Project Lightning Talk: What’s New In Kairos, 2026 Edition - Mauro Morales, Maintainer
About this talk
This talk introduces Kyros, a project that transforms Linux systems into immutable image-based systems, focusing on containerized environments like Kubernetes. The speaker, Mauro Morales, highlights the flexibility of Kyros, which supports various Linux distributions and Kubernetes configurations, including K3s and K8s. Key features discussed include trusted boot technology for enhanced security and the ability to perform seamless upgrades and rollbacks, especially important for edge and cloud applications. The speaker shares real-world use cases, such as Deep Network's secure devices and Arya Imaging's agricultural solutions, which rely on Kyros for consistent and manageable deployments. Notable updates to the project include the introduction of Kairos init for easy image conversion, the Kairos factory for generating bootable artifacts, and the future development of a new Linux distribution aimed at Kubernetes workloads. The session concludes with an invitation for further inquiries and information at the project pavilion booth.
Full transcript
Hello everyone. Yeah, my name is Mauro Morales and I am one of the maintainers at the project Kyros. We are a sandbox project. We're currently at version 4.03 and I bring you some of the updates that have happened. But first of all, let me share a little bit what Kyros is. Basically, you take Linux systems and you through Kyros you transform them into immutable image-based systems. You
can get an Ubuntu and an openSUSE and make them immutable. It's declarative and container-based. So, you keep using the same tools that you're already using with Kubernetes. And it's focused on Linux and Kubernetes workloads. At the moment, you can pick between K3s and K8s by default, but there are also community providers that allow you to do also other Kubernetes distributions. So, if you can see, we're very
flexible in terms of Linux distribution, Kubernetes And the main goal of Kyros is to make day-two operations very easy. That means upgrades, rollbacks. If you need to reset a node, so that you can do it whether you're on edge, whether you're on cloud, etc. Two examples that I have to share of what our community is using Kyros for. On the bottom, you can see Deep Network. They
sell these devices that give you access to their network. And you can imagine that if you're given a device with that much access to someone, you really want to make sure that they cannot just tamper with the operating system. They are using one feature that we call trusted boot that uses through TPM measured uh the kernel, the initramfs, ensuring that you really only can have the systems
that you have signed with your own keys. And that's what gives them the sleep at night, Um, safety to uh, sleep at night, know, uh, knowing they're not going to get their assistance uh, attacked. Uh, and another example that I have up there is Arya Imaging. They are uh, putting these devices on tractors to uh, um, analyze uh, trees and know where to spray them. And they're
using Kairos to be able to uh, deliver um, on Nvidia uh, boards uh, to be sure that they always have the same images that they can roll back easily and and the these kind of uh, things. We have a session uh, on Thursday if you want to know more about that. I'll have more details later. Uh, what's kind of newish in the project? Uh, first of all,
Kairos init, it's one-liner. You take your Dockerfile, just put what you want uh, uh, on this system and it helps you convert that image into a Kairos ready image. Uh, the Kairos factory um, is uh, basically uh, making it easy for you to generate bootable artifacts, that is ISOs, raw images, cloud images based on those Kairos images that I mentioned uh, just before. And last but not
least, the Kairos operator which allows you to uh, perform system operations from your Kubernetes cluster. That means that from Kubernetes you can uh, upgrade your nodes, so the operating system within uh, your node can be all done through um, And what's new new uh, or the thing that we're uh, promoting a lot and and and sharing with you guys is that after uh, dealing with so many
different Linux distributions, we also decided, hey, we're going to come up with our own Linux distribution because why not, right? Um, uh, there are obviously big reasons why we're doing this. I don't have the time to share that right now, but if you want to come to the booth, uh, uh, we're definitely um, have some time there to tell you why we've uh, created this uh, minimal
upstream uh, focused uh, system that is meant to run Kubernetes but do it in an image-based immutable way. Last but not least, we have our first external maintainer. I would like to say welcome and thank you to William Rizzo for being part of the maintainer team at Kyros. He is known on GitHub as WR code. He's field CTO Mirantis and he's going to be working on Kyros
Cappy feature at the moment. I don't know if you have met William but he's a fantastic guy so I'm very excited to have him there in the team. yes, so if you want to know any more information like I was saying we're at the project pavilion booth 18A tomorrow morning and Thursday afternoon and we have a session on Thursday at 13:45 in the auditorium called Cloud Native
at the Farm Edge where we're going to talk how together with Arya Imaging we use Kyros for the project I was mentioning that they use on farming. Those are the links and if you see me on the hallway, please stop by and say hi and I'm happy to talk to you about Kyros. Thank you very much. Thank you, sir.
More from this event
See all 436 talks →
Best of KubeCon + CloudNativeCon Amsterdam 2026
2:17
The Quiet Work of Forever: Sustaining Open Source Communities - O. Hope Amaechi-Okorie, JSON Schema
26:24
Evolving KServe: The Unified Model Inference Platform for Both Predictive and... F. Spolti & J. Lee
32:40
Preventing S3 Cost Storms: Applying Cortex’s Efficiency Lessons to I/O-Heav... A. Fishman-Lichterman
5:32