Releases: katl-dev/katl
Release list
KatlOS 2026.8.0-beta.3
Support boundary
This is an experimental beta release for home-lab evaluation, not a production-supported release. Read SUPPORT.md before installation for the tested surface, trust and compatibility limits, recovery scope, and required issue evidence.
Changes
- katlctl: retain shutdown poll authentication (#215) (
d8b62a0) - agent: require management mTLS (#214) (
6b44021)
Verify downloads
Release assets have keyless GitHub build-provenance attestations. See PROVENANCE.md for verification instructions and scope.
Full comparison: v2026.8.0-beta.2...v2026.8.0-beta.3
KatlOS 2026.8.0-beta.2
Support boundary
This is an experimental beta release for home-lab evaluation, not a production-supported release. Read SUPPORT.md before installation for the tested surface, trust and compatibility limits, recovery scope, and required issue evidence.
Changes
- storage: bind volumes to exact identities (#213) (
0b8ae7f) - kubernetes: use config as upgrade authority (#212) (
ebea916) - networking: keep CNI links outside fallback DHCP (#211) (
ab61e1d) - security: bind mutations to enrolled nodes (#210) (
c66a8f8)
Verify downloads
Release assets have keyless GitHub build-provenance attestations. See PROVENANCE.md for verification instructions and scope.
Full comparison: v2026.8.0-beta.1...v2026.8.0-beta.2
KatlOS 2026.8.0-beta.1
Support boundary
This is an experimental beta release for home-lab evaluation, not a production-supported release. Read SUPPORT.md before installation for the tested surface, trust and compatibility limits, recovery scope, and required issue evidence.
Changes
- agent: clean identity on dispatch failure (
35d8709) - bootstrap: retry repaired operations (
d76c860) - kubernetes: remove failed identity staging (
8804347) - kubernetes: preserve identity on reprovision (
d72ec7b) - docs: publish operator journeys (
6a610a9) - vmtest: assert durable bootstrap health (
6c1415f) - installer: keep automatic handoff alive (
16c2335) - installer: make pxe handoff safe (
4f2ae3b) - bootstrap: validate the durable generation (
cc73e1e) - lifecycle: resume node replacement safely (
b7da08a) - etcd: transfer leadership through the leader (
da3128a) - runtime: stop endpoint services natively (
cdbf40b) - installer: enable configured debug ssh (
13dd737) - katldev: reset managed-save vms cleanly (
680ce68) - generation: revalidate recovered fallback boots (
251b66a) - generation: reconcile known-good fallback boots (
335f57d) - generation: prove live candidates on boot (
d04331c) - kubernetes: make upgrade generations bootable (
20d263c) - docs: make cni ownership explicit (
dfb5bd4) - runtime: give root shells the kubeadm context (
66a695a) - kubernetes: keep upgrade discovery node-local (
a9c4ac5) - config: aggregate validation diagnostics (#207) (
0ec60a0) - config: clarify Kubernetes networking ownership (#206) (
dc39825) - config: name storage volumes explicitly (#205) (
3ed9774) - storage: preserve data when removing volumes (#204) (
2655e27) - config: report extension pins everywhere (#203) (
a6480e3) - config: pin system-extension selection (#202) (
55dca9d) - config: require explicit kubernetes version (#201) (
5f2fced) - config: support per-node kubelet policy (#200) (
51c23a4) - config: refuse cross-node diffs (#199) (
3c5a293) - config: expose effective node inspection (#198) (
5d625b6) - storage: require operation-scoped wipe authority (#197) (
490906c) - storage: restrict defaults to safe policy (#196) (
9ea7bb4) - lifecycle: enforce explicit node transitions (#195) (
7282ad3) - config: generate accurate clusterconfig schema (#194) (
f139896) - config: report public validation paths (#193) (
ee8ad4d) - config: make node defaults predictable (#192) (
9c8aa3e) - storage: support live disk and partition volumes (#190) (
8300072) - kubernetes: select exact node address (#189) (
ede7fcd) - network: leave cni routes unmanaged (#188) (
fbc9c1a) - network: use file sets for networkd config (#187) (
144cbfe) - release: bound kubernetes bundle automation (#186) (
9796a99)
Verify downloads
Release assets have keyless GitHub build-provenance attestations. See PROVENANCE.md for verification instructions and scope.
Full comparison: v2026.7.0-beta.14...v2026.8.0-beta.1
KatlOS 2026.7.0-beta.14
Support boundary
This is an experimental beta release for home-lab evaluation, not a production-supported release. Read SUPPORT.md before installation for the tested surface, trust and compatibility limits, recovery scope, and required issue evidence.
