> ## Documentation Index
> Fetch the complete documentation index at: https://siderolabs-fe86397c-config-evolution.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Time Servers

> Learn how to configure time servers (NTP sync).

export const VersionWarningBanner = () => {
  const latestVersion = "v1.13";
  const [latestUrl, setLatestUrl] = useState(null);
  const [currentVersion, setCurrentVersion] = useState(null);
  const [isBeta, setIsBeta] = useState(false);
  const parseVersion = v => v.replace("v", "").split(".").map(Number);
  const isGreaterVersion = (a, b) => {
    const [aMajor, aMinor] = parseVersion(a);
    const [bMajor, bMinor] = parseVersion(b);
    if (aMajor > bMajor) return true;
    if (aMajor === bMajor && aMinor > bMinor) return true;
    return false;
  };
  useEffect(() => {
    if (typeof window === "undefined") return;
    const {pathname, hash, search} = window.location;
    const match = pathname.match(/\/talos\/(v\d+\.\d+)\//);
    if (!match) return;
    const detectedVersion = match[1];
    if (detectedVersion === latestVersion) return;
    setCurrentVersion(detectedVersion);
    if (isGreaterVersion(detectedVersion, latestVersion)) {
      setIsBeta(true);
    }
    const newPath = pathname.replace(`/talos/${detectedVersion}/`, `/talos/${latestVersion}/`);
    setLatestUrl(`${newPath}${search}${hash}`);
  }, []);
  if (!latestUrl || !currentVersion) return null;
  return <div className="not-prose sticky top-6 z-50 my-6">
      <div className="border border-yellow-500/30 bg-yellow-500/10 px-4 py-3 rounded-xl">
        <div className="text-sm">
          {isBeta ? <>
              ⚠️ You are viewing a <strong>beta version</strong> of Talos ({currentVersion}).
              This version may be unstable.
              <a href={latestUrl} className="ml-2 underline text-yellow-400 hover:text-yellow-300 font-medium">
                View latest stable version {latestVersion} →
              </a>
            </> : <>
              ⚠️ You are viewing an older version of Talos ({currentVersion}).
              <a href={latestUrl} className="ml-2 underline text-yellow-400 hover:text-yellow-300 font-medium">
                View the latest version {latestVersion} →
              </a>
            </>}
        </div>
      </div>
    </div>;
};

<VersionWarningBanner />

Talos Linux defaults to using `time.cloudflare.com` as the NTP server for time synchronization, with [NTS](#network-time-security-nts) (Network Time Security) enabled.

## Configuration

To customize the NTP servers used by Talos, create a [TimeSyncConfig](../../reference/configuration/network/timesyncconfig) document like:

```yaml theme={null}
apiVersion: v1alpha1
kind: TimeSyncConfig
ntp:
    servers:
        - 0.pool.ntp.org
        - 1.pool.ntp.org
```

See [Time Sync](../../configure-your-talos-cluster/system-configuration/time-sync) for more details about time synchronization in Talos Linux.

## Network time security (NTS)

[NTS](https://datatracker.ietf.org/doc/html/rfc8915) authenticates NTP: the client performs a TLS key exchange with the time server, and the NTP packets themselves
are then cryptographically authenticated, so an on-path attacker can't tamper with the time a node receives.

NTS is used by default with the default time server (`time.cloudflare.com`) when no time server configuration is provided at all.
As soon as time servers are configured from any source, NTS is only used if it is explicitly enabled in the `TimeSyncConfig` document:

```yaml theme={null}
apiVersion: v1alpha1
kind: TimeSyncConfig
ntp:
    useNTS: true
    servers:
        - time.cloudflare.com
```

Time servers coming from other sources (DHCP, kernel arguments, platform metadata) are always queried over plain NTP.

Requirements and behavior when NTS is enabled:

* Every time server must be specified as a hostname, not as an IP address: the hostname is required to validate the server's TLS certificate.
  The machine configuration is rejected if an IP address is used, and time servers from other sources which are IP addresses are skipped with a warning.
* The key exchange runs over TCP to port `4460` of the time server (unless the server address specifies a different port), while NTP itself keeps using UDP port `123`
  (or the port negotiated during the key exchange), so both need to be allowed through the firewall.
* Server certificates are validated against the Talos trust store.
* Enabling or disabling NTS does not require a reboot: the time syncer is restarted when the setting changes.

See [Time Sync](../../configure-your-talos-cluster/system-configuration/time-sync#network-time-security-nts) for the way NTS is bootstrapped when the machine
clock is wrong at boot time.

> Note: NTS requires time server hostnames to be resolved, and [encrypted DNS](../host-dns#encrypted-dns-and-time-synchronization) (`DoT`/`DoH`) requires a correct
> clock to validate certificates.
> When every configured nameserver uses `DoT` or `DoH`, a machine which boots with a wrong clock cannot resolve its time servers, and cannot fix the clock either.
> Keep at least one plain DNS nameserver as a fallback in that case.

## Observing status

Use `talosctl` to get the current time synchronization configuration of a node:

```bash theme={null}
talosctl get timeservers
```

```text theme={null}
NODE         NAMESPACE   TYPE               ID            VERSION   TIMESERVERS                USENTS
172.20.0.2   network     TimeServerStatus   timeservers   1         ["time.cloudflare.com"]    true
```

To see all time server configuration sources, use the following:

```bash theme={null}
talosctl get timeserverspec --namespace=network-config
```

```text theme={null}
NODE         NAMESPACE        TYPE             ID                    VERSION
172.20.0.2   network-config   TimeServerSpec   default/timeservers   1
```
