One OS · every workload
One immutable OS for Kubernetes, virtual machines and AI.Open at the core. Secure by architecture.
The secure, minimal, open-source OS your clusters already trust, now running your virtual machines and your AI on the same foundation. No SSH, no shell, no drift, and commercial platforms to operate each workload at scale.
What we offer
One foundation. Three workloads. Open at the core, commercial at scale.
Talos Linux is one immutable, open-source OS, and everything runs on it: your Kubernetes, your virtual machines, your AI. The same security and the same open core, with commercial platforms to operate each workload at scale.
The foundation
Free · MPL-2.0
Talos Linux
The immutable, API-driven OS that can't drift and can't be logged into. Minimal attack surface, minimal CVEs, free forever, and the same OS under every workload.
Get started →Enterprise
Talos Enterprise Linux
Everything free Talos does, plus the audit evidence, indemnity and 24/7 response that clears the security review, across every workload.
Omni included · 24/7 support · FIPS 140-3 · CVE SLAs · SBOM & VEX · IP indemnity
Talk to us →Run any workload on it
Kubernetes
Production Kubernetes on the immutable OS your clusters already trust, managed fleet-wide from one API.
- Open source
- Talos LinuxMPL-2.0
- At scale
- Talos Omnisource available · BSL 1.1
Virtual machines
Run VMs on the same immutable, audit-ready host as your clusters, no KubeVirt and no second platform. The alternative to VMware.
- Open source
- Talos HypervisorMPL-2.0 · GA December
- At scale
- Talos DirectorLimited Availability
AI
Serve, fine-tune and ground open models on infrastructure you own, and govern the whole AI lifecycle from one place.
- Open source
- Talos Linux for AIMPL-2.0
- At scale
- Talos CuparGA March 2027
Who’s using it
Proven in production. Adopted in the open.
Trusted by enterprise platform teams
Security & Audit
Security by architecture. Audit evidence by design.
The same properties that make Talos hard to attack are the ones that make it straightforward to prove. Nothing to log into, nothing to drift, one surface to audit, for VMs and containers alike.
Minimal
Nothing to attack
Fewer than 50 binaries. No shell, no SSH, no package manager. What isn’t installed can’t be exploited, and it’s less to document for the auditor.
Immutable
Can’t drift
Read-only and declarative, identical across the fleet. Every node provably matches its declared state, so “prove your configuration” has a one-line answer.
API-driven
One surface to audit
Every action flows through one mutual-TLS API. One place to look, one to prove, nothing hiding in shell history.
Auditable
A short review
A minimal, immutable, API-only OS is a small, well-defined thing to audit. Talos Enterprise Linux adds the formal artifacts, FIPS builds, SBOM, VEX, and CVE SLAs, when the review demands them.
One platform
One platform. One team, one audit surface, one lifecycle.
Most teams run Kubernetes, a separate hypervisor, and a separate AI stack: three toolchains, three patch cycles, three things to secure and prove at audit. Consolidating onto one immutable OS removes the duplication.
- One OS to operate
- One mTLS API to audit
- One relationship to manage
Open by design
Open, standard, and yours to run.
An open-source core, standard KVM and container formats, and hardware you already own keep your platform portable, inspectable, and fully in your control.
Open-source core
Inspect it, build it, fork it, run it yourself. Core Talos Linux is MPL-2.0, forever. No open-core bait-and-switch, no surprise license change.
Your hardware, your jurisdiction
No certified-hardware lists, no cloud-only features. Run Talos on bare metal, on-prem, or air-gapped, wherever your compliance requirements demand.
Standard formats, portable by default
Standard KVM for VMs, standard OCI for containers. No proprietary image formats or vendor-specific tooling to escape from later.
Self-hostable and air-gap capable
Talos Omni can run fully self-hosted. The whole platform operates in disconnected environments, with no callbacks and no telemetry requirements.
machine:type: controlplaneinstall:disk: /dev/sdaimage: ghcr.io/siderolabs/installer:v1.14.0wipe: falsecluster:network:cni:name: flannel
MPL-2.0 · Source on GitHub · Build it yourself
# Any hardware, any location$ talosctl apply-config \--nodes 10.0.0.10 \--file controlplane.yaml# Watch it come up$ talosctl health --wait-timeout 10m
Runs on bare metal · On-prem · Air-gapped
Built in the open
Talos is what it is because people chose it before it was obvious.
Core Talos Linux is open source under MPL-2.0, and it stays open. Everything new (the hypervisor, sovereign AI, Enterprise) adds capability on top, with nothing closed off or gated.
- Talos Linux
- Talos Hypervisor
- Talos Linux for AI
- Talos Omni