An Omni infrastructure provider that provisions Talos Linux VMs on OpenStack. It automatically manages the full lifecycle: uploading Talos images to Glance, creating Nova instances, and cleaning up on deprovisioning.
- An Omni account
omnictlCLI installed- An OpenStack cloud with API access (Nova, Glance, Neutron)
- OpenStack application credentials
- Docker (to run the provider)
omnictl infraprovider create openstackThis outputs the service account key. Save it to a .env file.
Create application credentials in your OpenStack dashboard (Identity > Application Credentials) or via CLI:
openstack application credential create omni-infra-provider --unrestrictedSave the OpenStack credentials to the .env file. You should have the following environment variables.
OS_AUTH_URL=https://your-openstack:5000
OS_APPLICATION_CREDENTIAL_ID=<credential-id>
OS_APPLICATION_CREDENTIAL_SECRET=<credential-secret>
OS_REGION_NAME=RegionOnedocker run -d --name omni-infra-provider-openstack \
--env-file .env \
ghcr.io/rothgar/omni-infra-provider-openstack:latest --os-insecureRemove
--os-insecureif your OpenStack endpoint has a valid TLS certificate.
Create a file machineclass.yaml:
metadata:
namespace: default
type: MachineClasses.omni.sidero.dev
id: openstack
spec:
autoprovision:
providerid: openstack
providerdata: |
flavor: gen2.medium
network: ExternalSet flavor and network to match your OpenStack environment. Apply it:
omnictl apply -f machineclass.yamlCreate a file cluster-template.yaml:
kind: Cluster
name: my-cluster
kubernetes:
version: v1.35.3
talos:
version: v1.13.0
---
kind: ControlPlane
machineClass:
name: openstack
size: 1
---
kind: Workers
name: workers
machineClass:
name: openstack
size: 2Apply it:
omnictl cluster template sync -f cluster-template.yamlThe provider will automatically:
- Generate a Talos schematic
- Upload the Talos OpenStack image to Glance (cached for reuse)
- Create Nova instances with the correct flavor, network, and cloud-init config
- Report machine status back to Omni
| Flag | Env Var | Description |
|---|---|---|
--omni-api-endpoint |
OMNI_ENDPOINT |
Omni API endpoint |
--omni-service-account-key |
OMNI_SERVICE_ACCOUNT_KEY |
Omni service account key |
--os-auth-url |
OS_AUTH_URL |
OpenStack Keystone auth URL |
--os-application-credential-id |
OS_APPLICATION_CREDENTIAL_ID |
Application credential ID |
--os-application-credential-secret |
OS_APPLICATION_CREDENTIAL_SECRET |
Application credential secret |
--os-region-name |
OS_REGION_NAME |
OpenStack region |
--os-insecure |
Skip TLS verification for OpenStack API | |
--insecure-skip-verify |
Skip TLS verification for Omni API | |
--id |
Provider ID (default: openstack) |
|
--provider-name |
Display name in Omni UI (default: OpenStack) |
The providerdata in the machine class supports:
| Field | Type | Required | Description |
|---|---|---|---|
flavor |
string | yes | OpenStack flavor name (e.g., m1.large, gen2.medium) |
network |
string | yes | OpenStack network name or UUID |
To delete a cluster and its VMs:
omnictl cluster template delete -f cluster-template.yamlThe provider will automatically delete the Nova instances. Glance images are left cached for future use.
# Build binary
make build
# Build container
make docker-build
# Run locally
make run