Talos 1.14.2 (2026-09-29)
Welcome to the v1.14.2 release of Talos!
Please try out the release binaries and report any issues at
https://github.com/siderolabs/talos/issues.
Kubelet Resource Manager State
Talos now validates the kubelet CPU manager and memory manager state files (/var/lib/kubelet/cpu_manager_state, /var/lib/kubelet/memory_manager_state)
the same way kubelet does on startup, and removes a state file kubelet would refuse to load before starting kubelet.
Previously only a change of the manager policy was detected, so changing e.g. reservedSystemCPUs or reservedMemory, or
a change of the CPU/NUMA topology of the machine, left kubelet unable to start until the state file was removed manually.
Only the rendered KubeletConfiguration (machine.kubelet.extraConfig) is checked: the resource manager settings passed as kubelet
command line flags via machine.kubelet.extraArgs (e.g. --cpu-manager-policy, --reserved-cpus) are not taken into account.
Component Updates
Linux: 6.18.54
containerd: 2.3.6
runc: 1.5.2
Kubernetes: 1.37.1
Talos is built with Go 1.26.8.
Contributors
- Andrey Smirnov
- Jarrad S
- Noel Georgi
- Joakim Nohlgård
- Karthik Chowdary
- Loki San
Changes
20 commits
- f513c7358 release(v1.14.2): prepare release
- 114c70ae3 feat: update Kubernetes default to 1.37.1
- 00a53e13d feat: update containerd to 2.3.6
- 305ced360 test: fix the md-boot pipeline
- 540a427c3 docs: clarify the KMS endpoint scheme
- f53a00050 fix: drop devices from the last observed generation if they are gone
- a015f8176 feat: handle the change in kubelet's CPU and memory policies
- c792fa485 fix: perform stricter validation of hostnames/search domains
- 3137edfb0 fix: handle correctly routes without outlinkname set
- e966b131d chore: clean up unused settings in LVM reconcile controllers
- da3b328db fix: do not disclose pre-shared Wireguard key in LinkStatus
- 80fd649d1 fix: retry transient LVM reconciliation failures
- 98b3cb51e feat: add macsec module
- 949b85fa7 fix: preserve hostname under Docker (in container mode)
- ad65799ab fix: handle Akamai/Linode metadata without IPv6
- 2e87819aa docs: clarify admission control and flannel config docs
- a9422412d test: fix the aws-arm64 test
- c7e25249d fix: use correct conditions on CRI <> sandboxd dependency
- 5a78c3fc3 fix: extend the USB settle code for more code paths
- a8ac3ca50 feat: sync pkgs/tools
Changes from siderolabs/pkgs
12 commits
- siderolabs/pkgs@6c312e4 fix: add a patch to fix booting on Apple hardware
- siderolabs/pkgs@e1a76c7 feat: update Linux to 6.18.54, runc to 1.5.2
- siderolabs/pkgs@3f054f6 feat: enable CONFIG_CRYPTO_ECC, CONFIG_CRYPTO_ECDH on arm64 to match amd64
- siderolabs/pkgs@cc717ed feat: enable CONFIG_BLK_WBT
- siderolabs/pkgs@cc32ceb feat: update containerd to 2.3.6
- siderolabs/pkgs@b9f707f feat: update Linux to 6.18.53
- siderolabs/pkgs@cf70858 fix: add missing sboms for swtpm
- siderolabs/pkgs@7f22731 feat: enable CONFIG_MACSEC in the kernel
- siderolabs/pkgs@3e199fb feat: add swtpm
- siderolabs/pkgs@31af1a6 feat: update DRBD & Linux firmware
- siderolabs/pkgs@612628d feat: update Linux to 6.18.52
- siderolabs/pkgs@ed28ebb chore: sync tools with release-1.14
Changes from siderolabs/tools
Dependency Changes
- github.com/containerd/containerd/v2 v2.3.5 -> v2.3.6
- github.com/siderolabs/pkgs v1.14.0-25-gf694e1b -> v1.14.0-37-g6c312e4
- github.com/siderolabs/talos/pkg/machinery v1.14.1 -> v1.14.2
- github.com/siderolabs/tools v1.14.0-7-ga404efb -> v1.14.0-8-g9776960
- k8s.io/api v0.37.0 -> v0.37.1
- k8s.io/apiextensions-apiserver v0.37.0 -> v0.37.1
- k8s.io/apimachinery v0.37.0 -> v0.37.1
- k8s.io/apiserver v0.37.0 -> v0.37.1
- k8s.io/client-go v0.37.0 -> v0.37.1
- k8s.io/component-base v0.37.0 -> v0.37.1
- k8s.io/kube-proxy v0.37.0 -> v0.37.1
- k8s.io/kube-scheduler v0.37.0 -> v0.37.1
- k8s.io/kubectl v0.37.0 -> v0.37.1
- k8s.io/kubelet v0.37.0 -> v0.37.1
- k8s.io/pod-security-admission v0.37.0 -> v0.37.1
- k8s.io/utils cf1189d6abe3 new
Previous release can be found at v1.14.1
Images
ghcr.io/siderolabs/flannel:0.28.9
registry.k8s.io/coredns/coredns:v1.14.7
registry.k8s.io/etcd:3.7.1
registry.k8s.io/pause:3.10.2
registry.k8s.io/kube-apiserver:v1.37.1
registry.k8s.io/kube-controller-manager:v1.37.1
registry.k8s.io/kube-scheduler:v1.37.1
registry.k8s.io/kube-proxy:v1.37.1
ghcr.io/siderolabs/kubelet:v1.37.1
registry.k8s.io/networking/kube-network-policies:v1.1.1
ghcr.io/siderolabs/installer-base:v1.14.2
ghcr.io/siderolabs/imager:v1.14.2
ghcr.io/siderolabs/talos:v1.14.2
ghcr.io/siderolabs/talosctl-all:v1.14.2
ghcr.io/siderolabs/overlays:v1.14.2
ghcr.io/siderolabs/extensions:v1.14.2