update etcd 3.6.7, CoreDNS 1.13.2b95912e04 feat: enforce proc_mem.force_override=never by default681f3e84c test: run virtiofs tests only when virtiofsd is running0592ff0cd fix: drop the Omni API URL check on IP addressa4879a5fa feat: update Linux to 6.18.143b43ff18 docs: split talosctl commands into groups6d17c18bf feat: enable Powercap and Intel RAPL884e76662 docs: fix the talosctl cluster create help output6dc31be4f fix: exclude new Virtual IPs configured with new config94905c73e feat(talosctl): support running qemu x86 on Macf871ab241 fix: provide json support in nft binary694f45413 feat: external volumes39feb16d2 fix: update containerd 2.2.0 with cgroups patch82027eb9b fix: bond configuration with new settings121b13b8f fix: disable kexec on arm647eaa725d0 fix: selection of boot entry949bdb90a feat: add Secure Boot to CloudStack platform config798143a88 fix: discard better klog message from Kubernetes client008cd0986 fix: disable kexec in talosctl cluster create on arm64bb62b29ed chore: prepare talos for 1.13c0935030a chore: fork reference docs for 1.13.xe387e48b3 fix: do not override DNS on MacOS1e7e87fb1 fix: rework NFT rules for KubeSpan51bcfb567 feat: rename image default and source bundle585abe944 feat: update Kubernetes to v1.35.0-rc.1f301e3e9b fix: update KubeSpan MSS clamping74c1df6f4 test: propagate MTU size to QEMU in talosctl cluster created347ca1af fix: update CNI plugins to 1.9.0e3f8196b4 chore: update Grype and Syfte1b8ab323 docs: add misssing periodcd04c3dde docs: update release notesfc8ae3249 docs: add omni join token example to create qemu command9fa00773c chore: update go-blockdeviceba13b6786 fix: correct condition to use UKI cmdline in GRUBd2ce3f47f docs: drop machine.network examplecf087c1e0 test: bird2 extension13df94388 fix: adapt SELinuxSuite.TestNoPtrace to new strace version861787c38 fix: mark secureboot as supported for metal04e3e87ad fix: clean up kubelet mounts21057903a fix: clear provisioning data on SideroLink config change0f9f4c05f feat: update Kubernetes to 1.35.0-rc.0d4309d7b1 fix: add a timeout for DNS resolving for NTPdd6c1089c feat: update Linux to 6.18.0e9a30bf9a test: revert add direct connectivity CA rotation testcc95562bc fix: don't disable LACP by defaultc9fe4679b test: add platform acquire/not valid config unit-test5a03a7a20 chore: fix longhorn testa0cfc3527 feat: implement logs persistence51b732bea fix: selection of boot entry18f8ac369 feat: update Kubernetes to 1.35.0-beta.092fa7c5e4 chore: update pkgs for NVIDIA 580.105.08f489299b6 chore: correct condition for running k8s integration testsab149750d chore: update tools/pkgs to 1.13.0-alpha.087ff9f860 test: fix the image-factory test to pass IF endpoint2ffe538e7 test: add direct connectivity CA rotation test70f6b80e0 chore(ci): skip multipath extension tests561cfb60c chore: update pkgs and tools version2f42202a7 fix: simplify OOM expression7b06ae8c2 test: fix flaky LinkSpec/Wireguard teste715f3871 feat: present kernel log as talosctl logs kernele2ee39b8a fix: support specifying patch file without '@' symbole202b1f9e fix: trim trailing dots from certificate SANs7f7079f9c fix: assign value of multicast setting properlyeba96141e feat: update etcd to 3.6.69945ceef3 docs: add API Server Cipher Suites changelog9ed488d09 feat: update TLS cipher suites for API serverf1c04e4d6 feat: generate mirrors patcha89108995 fix: add CA subject to generated certificate35dd612a5 fix: add more resilient move83675838f feat: extend flags of cache-cert-gen80ab7a064 chore: remove spammy 'clean up unused volumes' logs74d35900a chore: disable k8s integration tests for 1GiB worker nodes4f6218674 feat: support TALOS_HOME env var0c59b3ea3 feat: add multicast to linkconfig6db06f4d5 feat: implement multicast settingeeded98f5 fix: add riscv64 talosctl to release artifactsa6bbae91b](https://git…variables for Talos components. It replaces and deprecates the previous method of setting environment variables via the .machine.env field.
Welcome to the v1.13.0-beta.1 release of Talos!
This is a pre-release of Talos
Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues.
Talos now uses a kernel built using Clang compiler, and optimized using ThinLTO. This should bring a small performance improvement, alongside some hardening features, such as BTI on supported ARM systems.
Talos now enables CDI by default and extension/extension services can bring in dynamic
CDI spec files under /run/cdi.
Talos Linux now provides a way to run and attach to the privileged debug container with a user-provided container image. The debug container might be used for troubleshooting and debugging purposes.
A new EnvironmentConfig document has been introduced to allow users to specify environment variables for Talos components.
It replaces and deprecates the previous method of setting environment variables via the .machine.env field.
Multiple values for the same environment variable will replace previous values, with the last one taking precedence.
To remove an environment variable, remove it from the EnvironmentConfig document and restart the node.
Talos now supports virtiofs-based external volumes via the new ExternalVolumeConfig document.
These virtiofs external volumes are not supported when SELinux is running in enforcing mode.
Several Talos configuration fields that previously accepted single string values for extra arguments have been updated to accept slices of strings as well.
This includes fields such as .cluster.apiServer.extraArgs.
BREAKING: If you were relying on the resources EtcdConfigs, KubeletConfigs, ControllerManagerConfigs, SchedulerConfigs or APIServerConfigs, the protobuf format has changed from map<string,string> to map<string,message>.
Talos now supports machine-wide container image signature verification via the new ImageVerificationConfig machine config document.
Any image which gets pulled on the node will be verified against the configured rules, and if no rule matches, it will be pulled without verification.
Talos imager now supports running rootless. --privileged and -v /dev:/dev are no longer required.
Talos Linux provides new APIs to manage container images on the node: listing, pulling, importing and removing images. The new pull APIs provides pull progress notifications.
The CLI commands talosctl image pull, talosctl image list and talosctl image remove have been updated to interact with the new APIs.
The talosctl images k8s-bundle command now accepts an optional version overrides arguments.
Talos now exposes install and upgrade operations via the LifecycleService API, enabling programmatic installs and upgrades through a single, consistent interface.
The legacy upgrade API is deprecated; new integrations should migrate to LifecycleService for future compatibility.
Talos now uses inventory backed server-side apply when applying bootsrap manifests (including extraManifests and inlineManifests).
Purging of unneeded manifests is automatically performed.
The switch and inventory backfill is automatic and no action is needed from the user.
Talos Linux now defaults to dynamic Linux kernel preemption model, the default value none matches
previous version, but now with kernel argument preempt= the preemption model can be changed.
See Linux kernel documentation for more information on supported values.
This change only applies to amd64 (x86_64) architecture.
A new KubeSpanConfig document has been introduced to configure KubeSpan settings.
It replaces and deprecates the previous method of configuring KubeSpan via the .machine.network.kubespan field.
