v1.12.0-alpha.1 #11937
smira
announced in
Announcements
v1.12.0-alpha.1
#11937
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Talos 1.12.0-alpha.1 (2025-10-01)
Welcome to the v1.12.0-alpha.1 release of Talos!
This is a pre-release of Talos
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Disk Encryption
Talos versions prior to v1.12 used the state of PCR 7 and signed policies locked to PCR 11 for TPM based disk encryption.
Talos now supports configuring which PCRs states are to be used for TPM based disk encryption via the
options.pcrsfield in the
tpmsection of the disk encryption configuration.If user doesn't specify any options Talos defaults to using PCR 7 for backwards compatibility with existing installations.
This change was made to improve compatibility with systems that may have varying states in PCR 7 due to UEFI Secure Boot configurations
and users may wish to disable locking to PCR 7 state entirely.
Signed PCR policies will still be bound to PCR 11.
The currently used PCR's can be seen with
talosctl get volumestatus <volume> -o yamlcommand.Embedded Config
Talos Linux now supports embedding the machine configuration directly into the boot image.
Ethernet Configuration
The Ethernet configuration now includes a
wakeOnLANfield to enable Wake-on-LAN (WOL) support.This field can be set to enable WOL and specify the desired WOL modes.
Extra Binaries
Talos Linux now ships with
nftbinary in the rootfs to support CNIs which shell out tonftcommand.Kernel Security Posture Profile (KSPP)
Talos now enables a stricter set of KSPP sysctl settings by default.
The list of overridden settings is available with
talosctl get kernelparamstatuscommand.Encrypted Volumes
Talos Linux now consistently provides mapped names for encrypted volumes in the format
/dev/mapper/luks2-<volume-id>.This change should not affect system or user volumes, but might allow easier identification of encrypted volumes,
and specifically for raw encrypted volumes.
Component Updates
Linux: 6.16.9
Kubernetes: 1.34.1
CNI Plugins: 1.8.0
cryptsetup: 2.8.1
LVM2: 2_03_34
systemd-udevd: 257.8
runc: 1.3.1
CoreDNS: 1.12.4
etcd: 3.6.5
Talos is built with Go 1.25.1.
Contributors
Changes
179 commits
constants.MinimumGOAMD64Levelusing build tag.gittext/templateinmachinedcode pathstalos.config.earlycommand line argChanges since v1.12.0-alpha.0
80 commits
constants.MinimumGOAMD64Levelusing build tagChanges from siderolabs/crypto
2 commits
Changes from siderolabs/go-api-signature
1 commit
invalid signatureerror when a signature is requiredChanges from siderolabs/go-debug
1 commit
Changes from siderolabs/go-loadbalancer
1 commit
Changes from siderolabs/pkgs
32 commits
Changes from siderolabs/tools
8 commits
Dependency Changes
Previous release can be found at v1.11.0
Images
This discussion was created from the release v1.12.0-alpha.1.
Beta Was this translation helpful? Give feedback.
All reactions