Skip to content Skip to footer

Talos OS Installation: Deploy a Production-Ready Kubernetes Cluster

Talos OS Installation: Deploy a Production-Ready Kubernetes Cluster

 

Series Part 2 Cloud-to-OnPrem Kubernetes Migration

Author: Zohair Diab | DevOps Engineer | K8s Migration Lab

Reading Time: ~5 minutes


Why Use Talos OS for Kubernetes? 

Talos OS is a modern, secure, minimal operating system designed specifically for Kubernetes. Unlike traditional Linux distributions, Talos is immutable, API-driven, and free of unnecessary components — making it lightweight, secure, and purpose-built for container orchestration.

🎯 Key Insight: Talos eliminates the “pets vs cattle” problem at the OS level. Every node is identical, declaratively managed, and can be replaced without manual intervention.

Core Benefits

FeatureDescription
ImmutabilityNo SSH, shell, or package manager — reducing attack surface and configuration drift
API-DrivenAll operations (upgrades, troubleshooting) use a secure API for automation and remote management
ConsistencyEvery node is identical and declaratively managed, ensuring predictable cluster behavior
SecurityMinimal footprint and locked down by default, following security best practices
Easy UpgradesSeamless, coordinated upgrades and rollbacks for both OS and Kubernetes via talosctl

 

Talos OS simplifies Kubernetes infrastructure management, letting you focus on workloads instead of nodes.


Preparing the Environment

In this guide, we will:

  • Deploy a 3-node Talos cluster in a Proxmox virtual environment
  • Bootstrap Kubernetes on the Talos cluster
  • Configure a Virtual IP to load balance requests to the Kubernetes API
  • Configure our local machine to access the Kubernetes API
  • Deploy and expose an NGINX web server on the cluster

Prerequisites

1 Download the Talos ISO

export TALOS_VERSION=v1.5.3
wget https://github.com/siderolabs/talos/releases/download/$TALOS_VERSION/metal-amd64.iso -O talos-$TALOS_VERSION-amd64.iso

Upload this ISO to your Proxmox storage for VM creation.

2 Provision Virtual Machines

Create at least one server or VM. For this demo, we’ll set up 3 VMs with the following specs:

ResourceSpecification
CPU8 cores per node
RAM16 GB per node
Boot Disk32 GB per node

3 Reserve IPs in DHCP

HostnameIP Address
cn-1194.36.139.201
cn-2194.36.139.202
cn-3194.36.139.203

Install talosctl

# Set Talos version
export TALOS_VERSION=v1.5.3

# Download binary
wget https://github.com/siderolabs/talos/releases/download/$TALOS_VERSION/talosctl-linux-amd64

# Make executable and move to PATH
chmod +x talosctl-linux-amd64
sudo mv talosctl-linux-amd64 /usr/local/bin/talosctl

# Verify installation
talosctl --version


Creating the Talos Configuration

Step 1: Generate Secrets Bundle

⚠️ Security Warning: The secrets file contains all sensitive information (keys, certificates). Never push this to git unencrypted. Use tools like sops for encryption.

talosctl gen secrets

Step 2: Generate Cluster Configuration

The talosctl gen config command requires two parameters:

  1. Cluster Name: Used for context switching (similar to kubectl contexts). We’ll use demo-cluster.
  2. Kubernetes Endpoint: The VIP for the Kubernetes API. Since our nodes are 194.36.139.201-203, we’ll use 194.36.139.210 for the VIP.
talosctl gen config demo-cluster https://194.36.139.200:6443 \
--with-secrets secrets.yaml \
--config-patch @patches/allow-controlplane-workloads.yaml \
--config-patch @patches/cni.yaml \
--config-patch @patches/dhcp.yaml \
--config-patch @patches/install-disk.yaml \
--config-patch @patches/interface-names.yaml \
--config-patch @patches/kubelet-certificates.yaml \
--config-patch-control-plane @patches/vip.yaml \
--output rendered/

This generates three files:

FilePurpose
controlplane.yamlMachine config for control-plane nodes
worker.yamlMachine config for worker nodes
talosconfigTalos equivalent of kubeconfig

Step 3: Apply Configuration to Nodes

talosctl apply -f rendered/controlplane.yaml -n 194.36.139.201 --insecure
talosctl apply -f rendered/controlplane.yaml -n 194.36.139.202 --insecure
talosctl apply -f rendered/controlplane.yaml -n 194.36.139.203 --insecure
 

💡 Note: talosctl follows the UNIX principle of “no output is good output.” Check the Proxmox VM console — status should change from Maintenance → Booting → Installing.


Configuring talosctl Access

Set Up the Configuration File

# Create .talos directory and copy config
mkdir -p ~/.talos
cp rendered/talosconfig ~/.talos/config

# Or use environment variable
export TALOSCONFIG=./rendered/talosconfig

Configure Endpoints

# Check current context
talosctl config contexts

# Set endpoints (load balances across all control plane nodes)
talosctl config endpoint 194.36.139.201 194.36.139.202 194.36.139.203

# Optionally set a default node
talosctl config node 194.36.139.201

Your context should now look like this:

CURRENT NAME ENDPOINTS NODES
* demo-cluster 194.36.139.201 194.36.139.202 194.36.139.203 194.36.139.201

Verify Cluster Members

talosctl get members -n 194.36.139.201

Expected output:

NODE NAMESPACE TYPE ID VERSION HOSTNAME MACHINE TYPE OS ADDRESSES
194.36.139.201 cluster Member talos-demo-01 2 talos-demo-01.mirceanton.local controlplane Talos (v1.5.4) ["194.36.139.201"]
194.36.139.201 cluster Member talos-demo-02 1 talos-demo-02.mirceanton.local controlplane Talos (v1.5.4) ["194.36.139.202"]
194.36.139.201 cluster Member talos-demo-03 1 talos-demo-03.mirceanton.local controlplane Talos (v1.5.4) ["194.36.139.203"]

Bootstrapping Kubernetes

Once all Talos nodes have booted and joined the cluster, we can install Kubernetes.

Open Dashboard (Optional but Recommended)

talosctl dashboard -n talos-demo-01

Bootstrap the Cluster

talosctl bootstrap -n talos-demo-01

Tip: It doesn’t matter which control-plane node you bootstrap from — all nodes are equal after the process completes.

Fetch kubeconfig

talosctl kubeconfig -n talos-demo-01

This creates ~/.kube/config automatically. You can now use kubectl:

kubectl get nodes

Success! Your Talos Kubernetes cluster is now running and accessible via kubectl.


What’s Next?

With Kubernetes running on Talos, you’re ready for the next steps:

  • Part 3: Installing Rook-Ceph for distributed storage
  • Part 4: Cilium networking and network policies
  • Part 5: Velero backup configuration

References


Questions or feedback? Drop a comment below or reach out on LinkedIn. Happy learning! 

Leave a Comment