NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #306 by repository stars
Last release today
23 Sep 2026
Ships on a steady schedule
a new release about every 8 days
Some releases are documented
notes for 15 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
2948 releases · first in 2018
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
67464cbef fix: update the vulnerability dates and description
Welcome to the v1.14.0-beta.1 release of Talos!
This is a pre-release of Talos
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Talos now supports DNS over TLS (DoT) and DNS over HTTPS (DoH) for secure DNS resolution.
These features allow Talos to encrypt DNS queries and responses, enhancing privacy and security for DNS traffic.
The DNS protocol can be configured on a per-name server basis in the ResolverConfig document, allowing for flexible configuration of DNS resolution.
Talos 1.14 clusters now default the EPHEMERAL volume (/var) to noexec in addition to the existing nosuid and nodev
mount options through generated machine configuration.
Existing machines are not affected on upgrades.
Note: Workloads that execute binaries placed under /var can break on new machines.
Longhorn v1 and vCluster are known to be affected.
For example, Longhorn v1's instance-manager executes engine binaries that the engine-image DaemonSet places under
/var/lib/longhorn/engine-binaries/, which now fails with permission denied.
Affected users can opt out via a VolumeConfig document:
apiVersion: v1alpha1
kind: VolumeConfig
name: EPHEMERAL
mount:
secure: falseNOTE: Setting
secure: falsewill also disablenosuidandnodev, which may have security implications. Use with caution.
Longhorn v2 (SPDK data engine) runs the data plane inside the instance manager process and is not affected.
The '--mode=reboot' option has been removed from the talosctl apply-config command; by default, configuration is applied without a reboot.
Most configuration changes don't require a reboot; the documentation lists the changes that do.
Talos now supports running native BGP routing instances on the host via embedded GoBGP servers, configured with BGPInstanceConfig documents.
This removes the need to ship FRR as a system extension for the common fabric-facing use case.
List of changes:
BGPInstanceConfig documents to configure local ASN, router-id, optional Linux VRF, advertised interfaces, neighbors, and per-route preferred source (routeSource).installRoutes: false to retain learned routes in the BGP RIB without installing them into the Linux routing table.importRoutes prefix selectors. Imports are one-way, preserve path attributes, and do not recursively import locally originated or previously imported paths.BGPPeerStatus resources (talosctl get bgppeerstatus).RouteSpec/RouteStatus now carry a multipath next-hop list to support ECMP and cross-family (RFC 8950) next-hops.Talos now supports mounting and provisioning btrfs filesystem for user volumes and existing volumes.
Support for btrfs is enabled by installing btrfs system extension.
Talos now supports overriding the default OCI runtime specification for CRI containers with a
CRIBaseRuntimeSpecConfig document:
apiVersion: v1alpha1
kind: CRIBaseRuntimeSpecConfig
overrides:
process:
rlimits:
- type: RLIMIT_NOFILE
hard: 1024
soft: 1024The .machine.baseRuntimeSpecOverrides field is deprecated and remains supported during the deprecation
period. It is mutually exclusive with CRIBaseRuntimeSpecConfig; configurations containing both are rejected.
Applying, updating, or removing either source regenerates the base runtime specification and restarts CRI
automatically. A machine reboot is no longer required.
Talos now supports customizing the CRI containerd configuration with named CRICustomizationConfig
documents. Each document contains a TOML fragment; fragments are merged in lexicographical order by name.
Applying, updating, or removing these documents updates the generated CRI configuration and restarts CRI
automatically.
The legacy /etc/cri/conf.d/20-customization.part machine-file configuration remains supported during the
deprecation period and is exposed under the reserved name customization. A CRICustomizationConfig document
cannot use that name.
NOTE: a machine reboot is no longer required to apply changes to CRI configuration.
Talos no longer disables NRI (Node Resource Interface) for the CRI containerd instance by default, so NRI is available
to use without any machine config patches.
To bring back the old behavior of NRI disabled by default, add the following machine configuration document:
apiVersion: v1alpha1
kind: CRICustomizationConfig
name: disable-nri
content: |
[plugins]
[plugins."io.containerd.nri.v1.nri"]
disable = trueThe default installer image has been updated to use the Image Factory.
The ghcr.io/siderolabs/installer image is no longer published with releases; use the Image Factory installer image instead.
DHCPv4 search domains are now applied to the resolver configuration.
DHCPv4 configuration now supports ignoreRoutes option to ignore routes provided by DHCPv4 servers.
Talos introduces support for configuring multiple discovery service endpoints.
Talos introduces new document for configuring the cluster discovery identity.
List of changes:
.cluster.discovery in the v1alpha1 config; use the DiscoveryServiceConfig document for discovery service configuration. The v1alpha1 config and DiscoveryServiceConfig are mutually exclusive..cluster.secret and cluster.id in the v1alpha1 config; use the DiscoveryIdentityConfig document for discovery identity configuration. The v1alpha1 config and DiscoveryIdentityConfig are mutually exclusive.base64.URLEncoding to base64.StdEncoding. This aligns the encoding with the rest of Talos.Volume encryption now supports an allowDiscards option (disabled by default) which passes TRIM/discard requests
through to the underlying device when the encrypted volume is opened.
This only enables passing discards through to the underlying device; Talos does not perform any fstrim/discard operation by itself.
Talos is now compatible with etcd v3.6.x only (the default etcd version was 3.6.x since Talos v1.11).
The default version is 3.7.0+ now.
etcd now serves its HTTP-only endpoints (/metrics, /health, the gRPC-gateway JSON API) on a dedicated
listener on port 2383, while the client port 2379 serves gRPC only. This keeps gRPC off Go's net/http
HTTP/2 server, avoiding watch-stream starvation under TLS (see etcd-io/etcd#15402, golang/go#58804,
etcd-io/etcd#21605).
Upgrade note: etcd metrics and the HTTP health endpoint are no longer reachable on 2379; scrape them on
port 2383 instead (same client mTLS as before). etcd gRPC clients and the Talos health check are unaffected.
Firewall might need to be adjusted to block the port 2383 if previously 2379 was blocked.
If --listen-metrics-urls was customized, the metrics should not move.
Talos now supports managing user-owned files under /etc with the new EtcFileConfig multi-document
configuration kind. The document name is the path relative to /etc, and each document owns the complete
file contents and mode.
This can be used to configure files such as /etc/nfsmount.conf or /etc/multipath.conf. Talos-managed
paths, including resolv.conf, hosts, machine-id, CRI and Kubernetes configuration, trust bundles, and
identity files, are rejected to prevent overriding files owned by Talos.
Talos can now periodically trim (the equivalent of the fstrim command) mounted filesystems which support trimming,
discarding unused blocks. This is useful for SSDs and thin-provisioned storage.
Trimming is opt-in via a new FilesystemTrimConfig document which sets the global trim interval:
apiVersion: v1alpha1
kind: FilesystemTrimConfig
interval: 168h0m0s # one weekThe default machine configuration for Talos 1.14+ includes a FilesystemTrimConfig document with a default trim interval of one week,
so trimming is enabled by default for eligible filesystems. For cluster which were upgraded from older versions, the FilesystemTrimConfig document will be missing,
so trimming will be disabled by default until the document is added.
