CLI Usage
Configuration Reference
Documentation for basic configuration parameters.http
HTTP configuration for the image factory frontend.
http.httpListenAddr
- Type:
string - Env:
HTTP_HTTPLISTENADDR
http.certFile
- Type:
string - Env:
HTTP_CERTFILE
http.keyFile
- Type:
string - Env:
HTTP_KEYFILE
http.externalURL
- Type:
string - Env:
HTTP_EXTERNALURL
http.externalPXEURL
- Type:
string - Env:
HTTP_EXTERNALPXEURL
http.allowedOrigins
- Type:
[]string - Env:
HTTP_ALLOWEDORIGINS
build
Options for building assets used in images, including concurrency and Talos version constraints.
build.minTalosVersion
- Type:
string - Env:
BUILD_MINTALOSVERSION
build.brokenTalosVersions
- Type:
[]string - Env:
BUILD_BROKENTALOSVERSIONS
build.maxConcurrency
- Type:
int - Env:
BUILD_MAXCONCURRENCY
containerSignature
ContainerSignature holds configuration for verifying container image signatures.
containerSignature.subjectRegExp
- Type:
string - Env:
CONTAINERSIGNATURE_SUBJECTREGEXP
containerSignature.issuerRegExp
- Type:
string - Env:
CONTAINERSIGNATURE_ISSUERREGEXP
containerSignature.issuer
- Type:
string - Env:
CONTAINERSIGNATURE_ISSUER
containerSignature.publicKeyFile
- Type:
string - Env:
CONTAINERSIGNATURE_PUBLICKEYFILE
containerSignature.publicKeyHashAlgo
- Type:
string - Env:
CONTAINERSIGNATURE_PUBLICKEYHASHALGO
containerSignature.disabled
- Type:
bool - Env:
CONTAINERSIGNATURE_DISABLED
cache
Cache contains configuration for storing and retrieving boot assets.
cache.oci
OCI contains configuration for using OCI Registry to store cached assets.
This configuration is required.
cache.oci.registry
- Type:
string - Env:
CACHE_OCI_REGISTRY
ghcr.io.
This is where images are stored.
cache.oci.namespace
- Type:
string - Env:
CACHE_OCI_NAMESPACE
sidero-labs.
Some registries allow repositories without a namespace.
cache.oci.repository
- Type:
string - Env:
CACHE_OCI_REPOSITORY
talos.
Combined with Registry and Namespace, it forms the fully qualified repository path.
cache.oci.insecure
- Type:
bool - Env:
CACHE_OCI_INSECURE
cache.signingKeyPath
- Type:
string - Env:
CACHE_SIGNINGKEYPATH
cache.gsa
GSA contains configuration for Google Service Account keyless signing via Sigstore.
When set, GSA-based keyless signing is used instead of a static key.
Mutually exclusive with SigningKeyPath.
cache.gsa.serviceAccountEmail
- Type:
string - Env:
CACHE_GSA_SERVICEACCOUNTEMAIL
cache.gsa.keyFile
- Type:
string - Env:
CACHE_GSA_KEYFILE
cache.gsa.fulcioURL
- Type:
string - Env:
CACHE_GSA_FULCIOURL
cache.gsa.rekorURL
- Type:
string - Env:
CACHE_GSA_REKORURL
cache.gsa.tsaURL
- Type:
string - Env:
CACHE_GSA_TSAURL
cache.cdn
CDN contains configuration for using a CDN to serve cached assets.
cache.cdn.host
- Type:
string - Env:
CACHE_CDN_HOST
cache.cdn.trimPrefix
- Type:
string - Env:
CACHE_CDN_TRIMPREFIX
cache.cdn.enabled
- Type:
bool - Env:
CACHE_CDN_ENABLED
cache.s3
S3 contains configuration for using S3 to store cached assets.
cache.s3.bucket
- Type:
string - Env:
CACHE_S3_BUCKET
cache.s3.endpoint
- Type:
string - Env:
CACHE_S3_ENDPOINT
cache.s3.region
- Type:
string - Env:
CACHE_S3_REGION
cache.s3.insecure
- Type:
bool - Env:
CACHE_S3_INSECURE
cache.s3.enabled
- Type:
bool - Env:
CACHE_S3_ENABLED
cache.s3.presignedURLTTL
- Type:
time.Duration - Env:
CACHE_S3_PRESIGNEDURLTTL
cache.schematic
Schematic contains configuration for caching schematic blobs.
