Skip to content
Where did you find out about us? If you have 30 seconds, let us know.
Sidero Labs Logo
  • Products
    • OmniOmni
      Integrate across Kubernetes environments to make infrastructure consistent, seamless, and scalable.
      Integrate across Kubernetes environments to make infrastructure consistent, seamless, and scalable.
    • Talos LinuxTalos Linux
      API Managed, declarative, minimal Linux for K8s. Easier updates, simpler scale.
      API Managed, declarative, minimal Linux for K8s. Easier updates, simpler scale.
    • SupportSupport
      Comprehensive enterprise production coverage for Talos Linux and Omni
      Comprehensive enterprise production coverage for Talos Linux and Omni
  • Solutions
    • Omni data centerOmni data center
      Extend the value of Kubernetes to the infrastructure level with a minimal, secure-by-default platform.
      Extend the value of Kubernetes to the infrastructure level with a minimal, secure-by-default platform.
    • Omni edgeOmni edge
      Edge is hard. We make it easy. Focus on your business, not your platform.
      Edge is hard. We make it easy. Focus on your business, not your platform.
    • Omni bare metalOmni bare metal
      Streamlined, automated, and reliable bare metal infrastructure.
      Streamlined, automated, and reliable bare metal infrastructure.
    • SecuritySecurity
      Minimal by design, secure by default. Talos Linux and Omni.
      Minimal by design, secure by default. Talos Linux and Omni.
    • FIPS Talos LinuxFIPS Talos Linux
      FIPS-compliant Kubernetes OS builds for highly regulated environments.
      FIPS-compliant Kubernetes OS builds for highly regulated environments.
  • Resources
    • About usAbout us
      Sidero Labs® was born out of real-world experience of running Kubernetes in production. Read our story.
      Sidero Labs® was born out of real-world experience of running Kubernetes in production. Read our story.
    • Omni DocsOmni Docs
      From quick start tips & getting familiar with Omni, Omni Docs has everything you need
      From quick start tips & getting familiar with Omni, Omni Docs has everything you need
    • Case StudiesCase Studies
      See how organizations innovate and build better infrastructure across data center, cloud, and edge
      See how organizations innovate and build better infrastructure across data center, cloud, and edge
    • Talos DocsTalos Docs
      From quick start tips & getting familiar with Talos, to meeting the community, Talos Docs has you covered.
      From quick start tips & getting familiar with Talos, to meeting the community, Talos Docs has you covered.
    • Blog & NewsBlog & News
      Discover the latest news on Talos Linux, Omni, and Kubernetes
      Discover the latest news on Talos Linux, Omni, and Kubernetes
    • Learning resourcesLearning resources
      Talos Linux and Omni resources, all in one place.
      Talos Linux and Omni resources, all in one place.
    • PartnersPartners
      Our ecosystem of partners enable Kubernetes across bare metal, data center, edge, AI, and private cloud
      Our ecosystem of partners enable Kubernetes across bare metal, data center, edge, AI, and private cloud
    • CareersCareers
      Help shape the future of Kubernetes,
      Help shape the future of Kubernetes,
PricingContactTry OmniBook a DemoTry Omni On-Prem
PricingContactTry OmniBook a DemoTry Omni On-Prem

Case Studies

Equinix switches from KubeSpray to Talos Linux, cutting deployment time while maintaining security

EdgeEdgeLocationGlobalRetailRetail
Equinix case study feature

Equinix is the world’s digital infrastructure company, with over 250 data centers worldwide, covering 27 countries, 5 continents, and $7 billion in revenue.

Challenge

  • Time-consuming upgrades and deployments
  • Thin SRE resources

Environment

  • 250 Data Centers
Impact

Impact

  • Fully retired Kubespray
  • Faster deployments and upgrades
  • Improved operability
Question

Why Sidero and Omni

  • Declarative configuration
  • Minimal attack surface
  • API-based management
Challenge

Growth outpaces the team, and Kubespray can’t keep up

Jorik Jonker’s DevOps team at Equinix offers managed Kubernetes and other managed services to enterprise customers who want to focus on security and compliance. Their initial managed Kubernetes offering was built on Kubespray and Flatcar, but as adoption scaled up, their team did not. They faced complications as they ran Kubespray alongside a system of very convoluted Ansible scripts and upgrades and deployments took a lot of time, tying up the SREs for too long. Equinix knew they had to become more efficient.

In 2019, Equinix found Talos Linux and liked its declarative configuration, reduced attack surface, and API management. However, they were concerned by how different Talos Linux was compared to their previous experiences. They also needed to prove security compliance for their enterprise customers and were unsure how to do this with Talos Linux, so they decided to continue using Kubespray for as long as they could.

Solution

A clean break from Kubespray and Ansible

Eventually, Equinix chose to do a proof of concept with Talos Linux. They found that, because Talos Linux only does Kubernetes and is API managed, it is architecturally simple and fast.

It was settled. Equinix knew Talos Linux would work for them, and they wanted to give the team time to practice and get acquainted with it. Equinix scheduled for team members to deploy Talos Linux while someone with experience broke the deployment, providing each individual with real-world experience of working with Talos Linux. Within hours, the team was comfortable with the new Operating System.

Equinix chose to build their first product, a new generation of their managed Kubernetes service,  on Talos Linux.

The next step was setting up proof of compliance for their clients. They use Kubebench to assess their platform against CIS hardening guidelines. Initially, Kubebench reported some tests as failed, as it could not determine that some files and packages were set with limited permissions or disabled on Talos Linux. This was problematic because such files did not even exist within Talos Linux; thus, Kubebench was not able to process the information properly. Equinix submitted patches to Kubebench and resolved all the false positives and submitted PRs so that the Dutch government security compliance standards would correctly recognize Talos Linux as secure.

Equinix has now end-of-life’d their Kubespray Kubernetes offering and is solely supporting their Talos Linux-based Kubernetes product.

Results

Deployments drop from 45 Minutes to 10

With Talos Linux, Equinix has reduced the time to deploy Kubernetes on virtual machines from 45 minutes to less than 10. They have also significantly reduced the time required for upgrades, allowing them to iterate releases faster. Now, when there is an issue that needs troubleshooting, they can simply replace a node to make things work. You can’t do that with Kubespray. Talos Linux encourages you to address infrastructure as cattle, which has systematic advantages in all parts of operations.

This article is based on the talk Jorik gave at TalosCon 2023.

Thanks for reading!

Sidero Labs, the creator of Talos Linux and Omni, focuses on bringing simplicity and security to Kubernetes on bare metal, data center, edge, and hybrid cloud.

Try OmniBook a demo
  • Omni
  • Talos Linux
  • Support and services
  • Omni data center
  • Omni edge
  • Talos Docs
  • Omni Docs
  • Learning resources
  • News & Insight
  • About us
  • Partners
  • Contact
  • FAQ

Address:

5662 Calle Real #471
Goleta CA 93117

Get in touch:

e: info@SideroLabs.com
t: (888) 488-2567

Sidero Footer
  • GitHub
  • LinkedIn
  • X
  • BlueSky
  • YouTube
© 2026 Sidero Labs, Inc - All Rights ReservedPrivacy PolicyTerms & Conditions