When the document is present, Talos builds a stable schedule (hashed by node ID and volume ID, so trims are spread out
across volumes and across nodes in a cluster) and trims eligible volumes (ready disk/partition volumes with a
trim-capable filesystem; for encrypted volumes only when allowDiscards is set).
The trim interval can be overridden or disabled per-volume via a trim block on the volume documents
(VolumeConfig, UserVolumeConfig, ExistingVolumeConfig, ExternalVolumeConfig):
trim:
enabled: true
interval: 24h0m0sTalos now configures Flannel with the EnableNFTables option enabled, which uses nftables native backend instead of iptables-nft compatibility layer.
Talos no longer provisions the deprecated FlexVolume executable host path at
/usr/libexec/kubernetes. FlexVolume has been deprecated since Kubernetes 1.23.
Modern CSI plugin paths under /var/lib/kubelet are unaffected.
HostDNS configuration was moved from the v1alpha1 config .machine.features.hostDNS field to the new hostDNS in the ResolverConfig document.
Talos now supports HTTP network probes, allowing for monitoring of HTTP endpoints.
HTTP responses with status 200-399 are considered successful, while connection and transport errors are treated as failures.
Talos now supports a new ImageCacheConfig document for configuring the Image Cache feature, replacing the old machine.features.imageCache field in the v1alpha1 config.
Old configuration is still supported for backwards compatibility.
Talos introduces new multi-document configuration for kernel parameters (sysctl and sysfs settings), replacing the old v1alpha1 config fields.
The old configuration is still supported for backwards compatibility, but new deployments should use the new documents.
If both old and new configuration sources are used, the new multi-document configuration takes precedence over the old v1alpha1 config on conflicting fields.
List of changes:
.machine.sysctls in the v1alpha1 config; use the SysctlConfig document for kernel sysctl configuration..machine.sysfs in the v1alpha1 config; use the SysfsConfig document for sysfs configuration..machine.kernel in the v1alpha1 config; use the KernelModuleConfig document for kernel module configuration.Talos now reports the status of both dynamically loaded, and built-in kernel modules.
The LoadedKernelModule resource has been deprecated and superseded by the new KernelModuleStatus resource.
Because the kubelet now runs inside the sandbox namespace (see the workload isolation note), the in-tree
Kubernetes volume plugins that require the kubelet to reach host-level daemons no longer work. In particular
the in-tree iscsi volume plugin, which drives the kubelet's iscsiadm wrapper to talk to the host iscsid,
can no longer locate it across the sandbox PID namespace boundary.
Use CSI drivers instead — a CSI node plugin performs the attach/mount itself in its own privileged pod and is
unaffected by the sandbox. For iSCSI, kubernetes-csi/csi-driver-iscsi (or democratic-csi) consumes a
target the same way. All in-tree (non-CSI) volume plugins are deprecated for the kubelet and support for them
may be removed in a later release.
Talos introduces new multi-document Kubernetes configuration, which allows for more flexible and modular configuration of Kubernetes components.
Talos still supports the old v1alpha1 config for backwards compatibility, but new features and fields will only be available in the new multi-document format.
The kube-proxy is now using configuration to manage its settings instead of command line arguments (with new KubeProxyConfig document).
List of changes:
.cluster.secretboxEncryptionSecret in the v1alpha1 config; use the KubeEtcdEncryptionConfig document for full etcd encryption configuration..cluster.apiServer in the v1alpha1 config; use the KubeAPIServerConfig, KubeAdmissionControlConfig, KubeAuditPolicyConfig, KubeAuthenticationConfig and KubeAuthorizerConfig documents for kube-apiserver configuration..cluster.ca, .cluster.acceptedCAs and .cluster.aggregatorCA in the v1alpha1 config; use the KubeAPIServerCAConfig, KubeAggregatorCAConfig documents..cluster.controllerManager in the v1alpha1 config; use the KubeControllerManagerConfig document for kube-controller-manager configuration..cluster.scheduler in the v1alpha1 config; use the KubeSchedulerConfig document for kube-scheduler configuration..cluster.proxy in the v1alpha1 config; use the KubeProxyConfig document for kube-proxy configuration..cluster.network in the v1alpha1 config; use the KubeNetworkConfig document for Kubernetes network configuration; Flannel can be configured using the KubeFlannelCNIConfig document..cluster.coreDNS in the v1alpha1 config; use the KubeCoreDNSConfig document for CoreDNS configuration..cluster.name and .cluster.controlPlane.endpoint in the v1alpha1 config; use the KubeClusterConfig` document for cluster name and control plane endpoint configuration..cluster.allowSchedulingOnControlPlanes.machine.kubelet.skipNodeRegistration.machine.kubelet.registerWithFQDN.machine.kubelet.nodeIP.machine.nodeLabels.machine.nodeAnnotations.machine.nodeTaintsNoSchedule taint for controlplane and label are now explicitly listed in KubeNodeConfig..machine.kubelet fields in the v1alpha1 config; use the KubeNodeConfig and KubeCredentialProviderConfig documents for kubelet configuration..machine.pods in the v1alpha1 config; use the KubeStaticPodConfig document for static pod configuration..machine.files in the v1alpha1 config; use dedicated configuration documents such as EtcFileConfig and CRICustomizationConfig instead..machine.baseRuntimeSpecOverrides in the v1alpha1 config; use the CRIBaseRuntimeSpecConfig document for base runtimespec overrides..cluster.inlineManifests in the v1alpha1 config; use the KubeInlineManifestConfig document for inline manifests..cluster.extraManifests and .cluster.extraManifestHeaders in the v1alpha1 config; use the KubeExternalManifestConfig document for external manifests..machine.features.kubePrism; use the KubePrismConfig document for KubePrism configuration (or remove it to disable KubePrism)..machine.features.kubernetesTalosAPIAccess; use the KubeTalosAPIAccessConfig document instead.nodeCIDRMaskSizeIPv4 (default 24) and nodeCIDRMaskSizeIPv6 (default 64) settings to the KubeNetworkConfig document to control the per-node pod CIDR mask size and validate the pod and service subnet sizes.Logical volumes can now be declared with a new LVMLogicalVolumeConfig multi-doc config kind. Each document
names a logical volume, its parent volumeGroup, a type (linear, raid0, raid1 or raid10) and a
maxSize (absolute, e.g. 50GiB, or a percentage of the volume group, e.g. 80%). RAID layouts accept
optional mirrors (raid1/raid10, default 1) and stripes (raid0/raid10, default: all available physical
volumes) fields. Once the volume group is assembled the logical volume is created via lvcreate.
Raising maxSize grows an existing logical volume via lvextend; percentage-sized volumes also grow when
their volume group is extended. Shrinking is never performed (it risks data loss) - a request to reduce the
size surfaces an LVMValidationError instead. Removal stays an explicit operation via the LVMService LV
remove RPC (talosctl wipe lv).
Talos now provides detailed LVM status information, allowing for better monitoring and management of LVM volumes.
New resources LVMPhysicalVolumeStatus, LVMVolumeGroupStatus, and LVMLogicalVolumeStatus expose PV, VG, and LV details.