The old configuration field will continue to work for backward compatibility.
KubeSpan now supports filtering of advertised networks using the excludeAdvertisedNetworks field in the KubeSpanConfig document.
This allows users to specify a list of CIDRs to exclude from the advertised networks. Please note that routing must be symmetric for any
pair of peers, so if one peer excludes a certain network, the other peer must also exclude it. In other words, for any given pair of peers,
and any pair of their addresses, the traffic should either go through KubeSpan or not, but not one way or the other.
LinkAliasConfig now supports pattern-based alias names using %d format verb (e.g. net%d).
When the alias name contains a %d format verb, the selector is allowed to match multiple links.
Each matched link receives a sequential alias (e.g. net0, net1, ...) based on hardware address order
of the links. Links already aliased by a previous config are automatically skipped.
This enables creating stable aliases from any N links using a single config document,
useful for BondConfig and BridgeConfig member interfaces on varying hardware.
Negative max size represents the amount of space to be left free on the device, rather than the size the volume should consume. For example: * a max size of "-10GiB" means the volume can grow to the available space minus 10GiB. * a max size of "-25%" means the volume can grow to the available space minus 25%.
Talos Linux now supports optionally deploying Flannel CNI with network policy support enabled. The network policy implementation is kube-network-policies.
To enable Flannel CNI with network policy support, use the following machine configuration patch:
cluster:
network:
cni:
name: flannel
flannel:
kubeNetworkPoliciesEnabled: true
(If the cluster is already running, sync the bootstrap manifests after applying the patch to deploy the new CNI configuration.)
Talos switched to using CDI and now supports configuring NVIDIA GPU via the gpu-operator helm chart. See the documentation on upgrade notes for more details on how to configure NVIDIA GPU support in Talos.
Talos now ships with igzip (amd64) and pigz (arm64) to speed up container image decompression.
The TCPProbeConfig configuration document allows to configure TCP probes for network reachability checks. This allows to define a custom connectivity condition.
A new kernel parameter proc_mem.force_override=never has been introduced by default to enhance system security
by preventing unwanted writes to protected process memory via /proc/PID/mem.
If the kernel parameter is removed, default behavior is restored, allowing access only if the process is traced.
Talos disk images are now reproducible. Building the same version of Talos multiple times will yield identical disk images.
Note: VHD and VMDK (Azure and VMware) images are not currently reproducible due to limitations in the underlying image creation tools. Users verifying reproducible images should use raw images, verify checksums, and convert them to VHD/VMDK as needed.
The nameservers configuration in machine configuration now overwrites any previous layers (defaults, platform, etc.) when specified. Previously a smart merge was performed to keep IPv4/IPv6 nameservers from lower layers if the machine configuration specified only one type.
Talos now supports routing rules via the new RoutingRuleConfig machine config document.
In API Server, passing extra args with service-account-issuer will append them after default value.
This allows easy migration, e.g. by changing .cluster.controlPlane.endpoint to new value, and keeping the old value in
.cluster.apiServer.extraArgs["service-account-issuer"].
talosctl images talos-bundle can ignore reaching to the registryThe talosctl images talos-bundle command now accepts optional --overlays and --extensions flags.
If those are set to false, the command will not attempt to reach out to the container registry to fetch the latest versions and digests of the overlays and extensions.
talosctl upgrades now route through LifecycleService, aligning CLI behavior with the new install/upgrade API and unifying the upgrade path.
This change is transparent to users but standardizes the backend used for upgrades.
Linux: 6.18.19 containerd: 2.2.2 etcd: 3.6.9 CoreDNS: 1.14.2 Kubernetes: 1.36.0-beta.0 CNI: 1.9.1 Flannel CNI plugin: v1.9.0-flannel1 Flannel: 0.28.1 LVM2: 2_03_38 runc: 1.4.1 systemd: 259.5 cryptsetup: 2.8.3 Tenstorrent: 2.7.0 iptables: 1.8.12 musl: 1.2.6
Talos is built with Go 1.26.1.
Talos now includes udev rules to support hot-adding of CPUs in virtualized environments.
Talos now supports VRF (Virtual Routing and Forwarding) via the new VRFConfig machine config document.
<details><summary>304 commits</summary> <p>
abc0ddf11 feat: bump musl to 1.2.6fcdfeab2b fix: incorrect route source for on-link routesa8f2a0af7 feat: update NVIDIA production drivers to 595.58.03ccf1e0c27 test: fix the PKI mismatch test flake7a9467306 test: fix cron failures for provision-1 & provision-2797815209 fix: allow blockdevice wipe in maintenance modeefc76f0bf test: fix the flakes in tests with trusted roots7fa16b497 test: bump memory for Flannel netpolicy tests576c26948 feat: add --platform=all support to image cache-createceec42f2a feat: update Linux to 6.18.19, CNI to 1.9.1902c78a17 test: improve maintenance API provision testsa4b0cbc49 feat: validate luks headers for tampering281584b88 chore: update go-kubernetes libraryb86360790 fix: add symlinks nvidia-ctk and nvidia-cdi-hook in /usr/bind82fada75 fix: unset rlimits for extension services76931f409 feat: enforce PID check on connections to services over file socketsdf4e0e7f5 feat: update etcd to 3.6.908ba425e6 feat: update Kubernetes to 1.36.0-beta.01cb2a8b30 fix: update diff library to v1.0.15e171a3de test: fix the apid test against AWS/GCPf98e76f8d fix: panics in diff algorithmsa544aea84 release(v1.13.0-beta.0): prepare releasef36f6ef54 chore: update pkgs and toolsb7d70cf62 feat: unify maintenance and regular APIs13d6b4a03 fix: trim down cosign dependencies5c39a8581 fix: drop aws & azure KMS APIs from the machined build3d059754c fix: accept image cache volume encryption configd2661d253 fix: apparmor parser config files13ef0cfc9 fix: unmount pseudo-late recursivelye9d45671a fix: panic in hardware.SystemInfoControllera728bbd89 fix: validate missing apiVersion in config document decoderc8a674afa fix: pull in a fix for dmesg timestampse7e21fe8e feat: bump dependencies6bb5cf57a feat: implement routing rules supporta0b9d6e77 feat: bump kernel with uhci_hcd driver1f0d2da39 feat: update containerd to 2.2.2cff0f5782 fix(machined): support USERDATA legacy fallback in OpenNebula driver5d3a326c8 feat(machined): add ONEGATE proxy route and deterministic interface iteration for OpenNebula3bec5cc7b feat(machined): inherit IP6_METHOD from METHOD in OpenNebula driver4f4ec9806 fix(machined): align OpenNebula hostname precedence with reference4d0244ddf feat(machined): add IPv6 alias address support for OpenNebula (ETH*_ALIAS*_IP6)5bb896230 feat(machined): support ETH*_IP6_METHOD (static/dhcp/auto/disable) for OpenNebula469db18d3 refactor(machined): extract per-interface IPv4 helper in OpenNebula driverae61f5a5e fix(machined): use ParseFQDN for hostname parsing in OpenNebula7adbbd2f8 feat(machined): support per-interface route metric for OpenNebula (ETH*_METRIC)196658c41 feat(machined): add network alias support for OpenNebula (ETH*_ALIAS*)e96766e81 feat(machined): merge global and per-interface DNS for OpenNebula23c99a3cb feat(machined): add static routes support