Talos Linux
Install the StackRadar scanner on Talos Linux: get a kubeconfig with talosctl, install the Helm chart, and get a CycloneDX SBOM and ranked findings per image.
Talos is an immutable, API-managed Kubernetes OS with no shell and no SSH. That changes nothing for the scanner, which is an ordinary in-cluster workload: it reads the Kubernetes API, pulls images, and uploads SBOMs. Talos’s default Pod Security Admission (restricted, enforced on every namespace except kube-system) admits the chart’s defaults as-is.
Prerequisites
- A Talos cluster and talosctl configured for it.
- Helm 3.8+ and kubectl.
- A free StackRadar account.
Point kubectl at your Talos Linux cluster
bashtalosctl kubeconfig ~/.kube/talos.yaml export KUBECONFIG=~/.kube/talos.yaml kubectl get nodesInstall the scanner
Create a cluster in the StackRadar dashboard and copy its cluster ID and cluster-scoped API key (see API keys & cluster scoping):
bashexport STACKRADAR_API_KEY=<your-api-key> export STACKRADAR_CLUSTER_ID=<your-cluster-id>Then install the scanner chart (Helm 3.8+ for the OCI method). The command pins the current release,
0.3.0— published versions are immutable, so the install is reproducible.bashhelm install stackradar-scanner \ oci://ghcr.io/lockdep/charts/stackradar-scanner \ --version 0.3.0 \ --namespace stackradar --create-namespace \ --set stackradar.apiKey=$STACKRADAR_API_KEY \ --set stackradar.clusterId=$STACKRADAR_CLUSTER_IDVerify
bashkubectl get pods --namespace stackradarOnce the pod is
Running, the scanner sends a heartbeat and the cluster shows as connected in the dashboard. SBOMs for running workloads follow within a few minutes. If the cluster never connects, see Troubleshooting.
Talos notes
- Pod Security: Talos enforces the restricted profile by default. The scanner’s non-root, read-only, no-capabilities defaults satisfy it, so no namespace label changes are needed.
- Registry mirrors configured in the Talos machine config (machine.registries) apply to the node’s containerd, not to the scanner. The scanner pulls images by their pod-spec reference over the network, so if a mirror is the only route to a registry, set proxy.noProxy or a dockerConfigSecret accordingly.
- Ephemeral storage: Talos nodes often run with small EPHEMERAL partitions. The chart requests 1Gi ephemeral storage and limits at 6Gi for image scratch; if pods are evicted for disk pressure, lower watcher.scratchSizeLimit.
Images from a private registry? The scanner pulls each image itself and reuses the imagePullSecrets your pods declare. If your nodes authenticate some other way, give the scanner a credential via dockerConfigSecret — see authenticating to a private registry. No public egress at all? Same page: restricted-network installs.
What happens after install
The scanner reports the cluster's workload inventory first — namespaces, workloads, containers, plus the Helm releases and GitOps applications that deliver them — so the dashboard shows every discovered workload and its scan coverage right away. Its first pass covers the whole cluster, not just new deploys: the initial sync lists every pod already running, and each container image is queued for scanning immediately. The scanner generates a CycloneDX SBOM per image and uploads it for matching against 900K+ OSV.dev advisories, then keeps coverage current as pods start, restart, or change — no scan schedules to configure. See architecture & data flow for what runs where and exactly what data leaves the cluster.
Next steps
- Architecture & data flowHow the StackRadar scanner works: what runs in your cluster, exactly what data leaves it, how SBOMs are matched to vulnerabilities, and where data is stored.
- TroubleshootingFixes for common StackRadar scanner issues: 401/403 API errors, a cluster that never appears in the dashboard, Helm install failures, and missing SBOMs.