Secure virtualization · Announced
The Kubernetes OS now runs your virtual machines.
The immutable, audit-ready host that runs your Kubernetes now runs your VMs. Minimal attack surface, no drift, one mTLS API to secure and audit. Native hypervisor, no KubeVirt, no general-purpose OS underneath.
Hypervisor availability Alpha at TalosCon, Oct 15–16 · GA December 2026
One host · all workloads
bare metal · edge · data center
Two separate platforms, now one host.
Secure by architecture
Immutable host. Mutable guests.
The same principles that made Talos exceptional for Kubernetes now apply at the VM layer, so a traditional hypervisor’s attack surface simply isn’t there.
Attack surface
Binaries, not gigabytes
No general-purpose OS underneath. No shell, no package manager, no SSH. A host that ran thousands of binaries now runs a few dozen.
No drift
Every host identical
Same image, same API, same lifecycle across every host. No configuration divergence over time, no new lock-in to replace the old one.
Declarative
Managed as code
The whole machine state is declarative, applied over a mutual-TLS API. Version it, review it, roll it back. No config tooling, no console clicking.
One audit trail
One surface to monitor
Every action on every resource, container or VM, flows through one secured API. One place for compliance to look, one surface for security to watch.
Two ways to run it
Open source first. Enterprise when you answer to auditors.
The hypervisor ships as part of Talos Linux: free, open source, and production-ready. Enterprise mode adds the support and supply-chain assurance regulated teams need, on the same host.
Same host · same OS
Open-source mode and Enterprise mode run the identical immutable Talos host. Enterprise adds support and assurance, not a separate stack.
Open-source mode · MPL-2.0
Talos Linux for Hypervisor
Free, open source, part of Talos Linux.
- Run and manage VMs across a fleet of hosts
- Schedule containers at the edge, no Kubernetes
- Declarative placement, storage, and networking
- The Talos security posture, extended to your VMs
Enterprise modeNew
Talos Enterprise Linux for Hypervisor
The same host, with support and supply-chain assurance.
- 24/7 enterprise support with CVE SLAs
- Schematic-specific SBOMs, curated VEX, signed attestations
- FIPS 140-3 compliant builds
- Commercial IP indemnity
Proven foundation
The host under all of this is already in production at scale.
- 320+Talos clusters at Nokia
- 130kcores on Talos Linux
- ~⅓the cost of public cloud
- ~1Mdownloads / year
“Talos is faster, lighter, and does what it is supposed to, and nothing else.”
Why one platform
Two systems. One host.
Kubernetes and a separate hypervisor mean two security models, two audit surfaces, two attack surfaces to defend. Talos runs both on one immutable, audit-ready OS, under one mTLS API.
The two-platform overhead
What it costs you today
- Duplicate tooling and duplicate expertise
- Two patching cycles, two audit surfaces
- A general-purpose hypervisor OS to patch and defend
- VMs and Kubernetes that never quite align
One platform
What Talos changes
- One OS your platform team already runs
- One mTLS API your security team audits
- Containers or VMs, consistent infrastructure
- Move to containers on your own timeframe
No new lock-in
Open by architecture. Portable by design.
An open-source core, standard formats, and hardware you already own mean the platform never holds leverage over you. Stay because it works, not because leaving is hard.
Open source core
Inspect it, build it, run it
Talos Linux is MPL-2.0, forever. The source is public, the build is reproducible, and the community edition is unchanged by any commercial release.
Your hardware
No certified-hardware tax
Run on commodity servers you already own: bare metal, edge, data center. No approved-hardware list, no appliance margin built into the price.
Standard formats
Portable by default
VMs use standard KVM. Containers use standard OCI images. Nothing proprietary in the data path, so you can move workloads to another platform any time.
One API
Automate end to end
Every machine state is declared and applied over a mutual-TLS API. Script it, version it, audit it. No console clicking, no tribal knowledge.
For the community
Free stays free.
Talos Linux is open source under MPL-2.0, and it stays that way. The hypervisor and Enterprise tier add capabilities on top of the same code. Nothing is closed off or gated. Same project, same principles, more ways to run it in production.
- Talos Linux
- Talos Linux for Hypervisor
- Talos Enterprise Linux for Hypervisor
TalosCon Amsterdam · October 15–16
See the hypervisor live.
The alpha and the first public demo land at TalosCon. Come watch Talos run a VM, or get notified the moment it ships. General availability follows in December 2026.