Summary
talos/talconfig.yaml pins factory.talos.dev/installer/7c9e329e408b058e4bdb5e18e4af75eed95d5b53944d6024fa59f8fa235e1741 on all three nodes, but the schematic that produced that hash exists nowhere in git — docs/architecture.md mentions iscsi-tools/util-linux-tools in prose only. Rebuilding or auditing the node image requires out-of-repo knowledge.
Proposed work
- Commit
talos/schematic.yaml; deterministically verify it regenerates the pinned ID (talhelper can compute the ID offline via --offline-mode).
- Document the rebuild/audit path in the talos README or architecture doc.
Note: no Renovate wiring — schematic IDs are content-derived, so there is no upstream release for Renovate to track.
Acceptance criteria
Summary
talos/talconfig.yamlpinsfactory.talos.dev/installer/7c9e329e408b058e4bdb5e18e4af75eed95d5b53944d6024fa59f8fa235e1741on all three nodes, but the schematic that produced that hash exists nowhere in git —docs/architecture.mdmentionsiscsi-tools/util-linux-toolsin prose only. Rebuilding or auditing the node image requires out-of-repo knowledge.Proposed work
talos/schematic.yaml; deterministically verify it regenerates the pinned ID (talhelper can compute the ID offline via--offline-mode).Note: no Renovate wiring — schematic IDs are content-derived, so there is no upstream release for Renovate to track.
Acceptance criteria
talconfig.yaml(or the delta is documented).