Skip to content

chore(deps): update module github.com/siderolabs/talos to v1.13.9 - #58

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github.com-siderolabs-talos-1.x
Open

chore(deps): update module github.com/siderolabs/talos to v1.13.9#58
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github.com-siderolabs-talos-1.x

Conversation

@renovate

@renovate renovate Bot commented Apr 24, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
github.com/siderolabs/talos v1.12.6v1.13.9 age adoption passing confidence

Release Notes

siderolabs/talos (github.com/siderolabs/talos)

v1.13.9

Compare Source

Talos 1.13.9 (2026-08-19)

Welcome to the v1.13.9 release of Talos!

Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.

Component Updates

Linux: 6.18.44
containerd: 2.2.7
Kubernetes: 1.36.3

Talos is built with Go 1.26.6.

Contributors
  • Andrey Smirnov
  • Noel Georgi
Changes
7 commits

Changes from siderolabs/pkgs
5 commits

Changes from siderolabs/tools
1 commit

Dependency Changes
  • github.com/siderolabs/pkgs v1.13.0-55-gf677246 -> v1.13.0-60-gf541ca4
  • github.com/siderolabs/talos/pkg/machinery v1.13.8 -> v1.13.9
  • github.com/siderolabs/tools v1.13.0-8-gc2844e6 -> v1.13.0-9-ga201d19
  • golang.org/x/net v0.57.0 -> v0.58.0
  • golang.org/x/text v0.40.0 -> v0.41.0
  • k8s.io/api v0.36.2 -> v0.36.3
  • k8s.io/apiextensions-apiserver v0.36.2 -> v0.36.3
  • k8s.io/apimachinery v0.36.2 -> v0.36.3
  • k8s.io/apiserver v0.36.2 -> v0.36.3
  • k8s.io/client-go v0.36.2 -> v0.36.3
  • k8s.io/component-base v0.36.2 -> v0.36.3
  • k8s.io/cri-api v0.36.2 -> v0.36.3
  • k8s.io/kube-scheduler v0.36.2 -> v0.36.3
  • k8s.io/kubectl v0.36.2 -> v0.36.3
  • k8s.io/kubelet v0.36.2 -> v0.36.3
  • k8s.io/pod-security-admission v0.36.2 -> v0.36.3

Previous release can be found at v1.13.8

Images

ghcr.io/siderolabs/flannel:0.28.8
registry.k8s.io/coredns/coredns:v1.14.6
registry.k8s.io/etcd:v3.6.12
registry.k8s.io/pause:3.10.1
registry.k8s.io/kube-apiserver:v1.36.3
registry.k8s.io/kube-controller-manager:v1.36.3
registry.k8s.io/kube-scheduler:v1.36.3
registry.k8s.io/kube-proxy:v1.36.3
ghcr.io/siderolabs/kubelet:v1.36.3
registry.k8s.io/networking/kube-network-policies:v1.1.0
ghcr.io/siderolabs/installer:v1.13.9
ghcr.io/siderolabs/installer-base:v1.13.9
ghcr.io/siderolabs/imager:v1.13.9
ghcr.io/siderolabs/talos:v1.13.9
ghcr.io/siderolabs/talosctl-all:v1.13.9
ghcr.io/siderolabs/overlays:v1.13.9
ghcr.io/siderolabs/extensions:v1.13.9

v1.13.8

Compare Source

Talos 1.13.8 (2026-08-04)

Welcome to the v1.13.8 release of Talos!

Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.

Component Updates

Linux: 6.18.42
CoreDNS: 1.14.6
Flannel: 0.28.8

Talos is built with Go 1.26.5.

Contributors
  • Andrey Smirnov
  • Mateusz Urbanek
  • Noel Georgi
  • ctr49
  • imusmanmalik
  • kastakhov
Changes
14 commits

Changes from siderolabs/pkgs
6 commits

Dependency Changes
  • github.com/google/cel-go v0.28.0 -> v0.29.0
  • github.com/gopacket/gopacket v1.5.0 -> v1.6.1
  • github.com/klauspost/compress v1.18.6 -> v1.18.7
  • github.com/siderolabs/pkgs v1.13.0-49-g91fe0a0 -> v1.13.0-55-gf677246
  • github.com/siderolabs/talos/pkg/machinery v1.13.7 -> v1.13.8
  • github.com/sigstore/sigstore-go v1.2.0 -> v1.2.1
  • golang.org/x/net v0.55.0 -> v0.57.0
  • golang.org/x/sync v0.20.0 -> v0.22.0
  • golang.org/x/sys v0.45.0 -> v0.47.0
  • golang.org/x/term v0.43.0 -> v0.45.0
  • golang.org/x/text v0.37.0 -> v0.40.0
  • google.golang.org/grpc v1.81.1 -> v1.82.1

Previous release can be found at v1.13.7

Images
ghcr.io/siderolabs/flannel:0.28.8
registry.k8s.io/coredns/coredns:v1.14.6
registry.k8s.io/etcd:v3.6.12
registry.k8s.io/pause:3.10.1
registry.k8s.io/kube-apiserver:v1.36.2
registry.k8s.io/kube-controller-manager:v1.36.2
registry.k8s.io/kube-scheduler:v1.36.2
registry.k8s.io/kube-proxy:v1.36.2
ghcr.io/siderolabs/kubelet:v1.36.2
registry.k8s.io/networking/kube-network-policies:v1.1.0
ghcr.io/siderolabs/installer:v1.13.8
ghcr.io/siderolabs/installer-base:v1.13.8
ghcr.io/siderolabs/imager:v1.13.8
ghcr.io/siderolabs/talos:v1.13.8
ghcr.io/siderolabs/talosctl-all:v1.13.8
ghcr.io/siderolabs/overlays:v1.13.8
ghcr.io/siderolabs/extensions:v1.13.8

v1.13.7

Compare Source

Talos 1.13.7 (2026-07-21)

Welcome to the v1.13.7 release of Talos!

Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.

Component Updates

Linux: 6.18.39
containerd: 2.2.6
Flannel: 0.28.7
CoreDNS: 1.14.4

Talos is built with Go 1.26.5.

Contributors
  • Andrey Smirnov
  • Mateusz Urbanek
  • Noel Georgi
  • Calin
  • Dario Emerson
  • Maja Bojarska
Changes
19 commits

Changes from siderolabs/pkgs
6 commits

Changes from siderolabs/tools
1 commit

Dependency Changes
  • github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azkeys v1.4.0 -> v1.5.0
  • github.com/aws/aws-sdk-go-v2/service/kms v1.51.1 -> v1.52.0
  • github.com/docker/cli v29.4.0 -> v29.4.3
  • github.com/google/go-containerregistry v0.21.5 -> v0.21.6
  • github.com/klauspost/compress v1.18.5 -> v1.18.6
  • github.com/moby/moby/api v1.54.1 -> v1.54.2
  • github.com/moby/moby/client v0.4.0 -> v0.4.1
  • github.com/siderolabs/pkgs v1.13.0-43-gd8c80cc -> v1.13.0-49-g91fe0a0
  • github.com/siderolabs/talos/pkg/machinery v1.13.6 -> v1.13.7
  • github.com/siderolabs/tools v1.13.0-7-gc58afd5 -> v1.13.0-8-gc2844e6
  • github.com/sigstore/sigstore v1.10.6 -> v1.10.8
  • github.com/sigstore/sigstore-go v1.1.4 -> v1.2.0
  • github.com/theupdateframework/go-tuf/v2 v2.4.1 -> 7e8f69f
  • google.golang.org/grpc v1.81.0 -> v1.81.1

Previous release can be found at v1.13.6

Images

ghcr.io/siderolabs/flannel:0.28.7
registry.k8s.io/coredns/coredns:v1.14.4
registry.k8s.io/etcd:v3.6.12
registry.k8s.io/pause:3.10.1
registry.k8s.io/kube-apiserver:v1.36.2
registry.k8s.io/kube-controller-manager:v1.36.2
registry.k8s.io/kube-scheduler:v1.36.2
registry.k8s.io/kube-proxy:v1.36.2
ghcr.io/siderolabs/kubelet:v1.36.2
registry.k8s.io/networking/kube-network-policies:v1.1.0
ghcr.io/siderolabs/installer:v1.13.7
ghcr.io/siderolabs/installer-base:v1.13.7
ghcr.io/siderolabs/imager:v1.13.7
ghcr.io/siderolabs/talos:v1.13.7
ghcr.io/siderolabs/talosctl-all:v1.13.7
ghcr.io/siderolabs/overlays:v1.13.7
ghcr.io/siderolabs/extensions:v1.13.7

v1.13.6

Compare Source

Talos 1.13.6 (2026-07-09)

Welcome to the v1.13.6 release of Talos!

Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.

Component Updates

Linux: 6.18.38

Talos is built with Go 1.26.5.

Contributors
  • Andrey Smirnov
  • Mateusz Urbanek
  • Noel Georgi
  • Maja Bojarska
  • Mark Glants
Changes
15 commits

Changes from siderolabs/gen
1 commit

Changes from siderolabs/pkgs
7 commits

Changes from siderolabs/tools
1 commit

Dependency Changes
  • github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.0 -> v1.21.1
  • github.com/aws/aws-sdk-go-v2 v1.41.4 -> v1.41.7
  • github.com/aws/aws-sdk-go-v2/config v1.32.12 -> v1.32.17
  • github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.20 -> v1.18.23
  • github.com/aws/aws-sdk-go-v2/service/kms v1.50.3 -> v1.51.1
  • github.com/aws/smithy-go v1.24.2 -> v1.25.1
  • github.com/siderolabs/gen v0.8.6 -> v0.8.7
  • github.com/siderolabs/pkgs v1.13.0-36-g6b315f7 -> v1.13.0-43-gd8c80cc
  • github.com/siderolabs/talos/pkg/machinery v1.13.5 -> v1.13.6
  • github.com/siderolabs/tools v1.13.0-6-g9b78252 -> v1.13.0-7-gc58afd5
  • github.com/sigstore/cosign/v3 v3.0.5 -> v3.0.6
  • github.com/sigstore/sigstore v1.10.5 -> v1.10.6
  • go.uber.org/zap v1.27.1 -> v1.28.0

Previous release can be found at v1.13.5

Images

ghcr.io/siderolabs/flannel:v0.28.5
registry.k8s.io/coredns/coredns:v1.14.2
registry.k8s.io/etcd:v3.6.12
registry.k8s.io/pause:3.10.1
registry.k8s.io/kube-apiserver:v1.36.2
registry.k8s.io/kube-controller-manager:v1.36.2
registry.k8s.io/kube-scheduler:v1.36.2
registry.k8s.io/kube-proxy:v1.36.2
ghcr.io/siderolabs/kubelet:v1.36.2
registry.k8s.io/networking/kube-network-policies:v1.0.0
ghcr.io/siderolabs/installer:v1.13.6
ghcr.io/siderolabs/installer-base:v1.13.6
ghcr.io/siderolabs/imager:v1.13.6
ghcr.io/siderolabs/talos:v1.13.6
ghcr.io/siderolabs/talosctl-all:v1.13.6
ghcr.io/siderolabs/overlays:v1.13.6
ghcr.io/siderolabs/extensions:v1.13.6

v1.13.5

Compare Source

Talos 1.13.5 (2026-06-22)

Welcome to the v1.13.5 release of Talos!

Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.

Component Updates

Linux: 6.18.36
containerd: 2.2.5
runc: 1.4.3

Talos is built with Go 1.26.4.

Contributors
  • Andrey Smirnov
  • Maja Bojarska
  • Noel Georgi
  • Mateusz Urbanek
  • Aleksei Sviridkin
Changes
9 commits

Changes from siderolabs/pkgs
8 commits

Changes from siderolabs/tools
2 commits

Dependency Changes
  • github.com/ryanuber/columnize v2.1.2 new
  • github.com/siderolabs/go-blockdevice/v2 v2.0.28 -> v2.0.30
  • github.com/siderolabs/pkgs v1.13.0-28-g54ec9fc -> v1.13.0-36-g6b315f7
  • github.com/siderolabs/talos/pkg/machinery v1.13.4 -> v1.13.5
  • github.com/siderolabs/tools v1.13.0-4-ga06bb31 -> v1.13.0-6-g9b78252
  • k8s.io/api v0.36.1 -> v0.36.2
  • k8s.io/apiextensions-apiserver v0.36.1 -> v0.36.2
  • k8s.io/apimachinery v0.36.1 -> v0.36.2
  • k8s.io/apiserver v0.36.1 -> v0.36.2
  • k8s.io/client-go v0.36.1 -> v0.36.2
  • k8s.io/component-base v0.36.1 -> v0.36.2
  • k8s.io/cri-api v0.36.1 -> v0.36.2
  • k8s.io/kube-scheduler v0.36.1 -> v0.36.2
  • k8s.io/kubectl v0.36.1 -> v0.36.2
  • k8s.io/kubelet v0.36.1 -> v0.36.2
  • k8s.io/pod-security-admission v0.36.1 -> v0.36.2

Previous release can be found at v1.13.4

Images

ghcr.io/siderolabs/flannel:v0.28.5
registry.k8s.io/coredns/coredns:v1.14.2
registry.k8s.io/etcd:v3.6.12
registry.k8s.io/pause:3.10.1
registry.k8s.io/kube-apiserver:v1.36.2
registry.k8s.io/kube-controller-manager:v1.36.2
registry.k8s.io/kube-scheduler:v1.36.2
registry.k8s.io/kube-proxy:v1.36.2
ghcr.io/siderolabs/kubelet:v1.36.2
registry.k8s.io/networking/kube-network-policies:v1.0.0
ghcr.io/siderolabs/installer:v1.13.5
ghcr.io/siderolabs/installer-base:v1.13.5
ghcr.io/siderolabs/imager:v1.13.5
ghcr.io/siderolabs/talos:v1.13.5
ghcr.io/siderolabs/talosctl-all:v1.13.5
ghcr.io/siderolabs/overlays:v1.13.5
ghcr.io/siderolabs/extensions:v1.13.5

v1.13.4

Compare Source

Talos 1.13.4 (2026-06-09)

Welcome to the v1.13.4 release of Talos!

Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.

Component Updates

Linux: 6.18.34
etcd: v2.6.12
Flannel: v0.28.5

Talos is built with Go 1.26.4.

Contributors
  • Andrey Smirnov
  • Noel Georgi
  • Mateusz Urbanek
  • Orzelius
  • Erwan Leboucher
  • Jonny
  • Rokoucha
  • appkins
Changes
17 commits

Changes from siderolabs/go-kubernetes
1 commit

Changes from siderolabs/pkgs
5 commits

Changes from siderolabs/tools
2 commits

Dependency Changes
  • github.com/siderolabs/go-kubernetes v0.2.37 -> v0.2.38
  • github.com/siderolabs/pkgs v1.13.0-23-g8c18616 -> v1.13.0-28-g54ec9fc
  • github.com/siderolabs/talos/pkg/machinery v1.13.3 -> v1.13.4
  • github.com/siderolabs/tools v1.13.0-2-g1fb762a -> v1.13.0-4-ga06bb31
  • go.etcd.io/etcd/api/v3 v3.6.11 -> v3.6.12
  • go.etcd.io/etcd/client/pkg/v3 v3.6.11 -> v3.6.12
  • go.etcd.io/etcd/client/v3 v3.6.11 -> v3.6.12
  • go.etcd.io/etcd/etcdutl/v3 v3.6.11 -> v3.6.12

Previous release can be found at v1.13.3

Images

ghcr.io/siderolabs/flannel:v0.28.5
registry.k8s.io/coredns/coredns:v1.14.2
registry.k8s.io/etcd:v3.6.12
registry.k8s.io/pause:3.10.1
registry.k8s.io/kube-apiserver:v1.36.1
registry.k8s.io/kube-controller-manager:v1.36.1
registry.k8s.io/kube-scheduler:v1.36.1
registry.k8s.io/kube-proxy:v1.36.1
ghcr.io/siderolabs/kubelet:v1.36.1
registry.k8s.io/networking/kube-network-policies:v1.0.0
ghcr.io/siderolabs/installer:v1.13.4
ghcr.io/siderolabs/installer-base:v1.13.4
ghcr.io/siderolabs/imager:v1.13.4
ghcr.io/siderolabs/talos:v1.13.4
ghcr.io/siderolabs/talosctl-all:v1.13.4
ghcr.io/siderolabs/overlays:v1.13.4
ghcr.io/siderolabs/extensions:v1.13.4

v1.13.3

Compare Source

Talos 1.13.3 (2026-05-26)

Welcome to the v1.13.3 release of Talos!

Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.

Component Updates

Linux: 6.18.33
Kubernetes: 1.36.1
containerd: 2.2.4

Talos is built with Go 1.26.3.

Contributors
  • Andrey Smirnov
  • Noel Georgi
  • Lukasz Raczylo
  • Maja Bojarska
  • Mateusz Urbanek
  • Utku Ozdemir
Changes
19 commits

Changes from siderolabs/go-smbios
1 commit

Changes from siderolabs/pkgs
12 commits

Dependency Changes
  • github.com/containerd/containerd/v2 v2.2.2 -> v2.2.4
  • github.com/siderolabs/go-smbios v0.3.3 -> v0.3.4
  • github.com/siderolabs/pkgs v1.13.0-11-g969f61c -> v1.13.0-23-g8c18616
  • github.com/siderolabs/talos/pkg/machinery v1.13.2 -> v1.13.3
  • golang.org/x/net v0.53.0 -> v0.55.0
  • golang.org/x/sys v0.43.0 -> v0.45.0
  • golang.org/x/term v0.42.0 -> v0.43.0
  • golang.org/x/text v0.36.0 -> v0.37.0
  • google.golang.org/grpc v1.79.3 -> v1.81.0
  • k8s.io/api v0.36.0 -> v0.36.1
  • k8s.io/apiextensions-apiserver v0.36.0 -> v0.36.1
  • k8s.io/apimachinery v0.36.0 -> v0.36.1
  • k8s.io/apiserver v0.36.0 -> v0.36.1
  • k8s.io/client-go v0.36.0 -> v0.36.1
  • k8s.io/component-base v0.36.0 -> v0.36.1
  • k8s.io/kube-scheduler v0.36.0 -> v0.36.1
  • k8s.io/kubectl v0.36.0 -> v0.36.1
  • k8s.io/kubelet v0.36.0 -> v0.36.1
  • k8s.io/pod-security-admission v0.36.0 -> v0.36.1

Previous release can be found at v1.13.2

Images

ghcr.io/siderolabs/flannel:v0.28.4
registry.k8s.io/coredns/coredns:v1.14.2
registry.k8s.io/etcd:v3.6.11
registry.k8s.io/pause:3.10.1
registry.k8s.io/kube-apiserver:v1.36.1
registry.k8s.io/kube-controller-manager:v1.36.1
registry.k8s.io/kube-scheduler:v1.36.1
registry.k8s.io/kube-proxy:v1.36.1
ghcr.io/siderolabs/kubelet:v1.36.1
registry.k8s.io/networking/kube-network-policies:v1.0.0
ghcr.io/siderolabs/installer:v1.13.3
ghcr.io/siderolabs/installer-base:v1.13.3
ghcr.io/siderolabs/imager:v1.13.3
ghcr.io/siderolabs/talos:v1.13.3
ghcr.io/siderolabs/talosctl-all:v1.13.3
ghcr.io/siderolabs/overlays:v1.13.3
ghcr.io/siderolabs/extensions:v1.13.3

v1.13.2

Compare Source

Talos 1.13.2 (2026-05-12)

Welcome to the v1.13.2 release of Talos!

Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.

Component Updates

Etcd: 3.6.11
Linux: 6.18.29

Talos is built with Go 1.26.3.

Contributors
  • Noel Georgi
Changes
1 commit

Dependency Changes
  • github.com/siderolabs/talos/pkg/machinery v1.13.1 -> v1.13.2

Previous release can be found at v1.13.1

Images

ghcr.io/siderolabs/flannel:v0.28.4
registry.k8s.io/coredns/coredns:v1.14.2
registry.k8s.io/etcd:v3.6.11
registry.k8s.io/pause:3.10.1
registry.k8s.io/kube-apiserver:v1.36.0
registry.k8s.io/kube-controller-manager:v1.36.0
registry.k8s.io/kube-scheduler:v1.36.0
registry.k8s.io/kube-proxy:v1.36.0
ghcr.io/siderolabs/kubelet:v1.36.0
registry.k8s.io/networking/kube-network-policies:v1.0.0
ghcr.io/siderolabs/installer:v1.13.2
ghcr.io/siderolabs/installer-base:v1.13.2
ghcr.io/siderolabs/imager:v1.13.2
ghcr.io/siderolabs/talos:v1.13.2
ghcr.io/siderolabs/talosctl-all:v1.13.2
ghcr.io/siderolabs/overlays:v1.13.2
ghcr.io/siderolabs/extensions:v1.13.2

v1.13.1

Compare Source

v1.13.0

Compare Source

Welcome to the v1.14.0-beta.1 release of Talos!
This is a pre-release of Talos

Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.

DNS over TLS (DoT) and DNS over HTTPS (DoH) Support

Talos now supports DNS over TLS (DoT) and DNS over HTTPS (DoH) for secure DNS resolution.
These features allow Talos to encrypt DNS queries and responses, enhancing privacy and security for DNS traffic.
The DNS protocol can be configured on a per-name server basis in the ResolverConfig document, allowing for flexible configuration of DNS resolution.

noexec on EPHEMERAL (/var)

Talos 1.14 clusters now default the EPHEMERAL volume (/var) to noexec in addition to the existing nosuid and nodev
mount options through generated machine configuration.

Existing machines are not affected on upgrades.

Note: Workloads that execute binaries placed under /var can break on new machines.
Longhorn v1 and vCluster are known to be affected.
For example, Longhorn v1's instance-manager executes engine binaries that the engine-image DaemonSet places under
/var/lib/longhorn/engine-binaries/, which now fails with permission denied.
Affected users can opt out via a VolumeConfig document:

apiVersion: v1alpha1
kind: VolumeConfig
name: EPHEMERAL
mount:
  secure: false

NOTE: Setting secure: false will also disable nosuid and nodev, which may have security implications. Use with caution.

Longhorn v2 (SPDK data engine) runs the data plane inside the instance manager process and is not affected.

Apply Configuration Modes

The '--mode=reboot' option has been removed from the talosctl apply-config command; by default, configuration is applied without a reboot.
Most configuration changes don't require a reboot; the documentation lists the changes that do.

Native BGP

Talos now supports running native BGP routing instances on the host via embedded GoBGP servers, configured with BGPInstanceConfig documents.
This removes the need to ship FRR as a system extension for the common fabric-facing use case.

List of changes:

  • Added repeatable, named BGPInstanceConfig documents to configure local ASN, router-id, optional Linux VRF, advertised interfaces, neighbors, and per-route preferred source (routeSource).
  • Peer hold-time and BFD behavior are configured inline on each concrete neighbor, which selects either an address or a link.
  • Numbered and unnumbered (IPv6 link-local, RFC 8950 extended next-hop) peering are supported, including IPv4 prefixes learned over an IPv6 link-local next-hop.
  • Neighbor-local ASN overrides and passive sessions are supported. ECMP (multipath) and BFD (fast failure detection) are supported for fabric peering.
  • BFD is currently supported only by the instance in the default routing domain; GoBGP's embedded BFD listener is not VRF-aware.
  • Each instance owns an isolated BGP RIB and, by default, installs learned routes into its default or VRF routing table through the existing route controllers. Set installRoutes: false to retain learned routes in the BGP RIB without installing them into the Linux routing table.
  • Instances can selectively import best neighbor-learned routes from other named instances with importRoutes prefix selectors. Imports are one-way, preserve path attributes, and do not recursively import locally originated or previously imported paths.
  • Peer state is observable via instance-qualified BGPPeerStatus resources (talosctl get bgppeerstatus).
  • RouteSpec/RouteStatus now carry a multipath next-hop list to support ECMP and cross-family (RFC 8950) next-hops.
Btrfs Support

Talos now supports mounting and provisioning btrfs filesystem for user volumes and existing volumes.

Support for btrfs is enabled by installing btrfs system extension.

CRI Base Runtime Specification Configuration

Talos now supports overriding the default OCI runtime specification for CRI containers with a
CRIBaseRuntimeSpecConfig document:

apiVersion: v1alpha1
kind: CRIBaseRuntimeSpecConfig
overrides:
  process:
    rlimits:
      - type: RLIMIT_NOFILE
        hard: 1024
        soft: 1024

The .machine.baseRuntimeSpecOverrides field is deprecated and remains supported during the deprecation
period. It is mutually exclusive with CRIBaseRuntimeSpecConfig; configurations containing both are rejected.

Applying, updating, or removing either source regenerates the base runtime specification and restarts CRI
automatically. A machine reboot is no longer required.

CRI Customization Configuration

Talos now supports customizing the CRI containerd configuration with named CRICustomizationConfig
documents. Each document contains a TOML fragment; fragments are merged in lexicographical order by name.
Applying, updating, or removing these documents updates the generated CRI configuration and restarts CRI
automatically.

The legacy /etc/cri/conf.d/20-customization.part machine-file configuration remains supported during the
deprecation period and is exposed under the reserved name customization. A CRICustomizationConfig document
cannot use that name.

NOTE: a machine reboot is no longer required to apply changes to CRI configuration.

Containerd NRI

Talos no longer disables NRI (Node Resource Interface) for the CRI containerd instance by default, so NRI is available
to use without any machine config patches.

To bring back the old behavior of NRI disabled by default, add the following machine configuration document:

apiVersion: v1alpha1
kind: CRICustomizationConfig
name: disable-nri
content: |
  [plugins]
    [plugins."io.containerd.nri.v1.nri"]
       disable = true
Default Installer Image

The default installer image has been updated to use the Image Factory.
The ghcr.io/siderolabs/installer image is no longer published with releases; use the Image Factory installer image instead.

DHCP

DHCPv4 search domains are now applied to the resolver configuration.

DHCPv4 configuration now supports ignoreRoutes option to ignore routes provided by DHCPv4 servers.

Cluster Discovery

Talos introduces support for configuring multiple discovery service endpoints.
Talos introduces new document for configuring the cluster discovery identity.

List of changes:

  • Deprecated .cluster.discovery in the v1alpha1 config; use the DiscoveryServiceConfig document for discovery service configuration. The v1alpha1 config and DiscoveryServiceConfig are mutually exclusive.
  • Deprecated .cluster.secret and cluster.id in the v1alpha1 config; use the DiscoveryIdentityConfig document for discovery identity configuration. The v1alpha1 config and DiscoveryIdentityConfig are mutually exclusive.
  • Changed cluster ID encoding in the generated secret bundle, from base64.URLEncoding to base64.StdEncoding. This aligns the encoding with the rest of Talos.
Encryption Discards

Volume encryption now supports an allowDiscards option (disabled by default) which passes TRIM/discard requests
through to the underlying device when the encrypted volume is opened.

This only enables passing discards through to the underlying device; Talos does not perform any fstrim/discard operation by itself.

etcd

Talos is now compatible with etcd v3.6.x only (the default etcd version was 3.6.x since Talos v1.11).
The default version is 3.7.0+ now.

etcd now serves its HTTP-only endpoints (/metrics, /health, the gRPC-gateway JSON API) on a dedicated
listener on port 2383, while the client port 2379 serves gRPC only. This keeps gRPC off Go's net/http
HTTP/2 server, avoiding watch-stream starvation under TLS (see etcd-io/etcd#15402, golang/go#58804,
etcd-io/etcd#21605).

Upgrade note: etcd metrics and the HTTP health endpoint are no longer reachable on 2379; scrape them on
port 2383 instead (same client mTLS as before). etcd gRPC clients and the Talos health check are unaffected.

Firewall might need to be adjusted to block the port 2383 if previously 2379 was blocked.

If --listen-metrics-urls was customized, the metrics should not move.

EtcFileConfig

Talos now supports managing user-owned files under /etc with the new EtcFileConfig multi-document
configuration kind. The document name is the path relative to /etc, and each document owns the complete
file contents and mode.

This can be used to configure files such as /etc/nfsmount.conf or /etc/multipath.conf. Talos-managed
paths, including resolv.conf, hosts, machine-id, CRI and Kubernetes configuration, trust bundles, and
identity files, are rejected to prevent overriding files owned by Talos.

Filesystem Trim

Talos can now periodically trim (the equivalent of the fstrim command) mounted filesystems which support trimming,
discarding unused blocks. This is useful for SSDs and thin-provisioned storage.

Trimming is opt-in via a new FilesystemTrimConfig document which sets the global trim interval:

apiVersion: v1alpha1
kind: FilesystemTrimConfig
interval: 168h0m0s # one week

The default machine configuration for Talos 1.14+ includes a FilesystemTrimConfig document with a default trim interval of one week,
so trimming is enabled by default for eligible filesystems. For cluster which were upgraded from older versions, the FilesystemTrimConfig document will be missing,
so trimming will be disabled by default until the document is added.

When the document is present, Talos builds a stable schedule (hashed by node ID and volume ID, so trims are spread out
across volumes and across nodes in a cluster) and trims eligible volumes (ready disk/partition volumes with a
trim-capable filesystem; for encrypted volumes only when allowDiscards is set).

The trim interval can be overridden or disabled per-volume via a trim block on the volume documents
(VolumeConfig, UserVolumeConfig, ExistingVolumeConfig, ExternalVolumeConfig):

trim:
  enabled: true
  interval: 24h0m0s
Flannel CNI

Talos now configures Flannel with the EnableNFTables option enabled, which uses nftables native backend instead of iptables-nft compatibility layer.

FlexVolume Host Path Removed

Talos no longer provisions the deprecated FlexVolume executable host path at
/usr/libexec/kubernetes. FlexVolume has been deprecated since Kubernetes 1.23.
Modern CSI plugin paths under /var/lib/kubelet are unaffected.

Host DNS Configuration

HostDNS configuration was moved from the v1alpha1 config .machine.features.hostDNS field to the new hostDNS in the ResolverConfig document.

HTTP Probe Support

Talos now supports HTTP network probes, allowing for monitoring of HTTP endpoints.
HTTP responses with status 200-399 are considered successful, while connection and transport errors are treated as failures.

Image Cache Configuration

Talos now supports a new ImageCacheConfig document for configuring the Image Cache feature, replacing the old machine.features.imageCache field in the v1alpha1 config.
Old configuration is still supported for backwards compatibility.

Kernel Multi-document Configuration

Talos introduces new multi-document configuration for kernel parameters (sysctl and sysfs settings), replacing the old v1alpha1 config fields.
The old configuration is still supported for backwards compatibility, but new deployments should use the new documents.

If both old and new configuration sources are used, the new multi-document configuration takes precedence over the old v1alpha1 config on conflicting fields.

List of changes:

  • Deprecated .machine.sysctls in the v1alpha1 config; use the SysctlConfig document for kernel sysctl configuration.
  • Deprecated .machine.sysfs in the v1alpha1 config; use the SysfsConfig document for sysfs configuration.
  • Deprecated .machine.kernel in the v1alpha1 config; use the KernelModuleConfig document for kernel module configuration.
Kernel Module Status

Talos now reports the status of both dynamically loaded, and built-in kernel modules.

The LoadedKernelModule resource has been deprecated and superseded by the new KernelModuleStatus resource.

In-tree Volume Plugins Deprecated

Because the kubelet now runs inside the sandbox namespace (see the workload isolation note), the in-tree
Kubernetes volume plugins that require the kubelet to reach host-level daemons no longer work. In particular
the in-tree iscsi volume plugin, which drives the kubelet's iscsiadm wrapper to talk to the host iscsid,
can no longer locate it across the sandbox PID namespace boundary.

Use CSI drivers instead — a CSI node plugin performs the attach/mount itself in its own privileged pod and is
unaffected by the sandbox. For iSCSI, kubernetes-csi/csi-driver-iscsi (or democratic-csi) consumes a
target the same way. All in-tree (non-CSI) volume plugins are deprecated for the kubelet and support for them
may be removed in a later release.

Kubernetes Multi-document Configuration

Talos introduces new multi-document Kubernetes configuration, which allows for more flexible and modular configuration of Kubernetes components.
Talos still supports the old v1alpha1 config for backwards compatibility, but new features and fields will only be available in the new multi-document format.
The kube-proxy is now using configuration to manage its settings instead of command line arguments (with new KubeProxyConfig document).

List of changes:

  • Deprecated .cluster.secretboxEncryptionSecret in the v1alpha1 config; use the KubeEtcdEncryptionConfig document for full etcd encryption configuration.
  • Deprecated .cluster.apiServer in the v1alpha1 config; use the KubeAPIServerConfig, KubeAdmissionControlConfig, KubeAuditPolicyConfig, KubeAuthenticationConfig and KubeAuthorizerConfig documents for kube-apiserver configuration.
  • Deprecated .cluster.ca, .cluster.acceptedCAs and .cluster.aggregatorCA in the v1alpha1 config; use the KubeAPIServerCAConfig, KubeAggregatorCAConfig documents.
  • Deprecated .cluster.controllerManager in the v1alpha1 config; use the `KubeControlle

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate

renovate Bot commented Apr 24, 2026

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 49 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.26.0 -> 1.26.6
github.com/siderolabs/go-kubernetes v0.2.36 -> v0.2.38
github.com/siderolabs/talos/pkg/machinery v1.13.0-beta.0 -> v1.13.9
golang.org/x/text v0.35.0 -> v0.41.0
k8s.io/api v0.35.3 -> v0.36.3
k8s.io/apimachinery v0.35.3 -> v0.36.3
k8s.io/client-go v0.35.3 -> v0.36.3
github.com/ProtonMail/go-crypto v1.3.0 -> v1.4.1
github.com/ProtonMail/gopenpgp/v2 v2.9.0 -> v2.10.0
github.com/cosi-project/runtime v1.14.0 -> v1.14.1
github.com/emicklei/go-restful/v3 v3.12.2 -> v3.13.0
github.com/fluxcd/cli-utils v0.37.2-flux.1 -> v1.2.0
github.com/fluxcd/pkg/ssa v0.70.0 -> v0.73.0
github.com/go-openapi/jsonpointer v0.21.1 -> v0.23.1
github.com/go-openapi/jsonreference v0.21.0 -> v0.21.6
github.com/go-openapi/swag v0.23.1 -> v0.26.0
github.com/google/cel-go v0.27.0 -> v0.29.0
github.com/google/gnostic-models v0.7.0 -> v0.7.1
github.com/google/go-containerregistry v0.21.3 -> v0.21.6
github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.8 -> v2.29.0
github.com/jsimonetti/rtnetlink/v2 v2.2.0 -> v2.2.1-0.20260317095713-310581b9c6ac
github.com/klauspost/compress v1.18.4 -> v1.18.7
github.com/mdlayher/netlink v1.8.0 -> v1.9.0
github.com/moby/moby/api v1.54.0 -> v1.54.2
github.com/neticdk/go-stdlib v1.0.0 -> v1.0.1
github.com/petermattis/goid v0.0.0-20250508124226-395b08cebbdb -> v0.0.0-20260226131333-17d1149c6ac6
github.com/sasha-s/go-deadlock v0.3.5 -> v0.3.6
github.com/siderolabs/crypto v0.6.4 -> v0.6.5
github.com/siderolabs/gen v0.8.6 -> v0.8.7
github.com/siderolabs/go-talos-support v0.1.4 -> v0.2.1
go.uber.org/zap v1.27.1 -> v1.28.0
go.yaml.in/yaml/v2 v2.4.3 -> v2.4.4
golang.org/x/crypto v0.49.0 -> v0.55.0
golang.org/x/exp v0.0.0-20250506013437-ce4c2cf36ca6 -> v0.0.0-20260218203240-3dfff04db8fa
golang.org/x/net v0.52.0 -> v0.58.0
golang.org/x/sync v0.20.0 -> v0.22.0
golang.org/x/sys v0.42.0 -> v0.47.0
golang.org/x/term v0.41.0 -> v0.45.0
golang.org/x/time v0.14.0 -> v0.15.0
google.golang.org/genproto/googleapis/api v0.0.0-20260311181403-84a4fc48630c -> v0.0.0-20260526163538-3dc84a4a5aaa
google.golang.org/genproto/googleapis/rpc v0.0.0-20260311181403-84a4fc48630c -> v0.0.0-20260729162451-8efbd57d26e0
google.golang.org/grpc v1.79.3 -> v1.82.1
k8s.io/cli-runtime v0.35.2 -> v0.36.3
k8s.io/component-base v0.35.2 -> v0.36.3
k8s.io/klog/v2 v2.130.1 -> v2.140.0
k8s.io/kube-openapi v0.0.0-20250910181357-589584f1c912 -> v0.0.0-20260319004828-5883c5ee87b9
k8s.io/kubectl v0.35.2 -> v0.36.3
k8s.io/utils v0.0.0-20251002143259-bc988d571ff4 -> v0.0.0-20260319190234-28399d86e0b5
sigs.k8s.io/controller-runtime v0.23.3 -> v0.24.0
sigs.k8s.io/structured-merge-diff/v6 v6.3.2-0.20260122202528-d9cc6641c482 -> v6.3.3

@renovate renovate Bot changed the title chore(deps): update module github.com/siderolabs/talos to v1.12.7 chore(deps): update module github.com/siderolabs/talos to v1.13.0 Apr 27, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-siderolabs-talos-1.x branch 5 times, most recently from fc28c24 to d8ee470 Compare May 1, 2026 16:51
@renovate renovate Bot changed the title chore(deps): update module github.com/siderolabs/talos to v1.13.0 chore(deps): update module github.com/siderolabs/talos to v1.13.1 May 12, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-siderolabs-talos-1.x branch 2 times, most recently from a6abd8e to 6de0c80 Compare May 12, 2026 18:52
@renovate renovate Bot changed the title chore(deps): update module github.com/siderolabs/talos to v1.13.1 chore(deps): update module github.com/siderolabs/talos to v1.13.2 May 12, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-siderolabs-talos-1.x branch from 6de0c80 to a6f5ba0 Compare May 26, 2026 09:36
@renovate renovate Bot changed the title chore(deps): update module github.com/siderolabs/talos to v1.13.2 chore(deps): update module github.com/siderolabs/talos to v1.13.3 May 26, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-siderolabs-talos-1.x branch from a6f5ba0 to d2961bf Compare June 9, 2026 19:39
@renovate renovate Bot changed the title chore(deps): update module github.com/siderolabs/talos to v1.13.3 chore(deps): update module github.com/siderolabs/talos to v1.13.4 Jun 9, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-siderolabs-talos-1.x branch from d2961bf to 9431b7e Compare June 22, 2026 17:50
@renovate renovate Bot changed the title chore(deps): update module github.com/siderolabs/talos to v1.13.4 chore(deps): update module github.com/siderolabs/talos to v1.13.5 Jun 22, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-siderolabs-talos-1.x branch from 9431b7e to 17700eb Compare July 9, 2026 10:45
@renovate renovate Bot changed the title chore(deps): update module github.com/siderolabs/talos to v1.13.5 chore(deps): update module github.com/siderolabs/talos to v1.13.6 Jul 9, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-siderolabs-talos-1.x branch from 17700eb to 88365c6 Compare July 21, 2026 16:44
@renovate renovate Bot changed the title chore(deps): update module github.com/siderolabs/talos to v1.13.6 chore(deps): update module github.com/siderolabs/talos to v1.13.7 Jul 21, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-siderolabs-talos-1.x branch from 88365c6 to 113df79 Compare August 4, 2026 15:49
@renovate renovate Bot changed the title chore(deps): update module github.com/siderolabs/talos to v1.13.7 chore(deps): update module github.com/siderolabs/talos to v1.13.8 Aug 4, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-siderolabs-talos-1.x branch from 113df79 to ec6e6d7 Compare August 19, 2026 17:16
@renovate renovate Bot changed the title chore(deps): update module github.com/siderolabs/talos to v1.13.8 chore(deps): update module github.com/siderolabs/talos to v1.13.9 Aug 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant