One OS · every type of container
Run production Kubernetes.On one open secure platform
One secure, immutable foundation for Kubernetes and soon virtual machines. Talos Linux is the API-driven OS proven in production: minimal attack surface, no SSH, no shell, no drift, plus the audit evidence and support that clear a security review.
What we offer
• Open Source · MPL-2.0
Talos Linux
Production Kubernetes on an OS that can't drift and can't be logged into. Minimal attack surface, minimal CVEs, free forever.
Get started →• Enterprise · MPL-2.0 · commercial subscription
Talos Enterprise Linux
Everything Talos Linux does, plus Omni fleet management, the audit evidence, indemnity, and 24/7 response that clears the security review.
24/7 support · FIPS 140-3 · CVE SLAs · SBOM & VEX · IP indemnity
Talk to us →• Source available · BSL 1.1
Talos Omni
One API for the entire Kubernetes cluster lifecycle, across your whole fleet from bare metal to the edge.
Explore Omni →- Machine onboarding with join tokens
- etcd backups and certificate rotation
- Health-gated Talos & Kubernetes upgrades
- SaaS or self-hosted, including air-gapped
• Alpha at TalosCon · GA December
Talos Hypervisor
A native hypervisor built into Talos Linux. Run VMs on the same immutable, audit-ready host as your Kubernetes, no KubeVirt, no second platform.
See it at TalosCon →- Native hypervisor, no KubeVirt
- Same immutable, audit-ready host
- Run VMs, no Kubernetes required
- Open source · MPL-2.0
Who’s using it
Adopted in the open. Proven in production.
Trusted by enterprise platform teams
Security & Audit
Hard to attack. Straightforward to prove.
The same properties that make Talos hard to attack are the ones that make it straightforward to prove. Nothing to log into, nothing to drift, one surface to audit, for VMs and containers alike.
Minimal
Nothing to attack
Fewer than 50 binaries. No shell, no SSH, no package manager. What isn’t installed can’t be exploited, and it’s less to document for the auditor.
Immutable
Can’t drift
Read-only and declarative, identical across the fleet. Every node provably matches its declared state, so proving your configuration means reading it, not reconstructing it.
API-driven
One surface to audit
Every action flows through one mutual-TLS API. One place to look, one to prove, nothing hiding in shell history.
Auditable
A short review
A minimal, immutable, API-only OS is a small, well-defined thing to audit. Talos Enterprise Linux adds the formal artifacts, FIPS builds, SBOM, VEX, and CVE SLAs, when the review demands them.
One platform
One platform means one of everything. One OS to operate, one API to audit.
Most teams run Kubernetes and a separate hypervisor: two toolchains, two patch cycles, two things to secure and prove at audit. Consolidating onto one immutable OS removes the duplication.
- One OS to operate
- One mTLS API to audit
- One lifecycle to patch
Open by design
Open, standard, and yours to run.
An open-source core, standard KVM and container formats, and hardware you already own. Keep your platform portable, inspectable, and fully in your control.
Open source
Inspect it, build it, fork it, run it yourself. Talos Linux is MPL-2.0, forever. No open-core bait-and-switch, no surprise license change.
Your hardware, your jurisdiction
No certified-hardware lists, no cloud-only features. Run Talos on bare metal, on-prem, or air-gapped, wherever your compliance requirements demand.
Standard formats, portable by default
Standard KVM for VMs, standard OCI for containers. No proprietary image formats or vendor-specific tooling to escape from later.
Self-hostable and air-gap capable
Talos Omni can run fully self-hosted. The whole platform operates in disconnected environments, with no callbacks and no telemetry requirements.
machine:type: controlplaneinstall:disk: /dev/sdaimage: ghcr.io/siderolabs/installer:v1.14.0wipe: falsecluster:network:cni:name: flannel
MPL-2.0 · Source on GitHub · Build it yourself
# Any hardware, any location$ talosctl apply-config \--nodes 10.0.0.10 \--file controlplane.yaml# Watch it come up$ talosctl health --wait-timeout 10m
Runs on bare metal · On-prem · Air-gapped
Built in the open
Talos is what it is because people chose it before it was obvious.
Talos Linux is open source under MPL-2.0, and it stays open. Everything new (the hypervisor, edge scheduling, Enterprise) adds capability on top, with nothing closed off or gated.
- Talos Linux
- Talos Hypervisor
- Talos Omni