via ETH*_ROUTES for OpenNebulaad3c59aad fix: prevent stale discovered volumes readsfc9749b9e feat: pull in kernel with preemptible kernelc14179e78 chore(ci): update nvidia test to use gpu-operatorda70cedfd refactor: drop apid file socketee53a18c8 fix: stop pulling wrong platform for images17335107b fix: use non-sensitive resource for health check precondition2fb6f6a16 feat: add symlinks needed by gpu-operatorf2bae55b8 feat: enable container device interface451b13c1b feat: update Linux to 6.18.16a02d578fa feat: add support for mirroring image signatures57599fb87 fix: skip some readiness checks when the CNI is disablede6d8669fb feat: update Go to 1.26.17f2eb4856 feat: add image verification endpoint1e4cd20d2 feat: add talosctl install command and upgrade via LifecycleService275fa351c test: add integration tests for LifecycleService upgrade path15a5ec998 feat: implement new install/upgrade API720a2148a fix: correctly calculate end ranges for nftables sets95287d2db fix: environment suite failures10f49ca91 feat: add trusted roots generation to stdpatches55b872185 fix: use correct dhcp option for unicast dhcp renewal58e006461 feat: update Kubernetes to 1.36.0-alpha.2ebcfafd4e feat: update Linux to 6.18.150ab84c2a1 fix: ignore image digest when doing upgrade-k8sd417d68e0 feat: bring in new ssa logic0bb6413ff fix: do not fail on RO virtiofsbf2cd0a85 feat: update Linux to 6.18.14ad29417ae fix(machined): opennebula: process ETH*_ vars regardless of NETWORK context flagb551cb9b8 feat: allow dashboard mouse supportbfb98a9ca feat: bump kube-network-policy to v1.0.0000c18d53 feat: implement blackhole route configcc636f1dd fix: image cache test fails with 'no space left on device'f0c51b280 feat: implement correct config patching for extraArgs fields1da2b63ab feat: multi-doc support for configuring vrfsc1d0a3360 fix: patch with delete for LinkConfigs59311a792 release(v1.13.0-alpha.2): prepare release009f0d6ca chore: update pkgsba56b0295 feat: include hid-multitouch.ko kernel module in rootfsae29a0dcc feat: update Linux to 6.18.137cf1de279 fix: bring in new version of go-cmd and go-blockdevicec8800b41e fix: update path handling on talosctl cgroups0a7b6eb2c chore: test extensions8b1c974a2 refactor: drop termui-widgets library5baa0028e fix: add owning inventory annotation to talos manifestsd3e793d14 fix: stop Kubernetes client from dynamically reloading the certs6a5a0e3bd feat: support pattern link aliases9758bd4fe feat: update Go to 1.26e00aed0f6 feat: update Kubernetes v1.36.0-alpha.1f20445ad0 chore: improve logging of disk encryption handlingf018fbe7b fix: handle raw encryption keys with \n properlye5b0eb017 fix: hold user volumes root mountpoint8a0e79774 refactor: split locate and provisiona59db0e92 fix: improve OpenStack bare metal network configuration reliability659009ad8 fix: remove stale endpointsdab0d4783 fix: allow static hosts in /etc/hosts without hostname45f214154 feat: update go-kubernetes to use new Myers diff35ad0448c fix: switch to better Myers algorithm implementation0048464be feat: update etcd to v3.6.85df10f260 fix: use mcopy instead of diskfs to populate VFATce53ffa90 fix: disks flag parsing and handling in create qemu command3bd3dd7ca fix: memory overuse in imager VFATf118ee47e fix: read multi-doc machine config with newer talosctl70c6c2154 feat: add filter for KubeSpan advertised networksdaf18abf4 fix: fix talosctl debug in enforcing mode33b5b2565 fix: ignore volumes in wave calculation without provisioninga16392559 feat: add explicit service account support to Talos client4d531884e chore: update dependencies406b8c83c feat: update doc links to docs.siderolabs.com87615f551 feat: implement network policies with Flannel CNI6995bc1b1 chore: update homebrew formula on release7942d5a98 fix: image gc controller config52e8727d0 feat: add IPv6 GRE support9690dbad0 chore: bump tools (including linter)2628eb2ec fix: typo with rpi_5 profile named5ebcd7ca fix: stop building talosctl debug on Windows8b85c7c63 chore: update depsd905035b5 fix: swap volume configuration for min/max sized43a01ccb feat: implement talosctl debug34a31c979 feat: add mount options support for existing volumes1bf95eed1 feat: improve dashboard uptime display055add7ae release(v1.13.0-alpha.1): prepare release900516e68 chore: update image signer938de566e feat: bump kernel388cec727 feat(overlays): add new overlays9f2dd6312 refactor: api testsa90783146 feat: add a helper module to generate standard patches1fec5b23d fix: implement merger for PercentageSize8b245b8f2 feat: implement new image service APIsd90c775b8 chore: rename internal talosctl debug air-gapped2165280d0 refactor: change the way one2many proxying is pickedb1b703dbe chore: move sync logging code to go-kubernetes packagee48c6d7ab fix: allow to expose a port multiple times in Docker410d8cb57 fix: undo CRLF on Windows (talosctl edit)859d3f03c feat: add RPi5 to the list of supported SBCs0bd48bbc6 fix(talosctl): pass --k8s-endpoint flag to rotate-ca kubernetes rotationb9e27ebe7 feat: update Linux kernel with dm-integrity6aa9b0677 fix: skip empty documents on config decoding494492489 fix: always set advertised peer URLs782cc507d fix: open the filesystem as read-only28e61a740 fix: set GRUB prefix correctly on arm64a4f1c5239 feat: update GRUB to 2.14562920701 fix: use node podCIDRs for kubespan advertiseKubernetesNetworks39460365c feat: implement layering for ProbeSpecb5c760f70 feat: add ProbeConfig for network connectivity probes4b274f761 feat: support aws cert manager in imager417209512 fix: fallback to /proc/meminfo for memory modules7f1147bed fix: add warnings to 802.3ad bondddd6b186e refactor: generate GRUB imagesc7aa266ea fix: overwrite resolver config with machine configcf70f05fa fix: oracle platform file format8c7b8f5b7 feat: add support for negative max size77bc3d21f fix: marshal of FailOverMac property38e280c93 fix: make OOM expression a bit less sensitive3d1301640 fix: wipe the first/last 1MiB in addition to wiping by signatures1aa6528ad fix: make OOM controller more precise by considering separate cgroup PSIf7072c050 fix: check if the device is not mounted when wiping743c3b94b fix: use correct containerd import pathf2dd08594 feat: report image pull progress in the console72fe98a06 fix: boot with GRUBd4ed13d93 fix: add talos version to Hetzner Cloud client user agent150c41c30 feat: update Linux to 6.18.501a367891 fix: use append instead of prepend in service-account-issuerd1954278a feat: add extraArgs from service-account-issuer91b88f7f9 feat: support multiple values for extraArgs96e604874 fix: add hostname to endpoints7033275a7 refactor: move BootloaderKind into machinery71adaf0ea fix: sort mirrors and tls configs when generating the machine config34f09a300 feat: add VLAN support to OpenStack platform5127ef7c2 fix: wipe disk by signatures415bfaedb fix: panic in configpatcher when the whole section is missinge5aca71cd fix: fix healthcheck timeout634b71e2d docs: move talosctl pcap example to Example Block818492731 feat: implement KubeSpan multi-document configuration4d0604b9d chore: remove unrelated machineconfige36863470 feat: add it87 hwmon module308c75090 fix: resolve SideroLink Wireguard endpoint on reconnecte4ef494de fix: drop the persist config flag from gen configc3176adcf feat: add EnvironmentConfig documentc839b3880 feat: expose more SSA options in the upgrade-k8s commandb8ff9677e fix: handle correctly incomplete RegistryTLSConfig99f2ddada fix: bond config via platform2449ffea4 fix: allow HostnameConfig to be used with incomplete machine config35fc52087 fix: lock down etcd listen address to IPv4 