Talos Commands
Common talosctl commands for debugging the Talos Linux cluster. Cluster lifecycle (apply, upgrade, reset) is handled by topf (mise exec -- topf ... from talos/pitower); talosctl complements it for read-only inspection and low-level operations.
Health Checks
Cluster Health
Check the overall health of the cluster, including etcd, kubelet, and API server status.
talosctl healthTarget a specific node:
talosctl health --nodes 10.20.10.1Node Dashboard
Open an interactive dashboard showing real-time CPU, memory, and service status for a node.
talosctl dashboardtalosctl dashboard --nodes 10.20.10.4Member List
List all cluster members as seen by Talos.
talosctl get membersJSON output (useful for scripting):
talosctl get members -o json | jq '.spec'Service Management
List Services
Show the status of all Talos services on a node.
talosctl services --nodes 10.20.10.1Service Logs
View logs for a specific Talos service (e.g., etcd, kubelet, apid, containerd).
# etcd logs
talosctl logs etcd --nodes 10.20.10.1
# kubelet logs
talosctl logs kubelet --nodes 10.20.10.1
# Follow logs in real time
talosctl logs etcd --nodes 10.20.10.1 -fService Status
Get detailed status for a specific service.
talosctl service etcd --nodes 10.20.10.1etcd Operations
Membership
List etcd cluster members and their status.
talosctl etcd members --nodes 10.20.10.1Etcd Status
Check etcd health and leadership.
talosctl etcd status --nodes 10.20.10.1Remove a Member
Remove a failed etcd member (use with caution).
talosctl etcd remove-member <member-id> --nodes 10.20.10.1Etcd Snapshot
Take a snapshot of the etcd database.
talosctl etcd snapshot etcd-backup.snapshot --nodes 10.20.10.1Kubeconfig
Refresh Kubeconfig
Generate a kubeconfig for kubectl access. mise.toml points KUBECONFIG at ~/.kube/pitower.yaml; do not write to ~/.kube/config, which is a different cluster.
talosctl kubeconfig ~/.kube/pitower.yaml --nodes 10.20.10.1just kubeconfig (topf) writes a short-lived (12h) admin kubeconfig to output/kubeconfig instead.
Configuration Inspection
View Running Config
Inspect the current machine configuration running on a node.
talosctl get machineconfig --nodes 10.20.10.1 -o yamlCompare Configs
Diff the running config against the declared state (redacted; exit 2 = changes pending):
mise exec -- topf apply --dry-run # all nodes
mise exec -- topf apply --dry-run --nodes-filter '^worker-01$' # one nodetopf render writes the full machine configs to output/ (gitignored) for inspection.
Version Information
Check the Talos version on a node.
talosctl version --nodes 10.20.10.1Resource Inspection
Kernel Logs (dmesg)
View kernel messages from a node.
talosctl dmesg --nodes 10.20.10.4Follow kernel messages:
talosctl dmesg --nodes 10.20.10.4 -fProcess List
List running processes on a node.
talosctl processes --nodes 10.20.10.1Disk Usage
Check disk usage on a node.
talosctl usage /var --nodes 10.20.10.1Container Images
List all container images on a node.
talosctl image list --nodes 10.20.10.1Network Interfaces
Show network interfaces and addresses.
talosctl get addresses --nodes 10.20.10.1Routes
Show routing table.
talosctl get routes --nodes 10.20.10.1Node Operations
Reboot
Reboot a node (with wait for it to come back).
talosctl reboot --nodes 10.20.10.4 --waitShutdown
Shut down a node.
talosctl shutdown --nodes 10.20.10.4Reset and Upgrade
Use topf for both, so the node ends up matching topf.yaml:
cd talos/pitower
mise exec -- topf reset --nodes-filter '^worker-04$' --full=false # or: just reset worker-04
mise exec -- topf upgrade --nodes-filter '^worker-04$'See Upgrades.
Troubleshooting Commands
Check Pod CIDR and Service CIDR
talosctl get machineconfig --nodes 10.20.10.1 -o yaml | grep -A3 -E 'podSubnets|serviceSubnets'
kubectl get nodes -o custom-columns=NAME:.metadata.name,PODCIDRS:.spec.podCIDRsCheck Certificate SANs
talosctl get certsan --nodes 10.20.10.1 -o yamlRead Machine Config Patches
talosctl get machineconfig --nodes 10.20.10.1 -o yamlCheck Time Sync
talosctl get timestatus --nodes 10.20.10.1Useful Aliases
Consider adding these aliases to your shell configuration:
alias tc='talosctl'
alias tcd='talosctl dashboard'
alias tch='talosctl health'
alias tcl='talosctl logs'
alias tcs='talosctl services'
alias tcm='talosctl get members'