DiscoveredVolume resources for logical volumes are listed by their kernel name (e.g. dm-0). To resolve the <vg>/<lv> for a given device, use the Disks or BlockSymlinks resources, which carry the udev-managed symlinks (e.g. /dev/disk/by-id/dm-name-<vg>-<lv>).
Talos can now create and grow LVM Volume Groups declaratively through a new LVMVolumeGroupConfig multi-doc
config kind. Each document names a Volume Group and a CEL volumeSelector over the disk inventory; matched
disks are initialised as Physical Volumes (pvcreate) and aggregated into the requested VG (vgcreate).
Newly matched disks added to an existing VG are attached via vgextend.
Reconciliation is strictly additive and safe-by-default.
Talos now provides the ability to securely wipe LVM metadata from logical volumes, volume groups, and physical volumes.
This feature allows for selective wiping of logical volumes, volume groups, and physical volumes.
With talosctl wipe lv/vg/pv <name>, users can wipe LVM metadata from a specific logical volume, volume group, or physical volume.
Talos now supports Network Time Security (NTS) for secure time synchronization.
This feature enhances the security of NTP by providing cryptographic authentication of time sources.
NTS is enabled by default (without any configuration sources) for the default time.cloudflare.com time server
NTS can be enabled for custom time servers via the new useNTS field in the TimeServerConfig document.
Talos can now create and grow Linux MD (software RAID) arrays declaratively through a new RAIDArrayConfig
multi-doc config kind. Each document names an array, its level (raid1) and a CEL volumeSelector over
the disk inventory; matched disks are assembled into the requested array with mdadm and exposed at the stable
/dev/disk/by-id/md-name-<name> path. New matching disks added to an existing array are attached automatically.
Reconciliation is strictly additive and safe-by-default. Arrays are never destroyed by removing the config;
removal stays an explicit operation via talosctl wipe md <device>. The new MDArrayStatus resource reports the
assembled array, level, device path, and members.
Talos can now be installed onto and boot from a Linux MD (software RAID) array. Define a RAIDArrayConfig for the
array and point the install disk selector (UnattendedInstallConfig) at the resulting /dev/disk/by-id/md-name-<name>
device.
Only raid1 arrays with metadata: "1.0" can be used for booting: the 1.0 format keeps its superblock at the end of
each member, so the partition table written to the array stays visible at the start of every disk, allowing the
firmware to boot from any member. metadata defaults to 1.0; other levels and metadata formats are not bootable.
The container runtime plane — CRI containerd, the kubelet, and all pods — now runs inside a dedicated PID and
mount namespace anchored by a new sandboxd service, instead of sharing machined's namespaces.
sandboxd runs in its own least-privilege SELinux domain (sandboxd_t). if it dies the kernel tears down the
namespace and Talos recreates it — relaunching CRI, the kubelet, and pods — without rebooting the node.
Its logs are available via talosctl logs sandboxd.
Workload isolation is controlled by the workloadIsolation field of the new SecurityProfileConfig document.
talosctl gen config emits it with workloadIsolation: true for Talos 1.14+, so new clusters are isolated by
default. Clusters upgraded from older versions do not have this document and therefore keep the previous
(non-isolated) behavior until it is added — upgrades change nothing on their own. To enable on an existing
cluster, add the document:
apiVersion: v1alpha1
kind: SecurityProfileConfig
workloadIsolation: trueNOTE: With workload isolation enabled, the deprecated in-tree Kubernetes iSCSI volume plugin does not work
(the kubelet cannot reach the hostiscsidacross the sandbox); use a CSI driver instead. See the in-tree
volume plugin deprecation note.
Talos now sets net.ipv4.conf.all.send_redirects=0 and net.ipv4.conf.default.send_redirects=0 by default,
preventing the node from emitting ICMP redirect messages. This aligns with CIS Benchmark recommendations and
does not affect normal Kubernetes pod or service traffic. Nodes that deliberately act as L3 gateways relying
on ICMP redirects can override this via machine.sysctls.
The talosctl support command now encrypts support bundles using the age encryption tool, enhancing the security of support data.
The default set of recipients includes the 'siderolabs' GitHub organization members, but it can be overridden with custom recipients.
The ETCD, CRI, KUBELET and LOG system volumes (/var/lib/etcd, /var/lib/containerd, /var/lib/kubelet and /var/log) can now be placed on dedicated partitions via a VolumeConfig document with provisioning set (optionally encrypted). By default they remain directories under the EPHEMERAL volume.
apiVersion: v1alpha1
kind: VolumeConfig
name: ETCD
provisioning:
minSize: 1GB
maxSize: 2GBThe backing (directory vs. dedicated partition) is fixed at cluster creation: switching an already-provisioned node between the two is rejected.
A dedicated partition has its own mount, so the mount.secure option (nosuid/noexec/nodev, enabled by default) can be set per volume; directory-backed volumes inherit the EPHEMERAL mount options.
Note that with ETCD on a dedicated partition, etcd data no longer lives under EPHEMERAL. Resetting a control plane node with only the EPHEMERAL partition wiped will not clear etcd data; wipe the ETCD volume to reset etcd.
Talos now runs etcd and kube-apiserver with a minimum TLS version of 1.3, improving security by leveraging the latest TLS features and cipher suites.
Custom settings for cipher suites have been removed, as they are ignored when TLS 1.3 is used, which simplifies configuration and ensures the use of modern, secure defaults.
Talos introduces new multi-document configuration UdevRulesConfig document for configuring custom udev rules.
The old v1alpha1 .machine.udev.rules field is still supported for backwards compatibility, but new deployments should use the new document.
If both old and new configuration sources are used, UdevRulesConfig takes precedence.
List of changes:
.machine.udev.rules in the v1alpha1 config; use the UdevRulesConfig document for custom udev rules.Talos introduces a new UnattendedInstall multi-document config kind which replaces the deprecated .machine.install
section of the v1alpha1 config. The document carries the installer image and a provisioning section with a CEL
volumeSelector to match the install disk, plus a wipe option.
When the UnattendedInstall document is present, the install is driven by the new UnattendedInstallController
(exposing an UnattendedInstallStatus resource) instead of the legacy install sequence.
talosctl gen config and talosctl cluster create now generate the UnattendedInstall document by default.
The .machine.install field remains supported for backwards compatibility and is still used for older version contracts.
Linux: 6.18.41
Kubernetes: 1.37.0-beta.0
containerd: 2.3.3
etcd: 3.7.1
Flannel: 0.28.8
runc: 1.5.1
CoreDNS: 1.14.6
Talos is built with Go 1.26.5.
Talos now supports declarative virtual Ethernet (veth) pairs through the new VethConfig multi-document
configuration kind. Both endpoints are created in the host network namespace and support the common link settings,
addresses, routes, and multicast configuration.
For example, the following configuration creates a pair named veth-host and veth-router with an address on each
endpoint:
apiVersion: v1alpha1
kind: VethConfig
name: veth-host
addresses:
- address: 10.3.0.1/30
peer:
name: veth-router
addresses:
- address: 10.3.0.2/30On non-rotational devices mkfs.xfs sizes the allocation group count to the number of CPUs, bounding the
allocation group size from below at 4 GiB only. On machines with many cores and a modest disk this produces
hundreds of tiny allocation groups, which squeezes the AG-local reflink/rmap metadata (leading to spurious
ENOSPC on reflink-heavy workloads while the filesystem still has plenty of free space) and inflates the
journal at the same time.
Talos now keeps XFS allocation groups at 64 GiB or above when it formats a volume. The bound can be changed
per volume, and setting it to zero restores the stock mkfs.xfs behavior:
apiVersion: v1alpha1
kind: VolumeConfig
name: EPHEMERAL
filesystem:
xfs:
minAllocationGroupSize: 128GiBThe same filesystem.xfs.minAllocationGroupSize setting is available for UserVolumeConfig.
Note: allocation group geometry is fixed when the filesystem is created, so this only affects volumes
formatted by Talos 1.14 or later. Existing volumes keep their current geometry until they are wiped and
re-created (e.g. talosctl reset --system-labels-to-wipe=EPHEMERAL).
Talos now supports automatically running background online filesystem maintenance tasks. Currently,
only XFS using xfs_scrub tool is supported.
This behavior can be enabled globally using a FilesystemScrubConfig document, or on per-volume
basis using a field in corresponding VolumeConfig documents.
KubeletConfigKubeNodeConfignoexec for EPHEMERAL only for new machinesNote truncated.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
`67464cbef` fix: update the vulnerability dates and description
Welcome to the v1.14.0-beta.0 release of Talos!
This is a pre-release of Talos
Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues.
Talos now supports DNS over TLS (DoT) and DNS over HTTPS (DoH) for secure DNS resolution.
These features allow Talos to encrypt DNS queries and responses, enhancing privacy and security for DNS traffic.
The DNS protocol can be configured on a per-name server basis in the ResolverConfig document, allowing for flexible configuration of DNS resolution.
Talos 1.14 clusters now default the EPHEMERAL volume (/var) to noexec in addition to the existing nosuid and nodev
mount options through generated machine configuration.
Existing machines are not affected on upgrades.
Note: Workloads that execute binaries placed under /var can break on new machines.
Longhorn v1 and vCluster are known to be affected.
For example, Longhorn v1's instance-manager executes engine binaries that the engine-image DaemonSet places under
/var/lib/longhorn/engine-binaries/, which now fails with permission denied.
Affected users can opt out via a VolumeConfig document:
apiVersion: v1alpha1
kind: VolumeConfig
name: EPHEMERAL
mount:
secure: false
NOTE: Setting
secure: falsewill also disablenosuidandnodev, which may have security implications. Use with caution.
Longhorn v2 (SPDK data engine) runs the data plane inside the instance manager process and is not affected.
The '--mode=reboot' option has been removed from the talosctl apply-config command; by default, configuration is applied without a reboot.
Most configuration changes don't require a reboot; the documentation lists the changes that do.
Talos now supports running a native BGP speaker on the host via an embedded GoBGP, configured with the new BGPPeerConfig document.
This removes the need to ship FRR as a system extension for the common fabric-facing use case.
List of changes:
BGPPeerConfig document to configure the local ASN, router-id, advertised interfaces (loopbacks originated as host routes), neighbors, and per-route preferred source (routeSource).BGPPeerStatus resource (talosctl get bgppeerstatus).RouteSpec/RouteStatus now carry a multipath next-hop list to support ECMP and cross-family (RFC 8950) next-hops.Talos now supports mounting and provisioning btrfs filesystem for user volumes and existing volumes.
Support for btrfs is enabled by installing btrfs system extension.
Talos now supports overriding the default OCI runtime specification for CRI containers with a
CRIBaseRuntimeSpecConfig document:
apiVersion: v1alpha1
kind: CRIBaseRuntimeSpecConfig
overrides:
process:
rlimits:
- type: RLIMIT_NOFILE
hard: 1024
soft: 1024
The .machine.baseRuntimeSpecOverrides field is deprecated and remains supported during the deprecation
period. It is mutually exclusive with CRIBaseRuntimeSpecConfig; configurations containing both are rejected.
Applying, updating, or removing either source regenerates the base runtime specification and restarts CRI automatically. A machine reboot is no longer required.
Talos now supports customizing the CRI containerd configuration with named CRICustomizationConfig
documents. Each document contains a TOML fragment; fragments are merged in lexicographical order by name.
Applying, updating, or removing these documents updates the generated CRI configuration and restarts CRI
automatically.
The legacy /etc/cri/conf.d/20-customization.part machine-file configuration remains supported during the
deprecation period and is exposed under the reserved name customization. A CRICustomizationConfig document
cannot use that name.
NOTE: a machine reboot is no longer required to apply changes to CRI configuration.
Talos no longer disables NRI (Node Resource Interface) for the CRI containerd instance by default, so NRI is available to use without any machine config patches.
To bring back the old behavior of NRI disabled by default, add the following machine configuration document:
apiVersion: v1alpha1
kind: CRICustomizationConfig
name: disable-nri
content: |
[plugins]
[plugins."io.containerd.nri.v1.nri"]
disable = true
The default installer image has been updated to use the Image Factory.
The ghcr.io/siderolabs/installer image is no longer published with releases; use the Image Factory installer image instead.
DHCPv4 search domains are now applied to the resolver configuration.
DHCPv4 configuration now supports ignoreRoutes option to ignore routes provided by DHCPv4 servers.
Talos introduces support for configuring multiple discovery service endpoints. Talos introduces new document for configuring the cluster discovery identity.
List of changes:
.cluster.discovery in the v1alpha1 config; use the DiscoveryServiceConfig document for discovery service configuration. The v1alpha1 config and DiscoveryServiceConfig are mutually exclusive..cluster.secret and cluster.id in the v1alpha1 config; use the DiscoveryIdentityConfig document for discovery identity configuration. The v1alpha1 config and DiscoveryIdentityConfig are mutually exclusive.base64.URLEncoding to base64.StdEncoding. This aligns the encoding with the rest of Talos.Volume encryption now supports an allowDiscards option (disabled by default) which passes TRIM/discard requests
through to the underlying device when the encrypted volume is opened.
This only enables passing discards through to the underlying device; Talos does not perform any fstrim/discard operation by itself.
Talos is now compatible with etcd v3.6.x only (the default etcd version was 3.6.x since Talos v1.11). The default version is 3.7.0+ now.
etcd now serves its HTTP-only endpoints (/metrics, /health, the gRPC-gateway JSON API) on a dedicated
listener on port 2383, while the client port 2379 serves gRPC only. This keeps gRPC off Go's net/http
HTTP/2 server, avoiding watch-stream starvation under TLS (see etcd-io/etcd#15402, golang/go#58804,
etcd-io/etcd#21605).
Upgrade note: etcd metrics and the HTTP health endpoint are no longer reachable on 2379; scrape them on
port 2383 instead (same client mTLS as before). etcd gRPC clients and the Talos health check are unaffected.
Firewall might need to be adjusted to block the port 2383 if previously 2379 was blocked.
If --listen-metrics-urls was customized, the metrics should not move.
Talos now supports managing user-owned files under /etc with the new EtcFileConfig multi-document
configuration kind. The document name is the path relative to /etc, and each document owns the complete
file contents and mode.
This can be used to configure files such as /etc/nfsmount.conf or /etc/multipath.conf. Talos-managed
paths, including resolv.conf, hosts, machine-id, CRI and Kubernetes configuration, trust bundles, and
identity files, are rejected to prevent overriding files owned by Talos.
Talos can now periodically trim (the equivalent of the fstrim command) mounted filesystems which support trimming,
discarding unused blocks. This is useful for SSDs and thin-provisioned storage.
Trimming is opt-in via a new FilesystemTrimConfig document which sets the global trim interval:
apiVersion: v1alpha1
kind: FilesystemTrimConfig
interval: 168h0m0s # one week
The default machine configuration for Talos 1.14+ includes a FilesystemTrimConfig document with a default trim interval of one week,
so trimming is enabled by default for eligible filesystems. For cluster which were upgraded from older versions, the FilesystemTrimConfig document will be missing,
so trimming will be disabled by default until the document is added.
When the document is present, Talos builds a stable schedule (hashed by node ID and volume ID, so trims are spread out
across volumes and across nodes in a cluster) and trims eligible volumes (ready disk/partition volumes with a
trim-capable filesystem; for encrypted volumes only when allowDiscards is set).
The trim interval can be overridden or disabled per-volume via a trim block on the volume documents
(VolumeConfig, UserVolumeConfig, ExistingVolumeConfig, ExternalVolumeConfig):
trim:
enabled: true
interval: 24h0m0s
Talos now configures Flannel with the EnableNFTables option enabled, which uses nftables native backend instead of iptables-nft compatibility layer.
Talos no longer provisions the deprecated FlexVolume executable host path at
/usr/libexec/kubernetes. FlexVolume has been deprecated since Kubernetes 1.23.
Modern CSI plugin paths under /var/lib/kubelet are unaffected.
HostDNS configuration was moved from the v1alpha1 config .machine.features.hostDNS field to the new hostDNS in the ResolverConfig document.
Talos now supports HTTP network probes, allowing for monitoring of HTTP endpoints. HTTP responses with status 200-399 are considered successful, while connection and transport errors are treated as failures.
Talos now supports a new ImageCacheConfig document for configuring the Image Cache feature, replacing the old machine.features.imageCache field in the v1alpha1 config.
Old configuration is still supported for backwards compatibility.
Talos introduces new multi-document configuration for kernel parameters (sysctl and sysfs settings), replacing the old v1alpha1 config fields. The old configuration is still supported for backwards compatibility, but new deployments should use the new documents.
If both old and new configuration sources are used, the new multi-document configuration takes precedence over the old v1alpha1 config on conflicting fields.
List of changes:
.machine.sysctls in the v1alpha1 config; use the SysctlConfig document for kernel sysctl configuration..machine.sysfs in the v1alpha1 config; use the SysfsConfig document for sysfs configuration..machine.kernel in the v1alpha1 config; use the KernelModuleConfig document for kernel module configuration.Talos now reports the status of both dynamically loaded, and built-in kernel modules.
The LoadedKernelModule resource has been deprecated and superseded by the new KernelModuleStatus resource.
Because the kubelet now runs inside the sandbox namespace (see the workload isolation note), the in-tree
Kubernetes volume plugins that require the kubelet to reach host-level daemons no longer work. In particular
the in-tree iscsi volume plugin, which drives the kubelet's iscsiadm wrapper to talk to the host iscsid,
can no longer locate it across the sandbox PID namespace boundary.
Use CSI drivers instead — a CSI node plugin performs the attach/mount itself in its own privileged pod and is
unaffected by the sandbox. For iSCSI, kubernetes-csi/csi-driver-iscsi (or democratic-csi) consumes a
target the same way. All in-tree (non-CSI) volume plugins are deprecated for the kubelet and support for them
may be removed in a later release.
Talos introduces new multi-document Kubernetes configuration, which allows for more flexible and modular configuration of Kubernetes components.
Talos still supports the old v1alpha1 config for backwards compatibility, but new features and fields will only be available in the new multi-document format.
The kube-proxy is now using configuration to manage its settings instead of command line arguments (with new KubeProxyConfig document).
List of changes:
.cluster.secretboxEncryptionSecret in the v1alpha1 config; use the KubeEtcdEncryptionConfig document for full etcd encryption configuration..cluster.apiServer in the v1alpha1 config; use the KubeAPIServerConfig, KubeAdmissionControlConfig, KubeAuditPolicyConfig, KubeAuthenticationConfig and KubeAuthorizerConfig documents for kube-apiserver configuration..cluster.ca, .cluster.acceptedCAs and .cluster.aggregatorCA in the v1alpha1 config; use the KubeAPIServerCAConfig, KubeAggregatorCAConfig documents..cluster.controllerManager in the v1alpha1 config; use the KubeControllerManagerConfig document for kube-controller-manager configuration..cluster.scheduler in the v1alpha1 config; use the KubeSchedulerConfig document for kube-scheduler configuration..cluster.proxy in the v1alpha1 config; use the KubeProxyConfig document for kube-proxy configuration..cluster.network in the v1alpha1 config; use the KubeNetworkConfig document for Kubernetes network configuration; Flannel can be configured using the KubeFlannelCNIConfig document..cluster.coreDNS in the v1alpha1 config; use the KubeCoreDNSConfig document for CoreDNS configuration..cluster.name and .cluster.controlPlane.endpoint in the v1alpha1 config; use the KubeClusterConfig` document for cluster name and control plane endpoint configuration..cluster.allowSchedulingOnControlPlanes.machine.kubelet.skipNodeRegistration.machine.kubelet.registerWithFQDN.machine.kubelet.nodeIP.machine.nodeLabels.machine.nodeAnnotations.machine.nodeTaintsNoSchedule taint for controlplane and label are now explicitly listed in KubeNodeConfig..machine.kubelet fields in the v1alpha1 config; use the KubeNodeConfig and KubeCredentialProviderConfig documents for kubelet configuration..machine.pods in the v1alpha1 config; use the KubeStaticPodConfig document for static pod configuration..machine.files in the v1alpha1 config; use dedicated configuration documents such as EtcFileConfig and CRICustomizationConfig instead..machine.baseRuntimeSpecOverrides in the v1alpha1 config; use the CRIBaseRuntimeSpecConfig document for base runtimespec overrides..cluster.inlineManifests in the v1alpha1 config; use the KubeInlineManifestConfig document for inline manifests..cluster.extraManifests and .cluster.extraManifestHeaders in the v1alpha1 config; use the KubeExternalManifestConfig document for external manifests..machine.features.kubePrism; use the KubePrismConfig document for KubePrism configuration (or remove it to disable KubePrism).nodeCIDRMaskSizeIPv4 (default 24) and nodeCIDRMaskSizeIPv6 (default 64) settings to the KubeNetworkConfig document to control the per-node pod CIDR mask size and validate the pod and service subnet sizes.Logical volumes can now be declared with a new LVMLogicalVolumeConfig multi-doc config kind. Each document
names a logical volume, its parent volumeGroup, a type (linear, raid0, raid1 or raid10) and a
maxSize (absolute, e.g. 50GiB, or a percentage of the volume group, e.g. 80%). RAID layouts accept
optional mirrors (raid1/raid10, default 1) and stripes (raid0/raid10, default: all available physical
volumes) fields. Once the volume group is assembled the logical volume is created via lvcreate.
Raising maxSize grows an existing logical volume via lvextend; percentage-sized volumes also grow when
their volume group is extended. Shrinking is never performed (it risks data loss) - a request to reduce the
size surfaces an LVMValidationError instead. Removal stays an explicit operation via the LVMService LV
remove RPC (talosctl wipe lv).
Talos now provides detailed LVM status information, allowing for better monitoring and management of LVM volumes.
New resources LVMPhysicalVolumeStatus, LVMVolumeGroupStatus, and LVMLogicalVolumeStatus expose PV, VG, and LV details.
DiscoveredVolume resources for logical volumes are listed by their kernel name (e.g. dm-0). To resolve the <vg>/<lv> for a given device, use the Disks or BlockSymlinks resources, which carry the udev-managed symlinks (e.g. /dev/disk/by-id/dm-name-<vg>-<lv>).
Talos can now create and grow LVM Volume Groups declaratively through a new LVMVolumeGroupConfig multi-doc
config kind. Each document names a Volume Group and a CEL volumeSelector over the disk inventory; matched
disks are initialised as Physical Volumes (pvcreate) and aggregated into the requested VG (vgcreate).
Newly matched disks added to an existing VG are attached via vgextend.
Reconciliation is strictly additive and safe-by-default.
Talos now provides the ability to securely wipe LVM metadata from logical volumes, volume groups, and physical volumes. This feature allows for selective wiping of logical volumes, volume groups, and physical volumes.
With talosctl wipe lv/vg/pv <name>, users can wipe LVM metadata from a specific logical volume, volume group, or physical volume.
Talos now supports Network Time Security (NTS) for secure time synchronization. This feature enhances the security of NTP by providing cryptographic authentication of time sources.
NTS is enabled by default (without any configuration sources) for the default time.cloudflare.com time server
NTS can be enabled for custom time servers via the new useNTS field in the TimeServerConfig document.
Talos can now create and grow Linux MD (software RAID) arrays declaratively through a new RAIDArrayConfig
multi-doc config kind. Each document names an array, its level (raid1) and a CEL volumeSelector over
the disk inventory; matched disks are assembled into the requested array with mdadm and exposed at the stable
/dev/disk/by-id/md-name-<name> path. New matching disks added to an existing array are attached automatically.
Reconciliation is strictly additive and safe-by-default. Arrays are never destroyed by removing the config;
removal stays an explicit operation via talosctl wipe md <device>. The new MDArrayStatus resource reports the
assembled array, level, device path, and members.
Talos can now be installed onto and boot from a Linux MD (software RAID) array. Define a RAIDArrayConfig for the
array and point the install disk selector (UnattendedInstallConfig) at the resulting /dev/disk/by-id/md-name-<name>
device.
Only raid1 arrays with metadata: "1.0" can be used for booting: the 1.0 format keeps its superblock at the end of
each member, so the partition table written to the array stays visible at the start of every disk, allowing the
firmware to boot from any member. metadata defaults to 1.0; other levels and metadata formats are not bootable.
The container runtime plane — CRI containerd, the kubelet, and all pods — now runs inside a dedicated PID and
mount namespace anchored by a new sandboxd service, instead of sharing machined's namespaces.
sandboxd runs in its own least-privilege SELinux domain (sandboxd_t). if it dies the kernel tears down the
namespace and Talos recreates it — relaunching CRI, the kubelet, and pods — without rebooting the node.
Its logs are available via talosctl logs sandboxd.
Workload isolation is controlled by the workloadIsolation field of the new SecurityProfileConfig document.
talosctl gen config emits it with workloadIsolation: true for Talos 1.14+, so new clusters are isolated by
default. Clusters upgraded from older versions do not have this document and therefore keep the previous
(non-isolated) behavior until it is added — upgrades change nothing on their own. To enable on an existing
cluster, add the document:
apiVersion: v1alpha1
kind: SecurityProfileConfig
workloadIsolation: true
NOTE: With workload isolation enabled, the deprecated in-tree Kubernetes iSCSI volume plugin does not work (the kubelet cannot reach the host
iscsidacross the sandbox); use a CSI driver instead. See the in-tree volume plugin deprecation note.
Talos now sets net.ipv4.conf.all.send_redirects=0 and net.ipv4.conf.default.send_redirects=0 by default,
preventing the node from emitting ICMP redirect messages. This aligns with CIS Benchmark recommendations and
does not affect normal Kubernetes pod or service traffic. Nodes that deliberately act as L3 gateways relying
on ICMP redirects can override this via machine.sysctls.
The talosctl support command now encrypts support bundles using the age encryption tool, enhancing the security of support data.
The default set of recipients includes the 'siderolabs' GitHub organization members, but it can be overridden with custom recipients.
The ETCD, CRI, KUBELET and LOG system volumes (/var/lib/etcd, /var/lib/containerd, /var/lib/kubelet and /var/log) can now be placed on dedicated partitions via a VolumeConfig document with provisioning set (optionally encrypted). By default they remain directories under the EPHEMERAL volume.
apiVersion: v1alpha1
kind: VolumeConfig
name: ETCD
provisioning:
minSize: 1GB
maxSize: 2GB
The backing (directory vs. dedicated partition) is fixed at cluster creation: switching an already-provisioned node between the two is rejected.
A dedicated partition has its own mount, so the mount.secure option (nosuid/noexec/nodev, enabled by default) can be set per volume; directory-backed volumes inherit the EPHEMERAL mount options.
Note that with ETCD on a dedicated partition, etcd data no longer lives under EPHEMERAL. Resetting a control plane node with only the EPHEMERAL partition wiped will not clear etcd data; wipe the ETCD volume to reset etcd.
Talos now runs etcd and kube-apiserver with a minimum TLS version of 1.3, improving security by leveraging the latest TLS features and cipher suites. Custom settings for cipher suites have been removed, as they are ignored when TLS 1.3 is used, which simplifies configuration and ensures the use of modern, secure defaults.
Talos introduces new multi-document configuration UdevRulesConfig document for configuring custom udev rules.
The old v1alpha1 .machine.udev.rules field is still supported for backwards compatibility, but new deployments should use the new document.
If both old and new configuration sources are used, UdevRulesConfig takes precedence.
List of changes:
.machine.udev.rules in the v1alpha1 config; use the UdevRulesConfig document for custom udev rules.Talos introduces a new UnattendedInstall multi-document config kind which replaces the deprecated .machine.install
section of the v1alpha1 config. The document carries the installer image and a provisioning section with a CEL
volumeSelector to match the install disk, plus a wipe option.
When the UnattendedInstall document is present, the install is driven by the new UnattendedInstallController
(exposing an UnattendedInstallStatus resource) instead of the legacy install sequence.
talosctl gen config and talosctl cluster create now generate the UnattendedInstall document by default.
The .machine.install field remains supported for backwards compatibility and is still used for older version contracts.
Linux: 6.18.39 Kubernetes: 1.37.0-beta.0 containerd: 2.3.3 etcd: v3.7.0 Flannel: 0.28.8 runc: 1.5.1 CoreDNS: 1.14.6
Talos is built with Go 1.26.5.
On non-rotational devices mkfs.xfs sizes the allocation group count to the number of CPUs, bounding the
allocation group size from below at 4 GiB only. On machines with many cores and a modest disk this produces
hundreds of tiny allocation groups, which squeezes the AG-local reflink/rmap metadata (leading to spurious
ENOSPC on reflink-heavy workloads while the filesystem still has plenty of free space) and inflates the
journal at the same time.
Talos now keeps XFS allocation groups at 64 GiB or above when it formats a volume. The bound can be changed
per volume, and setting it to zero restores the stock mkfs.xfs behavior:
apiVersion: v1alpha1
kind: VolumeConfig
name: EPHEMERAL
filesystem:
xfs:
minAllocationGroupSize: 128GiB
The same filesystem.xfs.minAllocationGroupSize setting is available for UserVolumeConfig.
Note: allocation group geometry is fixed when the filesystem is created, so this only affects volumes
formatted by Talos 1.14 or later. Existing volumes keep their current geometry until they are wiped and
re-created (e.g. talosctl reset --system-labels-to-wipe=EPHEMERAL).
<details><summary>447 commits</summary> <p>
7e58e0442 feat: add dedicated CRI configuration documents076c38136 fix: race with PCR extensions and volume unlock88884194c fix: teardown ephemeral mount request during resetc793bcbf5 fix: configure bonds during initial link creation9b3bf6e51 fix(talosctl): prevent duplicate QEMU config server portsfa6cd1ca8 fix(machined): preserve health when services reach running9d5554e69 fix(machined): wait for host namespace commands through reaperfc08533bf chore: update dependenciesc08863cdd feat: provide different heuristics for xfs allocation groupse955d9bd7 feat: update CoreDNS to 1.14.6c3f757f9e feat: update Flannel to 0.28.8fada0d960 fix: provide non-sensitive KubeletStatus resourcec68085286 fix: volume mount race (third attempt) around service restartb185752e5 feat: refactor KubePrism config into multidoc499d4ebf9 test: update Calico in canal reset test5b6ed0068 test: add a test for kata-qemu runtime class1a075383a feat: allow "duplicate" kinds in the config patches06943be9e feat: update Kubernetes to 1.37.0-beta.001f2a1423 fix: preserve trailing rate-limited trigger events46fab8057 test: stabilize AWS readiness and Talos 1.13 QEMU configa26ac746d feat: move static pods and manifests into multi-doc67464cbef fix: update the vulnerability dates and description4920ee06f feat: update Linux to 6.18.39286fa8006 feat: include CA into kube-apiserver serving certificate6d65e223b feat: drop kubernetes flexvolume mounts4935e9452 feat: refactor kubelet's config into KubeletConfig241bd0ff1 feat: custom cfg for system volumes (cri, kubelet, etcd)ea9557816 fix: talosctl buildc2b763608 feat: add UFSHC and some other modules2193b5781 feat: native BGP support via embedded GoBGP2e42c5900 fix: add ca-certificates to talosctl0f55e1f05 feat: refactor Kubernetes configs into KubeNodeConfig6efdc8f71 fix: zero MD superblock via block wipe on destroyf78f5e5a1 fix: vrf sorting77385181a fix: oom podruntime protectionc1184d38e feat: update to runc 1.5.14bff7eb90 feat: support reboot and sync for remote provisionerc791fa8c0 feat: add host-namespace debug profilee370e40b7 feat: implement KubeClusterConfig37c78bfc0 fix(ci): skip ephemeral noexec test on 1.130ab6695e6 feat: update Kubernetes to 1.37.0-alpha.3443ca17e1 test: bump test dependenciesc4242088b fix: enable noexec for EPHEMERAL only for new machinesfc9f72648 feat: bump CoreDNS, Flannel352b1bdeb fix: use symlinks for init aliases883775a9e fix: move sandboxd into a separate cgroup099a2ceda fix: remote provisioner nameff67aaf32 feat: bump go dependencies79c0c5414 feat: add iommufd as a kernel modulef34e93fe2 fix: do proper backoff for NTP Kiss-of-Death responsesa3e644d8d chore: bump tools and pkgsefa88f2f6 fix: flaky tests17a134711 feat: add ignoreRoutes option to DHCPv4 config document2519bf231 fix: make audit restartable54b4bbc03 fix: provide correct handler for Ctrl-Alt-Delete sequence87e126ab7 feat: isolate cri, kubelet and pods in a sandbox namespace3fb8f4e9e fix: avoid image cache mount request churn9753fc27f fix: e2e test flakesf756ff232 feat: kubenetworkconfig supports per-node pod cidr configurationb42c42976 fix(ci): fix more flaky tests5d97eccdf feat: bring in ifb.ko module6769a1d5c fix: terminate log persistence a bit harder98cce792f fix(ci): extensions test057d554d2 test: assert dm transport for device-mapper disks9fd16a21e feat: bump etcd to 3.7.03048eeb23 feat: support booting from MD RAID1 arraye1fc7a4a1 fix: do not block volume lifecycle teardown on failed user volumes147dea148 feat: add --no-reboot flag to upgrade cmd1b23b11fc chore: update pkgs and toolsbfa9fb4e8 fix: flaky testsa1ede48cb test: fix testremovemember etcd integration flakeea90e690d feat: add MD RAID gRPC service and reconcile controllers74486ef6d chore: update depsf59c3ccad feat: implement service account configurationbaff2d3f9 test: fix some test flakiness5450ec303 fix: use a forked version of secure-io/siv-go33fac3f85 test: stabilize netapp trident csi fio runsafdde2a8f chore(ci): add netapp trident csi integration tests21eca156f fix: print link status changes210f4e369 fix: shutdown/reboot via usermode helpersd193f278d test: fix cilium test config patchinge06898069 fix: flaky testsb7398ec00 feat: move kernel module config into multi-doc55bc643af fix: flaky serviceaccount suite testdced7d570 fix: correctly treat guaranteed QoS pods in the OOM handlerf783f6636 feat: implement controlplane only config validationd0291bb0b feat: extract Kubernetes CA config into a separate document97ed958a8 chore: use lefthook globs to skip noop jobsa145c6356 chore: lefthook USERNAME env, post-commit hookf836707ad fix: use UnattendedInstallConfig for extensions67293c809 chore: add lefthook.yml726ea8fc2 chore: switch v1alpha1 validation to use cluster config structd1d848022 feat: add mdadm tooling and udev rules020de3f51 chore: update go dependenciesae84f56a0 chore: remove orphaned unattendedinstall.md416073748 feat: add UnattendedInstall config and controller4e5b4c6a7 feat: extract clusterid and clustersecret to discoveryidentityconfig0a641f268 refactor: simplify device status controller99da7f27f fix: data race in manifest sync54ac1cbd6 fix: provide cooldown period for the QoS trigger788562586 feat: udevd controller and udev rules config document6e34da25c feat: delegate drain ops to go-kubernetes/nodedraine9e027c63 fix: kubelet stuck restarting6f481b420 fix: decode