localhost27253d731 feat: use new xfs config filec9d84ae21 fix: generate OCI-compliant image config7a4b2b33a fix: update VIP config example080efcbda feat: add k8s-version parameter to k8s-bundleb764f5f72 fix: skip sync test when kube-proxy is disabled70e67787d feat: imager: populate filesystems with root owned files7416dca59 fix: print talosctl images to release notesdc2009e47 chore: use context when creating filesystems85f7be6e3 chore: update slack links154952175 fix: disable swap for system servicesd98b415af fix: drop more non-overlay SBC stuff226cd6bc1 fix: do not allocate for the actual disk image file53f5bf8d2 fix: overlay installers10d0cfd93 fix: overlay install in image mode77086694d fix: partition data population4d5657b1a fix: drop SBC board codec4f3f6d3e feat: implement kubernetes server-side applyf12fd2b0a test: bump Image Factory testsc76484e58 release(v1.13.0-alpha.0): prepare releasef0d8a6851 test: skip the source bundle on exact tagc57701d65 fix: remove interactive installer43937c1cd feat: update Linux and systemd72a194df8 feat: add VM CPU hot-add rulesf09ae1e0d fix: probe small images correctly8f2b33799 feat: imager support rootless buildsc7525a97e feat: support creating filesystems from foldere2bffb5ce chore: refactor imager code so it's more clear0fb50dbd0 fix: invalid versions check in talos-bundleb5dd56032 test: upgrade versions in upgrade tests3dfa4d6e4 fix: make upgrade work with SELinux enforcing=1786c8e2ee feat: ship pigz/igzip in rootfs to speed up image decompression48d242918 feat: update containerd to 2.2.1536541afe fix: mount volume mount/unmount race39117d457 feat: update dependenciesf0f420725 fix: bond setting change detection8d6a7a867 feat: update Kubernetes to 1.35.0845a0d09c feat: update etcd 3.6.7, CoreDNS 1.13.2b95912e04 feat: enforce proc_mem.force_override=never by default681f3e84c test: run virtiofs tests only when virtiofsd is running0592ff0cd fix: drop the Omni API URL check on IP addressa4879a5fa feat: update Linux to 6.18.143b43ff18 docs: split talosctl commands into groups6d17c18bf feat: enable Powercap and Intel RAPL884e76662 docs: fix the talosctl cluster create help output6dc31be4f fix: exclude new Virtual IPs configured with new config94905c73e feat(talosctl): support running qemu x86 on Macf871ab241 fix: provide json support in nft binary694f45413 feat: external volumes39feb16d2 fix: update containerd 2.2.0 with cgroups patch82027eb9b fix: bond configuration with new settings121b13b8f fix: disable kexec on arm647eaa725d0 fix: selection of boot entry949bdb90a feat: add Secure Boot to CloudStack platform config798143a88 fix: discard better klog message from Kubernetes client008cd0986 fix: disable kexec in talosctl cluster create on arm64bb62b29ed chore: prepare talos for 1.13c0935030a chore: fork reference docs for 1.13.xe387e48b3 fix: do not override DNS on MacOS1e7e87fb1 fix: rework NFT rules for KubeSpan51bcfb567 feat: rename image default and source bundle585abe944 feat: update Kubernetes to v1.35.0-rc.1f301e3e9b fix: update KubeSpan MSS clamping74c1df6f4 test: propagate MTU size to QEMU in talosctl cluster created347ca1af fix: update CNI plugins to 1.9.0e3f8196b4 chore: update Grype and Syfte1b8ab323 docs: add misssing periodcd04c3dde docs: update release notesfc8ae3249 docs: add omni join token example to create qemu command9fa00773c chore: update go-blockdeviceba13b6786 fix: correct condition to use UKI cmdline in GRUBd2ce3f47f docs: drop machine.network examplecf087c1e0 test: bird2 extension13df94388 fix: adapt SELinuxSuite.TestNoPtrace to new strace version861787c38 fix: mark secureboot as supported for metal04e3e87ad fix: clean up kubelet mounts21057903a fix: clear provisioning data on SideroLink config change0f9f4c05f feat: update Kubernetes to 1.35.0-rc.0d4309d7b1 fix: add a timeout for DNS resolving for NTPdd6c1089c feat: update Linux to 6.18.0e9a30bf9a test: revert add direct connectivity CA rotation testcc95562bc fix: don't disable LACP by defaultc9fe4679b test: add platform acquire/not valid config unit-test5a03a7a20 chore: fix longhorn testa0cfc3527 feat: implement logs persistence51b732bea fix: selection of boot entry18f8ac369 feat: update Kubernetes to 1.35.0-beta.092fa7c5e4 chore: update pkgs for NVIDIA 580.105.08f489299b6 chore: correct condition for running k8s integration testsab149750d chore: update tools/pkgs to 1.13.0-alpha.087ff9f860 test: fix the image-factory test to pass IF endpoint2ffe538e7 test: add direct connectivity CA rotation test70f6b80e0 chore(ci): skip multipath extension tests561cfb60c chore: update pkgs and tools version2f42202a7 fix: simplify OOM expression7b06ae8c2 test: fix flaky LinkSpec/Wireguard teste715f3871 feat: present kernel log as talosctl logs kernele2ee39b8a fix: support specifying patch file without '@' symbole202b1f9e fix: trim trailing dots from certificate SANs7f7079f9c fix: assign value of multicast setting properlyeba96141e feat: update etcd to 3.6.69945ceef3 docs: add API Server Cipher Suites changelog9ed488d09 feat: update TLS cipher suites for API serverf1c04e4d6 feat: generate mirrors patcha89108995 fix: add CA subject to generated certificate35dd612a5 fix: add more resilient move83675838f feat: extend flags of cache-cert-gen80ab7a064 chore: remove spammy 'clean up unused volumes' logs74d35900a chore: disable k8s integration tests for 1GiB worker nodes4f6218674 feat: support TALOS_HOME env var0c59b3ea3 feat: add multicast to linkconfig6db06f4d5 feat: implement multicast settingeeded98f5 fix: add riscv64 talosctl to release artifactsa6bbae91b fix: fix typos across the project83f2bdb9c feat: support relative voume size
</p>
</details><details><summary>21 commits</summary> <p>
abc0ddf11 feat: bump musl to 1.2.6fcdfeab2b fix: incorrect route source for on-link routesa8f2a0af7 feat: update NVIDIA production drivers to 595.58.03ccf1e0c27 test: fix the PKI mismatch test flake7a9467306 test: fix cron failures for provision-1 & provision-2797815209 fix: allow blockdevice wipe in maintenance modeefc76f0bf test: fix the flakes in tests with trusted roots7fa16b497 test: bump memory for Flannel netpolicy tests576c26948 feat: add --platform=all support to image cache-createceec42f2a feat: update Linux to 6.18.19, CNI to 1.9.1902c78a17 test: improve maintenance API provision testsa4b0cbc49 feat: validate luks headers for tampering281584b88 chore: update go-kubernetes libraryb86360790 fix: add symlinks nvidia-ctk and nvidia-cdi-hook in /usr/bind82fada75 fix: unset rlimits for extension services76931f409 feat: enforce PID check on connections to services over file socketsdf4e0e7f5 feat: update etcd to 3.6.908ba425e6 feat: update Kubernetes to 1.36.0-beta.01cb2a8b30 fix: update diff library to v1.0.15e171a3de test: fix the apid test against AWS/GCPf98e76f8d fix: panics in diff algorithms
</p>
</details><details><summary>2 commits</summary> <p>
9c06846 feat: change the way excluded addresses are specifiedf71a14a feat: add advertised filters to discovery data
</p>
</details><details><summary>2 commits</summary> <p>
854400f feat: bump discovery API to v0.1.80a4c6fd chore: update dependencies and rekres
</p>
</details><details><summary>2 commits</summary> <p>
5f31ba9 chore: rekres and updatefff5698 feat: allow capturing full output to stdout, modernize API
</p>
</details><details><summary>1 commit</summary> <p>
47fce68 feat: support Go 1.26, rekres
</p>
</details><details><summary>3 commits</summary> <p>
…variables for Talos components. It replaces and deprecates the previous method of setting environment variables via the .machine.env field.
Welcome to the v1.13.0-beta.0 release of Talos!
This is a pre-release of Talos
Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues.
Talos now uses a kernel built using Clang compiler, and optimized using ThinLTO. This should bring a small performance improvement, alongside some hardening features, such as BTI on supported ARM systems.
Talos now enables CDI by default and extension/extension services can bring in dynamic
CDI spec files under /run/cdi.
Talos Linux now provides a way to run and attach to the privileged debug container with a user-provided container image. The debug container might be used for troubleshooting and debugging purposes.
A new EnvironmentConfig document has been introduced to allow users to specify environment variables for Talos components.
It replaces and deprecates the previous method of setting environment variables via the .machine.env field.
Multiple values for the same environment variable will replace previous values, with the last one taking precedence.
To remove an environment variable, remove it from the EnvironmentConfig document and restart the node.
Talos now supports virtiofs-based external volumes via the new ExternalVolumeConfig document.
These virtiofs external volumes are not supported when SELinux is running in enforcing mode.
Several Talos configuration fields that previously accepted single string values for extra arguments have been updated to accept slices of strings as well.
This includes fields such as .cluster.apiServer.extraArgs.
BREAKING: If you were relying on the resources EtcdConfigs, KubeletConfigs, ControllerManagerConfigs, SchedulerConfigs or APIServerConfigs, the protobuf format has changed from map<string,string> to map<string,message>.
Talos now supports machine-wide container image signature verification via the new ImageVerificationConfig machine config document.
Any image which gets pulled on the node will be verified against the configured rules, and if no rule matches, it will be pulled without verification.
Talos imager now supports running rootless. --privileged and -v /dev:/dev are no longer required.
Talos Linux provides new APIs to manage container images on the node: listing, pulling, importing and removing images. The new pull APIs provides pull progress notifications.
The CLI commands talosctl image pull, talosctl image list and talosctl image remove have been updated to interact with the new APIs.
The talosctl images k8s-bundle command now accepts an optional version overrides arguments.
Talos now exposes install and upgrade operations via the LifecycleService API, enabling programmatic installs and upgrades through a single, consistent interface.
The legacy upgrade API is deprecated; new integrations should migrate to LifecycleService for future compatibility.
Talos now uses inventory backed server-side apply when applying bootsrap manifests (including extraManifests and inlineManifests).
Purging of unneeded manifests is automatically performed.
The switch and inventory backfill is automatic and no action is needed from the user.
Talos Linux now defaults to dynamic Linux kernel preemption model, the default value none matches
previous version, but now with kernel argument preempt= the preemption model can be changed.
See Linux kernel documentation for more information on supported values.
This change only applies to amd64 (x86_64) architecture.
A new KubeSpanConfig document has been introduced to configure KubeSpan settings.
It replaces and deprecates the previous method of configuring KubeSpan via the .machine.network.kubespan field.
The old configuration field will continue to work for backward compatibility.
KubeSpan now supports filtering of advertised networks using the excludeAdvertisedNetworks field in the KubeSpanConfig document.
This allows users to specify a list of CIDRs to exclude from the advertised networks. Please note that routing must be symmetric for any
pair of peers, so if one peer excludes a certain network, the other peer must also exclude it. In other words, for any given pair of peers,
and any pair of their addresses, the traffic should either go through KubeSpan or not, but not one way or the other.
LinkAliasConfig now supports pattern-based alias names using %d format verb (e.g. net%d).
When the alias name contains a %d format verb, the selector is allowed to match multiple links.
Each matched link receives a sequential alias (e.g. net0, net1, ...) based on hardware address order
of the links. Links already aliased by a previous config are automatically skipped.
This enables creating stable aliases from any N links using a single config document,
useful for BondConfig and BridgeConfig member interfaces on varying hardware.
Negative max size represents the amount of space to be left free on the device, rather than the size the volume should consume. For example: * a max size of "-10GiB" means the volume can grow to the available space minus 10GiB. * a max size of "-25%" means the volume can grow to the available space minus 25%.
Talos Linux now supports optionally deploying Flannel CNI with network policy support enabled. The network policy implementation is kube-network-policies.
To enable Flannel CNI with network policy support, use the following machine configuration patch:
cluster:
network:
cni:
name: flannel
flannel:
kubeNetworkPoliciesEnabled: true
(If the cluster is already running, sync the bootstrap manifests after applying the patch to deploy the new CNI configuration.)
Talos switched to using CDI and now supports configuring NVIDIA GPU via the gpu-operator helm chart. See the documentation on upgrade notes for more details on how to configure NVIDIA GPU support in Talos.
Talos now ships with igzip (amd64) and pigz (arm64) to speed up container image decompression.
The TCPProbeConfig configuration document allows to configure TCP probes for network reachability checks. This allows to define a custom connectivity condition.
A new kernel parameter proc_mem.force_override=never has been introduced by default to enhance system security
by preventing unwanted writes to protected process memory via /proc/PID/mem.
If the kernel parameter is removed, default behavior is restored, allowing access only if the process is traced.
Talos disk images are now reproducible. Building the same version of Talos multiple times will yield identical disk images.
Note: VHD and VMDK (Azure and VMware) images are not currently reproducible due to limitations in the underlying image creation tools. Users verifying reproducible images should use raw images, verify checksums, and convert them to VHD/VMDK as needed.
The nameservers configuration in machine configuration now overwrites any previous layers (defaults, platform, etc.) when specified. Previously a smart merge was performed to keep IPv4/IPv6 nameservers from lower layers if the machine configuration specified only one type.
Talos now supports routing rules via the new RoutingRuleConfig machine config document.
In API Server, passing extra args with service-account-issuer will append them after default value.
This allows easy migration, e.g. by changing .cluster.controlPlane.endpoint to new value, and keeping the old value in
.cluster.apiServer.extraArgs["service-account-issuer"].
talosctl images talos-bundle can ignore reaching to the registryThe talosctl images talos-bundle command now accepts optional --overlays and --extensions flags.
If those are set to false, the command will not attempt to reach out to the container registry to fetch the latest versions and digests of the overlays and extensions.
talosctl upgrades now route through LifecycleService, aligning CLI behavior with the new install/upgrade API and unifying the upgrade path.
This change is transparent to users but standardizes the backend used for upgrades.
Linux: 6.18.18 containerd: 2.2.2 etcd: 3.6.8 CoreDNS: 1.14.2 Kubernetes: 1.36.0-alpha.2 Flannel CNI plugin: v1.9.0-flannel1 Flannel: 0.28.1 LVM2: 2_03_38 runc: 1.4.1 systemd: 259.5 cryptsetup: 2.8.3 Tenstorrent: 2.7.0 iptables: 1.8.12
Talos is built with Go 1.26.1.
Talos now includes udev rules to support hot-adding of CPUs in virtualized environments.
Talos now supports VRF (Virtual Routing and Forwarding) via the new VRFConfig machine config document.
<details><summary>282 commits</summary> <p>
f36f6ef54 chore: update pkgs and toolsb7d70cf62 feat: unify maintenance and regular APIs13d6b4a03 fix: trim down cosign dependencies5c39a8581 fix: drop aws & azure KMS APIs from the machined build3d059754c fix: accept image cache volume encryption configd2661d253 fix: apparmor parser config files13ef0cfc9 fix: unmount pseudo-late recursivelye9d45671a fix: panic in hardware.SystemInfoControllera728bbd89 fix: validate missing apiVersion in config document decoderc8a674afa fix: pull in a fix for dmesg timestampse7e21fe8e feat: bump dependencies6bb5cf57a feat: implement routing rules supporta0b9d6e77 feat: bump kernel with uhci_hcd driver1f0d2da39 feat: update containerd to 2.2.2cff0f5782 fix(machined): support USERDATA legacy fallback in OpenNebula driver5d3a326c8 feat(machined): add ONEGATE proxy route and deterministic interface iteration for OpenNebula3bec5cc7b feat(machined): inherit IP6_METHOD from METHOD in OpenNebula driver4f4ec9806 fix(machined): align OpenNebula hostname precedence with reference4d0244ddf feat(machined): add IPv6 alias address support for OpenNebula (ETH*_ALIAS*_IP6)5bb896230 feat(machined): support ETH*_IP6_METHOD (static/dhcp/auto/disable) for OpenNebula469db18d3 refactor(machined): extract per-interface IPv4 helper in OpenNebula driverae61f5a5e fix(machined): use ParseFQDN for hostname parsing in OpenNebula7adbbd2f8 feat(machined): support per-interface route metric for OpenNebula (ETH*_METRIC)196658c41 feat(machined): add network alias support for OpenNebula (ETH*_ALIAS*)e96766e81 feat(machined): merge global and per-interface DNS for OpenNebula23c99a3cb feat(machined): add static routes support via ETH*_ROUTES for OpenNebulaad3c59aad fix: prevent stale discovered volumes readsfc9749b9e feat: pull in kernel with preemptible kernelc14179e78 chore(ci): update nvidia test to use gpu-operatorda70cedfd refactor: drop apid file socketee53a18c8 fix: stop pulling wrong platform for images17335107b fix: use non-sensitive resource for health check precondition2fb6f6a16 feat: add symlinks needed by gpu-operatorf2bae55b8 feat: enable container device interface451b13c1b feat: update Linux to 6.18.16a02d578fa feat: add support for mirroring image signatures57599fb87 fix: skip some readiness checks when the CNI is disablede6d8669fb feat: update Go to 1.26.17f2eb4856 feat: add image verification endpoint1e4cd20d2 feat: add talosctl install command and upgrade via LifecycleService275fa351c test: add integration tests for LifecycleService upgrade path15a5ec998 feat: implement new install/upgrade API720a2148a fix: correctly calculate end ranges for nftables sets95287d2db fix: environment suite failures10f49ca91 feat: add trusted roots generation to stdpatches55b872185 fix: use correct dhcp option for unicast dhcp renewal58e006461 feat: update Kubernetes to 1.36.0-alpha.2ebcfafd4e feat: update Linux to 6.18.150ab84c2a1 fix: ignore image digest when doing upgrade-k8sd417d68e0 feat: bring in new ssa logic0bb6413ff fix: do not fail on RO virtiofsbf2cd0a85 feat: update Linux to 6.18.14ad29417ae fix(machined): opennebula: process ETH*_ vars regardless of NETWORK context flagb551cb9b8 feat: allow dashboard mouse supportbfb98a9ca feat: bump kube-network-policy to v1.0.0000c18d53 feat: implement blackhole route configcc636f1dd fix: image cache test fails with 'no space left on device'f0c51b280 feat: implement correct config patching for extraArgs fields1da2b63ab feat: multi-doc support for configuring vrfsc1d0a3360 fix: patch with delete for LinkConfigs59311a792 release(v1.13.0-alpha.2): prepare release009f0d6ca chore: update pkgsba56b0295 feat: include hid-multitouch.ko kernel module in rootfsae29a0dcc feat: update Linux to 6.18.137cf1de279 fix: bring in new version of go-cmd and go-blockdevicec8800b41e fix: update path handling on talosctl cgroups0a7b6eb2c chore: test extensions8b1c974a2 refactor: drop termui-widgets library5baa0028e fix: add owning inventory annotation to talos manifestsd3e793d14 fix: stop Kubernetes client from dynamically reloading the certs6a5a0e3bd feat: support pattern link aliases9758bd4fe feat: update Go to 1.26e00aed0f6 feat: update Kubernetes v1.36.0-alpha.1f20445ad0 chore: improve logging of disk encryption handlingf018fbe7b fix: handle raw encryption keys with \n properlye5b0eb017 fix: hold user volumes root mountpoint8a0e79774 refactor: split locate and provisiona59db0e92 fix: improve OpenStack bare metal network configuration reliability659009ad8 fix: remove stale endpointsdab0d4783 fix: allow static hosts in /etc/hosts without hostname45f214154 feat: update go-kubernetes to use new Myers diff35ad0448c fix: switch to better Myers algorithm implementation0048464be feat: update etcd to v3.6.85df10f260 fix: use mcopy instead of