---
title: "Read-Only Immutable OS with Ephemeral Worker Nodes | Zero-Trust Architecture Canon"
description: "SSH, kabuk (shell), paket yöneticisi ve yazılabilir kök dizini tamamen kaldırarak saldırı yüzeyini sıfırlayan Talos Linux tabanlı değiştirilemez ve geçici sunucu mimarisi."
image: "https://tinycto.tv/assets/zero-trust/zero_trust_architectures_og.jpg"
canonicalUrl: "https://tinycto.tv/tr/zero-trust/architectures/immutable-ephemeral-nodes-talos"
locale: "tr"
---

# Read-Only Immutable OS with Ephemeral Worker Nodes (`zt-arch-12`)

> **Sütun**: APPLICATIONS_WORKLOADS | **Arketip**: RUNTIME_KERNEL_DEFENSE
> **Engellenen MITRE ATT&CK Teknikleri**: T1543, T1053, T1556, T1548

## Mimari Özeti

SSH, kabuk (shell), paket yöneticisi ve yazılabilir kök dizini tamamen kaldırarak saldırı yüzeyini sıfırlayan Talos Linux tabanlı değiştirilemez ve geçici sunucu mimarisi.

## Saldırgan Modeli

Konteynerden ana makineye taşan saldırganın disk üzerine rootkit yüklemeye veya kalıcı arka kapı bırakmaya çalışması.

## NIST SP 800-207 Temel İlkeleri

- The enterprise monitors and measures the integrity and security posture of all owned and associated assets.
- No asset is inherently trusted.

## 3 Kademeli Olgunluk Yapılandırmaları

### INITIAL Seviyesi

- **Uygulama Kapsamı**: Standard Linux nodes hardened with CIS benchmarks and read-only container runtimes.
- **Kimlik Doğrulama Zorlaması**: SSH restricted to public key authentication via bastion host.
- **Ağ İzolasyonu**: Standard cloud security groups.

### ADVANCED Seviyesi

- **Uygulama Kapsamı**: Talos Linux deployed across all Kubernetes worker nodes with zero SSH access.
- **Kimlik Doğrulama Zorlaması**: Mutual TLS API-only machine control plane using client certificates.
- **Ağ İzolasyonu**: Strict kernel network namespace lockdown.

### OPTIMAL Seviyesi

- **Uygulama Kapsamı**: 100% ephemeral bare-metal/cloud nodes provisioned via declarative API, destroyed every 72 hours.
- **Kimlik Doğrulama Zorlaması**: TPM 2.0 Secure Boot with cryptographically signed UKI (Unified Kernel Image).
- **Ağ İzolasyonu**: Host network disabled; all communications encapsulated in encrypted eBPF mesh.

## Terraform HCL Manifest

```hcl
resource "talos_machine_secrets" "this" {
  talos_version = "v1.7.0"
}

resource "talos_machine_configuration_apply" "worker" {
  client_configuration        = talos_machine_secrets.this.client_configuration
  machine_configuration_input = talos_machine_secrets.this.worker_machine_configuration
  node                        = "10.0.1.50"
}
```

## Kubernetes / Tetragon Policy Manifest

```yaml
apiVersion: v1
kind: Pod
metadata:
  name: secure-app
spec:
  securityContext:
    runAsNonRoot: true
    runAsUser: 10001
    fsGroup: 10001
    seccompProfile:
      type: RuntimeDefault
  containers:
  - name: app
    image: ghcr.io/tiny-cto/api:latest
    securityContext:
      readOnlyRootFilesystem: true
      allowPrivilegeEscalation: false
      capabilities:
        drop: ["ALL"]
```


```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Read-Only Immutable OS with Ephemeral Worker Nodes | Zero-Trust Architecture Canon",
  "description": "SSH, kabuk (shell), paket yöneticisi ve yazılabilir kök dizini tamamen kaldırarak saldırı yüzeyini sıfırlayan Talos Linux tabanlı değiştirilemez ve geçici sunucu mimarisi.",
  "url": "https://tinycto.tv/tr/zero-trust/architectures/immutable-ephemeral-nodes-talos"
}
```
