feat(talosctl,omni): volumes belongs to talosctl; omni mints the talosconfig #2

Merged
beddari merged 1 commit from talosctl-owns-volumes into main 2026-09-19 20:11:34 +00:00
Owner

The disk layout is a Talos fact, so volumes now lives only on dataverket/talosctl/node and the copied layout module in omni is gone. omni gains talosconfig: mints one cluster admin talosconfig for the service account and stores it as a resource with a sensitive content field. talosctl gains a sensitive talosconfigContent argument materialized into a private temp file per call. Wired by CEL in fabrikk-infra. Adversarially reviewed, findings folded in. Published as 2026.09.19.2.

The disk layout is a Talos fact, so volumes now lives only on dataverket/talosctl/node and the copied layout module in omni is gone. omni gains talosconfig: mints one cluster admin talosconfig for the service account and stores it as a resource with a sensitive content field. talosctl gains a sensitive talosconfigContent argument materialized into a private temp file per call. Wired by CEL in fabrikk-infra. Adversarially reviewed, findings folded in. Published as 2026.09.19.2.
The disk layout is a Talos fact, so the volumes method now lives only on
@dataverket/talosctl/node, and the copied layout module in omni goes away.
omni gains a talosconfig method: it mints one cluster's admin talosconfig
for the service account in a private temporary directory, removes it, and
stores the content as a talosconfig resource with a sensitive content
field. talosctl gains a sensitive talosconfigContent global argument that
the transport materializes into a private temporary file per invocation
and removes afterwards; it wins over the talosconfig path, an empty string
counts as unset, and the content is redacted from errors. The two are
wired by CEL: nodes from the discovered node records, content from the
talosconfig resource, key from the vault. Reviewed adversarially; the
findings (all-field vaulting from sensitiveOutput, temp file mode, README
drift, migration note, precedence tests) are folded in. 2026.09.19.2.
beddari deleted branch talosctl-owns-volumes 2026-09-19 20:11:34 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dataverket/swamp-extensions!2
No description provided.