---
title: "Read-Only Immutable OS with Ephemeral Worker Nodes | Zero-Trust Architecture Canon"
description: "Ultra-secure container host architecture using Talos Linux, completely eliminating SSH, shells, local package managers, and writable root partitions in favor of immutable, ephemeral node lifecycles."
image: "https://tinycto.tv/assets/zero-trust/zero_trust_architectures_og.jpg"
canonicalUrl: "https://tinycto.tv/zero-trust/architectures/immutable-ephemeral-nodes-talos"
locale: "en"
---

# Read-Only Immutable OS with Ephemeral Worker Nodes (`zt-arch-12`)

> **Pillar**: APPLICATIONS_WORKLOADS | **Archetype**: RUNTIME_KERNEL_DEFENSE
> **Blocked MITRE ATT&CK Techniques**: T1543, T1053, T1556, T1548

## Architecture Summary

Ultra-secure container host architecture using Talos Linux, completely eliminating SSH, shells, local package managers, and writable root partitions in favor of immutable, ephemeral node lifecycles.

## Adversary Model

Adversary gains root execution inside a container and attempts to modify host binaries, install rootkits, or establish persistence on disk.

## NIST SP 800-207 Core Tenets

- The enterprise monitors and measures the integrity and security posture of all owned and associated assets.
- No asset is inherently trusted.

## 3-Tier Maturity Configurations

### INITIAL Maturity Target

- **Implementation Scope**: Standard Linux nodes hardened with CIS benchmarks and read-only container runtimes.
- **Authentication Enforcement**: SSH restricted to public key authentication via bastion host.
- **Network Isolation**: Standard cloud security groups.

### ADVANCED Maturity Target

- **Implementation Scope**: Talos Linux deployed across all Kubernetes worker nodes with zero SSH access.
- **Authentication Enforcement**: Mutual TLS API-only machine control plane using client certificates.
- **Network Isolation**: Strict kernel network namespace lockdown.

### OPTIMAL Maturity Target

- **Implementation Scope**: 100% ephemeral bare-metal/cloud nodes provisioned via declarative API, destroyed every 72 hours.
- **Authentication Enforcement**: TPM 2.0 Secure Boot with cryptographically signed UKI (Unified Kernel Image).
- **Network Isolation**: Host network disabled; all communications encapsulated in encrypted eBPF mesh.

## Terraform HCL Manifest

```hcl
resource "talos_machine_secrets" "this" {
  talos_version = "v1.7.0"
}

resource "talos_machine_configuration_apply" "worker" {
  client_configuration        = talos_machine_secrets.this.client_configuration
  machine_configuration_input = talos_machine_secrets.this.worker_machine_configuration
  node                        = "10.0.1.50"
}
```

## Kubernetes / Tetragon Policy Manifest

```yaml
apiVersion: v1
kind: Pod
metadata:
  name: secure-app
spec:
  securityContext:
    runAsNonRoot: true
    runAsUser: 10001
    fsGroup: 10001
    seccompProfile:
      type: RuntimeDefault
  containers:
  - name: app
    image: ghcr.io/tiny-cto/api:latest
    securityContext:
      readOnlyRootFilesystem: true
      allowPrivilegeEscalation: false
      capabilities:
        drop: ["ALL"]
```


```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Read-Only Immutable OS with Ephemeral Worker Nodes | Zero-Trust Architecture Canon",
  "description": "Ultra-secure container host architecture using Talos Linux, completely eliminating SSH, shells, local package managers, and writable root partitions in favor of immutable, ephemeral node lifecycles.",
  "url": "https://tinycto.tv/zero-trust/architectures/immutable-ephemeral-nodes-talos"
}
```
