# Xen Orchestra Blog > News about XO, the backup & management solution for the Vates Stack (XCP-ng) Public Ghost content for AI and LLM tooling. This file includes a bounded export of public pages first, then recent public posts. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages ### 10 tips to start with Xen Orchestra URL: https://xen-orchestra.com/blog/how-to-start-with-xen-orchestra/ Last updated: 2023-04-24T17:36:37.000Z This quick guide has been created to help the new comers in Xen Orchestra universe to make their first steps in our Appliance and to get the maximum from the trial period we provide. If you didn't [register](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup) yet, do it now and ask for the trial period in order to discover all the features of XOA. ℹ️ Citrix Hypervisor user? If you are struggling with with XenCenter to manage your infrastructure or if you want a [complete backup](https://xen-orchestra.com/?ref=xen-orchestra.com#!/features/backup) solution for you Citrix App and Desktop VMs, Xen Orchestra offers features for any of these use cases, as a complete all-in-one tool. And it work both with Citrix Hypervisor and [XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com) (even legacy versions of XenServer). Now that you have registered, here are 10 tips to help you in your journey with Xen Orchestra. Of course, this guide is just a glimpse of all the features and you can find a lot more information in our [documentation](https://xen-orchestra.com/docs/?ref=xen-orchestra.com) section. ##### 1 - Deploy Xen Orchestra on your XCP-ng host The easiest way to install Xen Orchestra is to use the deploy tool available on [this page](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xoa): ![deployeasy](https://xen-orchestra.com/blog/content/images/2019/07/deployeasy.png) An alternate method is to SSH into your XCP-ng console and execute this line of command: ```sh bash -c "$(wget -qO- https://xoa.io/deploy)" ``` 💡 Everything that happens in the deploy tool section is between your browser and your host. Nothing is sent to our servers. Our SHH command will simply import a VM in your infrastructure, nothing will be change on the server. It's 100% safe. #### 2 - Activate your Premium Trial In order to activate your Premium trial, you have to go on the **update** menu. Register yourself with the very same email and password that you use to register on our website. You will see a green button appear **"Start Trial"** click on that button. Then final step is to click on the **"upgrade"** button. The Premium edition will be downloaded and you will be able to use XOA Premium during 15 days. 💡 If you want to check the remaining trial period, you can go on update view at any moment and check it here. ##### 3 - Activate the plugins you want to use You are almost ready to use Xen Orchestra. The last configuration step you should do is to activate the plugins you needs. In **Settings/plugins** you can choose the optional features you want to use. For example, LDAP authentication or the backup report can be activated and configured from this panel. ![](https://xen-orchestra.com/blog/content/images/2017/06/xo5pluginspage.png) ##### 4 - Add a XCP-ng or Citrix Hypervisor host The very first time you will connect yourself to XOA, you will need to add a server. To do it, you simply have to enter the IP of you XCP-ng host (the pool master if in a pool). Once it's done, you are connected and will now have access to the classic view to manage your VMs objects. You can check the global [user interface](https://xen-orchestra.com/docs/user%5Finterface.html?ref=xen-orchestra.com) documentation for more detailed informations. ![](https://xen-orchestra.com/blog/content/images/2017/06/xo5connectedserver.png) ##### 5 - Create a VM with Xen Orchestra To create a VM using Xen Orchestra you can click on the **New VM** button on the home view. Select your pool, a template if you have one and give a name to your future VM. The performances you are needed vCPUs, RAM, CPU weight and cap. 💡 CPU weight and cap are advanced features, modify them only if you know what are you doing! ##### 6 - Manage your VMs In Xen Orchestra, you can edit almost everything. It means that each time you see a dotted underline, you can edit simply by clicking on it. It includes VM title, description, CPU and memory and a many more. By clicking on the **advanced options** you will have more management options for you VM like the Auto Power VM, the High Availability and even the option to copy your VM on any SR located in your XCP-ng infrastructure. ![](https://xen-orchestra.com/blog/content/images/2017/06/xoconsole.png) ##### 7 - Schedule a backup One of the most used option in Xen Orchestra is the backup. You can schedule full backup for your VM on your local XOA file-system or directly in a NFS or SMB share. To do so, click on the **backup** menu and choose the VM you want to backup. Then, adjust the frequencies and the "depth" to modify the retention (removing the oldest one) 💡 Keep in mind tht full backup are space consuming. Xen Orchestra is allowing delta backup which is far more optimized. You can find more information about delta backup [here](https://xen-orchestra.com/docs/delta%5Fbackups.html?ref=xen-orchestra.com). ![](https://xen-orchestra.com/blog/content/images/2017/06/xo_backup_view-1.png) ##### 8 - XCP-ng rolling pool update Patching a host manually is not only time consuming, it's boring too. That's why we provide a high level feature which is downloading and applying all missing patches automatically. The missing patches will be display on your dashboard view, on your pool view and on your host view. By just clicking on "Rolling Pool Update", you'll enjoy all the updates installed, hosts rebooted and without any impact on your production, since Xen Orchestra will migrate everything around automatically! ![](https://xen-orchestra.com/blog/content/images/2017/06/xo5patching.png) ##### 9 - Access your logs Sometimes it's useful to check XOA logs in order to detect issues. You can access logs by clicking on **Settings/Logs**. ![](https://xen-orchestra.com/blog/content/images/2017/06/xoalogs.png) ##### 10 - Ask for support 💡 Even during your trial period, you have the ability to open support ticket. Our [pro support is included](https://xen-orchestra.com/?ref=xen-orchestra.com#!/features/support) in our appliance. You can access your support menu in your customer interface. You can reach us trough the chatbox on the website too. Of course, the higher the plan is, the higher priority it gets for support. Our response time is usually under 24 hours. ℹ️ Do you want a bundle with both Xen Orchestra and XCP-ng support? Ask us! ## Posts ### Xen Orchestra 6.8 URL: https://xen-orchestra.com/blog/xen-orchestra-6-8/ Last updated: 2026-09-01T06:59:48.000Z This month is about what surrounds a migration rather than the migration itself: the backup tooling you already own, the hardware you can avoid buying, and the numbers you need before the decision gets made. Alongside Xen Orchestra 6.8, Veeam Backup & Replication now officially supports XCP-ng, TwinStor opened as a Technology Preview for two-host pools, and we published a calculator that puts a Vates VMS environment side by side with its VMware equivalent. On the product side, Backup gains synchronized snapshots for VMs that belong to the same application, XO 6 keeps closing the operations that still required a return to XO 5, and XO Lite can now create networks instead of only displaying them. Add XOA sizing its own memory, a declarative way to share a VM from Terraform or Go, and a round of documentation cleanup, and 6.8 is a release with as much happening around Xen Orchestra as inside it. #### 🔗 Summary 👨‍🚀 [Project & Community](#%F0%9F%91%A8%E2%80%8D%F0%9F%9A%80-project-community) 💡 [Insights](#%F0%9F%92%A1-insights) 🎫 [Events & webinars](#%F0%9F%8E%AB-events-webinars) [****XO 6.8**](#xo-68) 1. 💾 [Backup](#%F0%9F%92%BE-backup) 2. 🛰️ [XO 6](#%F0%9F%9B%B0%EF%B8%8F-xo-6) 3. 🔭 [XO Lite](#%F0%9F%94%AD-xo-lite) 4. 🪐 [XOA](#%F0%9F%AA%90-xoa) 5. ☸️ [DevOps Tools](#%E2%98%B8%EF%B8%8F-devops-tools) 6. 📖 [Documentation & Guides](##%F0%9F%93%96-documentation-guides) 7. 🌐 [Translations](##%F0%9F%8C%90-translations) 8. 🆕 [Misc](#%F0%9F%86%95-misc) As usual, this announcement is available as a Youtube video: ## 👨‍🚀 Project & Community A lot of the news from the ecosystem touches on questions that often come up before a migration. What happens to your backup tooling? Does a small pool really need a SAN? And how much will the whole setup cost? We also have some upstream and maintenance news, including the release of Xen 4.22. ### XCP-ng updates XCP-ng 8.3 LTS got two update batches over the past month, both centered on storage. The first brought storage performance improvements and fixes, plus a configurable OpenSSH. The second fixed a leaf-coalesce failure on QCOW2-backed disks with CBT enabled, which could leave longer disk chains and eat extra space, and a case of LVM metadata corruption on a secondary host using block-based shared SRs. Sparse QCOW2 disks also migrate faster now, since empty sectors are no longer transferred. Updates are cumulative and host reboots are required, so applying the second batch covers both. [August 2026 Updates #1 for XCP-ng 8.3 LTSMaintenance updates for XCP-ng: storage performance and fixes, configurable OpenSSH, and much more.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-d599a182-11e7-4579-a934-5e7af3c9cc00.png)XCP-ng BlogSamuel Verschelde![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1664742489170-efe3f3c01c30-57224ada-84d7-452d-8a14-4176a6618427)](https://xcp-ng.org/blog/2026/08/18/august-2026-updates-1-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) [August 2026 Updates #2 for XCP-ng 8.3 LTSNew updates published: bug fixes related to storage management.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-32fae71e-3132-4abf-ab33-c0029ed903b5.png)XCP-ng BlogSamuel Verschelde![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1622758342664-ce796582e479-db60234f-b77c-469a-ad48-848459c5f9d2)](https://xcp-ng.org/blog/2026/08/27/august-2026-updates-2-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) Refreshed XCP-ng 8.3 LTS installation ISOs came out on August 14, with the latest security updates and QCOW2 support out of the box. [XCP-ng 8.3 LTS: Refreshed Installation ISOsRefreshed ISOs for XCP-ng 8.3 LTS featuring the latest security updates, improvements, and QCOW2 support.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-e8d8409b-b81d-475c-9cfa-54049d28e2b0.png)XCP-ng BlogGaël Duperrey![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1591287968288-394880ef65a0-f36cf6aa-ee57-48b2-961a-d5ab7ceefe5a)](https://xcp-ng.org/blog/2026/08/14/xcp-ng-8-3-lts-refreshed-installation-isos/?ref=xen-orchestra.com) ### Windows PV drivers 9.2.350 Version 9.2.350 of the XCP-ng Windows PV drivers was released on August 6, with a new Windows guest agent. Full details are in the release notes. [Release 9.2.350 · xcp-ng/win-pv-driversThis major release brings a new Windows guest agent with many new features, plus multiple other improvements. To download XenClean, click here. The installer downloads also includes a copy of XenCl…![](https://xen-orchestra.com/blog/content/images/icon/favicon-0e15657e-e6ae-4ba7-af7f-4b8df6f1ad14.svg)GitHubxcp-ng![](https://xen-orchestra.com/blog/content/images/thumbnail/v9.2-aabbebed-9d4d-4e9c-94fe-561cd24bbe2c.350)](https://github.com/xcp-ng/win-pv-drivers/releases/tag/v9.2.350?ref=xen-orchestra.com) ### Vates and Xen 4.22 The Xen Project released Xen 4.22 at the end of July, with modern hardware support, Arm improvements, continued RISC-V progress, Xenstore scalability work, and a five-year security support lifecycle. Vates engineers are a growing part of that upstream work. In 2026 so far, Vates has authored about 10% of the commits merged into the Xen hypervisor and holds maintainer or reviewer roles in 12 subsystems. On the XAPI toolstack that powers XCP-ng, Vates authored 31% of this year's merged commits, up from 22% in 2025 and under 2% in 2024. ### XCP-ng is now officially supported by Veeam Veeam Backup & Replication now lists XCP-ng as a fully supported hypervisor. Backup jobs use Changed Block Tracking for incremental processing. Entire VMs restore onto XCP-ng from any supported hypervisor, cloud VM, or physical-server backup, and XCP-ng backups restore outward to that same range of targets. Disk mount, guest file-level restore, and backup export to VHD, VHDX, or VMDK are covered too. For anyone weighing a move off VMware, this settles a question that used to come up early in every migration conversation: whether the backup tooling already in place would follow. Existing Veeam backups can now be the route in, restored straight onto XCP-ng while the surrounding backup infrastructure stays where it is. [Hypervisor Protection - Veeam Backup & Replication What’s NewThe data center landscape is shifting. Workload migrations are accelerating, and Veeam is built to move with them. This release significantly expands native hypervisor coverage by adding the following hypervisors to the already broad portfolio of supported platforms. Sangfor aSV is now a fully supported hypervisor in Veeam Backup & Replication, with a comprehensive set of backup and restore capabilities aligned with Veeam’s cross-platform protection standards.![](https://xen-orchestra.com/blog/content/images/icon/favicon-228x228-58649854-e0d8-4104-9dba-8f6736f6366b.png)Veeam Help CenterVeeam Software![](https://xen-orchestra.com/blog/content/images/thumbnail/1600x800_helpcenter_es_build-83653584-b864-483f-94ca-609999e0274c.png)](https://helpcenter.veeam.com/docs/vbr/wn/hypervisor%5Fprotection.html?ver=13&ref=xen-orchestra.com) ### TwinStor Technology Preview: volunteers wanted TwinStor turns the local disks of a two-host pool into redundant, self-healing shared storage, so live migration, HA, and Rolling Pool Updates work with no SAN, no witness node, and no third host. It's now open as a Technology Preview, and we're looking for people willing to run it on real pools they can afford to break. A Technology Preview is a pre-release build: not feature-complete, not for production, and not guaranteed to ship. What it gives testers is early access and a direct line into the engineering direction while it's still being decided. The forum thread is where the testing is actually happening, and the fastest way to see what other people have hit before you install anything. [TwinStor | Vates VMS DocumentationHyperconverged storage for two XCP-ng hosts. TwinStor turns the local disks of a 2-host pool into fully redundant, self-healing shared storage: live migration, automatic VM restart (HA), and Rolling Pool Updates all work, with no SAN, no witness node, and no third host.![](https://xen-orchestra.com/blog/content/images/icon/vates-logo-128-2e7b005e-fe2a-4879-963e-1e53d0dceed1.png)Vates VMS Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-logo-128-2644cd61-989a-408f-a8d7-fae1cd2cd194.png)](https://docs.vates.tech/tech-preview/twinstor/?ref=xen-orchestra.com) [TWINSTOR: next gen 2 nodes HCITWINSTOR: help us torture-test a 2-node hyperconverged storage for XCP-ng Hi everyone, We have been working on something we are quite excited about, and toda…![](https://xen-orchestra.com/blog/content/images/icon/512-1521ba67-4b0c-4a8b-92e9-9f1018892647.png)XCP-ngolivierlambert![](https://xen-orchestra.com/blog/content/images/thumbnail/1-profileavatar-1620659303584-a4f34d60-c963-486e-adf2-790cd5351c56.jpeg)](https://xcp-ng.org/forum/topic/12323?ref=xen-orchestra.com) ### Estimating what a migration costs We published a calculator that puts a Vates VMS environment side by side with the equivalent on VMware. The figures come from publicly available reseller pricing, so they give an order of magnitude rather than a quote: a place to start the comparison and work out which questions to ask, not a substitute for one. [Vates VMS vs VMware Cost EstimatorEstimate per-host vs per-core licensing cost against VMware vSphere Standard, vSphere Foundation and Cloud Foundation. Every assumption is visible and editable.![](https://xen-orchestra.com/blog/content/images/icon/favicon-32x32-dc9fbab5-a834-4ff6-8309-731e4a1fbb21.png)Vates![](https://xen-orchestra.com/blog/content/images/thumbnail/vmware-vs-vates-vms-7b46cc0f-1dee-471a-a30e-0d15d93ce662.png)](https://vates.tech/en/pricing-and-support/vmware-cost-calculator/?ref=xen-orchestra.com) ## 💡 Insights Insights look at what's happening across the wider industry, and what it means for the way you run your own infrastructure. This time, two pieces on owning your infrastructure: what it looks like to run a company on it, and what to do about hardware prices before you buy more of it. ### Why infrastructure control matters more than ever in 2026 We published a piece on running a company of around 150 people internationally, mostly on open-source, self-hosted tools. It covers what owning your infrastructure looks like in practice at that scale, and what it costs to do. Worth a read if you're weighing how much of your stack you want to own. [On-prem and open source: how Vates operates in 2026Vates runs near 150 people. We are growing internationally, and we do it mostly on open-source, self-hosted tools. Here is what that actually looks like in practice, and why it matters.![](https://xen-orchestra.com/blog/content/images/icon/logo64-c4e9ed47-7c53-41f7-8369-986e82cbbd3f.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/infrastructure-control-virtualization-management-stack-96ffe644-b705-4a1b-8c1f-05c95ab82c88.webp)](https://vates.tech/blog/why-infrastructure-control-matters-more-than-ever-in-2026/?ref=xen-orchestra.com) ### Before buying new hardware, make sure you're using the hardware you already own RAM prices are up more than 400% in a year. Our latest post covers where unused capacity hides in virtualized environments, and how to find it before you budget for more hardware. [RAM prices are up. Here’s how to respond.RAM prices are up over 400% in a year. Where to find capacity before you buy more hardware, and when buying is the right call after all.![](https://xen-orchestra.com/blog/content/images/icon/logo64-c5681260-8434-48ad-ad68-b413db7cda14.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/ddr5-ram-price-surge-capacity-planning-7711d69d-2200-4600-b3d8-a285e8a5ca9c.webp)](https://vates.tech/blog/before-buying-new-hardware-make-sure-youre-using-the-hardware-you-already-own/?ref=xen-orchestra.com) ## 🎫 Events & webinars September takes the team to Munich, Paris and Lyon, plus a webinar you can join from anywhere. Here is where you can catch us, and what each one is about. ### Veeam User Group France in Paris, 8 September The French Veeam User Group meets in Paris on 8 September, hosted at Scality's offices, with Vates among the sponsors. The programme runs from 13h30 and includes a dedicated session on the XCP-ng / Veeam integration, alongside a Veeam and Kasten update with an Ask Me Anything, a talk on meeting LPM, NIS2 and DORA obligations, and a field report on VSA. It closes with a quiz and a vBeer cocktail. Registration is open. ### Xen Summit 2026 in Munich, 15-17 September The Xen community gathers in Munich for Xen Summit 2026, hosted by Renesas at the HEADS office in Aschheim. Two days of technical talks are followed by a day of design sessions, where contributors work through project direction and architecture face-to-face rather than on the mailing list. The event is hybrid, so you can join the talks remotely if you cannot make the trip, and registration is still open. [Xen Summit 2026Join the Xen Project community in Munich, Germany, September 15–17, 2026, for technical talks, design sessions, and collaboration.![](https://xen-orchestra.com/blog/content/images/icon/favicon-32x32-906ff66b-5038-4ad9-b23f-c8f983dcd03b.png)Register Now![](https://xen-orchestra.com/blog/content/images/thumbnail/social-card-f5798177-9c03-4bac-8afd-9785361d4d0f.jpg)](https://xenproject.org/resources/summit-2026/?ref=xen-orchestra.com) ### Altern'IT in Lyon, 25 September ADIRA and Polypus are running a morning in Lyon on digital sovereignty. Delphine Le Pochat, Marc-André Pezin and Simon Cojande are running the infrastructure, hosting and virtualisation workshop for us, alongside Bouygues Telecom Business and EasyVirt. In French, and limited to end-user organisations. [Altern’IT![](https://xen-orchestra.com/blog/content/images/icon/favicon-9a4b57c5-ce69-4a92-9de5-09fad539088d)ADIRA![](https://xen-orchestra.com/blog/content/images/thumbnail/logo-20adira1080-a07d999d-fb1e-46f9-9ff3-f42b0628c219)](https://www.adira.org/e/altern-it?ref=xen-orchestra.com) ### Another round with EasyVirt We're running the joint webinar with EasyVirt again on 24 September, 16:30 to 17:30 CEST, with Jeff Duerr (US Sales Manager) for us and François Machacek (Business developer) for EasyVirt. The thread is the same as in July: getting more out of the infrastructure you already have, managing more than one hypervisor from a single place, and testing a migration before it reaches production rather than after. Registration is open, and the first edition is still up on YouTube if you would rather watch that one back, 45 minutes. [Register for the webinar](https://register.gotowebinar.com/register/832295575536757595?ref=xen-orchestra.com) --- # XO 6.8 Synchronized snapshots are the main new capability in XO 6.8\. They address a specific problem: when a backup job covers a database and the services that depend on it, their restore points could previously end up hours apart. The rest of XO 6.8 picks up where previous work left off. XO 6 takes on more tasks that still required XO 5, and XO Lite can now do more with networks than simply display them. XOA and the DevOps tools also get a few fixes for problems that tend to show up when something goes wrong. ## 💾 Backup When a database and the services around it are backed up in the same job, the VM at the end of the queue may not be snapshotted until hours after the first. Synchronized snapshots take them all before any transfer starts, so the restore points line up. Separately, an unreachable backup repository no longer delays the listing of the ones that are available. ### Synchronized snapshots You can now synchronize VM snapshots in a backup job. When enabled, XO takes the snapshots for the selected VMs in a batch before starting any transfers. Each backup then uses the snapshot that was already taken, giving you restore points that are much closer together in time across related VMs. This is useful when your VMs are part of the same application, such as a database and the services that depend on it. Without this option, VMs further down the queue might not be snapshotted until hours later, leaving their restore points out of sync. You can synchronize snapshots for all VMs in a job, or use a tag to limit synchronization to VMs sharing that tag. ### Fixed: Unreachable backup repositories When a backup repository (BR) is unavailable, XO no longer waits for it before displaying the other backup archives. Available BRs are returned as soon as their information is ready, while unreachable ones are skipped for the current request. As a result, unreachable backup repositories no longer slow down backup listings, including the File restore and Backup health views. XO retries unavailable BRs in the background, so a temporary connection issue won't slow down subsequent requests. ## 🛰️ XO 6 You now have fewer reasons to switch back to XO 5\. You can scan PIFs and manage hosts directly from XO 6, and storage repositories now have their own dedicated view. Group and role management are ready as well, but they'll ship alongside the rest of the user management and RBAC work in a future release (shipping them on their own would only tell half the story). ### ‘Scan PIFs’ button In previous versions of XO 6, scanning for physical interfaces (PIFs) required you to switch back to the XO 5 interface. With the new **Scan PIFs** button, you can now run scans directly from XO 6, from the host’s **Network** tab. The scan runs as a background task, so you can keep working in Xen Orchestra while it completes. ![](https://xen-orchestra.com/blog/content/images/2026/08/628492650-f0ab51f2-c589-418b-89ab-9c883cebb663.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/628492871-382c27ed-4484-4378-9102-1b60c8e4123a.png) In previous versions of XO 6, you had to open XO 5 to scan for PIFs ![](https://xen-orchestra.com/blog/content/images/2026/08/628491262-24518067-1ff0-46ac-a005-f428559fdd22.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/628491367-b13df7da-1af9-4040-a323-d71c597b5b61.png) The new 'Scan PIFs' button in XO 6.8 ### Storage repository overview Storage repositories now have their own dedicated view. Opening an SR takes you directly to its **General** tab, where you can find its main information and configuration instead of having to look for it elsewhere in the interface. ![](https://xen-orchestra.com/blog/content/images/2026/08/642730119-076eee21-ce47-4637-98f9-9804df9f3c9e-1.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/642730164-f46453d5-035a-4ec3-af61-e3f88b054700-1.png) New SR view, with a General tab ### Host actions XO 6 now exposes host management actions, directly from the host view. You can restart the toolstack, reboot or shut down a host, forget a host, and force a reboot when needed. You can also use Smart Reboot to safely reboot a host, or Detach it from the pool. Emergency Shutdown is the one action still missing, and it lands next month. ![](https://xen-orchestra.com/blog/content/images/2026/08/detach-host-light.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/force-reboot-light.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/reboot-host-light.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/restart-toolstack-light.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/shut-down-host-light.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/635496841-1e976912-8f29-4eb7-b51b-6d67280c29c9.png) New actions available in XO 6 ### Connect and disconnect pools You can now connect or disconnect pools in the Pools tab, in two ways: from the pools table, or from the side panel. This way, you can manage a pool without opening its dedicated view. Disconnecting a pool also comes with a warning, since the pool can no longer be managed from XO while disconnected. You can reconnect it later from the same action. ![](https://xen-orchestra.com/blog/content/images/2026/08/627115793-63bc437d-d5c6-49ab-9d05-329b17d7143f.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/627115908-2341258e-ec16-4464-843f-907d99483bbf.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/627117112-1e76634f-cb6f-40a3-90c8-2cece03941ce.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/627117213-20213788-2fb9-4283-86ed-81fce122a2af.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/627117847-690212bb-bd03-4a9c-89b5-d0bf9a8adf6b.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/627117953-782b436a-0d70-46a4-9fe6-d069cef0cda5.png) Connect and disconnect pools straight from the Pools view ### Disable hosts and evacuate VMs Now, you can disable a host and evacuate its VMs from the host action menu. Before disabling the host, XO checks that it can safely evacuate the VMs, and asks for confirmation. Once disabled, the host won't receive new VMs, while its existing VMs can be migrated to other hosts in the pool. You can enable the host again from the same action menu when it's ready to be used again. ![](https://xen-orchestra.com/blog/content/images/2026/08/622699814-015312d5-ca27-4091-ba1c-232894c24daa.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/622699933-9185067b-31b6-4726-92ea-9f4a9f252e6c.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/622700025-6cd3cddb-5df8-4e00-b7cc-89f7f08339ec.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/622700110-d0755809-cbc8-43a6-9f81-6353a3906a3e.png) Disabling/enabling hosts in XO 6 ### Detailed guest tool status The VM dashboard now shows the status of the guest tools installed in each VM. You can see whether the tools are up to date, out of date, missing, or unknown. Clicking the status gives you more details about the installed guest tools, including the detected version when available. The same status is also shown in the VM’s **System** tab and side panel. ![](https://xen-orchestra.com/blog/content/images/2026/08/625581979-64b2fe7b-53dd-400d-9cc4-c42aa0dfbaf8.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/625582527-9d832e4a-a37f-4f6c-b1ff-f4588892b001.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/625584166-3a1ee048-95ca-4f4d-9d0d-e83f45534bf1.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/625584252-e926ef2c-c2a8-414e-84ae-02edf4fde2aa.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/625584414-04c40548-d814-4a34-acd0-7d19a69da8e1.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/625584509-9b9cb013-07eb-4bc2-b8d6-304a6a07265f.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/625584781-edaaf9db-cc3e-4b37-8633-5073f53a1f9b.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/625585095-1974e7c8-2251-4cf9-87ee-dfad59b869a8.png) Guest tool details in XO 6 ### Reconfigure the management PIF You can now move a host’s management interface to another physical interface (PIF), directly from XO 6\. The action is available from the PIF table and its side panel, provided the target PIF has an IP configuration and isn't already the management interface. 💡 ****Note:** Keep in mind that switching the management PIF can temporarily disconnect the host from XO, while the new configuration takes effect. ![](https://xen-orchestra.com/blog/content/images/2026/08/623957738-e2f5dcea-c9c5-4045-ac5a-bbd1979de643.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/623958996-10d168d1-e9d5-446b-a78e-7259e9d9e317.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/623960418-2db4881b-c0b3-4e08-a83d-ec9076622684.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/640751596-110f37b8-5209-47d2-9d68-f1bd6018e94a.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/623960778-cf068a4b-b0b6-44c1-8005-2871ad724e66.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/640751796-71a726a9-2f02-4d06-ac3b-7cfd8b1ad1f9.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/640751932-108dffac-ad72-4eb4-a0f0-da361c535690.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/640752077-fc6fec56-cc28-479d-8c6d-857a86da77c9.png) Change the management PIF right from XO 6 ## 🔭 XO Lite Network configuration in XO Lite was previously limited to viewing. You can now create networks, bonded networks and host internal networks without opening XO 6\. VDIs gain a page of their own, and VM actions are available from the tree view. ### Manage VDIs XO Lite now has a dedicated page for listing virtual disk images (VDIs), just like in XO 6\. The new page gives you an overview of your VDIs and lets you select one to view its details. VDI actions (create, attach, detach, delete) are coming soon. ![](https://xen-orchestra.com/blog/content/images/2026/08/637522166-4f50e6df-42b6-4642-9c54-82dcf38615c9.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/637522247-a5788a1b-82ac-4fa7-aa44-f0501f423eb3.png) Now, XO Lite shows you a table with all your VDIs ![](https://xen-orchestra.com/blog/content/images/2026/08/637577416-f400effe-eb86-4b27-bddc-7855e4fb65a1.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/637577328-e1aa6abe-27ab-41a3-8238-2bc2d26a2745-1.png) VDI details also appear in the side panel ### Create networks and bonded networks Starting with XO 6.8, you can create networks and bonded networks, without switching to XO 5\. From a pool’s **Network** tab, use the **Create network** action to set up a network and configure its properties. ![](https://xen-orchestra.com/blog/content/images/2026/08/626349341-c31f8494-9bd8-43d7-8589-7db1325f230c.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/626349595-dfb53376-d6f6-4490-a5ac-d708aac6ae63.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/626350063-7844527d-949a-4c9c-ae9e-8427eb83e3ba.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/626350241-3b28ad1f-b3e1-4408-9851-bb5c493cdf4c.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/626350873-76296d1d-835a-49f9-818b-ae7c84594ff7.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/626351092-9e348792-fbbc-4d79-bb72-6be26a1a0e45.png) How to create networks in XO Lite ### ### ‘Scan PIFs’ button We’re updating XO Lite to let you scan for physical interfaces (PIFs), just like we did [with XO 6](#%E2%80%98scan-pifs%E2%80%99-button). From a host’s **Network** tab, click the **Scan PIFs** button to start the scan. ![](https://xen-orchestra.com/blog/content/images/2026/08/632929825-645ca594-8f74-42c8-94cc-614f35295cda.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/632929834-c9fcff35-2865-4c26-8873-0e669b95fa43.png) The new 'Scan PIFs' button in XO Lite ### VM actions in the tree view We’ve added VM actions to the XO Lite tree view. This means you can access the actions from a VM’s context menu, without opening the VM first. Also, the tree view shows when an operation is running on a VM. ![](https://xen-orchestra.com/blog/content/images/2026/08/640964734-45cd6142-d899-4319-a03f-a17f99297ad4.png) ![](https://xen-orchestra.com/blog/content/images/2026/08/640964830-30282d10-f569-4f75-8716-676f6d126026.png) The tree view now shows the actions you can perform on a VM. ## 🪐 XOA `xo-server` now sizes its Node.js memory limit from the RAM allocated to the VM rather than from a fixed default, so additional memory given to XOA is actually used. License checks also no longer hang indefinitely when the HTTP proxy in front of XOA stops responding. ### Adapt memory usage to the VM size `xo-server` now adjusts Node.js's memory limit based on the amount of RAM available to the XOA virtual machine. The limit is set to 70% of the VM's RAM, with a minimum of 1 GiB, leaving enough memory for the operating system and other XOA services. The limit is recalculated every time `xo-server` starts, so resizing an XOA VM and rebooting it automatically updates the setting. This also prevents Node.js from hitting its default heap limit too early on VMs with more RAM. ### More resilient license management Previously, when an XOA instance used an HTTP proxy to access the Internet, a proxy that stops responding could leave license requests hanging indefinitely. In some cases, this prevented `xoa-updater` from falling back to its cached license information. XO now puts a timeout on these requests. If the proxy doesn't respond in time, the request is aborted and `xoa-updater` can use the cached license data instead. This keeps license management working even when the proxy temporarily loses access to the Internet. ## ☸️ DevOps Tools Until now, giving a whole team access to a VM meant opening the XO interface and sharing it manually, outside the configuration that originally defined the VM. The Terraform provider and the Go SDK both close that gap this cycle, alongside a fix for pools where several hosts have a storage repository named Local storage. The Kubernetes side moved too, with a first release candidate for the CSI driver and a maintenance release for the cloud controller manager. ### Terraform provider v0.41.0 The provider gains a plural `xenorchestra_srs` data source, modeled on `xenorchestra_pools`, so you can list and iterate over storage repositories. The singular `xenorchestra_sr` resolves one SR at a time, which left no way to work with a pool where several hosts each own an SR called "Local storage". The singular data source also gains `host_id` filtering, which disambiguates those host-local SRs. The VM resource picks up a `share` boolean. Setting it does what the Share button in the XO web UI does: the VM is granted to everyone in the resource set it belongs to, so team-wide access becomes a line in your configuration rather than a click afterwards. [Release v0.41.0 · vatesfr/terraform-provider-xenorchestraThis release of the Terraform provider for Xen Orchestra brings better storage visibility and a convenient, declarative way to share VMs with your team. What’s Changed New: xenorchestra\_srs data so…![](https://xen-orchestra.com/blog/content/images/icon/favicon-b55fdaa5-878f-44ee-bcdd-7f078a8d8f6b.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v0.41-2e2d380f-e001-4d41-b3b0-a94418b54f0c.0)](https://github.com/vatesfr/terraform-provider-xenorchestra/releases/tag/v0.41.0?ref=xen-orchestra.com) ### Go SDK v1.19.0 The v1 SDK learns the same `share` flag for VMs, which is what the Terraform provider builds on. If you drive Xen Orchestra from your own Go tooling rather than through Terraform, the capability is there directly. [Release v1.19.0 · vatesfr/xenorchestra-go-sdkWhat’s Changed v1 feat(vm): support the share flag for VMs by @gCyrille in #111 Other build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 by @dependabot\[bot\] in #103 build(deps): bump actions…![](https://xen-orchestra.com/blog/content/images/icon/favicon-0b5eb3f7-8d13-45dc-b1b2-c91ec2f5cf1c.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v1.19-c878bf90-a42c-40ef-8d80-91b13bde3036.0)](https://github.com/vatesfr/xenorchestra-go-sdk/releases/tag/v1.19.0?ref=xen-orchestra.com) ### CSI driver v1.0.0-rc.1 The CSI driver reaches its first release candidate for 1.0, with four changes worth calling out. Pick the storage repository at provision time. The driver now reads storageRepositoryId from a Kubernetes VolumeAttributesClass, so a PVC can target a specific SR instead of always landing in the pool's default one. The SR is validated against the selected pool and storage type before the VDI is created, and precedence runs VolumeAttributesClass first, then an explicit poolId, then topology-aware selection. You can also move an existing volume to another SR in the same pool at runtime by changing the `VolumeAttributeClass` of the PVC. Then, the migration is made without stopping or restarting the pod : it leverages the live migration of Xen Orchestra within Kubernetes. **Credentials stay on the controller.** The driver splits into controller and node modes: only the controller talks to the Xen Orchestra API, and the node server runs with no XO configuration and no credential secret mounted. Node metadata now comes from the CCM-provided `ProviderID` on the Kubernetes Node. This matters most in clusters where control-plane and worker nodes are separated, since the XO credential is no longer present on every worker. Note that it also makes the CCM a requirement rather than an option. A new Helm chart, aligned with the split deployment modes, with toggles to enable or disable individual components and Helm hook tests that provision a volume to check the install. The XO client timeout is now a driver flag, -xo-client-timeout, defaulting to 30 seconds, instead of living alongside the credentials. The kxo helper also gains a --vdi-name-prefix override. ### Cloud controller manager v1.1.2 The CCM's Helm chart gains an `rbac.create` switch, so you can turn off the Role and RoleBinding that the chart would otherwise create and manage RBAC yourself. Useful in clusters where a platform team owns RBAC centrally. The release workflow also learned to cut chart-only releases, so a packaging fix no longer needs a driver release behind it. The Kubernetes toolkit is still taking shape, and we would rather shape it with the people who will run it. If your team already runs Kubernetes on XCP-ng, or is working out whether to, tell us what you need from it. The Cluster API provider in particular is still early enough that there is real room to influence where it goes, and we would rather build against real workloads than our own assumptions. ## 📖 Documentation & Guides The documentation got a structural pass, along with a new page for the IPMI plugin covering sensor rules and the REST endpoint that shows what your hosts actually report. ### Cleaner documentation structure Documentation accumulates. Pages get added where there was room rather than where they belong, titles get written in whatever style the author had in mind that day, and after a while finding something depends on knowing where it was put. We went through the Xen Orchestra documentation to fix that. Page titles and navigation labels have been reworked to be easier to scan. XO 5 and XO 6 content is now clearly distinguished, which matters while both interfaces are in use and a page that applies to one but not the other is easy to land on by mistake. Naming follows a consistent style: title case is gone in favour of sentence case, as our guidelines recommend, and related pages now share the same patterns, so Management in XO 5 and Management in XO 6 read as a pair rather than as two unrelated pages. Navigation labels stay short without becoming cryptic. A few sections and pages also moved or were renamed where their previous location or title sent you looking in the wrong place. ![](https://xen-orchestra.com/blog/content/images/2026/08/Nouveau-projet.png) Old structure (left) vs. new structure (right) [Xen Orchestra in a nutshell | Xen Orchestra | XO DocumentationXen Orchestra (XO) is the complete solution to visualize, manage, back up and delegate your XCP-ng (or XenServer) infrastructure: any number of pools, on any site, from one place. No agent is required for it to work. Together with XCP-ng, it forms Vates VMS, the fully open source virtualization stack built and supported by Vates.![](https://xen-orchestra.com/blog/content/images/icon/favicon-ea8d9c35-ec81-472e-b35a-a5b9dbb90d2c.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-d64baeb1-2f9d-47fa-b93e-88f1875e9e16.png)](https://docs.xen-orchestra.com/?ref=xen-orchestra.com) ### IPMI plugin doc We’ve added a new documentation page for the IPMI plugin. It explains how the plugin handles IPMI sensors and what to do when a sensor isn't recognized by default. You’ll also find instructions for adding custom rules and using regular expressions to match specific sensors. The guide covers the [IPMI REST endpoint](#ipmi-sensors-over-the-rest-api) as well, which you can use to inspect the raw data available from your hosts. This should give you everything you need to set up the plugin and handle sensors that aren't covered by the default rules. ![](https://xen-orchestra.com/blog/content/images/2026/08/ipmi-plugin-doc.png) Preview of the IPMI plugin documentation ### IPMI sensors over the REST API The IPMI sensors plugin now has a REST endpoint. `GET /rest/v0/plugins/ipmi-sensors/hosts/{id}/ipmi` returns a host's IPMI sensor readings, so you can feed hardware health data into your own monitoring tooling. Also, the plugin [is now properly documented](#ipmi-plugin). ## 🌐 Translations A big thank you to our community for their ongoing efforts in translating Xen Orchestra! ### 6 languages updated This month, 6 languages were updated: **Brazilian Portuguese, Czech, Dutch, Finnish, Slovak, and Swedish.** ![](https://xen-orchestra.com/blog/content/images/2026/08/687474703a2f2f7472616e736c6174652e76617465732e746563682f7769646765742f78656e2d6f72636865737472612f6d756c74692d6175746f2e737667.svg) Current XO translation status Want to help translate Xen Orchestra or improve existing translations? You’re more than welcome to join in [here](https://translate.vates.tech/?ref=xen-orchestra.com). ## 🆕 Misc The most consequential item here is a memory fix. During a large backup over a slow connection, buffered task updates could accumulate enough to bring `xo-server` down. ### Fixed: task memory usage Now, XO 5 uses less memory when a client has a slow or unreliable connection. Previously, a slow or high-latency connection between `xo-server` and the client could cause task updates to pile up in memory. During a large backup, this could use enough memory to bring down `xo-server`. XO now limits how much task data it buffers, which prevents updates from piling up indefinitely. ### Xen Orchestra 6.7 URL: https://xen-orchestra.com/blog/xen-orchestra-6-7/ Last updated: 2026-07-30T15:32:47.000Z This month is about making the entire Vates ecosystem easier to use, whether you're deploying your first XCP-ng host, automating large-scale operations, or maintaining production infrastructure. Alongside Xen Orchestra 6.7, we've significantly refreshed our documentation on [**docs.vates.tech**](https://docs.vates.tech/?ref=xen-orchestra.com), making it easier to find hardware compatibility information, security advisories and common deployment guides. On the product side, we've invested heavily in the reliability of Rolling Pool Update, continued expanding the REST API for automation, and brought even more day-to-day administration workflows into XO 6. Add Backup improvements, quality-of-life enhancements across the platform and a growing ecosystem around Vates, and this release continues our focus on making infrastructure management simpler, safer and more predictable. #### 🔗 Summary 👨‍🚀 [Project & Community](#%F0%9F%91%A8%E2%80%8D%F0%9F%9A%80-project-community) 💡 [Insights](#%F0%9F%92%A1-insights) 🎫 [Events & webinars](#%F0%9F%8E%AB-events-webinars) [****XO 6.7**](#xo-67) 1. 🛡️ [Security](#%F0%9F%9B%A1%EF%B8%8F-security) 2. 💾 [Backup](#%F0%9F%92%BE-backup) / [Important: incremental backups on QCOW2 disks without NBD](#important-incremental-backups-on-qcow2-disks-without-nbd) 3. 🛰️ [XO 6](#%F0%9F%9B%B0%EF%B8%8F-xo-6) 4. 🔭 [XO Lite](#%F0%9F%94%AD-xo-lite) 5. 📡 [REST API](#%F0%9F%93%A1-rest-api) 6. ☸️ [DevOps Tools](#%E2%98%B8%EF%B8%8F-devops-tools) 7. 🆕 [Misc](#%F0%9F%86%95-misc) As usual, this announcement is available as a Youtube video: ## 👨‍🚀 Project & Community A lot has happened around the Xen Orchestra ecosystem this month. From opening the Twinstor Tech Preview to announcing a soft-launch of our Vates Alliance Network and strengthening our ties with academia, we're continuing to invest not only in the product itself, but also in the community and ecosystem around it. ### XCP-ng 8.3 updates XCP-ng 8.3 LTS received a new security and maintenance batch on July 28\. The core of it is a Xen security update covering several advisories, the most notable being a grant-table type confusion that could let a guest escalate to host privileges or bring a host down (XSA-500). The batch also fixes a XAPI regression that left VBDs attached after a VM.revert, plus minor changes to build a refreshed 8.3 LTS installer ISO. Host reboots are required, so apply it through your pool's usual update path. [July 2026 Updates #1 for XCP-ng 8.3 LTSThis release batch contains a security update for Xen. This update also brings a fix for a XAPI regression causing VBD leaks. Other minor changes were needed to build an updated XCP-ng 8.3 LTS installer (ISO).![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-f28db8a0-df3c-4c52-9e03-b79aadc38b07.png)XCP-ng BlogPhilippe Coval![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1549916028-5fe07973a5c5-2603ab78-f1f6-4084-8e4f-e6a89505e56d)](https://xcp-ng.org/blog/2026/07/28/july-2026-updates-1-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) ### Twinstor Tech Preview is now open Last month, we introduced Twinstor with a live technology demonstration. This month, we're taking the next step by officially launching the **Twinstor Tech Preview**. Twinstor is our upcoming hyperconverged storage solution designed specifically for **two-node XCP-ng clusters**, eliminating the need for a SAN, a witness node or a third server. The Tech Preview is available to everyone. Anyone can deploy it, experiment with it and share feedback by joining the dedicated discussion on our community forum. Like any Tech Preview, real-world testing is the best way to help us improve the product. [TWINSTOR: next gen 2 nodes HCITWINSTOR: help us torture-test a 2-node hyperconverged storage for XCP-ng Hi everyone, We have been working on something we are quite excited about, and toda…![](https://xen-orchestra.com/blog/content/images/icon/512-a0906cd5732d33168c6b00efe7604bc795f619e7ceb6c73dae414dbd4515d891.png)XCP-ngolivierlambert![](https://xen-orchestra.com/blog/content/images/thumbnail/1-profileavatar-1620659303584-e738e4eb673a9f283c6863a80f4377bd880f8d680817ce8007db404746eb66c9.jpeg)](https://xcp-ng.org/forum/topic/12323/twinstor-next-gen-2-nodes-hci?ref=xen-orchestra.com) For users who want to go one step further, we're also launching a **guided evaluation program**. You can apply to participate, and we'll select a limited number of environments that best match the use cases we want to validate during this phase. Selected participants will receive direct support from our engineering team, benefit from dedicated communication channels, and take part in feedback sessions that will directly influence Twinstor's development before General Availability. Whether you simply want to try it in your lab or help us validate it in production-like environments, we'd love to hear your feedback. [Join the Tech Preview — TWINSTORJoin the official TWINSTOR Tech Preview: guided deployment, direct feedback to the engineering team, and early influence on what ships in GA.![](https://xen-orchestra.com/blog/content/images/icon/favicon-3b907a97aafef8f5bcc42c749fa77d835d1e1098cb4e588e81474a3df2f32ca0.ico)vates](https://cdn.vates.tech/twinstor/preview/?ref=xen-orchestra.com) ### docs.vates.tech gets a major refresh Our documentation is part of the product, so this month we gave [docs.vates.tech](https://docs.vates.tech/?ref=xen-orchestra.com) a substantial overhaul, reworking and expanding a large part of the content across the whole Vates VMS stack. A refresh this size inevitably leaves a few rough edges behind, so if you land on an outdated section or a dead link, you can now tell us right where you found it: every page carries a small "Was this page helpful?" feedback tool, and we actually read what comes through it. It is the quickest way to help us fix what the rewrite missed. The welcome page is worth a look on its own, with a new Popular Tasks section that puts what people usually come to the docs for, like installing XCP-ng, deploying Xen Orchestra or checking hardware, one click away. Two pages in particular got real attention. The [Vates Security Advisories](https://docs.vates.tech/security-advisories/advisories/?ref=xen-orchestra.com) page is now searchable by VSA, CVE or XSA number and filterable by severity, product and year, with an RSS feed for teams who would rather subscribe than check back. And the new [hardware compatibility list](https://docs.vates.tech/compatible-solutions/hardware-compatibility-list?ref=xen-orchestra.com) lets you search close to a thousand servers, NICs, storage controllers, GPUs and CPUs known to work with XCP-ng, filtered by category or version. [Vates VMS DocumentationDocumentation for the Vates Virtualization Management Stack (VMS): build, run and protect your virtualized infrastructure with XCP-ng and Xen Orchestra, fully open source and backed by professional support.![](https://xen-orchestra.com/blog/content/images/icon/vates-logo-128-79e4d879-2938-4f47-a561-160ce69a55de.png)Vates VMS Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-logo-a5262118-7bd7-4edb-9101-e5659ec943f4.png)](https://docs.vates.tech/?ref=xen-orchestra.com) ### How the NetBox plugin works We also published a closer look at the xo-server-netbox plugin: how the one-way sync to NetBox works, what it treats as its own, and why choices like IP-to-prefix matching or name deduplication work the way they do. If you're running NetBox alongside XO, or considering it, it's worth a read! [Xen Orchestra NetBox plugin: How the sync worksXen Orchestra always knows exactly what’s running: every VM, every pool, every interface. The xo-server-netbox plugin keeps that in sync with NetBox automatically, one way, without touching what you built by hand.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-9230ab6d-6e77-428c-8aea-13905bce5cc2.png)Xen Orchestra BlogPierre Donias![](https://xen-orchestra.com/blog/content/images/thumbnail/Vates_Fond-nuages-sans-planete-dc0607e6-a887-4246-971d-1bae0c04b583.png)](https://xen-orchestra.com/blog/p/f89e8553-a445-46f5-b869-caa649379214/?member%5Fstatus=free) ### The Vates Alliance Network is taking shape This summer also marks the soft launch of the **Vates Alliance Network**, bringing together technology partners, service providers and solution experts around the Vates ecosystem. The official launch is planned for September, but the network is already growing steadily. 🍒 ****One more thing…** [Veeam Data Platform 13.1](https://www.veeam.com/products/veeam-data-platform/latest-release.html?ad=homepage-hero-banner-1&ref=xen-orchestra.com) is officially out, with native support for XCP-ng now generally available. More info coming for next month release. ### SYS1 joins our channel network We're pleased to welcome **SYS1** as a new Vates reseller partner. With strong expertise in virtualization, infrastructure modernization and automation, SYS1 will help organizations deploy and operate the Vates virtualization stack while benefiting from local expertise and support. We're excited to start working together. [#opensource #virtualisation #cloud #infrastructure #souveraineténumérique | Vates Virtualization Management Stack (XCP-ng / Xen Orchestra)Une nouvelle aventure commence ! SYS1 rejoint aujourd’hui notre réseau partenaire !🤝 Ce nouveau partenariat repose sur une vision commune : accompagner les organisations dans leurs stratégies de modernisation des infrastructures et de souveraineté numérique, en leur proposant des solutions performantes, sécurisées et adaptées à leurs besoins. Merci pour votre confiance, et cap sur de beaux projets ! 🚀 Xavier Creyf, Fabrice Etcheverry, David OUBRE, Pierre LEONARD, Amandine Bravetti, Fanny Basset #OpenSource #Virtualisation #Cloud #Infrastructure #SouverainetéNumérique![](https://xen-orchestra.com/blog/content/images/icon/al2o9zrvru7aqj8e1x2rzsrca-19b079c09197fba68d021fa3ba394ec91703909ffd237efa3eb9a2bca13148ec)LinkedInVates Virtualization Management Stack (XCP-ng / Xen Orchestra)![](https://xen-orchestra.com/blog/content/images/thumbnail/1782896159204-33e8a80ae6e13d002d9d6b6e9c54d07c5577ea64da45a61f1888950fec0513ec)](https://www.linkedin.com/posts/vates-sas%5Fsys1-vates-opensource-activity-7478074308280598528-Ws32?ref=xen-orchestra.com) ### Investing in the next generation We're also proud to announce a new partnership with **Grenoble INP – Ensimag**, one of France's leading engineering schools in computer science and applied mathematics. The partnership covers educational resources, internships, collaborative projects and closer ties between academia and industry, helping prepare the next generation of engineers working on open-source infrastructure technologies. [#partenariat #ensimag #relationsecoles #innovation #numérique | Vates Virtualization Management Stack (XCP-ng / Xen Orchestra)Vates signe aujourd’hui officiellement son contrat de partenariat avec Grenoble INP - Ensimag, UGA ! 🤝 Animé par la volonté de relier savoirs et pratiques, Vates se réjouit de s’associer à cette structure académique. L’Ensimag est une école née de la vision du mathématicien et pionnier du numérique Jean Kuntzmann, ayant façonné des générations d’ingénieurs. Membre du Groupe INP, cet établissement grenoblois est désormais une véritable référence parmi les écoles françaises du numérique. Cette alliance, tournée vers l’avenir, sera concrétisée par : 🔸la valorisation d’une alternative européenne et open source, 🔸la mise à disposition d’outils, de logiciels et de ressources, 🔸le rapprochement des besoins d’industriels et des problématiques de recherches, 🔸le développement de nouveaux travaux pédagogiques, 🔸la proposition de stages et le recrutement de talents, 🔸la participation aux événements et à la vie de l’école. Ensemble, en croisant nos expertises, nous accompagnerons avec conviction les ingénieurs du numérique de demain. Lors de cette signature, Nithida VIALLE et Estelle BOROT ont eu le plaisir d’accueillir Pr Alain TCHANA et Oarda Cesarano. Merci à eux et également à Grenoble INP, Ensimag pour cette opportunité. #Partenariat #Ensimag #RelationsEcoles #Innovation #Numérique![](https://xen-orchestra.com/blog/content/images/icon/al2o9zrvru7aqj8e1x2rzsrca-19b079c09197fba68d021fa3ba394ec91703909ffd237efa3eb9a2bca13148ec)LinkedInVates Virtualization Management Stack (XCP-ng / Xen Orchestra)![](https://xen-orchestra.com/blog/content/images/thumbnail/1784643426731-258abbd38b04111985293aa81fd841152b71fe65d2cc109084761a87c34fb377)](https://www.linkedin.com/posts/vates-sas%5Fpartenariat-ensimag-relationsecoles-activity-7485337074766848000-ybeo?ref=xen-orchestra.com) ### The team is still growing As Vates continues to grow, we're currently recruiting across several positions, including: - Internal Tools Developer - Channel Account Manager - XCP-ng XAPI Developer - Alliance Solutions Engineer If you'd like to help shape the future of open-source virtualization, we'd love to hear from you. [Careers at VatesWe recruit new talent every year, all over the world. If you don't see a vacancy that matches your profile but think you have something to contribute to Vates, please send us a CV anyway. We respond to everyone.![](https://xen-orchestra.com/blog/content/images/icon/apple-touch-icon-02f5e9d3a65d7fd40590a5e1d38a36241cef8dbb4c424309cccbf6254800e6f3.png)![](https://xen-orchestra.com/blog/content/images/thumbnail/logo-vates-aa972d123394ff3133108311980774387606864c08fe86ad4b8dfe97021a5651.png)](https://vates.tech/en/careers?ref=xen-orchestra.com) ## 💡 Insights This month, we are introducing a new section. **Insight** explores recent industry events and the practical takeaways they offer for our users and the wider virtualization ecosystem. ### What the Hugging Face incident teaches us about local AI Hugging Face disclosed on 16 July that an autonomous AI agent had compromised part of its production infrastructure, and OpenAI confirmed on 21 July that the models were its own, running a cyber-capability benchmark with refusals deliberately reduced. The technical timeline published since puts numbers on it: roughly 17,600 attacker actions between 09 July 02:28 UTC and 13 July 14:14 UTC, at a pace the responders describe as "far beyond what an operator could sustain by hand". They were not trying to break out. Hugging Face's own conclusion is blunter than anything we would write for them: "We believe the entire intrusion was, from the agent's point of view, an attempt to cheat the evaluation." The answer key lived on their production systems, and the agent got there through the sandbox's one permitted path, a package-registry cache proxy carrying a zero-day. From there it read a production object holding 136 keys, minted its own identity tokens from a harvested EdDSA signing key, joined the corporate mesh VPN on a stolen auth key, and respawned itself across eleven nodes. [OpenAI and Hugging Face partner to address security incident during model evaluationOpenAI and Hugging Face share early findings from a security incident during AI model evaluation, highlighting advanced cyber capabilities and lessons for defenders.![](https://xen-orchestra.com/blog/content/images/icon/favicon-c08baf70-6d57-4f6c-a44d-83ca9456d440.svg)OpenAI![](https://xen-orchestra.com/blog/content/images/thumbnail/Hugging_Face_Security_Incident_16x9-18a70382-55fa-4865-885e-15423d5ed3ed.png)](https://openai.com/index/hugging-face-model-evaluation-security-incident/?ref=xen-orchestra.com) The part worth your attention is where it stopped. The production database never answered, because the allow-list only accepted connections over a private link and the agent's attempt timed out. The CI pipelines refused it because execution policies said no. Neither of those is clever and neither was bought recently. They are boundaries you draw once and then maintain, and they are what something moving at that cadence ran into. The responders then hit a second problem: they could not send the attacker log to hosted models, because provider guardrails cannot tell an incident responder from an attacker, treating "reverse-engineering an exploit the same as launching one". They ran the forensics on ZAI's GLM-5.2 on their own infrastructure instead. If you want that option ready before you need it, our July 2025 walkthrough covers running GPU-powered models on XCP-ng. [Your own GPU-Powered LLMs with XCP-ngDiscover how easy it is to deploy a fast, local AI assistant on your infrastructure using XCP-ng and a single GPU.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-4434e8e39de9ea359f7aca69ed0207c6a51d045203147d6c87995f16495da9b5.png)XCP-ng BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/gpullmxcp-f16f0b3fb3f6d140399017f414d038ee7823945854d1b84d5fdba1d5ff8528c0.jpg)](https://xcp-ng.org/blog/2025/07/28/your-own-gpu-powered-llms-with-xcp-ng/?ref=xen-orchestra.com) ## 🎫 Events & webinars We keeps you up to date with where we've been, where we're heading next, and the events where you can meet the Vates team. #### Digital Summ'r - 2026/08/27 Jean-Baptiste (VP alliances) is giving a talk at Digital Summ'r, at the Campus Région du Numérique near Lyon. More details are coming soon, but you can already save the date on your calendar! ### Reduce infrastructure costs and simplify virtualization management, with EasyVirt ### We ran a joint webinar with EasyVirt on **2 July**, presented by Jeff Duerr (US Sales Manager) for us and François Machacek (Business developer) for EasyVirt. The thread running through it was doing more with the infrastructure you already have: bringing costs down, managing more than one hypervisor from one place, and taking the risk out of a migration before it reaches production rather than after. The recording is up, 45 minutes, so you can watch it back rather than take our word for it. ### Salon Souveraineté Numérique We were at the Salon Souveraineté Numérique at the start of July, on booth E02\. The pitch we took there was the one we keep coming back to: sovereignty is not only about where the data sits, it is about whether you could keep running if your vendor disappeared or changed direction tomorrow. [#souveraineténumérique #ssn26 #virtualisation #cloudsouverain | Vates Virtualization Management Stack (XCP-ng / Xen Orchestra)Reprenez la main sur votre infrastructure. Notre équipe vous attend au Salon Souveraineté Numérique ! 👋 Votre fournisseur disparaît ou change de stratégie. Seriez-vous toujours capable de faire fonctionner votre solution normalement ? C’est LA question à se poser lorsqu’on parle de souveraineté numérique. ❌ Non, la souveraineté n’est pas qu’une affaire de localisation de données. ✅ Il s’agit d’une question de maîtrise. C’est pour cela que la souveraineté se décline en trois niveaux d’exigences : 🟠 La souveraineté d’apparat. Rebranding : un drapeau européen est mis sur une technologie étrangère. 🟡 La souveraineté sous tutelle. Hébergement local, mais le code, les licences et la gouvernance restent extra-européens. 🟢 La pleine souveraineté. Maîtrise du code, des données, des mises à jour, de la gouvernance et du support sur le territoire européen. Ces niveaux sont une matrice de risque. Une manière d’évaluer ses dépendances, pour mieux situer son niveau d’autonomie réel. Pour faire progresser votre stratégie de souveraineté, nous vous présentons Vates VMS : une stack de virtualisation open source, sans mécanisme de verrouillage technologique ou dépendance à un éditeur propriétaire non européen. Franchissez un nouveau cap : venez échangez avec nous sur le stand E02, et découvrez comment maîtriser durablement votre infrastructure ici ➡️ https://lnkd.in/eVmWscgY Timothé Léonetti, Delphine Le Pochat, Jb Piacentino, Marc-André PEZIN #SouverainetéNumérique #SSN26 #Virtualisation #CloudSouverain![](https://xen-orchestra.com/blog/content/images/icon/al2o9zrvru7aqj8e1x2rzsrca-19b079c09197fba68d021fa3ba394ec91703909ffd237efa3eb9a2bca13148ec)LinkedInVates Virtualization Management Stack (XCP-ng / Xen Orchestra)![](https://xen-orchestra.com/blog/content/images/thumbnail/1782893178979-1caff61efb269cc7f22782bf25139160e9714edd61f2d1e7855198fd2b21ee8c)](https://www.linkedin.com/posts/vates-sas%5Fsouverainetaeznumaezrique-ssn26-virtualisation-activity-7477995999786000386--U1v?ref=xen-orchestra.com) ### What's next - 🇫🇷 ADIRA x Polypus — Lyon, France — 2026/09/25 - 🌍 Pure Accelerate (Everpure) — Paris, France — 2026/10/15 # XO 6.7 This month's release is primarily about operational excellence. You'll certainly notice the new features added throughout XO 6, but behind the scenes an enormous amount of work has gone into making Xen Orchestra more resilient, particularly during maintenance operations. From Rolling Pool Updates to Backup and REST API integrations, Xen Orchestra 6.7 focuses on reducing operational friction and making production environments even easier to manage. 🗒️ Read the changelog on Github: [CHANGELOG.md](http://changelog.md/?ref=xen-orchestra.com) ## 🛡️ Security Security rounds up the latest security advisories from Vates and the wider virtualization ecosystem, highlighting what deserves your attention and, more importantly, what action to take. ### July security update for XCP-ng 8.3 LTS The latest **XCP-ng 8.3 LTS** update delivers one of the largest security batches of the year, incorporating fixes related to **11 Xen Security Advisories**, alongside a XAPI regression fix and other maintenance improvements. Not every advisory affects XCP-ng, but all have been reviewed and assessed to provide complete transparency on their impact. [July 2026 Updates #1 for XCP-ng 8.3 LTSThis release batch contains a security update for Xen. This update also brings a fix for a XAPI regression causing VBD leaks. Other minor changes were needed to build an updated XCP-ng 8.3 LTS installer (ISO).![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-ff902648-d1d9-4971-a2c1-4fea8af9b693.png)XCP-ng BlogPhilippe Coval![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1549916028-5fe07973a5c5-7601a3e5-616f-4529-98f3-b3b4d9bdd652)](https://xcp-ng.org/blog/2026/07/28/july-2026-updates-1-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) One advisory worth highlighting is **XSA-498 (CVE-2026-42491)**, which affects the C# and PowerShell XAPI SDKs. While the main RPC connection correctly validates TLS certificates, some secondary HTTP handlers did not, potentially allowing a man-in-the-middle attacker to intercept authenticated traffic. There is no configuration-based mitigation. Updating XAPI is only the first step: any third-party application built against the affected C# or PowerShell SDKs should also be rebuilt using the corrected libraries, including the community PowerShell module. As always, we recommend keeping your XCP-ng hosts up to date. Our update process not only delivers upstream security fixes but also provides a clear assessment of which vulnerabilities actually affect XCP-ng, helping you focus on what really requires action. [XSA-498 - Xen Security Advisories![](https://xen-orchestra.com/blog/content/images/icon/favicon-5c40d4d7901e2a370440a03657de7cbad614851e3ca4c8333cd74e7bbf0c1600.ico)Xen Security Advisories](https://xenbits.xen.org/xsa/advisory-498.html?ref=xen-orchestra.com) ## 💾 Backup This month's Backup improvements focus on reliability rather than new functionality. Whether you're protecting production workloads or strengthening your ransomware strategy with immutable repositories, Xen Orchestra 6.7 removes several sources of unnecessary friction and improves the overall backup experience. ### No more false alerts for encrypted backups If you use encrypted backups, you've probably encountered warnings reporting an unexpected backup file size even though the backup itself completed successfully. While harmless, these alerts appeared frequently enough to become background noise, making it harder to distinguish genuine issues from false positives. After identifying the root cause, Xen Orchestra now correctly handles encrypted backup file sizes, eliminating these misleading warnings and making Backup reports more trustworthy. ### Better support for immutable repositories Immutable repositories are becoming an increasingly common part of ransomware protection strategies, and we're continuing to improve Xen Orchestra's support for them. Following feedback from early production deployments, several improvements have been made to better handle immutable remotes and improve compatibility across a wider range of environments. > This is another example of how real-world customer feedback directly helps us improve the platform for everyone. ### Important: incremental backups on QCOW2 disks without NBD ⚠️ ****Important:** If you use ****QCOW2** disks, ****please read this section carefully**. Some backup configurations could produce seemingly successful backups that are ****not fully recoverable**. Xen Orchestra 6.7 fixes the issue (latest branch), but additional action may be required depending on your setup. If you run QCOW2 disks without NBD, your backups and replications may have been silently completing green while holding almost no data. Xen Orchestra 6.7 (latest) fixes this. Find your situation below and take the matching action. **What happened** Our backup engine use 2MB block, QCow2 are exported by 64KB blocks of data, so we built adapter classes to produce 2MB block from 64KB data stream, computing a virtual offset of the 64KB chunk into the 2MB virtual block on the fly. The offset is measured from the start of the disk instead of from the start of that block. Block index 0 come out correct, because for the first block the two are the same. Every block after it write past the end of its destination buffer and does nothing, leaving zeros. The result announces itself as a full backup while holding real data only in its first block. No errors, no warning, and the job status is green. With NBD enabled, this adapter is never used, we can read any arbitrary offset of the disk data from the source, so we read it directly in the 2MB chunk needed by the backup engine. Incremental backup without NBD was expected to be a fall back scenario during beta/transition, since it can never run an incremental job: computing the 2MB block from a 64KB cluster need to read at arbitrary size in the parent to fill the 2MB block with the parent’s data, so the backup was fall back to a full each time. **What 6.7 (latest) does** Xen Orchestra 6.7 fixes the offset ([PR #10164](https://github.com/vatesfr/xen-orchestra/pull/10164?ref=xen-orchestra.com)) and adds two guards around it. On the next run, XO walks back to the root of the chain and forces a full transfer if the base disk's first blocks look empty. And NBD that is configured but not actually reachable, usually a transfer-network misconfiguration, now raises an explicit error instead of sliding quietly back into the fallback. **Which situation are you in?** Find the line that describes you. - **No QCOW2 disks.** VHD never goes through this code. Nothing to do. - **QCOW2 with NBD from the start.** This is the tested path. Nothing to do. - **QCOW2 with NBD enabled recently, after your last full backup or replication ran.** Action required (see below). - The safety net cannot detect this case: the damaged full (backup or replication) has since been merged with a delta that does put data at the front, so the check sees data and stays quiet. - **QCOW2 without NBD** Treat these backups as not valid. Action required (see below). [Incremental Backups | Xen Orchestra | XO Documentation\_NOTE:\_ Formerly known as Continuous Delta backups![](https://xen-orchestra.com/blog/content/images/icon/favicon-6536264c-3ea5-482b-81e6-e860a57d7cbd.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-c82dad5a-1858-4f41-8f42-fbf3c8e2f2ad.png)](https://docs.xen-orchestra.com/xo5/incremental%5Fbackups?ref=xen-orchestra.com#nbd-enabled-backups) Check here whether NBD is really active If you can't tell whether NBD was enabled recently or from the start, don't guess. - Run a health check and/or perform a test restore of your last backup (successful restore is the only real proof your data is safe) or - Create a fast clone of your replica and start the VM. **Your path to safety - 2 options** 1. **Upgrade to XOA 6.7 latest**, then follow *QCOW2 without NBD*: 1. Upgrade to 6.7 2. Let one full run complete on the new code 3. Then enable NBD [Incremental Backups | XO Documentation](https://docs.xen-orchestra.com/xo5/incremental%5Fbackups?ref=xen-orchestra.com#nbd-enabled-backups). 2. **Stay on XOA 6.6 or earlier**, then follow *QCOW2 with NBD enabled recently* 1. Delete that job's snapshots so the next run is forced to take a genuine full. 💡 ****In both case** : Check your backup, with the builtin health check or by doing a full restore of one backup. Automatic health check needs the VM to have guest tools installed. ### Backup retention calculator Choosing the right backup retention policy isn't always straightforward. To help with that, we released a new **Backup Retention Calculator** in the Xen Orchestra documentation. Whether you're designing a simple retention policy or a more advanced schedule, it provides an easy way to visualize how many restore points will be kept over time and validate your configuration before deploying it. [Backup retention calculator | Xen Orchestra | XO Documentation\- One restore point per backup run (the default is one run per day).![](https://xen-orchestra.com/blog/content/images/icon/favicon-7665a76a-8223-4ecb-b3b4-cb2406372f9f.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-9e7c09be-0716-4777-b4fa-232f56f379d5.png)](https://docs.xen-orchestra.com/xo5/calculator?ref=xen-orchestra.com) ## 🛰️ XO 6 One of our priorities with XO 6 remains simple: making the new interface the place where you can perform your everyday administration tasks without switching back to XO 5. ### More everyday workflows now available in XO 6 XO 6 continues to close the remaining feature gap with XO 5 by bringing more frequently used administration tasks directly into the new interface. This release introduces: - VM duplication - VM export - Creating a VM directly from the Host view - Adding a VIF from the VM Network tab - HA restart priority during VM creation - New actions in the Tree View - Better Traffic Rules filtering - Improved task names through object resolution - Estimated per-VM power consumption based on host IPMI metrics Rather than introducing a single headline feature, these improvements remove many of the small reasons administrators still occasionally switched back to XO 5. ![](https://xen-orchestra.com/blog/content/images/2026/07/Capture-d-----cran-du-2026-07-22-16-07-53.png) ![](https://xen-orchestra.com/blog/content/images/2026/07/image--1-.png) ![](https://xen-orchestra.com/blog/content/images/2026/07/image--2-.png) ![](https://xen-orchestra.com/blog/content/images/2026/07/image--3-.png) ![](https://xen-orchestra.com/blog/content/images/2026/07/image--4-.png) ![](https://xen-orchestra.com/blog/content/images/2026/07/image--6-.png) ### Highlights A few of these improvements deserve a special mention. **Duplicate a VM** VM duplication is now available directly from XO 6\. Whether you're preparing a risky upgrade, creating a test environment or replicating a manually configured appliance, you can now duplicate virtual machines without switching interfaces. **Create a VM directly from the Host view** Creating a virtual machine from a Host page now automatically selects the current host, reducing unnecessary navigation and making repetitive provisioning workflows smoother. **Estimated per-VM power consumption** Xen Orchestra can now estimate the power consumption of individual virtual machines using host IPMI power measurements combined with CPU utilisation. While not intended for billing, this provides a useful approximation when identifying the workloads that consume the most energy. ## 🔭 XO Lite XO Lite is designed for homelabs, small infrastructures and environments where deploying a full Xen Orchestra appliance would simply be unnecessary. ![](https://xen-orchestra.com/blog/content/images/2026/07/image--1--1.png) ![](https://xen-orchestra.com/blog/content/images/2026/07/image-6.png) ### More capabilities for lightweight infrastructure management With every release, we're carefully expanding its capabilities while keeping the interface lightweight and focused on the most common administration tasks. This release introduces several improvements, including: - connecting or disconnecting a VIF directly from the VM's **Network** view; - new Storage Repository management actions (connect, disconnect and delete); - additional copy helpers for IP addresses, bonded interfaces and network information. These additions make XO Lite even more practical for day-to-day administration, while preserving the simplicity that makes it a great fit for smaller deployments. ## 📡 REST API Xen Orchestra keeps becoming more automatable. Whether you're building your own self-service portal, integrating Xen Orchestra into an existing platform or simply automating repetitive administrative tasks, the REST API has become an essential part of the product. This release continues expanding its capabilities with several new endpoints covering host management, storage and backup operations. ### More control over hosts Host management receives a significant expansion in this release. Eight new Host actions are now available through the REST API, bringing it closer to feature parity with the Xen Orchestra interface and making infrastructure automation even easier. Maintenance mode has also evolved. Hosts will now **remain in Maintenance mode across reboots**, making hardware interventions and planned maintenance operations much safer. ⚠️ This is now the default behavior when enabling Maintenance mode through the REST API. ### Better backup repository management Backup repositories can now be validated directly through the REST API. Two new endpoints allow applications to verify repository connectivity before saving a configuration and benchmark repository performance when investigating backup throughput. These endpoints are particularly useful for custom portals, automation workflows and health checks, allowing problems to be detected before scheduled backups start. ### More API parity The REST API also continues closing the gap with the Xen Orchestra interface. This release introduces support for updating Virtual Disks through a new PATCH endpoint, while Storage Repository probe endpoints provide additional tooling for storage-related integrations. As always, complete endpoint documentation is available in the REST API reference. ## 🌐 SDN Controller SDN Controller covers new capabilities that simplify network policy management and day-to-day SDN operations. ### PATCH support for Traffic Rules The SDN Controller now supports updating Traffic Rules through PATCH endpoints at both the VIF and Network levels. Until now, modifying a rule required deleting and recreating it. With in-place updates now available, automating network policies becomes significantly simpler for configuration management and provisioning workflows. > This improvement originated directly from community feedback on the XCP-ng forum. ## ☸️ DevOps Tools This month, we're making it easier to automate existing infrastructures, integrate with Kubernetes and build against Xen Orchestra through continued improvements across our DevOps tooling. ### Terraform Provider Xen Orchestra v0.40.0 Importing existing Xen Orchestra VMs into Terraform is now supported, making it much easier to adopt Infrastructure as Code on existing environments without recreating resources. While some import drift still exists, work is already underway to further improve the experience. ### Kubernetes Cloud Controller Manager v1.1.1 This maintenance release includes Helm chart improvements, deployment manifest updates and dependency upgrades. If you deploy the Cloud Controller Manager through Helm, we recommend updating to this version. ### Golang SDK v1.18.0 Two releases landed since we last covered this one. v1.17.0 added the network service to the v2 client, so you can create, get and delete networks directly from it, and fixed the template value in the VM struct params so the template ID can be read directly rather than worked around at the call site. v1.18.0 followed with a smaller change: the v2 client's HTTP timeout is now configurable. ### Vates provider for the Kubernetes Cluster API keeps evolving Two new tags landed this cycle, v0.2.0-alpha1 and v0.2.0-alpha2, alongside a new templates/ directory covering ClusterClass definitions, machine templates and Packer image builds, plus more documentation. It is not production-ready, but it is already in the hands of customers and partners who are evaluating it, testing it, and sending back questions and feedback, so this is being co-built alongside the people who will actually run it. If you are looking at Kubernetes cluster lifecycle management on top of XCP-ng and Xen Orchestra, reach out. We want a close, fast line between your DevOps team and the people building this. [cluster-api-provider-vates/templates at main · vatesfr/cluster-api-provider-vatesCluster API provider implementation for Vates VMS (XCP-ng and Xen Orchestra) - vatesfr/cluster-api-provider-vates![](https://xen-orchestra.com/blog/content/images/icon/favicon-4b768ced-53b3-495a-aa75-3310a7aba265.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/cluster-api-provider-vates-c06c5971-5c5d-4bf8-a92b-b222294f8dd2)](https://github.com/vatesfr/cluster-api-provider-vates/tree/main/templates?ref=xen-orchestra.com) ## 🆕 Misc This month's misc updates focus on reliability and operational polish, making everyday administration more predictable, resilient and easier to troubleshoot. ### Automatic Pool Master tracking When a Pool Master changes, Xen Orchestra now automatically follows the new master instead of temporarily losing the pool connection. This removes one of the last manual recovery steps administrators occasionally encountered during maintenance operations. ### Rolling Pool Update becomes more traceable, safer and resilient Rolling Pool Update is one of Xen Orchestra's flagship features, allowing administrators to update an entire pool with minimal disruption. Because these operations are typically performed unattended on production infrastructure, reliability is just as important as new capabilities. This release delivers a broad set of improvements focused on making Rolling Pool Updates more resilient, more predictable and easier to troubleshoot. #### Better observability and recovery Rolling Pool Update (and Rolling Pool Reboot) now keeps a persistent execution trace on disk. If `xo-server` restarts during the operation, administrators and our Support team can easily determine which step was interrupted instead of losing the operation's history. To further improve safety, Xen Orchestra also prevents multiple Rolling Pool Updates from running simultaneously on the same pool. Connection handling has also been improved. Following a temporary loss of connectivity, such as when the Pool Master reboots during an update, Xen Orchestra now reconnects automatically instead of requiring manual intervention. #### Safer maintenance operations Several changes reduce the chances of an update failing halfway through maintenance. Before evacuating a host, Xen Orchestra now performs one final validation using the current state of the pool. If something has changed since the operation started, the update stops immediately with a meaningful XAPI error instead of failing later during the evacuation. Rolling Pool Update now also temporarily disables Pool Auto Power-On and restores the original configuration once maintenance is complete. This prevents virtual machines from unexpectedly restarting during maintenance and consuming resources needed by subsequent evacuations. Finally, workloads using PCI passthrough, SR-IOV or vGPU no longer prevent Rolling Pool Updates from running. After confirmation, Xen Orchestra gracefully shuts these VMs down before rebooting their host, then automatically powers them back on afterwards (requires Guest Tools). #### Improved production resilience Several additional improvements make Rolling Pool Updates behave more predictably on production infrastructures. If the Load Balancer plugin is enabled, it now remains suspended until a configurable safety delay has elapsed after maintenance, giving the infrastructure time to stabilize before workload rebalancing begins. LINSTOR environments also benefit from several improvements, including automatic retries when update plugins are temporarily busy and more accurate package installation progress reporting. Finally, compatibility with older XAPI versions has been improved by eliminating misleading warnings when Xen Orchestra transparently falls back to a compatible host evacuation method. ### DevBlog: Getting to know the NetBox plugin URL: https://xen-orchestra.com/blog/devblog-getting-to-know-the-netbox-plugin/ Last updated: 2026-08-12T12:38:40.000Z NetBox has become much more than an IP Address Management (IPAM) tool. For many organizations, it acts as the central source of truth for the entire infrastructure, bringing together virtualization, networking, documentation and automation in a single place. In that model, Xen Orchestra remains responsible for operating the infrastructure, while NetBox provides a consistent inventory consumed by network teams, CMDBs and automation platforms. The challenge is keeping both systems synchronized. As virtual machines are created, migrated or removed, manually updating NetBox quickly becomes impractical. That's exactly what the NetBox plugin is designed to solve. It continuously mirrors the virtualization layer into NetBox while preserving the manual information that belongs there, allowing each platform to focus on what it does best. #### 🔗 Summary [How synchronisation works](#how-synchronization-works) [What ends up in NetBox](#what-ends-up-in-netbox) [Running a synchronisation](#running-a-synchronization) [Keeping up with NetBox](#keeping-up-with-netbox) [Feedback and feature requests](#feedback-and-feature-requests) [Quick recap](#quick-recap) The NetBox plugin (`xo-server-netbox`) keeps your [NetBox](https://netbox.dev/?ref=xen-orchestra.com) instance in sync with Xen Orchestra. You point it at NetBox, choose which pools to track, and XO writes your clusters, VMs, network interfaces and IP addresses into NetBox for you. The setup steps, the NetBox objects you need to create beforehand and the list of supported NetBox versions are all in the official documentation, which we keep up to date: [Advanced features | Xen Orchestra | XO DocumentationThis section is dedicated to all others Xen Orchestra “advanced features”.![](https://xen-orchestra.com/blog/content/images/icon/favicon-ef527899-c5cd-471a-aa26-8620c98c91d6.ico)Xen Orchestra Documentationour blog post series about it![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-262b91b2-fe0c-40ab-bf56-35aa60f602be.png)](https://docs.xen-orchestra.com/xo5/advanced?ref=xen-orchestra.com#netbox) Check our setup guide here Set it up there first. What follows is a deep dive into how the plugin works and the cool things you can get from it. --- ## How synchronization works Synchronization goes one way. Xen Orchestra is the reference, and NetBox follows it. The plugin reads your pools and writes the result into NetBox, but it never synchronizes anything back into XO. ![](https://xen-orchestra.com/blog/content/images/2026/07/image.png) For the pools you select, it's also authoritative. If the plugin created a VM in NetBox and that VM later disappears from XO, the plugin removes it from NetBox on the next run. It only manages its own objects, though. Everything the plugin creates carries a custom field named `uuid` that ties it back to the matching object in XO. Anything in NetBox without that field, such as VMs, sites, prefixes or tenants you added by hand, is left untouched. The `uuid` field is also how the plugin updates an existing object instead of creating a duplicate, which is why the setup guide has you create it before anything else. This "only touch what it owns" rule is deliberate: the plugin is built to share your NetBox with you rather than take it over, and it goes out of its way to preserve your manual work. Objects you created yourself are never modified or deleted, and even when deduplicating names it avoids clashing with VMs you added by hand. The platforms and tags the plugin needs are only ever created, never removed or renamed, so the ones you set up yourself survive too. It fits VM IPs into the prefixes you've defined instead of inventing its own, never deletes a cluster on its own, and won't remove a tenant that other NetBox objects still depend on. When in doubt, it keeps your data rather than deleting it. ![](https://xen-orchestra.com/blog/content/images/2026/07/image-1.png) --- What ends up in NetBox A dedicated cluster type The plugin first makes sure a cluster type called `XCP-ng Pool` exists, and creates it if it doesn't. Everything XO manages goes under it, so you can always tell which clusters came from Xen Orchestra. One cluster per pool Each pool you selected becomes a NetBox cluster of that type. Clusters are created and updated automatically, but the plugin won't delete one on its own. Removing a cluster stays a manual decision, so you don't lose part of your topology because a pool was briefly unreachable. Virtual machines For every VM in a synchronized pool, NetBox gets a virtual machine with its name, description, notes (stored as comments), vCPUs, total disk, memory, power state, cluster, platform and tags. Running VMs are marked `active`, the rest `offline`. Two things to keep in mind: NetBox has stricter length limits than XO, so names are cut to 64 characters, descriptions to 200 and notes to 2048\. That's why a value can look slightly shorter in NetBox than in XO. Migrating a VM to another synchronized pool moves the existing NetBox VM to the new cluster instead of creating a second copy, again thanks to the `uuid` field. Name deduplication XO (and XCP-ng) lets you have ten VMs called `Web`. NetBox doesn't allow that, so when the plugin runs into a name that's already taken, it appends a counter: the first one stays `Web`, the next becomes `Web (1)`, then `Web (2)`, and so on. There are a few subtleties. The suffix is added so the name still fits in 64 characters (it shortens the base name if it has to), the comparison ignores case (`Web` and `web` count as the same name), and deduplication is computed across all the pools you sync at once. The last point avoids a VM bouncing between different numbers every time you migrate it. ![](https://xen-orchestra.com/blog/content/images/2026/07/image-2.png) The plugin is also smart about the counter when it checks whether a VM needs updating. When it compares a VM against the one already in NetBox, it ignores name differences that come only from the suffix. So a VM stored as `Web (2)` in NetBox isn't seen as changed just because XO still calls it `Web`, and it won't be renamed back and forth on every sync. Platforms When a VM reports its operating system, the plugin creates a NetBox platform from the distribution name (`Debian`, `Ubuntu`, and so on). On recent NetBox versions it also creates a versioned child platform such as `Debian 12` under `Debian`. The versioned name reuses the parent's spelling, so if one VM reports `fedora` and another reports `Fedora`, you still get a single `Fedora 38` rather than two nearly identical platforms. Tags XO VM tags are recreated as NetBox tags and attached to the matching VMs. Worth noting: NetBox matches tags by slug, and slugs ignore case. So `prod` and `Prod`, which are two separate tags in XO, become one tag in NetBox. Interfaces Each VM network interface (VIF) becomes a NetBox interface named after its device number (`eth0`, `eth1`, ...) and carries the VIF's MAC address. Remove an interface from a VM and it's gone from NetBox after the next sync. IP addresses An IP is only recorded in NetBox if it falls inside a prefix that already exists there. The plugin doesn't create prefixes for you, and that's deliberate: XO knows a VM's IP address but not the netmask behind it, so there's no reliable way to tell whether `10.0.0.5` belongs to a `/24`, a `/16` or a `/8`. Guessing would litter your IPAM with wrong or overlapping prefixes, so the plugin leaves that design to you and borrows the mask from the matching prefix when it records the IP. If an address has no matching prefix, it's skipped and logged in the XO server logs, so you know which prefix to add. When more than one prefix matches, the plugin uses the most specific one (the smallest network containing the address), so IPs land where you'd expect in your IPAM hierarchy. If you'd rather not import private addresses, the **Ignore RFC 1918 VM IPs** option skips the `10.0.0.0/8`, `172.16.0.0/12` and `192.168.0.0/16` ranges. Primary IPs The plugin also picks a primary IPv4 and a primary IPv6 for each VM, using the first address of each kind the VM reports. These are updated or cleared on their own as the VM's addresses change. ![](https://xen-orchestra.com/blog/content/images/2026/07/image-3.png) Users as tenants If you enable **Synchronize users**, your XO users become NetBox tenants and each VM is assigned to the tenant who created it, so you can see who created a given VM straight from NetBox. Deleted users are cleaned up too. When an XO user is gone, its tenant is removed, and if that tenant was still attached to some VMs, those VMs are unassigned first. The exception is a tenant that other NetBox objects depend on (a site, a prefix, a rack); the plugin leaves it alone and logs a warning rather than breaking those references. This feature needs the `uuid` custom field to cover the tenant type as well, which the setup guide explains. --- Running a synchronization The easiest way to keep NetBox current is the **Interval** option: set it to a number of hours and the plugin re-syncs on that schedule. Leave it empty and a sync only runs when you start one yourself: on a pool's page (XO 5 only), open the Advanced tab and click "Synchronize with NetBox". ![](https://xen-orchestra.com/blog/content/images/2026/07/image-4.png) The plugin tries to be light on your NetBox: it reads each collection once, batches its writes, and only ever sends the fields that actually changed, leaving anything that's already up to date alone. In practice the first sync does the heavy lifting, since it creates everything from scratch, so it can take a while on a large infrastructure. Every sync after that only touches what moved, so it's much faster. Triggering an on-demand sync from the XO REST API will be possible soon! --- Keeping up with NetBox NetBox moves fast, and we try to move with it. The plugin supports a wide range of NetBox versions, from older releases to the most recent ones, and every new NetBox version gets tested before we extend the supported range. You'll always find the current range in the [setup guide](https://docs.xen-orchestra.com/xo5/advanced?ref=xen-orchestra.com#supported-versions). Supporting a version isn't just about not breaking on it. When NetBox ships something useful, we try to make the most of it: the versioned sub-platforms you saw earlier (so `Debian 12` nests neatly under `Debian`) and the tenant mapping for XO users both build on capabilities NetBox added over time. At the same time, the plugin quietly adapts to the changes NetBox makes under the hood, so the same sync keeps working whether you're on an older instance or the latest one, without you having to think about it. --- Feedback and feature requests Got an idea for the plugin, or ran into something that should work differently? Let us know on [feedback.vates.tech](https://feedback.vates.tech/?ref=xen-orchestra.com). It's the best place to request features and tell us what would make the plugin more useful. --- Quick recap XO is the reference; NetBox mirrors it, one way only. The `uuid` custom field keeps the mirror accurate and your manual NetBox objects safe. Manual edits are preserved: the plugin never deletes what you created by hand and only ever adds the supporting objects it needs. Colliding names get a `(1)`, `(2)` suffix, computed across all your pools. An IP needs an existing matching prefix in NetBox; the smallest match wins. Clusters are never deleted automatically; VMs, interfaces and IPs are kept in step. For installation, prerequisites and the supported NetBox versions, see the [official documentation](https://docs.xen-orchestra.com/xo5/advanced?ref=xen-orchestra.com#netbox). ### Xen Orchestra 6.6 URL: https://xen-orchestra.com/blog/xen-orchestra-6-6/ Last updated: 2026-07-20T09:49:04.000Z It's release time again! With XO 6.6, we kept pushing on two fronts: who gets to do what, and what happens when an update goes wrong. You get scoped Storage and Network admin roles in the REST API, automatic XOA safety snapshots before updates, and a nice batch of V2V optimizations for smoother migrations. As always, plenty of smaller fixes round it out. Enjoy the read! #### 🔗 Summary 👨‍🚀 [Project & Community](#%F0%9F%91%A8%E2%80%8D%F0%9F%9A%80-project-community) 🏢 [User stories](#%F0%9F%8F%A2-user-stories) 🎫 [Events & webinars](#%F0%9F%8E%AB-events-webinars) [XO 6.6](#xo-66) 1. 🛡️ [Security](#%F0%9F%9B%A1%EF%B8%8F-security) 2. 💾 [Backup](#%F0%9F%92%BE-backup) 3. 🥝 [Core UI](#%F0%9F%A5%9D-core-ui) 4. 🛰️ [XO 6](#%F0%9F%9B%B0%EF%B8%8F-xo-6) 5. 🔭 [XO Lite](#%F0%9F%94%AD-xo-lite) 6. 🪐 [XOA](#%F0%9F%AA%90-xoa) 7. 📡 [REST API](#%F0%9F%93%A1-rest-api) 8. ☸️ [DevOps Tools](#%E2%98%B8%EF%B8%8F-devops-tools) 9. ⚖️ [Load Balancer](#%E2%9A%96%EF%B8%8F-load-balancer) 10. 🐦 [VMware to Vates (V2V)](#%F0%9F%90%A6-vmware-to-vates-v2v) 11. 📖 [Documentation & Guides](#%F0%9F%93%96-documentation-guides) 12. 🌐 [Translations](#%F0%9F%8C%90-translations) 13. 🆕 [Misc](#%F0%9F%86%95-misc) As usual, this announcement is available as a Youtube video: ## 👨‍🚀 Project & Community Beyond Xen Orchestra itself, the wider Vates platform kept moving this cycle: two rounds of XCP-ng updates, a signed Windows driver build, and a storage partnership worth flagging. ### DataCore storage compatibility Vates and DataCore announced a technical and strategic partnership to keep Vates VMS working smoothly with DataCore storage. For teams that already run DataCore, it's one less integration question when moving to XCP-ng and Xen Orchestra. [Vates and DataCore announce expanded storage compatibility for Vates VMSWe are pleased to announce a technical and strategic partnership between Vates and DataCore, designed to ensure seamless compatibility between Vates VMS and DataCore storage solutions, including SANsymphony and StarWind Virtual SAN.![](https://xen-orchestra.com/blog/content/images/icon/logo64-34c7a4374e6aada629d6344b403e9236ce922a1a013b741e577a7d074b7d4378.