diskfs to populate VFATce53ffa90 fix: disks flag parsing and handling in create qemu command3bd3dd7ca fix: memory overuse in imager VFATf118ee47e fix: read multi-doc machine config with newer talosctl70c6c2154 feat: add filter for KubeSpan advertised networksdaf18abf4 fix: fix talosctl debug in enforcing mode33b5b2565 fix: ignore volumes in wave calculation without provisioninga16392559 feat: add explicit service account support to Talos client4d531884e chore: update dependencies406b8c83c feat: update doc links to docs.siderolabs.com87615f551 feat: implement network policies with Flannel CNI6995bc1b1 chore: update homebrew formula on release7942d5a98 fix: image gc controller config52e8727d0 feat: add IPv6 GRE support9690dbad0 chore: bump tools (including linter)2628eb2ec fix: typo with rpi_5 profile named5ebcd7ca fix: stop building talosctl debug on Windows8b85c7c63 chore: update depsd905035b5 fix: swap volume configuration for min/max sized43a01ccb feat: implement talosctl debug34a31c979 feat: add mount options support for existing volumes1bf95eed1 feat: improve dashboard uptime display055add7ae release(v1.13.0-alpha.1): prepare release900516e68 chore: update image signer938de566e feat: bump kernel388cec727 feat(overlays): add new overlays9f2dd6312 refactor: api testsa90783146 feat: add a helper module to generate standard patches1fec5b23d fix: implement merger for PercentageSize8b245b8f2 feat: implement new image service APIsd90c775b8 chore: rename internal talosctl debug air-gapped2165280d0 refactor: change the way one2many proxying is pickedb1b703dbe chore: move sync logging code to go-kubernetes packagee48c6d7ab fix: allow to expose a port multiple times in Docker410d8cb57 fix: undo CRLF on Windows (talosctl edit)859d3f03c feat: add RPi5 to the list of supported SBCs0bd48bbc6 fix(talosctl): pass --k8s-endpoint flag to rotate-ca kubernetes rotationb9e27ebe7 feat: update Linux kernel with dm-integrity6aa9b0677 fix: skip empty documents on config decoding494492489 fix: always set advertised peer URLs782cc507d fix: open the filesystem as read-only28e61a740 fix: set GRUB prefix correctly on arm64a4f1c5239 feat: update GRUB to 2.14562920701 fix: use node podCIDRs for kubespan advertiseKubernetesNetworks39460365c feat: implement layering for ProbeSpecb5c760f70 feat: add ProbeConfig for network connectivity probes4b274f761 feat: support aws cert manager in imager417209512 fix: fallback to /proc/meminfo for memory modules7f1147bed fix: add warnings to 802.3ad bondddd6b186e refactor: generate GRUB imagesc7aa266ea fix: overwrite resolver config with machine configcf70f05fa fix: oracle platform file format8c7b8f5b7 feat: add support for negative max size77bc3d21f fix: marshal of FailOverMac property38e280c93 fix: make OOM expression a bit less sensitive3d1301640 fix: wipe the first/last 1MiB in addition to wiping by signatures1aa6528ad fix: make OOM controller more precise by considering separate cgroup PSIf7072c050 fix: check if the device is not mounted when wiping743c3b94b fix: use correct containerd import pathf2dd08594 feat: report image pull progress in the console72fe98a06 fix: boot with GRUBd4ed13d93 fix: add talos version to Hetzner Cloud client user agent150c41c30 feat: update Linux to 6.18.501a367891 fix: use append instead of prepend in service-account-issuerd1954278a feat: add extraArgs from service-account-issuer91b88f7f9 feat: support multiple values for extraArgs96e604874 fix: add hostname to endpoints7033275a7 refactor: move BootloaderKind into machinery71adaf0ea fix: sort mirrors and tls configs when generating the machine config34f09a300 feat: add VLAN support to OpenStack platform5127ef7c2 fix: wipe disk by signatures415bfaedb fix: panic in configpatcher when the whole section is missinge5aca71cd fix: fix healthcheck timeout634b71e2d docs: move talosctl pcap example to Example Block818492731 feat: implement KubeSpan multi-document configuration4d0604b9d chore: remove unrelated machineconfige36863470 feat: add it87 hwmon module308c75090 fix: resolve SideroLink Wireguard endpoint on reconnecte4ef494de fix: drop the persist config flag from gen configc3176adcf feat: add EnvironmentConfig documentc839b3880 feat: expose more SSA options in the upgrade-k8s commandb8ff9677e fix: handle correctly incomplete RegistryTLSConfig99f2ddada fix: bond config via platform2449ffea4 fix: allow HostnameConfig to be used with incomplete machine config35fc52087 fix: lock down etcd listen address to IPv4 localhost27253d731 feat: use new xfs config filec9d84ae21 fix: generate OCI-compliant image config7a4b2b33a fix: update VIP config example080efcbda feat: add k8s-version parameter to k8s-bundleb764f5f72 fix: skip sync test when kube-proxy is disabled70e67787d feat: imager: populate filesystems with root owned files7416dca59 fix: print talosctl images to release notesdc2009e47 chore: use context when creating filesystems85f7be6e3 chore: update slack links154952175 fix: disable swap for system servicesd98b415af fix: drop more non-overlay SBC stuff226cd6bc1 fix: do not allocate for the actual disk image file53f5bf8d2 fix: overlay installers10d0cfd93 fix: overlay install in image mode77086694d fix: partition data population4d5657b1a fix: drop SBC board codec4f3f6d3e feat: implement kubernetes server-side applyf12fd2b0a test: bump Image Factory testsc76484e58 release(v1.13.0-alpha.0): prepare releasef0d8a6851 test: skip the source bundle on exact tagc57701d65 fix: remove interactive installer43937c1cd feat: update Linux and systemd72a194df8 feat: add VM CPU hot-add rulesf09ae1e0d fix: probe small images correctly8f2b33799 feat: imager support rootless buildsc7525a97e feat: support creating filesystems from foldere2bffb5ce chore: refactor imager code so it's more clear0fb50dbd0 fix: invalid versions check in talos-bundleb5dd56032 test: upgrade versions in upgrade tests3dfa4d6e4 fix: make upgrade work with SELinux enforcing=1786c8e2ee feat: ship pigz/igzip in rootfs to speed up image decompression48d242918 feat: update containerd to 2.2.1536541afe fix: mount volume mount/unmount race39117d457 feat: update dependenciesf0f420725 fix: bond setting change detection8d6a7a867 feat: update Kubernetes to 1.35.0845a0d09c feat: update etcd 3.6.7, CoreDNS 1.13.2b95912e04 feat: enforce proc_mem.force_override=never by default681f3e84c test: run virtiofs tests only when virtiofsd is running0592ff0cd fix: drop the Omni API URL check on IP addressa4879a5fa feat: update Linux to 6.18.143b43ff18 docs: split talosctl commands into groups6d17c18bf feat: enable Powercap and Intel RAPL884e76662 docs: fix the talosctl cluster create help output6dc31be4f fix: exclude new Virtual IPs configured with new