Air-gapped Kubernetes
Run clusters securely and reliably without internet access. With support for internal registries and pre-seeded installation media, you maintain full control over your environment, meet regulatory requirements, and ensure operations continue even in isolated or highly restricted networks.
Kernel hardening with KSPP defaults
Out-of-the-box alignment with Linux Kernel Self-Protection Project standards delivers stronger memory protection, blocks unprivileged BPF, and prevents common attack vectors. Security by default with automatic safeguards that block attacks and protects your infrastructure for a more secure, resilient Kubernetes foundation.
Trusted Boot
Verifies every boot with signed, read-only images and Unified Kernel Images (UKI), creating a predictable, tamper-resistant state anchored by TPM. This ensures a predictable, tamper-resistant system state, giving you stronger security and confidence in your Kubernetes foundation.
Pod Security Admission (PSA) by default
Enforces Kubernetes baseline policies automatically, blocking insecure workloads and protecting your nodes. Stronger security without extra or manual configuration.
Kernel module signing
Guaranteed kernel integrity allowing only cryptographically trusted and signed modules, blocking tampered or unverified code and protecting runtime integrity at the system's most vulnerable layer.
OIDC and SAML authentication
Standards-based identity and access management that enables centralized, secure login across Kubernetes clusters and Talos Linux.
Audit logging
Automatically records every action in Omni, giving you full visibility, accountability, and compliance reporting without any extra setup.
Encrypted connectivity with WireGuard
End-to-end cluster traffic protection using encrypted WireGuard tunnels and default firewall rules via SideroLink, delivering secure communication without added complexity.