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/marcin-jozwiak-kGoPcmpPT7c-unsplash-2bb796eeb63fed34e0ef432b7eac3c4309d0dfa0b49006192f6fd19b8f783fa1.jpg)](https://vates.tech/blog/vates-and-datacore-announce-expanded-storage-compatibility-for-vates-vms/?ref=xen-orchestra.com) ### Signed Windows Guest Tools The XCP-ng Windows Guest Tools have a signed build again. Build **9.0.9137** is the first signed release since 8.2.2.200-RC1, more than six years ago, and **9.1.200** adds further bug fixes. A signed installer means Windows guests accept the drivers cleanly, without the friction that unsigned builds caused. If you maintain Windows guests, moving to a signed build is worth scheduling. [Release 9.0.9137 Release Signed · xcp-ng/win-pv-driversProudly presenting the first signed build of the XCP-ng Windows Guest Tools since 8.2.2.200-RC1 was released over six years ago. This build can be installed as-is without further configuration. To…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-e2c39927d004078983910c9017066f4257a1d80a7e2456753d1285938dd858e7.svg)GitHubxcp-ng![](https://xen-orchestra.com/blog/content/images/thumbnail/v9.0-4a801c96bdfd585692c5a6c742cbd241ab9ccac2ab4e891a24c694c30d66a68f.9137)](https://github.com/xcp-ng/win-pv-drivers/releases/tag/v9.0.9137?ref=xen-orchestra.com) ### XCP-ng 8.3 updates XCP-ng 8.3 LTS continued its regular maintenance and security cadence, with two update rounds this month. The first June round patched security vulnerabilities in the Linux kernel of the control domain (dom0), along with lower-priority maintenance fixes. The second round, pushed to the `xcp-ng-updates` repository across three tested batches, adds security fixes for both Xen and the kernel (not classed as critical, applied as defence-in-depth) on top of version bumps, bug fixes, and improvements. Apply them through your pool's usual update path. Each post lists the full set of changes and related advisories. [June 2026 Updates #1 for XCP-ng 8.3 LTSSecurity vulnerabilities have been identified and fixed in the Linux kernel used by XCP-ng’s control domain (dom0). Additional lower-priority maintenance updates are included in this release alongside these security fixes.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-4434e8e39de9ea359f7aca69ed0207c6a51d045203147d6c87995f16495da9b5.png)XCP-ng BlogPhilippe Coval![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1528035616016-47b960a7fac4-dd2573f76954df8ccd4813ae77745044ea55420f919f3b649e200838a7c3a711)](https://xcp-ng.org/blog/2026/06/02/june-2026-updates-1-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) [June 2026 Updates #2 for XCP-ng 8.3 LTSThis release batch contains security fixes for Xen and kernel as well as version updates, bug fixes and some improvements. The fixed vulnerabilities are not considered critical and are fixed as defence-in-depth.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-4434e8e39de9ea359f7aca69ed0207c6a51d045203147d6c87995f16495da9b5.png)XCP-ng BlogPhilippe Coval![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1534757889788-2aea3517f2ef-8f328d80ad1a8cbec732b0a5eaeffc4659701c5b8864d3aae9c097ba08447d16)](https://xcp-ng.org/blog/2026/06/23/june-2026-updates-2-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) ### TwinStor: a demonstrator for 2 nodes HCI Ever wanted a fully shared SR on just two XCP-ng hosts, no SAN, no NFS box, no third node playing witness? That is TwinStor: hyperconverged, replicated storage for a 2-node pool, built on the local disks you already have, so you finally get live migration, HA and snapshots on a two-host cluster. It is not a new storage engine, it is a harness over components you already trust (DRBD, iSCSI/multipath, XHA), and it is safe by default. We have hammered it hard ourselves, but there is no better QA than the community. So before we call it a product, we want you to break it: grab the test build, pull cables, cut power, reboot switches, and tell us what survives. [TWINSTOR: next gen 2 nodes HCITWINSTOR: help us torture-test a 2-node hyperconverged storage for XCP-ng Hi everyone, We have been working on something we are quite excited about, and toda…![](https://xen-orchestra.com/blog/content/images/icon/512-a0906cd5732d33168c6b00efe7604bc795f619e7ceb6c73dae414dbd4515d891.png)XCP-ngolivierlambert![](https://xen-orchestra.com/blog/content/images/thumbnail/1-profileavatar-1620659303584-e738e4eb673a9f283c6863a80f4377bd880f8d680817ce8007db404746eb66c9.jpeg)](https://xcp-ng.org/forum/topic/12323/twinstor-next-gen-2-nodes-hci?ref=xen-orchestra.com) 💡 Bonus: pair it with XO's Load Balancer anti-affinity and your VMs stay automatically balanced while the cluster is healthy, keeping the members of your own application-level HA (replicated databases, for example) on separate hosts. So even if you lose one host, you never lose both copies, your app's HA stays in your control! ### Behind the scenes: debugging a pool join failure When a host refused to join a pool after an upgrade from 8.2 to 8.3, the culprit was a TLS certificate verification error that traced back to a missing certificate bundle. This devblog from one of our engineers walks through the whole hunt, from the original forum report to the code, and the upstream change that now surfaces a clearer error message so the next person spots the cause without digging into the source. [Behind the scenes: debugging a pool join failureA user reported a pool join failure after upgrading to XCP-ng 8.3\. What started as a forum discussion led to a root-cause analysis, an upstream contribution, and a better error message for everyone.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-4434e8e39de9ea359f7aca69ed0207c6a51d045203147d6c87995f16495da9b5.png)XCP-ng BlogMarc Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/markus-winkler-NdhQbeGTA58-unsplash-1-9d3405d909210c8c8506329d464b9c7338f0a55fcd634b046c7f62e7de901ad6.jpg)](https://xcp-ng.org/blog/2026/07/20/behind-the-scenes-debugging-a-pool-join-failure/?ref=xen-orchestra.com) ## 🏢 User stories This month’s user stories highlight major migrations away from VMware toward Vates VMS. Biocoop successfully migrated its infrastructure to Vates VMS, reinforcing a broader trend we are seeing across organizations: moving away from legacy virtualization stacks in favor of more open, flexible, and cost-controlled environments. [Why Biocoop chose open-source virtualizationBiocoop chose Vates VMS to regain control over virtualization costs, governance, and long-term infrastructure decisions through open-source technologies.![](https://xen-orchestra.com/blog/content/images/icon/logo64-34c7a4374e6aada629d6344b403e9236ce922a1a013b741e577a7d074b7d4378.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/user-story-biocoop-vates-vms-migration-vmware-571fc228e3395037f241d3b5e4d37ab151cd2c3d6c71bc6879ebace9ceee75e1.webp)](https://vates.tech/blog/how-biocoop-began-its-strategy-to-move-away-from-vmware/?ref=xen-orchestra.com) KDDI France expanded its cloud offering and cut infrastructure costs with Vates VMS, without adding vendor lock-in. It is a good illustration of a trend we keep seeing: teams leaving legacy virtualization stacks for platforms that are more open, more adaptable, and cheaper to run over time. [KDDI France Scales Cloud Services with Vates VMSKDDI France reduced infrastructure costs and expanded its cloud offering by adopting Vates VMS! A pragmatic move toward flexibility and scalability, without added vendor dependency.![](https://xen-orchestra.com/blog/content/images/icon/logo64-34c7a4374e6aada629d6344b403e9236ce922a1a013b741e577a7d074b7d4378.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/kddi-france-vates-user-story-85431ba2552c4bbbf5cf7812c83edd65110dea088743161db2938da565f9a8e9.webp)](https://vates.tech/blog/expanding-cloud-capabilities-without-vendor-lock-in-the-kddi-france-story/?ref=xen-orchestra.com) ## 🎫 Events & webinars Beyond product updates, sharing experience and structuring knowledge remains an important part of the ecosystem. ### What we heard in Vienna and why Vates is investing in DACH We spent a week in Vienna alongside Bull, hearing how IT leaders across the DACH region now treat digital sovereignty as a mainstream procurement criterion rather than a defense-sector concern. The full write-up is in the Insights section above. [What we heard in Vienna and why Vates is investing in DACHDigital sovereignty has moved from defense-sector concern to mainstream procurement criterion in DACH. After a week in Vienna alongside Bull, we share what IT leaders are now asking, why the European stack conversation has changed, and how Vates is investing in the region, starting this June.![](https://xen-orchestra.com/blog/content/images/icon/logo64-34c7a4374e6aada629d6344b403e9236ce922a1a013b741e577a7d074b7d4378.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/jacek-dylag-5SjAaqqCCmY-unsplash-3bb51a1620a42ae464a8ab38e8672a2c2d1385d2b16f30b585e0b61d9ab0358e.jpg)](https://vates.tech/blog/what-we-heard-in-vienna-and-why-vates-is-investing-in-dach/?ref=xen-orchestra.com) ### Vates joins the HELIOS chair for confidential healthcare AI Vates is one of the industrial partners of **HELIOS** (Holistic Energy-aware & confidentiaL orchestratIOn for healthcare AI Systems), a new MIAI Cluster Industrial Chair hosted at Grenoble INP – UGA / LIG, which launched on **17–18 June 2026** in Grenoble, where Stanislas Assier de Pompignan signed the partnership for Vates. The chair tackles a hard problem: running healthcare AI on cloud infrastructure that is both energy-aware and genuinely confidential, so sensitive medical data stays protected end to end. On day two, Andrei Semenov (Vates) gave a talk titled "XCP-ng & Confidential VMs for healthcare", connecting XCP-ng (our open-source hypervisor) and our confidential-VM work to the chair's goal of a trustworthy, sovereign cloud for medical AI. ![](https://xen-orchestra.com/blog/content/images/2026/06/helios-signing.jpeg) (Philippe Wieczorek / Stanislas Assier de Pompignan (Vates)) [HELIOS - MIAI Industrial Chair![](https://static.ghost.org/v5.0.0/images/link-icon.svg)☀️ HELIOS![](https://xen-orchestra.com/blog/content/images/thumbnail/miai-9efa5c364644255545551b4ae5ede579d33bfe982d4e06620e800b004c41160f.jpeg)](https://helios.academy/?ref=xen-orchestra.com) #### VeeamOn Tour We were at VeeamON Tour Paris on June 18, where conversations with teams leaving VMware kept circling back to one topic: backup. Veeam's XCP-ng plugin has been in public beta since late 2025, and **official support is set to arrive with Veeam's next release**. Once it ships, you will be able to protect your XCP-ng workloads straight from Veeam Backup & Replication, while keeping the policies and repositories your teams already rely on. [XCP-NG Plugin for Veeam Backup & Replication Public BETA Review | Veeam Community Resource HubAfter about 18 months of many XCP-ng users making their voices heard on the Veeam Forums requesting Veeam to add Backup support, Veeam listened and has finally granted our request!...at least from a preliminary standpoint. As a member of the Veeam100 Community, I was one of several approached about…![](https://xen-orchestra.com/blog/content/images/icon/9fcbadba-fa71-42f3-a070-1df5e268329c-841e87acd6c9b986fb192cace145a11a70723efd14717e4157c1dafb1383fb69.png)veeam-en Logocoolsport00![](https://xen-orchestra.com/blog/content/images/thumbnail/dc66dfff-0a30-4692-89d3-ae8de9b951f9_thumb-825db8239f1445a5da4293d68ab60fee00bb3c25add86c983dc2194adfe3f38c.png)](https://community.veeam.com/blogs-and-podcasts-57/xcp-ng-plugin-for-veeam-backup-replication-public-beta-review-11677?ref=xen-orchestra.com) ### Vates & EasyVirt webinar On July 2, **Vates and EasyVirt** will host a webinar focused on infrastructure optimization, migration planning, and operational visibility across multi-hypervisor environments. The session will show how the integration of DC Scope and DC NetScope within the Vates ecosystem helps organizations optimize resource usage, secure migrations, monitor network flows, and keep control over infrastructure costs and operations from a single interface. [Register now](https://attendee.gotowebinar.com/register/530110195909328473?source=BlogPost+XO) --- # XO 6.6 This release moves on two fronts. On the access side, the REST API gains dedicated **Storage administrator** and **Network administrator** roles, and XO 6 adds an **Administration tab** with user management, so you can delegate scoped access without giving away the keys to everything. On the resilience side, **XOA now takes an automatic safety snapshot before every update**, turning a bad release into a quick rollback. A lot of the rest came from your feedback. A round of V2V memory optimizations makes large migrations lighter. Together with a fix for a memory crash on very large infrastructures, XO 6.6 keeps XO 6 maturing toward an interface you never need to leave. ## 🛡️ Security We continuously update our core components to keep your environment safe. This month, we refreshed several key dependencies to patch potential vulnerabilities and maintain modern safety standards. ### Security dependency updates XO 6.6 comes with security updates, as we’re bumping several critical dependencies to their latest versions. Keeping these packages up to date addresses known vulnerabilities and ensures compliance with modern security standards. These updates run under the hood and no manual configuration or changes to your existing workflows are required. ## 💾 Backup This month's updates don't change how your backups actually run, but rather how the interface displays what's happening. We focused on the front-end to bring back missing transfer details. After all, having clear, reliable numbers is the best way to keep things stress-free. ### Fixed: hidden incremental mirror size and speed Incremental mirror jobs stopped displaying their transferred size and transfer speed after a regression, which left you without the basic numbers you need to judge a job. We tracked down the regression and restored both readouts, so incremental mirror jobs once again report how much data has moved and how fast it is going. ![](https://xen-orchestra.com/blog/content/images/2026/06/598889757-94cef8f2-6520-486e-af67-9d4b894dacfc.png) Real-time status indicator for backup tasks ### ## 🥝 Core UI We're continuing to polish the Core UI so it looks and behaves more predictably. This month, it means fixing a major memory crash that triggered under heavy loads, while also refining a few visual elements to smooth out your daily workflow. ### Fixed: critical memory crash We resolved a critical bug where Xen Orchestra could crash when parsing massive NDJSON structures. This memory issue caused unexpected service interruptions, particularly in very large infrastructures with heavy data loads. By restructuring how the application handles these large data streams, the NDJSON parser no longer exhausts available resources. The platform now manages complex, large-scale environment data smoothly. This keeps the daemon up and running even under high stress. ### Web-core component polish We refined several of the building blocks used throughout XO 6, including the `UiInput` and `UiPanel` components, the side-panel title and identifier display, and the way the interface redirects you after an action completes. These are small changes on their own, but together they make the interface feel more consistent and predictable as you move between views. ![](https://xen-orchestra.com/blog/content/images/2026/06/608670636-339e8d75-ee37-4da1-becb-76b71bf90676.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/608670750-c9d3403a-44ad-4e17-a373-923085728946.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/608670961-0fb2130b-b069-4561-a4aa-4be2c7968187.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/608671034-6dcc315e-d0d5-4a44-973c-29337e90b019.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/608671333-ee3fe36c-68b7-4de4-add9-f6fa413513e2.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/608671397-61fc8689-9063-4c38-a0c9-4fb6fd2759c7.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/608671613-b948d822-86f7-4988-8de3-6274d3a2b7f4.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/608671682-b42b16a1-a5a3-4d35-94eb-a3c27a9ee4b8.png) Refreshed UI components ### Visible HA reboot settings Xen Orchestra now exposes the `ha_reboot_vm_on_internal_shutdown` setting at the pool level. This field controls what High Availability (HA) does when a VM is shut down from *inside* its own guest OS. If enabled, the pool will automatically restart the VM, even if the shutdown command came from the OS itself. Having this setting visible makes it easier to tweak your HA behavior across the entire pool. ![](https://xen-orchestra.com/blog/content/images/2026/06/604566417-45dd81db-ed95-418a-b84c-d495a0545612.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/605157776-1e23b566-4540-4094-bc31-4caf1757fa61.png) HA Reboot behavior settings in XO 6 ## 🛰️ XO 6 We're continuing to move everyday tasks over to XO 6 so you don't have to keep switching back to XO 5\. Now, You can handle things like storage repositories and network rules directly in the new interface, which also gets a few smart fixes to make navigation smoother. ### VIF column in the VM network view The **VM** → **Network** table now includes a Virtual Network Interface (VIF) column. This update provides a direct link between your VMs and their interfaces, so you can create, update, or delete traffic rules right from the network overview. ![](https://xen-orchestra.com/blog/content/images/2026/06/604885822-7596a9ab-6c55-4eb2-940c-f7e81fc7bbe8.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/604885883-af5943f3-7ca4-4130-abbd-3e4db1e5417c.png) VIF column in the VM → Network view ### Traffic rules mode notification We’ve added a notification to guide users who want to use the new network traffic rules feature, but are still using the legacy SDN controller configuration. Until now, the SDN controller defaulted to `channel` mode (where `useDirectChannel` is set to `true`). To create traffic rules, the controller must switch to `xapi-plugin` mode (`useDirectChannel` set to `false`). XO6 now detects this requirement and displays a clear notification to help users adjust their settings and unlock the feature. ![](https://xen-orchestra.com/blog/content/images/2026/06/611872458-9ae209a7-c615-4594-90ad-867903ccd853.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/611872772-330eccd1-be2f-4ee7-a88c-0497b41d5f9a.png) New notification for traffic rules ### Delete a traffic rule You can now delete a traffic rule directly from XO 6, so cleaning up a policy no longer means going back to XO 5\. Managing your network policies stays in the same interface as the rest of your pool networking. ![](https://xen-orchestra.com/blog/content/images/2026/06/603564638-60c806f0-8676-4b9e-adae-8adc70272486.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/603564704-90e5ecbc-6c72-49bd-a419-961fd1194a0d.png) 'Delete' action for traffic rules ### Admin tab + User management menu An **Administration** tab has been added to XO 6, with a dedicated **User Management** section . This layout simplifies administration by grouping access controls, roles, and permissions into a single, accessible view. It also lays the groundwork for more granular Role-Based Access Control (RBAC) management directly within XO. ![](https://xen-orchestra.com/blog/content/images/2026/06/602933519-2309e40d-61c1-407a-afcc-bfbe0d2895cd.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/602933628-0a81f280-ba13-4a32-9ea4-0a64eecf0529.png) Administration tab, with the User management menu ### Side panel title and ID updates We've refreshed the side panel header with cleaner spacing around the object title and IDs. We also turned the object's name into a direct link, so you can jump straight to its dedicated detail page with a single click. ![](https://xen-orchestra.com/blog/content/images/2026/06/581992429-e4f916bc-c2f0-4fee-b040-120a525ca924.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/581992512-a48de270-08d3-4000-9fa9-69938b7a4c7c.png) Refreshed side panel title and IDs ### Redirection after deleting an object XO 6 now handles page redirections gracefully after an object is deleted. Previously, if you deleted a VM or a VIF while viewing its dedicated page, you would often end up on a broken 404 error screen. Now, the UI automatically redirects you to a logical parent view. For example, deleting a VM will take you back to its host or pool VM list, while removing a VIF routes you right back to the parent VM's networks tab. If you trigger a deletion from a completely separate dashboard or list, your current view remains uninterrupted. ### Storage repository connect, disconnect, and delete You can now connect, disconnect, and delete storage repositories directly from XO 6, either on a single host or across every host in the pool. Managing SR connectivity no longer means dropping back to XO 5, which is one more daily task that lives entirely in the new interface. ![](https://xen-orchestra.com/blog/content/images/2026/06/606504413-a00eabed-61a7-4f16-9ea7-cb3b0b2b1697.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/606504917-74e8ef74-47c8-45d3-ab76-4d3f00619487.png) Connect/Disconnect/Delete SR actions ### **VDI export and migration** Virtual disks now have their own actions in XO 6\. You can export a VDI and migrate a VDI between storage repositories without leaving the new interface. Moving a disk to a different SR, or pulling a copy out for safekeeping, becomes a couple of clicks in the same place you manage the rest of your storage. ![](https://xen-orchestra.com/blog/content/images/2026/06/vdi-export-migrate-sidebyside.png) exporting a VDI from XO 6 / migrating a VDI between SRs in XO 6 ### Colored tags in the Policy column The **Policy** column under the **Pool → Security** view now supports colored tags. Instead of showing everything in a single neutral shade, the interface now assigns distinct colors to different tags. This tweak makes it easier to scan the table and quickly identify your security policies. ![](https://xen-orchestra.com/blog/content/images/2026/06/606971287-bee35694-704c-486e-ad7e-95ca4bc60e34.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/606971479-2f507ae6-38d1-4a29-b829-acef76a99359.png) Colored tags in the Pool -> Security -> Policy view ## 🔭 XO Lite XO Lite gets a couple of handy improvements to help you monitor and secure your infrastructure. We’ve added a Storage tab to help you keep an eye on your disk space, along with a safety warning to make sure you don't accidentally navigate away during an active deployment. ### Storage tab in Pool and Host views The **Pool** and **Host** views now feature a dedicated Storage tab. This way, you can inspect your storage configuration and monitor space usage easily. ![](https://xen-orchestra.com/blog/content/images/2026/06/612887228-e67d85c2-1944-46d8-a9da-afac79e3d18d.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/612887344-9d2abc7f-0518-4e1a-afc0-b669672021c5.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/612887839-5e25f8ff-a4fe-407a-9506-bea3d731614a.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/612888093-c75ecb12-c0df-4164-81f7-c5af432dc340.png) Storage tab in the Host and Pool views ### Warning before leaving a page XO Lite now warns you before you navigate away from a page while a deployment is still running. A deployment is exactly the moment you do not want to lose your place by accident, and this prompt gives you the chance to stay until it finishes. 0:00 /0:13 1× XO Lite throws a warning before leaving the page while a deployment is running ## 🪐 XOA With this release, we're adding some extra safety nets to XOA updates. You now get an automatic snapshot for an easy rollback if something goes wrong, and the `xoa check` tool will verify your network connection before a Node.js upgrade begins. ### Automatic safety snapshots Now, before applying an update, a new safety mechanism takes a snapshot of your XOA automatically. This provides an immediate fallback option if a release introduces unexpected issues or breaks the updater itself. This option is enabled by default, but it can be disabled in the settings if you prefer faster update times. The lifecycle of the safety snapshots is managed automatically, depending on the update outcome: - **Successful updates:** The snapshot is deleted after a 7-day retention period to save storage space. - **Failed updates:** The system prompts you to review the logs, gather bugtools for support, and safely revert to the pre-update state. ![](https://xen-orchestra.com/blog/content/images/2026/06/604498178-050deee5-ae95-424e-8810-79f332f83fda.png) XOA safety snapshot option 💡 ****Note:** Reverting an XOA snapshot will lead to audit log discrepancies. ### XOA check for nodejs.org access The `xoa check` diagnostic tool now verifies connectivity to `nodejs.org`. This check is crucial because some XOA updates include a Node.js version upgrade. Making sure your environment can reach this domain beforehand prevents update failures due to blocked network access. ### LDAP redundancy and multi-domain authentication Two enterprise authentication requests land together in this release. With LDAP redundancy, you can now configure a secondary LDAP server in the same domain. If the primary becomes unreachable, Xen Orchestra falls back to the replica, so a single directory outage no longer locks everyone out of the appliance. Multi-domain authentication lets Xen Orchestra authenticate users across more than one LDAP domain. This matters for organisations that grew through mergers or never had a single flat directory to begin with, because you no longer have to consolidate everyone into one tree just to sign in. Together these two changes make directory-backed login both more resilient and more flexible for larger deployments. ## 📡 REST API We’re expanding what you can do through the API with finer controls and better workflows. This includes the introduction of dedicated Storage and Network administrator roles, native authentication prompts, and new PATCH endpoints to update your resources more efficiently. ### Storage Administrator role A new **Storage administrator** role has been added to the API, as part of the ongoing ACL v2 / RBAC framework implementation. This role is perfect for team members who handle storage across your infrastructure. It gives them full control over storage repositories (SRs) and virtual disks (VDIs) on both hosts and VMs. This makes it easy to delegate storage management without handing over full admin access to everything else. Here are the privileges available for this role: | Resources | Action | Rationale | | ------------------------------------ | ------ | --------------------------------------------------------------------------------------- | | sr, vdi, vbd, pbd, backup-repository | \* | Full control over writable storage resources (wildcard is future-proof for new actions) | | vdi-unmanaged, sm | read | Read-only resources today — explicit read avoids granting phantom verbs | ### Network Administrator role Following the Storage administrator role, a new Network administrator role joins the ACL v2 / RBAC framework. It is ideal for team members who handle networking across your infrastructure, granting complete control over networks, bonds, and PIFs/VIFs across pools, hosts, and VMs while leaving the rest of the environment untouched. Here are the privileges available for this role: - **Networks** — `read`, `create`, `delete`, `update:tags` - **Pool** — `create:network` (network creation happens on the pool), `read` - **VIFs** (VM side) — full lifecycle: `read`, `create`, `delete`, `connect`, `disconnect` - **PIFs** (host side) — `read` only - **Hosts** — `read` only (context to see the hosts carrying the PIFs) ### Backup Repository endpoints The API now exposes endpoints to create and update backup repositories. These endpoints allow you to fully manage your backup storage destinations programmatically. You can now connect new remotes or adjust the configuration of existing ones directly through the API, making it much easier to automate infrastructure deployment and backup workflows. ### Basic auth challenge We’ve updated the behavior of the API when a request lacks authentication. Instead of returning a generic error, the API now responds with a standard `401 Unauthorized` status along with a `WWW-Authenticate` header. This change forces browsers and API clients to trigger a native Basic Auth prompt. With this change, you can now authenticate on the fly when accessing a protected endpoint. ![](https://xen-orchestra.com/blog/content/images/2026/06/601580193-024eac85-2b21-45b7-aea0-d0fb19aaf48d.png) Basic auth pop-up ### VM export compression options The API now offers detailed options to handle VM export compression. Instead of a generic true/false setting, you can now specify the exact compression method (`gzip`, `zstd`, or `undefined` to disable it). This provides clearer control and better flexibility when managing your exports. ![](https://xen-orchestra.com/blog/content/images/2026/06/image-1-.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/image.png) New export compression options ### E2E tests for the SDN controller To improve stability and prevent regressions, we’ve added end-to-end (E2E) tests covering all exposed SDN controller routes. These automated tests validate that the controller's API endpoints respond correctly and handle configuration changes as expected, which makes network management more robust and easier to maintain. ### PATCH endpoints for VMs, VIFs, and VDIs You can now update VMs and VIFs in place with PATCH requests on `/rest/v0/vms/{id}` and `/rest/v0/vifs/{id}`, so editing an object's properties no longer requires a workaround. A matching PATCH endpoint for VDIs on `/rest/v0/vdis/{id}` is on the way in this same cycle. ### Testing on a mock XO REST API A more subtle but impactful improvement this cycle is how software is built on top of Xen Orchestra. We’ve introduced a standalone simulator for the XO REST API, which is a mock environment you can run instead of a live instance. This allows client code to be tested without having to spin up a real Xen Orchestra server. The Go SDK is already putting it to use. Its integration tests now run against the simulator in CI, meaning the SDK is automatically validated on every change rather than relying on manual testing against a live server. This translates to faster, more reproducible testing for anything built on the API. Best of all, it’s fully open-source and not exclusive to Vates. Any partner or cloud provider building on the XO REST API is welcome to use it. [GitHub - vatesfr/xo-api-sim: A simulator (mock) for Xen Orchestra REST APIA simulator (mock) for Xen Orchestra REST API. Contribute to vatesfr/xo-api-sim development by creating an account on GitHub.![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-e2c39927d004078983910c9017066f4257a1d80a7e2456753d1285938dd858e7.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/xo-api-sim-792fc454a8c230060b471accd3596193d3560b1fae909d090d7ddceeb4c49e9d)](https://github.com/vatesfr/xo-api-sim/?ref=xen-orchestra.com) ## ☸️ DevOps Tools Our infrastructure-as-code tooling moved on several fronts this cycle, with new releases for the Terraform provider and the Kubernetes CSI driver, the first public appearance of a Kubernetes Cluster API provider, and a small addition to the Go SDK for those building directly on the API. ### Terraform provider v0.39.0 The Terraform provider gains two additions that make pool targeting and VM sizing more flexible. You can now use a new `xenorchestra_pools` data source with tag filtering, so a configuration can select every pool that carries a given tag instead of hardcoding each pool name by hand. This is particularly useful as your fleet grows and pools come and go, and it came directly from a community request. The release also adds CPU topology configuration through a `cores_per_socket` field, letting you describe how virtual cores are distributed across sockets rather than leaving the layout implicit. Together, these give you finer control over both where VMs land and how their CPUs are presented to the guest. [Release v0.39.0 · vatesfr/terraform-provider-xenorchestraWhat’s Changed feat(datasource/pools): Add xenorchestra\_pools data source with tag filtering in #409 feat(resource/vm): add CPU topology configuration (cores\_per\_socket) in #410 Full Changelog: v…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-e2c39927d004078983910c9017066f4257a1d80a7e2456753d1285938dd858e7.svg)GitHubvatesfr![](https://opengraph.githubassets.com/c6249b92acfe3d2119cdae7e3e72d120f093c001e35d54736f8eabdfdb48bc60/vatesfr/terraform-provider-xenorchestra/releases/tag/v0.39.0)](https://github.com/vatesfr/terraform-provider-xenorchestra/releases/tag/v0.39.0?ref=xen-orchestra.com) ### Kubernetes CSI driver v0.4.0 The Kubernetes CSI driver picks up local-storage support and an automatic pool-discovery fallback, so volume provisioning works in more cluster layouts with less manual configuration. The most significant change is internal: the driver now stores its Kubernetes metadata in Xen Orchestra VDI tags rather than the deprecated `other_config` field. A practical consequence is that the driver no longer requires Xen Orchestra 6.4 or newer, widening the range of deployments it supports. This release contains a breaking change. Because the metadata moved from `other_config` to VDI tags, a migration is required before you upgrade from v0.3.0\. Do not upgrade in place: follow the v0.3.0 to v0.4.0 migration guide in the release notes first, then move to v0.4.0. [Release v0.4.0 · vatesfr/xenorchestra-csi-driverNoteThis CSI doesn’t require anymore Xen Orchestra 6.4+. The driver now uses tags to store Kubernetes metadata in Xen Orchestra VDIs. WarningBreaking change — migration required before upgrading S…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-e2c39927d004078983910c9017066f4257a1d80a7e2456753d1285938dd858e7.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v0.4-82f48fb8e147dcac161865db907e58bab9a8b347e420fe791b147ef1c2ea40c8.0)](https://github.com/vatesfr/xenorchestra-csi-driver/releases/tag/v0.4.0?ref=xen-orchestra.com) The CSI driver is closing in on a stable release candidate, and early-adopter feedback is what will get it there. If you run Kubernetes on XCP-ng VMs, v0.4.0 is the one to try: tell us what works, what breaks, and which storage setups you are running. Every real cluster we hear about moves it closer to stable, so open an issue on the repo or come find us on the forum. ### Kubernetes Cluster API provider for Vates (early work in progress) We have started a brand-new project: a Cluster API infrastructure provider for Xen Orchestra. The goal is to manage the full lifecycle of VMs on XCP-ng pools as Kubernetes control-plane and worker nodes, so you can declare and scale clusters the Cluster API way and have the underlying virtual machines provisioned for you on Vates infrastructure. This is early development with no tagged release yet, so treat it as a preview of where we are heading rather than something to deploy today. The repository is public if you want to follow the work as it takes shape. [GitHub - vatesfr/cluster-api-provider-vates at xen-orchestra.comCluster API provider implementation for Vates VMS (XCP-ng and Xen Orchestra) - vatesfr/cluster-api-provider-vates![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-e2c39927d004078983910c9017066f4257a1d80a7e2456753d1285938dd858e7.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/cluster-api-provider-vates-03c220f1d96bfc5993716be3f30fc626945f2241830f8034bce6760e3c7135bf)](https://github.com/vatesfr/cluster-api-provider-vates?ref=xen-orchestra.com) ### Kubernetes cloud controller manager for Xen Orchestra v1.1.0 The Xen Orchestra Cloud Controller Manager reaches v1.1.0\. As a reminder, it registers Kubernetes nodes, keeps them labelled with Xen Orchestra metadata, and cleans them up when their backing VM disappears, so a single cluster can span several XO pools. The headline change is observability: the CCM now emits Kubernetes events when it fails, so a misconfiguration or a lost connection surfaces in `kubectl get events` instead of staying buried in the logs. Configuration also gets more deployment-friendly, with values that can now be supplied through environment variables, which fits container and Helm workflows better than file-only config. Under the hood, dependencies and tooling have been refreshed, and the project moved to a new pipeline that releases the Helm chart and the code together. [Release v1.1.0 · vatesfr/xenorchestra-cloud-controller-managerWhat’s Changed Refactor/extract shared k8s module by @gCyrille in #47 fix(chart): add existingConfigSecretPath value to fix hardcoded mount path by @gCyrille in #52 build(deps): bump azure/setup-h…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-e2c39927d004078983910c9017066f4257a1d80a7e2456753d1285938dd858e7.svg)GitHubvatesfr![](https://opengraph.githubassets.com/ed91bc2fae2d5689e1b67081899673fcef2abfa4f7c29d26b71f63ecff6dad0d/vatesfr/xenorchestra-cloud-controller-manager/releases/tag/v1.1.0)](https://github.com/vatesfr/xenorchestra-cloud-controller-manager/releases/tag/v1.1.0?ref=xen-orchestra.com) ### Go SDK v1.16.0 For those building on the Xen Orchestra API, the Go SDK adds a `StringifiedInt` type for the VBD `Position` and `UserDevice` fields, smoothing over how those values are handled. [Release v1.16.0 · vatesfr/xenorchestra-go-sdk1.16.0 (2026-06-09) Features v2/vbd: update Position and Userdevice fields to use StringifiedInt type (b5fc91f) v2: add StringifiedInt type for VIF device field (be204af) v1/vm: add coresPerSocket…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-e2c39927d004078983910c9017066f4257a1d80a7e2456753d1285938dd858e7.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v1.16-c3491859c2e5236e07dbddd1de223f639cad1ef03921f7c1b0878c182b13bf52.0)](https://github.com/vatesfr/xenorchestra-go-sdk/releases/tag/v1.16.0?ref=xen-orchestra.com) [Release v0.39.0 · vatesfr/terraform-provider-xenorchestraWhat’s Changed feat(datasource/pools): Add xenorchestra\_pools data source with tag filtering in #409 feat(resource/vm): add CPU topology configuration (cores\_per\_socket) in #410 Full Changelog: v…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-e2c39927d004078983910c9017066f4257a1d80a7e2456753d1285938dd858e7.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v0.39-1ba4759c5253147705ffc9070f7e4fd3fed7e78e210f551007f48f2c86145194.0)](https://github.com/vatesfr/terraform-provider-xenorchestra/releases/tag/v0.39.0?ref=xen-orchestra.com) [GitHub - vatesfr/cluster-api-provider-vates: Cluster API provider implementation for Vates VMS (XCP-ng and Xen Orchestra)Cluster API provider implementation for Vates VMS (XCP-ng and Xen Orchestra) - vatesfr/cluster-api-provider-vates![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-e2c39927d004078983910c9017066f4257a1d80a7e2456753d1285938dd858e7.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/cluster-api-provider-vates-03c220f1d96bfc5993716be3f30fc626945f2241830f8034bce6760e3c7135bf)](https://github.com/vatesfr/cluster-api-provider-vates/?ref=xen-orchestra.com) ### OpenMetrics now includes your XO tags Your XO tags are now included in the OpenMetrics output, so you can slice your monitoring by the same labels you already use inside Xen Orchestra. Dashboards and alerts can group hosts and VMs exactly the way you organise them in XO, with no extra mapping. ![](https://xen-orchestra.com/blog/content/images/2026/06/606288200-c3128a26-6039-4dbf-b877-aef99383ef83.png) XO tags appearing in the OpenMetrics output ### EasyVirt DC Scope integration update We updated the EasyVirt DC Scope integration so it keeps working smoothly with the latest changes on both sides. If you use DC Scope alongside Xen Orchestra for capacity planning and reporting, the integration stays current with this release. ## ⚖️ Load Balancer The load balancer is getting a welcome boost in transparency. Instead of discovering that a VM moved after the fact, you can now see these migrations directly as XO tasks, complete with the exact reason why the balance happened. ### Load balancer migrations show as XO tasks Migrations triggered by the load balancer now appear as XO tasks, complete with the reason each one happened. When a VM moves on its own, you can finally see why, whether it was for performance, density, or another policy, instead of discovering the move after the fact with no explanation. ![](https://xen-orchestra.com/blog/content/images/2026/06/599379744-8d2be79d-5ca9-4074-95c9-67fdf31b2374.png) Load balancer migration shown as an XO task ## 🐦 VMware to Vates (V2V) We're making large-scale migrations lighter on your infrastructure. This includes a major optimization that cuts memory consumption during transfers, alongside better interface visibility so you know exactly what type of migration to expect before launching the process. ### Smarter memory management We fixed an `invalid range` error with QCow2, when dealing with specific block size issues. While digging into this, we also found an opportunity to drastically optimize how memory is allocated during the process. The code now avoids loading massive datasets into memory multiple times. This change cuts memory consumption by up to 700 MB per terabyte of data transferred. It makes large-scale migrations much lighter on system resources and significantly more stable. ### Migration type visibility The interface now explicitly informs you whether a transfer will be a full migration or a delta transfer before you launch the operation. To reuse a previously started transfer for a delta sync, the target storage repository must match the original destination. Since full transfers can be quite long, this indicator eliminates guesswork and makes sure you know what to expect before committing to the migration. ![](https://xen-orchestra.com/blog/content/images/2026/06/611268933-938099f7-e8dd-4a66-9a78-987dae44562d.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/611269097-10f37159-8292-43df-afaa-c9d77c3c83e1.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/611269320-e87faae3-ec63-40b4-a514-f676301a2d23.png) ![](https://xen-orchestra.com/blog/content/images/2026/06/611269434-6941f6ed-a7f8-4c5f-a8d9-4600e95957da.png) Migration type indicators in XO 6.6 ## 📖 Documentation & Guides To support our recent networking updates, we've added a dedicated migration guide to the documentation. It walks you through switching your traffic rules over from OpenFlow to the XAPI plugin framework without hassle. ### Traffic rules migration guide The documentation now includes a clear guide for migrating network traffic rules from the OpenFlow protocol to the XAPI plugin framework. ![](https://xen-orchestra.com/blog/content/images/2026/06/Capture-d---cran-2026-06-25-145908.png) Preview of the traffic rules migration guide [SDN Controller | Xen Orchestra | XO DocumentationBe sure to enable the plugin on only one XOA instance.![](https://xen-orchestra.com/blog/content/images/icon/favicon-f17eb4729985c84d279e4dcd1332366c4b5bb84c000185030685e2a69eb73f09.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-795991691eb826e401bf4c89e32882d42524ced10f07399a632d2b3534caea9d.png)](https://docs.xen-orchestra.com/xo5/sdn%5Fcontroller?ref=xen-orchestra.com#migration-path) ## 🌐 Translations We're always working to make Xen Orchestra feel native to everyone. Thanks to our community's ongoing efforts, a large batch of our translations has been refreshed and refined for this release. ### 10 languages updated A big thank you to our community for their ongoing efforts in translating Xen Orchestra! This month, 10 languages were updated: **Chinese (simplified),** **Czech, Danish, Dutch, German, Korean, Norwegian (Bokmål), Slovak, Spanish**, and **Swedish**. ![](https://xen-orchestra.com/blog/content/images/2026/06/687474703a2f2f7472616e736c6174652e76617465732e746563682f7769646765742f78656e2d6f72636865737472612f6d756c74692d6175746f2e737667-1.svg) Current XO translation status Want to help translate Xen Orchestra or improve existing translations? You’re more than welcome to join in [here](https://translate.vates.tech/?ref=xen-orchestra.com) ## 🆕 Misc Here is our usual roundup of under-the-hood fixes and smaller quality-of-life improvements. This month brings significant stability updates to file-level restores, critical fixes for large disk migrations, and official support for Netbox v4.6 alongside several performance tweaks for the SDN controller. ### Improving file level restore reliability Thanks to a new end-to-end testing suite, the file-level restore feature is now more reliable. These tests will help us prevent future regressions. A key fix addresses an issue with certain OS installers, like Ubuntu Subiquity, which mistakenly mark LVM partitions with a generic Linux filesystem type instead of the standard LVM type. Xen Orchestra now correctly identifies these partitions anyway. To eliminate device collisions when restoring multiple files from identical VMs, the system now uses `dmsetup` snapshots and automatically renames LVM volumes and UUIDs on the fly. Finally, we tracked down and resolved a memory leak that occurred when exporting restored files as a zip archive, so performance stays stable even during large file transfers. 💡 ****Note:** File-level restore performance is typically 10 to 30 times slower than your remote storage speed. If you need to recover more than 10% of a disk, it is often faster to restore the entire VM or disk instead. ### Fixed: SDN controller cleanup We’ve fixed a bug affecting the SDN controller. Now, private network configurations clean up properly when a Virtual Network Interface (VIF) is deleted. Prior to XO 6.6, removing a VIF could leave behind stale network resources. Now, the controller triggers a thorough cleanup immediately upon interface deletion. This keeps your underlying network infrastructure clean and prevents resource leaks. ### Fixed: Migration errors for large QCOW2 disks We've fixed a `Map range error` that occurred when migrating large QCOW2 disks. This error occurred because of how disk data blocks were tracked during the transfer. By switching the internal storage method from maps to arrays, the migration tool can now handle exceptionally large disks without hitting range limitations. ### Netbox synchronization update The Netbox plugin now features an option to ignore RFC 1918 private IP addresses during synchronization. This is particularly useful if you want to filter out local internal addresses and only sync public IPs to your Netbox instance. ![](https://xen-orchestra.com/blog/content/images/2026/06/175721190-ccd288c1-d36d-46f8-9341-b8db1f13bf41.png) Many thanks to [Stephen Boyd](https://github.com/sboyd-m?ref=xen-orchestra.com) for this great contribution! ### Netbox v4.6 compatibility The Netbox plugin now officially supports Netbox v4.6\. This update keeps your synchronization workflows running smoothly with the latest Netbox release, while introducing two notable changes: - **Support for clusterless VMs:** Netbox v4.6 allows virtual machines to be assigned to devices without being tied to a cluster. The plugin now handles this gracefully, so these VMs are processed without issues. - **Deprecation of v1 API tokens:** Netbox v1 tokens are now deprecated and will be completely removed in Netbox v5.0\. While they still work for now, Xen Orchestra will display a warning in the console if a v1 token is detected. We highly recommend generating new v2 tokens at `/user/api-tokens/add/` in your Netbox instance to future-proof your setup. ![](https://xen-orchestra.com/blog/content/images/2026/06/image3.png) Warning about deprecated v1 tokens ### ### PATCH endpoint for traffic rules The SDN controller now also exposes a `PATCH` API endpoint for traffic rules at both the VIF and network levels. Instead of forcing a full configuration replacement, this endpoint allows for partial updates. This makes it easier to modify specific parameters of a rule on the fly. It also opens the door for smoother automation and tighter integration with external tools. ### SDN controller startup performance We’ve optimized how the SDN controller filters objects during initializations. As a result, the controller’s startup performance has improved significantly. Instead of scanning through all objects, the controller now targets specific object collections using type-based indexes. This completely eliminates unnecessary filtering for unrelated types. ### ### Xen Orchestra 6.5 URL: https://xen-orchestra.com/blog/xen-orchestra-6-5/ Last updated: 2026-06-03T07:05:28.000Z Another month, another step forward for Xen Orchestra 6! XO 6.5 keeps pushing feature parity, REST API growth and monitoring, and this cycle also brings real Kubernetes news: a fresh CSI release and a first look at our Cluster API provider. Enjoy the read! #### 🔗 Summary 👨‍🚀 [Project & Community](#%F0%9F%91%A8%E2%80%8D%F0%9F%9A%80-project-community) 🏢 [User stories](#%F0%9F%8F%A2-user-stories) 🎫 [Events & Webinars](#%F0%9F%8E%AB-events-webinars) [****XO 6.5**](#xo-65) 1. 🛡️ [Security](https://xen-orchestra.com/blog/xen-orchestra-6-3/#%F0%9F%9B%A1%EF%B8%8F-security) 2. 💾 [Backup](#%F0%9F%92%BE-backup) 3. 🥝 [Core UI](#%F0%9F%A5%9D-core-ui) 4. 🛰️ [XO 6](#%F0%9F%9B%B0%EF%B8%8F-xo-6) 5. 🔭 [XO Lite](#%F0%9F%94%AD-xo-lite) 6. 📡 [REST API](#%F0%9F%93%A1-rest-api) 7. ☸️ [DevOps Tools](#%E2%98%B8%EF%B8%8F-devops-tools) 8. 📖 [Documentation & Guides](#%F0%9F%93%96-documentation-guides) 9. 🌐 [Translations](#%F0%9F%8C%90-translations) 10. 🆕 [Misc](#%F0%9F%86%95-misc) As usual, this announcement is available as a Youtube video: ## 👨‍🚀 Project & Community Beyond Xen Orchestra itself, the wider Vates platform kept moving this cycle, with several XCP-ng updates, a new storage capability, signed Windows drivers, and a partnership worth flagging. ### Building sustainable open source infrastructure models One of the recurring themes is long-term viability in open source infrastructure. A recent article explores how organizations can ensure vendor independence without sacrificing stability or support. It highlights how open-source models, when properly structured, can provide a sustainable alternative to traditional proprietary approaches. [Why open‑source ensures continuity: the Vates approachHow does Vates reduce vendor risk? Discover how its open-source model and support-driven strategy ensure long-term continuity and true infrastructure independence.![](https://xen-orchestra.com/blog/content/images/icon/logo64-50.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/open-source-vendor-independance.png)](https://vates.tech/blog/open-source-long-term-viability-and-vendor-independence/?ref=xen-orchestra.com) ### Scaling infrastructure without storage bottlenecks Another key area of focus is scalability, particularly around storage. As infrastructures grow, storage often becomes a limiting factor. This month’s article discusses how these constraints can be removed to support larger and more flexible deployments, ensuring that storage architecture does not block infrastructure evolution. [Removing storage constraints for growing infrastructuresXCP-ng 8.3 now supports virtual disks up to 16TB, removing the long-standing 2TB per-disk limit. A practical step forward for backup workloads, storage-heavy applications and migrations from VMware.![](https://xen-orchestra.com/blog/content/images/icon/logo64-51.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/jukan-tateisi-bJhT_8nbUA0-unsplash.jpg)](https://vates.tech/blog/removing-storage-constraints-for-growing-infrastructures/?ref=xen-orchestra.com) ### Xen on RISC-V progress For those following the longer-term hardware story, our post about Xen on RISC-V covers Dom0 boot, hypercalls, and a Docker-based toolchain. While in early-stage, it shows the direction the Xen ecosystem is heading beyond x86, and the toolchain notes make it reproducible if you want to experiment yourself. [Xen on RISC-V: Dom0, Hypercalls and ToolchainLatest progress on Xen for RISC-V, including Dom0 boot, hypercalls and Docker-based tooling.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-45.png)XCP-ng BlogBaptiste Le Duc![](https://xen-orchestra.com/blog/content/images/thumbnail/xen-on-risc-v.webp)](https://xcp-ng.org/blog/2026/05/22/xen-on-risc-v-dom0-boot-hypercalls-and-docker-toolchain/?ref=xen-orchestra.com) ### XCP-ng 8.3 updates XCP-ng 8.3 LTS received a steady stream of security and maintenance updates through late April and May. If you run XCP-ng 8.3 in production, applying these keeps your hosts current with the latest Citrix-derived security patches and bug fixes. We recommend reading each post before patching, since they call out any reboot requirements and known interactions. [May 2026 Updates #2 for XCP-ng 8.3 LTSToday’s update addresses an issue with the rolling pool update process on pools using XOSTOR.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-46.png)XCP-ng BlogSamuel Verschelde![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1567095761054-7a02e69e5c43)](https://xcp-ng.org/blog/2026/05/07/may-2026-updates-2-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) [May 2026 Updates #3 for XCP-ng 8.3 LTSNew security and maintenance updates are available for XCP-ng 8.3 LTS. Xen, Linux kernel, Intel Microcode…![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-47.png)XCP-ng BlogSamuel Verschelde![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1598439119086-35655b8c333d)](https://xcp-ng.org/blog/2026/05/21/may-2026-updates-3-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) ### QCOW2 is now GA in XCP-ng The QCOW2 disk format reached general availability in XCP-ng, lifting the long-standing VHD ceiling and allowing individual VM disks up to **16 TiB**. For anyone running large databases, file servers, or media workloads that previously had to be split across multiple disks, this removes a real constraint on growing infrastructures. [QCOW2 is now GA in XCP-ngQCOW2 is now GA in XCP-ng 8.3, supporting VM disks up to 16 TiB and replacing the 2 TiB VHD limit. Production-ready, stability-focused, with performance optimizations coming soon.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-48.png)XCP-ng BlogDamien Thenot![](https://xen-orchestra.com/blog/content/images/thumbnail/qcow2.webp)](https://xcp-ng.org/blog/2026/05/05/qcow2-is-now-ga-in-xcp-ng/?ref=xen-orchestra.com) ### Windows PV drivers: first signed build since 8.2.2 The Windows guest driver line saw three releases this cycle. The notable milestone is **v9.0.9137** on **May 19**, the first signed build since the 8.2.2.20 series, which matters for clean installation on modern Windows without driver-signature warnings. A maintenance release **v9.1.200** followed recently, and the **v9.1.152** XenClean/XenBootFix build on **May 5** addresses the **VSA-2026-012** DLL sideloading advisory. If you maintain Windows guests, moving to a signed build is worth scheduling. [Release 9.0.9137 Release Signed · xcp-ng/win-pv-driversProudly presenting the first signed build of the XCP-ng Windows Guest Tools since 8.2.2.200-RC1 was released over six years ago. This build can be installed as-is without further configuration. To…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-108.svg)GitHubxcp-ng![](https://xen-orchestra.com/blog/content/images/thumbnail/v9.0.9137)](https://github.com/xcp-ng/win-pv-drivers/releases/tag/v9.0.9137?ref=xen-orchestra.com) [Release XenClean/XenBootFix 9.1.152 Release · xcp-ng/win-pv-driversThis release fixes VSA-2026-012 (DLL sideloading vulnerability in XenClean and XenBootFix). If your VM is running 9.1.146, you don’t need to update. You just need to replace any XenClean and XenBoo…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-109.svg)GitHubxcp-ng![](https://xen-orchestra.com/blog/content/images/thumbnail/v9.1.152)](https://github.com/xcp-ng/win-pv-drivers/releases/tag/v9.1.152?ref=xen-orchestra.com) ## 🏢 User stories This month’s user story highlights another major migration away from VMware toward Vates VMS. Biocoop successfully migrated its infrastructure to Vates VMS, reinforcing a broader trend we are seeing across organizations: moving away from legacy virtualization stacks in favor of more open, flexible, and cost-controlled environments. [Why Biocoop chose open-source virtualizationBiocoop chose Vates VMS to regain control over virtualization costs, governance, and long-term infrastructure decisions through open-source technologies.![](https://xen-orchestra.com/blog/content/images/icon/logo64-52.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/user-story-biocoop-vates-vms-migration-vmware.webp)](https://vates.tech/blog/how-biocoop-began-its-strategy-to-move-away-from-vmware/?ref=xen-orchestra.com) ## 🎫 Events & webinars Beyond product updates, sharing experience and structuring knowledge remains an important part of the ecosystem. ### Vates & EasyVirt webinar On July 2, Vates and EasyVirt will host a webinar focused on infrastructure optimization, migration planning, and operational visibility across multi-hypervisor environments. The session will showcase how the integration of DC Scope and DC NetScope within the Vates ecosystem helps organizations optimize resource usage, secure migrations, monitor network flows, and gain better control over infrastructure costs and operations through a single interface. [Register here](https://register.gotowebinar.com/?ref=xen-orchestra.com#register/530110195909328473) --- # XO 6.5 This release is a broad one. On the security side, **Redis encryption** protects XO's credential store at rest. On the backup side, **bidirectional incremental replication** removes one of the last friction points in paired-site DR setups. And on the interface side, XO 6 crosses a threshold: disk management and snapshot reversion all land this cycle, so daily VM operations no longer require switching back to XO 5. A lot of this came directly from your feedback and forum requests, alongside a substantial backend refactor of the backup cleanup code that sets the groundwork for upcoming storage integrations. XO 6.5 is one of the more complete releases we have shipped in this cycle. ## 🛡️ Security Keeping XO secure is an ongoing effort, and 6.5 adds another concrete step. After securing inter-XO communications and hardening the XAPI surface in previous releases, this cycle focuses on protecting what XO stores at rest. ### Redis encryption After hardening the XAPI surface and securing inter-XO communications in earlier releases, we are adding another layer of defense-in-depth: encryption of the Redis database that backs Xen Orchestra. Redis holds a great deal of the state that makes XO work, and encrypting it raises the bar considerably for anyone trying to read that data off a compromised system. The protection is built around a key-derivation scheme that splits the decryption key between the XAPI side and a local file on the appliance filesystem. Decrypting the database requires root access, XAPI access, and the local key file all at once, which is a considerably harder bar to clear than any single compromise. The feature is opt-in for now and will become the default in a later release, so you can adopt it on your own schedule. You enable it through a configuration flag on the XOA virtual machine, and the change is reversible if needed. Before enabling it, two things need to be in place: Xen Orchestra must run inside a VM, because the key-derivation mechanism depends on the appliance store, and configuration backups must have encryption turned on. The upgrade documentation walks through enabling it end to end. [Credential Database Encryption | Xen Orchestra | XO DocumentationXen Orchestra stores credentials for XenServer connections, remotes, users, and tokens in Redis. When credential encryption is enabled, all records are encrypted at rest using AES-256-GCM, and index keys are replaced with HMAC blind indexes so indexed field values (emails, hostnames, etc.) are not stored as plaintext. The performance impact is negligible for typical deployments.![](https://xen-orchestra.com/blog/content/images/icon/favicon-51.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-33.png)](https://docs.xen-orchestra.com/xo5/credential-encryption?ref=xen-orchestra.com#enabling-encryption?ref=xen-orchestra.com) ## 💾 Backup Backup work this month splits between a visible improvement for object-storage users, a large invisible backend cleanup, and a new replication mode. ### S3 user-agent identification Xen Orchestra now identifies itself to S3 providers by sending a `User-Agent: Xen Orchestra FS ` header on its object-storage requests. This means your S3 backend can see that the traffic is coming from Xen Orchestra and which version is running, which providers use to track usage and to move toward self-certification of their compatibility with our backup stack. The header is sent to all S3 providers, not a single one, so it works regardless of where your backup repository lives. Wasabi specifically asked for this, and it strengthens the relationship between Xen Orchestra and the storage vendors our users rely on for off-site backup. [Users | Xen Orchestra | XO DocumentationFor system users (in XOA), please refer to XOA section. Here, we are only talking about users in Xen Orchestra application![](https://xen-orchestra.com/blog/content/images/icon/favicon-52.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-34.png)](https://docs.xen-orchestra.com/xo5/users?ref=xen-orchestra.com#self-service-portal?ref=xen-orchestra.com) ### Refactor and cleanVM refactor We landed a substantial refactor of the backup cleanup code, the part of the system responsible for reflecting state and tidying up after backup jobs (the `cleanVM` path). Previously, this logic lived in one heavily coupled monolithic file that mixed many different checks and cleanup steps together, which made it both harder to reason about and harder to extend safely. The new structure builds on a disk abstraction with cleaner separation between concerns. There is no user-visible change here, but it makes the code more reliable to maintain today and opens the door for upcoming direct-storage integrations such as Pure Storage. This was first raised in forum threads about backup reliability and migration blocking during backups. [Master, commit a3139 failing backupsUpdated XO to Master, commit a3139 and now the backups are failing. Log sample: “tasks”: \[ { “data”: { “type”: “VM”, “id”: “11393…![](https://xen-orchestra.com/blog/content/images/icon/512-35.png)XCP-ngmanilx![](https://xen-orchestra.com/blog/content/images/thumbnail/site-logo-13.png)](https://xcp-ng.org/forum/topic/11875/?ref=xen-orchestra.com) ### Bidirectional incremental replication Incremental replication now supports **bidirectional** mode. When you run a replication job, XO looks for any snapshot already in common between source and destination (even one created by a different job) and transfers only what changed since then. No more full resync just because you're going the other way. In practice, this covers two main DR situations: - **Planned failover:** You had time to run a final prod-to-DR sync before cutting over. When you're ready to return, stop the VMs on DR, run the reverse job, and only the delta accumulated during the outage gets transferred back. - **Unplanned failover:** You started the DR VMs immediately without a last sync. The return is still delta-only, but since the original prod disks were never cleaned up, XO creates a new VM copy on the prod SR rather than updating in place. That copy will trigger a one-time full replication on its next run. One thing to keep in mind: this only kicks in when the job uses incremental replication mode with a single target SR. [feat(backups): bi directional replication by fbeauchamp · Pull Request #9806 · vatesfr/xen-orchestraDescription review by commit following the symmetrical backup PR reuse any snapshot in common between the source and destination if using incremental replication only one target a common snapshot…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-111.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/9806-1)](https://github.com/vatesfr/xen-orchestra/pull/9806?ref=xen-orchestra.com) ## 🥝 Core UI Much of the Core UI work this cycle went into shared components, with a particular focus on the groundwork for consistent form validation across the product. ### Shared components and form validation We did a lot of work on shared components this month to support upcoming form validation. Rather than validating each form in its own ad-hoc way, we are building the validation behavior into the common components that every form is assembled from. The visible result this release is a set of small component updates across the interface, the larger goal being consistency: as more screens adopt the shared components, you will see the same clear, predictable validation everywhere you enter data. It is groundwork that will show up progressively over the coming releases. [Infrastructure management | Xen Orchestra | XO DocumentationThis section is related on how to manage your XCP-ng/Citrix Hypervisor infrastructure.![](https://xen-orchestra.com/blog/content/images/icon/favicon-53.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-35.png)](https://docs.xen-orchestra.com/xo5/manage%5Finfrastructure?ref=xen-orchestra.com#available-updates?ref=xen-orchestra.com) ## 🛰️ XO 6 XO 6 is no longer just catching up. Disk management, VIF handling, snapshot reversion: most of what you relied on in XO 5 for daily VM operations is now in the new interface, plus Traffic Rules as the first feature built exclusively for XO 6. ### Traffic rules on networks and VIFs Traffic Rules are the first feature built only for XO 6, with no back-port to XO 5\. They let you define network-wide rules at the Network level and at the VIF level, giving you a single place to express how traffic should be allowed or blocked across your virtual networks. If you have been managing VM isolation on shared subnets or VLANs through workarounds, this gives you a proper tool to do it. It also sets the pattern for XO 6-only features to come. ![](https://xen-orchestra.com/blog/content/images/2026/05/598065759-8f7980e4-be36-40d4-81aa-1011092c00f0.png) ![](https://xen-orchestra.com/blog/content/images/2026/05/598065979-686a9e95-0ede-4dfa-adc7-05b6de045e38.png) The new Traffic rules form You have a recap of all the rules in a specific VIF: ![](https://xen-orchestra.com/blog/content/images/2026/05/591165332-ffb7eb45-d74e-4e8b-9245-6b28cbb9646d.png) [VM isolation on the same subnet/Vlan. Migration PlanningHey All, New to the forum and looking at moving to XCP from another hypervisor. I will be reaching out to Vates as I am looking for the enterprise support…![](https://xen-orchestra.com/blog/content/images/icon/512-23.png)XCP-ngAdmin55![](https://xen-orchestra.com/blog/content/images/thumbnail/site-logo-4.png)](https://xcp-ng.org/forum/topic/11727/?ref=xen-orchestra.com) ### Used space on snapshots The VDI view now displays the correct used space for snapshots. Previously, a VDI with a snapshot attached could report **0%** of its capacity in use, and the figure only looked right again once the snapshot was removed, which made it hard to understand how much storage a VM was actually consuming. We tracked this down to a display bug in how snapshot space was accounted for, and the view now shows accurate figures whether or not a snapshot is attached. If you have been puzzled by storage numbers that did not add up, this is the fix. [🛰️ XO 6: dedicated thread for all your feedback!With the December release, XO 6 will become the default experience. This also means a lot of new users will get their hands on it, and we want to make sure t…![](https://xen-orchestra.com/blog/content/images/icon/512-24.png)XCP-ngolivierlambert![](https://xen-orchestra.com/blog/content/images/thumbnail/1-profileavatar-1620659303584-7.jpeg)](https://xcp-ng.org/forum/topic/11604/?ref=xen-orchestra.com) ### Attach an existing disk in the VM view You can now attach an existing VDI to a VM directly from the VM view. This brings a routine operation that XO 5 users took for granted into the new interface, with a dedicated UI control in the VM's disk view. One less reason to switch back! ![](https://xen-orchestra.com/blog/content/images/2026/05/585532804-68904cca-c572-4cee-a8b1-514137e9aa30.png) ![](https://xen-orchestra.com/blog/content/images/2026/05/585532842-ad3a2f02-ea70-4efb-ae80-2aca6e74aeb3.png) New 'Attach existing VDI' action [No VDI for VMs?Not sure why..but I can’t see any VDI disks on any of my VMs. The VDI shows as 0B. If I go to the shared (iSCSI) storage in my test Pool, I can see all the d…![](https://xen-orchestra.com/blog/content/images/icon/512-25.png)XCP-ngcoolsport00![](https://xen-orchestra.com/blog/content/images/thumbnail/site-logo-5.png)](https://xcp-ng.org/forum/topic/11865/?ref=xen-orchestra.com) ### Create a new VDI from scratch Complementing disk attachment, XO 6 now lets you create a brand-new VDI from scratch in the VM view. You define the disk and add it to the VM without leaving the interface, which removes another reason to switch back to XO 5 for storage tasks. Together with attaching existing disks, this rounds out the basic disk lifecycle in the new UI. ![](https://xen-orchestra.com/blog/content/images/2026/05/595357752-c5529a57-70a6-4e53-94a1-55f40582c2d0.png) ![](https://xen-orchestra.com/blog/content/images/2026/05/595357870-37bf19cf-c8d2-474c-a083-c523af6f64ae.png) New VDI creation form [Infrastructure management | Xen Orchestra | XO DocumentationThis section is related on how to manage your XCP-ng/Citrix Hypervisor infrastructure.![](https://xen-orchestra.com/blog/content/images/icon/favicon-48.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-30.png)](https://docs.xen-orchestra.com/xo5/manage%5Finfrastructure?ref=xen-orchestra.com#vm-creation?ref=xen-orchestra.com) ### General tab for VIFs The VIF page in XO 6 gains a General tab, giving you a clear, organized place to see and manage a virtual interface's core properties. A small addition that makes the VIF view consistent with how other objects are presented across the new interface. ![](https://xen-orchestra.com/blog/content/images/2026/05/598055850-2ed8c5bb-1df9-4b04-a652-998bd8a97518.png) ![](https://xen-orchestra.com/blog/content/images/2026/05/598056137-eee9cc7b-35ec-4e29-940a-31f9952254d8.png) 'General' tab for VIFs [Query vif Interface ParametersHello, I try to read back the settings for a vif configured via CLI using this command: xe vif-param-set uuid= other-config:ethtool-tx=“off” Does anyone kno…![](https://xen-orchestra.com/blog/content/images/icon/512-27.png)XCP-ngCB0b![](https://xen-orchestra.com/blog/content/images/thumbnail/site-logo-7.png)](https://xcp-ng.org/forum/topic/8805/?ref=xen-orchestra.com) ### Improved revert-snapshot experience We redesigned the VM snapshot reversion process to make it clear and predictable from the UI. Because rolling back a VM is a high-stakes operation, a smoother, more intuitive flow means fewer doubts about what will happen next. If you want to dive into the core concepts behind it, the forum thread on how to revert a VM to a snapshot is a great place to start. ![](https://xen-orchestra.com/blog/content/images/2026/05/594837581-3fb654e5-a00c-4f2f-9fab-9679ffe32688.png) ![](https://xen-orchestra.com/blog/content/images/2026/05/594837659-61dcff81-ea43-41f1-bd7c-f00d2b187731.png) Improved experience for VM snapshot reversion [How to revert VM to snapshotRe: Automation script to revert and save snapshot I have the same question. I’m trying curl -k -X POST -b ‘authenticationToken=’ ’https:///rest/v0/vm-snapsho…![](https://xen-orchestra.com/blog/content/images/icon/512-28.png)XCP-ngslavavrn![](https://xen-orchestra.com/blog/content/images/thumbnail/site-logo-8.png)](https://xcp-ng.org/forum/topic/11384/?ref=xen-orchestra.com) ## 🔭 XO Lite XO Lite picks up one small but useful defensive improvement this cycle, worth knowing about if your instance is reachable from outside your network. ### A robots.txt for exposed instances XO Lite now serves a simple `/robots.txt` file. The point is to stop search engines from crawling and indexing XO Lite instances that happen to be reachable from the internet, so your management interface does not turn up in search results. It is a quiet defensive measure that costs nothing and avoids an easy form of exposure for instances that were never meant to be public. [XCP-ng 8.3 LTS | XCP-ng DocumentationXCP-ng 8.3 is an LTS Release. Download the installation ISO.![](https://xen-orchestra.com/blog/content/images/icon/xcpcrop128.png)XCP-ng Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/8_3-bootscreen-e66fe517570e8222d9207000925763e6.png)](https://docs.xcp-ng.org/releases/release-8-3?ref=xen-orchestra.com#xostor-and-xcp-ng-83?ref=xen-orchestra.com) ## 📡 REST API The REST API keeps expanding this release, with new endpoints across VIFs, snapshots, and backup repositories. There is also early groundwork for a VM Administrator role that separates VM management from full infrastructure access. ### SR deletion You can now remove a SR via the REST API. The front end will come next month! ![](https://xen-orchestra.com/blog/content/images/2026/05/545501945-cb24d8e7-5bba-4da6-97bc-043342ded2af-1.png) ### Revert a snapshot via the API A new endpoint lets you revert a VM to a snapshot through the REST API. Reverting was already possible from the interface, and exposing it programmatically means automation and disaster-recovery tooling can drive the operation without a human in the loop. A natural fit alongside the revert-snapshot UX work in XO 6 this release. [How to revert VM to snapshotRe: Automation script to revert and save snapshot I have the same question. I’m trying curl -k -X POST -b ‘authenticationToken=’ ’https:///rest/v0/vm-snapsho…![](https://xen-orchestra.com/blog/content/images/icon/512-31.png)XCP-ngslavavrn![](https://xen-orchestra.com/blog/content/images/thumbnail/site-logo-10.png)](https://xcp-ng.org/forum/topic/11384/?ref=xen-orchestra.com) ### Building a VM Administrator role We’re currently working on a new **VM Administrator role** following the ACL v2/RBAC model. The goal is simple: allow someone to manage VMs (like editing tags, changing descriptions, or toggling power states) without giving them access to the underlying infrastructure. While this is still a work in progress and not yet visible in the UI, the core API groundwork is being laid right now. If you've been waiting for a cleaner way to separate your VM operators from your infrastructure admins, this is where we're heading. [ACL v2 / RBAC (REST API/XO6) | Xen Orchestra | XO DocumentationACL v2 is the access control system for the Xen Orchestra REST API and the XO6 UI. It lets you define exactly what each user or group can see and do — down to individual objects — without granting them full administrator access.![](https://xen-orchestra.com/blog/content/images/icon/favicon-58.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-40.png)](https://docs.xen-orchestra.com/xo6/acl-v2?ref=xen-orchestra.com) ## ☸️ DevOps Tools The DevOps work this cycle covers two fronts: observability and Kubernetes integration. On the observability side, the new Prometheus/Grafana series drop straight into your existing setup, no configuration changes needed. On the Kubernetes side, our CSI driver gets a fresh release, and further down we share a first look at our Cluster API provider, a glimpse of where Kubernetes-on-Vates is heading. ### Kubernetes CSI new release `v0.3.0` is now available! On the menu: - **Stable CSI Volume Identity**: This decouples Kubernetes volume identity from backend storage lifecycle events (e.g. VDI migration between Storage Repositories) - **Topology-Aware Volume Provisioning**: Dynamic provisioning now supports topology-aware pool selection. ⚠️ Migration required from v0.2.0 to v0.3.0\. Read the full release notes in here: [Release v0.3.0 · vatesfr/xenorchestra-csi-driverImportantNew requirement — Xen Orchestra 6.4+ This release requires Xen Orchestra 6.4+. The driver now uses other\_config at VDI creation time to store Kubernetes volume metadata directly on the dis…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-113.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v0.3.0)](https://github.com/vatesfr/xenorchestra-csi-driver/releases/tag/v0.3.0?ref=xen-orchestra.com) ### More Prometheus metrics We added new metrics to the OpenMetrics / Prometheus plugin to help you track infrastructure behavior more precisely from your dashboards. This release focuses on **XOSTOR data**. It builds on the previous update, which introduced VDI labels and VM mapping. If you already scrape the `/openmetrics/metrics` endpoint into Grafana, the new series slot straight into your existing setup. We decided to prioritize these metrics to answer multiple requests on the forum for better visibility into host and storage data, through the Prometheus exporter. [Gather CPU utilization of host as variable for prometheus exporterHello, xsconsole and xen orchestra can display host CPU usage, is it possible to get these metrics somehow in shell into a variable? I would like to create s…![](https://xen-orchestra.com/blog/content/images/icon/512-32.png)XCP-ngpetr.bena![](https://xen-orchestra.com/blog/content/images/thumbnail/site-logo-11.png)](https://xcp-ng.org/forum/topic/5338/?ref=xen-orchestra.com) ![](https://xen-orchestra.com/blog/content/images/2026/05/593898367-3278de99-ad62-41bd-b259-8d995369d5da.png) ![](https://xen-orchestra.com/blog/content/images/2026/05/593905412-79fc7cd3-dd82-4301-8e2c-29a14759e126.png) XOSTOR metrics exposed #### New VDI storage metrics You can now monitor both the virtual size of your VDIs and the actual physical space they occupy on your SRs. These metrics include labels for pool, SR, and VDI names, and even identify the associated VM when a disk is attached. This extra level of detail helps you pinpoint exactly where your storage is being used and anticipate capacity needs directly from your monitoring dashboard. ![](https://xen-orchestra.com/blog/content/images/2026/04/574594996-b52f7d56-3d0b-4255-9ab6-d1201dcf21a9.png) VDI metrics exposed in OpenMetrics [GitHub - prometheus/OpenMetrics: Evolving the Prometheus exposition format into a standard.Evolving the Prometheus exposition format into a standard. - prometheus/OpenMetrics![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-90.svg)GitHubprometheus![](https://xen-orchestra.com/blog/content/images/thumbnail/OpenMetrics)](https://github.com/prometheus/OpenMetrics?ref=xen-orchestra.com) ### Updated Alpine Linux template We've updated the Alpine Linux template in the XOA Hub to version 3.23: ![](https://xen-orchestra.com/blog/content/images/2026/05/image.png) ![](https://xen-orchestra.com/blog/content/images/2026/05/image2.png) Alpine Linux 3.23 template ### Kubernetes Cluster API: a glimpse into the future If you've ever managed Kubernetes at scale, you know the real pain isn't creating a cluster, it's managing dozens of them over time: upgrades, scaling, node replacement, teardown. That's the problem Kubernetes Cluster API (CAPI) was built to solve. It turns clusters themselves into Kubernetes resources: you describe what you want in YAML, apply it, **and a management cluster orchestrates the rest.** CAPI uses a provider model, where each infrastructure (AWS, vSphere, OpenStack, etc.) plugs in via its own provider while the workflow stays identical. With a Vates VMS provider, the same declarative API can spin up workload clusters directly on XCP-ng, with XO doing the heavy lifting underneath. Combined with the pieces we already ship (the CSI driver for storage, the CCM for load balancers and node lifecycle), this closes the loop: full Kubernetes lifecycle management on your own infrastructure, no proprietary control plane in sight. Here's roughly how creating a cluster looks today: ```yaml apiVersion: cluster.x-k8s.io/v1beta2 kind: Cluster metadata: name: my-cluster spec: clusterNetwork: pods: cidrBlocks: - 172.31.0.0/16 services: cidrBlocks: - 192.168.0.0/16 serviceDomain: cluster.local topology: classRef: name: xo-almalinux version: v1.30.0 variables: - name: controlPlaneEndpoint value: host: "10.30.139.10" port: 6443 controlPlane: replicas: 1 workers: machineDeployments: - class: almalinux-worker name: worker-md-0 replicas: 2 ``` This is still very much a work in progress, but expect news on this front very soon. 🚀 ## 📖 Documentation & Guides Great software needs great documentation, so we're constantly working to make ours better every month! ### Restructuring our documentation for XO 6 We’ve started reworking our technical documentation to prepare for the future. To keep things organized, existing pages have been split into two distinct sections: one for XO 5 and one forXO 6.For now, the vast majority of our current guides and docs live in the XO 5 section. The new XO 6 section is a clean slate, designed for content that applies only to the new Xen Orchestra interface. As XO 6 picks up speed and gains new features, this section will grow alongside it, so you always know exactly which version a guide is meant for. ![](https://xen-orchestra.com/blog/content/images/2026/05/Capture-d---cran-2026-05-28-090839.png) The new XO documentation structure ### Setting up TOTP for your account We’ve updated the Xen Orchestra documentation to include clear instructions on how to set up TOTP (Time-based One-Time Password). If you want to add an extra layer of security to your account with two-factor authentication, you can now find the complete guide directly in the official docs. It covers everything from finding the settings in your profile to scanning the QR code with your authenticator app. ![](https://xen-orchestra.com/blog/content/images/2026/05/Capture-d---cran-2026-05-28-080941.png) Preview of the TOTP documentation [Users | Xen Orchestra | XO DocumentationFor system users (in XOA), please refer to XOA section. Here, we are only talking about users in Xen Orchestra application![](https://xen-orchestra.com/blog/content/images/icon/favicon-54.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-36.png)](https://docs.xen-orchestra.com/xo5/users?ref=xen-orchestra.com#built-in) ### Nagios plugin documentation The `transport-nagios` plugin is now properly documented. If you rely on Nagios or compatible monitoring systems to keep an eye on your infrastructure, this update is for you. The new section in the **Backup reports** documentation explains how to route your Xen Orchestra backup statuses directly into your existing monitoring dashboard. Instead of relying solely on emails, you can now integrate backup success and failure states into your central alerting system. ![](https://xen-orchestra.com/blog/content/images/2026/05/Capture-d---cran-2026-05-28-081410.png) Preview of the 'transport-nagios' plugin documentation [Backup reports | Xen Orchestra | XO DocumentationAt the end of a backup job, you can configure Xen Orchestra to send backup reports directly by email, Slack or in Mattermost. It’s up to you.![](https://xen-orchestra.com/blog/content/images/icon/favicon-56.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-38.png)](https://docs.xen-orchestra.com/xo5/backup%5Freports?ref=xen-orchestra.com#nagios) ## 🌐 Translations Thanks to our community translators, Xen Orchestra keeps expanding its language support. Translating the interface is just as valuable as contributing code or reporting bugs! If your language isn’t fully covered (or missing altogether) you can pitch in to help fill the gaps. ### 8 languages updated A big thank you to our community for their ongoing efforts in translating Xen Orchestra! This month, 8 languages were updated: **Czech, Chinese (simplified), Dutch, German, Korean, Slovak, Spanish,** and **Swedish.** ![](https://xen-orchestra.com/blog/content/images/2026/05/687474703a2f2f7472616e736c6174652e76617465732e746563682f7769646765742f78656e2d6f72636865737472612f6d756c74692d6175746f2e737667.svg) Current XO translation status Want to help translate Xen Orchestra or improve existing translations? You’re more than welcome to join in [here](https://translate.vates.tech/?ref=xen-orchestra.com). ## 🆕 Misc A handful of quality-of-life improvements round out the release. ### Timestamped XO config exports Exporting your Xen Orchestra configuration now adds a timestamp to the filename. It sounds minor, but users told us that XO 5 config exports were easy to lose track of because the files were hard to tell apart. With a timestamp baked into each filename, you can immediately see which export is which and find the one you want. This came directly from a request on our feedback platform. [Better informational XO-config filename · Vates VMS feedbackWhen doing a manual download/backup of the XO-config. It would be greatly informational if the filename had a timestamp appended to it as a suffix. An![](https://xen-orchestra.com/blog/content/images/icon/qZprAll0bofaK77abT3Hg93cBpodHgaHZDLk2GsiR40oQ1RNVD9xs84LBJcJYOXO-logo400-6.png)![](https://xen-orchestra.com/blog/content/images/thumbnail/qZprAll0bofaK77abT3Hg93cBpodHgaHZDLk2GsiR40oQ1RNVD9xs84LBJcJYOXO-logo400-6.png)](https://feedback.vates.tech/posts/61/?ref=xen-orchestra.com) ### Upload QCOW2 disks from the interface You can now upload a QCOW2 disk directly from the Xen Orchestra UI. Two API calls that were previously missing have been added, completing the path so the format that just reached GA in XCP-ng can be brought in through the interface. The capability works for both XO 5 and XO 6, so importing a QCOW2 image is now a first-class operation regardless of which interface you use. ![](https://xen-orchestra.com/blog/content/images/2026/05/588887148-b8b78efc-3616-4a12-84f3-eb5e2869a499.png) ![](https://xen-orchestra.com/blog/content/images/2026/05/588888237-40b196b5-89f7-4796-8dd8-a17c278b5fc7.png) How to import QCOW2 disks from the XO 5 interface [Disk import failedNot sure if this is an XO error or ngix proxy manager issue. When i try to upload an ISO to an NFS ISO share I get the following error when accessing XO via…![](https://xen-orchestra.com/blog/content/images/icon/512-33.png)XCP-ngacebmxer![](https://xen-orchestra.com/blog/content/images/thumbnail/1751626285458-screenshot-2025-07-04-064005.png)](https://xcp-ng.org/forum/topic/11033/?ref=xen-orchestra.com) ### IPMI sensors via a dedicated plugin IPMI sensor data has moved out of the core code and into its own dedicated plugin (`xo-server-ipmi`). Previously, we relied on hardcoded rules to map product names to specific sensors. The problem? New or uncommon hardware often got left in the dark until someone manually updated the source code. By switching to a plugin model, you now have the flexibility to configure exactly how sensors are classified for your specific hardware. This makes out-of-band monitoring much more adaptable, no matter what kind of machines you’re running in your racks. If you're looking to get started or troubleshoot missing temperature readings, check out the dedicated threads on our forum. ![](https://xen-orchestra.com/blog/content/images/2026/05/578525327-a4e27519-0574-4d5b-ab1e-4b205a488a81.png) The new IPMI sensor plugin [How to Setup IPMI in XOHi, Just updated to xcp-ng 8.3 and I tried searching the XO docs for IPMI but can’t find anything. How do I see IPMI info from our Dell PE 640 in XO? Thank y…![](https://xen-orchestra.com/blog/content/images/icon/512-34.png)XCP-ngstevewest15![](https://xen-orchestra.com/blog/content/images/thumbnail/site-logo-12.png)](https://xcp-ng.org/forum/topic/11536/?ref=xen-orchestra.com) ### Xen Orchestra 6.4 URL: https://xen-orchestra.com/blog/xen-orchestra-6-4/ Last updated: 2026-05-28T06:10:59.000Z It's time! Xen Orchestra 6.4 is now available, and it comes with many exciting things. From new features to long standing subtle bugs we fixed, it's a real adventure that happened in only a month. Enjoy the read. #### 🔗 Summary 👨‍🚀 [Project & Community](#%F0%9F%91%A8%E2%80%8D%F0%9F%9A%80-project-community) 🏢 [User stories](#%F0%9F%8F%A2-user-stories) 🎫 [Events & Webinars](#%F0%9F%8E%AB-events-webinars) [****XO 6.4**](#xo-64) 1. 🛡️ [Security](https://xen-orchestra.com/blog/xen-orchestra-6-3/#%F0%9F%9B%A1%EF%B8%8F-security) 2. 💾 [Backup](#%F0%9F%92%BE-backup) 3. 🛰️ [XO 6](#%F0%9F%9B%B0%EF%B8%8Fxo-6) 4. 🪐 [XOA](#%F0%9F%AA%90-xoa) 5. 📡 [REST API](#%F0%9F%93%A1-rest-api) 6. ☸️ [DevOps Tools](#%E2%98%B8%EF%B8%8F-devops-tools) 7. 📖 [Documentation & Guides](#%F0%9F%93%96-documentation-guides) 8. 🌐 [Translations](#%F0%9F%8C%90-translations) 9. 🆕 [Misc](#%F0%9F%86%95-misc) As usual, this announcement is available as a Youtube video: ## 👨‍🚀 Project & Community This month brought a mix of ecosystem progress, community contributions, and deeper involvement from Vates across the stack. ### SMAPI maintainership One notable step is that Vates is now actively maintaining parts of the XAPI storage stack (Smapi). This is more than a technical detail: storage is a critical layer in any virtualization platform, and this move reinforces the long-term sustainability of the ecosystem. [sm: change MAINTAINERS to switch maintenance to Vates by AnthoineB · Pull Request #801 · xapi-project/smAs discussed with the current maintainers, this commit will change maintainers of sm component to @Wescoeur, @Nambrok and @AnthoineB (same order as in MAINTAINERS file).![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-97.svg)GitHubxapi-project![](https://xen-orchestra.com/blog/content/images/thumbnail/180205964)](https://github.com/xapi-project/sm/pull/801/changes?ref=xen-orchestra.com) ### Security hardening guide This month, we also focused on security as a core part of the stack, not an afterthought. A dedicated hardening guide is now available to help users secure their infrastructure in a practical way. [Security hardening for Vates VMSDiscover key principles and get our guide to harden your virtualization infrastructure and strengthen your security posture with Vates VMS.![](https://xen-orchestra.com/blog/content/images/icon/logo64-48.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-vms-hardening-guide-security-virtualization.webp)](https://vates.tech/blog/security-is-part-of-the-stack/?ref=xen-orchestra.com) ### XCP-ng 8.3 updates At the platform level, XCP-ng 8.3 LTS continues to receive regular security and maintenance updates, ensuring stability and long-term reliability for production environments. [April 2026 Security and Maintenance Updates for XCP-ng 8.3 LTSSecurity vulnerabilities have been detected and fixed in Xen, oxenstored, XAPI, and OpenSSH. In addition to this, the updated packages bring bug fixes and small improvements which were queued for release.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-43.png)XCP-ng BlogSamuel Verschelde![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1614064641938-3bbee52942c7)](https://xcp-ng.org/blog/2026/04/28/april-2026-security-and-maintenance-updates-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) ### Everpure and Vates partnership Finally and officially, Vates joined the Everpure Technology Alliance Program, strengthening the ecosystem around storage and enterprise integrations. [Vates joins the Everpure Technology Alliance ProgramVates has joined the Pure Storage Technology Alliance Program (TAP), formalizing a technical collaboration between Vates VMS and Pure Storage.![](https://xen-orchestra.com/blog/content/images/icon/logo64-49.png)Vates BlogJb Piacentino![](https://xen-orchestra.com/blog/content/images/thumbnail/purestorage-array.jpg)](https://vates.tech/blog/vates-joins-the-everpure-technology-alliance-program/?ref=xen-orchestra.com) --- ## 🏢 User stories This month, one user story stands out and illustrates a broader trend across the industry. Virtual Computing BV migrated 550 VMs to Vates VMS. What started as a response to licensing changes quickly turned into a more strategic move, driven by the need for cost control, flexibility, and long-term independence. [How Virtual Computing moved 550 VMs to Vates VMSFacing VMware licensing changes, Virtual Computing migrated 550 VMs to Vates VMS. A controlled, step-by-step transition.![](https://xen-orchestra.com/blog/content/images/icon/logo64-46.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/virtual-computing-vates-user-story.webp)](https://vates.tech/blog/how-virtual-computing-migrated-550-vms-to-vates-vms/?ref=xen-orchestra.com) --- ## 🎫 Events & webinars Beyond product updates, sharing experience and structuring knowledge remains an important part of the ecosystem. ### Xen Spring Meetup 2026 The community gathered in early April for the Xen Spring Meetup 2026\. The event brought together developers, users, and contributors to share insights, discuss real-world use cases, and continue building momentum around the Xen ecosystem. [Xen Spring Meetup 2026: recap, talks and insightsA recap of Xen Spring Meetup 2026 featuring key talks, community insights, and real-world virtualization discussions.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-44.png)XCP-ng BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-at-xen-spring-meetup-2026-1.webp)](https://xcp-ng.org/blog/2026/04/29/xen-spring-meetup-2026-a-look-back-at-the-community-in-motion/?ref=xen-orchestra.com) ### NextInfra series This month, the NextInfra series ended, after exploring how organizations move from migration projects to broader infrastructure strategy. The focus was not just on replacing tools, but on designing platforms that are sustainable, adaptable, and aligned with long-term goals. 🥖 These webinars are in French and are not subtitled. [NextInfra series: From migration to sovereign ITFrom V2V migration to long-term strategy, the NextInfra series explores how to build a sovereign infrastructure step by step, with real-world insights from Exodata and Vates.![](https://xen-orchestra.com/blog/content/images/icon/logo64-47.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-exodata-webinar-nextinfra.webp)](https://vates.tech/blog/nextinfra-series-from-migration-to-strategy-building-a-sovereign-infrastructure/?ref=xen-orchestra.com) --- # XO 6.4 Our primary focus this month is the rollout of the **new RBAC (ACL v2) system**, a massive update that unlocks a new level of control within the platform. On top of this, we have integrated more features from XO 5 to XO 6, focused on core maintenance and reduced technical debt, to keep the environment healthy. Many of these updates come straight from your feedback, like the return of real-time backup progress and better disk management. We also tracked down and fixed a very old memory leak, which makes the whole platform feel more stable. With these improvements (on top of the major updates to our REST API and DevOps tools) XO 6 becomes more mature than ever. ## 🛡️ Security Keeping XO secure is our top priority. This month’s under-the-hood updates focus on refreshing core dependencies, to make sure the platform stays resilient and ready for our latest features. ### Security: Dependency updates We've updated several of our internal package dependencies to their latest versions. These updates mainly focus on patching potential security vulnerabilities and improving overall stability. You won't notice any changes in the interface, as this is all "under the hood" maintenance. However, keeping these libraries current is essential for making sure the platform stays secure and runs smoothly with modern web standards. 💡 Remember you can access all security advisory of the whole stack at [https://docs.vates.tech/category/advisories](https://docs.vates.tech/category/advisories?ref=xen-orchestra.com) ## 💾 Backup We know how important it is to see exactly what’s happening with your data. That’s why XO 6.4 brings back some of the visibility you missed, with real-time tracking and more detailed metrics to the backup logs. ### Backup progress in XO 6 Based on your feedback, we’ve brought back the real-time progress tracking that many of you relied on in XO 5\. Now, backup jobs feed directly into the general `XO Tasks` system (instead or their own task system), so you can monitor their status in real-time. Instead of wondering if a job is stalled, you can now see the progress percentage and current throughput directly in the interface. 💡 ****Note:** For now, this change won't affect how you see your history. However, once your older backup logs are eventually rotated out, this new system will allow for faster loading times when viewing your backup logs. [Show backup progress like XO5\. · Vates VMS feedbackIn XO5 its easy to watch a backup task progess (Which VM is being backed up / replicated and its progress and estimated completion) by viewing tasks.![](https://xen-orchestra.com/blog/content/images/icon/qZprAll0bofaK77abT3Hg93cBpodHgaHZDLk2GsiR40oQ1RNVD9xs84LBJcJYOXO-logo400-4.png)![](https://xen-orchestra.com/blog/content/images/thumbnail/qZprAll0bofaK77abT3Hg93cBpodHgaHZDLk2GsiR40oQ1RNVD9xs84LBJcJYOXO-logo400-4.png)](https://feedback.vates.tech/posts/9/show-backup-progress-like-xo5?ref=xen-orchestra.com) ### Merged size in backup logs We’ve added a new **merged size** metric to your backup task logs. This shows up whenever a backup job merges data, which is common with Delta backups. This change lets you see exactly how much data was processed during the cleanup phase. It's a great way to get a better handle on total disk activity. Also, it helps explain why some jobs take longer to finish, even when they aren't transferring much new data. ## 🛰️ XO 6 XO 6 is maturing fast. This month, we’ve ported over several of your most-requested features from XO 5, so can now manage your pools, networks, and storage without ever leaving the new dashboard. ### Security tab for Pools We’ve brought the **Security** tab over to the **Pool** view. The tab displays the current traffic rules for your networks and VIFs, so you can have a dedicated spot to manage security settings for your infrastructure. ![](https://xen-orchestra.com/blog/content/images/2026/04/585298483-f00f96ca-5eb4-4c60-a743-e9a45985adfb.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/585298635-e712f044-0b54-4839-aed5-cccbdc62e2c6.png) Security tab in the Pool view ### Network deletion You can now delete unneeded networks straight from XO 6\. This feature was previously only available in XO 5, but you can now handle everything without leaving the new interface. ![](https://xen-orchestra.com/blog/content/images/2026/04/581481484-cf211859-592e-4514-b53d-9a506d52c367.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/581481665-38256dd9-7568-428d-9fbb-321fee7d16f0.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/581482168-f826f23b-83a4-486c-ae72-1d9088856656.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/581482600-0a9b9089-f75a-46f8-bafd-cefb1c55a9e3.png) Dialog boxes for network deletion ### Network interface deletion XO 6 now lets you also remove network interfaces (VIFs) from your VMs. As we keep moving towards full feature parity with XO 5, you won’t have to jump back and forth between versions just to manage your VM networking. ![](https://xen-orchestra.com/blog/content/images/2026/04/579264791-6cb22355-9fdb-4a7a-b28c-e5986d4c4419.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/579264701-7f440eca-e8d3-467a-8334-0a7d8c05d174.png) Delete VIFs straight from XO 6 ### Snapshot deletion On top of deleting networks and VIFs, XO 6.4 lets you delete VM snapshots, with the new **Delete** action in the snapshot list. ![](https://xen-orchestra.com/blog/content/images/2026/04/581511794-a0560df6-b31a-4e17-b52e-e438fa1caf3a-1.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/581511865-da7776e4-ea43-4f5f-8c4c-b66d9efc670d-1.png) The new Delete button for snapshots ### Smarter IP display in Pool and Host views We’ve refined how IP addresses appear in the Pool and Host tables to keep the interface clean. Instead of crowding the columns with every available address, the table now prioritizes and displays only the Management IP. If a host has additional addresses, a small badge appears next to the main one. To see the full list, you can still find the **Management IP** and **Other IPs** in the side panel. This keeps your host list organized, showing you the primary IP first and hiding the rest until you need it. ![](https://xen-orchestra.com/blog/content/images/2026/04/584223047-79ad1804-d469-414c-903c-85df16c2ed85.png) ### Smarter tab navigation We’ve tweaked how XO 6 handles tabs to save you some unnecessary clicking. Now, if you’re looking at a VM’s **System** tab and switch to another VM, you’ll stay right where you are. This makes it faster to compare settings across multiple objects of the same type. To keep things predictable, the interface "resets" when you head elsewhere. If you jump to a different category (like moving from a VM to a Host) or pick a new page entirely, clicking an item in the treeview will land you back on its main dashboard. ### Improved VIF management You can now connect or disconnect network interfaces (VIFs) directly in XO 6\. It’s the virtual equivalent of plugging or unplugging a network cable. This makes troubleshooting much faster since you can cut the connection without losing any of your VIF settings. ![](https://xen-orchestra.com/blog/content/images/2026/04/582024364-668fd461-5729-4033-9350-465b961f570c-1.