Talos Linux
talos.dev
talos.dev
And so I opened your link to find out what it was about. Only to find it mentioning CAPI 2.0 which I only know from the ISDN days (https://en.wikipedia.org/wiki/Common_ISDN_Application_Progra...) and not as some form of I/O interface accelerator.
https://github.com/siderolabs/talos/releases/tag/v1.0.6
First time I have seen a project publish vmware-arm64.ova for ESXi arm edition.
Is it still possible to exec into a shell on a cluster node via something like https://github.com/kvaps/kubectl-node-shell ?
> Talos runs in memory from a SquashFS, and persists nothing, leaving the primary disk entirely to Kubernetes.
Hmm so if the entire disk is unused where is /boot in this configuration?
Unless we are talking about, like, a 100MB ramdisk, why is that a good thing?
And really, I'd prefer a 10MB ramdisk.
1. Learning. I want to self host to learn the stack top to bottom.
2. Build your own service.
3. Why not? (probably the best, most hackerish option)
> Especially considering that the managed offerings now fit most regulatory requirements (e.g. EKS is FedRAMP-High Authorized)?
Standards that meet regulatory requirements may not be updated or secure enough to meet private sector needs.
Edit: Was wrong, thanks for the correction.
[0] https://cloud.google.com/container-optimized-os/docs/concept...
That is strange. They aren't even some common base, CO-OS is literally based on Chromium OS.
CoreOS was too based on Chrome OS!
And Chrome OS is related to Gentoo Linux.
Or Ubuntu Eucalyptus?
(Neither is still with us. wonder why..)
So, no actual threat modelling, third party audits or integration and unit testing is done? Yes, that appears so.
https://www.talos.dev/v1.0/learn-more/philosophy/ "Security" section makes no mention of independent audits. It just boldly claims "There are no passwords in Talos" as if that was a panacea for security.
The existing integration tests don't verify any assumptions about security, only that the configuration is valid. Please correct me if I'm wrong or missed anything.
If you're going to call something "secure" you need to prove it.