Changes
- config: add typed sysfs settings (#185) (
229cccc) - config: add boot-time host overlays (#184) (
4ba55f0) - katldev: reserve pci capacity for extra disks (#183) (
4fd5153) - release: record supported Kubernetes compatibility (#182) (
9434a40) - installer: verify extra disk filesystem support (#181) (
da70a9b) - installer: mount managed extra disks after boot (#180) (
717cc78) - installer: isolate katlos image metadata (#179) (
64b15be) - bootstrap: make wait polling test deterministic (#178) (
d3dcad7) - release: record supported Kubernetes compatibility (#177) (
57489f7) - ci: approve required generated pr checks (#176) (
6cda6fe) - release: record supported Kubernetes compatibility (#175) (
a794f93) - ci: require kubernetes producer validation (#174) (
8e4f2a3) - release: record supported Kubernetes compatibility (#173) (
643462f) - ci: validate kubernetes bundles before merge (#172) (
cdefe77) - release: record supported Kubernetes compatibility (#171) (
8285107) - config: support custom kernel arguments (#170) (
5ae0191) - boot: include firmware and cpu microcode (#169) (
11f275d) - docs: define firmware and microcode support (#168) (
3c095de) - ci: gate immutable extension publication (#167) (
b7a483b) - oci: pack release-sized payloads (#166) (
14f7181) - extensions: support user-owned bundles (#165) (
801c8dc) - Sysext adr (#164) (
a0a9393) - katldev: generate vm cluster config (#163) (
8913005) - endpoint: decouple vip from bird lifecycle (#162) (
5d973c2) - docs: document cilium on immutable hosts (
9779f38) - cluster: retain desired kubeadm state (#160) (
35f5328) - kubernetes: support control-plane replacement (#159) (
9ef5f0c) - release: scope kubernetes bundle rebuilds (#158) (
77c80ec) - release: record supported Kubernetes compatibility (#157) (
9b9e333) - config: complete host configuration journeys (#156) (
67a7c0f) - release: record supported Kubernetes compatibility (#155) (
71ed821) - endpoint: migrate legacy VIP routing during upgrade (#154) (
c16059f) - docs: require katldev user journeys (#153) (
8536ef7) - release: record supported Kubernetes compatibility (#152) (
2608edb) - config: add native host configuration sets (#151) (
b1c4ef9) - docs: accept native host configuration file sets (#150) (
18dedcc) - release: record supported Kubernetes compatibility (#149) (
c308133) - release: approve generated catalog checks (#148) (
37f00c7) - release: record supported Kubernetes compatibility (#147) (
087317b) - release: retire superseded compatibility prs (#146) (
8745025) - release: record supported Kubernetes compatibility (#145) (
4bcb3d9) - release: link kubernetes bundles upstream (#144) (
73001df) - networking: route VIP only from healthy control planes (#142) (
3271003) - release: record supported Kubernetes compatibility (#140) (
d2beca3) - release: publish inspected kubernetes bundles (#139) (
8d250a3) - release: restore kubernetes sysext builds (#138) (
d2d7d38)
Verify downloads
Release assets have keyless GitHub build-provenance attestations. See PROVENANCE.md for verification instructions and scope.
Full comparison: v2026.7.0-beta.13...v2026.7.0-beta.14
KatlOS 2026.7.0-beta.13
Support boundary
This is an experimental beta release for home-lab evaluation, not a production-supported release. Read SUPPORT.md before installation for the tested surface, trust and compatibility limits, recovery scope, and required issue evidence.
Changes
- wipe: prove pre-bootstrap control-plane reinstall (
656ea76) - upgrade: reject unsafe sources before acceptance (
fb50be4) - cluster: skip kubeadm apply before bootstrap (
6fee5c5) - upgrade: honor the kubelet activation gate (
12ec1bd) - upgrade: keep kubelet on a healthy api path (
647703c) - upgrade: keep kubeadm on a healthy api path (
9e1ccd4) - katldev: validate local kubernetes generations (
2b857b4) - katldev: preserve kubernetes artifact identity (
fdb760b) - upgrade: deliver local kubernetes artifacts (
3e6991c) - upgrade: preserve single control plane access (
3a1831d) - upgrade: drain api connections before stacked etcd (
b242c6e) - kubeadm: declare the default service network (
3da88a2) - console: ignore tty control signals (
8a8b73d) - kubeadm: generate a usable default network (
fc5fcf1) - agents: preserve failed-state evidence (
cdb9cff) - bootstrap: preserve manifest failure recovery (
7294f78) - bootstrap: inherit observed node generations (
0eb0409) - ssh: repair invalid persistent host keys (
48d7b9c) - upgrade: use kubeadm state for host updates (
ad71e2a) - wipe: recover control planes before bootstrap (
bf6cac7) - config: tolerate absent pre-bootstrap kubelet (
63f1f9f) - installer: reuse verified image mounts (
38e0975) - installer: allow safe handoff retries (
89ac719) - release: align default artifact assertion (
e408f27) - release: refresh synchronized root inputs (
aa7c1e7) - bootstrap: reload systemd after extensions (
1580bac) - release: refresh synchronized root inputs (
de42c35) - upgrade: verify synchronized root slots (
8bda972) - vmtest: keep implicit kubernetes inputs resolvable (
4311abb) - release: refresh upgrade recovery inputs (
d09580a) - upgrade: accept passive optional route exchange (
e2a0b57) - upgrade: wait for kubernetes recovery (
0064eee) - release: refresh routing inputs (
0506008) - routing: tolerate transient api probe stalls (
cffe335) - release: refresh wipe journey inputs (
0dd2d8e) - wipe: power off successfully reset nodes (
66f4ce3) - release: expect refreshed bundle revision (
dac556a) - release: refresh kubernetes rebuild inputs (
0d3f8e2) - kubeadm: compare kubelet durations semantically (
2250894) - cli: report cluster apply progress (
9e78489) - docs: sharpen katldev journey verification (
77a3d7d) - release: make bundle retries deterministic (
079b75d) - release: build every supported kubernetes bundle (
3b6dac6) - release: declare supported kubernetes versions (
6b531d8) - release: select kubernetes v1.36.2 inputs (
0e62f3a) - routing: withdraw workload paths before power loss (#124) (
f5a4a44)
Verify downloads
Release assets have keyless GitHub build-provenance attestations. See PROVENANCE.md for verification instructions and scope.
Full comparison: v2026.7.0-beta.12...v2026.7.0-beta.13
KatlOS 2026.7.0-beta.12
Support boundary
This is an experimental beta release for home-lab evaluation, not a production-supported release. Read SUPPORT.md before installation for the tested surface, trust and compatibility limits, recovery scope, and required issue evidence.
Changes
- upgrade: recover streaming rpc status (#123) (
ba2af39) - build: snapshot runtime boot artifacts (#122) (
0159c99) - upgrade: stream local katlos artifacts (#121) (
5a63678) - tests: stop requiring worktree-local mkosi caches (
3512799) - agents: require katldev ux journeys (
a70695d) - kubernetes: make cluster config reapply idempotent (
ad9cf7a) - kubernetes: reconcile cluster configuration online (
d99cb83) - katldev: share mkosi caches across worktrees (
2aa0e1b) - kubernetes: apply declared labels after bootstrap (
8305dad) - katldev: build current checkout iso (
8c58cf5) - kubernetes: report topology roles in upgrades (
3d00dc5) - console: report kubernetes health reliably (#119) (
9e08103)
Verify downloads
Release assets have keyless GitHub build-provenance attestations. See PROVENANCE.md for verification instructions and scope.
Full comparison: v2026.7.0-beta.11...v2026.7.0-beta.12
KatlOS 2026.7.0-beta.9
Support boundary
This is an experimental beta release for home-lab evaluation, not a production-supported release. Read SUPPORT.md before installation for the tested surface, trust and compatibility limits, recovery scope, and required issue evidence.
Changes
Verify downloads
Release assets have keyless GitHub build-provenance attestations. See PROVENANCE.md for verification instructions and scope.
Full comparison: v2026.7.0-beta.8...v2026.7.0-beta.9
KatlOS 2026.7.0-beta.11
Support boundary
This is an experimental beta release for home-lab evaluation, not a production-supported release. Read SUPPORT.md before installation for the tested surface, trust and compatibility limits, recovery scope, and required issue evidence.
Changes
Verify downloads
Release assets have keyless GitHub build-provenance attestations. See PROVENANCE.md for verification instructions and scope.
Full comparison: v2026.7.0-beta.10...v2026.7.0-beta.11
KatlOS 2026.7.0-beta.10
Support boundary
This is an experimental beta release for home-lab evaluation, not a production-supported release. Read SUPPORT.md before installation for the tested surface, trust and compatibility limits, recovery scope, and required issue evidence.
Changes
Verify downloads
Release assets have keyless GitHub build-provenance attestations. See PROVENANCE.md for verification instructions and scope.
Full comparison: v2026.7.0-beta.9...v2026.7.0-beta.10
KatlOS 2026.7.0-beta.8
Support boundary
This is an experimental beta release for home-lab evaluation, not a production-supported release. Read SUPPORT.md before installation for the tested surface, trust and compatibility limits, recovery scope, and required issue evidence.
Changes
Verify downloads
Release assets have keyless GitHub build-provenance attestations. See PROVENANCE.md for verification instructions and scope.
Full comparison: v2026.7.0-beta.7...v2026.7.0-beta.8