cache.schematic.capacity
- Type:
uint64 - Env:
CACHE_SCHEMATIC_CAPACITY
cache.schematic.negativeTTL
- Type:
time.Duration - Env:
CACHE_SCHEMATIC_NEGATIVETTL
metrics
Metrics holds configuration for the Prometheus metrics endpoint.
metrics.addr
- Type:
string - Env:
METRICS_ADDR
secureBoot
SecureBoot contains configuration for generating SecureBoot-enabled assets.
secureBoot.file
File specifies file-based SecureBoot keys and certificates.
secureBoot.file.signingKeyPath
- Type:
string - Env:
SECUREBOOT_FILE_SIGNINGKEYPATH
secureBoot.file.signingCertPath
- Type:
string - Env:
SECUREBOOT_FILE_SIGNINGCERTPATH
secureBoot.file.pcrKeyPath
- Type:
string - Env:
SECUREBOOT_FILE_PCRKEYPATH
secureBoot.azureKeyVault
AzureKeyVault configures SecureBoot using Azure Key Vault.
secureBoot.azureKeyVault.url
- Type:
string - Env:
SECUREBOOT_AZUREKEYVAULT_URL
secureBoot.azureKeyVault.certificateName
- Type:
string - Env:
SECUREBOOT_AZUREKEYVAULT_CERTIFICATENAME
secureBoot.azureKeyVault.keyName
- Type:
string - Env:
SECUREBOOT_AZUREKEYVAULT_KEYNAME
secureBoot.awsKMS
AWSKMS configures SecureBoot using AWS KMS.
secureBoot.awsKMS.keyID
- Type:
string - Env:
SECUREBOOT_AWSKMS_KEYID
secureBoot.awsKMS.pcrKeyID
- Type:
string - Env:
SECUREBOOT_AWSKMS_PCRKEYID
secureBoot.awsKMS.certPath
- Type:
string - Env:
SECUREBOOT_AWSKMS_CERTPATH
secureBoot.awsKMS.certARN
- Type:
string - Env:
SECUREBOOT_AWSKMS_CERTARN
secureBoot.awsKMS.region
- Type:
string - Env:
SECUREBOOT_AWSKMS_REGION
secureBoot.enabled
- Type:
bool - Env:
SECUREBOOT_ENABLED
artifacts
Artifacts defines names and references for various images used by the factory.
artifacts.core
Core contains configuration for core images used by the image factory.
artifacts.core.registry
- Type:
string - Env:
ARTIFACTS_CORE_REGISTRY
artifacts.core.namespace
- Type:
string - Env:
ARTIFACTS_CORE_NAMESPACE
artifacts.core.components
Components defines the names of images used by the image factory.
This typically maps to repositories and tags for core components.
artifacts.core.components.installerBase
- Type:
string - Env:
ARTIFACTS_CORE_COMPONENTS_INSTALLERBASE
artifacts.core.components.installer
- Type:
string - Env:
ARTIFACTS_CORE_COMPONENTS_INSTALLER
artifacts.core.components.imager
- Type:
string - Env:
ARTIFACTS_CORE_COMPONENTS_IMAGER
artifacts.core.components.extensionManifest
- Type:
string - Env:
ARTIFACTS_CORE_COMPONENTS_EXTENSIONMANIFEST
artifacts.core.components.overlayManifest
- Type:
string - Env:
ARTIFACTS_CORE_COMPONENTS_OVERLAYMANIFEST
artifacts.core.components.talosctl
- Type:
string - Env:
ARTIFACTS_CORE_COMPONENTS_TALOSCTL
artifacts.core.components.imageFactory
- Type:
string - Env:
ARTIFACTS_CORE_COMPONENTS_IMAGEFACTORY
artifacts.core.insecure
- Type:
bool - Env:
ARTIFACTS_CORE_INSECURE
artifacts.schematic
Schematic is the OCI repository used to store schematic blobs required by the image factory for building images.
artifacts.schematic.registry
- Type:
string - Env:
ARTIFACTS_SCHEMATIC_REGISTRY
ghcr.io.
This is where images are stored.
artifacts.schematic.namespace
- Type:
string - Env:
ARTIFACTS_SCHEMATIC_NAMESPACE
sidero-labs.
Some registries allow repositories without a namespace.
artifacts.schematic.repository
- Type:
string - Env:
ARTIFACTS_SCHEMATIC_REPOSITORY
talos.
Combined with Registry and Namespace, it forms the fully qualified repository path.
artifacts.schematic.insecure
- Type:
bool - Env:
ARTIFACTS_SCHEMATIC_INSECURE
artifacts.installer
Installer contains configuration for storing and accessing installer images.
artifacts.installer.internal
Internal is the internal OCI registry used by the image factory to push installer images.
artifacts.installer.internal.registry
- Type:
string - Env:
ARTIFACTS_INSTALLER_INTERNAL_REGISTRY
ghcr.io.
This is where images are stored.
artifacts.installer.internal.namespace
- Type:
string - Env:
ARTIFACTS_INSTALLER_INTERNAL_NAMESPACE
sidero-labs.
Some registries allow repositories without a namespace.
artifacts.installer.internal.repository
- Type:
string - Env:
ARTIFACTS_INSTALLER_INTERNAL_REPOSITORY
talos.
Combined with Registry and Namespace, it forms the fully qualified repository path.
artifacts.installer.internal.insecure
- Type:
bool - Env:
ARTIFACTS_INSTALLER_INTERNAL_INSECURE
artifacts.installer.external
External is the public OCI registry used for redirects to installer images.
If this field is not set, Image Factory will proxy requests to the internal registry
through itself instead of issuing HTTP redirects to the external registry endpoint.
artifacts.installer.external.registry
- Type:
string - Env:
ARTIFACTS_INSTALLER_EXTERNAL_REGISTRY
ghcr.io.
This is where images are stored.
artifacts.installer.external.namespace
- Type:
string - Env:
ARTIFACTS_INSTALLER_EXTERNAL_NAMESPACE
sidero-labs.
Some registries allow repositories without a namespace.
artifacts.installer.external.repository
- Type:
string - Env:
ARTIFACTS_INSTALLER_EXTERNAL_REPOSITORY
talos.
Combined with Registry and Namespace, it forms the fully qualified repository path.
artifacts.installer.external.insecure
- Type:
bool - Env:
ARTIFACTS_INSTALLER_EXTERNAL_INSECURE
artifacts.talosVersionRecheckInterval
- Type:
time.Duration - Env:
ARTIFACTS_TALOSVERSIONRECHECKINTERVAL
artifacts.refreshInterval
- Type:
time.Duration - Env:
ARTIFACTS_REFRESHINTERVAL
authentication
Authentication settings.
Note: only available in the Enterprise edition.
authentication.enabled
- Type:
bool - Env:
AUTHENTICATION_ENABLED
authentication.provider
- Type:
string - Env:
AUTHENTICATION_PROVIDER
authentication.htpasswdPath
- Type:
string - Env:
AUTHENTICATION_HTPASSWDPATH
authentication.auth0
Auth0 holds configuration for the Auth0 JWT authentication provider.
Tokens must carry a non-empty string in the custom if_org_id claim,
which becomes the caller identity in the same way a username does for htpasswd.
Auth0’s native org_id claim is not read.
It is required when provider is “auth0”, and ignored otherwise.
Domain and audience alone validate bearer tokens.
The browser-login fields are optional, and add the sign-in routes on top when set.
authentication.auth0.domain
- Type:
string - Env:
AUTHENTICATION_AUTH0_DOMAIN
mycompany.auth0.com.
Required.
authentication.auth0.audience
- Type:
string - Env:
AUTHENTICATION_AUTH0_AUDIENCE
https://image-factory.example.com.
Required.
authentication.auth0.clientID
- Type:
string - Env:
AUTHENTICATION_AUTH0_CLIENTID
authentication.auth0.clientSecret
- Type:
string - Env:
AUTHENTICATION_AUTH0_CLIENTSECRET
authentication.auth0.sessionKey
- Type:
string - Env:
AUTHENTICATION_AUTH0_SESSIONKEY
openssl rand -base64 32.
Surrounding whitespace is trimmed, so a file or mounted secret with a trailing newline works.
All replicas must share the same key, since a session or in-progress login started
on one replica has to be decrypted by whichever replica handles the next request.
Optional; part of the browser-login group.
authentication.tokens
Tokens holds configuration for self-issued API token management.
authentication.tokens.keyPaths
- Type:
[]string - Env:
AUTHENTICATION_TOKENS_KEYPATHS
authentication.tokens.storage
Storage is the base OCI repository under which stored token records are persisted; presence of a record is what makes such a token valid.
Each provider-resolved principal gets its own repository beneath it, holding one tag per token,
so a listing costs one principal’s tokens rather than every token in the deployment.
A token minted with “stored”: false is not recorded, so it cannot be listed or revoked and does not count against MaxPerOrg.
authentication.tokens.storage.registry
- Type:
string - Env:
AUTHENTICATION_TOKENS_STORAGE_REGISTRY
ghcr.io.
This is where images are stored.
authentication.tokens.storage.namespace
- Type:
string - Env:
AUTHENTICATION_TOKENS_STORAGE_NAMESPACE
sidero-labs.
Some registries allow repositories without a namespace.
authentication.tokens.storage.repository
- Type:
string - Env:
AUTHENTICATION_TOKENS_STORAGE_REPOSITORY
talos.
Combined with Registry and Namespace, it forms the fully qualified repository path.
authentication.tokens.storage.insecure
- Type:
bool - Env:
AUTHENTICATION_TOKENS_STORAGE_INSECURE
authentication.tokens.ttl
TTL bounds token lifetimes by whether they are stored, plus the CLI-only bootstrap policy.
authentication.tokens.ttl.stored
Stored bounds revocable tokens persisted in the configured OCI repository.
authentication.tokens.ttl.stored.max
- Type:
time.Duration - Env:
AUTHENTICATION_TOKENS_TTL_STORED_MAX
authentication.tokens.ttl.stored.min
- Type:
time.Duration - Env:
AUTHENTICATION_TOKENS_TTL_STORED_MIN
authentication.tokens.ttl.stored.default
- Type:
time.Duration - Env:
AUTHENTICATION_TOKENS_TTL_STORED_DEFAULT
authentication.tokens.ttl.ephemeral
Ephemeral bounds tokens with no per-token list or revoke operation.
They normally leave circulation through expiry;
removing a verification key retires every token signed by that key.
authentication.tokens.ttl.ephemeral.max
- Type:
time.Duration - Env:
AUTHENTICATION_TOKENS_TTL_EPHEMERAL_MAX
authentication.tokens.ttl.ephemeral.min
- Type:
time.Duration - Env:
AUTHENTICATION_TOKENS_TTL_EPHEMERAL_MIN
authentication.tokens.ttl.ephemeral.default
- Type:
time.Duration - Env:
AUTHENTICATION_TOKENS_TTL_EPHEMERAL_DEFAULT
authentication.tokens.ttl.bootstrap
Bootstrap bounds the CLI-only cross-subject credential.
It is never stored and may live longer than ordinary ephemeral tokens because it is kept
offline and retired by removing its signing key from KeyPaths.
authentication.tokens.ttl.bootstrap.max
- Type:
time.Duration - Env:
AUTHENTICATION_TOKENS_TTL_BOOTSTRAP_MAX
authentication.tokens.ttl.bootstrap.min
- Type:
time.Duration - Env:
AUTHENTICATION_TOKENS_TTL_BOOTSTRAP_MIN
authentication.tokens.ttl.bootstrap.default
- Type:
time.Duration - Env:
AUTHENTICATION_TOKENS_TTL_BOOTSTRAP_DEFAULT
authentication.tokens.refreshInterval
- Type:
time.Duration - Env:
AUTHENTICATION_TOKENS_REFRESHINTERVAL
authentication.tokens.maxPerOrg
- Type:
int - Env:
AUTHENTICATION_TOKENS_MAXPERORG
enterprise
Enterprise contains configuration for enterprise-specific features.
enterprise.extraExtensions
ExtraExtensions contains configuration for extra (custom) extensions.
enterprise.extraExtensions.manifest
Manifest specifies the OCI repository holding the extra extensions manifest image.
It may live in a different registry than the official images.
enterprise.extraExtensions.manifest.registry
- Type:
string - Env:
ENTERPRISE_EXTRAEXTENSIONS_MANIFEST_REGISTRY
ghcr.io.
This is where images are stored.
enterprise.extraExtensions.manifest.namespace
- Type:
string - Env:
ENTERPRISE_EXTRAEXTENSIONS_MANIFEST_NAMESPACE
sidero-labs.
Some registries allow repositories without a namespace.
enterprise.extraExtensions.manifest.repository
- Type:
string - Env:
ENTERPRISE_EXTRAEXTENSIONS_MANIFEST_REPOSITORY
talos.
Combined with Registry and Namespace, it forms the fully qualified repository path.
enterprise.extraExtensions.manifest.insecure
- Type:
bool - Env:
ENTERPRISE_EXTRAEXTENSIONS_MANIFEST_INSECURE
enterprise.scanner
Scanner contains configuration for the vulnerability scanner.
enterprise.scanner.databaseURL
- Type:
string - Env:
ENTERPRISE_SCANNER_DATABASEURL
enterprise.scanner.databaseUpdateAt
- Type:
string - Env:
ENTERPRISE_SCANNER_DATABASEUPDATEAT
enterprise.scanner.databaseRootDir
- Type:
string - Env:
ENTERPRISE_SCANNER_DATABASEROOTDIR
enterprise.scanner.cache
Cache contains configuration for caching vulnerability scan results.
enterprise.scanner.cache.ttl
- Type:
time.Duration - Env:
ENTERPRISE_SCANNER_CACHE_TTL
enterprise.scanner.cache.capacity
- Type:
uint64 - Env:
ENTERPRISE_SCANNER_CACHE_CAPACITY
enterprise.spdx
SPDX contains configuration for SPDX document generation.
enterprise.spdx.cache
enterprise.spdx.cache.registry
- Type:
string - Env:
ENTERPRISE_SPDX_CACHE_REGISTRY
ghcr.io.
This is where images are stored.
enterprise.spdx.cache.namespace
- Type:
string - Env:
ENTERPRISE_SPDX_CACHE_NAMESPACE
sidero-labs.
Some registries allow repositories without a namespace.
enterprise.spdx.cache.repository
- Type:
string - Env:
ENTERPRISE_SPDX_CACHE_REPOSITORY
talos.
Combined with Registry and Namespace, it forms the fully qualified repository path.
enterprise.spdx.cache.insecure
- Type:
bool - Env:
ENTERPRISE_SPDX_CACHE_INSECURE
enterprise.vex
VEX contains configuration for VEX data fetching.
enterprise.vex.data
Data specifies the OCI repository where VEX documents are stored.
enterprise.vex.data.registry
- Type:
string - Env:
ENTERPRISE_VEX_DATA_REGISTRY
ghcr.io.
This is where images are stored.
enterprise.vex.data.namespace
- Type:
string - Env:
ENTERPRISE_VEX_DATA_NAMESPACE
sidero-labs.
Some registries allow repositories without a namespace.
enterprise.vex.data.repository
- Type:
string - Env:
ENTERPRISE_VEX_DATA_REPOSITORY
talos.
Combined with Registry and Namespace, it forms the fully qualified repository path.
enterprise.vex.data.insecure
- Type:
bool - Env:
ENTERPRISE_VEX_DATA_INSECURE
enterprise.vex.cache
Cache contains configuration for caching VEX documents.
enterprise.vex.cache.ttl
- Type:
time.Duration - Env:
ENTERPRISE_VEX_CACHE_TTL
enterprise.vex.cache.capacity
- Type:
uint64 - Env:
ENTERPRISE_VEX_CACHE_CAPACITY
registry
Registry contains low-level tuning for the registry client (pull/push concurrency, debugging).
registry.jobs
- Type:
int - Env:
REGISTRY_JOBS
registry.debug
- Type:
bool - Env:
REGISTRY_DEBUG
audit
Audit configures the audit log of authenticated requests.
audit.mode
- Type:
string - Env:
AUDIT_MODE
audit.file
File configures the “file” audit sink.
audit.file.path
- Type:
string - Env:
AUDIT_FILE_PATH