Skip to main content
Talos Director is in Limited Availability. Limited Availability customers receive full production support and work directly with Sidero Labs engineering during onboarding. General availability is planned for January 2027, and the console is changing quickly until then, so details on these pages may differ from what you see.To request access, visit siderolabs.com/getdirector.
A virtual network in Talos Director is a VLAN carried on a bridge on every host. VM network interfaces attach to a virtual network, and because the network exists on all hosts, a VM keeps its connectivity when it migrates from one host to another, including between clusters. The Network section of the console also holds Talos Director’s firewalling (security groups, policies, and the policy simulator). Those are covered in Security.

The Networks view

Navigate to Network > Virtual Networks (/networks) to see every virtual network. The Networks view The controls above the table work like those on the other inventory views: Filter networks… (for example vlan:100), Export CSV, Columns, and Refresh, plus Import from ACI and Create Network.

Create a virtual network

Select Create Network and fill in the following fields. A new network is configured on every host in every cluster, so the physical switch ports your hosts connect to must carry the VLAN.
Changing a network’s VLAN ID or bridge means reconfiguring every host. Plan it as you would any change to the physical network the VMs depend on.

Import networks from Cisco ACI

If your data center runs Cisco ACI, Network > ACI Integration connects Talos Director to your APIC controllers, read-only. Enter the address of the first APIC controller, the fabric name, and a username and password, then select Test Connection. With Enable EPG Import as Talos Director Networks turned on, saving the configuration imports your ACI endpoint groups (EPGs) as virtual networks. You can also import them later with Import from ACI in the Networks view.

Services and tags

  • Network > Services defines named network services (a protocol and its ports) that firewall rules can refer to, instead of repeating port numbers in every rule.
  • Network > Tags manages the tags you attach to VMs. Security groups can select VMs by tag, so tagging a VM can be enough to put it under the right firewall policy.