github siderolabs/omni v1.12.4

4 hours ago

Omni 1.12.4 (2026-10-07)

Welcome to the v1.12.4 release of Omni!

Please try out the release binaries and report any issues at
https://github.com/siderolabs/omni/issues.

Local Resource Service Removal

The local resource service, which served Omni resources on a local listener, is removed. Consumers should reach Omni through its regular API with a service account instead. Its services.localResourceService settings and flags have no effect.

Contributors

  • Utku Ozdemir
  • Oguz Kilcan
  • Artem Chernyshev
  • Andy Longwill
  • immanuwell

Changes

22 commits

  • f9d1743a5 release(v1.12.4): prepare release
  • a1265ba7a fix: return only the unauthenticated error for an unsigned request
  • 69c79f273 fix: redact config secrets and clear the stored OIDC client secret
  • 3b0446c85 fix: forward only known headers to the Kubernetes apiserver
  • 4dfee714f fix: remove conflicting join token renew alias
  • 6eddd8c08 fix: require a confirmed key for workload proxy access
  • 18ac5ee9d fix: make a resource's cluster label agree with its target
  • 3b2a95383 fix: extract the cluster ID from label query terms correctly
  • 42a6dd708 feat: allow upgrading one deprecated Talos to another one in maintenance
  • 999446893 fix: do not allocate machines with outdated schematics into a cluster
  • 3526d6614 fix: reject unknown Talos versions on the talosctl downloads endpoint
  • 7d5c9bf5c feat: remove the local resource service
  • 33d8d5b7e fix: resolve node headers only for the runtime that uses them
  • d9e69d606 fix: read local resource server stream metadata from its own context
  • dcfa43a27 fix: verify the caller before reporting a resolution failure
  • 29958ee1a fix: check access before rejecting a request that names several nodes
  • e38d71c06 fix: record the outcome of Talos access in the audit log
  • 6f7d8c83e fix: parse the role of a public key request before any lookup
  • 2982aa994 fix: return only the access error for a denied request
  • fcf4c8568 fix: return the same error for a missing and an inaccessible target
  • 668469919 chore: bump otel libraries to close a vuln
  • 47322b255 fix(frontend): add v prefix to installer image tag

Dependency Changes

This release has no dependency changes

Previous release can be found at v1.12.3

Don't miss a new omni release

NewReleases is sending notifications on new releases.