github siderolabs/talos v1.14.2

2 hours ago

Talos 1.14.2 (2026-09-29)

Welcome to the v1.14.2 release of Talos!

Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.

Kubelet Resource Manager State

Talos now validates the kubelet CPU manager and memory manager state files (/var/lib/kubelet/cpu_manager_state, /var/lib/kubelet/memory_manager_state)
the same way kubelet does on startup, and removes a state file kubelet would refuse to load before starting kubelet.

Previously only a change of the manager policy was detected, so changing e.g. reservedSystemCPUs or reservedMemory, or
a change of the CPU/NUMA topology of the machine, left kubelet unable to start until the state file was removed manually.

Only the rendered KubeletConfiguration (machine.kubelet.extraConfig) is checked: the resource manager settings passed as kubelet
command line flags via machine.kubelet.extraArgs (e.g. --cpu-manager-policy, --reserved-cpus) are not taken into account.

Component Updates

Linux: 6.18.54
containerd: 2.3.6
runc: 1.5.2
Kubernetes: 1.37.1

Talos is built with Go 1.26.8.

Contributors

  • Andrey Smirnov
  • Jarrad S
  • Noel Georgi
  • Joakim Nohlgård
  • Karthik Chowdary
  • Loki San

Changes

20 commits

  • f513c7358 release(v1.14.2): prepare release
  • 114c70ae3 feat: update Kubernetes default to 1.37.1
  • 00a53e13d feat: update containerd to 2.3.6
  • 305ced360 test: fix the md-boot pipeline
  • 540a427c3 docs: clarify the KMS endpoint scheme
  • f53a00050 fix: drop devices from the last observed generation if they are gone
  • a015f8176 feat: handle the change in kubelet's CPU and memory policies
  • c792fa485 fix: perform stricter validation of hostnames/search domains
  • 3137edfb0 fix: handle correctly routes without outlinkname set
  • e966b131d chore: clean up unused settings in LVM reconcile controllers
  • da3b328db fix: do not disclose pre-shared Wireguard key in LinkStatus
  • 80fd649d1 fix: retry transient LVM reconciliation failures
  • 98b3cb51e feat: add macsec module
  • 949b85fa7 fix: preserve hostname under Docker (in container mode)
  • ad65799ab fix: handle Akamai/Linode metadata without IPv6
  • 2e87819aa docs: clarify admission control and flannel config docs
  • a9422412d test: fix the aws-arm64 test
  • c7e25249d fix: use correct conditions on CRI <> sandboxd dependency
  • 5a78c3fc3 fix: extend the USB settle code for more code paths
  • a8ac3ca50 feat: sync pkgs/tools

Changes from siderolabs/pkgs

12 commits

Changes from siderolabs/tools

1 commit

Dependency Changes

  • github.com/containerd/containerd/v2 v2.3.5 -> v2.3.6
  • github.com/siderolabs/pkgs v1.14.0-25-gf694e1b -> v1.14.0-37-g6c312e4
  • github.com/siderolabs/talos/pkg/machinery v1.14.1 -> v1.14.2
  • github.com/siderolabs/tools v1.14.0-7-ga404efb -> v1.14.0-8-g9776960
  • k8s.io/api v0.37.0 -> v0.37.1
  • k8s.io/apiextensions-apiserver v0.37.0 -> v0.37.1
  • k8s.io/apimachinery v0.37.0 -> v0.37.1
  • k8s.io/apiserver v0.37.0 -> v0.37.1
  • k8s.io/client-go v0.37.0 -> v0.37.1
  • k8s.io/component-base v0.37.0 -> v0.37.1
  • k8s.io/kube-proxy v0.37.0 -> v0.37.1
  • k8s.io/kube-scheduler v0.37.0 -> v0.37.1
  • k8s.io/kubectl v0.37.0 -> v0.37.1
  • k8s.io/kubelet v0.37.0 -> v0.37.1
  • k8s.io/pod-security-admission v0.37.0 -> v0.37.1
  • k8s.io/utils cf1189d6abe3 new

Previous release can be found at v1.14.1

Images

ghcr.io/siderolabs/flannel:0.28.9
registry.k8s.io/coredns/coredns:v1.14.7
registry.k8s.io/etcd:3.7.1
registry.k8s.io/pause:3.10.2
registry.k8s.io/kube-apiserver:v1.37.1
registry.k8s.io/kube-controller-manager:v1.37.1
registry.k8s.io/kube-scheduler:v1.37.1
registry.k8s.io/kube-proxy:v1.37.1
ghcr.io/siderolabs/kubelet:v1.37.1
registry.k8s.io/networking/kube-network-policies:v1.1.1
ghcr.io/siderolabs/installer-base:v1.14.2
ghcr.io/siderolabs/imager:v1.14.2
ghcr.io/siderolabs/talos:v1.14.2
ghcr.io/siderolabs/talosctl-all:v1.14.2
ghcr.io/siderolabs/overlays:v1.14.2
ghcr.io/siderolabs/extensions:v1.14.2

Don't miss a new talos release

NewReleases is sending notifications on new releases.