Xen Orchestra 6.9
XO 6.9: start a VM straight from its backup with live mount, a much sturdier Rolling Pool Update, and a busy month for DevOps tools and the REST API.
XO 6.9 is about getting you back on your feet faster. The headline is live mount: when a VM has to come back right now, you no longer wait for its disks to be copied back, you start it straight from its backup. Florent had a VM holding a full copy of Wikipedia running again in 1 min 30.
Rolling Pool Update gets its biggest round of changes yet: it keeps its progress across xo-server restarts, no longer fails because a single VM can't return to its host, and an incomplete run can now be finalized. Our V2V tool keeps getting better, as usual. And it's a busy month for DevOps users: our Cluster API provider reaches its first release candidate, Kubernetes now marks nodes whose VM is gone as out of service, OpenMetrics scrapes no longer pile up in XOA memory, and the REST API gets qcow2 export and new endpoints. XO 6 and XO Lite keep closing the gap with XO 5. This release also comes with a security advisory, so plan the update early.
Outside the release, Xen on RISC-V booted on two real boards, one of them in the hands of a contributor we'd never met, and fourteen of us spent three days at Xen Summit in Munich telling people about it.
🔗 Summary
As always, this annoucement is available as a YouTube video:
👨🚀 Project & Community
If you run Windows VMs, start with the new guest tools: they fix data corruption during in-memory snapshots and backups. The latest security batch for XCP-ng 8.3 LTS deserves the same attention. And while you plan those reboots, have a look at what Samuel Olavo built on the Xen Orchestra REST API.
XCP-ng security update
The latest security batch for XCP-ng 8.3 LTS fixes four vulnerabilities in Xen, oxenstored and tapdisk. The most serious, XSA-513, could let a malicious guest run code inside the tapdisk process in the control domain. The two Xen issues only concern HVM guests with PCI passthrough. XSA-511 only affects PV guests, which XCP-ng 8.3 doesn't support, so its fix will follow upstream later. A host reboot is required.

Windows PV drivers 9.2.385
This version fixes data corruption during in-memory snapshots and backups, driver migration during upgrades, and missing IPv6 addresses in Xen Orchestra. XenClean is now a native .NET 10 binary, with no .NET Framework dependency and a DLL sideloading issue fixed.
If you are currently on version 9.2.350, install the XenTools-fix-9.2.351.msp hotfix included in the release first, or the upgrade will be blocked. No reboot needed for the hotfix.
From the community: a Laravel client for the XO REST API
Samuel Olavo released Laravel Xen Orchestra 1.0.0, an MIT-licensed package that brings the XO REST API to PHP and Laravel. It covers infrastructure, backups, users and RBAC, tasks and events, and handles authentication, field selection and task tracking for you:
$vms = Xo::vms()->fields(['name_label', 'power_state'])->running()->get();
Xo::vm($uuid)->start()->wait();Version 1.0.0 targets the REST API shipped with XO 6.8, and Samuel plans to track compatibility with each release. Try it and share your feedback in the forum thread. This is exactly the kind of project we hoped the REST API would make possible. Thanks, Samuel!
Centreon now monitors Vates VMS
Centreon, the French IT monitoring platform, now supports the Vates VMS stack. Its new Xen Orchestra plugin connects to the XO REST API and lets you track, from Centreon, how many VMs are in each power state, the status of your storage repositories, and whether the Xen Orchestra API is responding, with thresholds to alert on each. XCP-ng users had asked for it on Centreon's ideas board. If Centreon already watches the rest of your infrastructure, your virtualization layer can now show up there too.

💡 Insights
Xen on RISC-V used to run only in an emulator. It now boots on two physical boards, and we still haven't got our hands on one of them.
Xen on RISC-V just ran on real hardware
Baptiste Le Duc and Oleksii Kurochko got Xen to boot a guest domain on a HiFive Premier P550 board, on real silicon rather than QEMU. The challenge was the CPU: the P550 core implements an early draft of the RISC-V hypervisor extension, while Xen targets the ratified version, so Xen had to learn to work without the registers this chip lacks. The series also adds a CI job that flashes the board and waits for the guest's "Hello RISC-V World!". It will go to the Xen mailing list once other series land upstream, and reviewers are welcome in the meantime.