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/582024522-de814d51-29e6-44b5-91ab-6127c0bcd93a-1.png) Connect and Disconnect VIF actions ### Better disk management We’ve added new ways to manage your disks (VDIs) directly from the VM view. First, a new toggle lets you **connect or disconnect** a disk on the fly. It’s like virtually plugging or unplugging a cable. The disk stays in your settings, but the VM stops seeing it. If you want to remove a disk from the VM but keep the data, you can now **detach** it. This removes the VBD (the link to the VM) while leaving the disk safe in your storage. Finally, for a complete cleanup, the **destroy** action detaches the disk and **permanently deletes** it from your storage in one click. These updates mean you can now handle your entire storage workflow without leaving XO 6. ![](https://xen-orchestra.com/blog/content/images/2026/04/581513461-61ba1b07-1c6a-483e-9541-3ca3e706a2e7-1.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/582046259-417a2ea6-8179-447d-9f52-55994135fae5-1.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/582046498-f1145e72-d0cd-444a-be56-2f381b7e0802-1.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/579263982-a74c5dd0-fa98-46b6-8697-6f500784f1df-1.png) New disk management buttons in XO 6 ### Better system pages We improved the "System"pages layout to display key-value data in a tabular way (vertically aligned). Basically, it's a lot easier to read, see the before/after: ![](https://xen-orchestra.com/blog/content/images/2026/04/581313618-65f13155-42a8-4be3-b0a8-ac0794deab12-4.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/581311692-cb3ed8c1-6fc6-44b1-9fc2-b236a2c27bf0-2.png) Thanks *probain* [for the feedback!](https://feedback.vates.tech/posts/37/xo6-ui-very-messy-columns-width-in-vm-system-far-better-in-xo5?ref=xen-orchestra.com) ## 🪐 XOA Beyond the XO 6 updates, we're also maintaining the infrastructure that powers XOA. We’ve begun moving our internal tools to the next generation of Node.js, to ensure a seamless transition for everyone later this year. ### Upgrading the XOA latest to Node.js 22 LTS With Node 20 hitting its end-of-life on April 30, 2026, we’ve started transitioning our tools to the next LTS version. As a a result, we’ve upgraded Node.js to version 22 LTS on XOA with the `latest` release channel (XO 6.4, this very release). This update is meant to flush out any potential bugs or compatibility issues before we roll out the update progressively until reaching `stable`. 💡 ****Note:** While the `latest` branch will use Node.js v22 TLS and use XO 6.4, the `stable` branch will remain on XO 6.2. ## 📡 REST API The REST API is taking a massive step forward! The new RBAC (ACL v2) system is finally here, and we’ve also added AI-friendly formatting to help you automate your infrastructure more effectively. ### RBAC/ACLv2 management We’ve integrated our new RBAC ([Role-based access control](https://en.wikipedia.org/wiki/Role-based%5Faccess%5Fcontrol?ref=xen-orchestra.com))/ACL ([Access-control list](https://en.wikipedia.org/wiki/Access-control%5Flist?ref=xen-orchestra.com)) system into the REST API. This new version (ACL v2) offers increased flexibility and makes it easier to manage permissions programmatically. One of the biggest changes is that you no longer need full administrator privileges to access or manage these RBACs. As long as a user has the appropriate v2 permissions, they can interact with the API directly. This greatly simplifies permission management. You can now let people manage their own tasks, without giving them full access to everything else. Don't forget to check out our new documentation on this subject! Scroll down to the [Documentation & Guides section](#documentation-for-rbac-acl-v2) to know more. If you have any feedback on RBAC, feel free to join the conversation over on our forum: [ACL V2, we need your feedbacks!ACL v2: Fine-grained access control in Xen Orchestra With the v2 of the ACL system, Xen Orchestra takes a new step forward in permission management. Where v1…![](https://xen-orchestra.com/blog/content/images/icon/512-21.png)XCP-ngMathieuRA![](https://xen-orchestra.com/blog/content/images/thumbnail/70369997-1)](https://xcp-ng.org/forum/topic/12036/acl-v2-we-need-your-feedbacks?ref=xen-orchestra.com) ### Markdown output The REST API now supports **Markdown formatting** for endpoints that return collections of data. While it’s a nice touch for human readability, the real benefit is for automation and AI. By structuring data in Markdown, the API becomes more efficient for our MCP (Model Context Protocol) server. Large Language Models (like Claude or GPT) can parse Markdown much faster and more accurately than raw, unformatted text. This leads to better performance, lower token costs, and more reliable responses when you’re using AI to manage your infrastructure. ### Improving our MCP integration Since the Xen Orchestra API has more than 200 endpoints, it was counterproductive to map each endpoint to a dedicated tool in our MCP server. Giving too many options at once to a large language model creates context pollution, which leads to higher costs, slower responses, and a higher risk of the AI making mistakes during tool selection. We solved this by using our OpenAPI spec to load tools dynamically, and adding Markdown formattersto keep the data clean. This allows the MCP server to connect to Swagger, making all endpoints directly usable in a read-only mode. **The LLM receives only the most relevant information, in a format that's structured and readable.** Additionally, you can now connect the MCP server to several Xen Orchestra instances at once. These improvements make your interactions across all MCP clients (including Claude Code and Claude Desktop) more reliable, as the AI only receives the most relevant, cleanly formatted information. [MCP meets Xen OrchestraTalk to your infrastructure in plain language, get instant answers, and keep everything on-prem if you want.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-40.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/mcpxo62-1.webp)](https://xen-orchestra.com/blog/mcp-meets-xen-orchestra/) ## ☸️ DevOps Tools DevOps Tools team continues to deliver more every month, and the team itself is even growing. It's clearly a priority for us to make sure our XCP-ng+XO combo is cloud native. ### Cloud Storage Interface (CSI) driver v0.2.0 The latest CSI driver release introduces dynamic provisioning: by creating a Kubernetes storage class that references the XO CSI driver and sets the `poolId` parameter to the default SR of your chosen pool, you can then create a PVC and pod using that storage class, and Xen Orchestra will automatically provision new VDIs to satisfy the requested volumes. [Release v0.2.0 · vatesfr/xenorchestra-csi-driverWhat’s Changed feat: improve node metadata handling for CCM integration by @gCyrille in #23 tests: Sanity test by @JeremyLARDENOIS in #32 feat: dynamic provisioning by @gCyrille in #32 Full Chang…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-98.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v0.2-4.0)](https://github.com/vatesfr/xenorchestra-csi-driver/releases/tag/v0.2.0?ref=xen-orchestra.com) ### Golang SDK v1.15.1 The v2 SDK now includes an SR service and support for creating empty VDIs, letting users inspect storage repositories, provision blank virtual disks, and later attach them to VMs—capabilities that underpin our Kubernetes CSI Driver. [Release v1.15.1 · vatesfr/xenorchestra-go-sdk1.15.1 (2026-04-03) Bug Fixes v2/vdi: Add missing Create method in SDK library interface (f5749ef)![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-101.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v1.15-1.1)](https://github.com/vatesfr/xenorchestra-go-sdk/releases/tag/v1.15.1?ref=xen-orchestra.com) ### Terraform provider v0.38.0 All methods for connecting to the provider are now correctly listed in the example and dependencies have been bumped. [Release v0.38.0 · vatesfr/terraform-provider-xenorchestraWhat’s Changed ci(deps): bump setup-go action to v6 and update Go version handling by @gCyrille in #406 docs: specify and fix units of measurement by @JeremyLARDENOIS in #403 build(deps): bump git…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-100.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v0.38.0)](https://github.com/vatesfr/terraform-provider-xenorchestra/releases/tag/v0.38.0?ref=xen-orchestra.com) ### OpenMetrics We are still improving our OpenMetrics plugin, allowing to translate the RRDs into meaningful data for Prometheus/Grafana (for example). #### 9 more host RRD metrics exposed We’ve added 9 more host RRD metrics to give you even deeper insights into your infrastructure. These new metrics include : **host load**, **memory reclamation data**, **running vCPUs**, and **aggregated network traffic**. We’ve also added SR-level data like **IOPS**, **throughput**, and **latency**. This extra visibility helps you track your pool's performance and health more easily, through any OpenMetrics-compatible tool. ![](https://xen-orchestra.com/blog/content/images/2026/04/576434326-3d2bbcad-f033-4054-b373-5b233877d05e.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/576434327-2ee88ab4-00c3-4f58-834d-bd8722b64ed7.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/576434337-0f777556-493a-4548-a85c-1c6128f393c4.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/576434343-338b0547-41e1-4be2-a575-a158eae65d9c.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/576434349-15f96e44-805e-4ffa-8281-df89664409ce.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/576434357-47462741-0900-4368-a3bc-17ab09dfd364.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/576434360-b669659f-1b87-49ba-8d10-12b91edeabee.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/576434365-e84d2a3a-6500-48b0-b02b-dee8f3d1725d.png) ![](https://xen-orchestra.com/blog/content/images/2026/04/576434372-2f972a8f-02a2-4ef2-a8ea-91f4483a3be5.png) All 9 metrics returning valid data on a 3-host pool #### New VDI storage metrics You can now monitor both the virtual size of your VDIs and the actual physical space they occupy on your SRs. These metrics include labels for pool, SR, and VDI names, and even identify the associated VM when a disk is attached. This extra level of detail helps you pinpoint exactly where your storage is being used and anticipate capacity needs directly from your monitoring dashboard. ![](https://xen-orchestra.com/blog/content/images/2026/04/574594996-b52f7d56-3d0b-4255-9ab6-d1201dcf21a9.png) VDI metrics exposed in OpenMetrics [GitHub - prometheus/OpenMetrics: Evolving the Prometheus exposition format into a standard.Evolving the Prometheus exposition format into a standard. - prometheus/OpenMetrics![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-90.svg)GitHubprometheus![](https://xen-orchestra.com/blog/content/images/thumbnail/OpenMetrics)](https://github.com/prometheus/OpenMetrics?ref=xen-orchestra.com) ### ## 📖 Documentation & Guides A good software cannot exist without a good documentation. So we make progress every month to make it better! ### Documentation for RBAC / ACL v2 We’ve updated our documentation to reflect the new RBAC / ACL v2 system in the REST API. It’s a complete shift in how we deal with permissions. We’re moving to a more standard model, based on Subjects, Roles, and Permissions. The documentation now include clear definitions and updated terminology. Admins setting up complex delegation and developers using the new REST API can now find all the details to understand the updated logic. ![](https://xen-orchestra.com/blog/content/images/2026/04/aclv2-doc-preview.png) Preview of the RBAC documentation [ACL v2 / RBAC (REST API/XO6) | Xen Orchestra | XO DocumentationACL v2 is the access control system for the Xen Orchestra REST API and the XO6 UI. It lets you define exactly what each user or group can see and do — down to individual objects — without granting them full administrator access.![](https://xen-orchestra.com/blog/content/images/icon/favicon-55.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-37.png)](https://docs.xen-orchestra.com/xo6/acl-v2?ref=xen-orchestra.com) ## 🔦 Community spotlight Some two interesting items in our community this month. ### VMware exit strategy ### XenAdminQt XenAdminQt, an alternative management interface, recently saw a new alpha release, illustrating the diversity of tools built around the platform. [Release v0.0.6-alpha · benapetr/XenAdminQtPrebuilt packages for macOS, GNU/Linux and Windows![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-93.svg)GitHubbenapetr![](https://xen-orchestra.com/blog/content/images/thumbnail/v0.0.6-alpha)](https://github.com/benapetr/XenAdminQt/releases/tag/v0.0.6-alpha?ref=xen-orchestra.com) ### Nice words from our community > Thank you! I am always impressed by you guys. Making testing and reporting upstream (to you guys) a good experience! [Source: our forums](https://xcp-ng.org/forum/post/104820?ref=xen-orchestra.com) Thank you very much for those kind words 🤩 I personally think that's the best demonstration on how committed we are to serve our community! ## 🌐 Translations Having the capacity to use the software in your preferred language is a big plus. Thanks to a great community effort, combined with WebLate, we can track our progress. ### 17 languages updated A big thank you to our community for their ongoing efforts in translating Xen Orchestra! This month, 17 languages were updated: **Brazilian Portuguese, Czech, Danish, Dutch, Farsi, Finnish, German, Italian, Korean, Mandarin Chinese (simplified), Norwegian (Bokmål),** **Polish, Portuguese, Russian, Slovak, Spanish,** and **Swedish.** ![](https://xen-orchestra.com/blog/content/images/2026/04/xo-translation-status.svg) Current XO translation status Want to help translate Xen Orchestra or improve existing translations? You’re more than welcome to join in [here](https://translate.vates.tech/?ref=xen-orchestra.com). ## 🆕 Misc As usual, the things we cannot sort as "the rest" in this Misc section. ### Fixed: Years-old TLS memory leak We’ve finally fixed a persistent memory leak in our TLS session handling. This issue had been tucked away in the code for 8 years! It was very very variable, but in some extreme cases, some users were reporting up to 100MB of extra RAM every hour, which is definitely not ideal for long-term stability. **What was happening?** The issue was caused by a silent incompatibility between two libraries our web server uses: `http-server-plus` and `stoppable`. Because of a failed type check, the system wasn't properly tracking secure HTTPS connections. Every single request created a `TLSSocket` object that stayed stuck in memory forever, even after the connection was closed, because the garbage collector never received the signal to clean it up. **What we observed, in numbers** The memory leak impact was significant. Before the fix, heap snapshots from an affected XOA instance showed active `TLSSocket` instances jumping from 23 to **over 1,500** in less than six hours. This led to the JS Heap growing by about **46 MB per hour,** while native memory pressure from OpenSSL TLS contexts consumed roughly **2.6 GB of RAM per day**. Combined, this resulted in a total memory leak of approximately **3.7 GB per day**. **Closing an old chapter** The bug managed to survive for 12 years, with the affected code remaining untouched for the last 8\. With this fix, Xen Orchestra will stay more stable, especially in busy environments with lots of active connections. To know more about this, feel free to read this thread on our forum: [XOA - Memory UsageJust noticed alert today. Currently at default settings for XOA ram allocation 4gb 4vcpus. There is a recommendation for a set value based on pulls/hosts/…![](https://xen-orchestra.com/blog/content/images/icon/512-20.png)XCP-ngacebmxer![](https://xen-orchestra.com/blog/content/images/thumbnail/1771707071635-screenshot_20260221_155047.png)](https://xcp-ng.org/forum/topic/11892/xoa-memory-usage?ref=xen-orchestra.com) ### Fixed: VM copy timeouts We fixed a bug that was causing `408 Request Timeout` errors when copying VMs with compression enabled. Interestingly, we found that compression wasn't actually working in XO 5 due to an old bug, so users weren't getting the bandwidth savings they expected. The fix is simple: the system now waits until the first compressed bytes are ready before starting the transfer. This stops the random timeouts and ensures that compression finally works as intended. As a result, your remote VM copies are now more reliable. ### Smarter OS organization for NetBox Thanks your feedback, we’ve improved how operating systems are synced with NetBox by taking advantage of the platform hierarchies introduced in version 4.4. Now, when a major version number is detected, Xen Orchestra creates a versioned child platform (like `Debian 12`) under its parent distro (like `Debian`) and assigns the VM to it. If no version is found, it just uses the main distro platform as before. This addition makes your NetBox inventory much more organized and granular, directly addressing a request from our users. ![](https://xen-orchestra.com/blog/content/images/2026/04/570321119-c57086ec-6c7d-45d8-b028-8b641d6ddd79.png) Detailed OS hierarchy with NetBox ### Let's Encrypt DNS-01 support (Technical Preview) We’ve added support for Let's Encrypt DNS-01 challenges, a feature suggested by our community to improve how you secure Xen Orchestra. This new method allows you to generate SSL certificates without exposing your XO instance to the public Internet. Previously, using Let's Encrypt required an HTTP challenge, which meant opening your appliance to the outside world. With DNS-01, Xen Orchestra verifies domain ownership directly through your DNS provider instead. Your setup stays private and secure, but you still get the convenience of automatic renewals. As always, if you have any feedback, feel free to share it over at [https://feedback.vates.tech/](https://feedback.vates.tech/?ref=xen-orchestra.com)! [Challenge TypesWhen you get a certificate from Let’s Encrypt, our servers validate that you control the domain names in that certificate using “challenges,” as defined by the ACME standard. Most of the time, this validation is handled automatically by your ACME client, but if you need to make some more complex configuration decisions, it’s useful to know more about them. If you’re unsure, go with your client’s defaults or with HTTP-01.![](https://xen-orchestra.com/blog/content/images/icon/favicon-47.ico)Let's Encrypt![](https://xen-orchestra.com/blog/content/images/thumbnail/LetsEncrypt-SocialShare.png)](https://letsencrypt.org/docs/challenge-types/?ref=xen-orchestra.com#http-01-challenge) [XO Support for Lets Encrypt DNS-01 Challenges. · Vates VMS feedbackSupport Lets Encrypt DNS-01 Challenges. XO currently supports LE HTTP challenges but often times one does not want their XO exposed to the outside int![](https://xen-orchestra.com/blog/content/images/icon/qZprAll0bofaK77abT3Hg93cBpodHgaHZDLk2GsiR40oQ1RNVD9xs84LBJcJYOXO-logo400-2.png)![](https://xen-orchestra.com/blog/content/images/thumbnail/qZprAll0bofaK77abT3Hg93cBpodHgaHZDLk2GsiR40oQ1RNVD9xs84LBJcJYOXO-logo400-2.png)](https://feedback.vates.tech/posts/21/xo-support-for-lets-encrypt-dns-01-challenges?ref=xen-orchestra.com) ### Xen Orchestra 6.3 URL: https://xen-orchestra.com/blog/xen-orchestra-6-3/ Last updated: 2026-04-01T13:27:18.000Z March has been a packed month. Between InCyber in Lille, the Xen Spring Meetup in Grenoble, and everything happening around the project (new user stories, the Vates Alliance Network, a webinar series wrapping up) there was barely time to breathe. And yet the engineering team kept shipping. XO 6.3 is here, with some changes I'm particularly happy about, including a dashboard performance rewrite for large deployments, and a completely reworked immutable backup engine. Oh, and QCOW2 RC2 is landing next week: I'll need your help on that one. Happy Easter to those celebrating! 🐣 #### 🔗 Summary 👨‍🚀 [Project & Community](#%F0%9F%91%A8%E2%80%8D%F0%9F%9A%80-project-community) 🏢 [User stories](#%F0%9F%8F%A2-user-stories) 🎫 [Events & Webinars](#%F0%9F%8E%AB-events-webinars) [****XO 6.3**](#xo-63) 1. 🛡️ [Security](https://xen-orchestra.com/blog/xen-orchestra-6-3/#%F0%9F%9B%A1%EF%B8%8F-security) 2. 💾 [Backup](#%F0%9F%92%BE-backup) 3. 🥝 [Core UI](#%F0%9F%A5%9D-core-ui) 4. 🛰️[XO 6](#%F0%9F%9B%B0%EF%B8%8Fxo-6) 5. 📡 [REST API](#%F0%9F%93%A1-rest-api) 6. ☸️ [DevOps Tools](#%E2%98%B8%EF%B8%8F-devops-tools) 7. 🐦 [VMware to Vates (V2V)](#%F0%9F%90%A6-vmware-to-vates-v2v) 8. 📖 [Documentation & Guides](#%F0%9F%93%96-documentation-guides) 9. 🌐 [Translations](#%F0%9F%8C%90-translations) 10. 🆕 [Misc](#%F0%9F%86%95-misc) As usual, this announcement is available as a Youtube video but also a Spotify podcast: ## 👨‍🚀 Project & Community Beyond the product itself, the broader Vates ecosystem has also been moving fast lately, with **new technical content**, a **partner webinar**, and fresh **user stories** showing how organizations are modernizing their infrastructure with open virtualization. ### XCP-ng 8.3 March updates March was busy on the XCP-ng side with one maintenance update and two security patches for XCP-ng 8.3 LTS, all requiring a host reboot. The **March 10 maintenance update** was the most substantial XCP-ng: it brought OpenSSL up to version 3.0.9, a major version jump that strengthened cryptographic protections and required rebuilding many system packages. In most cases this is transparent, with one notable exception affecting XO's SDN controller plugin. [March 2026 Maintenance Updates for XCP-ng 8.3 LTSNew maintenance updates are available for XCP-ng 8.3 LTS.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-40.png)XCP-ng BlogSamuel Verschelde![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1554738458-6c6ae81806fb)](https://xcp-ng.org/blog/2026/03/10/march-2026-maintenance-updates-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) The **March 19 security update** addressed `XSA-480`, a vulnerability on x86 Intel systems with EPT support where unintended host or guest memory regions could be accessed from privileged VM code, potentially leading to privilege escalation, denial of service, or information leaks. An ipmitool bugfix was bundled in as well. [March 2026 Security Updates for XCP-ng 8.3 LTSNew security and maintenance updates are available for XCP-ng 8.3 LTS.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-41.png)XCP-ng BlogGaël Duperrey![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1651720602400-af454e39f3e1)](https://xcp-ng.org/blog/2026/03/19/march-2026-security-updates-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) The **March 26 security update** patched a second vulnerability (`CVE-2026-4397`) where insufficient memory sanitization during VM creation could leak data from earlier instances and open the door to privilege escalation. Notably, this was caught before the Xen Project issued any upstream release, so there is no corresponding XSA. [March 2026 Security Updates #2 for XCP-ng 8.3 LTSNew security updates are available for XCP-ng 8.3 LTS.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-42.png)XCP-ng BlogGaël Duperrey![](https://xen-orchestra.com/blog/content/images/thumbnail/cyber-security-concept-digital-art2.jpg)](https://xcp-ng.org/blog/2026/03/26/march-2026-security-updates-2-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) ### New Win PV driver release In fact 2 releases: `9.1.145`, which came 2 weeks ago, bundling the VGA display adapter to allow easy resolution change. The changelog is [available here](https://github.com/xcp-ng/win-pv-drivers/releases/tag/v9.1.145?ref=xen-orchestra.com). And more recently, the `9.1.146` (latest) which fixed a small bug: [Release 9.1.146 Release · xcp-ng/win-pv-driversThis is a small revision to fix issues when installing on certain Windows installations. Only the installer and XenClean were changed; the binaries inside stay the same. To download XenClean, click…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-88.svg)GitHubxcp-ng![](https://xen-orchestra.com/blog/content/images/thumbnail/v9.1.146)](https://github.com/xcp-ng/win-pv-drivers/releases/tag/v9.1.146?ref=xen-orchestra.com) ### DevOps Tools #1: Infrastructure as Code We recently published the first article in a new DevOps Tools series, focused on Infrastructure as Code. It shows how version-controlled, repeatable workflows also apply to virtualization, networking, and storage in modern on-prem and hybrid environments. [DevOps Tools with Vates VMS: IaC fundamentalsInfrastructure as Code is more than automation! Learn how Vates VMS lets you manage virtual machines, networks, and storage with version-controlled, repeatable workflows.![](https://xen-orchestra.com/blog/content/images/icon/logo64-39.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/devops-tools-iac-vates-vms.png)](https://vates.tech/blog/devops-tools-1-infrastructure-as-code/?ref=xen-orchestra.com) ### Introducing the Vates Alliance Network We introduced the Vates Alliance Network (VAN), a new framework for building and showcasing validated solutions around Vates VMS. Through assets such as the Solutions Compatibility List, Solution Briefs, and Solution Guides, the VAN is meant to make tested integrations easier to discover and deploy. [Introducing the Vates Alliance NetworkOrganizations moving to Vates VMS are not looking for products, they are building complete solutions. The Vates Alliance Network (VAN) ensures those solutions are tested, documented, and ready to deploy.![](https://xen-orchestra.com/blog/content/images/icon/logo64-45.png)Vates BlogJb Piacentino![](https://xen-orchestra.com/blog/content/images/thumbnail/Picture1-5.jpg)](https://vates.tech/blog/introducing-the-vates-alliance-network/?ref=xen-orchestra.com) 💡 If you are a technology vendor or solution provider interested in joining the Vates Alliance Network, we'd love to hear from you: [reach out here](https://vates.tech/contact/?ref=xen-orchestra.com). ### QCOW2 volumes: RC2 coming next week! The QCOW2 volume support (which removes the 2 TiB limit on virtual disks) is entering its **second and final Release Candidate** next week. This RC2 is the last planned testing round before the **General Availability release, targeted for end of April**. If you want to help make that GA as solid as possible, now is the perfect time to jump in. The more issues we can surface and squash during RC2, the more confidence we'll have going into production. We've set up a dedicated thread with full testing instructions: 👉 [Dedicated thread: Removing the 2TiB limit with QCOW2 volumes](https://xcp-ng.org/forum/topic/10308/dedicated-thread-removing-the-2tib-limit-with-qcow2-volumes?ref=xen-orchestra.com) Your feedback directly shapes the quality of the final release: don't hesitate to report anything you find, however minor it seems! ### Protect Xen Orchestra with BunkerWeb BunkerWeb recently shared a guide on securing Xen Orchestra’s management interface. It is a good example of how open source security tooling can complement XO with a safer access layer and reduced attack surface. [Protect Xen Orchestra with BunkerWeb GuideLearn how to protect Xen Orchestra’s management interface with BunkerWeb and reduce your attack surface with a cleaner, safer access layer.![](https://xen-orchestra.com/blog/content/images/icon/favicon.png)BunkerWebThéophile DIOT![](https://xen-orchestra.com/blog/content/images/thumbnail/xen_orchestra_hero-scaled.webp)](https://www.bunkerweb.io/2026/03/19/protect-xen-orchestra-bunkerweb/?ref=xen-orchestra.com) --- ## 🏢 User stories This month, we published two new user stories showing how organizations are putting Vates VMS to work in very different contexts: one in the French public sector, one in the private sector following a VMware migration. Both share a common thread: reducing vendor lock-in and regaining control over their infrastructure. #### DRAC Grand Est On the user stories side, we published a new case study on DRAC Grand Est, showing how a public-sector organization modernized its infrastructure while reducing vendor lock-in. The project highlights better cost control, simpler operations, and stronger alignment with sovereignty requirements. [How DRAC Grand Est modernized IT with Vates VMSSee how DRAC Grand Est modernized its IT: Vates VMS cut licensing costs, simplified management, and ensured compliance without vendor lock-in.![](https://xen-orchestra.com/blog/content/images/icon/logo64-41.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/drac-grand-est-vates-vms.png)](https://vates.tech/blog/how-drac-grand-est-modernized-its-infrastructure-while-reducing-vendor-lock-in/?ref=xen-orchestra.com) #### Fujifilm MicroChannel We also shared the story of Fujifilm MicroChannel, which migrated from VMware to Vates VMS with a strong focus on predictability and operational continuity. It is a good example of how a well-prepared migration can reduce lock-in and create a more stable foundation for the future. [Fujifilm Microchannel switches from VMware to Vates VMSFujifilm Microchannel migrated from VMware to Vates VMS, simplifying licensing and eliminating vendor lock-in. The transition caused minimal disruption and now delivers stable, scalable performance for both internal and hosted workloads.![](https://xen-orchestra.com/blog/content/images/icon/logo64-42.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/microchannel-migrating-vmware-to-vates-vms.webp)](https://vates.tech/blog/fujifilm-microchannel-what-a-well-planned-migration-can-change/?ref=xen-orchestra.com) --- ## 🎫 Events & webinars The event season is getting busy! In the coming weeks, Vates will be in Lille for **InCyber Forum Europe 2026**, our **webinar series with Exodata** will conclude in April, and the Xen community will gather again in Grenoble for **Xen Spring Meetup 2026**. Different formats, same focus: building better infrastructure through shared experience. ### InCyber 2026 From March 31 to April 2, Vates will be in Lille for InCyber Forum Europe 2026\. Meet us at booth G16 to talk about open virtualization, resilience, and infrastructure control. [Vates at InCyber 2026: meet us in Lille!Vates will be in Lille for InCyber 2026, where Charles-Henri Schulz will speak about digital sovereignty and infrastructure control. Meet us at booth G16.![](https://xen-orchestra.com/blog/content/images/icon/logo64-43.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-at-incyber-2026.webp)](https://vates.tech/blog/vates-at-incyber-2026-meet-us-in-lille/?ref=xen-orchestra.com) ### Xen Spring Meetup 2026 On April 2-3, the Xen community will gather in Grenoble for Xen Spring Meetup 2026\. It is a focused event for technical talks, design discussions, and direct exchanges with the people building and using Xen. [Xen Spring Meetup 2026: meet us in GrenobleJoin us in Grenoble on April 2-3 for the Xen Spring Meetup 2026: two days of technical talks, design sessions, and real community collaboration.![](https://xen-orchestra.com/blog/content/images/icon/logo64-44.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-at-xen-spring-meetup-2026.webp)](https://vates.tech/blog/xen-spring-meetup-2026-see-you-in-grenoble/?ref=xen-orchestra.com) ### Webinar series with Exodata Our webinar series with Exodata will conclude in April with a final session focused on sovereign infrastructure. The March 26 webinar looked at skills, support, and long-term autonomy for technical teams, before the series closes on April 16 with *NextInfra: building your roadmap toward sovereign infrastructure*. Like the rest of the series, the final session will take a practical approach to building a more coherent, resilient, and sovereign infrastructure strategy. 🥖 ****Reminder:** This series of webinars is held in French. [NextInfra - Compétences, support, autonomie : sécuriser dans la durée avec Vates👉 Une infrastructure souveraine n’a de valeur que si vos équipes peuvent la maîtriser dans le temps. Changer de technologie ne suffit pas. Encore faut-il garantir la continuité, la montée en compétences et l’autonomie. Dans ce webinaire, Exodata et Vates détaillent les leviers concrets pour sécuriser votre trajectoire dans la durée : - Comprendre le rôle du Technical Account Manager (TAM) - Identifier les dispositifs de support éditeur et leurs niveaux d’engagement - Structurer les parcours de formation : administration, exploitation, montée en compétences - Éviter la dépendance… y compris vis-à-vis de l’intégrateur - Retour d’expérience Exodata sur la prise en main et le transfert de compétences 🎯 Objectif : sécuriser votre autonomie et votre sérénité à long terme. Un format de 30 minutes. Pensé comme un épisode “sérénité long terme”. Inscrivez-vous juste ici :![](https://xen-orchestra.com/blog/content/images/icon/apple-touch-icon-20.png)StreamYard![](https://xen-orchestra.com/blog/content/images/thumbnail/og_introductory_webinar_1200x630.png)](https://streamyard.com/watch/t8y5trYnjv7a?ref=xen-orchestra.com) ### Past webinar: DataCore, Vates & NeoVAD Vates recently took part to a webinar with DataCore and NeoVAD on validated virtualization. The session looked at how Vates VMS, DataCore’s software-defined storage, and NeoVAD’s expertise can come together in a practical, production-ready approach. The webinar was held in French. [Webinar on March 24: Validated Virtualization with Vates VMSDiscover how Vates VMS and DataCore, integrated by NeoVAD, can help build a validated, modern virtualized infrastructure.![](https://xen-orchestra.com/blog/content/images/icon/logo64-40.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/webinar-datacore-neovad-vates-march-24-1.webp)](https://vates.tech/blog/join-vates-datacore-and-neovad-on-march-24-for-our-webinar-on-validated-virtualization/?ref=xen-orchestra.com) --- With all that happening around the project, let's get into the release itself! # XO 6.3 This release focuses on two things: performance and reliability: with a major UI overhaul for large pools, a rewritten immutable backup engine, and symmetrical replication to simplify disaster recovery. ## 🛡️ Security As a reminder, you can check all our 2026 security announcements across the whole stack in here: [2026 | Vates VMS DocumentationList of all our security advisories in 2026\. Each description provides: Published date / Severity / Affected products![](https://xen-orchestra.com/blog/content/images/icon/vates-logo-128-11.png)Vates VMS Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-logo-128-7.png)](https://docs.vates.tech/category/2026?ref=xen-orchestra.com) ### Axios supply chain attack We are **NOT AFFECTED** by this supply chain attack. But if you are interested to read more about it, the story is interesting: [https://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.html](https://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.html?ref=xen-orchestra.com) ## 💾 Backup For XO 6.3, we've worked on many aspects of backup management: from performance boosts to compatibility, and interface tweaks so that you can catch relevant information with no effort. ### Symmetrical replication With XO 6.3, we’re introducing symmetrical replication, which is an evolution of incremental replication. Previously, incremental replication created a new VM for every job execution. Now, we reuse the same target VM, with the same UUID, whenever possible. This change makes monitoring much simpler and ensures the source and target remain symmetrical. Also, this improvement will help **prepare the ground for reversing replication flows**. Reversing replication flows will make it easier to fall back after a disaster recovery scenario. 💡 ****Note:** This change won’t affect full replication, which will continue to operate as before. ### Optimized immutable backups We have completely rewritten the underlying engine for immutable backups (introduced in the XO 5.91 release) to significantly reduce resource consumption. Previously, some users encountered "out of memory" errors when managing a large number of virtual machines or disks. This new architecture replaces the old indexing system with a more efficient approach that uses native filesystem APIs. By batching operations and only locking a VM after all its disks have finished uploading, we have drastically reduced the memory footprint (dividing it by seven in our tests) while making both locking and **unlocking up to 30 times faster**. These technical improvements ensure that immutability remains stable and performant, even for the most demanding environments: ``` // Past performance watchRemote startup: 26 ms Phase A — rebuild index: 560023 ms TIMEOUT Phase B — write backups: 401587 ms Phase B — lock all: 2185 ms OK Phase C — lift all: 771545 ms (0 entries remaining) Memory before watch: 147.5 MB Memory after watch: 337.6 MB Peak RSS: 2081.5 MB Current RSS: 1789.2 MB ``` ``` // XO 6.3 performance watchRemote startup: 72 ms Phase A — rebuild index: 65726 ms OK Phase B — write backups: 18682 ms Phase B — lock all: 373 ms OK Phase C — lift all: 40866 ms (0 entries remaining) Memory before watch: 133.8 MB Memory after watch: 153.1 MB Peak RSS: 322.4 MB Current RSS: 322.4 MB ``` 💡 ****Please share your feedback!** We’re eager to hear how these updates improve your backup performance. Please take a moment to test the changes and let us know what kind of speed boost you’re seeing on your end. [Xen Orchestra 5.91Welcome to our inaugural 2024 release! This update is particularly robust, featuring an array of new additions: it’s one of our largest in terms of new features. A special shout-out to our new users transitioning from VMware; your enthusiasm is greatly propelling the entire Vates ecosystem, including XCP-ng and Xen![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-37.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/plam503711_a_mountain_landscape_in_January_in_the_Chartreuse_mo_07dc2e6e-c1c1-4209-964f-0f45f6c3ccae.jpg)](https://xen-orchestra.com/blog/xen-orchestra-5-91/#immutability-preview) ### CLI tools for backup repositories We’ve introduced new command-line tools to help you manage your backup repositories. With these tools, you can explore and list the contents of your backup storage straight from the terminal (no need to use the web interface). This addition is particularly useful for administrators who need to quickly verify backup sets or troubleshoot storage issues. Here are some examples: ``` $ xo-disk-cli list file:///mnt/backups /xo-vm-backups//vdis// ┌──────────────┬──────────────────────────────────────┬─────────────┬──────────────┬─────────────┬──────────────────────────────────────┐ │ File │ UID │ Size on disk│ Virtual size │ Differencing │ Parent UID │ ├──────────────┼──────────────────────────────────────┼─────────────┼──────────────┼─────────────┼──────────────────────────────────────┤ │ base.vhd │ xxxxxxxx-... │ 1.20 GiB │ 8.00 GiB │ no │ (none) │ │ snapshot.vhd │ yyyyyyyy-... │ 128.00 MiB │ 8.00 GiB │ yes │ ↑ │ └──────────────┴──────────────────────────────────────┴─────────────┴──────────────┴─────────────┴──────────────────────────────────────┘ ``` ``` $ xo-disk-cli transform file:///mnt/backups /xo-vm-backups//vdis//snapshot.vhd raw > disk.img $ xo-disk-cli transform file:///mnt/backups /xo-vm-backups//vdis//snapshot.vhd qcow2 > disk.qcow2 $ xo-disk-cli transform file:///mnt/backups /xo-vm-backups//vdis//snapshot.vhd vhd > disk.vhd ``` [xen-orchestra/@xen-orchestra/disk-cli at master · vatesfr/xen-orchestraThe global orchestration solution to manage and backup XCP-ng and XenServer. - vatesfr/xen-orchestra![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-81.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/6dcf71fd-bad9-4bfa-933f-b466c52d513d-1)](https://github.com/vatesfr/xen-orchestra/tree/master/%40xen-orchestra/disk-cli?ref=xen-orchestra.com) ### Better S3 compatibility We have improved our S3 backup compatibility to better support providers like DigitalOcean. Previously, some platforms handled bulk deletion commands differently, which could lead to issues when cleaning up old backup data. To ensure a consistent experience across all S3-compatible storage, we have updated the removal process to handle object deletions individually and asynchronously when needed. This technical adjustment makes your backup rotations more reliable, regardless of the specific cloud provider you choose to use. ## 🥝 Core UI The Core UI section covers updates shared by both the XO 6 and XO Lite interfaces. This month, we’ve added a small but essential option to the VM creation form: Secure Boot. ### VM Snapshot tab We’ve added a dedicated **Snapshots** tab to the VM management view. This section features a clean, organized table where you can view all snapshots for a specific VM, along with their names, creation dates, and descriptions. In addition to snapshots, you can now monitor active VDI tasks directly from this tab. This update makes it easier to keep an eye on ongoing storage operations without having to switch views. ![](https://xen-orchestra.com/blog/content/images/2026/03/569653027-65d3ced0-e844-4199-a7a4-eb9a40e3f5d4.png) ![](https://xen-orchestra.com/blog/content/images/2026/03/569653297-b3095331-3c0d-4c8f-9280-2672873b04d8.png) The VM Snapshot tab ### Secure Boot support in VM creation Secure Boot is now supported in XO 6 and XO Lite. You can enable or disable Secure Boot directly when creating a VM, with behavior aligned across interfaces. If a template includes a Secure Boot setting, it is now properly handled during deployment. ![](https://xen-orchestra.com/blog/content/images/2026/03/540528982-fcccb4f4-d9e7-4164-8ecb-e20f3f13c7df.png) ![](https://xen-orchestra.com/blog/content/images/2026/03/540529086-57bda73e-83b5-4691-92ed-3a8abc02401e.png) 'Secure boot' options in the VM creation form ### Bug tools download You can now download directly all the logs from your host or your entire pool, directly from the UI! ![](https://xen-orchestra.com/blog/content/images/2026/03/570497322-c06ad0a7-c904-4aaf-8a6e-565fffdcbc0d.png) ## New Stepper component We've added a new `Stepper` component to our web core library to simplify multi-step processes. This UI element breaks down complex tasks into a clear, numbered sequence, which makes the interface easier to follow. ![](https://xen-orchestra.com/blog/content/images/2026/03/559197769-76a54d99-8935-4c29-a970-844b42145d38.png) ![](https://xen-orchestra.com/blog/content/images/2026/03/559198000-68090c46-42e9-4938-ade9-20f83b3a927e.png) The new Stepper component ## 🛰️ XO 6 We've some big features to the XO 6 dashboard this month, including huge performance improvements and new visibility tools that allow you to keep a better check on your infrastructure. ### Major performance boost We have overhauled how the XO 6 interface handles data updates to resolve significant slowdowns. Previously, the system would recalculate every list and count one by one for every single event, which could cause the browser to freeze when connecting to large pools or during heavy activity. By switching to a bulk-processing approach, we’ve drastically reduced the internal workload. For example, in a environment with 500 VMs, the interface now performs a fraction of the operations it used to. This results in a much smoother, more responsive dashboard that stays fluid even when managing thousands of objects. ![](https://xen-orchestra.com/blog/content/images/2026/03/566901860-b2c406e7-03f7-49fb-8dfa-4d852212a229.png) Past performance: 1,456,300 iterations to build the VM store! ![](https://xen-orchestra.com/blog/content/images/2026/03/566902120-975bc9c9-06aa-4b5a-821b-64a5903f54cc.png) XO 6.3 performance: Only 4,700 iterations to build the VM store ### New color for paused VMs We’ve changed the **Paused** status color for your VMs, so that it’s more readable for users who use custom themes or different display settings. ![](https://xen-orchestra.com/blog/content/images/2026/03/558599734-cc418967-59ca-41ba-a8b1-2c8184cf6438.png) ![](https://xen-orchestra.com/blog/content/images/2026/03/558600141-5a3cd2db-7dab-4b3f-b91d-445b017035cf.png) New color for the Paused status This simple change will let you read your VM states easily, regardless of your preferred dashboard styling. ### New server connection loader Starting with XO 6.3, you will see a dedicated “Please wait” page and a loader during your first connection to the server. This addition ensures you aren't left staring at a blank screen while the initial configuration and services are warming up. ![](https://xen-orchestra.com/blog/content/images/2026/03/558789422-ac5f1142-ddda-4585-9994-ac9e6312973d.png) ![](https://xen-orchestra.com/blog/content/images/2026/03/558789627-7f3235bb-c741-4ccb-877c-b9db9e1e50dc.png) The new "Please wait" screen This quality-of-life improvement makes the onboarding experience much clearer. Now, the interface lets you know exactly when the system is ready for you to jump in and start managing your infrastructure. ### VM backup cards We’ve added backup cards to the VM dashboard. These cards show recent backup runs and available archives for each VM. ![](https://xen-orchestra.com/blog/content/images/2026/03/554777623-1811b33d-4971-402f-a31c-0ae5927e4c53.png) ![](https://xen-orchestra.com/blog/content/images/2026/03/554777805-e5dd4609-aed8-4c60-9669-5c7302795411.png) ![](https://xen-orchestra.com/blog/content/images/2026/03/554777960-9f3c2c7b-abb2-4ab4-a915-cca3f1a22938.png) ![](https://xen-orchestra.com/blog/content/images/2026/03/554778102-b9f12683-4c13-4913-b80d-af522e8529a8.png) VM backup cards Instead of jumping between menus, you can now check your restore points and ensure your data is safe right from the main VM view. ### Backup replication card We’ve added a **Replication** card to the VM dashboard. This card shows the replication status of any VM involved in a backup job, with the outcome of your latest synchronization, the exact timestamp and how long the process took. By making this information more visible, we’ve made it easier to confirm your disaster recovery readiness. You can now verify that your replicas are up to date, without having to dig through various backup logs. ![](https://xen-orchestra.com/blog/content/images/2026/03/555908843-86b6da01-4293-4980-941f-0dc19999fc5f.png) ![](https://xen-orchestra.com/blog/content/images/2026/03/555908942-eec20d32-9dfb-4ba7-9c10-5492c81d1eac.png) The new backup replication card ## 📡 REST API Our REST API continues to evolve into a powerful tool for your automation. This month, we’re doubling down on the MCP support we introduced last month (which lets you interact with Xen Orchestra using LLMs) while expanding our Swagger documentation with a special focus on plugin integration. ### Enhanced MCP support 💡 ****Note:** The Model Context Protocol (MCP) allows you to interact with Xen Orchestra by using large-language models. This is an all-new way to use XO features. Instead of clicking through menus, you can now use natural language to pull infrastructure data or execute changes in real-time. Following our recent introduction of the MCP (Model Context Protocol), we have significantly expanded the range of data available to your AI models. With the XO 6.3 release, you can now query for snapshot lists, virtual disks and storage repositories. We also exposed host and VM performance statistics, which were previously tucked away in our client but not yet accessible via MCP. Also, to make the connection more secure and easier to manage, you can now authenticate your MCP server using a dedicated token. ![](https://xen-orchestra.com/blog/content/images/2026/03/557600967-73c24130-371b-4124-8509-61c53e2703dc-1.png) Interact with Xen Orchestra by asking your LLM With these updates, you can get a clear overview of your infrastructure's health and resources through an AI interface, easily and quickly. [MCP meets Xen OrchestraTalk to your infrastructure in plain language, get instant answers, and keep everything on-prem if you want.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-35.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/mcpxo62.webp)](https://xen-orchestra.com/blog/mcp-meets-xen-orchestra/) [Xen Orchestra 6.2XO 6.2 is here! This release brings distributed backups, a visual query builder, new REST API endpoints, a refreshed dashboard, and a new MCP package for AI-driven workflows.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-36.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/matias-tapia-I_9arGH-r8U-unsplash.jpg)](https://xen-orchestra.com/blog/xen-orchestra-6-2/#new-mcp-package) ### New maintenance mode endpoints We’ve introduced new endpoints to manage maintenance mode for your hosts. Accessible directly via our Swagger documentation, these controls allow you to enable or disable maintenance mode programmatically: ![](https://xen-orchestra.com/blog/content/images/2026/03/560804583-923ce01f-440a-428e-9690-e95318ee836f.png) ![](https://xen-orchestra.com/blog/content/images/2026/03/560804660-7c2aa807-79fa-4c50-9272-fe19087abdb6.png) Maintenance mode endpoints in Swagger ### New endpoints We've added new endpoints (including their Swagger documentation). The new endpoints include: - Storage: `POST /rest/v0/srs/:id/actions/forget` - VMs: `POST /rest/v0/vms/:id/actions/clone` - Networking: `POST /rest/v0/pools/:id/actions/create_bonded_network` and `POST /rest/v0/pools/:id/actions/create_internal_network` This update continues our effort to bring full feature parity to the API. ### ACLv2 in preview We are working on a brand new access control model for Xen Orchestra. ACLv2 is a complete rethink of how permissions are handled, designed from the ground up to offer much finer-grained control over who can do what on your infrastructure. It will be available via the API first, so developers and advanced users can start exploring and providing feedback early. A dedicated forum thread with instructions will be shared next week: stay tuned! [WiP: ACL V2ACL V2 is coming soon! Feel free to follow this topic to know when it becomes available on the master branch. I will add usage examples and more details abou…![](https://xen-orchestra.com/blog/content/images/icon/512-19.png)XCP-ngMathieuRA![](https://xen-orchestra.com/blog/content/images/thumbnail/70369997)](https://xcp-ng.org/forum/topic/12036/wip-acl-v2?ref=xen-orchestra.com) ## ☸️ DevOps Tools We know how much you rely on automation to keep things running, so this month we’ve also focused on sharpening our tools for your deployment pipelines. ### Packer plugin for XCP-ng We’ve released version 0.11.4 of our Packer plugin for XCP-ng. This update introduces several new features and brings all underlying dependencies up to date. With the strength of an integration supported by Vates, built in the open and welcoming community contributions, we keep providing a reliable, up-to-date toolset for automated infrastructure deployment on XCP-ng. [Releases · vatesfr/packer-plugin-xenserverA builder plugin for Packer.IO to support building XCP-ng images. - vatesfr/packer-plugin-xenserver![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-65.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/69fc8c7f-7c39-44e8-8316-e7a6a86e0f4f)](https://github.com/vatesfr/packer-plugin-xenserver/releases?ref=xen-orchestra.com) ### Cloud Controller Manager v1.0.0 First stable release 🥳 💡 The XO CCM bridges your Kubernetes cluster and XO infrastructure: it maps VMs to their corresponding Kubernetes nodes and automatically labels them based on the underlying topology: pool, host, and more.The XO CCM bridges your Kubernetes cluster and XO infrastructure: it maps VMs to their corresponding Kubernetes nodes and automatically labels them based on the underlying topology, pool, host, and more. [Release v1.0.0 · vatesfr/xenorchestra-cloud-controller-managerFull Changelog: v0.9.0...v1.0.0 What’s Changed build: bump chart version - Use node DNS in the CCM pod by @nathanael-h in #39 Feat add host pool name label by @gCyrille in #40 build(deps): bump gi…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-68.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v1.0.0)](https://github.com/vatesfr/xenorchestra-cloud-controller-manager/releases/tag/v1.0.0?ref=xen-orchestra.com) Several improvements and fixes on the deployment and Helm Charts: deployment with daemon set, pool and host “name label” added in the node labels, cleaner chart roles and permissions, etc. ### Cloud Storage Interface (CSI) driver v0.1.0 Since the first communication on the CSI driver in last November, there have been a lot of improvements to this 'on development' driver. For the moment, it only offers 'static volume provisioning' (i.e. use an existing VDI by UUID), but deployment is made easier thanks to several fixes and improvements. 💡 A Container Storage Interface (CSI) driver that provides persistent storage for Kubernetes workloads using XenServer/XCP-ng infrastructure through Xen Orchestra.A Container Storage Interface (CSI) driver that provides persistent storage for Kubernetes workloads using XenServer/XCP-ng infrastructure through Xen Orchestra. [Release v0.1.0 · vatesfr/xenorchestra-csi-driverWhat’s Changed Fix wrong docker image name Add feature to load the config/credentials from env Add documentation Replace jRPC calls (v1 SDK) with calls to the REST API (v2 SDK) Remove dependencies…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-67.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v0.1.0)](https://github.com/vatesfr/xenorchestra-csi-driver/releases/tag/v0.1.0?ref=xen-orchestra.com) It is recommended to install the Xen Orchestra CCM in addition to the CSI driver. ### Golang SDK update v1.14.0 The v2 SDK has received a new implementation of endpoints: we can now use it to retrieve and manipulate VDBs. It can also be used to retrieve and connect/disconnect PBDs. [Release v1.14.0 · vatesfr/xenorchestra-go-sdk1.14.0 (2026-03-26) Features v2/pbd: add PBD service, including operations and integration tests (cf88cc0)![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-66.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v1.14.0)](https://github.com/vatesfr/xenorchestra-go-sdk/releases/tag/v1.14.0?ref=xen-orchestra.com) ## 🐦 VMware to Vates (V2V) It shouldn't be a headache to migrate your infrastructure, which is why we're always improving our V2V tools to make the move as simple as possible. With XO 6.3, we're rolling out smarter defaults and better disk handling. This way, switching to the Vates ecosystem gets more efficient and predictable. ### Choose QCOW2 during SR creation When creating a new Storage Repository, you can now choose in what order image formats will be used, depending on availabilty on the host. A new option lets you choose between **QCOW2** and **VHD** right from the start. Setting this at the creation stage ensures that all future virtual disks on that SR follow your chosen standard automatically. This helps you optimize storage performance or specific features for your needs. ![](https://xen-orchestra.com/blog/content/images/2026/03/569615101-bae014bc-dc19-4b96-9fdc-93ca1dae9394.png) 'Preferred image format' option during SR creation 💡 ****Notes:** • Keep in mind that for any disks under 2TB, the system will still default to VHD. • If the field is left blank, the default XCP-ng values will be used. ## 📖 Documentation & Guides We’ve refreshed our docs to clear up some of the more technical changes from our recent updates. Our goal is to make your configuration process as straightforward as possible so you can keep your infrastructure running smoothly. ### Migration cooldown Following the addition of a migration cooldown with Xen Orchestra 6.2, we've added a dedicated section to the **Load Balancer** documentation. As a reminder, the migration cooldown prevents the same virtual machine from being migrated twice in quick succession by the load balancer. ![](https://xen-orchestra.com/blog/content/images/2026/03/Capture-d---cran-2026-03-27-081127.png) Preview of the migration cooldown documentation [Load balancing | Xen Orchestra | XO DocumentationBasic notions![](https://xen-orchestra.com/blog/content/images/icon/favicon-45.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-28.png)](https://docs.xen-orchestra.com/load%5Fbalancing?ref=xen-orchestra.com#migration-cooldown) [Xen Orchestra 6.2XO 6.2 is here! This release brings distributed backups, a visual query builder, new REST API endpoints, a refreshed dashboard, and a new MCP package for AI-driven workflows.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-38.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/matias-tapia-I_9arGH-r8U-unsplash-1.jpg)](https://xen-orchestra.com/blog/xen-orchestra-6-2/) ### OpenSSL 3 certificates With OpenSSL 3 arriving in XCP-ng 8.3, some certificates generated by the SDN Controller plugin in Xen Orchestra will soon become incompatible. To avoid any issues, these certificates will need to be regenerated. We’ve updated our documentation to more clearly define which setups are affected, so there should be no more confusion. If your environment meets these criteria, we recommend regenerating your certificates before the March 2026 update to ensure your connectivity stays as it should. ![](https://xen-orchestra.com/blog/content/images/2026/03/Capture-d---cran-2026-03-27-081948.png) Preview of the updated requirements for regenerating OpenSSL 3 certificates [SDN Controller | Xen Orchestra | XO DocumentationBe sure to enable the plugin on only one XOA instance.![](https://xen-orchestra.com/blog/content/images/icon/favicon-46.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-29.png)](https://docs.xen-orchestra.com/sdn%5Fcontroller?ref=xen-orchestra.com#openssl-3--sdn-upgrade-path) ## 🌐 Translations Xen Orchestra is a global project, and it's always inspiring to see our community help make it accessible to everyone. Thanks to your ongoing contributions, we’ve just rolled out updates for many different languages, so the interface stays current for users all over the world. ### 16 languages updated A big thank you to our community for their ongoing efforts in translating Xen Orchestra! This month, 15 languages were updated: **Czech, Brazilian portuguese, Chinese (simplified), Danish, Dutch, English, French, Italian, German, Norwegian (Bokmål) Persian, Portuguese, Russian, Slovak, Spanish, and Swedish.** ![](https://xen-orchestra.com/blog/content/images/2026/03/687474703a2f2f7472616e736c6174652e76617465732e746563682f7769646765742f78656e2d6f72636865737472612f6d756c74692d6175746f2e737667-1.svg) Current XO translation status Want to help translate Xen Orchestra or improve existing translations? You’re more than welcome to join in [here](https://translate.vates.tech/?ref=xen-orchestra.com). ### General wording refinements A big thank you to our community for helping us polish the English localization in Xen Orchestra! This month’s release includes several fixes from user DustyArmstrong, which clean up technical labels, typos and other minor English mistakes. These changes ensure that the wording remains consistent across the entire portal, for a more predictable and intuitive experience. [DustyArmstrong - OverviewDustyArmstrong has 20 repositories available. Follow their code on GitHub.![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-89.svg)GitHub![](https://xen-orchestra.com/blog/content/images/thumbnail/13500305)](https://github.com/DustyArmstrong?ref=xen-orchestra.com) ## 🆕 Misc Behind every major feature are the smaller refinements thatmake a difference in your daily operations. This month, we’re giving you deeper visibility into your infrastructure by expanding the data available for your external monitoring tools. ### More data and documentation for OpenMetrics We’ve updated our OpenMetrics plugin to include several RRD (round-robin database) metrics that were previously missing. This gives you a clearer picture of your infrastructure’s performance when using external tools, like Prometheus or Grafana. You’ll now find **VM disk throughput** (read, write, and total), along with **average disk latency**. For supported hardware, we’ve also added **DCMI power readings**, so you can monitor the actual wattage your physical hosts are pulling. Also, we've updated the documentation for all the metrics exposed by Xen Orchestra through the OpenMetrics endpoint. By providing descriptions for each data point, you can build more accurate dashboards without jumping back into Xen Orchestra to check the details, and set up more effective alerts. ### MCP meets Xen Orchestra URL: https://xen-orchestra.com/blog/mcp-meets-xen-orchestra/ Last updated: 2026-08-12T13:06:09.000Z With XO 6.2, we shipped something we've been excited about for a while: native support for the **Model Context Protocol (MCP)**. Not a third-party plugin, not a community experiment: `@xen-orchestra/mcp` is a **first-party module** maintained by the Vates team as part of the Xen Orchestra codebase. It's a small package, but it opens up a fundamentally new way of interacting with your virtualization stack: instead of clicking through dashboards or writing API calls, you can now **ask questions in plain English** (or French, or any language your AI assistant understands) and get instant, accurate answers drawn directly from your live infrastructure. And if you want to go further (like running the AI model itself on your own GPUs, inside your own VMs, with zero external dependency) you can do that too. We'll get to that! Let's walk through what this looks like in practice. ## 🔌 A 30-second recap: what is MCP? MCP is an open standard, originally introduced by Anthropic and now governed by the Linux Foundation's Agentic AI Foundation. Think of it as a **universal adapter between AI assistants and external systems**. It's supported by Claude, ChatGPT, Gemini, and many others — so you're not locked into any single vendor. When you install the `@xen-orchestra/mcp` package and point it at your XO instance, your AI assistant gains the ability to query your pools, hosts, VMs, and documentation: all through a structured, secure interface. Because this is an official Xen Orchestra module, it follows our REST API directly, benefits from the same release cycle, and is covered by Vates support contracts. You're not depending on a third-party integration that might break on the next update. One important design choice: **everything is read-only**. The MCP server can look at your infrastructure, but it can't modify anything. You get the benefits of AI-assisted workflows without ever worrying about a chatbot accidentally shutting down your production VMs. ## ⚡ Getting started in 2 minutes ```bash npm install -g @xen-orchestra/mcp ``` Then add the MCP server to your AI client (Claude Desktop, Claude Code, etc.) with your XO credentials. That's it. Full setup instructions are in [our documentation](https://docs.xen-orchestra.com/mcp?ref=xen-orchestra.com). Now, let's look at the use cases that make this genuinely useful. ## 💡 What can you actually do with it? The best way to understand MCP is to see it in action. Below are real scenarios where talking to your infrastructure replaces clicking, scripting, or context-switching. None of them require writing code, just a question in plain language. ### The Monday morning infrastructure check It's 8:30 AM. Coffee in hand. Instead of opening three tabs and clicking through your pool dashboard, you type: > "Give me a full overview of my infrastructure. Are there any VMs that are down that shouldn't be?" The assistant calls `get_infrastructure_summary`, fetches pool details, host counts, and VM states. Within seconds, you get back something like: *"You have 2 pools with 8 hosts total. 142 VMs are running, 12 are halted. The halted VMs include `webfront-03`, `monitoring-secondary`, and `db-staging-replica` — these were running last Friday."* You didn't open a single dashboard. You didn't write a single query. You just asked. ![](https://docs.xen-orchestra.com/img/xo5/mcp-infra.gif) ### Quick triage during an incident Your monitoring fires an alert: `app-server-12` is behaving strangely. You need details, fast. Instead of navigating to the VM detail page, you type: > "What's the current state of app-server-12? What host is it running on, how much memory is allocated, and when was the last snapshot?" The assistant calls `list_vms` with a name filter, then `get_vm_details` on the result. In one conversational exchange, you get the VM's power state, resource allocation, host placement, tags, and snapshot history. During an incident, **seconds matter**. This is faster than any GUI could ever be. ### Capacity planning conversations You're in a meeting and someone asks: "Do we have room to deploy 20 more VMs on the production pool?" You don't need to leave the conversation. You pull up your assistant and ask: > "Show me the dashboard for the production pool. What's the current CPU and memory utilization across hosts?" The assistant calls `get_pool_dashboard`, which returns an aggregated view including host status, top resource consumers, and active alarms. You can follow up with: > "Which hosts have the most available memory right now?" And you get a sorted answer, in natural language, that you can share with your team on the spot. No spreadsheets, no CLI — just a conversation. ### Onboarding a new team member A new sysadmin joins your team. Instead of bookmarking 15 doc pages, you tell them: > "Just ask the assistant. It knows how to search the XO documentation too." They can type things like: > "How do I configure incremental backups in XO?" > "What's the difference between disaster recovery and continuous replication?" > "How do I set up the SDN controller?" The `search_documentation` tool lets the assistant pull relevant sections of XO docs by topic: backups, REST API, installation, users, troubleshooting, and more. It turns the AI assistant into a **context-aware onboarding companion** that already knows your stack. ![](https://docs.xen-orchestra.com/img/xo5/mcp-doc.gif) ### The executive summary you never have time to write Your manager wants a weekly infrastructure summary for the ops review. Instead of manually compiling it, you ask: > "Give me a summary of our infrastructure I can paste into our weekly ops report. Include pool names, total hosts, running vs. halted VMs, and flag anything unusual." The assistant calls `get_infrastructure_summary` and `get_pool_dashboard` for each pool, then composes a structured report. You copy, paste, and you just saved 20 minutes every week. Better yet: if your AI assistant is connected to other MCP servers (Slack, Matrix, or any messaging platform), you can skip the copy-paste entirely: > "Send this summary to the #ops-weekly channel on Slack." One prompt, zero context-switching. The infrastructure report goes from your XO instance to your team's chat without you touching a clipboard. ### Cross-referencing VMs with naming conventions Large environments often rely on naming conventions to identify workload types, environments, or owners. Now you can query them semantically: > "List all VMs with 'staging' in their name. How many are running vs. stopped?" > "Show me all VMs that start with 'k8s-worker'. Which pool are they in?" > "Do I have any VMs with 'test' in the name that have been running for more than a week?" The `list_vms` tool supports filter expressions and wildcards like `name_label:staging*`, and the assistant can combine multiple calls to build a richer picture. This turns naming conventions into a **queryable inventory system**. ### Pre-migration sanity checks Before migrating VMs between hosts or pools, you want to validate the target environment. Ask: > "What's the status of all hosts in pool 'datacenter-west'? Any hosts in maintenance mode? What's the memory pressure like?" The assistant uses `list_hosts` with pool filtering and `get_pool_dashboard` to give you a clear picture before you commit to the migration. You can follow up naturally: > "Which host in that pool has the lightest workload right now?" This kind of pre-flight check used to require multiple CLI commands or dashboard views. Now it's a two-sentence conversation. ### Audit and compliance quick checks When audit season comes around, or when you simply want a quick compliance check: > "How many VMs are running across all pools? Do any hosts have HA disabled?" > "List all pools and tell me which ones have auto power-on enabled." The assistant queries `list_pools` with the right fields and gives you a formatted answer. You're not building reports — you're asking questions and getting answers. ## 🏠 Your own AI, on your own infrastructure Everything above assumes you're using an external AI assistant — Claude Desktop, ChatGPT, or similar. But here's where it gets really interesting: **you can run the AI itself on XCP-ng too**. We published a detailed tutorial last year on [running GPU-powered LLMs with XCP-ng](https://xcp-ng.org/blog/2025/07/28/your-own-gpu-powered-llms-with-xcp-ng/?ref=xen-orchestra.com). The short version: thanks to PCI passthrough, you can assign a physical GPU directly to a VM and get near bare-metal performance for AI inference. Install Ollama, pull a model, and you have a fully private LLM running inside your virtualization stack. The open-source model ecosystem is thriving. You can run any of these locally, depending on your hardware: - **DeepSeek R1** — strong reasoning capabilities, available in multiple sizes - **Llama 3** (Meta) — one of the most versatile open model families - **Mistral** and **Mixtral** (Mistral AI) — excellent performance-to-size ratio, especially for European teams - **Qwen 3.5** (Alibaba) — competitive multilingual performance - **Gemma 2** (Google) — lightweight and efficient - **Phi-4** (Microsoft) — surprisingly capable for its size - **Command R+** (Cohere) — strong at RAG and tool use Pair any of these with Open WebUI for a polished chat interface, and you have a private AI assistant that rivals cloud offerings — running entirely on hardware you control. ### Why VM isolation matters for AI agents This is more than a convenience play. As AI agents become more capable: reading data, calling tools, making decisions… The question of **where your data goes** becomes critical. When you use a cloud-hosted AI with MCP, your infrastructure metadata flows through a third-party service. For many teams, that's fine. But for regulated industries, sovereign infrastructure requirements, or simply organizations that take data control seriously, it's a non-starter. Running your LLM inside a VM on XCP-ng gives you something unique: **hardware-level context isolation**. The Xen hypervisor enforces strict boundaries between VMs. Your AI agent runs in one VM, your production workloads run in others, and the hypervisor ensures they can never cross-contaminate. There's no shared kernel, no container escape risk — just clean, hardware-enforced separation. This turns your virtualization stack into a **sealed AI execution environment**: - Your model weights stay on your hardware - Your infrastructure queries never leave your network - Your prompts and responses are never sent to any external API - The VM boundary acts as a hard context seal — your AI agent can only see what you explicitly expose through MCP In the era of AI agents that can chain tool calls, browse documentation, and summarize entire infrastructures, this kind of isolation isn't paranoia at all. ### The full control loop Put it all together and you get a remarkably self-contained setup: 1. **XCP-ng** hosts your entire virtualization infrastructure 2. **A GPU-equipped VM** runs your open-source LLM via Ollama 3. **The XO MCP server** connects that LLM to your Xen Orchestra instance 4. You ask questions in natural language, and **everything stays on-prem** Your AI talks to your infrastructure manager, which manages your hypervisor, which hosts your AI. It's a closed loop: no cloud dependency, no data exfiltration risk, full sovereignty. For organizations that are building private clouds, running air-gapped environments, or simply want to keep their infrastructure metadata out of third-party hands, this is exactly the kind of stack that makes it possible to adopt AI **without compromise**. ## 🔒 Safe by design It's worth reiterating: the XO MCP server is **read-only**. It can list, query, and summarize — but it cannot start, stop, migrate, or delete anything. This was a deliberate choice. We want this to be a tool you feel comfortable enabling on production environments from day one. Your AI assistant can look at your infrastructure all it wants. It just can't touch it. ## 🔭 What's next This is just the beginning. The current set of tools covers the most common read operations: pools, hosts, VMs, dashboards, documentation. But the architecture is modular. As the REST API grows (and it keeps growing, as you saw in XO 6.2 with new endpoints for migrations, VDIs, and VIF rules), the MCP surface area will grow with it. We're also watching the MCP ecosystem closely. Now that the protocol is governed by the Linux Foundation and supported by every major AI provider, the tooling around it is maturing fast. The possibilities for infrastructure automation, multi-system orchestration, and AI-assisted operations are only expanding. ## 🚀 Try it now If you're running XO 6.2, you can set this up in minutes: 1. `npm install -g @xen-orchestra/mcp` 2. Configure it with your XO credentials 3. Add it to OpenWebUI, Claude Desktop, Claude Code, or any MCP-compatible client (Cursor, Cline, Gemini CLI, ChatMCP…) Full instructions: [docs.xen-orchestra.com/mcp](https://docs.xen-orchestra.com/mcp?ref=xen-orchestra.com) Talk to your infrastructure. It's ready to answer! ### Xen Orchestra 6.2 URL: https://xen-orchestra.com/blog/xen-orchestra-6-2/ Last updated: 2026-02-27T12:15:00.000Z February is already shaping up to be a busy month! XO 6.2 continues to build on the momentum of the new major version, bringing meaningful improvements across backup infrastructure, the core UI, and the REST API, alongside a refreshed dashboard and new DevOps tooling. As always, community feedback has played a direct role in shaping what landed in this release. We also celebrated ten consecutive years at FOSDEM 🎉, a milestone that reflects just how far this project has come and how big the Open-Source ecosystem has become. And the momentum continues: CloudFest and InCyber are just around the corner, and our new webinar series with Exodata is already underway for French-speaking infrastructure teams. 🎵 The podcast version of our release video [is here](https://open.spotify.com/episode/1lsQpEs4QWYFd3DMcdPwQM?si=L-ukVFwEQimITG-lavDwZg&ref=xen-orchestra.com) ! ## 👨‍🚀 Project & Community Beyond the solution itself, 2026 is off to a strong start on the community and ecosystem front: a redesigned homepage, an updated getting-started guide, a new migration guide for VMware and Hyper-V users, and the launch of our updated Partner Program. We are doing everything in our power to welcome newcomers in the smoothest way possible. ### New Partner Program In 2026, the Vates Partner Program focuses on active engagement, measurable impact, and long-term success. With 2025’s strong results and the addition of Distributors, we are building a collaborative, high-performing ecosystem that rewards partner contribution. [Vates 2026 Partner Program: Rewarding Commitment2025 at a Glance We would like to begin by thanking our entire partner network, MSPs, Resellers, CSPs, and Distributors. Your continued efforts play a vital role in our journey and drive us to keep moving forward as we build what comes next. We are very pleased with the continued![](https://xen-orchestra.com/blog/content/images/icon/logo64-35.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-partner-program-updated-2026.webp)](https://vates.tech/blog/vates-2026-partner-program-rewarding-commitment/?ref=xen-orchestra.com) ### New migration guide: VMware & Hyper‑V to Vates VMS Migrating from VMware or Hyper‑V to **Vates VMS** is a structured, low-risk program focused on phased execution, pilot testing, and rollback planning. Using **XCP‑ng** and **Xen Orchestra**, teams can move workloads safely while ensuring reliable operations, compliance, and long-term stability. [Vates Migration Guide : VMware/Hyper‑V to VMSMoving away from VMware or Hyper-V? Learn how to migrate to Vates VMS smoothly, cut costs, and regain control of your virtualization stack.![](https://xen-orchestra.com/blog/content/images/icon/logo64-36.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/vmware-to-vates-guide-1.webp)](https://vates.tech/blog/migrating-from-vmware-or-hyper-v-to-vates-vms/?ref=xen-orchestra.com) ### Getting started guide updated This updated guide walks users through setting up the Vates virtualization stack, from **XCP‑ng** installation to **Xen Orchestra** deployment, VM creation, backups, and monitoring. It covers practical steps, trial setup, and support options for safe, efficient operations. [Vates VMS Quick‑Start: Install XCP‑ng, Deploy XO & First VMNew to Vates VMS? Get up and running quickly with this practical guide to deploying and managing your virtualization stack.![](https://xen-orchestra.com/blog/content/images/icon/logo64-37.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/getting-started-with-vates-vms.png)](https://vates.tech/blog/getting-started-with-vates-vms/?ref=xen-orchestra.com) ### Vates homepage redesign The Vates homepage has been redesigned with one clear goal: making it easier for anyone discovering our solutions for the first time to find their footing. Whether you're evaluating alternatives, comparing virtualization stacks, or ready to take your first steps, the new layout guides you naturally through your journey, from learning about our solutions, to understanding how they compare, to trying them out for yourself. For returning visitors, key resources and partner ecosystem information remain front and center, now with a cleaner visual hierarchy and faster access to the content that matters most. ![](https://xen-orchestra.com/blog/content/images/2026/02/Capture-d---cran-2026-02-26-102523.png) [To Vates website](https://vates.tech/en/?ref=xen-orchestra.com) ### Windows standard VGA display driver We are releasing a new open-source Windows display driver for XCP-ng: `win-xstdvga`. This driver enables high-resolution consoles and dynamic resolution switching for Windows UEFI VMs using the standard VGA emulation (`std`), which is the default on XCP-ng VMs. This is an early release, currently available in beta, and already usable on your Windows VMs. Installation is straightforward: simply point `pnputil.exe` at the INF file, or right-click and install directly. The driver and its source code are [available on GitHub](https://github.com/xcp-ng/win-xstdvga?ref=xen-orchestra.com). You can check the [releases here](https://github.com/xcp-ng/win-xstdvga/releases?ref=xen-orchestra.com). ## 🎫 Events The busy event season continues! In the coming weeks, we will be attending two major European events: CloudFest in March (Germany) and InCyber in April (France). Meanwhile, we are kicking off a webinar series with Exodata, offering practical guidance for CIOs on migration, hypervisor choices, and long-term IT management. For now, the sessions are held in French only, but English content is on its way! ### FOSDEM 2026 Recap 🎂 This year marked Vates’ 10th consecutive FOSDEM! This year, we showcased XCP‑ng 9 on AlmaLinux 10, an Android VM, low-end SBCs, Xen + Zephyr on Raspberry Pi, and an open-source FPGA USB 3.0 analyzer. Discussions covered scaling, ARM/RISC‑V adoption, AI in open source, and KVM differentiation. The event reinforced collaborations and provided feedback shaping our 2026 roadmap. [FOSDEM 2026: Thank you for ten years of conversationsExplore XCP‑ng’s FOSDEM 2026 highlights: Android VM, ARM/RISC‑V demos, 8 000‑VM scaling talk, governance, and next‑step community links.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-39.png)XCP-ng BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/fosdem-2026-follow-up-1.png)](https://xcp-ng.org/blog/2026/02/19/fosdem-2026-follow-up/?ref=xen-orchestra.com) ### Cloudfest 2026 At CloudFest, from March 23 to 26, Vates will discuss practical VMware migration strategies, predictable costs and a production-ready open source virtualization stack. [CloudFest 2026: preparing VMware migrationAt CloudFest, Vates will discuss practical VMware migration strategies, predictable costs and a production-ready open source virtualization stack.![](https://xen-orchestra.com/blog/content/images/icon/logo64-38.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-at-cloudfest-2026.webp)](https://vates.tech/blog/cloudfest-2026-come-meet-us/?ref=xen-orchestra.com) ### Webinar series with Exodata Vates and Exodata are running a practical webinar series for CIOs and infrastructure leaders, offering actionable guidance on migration, hypervisor choices, and long-term infrastructure management. The first session, on February 26, 2026, covered seamless V2V migration, with upcoming episodes exploring hypervisor decisions, skills and support, and building a path toward sovereign infrastructure. 🇫🇷 This series of webinars are held in French. [Migrer sans rupture : réussir une migration V2V maîtrisée👉 Comment migrer vos charges existantes sans risque pour la production ? Migrer vos VM sans interruption critique ni stress inutile, c’est possible. Dans ce webinaire, Exodata et Vates partagent une méthode terrain pour réussir une migration V2V maîtrisée : - Comprendre ce qu’est vraiment une migration V2V - Éviter les erreurs classiques qui provoquent incidents et retours arrière - Profiter d’un retour d’expérience Exodata et Vates basé sur des migrations réelles. 🎯 Objectif : réduire la charge mentale des DSI. Un format de 30 minutes, pensé comme un véritable anti-stress.![](https://xen-orchestra.com/blog/content/images/icon/apple-touch-icon-19.png)StreamYard![](https://xen-orchestra.com/blog/content/images/thumbnail/cloudStorageItem_3awjvlihQtHkYCIQ.png)](https://streamyard.com/watch/ZHjryzYhmpwz?ref=xen-orchestra.com) ### InCyber 2026 Vates will be attending InCyber Forum 2026, held from March 31 to April 2, at the Grand Palais in Lille. You’ll find us at booth G16, where we’ll showcase our secure Xen‑based virtualization solutions and connect with cybersecurity professionals from across Europe. [INCYBER Forum Europe - MARCH APRIL 31-2, 2026INCYBER Forum Europe - The leading international event on cybersecurity and digital trust in Lille. Conferences, exhibitors, networking![](https://xen-orchestra.com/blog/content/images/icon/FAVICON_128px-1.png)FORUM INCYBER - EUROPE![](https://xen-orchestra.com/blog/content/images/thumbnail/INCYBER-FORUM_LILLE_EUROPE-1.webp)](https://europe.forum-incyber.com/en/home-en/?ref=xen-orchestra.com) --- # XO 6.2 Get ready for XO 6.2! It's packed with new updates to make your workflows easier to deal with, and answer your much-appreciated feedback. ## 💾 Backup After last month’s long-term retention (LTR) updates, we’re moving our attention to distributed backups and replication. These upgrades will make your workflows simpler and make better use of your storage capacity. ### Distributed backups and replications For a more flexible way to manage storage growth, we’re introducing **distributed backups** and **distributed replication**. Instead of attaching a job (backup or replication) to a single repository and reconfiguring everything when it the repository fills up, you can now group multiple targets into one logical pool. As your storage needs grow, you simply add new repositories. Xen Orchestra automatically starts using the available space for new backup chains, without requiring job edits or tedious data migrations. The system spreads data intelligently across the pool. It prioritizes available capacity, while keeping incremental chains consistent. 💡 ****Notes:** ****\-** It’s designed as a capacity and load management feature, not a redundancy mechanism. A distributed job still counts as a single copy in your backup strategy. \- This feature is available on an ****opt-in** basis. In case a repository fails, only the backups stored on that device are affected. The rest of the pool remains fully operational, and restores work as usual from the storage that holds the data. Overall, this approach makes backup infrastructure easier to scale and better suited to real-world growth, especially when long-term storage forecasting is hard to predict. ![](https://xen-orchestra.com/blog/content/images/2026/02/548247782-d93bed2a-651f-4459-bc9e-7e04e2596bce-1.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/548247917-fc600085-ec8c-440b-831d-8dab68d5e31a-1.png) Distributed backup and replication forms ## 🥝 Core UI This month, we’re enhancing XO 6 and XO Lite with a brand-new feature: the visual query builder. This tool is designed to simplify complex queries, so you can easily filter and manage your infrastructure components. Read on for more details! ### Visual query builder We're introducing a visual query builder. It’s designed to make creating, editing, and reusing complex searches more intuitive. Instead of typing filters manually, you can now build them visually with nested conditions, AND/OR operators, and different field types. Under the hood, this builder relies on our existing Complex Matcher engine. If you ever need something more advanced than what the visual builder can represent, you can still enter a raw Complex Matcher expression, directly in the search field. You get the best of both worlds: ease of use when you want it, and full power when you need it. ![](https://xen-orchestra.com/blog/content/images/2026/02/552661309-ac7fd1ce-2411-4ad0-a4c2-cb5c8678a51c.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/552661573-890cc525-17b2-464d-8690-93eceffd6afd.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/552661877-4c7cef56-312e-4886-b02d-8de0b92b47dd.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/552662244-6f14ffe0-7f15-46bb-9d00-d4c360ab45a6.png) The new visual query builder ## ## 🛰️ XO 6 We’re continuing to refine Xen Orchestra 6, with updates that put even more power in your hands. This release introduces new actions and a clearer interface, so you can manage your infrastructure with greater precision and ease. Explore what’s new below. ### Quick actions in treeview You can now access common actions directly from the treeview. Based on the community's suggestions, we’ve added a quick actions menu available from the three-dot icon next to each object. It gives you fast access to the most common operations for VMs and other resources, without having to open their dedicated view first. This small change in the user interface helps make everyday management tasks quicker and more user-friendly, especially if you have to manage several resources. ![](https://xen-orchestra.com/blog/content/images/2026/02/image-1.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/image2-1.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/image3-1.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/image4-1.png) Actions available from the quick-access menu ### ### Clearer connection status XO 6 now alerts you when the web interface loses connection to xo-server. Instead of leaving you guessing whether something is loading slowly or completely unreachable, the UI explicitly shows when it cannot reach the backend. This makes connectivity issues immediately visible, for easier troubleshooting and less confusion. ![](https://xen-orchestra.com/blog/content/images/2026/02/552750693-c7e4323e-e5f9-4219-9cd6-2f02d3446e5f.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/552750847-8009c499-5b01-4601-8890-950249abd5b7.png) Banners showing ongoing connectivity issues ### More VM actions XO 6 now lets you **take snapshots** and **permanently delete VMs**. Just open the **More actions** menu and you will find the **Snapshot** and **Delete** buttons. You will be able to take a snapshot of the selected VM, or delete the VM and all its data. No need to use any other tool or interface! This completes the VM lifecycle management in XO 6\. You now have full control, from creation to permanent removal. ![](https://xen-orchestra.com/blog/content/images/2026/02/541696945-8e395bfd-ec59-4ce9-a7a6-bf566363bcf0.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/541697094-0792d4d2-e0a7-480b-980e-17fbc3d43ace.png) The new Delete button in XO 6 ### SSH key setup during VM creation The VM creation form in XO 6 now includes the option to set up the SSH key. Before, deploying a VM from a cloud-init template could leave you with a running VM, but no way to define SSH keys or custom settings from the interface. This often meant losing immediate access to your new VM. Now, you can add SSH keys and customize configuration directly during creation. This makes cloud-init deployments fully functional in XO 6. ![](https://xen-orchestra.com/blog/content/images/2026/02/545672409-c639d5c5-64dc-40ad-ae08-69abe4afa40e.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/545672582-0c0c24dd-059b-4018-8ab3-98b2a54fc728.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/545672830-694312f4-e9ae-4967-96e3-5b2f9f8b6ad6.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/545673038-fd307553-ec2c-4c58-aff3-e7515092845c.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/545673691-dfe1fe16-8a0f-4b98-91cd-c04825cc836a.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/545673962-366db114-2453-42ca-ba03-be493f338c5a.png) SSH key setup during VM creation + SSH info in side panel ## Custom user config in VM creation You can now define custom `user-config` values directly from the new VM creation form. This makes it possible to pass advanced configuration parameters at deployment time, which is particularly useful with cloud-init templates or more complex provisioning scenarios. Instead of adjusting the VM after creation, you can inject the required settings right away. It gives you more flexibility and tighter control over how new VMs are initialized. ![](https://xen-orchestra.com/blog/content/images/2026/02/540994088-371b44e3-ba43-4c13-8ef9-66a2d1a2a7d2.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/540994142-d7984c04-52cd-4f14-99a7-6f2d4073878f.png) Custom user config field in the VM creation form ### Refreshed Dashboard We’ve redesigned the dashboard to align with the modern look and feel of the interface. The page is now easier to scan and more enjoyable to use, thanks to refined cards and clearer visual hierarchy. We still give you a quick overview of your infrastructure, but now key information stands out even better. ![](https://xen-orchestra.com/blog/content/images/2026/02/533938788-e9d5fd9a-f24f-4596-a1b9-d9a8a6537963.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/533938848-e6f67098-f8a2-466e-abde-1a05f377f5f1.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/533938920-944e0bd3-d292-41b8-8115-3e86a3d4b689.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/533939025-ab0c8b51-91a9-4192-87a3-a76d64951a3d.png) Refreshed dashboard design ## 📡 REST API Every month we’re growing our API to better handle real-world tasks and let you automate complex workflows. This time, on top of the new API endpoints, we’ve added support for MCP so you can start experimenting with AI in Xen Orchestra. ### New MCP package We’ve added a new package, called `@xen-orchestra/mcp`. MCP (Model Context Protocol) is a protocol that AI models can use when working with external systems, in a structured and secure way. This means that a tool such as Xen Orchestra can share its capabilities and contextual data with an AI assistant, who they can query infrastructure, retrieve information, and even make changes in a controlled manner. By adding a dedicated MCP package, we’re providing a clean and modular integration. It’s an important step toward enabling AI-driven workflows around your virtualization stack, while keeping clear boundaries in the codebase. [What is the Model Context Protocol (MCP)? - Model Context Protocol![](https://xen-orchestra.com/blog/content/images/icon/apple-touch-icon-18.png)Model Context Protocol![](https://xen-orchestra.com/blog/content/images/thumbnail/og-image.png)](https://modelcontextprotocol.io/docs/getting-started/intro?ref=xen-orchestra.com) ### New endpoints We’ve expanded the API to support more everyday operations. The new endpoints are: - `POST /vms/{id}/actions/migrate` : lets you trigger VM migrations - `POST /pbds/{id}/actions/plug` : lets you plug PBD routes - `POST /pbds/{id}/actions/unplug` : lets you unnplug PBD routes - `POST /vdis`: lets you create VDIs on demand - You can also manage VIF traffic rules for automated VM networking, with: - `POST /plugins/snd-controller/vif/rules/:id` - `DELETE/plugins/snd-controller/vif/rules/:id` These endpoints give you finer control when integrating Xen Orchestra into your own tools and workflows. ![](https://xen-orchestra.com/blog/content/images/2026/02/538500216-c5fbb15f-37ff-4974-bc05-abb284b833e7.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/547132125-e5b90d74-158c-4bd6-9c52-f7e87ef6fe99.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/547132149-bf45a699-2c5e-4f02-927f-e8291d957f66.png) ![](https://xen-orchestra.com/blog/content/images/2026/02/548145801-d1e238f1-4834-44a6-992e-776b53418451.png) New API endpoints documented in Swagger ### ## ☸️ DevOps Tools We're constantly refining the tools around Xen Orchestra to make development, automation, and integration more reliable. This section covers the latest updates across our ecosystem. ### Golang SDK Update New endpoints have been added to the v2 SDK. You can now retrieve and delete VDIs, manage tags, export and import VDI content. You can also migrate VDIs to different storage using the new v2 SDK VDI service. [Releases · vatesfr/xenorchestra-go-sdkGo SDK to build things on top of XO API. Contribute to vatesfr/xenorchestra-go-sdk development by creating an account on GitHub.![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-58.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/23ce3f92-bdfd-4fdf-bc81-7df6078e7863)](https://github.com/vatesfr/xenorchestra-go-sdk/releases?ref=xen-orchestra.com) ### Pulumi Provider upgrade We’ve updated to the latest Pulumi version and Terraform provider. This brings in all the latest fixes and features added to the Terraform provider over the last few months. [Release v2.4.0 · vatesfr/pulumi-xenorchestraWhat’s Changed Enable secure boot parameter on VM resource (set to false by default) Fix missing disk when create vm from template with >3 disks Fix creation of VDI resource (import vdi) Fix get x…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-61.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v2.4.0)](https://github.com/vatesfr/pulumi-xenorchestra/releases/tag/v2.4.0?ref=xen-orchestra.com) ### Terraform Provider We’ve updated several dependencies of the Terraform provider to improve security. [Release v0.37.3 · vatesfr/terraform-provider-xenorchestraNoteThis release includes a security update for the CIRCL and crypto packages. What’s Changed build(deps): bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 by @dependabot\[bot\] in #397 build(d…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-54.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v0.37.3)](https://github.com/vatesfr/terraform-provider-xenorchestra/releases/tag/v0.37.3?ref=xen-orchestra.com) ## 🐦 VMware to Vates (V2V) We’re committed to making your transition from VMware to the Vates ecosystem as easy as possible. Check out our latest improvements that will make the V2V experience more reliable! ### Automatic snapshot before migration Migrating a VM from VMware to Vates can be stressful, especially if you forget to create a snapshot before starting the process. To prevent unexpected downtime and simplify the workflow, Xen Orchestra now automatically creates a snapshot of any running VM without an existing snapshot before migration begins. ### Save VM import settings To make V2V migrations smoother, we've introduced a "Remember" checkbox on the VM import page. Thanks to this feature, you don't need to type in the same info over and over when you do several imports which saves time and contributes to a smooth experience. We are always grateful to our community for your suggestions, which significantly influence the choices of features we develop! ## ⚖️ Load balancer It's been a while since the last load balancer updates. They're back now! ### Cooldown for VM migrations The load balancer now offers a customizable cooldown period. This cooldown disables the migration of a VM shortly after the load balancer has moved it. It effectively prevents a cycle of unnecessary back-and-forth migrations caused by short-term metric fluctuations in the cluster. As a result, the balancing behavior becomes more stable and predictable, particularly in dynamic environments. ![](https://xen-orchestra.com/blog/content/images/2026/02/534589505-a2a2ef02-da75-4e80-b1f9-0a0c07e210e5.png) Migration cooldown configuration ## 🪐 XOA This release also makes license tiers easier to identify in XOA. ### Display license bundle name XO 5 now displays the name of the bundle associated with your current Xen Orchestra license. If you’re using XOA, you can immediately see which license level is linked to your instance. This makes it clearer what tier you’re running and helps avoid any confusion about available features. ![](https://xen-orchestra.com/blog/content/images/2026/02/551599768-e0b14070-bdb3-4336-9d22-73ea7778c3b6-1.png) Licence bundle name in XOA ## 📖 Documentation & Guides We want you to enjoy all the great new features to the fullest, that's why we always release them together with fully detailed documentation. Below are the most recent guides and updates that have been published in the last month. ### OpenMetrics Documentation Updates Last month, we updated the OpenMetrics documentation to explain how to expose the metrics form Xen Orchestra. To reflect the latest enhancements in the `xo-server-openmetrics` plugin, we’ve updated that documentation again. It covers new metrics, such as **host uptime**, **host status**, and the `is_control_domain` label. This way you can understand scraped data easily, and make use of these metrics in Prometheus queries or dashboards. Besides that, we’ve also updated the examples to match the current `/metrics` endpoint, to enable more precise monitoring and reduce the need for guessing. ![](https://xen-orchestra.com/blog/content/images/2026/02/Capture-d---cran-2026-02-20-093011.png) Preview of the updated Metrics documentation [Advanced features | Xen Orchestra | XO DocumentationThis section is dedicated to all others Xen Orchestra “advanced features”.![](https://xen-orchestra.com/blog/content/images/icon/favicon-41.ico)Xen Orchestra Documentationour blog post series about it![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-24.png)](https://docs.xen-orchestra.com/advanced?ref=xen-orchestra.com#available-metrics) ### Prepare your SDN controller for OpenSSL 3 We’ve published a step-by-step guide for manually updating the SDN controller before the March 2026 update of XCP-ng, which introduces OpenSSL 3. With OpenSSL 3 arriving in XCP-ng 8.3, the certificates previously generated by the Xen Orchestra SDN Controller plugin will no longer work. They will need to be regenerated. We recommend you take the time to handle this as soon as possible, so you’re ready for the XCP-ng’s March 2026 update. The guide details what to check and update for a seamless transition. If you use the SDN controller, review this documentation before upgrading your hosts to avoid disruptions. ![](https://xen-orchestra.com/blog/content/images/2026/02/Capture-d---cran-2026-02-24-141350.png) Preview of the SDN upgrade path documentation [SDN Controller | Xen Orchestra | XO DocumentationBe sure to enable the plugin on only one XOA instance.![](https://xen-orchestra.com/blog/content/images/icon/favicon-42.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-25.png)](https://docs.xen-orchestra.com/sdn%5Fcontroller?ref=xen-orchestra.com#openssl-3--sdn-upgrade-path) ### New MCP guide With the [new MCP package](#new-mcp-package) now included in Xen Orchestra, we’ve added comprehensive documentation to help you get started. This new page covers what MCP is, how it integrates with Xen Orchestra, and step-by-step setup instructions. If you’re planning to experiment with AI-driven workflows or automation around your virtualization stack, this documentation is the right place to start. ![](https://xen-orchestra.com/blog/content/images/2026/02/Capture-d---cran-2026-02-26-081727.png) Preview of the MCP documentation [Model Context Protocol (MCP) | Xen Orchestra | XO DocumentationWhat is MCP?![](https://xen-orchestra.com/blog/content/images/icon/favicon-43.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-26.png)](https://docs.xen-orchestra.com/mcp?ref=xen-orchestra.com) ### Clearer metadata backup documentation In response to community feedback, we’ve updated the documentation to define the two types of metadata backups in Xen Orchestra in more detail, Previously, some readers found the distinctions unclear, which could complicate backup and restore planning. The guide now clearly outlines the differences and what each type includes, so you can design a more reliable recovery strategy. [Metadata backup | Xen Orchestra | XO DocumentationXCP-ng and Citrix Hypervisor (Xenserver) hosts use a database to store metadata about VMs and their associated resources such as storage and networking. Metadata forms this complete view of all VMs available on your pool. Backing up the metadata of your pool allows you to recover from a physical hardware failure scenario in which you lose your hosts without losing your storage (SAN, NAS...).![](https://xen-orchestra.com/blog/content/images/icon/favicon-44.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-27.png)](https://docs.xen-orchestra.com/metadata%5Fbackup?ref=xen-orchestra.com) ## 🌐 Translations Xen Orchestra is used globally, and accurate translations are essential to ensure everyone can use it effectively. Here, we share the latest language updates and recognize the community contributors who help maintain these translations. Your work makes the platform more inclusive for all users. ### 17 languages updated A big thank you to our community for their ongoing efforts in translating Xen Orchestra! ![](https://xen-orchestra.com/blog/content/images/2026/02/687474703a2f2f7472616e736c6174652e76617465732e746563682f7769646765742f78656e2d6f72636865737472612f6d756c74692d6175746f2e737667.svg) Current XO translation status This month, 17 languages were updated: **Chinese (simplified), Czech, Danish, Dutch, Finnish, German, Italian, Japanese, Korean, Norwegian (Bokmål),** **Persian, Polish, Portuguese (Brazilian), Russian, Spanish, and Swedish**. Want to help translate Xen Orchestra or improve existing translations? You’re more than welcome to join in [here](https://translate.vates.tech/?ref=xen-orchestra.com). ## 🆕 Misc We've come up with several changes to make your daily activities easier. The main focus for us this month was on OpenMetrics and making VM migrations easier. ### More host data in OpenMetrics We’re exposing a few more useful data points in OpenMetrics exports. First, we’re adding the dedicated `is_control_domain = true` tag for the **dom0 VM**. This makes it easy to distinguish the dom0 VM from regular VMs in your monitoring setup. 💡 ****Note:** The dom0 VM is the VM that runs all the tools. When we access the host via SSH, we actually connect to this VM. **Host status** is now exposed as well, along with **host uptime**. With these changes, you can get a more accurate idea of the host's condition. For example: ``` # HELP xcp_host_uptime_seconds Host uptime in seconds since boot # TYPE xcp_host_uptime_seconds gauge xcp_host_uptime_seconds{pool_id="...",pool_name="...",uuid="...",host_name="..."} 3600 1706889600 ``` ![](https://xen-orchestra.com/blog/content/images/2026/02/543868284-135f5e4b-e7aa-40d9-9a13-07f3277ac792.png) Host uptime in OpenMetrics exports ### ### Warm migrations with stopped VMs Warm migrations now also work with stopped VMs. If a VM is already stopped when migration begins, the process completes successfully and returns the UUID of the newly created VM on the target. This ensures consistent behavior and simplifies automation, especially in scripted workflows. ### NetBox v4.5.x compatibility **XO 6.2** is now fully compatible with the latest **NetBox 4.5.x** releases. This ensures a smoother connection with your infrastructure management setup. ![](https://xen-orchestra.com/blog/content/images/2026/02/netbox-1.png) [Releases · netbox-community/netboxThe premier source of truth powering network automation. Open source under Apache 2\. Try NetBox Cloud free: https://netboxlabs.com/products/free-netbox-cloud/ - netbox-community/netbox![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-63.svg)GitHubnetbox-community![](https://xen-orchestra.com/blog/content/images/thumbnail/netbox)](https://github.com/netbox-community/netbox/releases?ref=xen-orchestra.com) ### Xen Orchestra 6.1 URL: https://xen-orchestra.com/blog/xen-orchestra-6-1/ Last updated: 2026-07-15T06:49:30.000Z First release of 2026, and also the first update for Xen Orchestra 6! XO 6.1 continues the work we started with the new major version: refining the platform, strengthening its foundations, and steadily improving day-to-day operations. This release focuses on practical improvements driven by real-world usage and community feedback. Oh ! And we also introduced a theme selector! From architectural changes under the hood to UI refinements, new API capabilities, improved backup visibility, and better tooling around monitoring, licensing, and automation, XO 6.1 is about making the platform clearer, more predictable, and easier to operate at scale. It also reflects a broader momentum around the project: growing adoption, deeper community involvement, and an ecosystem that continues to expand through partnerships, research initiatives, and events. 🎵 The podcast version of our release is available on [Spotify](https://open.spotify.com/episode/1ejxZkTNSAEksAxuk3zLph?si=KTLqtk8NQvGCRMTCS03OZA&ref=xen-orchestra.com). ## 👨‍🚀 Project & Community A recap and new partners, 2026 will be huge as it starts already well just in January! ### 2025 in numbers 2025 turned out to be a pretty exciting year for Vates, filled with ongoing growth in both usage and adoption. XCP-ng and Xen Orchestra made impressive progress, with more production deployments and a community that became increasingly involved. Beyond the numbers, the real highlight was consistency: more users, more infrastructures running Vates VMS every day, and a stronger feedback loop between the community and the engineering team. [Vates in 2025: key numbers and growth highlightsA clear snapshot of Vates in 2025: growth, adoption, and product momentum, shared openly through our yearly infographic.![](https://xen-orchestra.com/blog/content/images/icon/logo64-31.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1639501252219-130096b7b904-1)](https://vates.tech/blog/vates-in-2025-the-numbers/?utm%5Fsource=xo%5Frelease&utm%5Fmedium=blog&utm%5Fcampaign=xo%5F6%5F1) ### XCP-ng 8.3 security updates First round of updates and security fixes for 2026. [January 2026 Security and Maintenance Updates for XCP-ng 8.3 LTSNew security and maintenance updates are available for XCP-ng 8.3 LTS.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-37.png)XCP-ng BlogGaël Duperrey![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1663811459413-e9de4614f88f)](https://xcp-ng.org/blog/2026/01/29/january-2026-security-and-maintenance-updates-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) ### Pure Storage and Vates partnership We’re pleased to announce that Vates has officially joined the Pure Storage Technology Alliance Program (TAP). While we’ve already been working for some time on ensuring compatibility between our solutions, becoming an formal TAP member marks a new step: it formalizes our collaboration and allows us to validate integrations in a structured and official framework. ![](https://xen-orchestra.com/blog/content/images/2026/01/Pure-Storage-Emblem-1.png) More details will follow soon, but our objective is clear: bring the performance, intelligence, and advanced capabilities of Pure Storage directly into XCP-ng through a seamless integration. [Technology Alliance Program | Pure StoragePure Storage is committed to building strong partnerships that complement our solutions, enabling enterprises to maximize the power of their data.![](https://xen-orchestra.com/blog/content/images/icon/favicon-39.ico)\_inline\_processInlineSVG('.inline-svg-img-199735222 > svg');![](https://xen-orchestra.com/blog/content/images/thumbnail/partners-tap-og.png.imgw.720.720-1.png)](https://www.purestorage.com/partners/technology-alliance-partners.html?ref=xen-orchestra.com) ### VEEAM support coming soon Many of you are waiting for the official release of agentless Veeam support for XCP-ng. Over the past few months, the Veeam teams have been highly responsive and deeply involved in making the integration as smooth as possible. The beta release they published has already received largely positive feedback. We’re happy to share that we’re now very close to an official release of Veeam support. In the meantime, Veeam has updated its documentation to explain how to use its backup platform with XCP-ng using the agent-based method: [KB4703: Using Veeam Agents with Xen Orchestra (Vates XCP-NG and XenServer)This article documents how to use Veeam Agent for Microsoft Windows and Veeam Agent for Linux, managed by Veeam Backup & Replication, to protect virtual machines in XenServer and XCP-NG environments that are managed by Xen Orchestra. While these hypervisors are not directly supported for VM-level interaction by Veeam Backup & Replication, this article demonstrates how protection is possible through guest OS-level backup agents.![](https://xen-orchestra.com/blog/content/images/icon/favicon_180x180px.png)Veeam Software![](https://xen-orchestra.com/blog/content/images/thumbnail/meta_banner_kb.png)](https://www.veeam.com/kb4703?ref=xen-orchestra.com) ### New industrial research chair In 2025, the MIAI Cluster approved funding for an industrial research chair named **HELIOS**. Led by Alain Tchana, this initiative brings together Vates, EasyVirt, and the R&D teams from KrakOS and SANGRIA. The chair focuses on advancing research into secure, efficient, sustainable, and sovereign cloud and AI technologies, with a strong emphasis on healthcare use cases. Taking part in HELIOS is both a strong signal and a meaningful recognition of the work being done at the intersection of open infrastructure, academic research, and real-world operational constraints. [HELIOS - MIAI Industrial Chair![](https://static.ghost.org/v5.0.0/images/link-icon.svg)☀️ HELIOS![](https://xen-orchestra.com/blog/content/images/thumbnail/miai.jpeg)](https://helios.academy/?ref=xen-orchestra.com) --- ## 🎫 Events 2026 is starting strong with both FOSDEM and Tech&Fest. If you are based in Europe, come to say hi! ### FOSDEM 2026 FOSDEM 2026 will once again be a key moment for the open source community. For us at Vates, it’s a particularly meaningful edition, as it marks our tenth year of participation in this iconic event for the European, and global, open source ecosystem. We’ll be present with a booth, where you’ll be able to see live demonstrations of Xen Orchestra, and many members of our team will also take part in technical discussions throughout the event. [Vates at FOSDEM 2026Vates and XCP-ng will be at FOSDEM 2026 in Brussels. Meet the team and connect with the Xen and XCP-ng open source communities.![](https://xen-orchestra.com/blog/content/images/icon/logo64-33.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-at-fosdem-2026.png)](https://vates.tech/blog/fosdem-2026/?ref=xen-orchestra.com) ### Tech & Fest 2026 In February, we’ll be in Grenoble for Tech & Fest 2026\. The event brings together players from industry, research, and the public sector to explore concrete, real-world technology use cases, with an emphasis on practical outcomes rather than abstract discussions. Holding the event in Grenoble has a particular resonance for us, as it’s also where our headquarters are located. Olivier (Our CEO & co-founder) will be speaking about digital sovereignty from a technical perspective, focusing on what actually works in production environments. [Vates at Tech&Fest 2026 in GrenobleVates will attend Tech&Fest 2026 in Grenoble on February 4–5\. Meet us at booth S37 and join Olivier Lambert’s talk on digital sovereignty.![](https://xen-orchestra.com/blog/content/images/icon/logo64-32.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-at-tech-fest.jpg)](https://vates.tech/blog/vates-at-tech-fest-2026-in-grenoble/?utm%5Fsource=xo%5Frelease&utm%5Fmedium=blog&utm%5Fcampaign=xo%5F6%5F1) --- # XO 6.1 After l[ast month’s big milestone](https://xen-orchestra.com/blog/xen-orchestra-6-0/#xo-60) with XO 6.0, we’re back with a new release: XO 6.1\. Let’s take a look at the latest improvements, refinements, and fixes that make the interface and workflows even smoother. ## 🛡️ Security At Vates, security is our top priority. We actively monitor for vulnerabilities, fix issues as quickly as possible, and communicate openly so you can take informed action to protect your infrastructure. Here are the latest security notices and important updates for Xen Orchestra and related tools. ### VSA-2026-004 We've published a new security notice to the Vates VMS documentation platform: this page includes a detailed breakdown of the vulnerability known as **VSA-2026-004,** including affected components and potential impact, along with clear, actionable recommendations to secure your environment. This notice follows our commitment to transparency and proactive security. Admins and operators are encouraged to review it immediately to assess exposure and apply necessary measures. Click the link below to read the notice: [VSA-2026-004: Node-Tar | Vates VMS Documentation2026-01-29 / Low severity / XO is affected.![](https://xen-orchestra.com/blog/content/images/icon/vates-logo-128-c064bc94b81bd09a913e2c5208f3ce7b8a198b8db413b18d4a0ddd5f7f330a2e.png)Vates VMS Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-logo-128-c064bc94b81bd09a913e2c5208f3ce7b8a198b8db413b18d4a0ddd5f7f330a2e.png)](https://docs.vates.tech/trust-roadmap/security-advisories/advisories/2026/vates-sa-2026-004?ref=xen-orchestra.com) ## 💾 Backup Over the past months, we’ve been steadily improving long-term retention (LTR) management for backups. This month, we continue that work with enhancements that give you even better visibility and control over your backup policies. ### LTR tags on backups Backups now display their Long-Term Retention (LTR) tags in the interface. This makes it clear which backups are governed by long-term retention policies and which follow shorter rules. With LTR tags front and center, you can quickly confirm that your retention settings are applied correctly, without digging into configuration details or guessing based on dates alone. ### Improved Azure and S3 backup support We’ve fixed an issue affecting full backups of VMs with large disks (over 64 GB) on S3-compatible storage. And since the fix applies to shared code, Azure storage support benefits too. The problem came from underestimating the XVA file size: the backup process wasn’t accounting for the header of each block and the block hash entries. With this fix, full backups (including encrypted disks) now complete reliably, on both S3 and Azure storage repositories. This ensures consistent and predictable backup behavior across cloud targets. ## 🥝 Core UI This month, we’re refining XO 6 and XO Lite to make navigation faster and give you more control over your workflow. UI behavior is getting smarter, visuals are now sharper, and we've also enhanced VM creation. ### Auto-scroll to selected stems When you open a page with an item already selected in the navigation tree, the tree now automatically scrolls to highlight your selection. Your chosen host, pool, or VM is instantly visible. No need to search again! This is particularly helpful for large infrastructures, where selected items might otherwise be hidden out of view, and force you to scroll manually. The scrolling is smooth and consistent with the existing expand and collapse behavior. If nothing is selected, the tree behaves as usual. But when an item is selected, it’s now visible immediately, for more efficient navigation. ### New and updated icons Following the new icon system introduced with Xen Orchestra 5.109, we’ve added even more icons from that system. Their design are consistent with our design language and follow a consistent naming pattern. ![](https://xen-orchestra.com/blog/content/images/2026/01/Capture-d---cran-2026-01-29-090735.png) ![](https://xen-orchestra.com/blog/content/images/2026/01/Capture-d---cran-2026-01-29-090745.png) Our new icon system [Xen Orchestra 5.109This month’s XO 5.109 release brings solid progress across the board, from backup stability and UI improvements to new V2V migration tooling and upstream Windows PV driver work. Plus, plenty of updates on XCP-ng, real-world use cases, and more!![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-33.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/july.jpg)](https://xen-orchestra.com/blog/xen-orchestra-5-109/#new-icon-system) ### vTPM support for new VMs You can now enable Virtual Trusted Platform Module (VTPM) support when creating a Windows Server VM. Unlocking VTPM enhances security for features like BitLocker encryption. Simply select VTPM during VM creation. No extra steps are needed after deployment. ## 🛰️ XO 6 XO 6 became the default Xen Orchestra interface at the end of last year, and it keeps improving. This section highlights the latest improvements and refinements built specifically for XO 6, with a strong focus on usability, consistency, and everyday workflows. ### A reminder about feedback and support Xen Orchestra 6 is continuously evolving, and your feedback plays a crucial role in shaping its future. If you encounter any issues, notice unexpected behavior, or have ideas for improvement, we kindly ask that you **avoid opening a support ticket** on our portal for XO 6. Instead, we’ve introduced a dedicated feedback platform designed to gather your insights about how XO 6 is used. There, you can share suggestions, highlight pain points, and upvote existing requests. This ensures the most relevant topics gain visibility. Your input directly influences what we prioritize next. 💡 This approach ensures that our roadmap reflects actual needs and priorities, guided by how you use Xen Orchestra, not by our assumptions. [Vates VMS feedbackWelcome! This page collects feedback from all our users across the Vates VMS stack, from XCP-ng to Xen Orchestra 6, including XOSTOR and our other pro![](https://xen-orchestra.com/blog/content/images/icon/qZprAll0bofaK77abT3Hg93cBpodHgaHZDLk2GsiR40oQ1RNVD9xs84LBJcJYOXO-logo400-1.png)![](https://xen-orchestra.com/blog/content/images/thumbnail/qZprAll0bofaK77abT3Hg93cBpodHgaHZDLk2GsiR40oQ1RNVD9xs84LBJcJYOXO-logo400-1.png)](https://feedback.vates.tech/?ref=xen-orchestra.com) It's easy to get involved: log in with a third-party account (like Discord or GitHub) or sign up with your email. From there, you can explore existing feedback, upvote the ideas that matter most to you, or add new suggestions if your topic isn’t already covered. Feel free to also join the dedicated discussion on our forum, right here: [🛰️ XO 6: dedicated thread for all your feedback!End of November: XOA admin users on the latest channel will see a new option in the left-hand menu to access XO 6\. XO 5 will remain the default interface,…![](https://xen-orchestra.com/blog/content/images/icon/512-16.png)XCP-ngolivierlambert![](https://xcp-ng.org/forum/assets/uploads/forum/assets/uploads/profile/uid-752/752-profileavatar-1665407860052.jpeg)](https://xcp-ng.org/forum/topic/11604/xo-6-dedicated-thread-for-all-your-feedback/2?ref=xen-orchestra.com) ### Streamlined VM actions It’s now easier to manage your VMs from the XO 6 interface: the **Advanced** menu gives you quick access to a full range of actions, covering all common VM states and scenarios. From here, you can **start, pause, unpause, suspend, or resume** a VM, as well as perform **clean shutdowns and reboots** when the guest OS is responsive. If the OS is unresponsive, **force actions** (like hard reboots or forced shutdowns) are also available. You can even **delete** a VM directly, all in one place. This centralized approach makes everyday VM operations faster, clearer, and more efficient, so you can focus on what matters most. ### Project architecture refactor We’ve refactored the XO 6 codebase to improve the overall project architecture. The goal was to simplify how the different parts of the application are structured and how they interact with each other. This update does not affect the interface or existing features, but makes the project easier to maintain and extend over time. ``` /src /composables vm.composable.ts ... /components /vm /dashboard DashboardComponent.vue ... /utils vm.util.ts ``` Previous project structure ``` /src /modules /vm /composables vm.composable.ts /components /dashboard DashboardComponent.vue /utils vm.util.ts ``` New project structure ### Theme selector Xen Orchestra now comes with multiple themes you can choose from. Adapt the interface to your preferences, whether you want better contrast, a different mood, or just something that feels more comfortable for long sessions. ![](https://xen-orchestra.com/blog/content/images/2026/01/534253178-b5daedb1-381e-4bc7-bf6a-8baeb84dcab0.png) Theme selector in XO 6 Just select your favorite theme from the interface, and you’re good to go! ### Clearer side panels We’ve removed text ellipsis in side panels, so that labels and values are fully visible. This is especially helpful for longer names, paths, or descriptions: the information is now easier to read at a glance. On top of that, IDs now appear in `monospace font`. ![](https://xen-orchestra.com/blog/content/images/2026/01/541154286-28e44d95-da32-403b-839e-249b3d2ae986.png) ![](https://xen-orchestra.com/blog/content/images/2026/01/541154222-b6da1653-e0f7-473a-a903-0c71e5b1be10.png) New side panel design, without ellipsis ### Consistent disk naming from templates When creating a VM, its disk name now automatically follows the template’s naming convention at the time of creation. This ensures consistent identification of disks across your VMs, based on the original template name. If you later rename the template, existing disk names remain unchanged. This will prevent confusion from mismatched or outdated labels, and results in predictable storage naming. ## 📡 REST API We’re expanding the API to support more real-world scenarios and bridge the gap between manual and automated workflows. With this month's release, we give you more power over VM storage and networking. ### New storage API actions We’ve extended the REST API with several new endpoints to handle storage attachments and disk operations more directly. You can now create and delete VBDs, connect or disconnect them from VMs, and migrate VDIs through the API, with the following endpoints: - `POST /rest/v0/vbds` - `DELETE /rest/v0/vbds/{id}` - `POST /rest/v0/vdis/{id}/actions/migrate` - `POST /rest/v0/vbds/{id}/actions/connect` - `POST /rest/v0/vbds/{id}/actions/disconnect` These additions make it easier to automate storage workflows and bring the API closer to what you can already do from the UI, while giving integrators more precise control over VM disks. ### New endpoints for VIFs On top of that, we've added two endpoints to manage virtual network interfaces (VIFs). You can now: - **Create a VIF,** with `POST /rest/v0/vifs` - **Delete a VIF,** using `DELETE /rest/v0/vifs/{id}` These improvements give you full control over the VIF lifecycle over the API, so you can automate VM network management easily. No need to go through the XO interface anymore! ## ☸️ DevOps Tools We keep investing in the tools around Xen Orchestra to make development, automation, and integration easier and more robust. This section highlights the latest updates to our ecosystem, from infrastructure-as-code and SDKs to Kubernetes and deployment tooling. ### Packer plugin update We released a new version of the Packer plugin for XCP-ng, with multiple improvements. It now supports multiple disks, and the plugin documentation has been updated accordingly. Thanks to AtaxyaNetwork for this contribution! On top of that, the Packer plugin can now handle IP address changes during builds, thanks to Erik Wahlberger’s input. Finally, the update comes with a set of bug fixes that improve overall stability. Many thanks to all the community contributors who sent pull requests and helped make this update possible! [Release v10.0.2 · vatesfr/packer-plugin-xenserverWhat’s Changed New Features 🎉 Add support for multiple disks + documentation update by @AtaxyaNetwork in #186 Add support for IP address changes by @Erik142 in #62 Bug fixes Remove ToLower on is…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-49.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v10.0.2)](https://github.com/vatesfr/packer-plugin-xenserver/releases/tag/v10.0.2?ref=xen-orchestra.com) [Erik142 - OverviewOS Platform Engineer. Passionate about Linux, CI/CD solutions, build systems, IaC/CaC and open source 😄 - Erik142![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-48.svg)GitHub![](https://xen-orchestra.com/blog/content/images/thumbnail/4168364)](https://github.com/Erik142?ref=xen-orchestra.com) [AtaxyaNetwork - OverviewUptime: 25 years | Height: 35U | Freelance Cloud builder | DisruptiveMinds co-founder | Retro computing hobbyist - AtaxyaNetwork![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-47.svg)GitHub![](https://xen-orchestra.com/blog/content/images/thumbnail/58917141)](https://github.com/AtaxyaNetwork?ref=xen-orchestra.com) ### Terraform Provider update We released a new version of the Terraform Provider from Xen Orchestra. This update enables Secure Boot, which should fix issues related to VM creation or cloning. It also fixed the VDI creation when uploading ISOs and disks to Xen Orchestra. 💡 ****Note:** The update sets `secure_boot` to `false` by default. If you turn it on outside of Terraform, make sure you set it to 'true' in your HCL configuration. [Release v0.37.0 · vatesfr/terraform-provider-xenorchestraWhat’s Changed feat: enable secure boot by @gCyrille in #389 Full Changelog: v0.36.1...v0.37.0![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-45.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v0.37.0)](https://github.com/vatesfr/terraform-provider-xenorchestra/releases/tag/v0.37.0?ref=xen-orchestra.com) ### Official documentation for Talos Linux 💡 ****Reminder** **Talos* (or **Talos Linux*) is a modern OS for running Kubernetes: secure, immutable, and minimal. Talos is fully open source, production-ready, and supported by the people at [Sidero Labs](https://www.siderolabs.com/?ref=xen-orchestra.com). All system management is done via an API - there is no shell or interactive console. We’ve added step-by-step documentation to help you deploy and manage Talos Linux with Xen Orchestra. ![](https://xen-orchestra.com/blog/content/images/2026/01/Capture-d---cran-2026-01-29-083341.png) Preview of the documentation for using Talos with Xen Orchestra This new guide simplifies onboarding for users running Kubernetes on XCP-ng, and bridges the gap between Talos and XO. [Talos Linux - The Kubernetes Operating SystemTalos Linux is a secure, immutable, and minimal operating system for Kubernetes. API-managed, declarative configuration, and fast deployments.![](https://xen-orchestra.com/blog/content/images/icon/favicon-1.svg)TALOS LINUX![](https://xen-orchestra.com/blog/content/images/thumbnail/social-preview.png)](https://www.talos.dev/?ref=xen-orchestra.com) [Xen Orchestra - Sidero DocumentationCreating Talos Kubernetes cluster using Xen Orchestra.![](https://xen-orchestra.com/blog/content/images/icon/apple-touch-icon-17.png)Sidero Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/image)](https://docs.siderolabs.com/talos/v1.12/platform-specific-installations/virtualized-platforms/xenorchestra?ref=xen-orchestra.com) [Fedora CoreOS XCP-ng XO Template - LetheDataCreate a Fedora CoreOS template for Xen Orchestra with ignition support through cloud config templates.![](https://xen-orchestra.com/blog/content/images/icon/favicon-35.ico)LetheDataEcho Nar](https://lethedata.com/blog/xo%5Ffcos%5Ftemplate.html?ref=xen-orchestra.com) ### Kubernetes Cloud Controller Manager (CCM) 💡 ****Reminder** The Xen Orchestra Cloud Controller Manager (CCM) registers new nodes, keeps them labeled with Xen Orchestra metadata, and cleans them up when their backing VM disappears. It supports multiple pools, so a single Kubernetes cluster can span several Xen Orchestra pools. We’re shipping **v1.0.0-rc.1**, our **first release candidate** on the road to a stable 1.0.0! This RC is feature-complete and ready for real-world use. 🚀 Please try it out and share any feedback: bugs, regressions, or usability notes, so we can polish the final release. Thank you for testing and helping us! 🙌 [Release v1.0.0-rc.1 · vatesfr/xenorchestra-cloud-controller-manager🎉 We’re shipping v1.0.0-rc.1, our first release candidate on the road to a stable 1.0.0! This RC is feature-complete and ready for real-world use. 🚀 Please try it out and share any feedback—bugs, r…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-50.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v1.0.0-rc.1)](https://github.com/vatesfr/xenorchestra-cloud-controller-manager/releases/tag/v1.0.0-rc.1?ref=xen-orchestra.com) ### Golang SDK update The Go (or *Golang*) SDK v2 expands on v1’s Secure Boot and VDI import fixes, with significant enhancements. VM and Task services now match the latest REST API, while a new Host service simplifies host data retrieval. Integration tests have also been strengthened to boost reliability. The v2 SDK is gradually becoming our main library for all the other DevOps tools (Kubernetes drivers, Terraform provider…). ## 🐦 VMware to Vates (V2V) We’re always working to make it easier to migrate VMs from VMware to the Vates ecosystem. Below, you’ll find the latest improvements and fixes that help V2V operations run smoothly and predictably. ### More reliable Qcow2 imports We’ve resolved an issue where qcow2 imports could fail at the final stage of a V2V operation. In some situations, the import looked successful until the final step, where it would unexpectedly stop. Now, V2V imports to qcow2 complete more reliably, including the last stage of the process. Many thanks to our users and the wider community for their vigilance and feedback, which keep helping us improve Xen Orchestra and our tools. Thanks [**Andrw0830**](https://xcp-ng.org/forum/user/andrw0830?ref=xen-orchestra.com) for your helping to make this possible! ## 📖 Documentation & Guides We keep expanding and refining our documentation to make Xen Orchestra easier to deploy, operate, and monitor. This section highlights the latest guides and updates published over the past month. ### RHEL 10 dependency updates The Xen Orchestra documentation now includes clear, step-by-step instructions for retrieving required software dependencies on RHEL 10–based distributions (such as AlmaLinux, Rocky or CentOS). Since RHEL 10 introduces some differences from earlier versions, the previous documentation left gaps for users deploying on this platform. ![](https://xen-orchestra.com/blog/content/images/2026/01/Capture-d---cran-2026-01-27-145100.png) Preview of the updated documentation This update simplifies installation and maintenance by detailing the correct repositories and dependency configurations. This reduces guesswork and installation friction. [Installation | Xen Orchestra | XO DocumentationIf you want to deploy an XOA in an airgapped infrastructure, refer to the dedicated documentation.![](https://xen-orchestra.com/blog/content/images/icon/favicon-36.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-21.png)](https://docs.xen-orchestra.com/installation?ref=xen-orchestra.com#packages-and-prerequisites) ### Prometheus integration Following [last month’s release](https://xen-orchestra.com/blog/xen-orchestra-6-0/#xo-as-openmetrics-proxy), we’ve added dedicated documentation for the OpenMetrics and Prometheus integration. The new section explains how to expose metrics from Xen Orchestra and scrape them with Prometheus. ![](https://xen-orchestra.com/blog/content/images/2026/01/Capture-d---cran-2026-01-28-163751.png) Preview of the new OpenMetrics/Prometheus documentation The documentation is available in the **Advanced → Recipes** section of the XO documentation. It provides clear, practical guidance so you can get start monitoring quickly, without having to piece things together from scattered sources. [Advanced features | Xen Orchestra | XO DocumentationThis section is dedicated to all others Xen Orchestra “advanced features”.![](https://xen-orchestra.com/blog/content/images/icon/favicon-37.ico)Xen Orchestra Documentationour blog post series about it![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-22.png)](https://docs.xen-orchestra.com/advanced?ref=xen-orchestra.com#openmetrics--prometheus-integration) ## 🔦 Community spotlight The Xen Orchestra community continues to create valuable tools, resources, and projects that expand what the platform can do. Here, we showcase some of the most notable contributions and updates from users and collaborators, each one adding to the strength and diversity of the XO ecosystem. Your ideas and work make this community thrive! ### XenAdminQt v.0.0.3-alpha This month sees the new release of **XenAdminQt**: a lightweight Qt-based client for managing Xen environments. A special thanks to Petr Bena for his dedication and contributions to the Xen community! [Release v0.0.3-alpha · benapetr/XenAdminQtPrebuilt packages for macOS, GNU/Linux and Windows![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-53.svg)GitHubbenapetr![](https://xen-orchestra.com/blog/content/images/thumbnail/v0.0.3-alpha)](https://github.com/benapetr/XenAdminQt/releases/tag/v0.0.3-alpha?ref=xen-orchestra.com) To know more on XenAdminQt, check out the [dedicated thread](https://xcp-ng.org/forum/topic/11689/new-project-xenadminqt-a-cross-platform-gnu-linux-macos-windows-native-thick-client/11?ref=xen-orchestra.com) on our forum: [benapetr - OverviewI am a dev who likes UNIX and KISS philosophy. I like SW that is not bloated and does exactly what it was created for, is simple, small and fast - benapetr![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-51.svg)GitHub![](https://xen-orchestra.com/blog/content/images/thumbnail/1560121)](https://github.com/benapetr?ref=xen-orchestra.com) ## 🌐 Translations Xen Orchestra is used globally, and accurate translations are essential to ensure everyone can use it effectively. Here, we share the latest language updates and recognize the community contributors who help maintain these translations. Your work makes the platform more inclusive for all users. ### 16 languages updated A big thank you to our community for their ongoing efforts in translating Xen Orchestra! ![](https://xen-orchestra.com/blog/content/images/2026/01/687474703a2f2f7472616e736c6174652e76617465732e746563682f7769646765742f78656e2d6f72636865737472612f6d756c74692d6175746f2e737667.svg) Current XO translation status This month, lots of languages were updated: 16! Namely: **Czech, Danish, German, Spanish, Farsi, Finnish, Italian, Japanese, Korean, Norwegian (Bokmål), Dutch, Polish, Brazilian Portuguese, Russian, Swedish,** and **Ukrainian**. Want to help translate Xen Orchestra or improve existing translations? You’re more than welcome to join in [here](https://translate.vates.tech/?ref=xen-orchestra.com). ## 🆕 Misc Not every enhancement fits into a single category, but each one contributes to a better experience in your daily operations. This month, we gave particular care to how you can monitor storage and energy consumption, with access to even more metrics. ### SR capacity metrics The OpenMetrics plugin now exposes capacity information for Storage Repositories, not just performance data. Until now, SR metrics were limited to I/O statistics like IOPS, throughput, and latency, which meant storage usage itself was not visible in Prometheus. ![](https://xen-orchestra.com/blog/content/images/2026/01/xcp_sr_virtual_size_bytes.png) ![](https://xen-orchestra.com/blog/content/images/2026/01/xcp_sr_physical_size_bytes.png) ![](https://xen-orchestra.com/blog/content/images/2026/01/xcp_sr_physical_usage_bytes.png) SR capacity metrics exposed by the OpenMetrics plugin Three new metrics are now available: the virtual allocated size, the physical size of the SR, and the actual physical space used. Together, they make it easier to track capacity and anticipate saturation. This closes an important visibility gap and brings storage monitoring closer to what operators expect from a production-ready observability setup. ### Energy insights in DC Scope DC Scope in Xen Orchestra now provides energy consumption estimates, using minimum and maximum power values. This gives you an instant view of potential energy use, without manual calculations or using external tools. ![](https://xen-orchestra.com/blog/content/images/2026/01/capa2_xo.png) ![](https://xen-orchestra.com/blog/content/images/2026/01/dashboard2_xo.png) Preview of DC Scope in Xen Orchestra With this feature, you can plan more efficiently and monitor infrastructure sustainability. Plus, you can optimize both costs and environmental impact. ### Move management IP to another PIF You can now move a host’s management IP from one PIF to another directly, without having to remove and recreate it. 💡 ****Note** For now, you can only move a management IP to another PIF by using the API. We’re planning a future update so you can do it from the Xen Orchestra interface as well. This feature was developed in response to a user request submitted to our support team. Community feedback is a primary driver behind our roadmap. We’re constantly refining Xen Orchestra and the API, based on how you use it in the real world, from small workflow tweaks to major new capabilities. ### Xen Orchestra 6.0 URL: https://xen-orchestra.com/blog/xen-orchestra-6-0/ Last updated: 2025-12-18T16:03:31.000Z 🎵 The podcast version of our release is available on [Spotify](https://open.spotify.com/episode/7vpsC35XlZYOr1b1Arytiv?si=D6Z9XixSSx6h0xAiBlFIiw&ref=xen-orchestra.com). For more than a decade, Xen Orchestra has grown alongside the infrastructures it manages. What started in 2015 as a straightforward management layer for Citrix Hypervisor, and later for XCP-ng in 2018, has progressively become a critical control plane for production environments, sometimes spanning hundreds of hosts and thousands of virtual machines. Over the past few years, both Vates and its users have entered a new phase. Infrastructure sizes have increased, operational expectations have risen, and virtualization is now deeply intertwined with automation, security, DevOps practices, and long-term scalability concerns. These changes did not happen overnight, and neither did Xen Orchestra 6. ![](https://xen-orchestra.com/blog/content/images/size/w2000/2025/07/before-after-xo-6-min.png) Xen Orchestra 6 is the result of several years of anticipation, design, and groundwork, and we are genuinely proud to finally announce its very first release. This is a major architectural evolution, built to provide stronger foundations for large-scale environments, clearer operational visibility, and a platform that can sustainably evolve alongside our users’ needs in the years to come. At the same time, our commitment to open source remains unchanged. Xen Orchestra 6.0 is released under the same licenses as Xen Orchestra 5.0\. All features remain available to anyone building from source, just as they always have been. This new version is not only about scale and architecture: it also brings many improvements in features, usability, and overall ergonomics, making Xen Orchestra 6.0 a powerful and accessible tool for our community users as well - and yes, it finally comes with the long-requested tree view. With Xen Orchestra 6.0, we are opening a new chapter, one that continues to be shaped by our users, our community, and a shared belief that open source remains the strongest foundation for sustainable infrastructure software. As this year comes to a close, we want to sincerely thank everyone: our community users, our customers, and our amazing teams, who are about to enjoy a well-deserved break during the holiday season. 2025 has been an incredible year, with many milestones and new features delivered. And 2026 is shaping up to be even more exciting, because of all of you. **Thank you**. ## 👨‍🚀 Project & Community But Xen Orchestra 6.0 isn't the only news for today. Santa also bring many other cool surprises for this latest 2025 release. Buckle up! ### XCP-ng 8.3 last 2025 update The December 2025 update for XCP-ng 8.3 LTS delivers important security and maintenance fixes and requires a host reboot. [December 2025 Security and Maintenance Updates for XCP-ng 8.3 LTSNew security and maintenance updates are available for XCP-ng 8.3 LTS.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-36.png)XCP-ng BlogSamuel Verschelde![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1585776245991-cf89dd7fc73a-1)](https://xcp-ng.org/blog/2025/12/18/december-2025-security-and-maintenance-updates-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) It includes updated AMD microcode addressing entropy issues on some Zen 5 CPUs, along with a low-priority Xen security fix. The update also refreshes UEFI Secure Boot certificates for guest VMs, increases the supported number of virtual NICs per VM (16!), and updates Broadcom drivers in the installer to improve hardware compatibility. And since Christmas is just around the corner, we also managed to ship improved performance for resumed and migrated VMs thanks to superpage restoration support, along with the latest XO Lite version and an updated release of the Windows guest tools. 💡 Remember that since last month, Windows guest tools are now included in the bundled guest tools ISO, available out of the box with XCP-ng! ### XCP-ng 9.0 early demonstrator We’ve published an early demonstrator of **XCP-ng 9.0** to expose the technical direction early and gather community feedback. It’s built on a more modern base: Linux 6.12, Dom0 is loosely based on Alma 10 etc. Many things are **known not to work** (see the dedicated thread on XCP-ng forums below), and many others are incomplete or untested. We are **far below** the alpha quality level we usually target before public releases. Keep that in mind before testing or reporting issues. [XCP-ng 9.0 demonstrator- early previewContext We are making available a very first XCP-ng 9.0 demonstrator. This is not an alpha, not a beta, and not even the beginning of a production-ready path…![](https://xen-orchestra.com/blog/content/images/icon/512-14.png)XCP-ngolivierlambert![](https://xen-orchestra.com/blog/content/images/thumbnail/1-profileavatar-1620659303584-6.jpeg)](https://xcp-ng.org/forum/topic/11698/xcp-ng-9.0-demonstrator-early-preview?ref=xen-orchestra.com) ### XCP-ng QCOW2 release candidate Our QCOW2 format support has now reached **release candidate** status, in other words, the final step before general availability. We encourage you to test it and report your feedback: the more testing we get, the faster it can reach production in XCP-ng 8.3 in the coming months. [Dedicated thread: removing the 2TiB limit with qcow2 volumesHello everyone, The QCOW2 feature allow to use QCOW2 as the virtual disk format instead of VHD. VHD was used for all drivers to allow for implementing some f…![](https://xen-orchestra.com/blog/content/images/icon/512-15.png)XCP-ngtsukraw![](https://xen-orchestra.com/blog/content/images/thumbnail/2695-profileavatar-1.jpeg)](https://xcp-ng.org/forum/post/100844?ref=xen-orchestra.com) ### Xen at the Open Source Summit Japan Xen had a strong presence at **Open Source Summit Japan 2025**, with a clear focus on open automotive innovation. Talks and discussions highlighted concrete progress around secure, isolated, and safety-oriented systems, and showed how Xen is increasingly adopted in real-world automotive and embedded environments. [OSS Japan 2025: A Breakthrough Year for Open Automotive InnovationThe Xen Project is back from Open Source Summit Japan and Automotive Linux Summit 2025\. This year’s event felt like a true watershed moment for the automotive industry and for open source. Across talks, demos, and hallway conversations, one thing was clear: open source is now a foundational pillar![](https://xen-orchestra.com/blog/content/images/icon/apple-touch-icon-16.png)Blog - Xen ProjectCody Zuschlag![](https://xen-orchestra.com/blog/content/images/thumbnail/Dom0less-and-Deterministic--OSSJ26-.jpg)](https://xenproject.org/blog/oss-japan-2025-a-breakthrough-year-for-open-automotive-innovation/?ref=xen-orchestra.com) 🎫 In January 2025, Vates organized the [Xen Winter Meetup](https://xcp-ng.org/blog/2025/02/11/xen-winter-meetup-2025-a-recap/?ref=xen-orchestra.com) to bring together Xen Project developers and contributors, creating space for in-depth discussions, knowledge sharing, and groundwork on future directions. The event was a great success, and we are happy to share that it will return in 2026 as the ****Xen Spring Meetup**, once again in Grenoble, in the heart of the French Alps. This new edition will be organized by the ****Xen Project team**, with Vates strongly committed to supporting the event and contributing to making it another successful gathering for the Xen community. ### Playtonic Games: open source that keeps up with production Playtonic Games runs a production environment where infrastructure must stay out of the way. With XCP-ng and Xen Orchestra, they operate a stable, predictable platform with reliable backups, fast restores, and simple day-to-day operations, even under constant load. [How Playtonic Games modernized its infrastructure with XCP-ng and Xen OrchestraAbout Playtonic Games Playtonic Games is an independent game studio with a compact but highly technical team. Their virtualized environment supports development pipelines, internal services, testing workflows and day-to-day collaboration. VMware was the default choice… until it wasn’t. Home | Playtonic GamesPlaytonic Games Why leave VMware? During our conversation with![](https://xen-orchestra.com/blog/content/images/icon/logo64-28.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/game.webp)](https://vates.tech/blog/how-playtonic-games-modernized-its-infrastructure-with-xcp-ng-and-xen-orchestra/?ref=xen-orchestra.com) ### Festival de Cannes: when reliability is non-negotiable At the Festival de Cannes, infrastructure must work without exception. Xen Orchestra is used to operate and monitor critical workloads, providing clear visibility and reliable backup workflows in an environment where downtime is not an option. [Festival de Cannes chooses Vates VMS for its IT stackHow the Festival de Cannes modernized its IT infrastructure with Vates VMS, relying on open source, reliable backups and a resilient virtualization stack.![](https://xen-orchestra.com/blog/content/images/icon/logo64-29.png)Vates BlogClément Schilling![](https://xen-orchestra.com/blog/content/images/thumbnail/festival-de-cannes-vates-vms.jpg)](https://vates.tech/blog/how-the-worlds-most-iconic-film-event-modernized-its-virtualization-stack-with-vates-vms/?ref=xen-orchestra.com) ## 🎫 Events This year was rich in events! And it will be even richer in 2026. ### Vates at Open Source Experience 2025 We took part in the 2025 Open Source Experience (OSXP) in Paris, where our DevOps team discussed how the Vates VMS stack — including Xen Orchestra — fits into modern DevOps and cloud-native workflows. We covered our API-first approach, infrastructure-as-code integrations like Terraform and Pulumi providers, how XO’s REST API supports these use cases, and where we see the stack heading next. ![](https://xen-orchestra.com/blog/content/images/2025/12/osxp1.webp) **Missed the event?** You can still review the presentation slides — available online in French — to catch up on all the details: [OSXP - Vates VMS - Décembre 2025 - vates.tech![](https://xen-orchestra.com/blog/content/images/icon/favicon-33.ico)vates.tech](https://talks.vates.tech/2025/osxp%5Fdevops%5F20251211?ref=xen-orchestra.com) ### API days feedback ![](https://xen-orchestra.com/blog/content/images/2025/12/APIDAYS---DAY-2-219.jpg) Vates was also present at **API Days Paris**, an event focused on APIs, automation, and modern integration practices. It was an opportunity to exchange with a broader tech audience on infrastructure automation, observability, and how open platforms like XCP-ng and Xen Orchestra integrate into complex, API-driven environments. ### More to come in 2026 In 2026, we’ll continue engaging with the community at key events such as **FOSDEM**, **InCyber**, and **Tech&Fest**, with additional events planned, particularly in the **United States**. --- # XO 6.0 Let's talk about the elephant in the room: this is it. XO 6.0\. Let's go in details about what it means! But first, a mandatory disclaimer: ## ⚠️ Disclaimer Please read that carefully! - XO 6 by default is ONLY available on the `latest` release channel (see below). If you are on `stable`, nothing changes. - XO 6 is currently designed **for administrators only** and is not yet intended for regular or less technical users. - The interface remains primarily for "read" operation. Most day-to-day operations and changes should still be performed in the XO 5 interface until our next monthly releases. - **License management is not yet available** in XO 6\. All licensing actions must continue to be handled through the XO 5 interface. ### A note about feedback and support XO 6 is still evolving, and we really value your feedback. If you run into issues, unexpected behavior, or have suggestions, please **do not open a support ticket on our support portal** for XO 6. Alongside Xen Orchestra 6, we are launching a dedicated feedback platform to better capture how XO6 is used in real-world environments and to help us prioritize what comes next. This tool allows users to submit ideas, report friction points, and upvote existing requests so that the most impactful topics naturally rise to the top. 💡 This helps us prioritize the roadmap based on actual usage and collective user feedback, rather than assumptions. [Vates VMS feedbackWelcome! This page collects feedback from all our users across the Vates VMS stack, from XCP-ng to Xen Orchestra 6, including XOSTOR and our other pro![](https://xen-orchestra.com/blog/content/images/icon/qZprAll0bofaK77abT3Hg93cBpodHgaHZDLk2GsiR40oQ1RNVD9xs84LBJcJYOXO-logo400.png)![](https://xen-orchestra.com/blog/content/images/thumbnail/qZprAll0bofaK77abT3Hg93cBpodHgaHZDLk2GsiR40oQ1RNVD9xs84LBJcJYOXO-logo400.png)](https://feedback.vates.tech/?ref=xen-orchestra.com) Participating is simple: log in using one of the available third-party options (Discord, GitHub, …) or create an account with your email, browse existing feedback, upvote what matters most to you, or submit a new suggestion if it hasn’t been raised yet. You can also share your overall experience with XO6 in the dedicated forum thread here: [🛰️ XO 6: dedicated thread for all your feedback!End of November: XOA admin users on the latest channel will see a new option in the left-hand menu to access XO 6\. XO 5 will remain the default interface,…![](https://xen-orchestra.com/blog/content/images/icon/512-11.png)XCP-ngolivierlambert![](https://xen-orchestra.com/blog/content/images/thumbnail/752-profileavatar-1665407860052.jpeg)](https://xcp-ng.org/forum/topic/11604/xo-6-dedicated-thread-for-all-your-feedback/2?ref=xen-orchestra.com) Thanks for helping us shape what comes next! ### Switching back to XO 5 If you need to return to the XO 5 interface (whether temporarily or permanently) you can easily do so by adjusting your Xen Orchestra configuration. All the necessary steps are explained in the technical documentation (as we explained in [last month's blog post](https://xen-orchestra.com/blog/xen-orchestra-5-113/#switching-back-to-xo-5)): [Configuration | Xen Orchestra | XO DocumentationOnce Xen Orchestra is installed, you can configure some parameters in the configuration file. Let’s see how to do that.![](https://xen-orchestra.com/blog/content/images/icon/favicon-31.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-18.png)](https://docs.xen-orchestra.com/configuration?ref=xen-orchestra.com#using-xo-5-as-the-default-interface) ### Choosing your release channel As a reminder, you can switch your Xen Orchestra release channel at any time to follow a different update track. The process is simple and fully documented here: [Updates | Xen Orchestra | XO DocumentationAll updates are pushed through the updater, which is the central piece that keeps your XO Appliance running the latest Xen Orchestra code.![](https://xen-orchestra.com/blog/content/images/icon/favicon-32.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-19.png)](https://docs.xen-orchestra.com/updater?ref=xen-orchestra.com#release-channel) 💡 We'll continue to make XO 5 ****as default** on `stable` release channel until we are happy with it, limiting the change for people who want to be on `latest`. ### What's next? Many things in the pipes, each month will see more features available in XO 6\. Even themes! If you feel adventurous, you can already tinker with the colors via the `@xen-orchestra/web-core/lib/assets/css/_colors.pcss` file. We'll have a theme selector later, but to give an you an idea, it could look like this: ![](https://nextcloud.vates.tech/index.php/apps/files_sharing/publicpreview/TERYTd6iwye52dY?file=/nord-dark.png&fileId=2700618&x=3840&y=2160&a=true&etag=f0ed2dac579c497790aaae055c27e51a) In short, January will bring a huge number of new features in XO 6\. Stay tuned! ## 🛡️ Security Nothing specific this month, outside the usual dependencies upgrade. By the way, **we are NOT affected by the React2Shell vulnerability (CVE-2025-55182).** ## 💾 Backup Various improvements on the backup side, mostly on listing speed but also more relevant errors when something happens. ### Faster Backblaze directory listing Previously, listing a directory in Backblaze required a full tree scan, which slowed down responses and added unnecessary load. Now, Xen Orchestra uses a lightweight cache stored in the xo-vm-backup folder. When XO needs to list a directory, it relies on this cache instead of triggering a full scan. The result is much faster listings and a smoother experience when browsing Backblaze backups. ## 🥝 Core UI As you can guess, most of the frontend work is now done on Core UI. Each month is delivering more and more components and features! ### `TaskItem` component We’ve added a new `TaskItem` component to the core interface. This component standardizes how tasks are displayed. It provides a unified structure for status, progress, and context. It ensures task-related views remain visually consistent and behave predictably all across XO. ![](https://xen-orchestra.com/blog/content/images/2025/12/523809653-f46d694b-2950-4138-9f80-c4dc00e59bc8.png) ![](https://xen-orchestra.com/blog/content/images/2025/12/523809718-b31b9615-db59-4f93-9301-760a2e6f161a.png) New TaskItem component in Xen Orchestra ## 🛰️ XO 6 Outside Core UI that's used for both XO Lite and XO 6, we also have specific XO 6 component. Let's see what's up in here! ### Smarter navigation tree The navigation tree now remembers which sections you’ve expanded or collapsed, so it stays exactly as you left it when you return. Now you won’t have to readjust the view every time. Also, we’ve improved filtering the same way. Any changes you make to the tree’s layout while filtering (like expanding or collapsing items) won’t affect your default view. Once you clear the filter, your original setup is instantly restored. This update makes navigating navigation smoother in day-to-day use, especially on large infrastructures. ### XO 6 is now the default on build Starting this month, if you clone the repository and run XO from source, XO 6 will launch by default. No extra flags or environment tweaks are needed. You’ll get the latest version right away. If you prefer to stick with XO 5 for now, that’s still possible: just adjust your local configuration to make it the default. This update makes it much easier to try XO 6 early, while keeping the classic version available for those who need it. To know more, check out the blog post from last month’s release: [Xen Orchestra 5.113XO 5.113 delivers the last set of features and fixes on the XO 5.x branch before the jump to XO 6\. Explore what’s new and see why we’re closing this chapter on a high note.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-30.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1524815605630-82d184233a02-1-1.webp)](https://xen-orchestra.com/blog/xen-orchestra-5-113/#default-to-xo-6-on-build-incoming) ### Task page Xen Orchestra now has a dedicated **Tasks** page, with a side panel for monitoring task details, errors and background activity. You can view running, completed, or failed tasks in one place, with clear status and progress details. The side panel lets you quickly check ongoing operations without interrupting your workflow. This gives better visibility into into lengthy tasks and and makes task tracking tracking more intuitive. ![](https://xen-orchestra.com/blog/content/images/2025/12/526593974-61c69e6c-7d8c-4b08-b893-31c7bc43d784.png) ![](https://xen-orchestra.com/blog/content/images/2025/12/526594035-8b472c30-d3e9-4e74-a048-a16b0f925ec2.png) ![](https://xen-orchestra.com/blog/content/images/2025/12/526594176-17794cc8-85c4-4b36-9b91-f410a8b2a1f6.png) ![](https://xen-orchestra.com/blog/content/images/2025/12/526594263-07bd2b9c-6527-4da8-93ab-729554a3b4d8.png) The new Task page, with its side panel ### Tasks tab for VMs, Hosts, and Pools On top of the new Tasks page, you can also access tasks directly from the **VM, Host and Pool views**, with the **new Tasks tab**. When you select one of those resources in the navigation tree, the Tasks tab displays a filtered table of all related tasks and subtasks. The table uses the same layout as the [Site → Tasks page](#task-page), but focused only on the selected resource. ![](https://xen-orchestra.com/blog/content/images/2025/12/526630399-c1a3cdef-be30-49a8-a4a5-86b90ba4bdea.png) ![](https://xen-orchestra.com/blog/content/images/2025/12/526630452-b402736c-de1b-45a6-a971-f8eb50696f12.png) ![](https://xen-orchestra.com/blog/content/images/2025/12/526630929-28dc601e-ecc9-44c9-9e28-4b8008430ed0.png) ![](https://xen-orchestra.com/blog/content/images/2025/12/526630966-83e8d8cc-cc9a-4ef2-9648-9d644a5439b2.png) ![](https://xen-orchestra.com/blog/content/images/2025/12/526631379-ea0c0964-eef3-48a5-8600-99655c780da4.png) ![](https://xen-orchestra.com/blog/content/images/2025/12/526631492-f05a57b6-cc54-4a35-bb89-b0db52bb0d98.png) Task view for a selected VM, host or pool This makes it easier to track activity for a specific VM, host, or pool without searching through the global task list or switching views. ## 🐦 VMware to Vates (V2V) Following major improvements over the past months, we are very happy with our migration success rate. While a few corner cases still remain (and continue to be addressed with ongoing monthly improvements) overall, we are genuinely pleased with how well the tool has progressed this year. ## 📡 REST API The REST API is a foundational component of XO 6\. While much of the work is not directly visible, we have highlighted a selection of changes that have a real, tangible impact. ### Better reactivity on XO tasks The REST API now pushes task updates as they happen, so you no longer need to repeatedly check for changes. This means you can track progress in real time—whether you’re monitoring a long-running operation or building tools that rely on the API. This makes it easier to track task progress in real time reduces unnecessary requests, and makes managing tasks smoother. You get faster feedback and the overall experience is more responsive. ## ☸️ DevOps tools Unlike most of our releases this year, this one focuses on something completely new and unrelated to Terraform or Pulumi. ### XO as OpenMetrics proxy Thanks to a new plugin, Xen Orchestra can now serve as an OpenMetrics proxy for host and VM metrics, simplifying integration with Prometheus. The plugin can be configured here: ![](https://xen-orchestra.com/blog/content/images/2025/12/image--19-.png) Instead of working directly with raw RRD data from XAPI (which is quick to retrieve but cumbersome to process) XO handles the heavy lifting for you. **A dedicated service collects RRD metrics from your hosts and VMs, enriches them with helpful metadata and labels, and presents everything in OpenMetrics 1.0 format**. This makes it easy for an external Prometheus instance to scrape the data. 💡 Don't forget to open the relevant port in your XOA to allow Prometheus to scrape data from it! Eg: `ufw allow 9004` in our previous screenshot. ![](https://xen-orchestra.com/blog/content/images/2025/12/image--17-.png) ![](https://xen-orchestra.com/blog/content/images/2025/12/image--18-.png) The service is fully managed by XO: it runs locally, provides health and metrics endpoints, and is accessible through XO at `/openmetrics`. From Prometheus’s perspective, all it needs to do is connect to XO, which automatically discovers hosts, fetches metrics at regular intervals, and converts them into a standardized, modern format. The end result is a seamless way to [monitor your infrastructure with Prometheus](https://prometheus.io/?ref=xen-orchestra.com). [The OpenMetrics project — Creating a standard for exposing metrics data![](https://xen-orchestra.com/blog/content/images/icon/logo.png)![](https://xen-orchestra.com/blog/content/images/thumbnail/logo-with-text.png)](https://openmetrics.io/?ref=xen-orchestra.com) ## 📖 Documentation & guides This month’s documentation updates are lighter, but include a key improvement to the REST API documentation. It's especially valuable if you’re building integrations or automations with Xen Orchestra. ### Updated REST API Documentation We’ve updated the REST API documentation to make it clearer and more up-to-date. In particular, it better explains how to authenticate with the API, use it in your daily workflows, and create or refresh authentication tokens. Finally, we’ve refreshed the instructions for accessing the interactive Swagger documentation. ![](https://xen-orchestra.com/blog/content/images/2025/12/Capture-d---cran-2025-12-18-080517.png) REST API documentation (preview) These improvements will help you get started and work with the API more efficiently. [REST API | Xen Orchestra | XO DocumentationWe originally developed our existing API to be used between the Web UI xo-web and the server backend, xo-server. That’s why it’s a JSON-RPC API connected via websockets, allowing us to update objects live in the browser. This is perfect for our usage, but a bit complicated for others.![](https://xen-orchestra.com/blog/content/images/icon/favicon-34.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-20.png)](https://docs.xen-orchestra.com/restapi?ref=xen-orchestra.com) ## 🔦 Community spotlight This month, we spotted an interesting new project for hardcore fans of thick clients: **XenAdminQt**, a cross-platform desktop client to manage XCP-ng. While it is not officially supported (just like XCP-ng Center), it offers another option if you really do not want to use XO Lite or Xen Orchestra. [New project - XenAdminQt - a cross-platform GNU/Linux, macOS, Windows native thick clientHello, I know some people here will absolutely hate the idea of reviving that old-school thick client (yes I am talking about XenAdmin), but there are also s…![](https://xen-orchestra.com/blog/content/images/icon/512-13.png)XCP-ngbenapetr![](https://xen-orchestra.com/blog/content/images/thumbnail/1765922296449-13314316-bcce-4dcb-8bd3-209f6770395a-image.png)](https://xcp-ng.org/forum/topic/11689/new-project-xenadminqt-a-cross-platform-gnu-linux-macos-windows-native-thick-client?ref=xen-orchestra.com) ![](https://xen-orchestra.com/blog/content/images/2025/12/df3b5fb0-c5e5-43cd-8b09-b3e78aa80b61-image.png) [GitHub - benapetr/XenAdminQt: Port of original C# WinForms XenAdmin into Qt so that it works natively on every OSPort of original C# WinForms XenAdmin into Qt so that it works natively on every OS - benapetr/XenAdminQt![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-44.svg)GitHubbenapetr![](https://xen-orchestra.com/blog/content/images/thumbnail/XenAdminQt)](https://github.com/benapetr/XenAdminQt?ref=xen-orchestra.com) ## 🌐 Translations This month, we are coming with more than 10 languages updated. Maybe our new yearly record? A big thanks to our community for their ongoing efforts in translating Xen Orchestra! ![](https://xen-orchestra.com/blog/content/images/2025/12/687474703a2f2f7472616e736c6174652e76617465732e746563682f7769646765742f78656e2d6f72636865737472612f6d756c74692d6175746f2e737667.svg) Current XO translation status This month, special attention was given to **Czech, Danish, Spanish, French, Italian, Korean, Norwegian (Bokmål), Dutch, Brazilian Portuguese, and Russian.** We also improved the documentation for contributors. There is now a dedicated menu entry for **“Instructions for translators”**, including a complete step-by-step guide. You can find all the details here: [Xen Orchestra/Xen Orchestra 6Xen Orchestra is being translated into 16 languages using Weblate. Join the translation or start translating your own project.![](https://xen-orchestra.com/blog/content/images/icon/weblate-180-8.png)WeblateMichal Čihař![](https://xen-orchestra.com/blog/content/images/thumbnail/open-graph-1.png)](https://translate.vates.tech/projects/xen-orchestra/xen-orchestra-6/?ref=xen-orchestra.com#information) ### Choosing the right backup strategy URL: https://xen-orchestra.com/blog/choosing-the-right-backup-strategy/ Last updated: 2025-11-28T14:49:33.000Z As an IT decision maker, designing an effective **backup strategy** requires balancing **cost**, **complexity**, and **business requirements**. **Xen Orchestra** provides a comprehensive suite of **backup** and **replication** options tailored to different **Recovery Time Objectives (RTO)** and **Recovery Point Objectives (RPO)** while optimizing operational costs. 💡 ****RTO** (**Recovery Time Objective*) and ****RPO** (**Recovery Point Objective*) are the two key metrics that shape any backup architecture. ## 🧭 Understanding your options [](https://gist.github.com/fbeauchamp/ede8e500e51c067ae716c4ad3c508db1?ref=xen-orchestra.com#understanding-your-options) Xen Orchestra offers five key capabilities that define a robust and modern **data protection** strategy: ### **1\. Traditional backups** Standard backup operations that create **point-in-time snapshots** of your virtual machines, stored on designated backup repositories. Exists in **Full** and **incremental** flavors. [Concepts | Xen Orchestra | XO DocumentationThis section is dedicated to all general concepts about Xen Orchestra backups.![](https://xen-orchestra.com/blog/content/images/icon/favicon-22.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-10.png)](https://docs.xen-orchestra.com/backups?ref=xen-orchestra.com) Learn more about backup types in the official backup overview ### **2\. Pool-to-pool replication** Scheduled **replication** of VMs between different **XenServer pools**, providing faster recovery capabilities with configurable replication intervals. Exists in **Full** and **incremental** flavors. Multiple backups and replication targets can be combined in the same backup job, reading the VM data only once, and using the same snapshot. ### **3\. Mirror backup** Secondary replication of existing backups to additional storage locations, creating multiple copies for **enhanced protection**. ### **4\. Immutable backups** **Write-once, read-many** backup storage that prevents tampering or accidental deletion, crucial for **ransomware protection**, even in case where XO is compromised. XO supports "**object lock**" from object storages (**S3**). Vates also provides separate scripts to build you own **immutable backup server**, completly disjoined from XO to ensure a XO compromission won't impact the data. 💡 ****Immutable storage is the most effective safeguard against ransomware**, even if your backup server or XO instance is compromised. [Immutability | Xen Orchestra | XO DocumentationWhat You’ll Find on This Page![](https://xen-orchestra.com/blog/content/images/icon/favicon-24.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-12.png)](https://docs.xen-orchestra.com/immutability?ref=xen-orchestra.com) How immutability works in XO ### **5\. Health check validation** Automated testing of backups and replicas to ensure **recoverability** when needed. **Advanced Health** check can ensure that the application layer is ready to start, instead of only checking for the VM ability to boot. ### **6\. Backup encryption** **Encryption** ensure any data from XO to and from the Backup Repository is encrypted. In addition to the obvious safety benefit, the **authenticated algorithm** used ensure the data at restore time are exactly how they were at the backup time, or at least raise an error. [docs(xo): add backup strategy guide by thomas-dkmt · Pull Request #8881 · vatesfr/xen-orchestraThis pull request adds a comprehensive "How to" guide for building a backup strategy. It covers: a glossary of backup types and features preparation steps before creating backups advanta…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-33.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/8881-1)](https://github.com/vatesfr/xen-orchestra/pull/8881?ref=xen-orchestra.com) These options are explained in more detail in the official documentation ## ⚙️ Cost-effective strategy framework [](https://gist.github.com/fbeauchamp/ede8e500e51c067ae716c4ad3c508db1?ref=xen-orchestra.com#cost-effective-strategy-framework) Your optimal **backup strategy** depends primarily on two metrics: **Recovery Time Objective (RTO)**, which determines how quickly you need systems operational after a failure, and **Recovery Point Objective (RPO)**, which defines how much **data loss** is acceptable in terms of time. Regardless of the values you set for RTO and RPO, industry best practices provide a baseline. The **3-2-1 rule** calls for three copies of critical data, stored on two different types of media or locations, with one of those copies kept **offsite**. The more advanced **3-2-1-1-0 rule** adds an **immutable** or **air-gapped** copy to protect against **ransomware** and demands zero errors through systematic **health check** validation. **Xen Orchestra’s** features align naturally with both frameworks. For example, a simple **backup job** targeting multiple **repositories** achieves the 3-2-1 setup, while **S3 object lock** or Vates’ **immutable backup scripts** enable compliance with the enhanced standard. 💡 The 3-2-1 baseline is the minimum viable protection against hardware failures, human mistakes, and ransomware. Even organizations with limited budgets should prioritize meeting the 3-2-1 baseline before exploring advanced optimizations. This ensures essential protection against common threats such as **hardware failures**, **human mistakes**, and **ransomware attacks**. ## 🏷️ Strategy profiles by business requirements [](https://gist.github.com/fbeauchamp/ede8e500e51c067ae716c4ad3c508db1?ref=xen-orchestra.com#strategy-profiles-by-business-requirements) The right combination of features depends on the **criticality** of your systems. For **mission-critical workloads (Tier 1)**, where **downtime** must be measured in minutes and **RPO** kept near zero, **pool-to-pool replication** with intervals of **15 to 30 minutes** is the most effective choice. These environments should also include **daily immutable backups**, **health checks** on both primary and replica systems, and ideally **mirror backups** to a third location. While this setup requires significant investment in **infrastructure** and **bandwidth**, it delivers maximum **resilience**—ideal for **financial systems**, **e-commerce platforms**, and **critical databases**. For **business-critical systems (Tier 2)**, a more balanced approach may be appropriate. **Hourly backups** paired with **replication every four hours**, **weekly immutable snapshots**, and **twice-weekly health checks** deliver strong protection without the overhead of a Tier 1 setup. This strikes a **cost-effective** balance for **ERP systems**, **collaboration platforms**, or **departmental databases**. **Standard business systems (Tier 3)**, where **RTO** and **RPO** can be measured in hours, may only need **daily backups**, **weekly full backups**, and **occasional replication**. Adding **monthly immutable snapshots** and **quarterly health checks** ensures protection without straining resources. Finally, **archival and compliance-focused systems (Tier 4)** usually only require **weekly backups**, **long retention policies**, and occasional **immutable** or **replicated copies**. The priority here is **long-term data integrity** at minimal operational cost rather than performance. 💡 Tier 1 to Tier 4 define how strict your RTO/RPO requirements are, and therefore how aggressive your backup and replication schedule must be. ## 🛡️ Hybrid protection: Combining VM-level and application-level strategies [](https://gist.github.com/fbeauchamp/ede8e500e51c067ae716c4ad3c508db1?ref=xen-orchestra.com#hybrid-protection-combining-vm-level-and-application-level-strategies) Xen Orchestra provides robust **VM-level protection**, but for some workloads—particularly **databases** and **transactional systems**—supplementing this with **application-level strategies** can significantly improve **RPO** and **recovery flexibility**. Consider a **PostgreSQL** or **MySQL** deployment using **write-ahead logging (WAL)**. While Xen Orchestra handles **daily VM backups** and **four-hour replications**, the database itself can continuously ship **WAL files** to a remote server. This **hybrid setup** allows **point-in-time recovery** within the WAL retention period, cutting potential **data loss** from hours to mere minutes. A similar approach benefits **Exchange servers**, where **transaction logs** can be backed up every fifteen minutes, ensuring minimal email loss even if a full VM restore is required. **File servers** and **ERP systems** also benefit from combining VM-level protection with **application-native exports** or **real-time synchronization**, allowing for faster and more granular **recovery**. The implementation of **hybrid protection** requires careful planning. First, identify applications that already provide **native backup options** and compare their **RPO requirements** with what VM-level protection can achieve. Then, integrate these two layers by maintaining Xen Orchestra as your primary **disaster recovery** platform while using **application-specific backups** for granular restore needs. **Scheduling** must be coordinated to avoid resource conflicts, and both recovery paths should be **tested regularly**. While this dual approach introduces additional **costs** and **complexity**, it is particularly valuable for **Tier 1 systems** where improved RPO is worth the investment. ## 🧩 Implementation strategy [](https://gist.github.com/fbeauchamp/ede8e500e51c067ae716c4ad3c508db1?ref=xen-orchestra.com#implementation-strategy) The first step in building a strategy is **assessment**. **Workloads** should be categorized according to their **business impact**, and **downtime costs** should be calculated to justify investment levels. **Compliance requirements** may also dictate specific approaches to **backup** and **retention**. When optimizing **storage**, **incremental backups** help minimize space requirements, while **compression** (zstd where available) reduces the footprint of **full backups**. **Retention policies** should be designed to match business needs, using a **tiered approach** that balances **daily**, **weekly**, and **monthly copies**. Use the right storage for the right needs, from **fast, near storage** to allow for **fast recovery**, to **slow** and **cheap** but durable **offsite storage** with **long term retention** for **archiving** and **retention**. **Network planning** is equally important: **pool-to-pool replication** requires sufficient **bandwidth**, and large **backup operations** should be scheduled during **off-peak hours**. Especially **offsite backup** can be the tie breaker between a job writing to multiple **backup repository** and multiple **backup and mirror jobs** chained. Finally, don’t rely on **automation** alone. **Alerts** and automated **health checks** are critical, but organizations should also perform periodic **full restore tests** and maintain up-to-date **documentation** for each **recovery procedure**. 🚀 Start with a strategy you can maintain consistently, then validate it through regular testing and health checks. ## 📌 Conclusion [](https://gist.github.com/fbeauchamp/ede8e500e51c067ae716c4ad3c508db1?ref=xen-orchestra.com#conclusion) Xen Orchestra's flexible **backup** and **replication** capabilities allow you to implement a **cost-effective strategy** tailored to your specific **business requirements**. By aligning your **backup approach** with actual **RTO** and **RPO** needs rather than applying a one-size-fits-all solution, you can optimize **costs** while ensuring adequate **protection**. The key is to start with a clear understanding of your **business requirements**, implement a **tiered approach** that matches protection levels to **business criticality**, and continuously validate that your **backup strategy** meets its objectives through regular **testing** and **health checks**. Remember: the best **backup strategy** is one that you can afford to **implement**, **maintain**, and rely on when **disaster** strikes. ### Xen Orchestra 5.113 URL: https://xen-orchestra.com/blog/xen-orchestra-5-113/ Last updated: 2026-07-15T06:49:51.000Z XO 5.113 is here. It's the final chapter in the XO 5.x saga. Over nearly ten years, 113 releases, and countless improvements, we’ve grown from a simple management interface to a full-fledged, enterprise-ready virtualization orchestration platform. This last 5.x release packs security hardening, backup reliability, major UI improvements, and paves the way for a smooth transition to XO 6. 🎵 The podcast version of our release is available on [Spotify](https://open.spotify.com/episode/5yV3hnMCDzV15ss9eTJ6b0?si=Ohzxe%5FcSQ6e%5FoYApiHIJbA&ref=xen-orchestra.com). ## 👨‍🚀 Project & Community Funny enough, even with several exciting announcements on the horizon, this section is still smaller than the feature-packed release notes that follow. So let’s kick things off here! ### Vates and Nexsan One of the big highlights this month is our partnership with Nexsan. Their Unity platform brings the kind of storage you actually want in production: predictable performance, multiple protocols built-in, and real data protection features that don’t get in your way. For XCP-ng and Xen Orchestra users, it simply means a storage backend that does the job, scales properly, and doesn’t trap you in anyone’s ecosystem. It fits naturally with what we’ve been building for years: an open, transparent, and reliable virtualization stack. [Vates & Nexsan Unity: Open virtualization meets proven enterprise storageVates and Nexsan join forces to deliver a validated, production-ready solution combining XCP-ng, Xen Orchestra, and Nexsan Unity storage, offering enterprise performance, data protection, and freedom from vendor lock-in.![](https://xen-orchestra.com/blog/content/images/icon/logo64-27.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/domaintechnik-ledl-net-VHmBX7FnXw0-unsplash.jpg)](https://vates.tech/blog/vates-nexsan-unity-open-virtualization-meets-proven-enterprise-storage/?ref=xen-orchestra.com) ### Ampere ARM processors: diversity in the datacenter Our work with Ampere Computing also continues to gain traction. Their ARM processors aren’t just “another CPU option”: they offer high core density, excellent efficiency, and a design that really shines in modern, scale-out environments. For Xen Orchestra users, this means something we care deeply about: choice. You’re not tied to x86 anymore. ARM is becoming a credible option for cloud-native workloads, edge deployments, or even just reducing your power consumption without sacrificing performance. 🎉 We’re extremely proud of this work, and there’s a lot of history behind it.We’ll share more along the way. [XCP-ng on Ampere Altra: Our First ARM Demo at KubeConA first look at XCP-ng running on Ampere Altra ARM servers.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-33.png)XCP-ng BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/futurearmdc.webp)](https://xcp-ng.org/blog/2025/11/13/xcp-ng-on-arm-with-ampere/?ref=xen-orchestra.com) More details about this incredible journey here ### New Windows PV driver release (9.1.100) Here comes a fresh release of our Windows PV drivers, with new features, lots of fixes, and all of it fully baked at Vates. With our ongoing upstream work, we’re really moving the needle on driver quality for the whole Xen ecosystem. Drivers can be found here: [Release 9.1.100 Release Signed · xcp-ng/win-pv-driversThis release brings multiple bug fixes to all Windows drivers and guest tools components. To download XenClean, click here. The installer downloads also includes a copy of XenClean and XenBootFix.…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-42.svg)GitHubxcp-ng![](https://xen-orchestra.com/blog/content/images/thumbnail/v9.1.100)](https://github.com/xcp-ng/win-pv-drivers/releases/tag/v9.1.100?ref=xen-orchestra.com) If you want to read the story on how we managed to do all of this, don't miss our previous blog post: [Signed Windows PV drivers now availableAfter years of work and collaboration with Microsoft, we are proud to announce that the XCP-ng Windows PV drivers are now officially signed and ready for production, marking a major milestone in our journey toward full stack independence.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-34.png)XCP-ng BlogTu Dinh![](https://xen-orchestra.com/blog/content/images/thumbnail/winpvsigned-1.webp)](https://xcp-ng.org/blog/2025/10/10/signed-windows-pv-drivers-now-available/?ref=xen-orchestra.com) ### Choosing the right backup strategy Backups aren’t a “feature”, they’re a strategy. And depending on your constraints, your infrastructure, and your recovery goals, the right approach might look very different from someone else’s. This is why Xen Orchestra doesn’t force you into a single model. You can go with full snapshots, incremental backups, replication, or long-term archiving, whatever matches your workload and risk profile. The idea is simple: the tool adapts to your environment, not the opposite. [Cost-Effective Backup Strategy with XenOrchestraXen Orchestra provides fast, flexible, and cost-efficient backup and replication to meet your RTO and RPO needs![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-28.png)Xen Orchestra BlogFlorent Beauchamp![](https://xen-orchestra.com/blog/content/images/thumbnail/fernando-lavin-RxHCRDO0psE-unsplash.jpg)](https://xen-orchestra.com/blog/choosing-the-right-backup-strategy/) ### Xen 4.21 Xen 4.21 is out, with broader architecture support and key performance improvements. As one of the top contributors and the team behind Xen’s release management, we’re proud to help drive the hypervisor forward. [Xen Project Delivers Xen 4.21, a Modernized Hypervisor with Broader Architecture Support and Improved PerformanceOpenSSF Announces Key Membership Growth and Golden Egg Award Winners at Open Source SecurityCon North America![](https://xen-orchestra.com/blog/content/images/icon/favicon-28.ico)The Linux FoundationThe Linux Foundation![](https://xen-orchestra.com/blog/content/images/thumbnail/Press-20Release-Nov-18-2025-08-39-28-3682-PM.png)](https://www.linuxfoundation.org/press/xen-project-delivers-xen-4.21-a-modernized-hypervisor-with-broader-architecture-support-and-improved-performance?ref=xen-orchestra.com) ### XO 6 is coming: phased rollout starts now We’re entering the final stretch for the transition to XO 6, and things will start moving quickly over the next few weeks. **End of November:** If you’re on the latest channel in XOA, you’ll notice a new entry in the left menu giving you access to XO 6\. XO 5 stays the default interface for now, but you can start testing XO 6 whenever you feel ready. For those running XO from the sources, the switch is even more direct: XO 6 becomes the default UI, with an easy link to jump back to XO 5 if needed. **End of December:** The latest XOA channel will make XO 6 the default interface as well. And just like before, XO 5 remains available anytime, no pressure, no forced switch. If you prefer the stable channel, nothing changes yet: it will continue using XO 5 by default. 👌 In short: XO 6 is rolling out smoothly, at your pace, with both interfaces available throughout the transition. --- ## 🎫 Events Curious where you can meet us next? #### 🇫🇷 **API Days (December 9-11, Paris, France)** We'll have [a talk and a panel discussion there](https://www.apidays.global/events/paris?ref=xen-orchestra.com). If you are in Paris at those date, it's the opportunity to connect! [Paris - 9 - 11 December 2025 | apidaysAs Europe’s capital of tech, policy, and innovation, Paris provides the perfect setting to explore the convergence of APIs and AI. At the heart of this intersection, apidays Paris sparks essential conversations on data security, digital sovereignty, and sustainable innovation in the age of intelligent systems.![](https://xen-orchestra.com/blog/content/images/icon/685423133b318819c046b678_Favicon-20apidays-1.png)Apidays![](https://xen-orchestra.com/blog/content/images/thumbnail/68969043ea069a6c1e8c4e23_b294a_apidays-20Paris-202025-1.avif)](https://www.apidays.global/events/paris?ref=xen-orchestra.com) ### We've been there! #### 🇺🇸 KubeCon North America 2025 We were present at KubeCon with our own booth. We highlighted our work around **XCP-ng on ARM with Ampere processors**, showing how our stack is evolving to support modern ARM-based infrastructures and giving attendees a preview of what’s coming. [See more here.](https://xcp-ng.org/blog/2025/11/13/xcp-ng-on-arm-with-ampere/?ref=xen-orchestra.com) ![](https://xcp-ng.org/blog/content/images/2025/11/vates-and-ampere-kubecon-atlanta-1.png) #### 🇱🇺 **Luxembourg Internet Days 2025 (with C2D IT Solutions)** We were also involved through our partner C2D IT Solutions, who presented our solutions and engaged with organizations interested in open virtualization and infrastructure flexibility. --- # XO 5.113 **The final lap for the XO 5.x saga!** Release **5.113** marks the end of the line: the next stop is **XO 6.0**. That’s **113 releases** on the XO 5 branch, nearly a full decade of work (we’re only a few releases short of what would have been 120 in 10 years!). When we started XO 5, we definitely didn’t expect it to carry us this far. The amount of functionality added over these years (all while staying within the same UI and architecture) is honestly wild. As usual, our official changelog can be found here: [xen-orchestra/CHANGELOG.md at master · vatesfr/xen-orchestraThe global orchestration solution to manage and backup XCP-ng and XenServer. - vatesfr/xen-orchestra![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-43.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/6dcf71fd-bad9-4bfa-933f-b466c52d513d)](https://github.com/vatesfr/xen-orchestra/blob/master/CHANGELOG.md?ref=xen-orchestra.com#51130-2025-11-27) ## 🛡️ Security As always, we’re tightening things up on the security side. ### Updated xml2js Dependency We’ve upgraded xml2js to a safe, modern version, since anything below `0.5.0` carries a known moderate vulnerability. The update removes that risk and keeps our dependency stack aligned with current security standards. As part of the change, we checked the components still relying on older versions to ensure nothing breaks. Everything continues to behave as expected, just with one less security concern hanging around. ### VSA-2025-003 We've published a new security notice to the Vates VMS documentation platform: this page includes a detailed breakdown of the vulnerability known as **VSA-2025-003,** including affected components and potential impact, along with clear, actionable recommendations to secure your environment. This notice follows our commitment to transparency and proactive security. Admins and operators are encouraged to review it immediately to assess exposure and apply necessary measures. Click the link below to read the notice: [VSA-2025-003: Xen Orchestra SAML plugin Vulnerability | Vates VMS Documentation2025-11-04 / Important severity / Xen-Orchestra prior to 5.111.1 affected.![](https://xen-orchestra.com/blog/content/images/icon/vates-logo-128-c064bc94b81bd09a913e2c5208f3ce7b8a198b8db413b18d4a0ddd5f7f330a2e.png)Vates VMS Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-logo-128-c064bc94b81bd09a913e2c5208f3ce7b8a198b8db413b18d4a0ddd5f7f330a2e.png)](https://docs.vates.tech/trust-roadmap/security-advisories/advisories/2025/vates-sa-2025-003?ref=xen-orchestra.com) ## 💾 Backup Nothing flashy this time: just solid under-the-hood fixes and stability boosts. ### Long-term Retention fixes We've resoled inconsistencies with long-term retention backups. Previously, some configurations incorrectly retained the *last* backup of the day instead of the first. Automated tests failed unexpectedly, and in rare cases, no LTR backups were preserved at all. These issues have been fully addressed. LTR now accurately selects and retains the correct backups, tests validate successfully, and retention policies apply consistently across all environments. . This makes long-term backup strategies far more predictable and trustworthy. ## 🥝 Core UI Core UI is the next-gen common UI for both XO 6 and XO Lite. ### Switch from XO 5 to XO 6 On top of the fallback link to XO 5 (see the [XO 6 section](#seamless-fallback-to-xo-5)), we've added a link that lets you switch back to XO 6 at all times. The link stays visible in the XO 5 header, so you can go back to the new, default XO 6 experience with just one click. Previously, this option only worked the other way, from XO 6 to XO 5. ![](https://xen-orchestra.com/blog/content/images/2025/11/510061508-f3712720-3514-4d4f-8637-ded680d3292d.png) Switch to go back from XO 5 to XO 6 ### Redesigned Pool Hosts tab We've completely refreshed the **Hosts tab** in the **Pool** view to align with XO 6’s modern design. The tab was already there, but its layout and structure didn’t fit the new UI direction, so it’s been refactored for consistency and readability. ![](https://xen-orchestra.com/blog/content/images/2025/11/515256791-9244b32c-39ab-4765-ba0c-327806305e43.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/515256862-aa62a282-7b9c-4bd5-913b-f65a914e6d8a.png) Hosts tab prior to the update ![](https://xen-orchestra.com/blog/content/images/2025/11/515257024-7331d161-6aa9-4c5f-814b-435dd213541f.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/515257123-e3418337-0a88-4354-8ec2-1e770604f5c2.png) Hosts tab since the new update ### Shared TypeScript definitions XO 6 and XO Lite now rely on the common `@vates/types` package for their TypeScript definitions. Instead of maintaining separate sets of types on the frontend and backend, both sides now pull from the same source of truth. This removes duplicate definitions and makes the whole codebase a bit more predictable. It also simplifies cross-project work, since updates to shared types automatically propagate where they’re needed. ## 🛰️ XO 6 As you can see, development on XO 6 is now moving at full thrust. ### Default to XO 6 on build incoming From December 2025 onwards, cloning the repo and running XO from source will launch XO 6 by default. You won't need to set extra flags or environment variables anymore. We are removing the unnecessary steps so that you can immediately experience the next generation of Xen Orchestra. If you really want to continue with XO 5, it’s okay, just modify your local configuration to have it as the default. This change makes early access to XO 6 effortless, while those who want to stay with the classic version still have the ​‍​‌‍​‍‌option. ### Seamless fallback to XO 5 Since XO 6 is still in its MVP phase, some actions and views aren’t fully available yet. To keep your workflow uninterrupted, the UI now automatically links to the equivalent XO 5 page whenever you hit an unsupported feature. ![](https://xen-orchestra.com/blog/content/images/2025/11/511354993-8f583a04-2be3-4505-9570-50978cedeedb.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/511355007-c0559186-07bd-4e87-b4bb-d042971744ef.png) Fallback links from XO6 to XO5 This means you can explore XO 6 freely, and if you hit a missing feature, you’re just one click away from the XO 5 version. ### Real-Time UI updates Whenever changes occur in the backend, the XO 6 interface **will now update instantly**. With this new, real-time responsive system, you won't have to refresh manually anymore. Under the hood, we leverage the latest improvements in our REST API for reactivity. Views subscribe to the `/rest/v0/events` stream and receive updates the moment they’re pushed. XAPI Objects (VMs, hosts, SRs, VDIs, etc.) refresh fluidly, while the frontend manages subscriptions intelligently and clean up to optimize performance and avoid unnecessary re-renders. ### VDI Tab in the VM page A new **VDI tab** is now available when you open a VM in the treeview. It gives you a direct, consolidated view of all disks attached to that VM, along with its associated VDI tasks. ![](https://xen-orchestra.com/blog/content/images/2025/11/Screenshot-from-2025-11-27-08-52-14.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/Screenshot-from-2025-11-27-08-52-31.png) VM details showing the new VDI tab Instead of jumping around pool-level views to track storage details, everything is now in one place. It’s a cleaner way to inspect and understand a VM’s disk footprint from the VM page itself. ### Host and Pool VM tabs We've revamped the VM tab in the **Host and Pool views.** The idea is to match the current XO 6 design and offer a clear picture of the VMs tied to each resource. When you select a host, the VMs tab now shows a table listing every VM running on that machine. Same thing at the pool level: open a pool and switch to the VMs tab to see an updated, consistent view of all VMs in that pool. These pages already existed, but were rebuilt to fit the new layout and provide a more readable experience across the treeview. ![](https://xen-orchestra.com/blog/content/images/2025/11/515843021-10616f70-c71d-4441-822c-700516cd3883.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/515843101-9bc5d698-eff3-4b8d-9cb2-5e8496b13edf.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/515843499-cdac2aba-56bc-4433-ac94-ea66276d170c.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/515843544-e5bf8c29-8fe1-4a0a-a132-a2e07e59fd33.png) VM views prior to the update ![](https://xen-orchestra.com/blog/content/images/2025/11/516137100-53a542f1-953b-44a8-b5e7-07eb72586fbd.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/516137211-6aaff7f8-f234-4d9c-a8fb-3108018bcf12.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/516137612-aec34dd1-c1b2-42e5-aeab-9e7475918bce.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/516137712-7c844ddf-6df3-4a9d-af67-81ec27b1ffe7.png) VM views since the update, with the new design ### Site-level VM and Host tabs Site pages in XO 6 now include dedicated VMs and Hosts tabs. This way, you can see everything running in a site without navigating further down the tree view. Select a **Site** and open the **VMs tab** to see a clean table listing all VMs associated with that site. The **Hosts tab** works the same way, and gives you a full view of every host belonging to that site. ![](https://xen-orchestra.com/blog/content/images/2025/11/515794804-510dd2dd-e8be-432e-a8ca-ec31163bde95.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/515794950-23d125a5-33a7-4c30-99f4-e868c88cfb09.png) VM tab in the Site view ![](https://xen-orchestra.com/blog/content/images/2025/11/514459300-347d15ff-8385-484d-b1aa-f1f26df33a24.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/514459271-b20c7c01-bbab-4b7b-b8c9-7aa09d622270-1.png) Host tab in the Site view These improvements bring the Site view in line with the rest of the XO 6 design and make navigation more intuitive. ### Centralized settings page XO 6 now has a proper Settings page that brings all the essentials together in one place. Instead of digging through various menus, you can quickly check both XO/XOA and XCP-ng versions, jump to news, docs, community forums, support pages, or the API Swagger, all from the same screen. The page also lets you set your preferred theme (light, dark, or automatic) and pick your display language. ![](https://xen-orchestra.com/blog/content/images/2025/11/510755309-cc9edca8-2817-452c-bfe1-fd21be8b20f5.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/510755504-55f3f4ec-4a78-4b62-aa30-4db44a99421e.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/510756370-8f88ecde-2122-43e2-b72d-7a54ad03b4aa.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/510756549-4c7e68ff-20e7-4356-9a9f-f983811975d2.png) New Settings page in XO 6 ### Clearer backup mode labels We've replaced ambiguous or overly technical terms for backup modes. Some of the previous labels in the backup list page were a bit unclear or too technical, so the terminology has been refreshed to better reflect what each mode actually does. Here's what changes: - Disaster Recovery becomes **Full replication.** - Continuous replication becomes **Incremental replication.** - Mirror backup and Full backup become **Mirror full backup.** - Mirror backup and Incremental backup become **Mirror incremental backup.