Talos 1.14.1 (2026-09-15)
Welcome to the v1.14.1 release of Talos!
Please try out the release binaries and report any issues at https://github.com/siderolabs/talos/issues.
Component Updates
Linux: 6.18.51 containerd: 2.3.5
Talos is built with Go 1.26.8.
Contributors
- Andrey Smirnov
- Noel Georgi
- Maja Bojarska
- Utku Ozdemir
- Aleksei Sviridkin
- Brian Topping
- Dennis Docter
- Louis Deconinck
- Mateusz Urbanek
- Raphaël DUCOM
- Sacha Weatherstone
- leppeK
- usman.malik_ext
Changes
36 commits
* siderolabs/talos@2f86b9d2a release(v1.14.1): prepare release * siderolabs/talos@65f704ee1 chore: pass kernel version down to VEX generator * siderolabs/talos@63101af5b fix: prevent sandboxd signal dispositions leaking into services * siderolabs/talos@676276f72 test: peer passively with the MetalLB speaker * siderolabs/talos@2b8b46dcd test: stop ARP flux breaking the BGP VRF test * siderolabs/talos@357d6006a fix: rebuild the BGP server when its VRF is recreated * siderolabs/talos@db0b5a17c fix: guard against nil config document slices * siderolabs/talos@094741ff3 docs: clarify the kube-apiserver extra args and new config * siderolabs/talos@a13b560f4 docs: correct the UnattendedInstallConfig name in the schema * siderolabs/talos@166c4070c fix: make --insecure reachable for talosctl meta subcommands * siderolabs/talos@aac106867 fix: ignore apply config dry-run for try mode * siderolabs/talos@7a2c4e8cf fix: tighten the validation of v1alpha1 configs vs. migration * siderolabs/talos@aef64fa38 fix: reconnect the WireGuard over gRPC tunnel after a failure * siderolabs/talos@d07a21ad2 fix: drop logical links if they no longer declare as logical * siderolabs/talos@9996bc871 fix: create GRUB bootloader ISOs only for BIOS * siderolabs/talos@0604432de feat: add NixOS OVMF search path * siderolabs/talos@5cb44dcab fix: wait for USB settle explicitly * siderolabs/talos@20dcd515a fix: empty searchdomains dropped on merge * siderolabs/talos@1e3e3fe50 chore: support correctly various disk types for the system disk * siderolabs/talos@7c2e0b113 fix: notify about link alias changes * siderolabs/talos@e9a67e163 chore: use the host page cache for the QEMU cluster disks * siderolabs/talos@0afebca70 fix: use the final config version in upgrade-k8s * siderolabs/talos@0ad18bb55 feat: bring in containerd 2.3.5 * siderolabs/talos@04c49d8a3 feat: allow generating an ECDSA service account key in secrets bundles * siderolabs/talos@bb2cb91fc fix(security): define the permissions the 6.18 kernel expects in the classes * siderolabs/talos@bf31b2811 fix: improve resilience of the action tracker against dropped conns * siderolabs/talos@00a0ea03c fix: set TCP keealive and user timeout on apid proxied connections * siderolabs/talos@6c065607e test: revert disabling PS/2 in QEMU * siderolabs/talos@9841e0b47 docs: fix containerconfig.dependson examples * siderolabs/talos@a11a260e6 feat: add USB LAN78XX drivers to the rootfs * siderolabs/talos@9f8277434 fix: harden the code around kubelet's client certificate handling * siderolabs/talos@3260b1e1f fix: resolve volume devices in shared selector helper * siderolabs/talos@084152592 fix: create LVM physical volumes on the decrypted device * siderolabs/talos@7dabdeb43 feat: add xfrm interface module * siderolabs/talos@63963f7da feat: sync pkgs/tools * siderolabs/talos@09681e895 fix: correct the bug with overlay assets in ESP being dropped
Changes from siderolabs/gen
2 commits
* siderolabs/gen@cbd9518 chore: rekres and update deps * siderolabs/gen@26ccee1 feat: provide new YAMl unmarshal validator for null values
Changes from siderolabs/pkgs
10 commits
* siderolabs/pkgs@f694e1b feat: update Linux to 6.18.51 * siderolabs/pkgs@85a249a feat: update libpathrs to 0.2.6 * siderolabs/pkgs@fe037b6 feat: update Linux to 6.18.50 * siderolabs/pkgs@35e3898 feat: update containerd to 2.3.5 * siderolabs/pkgs@fd0c2b2 fix: add a kernel patch for EFI SecureBoot integrity lockdown * siderolabs/pkgs@2415a01 feat: add kernel modules to enable Intel HD audio * siderolabs/pkgs@202a677 feat: bump kernel to 6.18.49 * siderolabs/pkgs@5ddbb53 feat: enable CONFIG_USB_LAN78XX and CONFIG_MICROCHIP_PHY on amd64 * siderolabs/pkgs@c61bcc3 feat: enable CONFIG_XFRM_INTERFACE in the kernel * siderolabs/pkgs@40ccb0d chore: sync tools & toolchain
Changes from siderolabs/tools
2 commits
* siderolabs/tools@a404efb chore: bump util-linux 2.42.3 * siderolabs/tools@3c49a3c feat: bump go to 1.26.8
Dependency Changes
- github.com/containerd/containerd/v2 v2.3.4 -> v2.3.5
- github.com/containerd/platforms v1.0.0-rc.4 -> v1.0.0-rc.5
- github.com/siderolabs/gen v0.8.7 -> v0.8.8
- github.com/siderolabs/pkgs v1.14.0-15-g2f03590 -> v1.14.0-25-gf694e1b
- github.com/siderolabs/talos/pkg/machinery v1.14.0 -> v1.14.1
- github.com/siderolabs/tools v1.14.0-5-g87316ca -> v1.14.0-7-ga404efb
Previous release can be found at v1.14.0
Images
ghcr.io/siderolabs/flannel:0.28.9
registry.k8s.io/coredns/coredns:v1.14.7
registry.k8s.io/etcd:3.7.1
registry.k8s.io/pause:3.10.2
registry.k8s.io/kube-apiserver:v1.37.0
registry.k8s.io/kube-controller-manager:v1.37.0
registry.k8s.io/kube-scheduler:v1.37.0
registry.k8s.io/kube-proxy:v1.37.0
ghcr.io/siderolabs/kubelet:v1.37.0
registry.k8s.io/networking/kube-network-policies:v1.1.1
ghcr.io/siderolabs/installer-base:v1.14.1
ghcr.io/siderolabs/imager:v1.14.1
ghcr.io/siderolabs/talos:v1.14.1
ghcr.io/siderolabs/talosctl-all:v1.14.1
ghcr.io/siderolabs/overlays:v1.14.1
ghcr.io/siderolabs/extensions:v1.14.1