NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #305 by repository stars
Last release today
01 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Some releases are documented
notes for 17 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
3045 releases · first in 2018
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Deprecated .machine.sysctls in the v1alpha1 config; use the SysctlConfig document for kernel sysctl configuration.
Welcome to the v1.14.0-alpha.2 release of Talos!
This is a pre-release of Talos
Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues.
Talos now supports DNS over TLS (DoT) and DNS over HTTPS (DoH) for secure DNS resolution.
These features allow Talos to encrypt DNS queries and responses, enhancing privacy and security for DNS traffic.
The DNS protocol can be configured on a per-name server basis in the ResolverConfig document, allowing for flexible configuration of DNS resolution.
The EPHEMERAL volume (/var) is now mounted with noexec in addition to the existing nosuid and nodev,
blocking binary execution from /var.
Workloads that exec binaries placed under /var will break.
For example, Longhorn v1's instance-manager exec's engine binaries the engine-image DaemonSet drops under /var/lib/longhorn/engine-binaries/,
which now fails with permission denied. Affected users can opt out via a VolumeConfig document:
apiVersion: v1alpha1
kind: VolumeConfig
name: EPHEMERAL
mount:
secure: false
NOTE: Setting
secure: falsewill also disablenosuidandnodev, which may have security implications. Use with caution.
Upgrade note: apply this VolumeConfig patch before upgrading, otherwise affected workloads will fail after the next reboot. Longhorn v2 (SPDK data engine) runs the data plane inside the instance manager process and is not affected.
The '--mode=reboot' option has been removed from the talosctl apply-config command; by default, configuration is applied without a reboot.
Most configuration changes don't require a reboot; the documentation lists the changes that do.
Talos now supports mounting and provisioning btrfs filesystem for user volumes and existing volumes.
Support for btrfs is enabled by installing btrfs system extension.
Talos no longer disables NRI (Node Resource Interface) for the CRI containerd instance by default, so NRI is available to use without any machine config patches.
To bring back the old behavior of NRI disabled by default, use the following machine config patch:
machine:
files:
- content: |
[plugins]
[plugins."io.containerd.nri.v1.nri"]
disable = true
path: /etc/cri/conf.d/20-customization.part
op: create
The default installer image has been updated to use the Image Factory.
The ghcr.io/siderolabs/installer image is no longer published with releases; use the Image Factory installer image instead.
DHCPv4 search domains are now applied to the resolver configuration.
Volume encryption now supports an allowDiscards option (disabled by default) which passes TRIM/discard requests
through to the underlying device when the encrypted volume is opened.
This only enables passing discards through to the underlying device; Talos does not perform any fstrim/discard operation by itself.
Talos is now compatible with etcd v3.6.x only (the default etcd version was 3.6.x since Talos v1.11). The default version is 3.7.0+ now.
etcd now serves its HTTP-only endpoints (/metrics, /health, the gRPC-gateway JSON API) on a dedicated
listener on port 2383, while the client port 2379 serves gRPC only. This keeps gRPC off Go's net/http
HTTP/2 server, avoiding watch-stream starvation under TLS (see etcd-io/etcd#15402, golang/go#58804,
etcd-io/etcd#21605).
Upgrade note: etcd metrics and the HTTP health endpoint are no longer reachable on 2379; scrape them on
port 2383 instead (same client mTLS as before). etcd gRPC clients and the Talos health check are unaffected.
Firewall might need to be adjusted to block the port 2383 if previously 2379 was blocked.
If --listen-metrics-urls was customized, the metrics should not move.
Talos can now periodically trim (the equivalent of the fstrim command) mounted filesystems which support trimming,
discarding unused blocks. This is useful for SSDs and thin-provisioned storage.
Trimming is opt-in via a new FilesystemTrimConfig document which sets the global trim interval:
apiVersion: v1alpha1
kind: FilesystemTrimConfig
interval: 168h0m0s # one week
The default machine configuration for Talos 1.14+ includes a FilesystemTrimConfig document with a default trim interval of one week,
so trimming is enabled by default for eligible filesystems. For cluster which were upgraded from older versions, the FilesystemTrimConfig document will be missing,
so trimming will be disabled by default until the document is added.
When the document is present, Talos builds a stable schedule (hashed by node ID and volume ID, so trims are spread out
across volumes and across nodes in a cluster) and trims eligible volumes (ready disk/partition volumes with a
trim-capable filesystem; for encrypted volumes only when allowDiscards is set).
The trim interval can be overridden or disabled per-volume via a trim block on the volume documents
(VolumeConfig, UserVolumeConfig, ExistingVolumeConfig, ExternalVolumeConfig):
trim:
enabled: true
interval: 24h0m0s
Talos now configures Flannel with the EnableNFTables option enabled, which uses nftables native backend instead of iptables-nft compatibility layer.
HostDNS configuration was moved from the v1alpha1 config .machine.features.hostDNS field to the new hostDNS in the ResolverConfig document.
Talos now supports HTTP network probes, allowing for monitoring of HTTP endpoints. HTTP responses with status 200-399 are considered successful, while connection and transport errors are treated as failures.
Talos now supports a new ImageCacheConfig document for configuring the Image Cache feature, replacing the old machine.features.imageCache field in the v1alpha1 config.
Old configuration is still supported for backwards compatibility.
Talos introduces new multi-document configuration for kernel parameters (sysctl and sysfs settings), replacing the old v1alpha1 config fields. The old configuration is still supported for backwards compatibility, but new deployments should use the new documents.
If both old and new configuration sources are used, the new multi-document configuration takes precedence over the old v1alpha1 config on conflicting fields.
List of changes:
.machine.sysctls in the v1alpha1 config; use the SysctlConfig document for kernel sysctl configuration..machine.sysfs in the v1alpha1 config; use the SysfsConfig document for sysfs configuration.Talos now reports the status of both dynamically loaded, and built-in kernel modules.
The LoadedKernelModule resource has been deprecated and superseded by the new KernelModuleStatus resource.
Talos introduces new multi-document Kubernetes configuration, which allows for more flexible and modular configuration of Kubernetes components.
Talos still supports the old v1alpha1 config for backwards compatibility, but new features and fields will only be available in the new multi-document format.
Talos introduces support for configuring multiple discovery service endpoints.
The kube-proxy is now using configuration to manage its settings instead of command line arguments (with new KubeProxyConfig document).
List of changes:
.cluster.secretboxEncryptionSecret in the v1alpha1 config; use the KubeEtcdEncryptionConfig document for full etcd encryption configuration..cluster.apiServer in the v1alpha1 config; use the KubeAPIServerConfig, KubeAdmissionControlConfig, KubeAuditPolicyConfig, KubeAuthenticationConfig and KubeAuthorizerConfig documents for kube-apiserver configuration..cluster.controllerManager in the v1alpha1 config; use the KubeControllerManagerConfig document for kube-controller-manager configuration..cluster.scheduler in the v1alpha1 config; use the KubeSchedulerConfig document for kube-scheduler configuration..cluster.proxy in the v1alpha1 config; use the KubeProxyConfig document for kube-proxy configuration..cluster.network in the v1alpha1 config; use the KubeNetworkConfig document for Kubernetes network configuration; Flannel can be configured using the KubeFlannelCNIConfig document..cluster.discovery in the v1alpha1 config; use the DiscoveryServiceConfig document for discovery service configuration. The v1alpha1 config and DiscoveryServiceConfig are mutually exclusive.Logical volumes can now be declared with a new LVMLogicalVolumeConfig multi-doc config kind. Each document
names a logical volume, its parent volumeGroup, a type (linear, raid0, raid1 or raid10) and a
maxSize (absolute, e.g. 50GiB, or a percentage of the volume group, e.g. 80%). RAID layouts accept
optional mirrors (raid1/raid10, default 1) and stripes (raid0/raid10, default: all available physical
volumes) fields. Once the volume group is assembled the logical volume is created via lvcreate.
Raising maxSize grows an existing logical volume via lvextend; percentage-sized volumes also grow when
their volume group is extended. Shrinking is never performed (it risks data loss) - a request to reduce the
size surfaces an LVMValidationError instead. Removal stays an explicit operation via the LVMService LV
remove RPC (talosctl wipe lv).
Talos now provides detailed LVM status information, allowing for better monitoring and management of LVM volumes.
New resources LVMPhysicalVolumeStatus, LVMVolumeGroupStatus, and LVMLogicalVolumeStatus expose PV, VG, and LV details.
DiscoveredVolume resources for logical volumes are listed by their kernel name (e.g. dm-0). To resolve the <vg>/<lv> for a given device, use the Disks or BlockSymlinks resources, which carry the udev-managed symlinks (e.g. /dev/disk/by-id/dm-name-<vg>-<lv>).
Talos can now create and grow LVM Volume Groups declaratively through a new LVMVolumeGroupConfig multi-doc
config kind. Each document names a Volume Group and a CEL volumeSelector over the disk inventory; matched
disks are initialised as Physical Volumes (pvcreate) and aggregated into the requested VG (vgcreate).
Newly matched disks added to an existing VG are attached via vgextend.
Reconciliation is strictly additive and safe-by-default.
Talos now provides the ability to securely wipe LVM metadata from logical volumes, volume groups, and physical volumes. This feature allows for selective wiping of logical volumes, volume groups, and physical volumes.
With talosctl wipe lv/vg/pv <name>, users can wipe LVM metadata from a specific logical volume, volume group, or physical volume.
Talos now supports Network Time Security (NTS) for secure time synchronization. This feature enhances the security of NTP by providing cryptographic authentication of time sources.
NTS is enabled by default (without any configuration sources) for the default time.cloudflare.com time server
NTS can be enabled for custom time servers via the new useNTS field in the TimeServerConfig document.
Talos now sets net.ipv4.conf.all.send_redirects=0 and net.ipv4.conf.default.send_redirects=0 by default,
preventing the node from emitting ICMP redirect messages. This aligns with CIS Benchmark recommendations and
does not affect normal Kubernetes pod or service traffic. Nodes that deliberately act as L3 gateways relying
on ICMP redirects can override this via machine.sysctls.
The talosctl support command now encrypts support bundles using the age encryption tool, enhancing the security of support data.
The default set of recipients includes the 'siderolabs' GitHub organization members, but it can be overridden with custom recipients.
Talos now runs etcd and kube-apiserver with a minimum TLS version of 1.3, improving security by leveraging the latest TLS features and cipher suites. Custom settings for cipher suites have been removed, as they are ignored when TLS 1.3 is used, which simplifies configuration and ensures the use of modern, secure defaults.
Linux: 6.18.36 Kubernetes: 1.36.2 containerd: 2.3.2 etcd: 3.7.0-rc.0-0 Flannel: v0.28.5 runc: 1.5.0-rc.3 CoreDNS: 1.14.2
Talos is built with Go 1.26.4.
<details><summary>331 commits</summary> <p>
917820cb3 chore: sync pkgs/toolsb34be14e9 fix: cli.md codeblock generation25abcc6b5 docs: update kubespanconfig to match discoveryserviceconfig742589f50 feat: support multiple discovery service configsfc3f27d79 chore: enrich the SBOM with Go module licenses47d5c3351 fix: handle image cache being disabled1a965aec3 test: disable LongHorn ublk test and add more cores6d03b3f61 fix: align documented image cache partition label6447d854f fix(talosctl): use aio threads on darwinf856d1808 fix: image verification with referrers11a7fbe4c feat: extract kube-apiserver config into multi-doc configs337654d2b test: fix rook-ceph testse33a86825 feat: add AMD XGBE driver to initramfsbd2d6242a fix: revert coredns to 1.14.27c4e644f8 feat: update Linux to 6.18.366e23a5c2f chore: refactor bare opentree_clone into a mount helperdfbd30959 fix(talosctl): prevent appending type 11 smbios values on restart5926dd70d test: support running integration test against remote provisionerf146c6a18 feat: refactor /etc mountsebe364117 chore: bump containerd to 2.3.2bc30c61a1 chore: bump deps (go, k8s, docker)00d739d0a test: skip fstrim default schedule on cloud testsd9c6edf01 fix: bump number of open files for etcd990c5395c chore: update tools and pkgs 2026-06-17325be7cd8 refactor: config generate uses multi-doc sysctlconfigd6930633b fix: clean up and overhaul mount opsa0219404d fix: cgroups cleanup58d8b71c4 fix: stop the log persistence and close all files on shutdown4b32ebc17 refactor: simplify trustd/apid rootfs setupdc98e3553 feat: implement filesystem trim support897bef633 feat: introduce KubeProxyConfig multi-docebde543cf feat: introduce BootID resourcecd178b9f3 fix: ensure consistent manifest apply order19fac6151 feat: remote provisionerb6412e031 fix: drop one more reference to removed 'nodes'be7f7a7db feat: add human-readable size fields to LVM resourcesd4e0ca1ba fix: make LVM reconciliation robust and idempotent0dbc1e529 chore(ci): fix flaky testb687a47ab feat: implement an option to allow discards on encrypted volumes3fc981c57 fix: improve security of scheduler/controller-manager5d4af9f33 fix: gracefully stop node containers before removalc1593d8a3 fix: honor FailurePauseTimeout when pausing before reboot506dc1323 feat: add imager flag to set the SecureBoot key enrollment mode5d4ba702e refactor: generate pod definitions in k8stemplates995bc30d5 feat: drop apply config method reboot18f6cb4d0 fix: increment time epoch on wall-clock jump when time sync is disabled755a8c8eb feat: update etcd to 3.7.0-rc.0a0c76fad1 feat(talosctl): implement cluster logsdb052165c feat(talosctl): support rebooting cluster nodes0a04f463a feat(talosctl): use gateway dns for clustercf3eb1cad chore(talosctl): disable kexec for cluster create on arm64180182b0f fix: correct the link alias conditionac9014f05 fix: introduce pull attempt stall detection for image pullf2286d616 fix: move Flannel netpol patch to the controlplane9986c0b16 feat: bump kernel to 6.18.35e8845fba6 fix: route ProxyURL test via reachable endpoint44acedf30 feat: add declarative LVM logical volume provisioningf6058a11b feat: grab support bundle via client factorycdd719773 feat: add CPUCores resource8e41eb1bd feat: verify go.mod tidiness in generate targetb19e2ea42 feat: add kube-apiserver probesa321a1dcc feat: support proxy-url in talosconfig contextbb2ac7546 feat: parse schematic info out of extension status0c02a5a07 fix: align flannel MTU with kubespan to avoid permanent fragmentation3d5fd822c feat: expose disk firmware and BIOS version30115981c fix: relax LUKS header validation5923199fb refactor: use ClientFactory for the action tracker72c0ced3c refactor: deprecate sysfs and sysctl in machineconfigee74a41fb fix: handle cluster-scoped resources with a namespace correctly9df5a647a feat: allow to disable access time for EPHEMERAL partition9b667dbde chore: fix lint error in test311378386 test: increase resource inmem buffer to stabilize the tests6f85ce3d2 docs: hack/release.toml explains kernelmodulestatus9bb0a5d01 fix(talosctl): add scrolling to dashboard footer node list4c029c2d6 fix: machine configuration schemasc3052e845 feat: move CNI config out of v1alpha1 config1d2f1208c feat: add declarative LVM volume group provisioning85f1d428f chore: refactor tests to use debug apic901d47a5 refactor: talosctl streaming commands and more fixes166854959 fix: mark more resources as sensitive58adf2e00 fix: classify installer and imager exits9549930ff feat: update Flannel to v0.28.527362d18e refactor: replace the callback strategy for most commandscb42d9d9a feat: implement support bundle encryption9ae260b55 feat: enable NRI by defaultd1d5847b0 fix: flaky test0f2331586 feat: support external secureboot and pcr signersb349d919d feat: enforce strict QoS ordering in OOM victim selection76d9b49bd fix(ci): aws nvidia tests3131826cd fix: provide NTS sync with bad initial clock state89e307e58 fix: etcd client leak in the (legacy) Upgrade API476c4d050 fix: recreate dns server and listeners on host DNS runner restart9a283d9b1 feat: bump Go to 1.26.44759dc246 chore: bump dependencies26a25a073 chore(ci): drop homebrew workflowfa8a55192 feat: update etcd to v3.6.1241fcab476 feat: update kernel to 6.18.348ba00612b feat: update dependencies6e2dec1ea refactor: update talosctl commands to stop using WithNodesf9ad63a35 feat: add custom logging convention linter30dbce03f chore: make oci images reproducible38244fd5b feat: add sbom builder5177c50e2 refactor: deprecate loadedkernelmodulec2eef3645 fix: health request server-sided6eff8eff refactor: drop multi-nodes proxying for the dashboard2e547a964 refactor: deprecate multi-node proxyingddcc519e1 fix: add --fail to image-signer curl downloade5b0b1dde fix: normalize log fieldsd8e95c396 fix: drop installer from bundle7aad9ec81 feat: update pkgs, tools, Go dependenciesb50ee396f fix: fix trace fix to also lookup release branches027c93d25 release(v1.14.0-alpha.1): prepare release4eb862d09 feat: add LVMService for VG/LV/PV removalb88f16a52 fix: use POSIX shell idioms for error propagation5290eb374 fix: suppress ICMP redirects by default7b4aba2e5 fix: marshal kube-scheduler config correctly with int types894be9bf5 fix: touch rootfs files with SOURCE_DATE_EPOCHcde82224e fix: ignore cgroups with zero rank in OOM handlerbc0372411 fix: bring in a change to BCM2712_MIPf572c33f1 chore: fail on makefile errore317d4b47 fix: drop modprobe path and enforce usermode helper89e53f610 fix(machined): make built-in mod state always 'permanent'cfbec9bd5 test: skip UEFI vars wipe if TPM is enabled1e31deda3 fix: create parent directories when extracting tar archives14dc188bd chore: verify go-containerregistry preserves symlinks951922dfb fix: guard apply config API call3e173adf4 feat: move kube-controller-manager config to multi-docb5cda3438 fix: reset QEMU UEFI variable store when disk is wiped4a17ac6ac chore: script for tracking fixes made in upstream toolchain/tools/pkgsd71edeead feat: add LVM status resource definitions4aeba1cde fix: perform backwards-compatible kernel args cleanup9b7b2bf36 feat: implement support for btrfs user volumes03ee8ee3a feat(machined): support instance tags on Akamaid19f9ade0 fix: memorymodules resource reportinga6edcf6f3 chore: move out adv library40e66eac7 fix: bump Go golang.org/x modulese23ca4a0a chore(ci): add upgrade tests for trustedboote3003c0ec chore: bump tpm nonce size to match the algorithm used8fd04da1f feat: add bnxt_re module to the rootfs1cfab00f1 fix: update etcd experimental argsad96fc6ae fix: relax hostname config validationefd735334 chore(ci): add missing labels, move release metadata check to job9ec045059 feat: update containerd to 2.3.142f4144a1 feat: introduce new KubeSchedulerConfigf2b7f39db refactor: move Args type out of config/v1alpha1b959dcb3e fix: bump Kubernetes to 1.36.1 in one more place8ecc77f1a feat: update default Kubernetes version to 1.36.1cbd9c3745 chore: rekres to secure slack workflows6a92fc653 test: update Canal version used in the testsbe12d3d08 feat: support 4k sector size disk imagesa7e8f4c28 chore(ci): fix cloud image upload job name4319399f6 feat: introduce more modular Linux kerneled5df89f6 feat(ci): rotate credentialsa6a984ff7 chore(ci): fix the job conditionsecb7d4588 feat: enable Flannel nftables mode9919ff781 feat: update Linux to 6.18.321a7d136e4 feat: add Azure Secure Boot imager profiledf68e7391 feat: implement kernel module status resourcee98ee99d4 fix: streamline config validation flowd7f0a2fd4 feat: update Linux to 6.18.312b66e25a5 chore: update image signer5aa1795f9 chore: drop e2e step dependenciesd42b3b396 feat: update Linux to 6.18.30c3f6f3507 feat: implement static host resolving via host DNS2f06a68ef refactor: split host DNS handlere99c5be5a feat: implement DNS over HTTP(S)cf6065238 chore: stop publishing installer to ghcr0edabd29c fix: restore some shared (and some lower tier slave) mount propagationf1578dc63 fix: image verification issue with registry.k8s.io46b1f8a24 fix: rework how scheduler config is marshaled820a9fa59 chore: fix typos in comments649a384a9 feat: move more kernel stuff to modules4f3ab2012 chore(ci): try fixing homebrew action600c0ab5d feat(ci): validate that extensions PKGS and TOOLS sync with talos76080416b feat: redact more machine config secrets and audit redactorsaabf63957 docs: drop controlplane endpoint examplesb48a2bef4 test: relax kernel-default routing rule assertiond2208b034 refactor(talosctl): propagate command context throughout, handle interrupts0760b5c28 fix: normalize source name for syft consistencyc49ac0ec2 docs: document release policyec7e6ef9f feat: bump in-toto indirect dependency21858a674 feat: update kernel to 6.18.295a49dc61d feat: migrate Image Cache config to multi-doc574298ec1 fix: handle empty GCP operation errors366b10b79 feat: dockerfile improvements9a1d9d0af feat: bump go 1.26.36eec1c229 feat: support DNS over TLS for upstream resolversdee139aef feat: revert update CoreDNS to 1.14.3087bc4c18 chore: lint packages under tools9e7516fae fix: clarify documentation for image verification pattern41c8e9dc4 feat: bump dependencies2b6c06ef5 feat: update CoreDNS to 1.14.36b6f7978b feat: update containerd to 2.3.0f9c4f90da feat(ci): longhorn v2 ublk tests84d169c62 fix: make dnsd retry listening689974bd5 fix: volume mount permissionsff0f66bdf fix: skip reserved routing rule priorities850e2c754 feat: drop fakeroot, use go helper0c1bd701a feat: add golangci-lint fmt target53bd66956 feat: support conditional start of IPv6 dns serversb31d93e0d feat: auto-enroll SecureBoot keys for disk images849a68006 test: update pkgs to test new extensionsc30a6dfcb fix: preserve DHCP DNS servers5b81b20d3 feat: apply DHCP search domains4e5ff8fa2 fix(ci): zfs test14abe5140 fix: handle gateways which are not on-link routes in dhcp4e1f759af8 chore: fix lint issues automatically664c5f643 chore: update toolsc64df2b61 fix: add missing kernel modules in rootfsf73c24594 feat: run depmod with verification on rootfs build1371596d7 fix: provide proper AWS platform metadata4f11f021d feat: implement etcd encryption config (kube-apiserver)876f83643 feat: add support for HTTP Probes9b776d598 feat: update etcd to 3.6.11631a1bc5e fix: bring in hardened kernela349dac03 fix: stale discovered volume children13ce01879 fix: re-enable kexec on arm6432539d4ac fix: deadlock in the makefs ext4 with populated source0f3e1966a fix: panic in Kubernetes manifest sync3bae01ac1 fix: do not pick up a system disk from a loop devicededb7a96c fix(talosctl): protect k8sNames map writes with mutexcc2be213a fix: drop explicit platform matcher1dffebaf2 fix: mount throws EPERM on virtiofs with SELinux48a481c29 fix: replace Canal manifest with a more recent one6a445406e fix: make lacp active nilable0d1d95c7d fix: bump go-kmsg to fix the timestamp driftbd344fd53 fix: reset the ticker when the KubeSpan is disabled/enabled462015bcd release(v1.14.0-alpha.0): prepare release8a037a56e test: fix flaky tests08c81d838 feat: bump kernel to 6.18.25fe40b6e58 fix(ci): fetch empty pr labels837a9ed07 feat: move host DNS config into ResolverConfig96a8ecd1e feat: default to factory installer imagef19eef78b fix: revert add extraArgs from service-account-issuer6821225b6 fix: revert use append instead of prepend in service-account-issuerb43c3a124 feat: add quirk for talosctl factory downloadsdf0b9a8da refactor: make all controller unit-test follow modern patternsc2948cef2 feat: support auth for Image Factory in cluster create560bcf0ca feat: enforce TLS 1.3 minmum version for Kubernetes components3db14309e fix(talosctl): ensure uncordon runs after reboot/upgrade errorsecf2fa855 feat: update Kubernetes to v1.36.071557eadd fix(ci): skip misc jobs not on pull request026313b7c docs: rename security-insights.yml to lowercase for LFX detectiondc4ffd490 fix(ci): fix jobs not interpolating matrix due to condition25e2f37e2 chore: generate comments for fields in resource proto149592fa5 fix: watch kubelet's kubeconfig and time out for cache sync1f315e6e9 feat: update Linux to 6.18.230198eedc2 feat: add NTS (Network Time Security) support for NTP time sync6830a8b97 fix(ci): matrix jobs cleanups71aeb347f test: fix OOM test flake9b9542cc5 test: fix a flake in the manifest sync test863d882b6 test: add image verification for factory.talos.devbba0b4aee chore(ci): nvidia update helm values3399ff4de fix: propagate route table down to the resourcec684ec60e chore: prepare for Talos 1.14 releaseed9545d0d chore(ci): bump gpu operator version4de3e4393 fix(ci): cron triggered workflows212182e6f chore: bump container registry libraryc028db0b8 fix: do not flip machine stage to rebooting during shutdown6ce62d9e8 fix(ci): workflow runs with workflow_run509cd9733 fix: boot entry detection5e3f30188 feat(ci): rework to schedule daily runs after a cron7fa4d3919 fix: zfs extensions test1ef8e630a test: allow more tests to run in FIPS strict modebdcc9321b fix: reduce memory dashboard usage2d177af82 chore: update Syft to v1.42.4+patches0d8362119 fix: return failed precondition on upgrade when not installedbe58eafab fix: wrong slot of encryption key was logged015081c76 feat: update dependencies9fbb7c95d fix: audit trustd code for security986e97fc7 feat: update Flannel to 0.28.4f3817d1d1 chore: update sign images to support image name suffixe776721f3 feat: update Kubernetes 1.36.0-rc.1f6e7346fa fix: encode extra args fields in resources with new id3c7bb80ba chore: bump tools3ba35c9b9 chore(ci): nvidia try UKI boote3e8f01ca chore: bump tools181584a5f fix: handle boot failurec464c7e88 fix: upgrade API in maintenance mode (legacy)b7512d912 feat: update Kubernetes to 1.36.0-rc.04ba11156f refactor: allow overriding out image name suffixc81aa125c fix: panic in reading PCR values6a3ab87c5 feat(ci): add nvidia arm64 matrix21f459aab fix(talosctl): always use default GRPC dial optionsca208e514 fix: validate hostDNS forwarding requires hostDNS to be enabled9fcb9e05b feat: bump go to 1.26.20bfdf7f70 fix: create correct blackhole routes for IPv452b920032 feat: add client-side Kubernetes node drain to reboot and upgrade commands968ec1e0c refactor: propagate NAME properly, allow to set on buildacc69c346 fix: set the minimum TLS version to 1.30cfa6e302 chore: bump some tool dependencies4229bb9d2 feat: add dis-vulncheck toold697f5538 fix: don't set xattrs while decompressing extensions34fb2cbe5 refactor: remove manual shell completion and replace with cobra completion79fa2e300 feat: allow more nvidia and nvme files from extensions414f78a29 feat: allow glibc ld files in etc1bbba4301 feat: update Flannel to v0.28.255815e0fa fix: handle ISOs with zeroes in volume labels7b6ab0c1c feat: add flag to force fallback to legacy upgrade5e24d5265 feat: add resource view to talosctl dashboard649ab7fe4 fix: add os:meta:writer role to the dashboard10cdfa909 fix: drop talosctl install087ced85f fix: unseal with "slow" TPM11ab0a8c5 fix: drop unused type from ExternalVolume schemae2df0f6ce fix: always grow disks919d8c365 chore: drop debug shell783a35851 fix: add metal-agent mode to runtime capabilities37b2221cc docs: add SECURITY-INSIGHTS.yml for OSPS Baseline QA-04.01bed2bd414 feat: add graceful power off support to QEMU VM launcher3400059cc fix: incorrect route source for on-link routesb3dfbf743 feat: bump musl to 1.2.64227921b3 test: fix the PKI mismatch test flakef2bc2dcc6 feat: update NVIDIA production drivers to 595.58.03aa5946dd3 test: fix cron failures for provision-1 & provision-21dd701efa fix: allow blockdevice wipe in maintenance mode786bf00ab feat: add --platform=all support to image cache-createe1f645e3c feat: validate luks headers for tamperingad72c7300 test: improve maintenance API provision tests70cefab6a test: fix the flakes in tests with trusted rootsaacff17f4 test: bump memory for Flannel netpolicy tests9c3459114 feat: update Linux to 6.18.19, CNI to 1.9.1038cb8735](https://github.coNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →