For the latest version, please use Virtual Appliance 1.0.3!

Release Notes

Version 1.0.2

Date: 2026-10-07

This release introduces ERS Helm 3, Nitrokey HSM2 configuration and improvements to bundle uploads and platform reconciliation. The appliance update is the exact transition from 1.0.1 to 1.0.2 and requires Management 1.0.2.

ERS and HSM changes

Component 1.0.1 1.0.2

ERS Helm chart

2.1.0

3.0.0-rc.1

CARA

3.6.0

3.7.0

CLM and RIS

6.15.0

6.16.0

Management adds a Nitrokey option for an initialized Nitrokey HSM2, with a token serial and the appliance node to which the USB device is attached. All CARA replicas use the token on the selected node. Loss of that node or token interrupts HSM access, including on a three-node appliance.

Management improvements

  • Bundle uploads can run concurrently without disabling unrelated bundle actions. Each upload retains its own progress and cancellation controls.

  • Failed archive uploads display a request ID when the server supplies one, so the failure can be matched to diagnostics.

  • Management detects the previous ERS HSM configuration format and directs the operator to complete the appliance update before editing ERS settings.

Platform changes

  • Flux installs and maintains Kubernetes add-ons after networking and DNS bootstrap, including storage, certificate management and gateway components. Operator charts wait for their selected CRDs before advancing.

  • Database and namespace reconciliation retains state during ordinary GitOps removal. This does not protect against privileged direct deletion or replace backups.

  • Gateway rollouts create a replacement before removing the existing local endpoint.

  • Prometheus uses process signals to reload configuration and has a 120-second shutdown grace period.

Update requirements

Both single-node and clustered installations require a maintenance window for this update. There is no direct 1.0.0-to-1.0.2 update bundle.

Update Management to 1.0.2, then complete the appliance update before making other GitOps changes. Until the update converts the HSM values, Management cannot read the old ERS settings and Operations rejects ordinary GitOps publication. The update’s own publication runs after conversion.

Follow the update procedure and preserve the verified source recovery set. The update verifies the original 1.0.1 backup without rewriting it. Source backups remain recoverable with 1.0.1 release content; target backups require 1.0.2 release content. Keep both recovery sets with their matching release bundles.

The update loads changed offline content, replaces vendor declarations while retaining installation settings, and waits for the published configuration and workloads to converge. It retains explicit Retry for interrupted scripts or publication failures.

Version 1.0.1

Date: 2026-10-04

Published to the stable catalog.

This release refreshes the appliance platform and supplies the first published update bundle, for the exact transition from 1.0.0 to 1.0.1.

The minimum Management version remains 1.0.0.

Platform changes

The following table lists selected version changes. The versioned release inputs record the complete image and chart selections with their checksums and digests.

Component 1.0.0 1.0.1

Talos Linux

1.13.7

1.13.10

Kubernetes

1.36.3

1.36.4

CoreDNS

1.14.4

1.14.7

etcd

3.6.12

3.6.14

Cilium

1.20.0

1.20.1

Gateway API

1.5.1

1.6.2

NGINX Gateway Fabric

2.6.7

2.7.0

cert-manager

1.21.0

1.21.1

Garage

2.3.0

2.4.1

MariaDB

11.4.12

11.4.13

Prometheus

3.13.1

3.14.0

Grafana

13.1.1

13.2.1, distroless image

Loki

3.7.4

3.7.7

Alloy

1.18.0

1.19.2

Mimir

3.1.4

3.2.0

The ERS chart remains at 2.1.0, CARA at 3.6.0, CLM at 6.15.0 and Keycloak at 26.7.3.

Update from 1.0.0

The update bundle supplies the changed offline images and charts, including the matching Talos installers. Its numbered scripts update the platform, publish the target configuration, and verify component readiness before recording appliance version 1.0.1. The update preserves installation settings and selects the installer for the existing agentless, QEMU-agent or VMware-agent profile. Secure Boot configurations are outside this update’s supported installer profiles.

Follow the update procedure with Management 1.0.0 or a version explicitly qualified for this appliance. Keep the exact source recovery set outside Management and acknowledge it before applying the update. An interrupted script or failed publication requires explicit Retry. After completion, retain the new target backup and verify ERS access.

Single-node installations require maintenance. The published bundle declares that maintenance is not required for clustered installations.

Use the 1.0.1 release bundle for a fresh installation or recovery of a matching backup. A release bundle cannot replace the 1.0.0-to-1.0.1 update bundle.

Version 1.0.0

Date: 2026-09-15

First Release Scope

  • A separate Management VM boots from the Management ISO and keeps host and Management state on its dedicated disk.

  • Management also runs with Docker or Docker Compose on an operator workstation or an operator-created Linux VM. Operators supply and maintain the host, container runtime, networking, TLS and persistent storage.

  • Management installs the appliance from supplied release content and provides configuration, reconnection, ERS setup, HSM library administration, monitoring access and diagnostics.

  • Appliance backup configuration, completed-backup downloads, external publication and full recovery have dedicated operator workflows.

  • Release, update, artifact, backup, recovery and diagnostics bundles have distinct purposes and retention requirements.

Deploy Management using the Management ISO or Docker Compose, then follow appliance installation and verification.

Operator Actions

For Management ISO deployments, SSH is enabled with factory credentials for initial setup convenience. You must restrict SSH before first boot, configure it according to your organization’s policy, rotate the factory host credentials and verify persistence after reboot before production use. Follow Required ISO host SSH setup.

Retain the downloaded artifact bundle outside Management. Set up backups and protected external retention, record the deployed component identities and verify application access after ERS setup.

Management access is temporary. Keep the artifact bundle available for reconnection after access expiry or Management restart. Management loss and appliance loss use different recovery paths.

Compatibility and Update Paths

There is no upgrade path from an earlier released Virtual Appliance version because 1.0.0 is the first release. Migration from development media or state is not supported.

Use the supplied 1.0.0 release material to identify compatible Management media and embedded component versions. See components and version records. Full recovery requires the release bundle that matches the backed-up appliance release, together with its matching artifacts and compatible Management.

Operational Limits

  • The Management ISO remains attached and boots the host on every start. The state disk does not contain an installed host operating system.

  • The ISO provides no rollback workflow, Management password reset, or Management state-disk restore tool. Reconstruct Management for a surviving appliance with retained artifacts.

  • Full backups exclude metrics history, log history and Grafana’s local database and UI-created state. External HSM keys need separate protection.

  • Saving and publishing configuration do not confirm that workloads are healthy. Verify the affected service after changes.

  • Diagnostics retains only the latest temporary result. Download it before another collection or Management restart.

  • This manual does not define an individual-node replacement procedure. Contact support for that failure scenario.