Automic Vault

brew package intelligence

talosctl

Automic Vault tracks talosctl because plain text talos client config matters when AI agents run command-line tools on macOS.

overview

What Automic Vault knows about talosctl

CLI for out-of-band management of Kubernetes nodes created by Talos

Homepage

Not present in the local metadata.

Commands and aliases

No executable aliases were found in the local package database.

radioisotope

Plain Text Talos Client Config

talosctl stores cluster client configuration in ~/.talos/config by default. The file can contain client certificate, private key, CA, and basic auth material. Our isotope stores the talosconfig in the macOS keychain and injects it through a temporary TALOSCONFIG path while `talosctl` runs.

Local README excerpt

talosctl

talosctl reads its client configuration from ~/.talos/config by default. That talosconfig can contain client certificate, private key, CA, and basic auth material for Talos clusters.

This radioisotope migrates the default talosconfig to the keychain and wraps talosctl so it is recreated under a temporary home and selected with TALOSCONFIG while the CLI runs.

Source: data/radioisotopes/talosctl/README.md

Caveats

  • Runtime talosconfig changes are not persisted back to keychain.
  • Direct execution of the original binary will not receive credentials.

install metadata

Resolver facts

Package keybrew:talosctl
Last updated2026-05-12T19:29:10Z
Pulseupdated

source trail

Generated from repository data

This page is regenerated by scripts/generate-pkg-pages.py. Deployments refuse to publish if www/pkg/ is stale relative to local package data.

Used sources

  • Nucleus package database
  • local isotope README
  • radioisotope security manifest