config94905c73e feat(talosctl): support running qemu x86 on Macf871ab241 fix: provide json support in nft binary694f45413 feat: external volumes39feb16d2 fix: update containerd 2.2.0 with cgroups patch82027eb9b fix: bond configuration with new settings121b13b8f fix: disable kexec on arm647eaa725d0 fix: selection of boot entry949bdb90a feat: add Secure Boot to CloudStack platform config798143a88 fix: discard better klog message from Kubernetes client008cd0986 fix: disable kexec in talosctl cluster create on arm64bb62b29ed chore: prepare talos for 1.13c0935030a chore: fork reference docs for 1.13.xe387e48b3 fix: do not override DNS on MacOS1e7e87fb1 fix: rework NFT rules for KubeSpan51bcfb567 feat: rename image default and source bundle585abe944 feat: update Kubernetes to v1.35.0-rc.1f301e3e9b fix: update KubeSpan MSS clamping74c1df6f4 test: propagate MTU size to QEMU in talosctl cluster created347ca1af fix: update CNI plugins to 1.9.0e3f8196b4 chore: update Grype and Syfte1b8ab323 docs: add misssing periodcd04c3dde docs: update release notesfc8ae3249 docs: add omni join token example to create qemu command9fa00773c chore: update go-blockdeviceba13b6786 fix: correct condition to use UKI cmdline in GRUBd2ce3f47f docs: drop machine.network examplecf087c1e0 test: bird2 extension13df94388 fix: adapt SELinuxSuite.TestNoPtrace to new strace version861787c38 fix: mark secureboot as supported for metal04e3e87ad fix: clean up kubelet mounts21057903a fix: clear provisioning data on SideroLink config change0f9f4c05f feat: update Kubernetes to 1.35.0-rc.0d4309d7b1 fix: add a timeout for DNS resolving for NTPdd6c1089c feat: update Linux to 6.18.0e9a30bf9a test: revert add direct connectivity CA rotation testcc95562bc fix: don't disable LACP by defaultc9fe4679b test: add platform acquire/not valid config unit-test5a03a7a20 chore: fix longhorn testa0cfc3527 feat: implement logs persistence51b732bea fix: selection of boot entry18f8ac369 feat: update Kubernetes to 1.35.0-beta.092fa7c5e4 chore: update pkgs for NVIDIA 580.105.08f489299b6 chore: correct condition for running k8s integration testsab149750d chore: update tools/pkgs to 1.13.0-alpha.087ff9f860 test: fix the image-factory test to pass IF endpoint2ffe538e7 test: add direct connectivity CA rotation test70f6b80e0 chore(ci): skip multipath extension tests561cfb60c chore: update pkgs and tools version2f42202a7 fix: simplify OOM expression7b06ae8c2 test: fix flaky LinkSpec/Wireguard teste715f3871 feat: present kernel log as talosctl logs kernele2ee39b8a fix: support specifying patch file without '@' symbole202b1f9e fix: trim trailing dots from certificate SANs7f7079f9c fix: assign value of multicast setting properlyeba96141e feat: update etcd to 3.6.69945ceef3 docs: add API Server Cipher Suites changelog9ed488d09 feat: update TLS cipher suites for API serverf1c04e4d6 feat: generate mirrors patcha89108995 fix: add CA subject to generated certificate35dd612a5 fix: add more resilient move83675838f feat: extend flags of cache-cert-gen80ab7a064 chore: remove spammy 'clean up unused volumes' logs74d35900a chore: disable k8s integration tests for 1GiB worker nodes4f6218674 feat: support TALOS_HOME env var0c59b3ea3 feat: add multicast to linkconfig6db06f4d5 feat: implement multicast settingeeded98f5 fix: add riscv64 talosctl to release artifactsa6bbae91b fix: fix typos across the project83f2bdb9c feat: support relative voume size
</p>
</details><details><summary>60 commits</summary> <p>
f36f6ef54 chore: update pkgs and toolsb7d70cf62 feat: unify maintenance and regular APIs13d6b4a03 fix: trim down cosign dependencies5c39a8581 fix: drop aws & azure KMS APIs from the machined build3d059754c fix: accept image cache volume encryption configd2661d253 fix: apparmor parser config files13ef0cfc9 fix: unmount pseudo-late recursivelye9d45671a fix: panic in hardware.SystemInfoControllera728bbd89 fix: validate missing apiVersion in config document decoderc8a674afa fix: pull in a fix for dmesg timestampse7e21fe8e feat: bump dependencies6bb5cf57a feat: implement routing rules supporta0b9d6e77 feat: bump kernel with uhci_hcd driver1f0d2da39 feat: update containerd to 2.2.2cff0f5782 fix(machined): support USERDATA legacy fallback in OpenNebula driver5d3a326c8 feat(machined): add ONEGATE proxy route and deterministic interface iteration for OpenNebula3bec5cc7b feat(machined): inherit IP6_METHOD from METHOD in OpenNebula driver4f4ec9806 fix(machined): align OpenNebula hostname precedence with reference4d0244ddf feat(machined): add IPv6 alias address support for OpenNebula (ETH*_ALIAS*_IP6)5bb896230 feat(machined): support ETH*_IP6_METHOD (static/dhcp/auto/disable) for OpenNebula469db18d3 refactor(machined): extract per-interface IPv4 helper in OpenNebula driverae61f5a5e fix(machined): use ParseFQDN for hostname parsing in OpenNebula7adbbd2f8 feat(machined): support per-interface route metric for OpenNebula (ETH*_METRIC)196658c41 feat(machined): add network alias support for OpenNebula (ETH*_ALIAS*)e96766e81 feat(machined): merge global and per-interface DNS for OpenNebula23c99a3cb feat(machined): add static routes support via ETH*_ROUTES for OpenNebulaad3c59aad fix: prevent stale discovered volumes readsfc9749b9e feat: pull in kernel with preemptible kernelc14179e78 chore(ci): update nvidia test to use gpu-operatorda70cedfd refactor: drop apid file socketee53a18c8 fix: stop pulling wrong platform for images17335107b fix: use non-sensitive resource for health check precondition2fb6f6a16 feat: add symlinks needed by gpu-operatorf2bae55b8 feat: enable container device interface451b13c1b feat: update Linux to 6.18.16a02d578fa feat: add support for mirroring image signatures57599fb87 fix: skip some readiness checks when the CNI is disablede6d8669fb feat: update Go to 1.26.17f2eb4856 feat: add image verification endpoint1e4cd20d2 feat: add talosctl install command and upgrade via LifecycleService275fa351c test: add integration tests for LifecycleService upgrade path15a5ec998 feat: implement new install/upgrade API720a2148a fix: correctly calculate end ranges for nftables sets95287d2db fix: environment suite failures10f49ca91 feat: add trusted roots generation to stdpatches55b872185 fix: use correct dhcp option for unicast dhcp renewal58e006461 feat: update Kubernetes to 1.36.0-alpha.2ebcfafd4e feat: update Linux to 6.18.150ab84c2a1 fix: ignore image digest when doing upgrade-k8sd417d68e0 feat: bring in new ssa logic0bb6413ff fix: do not fail on RO virtiofsbf2cd0a85 feat: update Linux to 6.18.14ad29417ae fix(machined): opennebula: process ETH*_ vars regardless of NETWORK context flagb551cb9b8 feat: allow dashboarNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →