chore(deps): update module github.com/siderolabs/talos to v1.13.9 - #58
Open
renovate[bot] wants to merge 1 commit into
Open
chore(deps): update module github.com/siderolabs/talos to v1.13.9#58renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Contributor
Author
ℹ️ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
renovate
Bot
force-pushed
the
renovate/github.com-siderolabs-talos-1.x
branch
5 times, most recently
from
May 1, 2026 16:51
fc28c24 to
d8ee470
Compare
renovate
Bot
force-pushed
the
renovate/github.com-siderolabs-talos-1.x
branch
2 times, most recently
from
May 12, 2026 18:52
a6abd8e to
6de0c80
Compare
renovate
Bot
force-pushed
the
renovate/github.com-siderolabs-talos-1.x
branch
from
May 26, 2026 09:36
6de0c80 to
a6f5ba0
Compare
renovate
Bot
force-pushed
the
renovate/github.com-siderolabs-talos-1.x
branch
from
June 9, 2026 19:39
a6f5ba0 to
d2961bf
Compare
renovate
Bot
force-pushed
the
renovate/github.com-siderolabs-talos-1.x
branch
from
June 22, 2026 17:50
d2961bf to
9431b7e
Compare
renovate
Bot
force-pushed
the
renovate/github.com-siderolabs-talos-1.x
branch
from
July 9, 2026 10:45
9431b7e to
17700eb
Compare
renovate
Bot
force-pushed
the
renovate/github.com-siderolabs-talos-1.x
branch
from
July 21, 2026 16:44
17700eb to
88365c6
Compare
renovate
Bot
force-pushed
the
renovate/github.com-siderolabs-talos-1.x
branch
from
August 4, 2026 15:49
88365c6 to
113df79
Compare
renovate
Bot
force-pushed
the
renovate/github.com-siderolabs-talos-1.x
branch
from
August 19, 2026 17:16
113df79 to
ec6e6d7
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.12.6→v1.13.9Release Notes
siderolabs/talos (github.com/siderolabs/talos)
v1.13.9Compare Source
Talos 1.13.9 (2026-08-19)
Welcome to the v1.13.9 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Component Updates
Linux: 6.18.44
containerd: 2.2.7
Kubernetes: 1.36.3
Talos is built with Go 1.26.6.
Contributors
Changes
7 commits
3ebd10arelease(v1.13.9): prepare release9ade215feat: update Kubernetes to 1.36.314343cdtest: save the provision test logsb33e5fcfix: support try mode apply without prior config6a8f295fix: share IPC namespace with the host for extension servicesb525b82fix: size the receive/send buffers for nftables netlink7ac5264feat: update Go to 1.26.6Changes from siderolabs/pkgs
5 commits
f541ca4feat: bump kernel to 6.18.44a4f2c26feat: bump kernel to 6.18.4379a7531feat: update Linux firmware to202608189d76bffeat: update backportable dependenciesaf6c08afeat: update Go to 1.26.6Changes from siderolabs/tools
1 commit
a201d19feat: update Go to 1.26.6Dependency Changes
Previous release can be found at v1.13.8
Images
v1.13.8Compare Source
Talos 1.13.8 (2026-08-04)
Welcome to the v1.13.8 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Component Updates
Linux: 6.18.42
CoreDNS: 1.14.6
Flannel: 0.28.8
Talos is built with Go 1.26.5.
Contributors
Changes
14 commits
3de4932release(v1.13.8): prepare release76de777chore: update dependencies77d5fe2chore: update pkgsa7db9b2fix: verify the public key signed images correctlyd769389fix: use context without cancelation for etcd locks3a2abc0fix: redact resource specs in the merge controllers1531797fix(machined): preserve health when services reach runningfc75754fix: race with PCR extensions and volume unlock2a51fb1feat: update Flannel to 0.28.805471d3feat: update CoreDNS to 1.14.69e0b1cafix: volume mount race (third attempt) around service restartc5cb365fix: ignore insecure-only imager assetsc67b10dtest: update Calico in canal reset test9eca6eafix: preserve trailing rate-limited trigger eventsChanges from siderolabs/pkgs
6 commits
f677246chore: update kernel6c5daf2chore: replace gnu mirror4304e87feat: bump kernel to 6.18.41e66edebfeat: enable PCF8523 RTC support for arm64b2e51fcfeat: bump kernel to 6.18.4033195c5feat: enable CONFIG_NFT_SOCKET in the kernelDependency Changes
Previous release can be found at v1.13.7
Images
v1.13.7Compare Source
Talos 1.13.7 (2026-07-21)
Welcome to the v1.13.7 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Component Updates
Linux: 6.18.39
containerd: 2.2.6
Flannel: 0.28.7
CoreDNS: 1.14.4
Talos is built with Go 1.26.5.
Contributors
Changes
19 commits
b0039b7release(v1.13.7): prepare releasefc6f9b1test: add nginx to the image cache integrationc6c435btest: increase resource inmem buffer to stabilize the tests202dc15fix: add ca-certificates to talosctl3a14c8dfix: vrf sortinga4c1e6efix: oom podruntime protection57b8616feat: bump CoreDNS, Flannel58a78fefix: use symlinks for init aliases428872bfix: do proper backoff for NTP Kiss-of-Death responses1d55e28feat: add iommufd as a kernel module576638dfix: make audit restartable76328f9fix: avoid image cache mount request churn46f9ac6feat: bring in ifb.ko module0d752e7fix: provide correct handler for Ctrl-Alt-Delete sequencefe9d330fix: terminate log persistence a bit harder7c8021afeat: add --no-reboot flag to upgrade cmda155badfix: do not block volume lifecycle teardown on failed user volumesc63f078fix: flaky tests2bf6b74feat: bring in Linux 6.18.39, containerd 2.2.6Changes from siderolabs/pkgs
6 commits
91fe0a0feat: update Linux to 6.18.391018556feat: enable CONFIG_IOMMUFD and CONFIG_VFIO_DEVICE_CDEVd529479chore: bump nvidia to 580.167.08971fd23fix: enable CONFIG_IFB as a moduleacece91feat: update DRBD to 9.3.3b91905cfeat: update containerd to 2.2.6Changes from siderolabs/tools
1 commit
c2844e6feat: update util-linux to 2.42.2Dependency Changes
7e8f69fPrevious release can be found at v1.13.6
Images
v1.13.6Compare Source
Talos 1.13.6 (2026-07-09)
Welcome to the v1.13.6 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Component Updates
Linux: 6.18.38
Talos is built with Go 1.26.5.
Contributors
Changes
15 commits
0431885release(v1.13.6): prepare release9d8e47dchore: update pkgs and tools31552f4fix: shutdown/reboot via usermode helpersbc0c3f3fix: flaky serviceaccount suite test3e75592fix: flaky testsfbe4d90fix: data race in manifest sync6df3a45fix: provide cooldown period for the QoS trigger85f8dd6fix: decode extraArgs list values correctlyc2a56d5fix: kubelet stuck restarting8714408chore: bump rekor for GHSA-47q9-m4ww-924m3e37ef8fix: handle image cache being disabled466bcd8fix: align documented image cache partition labeld3cf09bfix: image verification with referrerse9609b9feat: add AMD XGBE driver to initramfsf18efccchore: update depsChanges from siderolabs/gen
1 commit
c526410fix: skip unknown-key check for types with custom YAML unmarshalerChanges from siderolabs/pkgs
7 commits
d8c80ccchore: update toolchain and tools71874fbfeat: bump kernel to 6.18.38a2406a1feat: bump kernel 6.18.37e410c35feat: update Linux firmware to2026062389b8aafix: patch Linux kernel for tunnel metadata buffer overflow7e4a719feat: add support for AMD XGBE driver1915c58feat: enable NF_TABLES_ARP optionChanges from siderolabs/tools
1 commit
c58afd5chore: bump toolchainDependency Changes
Previous release can be found at v1.13.5
Images
v1.13.5Compare Source
Talos 1.13.5 (2026-06-22)
Welcome to the v1.13.5 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Component Updates
Linux: 6.18.36
containerd: 2.2.5
runc: 1.4.3
Talos is built with Go 1.26.4.
Contributors
Changes
9 commits
51b0d8erelease(v1.13.5): prepare releasec5089c6fix: bump number of open files for etcde0b4d9dfix: stop the log persistence and close all files on shutdown23a080dfix: honor FailurePauseTimeout when pausing before reboot9adc63afix: correct the link alias conditionb902f9dfeat: verify go.mod tidiness in generate target765f0a1fix: relax LUKS header validationd63aba4feat: update pkgs and Kubernetesf0a5842fix: update go.mod and rekresChanges from siderolabs/pkgs
8 commits
6b315f7chore: update zfs to 2.4.3ebf23f3feat: update Linux to 6.18.367eed62dchore: bump containerd to 2.2.5 (cve patches)8b67babchore: update nvidia driver lts to 580.167.088cb61b2feat: bump runcd736aeffeat: bump kernel to 6.18.357ede376fix: avoid page_table_check BUG on time namespace VVAR pagee69debdfeat: update tools and rekresChanges from siderolabs/tools
2 commits
9b78252feat: update ca-certificates to 2026-05-144d13afffeat: bump OpenSSL to 3.6.3Dependency Changes
Previous release can be found at v1.13.4
Images
v1.13.4Compare Source
Talos 1.13.4 (2026-06-09)
Welcome to the v1.13.4 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Component Updates
Linux: 6.18.34
etcd: v2.6.12
Flannel: v0.28.5
Talos is built with Go 1.26.4.
Contributors
Changes
17 commits
707dbd8release(v1.13.4): prepare release27d7a19fix: handle cluster-scoped resources with a namespace correctlyfe74e00chore: update depsf44cafbfix: recreate dns server and listeners on host DNS runner restart5ed296bfix: marshal kube-scheduler config correctly with int types5992015fix: machine configuration schemasb8dfda7fix: mark more resources as sensitiveaad841bfeat: update Flannel to v0.28.57c0900bfix(ci): aws nvidia tests9f5122dfix: flaky testcf62af3fix: etcd client leak in the (legacy) Upgrade APId5c3136feat: enforce strict QoS ordering in OOM victim selectionb5ad39efeat: update etcd to v3.6.12c83dad3fix: health request server-side577cc6ffix: bring in a change to BCM2712_MIP29da68afix: touch rootfs files with SOURCE_DATE_EPOCHb19a03bfix: ignore cgroups with zero rank in OOM handlerChanges from siderolabs/go-kubernetes
1 commit
131a2bdfix: handle cluster-scoped resources with a ns correctlyChanges from siderolabs/pkgs
5 commits
54ec9fcfix: disable PAGE_TABLE_CHECK_ENFORCED in kernel config0d5985afeat: enable USB hiddev for apcupsd support593e34cfeat: bump kernel to 6.18.34366f575fix: enable CONFIG_BCM2712_MIP as built-in in arm64 kernel configb45e84cfeat: bump Go to 1.26.4Changes from siderolabs/tools
2 commits
a06bb31feat: bump go to 1.26.49bb7abefeat: update libcap to 2.78Dependency Changes
Previous release can be found at v1.13.3
Images
v1.13.3Compare Source
Talos 1.13.3 (2026-05-26)
Welcome to the v1.13.3 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Component Updates
Linux: 6.18.33
Kubernetes: 1.36.1
containerd: 2.2.4
Talos is built with Go 1.26.3.
Contributors
Changes
19 commits
befeda7release(v1.13.3): prepare releasef4d4510feat(ci): rotate credentials01b4348fix: guard apply config API calla42c37ffeat(machined): support instance tags on Akamaid62d54cfix: memorymodules resource reportingb673b4bfix: bump Go golang.org/x modules19755adfeat: add bnxt_re module to the rootfs532bc6bfix: relax hostname config validation3bbd3edfix: bump Kubernetes to 1.36.1 in one more place472b9d9feat: update default Kubernetes version to 1.36.16d53ce0chore(ci): fix cloud image upload job name5633c77fix: rework how scheduler config is marshaled52f0560fix: restore some shared (and some lower tier slave) mount propagation9de3c12fix: image verification issue with registry.k8s.io7dc716dfeat: redact more machine config secrets and audit redactorsd5448c6chore(ci): try fixing homebrew actionef9f0bfdocs: drop controlplane endpoint examples7ee3e78feat: update Linux to 6.18.33e99744bfix: update containerd to 2.2.4Changes from siderolabs/go-smbios
1 commit
063f5dcchore: rekres + new testdataChanges from siderolabs/pkgs
12 commits
8c18616feat: pre-generate drbd patches using spatch out of tree82e70a0feat: update Linux to 6.18.33993d4a6feat: enable PPP and INFINIBAND_BNXT_RE12d5337feat: enable more options for CRI-U checkpoint/restorec2e43aafeat: preserve System.map on kernel builds230b4bcchore: update deps847a37efeat: bump kernel 6.18.32d7ae843feat: update Linux to 6.18.31a26d3c0feat: update ZFS & NVIDIA LTS94d28c5feat: update Linux to 6.18.30b3dd525fix: macb silent TX stall on BCM2712/RP1 (v2 patches from netdev)8bdd5e0feat: update containerd to 2.2.4Dependency Changes
Previous release can be found at v1.13.2
Images
v1.13.2Compare Source
Talos 1.13.2 (2026-05-12)
Welcome to the v1.13.2 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Component Updates
Etcd: 3.6.11
Linux: 6.18.29
Talos is built with Go 1.26.3.
Contributors
Changes
1 commit
c5d7c65release(v1.13.2): prepare releaseDependency Changes
Previous release can be found at v1.13.1
Images
v1.13.1Compare Source
v1.13.0Compare Source
Welcome to the v1.14.0-beta.1 release of Talos!
This is a pre-release of Talos
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
DNS over TLS (DoT) and DNS over HTTPS (DoH) Support
Talos now supports DNS over TLS (DoT) and DNS over HTTPS (DoH) for secure DNS resolution.
These features allow Talos to encrypt DNS queries and responses, enhancing privacy and security for DNS traffic.
The DNS protocol can be configured on a per-name server basis in the
ResolverConfigdocument, allowing for flexible configuration of DNS resolution.noexec on EPHEMERAL (/var)
Talos 1.14 clusters now default the EPHEMERAL volume (
/var) tonoexecin addition to the existingnosuidandnodevmount options through generated machine configuration.
Existing machines are not affected on upgrades.
Note: Workloads that execute binaries placed under
/varcan break on new machines.Longhorn v1 and vCluster are known to be affected.
For example, Longhorn v1's
instance-managerexecutes engine binaries that theengine-imageDaemonSet places under/var/lib/longhorn/engine-binaries/, which now fails withpermission denied.Affected users can opt out via a
VolumeConfigdocument:Longhorn v2 (SPDK data engine) runs the data plane inside the instance manager process and is not affected.
Apply Configuration Modes
The '--mode=reboot' option has been removed from the
talosctl apply-configcommand; by default, configuration is applied without a reboot.Most configuration changes don't require a reboot; the documentation lists the changes that do.
Native BGP
Talos now supports running native BGP routing instances on the host via embedded GoBGP servers, configured with
BGPInstanceConfigdocuments.This removes the need to ship FRR as a system extension for the common fabric-facing use case.
List of changes:
BGPInstanceConfigdocuments to configure local ASN, router-id, optional Linux VRF, advertised interfaces, neighbors, and per-route preferred source (routeSource).installRoutes: falseto retain learned routes in the BGP RIB without installing them into the Linux routing table.importRoutesprefix selectors. Imports are one-way, preserve path attributes, and do not recursively import locally originated or previously imported paths.BGPPeerStatusresources (talosctl get bgppeerstatus).RouteSpec/RouteStatusnow carry a multipath next-hop list to support ECMP and cross-family (RFC 8950) next-hops.Btrfs Support
Talos now supports mounting and provisioning
btrfsfilesystem for user volumes and existing volumes.Support for
btrfsis enabled by installingbtrfssystem extension.CRI Base Runtime Specification Configuration
Talos now supports overriding the default OCI runtime specification for CRI containers with a
CRIBaseRuntimeSpecConfigdocument:The
.machine.baseRuntimeSpecOverridesfield is deprecated and remains supported during the deprecationperiod. It is mutually exclusive with
CRIBaseRuntimeSpecConfig; configurations containing both are rejected.Applying, updating, or removing either source regenerates the base runtime specification and restarts CRI
automatically. A machine reboot is no longer required.
CRI Customization Configuration
Talos now supports customizing the CRI containerd configuration with named
CRICustomizationConfigdocuments. Each document contains a TOML fragment; fragments are merged in lexicographical order by name.
Applying, updating, or removing these documents updates the generated CRI configuration and restarts CRI
automatically.
The legacy
/etc/cri/conf.d/20-customization.partmachine-file configuration remains supported during thedeprecation period and is exposed under the reserved name
customization. ACRICustomizationConfigdocumentcannot use that name.
NOTE: a machine reboot is no longer required to apply changes to CRI configuration.
Containerd NRI
Talos no longer disables NRI (Node Resource Interface) for the CRI containerd instance by default, so NRI is available
to use without any machine config patches.
To bring back the old behavior of NRI disabled by default, add the following machine configuration document:
Default Installer Image
The default installer image has been updated to use the Image Factory.
The
ghcr.io/siderolabs/installerimage is no longer published with releases; use the Image Factory installer image instead.DHCP
DHCPv4 search domains are now applied to the resolver configuration.
DHCPv4 configuration now supports
ignoreRoutesoption to ignore routes provided by DHCPv4 servers.Cluster Discovery
Talos introduces support for configuring multiple discovery service endpoints.
Talos introduces new document for configuring the cluster discovery identity.
List of changes:
.cluster.discoveryin the v1alpha1 config; use theDiscoveryServiceConfigdocument for discovery service configuration. The v1alpha1 config andDiscoveryServiceConfigare mutually exclusive..cluster.secretandcluster.idin the v1alpha1 config; use theDiscoveryIdentityConfigdocument for discovery identity configuration. The v1alpha1 config andDiscoveryIdentityConfigare mutually exclusive.base64.URLEncodingtobase64.StdEncoding. This aligns the encoding with the rest of Talos.Encryption Discards
Volume encryption now supports an
allowDiscardsoption (disabled by default) which passes TRIM/discard requeststhrough to the underlying device when the encrypted volume is opened.
This only enables passing discards through to the underlying device; Talos does not perform any fstrim/discard operation by itself.
etcd
Talos is now compatible with etcd v3.6.x only (the default etcd version was 3.6.x since Talos v1.11).
The default version is 3.7.0+ now.
etcd now serves its HTTP-only endpoints (
/metrics,/health, the gRPC-gateway JSON API) on a dedicatedlistener on port
2383, while the client port2379serves gRPC only. This keeps gRPC off Go'snet/httpHTTP/2 server, avoiding watch-stream starvation under TLS (see etcd-io/etcd#15402, golang/go#58804,
etcd-io/etcd#21605).
Upgrade note: etcd metrics and the HTTP health endpoint are no longer reachable on
2379; scrape them onport
2383instead (same client mTLS as before). etcd gRPC clients and the Talos health check are unaffected.Firewall might need to be adjusted to block the port
2383if previously2379was blocked.If
--listen-metrics-urlswas customized, the metrics should not move.EtcFileConfig
Talos now supports managing user-owned files under
/etcwith the newEtcFileConfigmulti-documentconfiguration kind. The document
nameis the path relative to/etc, and each document owns the completefile contents and mode.
This can be used to configure files such as
/etc/nfsmount.confor/etc/multipath.conf. Talos-managedpaths, including
resolv.conf,hosts,machine-id, CRI and Kubernetes configuration, trust bundles, andidentity files, are rejected to prevent overriding files owned by Talos.
Filesystem Trim
Talos can now periodically trim (the equivalent of the
fstrimcommand) mounted filesystems which support trimming,discarding unused blocks. This is useful for SSDs and thin-provisioned storage.
Trimming is opt-in via a new
FilesystemTrimConfigdocument which sets the global trim interval:The default machine configuration for Talos 1.14+ includes a
FilesystemTrimConfigdocument with a default trim interval of one week,so trimming is enabled by default for eligible filesystems. For cluster which were upgraded from older versions, the
FilesystemTrimConfigdocument will be missing,so trimming will be disabled by default until the document is added.
When the document is present, Talos builds a stable schedule (hashed by node ID and volume ID, so trims are spread out
across volumes and across nodes in a cluster) and trims eligible volumes (ready disk/partition volumes with a
trim-capable filesystem; for encrypted volumes only when
allowDiscardsis set).The trim interval can be overridden or disabled per-volume via a
trimblock on the volume documents(
VolumeConfig,UserVolumeConfig,ExistingVolumeConfig,ExternalVolumeConfig):Flannel CNI
Talos now configures Flannel with the
EnableNFTablesoption enabled, which uses nftables native backend instead ofiptables-nftcompatibility layer.FlexVolume Host Path Removed
Talos no longer provisions the deprecated FlexVolume executable host path at
/usr/libexec/kubernetes. FlexVolume has been deprecated since Kubernetes 1.23.Modern CSI plugin paths under
/var/lib/kubeletare unaffected.Host DNS Configuration
HostDNS configuration was moved from the v1alpha1 config
.machine.features.hostDNSfield to the newhostDNSin theResolverConfigdocument.HTTP Probe Support
Talos now supports HTTP network probes, allowing for monitoring of HTTP endpoints.
HTTP responses with status 200-399 are considered successful, while connection and transport errors are treated as failures.
Image Cache Configuration
Talos now supports a new
ImageCacheConfigdocument for configuring the Image Cache feature, replacing the oldmachine.features.imageCachefield in the v1alpha1 config.Old configuration is still supported for backwards compatibility.
Kernel Multi-document Configuration
Talos introduces new multi-document configuration for kernel parameters (sysctl and sysfs settings), replacing the old v1alpha1 config fields.
The old configuration is still supported for backwards compatibility, but new deployments should use the new documents.
If both old and new configuration sources are used, the new multi-document configuration takes precedence over the old v1alpha1 config on conflicting fields.
List of changes:
.machine.sysctlsin the v1alpha1 config; use theSysctlConfigdocument for kernel sysctl configuration..machine.sysfsin the v1alpha1 config; use theSysfsConfigdocument for sysfs configuration..machine.kernelin the v1alpha1 config; use theKernelModuleConfigdocument for kernel module configuration.Kernel Module Status
Talos now reports the status of both dynamically loaded, and built-in kernel modules.
The
LoadedKernelModuleresource has been deprecated and superseded by the newKernelModuleStatusresource.In-tree Volume Plugins Deprecated
Because the kubelet now runs inside the sandbox namespace (see the workload isolation note), the in-tree
Kubernetes volume plugins that require the kubelet to reach host-level daemons no longer work. In particular
the in-tree
iscsivolume plugin, which drives the kubelet'siscsiadmwrapper to talk to the hostiscsid,can no longer locate it across the sandbox PID namespace boundary.
Use CSI drivers instead — a CSI node plugin performs the attach/mount itself in its own privileged pod and is
unaffected by the sandbox. For iSCSI,
kubernetes-csi/csi-driver-iscsi(ordemocratic-csi) consumes atarget the same way. All in-tree (non-CSI) volume plugins are deprecated for the kubelet and support for them
may be removed in a later release.
Kubernetes Multi-document Configuration
Talos introduces new multi-document Kubernetes configuration, which allows for more flexible and modular configuration of Kubernetes components.
Talos still supports the old v1alpha1 config for backwards compatibility, but new features and fields will only be available in the new multi-document format.
The
kube-proxyis now using configuration to manage its settings instead of command line arguments (with newKubeProxyConfigdocument).List of changes:
.cluster.secretboxEncryptionSecretin the v1alpha1 config; use theKubeEtcdEncryptionConfigdocument for full etcd encryption configuration..cluster.apiServerin the v1alpha1 config; use theKubeAPIServerConfig,KubeAdmissionControlConfig,KubeAuditPolicyConfig,KubeAuthenticationConfigandKubeAuthorizerConfigdocuments for kube-apiserver configuration..cluster.ca,.cluster.acceptedCAsand.cluster.aggregatorCAin the v1alpha1 config; use theKubeAPIServerCAConfig,KubeAggregatorCAConfigdocuments..cluster.controllerManagerin the v1alpha1 config; use the `KubeControlleConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.