Xen boots on the Spacemit K3, our first RVA23 board
Xen also boots on the Spacemit K3, the first RVA23-compliant board and for now the only one with both the hypervisor extension and APLIC/IMSIC. We don't own one. Zheng Zhang from ISCAS, who wanted to start contributing to Xen on RISC-V, picked up Baptiste's P550 patches and booted his own K3 with them. That's how open hardware should work. Thank you, Zheng! We hope to get a K3 into our CI soon, and if you know RISC-V or low-level development, come help us cover more boards.

🎬 Watch the Xen Summit talk: Xen on RISC-V, From Dom0less to xl
🎫 Events & webinars
We're at five events in October, four of them in or around Paris, so there's a good chance we'll cross paths. September kept the team busy too, from Xen Summit in Munich to Altern'IT in Lyon.
What's next
🇫🇷 Scality Day · Paris, France · 8 October
Scality's annual event, at the 3 Mazarium in the Institut de France, focuses on AI infrastructure, with tracks on AI, cyber resilience, and regulation and sovereignty. Scality hosted the Veeam User Group we joined in September, so we're glad to return the visit.

🇫🇷 Econocom Innovation Day · Puteaux, France · 15 October
Econocom's Innovation Day returns to The Hub, its Paris offices, with conferences, workshops and an innovation area where its partners, Vates included, show their work. Come talk to us about your virtualization plans.

🇫🇷 Pure Accelerate · Paris, France · 15 October
Same day, Everpure holds Pure Accelerate at the Pavillon d'Armenonville, with Vates among the sponsors. One afternoon track covers VMware alternatives, a topic we know a thing or two about. The event is reserved for Everpure's partners, customers and prospects.
🇫🇷 Forum Teratec · Paris, France · 20-21 October
The yearly meeting point for HPC, simulation, AI and quantum computing in France, at the Palais des Congrès, with around 70 exhibitors and 2,000 decision-makers expected.

🇫🇷 Cloud Nord · Lille, France · 30 October
At 11:00 in Amphi RS 031, our community manager Bruno Verachten presents « 100 % open source, au-dessus de cette ligne », a 50-minute talk in French in the security track. Would you trust a machine whose boot you don't control? Bruno goes down the stack from the VM to the silicon, rating each layer's openness, and ends where RISC-V and OpenSBI are starting to change things.

We've been there!
🇫🇷 Veeam User Group · Paris, France · 8 September
Nicolas Leblanc, Jb Piacentino, Jonathan Jacquotot and Steeve Sanseverino joined the Veeam User Group meetup hosted by Scality, a few weeks after Veeam Backup & Replication added XCP-ng support. The agenda included a session on the XCP-ng and Veeam integration. Thanks for having us!
🇫🇷 SYS1 annual event · Le Bouscat, France · mid-September
Our new partner SYS1 held its annual evening at the Le Bouscat racecourse near Bordeaux, and we went along with NeoVAD. Horse races, and plenty of talk about the tools changing how we work. Thanks to SYS1 and NeoVAD!
🇩🇪 Xen Summit 2026 · Munich, Germany · 15-17 September

Fourteen of us went to Munich for Xen Summit 2026, hosted by Renesas, and gave three talks. Bruno Verachten opened with the XCP-ng State of the Union, where he shared that Vates authored 10.9% of Xen 4.22, making us its third-largest contributor, with more than half of those commits on RISC-V. Teddy Astie covered the Xen work behind XCP-ng, from guests with more than 128 vCPUs to AMD SEV and GPU virtualisation. Baptiste Le Duc and Oleksii Kurochko took the last slot of day two and still got applause mid-talk, showing Xen on RISC-V running guests on real boards with a working xl toolstack. Thanks to the Xen Project team and to Renesas for organising it.
- XCP-ng State of the Union, Bruno Verachten
- XCP-ng+Xen status update, Teddy Astie
- Xen on RISC-V: From Dom0less to xl, Baptiste Le Duc and Oleksii Kurochko
Bruno tells the whole story, hallway conversations included, in his recap:

🌍 Webinar with EasyVirt · online · 24 September
Our second webinar with EasyVirt, with Jeff Duerr and François Machacek, covered life after migration: rightsizing with DC Scope so old over-provisioning doesn't follow you, then monitoring network flows with DC NetScope.
Get access to the replay of the webinar
🇫🇷 Altern'IT · Lyon, France · 25 September
At this morning event run by ADIRA and Polypus on sovereign digital alternatives, we presented with EasyVirt a field report on Exodata's move from VMware to a sovereign infrastructure. Hosting, software, hardware: each choice moves you closer to independence or away from it. Thanks to ADIRA and Polypus!
🇨🇭 Swiss IT Forum(s) · Geneva, Switzerland · 30 September-1 October
The Swiss IT Forum(s) is the reference IT event in French-speaking Switzerland, a forum and a trade show in one, at Palexpo in Geneva. Over two days, more than 160 exhibitors and 100 talks covered nine themes, from AI and cybersecurity to cloud, infrastructure and datacenters. It was a good opportunity to meet Swiss IT teams looking at their next virtualization platform. Thanks to BY Connect for organising it!

XO 6.9
Live mount is the star of this release: start a VM straight from its backup instead of waiting for a full restore. Rolling Pool Update gets its biggest round of changes yet, V2V keeps improving, and DevOps users get plenty this month: a first release candidate for our Cluster API provider, out-of-service Kubernetes nodes, lighter OpenMetrics scrapes, and new REST API endpoints including qcow2 export.
XO 6 and XO Lite keep closing the gap with XO 5. This release also comes with a security advisory, so plan the update early.
🛡️ Security
Security is an ongoing part of Xen Orchestra development, with contributions from the Vates team and the wider community. Here’s the security advisory that comes with this release:

Security advisory
A Vates Security Advisory accompanies Xen Orchestra 6.9. It contains the details, affected versions, and recommended actions, so we’ll let the advisory speak for itself rather than repeat them here. As always, we recommend updating to this release as soon as your maintenance window allows.
💾 Backup
Backup repositories fill up over time, and not always with data you still need: this release gives you a way to find and free that space. When you need a VM back quickly, live mount now lets you start it straight from its backup instead of waiting for a full restore.
Live mount: get a VM back in minutes
Restoring a large VM the usual way means copying all of its disks back before you can start it. Live mount lets you use the backed-up disks directly, without restoring them first. Florent got a VM holding a full copy of Wikipedia running again in 1 minute 30 seconds.
This helps in two situations. When you need files that file-level restore can't easily reach (a complex LVM layout, an encrypted filesystem, or simply too many files), you can start the VM and get them from the inside. And when a service has to be back online fast, you don't have to wait for a full restore. You can also mix both approaches in the same restore: restore some disks normally, and live mount the others.
Faster backup listing
XO now lists a backup repository once, then keeps that list up to date by replaying the repository's journal instead of listing everything again. It's most noticeable on S3 repositories with Object Lock, where nothing could be cached before. Repositories attached to an XO Proxy benefit too.
Delete disk data with backup metadata
Deleting an incremental backup now also removes its associated disk data, freeing the space it was using. Previously, deleting the backup metadata did not immediately remove the underlying data, leaving the space occupied until the backup chain was cleaned up.
Reclaim space from backups
Backups deleted before this release may still hold disk data that is no longer needed. You can now reclaim this space from a backup repository. XO checks the remaining backup data and merges or removes disk data that is no longer referenced, freeing the corresponding space on the repository. You can run the operation for a specific VM, or for the entire backup repository.
No more stuck files on immutable S3
During cleanup, XO no longer creates a cache.json.gz file on immutable or S3 repositories. Object Lock meant that file could never be deleted, so it stayed there (and stayed billed) forever.
Faster qcow2 replication
Replicating VMs with qcow2 disks now starts faster, and it no longer falls back to a full transfer when a delta is possible.
No more piled-up replicas
Failed continuous replication transfers no longer pile up extra replicas on the target.
🔁 Rolling Pool Update
A Rolling Pool Update touches every host in a pool, so when something goes wrong halfway, you need to know exactly where you stand. This release makes RPU much harder to derail, and much easier to recover when it does. Most of these changes apply to Rolling Pool Reboot as well.
VMs return to their host more reliably
Until now, a single VM that couldn't return to its original host, for lack of free memory for example, was enough to fail an entire Rolling Pool Update or Rolling Pool Reboot. XO now goes through the hosts in reverse reboot order and retries the VMs that were refused. If a VM still can't go back, XO reports it in the task instead of failing the run. On 711 simulated, heavily loaded pools, 94% of runs used to end in error. Now, none do.
If you don't need your VMs to go back at all, you can skip that phase entirely:
xo-cli pool.set id=<pool> rpuMigrateVmsBack=falseOn the pool behind the original ticket, that phase took 2h11 of a 4h19 run, with 350 live migrations. The default behaviour doesn't change.
RPU progress survives an xo-server restart
Restarting xo-server in the middle of an RPU used to lose everything: which hosts were already done, and which VMs had been shut down because they couldn't migrate (PCI passthrough, vGPU, SR-IOV), with nobody left to start them again. XO now saves the progress on disk. The pool's Patches tab shows a banner with the progress per host, the last error, and the VMs still stopped. The same state is available over REST: GET /rest/v0/pools/{id}/rolling_update_recovery.
No new RPU on a half-updated pool
As long as a previous run isn't closed, XO won't start another one. It also spots pools where the master is up to date but other hosts aren't, after manual patching for instance: it lists the hosts that are behind and asks for confirmation before going further. The RPU button now becomes available as soon as any host is missing patches, not only the master.
Finalize an incomplete RPU
Once you've checked the pool, the new Finalize button in the banner closes an incomplete run. If the run changed settings it didn't restore (HA, auto power-on, WLB, load balancer, disabled backup jobs, a disabled host, VMs moved or stopped), XO lists them and asks for a second confirmation. Finalizing doesn't restore anything: the list of what was left behind stays in the task and the logs. Over REST: POST /rest/v0/pools/{id}/actions/finalize_rolling_update.
What's next for Rolling Pool Update
Everything above lays the groundwork for a bigger change. Saving RPU progress on disk, refusing to start on a half-updated pool, and listing what a run left behind give XO the information it needs for the next step: resuming a failed Rolling Pool Update and bringing the pool back to its original state. That work continues over the next few months, and we'll cover each step in the coming releases.
🛰️ XO 6
XO 6 continues to bridge the gap with XO 5. Several parts of the interface now have their own dedicated views and controls, and we've tweaked details in multiple areas to make information easier to read.
‘Disabled’ host icon
Disabled hosts now stand out thanks to a dedicated icon, visible throughout the interface: tree view, dashboards, and VM details.
This makes disabled hosts easier to distinguish from hosts that are simply powered off or in another state.


XO 6 now shows an icon for disabled hosts
Dedicated SR views
Access dedicated views for storage repositories (SRs) in XO 6, with separate General and Hosts tabs.
SR links now open directly on the relevant tab, letting you jump from the general information to the connected hosts without manual navigation.


The new, dedicated SR view, with its different tabs
Native Groups tab
You can now find a dedicated Groups tab in the User management screen. It replaces the link that previously sent you back to XO 5. The table in this new tab lists each group along with its provider, number of members, and number of roles.
You can filter the list using the query builder and navigate through paginated results. An information panel also explains what groups are and how roles inherited through group membership work.

Edit traffic rules
Edit existing traffic rules directly in XO 6: select a rule from the Traffic rules table, and open the edit form to update its settings.
The object targeted by the rule, such as a VM, VIF, or network, remains read-only, while the other rule settings can be changed. If the targeted VM is no longer available or you don't have permission to view it, XO shows it as Unknown, without preventing you from editing the rule.


Edit traffic rules straight from XO 6
Backup repository list
View and administer all backup repositories from a single list within the Administration tab. All configured backup repositories are displayed in the list, regardless of their type.


The backup repository list
Fixed: backup transfer size
Backup transfer sizes are now calculated consistently, fixing display discrepancies between XO 5 and XO 6.


And more!
- You can now change which PIF a host uses for its management interface, without deleting and recreating the network configuration.
- A new action rescans a host's physical network interfaces directly from the host page.VM actions that open a dialog now show the VM's name, so you always know which VM you're about to act on.
🔭 XO Lite
Aside from XO 6, XO Lite expands its capabilities as well, with more host and network operations now available directly from the interface. That includes additional host actions and basic management for host internal networks and VM network interfaces.
More host actions
Building on the host management improvements added to XO 6 last month, XO Lite now allows you to start, shut down, reboot, forget, or force reboot hosts directly.





New actions available in XO Lite
Manage host internal networks
An internal network connects virtual machines to each other without using the physical network. Create new internal networks or delete existing ones, directly from a pool's Network tab.



You can now create and delete host internal networks in XO Lite.
Manage VM network interfaces
Full VIF management is now available in XO Lite: create, connect, or edit a VM's network interfaces.



Manage VIFs in XO Lite
🪐 XOA
XOA now depends less on a clean network path to Vates. Proxy licenses are checked centrally, and license requests no longer hang when an HTTP proxy stops answering.
A license check can no longer block an XO Proxy backup
XOA now handles license checks for its XO proxies, instead of having each proxy check its own license. XOA already knows which proxies it manages, so it can check their licenses and report their status without requiring each proxy to contact Vates directly. License checks no longer prevent a proxy from running backups.
License requests are also more resilient when XOA is behind an HTTP proxy. If the proxy stops responding, xoa-updater now times out the request instead of waiting indefinitely, which allows it to fall back to its cached license information.
Safer XO Config Cloud Backup
Enabling XO Config Cloud Backup now requires an explicit acknowledgment, and disabling it warns you that your existing cloud backups will be deleted.
🐦 VMware to Vates (V2V)
Our V2V tool keeps getting better. Migrations start faster on large disks: when Changed Block Tracking is enabled on the source, XO asks the host which blocks to read instead of scanning the whole disk. Setup is simpler too, since everything V2V needs now ships with XO and installs in one click from the import screen.
Long imports are more robust: sessions are renewed when they expire and closed properly on the source host. Delta transfers no longer silently fall back to a full copy, and errors now show what the source host actually reported.
📡 REST API
As usual, new endpoints and improvements this month for our shiny REST API.
Qcow2 export
VDIs can now be exported in qcow2 through the REST API, whatever format the disk is stored in. VHD and qcow2 exports use NBD when it's available, and every export format, raw included, now gives the download size.
New endpoints
- POST
/rest/v0/backup-repositories/{id}/actions/reclaim-spacereclaims backup space for one VM or a whole repository. - POST
/rest/v0/backup-archives/{id}/actions/mount_live_diskand POST/rest/v0/backup-archives/{id}/live_disks/{liveDiskId}/actions/unmountattach a disk from a backup to a host without restoring it (administrators only). - POST
/rest/v0/hosts/{id}/actions/scan_pifsrescans a host's PIFs. - GET
/rest/v0/plugins/ipmi-sensors/hosts/{id}/ipmireturns every raw IPMI sensor of a host, with its resolved type.
Other changes
- Rolling pool updates and reboots started through the REST API are now refused while a backup job runs on the pool, like in XO 5 and XO 6. Set
bypassBackupCheckin the request body to override it. - Real-time event updates (SSE) now also cover objects that don't come from XAPI: users, groups, ACL privileges and roles, proxies, servers, backup repositories, backup jobs and schedules.
☸️ DevOps Tools
If you run Xen Orchestra with Prometheus or Kubernetes, this release fixes things you've probably run into. OpenMetrics scrapes no longer fill up XOA memory, and Kubernetes now recognises a node whose VM is gone for good instead of waiting for it to come back. The CSI driver and our Cluster API provider both take a step towards 1.0.
OpenMetrics: less memory, fewer timeouts
If you scrape Xen Orchestra with Prometheus, three fixes are for you. A scrape of /openmetrics that timed out no longer leaks memory. Metrics collection is now shared between requests, so repeated scrapes don't fill up XOA memory. And a host with an unresponsive IPMI controller no longer holds up the whole response until Prometheus gives up.
Kubernetes: nodes whose VM is gone are marked out of service
Kubernetes Cloud Controller Manager 1.2.0 adds a controller that applies the standard node.kubernetes.io/out-of-service taint when a node's VM is halted or deleted in Xen Orchestra. Kubernetes can then move workloads and volumes off that node instead of waiting for it to come back. The sync interval and grace period are configurable in the Helm chart. Version 1.2.1 fixes a "host not found" error on VMs that aren't running.
CSI driver: Helm chart 1.0.0-rc.2
The CSI driver keeps moving towards a stable 1.0. This chart-only release adds the missing cluster role access to VolumeAttributesClasses and passes the driver-name flag to the driver correctly, with updated documentation. The driver itself stays at 1.0.0-rc.1.
Cluster API provider: first release candidate
Our Cluster API provider runs Kubernetes control plane and worker nodes as VMs on XCP-ng pools, through Xen Orchestra, and manages them from creation to deletion. Its first release candidate, 1.0.0-rc1, adds support for the Talos bootstrap provider and turns on the out-of-service taint controller described above. Deleting a node's VM no longer takes the data on its persistent volumes with it: the provider detaches those disks first, and stops the VM beforehand if it's paused. Nodes built from scratch now also get the Kubernetes version you asked for.
📖 Documentation & Guides
Some answers used to be hard to find in the docs, starting with which versions receive security fixes. This release puts that information where you'd expect it, and makes the documentation easier to navigate.
Security support
The Xen Orchestra documentation now clearly indicates which versions receive security fixes. This information was previously available only in the XO repository's security policy, so it wasn't easy to find in the main documentation.
The supported versions are now listed alongside the other release information, which makes the security support policy easier to find and understand.


Clickable breadcrumbs
The documentation sidebar is now generated automatically from the folder structure, instead of being maintained manually. While this change is mostly behind the scenes, it also brings a visible improvement: category breadcrumbs are now clickable, which gives you another way to navigate through the documentation.
The new structure also makes the documentation easier to maintain, as the Markdown folder hierarchy now directly determines how pages are organized in the sidebar.

Maximum token validity
The REST API documentation now describes the maxTokenValidity setting, which controls how long authentication tokens can remain valid.


🌐 Translations
Xen Orchestra is translated by its community, and we thank all our contributors!
12 languages updated!
Turkish was added and 12 languages were updated: Chinese (Simplified), Czech, Dutch, Finnish, Italian, Norwegian, Persian, Portuguese, Russian, Slovak, Spanish and Swedish.
Want to help translate Xen Orchestra or improve existing translations? You’re more than welcome to join in here.
🆕 Misc
Smaller changes that still count: the toolstack can no longer be restarted on an HA pool, health check VMs are easier to spot, XO can authenticate users from several independent LDAP domains, and a few backup fixes put an end to errors that were hard to pin down.
No toolstack restart on HA pools
The "restart toolstack" action is now disabled for hosts in an HA-enabled pool, in both XO 6 and XO 5. This is a protection against triggering HA without a good reason.
Clearer health check names
VMs created during a backup health check now use the [Health Check…] prefix instead of [Importing…]. This makes them easier to distinguish from VMs created by a regular import, such as an import from VMware.
No more orphaned VMs after failed transfers
A failed replication transfer could previously leave an orphaned VM on the target and break the incremental chain. As a result, the next transfer had to start with a full backup instead of using the existing delta.
XO now keeps the delta base when a transfer fails, so the next run can continue incrementally and no longer leaves an orphaned VM on the target. This also avoids having to transfer the entire VM again after a failed transfer.
Fixed: BodyTimeoutError during long transfers
Some backup jobs could fail with a BodyTimeoutError ("Body Timeout Error" in job reports), typically during long transfers. Retrying the same job would sometimes work, which made the issue particularly difficult to diagnose.
The error came from the HTTP client library Xen Orchestra uses for these transfers, and updating the dependency fixes the problem. If you've been running into this issue, update your appliance to the latest release channel, or contact our support team if you need the fix sooner.
Multiple LDAP domain support
XO can now authenticate users from multiple independent LDAP domains. You can configure a primary domain and add additional domains, allowing users from separate directories to access the same XO instance without requiring a trust relationship between those domains.
Users and groups from each domain remain scoped to their respective LDAP directory, so separate domains can keep their existing security boundaries while sharing the same XO instance.
More user profile fields
XO users can now have a separate first name, last name and username in the XO database. The existing name property is being deprecated in favour of these new fields, while email stays as it is. You can set the new fields when creating or updating a user, and all three are optional when creating one.
For now, this change only applies server-side and doesn't affect the Xen Orchestra interface.
Other improvements
- Audit: actions made from XO 5 now record the client's real IP address, instead of 127.0.0.1 or ::1.
- Netbox: IP addresses are now synced with the right prefix (for example /24), not a broader container prefix like /8.
- MCP server: it starts again on Node 26, and search_documentation now respects HTTP_PROXY, HTTPS_PROXY and NO_PROXY.
- Netdata: the "You must enable Javascript" error in XO 5 is gone.







