A community member added Niklaus Wirth’s RISC5 Oberon workstation to Cozystack as a one-click app — using the pluggable-catalog and KubeVirt sidecar mechanisms, with no fork of Cozystack or KubeVirt.
CVE-2026-53359 (“Januscape”) is a KVM guest-to-host escape affecting all current Talos kernels. Cozystack clusters that run VMs or tenant Kubernetes should disable nested virtualization now.
Cozystack 1.3 brings storage-aware pod scheduling, a managed LINSTOR GUI, a curated VM image catalog, application-level observability, and cross-namespace VM backup restore.