extraArgs list values correctlyc8bdcc252 feat: update runc to 1.5.0eae11ab0c feat: allow user managed etc files47d4bd87e feat: set user-agent for Kubernetes clientba926c6ce chore: update golangcilint config45497bd5b feat: bring systemd 261.18d9ecec93 refactor: improve stability for process_test.go31221e7ee refactor: talosctl running tasks are yellowb268a6b08 feat: refactor CoreDNS config into multi-doc416d5fe4b fix: race in etcd member addc244e4c46 fix: building integration test binary on darwinb15a64b31 chore: bump rekor for GHSA-47q9-m4ww-924mcd8b0fe39 release(v1.14.0-alpha.2): prepare release917820cb3 chore: sync pkgs/toolsb34be14e9 fix: cli.md codeblock generation25abcc6b5 docs: update kubespanconfig to match discoveryserviceconfig742589f50 feat: support multiple discovery service configsfc3f27d79 chore: enrich the SBOM with Go module licenses47d5c3351 fix: handle image cache being disabled1a965aec3 test: disable LongHorn ublk test and add more cores6d03b3f61 fix: align documented image cache partition label6447d854f fix(talosctl): use aio threads on darwinf856d1808 fix: image verification with referrers11a7fbe4c feat: extract kube-apiserver config into multi-doc configs337654d2b test: fix rook-ceph testse33a86825 feat: add AMD XGBE driver to initramfsbd2d6242a fix: revert coredns to 1.14.27c4e644f8 feat: update Linux to 6.18.366e23a5c2f chore: refactor bare opentree_clone into a mount helperdfbd30959 fix(talosctl): prevent appending type 11 smbios values on restart5926dd70d test: support running integration test against remote provisionerf146c6a18 feat: refactor /etc mountsebe364117 chore: bump containerd to 2.3.2bc30c61a1 chore: bump deps (go, k8s, docker)00d739d0a test: skip fstrim default schedule on cloud testsd9c6edf01 fix: bump number of open files for etcd990c5395c chore: update tools and pkgs 2026-06-17325be7cd8 refactor: config generate uses multi-doc sysctlconfigd6930633b fix: clean up and overhaul mount opsa0219404d fix: cgroups cleanup58d8b71c4 fix: stop the log persistence and close all files on shutdown4b32ebc17 refactor: simplify trustd/apid rootfs setupdc98e3553 feat: implement filesystem trim support897bef633 feat: introduce KubeProxyConfig multi-docebde543cf feat: introduce BootID resourcecd178b9f3 fix: ensure consistent manifest apply order19fac6151 feat: remote provisionerb6412e031 fix: drop one more reference to removed 'nodes'be7f7a7db feat: add human-readable size fields to LVM resourcesd4e0ca1ba fix: make LVM reconciliation robust and idempotent0dbc1e529 chore(ci): fix flaky testb687a47ab feat: implement an option to allow discards on encrypted volumes3fc981c57 fix: improve security of scheduler/controller-manager5d4af9f33 fix: gracefully stop node containers before removalc1593d8a3 fix: honor FailurePauseTimeout when pausing before reboot506dc1323 feat: add imager flag to set the SecureBoot key enrollment mode5d4ba702e refactor: generate pod definitions in k8stemplates995bc30d5 feat: drop apply config method reboot18f6cb4d0 fix: increment time epoch on wall-clock jump when time sync is disabled755a8c8eb feat: update etcd to 3.7.0-rc.0a0c76fad1 feat(talosctl): implement cluster logsdb052165c feat(talosctl): support rebooting cluster nodes0a04f463a feat(talosctl): use gateway dns for clustercf3eb1cad chore(talosctl): disable kexec for cluster create on arm64180182b0f fix: correct the link alias conditionac9014f05 fix: introduce pull attempt stall detection for image pullf2286d616 fix: move Flannel netpol patch to the controlplane9986c0b16 feat: bump kernel to 6.18.35e8845fba6 fix: route ProxyURL test via reachable endpoint44acedf30 feat: add declarative LVM logical volume provisioningf6058a11b feat: grab support bundle via client factorycdd719773 feat: add CPUCores resource8e41eb1bd feat: verify go.mod tidiness in generate targetb19e2ea42 feat: add kube-apiserver probesa321a1dcc feat: support proxy-url in talosconfig contextbb2ac7546 feat: parse schematic info out of extension status0c02a5a07 fix: align flannel MTU with kubespan to avoid permanent fragmentation3d5fd822c feat: expose disk firmware and BIOS version30115981c fix: relax LUKS header validation5923199fb refactor: use ClientFactory for the action tracker72c0ced3c refactor: deprecate sysfs and sysctl in machineconfigee74a41fb fix: handle cluster-scoped resources with a namespace correctly9df5a647a feat: allow to disable access time for EPHEMERAL partition9b667dbde chore: fix lint error in test311378386 test: increase resource inmem buffer to stabilize the tests6f85ce3d2 docs: hack/release.toml explains kernelmodulestatus9bb0a5d01 fix(talosctl): add scrolling to dashboard footer node list4c029c2d6 fix: machine configuration schemasc3052e845 feat: move CNI config out of v1alpha1 config1d2f1208c feat: add declarative LVM volume group provisioning85f1d428f chore: refactor tests to use debug apic901d47a5 refactor: talosctl streaming commands and more fixes166854959 fix: mark more resources as sensitive58adf2e00 fix: classify installer and imager exits9549930ff feat: update Flannel to v0.28.527362d18e refactor: replace the callback strategy for most commandscb42d9d9a feat: implement support bundle encryption9ae260b55 feat: enable NRI by defaultd1d5847b0 fix: flaky test0f2331586 feat: support external secureboot and pcr signersb349d919d feat: enforce strict QoS ordering in OOM victim selection76d9b49bd fix(ci): aws nvidia tests3131826cd fix: provide NTS sync with bad initial clock state89e307e58 fix: etcd client leak in the (legacy) Upgrade API476c4d050 fix: recreate dns server and listeners on host DNS runner restart9a283d9b1 feat: bump Go to 1.26.44759dc246 chore: bump dependencies26a25a073 chore(ci): drop homebrew workflowfa8a55192 feat: update etcd to v3.6.1241fcab476 feat: update kernel to 6.18.348ba00612b feat: update dependencies6e2dec1ea refactor: update talosctl commands to stop using WithNodesf9ad63a35 feat: add custom logging convention linter30dbce03f chore: make oci images reproducible38244fd5b feat: add sbom builder5177c50e2 refactor: deprecate loadedkernelmodulec2eef3645 fix: health request server-sided6eff8eff refactor: drop multi-nodes proxying for the dashboard2e547a964 refactor: deprecate multi-node proxyingddcc519e1 fix: add --fail to image-signer curl downloade5b0b1dde fix: normalize log fieldsd8e95c396 fix: drop installer from bundle7aad9ec81 feat: update pkgs, tools, Go dependenciesb50ee396f fix: fix trace fix to also lookup release branches027c93d25 release(v1.14.0-alpha.1): prepare release4eb862d09 feat: add LVMService for VG/LV/PV removalb88f16a52 fiNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →