feat(github-release): update aqua:siderolabs/talos ( 1.10.2 → 1.13.8 ) - #892
Closed
renovate[bot] wants to merge 1 commit into
Closed
feat(github-release): update aqua:siderolabs/talos ( 1.10.2 → 1.13.8 )#892renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/aqua-siderolabs-talos-1.x
branch
from
May 26, 2026 11:26
0df56d8 to
2aff952
Compare
renovate
Bot
force-pushed
the
renovate/aqua-siderolabs-talos-1.x
branch
from
June 9, 2026 17:12
2aff952 to
b36e192
Compare
renovate
Bot
force-pushed
the
renovate/aqua-siderolabs-talos-1.x
branch
from
June 22, 2026 17:06
b36e192 to
8b960c6
Compare
renovate
Bot
force-pushed
the
renovate/aqua-siderolabs-talos-1.x
branch
from
July 9, 2026 10:58
8b960c6 to
e67597a
Compare
renovate
Bot
force-pushed
the
renovate/aqua-siderolabs-talos-1.x
branch
from
July 21, 2026 15:49
e67597a to
5b0f61e
Compare
renovate
Bot
force-pushed
the
renovate/aqua-siderolabs-talos-1.x
branch
from
August 4, 2026 18:47
5b0f61e to
9dee8f9
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.10.2→1.13.8Release Notes
siderolabs/talos (aqua:siderolabs/talos)
v1.13.8Compare Source
Talos 1.13.8 (2026-08-04)
Welcome to the v1.13.8 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Component Updates
Linux: 6.18.42
CoreDNS: 1.14.6
Flannel: 0.28.8
Talos is built with Go 1.26.5.
Contributors
Changes
14 commits
3de4932release(v1.13.8): prepare release76de777chore: update dependencies77d5fe2chore: update pkgsa7db9b2fix: verify the public key signed images correctlyd769389fix: use context without cancelation for etcd locks3a2abc0fix: redact resource specs in the merge controllers1531797fix(machined): preserve health when services reach runningfc75754fix: race with PCR extensions and volume unlock2a51fb1feat: update Flannel to 0.28.805471d3feat: update CoreDNS to 1.14.69e0b1cafix: volume mount race (third attempt) around service restartc5cb365fix: ignore insecure-only imager assetsc67b10dtest: update Calico in canal reset test9eca6eafix: preserve trailing rate-limited trigger eventsChanges from siderolabs/pkgs
6 commits
f677246chore: update kernel6c5daf2chore: replace gnu mirror4304e87feat: bump kernel to 6.18.41e66edebfeat: enable PCF8523 RTC support for arm64b2e51fcfeat: bump kernel to 6.18.4033195c5feat: enable CONFIG_NFT_SOCKET in the kernelDependency Changes
Previous release can be found at v1.13.7
Images
v1.13.7Compare Source
Talos 1.13.7 (2026-07-21)
Welcome to the v1.13.7 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Component Updates
Linux: 6.18.39
containerd: 2.2.6
Flannel: 0.28.7
CoreDNS: 1.14.4
Talos is built with Go 1.26.5.
Contributors
Changes
19 commits
b0039b7release(v1.13.7): prepare releasefc6f9b1test: add nginx to the image cache integrationc6c435btest: increase resource inmem buffer to stabilize the tests202dc15fix: add ca-certificates to talosctl3a14c8dfix: vrf sortinga4c1e6efix: oom podruntime protection57b8616feat: bump CoreDNS, Flannel58a78fefix: use symlinks for init aliases428872bfix: do proper backoff for NTP Kiss-of-Death responses1d55e28feat: add iommufd as a kernel module576638dfix: make audit restartable76328f9fix: avoid image cache mount request churn46f9ac6feat: bring in ifb.ko module0d752e7fix: provide correct handler for Ctrl-Alt-Delete sequencefe9d330fix: terminate log persistence a bit harder7c8021afeat: add --no-reboot flag to upgrade cmda155badfix: do not block volume lifecycle teardown on failed user volumesc63f078fix: flaky tests2bf6b74feat: bring in Linux 6.18.39, containerd 2.2.6Changes from siderolabs/pkgs
6 commits
91fe0a0feat: update Linux to 6.18.391018556feat: enable CONFIG_IOMMUFD and CONFIG_VFIO_DEVICE_CDEVd529479chore: bump nvidia to 580.167.08971fd23fix: enable CONFIG_IFB as a moduleacece91feat: update DRBD to 9.3.3b91905cfeat: update containerd to 2.2.6Changes from siderolabs/tools
1 commit
c2844e6feat: update util-linux to 2.42.2Dependency Changes
7e8f69fPrevious release can be found at v1.13.6
Images
v1.13.6Compare Source
Talos 1.13.6 (2026-07-09)
Welcome to the v1.13.6 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Component Updates
Linux: 6.18.38
Talos is built with Go 1.26.5.
Contributors
Changes
15 commits
0431885release(v1.13.6): prepare release9d8e47dchore: update pkgs and tools31552f4fix: shutdown/reboot via usermode helpersbc0c3f3fix: flaky serviceaccount suite test3e75592fix: flaky testsfbe4d90fix: data race in manifest sync6df3a45fix: provide cooldown period for the QoS trigger85f8dd6fix: decode extraArgs list values correctlyc2a56d5fix: kubelet stuck restarting8714408chore: bump rekor for GHSA-47q9-m4ww-924m3e37ef8fix: handle image cache being disabled466bcd8fix: align documented image cache partition labeld3cf09bfix: image verification with referrerse9609b9feat: add AMD XGBE driver to initramfsf18efccchore: update depsChanges from siderolabs/gen
1 commit
c526410fix: skip unknown-key check for types with custom YAML unmarshalerChanges from siderolabs/pkgs
7 commits
d8c80ccchore: update toolchain and tools71874fbfeat: bump kernel to 6.18.38a2406a1feat: bump kernel 6.18.37e410c35feat: update Linux firmware to2026062389b8aafix: patch Linux kernel for tunnel metadata buffer overflow7e4a719feat: add support for AMD XGBE driver1915c58feat: enable NF_TABLES_ARP optionChanges from siderolabs/tools
1 commit
c58afd5chore: bump toolchainDependency Changes
Previous release can be found at v1.13.5
Images
v1.13.5Compare Source
Talos 1.13.5 (2026-06-22)
Welcome to the v1.13.5 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Component Updates
Linux: 6.18.36
containerd: 2.2.5
runc: 1.4.3
Talos is built with Go 1.26.4.
Contributors
Changes
9 commits
51b0d8erelease(v1.13.5): prepare releasec5089c6fix: bump number of open files for etcde0b4d9dfix: stop the log persistence and close all files on shutdown23a080dfix: honor FailurePauseTimeout when pausing before reboot9adc63afix: correct the link alias conditionb902f9dfeat: verify go.mod tidiness in generate target765f0a1fix: relax LUKS header validationd63aba4feat: update pkgs and Kubernetesf0a5842fix: update go.mod and rekresChanges from siderolabs/pkgs
8 commits
6b315f7chore: update zfs to 2.4.3ebf23f3feat: update Linux to 6.18.367eed62dchore: bump containerd to 2.2.5 (cve patches)8b67babchore: update nvidia driver lts to 580.167.088cb61b2feat: bump runcd736aeffeat: bump kernel to 6.18.357ede376fix: avoid page_table_check BUG on time namespace VVAR pagee69debdfeat: update tools and rekresChanges from siderolabs/tools
2 commits
9b78252feat: update ca-certificates to 2026-05-144d13afffeat: bump OpenSSL to 3.6.3Dependency Changes
Previous release can be found at v1.13.4
Images
v1.13.4Compare Source
Talos 1.13.4 (2026-06-09)
Welcome to the v1.13.4 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Component Updates
Linux: 6.18.34
etcd: v2.6.12
Flannel: v0.28.5
Talos is built with Go 1.26.4.
Contributors
Changes
17 commits
707dbd8release(v1.13.4): prepare release27d7a19fix: handle cluster-scoped resources with a namespace correctlyfe74e00chore: update depsf44cafbfix: recreate dns server and listeners on host DNS runner restart5ed296bfix: marshal kube-scheduler config correctly with int types5992015fix: machine configuration schemasb8dfda7fix: mark more resources as sensitiveaad841bfeat: update Flannel to v0.28.57c0900bfix(ci): aws nvidia tests9f5122dfix: flaky testcf62af3fix: etcd client leak in the (legacy) Upgrade APId5c3136feat: enforce strict QoS ordering in OOM victim selectionb5ad39efeat: update etcd to v3.6.12c83dad3fix: health request server-side577cc6ffix: bring in a change to BCM2712_MIP29da68afix: touch rootfs files with SOURCE_DATE_EPOCHb19a03bfix: ignore cgroups with zero rank in OOM handlerChanges from siderolabs/go-kubernetes
1 commit
131a2bdfix: handle cluster-scoped resources with a ns correctlyChanges from siderolabs/pkgs
5 commits
54ec9fcfix: disable PAGE_TABLE_CHECK_ENFORCED in kernel config0d5985afeat: enable USB hiddev for apcupsd support593e34cfeat: bump kernel to 6.18.34366f575fix: enable CONFIG_BCM2712_MIP as built-in in arm64 kernel configb45e84cfeat: bump Go to 1.26.4Changes from siderolabs/tools
2 commits
a06bb31feat: bump go to 1.26.49bb7abefeat: update libcap to 2.78Dependency Changes
Previous release can be found at v1.13.3
Images
v1.13.3Compare Source
Talos 1.13.3 (2026-05-26)
Welcome to the v1.13.3 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Component Updates
Linux: 6.18.33
Kubernetes: 1.36.1
containerd: 2.2.4
Talos is built with Go 1.26.3.
Contributors
Changes
19 commits
befeda7release(v1.13.3): prepare releasef4d4510feat(ci): rotate credentials01b4348fix: guard apply config API calla42c37ffeat(machined): support instance tags on Akamaid62d54cfix: memorymodules resource reportingb673b4bfix: bump Go golang.org/x modules19755adfeat: add bnxt_re module to the rootfs532bc6bfix: relax hostname config validation3bbd3edfix: bump Kubernetes to 1.36.1 in one more place472b9d9feat: update default Kubernetes version to 1.36.16d53ce0chore(ci): fix cloud image upload job name5633c77fix: rework how scheduler config is marshaled52f0560fix: restore some shared (and some lower tier slave) mount propagation9de3c12fix: image verification issue with registry.k8s.io7dc716dfeat: redact more machine config secrets and audit redactorsd5448c6chore(ci): try fixing homebrew actionef9f0bfdocs: drop controlplane endpoint examples7ee3e78feat: update Linux to 6.18.33e99744bfix: update containerd to 2.2.4Changes from siderolabs/go-smbios
1 commit
063f5dcchore: rekres + new testdataChanges from siderolabs/pkgs
12 commits
8c18616feat: pre-generate drbd patches using spatch out of tree82e70a0feat: update Linux to 6.18.33993d4a6feat: enable PPP and INFINIBAND_BNXT_RE12d5337feat: enable more options for CRI-U checkpoint/restorec2e43aafeat: preserve System.map on kernel builds230b4bcchore: update deps847a37efeat: bump kernel 6.18.32d7ae843feat: update Linux to 6.18.31a26d3c0feat: update ZFS & NVIDIA LTS94d28c5feat: update Linux to 6.18.30b3dd525fix: macb silent TX stall on BCM2712/RP1 (v2 patches from netdev)8bdd5e0feat: update containerd to 2.2.4Dependency Changes
Previous release can be found at v1.13.2
Images
v1.13.2Compare Source
Welcome to the v1.13.0-alpha.2 release of Talos!
This is a pre-release of Talos
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Clang built kernel and ThinLTO
Talos now uses a kernel built using Clang compiler, and optimized using ThinLTO. This should bring a small performance improvement,
alongside some hardening features, such as BTI on supported ARM systems.
talosctl debug
Talos Linux now provides a way to run and attach to the privileged debug container with a user-provided container image.
The debug container might be used for troubleshooting and debugging purposes.
Environment Configuration Document
A new
EnvironmentConfigdocument has been introduced to allow users to specify environment variables for Talos components.It replaces and deprecates the previous method of setting environment variables via the
.machine.envfield.Multiple values for the same environment variable will replace previous values, with the last one taking precedence.
To remove an environment variable, remove it from the
EnvironmentConfigdocument and restart the node.External Volumes
Talos now supports virtiofs-based external volumes via the new
ExternalVolumeConfig
document.
These virtiofs external volumes are not supported when SELinux is running
in enforcing mode.
Extra Arguments accept slices in addition to strings
Several Talos configuration fields that previously accepted single string values for extra arguments have been updated to accept slices of strings as well.
This includes fields such as
.cluster.apiServer.extraArgs.BREAKING: If you were relying on the resources EtcdConfigs, KubeletConfigs, ControllerManagerConfigs, SchedulerConfigs or APIServerConfigs, the protobuf format has changed from
map<string,string>tomap<string,message>.Talos Imager Enhancements
Talos imager now supports running rootless.
--privilegedand-v /dev:/devare no longer required.Image APIs Updated
Talos Linux provides new APIs to manage container images on the node: listing, pulling, importing and removing images.
The new pull APIs provides pull progress notifications.
The CLI commands
talosctl image pull,talosctl image listandtalosctl image removehave been updated to interact with the new APIs.Talosctl images k8s-bundle subcommand accepts version parameter
The
talosctl images k8s-bundlecommand now accepts an optional version overrides arguments.Kubernetes server-side apply
Talos now uses inventory backed server-side apply when applying bootsrap manifests (including
extraManifestsandinlineManifests).Purging of unneeded manifests is automatically performed.
The switch and inventory backfill is automatic and no action is needed from the user.
KubeSpan Configuration
A new
KubeSpanConfigdocument has been introduced to configure KubeSpan settings.It replaces and deprecates the previous method of configuring KubeSpan via the
.machine.network.kubespanfield.The old configuration field will continue to work for backward compatibility.
KubeSpan Advertised Network Filters
KubeSpan now supports filtering of advertised networks using the
excludeAdvertisedNetworksfield in theKubeSpanConfigdocument.This allows users to specify a list of CIDRs to exclude from the advertised networks. Please note that routing must be symmetric for any
pair of peers, so if one peer excludes a certain network, the other peer must also exclude it. In other words, for any given pair of peers,
and any pair of their addresses, the traffic should either go through KubeSpan or not, but not one way or the other.
LinkAliasConfig Pattern-Based Multi-Alias
LinkAliasConfignow supports pattern-based alias names using%dformat verb (e.g.net%d).When the alias name contains a
%dformat verb, the selector is allowed to match multiple links.Each matched link receives a sequential alias (e.g.
net0,net1, ...) based on hardware address orderof the links. Links already aliased by a previous config are automatically skipped.
This enables creating stable aliases from any N links using a single config document,
useful for
BondConfigandBridgeConfigmember interfaces on varying hardware.Negative Max Volume Size
Negative max size represents the amount of space to be left free on the device, rather than the size the volume should consume.
For example:
* a max size of "-10GiB" means the volume can grow to the available space minus 10GiB.
* a max size of "-25%" means the volume can grow to the available space minus 25%.
Flannel CNI with Network Policy Support
Talos Linux now supports optionally deploying Flannel CNI with network policy support enabled.
The network policy implementation is kube-network-policies.
To enable Flannel CNI with network policy support, use the following machine configuration patch:
(If the cluster is already running, sync the bootstrap manifests after applying the patch to deploy the new CNI configuration.)
Container Image Decompression
Talos now ships with
igzip(amd64) andpigz(arm64) to speed up container image decompression.ProbeConfig
The TCPProbeConfig configuration document allows to configure TCP probes for network reachability checks.
This allows to define a custom connectivity condition.
/proc/PID/mem Access Hardening
A new kernel parameter
proc_mem.force_override=neverhas been introduced by default to enhance system securityby preventing unwanted writes to protected process memory via
/proc/PID/mem.If the kernel parameter is removed, default behavior is restored, allowing access only if the process is traced.
Reproducible Disk Images
Talos disk images are now reproducible. Building the same version of Talos multiple times will yield
identical disk images.
Note: VHD and VMDK (Azure and VMware) images are not currently reproducible due to limitations in the underlying image creation tools.
Users verifying reproducible images should use raw images, verify checksums, and convert them to VHD/VMDK as needed.
ResolverConfig
The nameservers configuration in machine configuration now overwrites any previous layers (defaults, platform, etc.) when specified.
Previously a smart merge was performed to keep IPv4/IPv6 nameservers from lower layers if the machine configuration specified only one type.
Service Account Issuer configuration
In API Server, passing extra args with
service-account-issuerwill append them after default value.This allows easy migration, e.g. by changing
.cluster.controlPlane.endpointto new value, and keeping the old value in.cluster.apiServer.extraArgs["service-account-issuer"].talosctl images talos-bundlecan ignore reaching to the registryThe
talosctl images talos-bundlecommand now accepts optional--overlaysand--extensionsflags.If those are set to
false, the command will not attempt to reach out to the container registry to fetch the latest versions and digests of the overlays and extensions.Component Updates
Linux: 6.18.13
containerd: 2.2.1
etcd: 3.6.8
CoreDNS: 1.14.1
Kubernetes: 1.36.0-alpha.1
Flannel CNI plugin: v1.9.0-flannel1
Flannel: 0.28.1
LVM2: 2_03_38
runc: 1.4.0
systemd: 259.1
cryptsetup: 2.8.3
Tenstorrent: 2.7.0
iptables: 1.8.12
Talos is built with Go 1.26.0.
VM Hot-Add Support
Talos now includes udev rules to support hot-adding of CPUs in virtualized environments.
Contributors
Changes
221 commits
009f0d6cachore: update pkgsba56b0295feat: include hid-multitouch.ko kernel module in rootfsae29a0dccfeat: update Linux to 6.18.137cf1de279fix: bring in new version of go-cmd and go-blockdevicec8800b41efix: update path handling on talosctl cgroups0a7b6eb2cchore: test extensions8b1c974a2refactor: drop termui-widgets library5baa0028efix: add owning inventory annotation to talos manifestsd3e793d14fix: stop Kubernetes client from dynamically reloading the certs6a5a0e3bdfeat: support pattern link aliases9758bd4fefeat: update Go to 1.26e00aed0f6feat: update Kubernetes v1.36.0-alpha.1f20445ad0chore: improve logging of disk encryption handlingf018fbe7bfix: handle raw encryption keys with\nproperlye5b0eb017fix: hold user volumes root mountpoint8a0e79774refactor: split locate and provisiona59db0e92fix: improve OpenStack bare metal network configuration reliability659009ad8fix: remove stale endpointsdab0d4783fix: allow static hosts in/etc/hostswithout hostname45f214154feat: update go-kubernetes to use new Myers diff35ad0448cfix: switch to better Myers algorithm implementation0048464befeat: update etcd to v3.6.85df10f260fix: use mcopy instead of diskfs to populate VFATce53ffa90fix: disks flag parsing and handling in create qemu command3bd3dd7cafix: memory overuse in imager VFATf118ee47efix: read multi-doc machine config with newer talosctl70c6c2154feat: add filter for KubeSpan advertised networksdaf18abf4fix: fix talosctl debug in enforcing mode33b5b2565fix: ignore volumes in wave calculation without provisioninga16392559feat: add explicit service account support to Talos client4d531884echore: update dependencies406b8c83cfeat: update doc links to docs.siderolabs.com87615f551feat: implement network policies with Flannel CNI6995bc1b1chore: update homebrew formula on release7942d5a98fix: image gc controller config52e8727d0feat: add IPv6 GRE support9690dbad0chore: bump tools (including linter)2628eb2ecfix: typo with rpi_5 profile named5ebcd7cafix: stop building talosctl debug on Windows8b85c7c63chore: update depsd905035b5fix: swap volume configuration for min/max sized43a01ccbfeat: implementtalosctl debug34a31c979feat: add mount options support for existing volumes1bf95eed1feat: improve dashboard uptime display055add7aerelease(v1.13.0-alpha.1): prepare release900516e68chore: update image signer938de566efeat: bump kernel388cec727feat(overlays): add new overlays9f2dd6312refactor: api testsa90783146feat: add a helper module to generate standard patches1fec5b23dfix: implement merger for PercentageSize8b245b8f2feat: implement new image service APIsd90c775b8chore: rename internaltalosctl debug air-gapped2165280d0refactor: change the way one2many proxying is pickedb1b703dbechore: move sync logging code to go-kubernetes packagee48c6d7abfix: allow to expose a port multiple times in Docker410d8cb57fix: undo CRLF on Windows (talosctl edit)859d3f03cfeat: add RPi5 to the list of supported SBCs0bd48bbc6fix(talosctl): pass --k8s-endpoint flag to rotate-ca kubernetes rotationb9e27ebe7feat: update Linux kernel with dm-integrity6aa9b0677fix: skip empty documents on config decoding494492489fix: always set advertised peer URLs782cc507dfix: open the filesystem as read-only28e61a740fix: set GRUB prefix correctly on arm64a4f1c5239feat: update GRUB to 2.14562920701fix: use node podCIDRs for kubespan advertiseKubernetesNetworks39460365cfeat: implement layering for ProbeSpecb5c760f70feat: add ProbeConfig for network connectivity probes4b274f761feat: support aws cert manager in imager417209512fix: fallback to /proc/meminfo for memory modules7f1147bedfix: add warnings to 802.3ad bondddd6b186erefactor: generate GRUB imagesc7aa266eafix: overwrite resolver config with machine configcf70f05fafix: oracle platform file format8c7b8f5b7feat: add support for negative max size77bc3d21ffix: marshal of FailOverMac property38e280c93fix: make OOM expression a bit less sensitive3d1301640fix: wipe the first/last 1MiB in addition to wiping by signatures1aa6528adfix: make OOM controller more precise by considering separate cgroup PSIf7072c050fix: check if the device is not mounted when wiping743c3b94bfix: use correct containerd import pathf2dd08594feat: report image pull progress in the console72fe98a06](https://redirect.githConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.