** We've also removed the "Metadata backup" wording for the **Pool metadata** and **XO config backup** modes. Finally, we've updated how backup modes appear in backup job lists. Instead of tag lists, they now appear as simple lists: ![](https://xen-orchestra.com/blog/content/images/2025/11/511413741-7037547e-35dc-42bb-803e-11e9139b81e7.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/511413792-7e5e4936-f564-4694-8213-2153155d899a.png) Backup modes previously appearing as tag lists ![](https://xen-orchestra.com/blog/content/images/2025/11/511413238-48757778-a6c0-4db0-be76-c8119d6352dc.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/511413337-45de2b74-d6e6-4de3-9d50-96530612b995.png) Backup modes appearing as simple lists Nothing changes in how backups work under the hood. The goal is simply to make the list more readable so you can immediately tell how each job is configured without second-guessing the terminology. ### VM creation form notice The VM creation form in XO 6 is currently in its MVP phase. As a result, it now includes a clear notice about its limitations. This banner outlines unsupported features —such as cloud-init configuration, advanced options, or vTPM management — and provides a direct link to the fully featured XO 5 form, with the correct pool preselected for convenience. ![](https://xen-orchestra.com/blog/content/images/2025/11/513247673-15b6685e-30e5-4dde-92da-629d777b918f.png) Notice on current XO 6 limitations, on the VM creation form This ensures you know exactly what to expect while we continue enhancing the XO 6 form, with the complete version scheduled for 2026. ### VM boot firmware option The VM creation form now includes the **Boot firmware** field. You can choose the firmware you want your VM to use, directly during setup, instead of relying on defaults or switching back to XO 5. ![](https://xen-orchestra.com/blog/content/images/2025/11/507605219-7a8780f1-9a23-4902-95dd-a46d20f296ea.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/507605379-a930488f-b52c-4d06-9dc3-b6f77f2c8272.png) Boot firmware option when creating VMs in XO 6 This addition brings the form closer to feature parity with XO 5 and gives you proper control over how new VMs start up. ### Host and Pool Storage tabs We've added a **Storage tab** for both the **Host and Pool views** in XO 6\. Selecting a host or a pool now gives you a dedicated tab listing all storage repositories connected to them. ![](https://xen-orchestra.com/blog/content/images/2025/11/515128681-8ebc9f7c-4735-4ca4-929b-d7e7ba75b2b4.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/515128864-849f518a-818a-4794-9b3d-f153c92b0c9c.png) Storage tab in the Host view ![](https://xen-orchestra.com/blog/content/images/2025/11/515126883-87d1b517-ef6b-427b-b9e3-e08ae6c94233.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/515127324-b652fab4-bb9f-4b22-b6d3-f9b7c86b97e2.png) Storage tab in the Pool view These additions let you inspect storage repositories directly from the treeview, without drilling down into individual hosts or unrelated pages, for a more straightforward workflow. ## 🐦 VMware to Vates (V2V) Our V2V tool also received important improvements. First, we now properly handle disks that aren’t aligned on 2 MB boundaries, which significantly increases migration success rates and fixes cases where exports could get stuck. And on top of that, warm migration is now supported even on older ESXi versions (including ESXi 6) expanding compatibility for smoother VMware-to-Vates transitions. ## ⚖️ Load balancer Guess what? Load balancer updates are back! ### Affinity rule option In the `load-balancer` plugin for Xen Orchestra, you’ll now find a new **Affinity rule** option (in addition to the existing **Anti-affinity rule**). With this setting, you can guide VMs to land on the *same* host when it makes sense. ![](https://xen-orchestra.com/blog/content/images/2025/11/501531482-be6b8891-319a-4a59-93ce-0bca83c09ec6.png) New Affinity rule option in the load-balancer plugin This new rule gives you more flexibility in how you group VMs across hosts, which is useful when you have workloads that benefit from being together (e.g., low-latency inter-VM comms) instead of always trying to spread them. ## 🪐 XOA This release also brings an important improvement to how we ship XOA. ### Automated XOA image builds The release process for Xen Orchestra appliance (XOA) images has been fully automated. Previously, although nightly builds were generated automatically, promoting a version to stable required manual coordination between quality assurance and DevOps teams. As of this release, the entire workflow (including image build, testing, and publication) is **now triggered automatically as part of the stable release process**. This ensures that every Xen Orchestra release is accompanied by its corresponding, validated XOA image without delay. The change streamlines operations, minimizes potential errors, and guarantees that users receive a consistent, up-to-date appliance image with each release. ### DC Scope and DC NetScope access buttons XO 6 now has a **Third party apps** dropdown in the header, which lets you reach DC Scope and DC NetScope directly from the interface. If these EasyVirt tools are already deployed, the links open their dashboards right away. If not, you’ll be redirected to the deployment interface, in the XO 5 interface (for now). ![](https://xen-orchestra.com/blog/content/images/2025/11/518562414-6ba7e393-6d1c-4aeb-ac90-9116f91352dc.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/518562517-df37c39a-1fbb-4a5b-8490-595ff0e08db0.png) Third party apps dropdown menu This makes the EasyVirt integration much more visible and saves you from searching through menus to find or deploy DC Scope or DC NetScope. ## 📡 REST API Last month was a huge leap for the REST API: this release keeps the momentum going on top of those solid foundations. ### VM dashboard endpoints The VM dashboard is now available through the REST API. Existing JSON-RPC endpoints have been migrated, and the missing ones have been added so the dashboard can be fetched cleanly and consistently over REST. This gives you direct access to all the usual VM dashboard details without relying on legacy calls. As a result, experience becomes more modern, stable, and easier to integrate with external tools. ![](https://xen-orchestra.com/blog/content/images/2025/11/509029520-0553a87c-26da-48fc-bbf1-9dd4d423c222.png) Dashboard endpoint now exposed in the REST API ![](https://xen-orchestra.com/blog/content/images/2025/11/image-2-.png) VM dashboard view ### SSE support The API now supports **Server-Sent Events** (SSE), so you can subscribe to real-time updates. To start receiving events, open an SSE stream by calling `GET /rest/v0/events`. The first event returned will include a unique connection identifier. To subscribe to specific events, send a POST request to `/rest/v0/events/:id`, using the ID received earlier. The server will respond with a subscription ID, which you can use to manage or cancel the subscription later. ![](https://xen-orchestra.com/blog/content/images/2025/11/503245786-81af7c97-2cd8-4ff2-ab45-74ff376f548e.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/504121676-70ea4a8d-ed28-4fcd-85a6-4f43d13b8151.png) SSE events, documented in Swagger This feature lets you track live changes across infrastructure objects (VMs, hosts, pools, and more) so front-end views update instantly when modifications occur. ## ☸️ DevOps Tools We’re not forgetting the DevOps Tools side: updates across our providers/plugins, plus an exciting preview. ### Terraform Provider v0.36.1 We’ve released version 0.36.1 of the Xen Orchestra Terraform provider, which includes a fix for creating VMs from templates that have three or more disks. This scenario could previously fail or behave inconsistently, and the update makes the workflow fully reliable again. This release goes hand-in-hand with the updated [Go SDK (v1.8.0)](https://github.com/vatesfr/xenorchestra-go-sdk/releases/tag/v1.8.0?ref=xen-orchestra.com), which provides the underlying improvements needed by the provider. A big thank you to lkirkwood for your contributions in this release! [Release v0.36.1 · vatesfr/terraform-provider-xenorchestraWhat’s Changed fix: missing disk when create vm from template with >3 disks by @lkirkwood in vatesfr/xenorchestra-go-sdk#49 New Contributors @lkirkwood made their first contribution in vatesfr/x…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-35.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v0.36.1)](https://github.com/vatesfr/terraform-provider-xenorchestra/releases/tag/v0.36.1?ref=xen-orchestra.com) [lkirkwood - Overviewssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOns3Fsa5sxw/n2j/CQeadwKD3IqmEeGQRIL682RXQmI - lkirkwood![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-38.svg)GitHub![](https://xen-orchestra.com/blog/content/images/thumbnail/8290148)](https://github.com/lkirkwood?ref=xen-orchestra.com) ### Packer Plugin v0.9.0 The latest Packer plugin (v0.9.0) improves how Packer can interact with the VM console. It now supports precise key combinations — like `x` — and a broader range of special keys. This makes automated OS installs more reliable, especially for distros or installers that depend on specific keyboard sequences. [Release v0.9.0 · vatesfr/packer-plugin-xenserverWhat’s Changed Other Changes Improve boot command parser by @nathanael-h in #176 Add:cooldown period(15 days) by @wbatchayon in #182 New Contributors @wbatchayon made their first contribution in…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-39.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v0.9.0)](https://github.com/vatesfr/packer-plugin-xenserver/releases/tag/v0.9.0?ref=xen-orchestra.com) This feature was initiated by a partner request and came together quickly — from the initial request in late July to a pre-release review by the end of September.It’s a great example of how Vates collaborates closely with partners to deliver practical improvements fast! ### Kubernetes CSI driver preview We have lifted the veil on next projet to improve Kubernetes integration with Xen Orchestra, the XenOrchestra CSI Driver for Kubernetes. 💡 CSI was developed as a standard for exposing arbitrary block and file storage systems to containerized workloads on Container Orchestration Systems (COs) like Kubernetes. A Container Storage Interface (CSI) driver that provides persistent storage for Kubernetes workloads using XenServer/XCP-ng infrastructure through Xen Orchestra. This repository hosts the CSI driver and all of its build and dependent configuration files to deploy the driver. It is recommended to install the Xen Orchestra CCM in addition to the CSI driver. [GitHub - vatesfr/xenorchestra-csi-driverContribute to vatesfr/xenorchestra-csi-driver development by creating an account on GitHub.![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-40.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/76ef7441-f387-4fa0-971e-327bf500de1c)](https://github.com/vatesfr/xenorchestra-csi-driver?ref=xen-orchestra.com) ## 📖 Documentation & Guides Documentation keeps moving forward too, with new guides and improvements. ### Improved email report plugin documentation The documentation for the email transport plugin has been updated to clearly explain its OAuth 2.0 support, including step-by-step guidance for Gmail and Microsoft accounts. ![](https://xen-orchestra.com/blog/content/images/2025/11/Capture-d---cran-2025-11-26-081417-1-.png) Preview of the updated documentation for the email report plugin These details were available in the code but not clearly documented. The details are now easily accessible, which eliminates guesswork makes setup easier for modern email providers. [Backup reports | Xen Orchestra | XO DocumentationAt the end of a backup job, you can configure Xen Orchestra to send backup reports directly by email, Slack or in Mattermost. It’s up to you.![](https://xen-orchestra.com/blog/content/images/icon/favicon-26.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-14.png)](https://docs.xen-orchestra.com/backup%5Freports?ref=xen-orchestra.com#email-provider-configuration) ### Switching back to XO 5 Since [XO 6 is now the default interface](#default-to-xo-6-on-build), we've updated the documentation to explain how to change the XO interface from XO 6 back to XO 5, either temporarily or by default: ![](https://xen-orchestra.com/blog/content/images/2025/11/Capture-d---cran-2025-11-27-095315.png) Documentation preview on how to switch back to the XO 5 interface [Configuration | Xen Orchestra | XO DocumentationOnce Xen Orchestra is installed, you can configure some parameters in the configuration file. Let’s see how to do that.![](https://xen-orchestra.com/blog/content/images/icon/favicon-27.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-15.png)](https://docs.xen-orchestra.com/configuration?ref=xen-orchestra.com#using-xo-5-as-the-default-interface) ## 🔦 Community spotlight This month’s highlight comes straight from our community. ### Improved LVM File Restore File-level recovery for Linux VMs using LVM partitions has been significantly improved, in response to a persistent issue reported by the community. Xen Orchestra now reliably detects and mounts LVM partitions during restore operations. Thanks a lot to Julien Porschen for the contribution! [djul1981 - OverviewIT Swiss Army Knife. djul1981 has 4 repositories available. Follow their code on GitHub.![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-34.svg)GitHub![](https://xen-orchestra.com/blog/content/images/thumbnail/23528272)](https://github.com/djul1981?ref=xen-orchestra.com) ## 🌐 Translations Those translations are directly embedded in XO Lite and XO 6, thanks to Weblate. ### 8 languages updated A big thank you to our community for their ongoing efforts in translating Xen Orchestra! ![](https://xen-orchestra.com/blog/content/images/2025/11/687474703a2f2f7472616e736c6174652e76617465732e746563682f7769646765742f78656e2d6f72636865737472612f6d756c74692d6175746f2e737667.svg) Current XO translation status This month, special attention was given to **Czech, Danish, German, French, Italian, Dutch, Brazilian Portuguese**, and **Ukrainian**. Want to help translate Xen Orchestra or improve existing translations? You’re more than welcome to join in [here](https://translate.vates.tech/?ref=xen-orchestra.com). ## **🆕** Misc A couple of handy enhancements made their way into this release too. ### OS details in usage reports The `usage-report` plugin now includes each VM’s operating system information in its output. By adding the os\_version field to the data returned by the plugin, the usage report email gives a clearer picture of the types of systems running in your infrastructure. ![](https://xen-orchestra.com/blog/content/images/2025/11/509406796-37f35161-e7a3-42ca-85be-13481509b539.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/509407176-fa18e37f-837f-4565-9aab-9e6c10414447.png) OS details included in usage reports This addition makes reports more informative and helps with inventory tracking, planning, and general visibility. ### OIDC group mapping The OIDC plugin can now map groups from an identity provider directly to XO groups. It works much like the existing LDAP integration: **XO reads the group claims in the OIDC token and uses them to assign users to the right XO groups at login.** This is especially handy for environments using providers like Active Directory Fedceration Services (AD FS), where group membership is already managed centrally. It cuts down on manual group maintenance inside XO and makes authentication flow more in line with corporate identity setups. ### Improved performance alerts We've redesigned the performance alert plugin to leverage XAPI’s built-in alert system and eliminate the need for resource-heavy, manual monitoring within XO. Previously, the plugin downloaded and processed RRD data from every pool. It used up too much CPU and RAM, and sometimes even degraded `xo-server` performance. ![](https://xen-orchestra.com/blog/content/images/2025/11/518589975-eeb5a82f-f34d-450b-a28c-3af240ffd088.png) Previous design of performance report emails ![](https://xen-orchestra.com/blog/content/images/2025/11/image--12-.png) Redesigned performance report emails The new implementation no longer generates the XAPI alarm, as its lifecycle is not completly defined and may cause excessive load on `xo-server`. Stay tuned for the next iteration! ### Updates to `vhd-cli` command parameters The `vhd-cli` tool has been updated to support all Backup Repositories types (not just unencrypted BR). As a result, we've had to change the parameters for most commands. While `vhd-cli` is a low-level tool used primarily in scripts or automation, you may need to adjust your command lines to align with the new syntax. 💡 ****Note:** The tool’s core functionality remains unchanged. Only the argument structure has evolved. If you rely on `vhd-cli`, we recommend reviewing your scripts before updating to ensure compatibility. To know more, run your command with the `--help` argument, for instance `vhd-cli check --help`. ### Non-destructive VIF network changes Changing the network of a VIF no longer destroys and recreates it. XO now uses `VIF.move`, a safer and non-destructive XAPI call that keeps the original VIF UUID intact and avoids unnecessary guest disruption. Previously, XO unplugged and deleted the VIF before creating a new one, which could break in edge cases — for example when a VM had more than seven VIFs and XAPI refused to recreate them. In those situations, the VIF simply disappeared. With `VIF.move`, the operation is smoother, more reliable, and resilient to those corner cases. It also makes life easier for users migrating large VMs that come with many VIFs attached. ### Memory info in usage reports The `usage-reports` plugin now shows the RAM usage for each each VM. This lets you easily spot VMs that are over- or under-provisioned, optimize resources and keep your infrastructure running efficiently. ![](https://xen-orchestra.com/blog/content/images/2025/11/516741857-99d4e2ad-b113-461f-96ce-c4db6b8a8b7c.png) ![](https://xen-orchestra.com/blog/content/images/2025/11/516742300-a146312c-17af-46bb-be2e-a59ebc8a2f80.png) Usage reports showing RAM usage (in HTML and CSV formats) ### Xen Orchestra 5.112 URL: https://xen-orchestra.com/blog/xen-orchestra-5-112/ Last updated: 2026-07-15T06:50:07.000Z Welcome for this October release of Xen Orchestra, numbered 5.112 🎃 Nothing spooky this month, just great things to announce! Let's address the elephant in the pumpkin: VEEAM has now a public beta with native XCP-ng support (see below). One less component to switch when exiting VMware! On the XCP-ng front, it's also very rich in content: new signed Windows PV drivers, Qcow2 format now available in public beta (last step before production!), and some security updates. And about XO then? Well, it's a pretty big release (as usual, we can say know). Many improvements and fixes, while the REST API is really accelerating, acting as a foundation of XO 6. 🎵 The podcast version of our release is available on [Spotify](https://open.spotify.com/episode/0ItN2kvzdfc9iEA09gsabx?si=vNpEgWy4RDKih9wBD0m0cA&ref=xen-orchestra.com). ## 👨‍🚀 Project & Community If I had to summarize this section in one word, it would be **“busy”**. There are *so many* exciting announcements this month! In a perfect world, I’d have loved to spread them across several releases. But, well… you know how it goes 😅 ### VEEAM Open Beta > It’s tiiiiiime. © Yes, **it’s finally happening:** the **VEEAM public beta with native XCP-ng support** is here! 🎉 ![](https://xen-orchestra.com/blog/content/images/2025/10/veeam.png) Why are we so happy about it? After all, Xen Orchestra already provides powerful backup features. Well, there are **two great reasons** to celebrate: 1. **Simpler migrations:** if you’re coming from VMware, you now only have **one component to replace instead of two**. You can even **backup and restore between both platforms** (or even other platforms!) giving you a smooth migration path and letting you keep using tools you already trust. 2. **Collaboration matters:** we love working in an open ecosystem. We’ve been in close contact with VEEAM, helping, testing, and validating along the way. It’s been a pleasure collaborating with their team, and we’re looking forward to continuing this partnership! More info and download on VEEAM forums: [\[BETA\] \[XCP-ng\] Veeam Plug-In for XCP-ng 12.3.2 Beta (September 30, 2025)Veeam Community discussions and solutions for: \[BETA\] \[XCP-ng\] Veeam Plug-In for XCP-ng 12.3.2 Beta (September 30, 2025) of KVM (RHV, OLVM, PVE, SCHC)![](https://xen-orchestra.com/blog/content/images/icon/favicon-180x180.png)Veeam Community ForumsPost![](https://xen-orchestra.com/blog/content/images/thumbnail/veeam.png)](https://forums.veeam.com/kvm-rhv-olvm-pve-schc-f62/veeam-plug-in-for-xcp-ng-12-3-2-beta2-t100399.html?ref=xen-orchestra.com) ### Signed Windows PV drivers After years of work (and countless exchanges with Microsoft) we’re proud to announce that the **XCP-ng Windows PV drivers are now officially signed and available for download**. Why is this such a major milestone? Because it means we can now **officially distribute the drivers we build ourselves**, with Microsoft’s approval. Even more importantly, as the **upstream maintainer** of these drivers, **Vates is now the official reference for Open Source Windows PV drivers across the entire Xen ecosystem**. A huge step forward for both **XCP-ng** and **Xen** users alike! [Signed Windows PV drivers now availableAfter years of work and collaboration with Microsoft, we are proud to announce that the XCP-ng Windows PV drivers are now officially signed and ready for production, marking a major milestone in our journey toward full stack independence.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-29.png)XCP-ng BlogTu Dinh![](https://xen-orchestra.com/blog/content/images/thumbnail/winpvsigned.webp)](https://xcp-ng.org/blog/2025/10/10/signed-windows-pv-drivers-now-available/?ref=xen-orchestra.com) ### Beyond 2TiB: Qcow2 open beta The wait is over: **Qcow2 support in XCP-ng** is now entering **public beta**! After years of relying on the legacy VHD format, this new milestone brings a **modern and scalable storage foundation** to XCP-ng. With Qcow2, you can expect **larger disks**, **improved efficiency**, and **a path toward advanced features** that simply weren’t possible before. We’re incredibly grateful to everyone who tested the alpha builds and shared feedback — it played a key role in reaching this point. [QCOW2 beta announcementThe long-awaited QCOW2 support has arrived in public beta!![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-31.png)XCP-ng BlogDamien Thenot![](https://xen-orchestra.com/blog/content/images/thumbnail/qcow2b.webp)](https://xcp-ng.org/blog/2025/10/16/qcow2-beta-announcement/?ref=xen-orchestra.com) **Your feedback is crucial:** the more we get, the sooner we can reach production! [We are waiting for you in our forums.](https://xcp-ng.org/forum/topic/10308/dedicated-thread-removing-the-2tib-limit-with-qcow2-volumes?ref=xen-orchestra.com) ### October security & maintenance update for XCP-ng 8.3 This month’s update includes **important security fixes** for XCP-ng 8.3, along with several **bug fixes and improvements** that were pending release. As always, we recommend keeping your hosts up to date to benefit from the latest stability and security enhancements. [October 2025 Security and Maintenance Update for XCP-ng 8.3 LTSNew security, bugfix and enhancement updates are available for XCP-ng 8.3 LTS.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-32.png)XCP-ng BlogSamuel Verschelde![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1612521564730-62fc7691cd85)](https://xcp-ng.org/blog/2025/10/23/october-2025-security-and-maintenance-update-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) ### Xen Community manager interview This week on the **FLOSS Weekly Podcast**, **Cody Zuschlag**, Xen Community Manager, talks about the **Xen Project**, and naturally, about **XCP-ng** and **Xen Orchestra** too! ### Exodata case study **Exodata partnered with Vates to build a sovereign, high-performance cloud infrastructure spanning multiple regions.** In just a few months, they deployed nine independent platforms across six territories: from French Polynesia to mainland France. Their success proves that open infrastructure can combine control, scalability, and reliability at scale. [What Sovereign IT looks like in practice: the Exodata Use Case with VatesFrom strategy to production, Exodata’s journey with Vates shows how sovereignty and performance can go hand in hand proving that open infrastructure is a viable path for critical cloud operations.![](https://xen-orchestra.com/blog/content/images/icon/logo64-25.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/laurence-fusco-SKryJkQogrA-unsplash-1.jpg)](https://vates.tech/blog/what-sovereign-it-looks-like-in-practice-the-exodata-use-case-with-vates/?ref=xen-orchestra.com) ### XOA and the Vates Virtualization & Management Stack It’s hard to believe, but we started [selling **Xen Orchestra** over **10 years ago**](https://xen-orchestra.com/blog/xoa-starter-early-access/) (almost 11!) as a standalone virtual appliance: **XOA**. A lot has changed since then. We’ve [**forked XenServer**](https://archive.fosdem.org/2019/schedule/event/vai%5Fxcp%5Fng%5Fbuilding%5Fan%5Fopen%5Fsource%5Fand%5Fturnkey%5Fvirtualization%5Fplatform/?ref=xen-orchestra.com) (2018), built our own **fully open virtualization stack**, and helped thousands of users **move away from VMware** in the post-Broadcom era. With the **Vates Virtualization & Management Stack** [now established and growing fast](https://vates.tech/blog/introducing-vates-virtualization-management-stack/?ref=xen-orchestra.com), it’s time to **sunset the legacy "standalone" XOA plans**. The reason is simple: today’s market needs **a coherent, integrated stack**, not isolated components. Of course, this decision **does not affect XO from the sources:** we remain *fully* committed to open source, and nothing changes for the community edition. [Transitioning to the next chapter of Xen OrchestraVates announces the retirement of legacy Xen Orchestra subscriptions by July 2026, inviting users to transition to the unified Vates VMS model with dedicated migration paths and early upgrade discounts.![](https://xen-orchestra.com/blog/content/images/icon/logo64-22.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/jordan-wozniak-xP_AGmeEa6s-unsplash-1.jpg)](https://vates.tech/blog/transitioning-to-the-next-chapter-of-xen-orchestra/?ref=xen-orchestra.com) ### EasyVirt early bird offer for DC Scope & DC Net Scope With our **EasyVirt integration** now in stable release, you can directly **deploy DC Scope and DC Net Scope from your XOA**! To celebrate, we’re offering an **early-bird deal** so you can try (and maybe adopt!) these great tools. For those unfamiliar: - **DC Scope** helps you **analyze virtualization usage**, **plan capacity**, and **spot optimization opportunities**. - **DC Net Scope** lets you **visualize network flows**, detect **bottlenecks**, and **keep performance under control**. ![](https://xen-orchestra.com/blog/content/images/2025/10/dashboard2_xo.png) Together, they deliver **deep, actionable visibility** into your **Vates VMS** infrastructure — intuitive dashboards, native API integration, and deployment in just a few clicks. [Early bird offer: 20% off DC Scope and DC Net Scope subscriptionsTake advantage of our early-bird offer: get 20% off any Easyvirt DC Scope or DC Net Scope subscription finalized before December 15th, 2025\. Now available directly from Xen Orchestra for all up-to-date Vates VMS users.![](https://xen-orchestra.com/blog/content/images/icon/logo64-26.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/steve-smith--0ARBUGpqrE-unsplash-1.jpg)](https://vates.tech/blog/early-bird-offer-20-off-dc-scope-and-dc-net-scope-subscriptions/?ref=xen-orchestra.com) --- ## 🎫 Events A new section, regarding events you could have found us, or you might find us in the future. ### What's next Some events you can see us directly in the next weeks or in 2 months tops. #### 🇫🇷 API Days (December 9-11, Paris, France) We'll have [a talk and a panel discussion there](https://www.apidays.global/events/paris?ref=xen-orchestra.com). If you are in Paris at those date, it's the opportunity to connect! #### 🇺🇸 KubeCon (November 10-13, Atlanta, USA) We'll have a booth and we'll have some nice announcement there. More info at [https://events.linuxfoundation.org/kubecon-cloudnativecon-north-america/](https://events.linuxfoundation.org/kubecon-cloudnativecon-north-america/?ref=xen-orchestra.com) #### 🇱🇺 Luxembourg Internet Days 2025 with C2D IT Solutions (November 18-19) Our partner, C2D IT Solution, will attend [and talk about our solutions](https://vates.tech/blog/our-partner-c2d-it-solutions-at-luxembourg-internet-days-2025?ref=xen-orchestra.com). ### We've been there #### 🇺🇸 Xen Summit 2025 feedback A feedback on what happened during the last Xen Summit 2025, in San Jose, CA, USA. Don't miss it, it's an interesting read on our contributions in general toward the Xen Project! [Xen Summit 2025: how we shaped what’s nextThe Xen community gathered at AMD/Xilinx in San Jose, showcasing a thriving open-source ecosystem and Vates’ growing role in shaping its future.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-30.png)XCP-ng BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/xen-summit-2025-banner-1.webp)](https://xcp-ng.org/blog/2025/10/14/xen-summit-2025-how-we-shaped-whats-next/?ref=xen-orchestra.com) --- # XO 5.112 The **5.x branch** is living its last few versions, and what a journey it’s been! As we get closer to the **official release of XO 6.0**, each update brings us one step nearer to the next generation of Xen Orchestra ## 🛡️ Security Each month, we prioritize **transparency around potential security issues** affecting Xen Orchestra. This regular communication helps everyone stay informed and protected. As part of our ongoing work, we’ve also done another round of **dependency cleanup and updates:** reducing the potential **supply chain risk** in case of a compromised package. ### VSA-2025-005: Redis vulnerabilities Several new CVEs were recently published for **Redis**, which is used by Xen Orchestra: **CVE-2025-49844**, **CVE-2025-46817**, **CVE-2025-46818**, and **CVE-2025-46819**. After review, we’ve confirmed that **Xen Orchestra is not impacted**, due to its **specific thread model and usage context**. [VSA-2025-005: Redis vulnerabilities | Vates VMS Documentation2025-10-09 / Low severity / None of XO affected.![](https://xen-orchestra.com/blog/content/images/icon/vates-logo-128-c064bc94b81bd09a913e2c5208f3ce7b8a198b8db413b18d4a0ddd5f7f330a2e.png)Vates VMS Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-logo-128-c064bc94b81bd09a913e2c5208f3ce7b8a198b8db413b18d4a0ddd5f7f330a2e.png)](https://docs.vates.tech/trust-roadmap/security-advisories/advisories/2025/vates-sa-2025-005?ref=xen-orchestra.com) And don’t forget to keep an eye on our [**VSA page**](https://docs.vates.tech/category/advisories?ref=xen-orchestra.com) — your centralized source for all **security information across the entire Vates stack**. ## 💾 Backup This month brings several **resiliency improvements** to Xen Orchestra backups. We’ve resolved a few **long-standing edge-case issues** that were difficult to reproduce, thanks to an excellent collaboration between the **XCP-ng** and **XO** teams. ### Synchronous merge for mirror backups We’ve added a new **Merge backups synchronously** option for mirror backups. When enabled, the merge process runs as part of the backup job, rather than asynchronously afterward. ![](https://xen-orchestra.com/blog/content/images/2025/10/501914467-e1f279c9-510f-4627-a051-45650af8d4ef.png) This option is useful restarting a backup job, or when multiple mirror backup jobs are chained. It gives you greater control over backup timing and helps prevent potential merge-related issues in certain environments. ### Rate limiter Backup jobs offer customization over speed controls again. You can set a speed limit for full backups, incremental backups, replications, and mirror backups. This helps prevent network overload and ensures smoother performance during backup operations. Additionally, we’ve reintroduced a timeout for XAPI reads, to make backup processes more reliable. ### Fixed `VDI_NOT_MANAGED` error A long-standing and rare `VDI_NOT_MANAGED` backup error has finally been fixed. This issue had been around for quite some time but only appeared in specific setups. After in-depth debugging, the root cause was identified and resolved. Backups now run without interruption, even in environments where this error previously occurred. ### Fixed: Backup job timeouts We’ve resolved an issue where source-side timeout errors could cause backup jobs to hang indefinitely. Now, the job properly stops and reports the error, and you won't get stuck anymore. ## 🥝 Core UI Core UI is the next-gen common UI for both XO 6 and XO Lite. ### Treeview search loader The treeview now displays a visual loader whenever a search is in progress. Previously, typing in the search bar could sometimes result in a brief delay before results appeared, so users were unsure if anything was happening. ![](https://xen-orchestra.com/blog/content/images/2025/10/504799199-4b5574af-d00b-4b3f-95f1-91bb30f3742c-1.png) With this update, users receive instant visual feedback that their search is processing, making the interaction more responsive. ## 🛰️ XO 6 We worked hard this month to bring many more view in XO 6. ### Backup targets views XO 6 now includes a dedicated Backup Targets view, which lets you check all backup destinations configured in your environment, at a glance. You can easily review, sort and organize all of your backup targets, right from this page, under your Backup Jobs. ![](https://xen-orchestra.com/blog/content/images/2025/10/507042697-e72198b6-5024-4d02-9a3c-9f00f67ceb37.png) ![](https://xen-orchestra.com/blog/content/images/2025/10/507042923-e7f872b0-af7c-4af3-8359-f43a26989260.png) Backup Targets page ### Backed-up VMs view In the Backup Jobs section, we've added a view for backed-up VMs. This view lists all virtual machines covered by existing backup jobs. As a result, you can easily check which VMs are protected and which are not. ![](https://xen-orchestra.com/blog/content/images/2025/10/495191731-3713de38-84fe-49a3-b2c1-69dc175734b2.png) ![](https://xen-orchestra.com/blog/content/images/2025/10/495192074-11aeb26a-2200-48ec-86a7-ec9fd70cc823.png) Backed-up VMs view ### Backup jobs Configuration page We've added a brand-new Configuration page to the Backup Jobs section: ![](https://xen-orchestra.com/blog/content/images/2025/10/505299987-0fbbd681-25f9-401f-acc4-b2b6ac826f7f.png) ![](https://xen-orchestra.com/blog/content/images/2025/10/505300145-ced674fc-59c2-4ad6-b96d-4e59f3bdd53f.png) New Configuration page in the Backup Jobs section It lets you easily review and adjust key backup settings, such as schedules, retention policies, and destinations. ### Improved user menu We added more links in the user menu, so we can guide you more easily in various things, giving quick access to important resources. ![](https://xen-orchestra.com/blog/content/images/2025/10/502632303-8b22c290-9d17-40e3-afe8-67c5b08c2dd6.png) ### Ready for large scale infrastructures The user interface has been completely reworked to handle massive environments without slowing down. The biggest improvement comes from **virtual lists**: instead of loading every single item in the DOM (for example, thousands of VMs or alarms), XO now only renders what’s visible on screen and loads more as you scroll. This is particularly effective when XO handles Treeviews, Alarms and QuickTasks. In practical terms, that means you can now browse environments that were previously impossible to load in your browser. **Before this update:** Large setups with thousand of hosts and tens of thousands of VMs could cause your browser tab to freeze or crash, consuming several gigabytes of RAM. **Now:** The same environment (for example, **200 hosts**, **1,000 VMs**, and **60,000 alarms**) uses roughly **500 MB** of browser memory instead of several gigabytes. Even at 10,000 VMs and beyond, XO 6 remains responsive while still having an initial load time between 10 to 100 times faster than XO 5. ![](https://xen-orchestra.com/blog/content/images/2025/10/Resource-usage-with-1-000-VMs.png) ![](https://xen-orchestra.com/blog/content/images/2025/10/Resource-usage-with-10-000-VMs.png) ![](https://xen-orchestra.com/blog/content/images/2025/10/Resource-usage-with-100-VMs.png) Resource usage graphs for 100, 1,000 and 10,000 VMs ## 🪐 XOA We updated our XOA image to contains all the dependencies needed to use V2V out-of-the-box! ## 📡 REST API We’ve reached a **major milestone:** the REST API has now become the **solid foundation of XO 6**, powering the next generation of Xen Orchestra. ### Migration to swagger completed It took us some time. When we first started to develop the REST API, we didn't use the Open API standard. But we've seen how great it was, helping to directly generate an interactive documentation (Swagger). So we took the job seriously and we decided to rewrite the existing REST API endpoints to be Open API compatible, while write all our new endpoints directly for Swagger. And after months of hard work, we are proud to say it's finally done! Now all REST API endpoint are exposed in Swagger. Kudos! ### Multiple endpoint migrations We've migrated several endpoints, such as: tasks, delete/put tags, and messages. They're now all available under a unified structure, for all XAPI collections (`/:collection/:id`). ### New PBDs endpoints The API now includes PBDs (Physical Block Devices), so you can query and manage storage connections between storage repositories and hosts directly. ![](https://xen-orchestra.com/blog/content/images/2025/10/500850852-0f586cdb-6ff7-4a04-8188-f383d9865288.png) PBD endpoints in the REST API This simplifies the process of integrating storage management into automation workflows or external tools. ### Backup archives You can now list all your existing backups from the REST API. ![](https://xen-orchestra.com/blog/content/images/2025/10/503620508-0e4c39f7-34b5-4b3b-a727-dff0a48b4f17.png) ### Basic Auth support The REST API now includes Basic Auth for authenticated requests. You can now easily integrate Xen Orchestra with external tools or scripts that rely on standard HTTP authentication. This is big, because it means there is no need to generate a token from the UI or previous API as before! The REST API become self-sufficient for almost all your tasks. **How it works:** Basic Authentication is a simple way to authenticate directly through HTTP headers. Each request must include an `Authorization` header, containing your credentials encoded in Base64. The format is: `Authorization: Basic ` . For example, if your username is `admin` and your password is `admin`, the Base64 encoding of `admin:admin` is `YWRtaW46YWRtaW4=`. As a result, your request header should look like this: `Authorization: Basic YWRtaW46YWRtaW4=`. 💡 ****Note:** Many HTTP clients automatically handle this Base64 encoding for you. For example, with `curl`, you can simply run: `curl -u admin:password /rest/v0/vms` . ### Ping endpoint It sounds trivial but it's a very important feature to check the sanity of your XO instance. ![](https://xen-orchestra.com/blog/content/images/2025/10/503582182-5e435842-f9ed-4609-a260-222d854629af.png) ## ☸️ DevOps Tools Continuous progress on our **DevOps tooling ecosystem**, expanding integrations and refining automation around the Vates stack. ### Terraform provider v0.36.0 The Terraform provider for Xen Orchestra has been updated to version 0.36.0\. This release focuses on better stability, updated dependencies and exposing the `boot_firmware` for templates. If you use Terraform to manage your Xen Orchestra resources, upgrading to this version is recommended for a more reliable and up-to-date experience. [Release v0.36.0 · vatesfr/terraform-provider-xenorchestraWhat’s Changed bump github.com/vatesfr/xenorchestra-go-sdk from 1.5.1 to 1.7.0 to fix #379 and #377 (see related PR) feat: Read and expose boot\_firmware on template data-source by @sakaru in #381…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-30.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v0.36.0)](http://github.com/vatesfr/terraform-provider-xenorchestra/releases/tag/v0.36.0?ref=xen-orchestra.com) ### Xen Orchestra Go SDK v1.7.0 With valuable help from our contributors, the Go SDK for Xen Orchestra has been updated to **v1.7.0**, with several key improvements: - **New feature:** You can now expose boot parameters directly in templates (thanks to [sakaru](https://github.com/sakaru?ref=xen-orchestra.com)). - **VM creation fixes:** The SDK now handles existing VDB positions more reliably and automatically excludes the CD drive during VM creation (thanks to [gCyrille](https://github.com/gCyrille?ref=xen-orchestra.com)). - **Legacy support:** Added a v1 legacy client alongside the main "v2" interface, simplifying migration for existing integrations (thanks again to [gCyrille](https://github.com/gCyrille?ref=xen-orchestra.com)). If you’re integrating Xen Orchestra control into Go applications, upgrading to **v1.7.0** delivers smoother functionality and enhanced template management. ![](https://xen-orchestra.com/blog/content/images/2025/10/38780822.png) ## 🐦 VMware to Vates (V2V) Our **V2V migration tool** keeps improving every month — this release brings **better handling of edge cases** and smoother transitions for even more VMware environments. ### 2 TB+ disk support on qcow SRs Good news if you're migrating large VMware VMs: Xen Orchestra now allows you to import disks larger than 2 TB when the destination SR uses the qcow format. Before, large disks of this size couldn’t be imported properly because of restrictions in certain storage backends. With this update, as long as your SR supports qcow, you’re good to go, even for disks well beyond the 2 TB mark. This feature works out of the box, no additional configuration is required. ### Fixed: Stopped VMs getting locked When performing a V2V migration, imported VMs are locked in anticipation for. for a future resume. However, stopped VMs were also locked, which prevented them from restarting after the transfer. We've fixed this behavior. Stopped VMs are no longer locked, so that migrations can go on smoothly. Thank you to our community for reporting this issue! ### Fixed: Server thumbprint computation We resolved an issue where Xen Orchestra could fail to compute the server’s thumbprint during V2V imports, which caused the process to stop prematurely. The thumbprint calculation now works as intended. V2V imports are now smoother and more reliable, with no interruptions. ## 📖 Documentation & guides Documentation is essential, and we’re glad to **highlight the growing effort** we’ve been putting into it. ### New dedicated Terraform documentation Our **Terraform provider** now has its own detailed documentation: with examples, configuration tips, and usage guides to help you automate your Vates infrastructure with ease. [Terraform provider | Vates VMS DocumentationIntroduction![](https://xen-orchestra.com/blog/content/images/icon/vates-logo-128-9.png)Vates VMS Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/wb_xo_tf1-062897661b39aba89d13ec281c258057.png)](https://docs.vates.tech/devops-tools/terraform-provider/?ref=xen-orchestra.com) ### Configuration file path The documentation now explicitly specifies the location of the Xen Orchestra configuration file (`/etc/xo-server/config.toml`). Previously, instructions just said to "modify the config file", without indicating its exact path, which could lead to confusion during setup or troubleshooting. This update helps you quickly locate and modify the correct file, for easier configuration and maintenance. ### OpenFlow XAPI plugin usage The SDN Controller documentation has new information on the OpenFlow XAPI plugin. It explains how to use the plugin, from setup to configuration and practical usage. ![](https://xen-orchestra.com/blog/content/images/2025/10/Capture-d---cran-2025-10-27-094434.png) ![](https://xen-orchestra.com/blog/content/images/2025/10/Capture-d---cran-2025-10-27-094456-1.png) OpenFlow plugin documentation This update builds on the existing SDN Controller page, with a clear guide for anyone wanting to manage network flows programmatically through Xen Orchestra. [SDN Controller | Xen Orchestra | XO DocumentationBe sure to enable the plugin on only one XOA instance.![](https://xen-orchestra.com/blog/content/images/icon/favicon-20.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-8.png)](https://docs.xen-orchestra.com/sdn%5Fcontroller?ref=xen-orchestra.com) [Configuration | Xen Orchestra | XO DocumentationOnce Xen Orchestra is installed, you can configure some parameters in the configuration file. Let’s see how to do that.![](https://xen-orchestra.com/blog/content/images/icon/favicon-19.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-7.png)](https://docs.xen-orchestra.com/configuration?ref=xen-orchestra.com#sdn-controller-mode) ### Updated HA documentation The **High Availability** section of the XO documentation has been expanded, with practical information on how to set up and use HA effectively. In addition, this section now links to the up-to-date version of the XCP-ng documentation (instead of the XCP-ng blog posts). [![](https://xen-orchestra.com/blog/content/images/2025/10/Capture-d---cran-2025-10-28-143633.png)](https://docs.xen-orchestra.com/manage%5Finfrastructure?ref=xen-orchestra.com#vm-high-availability-ha) These updates ensure that anyone configuring High Availability can follow the latest best practices and depend on precise, practical guidance. ### EasyVirt documentation We’ve expanded the Vates VMS documentation with a dedicated page on integrating EasyVirt’s DC Scope and DC NetScope solutions with Xen Orchestra. [![](https://xen-orchestra.com/blog/content/images/2025/10/Capture-d---cran-2025-10-28-143440.png)](https://docs.vates.tech/vms-addons/easyvirt?ref=xen-orchestra.com) This new resource provides setup instructions, usage guidance, and key integration details. **Missed the announcement about our new Vates VMS documentation platform?** You can find all the details in the blog post for the previous release: [Xen Orchestra 5.111Xen Orchestra 5.111 is out! This release brings key security improvements, smoother backup and UI experiences, deeper XOA integrations, and new DevOps tools to keep your infrastructure efficient and secure.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-26.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/xo511.webp)](https://xen-orchestra.com/blog/xen-orchestra-5-111/#introducing-the-vates-vms-documentation) ## 🔦 Community spotlight If you contributed anywhere in the Vates stack, feel free to let us know, we'll be happy to showcase your contribution in here! ### Xen Orchestra inventory For those who want to export their infrastructure inventory into a CSV, [wmazren](https://github.com/wmazren?ref=xen-orchestra.com) on Github, created a script to do exactly that! He posted a [demo in our forum](https://xcp-ng.org/forum/topic/11489/xen-orchestra-inventory-export-script?ref=xen-orchestra.com), and you can find the code in this following repository: [GitHub - wmazren/xen-orchestra-inventory: Xen Orchestra Full Inventory Export ScriptXen Orchestra Full Inventory Export Script. Contribute to wmazren/xen-orchestra-inventory development by creating an account on GitHub.![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-31.svg)GitHubwmazren![](https://xen-orchestra.com/blog/content/images/thumbnail/xen-orchestra-inventory)](https://github.com/wmazren/xen-orchestra-inventory?ref=xen-orchestra.com) ### Dell Open Manage Appliance (OME) A new version of Dell Open Manage for XCP-ng is now available, thanks to [Cécile](https://x.com/AtaxyaNetwork?ref=xen-orchestra.com). More info in the following thread on our forums: [\[dedicated thread\] Dell Open Manage Appliance (OME)New version release ! A new patch version of the OME appliance is now available What I changed: Add xen-blkfront and xen-netfront driver Add guest tool (s…![](https://xen-orchestra.com/blog/content/images/icon/512-10.png)XCP-ngTheMonkeyBrain![](https://xen-orchestra.com/blog/content/images/thumbnail/1761814461561-606721a0-e549-47b3-8b69-55d7b233d21f-image.png)](https://xcp-ng.org/forum/post/99014?ref=xen-orchestra.com) ## 🌐 Translations Those translations are directly embedded in XO Lite and XO 6, thanks to weblate. ### 10 languages updated A big thank you to our community for their ongoing efforts in translating Xen Orchestra! ![](https://xen-orchestra.com/blog/content/images/2025/10/687474703a2f2f7472616e736c6174652e76617465732e746563682f7769646765742f78656e2d6f72636865737472612f6d756c74692d6175746f2e737667.svg) Current XO translation status This month, special attention was given to **Brazilian Portuguese**, **Czech**, **Dutch**, **Farsi**, **French**, **German**, **Spanish**, **Russian**, **Swedish**, and **Ukrainian.** Want to help translate Xen Orchestra or improve existing translations? You’re more than welcome to join in [here](https://translate.vates.tech/?ref=xen-orchestra.com). ## **🆕** Misc And finally, the **Misc** section: a mix of smaller additions and quality-of-life improvements that come on top of all the great work above! 🎁 ### Bug report extraction You can now generate and retrieve XCP-ng/XenServer system status (bug reports) directly from a host or pool, whether through the API or `xo-cli`. This eliminates the need to manually connect to each host of a pool. To do that, use one of the following commands: - `host.getSystemStatus` \- Download system status from a single host - `pool.getSystemStatuses` \- Download system status from all hosts in a pool in parallel With this update, admins can trigger the archive creation and download it in a single step. Support becomes easier, as well as troubleshooting workflows. ### IPMI data for Lenovo servers Following support for **2CRSi** and **Dell** hardware, **Lenovo servers** now join the list! You can now access **IPMI information** including the management address, total power usage, PSU and fan status, and the most useful temperature sensors: all directly from Xen Orchestra. ![](https://xen-orchestra.com/blog/content/images/2025/10/506240536-fc6378b6-1c57-450f-b939-1b2ffb6585d6.png) ### NetBox v4.4.x compatibility **XO 5.112** is now fully compatible with the latest **NetBox 4.4.x** releases, ensuring smoother integration and improved interoperability with your infrastructure management setup. ![](https://xen-orchestra.com/blog/content/images/2025/10/netbox.png) ### Xen Orchestra 5.111 URL: https://xen-orchestra.com/blog/xen-orchestra-5-111/ Last updated: 2026-07-15T06:51:26.000Z September is always that “back-to-school” month in Europe: summer slows down, then everything hits full speed again. This year was no exception: new partnerships, a brand-new security process, and a marathon of events worldwide. And in the middle of all that, we’re shipping XO 5.111, packed with practical updates: Core UI refinements, backup improvements, EasyVirt integration in XOA, REST API progress, and fresh docs to guide you through it all. Let’s jump in! 🎵 The podcast version of our release is available on [Spotify](https://open.spotify.com/episode/0ItN2kvzdfc9iEA09gsabx?si=vNpEgWy4RDKih9wBD0m0cA&ref=xen-orchestra.com). ## 👨‍🚀 Project & Community Let’s start with what’s been happening around Vates, our partners, and the community before diving into the release itself. ### Vates + Eviden: Advanced Virtualization Alliance We’re excited to announce our new partnership with **Eviden**, bringing serious hardware power into the Vates ecosystem. ![](https://xen-orchestra.com/blog/content/images/2025/09/Logotype_Eviden_RGB_Orange-2.webp) The **Bull Sequana SH** range is now validated with the fully open-source **Vates VMS stack**—including massive multi-socket servers scaling up to **8 CPU sockets** and **960 vCPUs**. ![](https://xen-orchestra.com/blog/content/images/2025/09/bullsequanaSH.png) For those who like to push infrastructure to its limits, this means you can now combine **enterprise-grade hardware** with a **transparent, sovereign virtualization platform**—without compromise. [Vates and Eviden: An European alliance for advanced sovereign virtualizationVates and Eviden join forces to deliver a sovereign, high-performance alternative to VMware, combining Bull servers with the open source Vates VMS stack, backed by technical validation and a joint commercial strategy.![](https://xen-orchestra.com/blog/content/images/icon/logo64-19.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/europe-vates-eviden.png)](https://vates.tech/blog/vates-and-eviden-an-european-alliance-for-advanced-sovereign-virtualization/?ref=xen-orchestra.com) ### EasyVirt Integration: DC Scope & NetScope ![](https://xen-orchestra.com/blog/content/images/2025/09/easyvirt-logo.png) Just five months after announcing our collaboration with Easyvirt, we’re excited to share that the first milestone of this integration is complete. You can now deploy both **DCSCOPE** and **DCNETSCOPE** directly from your Xen Orchestra appliance, and even purchase the Easyvirt suite as an add-on to your Vates VMS subscription. [Expanding the Vates ecosystem with EasyvirtEasyvirt’s DC Scope and DC NetScope are now fully integrated into Vates VMS! Optimize resources, control costs, and track sustainability, all from your existing ecosystem. Try it free for 15 days or get a co-renewal quote today.![](https://xen-orchestra.com/blog/content/images/icon/logo64-18.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/jakub-zerdzicki-itgsDhR1e2w-unsplash.jpg)](https://vates.tech/blog/expanding-the-vates-ecosystem-with-easyvirt/?ref=xen-orchestra.com) You can read more on how to deploy it in the dedicated section below. ### VSA: a new global security process We’re introducing a unified process for security: **Vates Security Advisories (VSA)**. From now on, all advisories will be centralized under the VSA system, giving you a single, reliable source to track issues, impacts, and fixes across the entire Vates stack. A VSA is an official Vates document that includes: - The nature of a security issue - Which Vates products and versions are affected - The severity and potential impact - Mitigation steps and resolution status Each advisory is uniquely identified in the format: `**VSA-YYYY-NNN**` (for example: `VSA-2025-001`). You can read more about the [security process in here](https://docs.vates.tech/trust-roadmap/security-advisories/security?ref=xen-orchestra.com). All VSAs are accessible there: [Advisories | Vates VMS DocumentationList of all our security advisories![](https://xen-orchestra.com/blog/content/images/icon/vates-logo-128-c064bc94b81bd09a913e2c5208f3ce7b8a198b8db413b18d4a0ddd5f7f330a2e.png)Vates VMS Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-logo-128-c064bc94b81bd09a913e2c5208f3ce7b8a198b8db413b18d4a0ddd5f7f330a2e.png)](https://docs.vates.tech/category/advisories?ref=xen-orchestra.com) ### XCP-ng 8.2 LTS reached EoL If you haven't upgraded yet to [XCP-ng 8.3 LTS](https://docs.xcp-ng.org/releases/release-8-3/?ref=xen-orchestra.com), now is time to do so, as **XCP-ng 8.2 reached its end of life on the 16th of September, 2025**, as announced previously. There will be no more bug fixes nor security updates for this release. The currently supported release is XCP-ng 8.3 LTS. [XCP-ng 8.2 LTS reached its End Of LifeSupport ended for XCP-ng 8.2 LTS. Upgrade to XCP-ng 8.3 LTS.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-26.png)XCP-ng BlogSamuel Verschelde![](https://xen-orchestra.com/blog/content/images/thumbnail/freestocks-ebZUZ1MiVnU-unsplash.jpg)](https://xcp-ng.org/blog/2025/09/16/xcp-ng-8-2-lts-reached-its-end-of-life/?ref=xen-orchestra.com) ### XCP-ng 8.3 various updates First, an important security fix: [September 2025 Security Update for XCP-ng 8.3 LTSNew security updates are available for XCP-ng 8.3 LTS.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-27.png)XCP-ng BlogGaël Duperrey![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1639503547276-90230c4a4198)](https://xcp-ng.org/blog/2025/09/11/september-2025-security-update-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) 💡 The security fix is related to `VSA-2025-002`. More details at [https://docs.vates.tech/security/advisories/2025/vates-sa-2025-002](https://docs.vates.tech/trust-roadmap/security-advisories/advisories/2025/vates-sa-2025-002?ref=xen-orchestra.com) And then, some various improvements: [September 2025 Maintenance Update for XCP-ng 8.3New bugfix and enhancement updates are available for XCP-ng 8.3 LTS. Network performance improvement for Linux VMs on AMD hardware.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-28.png)XCP-ng BlogGaël Duperrey![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1622758342664-ce796582e479)](https://xcp-ng.org/blog/2025/09/01/september-2025-maintenance-update-for-xcp-ng-8-3/?ref=xen-orchestra.com) Don't forget to stay up to date! ### Community forum milestone Huge thanks to our community: we hit a new record in September with **3 million unique visitors** on the forum! 🚀 ![](https://xen-orchestra.com/blog/content/images/2025/09/43d52162-a75b-4a9c-9e7a-ead2c4595777-1.webp) --- ## 💡 Insights Here are some recent reflections—our own and from others—that shed light on how we work and where our stack is heading. ### Remote, hybrid, office? Yes. A look at how we work at Vates, from my perspective—maybe you’ll pick up a thing or two along the way 😉 [Remote, hybrid, office? Yes.Treat people like adults, and they usually act like it.![](https://xen-orchestra.com/blog/content/images/icon/faviconV2-7)VirtualizeOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/hybridremote-1.webp)](https://virtualize.sh/blog/remote-hybrid-office-yes/?ref=xen-orchestra.com) My associate, Nithida, also wrote a complementary article (in French) for a business journal: [https://www.cadre-dirigeant-magazine.com/reussir-en-entreprise/travailler-a-distance-ce-que-les-entreprises-peuvent-apprendre/](https://www.cadre-dirigeant-magazine.com/reussir-en-entreprise/travailler-a-distance-ce-que-les-entreprises-peuvent-apprendre/?ref=xen-orchestra.com) ### Buying software is a political act In this column (in French, but easily translatable in your browser), I explain why supporting European open source is both a technological and a strategic choice, essential for long-term independence. [« Acheter un logiciel est un acte politique » : Olivier Lambert (Vates) appelle à soutenir l’open source européen - Solutions-NumeriquesLa Linux Foundation Europe vient de publier son rapport 2025 : si les entreprises européennes adoptent massivement l’open source, rares sont celles qui disposent d’une stratégie claire ou d’un pilotage structuré. Cela a pour conséquences directes une dépendance persistante à des technologies extra-européennes, des difficultés à sécuriser la supply chain logicielle et entraîne indéniablement une \[…\]![](https://xen-orchestra.com/blog/content/images/icon/webicon-300x300.png)Solutions-NumeriquesCamille Suard![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-olivier-2025-94-franck-dunouau.jpg)](https://www.solutions-numeriques.com/acheter-un-logiciel-est-un-acte-politique-olivier-lambert-vates-appelle-a-soutenir-lopen-source-europeen/?ref=xen-orchestra.com) ### Best practices for XCP-ng setup A big thanks to **Tom from Lawrence Systems**, who shared a comprehensive recap of the entire stack in a dedicated forum thread. It’s a great resource if you want to get your XCP-ng setup right from the start: [How to Set Up XCP-ng Right the First Time – Best Practices and Configuration Tips🛠 XCP-ng Server Setup Best Practices 🧱 1\. Hardware Planning ✅ General Hardware Both older and newer hardware are fine, as long as it is x86 and supports virtualization. ✅ Software RAID Boot XCP-ng supports mdadm mirror setup on install ✅ Hardware RAID Controller Good for local storage management ✅ HBA or passthrough — Allows software (like ZFS or external storage) to manage redundancy. RAID…![](https://xen-orchestra.com/blog/content/images/icon/209fc86fdffd030f95fe29598078144241514bf3_2_180x180.png)Lawrence Systems ForumsLTS\_Tom![](https://xen-orchestra.com/blog/content/images/thumbnail/7ca867e988231520d08441caf8ead138b992bebd_2_1024x576.jpeg)](https://forums.lawrencesystems.com/t/how-to-set-up-xcp-ng-right-the-first-time-best-practices-and-configuration-tips/24698/1?ref=xen-orchestra.com) ### VMScape and why Xen dodged it ETH Zürich’s new VMScape attack hit KVM and VMware, but Xen’s microkernel-like design kept it out of reach. Discover the reasons. [VMScape and why Xen dodged itETH Zürich’s new VMScape attack hit KVM and VMware, but Xen’s microkernel-like design kept it out of reach.![](https://xen-orchestra.com/blog/content/images/icon/faviconV2-8)VirtualizeOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/lczxrdhpvuhe1.jpeg)](https://virtualize.sh/blog/vmscape-and-why-xen-dodged-it/?ref=xen-orchestra.com) --- ## 🎫 Events A new section, regarding events you could have found us, or you might find us in the future. ### What's next Some events you can see us directly in the next weeks or in 2 months tops. #### 🇫🇷 IP & IPAs (October 2, Orléans, France) Yann will do a presentation and a demo on XCP-ng and Xen Orchestra! [Link to event](https://www.linkedin.com/events/ip-ipas-2parcastleit7341031359374585858?ref=xen-orchestra.com). #### 🇫🇷 Volcamp (October 2-3, Clermont-Ferrand, France) Nath [will do a talk dedicated on how to use DevOps tools](https://www.volcamp.io/talks/d2t2s8?ref=xen-orchestra.com) with the Vates stack. #### 🇫🇷 DataCore Days (October 6-7, Avignon, France) I'll be personally there. Details and info can be [found on our Vates blog post](https://vates.tech/blog/vates-at-datacore-days-2025/?ref=xen-orchestra.com). #### 🇦🇪 GITEX Global - Expand North Star (October 13-17, Dubaï, UAE) We'll have a Vates booth. Come to say hi! [https://www.gitex.com/](https://www.gitex.com/?ref=xen-orchestra.com) #### 🇺🇸 KubeCon (November 10-13, Atlanta, USA) We'll have a booth and we'll have some nice announcement there. [https://events.linuxfoundation.org/kubecon-cloudnativecon-north-america/](https://events.linuxfoundation.org/kubecon-cloudnativecon-north-america/?ref=xen-orchestra.com) ### We've been there Let's review the main events we've been in this September. #### 🇺🇸 Xen Summit 2025 (Santa Clara) I will write a dedicated article about the event, with all our presentation, photos and Youtube replays. ![](https://xenproject.org/img/others/xen-summit-2025-banner.png) ![](https://xen-orchestra.com/blog/content/images/2025/09/xensummitOLT.jpg) It's still too early now, but keep an eye on the XCP-ng blog. Or wait for the next release in here! Event URL: [https://events.linuxfoundation.org/xen-project-summit](https://events.linuxfoundation.org/xen-project-summit/?ref=xen-orchestra.com) #### 🇩🇪 Qubes OS Summit 2025 (Berlin) As we have strong commitment in the upstream, we are also discussing security and isolation in a broad way, not just inside the datacenter. That's why we are proud to participate to the Qubes OS Summit. More on [https://events.dasharo.com/event/2/qubes-os-summit-2025](https://events.dasharo.com/event/2/qubes-os-summit-2025?ref=xen-orchestra.com) #### 🇳🇴 Security Expo 2025 (Oslo) It was about Sovereign Private Cloud, and as you can imagine, we've been a good fit there! More at [https://blue-services.nl/evenement/blue-services-security-expo-september-2025/](https://blue-services.nl/evenement/blue-services-security-expo-september-2025/?ref=xen-orchestra.com) Pheeewww. We did it! Busy month, right? --- # XO 5.111 Now let's talk about this new XO release. ## 🛡️ Security Unlike previous releases, we'll start with a new section: security. ### Npm supply chain attack Our first VSA was regarding XO. You might have been heard about an npm supply chain attack (npm is the package managed for NodeJS, the engine of Xen Orchestra). That's why we published a first Vates Security Advisory (VSA) for it, even if we were not impacted (no production dependency was in the list of affected repositories). You can read more details in the VSA: [VSA-2025-001: npm supply chain attack | Vates VMS Documentation2025-09-10 / Low severity / Only XO devel affected.![](https://xen-orchestra.com/blog/content/images/icon/vates-logo-128-2.png)Vates VMS Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-logo-128.png)](https://docs.vates.tech/security/advisories/2025/vates-sa-2025-001?ref=xen-orchestra.com) ### More on the XO 5.107 security patch Even if it happened few releases ago, we wanted to make sure everyone is up to speed, if you use our LDAP plugin. With the Xen Orchestra 5.107 update, we released a subtle but important security patch, without disclosing too many details at the time. Here’s what was happening: prior to XO 5.107, if you were using the LDAP plugin (`auth-ldap`) and had misconfigured the `ID attribute` field in its settings (by specifying an attribute name that doesn’t exist in the user schema), then a user A could have been able to log into Xen Orchestra as another user B (potentially even an admin). In some cases, user B’s username might also have been overwritten with user A’s username, resulting in duplicate usernames in the user list. Although it’s unlikely this issue occurred on your XOA, let alone went unnoticed, we still recommend following these steps: - Ensure you’re running Xen Orchestra 5.107.0 or later (`auth-ldap` 0.10.11). - Go to **Settings → Users** and check for duplicate usernames. If any are found, the account with Admin permissions is most likely the one that needs to be corrected. - Use the `permission:admin` filter to confirm there are no unexpected users with Admin permissions. ## 💾 Backup Since we published our new backup engine, things are going pretty smooth. We are entering a phase of various improvements and fixing details. ### Prevent accidental space reclamation We’ve added a safety check to the space reclamation process. Because reclaiming freed space during active backups can lead to serious issues, Xen Orchestra will automatically block the operation while backups are running. If you still need to proceed, you can override the protection using the new confirmation dialog: ![](https://xen-orchestra.com/blog/content/images/2025/09/486164430-1a20c661-102c-4e62-b209-8629b30e9d79.png) Dialog box to prevent accidental space reclamation during backups ## 🥝 Core UI Core UI is the next-gen common UI for both XO 6 and XO Lite. ### Improved `UIcollapsibleList` Component We’ve updated the `UIcollapsibleList` component across the interface. Previously, the text showing how many extra items were hidden wasn’t clickable—you had to use a separate *See all* link. Now, you can click directly on the item count to expand the list. ![](https://xen-orchestra.com/blog/content/images/2025/09/beforeafter.png) This makes the interaction more straightforward, and the component feels cleaner and more responsive overall. ### Updated VM dashboard We’ve updated the VM dashboard in the core UI to align with our latest designs. The new layout, spacing, and visual elements follow the design specs more closely, which results in a **cleaner and more readable interface**. ![](https://xen-orchestra.com/blog/content/images/2025/09/486873343-1e5679c9-d91c-4061-a342-e9a603120ccf.png) VM dashboard before the update ![](https://xen-orchestra.com/blog/content/images/2025/09/486872725-0b4bf31c-b635-40b4-b3d2-1de67069b507.png) VM dashboard since the XO 5.111 update This update doesn’t introduce new functionality, but enhances the overall experience with a more polished and intuitive look. ### Error visibility in dashboard cards Dashboard cards now display an error indicator when the data for a card fails to load. This means you no longer need to sift through logs or secondary views. The problem is flagged right where you’re already looking. This makes it easier to spot issues quickly and respond without delay. ## 🛰️ XO 6 Some features of Core UI are exclusive to XO 6, as XO Lite isn't meant to provide all XO features. And this month, it's all about backups! ### VM backup jobs table XO6 now features a dedicated table that lists all backup jobs associated with a specific VM. This makes it easy to see which jobs are protecting the VM and how they’re configured. ![](https://xen-orchestra.com/blog/content/images/2025/09/489591398-b6eba8fa-0552-4910-952a-488544841792.png) Table listing a VM's backup jobs Instead of digging through the global backup view, you can now check everything directly from the VM page, and quickly verify that the right jobs are in place. It’s a small but highly practical improvement for monitoring your backup coverage. ### Backup job details in the side panel Now, as soon as you enter the **Backup job** view, you can see the backup job details in the side panel. This way, you no longer have to leave the page or open a separate view to get the information. ![](https://xen-orchestra.com/blog/content/images/2025/09/488185900-b3dccb6d-d5e5-419b-a8b4-8f41c446e2d7.png) ![](https://xen-orchestra.com/blog/content/images/2025/09/488186336-c5c7e3dc-3bdb-4c69-bc0b-22b5d65a62f1.png) ![](https://xen-orchestra.com/blog/content/images/2025/09/488186889-42d61f64-e847-4118-87fc-5a0b75c71664.png) ![](https://xen-orchestra.com/blog/content/images/2025/09/488187649-e45b26e4-098e-4571-b10a-d0ec1b6d075a.png) ![](https://xen-orchestra.com/blog/content/images/2025/09/488188865-791b58c9-deca-410c-acd5-5fa09a4f0cf2.png) Backup jobs appearing in the side panel ### Alarms and patches in dashboards The dashboards for **hosts** and **VMs** now show active alarms front and center. You can see issues immediately, without navigating through multiple screens, so you can respond faster when problems arise. Also, the **host dashboard** now includes a dedicated **Patches** section. You can instantly check applied and missing patches, all without leaving the dashboard. ![](https://xen-orchestra.com/blog/content/images/2025/09/489572314-f9776007-72e3-4ed6-a020-9f6c240066fa.png) VM dashboard, with the Alarm section ![](https://xen-orchestra.com/blog/content/images/2025/09/489572550-4e0483b0-43b2-4677-9de0-03584785ee63.png) Host dashboard, with the Alarm and Patches sections ### Backup job run list XO6 has a new **Runs** page, dedicated to backup jobs. You can now see the history of when and how each backup job has run, if the run has succeeded or failed. In addition, you can also access detailed logs for those jobs. ![](https://xen-orchestra.com/blog/content/images/2025/09/493278223-a31c9929-e425-4ea2-963c-fc82105ebaad.png) Backup job runs (success) ![](https://xen-orchestra.com/blog/content/images/2025/09/493278587-01ddcb7f-2500-4cd4-9e97-111e11931c26.png) Backup job runs (failure) This makes it much easier to monitor backups, identify issues, and verify the protection of your VMs without jumping between screens. ## 🔭XO Lite As we are moving forward with Core UI and XO 6, XO Lite is also enjoying new view and features. ### Visual indicator for external links We've made the user experience a little more reliable and consistent, with a little icon that now accompanies all external links. This will clearly signal when the user will navigate outside the application. ![](https://xen-orchestra.com/blog/content/images/2025/09/490039740-0367f0bd-5af5-4d8b-b326-d5cc4e85e0cc-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/09/490039361-419c3603-9f20-4354-a441-fe8fd494bddc-1.png) External links before the update ![](https://xen-orchestra.com/blog/content/images/2025/09/490050820-ba8796af-2269-4728-a321-65af6571cdc7.png) ![](https://xen-orchestra.com/blog/content/images/2025/09/490051002-1f8996ac-5960-4b1b-8f97-8968442cd011.png) External links since the XO 5.111 update ### Improved key/value alignment in Settings The **Settings** page now shows keys and values aligned naturally, rather than splitting them into separate columns. This small change makes the page easier to read and keeps the layout clean and consistent. ![](https://xen-orchestra.com/blog/content/images/2025/09/490039361-419c3603-9f20-4354-a441-fe8fd494bddc-2.png) ![](https://xen-orchestra.com/blog/content/images/2025/09/490039740-0367f0bd-5af5-4d8b-b326-d5cc4e85e0cc-2.png) Key/value alignment before the update ![](https://xen-orchestra.com/blog/content/images/2025/09/490065600-c6837309-7dad-4d68-bef8-4c9d41c1184a.png) ![](https://xen-orchestra.com/blog/content/images/2025/09/490065414-5c45f6d2-89af-40c3-9807-417fd22338dc.png) Key/value alignment since the XO 5.111 update ## 🪐 XOA This month, we are introducing the capability to deploy a partner solution as if it was a Vates product! If you need capacity planning, energy usage overview or even Network flow analysis, you should try it now! ### EasyVirt DC Scope and NetScope integration You can now deploy and access EasyVirt’s DC Scope and DC NetScope tools directly from Xen Orchestra. The tools open within XO, so you can access their overviews without switching applications. The deployment forms and overview cards appear in the **Recipes** view for all users, whether on the free version of Xen Orchestra or XOA: ![](https://xen-orchestra.com/blog/content/images/2025/09/image.png) DC Scope deployment card from the Recipes view ![](https://xen-orchestra.com/blog/content/images/2025/09/486818215-38557c3e-0e22-4bd9-b4c2-9f5340b4a50f.png) New button to access DC Scope/NetScope instances, from the XO interface This integration makes it easier to manage, deploy and monitor your infrastructure with EasyVirt’s tools. ## 📡 REST API Our REST API is evolving fast, and going to be almost 100% swagger compatible in our next releases. ### Deprecated endpoints Several API endpoints for backups and restores are now **deprecated** and **will be removed in one year**. If your integrations rely on these endpoints, you’ll need to update them before the removal date. **Affected endpoints:** - `GET /rest/v0/backup/jobs/vm` - `GET /rest/v0/backup/jobs/vm/` - `GET /rest/v0/backup/jobs/metadata` - `GET /rest/v0/backup/jobs/metadata/` - `GET /rest/v0/backup/jobs/mirror` - `GET /rest/v0/backup/jobs/mirror/` - `GET /rest/v0/backup/logs` - `GET /rest/v0/backup/logs/` - `GET /rest/v0/restore/logs` - `GET /rest/v0/restore/logs/` **What to use instead:** - Replace `/backup/jobs/vm`, `/backup/jobs/metadata`, and `/backup/jobs/mirror` with `/rest/v0/backup-jobs`. - Replace `/backup/logs` with `/rest/v0/backup-log`. - Replace `/restore/logs` with `/rest/v0/restore-logs`. Be sure to update your integrations before these endpoints are removed! ### Endpoints moved to Swagger Several existing endpoints have been moved to Swagger. Here's the full list: - `DELETE /rest/v0/tasks` - `DELETE /rest/v0/tasks/` - `DELETE /rest/v0/vms/` - `DELETE /rest/v0/vm-templates/` - `DELETE /rest/v0/vm-snapshots/` - `DELETE /rest/v0/vdis/` - `DELETE /rest/v0/vdi-snapshots/` - `POST /rest/v0/tasks//actions/abort` - `POST /rest/v0/srs//vdis` - `GET /rest/v0/vdis/.(raw|vhd)` - `GET /rest/v0/vdi-snapshots/.(raw|vhd)` - `GET /rest/v0/vms/.(xva|ova)` - `GET /rest/v0/vm-templates/.(xva|ova)` - `GET /rest/v0/vm-snapshots/.(xva|ova)` - `GET /rest/v0/groups//users` - `GET /rest/v0/users//groups` - `GET /rest/v0/users/me` - `GET /rest/v0/users/me/*` - `GET /rest/v0/vms//messages` - `GET /rest/v0/users//authentication_tokens` - `GET /rest/v0/vms//tasks` - `GET /rest/v0/vm-snapshots//messages` - `GET vm-templates/:id/messages` We've also added brand new endpoints to Swagger: `/rest/v0/proxies` and`/rest/v0/proxies/` This update makes it easier to test the REST API, and brings us closer to having it fully documented and accessible in Swagger. For more details on the migration of the API documentation to Swagger, see the initial announcement from the XO 5.104 release: [Xen Orchestra 5.104This month at Vates, we’re bringing you a wave of updates across the board! Our virtualization stack is now validated for Red Hat Enterprise Linux 9, and we’ve announced a strategic partnership with VyOS to enhance networking capabilities in Vates VMS.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-23.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/rodion-kutsaiev-b6Kfzd8pDaQ-unsplash-6.jpg)](https://xen-orchestra.com/blog/xen-orchestra-5-104/#swagger-and-openapi-integration-a-big-step-forward) ## ☸️ DevOps Tools We continue to move forward on DevOps tools. Getting the initiative and doing it ourselves is a lot of work, for sure, but also the guarantee of the quality level we can bring you, instead of relying only on community maintained plugins or tools. Terraform Provider is now available in version 0.35.1: [Release v0.35.1 · vatesfr/terraform-provider-xenorchestraFixed behavior when creating a VM from a template: All existing disks in the template are used if they are declared in the TF plan. All unused disks in the template are deleted to avoid inconsiste…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-26.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v0.35.1)](https://github.com/vatesfr/terraform-provider-xenorchestra/releases/tag/v0.35.1?ref=xen-orchestra.com) 3 bugs fixed making template and VM creation a lot easier. We also worked on the library which is the foundation of our Go providers, the Golang SDK. You can now have more logs by using `TF_LOG_PROVIDER=DEBUG`. ## 🐦 VMware to Vates (V2V) It's been a month since we had our new V2V engine, using VDDK, considerably accelerating the migration, and allowing warm migration. This code is now landing in stable as it was working great! Don't forget to take a look at our previous announcement for all the details: [Xen Orchestra 5.110Migration, storage, and backup take a big step forward this month.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-25.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/xo5110.webp)](https://xen-orchestra.com/blog/xen-orchestra-5-110/#%F0%9F%90%A6-vmware-to-vates-v2v) As a quick reminder, the performance difference with VDDK is really huge: ![](https://xen-orchestra.com/blog/content/images/2025/08/1754568923689.jpeg) We also vastly improved the documentation on how to migrate from VMware with a brand new detailed V2V guide, see below. ## 📖 Documentation & guides Having a good documentation is an important part of doing a good product. That's why we are committed to provide, each month, a recap on the work we are doing regarding the documentation. ### Introducing the Vates VMS documentation We’ve launched a new documentation site for the Vates Virtualization Management Stack (or Vates VMS). Since our products are deeply interconnected, we needed a **centralized resource** to cover topics that span across multiple solutions, without tying them to any single product’s documentation. ![](https://xen-orchestra.com/blog/content/images/2025/09/vatesdoc.webp) Preview of the Vates VMS documentation The site provides a **clear overview of our products and services**, along with **general guides on cross-cutting topics**. It’s designed as a starting point for anyone looking to understand what Vates offers, and how our solutions work together. However, it **doesn’t replace the existing technical docs** for [Xen Orchestra](https://docs.xen-orchestra.com/?ref=xen-orchestra.com) or [XCP-ng](https://docs.xcp-ng.org/?ref=xen-orchestra.com), which are still available at their usual locations. Some sections are still being filled in, but we’ll continue to expand it over time. You can check out the Vates VMS documentation here: [Vates VMS DocumentationWelcome to the official documentation for Vates and the Vates Virtualization Management Stack (VMS).![](https://xen-orchestra.com/blog/content/images/icon/vates-logo-128-1.png)Vates VMS Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates_logo_background.webp)](https://docs.vates.tech/?ref=xen-orchestra.com) ### Migrating VMs from Vmware We've published a new guide in the Xen Orchestra documentation! It will help you migrate your VMs from VMware to a Vates stack, without any issues. The guide covers the important steps, good practices and key factors to reduce downtime and make this process as seamless as possible. ![](https://xen-orchestra.com/blog/content/images/2025/09/preview_v2v_migration_guide.png) Preview of the new V2V migration guide The V2V migration guide guide expands our documentation with practical, up-to-date guidance for organizations looking to move away from VMware. [V2V Migration Guide | Xen Orchestra | XO Documentation📌 Introduction![](https://xen-orchestra.com/blog/content/images/icon/favicon-17.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-5.png)](https://docs.xen-orchestra.com/v2v-migration-guide?ref=xen-orchestra.com) ### New guide for backup strategies We just added a guide to the XO documentation, designed to help you formulate a good backup strategy. It walks you through some of the key decisions, including which backup type to choose and how to determine your retention strategy, so you can keep your data safe and recoverable. ![](https://xen-orchestra.com/blog/content/images/2025/09/preview_backup_strategy_gide-min.png) Preview of the backup strategy guide This guide is a practical resource for anyone setting up or reviewing their backup policies. We’ll continue to update and expand it over time, based on feedback and new best practices. [Backup strategy guide | Xen Orchestra | XO DocumentationThis guide explains how to design and implement a backup strategy in Xen Orchestra.![](https://xen-orchestra.com/blog/content/images/icon/favicon-18.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-6.png)](https://docs.xen-orchestra.com/backup%5Fhowto?ref=xen-orchestra.com) ### Getting started with Recipes The **Advanced Features** page in the Xen Orchestra documentation has a new section dedicated to Recipes.This sectionexplains what Recipes are and what they do (in short: you can use them to automate your VM deployments): [Advanced features | Xen Orchestra | XO DocumentationThis section is dedicated to all others Xen Orchestra “advanced features”.![](https://xen-orchestra.com/blog/content/images/icon/favicon-16.ico)Xen Orchestra Documentationour blog post series about it![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-4.png)](https://docs.xen-orchestra.com/advanced?ref=xen-orchestra.com#recipes) For advanced users, the section also links to the new [Vates VMS documentation](#introducing-the-vates-vms-documentation), where you’ll find a step-by-step guide on using Recipes to deploy a full **Kubernetes** environment, in just a few clicks: ![](https://xen-orchestra.com/blog/content/images/2025/09/preview_k8s_doc.png) You can access the Kubernetes deployment guide directly, by clicking the link below: [Deploy Kubernetes with recipes | Vates VMS DocumentationIntroduction![](https://xen-orchestra.com/blog/content/images/icon/vates-logo-128.png)Vates VMS Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/hub_recipes-36650eea6d1bcd1e14103d5f65ee2bb7.png)](https://docs.vates.tech/devops-tools/kubernetes?ref=xen-orchestra.com) ## 🌐 Translations It's important for us to have our software translated in many languages as possible, and we do it in a collaborative fashion, thanks to Weblate! ### 8 languages updated A big thank you to our community for their ongoing efforts in translating Xen Orchestra! ![](https://xen-orchestra.com/blog/content/images/2025/09/687474703a2f2f7472616e736c6174652e76617465732e746563682f7769646765742f78656e2d6f72636865737472612f6d756c74692d6175746f2e737667.svg) Xen Orchestra translation status This month, special attention was given to **Czech**, **Spanish,** **Italian**, **Dutch**, **Brazilian Portuguese, Russian**, and **Ukrainian**. A special shout-out to **Lux\_** for also refining the **French** translation, with better wording for several strings. Want to help translate Xen Orchestra or improve existing translations? You’re more than welcome to join in [here](https://translate.vates.tech/?ref=xen-orchestra.com). [Luxinenglish - OverviewDévloppeur . Luxinenglish has 53 repositories available. Follow their code on GitHub.![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-24.svg)GitHub![](https://xen-orchestra.com/blog/content/images/thumbnail/80638883)](https://github.com/Luxinenglish?ref=xen-orchestra.com) ## 🔦 Community spotlight We had some nice community contribution this month, let's showcase one! First, maybe you remember our PowerShell module, release few month ago: [GitHub - vatesfr/xo-powershell: PowerShell module for Xen-OrchestraPowerShell module for Xen-Orchestra. Contribute to vatesfr/xo-powershell development by creating an account on GitHub.![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-25.svg)GitHubvatesfr![](https://opengraph.githubassets.com/53610994f92ba32f3611f888e6746d734a4615bb4186a578ad71d5fc96d36ee0/vatesfr/xo-powershell)](https://github.com/vatesfr/xo-powershell?ref=xen-orchestra.com) It was a huge success and we have many users now. Some are already building cool things on top of it, for example a script used to do a custom backup report: ![](https://xen-orchestra.com/blog/content/images/2025/09/report.webp) You can find the dedicated thread on our forum and the author, [tmk](https://xcp-ng.org/forum/user/tmk?ref=xen-orchestra.com), in here: [Powershell script for backup summary reportsI recently developed a PowerShell script that fills a need that I couldn’t find with the built-in reporting options for Xen Orchestra backups. The script is…![](https://xen-orchestra.com/blog/content/images/icon/512-7.png)XCP-ngtmk![](https://xen-orchestra.com/blog/content/images/thumbnail/1758826638903-sample_report_screenshot.png)](https://xcp-ng.org/forum/topic/11341/powershell-script-for-backup-summary-reports?ref=xen-orchestra.com) ## **🆕** Misc I know, September is the big "back to school", but still, the sheer size of the "Misc" section deserve a big kudo to the XO team! ### SSH keys in CloudConfig templates We’ve added a new `sshKey` variable to Cloud config templates. Previously, you could already inject your public key when launching a VM, but this update simplifies the entire process. You'll no longer have to manage multiple versions of the same template. It’s a simple way to keep your configuration tidy and ensure secure access right from the start. ![](https://xen-orchestra.com/blog/content/images/2025/09/489540063-75a66433-30c5-4e81-9b45-de272a28291f.png) New sshKey variable in the template selector ### Configurable import timeout You can now set a custom timeout when importing a VM from a URL. This feature was added in response to partner feedback requesting more flexibility for lengthy transfers. 💡 Our partner and Public Cloud provider [Cloud Temple](https://www.cloud-temple.com/en/?ref=xen-orchestra.com), is using a large S3 storage acting as a central place for all their VM templates (generated via Packer). When they are deploying new pools, they are importing dozens of templates at once, and in parallel. This created some timeout on our HTTP library, so we made it configurable, and everyone is happy now! To configure the timeout, use the following parameter: ``` [jsonrpc-api] xvaImportFromUrlTimeout = '6s' ``` By adjusting the timeout to match your environment, you can prevent unexpected failures during large or slow downloads, ensuring a smooth import process every time. ### Removing Jest and unused dependencies We've removed [Jest](https://jestjs.io/?ref=xen-orchestra.com) and a few related dependencies from the codebase. They were no longer in use but they still lingered in our stack. Dropping them shrinks the overall dependency footprint and reduces the potential attack surface. This cleanup doesn’t affect how you use Xen Orchestra, but it makes the project lighter and more secure behind the scenes. ### Natural sorting for PIFs and VIFs Physical interfaces (PIFs) and virtual interfaces (VIFs) are now sorted naturally. This means names like `eth2` will appear before `eth10`, instead of being ordered alphabetically as plain text. ![](https://xen-orchestra.com/blog/content/images/2025/09/493821076-9d917311-0864-40c2-8df3-304337e6fb1a.png) PIF sorting before the update ![](https://xen-orchestra.com/blog/content/images/2025/09/493821105-01e4f7f0-60c4-45a3-bf3b-9b72a179768f.png) PIF sorting since the XO 5.111 update This small change makes scanning and selecting interfaces much more intuitive, especially when managing hosts with multiple NICs. ### Template UUIDs visible in the list view The template list now displays each template's UUID, next to its name. This makes it easier to find the exact template you’re working with , especially when many of the templates have similar names. This is small update will help you work faster, while minimizing mistakes. ![](https://xen-orchestra.com/blog/content/images/2025/09/486670748-b7887878-148b-4dea-bc21-278040d3cc01.png) Template UIDs in the template list view ### XOSTOR - Tie breaker status XOSTOR now display resources without an associated volume. This includes tie-breaker and diskless ressources, which simplifies troubleshooting and advanced usage. ![](https://xen-orchestra.com/blog/content/images/2025/09/492700371-0ec3a13f-df11-46f8-a05d-ac94d8fd2d67.png) Resource list with a custom filter, to show diskless resources in use [Posts](https://xen-orchestra.com/blog/ghost/#/posts/?type=draft) ### Xen Orchestra 5.110 URL: https://xen-orchestra.com/blog/xen-orchestra-5-110/ Last updated: 2025-08-28T12:24:15.000Z As summer winds down in Europe, August often feels like a long pause (especially in France), where the country collectively goes into standby mode before September brings everything back to full speed. But at Vates, we somehow missed the memo again: we’ve been busy building a hefty release with big steps forward in VMware migration, backup, and plenty more. Consider this our own “back-to-school” release—minus the mandatory essay on *“What I did this summer.”* Enjoy the read! 🎵 The podcast version of our release is available on [Spotify](https://open.spotify.com/episode/4VNhQcEEwRHHPUfPJJqqNn?si=zWPpvZ-ETzSsJFQ7xf4YkA&ref=xen-orchestra.com). ## 👨‍🚀 Project & Community Plenty happening on the ecosystem front this month: VEEAM’s first pre-release with native XCP-ng support, our presence at Datacore Days, and the upcoming Xen Summit where we’ll be deeply involved. We also welcome a new distributor in France, and share some valuable feedback from users who successfully migrated away from VMware. ### VEEAM Closed beta started ![](https://xen-orchestra.com/blog/content/images/2025/08/Veeam_logo.png) If you’re part of the "Veeam 100" Program, you can already test the brand new XCP-ng plugin, bringing native compatibility between the Vates stack and Veeam products. We’re also running the plugin internally and sharing direct feedback with Veeam, to make sure the first official release is as solid and polished as possible.If you’re currently running VMware + Veeam, this means one less habit to change. Your backup workflows stay the same, while the infrastructure underneath can move to XCP-ng. Combined with our new VMware migration tool (10–20x faster, with warm migration support), leaving VMware is becoming a LOT easier! ### Vates at DataCore days We’re thrilled to be part of the 2025 edition of DataCore Days, happening October 6–7 at the Palais des Papes in Avignon. [Vates at DataCore Days 2025We’re excited to announce that Vates will participate in the 2025 edition of DataCore Days, taking place on October 6–7 at the Palais des Papes conference center in Avignon.![](https://xen-orchestra.com/blog/content/images/icon/logo64-15.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/chelsea-essig-2dQJnBFsc4Q-unsplash.jpg)](https://vates.tech/blog/p/97f96afc-5f56-4868-bb65-ddede659f226?ref=xen-orchestra.com) This event is a great opportunity to connect with the DataCore team as we explore new technical collaborations and joint initiatives. We’re already in active discussions and look forward to sharing more news in the coming months. ### Xen Summit 2025 Many people from Vates, including myself, will be at the upcoming Xen Summit (just a few weeks away)! Our commitment to the Xen Project is reflected not only in the number of talks we’ll deliver, but also in the design sessions we’ll be co-leading. And of course, we’re proud to sponsor the event once again, contributing not just code, but also ideas, funding, and organization. Read on for more details about the program and what to expect: [Xen Summit 2025, Talks & PizzaXen Summit 2025 is just weeks away — with Vates on stage in San Jose and hosting a pizza-powered watch party back in Grenoble.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-25.png)XCP-ng BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/xen-summit-2025-banner.webp)](https://xcp-ng.org/blog/2025/08/26/xen-summit-2025-talks-pizza/?ref=xen-orchestra.com) ### Consolidating our French market Maybe some of you know this already, but we are a French company! That said, our main market has always been outside of France, as VMware initially had a firm grip on the French virtualization space. Over the last few years, though, we’ve seen a growing number of French users turning to our solutions. To strengthen our position at home, we’ve partnered with NeoVAD, a value-added French distributor, to make our stack more accessible to partners and customers across the country. [Vates partners with NeoVAD to accelerate adoption of its virtualization stack in FranceVates teams up with NeoVAD to strengthen its presence in France and bring its open-source virtualization platform to a wider network of partners. Together, we’re making it easier for the French IT channel to offer a sovereign, robust alternative to VMware.![](https://xen-orchestra.com/blog/content/images/icon/logo64-16.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/vardan-papikyan-DnXqvmS0eXM-unsplash.jpg)](https://vates.tech/blog/vates-partners-with-neovad-to-accelerate-adoption-of-its-virtualization-stack-in-france/?ref=xen-orchestra.com) 🥖 To support this momentum, we’re also preparing a full French-language version of our website, which will be available in the coming weeks. ### Exploring alternatives to VMware It’s been almost two years since VMware was finally acquired by Broadcom, and during that time we’ve had hundreds of conversations with customers looking to migrate away from VMware. Through these discussions, we’ve built a strong understanding of the virtualization landscape and where our stack fits. To share that knowledge, we recently published our first **2025 Platform Guide**, comparing Vates VMS with other platforms in today’s market. If you’re currently exploring your options to move away from VMware, don’t miss this guide. [Open Virtualization Platform - VM infrastructure made simple![](https://xen-orchestra.com/blog/content/images/icon/apple-touch-icon-12.png)VM infrastructure made simpleCHUCK COLBY (IT/OT Solutions Architect Nor-Cal Controls ES.)![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-vms-vs-vmware-1.png)](https://vates.tech/vmware-alternative/?ref=xen-orchestra.com) With the community updates covered, it’s time to unpack what’s new in this release. --- ## 💾 Backup On the backup side of things, we've addressed a couple issues reported by our customers. Thank you to our partners and our community for your feedback! Your assistance is crucial in making Xen Orchestra a more useful and reliable solution. ### Extended timeout for S3 backup listings Not all S3 providers are created equal: some respond much more slowly than others. To handle this, we’ve adjusted our backup listing process with longer timeouts when necessary (yes, Backblaze, we mean you). ### Fixed backup sequences Previously, if a backup job in a sequence was skipped because there were no VMs to back up, the entire sequence would stop, which was frustrating when you had other jobs waiting to run behind it. Now, sequences will continue even if a job is skipped. So, if one backup job is empty, the rest of your workflow won't be blocked. ### Fixed `footer1 !== footer2` backup error Some users encountered a backup error with the message `footer1 !== footer2` when listing backups. This issue is now resolved, and backup listings should work smoothly without triggering the error. ![](https://xen-orchestra.com/blog/content/images/2025/08/xoa_backup_error_2.png) Backup listing showing the 'footer1 !== footer 2' error ## 🥝 Core UI Even though things usually slow down during the summer months, we've kept refining the Core UI with little additions that combine to make XO more usable than ever. ### Improved progress bar We’ve updated the core interface so the progress bar and data ruler now work together seamlessly. This way, you always know exactly how far along the process is and how much data is involved. ### Stay on the same tab when changing VMs In previous versions of XO 6 and XO Lite, switching between VMs would default back to the Console tab every time, even if you were viewing other tabs like Network or Storage. This was cumbersome when comparing settings across VMs since you'd have to find and re-click the right tab every time. Now, XO retains your current tab and keeps it selected when you move to another VM. This makes it faster and more intuitive to compare settings or evaluating multiple VMs. ## 🛰️ XO 6 Quality-of-life improvements just keep coming! We've just added a Backup jobs view to XO 6, and since we documented the REST API in Swagger, the API is now available directly from the XO 6 interface (see the Misc section). 💡 Remember: you can try the new XO 6 UI today: just add `/v6` to your XOA URL. ### Backup jobs view XO 6 now has a dedicated **Backup jobs** view, which brings all your backup jobs together in one place. There are multiple columns showing each job's status, any scheduling associated with them, and you can jump straight into relevant actions, without needing to search across different screens and sections. ![](https://xen-orchestra.com/blog/content/images/2025/08/481667051-cdbe4414-fe7a-41b2-bde0-7e7efaa87fd7.png) Backup jobs view in XO 6 This update to the XO 6 UI gives a much clearer picture of what's happening in your environment and makes it easier to deal with multiple backup jobs! ## 🔭XO Lite Just as XO 6 now links directly to Swagger, we’re making it easier to access useful external resources from XO Lite, starting with Weblate. ### Easier access to translations You’ll now see a link to Weblate right next to the language selector in the **Settings** menu. This means that if a translation is missing or needs a tweak, you can jump straight to our translation platform and fix it in just a few clicks. ![](https://xen-orchestra.com/blog/content/images/2025/08/478880354-1dd3b823-1150-4a0e-85c0-670bbe4e2648.png) Link to Weblate from the XO Lite interface Big thanks to everyone in the community for helping make Xen Orchestra better, and a special shout-out to **p-bo** for suggesting this improvement! You can start contributing here: [Get involved in Xen Orchestra!Xen Orchestra is being translated into 12 languages using Weblate. Join the translation or start translating your own project.![](https://xen-orchestra.com/blog/content/images/icon/weblate-180-7.png)WeblateMichal Čihař![](https://xen-orchestra.com/blog/content/images/thumbnail/open-graph.png)](https://translate.vates.tech/engage/xen-orchestra/?ref=xen-orchestra.com) [p-bo - Overviewp-bo has 184 repositories available. Follow their code on GitHub.![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-23.svg)GitHub![](https://xen-orchestra.com/blog/content/images/thumbnail/12208593-1)](https://github.com/p-bo?ref=xen-orchestra.com) ## 🪐 XOA **Debian 13** and **Ubuntu 22.04** are now available in the XO Hub. This gives you more up-to-date options for setting up your environment, with the benefits of the latest system improvements or long-term support from these distributions. ![](https://xen-orchestra.com/blog/content/images/2025/08/xo-hub-debian-13-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/08/xo-hub-ubuntu-22-04-1.png) Debian 13 and Ubuntu 22.04 templates in the XO Hub ## 📡 REST API It’s been a while since we started working on the Swagger API documentation. Thanks to the ongoing efforts of our wonderful team, the doc is more complete than ever! This month we not only added additional endpoints, but also made the API easier to use by supplying the full specification in JSON format. ### Task and host SMT endpoints added to Swagger We’ve added the `get` and `getId` endpoints for tasks to our Swagger documentation. With these endpoints, you can pull the complete list of tasks or a specific task based off of a specific ID, so it’s much easier to understand how they work and test them directly from the Swagger interface. Also, we've added the host simultaneous multithreading (SMT) endpoint: ![](https://xen-orchestra.com/blog/content/images/2025/08/474044866-c46329af-07b9-4eef-bdce-6a2acf6a0bf2-2.png) ![](https://xen-orchestra.com/blog/content/images/2025/08/474909122-90bab6b3-4c5f-4466-99e3-793a2675ebc5-1.png) These improvements are all part of the effort we started in the XO 5.104 release, to provide full documentation of the REST API and to be compliant with OpenAPI. We want to give developers and integrators all the tools they need to experiment with the API, automate their workflows, and construct integrations without any guesswork. [Xen Orchestra 5.104This month at Vates, we’re bringing you a wave of updates across the board! Our virtualization stack is now validated for Red Hat Enterprise Linux 9, and we’ve announced a strategic partnership with VyOS to enhance networking capabilities in Vates VMS.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-22.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/rodion-kutsaiev-b6Kfzd8pDaQ-unsplash-5.jpg)](https://xen-orchestra.com/blog/xen-orchestra-5-104/#swagger-and-openapi-integration-a-big-step-forward) ### Swagger spec available in JSON You can now retrieve the full Swagger/OpenAPI specification in JSON format through the API. This is particularly useful if you want to interface Xen Orchestra with another tool or generate client code automatically, as you can point your tooling to the spec. This small change is one step towards full API documentation and OpenAPI compliance! ## ☸️ DevOps Tools Our DevOps Tools team keeps improving third-party integrations, making it easier than ever to automate with our stack. ### New releases for Terraform and Pulumi providers! This new version introduces a new field, `memory_min`, for the VM resource and makes a slight change to the `memory_max` field, which now sets both the dynamic and static maximum memory limits and providing better control of VM memory. [Release v2.2.0 · vatesfr/pulumi-xenorchestraWhat’s Changed feat: Update TF provider to get VM memory improvements by @gCyrille in #420 Full Changelog: v2.1.0...v2.2.0 JavaScript/TypeScript: @vates/pulumi-xenorchestra Python: pulumi-xenorc…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-20.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v2.2.0)](https://github.com/vatesfr/pulumi-xenorchestra/releases/tag/v2.2.0?ref=xen-orchestra.com) [Release v0.33.0 · vatesfr/terraform-provider-xenorchestraWhat’s Changed fix: add memory\_min field and change memory\_max behavior by @gCyrille in #362 Full Changelog: v0.32.0...v0.33.0![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-21.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v0.33.0)](https://github.com/vatesfr/terraform-provider-xenorchestra/releases/tag/v0.33.0?ref=xen-orchestra.com) Naturally, the Go SDK has been updated so both providers can take advantage of these new features: [Release v1.4.0 · vatesfr/xenorchestra-go-sdkWhat’s Changed build(deps): bump actions/checkout from 4 to 5 by @dependabot\[bot\] in #28 build(deps): bump github.com/sourcegraph/jsonrpc2 from 0.0.0-20210201082850-366fbb520750 to 0.2.1 by @depen…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-22.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v1.4.0)](https://github.com/vatesfr/xenorchestra-go-sdk/releases/tag/v1.4.0?ref=xen-orchestra.com) ## 🐦 VMware to Vates (V2V) We’ve got some exciting changes this month for V2V migrations! We've implemented a new backend and resolved a key issue, so migrations are more stable and ready to handle more complex configurations. Below is a detailed guide for using the new NBDkit and VDDK backend. Follow it closely to take full advantage of the improvements and see how they work in practice! ### NBDkit + VDDK: How to enable the new V2V backend In [last month’s release](https://xen-orchestra.com/blog/xen-orchestra-5-109/#new-v2v-backend-with-nbdkit-and-vddk), we introduced a completely new V2V backend, based on NBDkit and VDDK. It replaces the old approach, and delivers : - Warm migration for all ESXi versions - Improved performance - A cleaner design for easier maintenance #### Key improvements **Ease of use and compatibility**: the new backend reads only allocated blocks, which speeds up transfers. Additionnally having snapshot does not have a notable performance impact. There’s no longer a need for temporary NFS storage or remote VSAN targets. The system is also designed to handle very large disks, with support for sizes beyond 2 TB (planned for a future update). **The interface has been polished** as well. There’s now a progress bar visible from the start of the migration, speed metrics are recorded in the VDI, and snapshots are created at each step. This allows the process to pause and resume safely without needing to create multiple VMs. Finally, UEFI VMs are no longer forced into Secure Boot mode, avoiding previous boot issues. **Performance gains can be significant**, though results depend on the environment. **In the best case**, when using VMs with many snapshots or mostly empty disks, migrations can be up to 100 times faster. In our high-performance lab, we measured around 150 MB/s per disk and up to 500 MB/s total, which means an infrastructure with 10 TB of data could be migrated in a single day, with less than five minutes of downtime per VM. ![](https://xen-orchestra.com/blog/content/images/2025/08/1754568923689.jpeg) A test case of importing a Debian VM with around 30GiB disk. **In less favorable situations**, such as a fully allocated disk with no snapshots and a powered-off VM, improvements are smaller, mainly due to compression between XO and ESXi. In general, the limiting factor is the import speed on the XCP-ng side, which scales well until the storage is saturated. Most of the transfer occurs while the VM is running, so production data remains safe. 💡 VSAN+VDDK compatibility has not been tested yet, we'll keep you posted! #### Preparing the Environment First, **make sure Xen Orchestra is up to date**. The import page now includes an automatic check that highlights errors and warnings before migration. Errors must be resolved, and warnings should be addressed when possible: ![](https://xen-orchestra.com/blog/content/images/2025/08/ima2ge.png) ![](https://xen-orchestra.com/blog/content/images/2025/08/image-2.png) ![](https://xen-orchestra.com/blog/content/images/2025/08/477501220-8ebda4cc-fe11-4bfb-ac6e-d1e6025c023d-2.png) Error check before the VM import Next, **install the required dependencies:** nbdkit, the VDDK plugin, and nbdinfo. On Debian, these are available through the contrib repository as `nbdkit-plugin-vddk` and `libnbd-bin`. You can also compile [nbdkit](https://gitlab.com/nbdkit/nbdkit?ref=xen-orchestra.com) and [libnbd](https://gitlab.com/nbdkit/libnbd?ref=xen-orchestra.com) from source on GitLab, but the correct dependencies must be in place for nbdinfo and VDDK. Finally, **download the VMware Virtual Disk Development Kit** (VDDK) from the [Broadcom developer portal](https://developer.broadcom.com/sdks/vmware-virtual-disk-development-kit-vddk/latest?ref=xen-orchestra.com). Select the Linux tar.gz archive and upload it through the Xen Orchestra interface. #### The payoff Setting up the new backend requires a bit more effort than before, but the results are worth it: faster migrations, warm mode support across all ESXi versions, and a process that scales far better than the previous solution. ### Fixed import issue with large disk sets We’ve fixed a bug that blocked V2V imports when the VM had more than 10 disks. If you ran into this limitation previously, you can now successfully import your VMs. This fix came out of user feedback, helping us make migration more robust for complex environments. ## 📖 Documentation & guides We never stop improving the XO documentation! This month, we filled in some gaps, updated our existing pages, and took in some feedback from the community. Thanks to everyone who shared their input! ### Fixed broken anchors We've fixed an issue in the Xen Orchestra documentation where links with HTML anchors were not working properly: instead of jumping directly to the desired section, they always landed at the top of the page. Now, anchored links take you to the specific sections as intended, so you don't have to hunt for the wanted content, especially in long pages. ### Large backup deltas explained The documentation has been updated to explain why some incremental backup deltas can end up larger than expected. It also describes common scenarios that lead to large deltas, things to look for, and ways to investigate or reduce the delta size. ![](https://xen-orchestra.com/blog/content/images/2025/08/Capture-d---cran-2025-08-26-140704-1.png) Excerpt from the new documentation on large backup deltas This information will help set expectations and prevent confusion when the backup report unusually high sizes. Thank you to the community in providing valuable input on a specific scenario that adds further clarity! Read the updated documentation here: [Incremental Backups | Xen Orchestra | XO Documentation\_NOTE:\_ Formerly known as Continuous Delta backups![](https://xen-orchestra.com/blog/content/images/icon/favicon-12.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline.png)](https://docs.xen-orchestra.com/incremental%5Fbackups?ref=xen-orchestra.com#understanding-large-deltas) ### Network bonding explained The Xen Orchestra documentation now gathers all the key information about network bonding in one place. Previously, details were scattered across blog posts and other resources, which was indeed hard to follow. ![](https://xen-orchestra.com/blog/content/images/2025/08/Capture-d---cran-2025-08-26-140942.png) Excerpt from the new documentation on network bonding The docs provide a clear explanation of what network bonding is and how to set it up, making it the main reference for this feature. You can now access everything you need directly in the official documentation. Check out the updated section here: [Infrastructure management | Xen Orchestra | XO DocumentationThis section is related on how to manage your XCP-ng/Citrix Hypervisor infrastructure.![](https://xen-orchestra.com/blog/content/images/icon/favicon-13.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-1.png)](https://docs.xen-orchestra.com/manage%5Finfrastructure?ref=xen-orchestra.com#network-bonding) ### Improved load balancing doc We've reworked and expanded the the documentation for load balancing. The doc now makes it clearer what load balancing is, how the load balancing plugin works, and how to create or edit a load balancing plan. Also, all previously missing parameters are now properly documented. ![](https://xen-orchestra.com/blog/content/images/2025/08/Capture-d---cran-2025-08-26-141147.png) Excerpt from the updated doc on load balancing On top of that, we've made the style more consistent, reworked the structure and added illustrations to help visualize complex processes. As a result, following instructions should be more straightforward and intuitive. Check out the updated page here: [Load balancing | Xen Orchestra | XO DocumentationBasic notions![](https://xen-orchestra.com/blog/content/images/icon/favicon-14.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-2.png)](https://docs.xen-orchestra.com/load%5Fbalancing?ref=xen-orchestra.com) ### `usage-report` plugin clarified The `usage-report` plugin documentation is better organized now. We've explained the parameters in more detail, particularly the `all` toggle and what it does. As a result, you can now set up the plugin without confusion. ![](https://xen-orchestra.com/blog/content/images/2025/08/Capture-d---cran-2025-08-26-141333.png) Preview of the updated usage-report plugin documentation On top of that, we've refined the overall section, touched up the style a little and fixed a few errors. The revised documentation should be more useful and easier to read than ever. Feel free to read it here: [Infrastructure management | Xen Orchestra | XO DocumentationThis section is related on how to manage your XCP-ng/Citrix Hypervisor infrastructure.![](https://xen-orchestra.com/blog/content/images/icon/favicon-15.ico)Xen Orchestra Documentation![](https://xen-orchestra.com/blog/content/images/thumbnail/vates-xo-logo-smol-new-baseline-3.png)](https://docs.xen-orchestra.com/manage%5Finfrastructure?ref=xen-orchestra.com#usage-reports) ## 🌐 Translations ### 5 languages updated A big thank you to our community for their ongoing efforts in translating Xen Orchestra! ![](https://xen-orchestra.com/blog/content/images/2025/08/687474703a2f2f7472616e736c6174652e76617465732e746563682f7769646765742f78656e2d6f72636865737472612f6d756c74692d6175746f2e737667.svg) Xen Orchestra translation status This month, special attention was given to **Czech**, **German**, **Italian**, **Dutch**, and **Brazilian Portuguese**. Want to help translate Xen Orchestra or improve existing translations? You’re more than welcome to join in [here](https://translate.vates.tech/?ref=xen-orchestra.com). ## **🆕** Misc Even though most of our efforts are focused on XO 6, we’re still rolling out general improvements across the software, so the Misc section is never empty! ### Ipmitool plugin now supports Dell servers The **Ipmitool** plugin was created to provide hardware information on 2CRSI servers when running XCP-ng hosts. We have adapted the plugin to service Dell servers as well, extending the capabilities and generalizing the plugin. The goal stays the same: we will give you the same great hardware information through Xen Orchestra, whether you are using 2CRSI or Dell servers. This change is part of our ongoing effort to make XO more versatile and useful across different environments, starting with what our partners need most. ![](https://xen-orchestra.com/blog/content/images/2025/08/474546234-ea84c43c-557d-4c9f-99db-b8baf77d181a.png) Ipmitool plugin showing information for Dell servers ### Automated end-to-end tests for `xo-server` We've made our first steps toward automated QA and end-to-end (e2e) testing for `xo-server`. It's part of a larger effort to improve the reliability of Xen Orchestra and make the project easier to maintain over the long term. We began by looking at what's missing in the REST API, then moved on to defining the testing architecture and tooling. From now on, we are able to automatically run e2e tests on key features, which allows us to catch regressions sooner, increase overall stability, all without slowing down development. ### Direct link to Swagger We’ve made it easier to work with the REST API by adding a direct link to the Swagger documentation. Instead of finding the Swagger URL by yourself, you can now access the page straight from XO 5 or XO 6\. Swagger gives you a complete list of the available endpoints, along with parameters and expected responses. This will be a great resource if you’re integrating XO with other tools or building automations. The link is available: - **From XO 5**, in the navigation bar - **From XO 6**, by clicking the **Account menu** button: With this small addition, the documentation is only a click away while you're using Xen Orchestra, so developers and integrators can access it without additional steps. From there, you can view the API, see the request and response formats, and even test the calls if you have the proper credentials. ![](https://xen-orchestra.com/blog/content/images/2025/08/482105184-3ac2bb40-d357-45dc-8638-56f6c9895061-1-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/08/482104957-02a5726e-323f-46fd-bdbb-4e352e0b9038-1-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/08/482106214-93fa5ec9-4ee6-4b90-9fa1-f7ced3211d50-1.png) Link to Swagger, from XO 5 and XO 6 ### Xen Orchestra 5.109 URL: https://xen-orchestra.com/blog/xen-orchestra-5-109/ Last updated: 2025-07-31T15:09:25.000Z It’s mid-summer up here in the Northern Hemisphere, and while many are taking a break, things haven’t slowed down on our side. This month’s release is a good opportunity to look back at what’s been moving: XO 6 is progressing well, same for our work on Windows PV drivers, and we’re running some interesting tests on XCP-ng too. Security updates? Still coming. And the backup engine we started rewriting months ago? It’s now considered stable. Both XO 6 and XO Lite are gaining momentum: we’re on track with our goals. And to wrap it up, don’t miss the user feedback on how the auto health check backup feature saved their day. Real stories like this matter. Enjoy the update! 🔉 Looking for the Podcast format? Find it on [Spotify](https://open.spotify.com/episode/3xnAHwcelmUVude0oRRjqK?si=kgWCYXjET9O53h6JsO5nVA&ref=xen-orchestra.com). ## 👨‍🚀 Project & Community What’s going on at Vates? A lot, and not just on the XO side. We’ve got updates on XCP-ng, a current status on Windows PV drivers, a fresh recap on XO 6… and honestly, so much is coming in September that we’re not even sure how we’ll announce it all. ### Your own GPU-Powered LLMs with XCP-ng? Ever wondered if you could spin up a dedicated LLM VM *right inside* your existing virtual infrastructure? Short answer: **yes**. But why would you want to? Start here with the reasons behind it: [Building an AI-ready infrastructure with Vates VMSAI is transforming industries and reshaping how companies approach infrastructure. Beyond performance, key questions emerge around security, sovereignty, and technical capabilities, especially as organizations consider where and how to run their AI workloads.![](https://xen-orchestra.com/blog/content/images/icon/logo64-14.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/ai-infra-banner-1.png)](https://vates.tech/blog/building-an-ai-ready-infrastructure-with-vates-vms/?ref=xen-orchestra.com) And yes, it works, even with aging hardware. You’ll see how easy it is to assign a GPU to a VM without affecting the rest of your setup. Follow our step-by-step guide: [Your own GPU-Powered LLMs with XCP-ngDiscover how easy it is to deploy a fast, local AI assistant on your infrastructure using XCP-ng and a single GPU.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-22.png)XCP-ng BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/gpullmxcp-1.jpg)](https://xcp-ng.org/blog/2025/07/28/your-own-gpu-powered-llms-with-xcp-ng/?ref=xen-orchestra.com) No more excuses. It's time to run local LLMs! ### Inside the making of Xen Orchestra 6 We didn’t start XO 6 just for fun, there were real needs behind it. Over the years, infrastructures have grown massively, and we hit some clear limits with the old architecture. So instead of patching over them forever, we decided to build something better from the ground up: cleaner, faster, and more future-proof. This article explains the reasoning behind the project, where we are today, and what’s coming next: [Inside the making of Xen Orchestra 6Xen Orchestra 6 is taking shape. From a redesigned UI to deep architectural changes, this new version brings better performance, improved workflows, and modern DevOps integrations, all shaped by community feedback and real-world use cases.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-21.png)Xen Orchestra BlogMarc Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/before-after-xo-6-min-1.png)](https://xen-orchestra.com/blog/inside-the-making-of-xen-orchestra-6/) But let’s talk numbers. Here’s a glimpse at performance on our reference setup: 1000 VMs, across 20 pools and 40 hosts: And that’s just scratching the surface. Obviously, smaller setups won’t notice much, but for those managing larger infrastructures, the difference is huge. We’re seeing more and more deployments worldwide with 10,000+ VMs, and for those environments, XO 6 isn’t just “nice”, it’s essential! Load times are slashed, responsiveness is way up, and the whole thing becomes actually pleasant to use. And this is just the beginning. ### Windows PV drivers: updates and roadmap If you’re running any Windows VMs, this is a must-read. We’re proud to announce that **Vates is now officially part of the Windows PV drivers maintainer team *upstream* in the Xen Project**. It’s a strong signal of our long-term commitment: we’re not just using the stack, we’re helping to build and maintain it at the source. But there’s more. We’ve also made solid progress on our downstream work, with concrete improvements already available for our users. Check out the full update here: [Windows PV drivers: update and roadmapFrom downstream fixes to upstream collaboration, here’s where we stand with Windows PV drivers. And where we’re headed next!![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-20.png)XCP-ng BlogTu Dinh![](https://xen-orchestra.com/blog/content/images/thumbnail/winpvdriver.jpg)](https://xcp-ng.org/blog/p/f9f043e2-0409-4c4c-90aa-0cb03a8e6a61/?ref=xen-orchestra.com) ### XCP-ng updates This month brought a solid round of updates on the XCP-ng side, especially focused on security. As usual, we’re making sure both LTS versions stay up to date, with quick responses to upstream advisories and ongoing improvements from real-world usage. If you're still running **XCP-ng 8.2 LTS**, note that it will reach end-of-life in just a few months. Now’s a good time to start planning your upgrade to 8.3 if you haven’t already. In the meantime, you can find the latest 8.2 security updates here: [July 2025 Security and Maintenance Update for XCP-ng 8.2 LTSNew security and bugfix updates are available for XCP-ng 8.2 LTS.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-17.png)XCP-ng BlogSamuel Verschelde![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1495616811223-4d98c6e9c869)](https://xcp-ng.org/blog/2025/07/03/july-2025-security-and-maintenance-update-for-xcp-ng-8-2-lts/?ref=xen-orchestra.com) The AMD XSA is also available: [July 2025, Security Update #2 for XCP-ng 8.2 LTSNew security updates are available for XCP-ng 8.2 LTS.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-24.png)XCP-ng BlogGaël Duperrey![](https://xen-orchestra.com/blog/content/images/thumbnail/82secjuly25-1.jpg)](https://xcp-ng.org/blog/2025/07/29/july-2025-security-update-2-for-xcp-ng-8-2-lts/?ref=xen-orchestra.com) As for XCP-ng 8.3, we’ve released two separate update trains. First, a batch of general fixes and improvements: [July 2025 Security and Maintenance Update for XCP-ng 8.3 LTSNew security, bugfix and enhancement updates are available for XCP-ng 8.3 LTS.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-18.png)XCP-ng BlogSamuel Verschelde![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1473221326025-9183b464bb7e)](https://xcp-ng.org/blog/2025/07/03/july-2025-security-and-maintenance-update-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) Then, a dedicated update addressing the AMD-related security advisory (XSA-471). **Stay up to date: especially when security is involved.** [July 2025 Security Update #2 for XCP-ng 8.3 LTSNew security and bugfix updates are available for XCP-ng 8.3 LTS.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-19.png)XCP-ng BlogGaël Duperrey![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1606639386779-99d873cac706)](https://xcp-ng.org/blog/2025/07/15/july-2025-security-update-2-for-xcp-ng-8-3-lts/?ref=xen-orchestra.com) --- Alright, now let’s dive into what’s new in this July release. ## 💾 Backup It’s been three months since we released the major overhaul of our backup code, and the results are in: things are looking solid. After extensive testing and real-world usage, we’re happy to report it’s now stable enough to promote it to the **stable channel**, starting with last month’s release. Curious about what changed and why it matters? Check this previous blog post: [Next-gen XO backup engine: beyond VHDDiscover how we’re building a smarter, format-agnostic backup system to meet the demands of tomorrow’s infrastructure.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-20.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/backupnew-2.jpg)](https://xen-orchestra.com/blog/next-gen-xo-backup-engine-beyond-vhd/) ### Better error reporting on remote read failures When a restore failed due to an incomplete backup file (like a legacy VHD that couldn’t be fully read), the error message was often vague and not particularly helpful. This understandably led some users to reach out to support just to figure out what went wrong. We’ve now improved the error handling: if a remote can’t provide the full file during a restore, you’ll get a much clearer and more actionable message. Troubleshooting these cases should be far easier from now on. #### Saving the day Here’s a real-world story that perfectly illustrates why backup verification matters. One of our users had a backup stored on a NAS using NFS. Everything looked fine, the backup completed successfully. But later, the NAS started failing silently, and the disk storing that backup became corrupted. The user wouldn’t have noticed… if not for the **Backup Health Check** feature in Xen Orchestra. That’s what flagged the issue: long before they actually needed to restore anything. Without it, the corrupted backup would’ve gone unnoticed until it was too late. Instead, they had time to react and ensure their data was truly safe. This is exactly why we always say: **a backup you haven’t tested isn’t really a backup**. In this case, that one check made all the difference. It might just save your day too. ## 🥝 Core UI Work on the Core UI is moving along nicely: all part of our plan to make the new interface the default for Xen Orchestra in the next few months. Bit by bit, we’re closing the gap with the current UI while also bringing a much more modern and streamlined experience. Stay tuned, it’s coming together fast! ### Updated progress bar design We've updated the progress bar in the web interface to better reflect our current design system. The new progress bar keeps the same behavior, while giving XO 6 and XO Lite a more unified look and feel. It's a small visual update, but is part of a broader effort in modernizing the interface as a whole. ![](https://xen-orchestra.com/blog/content/images/2025/07/469227905-b2616a80-1762-4677-b414-7b4e28d3cb3e.png) Updated progress bar ### Data ruler component We’ve added a new UI component called `DataRuler`. It's designed to present storage or memory usage in a compact and readable format, featuring clear visual markers. Like the updated progress bar, this addition is part of our ongoing efforts to align the UI with our latest design system. ![](https://xen-orchestra.com/blog/content/images/2025/07/469111543-d2eb8712-e37b-480c-a738-4db2577c402a.png) The new Data ruler ### New icon system In XO 6 and XO Lite, we've transitioned all icons to a new, unified system. This update enhances consistency throughout the interface and simplifies future design updates. You'll notice smoother visuals and better integration with the overall design system, resulting in a cleaner and more modern UI. ## 🛰️ XO 6 💡 In case you missed it at the top, don’t forget to check out our dedicated blog post on the evolution of XO 6 and what’s coming next: ### `AlarmItem` component We're introducing a new **`AlarmItem`** component, which displays the important messages more clearly. It makes spotting issues easier and helps you react faster. This building block will further improve how notifications and warnings are shown, as we continue to refine the user experience. ![](https://xen-orchestra.com/blog/content/images/2025/07/435196898-b4385657-de69-4467-ba3d-16d839b01e72.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/435196899-92e7add1-c1ed-4883-80e4-008037c6ab78.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/435196900-c77cb94c-0865-45c5-b829-d675b778556c.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/435197020-6e843d48-db38-4fb8-9e3c-b41410402e81.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/435197548-ce96c4fa-2a98-4156-9584-a4d30aea3318.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/435197550-0e9f7b47-5c6e-477b-82dd-3d2b40f0b8af.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/435197554-9ed7c79b-9e04-4ef1-b026-35596d1ed566.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/435197559-9c57b11a-9654-4948-851e-f35101b1e4a2.png) ### Server connection page We've added a special page for connecting to a new server. It enables you to add a host to your environment by rapidly entering information like the IP address, proxy URL, username, and password. Starting a new server is made simple with this new page. No more navigating intricate menus! ![](https://xen-orchestra.com/blog/content/images/2025/07/461571177-2c572118-d908-47ec-897f-00a5555ab2eb.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/461571261-4b4c433d-bed6-467f-91a4-a9eb8cb49227.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/461571676-69c61964-28b3-4841-8bec-0a7d187a595f.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/461571785-4b78873c-51ed-4415-9c45-5b06126517cf.png) New server connection page ### Pool dashboard Now the Pool default view (Dashboard) is available and displays a recap on the pool. ![](https://xen-orchestra.com/blog/content/images/2025/07/472082672-7c198253-5462-4d4f-b637-df94ecfe9c53.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/472082573-8da2b37b-1f1d-4bcb-9dbc-4d0798e51c3f.png) Another extra view finished, we are on schedule for December and getting finally a release of XO starting with 6.0! ### Alarms in the site dashboard The site dashboard has been updated with a new section called **Alarms**. This component gives you a quick overview of active alarms across your infrastructure, so you can spot issues faster and respond quickly to any developing situation. While it is a small addition, it remains a building block to make monitoring easier at a glance. ![](https://xen-orchestra.com/blog/content/images/2025/07/472111039-236359fd-3752-4f57-aa6e-fc3956561197.png) Site dashboard featuring the new Alarms section ## 🔭XO Lite XO Lite, our lightweight, embedded UI bundled with XCP-ng 8.3, continues to benefit from the progress made on shared components with XO 6\. And speaking of that… ### Migrating XO Lite to Core components We've updated XO Lite by replacing its old components with the Core components used throughout Xen Orchestra. This change helps maintain a cleaner codebase and ensures a more consistent experience. By utilizing the shared Core components, XO Lite can benefit from continuous improvements and bug fixes without additional effort, making the interface smoother and more dependable. ## 🪐 XOA We updated our XO Hub with a refresh of Ubuntu 24.04\. Even if it's minor, we used that opportunity to use even more automation, so expect other updated templates soon! ## 📡 REST API Our REST API is becoming widely used and replacing almost entire our JSON-RPC API, at least for the most used endpoints. And in the meantime, we are also improving this new API via our Swagger. ### New endpoints documented in Swagger We've added more endpoints to Swagger, as part of our effort to enhance the API documentation since the 5.104 release: - **Alarms** (Hosts, networks, PIFs, pools, SRs, VBDs, VDIs, VDI snapshots, VIFs, VM controllers, VM snapshots, VM templates and VMs) - **Pools** (dashboards, stats) - **Groups** (create, update, delete) - **User** (create, update, delete) Now that these endpoints are documented and available in Swagger, developers and integrators can more easily understand how they operate, test them and build around them. This is one more step in our long-term goal to make the entire Xen Orchestra API clearly documented and OpenAPI-compliant. You can read more on this [previous blog post](https://xen-orchestra.com/blog/xen-orchestra-5-104/#swagger-and-openapi-integration-a-big-step-forward). ![](https://xen-orchestra.com/blog/content/images/2025/07/459983915-27706307-53d9-4631-a292-5a5511567545.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/462533554-5cf7b8d0-280a-42f4-8930-4ac4feb404da.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/461870022-561c90fb-06b3-455a-990b-34824ba0d0c3.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/461881753-b00241c6-bba8-439c-89da-5343c1352055.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/463260303-a0ffc677-198c-4ec3-a4aa-2e37b8e84c23.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/466948264-144a743d-95b6-46fe-9126-3619aa90e5cb.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/467085161-306274f7-64d4-47f3-86c2-1fd5676e51d3.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/467946206-d0346bb2-151b-434d-9f42-7acdb2596b58.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/469793478-76f1e90a-da25-43c8-95ee-870e9b19e973.png) Endpoints newly documented in Swagger ## ☸️ DevOps Tools Even with much of the team away in July, we still managed to ship a few improvements, because progress never really stops. ### New release of our XO Cloud Controller Manager It’s still early days, but we’ve just published a new release of the **XO CCM**. One neat addition: if you migrate a VM that’s used as a Kubernetes node, the new resident host will now be automatically synchronized at the Kubernetes level. Pretty cool, right? If you want to learn more about this feature: [feat: add cloud-node-label-sync controller to sync labels with actual XO VM state by nathanael-h · Pull Request #9 · vatesfr/xenorchestra-cloud-controller-managerPull Request What? (description) A new controller has been added to synchronise node labels with the current state of the VM. This means that the zone and region labels are no longer immutable, but…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-17.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/9)](https://github.com/vatesfr/xenorchestra-cloud-controller-manager/pull/9?ref=xen-orchestra.com) All our CCM releases are available here: [Tags · vatesfr/xenorchestra-cloud-controller-managerKubernetes Cloud Controller Manager for Xen Orchestra - Tags · vatesfr/xenorchestra-cloud-controller-manager![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-18.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/xenorchestra-cloud-controller-manager-1)](https://github.com/vatesfr/xenorchestra-cloud-controller-manager/tags?ref=xen-orchestra.com) ### New Pulumi XO provider release We’ve just released an updated version of our Pulumi provider for XO! This includes improvements to disk lifecycle management, reflecting the same fixes we made in our Terraform provider last month. A good sign that we’re committed to supporting *both* tools equally: no favoritism here (go Pulumi, go! 😂) [Release v2.1.0 · vatesfr/pulumi-xenorchestraThis new version builds on the improvements to the Terraform Provider regarding the disk lifecycle of a VM. (see the provider release ) Does the PR have any schema changes? Looking good! No breakin…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-19.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v2.1.0)](https://github.com/vatesfr/pulumi-xenorchestra/releases/tag/v2.1.0?ref=xen-orchestra.com) ## 🐦 VMware to Vates (V2V) We keep migrating more and more users away from the Broadcom/VMware ecosystem to the Vates stack (XCP-ng + Xen Orchestra). And our V2V migration tool plays a key role in making that transition as smooth as possible. But we’re not stopping there. ### New V2V backend with nbdkit and VDDK We’re currently testing a new backend for V2V migrations, built around **nbdkit** and VMware’s **Virtual Disk Development Kit (VDDK)**. While our current in-house system has done a good job, it starts to show its limits on heavier workloads: slower transfers, higher load on the ESXi host, and no support for disks over 2 TB. With this new approach, VMware disks are exposed over the **NBD protocol**, giving us: - Better performance - Lower load on the source host - Support for warm migrations regardless the ESXi versions - Cleaner, more maintainable code - No more headaches with handling different VMDK formats There’s one manual step: users will need to upload the VDDK library to Xen Orchestra. But once that’s done, the benefits are well worth it. We’re still polishing the tooling (including snapshot support and socket-based communication), and we’ll soon publish clear documentation to guide you through installation and checks. **This is a big step forward in making migrations even faster, safer, and simpler.** ## 📖 Documentation & guides Good documentation is key to understanding your tools, and getting the most out of them. This month, we focused on filling in some of the missing pieces where features existed but weren’t clearly documented. ### Backup scheduling We’ve updated the Xen Orchestra documentation to better explain [how backup scheduling works](https://docs.xen-orchestra.com/backups?ref=xen-orchestra.com#schedule). You’ll now find details on how to view existing schedules, create new ones, and configure all the relevant parameters. Clearer docs mean fewer surprises — and fewer questions! ## 🌐 Translations Making Xen Orchestra available in multiple languages wouldn’t be possible without the help of our amazing community. Every contribution makes the platform more accessible and helps grow the user base worldwide. [Weblate - web-based localizationCopylefted libre software, used by over 2,500 libre software projects and companies in over 165 countries.![](https://xen-orchestra.com/blog/content/images/icon/weblate-180-6.png)Weblate![](https://xen-orchestra.com/blog/content/images/thumbnail/og-6.png)](https://weblate.org/en/?ref=xen-orchestra.com) ### 6 languages updated A big thank you to our community for their ongoing efforts in translating Xen Orchestra! ![](https://xen-orchestra.com/blog/content/images/2025/07/687474703a2f2f7472616e736c6174652e76617465732e746563682f7769646765742f78656e2d6f72636865737472612f6d756c74692d6175746f2e737667.svg) Current translation status This month, special attention was given to **Czech**, **German**, **Spanish**, **Italian**, **Dutch**, and **Russian**. Want to help translate Xen Orchestra or improve existing translations? You’re more than welcome to join in [here](https://translate.vates.tech/?ref=xen-orchestra.com). ## **🆕** Misc That’s not all! As always, we’ve made a number of smaller improvements that don’t fit neatly into a single category, but they all add up to make Xen Orchestra more powerful, practical, and enjoyable to use. It’s the kind of progress that quietly improves your day-to-day experience. ### Clearer messages in the snapshot table This one caused confusion for quite a few users. Technically, a VM snapshot in XCP-ng is just a regular VM with a `snapshot: true` flag — but that detail isn’t always intuitive when you're managing snapshots. So we improved the messaging in the snapshot table, especially when removing snapshots. The goal: make it much clearer what’s happening, without needing to understand the low-level details. ![](https://xen-orchestra.com/blog/content/images/2025/07/461138084-27ebd1f7-0d50-4e2c-8531-be510205b8cd.png) ### Confirmation for deletion, even on a single item We heard your feedback: deleting something like an ACL or a backup (even if it’s just one item) can be risky. To help avoid accidents, we’ve added an extra confirmation modal, even for single-item deletions. A small change, but one that adds a bit more peace of mind. ![](https://xen-orchestra.com/blog/content/images/2025/07/461122979-f350644e-505e-438a-af9d-776901fc83a2.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/469210816-a0f9e9f2-c9cb-4d41-b0b3-e2dcce2ebc98.png) ### Show supported image formats in storage repositories Xen Orchestra now displays which image formats are supported by each storage repository (SR) and VM disk. When creating a new SR or virtual disk, the UI will automatically show you the supported formats, making it easier to pick the right one without guesswork. ![](https://xen-orchestra.com/blog/content/images/2025/07/470857421-080acd8d-5b0e-48f0-a40e-8bf82f958ed2.png) 💡 Note: exporting ****QCOW2** disks is currently disabled to avoid issues, as this format isn’t fully supported for export yet. ### Inside the making of Xen Orchestra 6 URL: https://xen-orchestra.com/blog/inside-the-making-of-xen-orchestra-6/ Last updated: 2025-07-22T13:04:54.000Z Xen Orchestra 6 is a major step forward for our virtualization stack, not just in how the platform looks, but in how it works and evolves. Over the past few months, we’ve shared early devblogs, collected feedback from our community and customers, and made steady progress on both design and architecture. In this post, we’re taking a step back to show you where we started, what we’ve achieved so far, and what’s coming next. ## Looking back: how we got here When we started working on Xen Orchestra 6, the goal wasn’t just to give the interface a facelift. Over the years, Xen Orchestra 5 has grown a lot, with more than 100 releases since its initial launch, we added a huge number of new features, often incrementally. We introduced backup improvements, advanced filtering, new views, alerts, monitoring tools… all progressively layered on top of the original design. While this made XO 5 more powerful, it also made the interface more complex. Some features became harder to find for new users, and the overall structure started to feel cluttered. It was time to step back and rethink everything from the ground up, not just to clean up the UI, but to design something that could fully support the scope of what Xen Orchestra has become. We also wanted to lift some long-standing limitations, answer recurring requests (as the treeview), improve performance, and build a more scalable, flexible foundation for the future. That’s what led to the XO 6 project! ### 🛠️ Technical foundation Back in 2019, we introduced the idea of Xen Orchestra 6 for the first time in a DevBlog. We explained the limitations of the existing stack. Bulk actions were hard to implement, performance was becoming a bottleneck, and many features required UI components that simply didn’t exist yet. For example, in a 1000 VMs infrastructure (which were coming more and more common even back in 2019, which is another Monday today), the initial load time of Xen Orchestra started to be around 10 seconds, and around 30 MiB to download. XO 6 goal is to reduce that by transferring only what you need. See the "results" section for what we managed to achieve! This pushed us to rebuild the interface from the ground up using a modern, more maintainable tech stack. XO 6 is now built with **Vue.js**, which offers better performance, simpler component architecture, and improved developer experience. [DevBlog #4 - Xen Orchestra 6We are currently working on a new major version of our Xen Orchestra interface which is planned to be released during the year 2020\. We will completely revamp our web interface as well as a lot of components as listed below.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-13.png)Xen Orchestra BlogMohamed![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1523726491678-bf852e717f6a)](https://xen-orchestra.com/blog/devblog-3-working-on-xo-6/) ### 📐 Redesigning the experience Of course, it was not just about technical limitation and we didn’t stop at the codebase. Alongside this effort, we launched a complete UX redesign. From the start, we introduced updated mockups featuring a sidebar with filters, saved searches, and a tree view of the infrastructure. Not just a cosmetic update but instead a major shift in how users would navigate and manage their virtual environment. We also made sure that Xen Orchestra 6 reflects the way modern IT teams work today. That means better support for **DevOps tools** and improved **interoperability**. We’ve introduced a **fully documented, Swagger-based REST API** that makes it easier to integrate XO into automated workflows, CI/CD pipelines, or external orchestration platforms. Whether you're using **Ansible**, **Terraform**, or **Pulumi**, XO 6 is designed to fit into your tooling. ℹ️ We've also added new tools to support collaboration and internationalization, most notably [****Weblate**](https://translate.vates.tech/projects/xen-orchestra/xen-orchestra-6/?ref=xen-orchestra.com), which allows our community to contribute directly to improving translations for Xen Orchestra. [UX/UI Design for XO and XOLiteWith the launch of XOLite and the redesign of Xen Orchestra itself, UX/UI Design is getting a revisit in the XO world.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-14.png)Xen Orchestra BlogClémence Barthoux![](https://xen-orchestra.com/blog/content/images/thumbnail/XO-Blog---UX-UI-Design-for-XO-and-XOLite.jpg)](https://xen-orchestra.com/blog/ux-ui-design-for-xo-and-xolite/) ### 🧪 From concept to prototype In 2022, we launched **XO Lite**, a simplified web interface built with Vue.js. This served as a testbed for many of the components and design patterns that would later be used in XO 6\. It allowed us to validate our choices before integrating them into the full-scale application. [DevBlog #10 - Xen Orchestra LiteXO Lite is an ongoing project revolving around a XAPI-based web application - just like Xen Orchestra, but it doesn’t require you to host an appliance![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-15.png)Xen Orchestra BlogPierre Donias![](https://xen-orchestra.com/blog/content/images/thumbnail/holly-chisholm-FTMfgstdJm8-unsplash.jpg)](https://xen-orchestra.com/blog/xen-orchestra-lite/) ### Shaping XO 6 with your input To help us prioritize the MVP for Xen Orchestra 6, we recently surveyed both our community and our customers. The goal was to better understand which features are essential from day one, and which ones can come later in the rollout. Here’s what came out on top: **Most critical features:** - VM lifecycle management - Host and pool management - Backup and restore - Storage management - Network configuration These are the core building blocks users expect to have ready in the initial version. **Lower priority (for now):** - RBAC - API and automation workflows - DevOps integrations - External authentication - Dashboards and performance metrics These features are still important, but users told us they can wait until the basics are solid. ![](https://xen-orchestra.com/blog/content/images/2025/07/rate-xo5-min.jpg) ![](https://xen-orchestra.com/blog/content/images/2025/07/rate-xo5-ce-min.jpg) ![](https://xen-orchestra.com/blog/content/images/2025/07/ranking-xo6-min.jpg) ![](https://xen-orchestra.com/blog/content/images/2025/07/ranking-xo6-ce-min.jpg) This feedback played a key role in shaping the roadmap. Combined with our current development progress, technical constraints, and planning decisions, it helped us define what’s coming next. ### What's on the horizon Development on Xen Orchestra 6 is ramping up this year, with a clear objective: deliver a modern, more intuitive, better-structured and high-performance interface, while ensuring a smooth transition for current Xen Orchestra 5 users. Here's an overview of what we're working on. ## 🖥️ Frontend We’re making steady progress on the XO 6 interface, with a strong focus on read-only views first. This allows users to explore their infrastructure without switching back to XO 5\. Several screens are already available in consult mode, and some actions, like creating VMs or networks, can now be performed directly in XO 6. Current views include global and per-object dashboards (for pools, hosts, VMs…), detailed system tabs, object relationship listings (such as pool-to-host and host-to-VM links), network management, and backup jobs with their corresponding reports. One of the key additions is the redesigned **Tasks** view, which brings: - Clearer distinction between tasks and subtasks - Visual progress indicators - More detailed information for better operational tracking This new approach makes it much easier to follow what’s happening in the platform, especially in large or busy environments. ![](https://xen-orchestra.com/blog/content/images/2025/07/dashboard-xo6.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/pool-dashboard-xo6-2.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/pool-dashboard-xo6.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/vm-dashboard-xo6.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/host-dashboard-xo6.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/host-dashboard-xo6-tablet.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/dashboard-xo6-tablet.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/dashboard-xo6-mobile.png) ![](https://xen-orchestra.com/blog/content/images/2025/07/dashboard-xo6-2.png) ## ⚙️ Backend On the backend side, several foundational improvements are underway: - Migrating the first-gen REST API endpoints to the new REST architecture - Enhancements and fixes to backup management - Support for VMware to Xen Orchestra migration - QCOW2 support, including disks over 2TiB for V2V (VMware to Vates) Improved task engine, for better reliability and monitoring of background operations ## 🚀 Key Features Coming Soon Xen Orchestra 6 marks a significant evolution of the platform. Beyond the new interface, it includes deep work on core features, architectural improvements, and long-term planning. We're using this opportunity to rethink how things work under the hood, modernize key systems, and improve both the user experience and the development process itself. Many of these changes are already in progress and will continue to roll out over the coming months. First, we’ve started a complete overhaul of the **ACL system**. This is a strategic project that begins with a deep analysis of how permissions are currently used, followed by a full redesign, both functionally and technically, before implementing it across the frontend and backend. The goal is to make permission management simpler, more flexible, and better suited to modern use cases. At the same time, we’re continuing the **progressive rollout of core management features** in XO 6\. VM creation and editing, power operations, backup configuration, and more are being added gradually. This phased approach ensures a smooth transition from XO 5, with a full replacement target by 2026. We’re also working on several under-the-hood improvements. These include a more robust **task engine** with better tracking and error reporting, ongoing work on **VMware migration tooling** (V2V), and refinements to the **backup workflow**, especially for large-scale infrastructures. Finally, we’re improving our **release process**, with the aim of delivering security updates more quickly and reliably across all supported versions. ## First results Our reference architecture, containing 1000 VMs in 20 pools with 40 hosts, is now giving great results. Obviously, only large(r) infrastructure will show case the difference, but as we have bigger and bigger deployments all around the world (10,000 VMs+), it's night and day for some users. ## 🤝 Partnerships As part of our effort to expand the value of Xen Orchestra, we’re introducing native integrations with third-party tools and we are starting with two solutions from our partner **EasyVirt**: **DC Scope** and **DC NetScope**. - **DC Scope** is an analysis and optimization platform that helps administrators better understand how their virtual infrastructure is used. It identifies over- and under-provisioned resources, tracks performance trends over time, and provides actionable insights to improve efficiency and reduce waste. - **DC NetScope** focuses on the network side of your infrastructure. It offers advanced traffic analysis between VMs and hosts, helping you understand internal communication patterns and uncover misconfigurations or bottlenecks that can impact performance. Both tools will be integrated directly into Xen Orchestra: - You’ll be able to **deploy DC Scope and DC NetScope** from within the XO interface - Access to their **dashboards and reports** will be embedded into the XO user experience - Data correlation between XO and EasyVirt tools will provide **unified, actionable insights** for infrastructure and network optimization This integration is designed to be seamless, with no extra complexity for users. It’s the first step in turning Xen Orchestra into a centralized platform for managing, analyzing, and optimizing your virtualization stack. ## 🔮 Longer-Term Projects Beyond the upcoming features, we’re also laying the groundwork for deeper structural improvements that will shape the future of Xen Orchestra. One key initiative is the **gradual deprecation of the JSON-RPC API**, which will be replaced by our more modern and robust **REST-based architecture**. This shift will make integrations easier, improve API clarity, and align with industry standards. We're also exploring the introduction of a **dedicated database layer** within XO. This would open the door to more advanced features, including historical data tracking, richer filtering capabilities, and improved scalability for large-scale environments. Finally, we’ve started internal discussions around **improving our QA process**. The goal is to increase test coverage and automation to speed up development cycles, reduce regressions, and raise overall software reliability as the platform continues to grow. ### Xen Orchestra 5.108 URL: https://xen-orchestra.com/blog/xen-orchestra-5-108/ Last updated: 2025-06-30T19:30:28.000Z As we head into the quieter summer months in Europe, we’re closing June with a pretty big release. XO 5.108 brings a wave of updates and sets the tone for what’s clearly becoming the top priorities: Backup, REST API, the new UI, and DevOps tooling. You’ll also notice fewer changes to the current XO 5 UI: that’s by design. Our team is now focusing more on what’s next: XO 6, which we’re aiming to make the default experience by the end of the year! I’m also back on video this month — after missing the last two releases due to a whirlwind of work trips around the globe. So if you’d rather watch or listen to everything packed into this release, here you go: 🎧 Prefer listening? This release is also available in [podcast format](https://creators.spotify.com/pod/show/vates7/episodes/Episode-18---Xen-Orchestra-5-108---Big-backups--new-LTS--and-Azure-storage-e34tjlb?ref=xen-orchestra.com)! We’re back on Spotify! ## 👨‍🚀 Project & Community This section keeps growing — a good sign that not only is Vates expanding, but the entire ecosystem around it is gaining momentum too. ### XCP-ng 8.3 reaches LTS status Almost 9 months after its initial release, **XCP-ng 8.3 is now officially an LTS version**. That means long-term support, a refreshed ISO including all updates and security fixes to date, and a clear signal: the countdown has started for the eventual sunset of XCP-ng 8.2. Please take time to read all the details, changes and consequences in our dedicated blog post: [XCP-ng 8.3 is now LTSToday, XCP-ng 8.3 becomes LTS, including new ISOs and XOSTOR officially available with it.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-14.png)XCP-ng BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/83lts.jpg)](https://xcp-ng.org/blog/2025/06/16/xcp-ng-8-3-is-now-lts/?ref=xen-orchestra.com) ### CloudStack support for XCP-ng 8.3 It wasn’t planned to align, but by a nice coincidence, **CloudStack is now fully compatible with XCP-ng 8.3 LTS**. For those unfamiliar, CloudStack is an open-source cloud management platform designed to orchestrate and manage large-scale virtualized infrastructure (from compute to networking and storage). This compatibility milestone makes it even easier to build and manage your own cloud with the latest XCP-ng release. [Apache CloudStack 4.19.3.0 and 4.20.1.0 Release | Apache CloudStackThe Apache CloudStack project is pleased to announce the release of CloudStack 4.19.3.0 and 4.20.1.0.![](https://xen-orchestra.com/blog/content/images/icon/favicon-10.ico)apache-cloudstackPearl Dsilva![](https://xen-orchestra.com/blog/content/images/thumbnail/Pearl1594.png)](https://cloudstack.apache.org/blog/cloudstack-4.19.3.0-4.20.1.0-release/?ref=xen-orchestra.com) ### Vates Partners insights If you're already a partner — or thinking about becoming one — don’t miss the latest edition of our partner update. It’s packed with fresh news, opportunities, and key info tailored just for you. [Vates Partners Insight #4 - 2025 updates for Vates PartnersAs we approach the second half of 2025, we’d like to take a moment to reflect on what we’ve accomplished together so far, and to share what’s coming next.![](https://xen-orchestra.com/blog/content/images/icon/logo64-12.png)Vates BlogRăzvan Roșca![](https://xen-orchestra.com/blog/content/images/thumbnail/imagine-buddy-vsLbaIdhwaU-unsplash.jpg)](https://vates.tech/blog/vates-partners-insight-4-2025-updates-for-vates-partners/?ref=xen-orchestra.com) ### Ford joins the Xen Project board We’re proud to see the Xen Project gaining momentum and the latest proof is Ford joining the board, just a few months after Honda did the same. It’s no accident: Xen is becoming the reference hypervisor for automotive use cases, thanks to its minimalist and secure architecture. What does it mean for the broader ecosystem? More contributors, faster progress, and a stronger, more robust code base, benefits that extend beyond the automotive world. While cars and servers may seem unrelated, Xen’s core mission is the same: providing strong and efficient VM isolation on shared hardware. If it’s trusted to help run your car safely, it’s more than ready for your production environment. ### Xen Summit 2025 San Jose I’ll be in San Jose for **Xen Summit 2025**, where I’ll present the current state of **XCP-ng** — the Xen Project-based platform we’ve been building as part of the Linux Foundation ecosystem. It’s also a great opportunity to catch up with the Xen community (and beyond, interest is clearly growing!). If you’re in the area, feel free to register and come say hi! [Xen SummitXen Summit is our annual event where the community connects with experts, discovers innovations, and shapes the future of virtualization.![](https://xen-orchestra.com/blog/content/images/icon/apple-touch-icon-9.png)Xen-Project![](https://xen-orchestra.com/blog/content/images/thumbnail/logo-xen.svg)](https://xenproject.org/resources/xen-summit/?ref=xen-orchestra.com) You can also participate directly to a talk by submitting your paper, it's closing soon! [🛠️ Xen Summit 2025: Find Your Place in the Future of VirtualizationThe annual Xen Summit is right around the corner, and there has never been a more exciting time to be part of the Xen Project. As enterprise and industrial needs shift and proprietary vendors rethink their licensing, the industry is ready for strong, open alternatives. Xen stands out not only![](https://xen-orchestra.com/blog/content/images/icon/apple-touch-icon-10.png)Blog - Xen ProjectCody Zuschlag![](https://xen-orchestra.com/blog/content/images/thumbnail/xen-summit-panda-2.webp)](https://xenproject.org/blog/xen-summit-2025-find-your-place-in-the-future-of-virtualization/?ref=xen-orchestra.com) ### Who owns your virtualization stack? In a world full of open-source wrappers and orchestration layers, it’s easy to forget the most important question: who really controls the foundation your infrastructure runs on? I share my thoughts on the topic (from a sovereignty and long-term risk perspective) in a new post on my personal blog. [Who owns your virtualization stack?In a world full of open-source wrappers and orchestration layers, who actually owns the foundation your infrastructure runs on?![](https://xen-orchestra.com/blog/content/images/icon/faviconV2-6)VirtualizeOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/dc1.jpg)](https://virtualize.sh/blog/who-owns-your-virtualization-stack/?ref=xen-orchestra.com) Pheeeww. And that was only the announcements: time to dig into what’s actually in the XO 5.108 release! --- ## 💾 Backup Our team has been working hard this month to enhance the compatibility and interoperability of backups with external vendors and services! ### Azure storage support preview Xen Orchestra now supports [Azure storage](https://learn.microsoft.com/en-us/azure/storage/common/storage-introduction?ref=xen-orchestra.com) as a backup repository (BR) for your backups. Once the BR is configured with your storage credentials, it integrates with all backup types, including full or incremental. Azure-specific settings are also now visible in the interface, so you can easily verify or troubleshoot your configuration without relying on config files or the API. As for S3, it's using the block format to store your VM disks, meaning it works with NBD-enabled hosts. ![](https://xen-orchestra.com/blog/content/images/2025/06/458897206-2129aff6-af7b-42cb-9d7b-e63504a48a11.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/458897549-88eba1fc-9835-4566-b5e6-262d62d9ec62.png) New form for Azure and Azurite remotes Our Azure storage support is backed by brand-new code, with a custom implementation tailored to our architecture. While the functionality is broadly similar to S3, we built a dedicated logic under the hood, this wasn’t just a wrapper. Because of that, it's currently only available on the latest channel and should be considered **a technical preview**, not yet production-ready. We're actively testing and refining it, and early feedback is welcome! ### Support for Qcow2 backups Our great work working on the next backup engine is now yielding results. If you want a reminder about it: [Next-gen XO backup engine: beyond VHDDiscover how we’re building a smarter, format-agnostic backup system to meet the demands of tomorrow’s infrastructure.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-12.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/backupnew-1.jpg)](https://xen-orchestra.com/blog/next-gen-xo-backup-engine-beyond-vhd/) In short, it means that Xen Orchestra now supports all backup operations on Qcow2: regular backups, incremental AND replication. Restore is also working. And even beyond that, it's very agnostic and can handle any format transformation, like going from VHD to Qcow2 and vice-versa, which is a great ally in replication when you are mixing VM disks formats. Regarding the requirements: - You must have a backup job configured with NBD and block based backup (since we won't store any VHD or Qcow2 directly) - You are testing Qcow2 and installed the extra packages on your host (don't forget this is still preview and not yet officially supported in production!) - The VM drive is larger than 2TiB (so obviously it can only be Qcow2) In short, if you are already testing Qcow2 with 2TiB+ drives, you can now backup, replicate AND restore your VMs. Perfect to test the entire stack and report if you had any issues! ⚠️ Remember that Qcow2 support in XCP-ng is still in preview. We are doing good progress though. If you want to test and report, [please go in the dedicated forum thread!](https://xcp-ng.org/forum/topic/10308/dedicated-thread-removing-the-2tib-limit-with-qcow2-volumes?ref=xen-orchestra.com) If you want to follow our work on Qcow2 on XCP-ng, don't miss our most recent article about it: [QCOW2 in XCP-ng: engineering a new storage pathWe’re working on bringing QCOW2 support to XCP-ng as an alternative to VHD to support larger disk than 2TiB. This article dives into the technical changes involved, the challenges we faced, and what’s planned to make QCOW2 ready for production use.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-16.png)XCP-ng BlogDamien Thenot![](https://xen-orchestra.com/blog/content/images/thumbnail/joshua-hoehne-CAokgx1GGKE-unsplash-1.jpg)](https://xcp-ng.org/blog/2025/06/27/qcow2-in-xcp-ng-engineering-a-new-storage-path/?ref=xen-orchestra.com) ### Decoupling NBD from CBT NBD is more and more essential to do faster and efficient backups. Until now, it was also coupled with the activation of CBT. The storage CBT feature is kind of complex and could have some specific interaction, causing some race conditions sometime. In order to simplify things, we decided to decouple both options. You can now rely on NBD for backups without using CBT. ### Improved timeout handling for S3 We've improved how timeouts are managed when interacting with S3 and S3-compatible storage. Previously, timeout errors were not retried, which could result in failed backups, particularly with providers like Backblaze, where temporary issues are more frequent. We now properly retry when a timeout error happens, which helps prevent failures caused by brief network issues or slow responses from the remote. Additionally, errors that trigger a retry are now properly logged. This way, the support team has more information about what happened and can solve timeout issues faster. ### New backup code fixes Xen Orchestra 5.108 improves how backup jobs handle situations where one or more target storage repositories (SRs) become invalid or unavailable, an issue that several users had reported as a cause of backup failures. Previously, if one of the selected SRs couldn't be used, the entire job might fail or behave unpredictably. Now, Xen Orchestra detects and skips over invalid SRs when multiple targets are defined, allowing the backup to proceed with the remaining valid ones. This makes backup jobs more robust and reduces the risk of interruptions in environments with multiple or rotating storage locations. ### Better backup reports Backup reports now behave more predictably and are no longer tied to the **Report when** setting. Previously, if this option was set to "failure" the report summary would only include failed VMs. Successful ones were left out, even though their logs existed. From now on, the content of the report is based solely on the actual backup logs, regardless of when the report is triggered. This gives a more complete and accurate view of what happened during the backup run. To keep things flexible, a new option has been added to backup task configuration. It lets you choose whether to include successful VMs in reports triggered by failures, which preserves the old behavior if needed. This sits alongside the existing **Shorter backup reports** setting, so you can tailor the level of detail to your needs. ![](https://xen-orchestra.com/blog/content/images/2025/06/459318204-b0404096-700a-450d-9696-7a43d01c7772.png) New ****Shorter backup reports** option ## 🥝 Core UI The Core UI is getting even better and more efficient. From a new icon library to fresh visual components, we're improving both what you see and what happens behind the scenes to make future updates quicker. ### UI code quote block XO 6 features a new UI component that makes it easier to display inline code or technical content, like command-line snippets, configuration values, error listings, and logs. It's great for showing raw logs in a clean, readable format. This component ensures a consistent look and better readability in the whole application, especially in tooltips, dialogs, or help messages. This small change helps make technical details clearer wherever they appear. ![](https://xen-orchestra.com/blog/content/images/2025/06/453998887-ef45c4ef-a33f-47be-8a5f-a7566ed48861-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/453999019-afde12bd-4444-4cf5-b023-9c39c3e7db33.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/453999132-49338d78-b8b0-48b2-9406-795e7524025d.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/453999237-adc1405e-ac37-4250-928e-5a7691b6cbad-1.png) ### Icon management library We've changed the way we handle icons across our web apps. Until now, we were using FontAwesome icons directly (e.g. `faDisplay`). However, each time we used complex icons (with stacking, colors, and specific positioning) multiple times, we ended up with duplicated code and overly complex component hierarchies. To solve this, we built our own icon library, where each icon (even complex and multi-layered ones) is identified by just a name. Now, we can simply use that name as a prop in our components. Let's say we need to propagate a complex 3-icon stack with custom colors and positioning. We can define it in the library just once, and use it by name everywhere. For instance: ``. With this system, code and component APIs are cleaner, and visuals are more consistent. ### Table pagination ![](https://xen-orchestra.com/blog/content/images/2025/06/457902624-4ba84075-882a-4035-9ca8-be7b8c337b9e.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/457902709-3179e40c-800c-46ba-a4bd-5508a6d928a6.png) ### New Select and Multi-select components We’ve introduced brand new Select and Multi-Select components to improve both the user experience and developer ergonomics. While the changes might seem subtle visually, this is actually a major enhancement behind the scenes. These components now offer a more unified and polished interface for picking one or several options, with consistent styling aligned with our design system. #### What’s new: - ✅ Full keyboard navigation - 🔍 Optional search field with customizable search terms - 🧩 Multi-selection support - 🗣️ Customizable labels when multiple items are selected #### For developers: - Simplified usage of both the component and its composable logic - Cleaner API and more predictable behavior ![](https://xen-orchestra.com/blog/content/images/2025/06/image--5-.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/image--6-.png) ### VM dashboard XO6 and XO Lite have a new VM dashboard with a responsive and light design, so that you can see key metrics and VM status in an instant. The dashboard shows basic resource usage (CPU, RAM, disk), health info, and network activity, but this is just the beginning! In the future, we'll add more details to the dashboard to make it even more useful. ![](https://xen-orchestra.com/blog/content/images/2025/06/xo6-vm-dashboard-dark.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/xo6-vm-dashboard-light.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/xolite-vm-dashboard-dark.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/xolite-vm-dashboard-light.png) New VM dashboard ### Pool section in the System tab We've added a **Pool** section to the **System** tab. This gives you a quick look at essential host info like hardware details, CPU, and memory usage, all in one place. It's an easy way to keep an eye on your infrastructure and paves the way for future monitoring improvements. ![](https://xen-orchestra.com/blog/content/images/2025/06/xo6-pool-dark.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/xo6-pool-light.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/xolite-pool-dark.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/xolite-pool-light.png) New Pool section in the System tab ### Mobile support for side panel and tables We've revamped the side panels and tables to ensure they work smoothly on mobile devices. The layout now dynamically adjusts to fit smaller screens, preventing content from being cut off and ensuring a user-friendly experience. ![](https://xen-orchestra.com/blog/content/images/2025/06/457893279-bd8a7fa5-e45d-47ef-a20b-d28a783c6667.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/457893379-79c6cbc6-0446-4f56-af06-54ec1bdd8e65.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/458295709-6988d781-60f9-4c94-b20d-b6e9af8fde5f.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/458296208-a273877e-bdd8-42ed-9060-b2eac5851493.png) ### ## 🛰️ XO 6 Beyond updates to the core UI, we've continued to enhance XO 6 visually and under the hood, with fresh interface components and optimizations for faster performance. ### Adding sites to the treeview There's a new level in the treeview hierarchy: the site, which is positioned above pools. Selecting a site shows all your pools and opens a dedicated dashboard tab for your current XOA, with all related information. This addition helps organize infrastructure more clearly, especially in large deployments with multiple pools spread across various locations, and will enable us to add more site-level features in the future 💡 ****Note:** Sites are temporarily labeled as "Xen Orchestra Appliance" until we implement support for custom naming. ![](https://xen-orchestra.com/blog/content/images/2025/06/453518473-38ac307d-e62a-40bf-a85a-5e187336bd1d.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/455394385-234112e2-3faa-41c2-8d91-632144905562.png) ### Improved host dashboards We've updated the host dashboard in XO 6 to better align with the one in XO Lite. This includes clearer wording and a more consistent presentation overall. For instance: - "RAM usage" becomes "RAM provisioning" - "Memory usage" becomes "RAM usage" One key improvement is in how CPU provisioning is calculated: it now matches the values shown in XO Lite, for a more accurate and unified view of your hosts' resources in both interfaces. ### Dashboard powered by data streams The dashboard now displays data as soon as it's available, instead of waiting for everything to be fully loaded. When you open the page, the system starts calculating the metrics in the background and shows them progressively as they're ready. This change makes a noticeable difference in larger environments, where generating all the dashboard data can take several seconds. Instead of staring at an empty screen, you’ll now start seeing partial results almost immediately. In the future, we will reuse this improvement in other parts of Xen Orchestra where heavy data processing is required. ![](https://xen-orchestra.com/blog/content/images/2025/06/dashboard-after.gif) ![](https://xen-orchestra.com/blog/content/images/2025/06/dashboard-before.gif) XO6 dashboard now and before the update ### Better backup views We've updated the **backup** section to make it clearer and easier to use. With improved layouts and naming, it's now simpler to understand how backup jobs are structured and quickly find what you need. This update makes managing backups more intuitive, especially when dealing with multiple schedules, remotes, or job types. ![](https://xen-orchestra.com/blog/content/images/2025/06/365570567-5749cced-415d-43a7-8418-2ff8c6d7aa2b-1.png) The backup view before XO 5.108 ![](https://xen-orchestra.com/blog/content/images/2025/06/451778659-35b6f0e8-70c1-4c6e-85c7-1f7b800ae20b-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/451778847-2a5b379b-5c23-45eb-8f3f-89aee1632220.png) The backup view since XO 5.108 ## 🪐 XOA Behind the scenes, we've made substantial improvements to improve how updates are built and delivered. Although these changes aren't visible in the app, they allow us to roll out better updates and address issues faster - all thanks to a collaborative effort from the entire team! ### Improved XO release process The Xen Orchestra release process has been refined. As a result, that the platform is now more reliable and easier to maintain, particularly for backporting urgent security fixes. The updated approach improves support for multiple release channels and ensures better consistency between development and production environments. It also streamlines packaging and version tracking, making patch management more efficient and reducing the likelihood of build-related issues. ## 📡 REST API We're continuing our journey into documenting our API with Swagger. Not only are we migrating existing endpoints, but we've also added new ones, opening up even more possibilities for managing your environment. ### Support for more VM state changes The API now includes support for more VM state change operations that were previously unavailable. You can perform actions like `force shutdown`, `clean shutdown`, `suspend`, `resume`, and both soft and hard reboot through the API. This update brings the REST interface closer to matching the features of the existing JSON-RPC API so that you can more easily automate common VM lifecycle operations. ![](https://xen-orchestra.com/blog/content/images/2025/06/457955368-d870b5a3-6f70-4ea0-a364-6c50a12bb889.png) ### Extended VM stats We have two new methods in the REST and JSON-RPC APIs, namely `addDataSource` and `removeDataSource`. They let you pick more data sources to keep an eye on a particular VM, give you the ability to monitor the metrics in more detail and maybe even unlock new possibilities in Xen Orchestra. ![](https://xen-orchestra.com/blog/content/images/2025/06/453921536-f0414a7a-d787-46e0-8d4f-af2187a9f3ad.png) They are really great metrics, like the `runstate` family. For example: - **runstate\_concurrency\_hazard > 0%** indicates that sometimes, at least one vCPU is running while at least one other vCPU wants to run but can’t get pCPU time. If the vCPUs must coordinate, this behavior causes performance issues. - **runstate\_full\_contention > 0%** indicates that sometimes the vCPUs want to run all at the same time but none can get pCPU time. Those metrics are critical to do capacity planning and resource optimization. And they are already used by our new partner, EasyVirt, for their "Aria-like" product, DC Scope. You can read more about it in here: [Vates & Easyvirt: a new alliance strengthening the Cloud technology ecosystemDC Scope brings advanced monitoring, optimization, and sustainability features to XCP-ng environments, offering a powerful, turnkey alternative to VMware Aria.![](https://xen-orchestra.com/blog/content/images/icon/logo64-13.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/dcalpsgreen-1.jpg)](https://vates.tech/blog/vates-easyvirt-a-new-alliance-strengthening-the-cloud-technology-ecosystem/?ref=xen-orchestra.com) ### Introducing many new endpoints In addition to the VM data sources, we continue to add and migrate new API endpoints to Swagger each month. This is part of the ongoing effort we announced during the 5.104 release back in February. This time around, we've introduced several new endpoints: - Networks (`create`, `delete`) - PCIs (`get`, `get id`) - PGPUs (`get`, `get id`) - Servers (`delete`) - SMs (`get`, `get id`) - VM actions (`pause`, `suspend`, `resume`, `unpause`) ![](https://xen-orchestra.com/blog/content/images/2025/06/451971776-8dcab306-dda5-4fc2-83fd-f1383e929ab8.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/452242927-2535a367-accb-4556-9306-b406bec3895a.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/452335843-f10693d7-25cc-4bf8-8df4-2927a4692be2.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/453921536-f0414a7a-d787-46e0-8d4f-af2187a9f3ad-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/454920622-fc1500be-8709-4883-9b02-d287a61ff136.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/457408007-3bf55cc2-00f5-471b-9e9c-856e01ee82e3.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/457955368-d870b5a3-6f70-4ea0-a364-6c50a12bb889-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/458787109-c9cec8b3-a1f8-48cb-95bb-10380f721e38.png) ### Existing endpoints moved to Swagger On top of the new endpoints listed above, we've migrated multiple endpoints from the API over to Swagger: - Pool actions (`emergency_shutdown`, `rolling_reboot`, `rolling_update`) - Dashboards - VMs (`import` and `create`) [Xen Orchestra 5.104This month at Vates, we’re bringing you a wave of updates across the board! Our virtualization stack is now validated for Red Hat Enterprise Linux 9, and we’ve announced a strategic partnership with VyOS to enhance networking capabilities in Vates VMS.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-7.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/rodion-kutsaiev-b6Kfzd8pDaQ-unsplash-1.jpg)](https://xen-orchestra.com/blog/xen-orchestra-5-104/) ![](https://xen-orchestra.com/blog/content/images/2025/06/445596758-9ffa1f80-1f0e-430f-b57f-4430f4231628-2.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/448320239-dac2417e-3450-4bf3-a5a4-9c11901adb57-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/455896870-b9e34b84-3ddb-4b3d-bc34-ecc03b2cacb3-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/458421238-5497b24f-aa10-49f9-b0f5-81ce6a880d6d-1.png) Now it's a matter of few releases to get absolutely all our REST API endpoints to swagger, meaning XO REST API will be fully documented! ## ☸️ DevOps Tools It’s also been a packed month on the DevOps side, with new releases, improvements, and growing internal ownership of key tools. ### VirtOps#6: Kubernetes cluster in minutes In this latest update, we show how you can use **Xen Orchestra recipes** to deploy a fully working Kubernetes cluster in just a few minutes. We also break down what’s happening behind the scenes (from the underlying components to the orchestration logic), so you can understand exactly how it all comes together. [VirtOps#6: create a Kubernetes cluster in minutesLearn how to deploy a full Kubernetes cluster in minutes using our built-in recipe feature in Xen Orchestra, and discover the components running under the hood.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-10.png)Xen Orchestra BlogNathanaël Hannebert![](https://xen-orchestra.com/blog/content/images/thumbnail/k8spyrgos.jpg)](https://xen-orchestra.com/blog/virtops-6-create-a-kubernetes-cluster-in-minutes/) ### Terraform provider & Packer plugin update Last week, we released an update for the Terraform (and OpenTofu) provider. This new version improves the VM disk lifecycle : resizing an existing VDI handles the needed VM reboot automatically, and a few others fixes. Read the changelog here: [https://github.com/vatesfr/terraform-provider-xenorchestra/releases/tag/v0.32.0](https://github.com/vatesfr/terraform-provider-xenorchestra/releases/tag/v0.32.0?ref=xen-orchestra.com) #### Packer plugin v0.8.1 The Packer plugin has just been released in version `v0.8.1`, marking the first release since ownership was officially transferred from Dom to Vates. This milestone reflects how Vates is steadily internalizing more DevOps expertise and tooling, reinforcing our long-term commitment to ecosystem sustainability and autonomy. This update provides support for auto install of Linux distros such as Ubuntu 24.04 that can find the `autoinstall` file only on a virtual CD, not on a good old -virtual- floppy! [Release v0.8.1 · vatesfr/packer-plugin-xenserverWhat’s Changed Other Changes Add support for cd\_files in addition to floppy\_files by @ceejatec in #144 Update-url by @nathanael-h in #166 New Contributors @ceejatec made their first contribution…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-15.svg)GitHubvatesfr![](https://opengraph.githubassets.com/c8344d711bb27178268d021b08b6463aebcbcf88ab3ae30be2c1fc1376082a2a/vatesfr/packer-plugin-xenserver/releases/tag/v0.8.1)](https://github.com/vatesfr/packer-plugin-xenserver/releases/tag/v0.8.1?ref=xen-orchestra.com) ### XO Cloud Controller Manager (CCM) The XO CCM acts as a bridge between your Kubernetes cluster and your XO infrastructure. It connects to Xen Orchestra, retrieves detailed information about your VMs, and automatically maps them to their corresponding Kubernetes nodes. Using this mapping, it then applies meaningful labels to the Kubernetes nodes based on the underlying XO topology, such as the pool or host each VM is running on. #### Real-world example Imagine you’re running a Kubernetes cluster spread across two different XO pools located in separate datacenters. Thanks to the labels applied by the XO CCM, Kubernetes is now aware of the physical location of each node. This enables features like anti-affinity rules — allowing you to schedule workloads in a way that avoids placing replicas on the same pool or even in the same datacenter, increasing resilience and fault tolerance. [GitHub - vatesfr/xenorchestra-cloud-controller-manager: Kubernetes Cloud Controller Manager for Xen OrchestraKubernetes Cloud Controller Manager for Xen Orchestra - vatesfr/xenorchestra-cloud-controller-manager![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-11.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/xenorchestra-cloud-controller-manager)](https://github.com/vatesfr/xenorchestra-cloud-controller-manager?ref=xen-orchestra.com) ## 📖 Documentation & guides We've put a lot of effort into updating the Xen Orchestra documentation to make it clearer, more useful, and better aligned with the current state of the application. Below, you'll find a list of some of the most recent additions to that documentation: - [Configure a Syslog server](https://docs.xen-orchestra.com/backups?ref=xen-orchestra.com#send-xo-logs-to-an-external-syslog-server) - [Revamped REST API page](https://docs.xen-orchestra.com/restapi?ref=xen-orchestra.com) - [Viridian extensions](https://docs.xen-orchestra.com/vm-templates?ref=xen-orchestra.com#viridian-extensions) - [CloudBase init for Windows](https://docs.xen-orchestra.com/windows-templates?ref=xen-orchestra.com) - [Network locking mode](https://docs.xen-orchestra.com/manage%5Finfrastructure?ref=xen-orchestra.com#network-locking-mode) - [How to receive usage reports](https://docs.xen-orchestra.com/manage%5Finfrastructure?ref=xen-orchestra.com#usage-reports) ## 🤝 External contributions Our community continues to play a vital role in making Xen Orchestra better every day. Thanks to your contributions, which range from fixing typos to expanding language support, we are able to improve both the polish and accessibility of the platform! ### Widespread typo corrections This month, lots of spelling errors and typos were fixed, both in the documentation and the source code. The work was done in two parts, one about comments and documentation that is already fully merged, and another about the code itself, which we are reviewing and merging little by little to make sure nothing breaks. **A big thanks to community member Josh Soref for making this possible, we really appreciate the time and attention to detail!** [jsoref - OverviewWondering how I’m finding spelling errors / want to prevent new ones? https://check-spelling.dev - jsoref![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-13.svg)GitHub![](https://xen-orchestra.com/blog/content/images/thumbnail/2119212-1)](https://github.com/jsoref?ref=xen-orchestra.com) ### Access to XO 6–only languages Thanks to a contribution from p-bo, users can now select languages in XO 5 that are exclusive to XO 6. Since XO 6 lacks a settings page, language selection depends on the cookie set by XO 5\. However, some languages available in XO 6 weren't selectable through XO 5, making them inaccessible in practice. To address this, **p-bo** temporarily added these missing languages to the XO 5 language selector. This allows users to switch to any supported language in XO 6, even before a proper settings interface is introduced. [p-bo - Overviewp-bo has 182 repositories available. Follow their code on GitHub.![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-14.svg)GitHub![](https://xen-orchestra.com/blog/content/images/thumbnail/12208593)](https://github.com/p-bo?ref=xen-orchestra.com) ## 🌐 Translations Since we started to use Weblate, we never had so many translation contributions. That's great! If you want to discover more about Weblate, check out their website: [Weblate - web-based localizationCopylefted libre software, used by over 2,500 libre software projects and companies in over 165 countries.![](https://xen-orchestra.com/blog/content/images/icon/weblate-180-5.png)Weblate![](https://xen-orchestra.com/blog/content/images/thumbnail/og-5.png)](https://weblate.org/en/?ref=xen-orchestra.com) ### Updates for 5 languages Thanks to our community and their efforts, translations have been improved across the app, with updates for Czech, Dutch, German, Russian and Spanish. This makes the interface more accessible and consistent for our international users, as part of our effort to enhance the experience for everyone. ![](https://xen-orchestra.com/blog/content/images/2025/06/687474703a2f2f7472616e736c6174652e76617465732e746563682f7769646765742f78656e2d6f72636865737472612f6d756c74692d6175746f2e737667.svg) Current XO 6 translation status Thanks a lot to the community! If you'd like to help translate Xen Orchestra or fix existing translations, feel free to contribute [here](https://translate.vates.tech/?ref=xen-orchestra.com). ## **🆕** Misc Not every update fits neatly into a specific category, but that doesn’t make them any less useful. From tighter control over security warnings to small improvements that simplify everyday tasks, these changes add up to make Xen Orchestra more aligned with your needs and enjoyable to use. ### Hide XSA-468 warnings per VM Xen Orchestra automatically checks Windows VMs for vulnerable PV drivers and shows a warning if it detects an issue related to the XSA-468 vulnerability (CVE-2025-27462, CVE-2025-27463 and CVE-2025-27464). While we strongly recommend to upgrade these drivers (or ideally, the OS itself) some setups can’t be updated. This is especially true for legacy systems like Windows 7 or Windows Server 2012\. If you're stuck with one of these VMs, a mitigation script will be made available on the XCP-ng side, but XO won’t be able to confirm whether you’ve applied it or not. ![](https://xen-orchestra.com/blog/content/images/2025/06/image-5.png) To avoid unnecessary clutter, you can now prevent the warning from showing for a particular VM, by tagging it with `HIDE_XSA468`. The banner at the top of the VM view will only appear if there are vulnerable VMs *without* this tag. ### VDI format in SR and disk views You can now see the VDI format, such as Qcow2 or VHD, directly in the interface at both the VM and storage repository levels. In a VM's disk view, each disk displays its format. The same goes for the SR view, where all associated disks now clearly show their format. When creating a new disk or VM, the SR selection dropdown also indicates the format that will be used, helping you choose the right storage backend from the get-go. ⚠️ Qcow2 disks are now explicitly labeled, and export actions are disabled for them since Qcow2 export isn't officially supported (yet) at this stage. This update brings more clarity when working with different storage formats and helps avoid incompatible operations. ![](https://xen-orchestra.com/blog/content/images/2025/06/414638706-c49fe631-acfc-4ed6-8a72-3b3a1930a097-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/412347407-d9ea736f-6227-4095-9338-5eca4f193837-2.png) ### Remove a remote syslog server You can now remove the remote Syslog configuration of a XCP-ng host directly from Xen Orchestra. Previously, once a remote Syslog server was set, you couldn't clear that field through the UI without manually editing the host. This improvement gives you complete control over the remote logging setup from the host's advanced settings, letting you update, replace, or entirely remove a Syslog destination. ### VirtOps#6: create a Kubernetes cluster in minutes URL: https://xen-orchestra.com/blog/virtops-6-create-a-kubernetes-cluster-in-minutes/ Last updated: 2025-06-23T13:57:59.000Z Two years ago, we introduced a new section in Xen Orchestra called **Recipes,** designed as the foundation for more advanced features. One of the most exciting use cases that followed was the ability to deploy a full Kubernetes cluster in just minutes. Internally, we called this effort **Project Pyrgos**: [Announcing project PyrgosHave you ever wanted to easily create and update Kubernetes clusters on top of your on-prem infrastructure? That’s exactly what Pyrgos project is.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-9.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/pyrgos-1-1.jpg)](https://xen-orchestra.com/blog/announcing-project-pyrgos/) As a big update on this recipe was released with Xen Orchestra 5.106, let's rediscover it together and look how it is easy-to-use! ## Creating the cluster From Xen Orchestra, I go to Hub, then Recipes : ![From Xen Orchestra, go to Hub, then Recipes : ](https://xen-orchestra.com/blog/content/images/2024/12/image.png) Then I chose the Kubernetes recipe and fill the form. ![Kubernetes recipe in Xen Orchestra Hub](https://xen-orchestra.com/blog/content/images/2024/12/image-1.png) Kubernetes recipe in Xen Orchestra Hub As you can see in the form we can choose the number of nodes use for the control plane, and thus whereas we want it to be highly available and fault tolerant, and also the number of worker nodes. As expected we have to fill information about the virtual machines to be created: which Pool to create the cluster Kubernetes on, which SR (storage repository) to use, which network, which Kubernetes version, the name of the cluster which will be reflected in the name-label of the VMs. Let's go with a simple HA cluster, with 3 worker nodes! ![](https://xen-orchestra.com/blog/content/images/2025/06/image-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/06/image-2.png) We can see the task has been created, and is running. When it will be finished, it will disappear from the list. ![](https://xen-orchestra.com/blog/content/images/2025/06/image-3.png) The name provided to the cluster is also used to tag VMs, so that we can easily find them all. ![](https://xen-orchestra.com/blog/content/images/2025/06/image-4.png) ## Accessing the cluster Once the task is done and the virtual machines are deployed, I will connect via SSH on the first node of the control plane, and there I will be able to manage my Kubernetes cluster. ```sh $ ssh debian@ $ debian@cp-1:~$ microk8s kubectl get nodes NAME STATUS ROLES AGE VERSION cp-1 Ready 40m v1.33.0 cp-2 Ready 30m v1.33.0 cp-3 Ready 31m v1.33.0 worker-1 Ready 31m v1.33.0 worker-2 Ready 31m v1.33.0 worker-3 Ready 31m v1.33.0 ``` 💡 As I enabled HA for the control plane, I will use the VIP (virtual IP address) to connect to my Kubernetes cluster. Here how I can retrieve a `kubeconfig` file to use external tools to manage my Kubernetes cluster: ``` $ microk8s config apiVersion: v1 clusters: - cluster: certificate-authority-data: [...] server: https://10.1.134.51:16443 name: microk8s-cluster contexts: - context: cluster: microk8s-cluster user: admin name: microk8s current-context: microk8s kind: Config preferences: {} users: - name: admin user: client-certificate-data: LS0tLS1CRU[...] client-key-data: LS0tLS1CRUdJ[...] ``` 💡 As I enabled HA for the control plane, I will use the VIP (virtual IP address) to connect to my Kubernetes cluster. In the `kubeconfig` above, I will update the URL with the VIP I defined in the recipe form: `server: https://10.1.134.50:16443` ## Cluster architecture Now let’s take a look behind the scenes to see which components the cluster is built on. ### MicroK8S This recipe was updated last month to use a well known Kubernetes distribution: MicroK8s, from Canonical. This choice was made to ease the maintenance and the lifecycle of the Kubernetes cluster. [Xen Orchestra 5.106Big improvements are coming to Xen Orchestra: a new universal backup engine, a smarter SDN controller, and more under the hood. Discover what’s next!![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-8.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/pasture-5328009_1280.jpg)](https://xen-orchestra.com/blog/xen-orchestra-5-106/#project-pyrgos-now-using-microk8s) This recipe provides a simple way to deploy an official Kubernetes distribution. All of the official [MicroK8s documentation](https://microk8s.io/docs?ref=xen-orchestra.com) is relevant and will help you with your daily use of this cluster. ### Add-ons In addition to the core components of the Kubernetes control plane, this recipe installs automatically the following add-ons: - **DNS**: This deploys CoreDNS to supply address resolution services to Kubernetes. - **Helm**: Installs the [Helm 3](https://helm.sh/?ref=xen-orchestra.com) package manager for Kubernetes - **RBAC**: Enable Role Based Access Control for authorization. Note that this is incompatible with some other add-ons. We also include additional components, but only when HA is enabled: - **HA-cluster**: Allows for high availability on clusters with at least three nodes. - **Kube-VIP**: Provides Kubernetes clusters with a virtual IP and load balancer for both the control plane. This one is deployed using the official helm-chart. ### Kubernetes updates One of the great benefit provided by MicroK8s is the automatic deployment of security updates. Patch release updates (e.g 1.30.x to 1.30.x+1) happen automatically for the installed version of MicroK8s. This really removes a burden from the Kubernetes administrators. Then for minor updates, (e.g. 1.30.x to 1.31.x) we should simply follow the [MicroK8s documentation](https://microk8s.io/docs/upgrading?ref=xen-orchestra.com). ### Xen Orchestra 5.107 URL: https://xen-orchestra.com/blog/xen-orchestra-5-107/ Last updated: 2025-06-23T12:40:11.000Z Welcome to the May edition of our monthly Xen Orchestra updates! I'm starting this month’s post a little differently by leading with essential security updates. In today’s world, keeping your infrastructure safe is more critical than ever, and we’re dedicated to making sure you have the tools and knowledge to do just that. Beyond security, we’ve got plenty to share: from our new partnership with Hexatrust to the upcoming Vates Innovation Summit in Capri, the latest progress on Xen Orchestra 6, and continuous improvements in usability and reliability. Let’s jump in and see what’s new! ## 🚨 Latest security updates We’ve released three important security updates this month to ensure your infrastructure stays secure and up to date. ### XSA-468: multiple Windows PV driver vulnerabilities - update now! We've found several vulnerabilities in all existing Xen PV drivers for Windows from all vendors (XCP-ng, XenServer, AWS, etc.), which allow unprivileged users to gain system privileges inside Windows guests. To keep your environment secure, we strongly recommend updating your PV drivers. 💡 Another strong proof of our commitment: these vulnerabilities were [discovered by Tu Dinh](https://xcp-ng.org/blog/author/tu-dinh/?ref=xen-orchestra.com), our lead developer for Microsoft compatibility and Windows PV drivers. It's a clear demonstration that we don’t just **consume* upstream work, ****we actively contribute to it**. Tu will now join the official upstream Windows PV driver team as a maintainer. Please read the critical information in the following XCP-ng blog post and follow the instructions provided: [XSA-468: multiple Windows PV driver vulnerabilities - update now!Multiple vulnerabilities have been discovered in Windows PV drivers, allowing unprivileged users to gain system privileges inside Windows VMs. We provide updates, tools and guidance in response.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-13.png)XCP-ng BlogTu Dinh![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1620843002805-05a08cb72f57)](https://xcp-ng.org/blog/2025/05/27/xsa-468-windows-pv-driver-vulnerabilities/?ref=xen-orchestra.com) ### XCP-ng security update: mitigating Intel vulnerabilities A new security update is now available for XCP-ng 8.3 and XCP-ng 8.2, focusing on addressing hardware vulnerabilities related to Intel processors. This update includes: - Updated Intel microcode to help protect against newly disclosed CPU vulnerabilities - A Xen patch for XSA-469 (CVE-2024-28956), improving protection against potential memory inference attacks [May 2025 Security Update for XCP-ng 8.2 & 8.3New security updates are available for XCP-ng 8.2 LTS and XCP-ng 8.3![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-11.png)XCP-ng BlogDavid Morel![](https://xen-orchestra.com/blog/content/images/thumbnail/binary-1332816_1920.jpg)](https://xcp-ng.org/blog/2025/05/14/may-2025-security-update-for-xcp-ng-8-2-8-3/?ref=xen-orchestra.com) ⚠️ Please note that applying this update will require a host reboot. ### Xen Orchestra security patches This month’s release also includes an important security patch for Xen Orchestra. **We strongly recommend updating as soon as possible**. Details about this patch will be disclosed in a future changelog. ℹ️ The patch is available for both the `stable` and `latest` release channels. Now let's move to our usual first section: "Project and community"! --- ## 👨‍🚀 Project & Community This month is packed with important news, as we're joining Hexatrust to support digital sovereignty in Europe, we're releasing a maintenance update for XCP-ng 8.3, and thanks to your input, we've set the priorities for our Xen Orchestra 6 MVP. We're also looking forward to the Vates Innovation Summit in Capri, and finally, don't miss our new guide to deploying Windows VMs with Cloudbase-init. Stay tuned for more updates! ### Strengthening virtualization independence with Hexatrust We’re proud to announce that [Vates ](https://vates.tech/?ref=xen-orchestra.com)has joined [Hexatrust](https://www.hexatrust.com/en/?ref=xen-orchestra.com), a non-profit alliance uniting key players in cybersecurity and trusted digital infrastructure. This marks another milestone in our commitment to building a credible, open alternative in virtualization. [Vates Joins Hexatrust: advancing trusted and sovereign IT InfrastructureVates joins Hexatrust to promote trusted, sovereign IT infrastructure in Europe. As part of the ecosystem, we aim to drive collaboration, share expertise, and advocate for strong virtualization alternatives in strategic industries.![](https://xen-orchestra.com/blog/content/images/icon/logo64-10.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/maximalfocus-VT4rx775FT4-unsplash.jpg)](https://vates.tech/blog/vates-joins-hexatrust-advancing-trusted-and-sovereign-it-infrastructure/?ref=xen-orchestra.com) I recently shared more thoughts on this in my personal blog post, *“The Right Time for Europe,”* where I explain why investing in digital independence is more urgent than ever. [The right time for EuropeIn a world where resilience depends on more than supply chains, Europe must decide where it wants control—and where it’s willing to depend on others.![](https://xen-orchestra.com/blog/content/images/icon/faviconV2-4)VirtualizeOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/europemap.jpg)](https://virtualize.sh/blog/the-right-time-for-europe/?ref=xen-orchestra.com) Joining Hexatrust is part of that journey: helping to ensure that critical digital infrastructure remains open, secure, and sovereign. ### Sneak peek: XO6 MVP priorities We recently surveyed our community and customers to gather input on the most essential features for the MVP of Xen Orchestra 6 we are working on. Here’s a quick glimpse of what **you have highlighted as top and lower importance** – these are valuable insights that will help us to define the roadmap for the **Xen Orchestra 6 MVP.** - **What stood out** - VM lifecycle management - Host and pool management - Backup & restore - Storage management - Network configuration - Seen as less critical - RBAC - API / automation readiness - DevOps integrations - Integration with external authentication - Dashboard and performance metrics ![](https://xen-orchestra.com/blog/content/images/2025/05/ranking-xo6-ce-min.jpg) ![](https://xen-orchestra.com/blog/content/images/2025/05/ranking-xo6-min.jpg) ![](https://xen-orchestra.com/blog/content/images/2025/05/rate-xo5-ce-min.jpg) ![](https://xen-orchestra.com/blog/content/images/2025/05/rate-xo5-min.jpg) We’ll share a dedicated blogpost soon to deep dive into these findings and outline how they’ll shape the next major release of Xen Orchestra **—** stay tuned! ### Maintenance update for XCP-ng 8.3 We’ve also released a maintenance update for XCP-ng 8.3 this month. It focuses on stability, hardware support, and performance improvements, while including some defense-in-depth security updates and refreshed guest OS templates (like Windows Server 2025 and Ubuntu 24.04). This update lays the groundwork for XCP-ng 8.3’s upcoming long-term support phase, so don’t miss out! [May 2025 Maintenance Update for XCP-ng 8.3New bugfix and enhancement updates are available for XCP-ng 8.3.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-12.png)XCP-ng BlogSamuel Verschelde![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1558691518-bb52033a69e4)](https://xcp-ng.org/blog/2025/05/26/may-2025-maintenance-update-for-xcp-ng-8-3/?ref=xen-orchestra.com) ### Vates Innovation Summit in Capri We’re excited to announce that the Vates Innovation Summit is just around the corner! On May 30, in the stunning setting of Capri, Italy, we’re bringing together industry leaders, policymakers, and technology experts to discuss the future of sustainable virtualization and digital sovereignty in Europe. [](https://vates.tech/blog/vatescapri/?utm%5Fsource=chatgpt.com) [Vates Capri Innovation SummitData Centers and the Environment: The Path Toward Sustainable Virtualization Today’s global innovation is driven by emerging and constantly evolving technologies. Current scenarios demand a hybrid and open approach that allows for achieving both efficiency and environmental sustainability goals. Vates has always been committed to developing sustainable open source![](https://xen-orchestra.com/blog/content/images/icon/logo64-11.png)Vates BlogBertille OLDMAN![](https://xen-orchestra.com/blog/content/images/thumbnail/a82f7ece-5277-44cf-8dd5-1f3910c2e9e6-1280x640.jpg)](https://vates.tech/blog/vatescapri/?ref=xen-orchestra.com) ### ### Windows templates with Cloudbase-Init: Step-by-step guide & best practices We’ve published a comprehensive guide on streamlining Windows VM deployments in XCP-ng using Cloudbase-Init. This step-by-step tutorial walks you through creating a master Windows VM, configuring Cloudbase-Init, and preparing reusable templates. [Windows Templates with Cloudbase-init: Step-by-step Guide & Best PracticesEasily automate Windows VM deployments in XCP-ng with Cloudbase-init and Xen Orchestra. Here’s how to do it right!![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-5.png)Xen Orchestra BlogTu Dinh![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1530133532239-eda6f53fcf0f)](https://xen-orchestra.com/blog/windows-templates-with-cloudbase-init-step-by-step-guide-best-practices/) Okay now let's switch to our monthly XO release content! --- ## 💾 Backup A major refactor of the backup code has been done. If it's not visible for you, we [announced it last month](https://xen-orchestra.com/blog/next-gen-xo-backup-engine-beyond-vhd/) and we delivered. If you want to play with it, use your XOA on `latest` release channel. We also used the opportunity to fix some bugs. ### Full backup mirroring over 50GB from encrypted S3 remotes We’ve resolved an issue where mirroring full backups larger than 50GB from encrypted S3 remotes could fail. The problem was related to how part sizes were calculated during large file uploads: too many chunks would cause things to break. Now, Xen Orchestra estimates the backup size even when it’s coming from an encrypted remote and uses that to calculate a proper part size. This keeps the upload within S3’s limits (max. 10,000 parts), while balancing memory usage. ## 🥝 Core UI This month, we're introducing new ways to view critical information about your hosts at a glance, by updating the System tab. Also, we've improved translations and the dated the interface, with new SVG visuals for a cleaner look. ### New Host section in the System tab We've added a **Host** section inside the **System** tab. This gives you a quick look at essential host info like hardware details, CPU, and memory usage, all in one place. It's an easy way to keep an eye on your infrastructure and paves the way for future monitoring improvements. ![](https://xen-orchestra.com/blog/content/images/2025/05/438193200-4f326bd6-a2b7-4b38-ae00-3c19e3cf9bcb-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/05/438193206-e6bbe26f-8d22-467c-82cb-94fc6c24add4-1.png) New Host section in the System tab ### Updated translations Thanks to our community and their efforts on Weblate, translations have been improved across the app, with updates for Czech, German, Spanish, Dutch, Russian, and Swedish. This makes the interface more accessible and consistent for our international users, as part of our effort to enhance the experience for everyone. ![](https://xen-orchestra.com/blog/content/images/2025/05/687474703a2f2f7472616e736c6174652e76617465732e746563682f7769646765742f78656e2d6f72636865737472612f6d756c74692d6175746f2e737667.svg) Current translation status Thanks a lot to the community! If you'd like to help translate Xen Orchestra or fix existing translations, feel free to contribute [here](https://translate.vates.tech/?ref=xen-orchestra.com). If you want to discover more about Weblate, check out their website: [Weblate - web-based localizationCopylefted libre software, used by over 2,500 libre software projects and companies in over 165 countries.![](https://xen-orchestra.com/blog/content/images/icon/weblate-180-4.png)Weblate![](https://xen-orchestra.com/blog/content/images/thumbnail/og-4.png)](https://weblate.org/en/?ref=xen-orchestra.com) ### Improved visuals with new SVG images The interface of both XO 6 and XO Lite now uses a new set of SVG images. The new graphics look neater, more consistent, and perform better on all screen sizes and resolutions. ![](https://xen-orchestra.com/blog/content/images/2025/05/445071486-fc3fdb1c-d229-4021-bb5c-c2b13f9470bb.png) ![](https://xen-orchestra.com/blog/content/images/2025/05/445072314-89036ef3-aa22-4b46-ad60-2ba3e885e14d.png) ![](https://xen-orchestra.com/blog/content/images/2025/05/445072521-d217dbcf-02c5-4338-9900-6c23830fe3ad.png) ![](https://xen-orchestra.com/blog/content/images/2025/05/445072645-3cc764cf-501a-4143-8d8c-5349c99ffdb5.png) ![](https://xen-orchestra.com/blog/content/images/2025/05/445072829-a499a1f7-4090-4990-810d-b0595912c1c6.png) ![](https://xen-orchestra.com/blog/content/images/2025/05/445072963-b90fb124-d1c4-4b17-ba5b-689faf07fe1f.png) ![](https://xen-orchestra.com/blog/content/images/2025/05/446091483-06c23133-cff1-46e1-99f3-8ca0c0ebaaef.png) New SVG visuals available in XO 6 and XO Lite ## 🔭XO Lite This month with XO Lite, you can now choose storage repositories for VDIs when creating a VM! Read on for more details. ### Select a storage repository for existing VDIs at VM creation When creating a VM, you can now select which storage repository (SR) you want to use for each virtual disk (VDI). This gives you more control over where your VM's storage resides from the start. Whether you're balancing the load across multiple SRs or certain types of storage, this new option makes creating the VM more flexible and tailored to your setup. ![](https://xen-orchestra.com/blog/content/images/2025/05/436945605-5c655bdb-e40c-4523-b26f-eef68e2d5d46.png) Before the update, the storage repository field was disabled ![](https://xen-orchestra.com/blog/content/images/2025/05/436945719-5b9d5a7b-f63a-47aa-874e-71938be03628.png) After the update, the storage repository field is now enabled ## 🛰️ XO 6 This month, we've updated XO 6 to add a System tab to the VM page, so that you can see key information in an instant. ### System tab available for VMs VMs now have their own **System** tab. That makes it easy to quickly check key metrics for your VMs. ![](https://xen-orchestra.com/blog/content/images/2025/05/443195570-b2e6d7b1-01c0-43c2-be5a-92f4cb73cca4-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/05/443195576-58c7d6a3-b09c-4d41-a5d4-9573fee5b977-1.png) New System tab available for the VM view ## 🪐XOA We've made some important updates for XOA as well, tightening security to prevent misuse of trial accounts, while keeping it accessible for genuine users. Additionally, we've released a new XOA image build! ### Enhanced security for trial accounts We've made some tweaks to how account changes are managed in XOA. The reason for this is to cut down on trial abuse and **ensure that our trial system remains a resource for genuine users exploring our platform**. As our CEO Olivier Lambert highlighted in his recent blog post, we've encountered instances where organizations repeatedly exploited our trial system instead of opting for our open-source version or a supported subscription. Such practices challenge the sustainability of our open-source model and the trust we place in our user community. [Ground control to Major TrialWhen a $130M aerospace company chooses to endlessly abuse free trials instead of typing git pull, you start to question gravity, or at least common sense.![](https://xen-orchestra.com/blog/content/images/icon/faviconV2-5)VirtualizeOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/majortrial-1.jpg)](https://virtualize.sh/blog/ground-control-to-major-trial/?ref=xen-orchestra.com) Prior to these adjustments, users could easily update both their email and password in the registration tab. Now, to enhance security and discourage misuse, we've implemented a few changes specifically for trial users. If you're using XOA in trial mode and open the **Registration** form to update your details, the email field will be greyed out, and you won’t be able to change your email address anymore. ![](https://xen-orchestra.com/blog/content/images/2025/05/39808b7ca1a7424d979733f808f63092-image-1.png) Updated registration form ![](https://xen-orchestra.com/blog/content/images/2025/05/a2baa72af97541dc8864ec01c5c37690-image.png) Updated Registration form, with fixed email field Obviously, if you need to do it because you had a good reason for that, contact us, we'll be happy to assist! ### XOA image updated A new build of the XOA image was released, based on Debian 12.10 and XO 5.105.0\. As usual, you can grab it on [vates.tech/deploy](https://vates.tech/deploy?ref=xen-orchestra.com). [Xoa Deploy![](https://xen-orchestra.com/blog/content/images/icon/apple-touch-icon-8.png)![](https://xen-orchestra.com/blog/content/images/thumbnail/xo-logo-5.png)](https://vates.tech/deploy/?ref=xen-orchestra.com) It's very easy to export your config and import it on a new XOA, so if yours is still running a older Debian release (10 or 11), it's time to switch! ## 🖥️ XO CLI This month brings improvements to the CLI as well, as you can now manage network-wide traffic rules directly via XAPI and the CLI. This adds more control and flexibility to your SDN setup, with support for advanced policies coming soon. ### New traffic rules system now accessible through XAPI and XO CLI We have expanded the capabilities of the SDN Controller to let you manage network-wide traffic rules directly via XAPI, and support for per-VIF traffic rules on any network, including private networks. This leverages the efforts made in the past to manage OpenFlow rules on a per-VIF basis, and lets you specify traffic filtering routes that apply to entire networks without needing to manually configure each VM. From here on out, network policies can be added and deleted with the new XAPI endpoints. Policies are fully integrated in Xen Orchestra's SDN Controller and you can even use `xo-cli` to access them for testing or scripting. 💡 This feature requires a plugin on the XCP-ng side. While it’s already functional on the XO/XAPI side, we can’t commit to a release date for the plugin just yet. This update improves consistency and control over network traffic, while setting the stage for more complex network policies in the future. ## 📡 REST API As we keep improving the REST API month after month, you can now perform key server operations through the API. Plus, we've added even more endpoints to Swagger! ### Managing servers With the new release, not only can you **create new servers** straight from the API, but you can also **enable or disable existing servers** as well. This feature will help you better integrate and automate your infrastructure setup. ![](https://xen-orchestra.com/blog/content/images/2025/05/440822929-9484a75e-a5d0-4dec-bfa8-ddd314d068db-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/05/441147950-9a1f3e4f-8cf2-4305-aa1e-07a944159b6f.png) New server endpoints in the REST API ### More API endpoints available in Swagger A few releases ago, we began a project to fully document our REST API in Swagger (something we first discussed in the XO 5.104 blog post). As part of that process, we have now included more endpoints to Swagger: - PIFs (`get` and `getId`) - VMs (`snapshot`, `hard_shutdown`, `hard_reboot`, `clean_shutdown`,`clean_reboot`) If you are repeatedly calling the API or just like to have a more visual, interactive way to explore it, these additions will make your life **—**and integrations**—** easier. ![](https://xen-orchestra.com/blog/content/images/2025/05/441267500-6370cfe0-de1b-4aaa-9f16-f6f354a03f87-1.png) PIF endpoints documented in Swagger ![](https://xen-orchestra.com/blog/content/images/2025/05/446151608-0ed5a9e7-1453-491b-899f-67c1ffded9cc-1-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/05/446630262-7a68403d-d66d-45fb-8961-df7c9de193d2-1-1.png) New endpoints documented in Swagger [Xen Orchestra 5.104This month at Vates, we’re bringing you a wave of updates across the board! Our virtualization stack is now validated for Red Hat Enterprise Linux 9, and we’ve announced a strategic partnership with VyOS to enhance networking capabilities in Vates VMS.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-4.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/rodion-kutsaiev-b6Kfzd8pDaQ-unsplash.jpg)](https://xen-orchestra.com/blog/xen-orchestra-5-104/#swagger-and-openapi-integration-a-big-step-forward) ## ☸️DevOps Tools If you're using Xen Orchestra in a DevOps environment, we've got some great updates for you! We're making it easier to automate your workflow, with additions such as: a major new release of our Pulumi provider, improvements in our PowerShell module, and fresh template options in the Hub. Plus, we’ve restored full compatibility with the older versions of NetBox. Read on for more details! ### Introducing the Pulumi Xen Orchestra provider v2.0.0 The DevOps team has released a newer version of the Pulumi Xen Orchestra provider. Pulumi is an infrastructure-as-code SDK, that lets you manage infrastructure using a variety of programming languages. With our Xen Orchestra provider, you can manage XCP-ng and Xen Orchestra resources alongside your application code, using TypeScript, JavaScript, Python, Go, C#, or YAML. [Pulumi XO provider v2We just released our last version for our Pulumi provider for XO (v2)![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-6.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/pulumiv2.jpg)](https://xen-orchestra.com/blog/pulumi-xo-provider-v2/) This release ensures that the provider is up to date with the latest version of the pulumi-terraform-bridge, making it easier to keep up with new Pulumi versions. Since previously deprecated and replaced functions have been removed, this is considered a major release. Check out the Pulumi registry for provider documentation and code examples [Xen OrchestraProvides an overview of the Xen Orchestra Provider for Pulumi.![](https://xen-orchestra.com/blog/content/images/icon/favicon-8.ico)pulumi![](https://xen-orchestra.com/blog/content/images/thumbnail/og-default-4.png)](https://www.pulumi.com/registry/packages/xenorchestra/?ref=xen-orchestra.com) ### Hub templates Head over to the Hub in Xen Orchestra to install a new Alma Linux 9 template! Ready to use, with cloud-init you can start new VMs in seconds. ![Almalinux 9 template](https://xen-orchestra.com/blog/content/images/2025/05/image.png) ### Xen Orchestra PowerShell module The `xo-powershell` module has moved from alpha to beta and is now published in the PowerShell Gallery as version **1.0.0-beta** 🥳 [xo-powershell 1.0.0-betaXen Orchestra PowerShell module![](https://xen-orchestra.com/blog/content/images/icon/favicon-9.ico)PowerShell Gallery Home![](https://xen-orchestra.com/blog/content/images/thumbnail/PackageDefaultIcon.png)](https://www.powershellgallery.com/packages/xo-powershell/1.0.0-beta?ref=xen-orchestra.com) Grab it with this Powershell command in your console: `Install-Module -Name xo-powershell -AllowPrerelease` Then check out the cmdlets documentation here: [GitHub - vatesfr/xo-powershell: PowerShell module for Xen-OrchestraPowerShell module for Xen-Orchestra. Contribute to vatesfr/xo-powershell development by creating an account on GitHub.![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-10.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/xo-powershell-1)](https://github.com/vatesfr/xo-powershell?tab=readme-ov-file&ref=xen-orchestra.com#available-commands) ## **🆕** Misc As we are focusing more and more on XO 6 and XO Lite, the misc section is getting thinner. That's a very good sign for 2 reasons: there's less things to fix and it shows how focused we are on the new UI! ### Support for NetBox 4.3 and earlier NetBox is an open-source platform designed to help you manage and document complex networks. It's commonly used to monitor IP addresses, racks, devices, and other infrastructure details, making automation and organization easier. Xen Orchestra now fully supports NetBox 4.3 and earlier versions. Recent updates to NetBox had caused some compatibility issues, but the new Xen Orchestra release has resolved these. If you’ve upgraded NetBox, everything should work smoothly again without any extra steps. ### Enhanced Safari compatibility We've fixed an issue in Safari where the Xen Orchestra logo on the login page appeared way too large. This release corrects the layout, so the page now displays as expected. ![](https://xen-orchestra.com/blog/content/images/2025/05/442011048-486f50be-348c-45dd-bd76-0ba3cd9522a1.png) ![](https://xen-orchestra.com/blog/content/images/2025/05/442011052-6a1609fc-8452-4df2-896e-fb001b956c44.png) The Xen Orchestra login page, as it should appear on all major browsers We've also improved how the XO header renders on the mobile site. Previously, resizing the window could push the burger icon out of place and shrink the "Xen Orchestra" text. Now, Safari refreshes the header more intelligently, ensuring everything displays properly. ![](https://xen-orchestra.com/blog/content/images/2025/05/442664786-af9d3749-06b0-475a-8b69-43ffc3c1282c.png) Burger icon not positioned correctly ![](https://xen-orchestra.com/blog/content/images/2025/05/442664868-ab247271-f239-43e6-84a3-e5817f924d5a.png) Wrong text resizing ### Windows Templates with Cloudbase-init: Step-by-step Guide & Best Practices URL: https://xen-orchestra.com/blog/windows-templates-with-cloudbase-init-step-by-step-guide-best-practices/ Last updated: 2025-05-21T09:47:25.000Z If you have ever dealt with Windows deployment, you are likely familiar with the System Preparation Tool (Sysprep), a built-in Windows utility for generalizing and customizing Windows images for cloning. In Xen Orchestra, per-VM customization is provided by *cloud-init*, which is a cross-platform, YAML-based VM deployment method supporting Linux and BSD. Windows does not support cloud-init out of the box; however, [Cloudbase-init](https://cloudbase.it/cloudbase-init/?ref=xen-orchestra.com) provides a compatible implementation. Read the [online documentation](https://cloudbase-init.readthedocs.io/en/latest/index.html?ref=xen-orchestra.com) for more details on how to use Cloudbase-init. ## Overview The idea is to maintain a *master VM* containing a fresh, up-to-date copy of Windows. From this master VM, you can branch out *template VMs* and customize them with drivers, tooling and settings as desired. Finally, these template VMs will be generalized with Sysprep and converted into templates that can be used for VM creation. You will find an overview diagram below: ![](https://xen-orchestra.com/blog/content/images/2025/05/overview.png) Following is a list of steps for preparing a Windows template: 1. Create and install master VM (for Windows Update) 2. Branch out master VM to template VM 3. Install software in template VM 4. Sysprep and reseal; template creation 5. Instantiate new VM **Why use a master VM?** - Windows installed from older media may take a very long time to catch up with updates (especially in the case of Server 2016). - Creating VMs from a recently-updated template also reduces the time and resources needed to bring each new VM up to date. - Many different kinds of template VMs can be branched from the same master, saving time and effort. - Note that you don't need to produce a new template every time you update Windows. Instead, consider your VM update policy and refresh your templates as necessary. - If you don't expect to have multiple different kinds of templates, feel free to install software directly onto your master VM. Every time you want to refresh your template, simply clone your master then run Sysprep. ## Step-by-step guide ### Installing master VM Create a Windows VM using the included default templates for Windows, then install Windows as usual. However, at the initial Welcome screen after Windows starts up, we will enter Audit mode by pressing **Ctrl+Shift+F3**. 💡 Our guide uses Windows Server 2022, however any supported version of Windows would also work. 💡 We highly recommend starting from the default Windows templates, as they contain optimal settings for Windows guests. Use at least 4 vCPUs and 4 GB of RAM to ensure that the update process goes smoothly. 💡 Audit mode is a special Windows boot mode that skips customizations normally applied after Setup. Using Audit mode helps avoid certain Sysprep issues, especially with Store apps. ![](https://xen-orchestra.com/blog/content/images/2025/05/1-audit1.png) Master VM: Press Ctrl+Shift+F3 here to enter Audit mode. Windows will automatically restart, and you will be presented with the Sysprep GUI as follows. ![](https://xen-orchestra.com/blog/content/images/2025/05/1-audit2.png) Master VM: Windows in Audit mode ⚠️ Keep this Sysprep window open throughout the entire Audit mode up until you manually invoke Sysprep.exe. If you close the Sysprep window by accident, you may get locked out and be forced to reboot. Now, you can keep your master VM up-to-date using Windows Updates in preparation for future templates. ### Branching out template VM Every time you want to refresh your templates, copy your master VM into a new *template VM*. As its name indicated, this VM will become your new Windows template for future production VMs. 💡 Use a full VM copy (**Copy* button) to avoid having too many VM disk layers, which may degrade performance. ![](https://xen-orchestra.com/blog/content/images/2025/05/1-copyvm.png) ### Installing software in template You can install any software you need in this template. In this example, we install the XenServer VM Tools: ![](https://xen-orchestra.com/blog/content/images/2025/05/2-winpv2.png) You can freely restart the VM when prompted. Once restarted, the VM will go back to Audit mode until you run Sysprep again. ### Configure Cloudbase-init Grab the latest installer from [cloudbase.it](https://cloudbase.it/cloudbase-init/?ref=xen-orchestra.com) and start the installation process. ![](https://xen-orchestra.com/blog/content/images/2025/05/2-cbi1.png) Don't run Sysprep at this step yet; you still need to configure cloudbase-init. ![](https://xen-orchestra.com/blog/content/images/2025/05/2-cbi2-1.png) Enter the directory `C:\Program Files\Cloudbase Solutions\Cloudbase-Init\conf`. You will find the following two files: `cloudbase-init.conf` and `cloudbase-init-unattend.conf`. For each file, replace any `metadata_services` lines with the following: ``` metadata_services=cloudbaseinit.metadata.services.nocloudservice.NoCloudConfigDriveService ``` This line makes sure Cloudbase-init uses the NoCloud configuration drive (as generated by XO) as its data source. ![](https://xen-orchestra.com/blog/content/images/2025/05/3-cbi.png) Your VM is now ready for conversion to template. ### Sysprep and reseal Close the running Sysprep window, then run the following command in a PowerShell window running as Administrator: ``` C:\Windows\System32\Sysprep\sysprep.exe /generalize /oobe /shutdown "/unattend:C:\Program Files\Cloudbase Solutions\Cloudbase-Init\conf\Unattend.xml" ``` ⚠️ You must specify Cloudbase-init's Unattend.xml since this file is what starts the cloud-init configuration process. The `Unattend` parameter should be fully quoted because the Unattend.xml path contains spaces. Once the Sysprep process is complete, your template VM will shut itself down. ![](https://xen-orchestra.com/blog/content/images/2025/05/4-sysprep.png) Finally, immediately convert your VM to a template; do not start it again or the cloud-init configuration process will begin. ### Instantiating new VMs Create VMs from your prepared template and enter your cloud-init configs as necessary. ![](https://xen-orchestra.com/blog/content/images/2025/05/5-instantiate.png) 💡 Refer to the [Cloudbase-init plugins documentation](https://cloudbase-init.readthedocs.io/en/latest/plugins.html?ref=xen-orchestra.com) for information on how to configure cloud-init for Windows guests. Your VMs will reboot several times during the unseal process. ![](https://xen-orchestra.com/blog/content/images/2025/05/5-unseal.png) Enjoy your finished product. ![](https://xen-orchestra.com/blog/content/images/2025/05/6-finish.png) ## Tips and tricks - If you are Sysprepping an installation containing the XenServer/XCP-ng PV drivers, you may need to set the [PersistAllDeviceInstalls](https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/microsoft-windows-pnpsysprep-persistalldeviceinstalls?ref=xen-orchestra.com) option in your Unattend.xml. (Cloudbase-init's Unattend.xml already includes this option) - Windows Server in Audit mode is not activated, and will automatically shut down after 1 hour. Be sure to either finish your work in 1 hour, or simply reboot before the timeout expires. ### Pulumi XO provider v2 URL: https://xen-orchestra.com/blog/pulumi-xo-provider-v2/ Last updated: 2025-05-15T12:47:07.000Z Version 2.0.0 of our Pulumi provider is out! It leverages the Xen Orchestra API to manage your XCP-ng infrastructure as code. 💡 ****Why use the Xen Orchestra API instead of talking to each XCP-ng host directly?** Because XO already abstracts and centralizes everything. You don’t need to worry about which host runs what : the API gives you a unified, consistent way to manage your whole platform (VMs, storage, networks, and more). It's the smart layer on top of your infrastructure! This release aims to ensure that the provider is up to date with the latest version of the pulumi-terraform-bridge. This will make it easier to follow new Pulumi versions. ![](https://xen-orchestra.com/blog/content/images/2025/05/avatar-on-white.png) The underlying Terraform provider XenOrchestra is updated to version 0.31.1, which fixes: - Issues with blocked operations when creating VMs. [#344](https://github.com/vatesfr/terraform-provider-xenorchestra/pull/344?ref=xen-orchestra.com) - A problem where the `destroy_cloud_config_vdi_after_boot` setting was ignored when the VM wasn't running. [#345](https://github.com/vatesfr/terraform-provider-xenorchestra/pull/345?ref=xen-orchestra.com) As the major version number suggests, this release introduces changes that break compatibility with previous versions (mostly deprecated functions and resources that have been removed). **Find the release in the Pulumi registry:** [Xen OrchestraProvides an overview of the Xen Orchestra Provider for Pulumi.![](https://xen-orchestra.com/blog/content/images/icon/favicon-6.ico)pulumi![](https://xen-orchestra.com/blog/content/images/thumbnail/og-default-2.png)](https://www.pulumi.com/registry/packages/xenorchestra/?ref=xen-orchestra.com) **Full Release Note:** [Release v2.0.0 · vatesfr/pulumi-xenorchestraThis release aims to ensure that the provider is up to date with the latest version of the pulumi-terraform-bridge. This will make it easier to follow new Pulumi versions. What’s Changed Update RE…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-9.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/v2.0.0)](https://github.com/vatesfr/pulumi-xenorchestra/releases/tag/v2.0.0?ref=xen-orchestra.com) ### Xen Orchestra 5.106 URL: https://xen-orchestra.com/blog/xen-orchestra-5-106/ Last updated: 2025-04-30T15:56:41.000Z Welcome to the April edition of our monthly Xen Orchestra updates! This month brings exciting progress across the board: from major backend work on our revamped backup engine, to the evolution of our SDN controller plugin, and plenty of improvements and fixes along the way. As always, everything we’re doing is about making XO more powerful, more reliable, and easier for you to use — whether you're managing a handful of hosts or running a massive infrastructure. Let’s dive in and see what’s new! ## 👨‍🚀 Project & Community As we keep innovating and growing, we’re excited to share the latest updates from Xen Orchestra and Vates. From new features in XO 6 and our partnership with EasyVirt, to expanding our services and upcoming events like the Vates Innovation Summit, your input plays a key role in shaping the next chapter of our journey. ### XO 6: we need your input! As our team works hard to deliver the MVP of **Xen Orchestra 6** before the end of the year, we’re looking to our amazing community for help shaping what matters most in this next major release. To do that, we’ve prepared a **quick survey** to gather your feedback on current features, pain points, and what you’d love to see in XO 6\. Your input will directly influence the roadmap and priorities of the first release. [Shape XO6 MVP roadmap (XOCE)Thanks a lot for your time 🙏![](https://xen-orchestra.com/blog/content/images/icon/favicon-4.ico)Formbricks![](https://xen-orchestra.com/blog/content/images/thumbnail/og)](https://survey.vates.tech/s/xbz59mbp7c58g16jypc5b9sc?ref=xen-orchestra.com) ❗ If you're using Xen Orchestra in a ****production environment** as part of the ****Vates VMS bundle**, you’ll receive a ****dedicated customer survey** in the coming days, stay tuned! ### Vates & Easyvirt: strengthening the Cloud ecosystem EasyVirt and Vates have joined forces to offer a credible French alternative to VMware—one that covers the key features of both vCenter and Aria Operations. This partnership is a concrete response to the growing needs of IT leaders who are re-evaluating their technological dependencies and seeking clear, sovereign, and sustainable virtualization solutions that align with both business objectives and regulatory requirements. [Vates & Easyvirt: a new alliance strengthening the Cloud technology ecosystemDC Scope brings advanced monitoring, optimization, and sustainability features to XCP-ng environments, offering a powerful, turnkey alternative to VMware Aria.![](https://xen-orchestra.com/blog/content/images/icon/logo64-9.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/dcalpsgreen.jpg)](https://vates.tech/blog/p/123d4912-73d4-4f7c-b9a4-91395f30e4e0/?ref=xen-orchestra.com) ![](https://xen-orchestra.com/blog/content/images/2025/04/dashboard2_xo.png) One of the EasyVirt dashboard, connected to XO API ### The Open Source we use at Vates: 2025 edition From 3 co-founders to a team of nearly 100, our commitment to open source has never wavered. We've built our business on open source tools—and contributed back by creating our own, like XCP-ng and Xen Orchestra, now powering datacenters worldwide. Discover what we use today to run our entire company! [The Open Source we use at Vates: 2025 editionHow do you scale from 3 to 100 people while staying fully self-hosted and open source? Here’s our 2025 update on the tools we use, to prove it’s not just possible, it’s powerful.![](https://xen-orchestra.com/blog/content/images/icon/logo64-8.png)Vates BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/selfhosted.webp)](https://vates.tech/blog/the-open-source-we-use-at-vates-2025-edition/?ref=xen-orchestra.com) Alternatively, you can look at the recent video from Tom (Lawrence Systems) who made a recap about it: ### Vates services offering is shaping up We're expanding our portfolio to go beyond regular support, with a growing suite of professional services designed to support our users at every stage of their journey with Vates VMS. Whether you're looking for long-term strategic guidance with a dedicated [Technical Account Manager](https://vates.tech/services/technical-account-manager/?ref=xen-orchestra.com), need expert help for a [VMware migration project](https://vates.tech/services/migration-package/?ref=xen-orchestra.com), or want to bring in one of our [consultants](https://vates.tech/services/consultant/?ref=xen-orchestra.com) for a specific mission, our goal is simple: help you get the most out of your infrastructure with peace of mind. [![](https://xen-orchestra.com/blog/content/images/2025/04/VATES_Sans-Fond_Support-blog-1.png)](https://vates.tech/services/technical-account-manager/?ref=xen-orchestra.com) ### Vates Innovation Summit 2025 Last year, our Italian subsidiary hosted the very first Vates Innovation Summit in Venice. In 2025, we’re back with a new edition—this time set against the stunning backdrop of Capri. The event will feature a series of talks focused on innovation within public institutions, as well as discussions around European cybersecurity and digital sovereignty. [Vates Innovation Summit 2025 | 30 MaggioVates Innovation Summit 2025 “La sovranità Digitale”![](https://xen-orchestra.com/blog/content/images/icon/cropped-logo250-270x270.png)Vates![](https://xen-orchestra.com/blog/content/images/thumbnail/Vates-Capri-Innovation-Summit-2025-EDITED2.jpg)](https://www.vatesis.com/?ref=xen-orchestra.com) ### Beyond VMware: the shifting landscape of virtualization Meet our Chief Marketing Officer, Marc-André Pezin, during the [RPLL](https://www.rpll.fr/?ref=xen-orchestra.com) (Rencontres Profesionnelles du Logiciel Libre) 2025\. Marc-André will deliver a conference about the future of virtualization: > The acquisition of VMware by Broadcom sent shockwaves through the virtualization industry, prompting many companies and institutions to rethink their strategy. Rising prices, licensing changes, and reduced partner programs have accelerated the search for alternatives. Vates, the French publisher behind Vates VMS (XCP-ng and Xen Orchestra), will share its perspective after more than two years of helping organizations migrate away from VMware. [Website of the event](https://www.rpll.fr/?ref=xen-orchestra.com) 🗣️ The conference will be conducted in French. ### Dell Open Manage Enterprise with XCP-ng If you want to use Dell OME with XCP-ng, you need to modify it to boot correctly on XCP-ng. Luckily, Cecile wrote an article on how to do it and get a working OME running as a VM for your Dell servers! [Add Xen driver to OME (Dell Open Manage enterprise)If you try to boot OME on an XCP-ng box, you might end up with a black screen. How disappointing, I know. But, during my latest insomnia, I found the explanation: Dell removed the Xen driver needed to “speak” to the disk and network interfaces. I’ll show you how you![](https://xen-orchestra.com/blog/content/images/icon/favicon-5.ico)Ataxya's BlogCécile MORANGE![](https://xen-orchestra.com/blog/content/images/thumbnail/publication-cover.png)](https://blog.ataxya.net/add-xen-driver-to-ome-dell-open-manage-enterprise/?ref=xen-orchestra.com) We even have a dedicated community thread to share your feedback about it: [\[dedicated thread\] Dell Open Manage ApplianceHi, I am trying to import Dell OpenManage appliance and I have the following files: In Xen Orchestra I know how to import the OVF file but I am nit sure wha…![](https://xen-orchestra.com/blog/content/images/icon/512-6.png)XCP-ngfred974![](https://xen-orchestra.com/blog/content/images/thumbnail/1656683778187-41702ae1-2593-4b61-98b1-f1a8b82c66f9-image.png)](https://xcp-ng.org/forum/topic/6049/dedicated-thread-dell-open-manage-appliance?ref=xen-orchestra.com) ### What it takes to build a virtualization platform Today, everyone relies on virtualization, but very few truly understand the complexity beneath the surface. It's easy to think of hypervisors as simple, interchangeable commodities, but that view is a dangerous illusion. In this post, I share my perspective on what it really takes to build a complete virtualization stack: from working at the hypervisor level with Xen, all the way up to delivering powerful management tools like Xen Orchestra. [Few build Hypervisors. We’re one of them.Everyone uses virtualization. Few truly understand what they’re building on. That’s why calling hypervisors a commodity is a dangerous illusion.![](https://xen-orchestra.com/blog/content/images/icon/faviconV2-2)VirtualizeOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/engineplane.jpg)](https://virtualize.sh/blog/few-build-hypervisors-were-one-of-them/?ref=xen-orchestra.com) --- Time to switch on XO release. What's up in April? ## 💾 Backup This month, our backend team is hard at work on the new, revamped backup engine. The aim is to make it truly **universal**, capable of handling any format — whether it's qcow2, VHD, VMDK, XVA, and beyond. It’s also the perfect opportunity to **build it right from the ground up**, with strong foundations like unit tests, full TypeScript support, and modern best practices. For a deeper dive into the project and what’s coming next, check out our dedicated blog post: [Next-gen XO backup engine: beyond VHDDiscover how we’re building a smarter, format-agnostic backup system to meet the demands of tomorrow’s infrastructure.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-1.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/backupnew.jpg)](https://xen-orchestra.com/blog/next-gen-xo-backup-engine-beyond-vhd/) ## 🥝 Core UI We managed to get many new components ready in those last 4 weeks, but even more than this, to prepare some VueJS helpers to make the use of Core UI even better. ### Many new and updated translations Since introducing Weblate just two months ago, we've seen a **huge surge in contributions:** more activity on XO 6 and XO Lite translations than **everything before on XO 5 combined**. ![](https://xen-orchestra.com/blog/content/images/2025/04/687474703a2f2f7472616e736c6174652e76617465732e746563682f7769646765742f78656e2d6f72636865737472612f6d756c74692d6175746f2e737667.svg) Thanks to our amazing community, we’ve updated **Swedish, Czech, Spanish, Persian, Italian, and Russian** — and we’ve also added **Dutch** support! ### Add master icon in host header When viewing a host dashboard, it’s now easy to spot whether the host is the **pool master**, thanks to a new icon added directly in the header. ![](https://xen-orchestra.com/blog/content/images/2025/04/434364409-613d6559-a055-4173-93ad-98b44c846ba6.png) ![](https://xen-orchestra.com/blog/content/images/2025/04/434364415-0c355f64-5ab4-46ff-8794-566da4a8a788.png) This improvement also marks the **first contribution from a new member** of our frontend team — and we’re excited to see our latest recruits ramping up and bringing even more features and components to the **Core UI**! ### New `TaskItem` component We've introduced a new component to standardize the display of tasks across the interface. This update gives task-based elements a cleaner and more consistent look. This part is made with reuse in mind, so look for it to appear wherever tasks are shown, for improved visual consistency and allowing us to develop more efficiently in the future. It's a subtle change under the hood, but it opens the door for a more cohesive user experience. ![](https://xen-orchestra.com/blog/content/images/2025/04/431276865-e08d124d-ddf9-4849-8c62-1210428914c9.png) New TaskItem component in XO6 and XO Lite ### New `Alert` component There is now an `Alert` component to display messages and notifications in a standard and readable way. It offers different alert types (e.g. info, warning, or error) and makes it easier to convey status or feedback to users. This component brings consistency to how notifications are displayed in the interface. It will replace ad hoc implementations, making notifications look better and more reliable throughout Xen Orchestra. ![](https://xen-orchestra.com/blog/content/images/2025/04/427083745-b865cef0-cbb9-4350-ab3b-7c1672eae4d9-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/04/427083689-134b3b3e-efbe-458c-bd05-34444105a000-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/04/427083629-74b67bd4-4ab6-4340-9d8e-e21c9d7d0ecb-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/04/427083449-295060b7-019d-4ad1-842a-5f80388985bf-1.png) ## 🔭 XO Lite XO Lite is becoming now functional enough to bootstrap your infrastructure, and we continue to deliver new visualizations and features! ### New host dashboard XO Lite contains a newly refreshed host dashboard, with a responsive and light design, that makes you instantly access important performance metrics like memory, CPU, load, and running virtual machines. All you will need for a quick status check. ![](https://xen-orchestra.com/blog/content/images/2025/04/432840682-bdfbb84a-5c22-4afb-ba71-618170ef911e.png) XO Lite host dashboard - Light theme ![](https://xen-orchestra.com/blog/content/images/2025/04/432840831-5a17e8ec-4d03-4ca2-b7fd-e495b4205943.png) XO Lite host dashboard - Dark theme ### Additional VM creation capabilities VM creation in XO Lite is now more complete, with the ability to edit the Affinity host, Tags, and Typology fields. You can specify an affinity host at creation to determine VM placement, assign tags for better organization, and specify CPU typology (cores, sockets, threads) beforehand—all from within the XO Lite interface. These improvements make XO Lite a better tool for day-to-day operations, especially when you must deploy VMs quickly with the correct settings from the start. ![](https://xen-orchestra.com/blog/content/images/2025/04/431355356-096c3ae5-c569-4e93-86f8-268e97909845-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/04/435132593-9f6bfca4-3ec7-44eb-aee9-8d2ae12d49c4-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/04/435132541-7387ad28-11c5-4293-a780-3a896578f183-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/04/430453255-6d22dcfb-3817-4f37-81d2-a27c74cfa791-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/04/430453180-dc746986-9bb0-480e-9992-e79b368817f0-1.png) ## 🛰️ XO 6 Our goal for XO 6 is to make it complete enough to replace XO 5 by default before the end of the year. This month, more views are available! ### New `AlarmItem` component XO 6 introduces the new `AlarmItem` component, designed to display individual alarm details in a way thats both consistent and user-friendly. This means alarms are presented with clear, actionable information, for easier monitoring. ![](https://xen-orchestra.com/blog/content/images/2025/04/435197020-6e843d48-db38-4fb8-9e3c-b41410402e81-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/04/435196900-c77cb94c-0865-45c5-b829-d675b778556c-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/04/435196898-b4385657-de69-4467-ba3d-16d839b01e72-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/04/435196899-92e7add1-c1ed-4883-80e4-008037c6ab78-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/04/435197554-9ed7c79b-9e04-4ef1-b026-35596d1ed566-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/04/435197550-0e9f7b47-5c6e-477b-82dd-3d2b40f0b8af-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/04/435197559-9c57b11a-9654-4948-851e-f35101b1e4a2-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/04/435197548-ce96c4fa-2a98-4156-9584-a4d30aea3318-1.png) ### `useCollection` composable (VueJS) A new VueJS composable that greatly improves developer experience and maintainability of components that handle big collections of objects. The composable will allow us to create and manipulate lists and sub-lists of objects (like VMs, VDIs, etc.), assign derived properties and flags to each item (like whether an item is selected or not), group the items by category, and many more things! All of that without losing VueJS's reactivity and performance. The composable also exposes builtin helpers to easily know how many items have a certain flag on, to toggle flags on and off, to extract a sub-set of the list, etc. All in all, this is a very generic composable that makes handling collections very easy and will help us create or improve other components like tables, selectors, trees, etc. And since this is a composable built from scratch for XO Lite and XO 6, we'll be able to easily add other features as needed! ## 🪐 XOA Our turnkey virtual appliance is improved on a regular basis. This time, it's about compliance with better management of audit logs. ### Import audit logs from another appliance If you're moving to a new Xen Orchestra Appliance (XOA) and wish to take your audit logs with you, there is now an easy way of doing it. The new `audit.importRecords` feature allows you to import all audit records from a ndJSON file. This is really convenient if you have compliance requirements to keep logs around for a period of time, or if you want to keep historical data for a migration. When you use this feature, it automatically ensures that there are no existing records in the target appliance. This maintains log integrity and prevents duplication issues. This feature was developed in response to user feedback requesting a way to migrate audit logs between appliances. Now you can transfer your logs and transition effortlessly to a new instance without losing historical information. ![](https://xen-orchestra.com/blog/content/images/2025/04/429571817-b95d2388-8c19-48b0-886a-5ecde1c315b8.png) New Import audit button ## 📡 REST API We’re making big strides with our REST API, as we're simplifying it and adding rich new features for both developers and devops. With more endpoints now on Swagger and greater automation capabilities, the API is faster, more robust, and ready for even the most custom integrations. ### Additional endpoints moved to Swagger We've continued to clean up and modernize our REST API by moving even more endpoints over to Swagger. This batch includes: - Alarms - Groups - Networks - Messages - Pools - Users All of these now have their `get` and `getId` routes completely defined in Swagger, following the same logic and pattern we added during the initial migrations. The goal is the same: to make the API more consistent, discoverable, and easy to work with—regardless of whether you're coding custom integrations, creating automation tools, or just browsing around with OpenAPI-compliant clients. As with the previous migration, type definitions were brought closer to true XAPI responses to help avoid mismatches and surprises consuming the API. This ongoing effort is all about giving you a more predictable, stable experience when dealing with Xen Orchestra's REST endpoints. ### Swagger improvements We’ve made a few quality-of-life improvements to the Swagger interface to make it smoother and more pleasant to use. Snippets have been added across the board, so endpoints are easier to understand at a glance. We’ve also improved tags, sorting and naming to better reflect the actual API structure, making it more intuitive when browsing or integrating with tools like Postman or the Swagger UI. Here's an example: ![](https://xen-orchestra.com/blog/content/images/2025/04/430000695-8998ad20-2ceb-44f5-9c7f-a0f237a86d5d.png) ### Run schedules via the API You can now launch schedules right through the REST API. This feature lets you run a schedule whenever you want, which is perfect for testing, debugging, or to perform an on-demand run, even for tasks that don’t have a dedicated endpoint yet. For example, if you need to reboot a host but there’s no call available on the API, you can simply create a reboot job in Xen Orchestra, attach it to a schedule, and trigger it via the API. A new endpoint has been added for that purpose: `POST /rest/v0/schedules//actions/run` It will fetch the schedule and the job associated, then run it as if it were launched automatically. On top of that, two new endpoints allow you to list all schedules or retrieve a specific one: • `GET /rest/v0/schedules` • `GET /rest/v0/schedules/` With this, you can automate backups, reboots, or any other custom job wrapped in a schedule, giving you full control from your scripts or orchestration tools. ## ☸️ DevOps Tools Our DevOps tools keep evolving to make your infrastructure easier to deploy and manage. This month, we’re bringing important updates that simplify Kubernetes deployments and make production environments even more accessible from Xen Orchestra. ### Project Pyrgos: now using MicroK8s The Pyrgos project, our Kubernetes cluster recipe available in the XOA Hub, has been greatly enhanced. It now uses MicroK8s, a light, open-source, scalable and production-ready Kubernetes distribution. **This update makes deployments more stable, easier to maintain, and quicker to set up.** With just a few clicks, you have an environment ready for production, with built-in support for high availability if needed. Networking, core services and node configuration are all handled automatically. This update makes Kubernetes deployments in Xen Orchestra easier and more reliable. To know more about MicroK8s, visit the official website: [MicroK8s - Zero-ops Kubernetes for developers, edge and IoT | MicroK8sMicroK8s is the simplest production-grade conformant K8s. Lightweight and focused. Single command install on Linux, Windows and macOS. Made for devOps, great for edge, appliances and IoT. Full high availability Kubernetes with autonomous clusters and distributed storage.![](https://xen-orchestra.com/blog/content/images/icon/f38b9c7e-COF-20apple-touch-icon.png)microk8s.io![](https://xen-orchestra.com/blog/content/images/thumbnail/82818827-CoF_white.svg)](https://microk8s.io/?ref=xen-orchestra.com) ### Powershell module Our team worked hard on the newly PowerShell module we announced last month. We added new cmdlets to manage pools, networks, VBDs and improved the output formatting. It seems this PowerShell module was very expected, as we have already received valuable comments, reports and issues and feature requests from users! It is very nice to see a new tool warmly welcomed by community! [GitHub - vatesfr/xo-powershellContribute to vatesfr/xo-powershell development by creating an account on GitHub.![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-6.svg)GitHubvatesfr![](https://opengraph.githubassets.com/f9d8498c810b94af6461b1aa713f44f53334ecbcba6e1b0ba470ca98271e6f8f/vatesfr/xo-powershell)](https://github.com/vatesfr/xo-powershell?ref=xen-orchestra.com) ## 🌐 New XO SDN controller incoming Even though it’s not released yet, we wanted to give you an early look at the evolution of our XO SDN controller. Initially, the core logic lived directly inside Xen Orchestra, which acted as the controller for Open vSwitch (OVS). This approach enabled some very cool capabilities, like creating **private networks between pools** and more. If you want to dive deeper, you can check out the [original documentation](https://xen-orchestra.com/blog/xo-sdn-controller/) and past posts like: [DevBlog #2 - XO SDN controllerWe are working on a new XO plugin: a SDN controller allowing to create pool-wide private networks.![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-2.png)Xen Orchestra BlogBenjamin REIS![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1545987796-200677ee1011)](https://xen-orchestra.com/blog/xo-sdn-controller/) [DevBlog #3 - Extending the SDN ControllerAn update of the SDN Controller is coming. Soon, creating cross-pool private networks will be possible!![](https://xen-orchestra.com/blog/content/images/icon/squaresmallxo-1-3.png)Xen Orchestra BlogBenjamin REIS![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1532187643603-ba119ca4109e)](https://xen-orchestra.com/blog/devblog-3-extending-the-sdn-controller/) However, this first version came with a few limitations: - **Traffic rules** could only be applied to VIFs (virtual network interfaces) that were attached to the management network — not to most VM networks, which are often separated in production. - You couldn't apply **traffic rules at the network level**, only at the VIF level. - If XO became unavailable and you rebooted a host, you would **lose** the flow rules. - **Only one** virtual switch could be configured globally. - And finally, you needed to open a **specific port** on each host for XO to communicate directly with OVS — something that wasn’t ideal for security or scalability. Given these challenges, we decided it was time for a fresh approach — one that's more aligned with the broader XCP-ng + XO architecture. Instead of having XO talk directly to OVS, we’re moving the logic into XCP-ng itself, with XO orchestrating it via **native XAPI calls**. This new design involves creating a **XAPI plugin** that exposes the necessary OVS commands, allowing XO to interact cleanly without opening any extra ports — simply using the existing XAPI connection already in place. Together, the XAPI team and XO backend team have kicked off the work to **rewrite the XO SDN controller** with this improved model. The result? A simpler, more reliable architecture that **eliminates previous limitations** and **enhances** cross-pool private networking capabilities — paving the way for even more features in the future! ## 🐦 VMware to Vates (V2V) Moving from VMware to the Vates environment should be as seamless as possible. That’s why we’re adding more enhancements to the V2V process, one release after another. ### Resume interrupted imports You can now resume V2V imports if they get interrupted—no need to start from scratch again. It could be a network hiccup, a reboot, or something else entirely, but Xen Orchestra will continue where it left off. This makes large or long imports more reliable, especially in environments where interruptions are common. Previously-imported data is recognized and won’t be duplicated, saving both time and frustration. 💡 This feature is based on warm migration mode, so this mode needs to be enabled and functional. If warm migration is unavailable or fails, resuming won't be possible. Also, intermediate VMs created during the process aren’t automatically cleaned up—you’ll need to remove them manually once the import is successfully completed and validated. ## **🆕** Misc As always, we’ve added a few extra touches to make your experience even better, this time covering how Xen Orchestra interacts with Office 365. ### Support for the Office 365 connector webhook format The **web-hooks** plugin in Xen Orchestra now supports the Office 365 connector format, making it easier to send notifications directly to Microsoft Teams channels. This feature ensures webhook payloads are formatted correctly for Teams, so that messages and alerts appear as intended. This improvement is particularly useful for users who use Teams for collaboration since it simplifies the integration procedure. By adhering to the Office 365 connector template, Xen Orchestra enables straightforward communication between your virtual infrastructure and Teams. ![](https://xen-orchestra.com/blog/content/images/2025/04/438127999-60b6a7bb-8c0b-459f-88b0-d78e565cb051.png) ![](https://xen-orchestra.com/blog/content/images/2025/04/438129860-7c643a5d-2971-42d7-b304-67f114576c47.png) Office 365 selection in the web-hooks plugin + Sample of an automatic notification in Microsoft Teams ### Next-gen XO backup engine: beyond VHD URL: https://xen-orchestra.com/blog/next-gen-xo-backup-engine-beyond-vhd/ Last updated: 2025-04-25T07:50:59.000Z If you've been keeping an eye on our community forum, you may have spotted a recent thread inviting users to test a brand new backup engine in Xen Orchestra: [Our future backup code: test it!A big change is coming! As we prepare to add qcow2 support for backups, we took the opportunity to redesign major parts of the backup engine. The result? A m…![](https://xen-orchestra.com/blog/content/images/icon/512-5.png)XCP-ngolivierlambert![](https://xen-orchestra.com/blog/content/images/thumbnail/1-profileavatar-1620659303584-3.jpeg)](https://xcp-ng.org/forum/topic/10664/our-future-backup-code-test-it?ref=xen-orchestra.com) That’s right: we’ve been working behind the scenes on a major revamp of how XO handles backups, and it’s now far enough along that we can share more details. This is more than just a refactor. It’s a foundational redesign that opens the door to bigger, faster, and more flexible backup workflows, and it's built to support the future of virtualization at scale. ## Why change the backup engine at all? Today, when Xen Orchestra performs a backup (whether from XAPI or via a VMware import), it transforms the data into a VHD stream. This approach has served us well, offering solid performance and flexibility. But it comes with one critical limitation: VHD streams simply can’t handle virtual disks larger than 2TB. This isn’t a bug: it’s a design constraint of the format. Each offset in the VHD allocation table is a 32-bit value pointing to 512-byte sectors. Do the math, and you hit that 2TB ceiling pretty quickly. As more users run larger and more complex environments, this limitation becomes a blocker — not just for backups, but for restores, V2V migrations, and imports. On top of that, our current implementation has grown increasingly complex. We’re juggling multiple disk formats — various VMDKs, VHDS, and now QCOWs — with different logic paths for backups, restores, V2V, browser uploads, and more. ![](https://xen-orchestra.com/blog/content/images/2025/04/formats.png) Over time, this led to duplicated code, inconsistencies in block size handling (2MB for VHD, 64KB for CBT, and everything from 512B to 64KB for VMDKs), and an increasingly tangled web of logic. Adding support for QCOW disks would mean wiring yet another format into all those separate flows — in a non-typed codebase with hundreds of thousands of lines. Not ideal. So, we stepped back and decided to rethink the architecture from the ground up. ## How we’re doing it The new engine is being built with clarity and modularity in mind. We’ve introduced base classes to represent disks in a consistent way, regardless of the source or format. These are written in [TypeScript](https://www.typescriptlang.org/?ref=xen-orchestra.com), unit tested, and designed to be composable — a big step forward in maintainability. [![](https://xen-orchestra.com/blog/content/images/2025/04/ts-logo-256.png)](https://www.typescriptlang.org/?ref=xen-orchestra.com) We also moved a lot of low-level logic, like CBT and NBD handling, into their own dedicated classes. That makes the whole system easier to understand, test, and extend. Instead of relying on Node.js streams, we’ve adopted generators to process data in a linear, step-by-step fashion. This makes the code much easier to follow, and more importantly, helps us handle errors exactly where they happen — a key improvement for reliability. Right now, the new engine can read from a variety of sources — XAPI streams, NBD+CBT, backup repositories — and write either individual blocks or full VHD streams. It’s already a big leap forward, and you can explore the progress in these pull requests: [feat(generator): create a toolbox by fbeauchamp · Pull Request #8295 · vatesfr/xen-orchestraDescription Code written with the goal of being compatible with node 23.6+, no enum nor protected Review in order : throttle : throttle a generator to limit its speed. timeout : emit an error if a…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-4.svg)GitHubvatesfr![](https://opengraph.githubassets.com/4d715c9c5ac9b386ad9d8a08a2546cb646555255737920ad7f06b7c8b967d3a0/vatesfr/xen-orchestra/pull/8295)](https://github.com/vatesfr/xen-orchestra/pull/8295?ref=xen-orchestra.com) [feat(backups): use generator instead of streams for backup and replication by fbeauchamp · Pull Request #8432 · vatesfr/xen-orchestraTo the testers Not production ready please use it with the same settings as your current running job and report any error or discrepency. report to us th change in CPU / memory usage and backup sp…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-5.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/8432-1)](https://github.com/vatesfr/xen-orchestra/pull/8432?ref=xen-orchestra.com) ## What to expect and what to watch for Even with a wide test campaign and help from our amazing community, we know that we haven’t yet tested every combination or edge case. The most visible issues would be backup job errors. But more subtle bugs, like slight shifts in binary stream parsing, could break backups without being immediately obvious. There’s also the risk of mishandling disk chains — restoring the wrong data if the chain isn’t rebuilt correctly. That’s why it’s more important than ever to run health checks and test your restores regularly. If you do encounter any issues, please report them with as much detail as you can. It helps us tremendously. ## What’s next? As soon as XAPI exposes the needed endpoints for QCOW export/import (very soon!), we’ll unlock one of the biggest benefits of this new architecture: **incremental backup and replication support for disks over 2TB**. Beyond that, we’re planning to rewrite other parts of the system — like V2V, disk import, and VM import — to reuse this new code path. That will make our handling of large and diverse disks much simpler and more robust. And this is just the beginning. These changes set the stage for closing the gap with the biggest names in the backup space — with a clean, powerful, open-source engine at the core. ## Stay tuned We’re really excited about what this unlocks, and we’ll let you know as soon as it lands in a stable release. Until then, you can keep an eye on the GitHub progress or join the discussion on our community forum: [Our future backup code: test it!A big change is coming! As we prepare to add qcow2 support for backups, we took the opportunity to redesign major parts of the backup engine. The result? A m…![](https://xen-orchestra.com/blog/content/images/icon/512-5.png)XCP-ngolivierlambert![](https://xen-orchestra.com/blog/content/images/thumbnail/1-profileavatar-1620659303584-3.jpeg)](https://xcp-ng.org/forum/topic/10664/our-future-backup-code-test-it?ref=xen-orchestra.com) Thanks for your continued support, and for helping us build the future of open-source backup! ### Xen Orchestra 5.105 URL: https://xen-orchestra.com/blog/xen-orchestra-5-105/ Last updated: 2025-04-24T14:04:32.000Z Another month, another release—once again, we have a ton of updates to share with you across the XCP-ng project, the community, and Xen Orchestra itself. From deeper hardware integration and major UI improvements to important progress in the ARM architecture and LTS arenas, this month's release is is chock-full of new features and improvements with meaningful changes. Whether you're running production environments, managing backups, exploring DevOps tooling, or just keeping an eye on what’s next, there's something in here for you. Let's dive in. The detailed changelog for XO is [available on this link](https://github.com/vatesfr/xen-orchestra/blob/master/CHANGELOG.md?ref=xen-orchestra.com#51050-2025-03-31). ## 👨‍🚀 Project & Community Let’s start with the broader ecosystem. From advancements in XCP-ng virtualization on ARM architecture to details about our upcoming LTS release, and key milestones in the Xen Project, there’s been strong momentum this month across the community and upstream. Here’s a look at what’s been happening. ### A new Xen Community manager We’re **super excited** about this: after starting as a **Xen Evangelist**, **Cody** has now officially stepped into the role of **Xen Project Community Manager**! 🎉 Personally, I think he’s a great guy and an **ideal fit** for the job. Fun fact? He’s almost a neighbor! At **Vates**, we’re doubling down on our commitment to the Xen Project and have **big plans** to help accelerate its growth even more — so expect more exciting news on this front in **2025**! [Let’s Grow Xen Together!Xen is open, secure, and built for the future. As the new Community Manager, I’m focused on growing the Xen community, welcoming new contributors, and ensuring a thriving ecosystem. Let’s build the future of virtualization together!![](https://xen-orchestra.com/blog/content/images/icon/apple-touch-icon-2.png)Blog - Xen ProjectCody Zuschlag![](https://xen-orchestra.com/blog/content/images/thumbnail/photo-1617500756598-a0ee57567ac8)](https://xenproject.org/blog/lets-grow-xen-together/?ref=xen-orchestra.com) ### Xen on Ampere [Cody](https://xenproject.org/blog/lets-grow-xen-together/?ref=xen-orchestra.com), the new Community Manager of the Xen Project, recently shared an update on our ongoing work to port XCP-ng to the ARM architecture. With support from Ampere—who provided access to their high-performance hardware—we’ve been able to start testing and validating the platform. While it’s still early, we’re aiming to release a public preview before the end of the year, so stay tuned. [Xen on Ampere: A New Era for ARM in the Data CenterARM-based servers are redefining efficiency in data centers. The XCP-ng team is testing Xen on Ampere Altra CPUs, bringing high-density, power-efficient virtualization to ARM—and laying the groundwork for RISC-V. 🚀 Discover what’s next!![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-6.png)XCP-ng BlogCody Zuschlag![](https://xen-orchestra.com/blog/content/images/thumbnail/adrien-obMUS2F3MzM-unsplash.jpg)](https://xcp-ng.org/blog/2025/03/18/xen-on-ampere-new-era/?ref=xen-orchestra.com) ### Xen 4.20 is out Xen 4.20 has been officially released! While this version won’t impact XCP-ng in the immediate term, it’s an important milestone for the Xen Project itself. It also sets the foundation for the future: Xen 4.20 is expected to power our next major release, **XCP-ng 9.0**. [Xen 4.20 is outXen 4.20 is here! This release enhances security, performance, and hardware support—key for Vates VMS and XCP-ng as Xen 4.20 is set to power XCP-ng 9.0, bringing critical improvements.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-8.png)XCP-ng BlogMarc Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/chris-abney-qLW70Aoo8BE-unsplash.jpg)](https://xcp-ng.org/blog/2025/03/13/xen-4-20-is-out/?ref=xen-orchestra.com) ### The future of XCP-ng LTS Our current Long-Term Support (LTS) version, XCP-ng 8.2, will reach the end of its support lifecycle in June 2025. To ensure a smooth transition, we have introduced its successor: XCP-ng 8.3 LTS. Released last October, XCP-ng 8.3 will soon enter its LTS support phase as originally announced. To facilitate migration, we will ensure a three-month overlap between XCP-ng 8.2 LTS and 8.3 LTS, allowing users to upgrade without pressure. [The future of XCP-ng LTSXCP-ng 8.3 will be our next LTS release, bringing stability, long-term support, and key enhancements. Following its feature update phase, it will transition to an LTS model with a guaranteed overlap period of at least three months with XCP-ng 8.2.1.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-7.png)XCP-ng BlogMarc Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/aron-visuals-BXOXnQ26B7o-unsplash.jpg)](https://xcp-ng.org/blog/2025/03/14/the-future-of-xcp-ng-lts/?ref=xen-orchestra.com) ### XCP-ng March Updates March also brought fresh security and maintenance updates for both **XCP-ng 8.2** and **XCP-ng 8.3**. These patches are part of our ongoing effort to deliver reliable, consistent updates—now almost on a monthly basis—to keep your infrastructure secure and up to date. [March 2025 Security and Maintenance Update for XCP-ng 8.2 LTSNew bugfix, and enhancement updates are available for XCP-ng 8.2 LTS.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-9.png)XCP-ng BlogGaël Duperrey![](https://xen-orchestra.com/blog/content/images/thumbnail/pexels-pixabay-414181-02.jpg)](https://xcp-ng.org/blog/2025/03/12/march-2025-security-and-maintenance-update-for-xcp-ng-8-2-lts/?ref=xen-orchestra.com) [March 2025 Maintenance Update for XCP-ng 8.3New bugfix, and enhancement updates are available for XCP-ng 8.3.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-10.png)XCP-ng BlogGaël Duperrey![](https://xen-orchestra.com/blog/content/images/thumbnail/pexels-pixabay-36478-02.jpg)](https://xcp-ng.org/blog/2025/03/12/march-2025-maintenance-update-for-xcp-ng-8-3/?ref=xen-orchestra.com) ### Thoughts about IT monoculture In the wake of the VMware situation, I penned a personal and timely blog post calling for greater digital biodiversity. It's a reminder that putting all your eggs in one vendor’s basket comes with real risks—and why open, diverse ecosystems matter more than ever. [Please stop planting only cornA blog post in defense of digital biodiversity![](https://xen-orchestra.com/blog/content/images/icon/faviconV2-1)VirtualizeOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/cornfield-902877_1280.jpg)](https://virtualize.sh/blog/please-stop-planting-only-corn/?ref=xen-orchestra.com) ### Coder+Terraform We also want to highlight a great contribution from the community: a blog post by Millefeuille, who shared how they created a template to use [Coder](https://coder.com/?ref=xen-orchestra.com) with XCP-ng and Xen Orchestra. It's a great example of how the ecosystem keeps growing through shared knowledge and real-world use cases. [Coder workspaces with XCP-ng and XOA - Millefeuille’s blogHow and why I created a template to use coder.com with XCP-ng and XOA![](https://xen-orchestra.com/blog/content/images/icon/apple-touch-icon-1.png)Millefeuille's blog![](https://xen-orchestra.com/blog/content/images/thumbnail/card.png)](https://blog.millefeuille42.fr/blog/coder-xcp-ng-xoa/?ref=xen-orchestra.com) ### Vates is joining the Eclipse Foundation As our involvement in the Xen Project within the Linux Foundation continues to grow, we’re also expanding our commitment to open-source collaboration by joining the Eclipse Foundation. This marks another step forward in reinforcing our long-term vision: building reliable, transparent, and community-driven infrastructure software through active participation in key open-source ecosystems. [Vates joins the Eclipse Foundation to strengthen open-source innovationVates deepens its open-source commitment: alongside our growing involvement in the Linux Foundation and Xen Project, we’re now joining the Eclipse Foundation to further drive collaborative innovation in virtualization and infrastructure solutions.![](https://xen-orchestra.com/blog/content/images/icon/logo64-7.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/jongsun-lee-F-pSZO_jeE8-unsplash.jpg)](https://vates.tech/blog/vates-joins-the-eclipse-foundation-to-strengthen-open-source-innovation/?ref=xen-orchestra.com) ### Our stack inside the Italian Cyber Command Our collaboration with the Italian Cyber Command continues to move forward. What began as a strategic proof of concept has now been extended, reinforcing the role of **Vates VMS** in strengthening European technological sovereignty. [Strengthening European technological sovereignty: Vates VMS advances with the Italian CybercommandThe current geopolitical context is driving European institutions to reduce their dependence on foreign technologies. In this landscape, the Italian Cor Difesa has chosen Vates VMS for a strategic POC, now extended after a year of success.![](https://xen-orchestra.com/blog/content/images/icon/logo64-6.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/mauricio-artieda-h7WxFNO3MNY-unsplash.jpg)](https://vates.tech/blog/strengthening-european-technological-sovereignty-vates-vms-advances-with-the-italian-cybercommand/?ref=xen-orchestra.com) **Phew. And now we can talk about our monthly release!** --- Many many many things on the menu. Let's discover all of that together! ## 💾 Backup While no major production features dropped this month, the backup team has been hard at work behind the scenes — preparing for the “post-2 TiB” era in XCP-ng and laying the groundwork for many improvements to come. ### A new generic code to prepare the future A big change is coming! As we prepare to add qcow2 support for backups, we took the opportunity to redesign major parts of the backup engine. The result? A much more flexible and abstracted system that can better handle various scenarios like V2V, qcow2, VHD, and more. We're also moving from traditional streams to Node generators, adding backup throttling, and laying the groundwork for future improvements. It's not production-ready yet, but that’s where you come in! If you're working from sources, you can test it by switching to the branch: `feat_generator_backups`. Bug reports and feedback are more than welcome! To provide some feedback, we created a dedicated thread in our forums: [Our future backup code: test it!A big change is coming! As we prepare to add qcow2 support for backups, we took the opportunity to redesign major parts of the backup engine. The result? A m…![](https://xen-orchestra.com/blog/content/images/icon/512-4.png)XCP-ngolivierlambert![](https://xen-orchestra.com/blog/content/images/thumbnail/1-profileavatar-1620659303584-2.jpeg)](https://xcp-ng.org/forum/topic/10664/our-future-backup-code-test-it?ref=xen-orchestra.com) ### Improved replications Replication just got a lot more robust. The new logic can handle more variations in the source VM: **add or remove disks**, change their order, it will **just work**. We’ve fixed several edge cases that previously caused issues, making replication much more reliable across the board. ### Better BackBlaze compatibility Our S3 backup system is built on the official AWS SDK for Node.js — which is why **AWS S3** has always been our primary supported target. However, recent updates to the SDK introduced additional headers that **broke compatibility with some S3-compatible providers**, such as **Backblaze B2**. (To be fair, not all providers were affected — some simply ignored the extra headers.) Backblaze addressed the issue [in their documentation](https://www.backblaze.com/docs/cloud-storage-use-the-aws-sdk-for-javascript-v3-with-backblaze-b2?ref=xen-orchestra.com). ❤️ ****Special thanks to** [****Jonas**](https://github.com/cloudrootab?ref=xen-orchestra.com) for identifying the root cause — his insight made the fix quick and easy! ## 🥝 Core UI A quick reminder: **Core UI** is our brand-new UI foundation, powering both **XO Lite** and the upcoming **XO 6**. ### New progress bar component We’ve rolled out the `CircleProgressBar` component to the interface. It’s a customizable, circular progress bar that makes tracking progress smoother and more engaging. You can use it for things like loading states or tracking tasks such as migrations and backups. It’s easy to drop into your interface and adds a cleaner, more dynamic way to show progress. ![](https://xen-orchestra.com/blog/content/images/2025/03/419353794-7809f334-65f0-4a6f-856f-b8811a562057.png) ### Improved pagination mechanism We’ve enhanced the pagination system. This improvement is fully transparent, meaning there are no visible changes, but the system now loads more efficiently. It makes navigating large sets of data faster and smoother, so you can jump between pages without the annoying delays. The page number is now available directly as a query string in the URL. ## 🔭 XO Lite By the way, all of our XO Lite releases are synced with the monthly XO release! ### VM creation XO 6 and XO Lite now make creating virtual machines a breeze. You just choose a template and configure the basics. This release is ideal for users who need a simple method of managing VMs. ![](https://xen-orchestra.com/blog/content/images/2025/03/422711639-d412057b-4fd9-4f8d-ba00-a9a789134beb-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/03/422711513-307092ed-6772-4f61-88f2-bc5ca3a75584-1.png) ### VM network tab and VIFs table We've introduced a table list for VIFs (Virtual Interfaces) in the VM **Network** tab. You can now comfortably view and manage the network interfaces attached to your VMs. It displays all the vital information, such as configuration and status, directly within the tab. There is a side panel as well for quick access to additional information. ![](https://xen-orchestra.com/blog/content/images/2025/03/425004123-fc1c8e03-e817-419b-ac6a-88003b0eea42-2-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/03/425004123-fc1c8e03-e817-419b-ac6a-88003b0eea42-3.png) ## 🛰️ XO 6 You can already enjoy XO 6 by adding `/v6` at the end of your XOA URL. As we already seen VM creation working for both XO 6 and XO Lite, we'll talk about new view in XO 6 in here. ### Pool network view side panel We've added a side panel to the pool network view. This gives you a more streamlined experience for your network settings management and easy access to important information. Now, when you look at network configurations of a pool, you're given more information upfront, and you can make changes without having to bounce back and forth between pages. ![](https://xen-orchestra.com/blog/content/images/2025/03/408603984-dc946765-c76e-4b5b-93d0-24869e42ddaa-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/03/408604125-7f1ea882-e084-4061-af63-f363bc9fd72c-1.png) ### Host network view side panel We've included a side panel within the host network view. As in the view for pool networks, this panel allows you to quickly absorb essential network information without hassle. It's a small update, but it makes it so much easier to work with host networks and gain an overview. ![](https://xen-orchestra.com/blog/content/images/2025/03/417043188-1ac35f28-2db6-4fb2-845c-5d594fd5faa9-1-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/03/417043188-1ac35f28-2db6-4fb2-845c-5d594fd5faa9-2.png) ### Virtual interface side panel It's now easier to examine a VM's network information with a new side panel in the **Network** tab. Just click on a network interface to see details like MAC address, connected network, and traffic statistics—without switching out of the main view. ![](https://xen-orchestra.com/blog/content/images/2025/03/424998106-6e14f620-1dfd-4343-95d2-08a883d14d38-2.png) ![](https://xen-orchestra.com/blog/content/images/2025/03/425004123-fc1c8e03-e817-419b-ac6a-88003b0eea42-1-1.png) ### ### Host dashboard We've included a host dashboard that provides you with a clear and easy-to-grasp view of your host health and performance. You can easily view important statistics such as CPU, memory, and storage, so it's even easier to keep an eye on your host's status. ![](https://xen-orchestra.com/blog/content/images/2025/03/425351744-62c4e92c-8c33-4a69-b78b-2d95d4f86231--1-.png) ![](https://xen-orchestra.com/blog/content/images/2025/03/424925638-bed44282-a685-4de1-8cd8-65ad06b98ce8-1.png) ## 💠 XOSTOR XOSTOR continues to evolve as our HCI (Hyperconverged Infrastructure) solution, becoming more stable, and now also easier to use and update! ### RPU support with XOSTOR Rolling pool updates (RPU) now manage pools that use XOSTOR. If there is no Linstor Storage Repository (SR), the RPU continues as usual. If there is a Linstor SR, the update process includes extra steps to make it compatible before performing the standard rolling update. This update keeps your XOSTOR pools running smoothly and in sync throughout the update process. For a better description of the workings of rolling pool updates, see the [RPU](https://docs.xcp-ng.org/management/updates/?ref=xen-orchestra.com#rolling-pool-update-rpu) and [XOSTOR](https://docs.xcp-ng.org/xostor/?ref=xen-orchestra.com) chapters of the XCP-ng documentation. ## 📡 REST API We now have two driving forces behind the evolution of our REST API: the upcoming XO 6 and a growing number of users requesting more features. And guess what? We’ve delivered — with new capabilities already available and more on the way! ### Migrating endpoints to Swagger We've done some solid work in simplifying and making our REST API more logical, by moving several `get` and `getId` endpoints, along with some actions, to Swagger. This translates to more consistency, easier organization, and a smoother overall experience. A lot of this update involved getting our API to adhere to a more consistent structure and fully utilizing the standardized format of Swagger/Open API. We've updated a number of controllers to accommodate this new format, including: - Servers (`getServers` and `getServer`) - VM templates (`getVmTemplates` and `getVmTemplate`) - VM snapshots (`getVmSnapshots` and `getVmSnapshot`) - VM controllers (`getVmControllers` and `getVmController`) - VM operations (`vm.start`) - VIFs - VDIs - VDI snapshots - VBDs - SRs - Hosts (`getHosts`, `getHost`, and `getHostStats`) These endpoints are now properly organized in Swagger, which improves integration with OpenAPI-compatible tools as well as making API interaction more intuitive. On top of relocating the endpoints, we also changed type definitions to better reflect what XAPI actually returns. This prevents inconsistencies, particularly for VM templates, snapshots, and controllers. We also added explicit controllers for VM templates and snapshots to retain more of a logical structure. This opens the door for a more consistent API experience with better discoverability and easier maintainability in the future. ![](https://xen-orchestra.com/blog/content/images/2025/03/421347007-79ec797f-ff0a-4ddc-b1c9-b8013b7c06cd-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/03/vdis-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/03/vbds-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/03/srs-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/03/hosts-1.png) ## ☸️ DevOps Tools There are plenty of exciting things in the pipeline — and you can expect even more updates next month. Stay tuned! ### Pulumi provider published The [Xen Orchestra](https://team.vates.fr/vates/channels/town-square?ref=xen-orchestra.com) provider for [#Pulumi](https://team.vates.fr/vates/channels/town-square?ref=xen-orchestra.com) is now live on the Pulumi Registry (alongside AWS, Azure, and others!) Describe and deploy your infrastructure on Xen Orchestra using Python, TypeScript, Go, C#, or even YAML. [Xen OrchestraProvides an overview of the Xen Orchestra Provider for Pulumi.![](https://xen-orchestra.com/blog/content/images/icon/favicon-3.ico)pulumi![](https://xen-orchestra.com/blog/content/images/thumbnail/og-default-1.png)](https://www.pulumi.com/registry/packages/xenorchestra/?ref=xen-orchestra.com) ### A brand new PowerShell module The PowerShell module for Xen Orchestra allows administrators to interact with their XO infrastructure via PowerShell. It provides [cmdlets](https://learn.microsoft.com/en-us/powershell/scripting/developer/cmdlet/cmdlet-overview?view=powershell-7.5&ref=xen-orchestra.com) to manage VMs, VDIs, snapshots, and servers, including features for exporting/importing VDIs, creating snapshots, starting/stopping VMs, and monitoring tasks. ![](https://xen-orchestra.com/blog/content/images/2025/03/Screenshot-2025-03-26-at-17.24.58.png) This first alpha version covers essential operations, enabling automation of common workflows directly from PowerShell scripts. You can find the repository here: [vatesfr/xo-powershellContribute to vatesfr/xo-powershell development by creating an account on GitHub.![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-2.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/xo-powershell)](https://github.com/vatesfr/xo-powershell?ref=xen-orchestra.com) ### Stability upgrade for XO Terraform Provider The **Terraform Provider for Xen Orchestra** v0.31.1 brings significant improvements in reliability and stability. We have reimplemented the core client to use our own `xenorchestra-go-sdk`, for enhanced maintainability and consistency of behavior. This version fixes critical issues, such as VM creation with blocked operations, and resolves a bug where cloud config VDIs were being treated incorrectly for non-running VMs. We've also improved protection against unintended VM deletion, security dependencies, and enhanced documentation with better examples. These enhancements make the provider better for production use while maintaining backward compatibility. ![](https://xen-orchestra.com/blog/content/images/2025/03/0_3i0MOCi2wHX607Jp.png) ## 🐦 VMware to Vates (V2V) Our continued work to make VMware migration to Vates easier than ever continues to pay off. From tooling to automation, we're doing everything we can to eliminate friction and enable users to migrate with ease. ### Better import management We've solved an issue where an Assertion error was raised while importing delta snapshots from ESXi versions prior to 7.5\. The problem was related to disk sizes not being correctly aligned on import. Xen Orchestra is now more tolerant of such cases, and imports are less likely to fail. This results in more reliable V2V migrations, particularly with older ESXi setups. ## 🛡️ Air gap features As our customer list expands to more strategic and security-conscious organizations, we're further developing our air gap functionality. ### Fully-offline XOA updates We just reached the first beta milestone of a new feature: fully-offline updates of Xen Orchestra Appliance (XOA) using a simple script. A massive step, paving the way for a future where even support license management can be done fully offline. ## **🆕** Misc Even with all these new features, we haven’t forgotten the existing UI — it continues to get lots of polish and improvements. Yep, this release is a big one. And we’re just getting started! ### Health view: display snapshots older than 30 days Snapshots older than 30 days are now displayed in the health view (navigate to **Dashboard → Health**), for a better overview of your storage usage. This feature was created in response to user input. It especially targets users who yearned for an easier method of handling old snapshots that might be occupying space unnecessarily. Now you can easily find and deal with these snapshots in order to keep your system structured and your storage even more efficient, without performing lengthy searches: ![](https://xen-orchestra.com/blog/content/images/2025/03/image.png) ### Self-service users can now attach disks to their VMs Users were able to detach disks from their VMs but not attach them before—an annoying restriction. That's changed! If your users have suitable ACLs on an SR, they'll now be able to attach VDIs running on that SR to their VMs. While we normally recommend keeping self-service and ACLs separate, this can be a handy workaround if you are dedicating an SR to your users and want to give them more freedom while staying within the self-service system. ![](https://xen-orchestra.com/blog/content/images/2025/03/Capture_2025-03-26_09_19_31.png) ### New XAPI platform flag for nested virtualization Starting with XCP-ng 8.3, Xen Orchestra now uses `platform:nested-virt` instead of `platform:exp-nested-hvm` for nested virtualization. This update follows a XAPI fix and ensures everything works smoothly in the future. You'll find the setting on **Advanced** page of the VM. If you're running XCP-ng 8.3 or later, XO will automatically read and write the new flag. 💡 This doesn't mean nested is now fully supported. You are basically back at the level of "it works" from XCP-ng 8.2\. There's still a lot of work in that area, but be sure this is planned in our XCP-ng team backlog! ### NetBox v4.2.x now supported Xen Orchestra is now completely compatible with NetBox v4.2.x, so you can upgrade without any issues. This release offers better compatibility, so NetBox is easier to integrate into your workflow without unexpected problems. If you've been waiting on an upgrade, you can now do so with confidence. ### Performance notifications are now less repetitive We've fixed a bug in the `perf-alert` plugin that was causing it to send duplicate performance alert messages for the same problem even if there was no new event. This is a user feedback-driven feature where some environments were getting too many notifications—namely database-intensive VMs that will use most of their allocated memory by design. With this fix, alerts will be fired only when there's an update that's pertinent, reducing noise and making alerts more actionable. ### ACL setup when creating VMs Creating VMs is now more convenient for administrators, with the option to assign Access Control Lists (ACLs) directly within the **Advanced** tab. This allows for easier setting of user or group permissions on new VMs while creating them. ![](https://xen-orchestra.com/blog/content/images/2025/03/419494616-d6c74186-3a11-45bf-81ce-21eb7cce1f02.png) ![](https://xen-orchestra.com/blog/content/images/2025/03/419494620-05d0a76c-a7d9-42e0-aeff-eae8b6937ca0.png) ### Improved translations XO 6 and XO Lite translations are improved. More accurate and improved translations enable easier, intuitive use of the interface with less misunderstanding, especially for non-English users. Languages which have been updated this month (meaning new words translated or improved): Swedish, Spanish, Czech, Persian and German. Russian and Ukrainian have been added but not finished yet. ![](https://xen-orchestra.com/blog/content/images/2025/03/Capture-d--cran-2025-03-26-084233.png) If you'd like to help translate Xen Orchestra or fix existing translations, feel free to contribute [here](https://translate.vates.tech/?ref=xen-orchestra.com). Thank you to the community for the contributions! The list of contributors can be found in here: [feat(web-stack/i18n): update Xen Orchestra 6 by nathanael-h · Pull Request #8396 · vatesfr/xen-orchestraTranslations update from Weblate for Xen Orchestra/Xen Orchestra 6\. Current translation status: Credits: Czech Pavel Borecki (38) Romain THOMANN (9) German Romain THOMANN (238) Ivan Skachko…![](https://xen-orchestra.com/blog/content/images/icon/pinned-octocat-093da3e6fa40-3.svg)GitHubvatesfr![](https://xen-orchestra.com/blog/content/images/thumbnail/8396)](https://github.com/vatesfr/xen-orchestra/pull/8396?ref=xen-orchestra.com) And thanks to Weblate for this fantastic tool! ![](http://translate.vates.tech/widget/xen-orchestra/multi-auto.svg) If you want to discover more about Weblate, [take a look on their website](https://weblate.org/en/?ref=xen-orchestra.com). ### Xen Orchestra 5.104 URL: https://xen-orchestra.com/blog/xen-orchestra-5-104/ Last updated: 2025-02-28T13:55:20.000Z This month at Vates, we’re bringing you a wave of updates across the board! Our virtualization stack is now validated for Red Hat Enterprise Linux 9, and we’ve announced a strategic partnership with VyOS to enhance networking capabilities in Vates VMS. We’re also fine-tuning XOA on AWS, expanding REST API functionalities, and rolling out new DevOps tools like a Pulumi provider and a Go SDK for Xen Orchestra. Plus, our Xen Winter Meetup recap is here, and we’re gearing up for CloudFest 2025! ## 👨‍🚀 Project & Community This month, Vates continues to expand its ecosystem and strengthen its enterprise-grade solutions while preparing for upcoming key events. ### Vates Virtualization Management Stack validated for Red Hat Enterprise Linux 9 ![](https://xen-orchestra.com/blog/content/images/2025/02/redhat-vates-logo.png) Vates Virtualization Management Stack (VMS) is now officially recognized as a **partner-validated product** for Red Hat Enterprise Linux 9 as a guest operating system. This validation, now listed in the [Red Hat Ecosystem Catalog](https://catalog.redhat.com/hardware/system/detail/260327?ref=vates.tech), marks a key milestone in our commitment to delivering **enterprise-grade, reliable virtualization solutions**. [Vates virtualization management stack validated for Red Hat Enterprise Linux 9 guest OSVates Virtualization Management Stack the solution that powers XCP-ng and Xen Orchestra, is now recognized as a partner validated product for Red Hat Enterprise Linux 9 as a guest operating system.![](https://xen-orchestra.com/blog/content/images/icon/logo64-4.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/joshua-sortino-LqKhnDzSF-8-unsplash.jpg)](https://vates.tech/blog/vates-virtualization-management-stack-validated-for-red-hat-enterprise-linux-9-guest-os/?ref=xen-orchestra.com) ### CloudFest 2025 ![](https://xen-orchestra.com/blog/content/images/2025/02/cloudfest-logo.png) We’re heading to [**CloudFest 2025**](https://vates.tech/blog/vates-at-cloudfest-2025-the-return-2/?ref=xen-orchestra.com), the premier event for the cloud and internet infrastructure industry! Once again, you’ll find us at the **iconic Europa Park in Rust, Germany, from March 17 to 20**. Join us there to discuss virtualization, cloud solutions, and the future of open infrastructure. ### Xen Winter Meetup recap In late January, we hosted our first **Xen Winter Meetup** in Grenoble, our home city nestled in the French Alps. It was an incredible experience, bringing together key members of the **Xen Project ecosystem** for in-depth discussions, technical presentations, and community networking. With so much positive feedback, we’re already brainstorming ideas for the next edition! If you missed it, don’t worry—we’ve put together a full **recap**, covering the event’s highlights, discussions, and plenty of great photos. [Xen Winter Meetup 2025: a recapThe Xen Winter Meetup 2025 brought together developers, researchers, and industry experts for two days of deep technical discussions, hands-on design sessions, and plenty of cheese.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-5.png)XCP-ng BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/thumbnail/xenwinter.jpg)](https://xcp-ng.org/blog/2025/02/11/xen-winter-meetup-2025-a-recap/?ref=xen-orchestra.com) ### Vates & VyOS partnership ![](https://xen-orchestra.com/blog/content/images/2025/02/vyos-logo.png) We’re excited to announce a **strategic partnership** with **VyOS Networks**, a leader in open-source network operating systems. Together, we’re working to develop an advanced network solution for Vates VMS, integrating **VyOS’s network expertise with our virtualization technology**. This collaboration will bring **cutting-edge networking capabilities**—similar to VMware NSX—directly into the **Vates stack**, offering our customers a seamless, enterprise-ready alternative. [Vates and VyOS Networks announce strategic partnership to develop advanced network solutions for Vates VMSVates and VyOS Networks partner to bring advanced networking to Vates VMS, offering a secure, scalable alternative to VMware NSX by combining virtualization and network expertise.![](https://xen-orchestra.com/blog/content/images/icon/logo64-3.