feat(talosctl,omni): volumes belongs to talosctl; omni mints the talosconfig #2
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "talosctl-owns-volumes"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The disk layout is a Talos fact, so volumes now lives only on dataverket/talosctl/node and the copied layout module in omni is gone. omni gains talosconfig: mints one cluster admin talosconfig for the service account and stores it as a resource with a sensitive content field. talosctl gains a sensitive talosconfigContent argument materialized into a private temp file per call. Wired by CEL in fabrikk-infra. Adversarially reviewed, findings folded in. Published as 2026.09.19.2.