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/pietro-jeng-n6B49lTx7NM-unsplash.jpg)](https://vates.tech/blog/vates-and-vyos-strategic-partnership/?ref=xen-orchestra.com) ### 2025 Partner Program Vates is rolling out its **2025 Partner Program**, designed to provide **stronger benefits, tailored incentives, and new growth opportunities** for MSPs, Resellers, Cloud Service Providers, and Order Takers. With **250+ partners across 60 countries** our Partners network is growing more than ever. [The Vates 2025 Partner Program: Tailored to Your Needs, Designed for SuccessWe’re excited to introduce our 2025 Partner Program — designed to equip a diverse range of partners with the resources and incentives needed to accelerate growth, enhance profitability, and deliver exceptional value to customers.![](https://xen-orchestra.com/blog/content/images/icon/logo64-5.png)Vates BlogRăzvan Roșca![](https://xen-orchestra.com/blog/content/images/thumbnail/2025-partner-program.webp)](https://vates.tech/blog/2025-partner-program/?ref=xen-orchestra.com) ### XCP-ng Windows PV Tools released with Rust-based Xen guest agent XCP-ng has released version 9.0.9030 of its Windows PV drivers, introducing significant improvements and new features. This update brings a Rust-based Xen Guest Agent for enhanced resource and IP address reporting, along with the XenBootFix tool designed to repair boot issues in VMs affected by various Xen drivers. While this release includes multiple stability fixes and improved installation safety checks, it is intended for testing purposes only and requires enabling testsigning mode. [XCP-ng Windows PV tools 9.0.9030 Testsign released: now with Rust-based Xen Guest AgentHello all, Version 9.0.9030 of the new Windows PV drivers has been released. This release brings multiple driver stability fixes, a new Rust-based Xen Guest…![](https://xen-orchestra.com/blog/content/images/icon/512-2.png)XCP-ngdinhngtu![](https://xen-orchestra.com/blog/content/images/thumbnail/site-logo.png)](https://xcp-ng.org/forum/topic/10550/xcp-ng-windows-pv-tools-9.0.9030-testsign-released-now-with-rust-based-xen-guest-agent?ref=xen-orchestra.com) ### Breaking the 2TiB limitation - Alpha 2 We're releasing the second alpha phase of our improvements to remove the 2TiB limitation. This update fixes corruption issues during live coalescing of Qcow2, reintroduces LVMSR support for Qcow2, and adds compatibility with VHD. It also enhances storage performance and integrates a new coalescing approach for Qcow2 in blktap. As this is still an alpha, we welcome your feedback. Full details is available here: [Dedicated thread: removing the 2TiB limit with qcow2 volumesHello, We are announcing our second alpha. This new version resolve the problem of corruption that appeared when coalescing QCOW2 live but also re-introduce…![](https://xen-orchestra.com/blog/content/images/icon/512-3.png)XCP-ngravenet![](https://xen-orchestra.com/blog/content/images/thumbnail/2695-profileavatar.jpeg)](https://xcp-ng.org/forum/topic/10308/dedicated-thread-removing-the-2tib-limit-with-qcow2-volumes/19?ref=xen-orchestra.com) --- February brings new enhancements across the Vates ecosystem, from UI improvements to API upgrades and expanded cloud integration. Let’s dive into what’s new in this month’s release! ## 🥝 Core UI CoreUI is our new component framework and design system, built to power both XO Lite and XO 6\. ### Improved translation system We’ve simplified the translation system by merging the separate translation files from XO 6, XO Lite, and Web Core into a single location. This makes Weblate much easier to use for managing and updating translations. If you’d like to help translate Xen Orchestra or improve existing translations, feel free to contribute [here](https://translate.vates.tech/?ref=xen-orchestra.com)! ## 🔭 XO Lite XO Lite receives monthly updates, and this month, we focused on improving the network panel. Your XO Lite instance will automatically update to the latest version. ### Show PIF information in the side panel You can now see detailed information about physical interface (PIF) devices directly in the side panel. This improvement provides quick access to essential network interface details. ![](https://xen-orchestra.com/blog/content/images/2025/02/pif-info.png) ## 🪐 XOA We're enhancing Xen Orchestra Appliance (XOA) to be more versatile and adaptable, supporting diverse use cases like edge deployments and hybrid cloud infrastructure. ### Try XOA on AWS As we mentioned last month, we’ve been working on dedicated XOA instances for AWS, designed specifically for users managing hybrid cloud environments. This is part of our efforts to make it easier for you to handle both on-premises and cloud infrastructures together. This month, we’ve been focusing on stabilizing XOA on AWS EC2 and fine-tuning the image build process. We now have a beta XOA image available for you to test. If you're interested, just [reach out to us](https://vates.tech/contact/?ref=xen-orchestra.com), and we’ll help you get set up. More updates are coming as we continue to refine things! ## 🖥️ XO CLI XO CLI offers a powerful way to manage Xen Orchestra from the command line. This month, we’ve documented file restoration from VHD backups, making large recoveries easier without relying on the UI. ### File restoration from VHD backups—Now documented We’ve just added step-by-step instructions on how to restore files from VHD backups using the `fuse-vhd` CLI. If you’re dealing withlarge files or folders that can’t be restored through the UI (because it fails on big recoveries), this CLI method is the way to go. You’ll find everything you need to get started in the [fuse-vhd README](https://github.com/vatesfr/xen-orchestra/blob/master/%40vates/fuse-vhd/README.md?ref=xen-orchestra.com#restore-a-file-from-a-vhd-using-fuse-vhd-cli). ## 📡 REST API We've been making significant improvements to the REST API, focusing on better automation, enhanced integration capabilities, and a more structured approach to development. From expanded user and group management to a gradual migration to Swagger for improved consistency, these updates lay the foundation for a more powerful and developer-friendly API. ### Manage users and groups The REST API now gives you full control over user and group management. You can create and delete users and groups programmatically, making it easier to automate access control, integrate with external identity management systems, or sync permissions with your organization's policies. This means you no longer have to rely on the web UI for these tasks—everything can be handled through API calls, which is a real time-saver, especially in larger environments. However, please note that the new endpoints for managing users and groups are not yet available through Swagger (OpenAPI). They’ve been added to the REST API, but the documentation for these endpoints is still being worked on. If you want to get started, here are some example requests: ``` // Create group POST /rest/v0/groups request body: {name: string} // Update group name PATCH rest/v0/groups/:id request body : { name?: string } // Add user in a group PUT rest/v0/groups/:id/users/:id // Remove user from a group DELETE rest/v0/groups/:id/users/:id // Delete group DELETE /rest/v0/groups/ // Create user POST rest/v0/users request body : { email: string, password: string, permission?: string } // Delete user DELETE rest/v0/users/:id // Update user information PATCH rest/v0/users/:id request body : { name?: string, password?: string, permission?: string, preferences?: object } ``` ### ### Swagger and OpenAPI Integration: A big step forward We've made a major move by integrating Swagger (OpenAPI) into our REST API. This is the foundation for a full rewrite using TypeScript and the TSOA framework, and it’s not just about improving documentation—this is a complete overhaul aimed at making the API more reliable, consistent, and ready for future development. **Why this matters** This integration brings major improvements to the way the API is built and maintained. By adopting Swagger, we now have endpoints that follow a clear, predictable structure, making it easier for developers to work with them—especially those building integrations. The Swagger docs are generated directly from the code, ensuring they’re always accurate and up to date, so you’ll never run into outdated references again. And the best part? You can explore and test the endpoints straight from the Swagger UI, which makes things much more interactive and developer-friendly. On top of that, with a more structured API and the power of TypeScript’s strong typing, we can minimize bugs and speed up the development of new features down the road. Integrating with Xen Orchestra has also become smoother, as Swagger now supports automatic client library generation, making third-party integrations much easier. **Taking it one step at a time** We’re not rushing the migration. A full API rewrite takes time, and we want to ensure everything works perfectly for you along the way. That’s why we’re migrating endpoints gradually. The existing REST API is still up and running as usual, and we're doing everything to keep it that way. You can continue using the same endpoints, parameters, and return values you’re already familiar with, so there won’t be any surprises. Both versions of the API are now accessible at `/rest/v0`, but here's the twist: only the endpoints that have been migrated to the new Swagger setup will show up in the documentation at `/rest/v0/docs`. As we continue migrating, the documentation will grow and evolve, with the plan being that once everything’s transitioned, `/rest/v0` will automatically redirect to the docs. **Looking ahead** This rewrite isn't just about cleaning things up—it's about laying the groundwork for faster, more flexible development. In the future, this will allow us to roll out new features quicker, like better user management, real-time data updates, and advanced API capabilities. We’re only just getting started, and while it’ll take time, we’re confident this is the right move toward a more developer-friendly Xen Orchestra API. Big thanks to everyone at Vates who helped bring this to life. Your contributions make this all possible! ![](https://xen-orchestra.com/blog/content/images/2025/02/swagger.png) ### Migrate VM Retrieval Endpoints to Swagger We’ve started moving VM retrieval endpoints (`get` and `getId`) over to the new Swagger-based API. These endpoints are now fully documented and easier to use. Everything follows the OpenAPI spec, making the API clearer and more predictable. This is part of our ongoing effort to modernize the REST API, and it’s just the beginning. As we continue migrating more endpoints, the API will become even more structured, easier to maintain, and faster to develop. ### Get host and VM metrics Looking for real-time performance insights on your hosts and VMs? The REST API now provides direct access to RRD (Round-Robin Database) metrics, allowing you to retrieve key stats like CPU usage, memory consumption, and network activity—no need to rely on the web UI. This update makes it easier to integrate Xen Orchestra with your monitoring tools or build custom dashboards, giving you greater control over how you track and analyze your infrastructure’s performance. You can access the endpoints here: - **VM stats:** `/rest/v0/vms//stats` - **Host stats:** `/rest/v0/hosts//stats` ## ☸️ DevOps Tools With our dedicated DevOps team, we’re expanding automation capabilities across the Vates ecosystem. This month, we’re introducing official support for the Pulumi provider and the first release of the Xen Orchestra Go SDK, making infrastructure management even more seamless. ### New Pulumi provider We now commit to support the Pulumi Provider for Xen Orchestra! Pulumi provider was originally created by DESY (Deutsches Elektronen-Synchrotron) and is now supported by the Vates DevOps team. ![](https://xen-orchestra.com/blog/content/images/2025/02/render1740736588174.gif) With this provider, you can manage your Xen Orchestra infrastructure as code using Pulumi. It supports Node.js (JavaScript and TypeScript), Python, and Go, and SDKs are available for each language: - [NodeJS](https://www.npmjs.com/package/@vates/pulumi-xenorchestra?ref=xen-orchestra.com) - [Python](https://pypi.org/project/pulumi-xenorchestra/?ref=xen-orchestra.com) - [Go](https://pkg.go.dev/github.com/vatesfr/pulumi-xenorchestra/sdk/go/xenorchestra?ref=xen-orchestra.com) This is a great example of open-source collaboration in action. Thanks to the community’s work, automating and scaling your Xen Orchestra setup is now smoother than ever. ### Introducing the Go Xen Orchestra API client The[first release](https://github.com/vatesfr/xenorchestra-go-sdk/releases/tag/v1.0.0?ref=xen-orchestra.com)of the Xen Orchestra Go SDK is here! This new Golang client lets you interact with the Xen Orchestra JSON-RPC API, making it easier to integrate Xen Orchestra into your Go projects. By the way, this SDK is used by the Terraform provider, one of the most popular tools for Infrastructure as code! Contributions are welcome, so feel free to dive in and contribute! ## **🆕** Misc This month’s miscellaneous updates bring several quality-of-life improvements to Xen Orchestra. While much of our focus remains on XO Lite, XO 6, and API enhancements, we’ve also streamlined VM disk cloning, expanded self-service capabilities, improved Smart Reboot, and updated translations—small but impactful changes to enhance your experience. ### Streamlined disk cloning during VM creation When creating a VM, Xen Orchestra now speeds up the disk cloning process by eliminating unnecessary steps. During cloning, the system checks for existing virtual disk images (VDIs) and selects a storage repository (SR) to copy from, giving priority to either the first VDI or the largest disk. If it finds a valid SR, the process switches to a copy operation instead of a clone, even if the clone flag is set. This prevents duplicating disks that are already on the selected SR. In addition, the system now only uses `moveVdi`for disks that are not on the SR being used for cloning, making the process more efficient and reducing overhead during VM creation. ### Self-service users can now attach disks to their VMs Until now, self-service users could detach disks from their VMs but couldn’t attach them—a frustrating limitation. That's fixed! If your users have the proper ACLs on an SR, they'll be able to see and attach VDIs hosted on that SR to their VMs. While we usually suggest keeping self-service and ACLs separate, this can be a handy workaround if you’re dedicating an SR to your users and want to give them more freedom while staying within the self-service system. ### Smart Reboot Enhancements We've made Smart Reboot more robust by adding checks to ensure VMs can be suspended before proceeding. If a VM can't be suspended—perhaps due to PCI passthrough devices—you'll get a heads-up and the option to bypass this check if needed. Plus, if suspending a VM fails during the reboot process, we'll now attempt to gracefully shut it down as a fallback, ensuring the host reboot continues smoothly. ![](https://xen-orchestra.com/blog/content/images/2025/02/modal-smart-reboot.png) ### Updated translations for the interface The translations in Xen Orchestra's interface have been improved to make the platform more accessible and easier to use for non-English speakers. By providing translations in more languages, we ensure that users can navigate and interact with Xen Orchestra in their native language, making the experience feel more natural and reducing the chance of misunderstandings. Languages that have been updated include **French, Spanish, Czech, and Swedish**. ![](https://xen-orchestra.com/blog/content/images/2025/02/xo-new-translations.png) A big thank you to the entire community for their contributions! ### Xen Orchestra 5.103 URL: https://xen-orchestra.com/blog/xen-orchestra-5-103/ Last updated: 2025-01-30T13:48:12.000Z Happy New Year! We’re kicking off 2025 with a feature-packed release: XO 5.103\. This update not only brings powerful improvements to backups, UI, network management, and storage, but also opens the door for **even more community-driven innovation**. This month, we’re inviting you to shape the future of Xen Orchestra and the Vates VMS stack—whether by testing cutting-edge features, contributing to translations, or helping us define the roadmap for our DevOps tools. Let’s make 2025 the biggest year yet. So… let’s dive in! ## 👨‍🚀 Project & Community This month might set a new record—we’re actively **seeking your feedback on three different topics!** Your input is invaluable in shaping the future of XCP-ng, Xen Orchestra, and Vates. Whether it’s DevOps priorities, translations, or testing new features, you get to choose where you can help the most! Let’s build the best Open Source virtualization platform together. 💪🔥 ### New translation platform We’re excited to announce that we are rolling out a new translation tool for XO Lite and XO 6! 🎉 The platform we’ve chosen is Weblate, and—of course—we are self-hosting it on our own infrastructure running XCP-ng, with backups managed via Xen Orchestra. For now, we’re testing the system, so we’re not expecting full translations just yet. Instead, we encourage you to submit a few words or phrases in different languages to help us validate the workflow. If everything runs smoothly, this will make contributing translations much easier going forward! 📢 **Want to help? Register and submit a few translations in the language of your choice:** [WeblateThis site runs Weblate for localizing various software projects.![](https://xen-orchestra.com/blog/content/images/icon/weblate-180-1.png)WeblateMichal Čihař![](https://xen-orchestra.com/blog/content/images/thumbnail/og-1.png)](https://translate.vates.tech/?ref=xen-orchestra.com) ### Removing the 2TiB limitation While it was already possible to use volumes larger than 2TiB with the raw driver, there were major limitations: no snapshots, no live migration, and other missing features. Now, we’re excited to introduce an alpha release of our elegant solution—one that minimizes migration complexity while unlocking full functionality. Instead of requiring a complete overhaul, we’ve added qcow2 format support to the existing tapdisk component. In simple terms: - You can keep all your existing SRs. - Any new VDIs will automatically use the new format, enabling snapshots, live migration, and more. - No disruptive migrations—just seamless support for larger VDIs! You can learn more, test and report in here: [Dedicated thread: removing the 2TiB limit with qcow2 volumesHello everyone, As some of you may know, we are in the process of tackling the limitation of 2TiB for VM disks while keeping snapshots, copy on write capabil…![](https://xen-orchestra.com/blog/content/images/icon/512.png)XCP-ngolivierlambert![](https://xen-orchestra.com/blog/content/images/thumbnail/1-profileavatar-1620659303584.jpeg)](https://xcp-ng.org/forum/topic/10308/dedicated-thread-removing-the-2tib-limit-with-qcow2-volumes?ref=xen-orchestra.com) ⚠️ ****This is still in the alpha stage, so** 🚨 ****DO NOT USE IT IN PRODUCTION (yet)!** 🚨 The more users we have testing it, the faster we can refine it and ****make it production-ready**. ### Our DevOps team is waiting for your feedback We now have a dedicated DevOps team, which means exciting progress ahead on key topics like Kubernetes integration, compatibility with existing K8s tools, CSI support, Pyrgos, and more. However, to ensure we prioritize the right features, we need your feedback! Let us know what matters most to you, what challenges you're facing, and what integrations would help streamline your workflows. 📢 **Share your needs and ideas, and we’ll work on making them a reality!** [DevOps Megathread: what you need and how we can help!Hello everyone, We’re gathering all your DevOps needs in this thread to ensure our DevOps tools (Terraform, Packer, Pulumi, Ansible, and more) support what m…![](https://xen-orchestra.com/blog/content/images/icon/512-1.png)XCP-ngolivierlambert![](https://xen-orchestra.com/blog/content/images/thumbnail/1-profileavatar-1620659303584-1.jpeg)](https://xcp-ng.org/forum/topic/10301/devops-megathread-what-you-need-and-how-we-can-help?ref=xen-orchestra.com) ### XCP-ng monthly updates This month brings updates for both XCP-ng 8.2 and 8.3\. Be sure to read the announcement carefully and, as always, we recommend keeping your hosts up to date to benefit from the latest improvements, fixes, and security patches. [January 2025 Maintenance Update for XCP-ng 8.2 LTSNew bugfix, and enhancement updates are available for XCP-ng 8.2 LTS.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-3.png)XCP-ng BlogGaël Duperrey![](https://xen-orchestra.com/blog/content/images/thumbnail/PaysageMontagneNeigeAutomne.jpeg)](https://xcp-ng.org/blog/2025/01/23/january-2025-maintenance-update-for-xcp-ng-8-2-lts/?ref=xen-orchestra.com) [January 2025 Maintenance Update for XCP-ng 8.3New bugfix, and enhancement updates are available for XCP-ng 8.3.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-4.png)XCP-ng BlogGaël Duperrey![](https://xen-orchestra.com/blog/content/images/thumbnail/ForetCheminNeigeLumiere.jpeg)](https://xcp-ng.org/blog/2025/01/23/january-2025-maintenance-update-for-xcp-ng-8-3/?ref=xen-orchestra.com) --- As progress continues across the Vates ecosystem—spanning XCP-ng, Xen Orchestra, and the wider community—we’ve also been hard at work improving core functionalities. Now, let’s dive into this month’s release and explore what’s new! ## 💾 Backup This month brought significant improvements to the backup system in Xen Orchestra. Let’s take a closer look at what’s new! ### Encryption algorithm upgrade We’ve introduced **ChaCha20-Poly1305** as the new encryption standard for backups, replacing AES-256-GCM as the default. This algorithm is widely regarded for its security, efficiency, and modern design. Already a de facto standard in projects like **SSH** and **WireGuard**, it is also recommended by **ANSSI (the French cybersecurity agency)**. [ChaCha20-Poly1305 - Wikipedia![](https://xen-orchestra.com/blog/content/images/icon/wikipedia.png)Wikimedia Foundation, Inc.Contributors to Wikimedia projects![](https://xen-orchestra.com/blog/content/images/thumbnail/550px-ChaCha20-Poly1305_Encryption.svg.png)](https://en.wikipedia.org/wiki/ChaCha20-Poly1305?ref=xen-orchestra.com) ![](https://xen-orchestra.com/blog/content/images/2025/01/ChaCha20.jpg) ChaCha20 algorithm Like AES-256-GCM, ChaCha20-Poly1305 is an **AEAD (Authenticated Encryption with Associated Data)** algorithm. This means it provides both **confidentiality** and **data integrity** without requiring additional checksum verification. Because encryption inherently includes integrity protection, we were able to remove redundant checksum calculations, leading to improved backup performance. Performance-wise, AES-256-GCM benefits from hardware acceleration on modern CPUs via **AES-NI**, making it very efficient on x86-based architectures. However, ChaCha20-Poly1305 is often **faster on systems that lack AES-NI**, such as ARM-based platforms, making it a better choice for cross-platform compatibility. Another key advantage is that **ChaCha20-Poly1305 does not impose a 64 GiB file size limit**, unlike AES-256-GCM, which can be restrictive for large, block-based backups. While ChaCha20-Poly1305 is **not FIPS-certified**, we continue to support **AES-256-GCM** for users who require compliance. If FIPS certification is necessary for your environment, you can manually configure your Backup Repository to use AES-256-GCM instead. For those interested in the technical details, you can find the full **ChaCha20-Poly1305 specification in** **RFC 8439** **.** ### Faster encrypted backups Encrypted backups now run faster, thanks to a key optimization: **removing redundant checksums**. Since encryption inherently provides integrity verification, separate checksum calculations were unnecessary, so we removed them, significantly boosting performance. ### Incremental replication backup size displayed You can now **see the actual space used** by incremental replication backups. This was tricky to compute accurately, but we made it work! The backup view now displays the real storage consumption on the destination Storage Repository (SR), giving you a better understanding of your backup footprint. It will be displayed in the new XO 6 dashboard. ### Avoid disabling blocks on encrypted SR We’ve added a safeguard to **prevent disabling block-based mode** on an existing backup configured with both **blocks + encryption**. Without this check, disabling blocks could lead to issues during merge, as some parts of the backup would remain encrypted while others wouldn’t. This new backend-level safety measure ensures a seamless and reliable backup workflow. ### More documentation on backups We’re continuously improving our **backup documentation**, especially around **retention policies**—a topic that can be complex to navigate. If you haven’t checked it in a while, we highly recommend taking a look at the latest updates: 👉 [**Backup Documentation**](https://docs.xen-orchestra.com/backups?ref=xen-orchestra.com) ## 🥝 Core UI CoreUI is our new component framework and design system, built to power both XO Lite and XO 6\. This month, we've made various improvements, particularly in the VM console experience. ### Better consoles We've introduced a **loading state indicator** for consoles, ensuring better feedback when a session is starting. Additionally, when a VM is halted, instead of displaying a blank or unresponsive console, a **clear visual placeholder image** is now shown, improving the user experience. Interacting with the console has also become more seamless. We've added **essential actions** such as **Ctrl+Alt+Del** and other key commands directly within the interface. The console now also supports **full-screen mode**, making it easier to work with VMs in a dedicated view. Finally, **keyboard focus improvements** ensure a smoother workflow. When the console is active, focus is now automatically set, meaning you can start typing without extra clicks. Additionally, **tab navigation** is fully supported, allowing users to switch between UI elements efficiently using just the keyboard. ![](https://xen-orchestra.com/blog/content/images/2025/01/402019649-2a112b75-59a1-41f4-a494-3091d62a9f1d.png) ### Network management We've laid the groundwork for **network management** in CoreUI! All the necessary components have been created and assembled, allowing us to accurately report network data within the UI. While the side panel for managing network configurations is not yet available, rest assured that it’s coming next month. This marks an important step toward a more integrated and seamless network management experience in both XO Lite and XO 6\. Stay tuned for further updates! ### Spanish translation A huge thanks to David Johnston (aka DSJ2 on GitHub) for his valuable contribution in adding Spanish language support to both XO Lite and XO 6! This marks another step in making Xen Orchestra more accessible to a broader audience. We truly appreciate the community's efforts in helping us improve and expand localization. ¡Gracias! ![](https://xen-orchestra.com/blog/content/images/2025/01/spain-4522800_1280.jpg) ## 🛰️ XO 6 While CoreUI serves as the global component library, XO 6 and XO Lite remain two distinct products, each designed to solve different challenges. Let’s take a look at what’s new in XO 6 this month. ### Mobile-friendly dashboard The dashboard now adapts properly to mobile devices, ensuring a smoother experience when managing your XCP-ng infrastructure on the go. While most users interact with Xen Orchestra from a desktop or laptop, sometimes you only have your phone: and in those cases, having a functional interface is far better than nothing! ![](https://xen-orchestra.com/blog/content/images/2025/01/Capture-d--cran-2025-01-27-174006-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/01/Capture-d--cran-2025-01-27-173959-1.png) ### Network display A dedicated network view is now available for both pools and hosts. This new interface provides a clear summary of everything you need to know about your network configuration in XCP-ng, helping you quickly assess and manage connectivity across your infrastructure. ![](https://xen-orchestra.com/blog/content/images/2025/01/394359037-ff889348-ff4a-4502-ab9e-10921345d150-1.png) ![](https://xen-orchestra.com/blog/content/images/2025/01/390319007-b7262cd2-0fdc-4407-af46-e786016f7a60-1.png) ### Language Sync from XO 5 to XO 6 XO 6 doesn’t yet have a dedicated preferences section, but language settings from XO 5 are now automatically synced. If you’ve set your preferred language in the User Zone of XO 5, it will be reflected in XO 6 as well! ## 🔭 XO Lite Just like XO 6, XO Lite continues to receive monthly updates, ensuring a steady stream of improvements. If your system is connected to the internet, XO Lite will automatically update to the latest version. For air-gapped environments, make sure to keep up with your regular XCP-ng updates to benefit from the latest features. ### Network display Similar to XO 6, XO Lite now includes a dedicated network view for both pools and hosts. This new feature brings essential network insights directly into the XO Lite interface, making network management more accessible and intuitive. ## 🪐 XOA We’re actively working on bringing dedicated XOA instances tailored for deployment on AWS, designed specifically for users operating in hybrid cloud environments. This initiative aims to provide a seamless experience for those managing both on-premises and cloud-based infrastructures. Currently, this feature is in beta, but we’re making steady progress—stay tuned for more updates in the near future! If you are interested, [please contact us](https://vates.tech/contact?ref=xen-orchestra.com). ![](https://xen-orchestra.com/blog/content/images/2025/01/Amazon_Web_Services_Logo.svg-1.png) ## 📡 REST API This month, we’ve added a new endpoint—but more importantly, we’ve embarked on a major API overhaul that will bring better standardization, improved documentation, and long-term stability. Here’s what’s happening. ### Data on space usage for replication We've enhanced the Dashboard API endpoint to now include size usage on destination SRs for replication backups. This means you can programmatically retrieve the actual space consumed by replication backups, giving you better insights into your storage usage. For those looking to interact with this endpoint, here’s an example request: ``` "storageRepositories": { "size": { "total": 80590583250944, "used": 4423463350272, "available": 76167119900672, "other": 0, "replicated": 0 } }, ``` ### Major refactoring We’ve started a major refactoring of our REST API, **migrating it to the TSOA framework**. TSOA allows us to directly generate OpenAPI specifications from TypeScript, bringing us closer to industry standards and improving maintainability. [Introduction | tsoaA VitePress site![](https://xen-orchestra.com/blog/content/images/icon/faviconV2)tsoa](https://tsoa-community.github.io/docs/introduction.html?ref=xen-orchestra.com) Our goal is to make the REST API a first-class citizen in Xen Orchestra, ensuring better documentation, consistency, and ease of integration for developers. With this shift, API documentation will be automatically generated from the code itself, keeping it always up to date with the latest changes. ![](https://xen-orchestra.com/blog/content/images/2025/01/Capture-d--cran-de-2025-01-27-17-26-23.png) These modifications won’t break the existing API, but they will likely introduce a new versioned endpoint (`v1` instead of `v0`). Versioning ensures smooth transitions between API updates, allowing users to adopt new improvements while maintaining compatibility with existing integrations. This is a significant step toward a more robust, standardized, and developer-friendly Xen Orchestra API. Stay tuned for more updates!. ## 🐦 VMware to Vates (V2V) We've improved VSAN support in our VMware to Vates (V2V) migration tool, ensuring better handling of specific URL changes. In most cases, migrating VMs from VSAN to XCP-ng now works out of the box. However, due to limitations in VMware’s API, VSAN transfers are not the fastest and unfortunately do not provide real-time progress updates. In some cases, you may find that exporting VSAN VM disks to an NFS share first results in a faster migration process. That said, V2V can now natively import VMs from an existing VSAN environment, making the transition from VMware to XCP-ng even smoother. ## **🆕** Misc This month’s miscellaneous updates list is a bit shorter than usual. That’s because a significant portion of our efforts went into the XenServer 8 updates, along with the increasing priority of XO Lite and XO 6\. However, we still have some notable improvements! ### Improved CloudInit drive removal Previously, you could configure XO to automatically remove the CloudInit drive after the first boot, preventing an unnecessary 10MiB drive from lingering after initial configuration. However, in some cases, we discovered that the removal process was happening too soon—before CloudInit had fully completed its setup. This issue occurred because XO waited for the guest tools to be active before removing the drive, but in some operating systems, the tools could start before CloudInit finished its configuration, creating a race condition. While this didn't affect all users, it was inconsistent across different OS environments. To ensure reliability, we’ve now added an extra delay of 30 seconds before the drive is removed. While this isn’t the most elegant solution, it guarantees that CloudInit has completed its job before cleanup occurs. In the end, waiting an additional 30 seconds to remove a 10MiB drive was a small tradeoff for ensuring this feature works correctly across all setups. ### Server: remember pool's name and description Previously, when adding a pool from the Settings > Server section in XO, you could assign a custom label to help identify it. However, there was a limitation: the pool name was only available while the pool remained connected. If the connection was lost, so was the pool name—leaving only the IP address as a reference. If no label had been set, it became impossible to determine which pool it was. We've now improved this behavior. On first connection, if you haven't manually provided a label, XO will automatically fill it with the pool's name. This ensures that even if the pool gets disconnected for maintenance (or any other reason), you’ll still remember what it was, making it easier to reconnect later. This small but impactful change improves usability and helps prevent confusion when managing multiple pools over time. ### XS 8 updates installation Last month, we introduced the ability to fetch available updates for XenServer 8 directly within Xen Orchestra. This month, we've taken it a step further: you can now download and install these updates easily from within XO. To make the process as smooth as possible, you can leverage our Rolling Pool Upgrade (RPU) process, allowing you to apply updates efficiently across your infrastructure. Our update algorithm is designed to apply all updates at once, minimizing downtime and making the installation process as fast as possible. Of course, if you prefer to install updates manually, that option is still available. While this feature required a fair amount of work, we’re happy to continue supporting our small but dedicated XenServer user base. Consider it a gesture of appreciation toward the project that originally inspired XCP-ng, as well as the powerful toolstack that helped shape Xen Orchestra into what it is today. ### Xen Orchestra 5.102 URL: https://xen-orchestra.com/blog/xen-orchestra-5-102/ Last updated: 2024-12-30T18:25:34.000Z Welcome to the final release of the year! Despite December being a shorter month, we’ve managed to deliver a feature-packed update to close out 2024 on a high note. This release also gives us the perfect opportunity to reflect on the incredible progress we’ve made throughout 2024, as we gear up to tackle exciting challenges in the year ahead. ## 👨‍🚀 Project & Community As we close out the year, it’s clear that both our **project and community are thriving like never before**! Let’s take a moment to celebrate the highlights of 2024 and look ahead to an even brighter future. ### Vates in 2024: a year of transformation 2024 has truly been a landmark year for Vates. In just two years, our team has **tripled in size**, and this incredible growth has opened the door to exciting new possibilities. But we’re not stopping here. With this momentum, we can confidently see ourselves **breaking the 100-person milestone** in 2025 (another exciting horizon for us to reach). The future is bright, and we’re just getting started! [2024: A year full of success and transformations for Vates!As we close the chapter on 2024, it’s time to look back on an incredible year for Vates. Between innovations and significant achievements, this year has been a testament to our growth and commitment to open source excellence.![](https://xen-orchestra.com/blog/content/images/icon/logo64-2.png)Vates BlogBertille OLDMAN![](https://xen-orchestra.com/blog/content/images/thumbnail/anton-shcherbakov-4EmKK2xERaA-unsplash.jpg)](https://vates.tech/blog/2024-a-year-full-of-success-and-transformations-for-vates/?ref=xen-orchestra.com) ### XO Project Health in 2024 Just in 2024, we had: - 20 new committers - 695 pull requests merged - 123 issues closed - Many new backup features: CBT support, mirror backup, chained backup, immutability, auto retry, better backup reports, GFS retention, sync backup merging, many auto backup healthcheck improvements… - First XO 6 preview available, after sharing all our UI/UX work Some interesting stats generated by "[Git of Theseus](https://github.com/erikbern/git-of-theseus?ref=xen-orchestra.com)" project: ![](https://xen-orchestra.com/blog/content/images/2024/12/stack_plot-1.png) The number of line of codes added by year. You can see that 2024 was busy! ![](https://xen-orchestra.com/blog/content/images/2024/12/line_plot-1.png) Percentage of line of codes "owned" by person. It's very visible that XO code is now a lot more diverse than few years ago, meaning the project is really growing. ### Meet us at the FOSDEM! We’re thrilled to announce that Vates will have a booth at **FOSDEM 2025** in Brussels, taking place on **February 1st and 2nd**. Come visit us to explore the entire **Vates Virtualization Management Stack** and chat with our team. Oh, and did we mention? We’re bringing plenty of swag, so don’t miss out! [![](https://xen-orchestra.com/blog/content/images/2024/12/fosdem.videobox.logo.svg)](https://fosdem.org/2025/stands/?ref=xen-orchestra.com) ### Xen Project Winter Meeting: final stretch The countdown is on! The **Xen Project Winter Meeting** kicks off in exactly one month. We’re in the final stages of preparation and are excited to announce the full program (including all Xen talks and design sessions) in just two weeks. Stay tuned, and don’t worry: **we’ll share a complete recap in February** to keep you in the loop! [Xen Project Winter Meetup - Grenoble![](https://xen-orchestra.com/blog/content/images/icon/favicon-1.ico)Grenoble![](https://xen-orchestra.com/blog/content/images/thumbnail/grenobleimag-1.jpg)](https://campaign.vates.tech/xen-project-winter-meetup?ref=xen-orchestra.com) ### OpenBSD support in XCP-ng 8.3 Thanks to [knightjoel](https://xcp-ng.org/forum/user/knightjoel?ref=xen-orchestra.com) on our forums, a patch was submitted in [OpenBSD upstream](https://marc.info/?l=openbsd-tech&m=173154320510806&w=2&ref=xen-orchestra.com) to fix an issue related to Xen 4.17\. The fix was [merged in November](https://cvsweb.openbsd.org/src/sys/dev/pv/xen.c?rev=1.100&content-type=text/x-cvsweb-markup&ref=xen-orchestra.com) meaning any recent OpenBSD 7.6 snapshot past that date is working now on XCP 8.3! (thanks [Andrew](https://xcp-ng.org/forum/user/andrew?ref=xen-orchestra.com) for the test). ![](https://xen-orchestra.com/blog/content/images/2024/12/OpenBSD_Logo_-_Cartoon_Puffy_with_textual_logo_below.svg.png) ### New XO translation management We've made major improvements to the way translations are managed in Xen Orchestra. Weblate now works directly with our GitHub repository to automatically create commits, push changes and open pull requests for updates. [WeblateThis site runs Weblate for localizing various software projects.![](https://xen-orchestra.com/blog/content/images/icon/weblate-180.png)WeblateMichal Čihař![](https://xen-orchestra.com/blog/content/images/thumbnail/og.png)](https://translate.vates.tech/?ref=xen-orchestra.com) ![](https://xen-orchestra.com/blog/content/images/2024/12/image-2.png) Syncing changes from GitHub to Weblate is still done manually for now, but it's something we can automate later using GitHub hooks. These updates will make it easier to keep translations up to date and ensure that the interface remains accessible to users around the world. We'll provide a guide as soon this enters in production! --- And now, what's up in this last release of 2024! ## 💾 Backup 2024 was big on backup, and December is no exception! ### Synchronous backup merging In Xen Orchestra 5.102, you can now merge backups synchronously through the advanced settings, which makes it easier to manage incremental and mirrored backups while avoiding lock issues. If this option is enabled: - Backups may take a little longer because the merge time is included in the total backup time. - Backup speeds will be slightly slower because some merges are performed in parallel, which can affect I/O performance. - Merges and transfers will not overlap, meaning that the next transfer will not start until the merge is complete (especially for VMs with concurrency set to 1). This update simplifies backup workflows, helping to prevent problems and making it easier to handle complex backup chains. If you have lock errors in the past, this will solve it! ![](https://xen-orchestra.com/blog/content/images/2024/12/394968387-7de57fec-1055-48ed-ae20-f305c4856615.png) ![](https://xen-orchestra.com/blog/content/images/2024/12/395622291-96c122dd-5480-4e88-8f33-bc1b1ebf4872.png) ### Health Check: Adding tags to exclude VMs You can now use tags to exclude VMs from health checks. This makes it easier to control which VMs are monitored. Just add a tag on the VM called `xo:no-health-check` and the VM won't be checked: ![](https://xen-orchestra.com/blog/content/images/2024/12/image-4.png) Also, as we have a great tag system, you can add the reason if you want. For that, you just need to use the format `xo:no-health-check=REASON`. Here is an example: ![](https://xen-orchestra.com/blog/content/images/2024/12/image-6.png) In that case, you know "why" you disabled the health-check! All in all, this is useful for VMs that are in maintenance mode or have special configurations that don't require monitoring at certain times. Excluding these VMs helps to make the health checks more efficient and focused on the ones that matter. ### Long term retention documented We've documented the long-term retention feature that was introduced in [the previous release (Xen Orchestra 5.101)](https://xen-orchestra.com/blog/xen-orchestra-5-101/). This feature, based on the Grandfather-Father-Son (GFS) backup strategy, ensures that the first backup of each time bucket (daily, weekly, monthly) is kept. In addition, any backup that meets certain conditions, such as being the first of a time bucket or meeting a specified number of backups, will also be retained. This documentation explains how to set up and use this feature. You can find it over at [https://docs.xen-orchestra.com/backups#retention-and-scheduling](https://docs.xen-orchestra.com/backups?ref=xen-orchestra.com#retention-and-scheduling) ## 🥝 Core UI Core UI is the main UI used both for XO Lite and XO 6, since they share the same components. ### New components State here for empty tables, tag list, dropdown… They are now part of the available components! ![](https://xen-orchestra.com/blog/content/images/2024/12/380676192-533002b6-7c1e-42a6-b483-9dae448bfc09-1.png) ![](https://xen-orchestra.com/blog/content/images/2024/12/390830492-720368ed-8611-44b4-b07e-46e4791543d2-1.png) ![](https://xen-orchestra.com/blog/content/images/2024/12/388895202-9f212023-ac41-4ac8-a43a-b9bf64392750-1.png) ![](https://xen-orchestra.com/blog/content/images/2024/12/388895209-632dba91-2631-41bc-bda6-1919a3c9057c-1.png) ### ### New centralized task system Managing tasks across your infrastructure can be complex, but our new centralized Job Management feature simplifies this process. A "job" in Xen Orchestra is now a centralized part of the code designed to handle specific tasks, with the following capabilities: - **Defined execution logic**: each job clearly defines what happens when it runs, ensuring consistency and reliability in task execution. - **Argument validation**: built-in mechanisms validate job arguments, preventing errors before execution begins. - **State tracking**: keep track of whether a job is running both internally (by monitoring its promise) and externally (using custom checks), ensuring consistency across the app. - **Extensibility**: easily add new job types to adapt to evolving needs. This feature provides a robust foundation for managing tasks efficiently, ensuring reliability and consistency across the app. ### New menu management system Managing menus in a complex application like Xen Orchestra can be a challenging task. That’s why we’ve developed a new, dynamic menu management system to simplify the process and enhance usability. This system allows you to easily define and manage menus, offering a range of flexible options to suit your needs. You can define menu items in various ways: as external links, internal links (leveraging Vue Router), actions (with handler functions), jobs (integrating with the Centralized Job Management feature), or even submenus, which handle toggling and positioning automatically. Once a menu is set up, each element becomes programmatically accessible, so you can refer to it directly (e.g., `menu.help.documentation`) and pass it to the menu item component. The menu item component itself is designed to adapt seamlessly to the data you provide. It ensures the correct HTML tags, attributes, handlers, and behaviors are applied automatically based on the item type. Submenus are also dynamically positioned and toggled for a smooth and user-friendly experience. This new system makes creating, updating, and managing menus more intuitive than ever, ensuring a consistent and efficient user experience throughout the application. ### Improved Guidelines for Vue.js Components We've updated our development guidelines, focusing on Vue.js components for web-core, XO 6, and XO Lite. The new documentation provides clear advice on how to structure components, name them, and maintain consistency across the codebase. These changes are designed to help developers write code that fits well within the existing framework and is easy to maintain. Whether you're new to the project or have been working on it for a while, these updates should make it easier to contribute effectively. ## 🛰️ XO 6 As a reminder, XO 6 preview is available by adding `/v6` at the end of your XOA URL. ### Dashboard: pool status The new **Pool status** component shows key details about your connected servers, like their health, connection status, and resource usage. It helps you keep track of your servers and quickly spot any issues. ![](https://xen-orchestra.com/blog/content/images/2024/12/397011812-02a0fead-dd15-413e-bca5-894143ace3e0.png) And now your pool dashboard is looking like this: ![](https://xen-orchestra.com/blog/content/images/2024/12/image-7.png) ## 📡 REST API With XO 6 fully adopting our REST API (leaving the legacy JSON-RPC behind), the API is evolving faster than before. ### Add pool status in dashboard endpoint You can get all the visible info in the XO 6 dashboard by doing an API call to the `/dashboard` endpoint. And obviously, since we added the pool status, it's part of the data now, eg in this JSON: ```json { … }, "poolsStatus": { "connected": 3, "unreachable": 4, "unknown": 0 } } ``` ### Manage VDIs when creating VMs via the REST API We've made it easier to manage Virtual disk images (VDIs) when creating virtual machines through the REST API. Before this update, VDIs were automatically included from the selected template, but you couldn’t add, change, or remove them during the creation process. Now, you can add, modify, or remove VDIs as you create the VM. This gives you more control over the storage setup, allowing you to customize your VM exactly how you want it. Example: ``` // The VM will be created with the template's VDIs xo-cli rest post pools//actions/create_vm \ name_label="mra-vm-from-rest-api" \ template="" // The VM will be created with the template's VDIs + one VDI xo-cli rest post pools//actions/create_vm \ name_label="mra-vm-from-rest-api" \ template="" \ vdis=json:'[{"name_label":"foobar", "size": 1073741824 }]' // The VM will be created with the template's VDIs but the VDI with `userdevice 0` will be updated xo-cli rest post pools//actions/create_vm \ name_label="mra-vm-from-rest-api" \ template="" \ vdis=json:'[{"userdevice":"0", "name_label":"foobarbaz"}]' // The VM will be created with the template's VDIs but, the VDI with `userdevice 0` will be removed xo-cli rest post pools//actions/create_vm \ name_label="mra-vm-from-rest-api" \ template="" \ vdis=json:'[{"userdevice":"0", "destroy": true}]' ``` ## 🛡️ Air gap features 2024 marked a turning point for air-gapped deployments. We’ve worked tirelessly to ensure our entire stack is fully operational and seamlessly updatable in isolated environments. The result? A robust solution tailored for air-gapped production environments. To help you get started, we’ve created a comprehensive guide that walks you through every step. If your production environment requires air-gap compatibility, don’t hesitate to reach out: we’ll provide everything you need to succeed! [Contact us](https://vates.tech/contact?ref=xen-orchestra.com) ## **🆕** Misc Despite December being a shorter month (with just one sprint instead of the usual two due to the holiday season) our Misc section remains packed with updates and enhancements. ### Updated Sign-In Page Design The sign-in page has been updated to better match the style of XO6\. This includes a new logo and some style tweaks to make it look more consistent with the rest of the interface. We have kept the changes to a minimum, to maintain a familiar feel for users. ![](https://xen-orchestra.com/blog/content/images/2024/12/image-3.png) ### Editing XenStore Entries in the UI 💡 XenStore is an information storage space shared between domains maintained by the Xenstored. It is meant for configuration and status information rather than for large data transfers. Each domain gets its own path in the store, which is somewhat similar in spirit to procfs. When values are changed in the store, the appropriate drivers are notified. You can now edit XenStore entries directly from the Xen Orchestra interface. This feature is available on the **VMs → Advanced** page, and allows you to modify string entries, making it easier to manage XenStore data. For example, you can add a key pair this way: ![](https://xen-orchestra.com/blog/content/images/2024/12/image-10.png) ![](https://xen-orchestra.com/blog/content/images/2024/12/395593329-a7633f10-53e8-4d79-859c-b9d8204afdf0.png) Then, from the guest OS, you can now read the value: ``` # xenstore read vm-data/foo bar ``` **And it works both ways!** If you write a key from the OS, it will be displayed in XO: if you input `xenstore write vm-data/foo baz`, Xen Orchestra will instantly display the updated result in the UI! As demonstrated, Xenstore offers a powerful yet straightforward mechanism for communication between XO and virtual machines. ### RPU scheduling You can now schedule a [Rolling Pool Update](https://docs.xen-orchestra.com/manage%5Finfrastructure?ref=xen-orchestra.com#xcp-ng) in the job section. For instance, you might want to kick off an RPU every Sunday at 3 AM to keep things fresh. Here's how to set it up: 1. **Create the job**: use the `pool.rollingUpdate` option and specify the pools you want to include. 2. **Set the schedule**: create a schedule (e.g., weekly on Sunday at 3 AM) and link it to your job. 3. Profit! ![](https://xen-orchestra.com/blog/content/images/2024/12/image-8.png) Creating the RPU job ![](https://xen-orchestra.com/blog/content/images/2024/12/image-9.png) Scheduling the RPU job ⚠️ Obviously, schedule updates outside of production hours. While RPUs are designed to be transparent, it’s always wise to allow for some buffer time in case anything unexpected arises. ### Expanded alarm notifications We've expanded the range of alarms displayed in the dashboard to include critical system messages that were previously overlooked. This enhancement ensures that important alerts, such as `MULTIPATH_PERIODIC_ALERT` and `BOND_STATUS_CHANGED`, are now prominently featured, providing a more comprehensive view of your system's health. ![](https://xen-orchestra.com/blog/content/images/2024/12/397727329-a7710551-20e8-4eb4-8a30-fcd49aae8293.png) ### `mdadm` status We’ve made it easier than ever to monitor the health of your software RAID arrays! The **mdadm status** is now displayed directly in the **Host → Advanced** section, giving you quick and clear insights into your RAID's condition: ![](https://xen-orchestra.com/blog/content/images/2024/12/395257123-c4553c45-6795-4f18-872d-c84433235521.png) Additionally, if a host contains a degraded software RAID, you’ll see a **dedicated red triangle** in the host view. Clicking on it provides detailed information about the issue, ensuring that it’s impossible to overlook critical problems: ![](https://xen-orchestra.com/blog/content/images/2024/12/395257147-85ffc57d-2c43-440f-af91-ddb129caae47.png) ### Cloudbase-Init Support Now Documented In the [previous Xen Orchestra update (version 5.101)](https://xen-orchestra.com/blog/xen-orchestra-5-101/), we added support for Cloudbase-Init, a tool that automates the initialization of Windows virtual machines in cloud environments. With Xen Orchestra 5.102, we’ve ensured that this support is properly documented in our official documentation, available in the [Advanced](https://docs.xen-orchestra.com/advanced?ref=xen-orchestra.com#cloud-init-and-cloudbase-init) section. This documentation explains how Cloudbase-Init integrates with Xen Orchestra and covers the setup process. You can now easily refer to this guide to more effectively manage Windows VMs with Cloudbase-Init. ### Listing Missing Patches for XenServer 8 For XenServer 8 (effectively 8.4-ish) and newer, Xen Orchestra now highlights any missing patches directly in the interface. This makes it easier to quickly see what needs updating and take action without switching between tools. It’s a straightforward way to help administrators keep their systems secure and running smoothly. 💡 The XenServer update process has changed multiple times over the years, which made keeping up a challenge. While we’ve adapted to support these changes, we strongly recommend migrating to ****XCP-ng** whenever possible for a more consistent and seamless experience. ### Xen Orchestra 5.101 URL: https://xen-orchestra.com/blog/xen-orchestra-5-101/ Last updated: 2024-11-29T14:05:11.000Z Welcome to the November 2024 release! As we near the end of 2024, this month’s release is the second-to-last update of the year, and there’s plenty to talk about. From updates across our ecosystem and community to exciting new features in Xen Orchestra, we’ve got a mix of highlights and improvements to share. In this release, we’ve added **GFS retention policies for backups**, support for **vTPM restores**, and **an improved health check** to keep your infrastructure running smoothly. We’ve also continued refining the **new UI**, bringing in new features and making dozens of tweaks to improve usability. Let’s take a closer look at what’s new in 5.101! ## 👨‍🚀 Project & Community It’s hard to believe it’s been just a month since our last release, considering the sheer amount of news and activity in our community and ecosystem. From updates on projects to exciting developments across the board, there’s been no shortage of momentum. If you’re here just for the details on the latest Xen Orchestra release, feel free to scroll down to dive straight into what’s new in 5.101\. Otherwise, stick around to catch up on the bigger picture! ### Making Rust a first-class citizen for Xen At Vates, we’re not just building open-source software: we’re driving innovation and fostering collaboration. As part of our efforts, we’re working with the Xen Project community to make Rust a first-class citizen within the ecosystem. ![](https://xen-orchestra.com/blog/content/images/2024/11/rustacean-orig-noshadow.png) Rust’s focus on safety, performance, and modern development practices aligns perfectly with the future of Xen. By advocating for and contributing to this transition, we aim to unlock new possibilities and bring long-term benefits to the entire community. You can read more about this initiative in our latest XCP-ng blog post: [Making Rust a first-class citizen for XenDiscover our work at Vates to make Rust a first-class language in the Xen Project.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-2.png)XCP-ng BlogTeddy Astie![](https://xen-orchestra.com/blog/content/images/thumbnail/rustnewsdec24.jpg)](https://xcp-ng.org/blog/2024/11/26/making-rust-a-first-class-citizen-for-xen/?ref=xen-orchestra.com) ### XCP-ng 8.2 & 8.3 security updates With two supported releases for XCP-ng now available—**8.2 LTS** and **8.3**—we’re continuing to deliver security updates and bug fixes for both on a steady monthly schedule. Managing updates for twice the number of packages is no small feat, so kudos to our XCP-ng team for keeping everything on track while maintaining the high standards our users expect! [November 2024 Security Update for XCP-ng 8.3Security updates for Xen and Intel microcodes for XCP-ng 8.3.![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge.png)XCP-ng BlogGaël Duperrey![](https://xen-orchestra.com/blog/content/images/thumbnail/security-3742114_1280.jpg)](https://xcp-ng.org/blog/2024/11/15/november-2024-security-update-for-xcp-ng-8-3/?ref=xen-orchestra.com) [November 2024 Security and Maintenance Update for XCP-ng 8.2 LTSNew bugfix, security (Xen, Intel microcode) and enhancement updates are available for XCP-ng 8.2 LTS (XAPI, blktap, sm, ...)![](https://xen-orchestra.com/blog/content/images/icon/SVG-_XCPNG---Badge-1.png)XCP-ng BlogGaël Duperrey![](https://xen-orchestra.com/blog/content/images/thumbnail/pexels-david-bartus-43782-1545347-pt.jpg)](https://xcp-ng.org/blog/2024/11/15/november-2024-security-and-maintenance-update-for-xcp-ng-8-2-lts/?ref=xen-orchestra.com) ### Our growing ecosystem There’s been a lot happening on this front! Not only are partners—integrators and service providers—actively selling our virtualization stack, but they now have even more tools and opportunities thanks to our updated partner portal: [Vates Partner Insights #2: Expanding horizons for our partnersExplore the latest updates exclusively for our partners, including enhanced Partner Portal features, expanded training opportunities, and key milestones from 2024.![](https://xen-orchestra.com/blog/content/images/icon/logo64-1.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/jason-leung-Xaanw0s0pMk-unsplash.jpg)](https://vates.tech/blog/vates-partners-insight-2-expanding-horizons-for-our-partners/?ref=xen-orchestra.com) On top of that, our technological partners are using our platform as a core component of their offerings, whether for hosting services or even public cloud solutions (stay tuned for more updates soon!). Check this recent example with Exodata: [Exodata and Vates form strategic partnership to deliver a robust sovereign cloud solution with global supportVates and Exodata announce a strategic partnership to deliver a robust, sovereign, and French-based cloud solution. This collaboration combines Vates’ virtualization expertise with Exodata’s cloud and cybersecurity services, featuring a 100% French virtualization stack and 24/7 global support.![](https://xen-orchestra.com/blog/content/images/icon/logo64.png)Vates BlogMarc-André Pezin![](https://xen-orchestra.com/blog/content/images/thumbnail/sergey-zhesterev-VJlLx10OYRo-unsplash.jpg)](https://vates.tech/blog/vates-exodata-strategic-partnership-for-cloud-sovereignty/?ref=xen-orchestra.com) ### RedHat certification This is yet another sign of our growing presence in the IT world. We’re now officially certified for Red Hat, meaning that while Red Hat distributions have always worked well on XCP-ng, they’re now tested and validated by Red Hat itself! ![](https://xen-orchestra.com/blog/content/images/2024/11/Red_Hat_Logo_2019.svg.png) You can read more about this certification on [https://catalog.redhat.com/hardware/system/detail/260327](https://catalog.redhat.com/hardware/system/detail/260327?ref=xen-orchestra.com) ### Many new open positions We’re growing fast! Just two years ago, when Broadcom announced its acquisition of VMware, Vates was a team of about 20 people. Today, we’re approaching **70** and are on track to hit **100 next year**. With this growth comes many new opportunities: we’ve opened several positions to expand our team. To be honest, the volume of applications has been incredible, and we’re doing our best to respond to everyone. If it takes us a little time, we appreciate your patience. Rest assured, we’re carefully considering all candidates. You can check out the list of open positions on our website: [Careers at Vates![](https://xen-orchestra.com/blog/content/images/icon/apple-touch-icon.png)![](https://xen-orchestra.com/blog/content/images/thumbnail/logo-vates.png)](https://vates.tech/careers?ref=xen-orchestra.com) ### An expanding community Our growth isn’t just commercial: it’s also happening on the community side, which is now bigger than ever and continues to expand rapidly. In my opinion, this is the secret sauce for success in Open Source: revenue and community. One without the other doesn’t work, neither for end users nor for the company driving the projects. Just take a look at these recent numbers from our community forums: ![](https://xen-orchestra.com/blog/content/images/2024/11/1730535976417.jpg) ### Xen Winter Meetup: last tickets! If you’re a system developer interested in Xen (or already part of the Xen developer community) don’t miss the next Xen event we’re hosting in Grenoble! Tickets are running out, so act fast if you want to join. You’ll find all the details on the event website: [Xen Project Winter Meetup - Grenoble![](https://xen-orchestra.com/blog/content/images/icon/favicon.ico)Grenoble![](https://xen-orchestra.com/blog/content/images/thumbnail/grenobleimag.jpg)](https://campaign.vates.tech/xen-project-winter-meetup?ref=xen-orchestra.com) --- And now, let's talk about this 5.101 release! ## 💾 Backup Many improvements on stability and robustness among some cool features. ### Long-term backup retention with GFS Strategy Managing backups is key to keeping your virtual infrastructure running smoothly. To help with long-term data retention, we've added an option in Xen Orchestra to configure Grandfather-Father-Son (GFS) backup retention strategies. You'll find this new feature in the **Scheduling** section, where administrators can easily set how many backups to keep for different periods of time: - Daily backups - Weekly backups - Monthly backups - Yearly backups The most recent backup for each interval (daily, weekly, monthly, and yearly) is retained. Only intervals that have at least one backup are considered for retention, and older backups in those intervals will be deleted to make room for the newer ones. ⚠️ Before using this feature, ****do not test it on critical backups**. There is a potential risk of accidentally deleting more backups than intended, especially if you're unfamiliar with the retention settings. We recommend testing on less critical backups first to understand the impact. If you notice any strange behavior or issues with the feature, please ****reach out to** [****Vates support**](https://help.vates.tech/?ref=xen-orchestra.com) for assistance. These settings apply only to backup schedules, not to rolling snapshots or replication jobs. By customizing these options, you can ensure that your backup retention meets your organization's needs. This approach is similar to tools like Restic and Borg, and is designed to handle situations where older backups are deleted. GFS also works independently of the base/delta backup policy, making it adaptable to different scheduling needs. ![](https://xen-orchestra.com/blog/content/images/2024/11/image.png) ![](https://xen-orchestra.com/blog/content/images/2024/11/image--1-.png) ### **Support for vTPM backup and restore** We've made it easier to back up and restore the contents of virtual Trusted Platform Modules (vTPMs). This enhancement automatically includes sensitive data (such as encryption keys) in backups, ensuring that nothing critical is left behind. This update adds an extra layer of protection for environments that rely on advanced security, making restores smoother and safer when working with encrypted or secure workloads. 💡 ****A note on security** The data stored in vTPMs, such as encryption keys, is particularly critical. It's important to secure backups, especially using encryption in Xen Orchestra, to protect this sensitive information from unauthorized access. ### Better backup health checks We’ve made improvements to backup health checks to resolve an issue where restores could occasionally remain stuck in an idle state during the process. The health check now uses `PV_drivers_detected` instead of `PV_drivers_version.major` to confirm whether a VM has booted properly. This adjustment enhances reliability, particularly for PVH VM types or cases where VMs had trouble reporting the driver version. ### Smoother backups with sequential host connections Sometimes, backups can fail because a virtual disk (VDI) is still in use by a host, causing errors like `VDI_IN_USE`. To solve this, Xen Orchestra now connects to hosts one at a time during backups. This change reduces conflicts and makes the backup process more reliable, even for busy environments. It’s a small but important tweak to ensure your backups run without a hitch. ## 🦾 Hardware integration We’re making steady progress on hardware integration with our technological hardware vendors, almost on a monthly basis. It’s not just about fixing bugs (though we did resolve an issue with Lenovo servers and fans running at full speed), it’s also about enhancing the experience by providing more detailed hardware information directly in Xen Orchestra. ### BIOS update checks for 2CRSi servers Keeping your hardware up to date just got easier! Xen Orchestra now automatically checks the **BIOS version of your 2CRSi hosts** against the latest version available in the 2CRSi repository. If an update is available, you’ll see the latest version displayed, along with a **direct link to download it**, right in the host’s general tab. ![](https://xen-orchestra.com/blog/content/images/2024/11/388498922-baa9f390-2858-439f-be02-3db4b584d1ab.png) 💡 To take advantage of this improvement, make sure Xen Orchestra has access to the ****2CRSi domain**. ## 🥝 Core UI As development on both **XO 6** and **XO Lite** continues, the lines between the two projects are becoming increasingly blurred, especially when it comes to the core components of their user interfaces. Many of these components are now shared, making it almost impossible to separate the two in terms of development. To reflect this growing overlap, we’ve introduced a new section called **"Core UI"**, which encompasses shared features and improvements that apply to both XO 6 and XO Lite. This unified approach allows us to deliver a more consistent experience across both projects while streamlining development efforts. ### Improved console view We've updated the console view in Xen Orchestra to make it more user-friendly and responsive. - Cleaner and simpler layout: the interface looks more organized, so it's easier to find what you need. - Faster performance: the console loads faster, which helps if you're working with multiple VMs at once. - Easier controls: the improved controls (such as keyboard shortcuts or a clipboard) make it simpler to interact with your VMs, whether you're managing or troubleshooting them. With these changes, the console is now smoother and more efficient, making VM management a better experience overall. ![](https://xen-orchestra.com/blog/content/images/2024/11/384432847-4c754a25-cafb-493c-9ebe-36fe0e346d18.png) ### Czech language support This month, we’re expanding our language support by introducing **Czech**! This new addition creates a more inclusive experience for Czech-speaking users, enabling them to interact with Xen Orchestra in their native language. A huge thanks goes to **p-bo** from GitHub ([GitHub profile](https://github.com/p-bo?ref=xen-orchestra.com)) for making this possible. His dedication and attention to detail have brought this feature to life, once again demonstrating the incredible value of our community. Whether you’re managing VMs, configuring backups, or exploring advanced settings, you can now navigate everything in **Czech**. ![](https://xen-orchestra.com/blog/content/images/2024/11/Capture_2024-11-29_10_25_31.png) ![](https://xen-orchestra.com/blog/content/images/2024/11/Capture_2024-11-29_10_27_38.png) ### Card component Xen Orchestra has a new "card" component that improves the way information is displayed in the interface. It provides a clearer and more polished way to present important details while keeping the interface visually appealing: ![](https://xen-orchestra.com/blog/content/images/2024/11/390717256-eb0a7c22-b05f-4c26-9162-9ceaa8fef076.png) The network management view coming with it will be available soon: ![](https://xen-orchestra.com/blog/content/images/2024/11/389900731-9f21206e-9d5a-4f1e-8c5c-393f80006178.png) ### Panel The logical next component after the card is the panel itself: ![](https://xen-orchestra.com/blog/content/images/2024/11/384317390-813ee509-9c7c-4376-8361-13c6a1abe0af.png) ### 404 page We also added a new 404 error page to make it easier to navigate when a page can’t be found. Instead of just showing a plain error message, this page now includes visuals, to make the issue clear, less frustrating and provide helpful links: ![](https://xen-orchestra.com/blog/content/images/2024/11/387747700-20ebe894-65a4-42fc-9211-12fe6ede347f.png) This new page reduces frustration by offering clear information and alternatives, helping users get back on track. ### Improved user menu The user menu in XO Lite has been updated to match the sleek design of XO 6, using the same user icon. This change brings a more consistent look across the platforms, making the interface feel more unified and modern. Before: ![](https://xen-orchestra.com/blog/content/images/2024/11/383486684-c3441539-62d1-48ef-bb2d-c9251918d23f.png) After: ![](https://xen-orchestra.com/blog/content/images/2024/11/383485667-9523703a-a1a4-4b35-8704-d32dce1e4163.png) Also, the user menu now provides quick access to key resources: ![](https://xen-orchestra.com/blog/content/images/2024/11/383653223-540c8508-a25f-4fad-ad76-4ceae3bef261-2.png) - Access the XCP-ng Documentation straight from the menu to find detailed guidance. - Access Professional support - Send Feedback and join conversations through our forum Now, these essential resources just a click away! ### Improved empty table display We've added a more informative and visually clear placeholder for empty tables throughout the web interface. If no data is available, users will see a message explaining the situation and suggesting relevant next steps or actions, making navigation smoother and the UI more intuitive. ![](https://xen-orchestra.com/blog/content/images/2024/11/388895202-9f212023-ac41-4ac8-a43a-b9bf64392750.png) ![](https://xen-orchestra.com/blog/content/images/2024/11/388895209-632dba91-2631-41bc-bda6-1919a3c9057c.png) ### New panel states We've added visually distinct state cards in the panel. These cards represent specific states like errors, no selection, or loading, so that users can quickly understand the current status of a process or action. The design emphasizes clarity and accessibility, helping users navigate complex workflows easily. ![](https://xen-orchestra.com/blog/content/images/2024/11/384341450-59444fd2-8923-49d2-af97-eb14cbc7dfb8-1-1.png) ![](https://xen-orchestra.com/blog/content/images/2024/11/384341453-2afb7a0e-71d0-4266-ade1-7f03cd9e94ec-1-1.png) ### XO 6: host console access With the latest release, you can open a console session for any connected host directly from the web interface. Whether you need to troubleshoot an issue, run quick commands, or review host logs, everything is just a few clicks away. ![](https://xen-orchestra.com/blog/content/images/2024/11/383108410-2fbb3551-bb68-448c-993a-1ec2eb0133fd.png) ### XO Lite: console actions ![](https://xen-orchestra.com/blog/content/images/2024/11/389893103-fabdfb9a-746e-400e-9f50-62686f890f21.png) You have now a panel dedicated with all console actions on the side. Convenient and efficient! ## 🪐 XO Proxy Our proxy has grown far beyond its original purpose of scaling backups horizontally. It can now also act as a **relay in distributed infrastructures**, eliminating the need to set up dedicated private networks. ### Showing proxy version You can now easily check the version of a proxy directly from the Xen Orchestra interface: no need to tunnel in or run CLI commands. This new feature streamlines the user experience, providing instant visibility into the proxy version and making it easier to ensure you’re running the latest updates. ![](https://xen-orchestra.com/blog/content/images/2024/11/383161366-3237b295-1fc4-4b3f-aeee-4526923e9599.png) ## 📡 REST API Our REST API isn’t just easier to use than the older JSON-RPC version—it’s also the foundation for our new UI, making it a future-proof solution for both developers and users. ### Manage VIFs when creating VMs via the REST API You can now manage **virtual interfaces (VIFs)** through the REST API when creating virtual machines. This makes it easier to configure network settings for your VMs right from the start, eliminating the need for manual adjustments after creation. With this feature, you can specify which network a VM’s VIF should connect to using simple commands, streamlining and automating the setup process. While this functionality has been available in the Xen Orchestra UI (XOA) for some time, it’s now extended to the REST API. This brings the two closer together and is part of our ongoing efforts to make VM creation via the API just as complete and user-friendly as it is in the UI, step by step. ``` // The VM will be created with the template's VIFs xo-cli rest post pools//actions/create_vm \ name_label="mra-vm-from-rest-api" \ template="" // The VM will be created with the template's VIFs + one VIF xo-cli rest post pools//actions/create_vm \ name_label="mra-vm-from-rest-api" \ template="" \ vifs=json:'[{"network":""}]' // The VM will be created with the template's VIFs, but the VIF with `device 0` will be updated xo-cli rest post pools//actions/create_vm \ name_label="mra-vm-from-rest-api" \ template="" \ vifs=json:'[{"device":"0", "network":""}]' // The VM will be created with the template's VIFs, but the VIF with `device 0` will be removed xo-cli rest post pools//actions/create_vm \ name_label="mra-vm-from-rest-api" \ template="" \ vifs=json:'[{"device":"0", "destroy": true}]' ``` ## 🛡️ Air gap features We’ve reached an important milestone in supporting fully air-gapped infrastructure, enabling the complete lifecycle of XCP-ng, XO, and even XOSTOR in physically disconnected environments. This functionality is ideal for highly sensitive installations like nuclear power plants, as well as naval ships, offshore oil rigs, or airplanes where network connectivity simply isn’t an option. ![](https://xen-orchestra.com/blog/content/images/2024/11/Airgap-cover--1-.png) To make things easier, we now offer a dedicated service for these growing use cases. Along with this, we’ve prepared a comprehensive guide detailing how to deploy, install, and perform fully disconnected updates across our entire stack. If you’d like to learn more, feel free to get in touch with us! [Contact us](https://vates.tech/contact/?ref=xen-orchestra.com) ## **🆕** Misc This month brought a wide range of improvements and new features to the existing interface. As you’ll see, it’s been a busy month, and we’re committed to continuing to refine and enhance the experience for all our users! ### Easier Maintenance mode with migration bypass We've made some improvements to host maintenance in Xen Orchestra to give you more flexibility and control. In the past, entering maintenance mode could get blocked by VMs with "stuck" backup flags, even if no backups were running. This caused delays and slowed things down. Now, we've added a feature that detects when migrations are blocked during maintenance mode. If something goes wrong, a pop-up will tell you which VMs are causing the issue and give you the option to override the block. You can then go ahead with the forced migration and smoothly transition to maintenance mode without any roadblocks. ![](https://xen-orchestra.com/blog/content/images/2024/11/388639567-208c26cd-9adc-47c2-bc75-2b885ded3d37.png) This update makes it easier to spot problems, fix them quickly, and have a more predictable host maintenance process. ### New control to block or unblock VM Migrations We’ve added a new feature in Xen Orchestra to give admins more control over VM migrations. You can now easily block or unblock VM migrations with just a click in the **Advanced VM** tab. The new **Unblock Migration** button helps clear specific migration restrictions. If a migration is blocked, the button will appear with a warning, so it’s easy to spot and fix the issue. If the migration isn’t blocked, the button stays grayed out, showing the current state of the VM. ![](https://xen-orchestra.com/blog/content/images/2024/11/385770574-2ced0254-2e86-46f4-acdd-c54b1eb9afda.png) ![](https://xen-orchestra.com/blog/content/images/2024/11/386286474-d875ec5d-5446-4c82-af93-ea8944c09c77.png) ![](https://xen-orchestra.com/blog/content/images/2024/11/389900280-5efe4cb5-82ac-4e83-83bd-b2034e8b21a0.png) This update makes it easier to manage VM migrations, especially when dealing with things like host maintenance or system upgrades. ### Automatic trimming of editable text Editing names or descriptions for pools, hosts, VMs, and storage repositories (SRs) is now smoother with automatic trimming of extra spaces at the beginning and end. This update automatically cleans up extra spaces, preventing errors and making the interface more consistent and polished. ### A new era for the Xen Orchestra documentation We've made a major upgrade to our documentation platform by migrating from **VuePress 1.4** to **Docusaurus 3.6**. With VuePress no longer maintained, this move ensures that our documentation remains robust, up to modern standards, and able to support more frequent updates. This change brings Xen Orchestra's documentation in line with our XCP-ng documentation, which is already hosted on Docusaurus. As a bonus, the migration provided an opportunity to refresh and slightly reorganize the content, paving the way for an even more dynamic documentation experience in the future. ![](https://xen-orchestra.com/blog/content/images/2024/11/Capture-d--cran-du-2024-11-29-11-32-06.png) ### Clearer error messages for host key problems Getting an error due to a small host key can be confusing. Xen Orchestra now provides clearer, more detailed error messages when a host key is too small. Instead of generic messages, you'll now see a precise explanation of the problem, making it easier to understand what went wrong and how to fix it. ![](https://xen-orchestra.com/blog/content/images/2024/11/383488089-2acf0894-c421-4dd3-a294-99a8bf13e67f.png) ### Fixed encoding issues in S3 remote usernames We’ve fixed an issue that caused usernames to be improperly encoded when connecting to S3-compatible storage. This means no more errors or disruptions during backups and restores—just smooth, reliable operations with your S3 remotes. ### CloudBase Init This one was a bit tricky, but we did it! Xen Orchestra now supports [**CloudBase Init** for Windows VMs](https://cloudbase.it/cloudbase-init/?ref=xen-orchestra.com), enabling configuration to be pushed in a similar way to **CloudInit** for Linux. ![](https://xen-orchestra.com/blog/content/images/2024/11/pngegg-1.png) Behind the scenes, we forked the `fatfs` library to implement the `createLabel` function, which is required to properly label disks for Windows VMs. Without this, the disk would be mounted without a label, causing issues during the setup process. We’ve put together a comprehensive [README](https://github.com/vatesfr/xen-orchestra/tree/master/%40vates/fatfs?ref=xen-orchestra.com#readme) with all the technical details if you want to understand our work. With this feature, you can now use **CloudBase Init** to streamline configuration for your Windows VMs—just as you would for Linux! ### Xen Orchestra 5.100 URL: https://xen-orchestra.com/blog/xen-orchestra-5-100/ Last updated: 2024-10-31T14:12:55.000Z 5.100 isn’t just a nice, round number; it marks an exciting XO release packed with new features and improvements. This update reflects the pulse of our fast-growing ecosystem, bringing even more capabilities to XO as we expand alongside it: no tricks, just treats! ## 👨‍🚀 Project & Community It’s been a busy month! Along with a major XCP-ng release, our ecosystem is expanding, with VEEAM now supporting XCP-ng and our service offerings growing to meet diverse needs, and there’s even more on the horizon. ### XCP-ng 8.3 official release We're thrilled to unveil XCP-ng 8.3, the final installment in our 8.x platform series. This release is a pivotal moment for our community, paving the way for future advancements. The journey to bring XCP-ng 8.3 to life has been monumental, and the scale of our efforts highlights the dedication behind it: - 450 tasks tracked and managed within our Kanban board - 1,200 builds generated through our Koji build system - Over 1,000 messages exchanged in forums dedicated to testing (excluding countless related discussions) - Thousands of test runs executed to secure top-notch quality and performance - More than 11,000 pre-release ISO downloads by our community, reflecting your enthusiastic support [XCP-ng 8.3XCP-ng 8.3 marks the culmination of years of hard work, delivering new features, enhanced hardware support, and a solid foundation for the exciting innovations still to come.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOlivier Lambert![](https://xcp-ng.org/blog/content/images/2024/10/xcpng83release.jpg)](https://xcp-ng.org/blog/2024/10/07/xcp-ng-8-3/?ref=xen-orchestra.com) 💡 A more technically detailed version of the announcement can be found [in our official release notes](https://docs.xcp-ng.org/releases/release-8-3/?ref=xen-orchestra.com), we strongly suggest to read them. The dedicated blog post provides an overview on what's new, without entering into all the details. Also a big thanks to Tom who made a great Youtube video about it: ### Extending our service portfolio To support the varied requirements of our clients and partners, we are introducing a suite of professional services specifically crafted to facilitate the seamless integration and use of Vates VMS. These services are thoughtfully tailored to meet the distinct needs of both prospective and current customers, whether they engage directly with Vates or through our trusted network of expert partners. In other words, you’ll have access to Technical Account Managers, Consultants, and Project Managers to address all your needs. These experts are either directly part of the Vates team or certified professionals, ensuring you receive the highest standard of tailored support. [Expanding our service portfolio to empower your Vates VMS journeyVates is introducing new services to support complex use cases and help you get the most from your Vates VMS deployment.![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogMarc-André Pezin![](https://vates.tech/blog/content/images/2024/10/possessed-photography-jIBMSMs4_kA-unsplash.jpg)](https://vates.tech/blog/expanding-our-service-portfolio-to-empower-your-vates-vms-journey/?ref=xen-orchestra.com) ### VEEAM support for XCP-ng VEEAM has released a first working prototype compatible with the XCP-ng API, announced personally by their Chief Product Officer: [![](https://xen-orchestra.com/blog/content/images/2024/10/image.png)](https://forums.veeam.com/post531802.html?ref=xen-orchestra.com#p531802) While we handle backups with Xen Orchestra at Vates, we’re thrilled to see our ecosystem expanding. The feedback from VEEAM's developers has been excellent, and we’re optimistic this will move beyond a prototype in the coming months. We’ll continue to monitor the progress closely and offer support to VEEAM as needed. ### Does Vates VMS scale? As we continue to support increasingly large customers and infrastructures, we’re often asked, “Does it scale?” In this blog post, we aim to answer that question. Spoiler alert: it does. This example showcases a major online travel company handling millions of requests daily: a true testament to Vates VMS's robust scalability. [Leading online travel platform builds massive, scalable internal cloud with Vates VMSAn industry-leading online travel company creates a global, scalable, and cost-effective internal cloud infrastructure using XCP-ng and Xen Orchestra, managing over 2,000 hosts across two continents and leveraging the Xen Orchestra API for centralized management and streamlined automation.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOlivier Lambert![](https://xcp-ng.org/blog/content/images/2024/10/nils-nedel-ONpGBpns3cs-unsplash.jpg)](https://xcp-ng.org/blog/2024/10/08/leading-online-travel-platform-builds-massive-scalable-internal-cloud-with-vates-vms/?utm%5Fcampaign=mail%5F5.100&utm%5Fterm=userstory&utm%5Fsource=image) ### Project management: switching to Plane We are proud to use self-hosted software to build our own company and products. In our case, we were using [WeKan](https://wekan.github.io/?ref=xen-orchestra.com) before. As our team grew a lot, we needed something more flexible and scalable. So we decided to switch to Plane, and we are really happy about it. It's still a young project, but each release provides a huge number of improvements, so we are confident about it. 💡 We are proud customers of the Pro Offer with a self-hosted setup. You can find more details on their website: [https://plane.so/](https://plane.so/?ref=xen-orchestra.com) ![](https://xen-orchestra.com/blog/content/images/2024/10/plane.jpg) The Kanban view for the XO project ### XO team growing rapidly It's not just Vates experiencing rapid growth—our XO team is expanding at an impressive rate, too! We’ll share the final 2024 numbers soon, but the progress is clear. Recently, we welcomed two new VueJS developers, Joris and Sebastian, who are diving into work on our new UI. Our backend team also gained a valuable member, Stéphane, and we’re thrilled to have Thomas as our new Technical Writer. And the expansion doesn’t stop there! With more team members set to join soon, we’re on track to triple the team size in less than a year. ![](https://content.vates.tech/assets/partner-min.png) --- And now back on our monthly release! ## 💾 Backup In addition to regular bug fixes, we're dedicating efforts to enhancing the existing code base, further boosting stability and reliability. ### Better old XenServer support (<7.3) without CBT We've fixed an issue that could block VHD backups if Changed Block Tracking was not available. Some older XenServer versions don't support CBT, but this should not stop your VHD exports. Now, if CBT isn't enabled or if there is no Network Block Device (NBD) network, your legacy VHD backups can continue without any problems. This fix provides a smoother experience for users with legacy systems while seamlessly maintaining backup functionality. ### Chained backup optimizations After a month since the initial release, we’ve fine-tuned backup chaining, reducing re-transfer in certain scenarios. It’s now even more efficient and resilient! ## 🛰️ XO 6 The major overhaul of XO is steadily advancing, and with more developers on board, the pace of progress is set to accelerate even further. #### Server status The Server Status card is a new addition to the XO 6 Dashboard. It provides a quick, comprehensive view of server health and operational status in Xen Orchestra. This card makes it easy to monitor key metrics at a glance, keeping administrators informed and simplifying routine checks across multiple servers. ![](https://xen-orchestra.com/blog/content/images/2024/10/349554793-6327832e-fa3a-469e-841b-bf91b9cdff6b.png) #### New components This release introduces several new UI components that, while currently behind the scenes, provide the foundation for future views and interactions within Xen Orchestra. These elements set the stage for an even more dynamic, user-friendly interface as they're rolled out in future updates. Stay tuned for new enhancements to the Xen Orchestra experience! 💡 You can find all the components that are a "work in progress" on our Github with [this filtered search](https://github.com/vatesfr/xen-orchestra/pulls?q=sort%3Aupdated-desc+is%3Apr+is%3Aopen+label%3A%22XO+Web+Core%22&ref=xen-orchestra.com). There's so many different components worked on that we can't sum them up in here, but our small gallery will give you a hint: ![](https://xen-orchestra.com/blog/content/images/2024/10/341702023-5818c8d2-d120-43da-92ea-55ee67451c8f.png) ![](https://xen-orchestra.com/blog/content/images/2024/10/341702017-aa8bbb71-70d6-46c3-a621-87507aed2ed1.png) ![](https://xen-orchestra.com/blog/content/images/2024/10/376171627-a7361d93-9969-404d-84c9-3ad2e64d66f0.png) ![](https://xen-orchestra.com/blog/content/images/2024/10/380183222-41a3f83f-2d4f-43f6-aeab-a2cb34652089.png) #### Behind the scenes In XO 6 & XO Lite, we’ve overhauled the contribution process to be more accessible and user-friendly. With updated documentation and clearer guidelines (particularly for `web-core` components), outside developers can now contribute with ease and confidence. We’ve also established consistent coding standards and templates, ensuring alignment across all contributions. These updates foster collaboration, making it simpler to share ideas and code, which ultimately strengthens our community and fuels innovation. While this long-term work does require some resources in the short term, it’s a commitment to building a future-ready product—for both Vates and our community. ## 🔭 XO Lite We're continuing our work on XO Lite, refining the UX design for the networking features and enhancing the capabilities of XO Deploy. ### Deploy XOA with custom NTP servers XO Lite now supports the addition of custom Network Time Protocol (NTP) servers during XOA deployment. This enhancement allows you to specify your preferred time servers to ensure accurate time synchronization across your infrastructure. It's a small change that can make a big difference in maintaining the integrity of your systems. Enjoy greater flexibility and control over your NTP settings! ![](https://xen-orchestra.com/blog/content/images/2024/10/377502214-dfb2a9c0-3a80-4e88-96df-b3c3ab977de6.png) Custom NTP servers ### Network management UX Since last month, we’ve made significant progress on the UX mockups for network management. With most screens now designed, we're close to moving into the next exciting phase: implementation! ![](https://xen-orchestra.com/blog/content/images/2024/10/Capture_2024-10-31_10_36_34.png) ![](https://xen-orchestra.com/blog/content/images/2024/10/Capture_2024-10-30_11_12_25.png) ![](https://xen-orchestra.com/blog/content/images/2024/10/Capture_2024-09-30_15_38_33-1-.png) ## 🪐 XOA & XO Proxy This month, we’ve rebuilt our virtual appliances, equipping them with expanded capabilities right out of the box. ### Multiple DNS server support We've added support for multiple DNS servers during initial setup in XOA. By configuring multiple DNS servers, you can improve the redundancy and reliability of name resolution, ensuring a more robust network configuration from the start and streamlining the management of your infrastructure. ### CLI: New network ntp command We're pleased to introduce the `network ntp` command. This new feature simplifies the management of Network Time Protocol (NTP) settings directly from the command line interface. Accurate time synchronization is critical to maintaining consistency across virtual environments, making this a valuable tool for improving system reliability and ensuring accurate timekeeping in logs and network operations. 💡 This command is also available for the XO Proxy Appliance. ### New Proxy appliance We're happy to announce a new proxy for Xen Orchestra based on Debian 12\. This new appliance replaces the older version that had some limitations. The updated proxy improves connectivity and performance, making it easier to effectively manage remote hosts. For those interested in how proxies work, you can explore their benefits further in our [Concrete guide to XO proxies](https://xen-orchestra.com/blog/xo-proxy-a-concrete-guide/). ## 📡 REST API With each release, our REST API continues to expand. This month, we’ve added two new features: authentication token management and the ability to create VMs using CloudInit. ### Authentication tokens Xen Orchestra 5.100 introduces a powerful new feature in the REST API: **authentication token creation with strong security**. To create tokens, users need to authenticate with a password or, if enabled, a one-time password (OTP), adding a robust layer of protection to your automated workflows and integrations. Tokens can be configured for short or long-term access, providing flexibility without compromising security, especially useful for recurring scripts or temporary access scenarios. Here's an example, eg to create an authentication token with a POST request to `/rest/v0/users/authentication_tokens`. First, the `--user username:password` flag sends user credentials in the HTTP request for authentication. Then, the `-H` option sends a header specifying the `Content-Type` as JSON. Use the `-d` option to add a body to the request with optional token details, like client name, description, and expiration time (in milliseconds). The result: ``` curl -X POST http://xoa.localdomain/rest/v0/users/authentication_tokens?otp=1234 \ --user foo:bar \ -H "Content-Type: application/json" \ -d '{"client": "some-client", "description": "some-description", "expiresIn": 60000 }' ``` Great! Now you can retrieve the user’s existing tokens with a GET request to `/rest/v0/users/authentication_tokens`: ``` curl http://xoa.localdomain/rest/v0/users/me/authentication_tokens \ --cookie "token=some-token-id" \ -L ``` 💡 Use the `/users/me` alias to redirect automatically to the user’s specific ID endpoint. If the user doesn’t know their ID, they can access `/rest/v0/users/me/authentication_tokens`,which redirects them to GET `/rest/v0/users/authentication_tokens`. The `--cookie` option sends the token ID for authentication. ### VM creation with Cloud-Init support We’ve enhanced the REST API by adding Cloud-Init support for VM creation. This feature simplifies the setup of virtual machines by automating their initialization and configuration, making it easier to manage cloud environments at scale. With Cloud-Init, administrators can now customize VMs at creation, ideal for scripting initial configurations or deploying standardized setups. This feature represents a significant increase in automation and flexibility for Xen Orchestra users. Here's an example: ```curl curl --cookie "token=" \ -H "Content-Type: application/json" \ -X POST http://localhost:9000/rest/v0/pools//actions/create_vm \ -d '{"name_label":"mra-rest-api", "template":"", "cloud_config":"#cloud-config\nhostname: Debian-12-Cloud-init-(Hub)\nssh_authorized_keys:\n - ssh-rsa AAAA...", "boot":true, "destroy_cloud_config_vdi": true}' ``` To know more, check out the [Cloud-Init website](https://cloud-init.io/?ref=xen-orchestra.com). ## 🐦 VMware to Vates (V2V) Previously, warm migrations from VMware ESXi to Vates could encounter session timeouts, particularly during the final steps when the VM shuts down and the last snapshot transfers. This update brings a more resilient approach, automatically refreshing the session to avoid interruptions and ensure a smoother migration process. By maintaining an active connection throughout the data sync, the final snapshot handoff is now less likely to encounter delays or errors, making V2V migrations more reliable and efficient. ## **🆕** Misc Our "Misc section" is packed with updates this month! And with our continued growth, you can expect it to keep expanding. ### Fix tooltip disappearing We've fixed an issue where tooltips would randomly disappear. This fix ensures that users can rely on consistent and informative tooltips. No more losing valuable context or guidance as you navigate the interface! This improvement is part of our ongoing commitment to refining the user experience and making your workflow smoother. ### Home/VMs filter by MAC address We've introduced a new filter that allows Xen Orchestra Appliance (XOA) users to locate a VM by MAC address. Simply enter the MAC address in quotes (e.g., `"70:1A:83:62:90:D0"`), and you’ll get a streamlined list of matching VMs—perfect for identifying specific machines within large environments or troubleshotoing connectivity issues more efficiently. ![](https://xen-orchestra.com/blog/content/images/2024/10/image-2.png) ### Hide PVS accelerator in orphan VDIs We've improved the dashboard by hiding PVS accelerators associated with orphaned virtual disk images (VDIs). These VDIs, used by Citrix Provisioning Services, serve as a temporary cache and are not associated with any virtual machines. This change helps users focus on relevant information without unnecessary distractions, resulting in a cleaner and more intuitive dashboard experience. ### Synchronized descriptions and comments in Netbox We've added a handy feature to synchronize the new "description" field in Netbox between XO and Netbox. This enhancement ensures that any changes made to this new field in your Xen Orchestra configuration is automatically reflected in Netbox, keeping everything consistent and up to date. This feature streamlines your workflow and improves your ability to effectively manage your resources. To learn more about Netbox, read our [Netbox synchronization with XO DevBlog](https://xen-orchestra.com/blog/netbox-sync-with-xen-orchestra/)! ### Filter object selectors by tags We're pleased to introduce a new feature that allows users to filter object selectors by tags in access control lists (ACLs). This enhancement is in direct response to user requests for more granular control over user and group access to virtual machines (VMs) based on specific tags. With this functionality, you can now create customized permissions that meet your organization's needs, making it easier to efficiently manage access rights. ![](https://xen-orchestra.com/blog/content/images/2024/10/379194417-8a97e216-cf73-4def-8dbb-2376aac3cbc1.png) ### New Cloud-init Template Variable : {index} This release introduces the `{index}` Cloud-init template variable, as a more compatible alternative to the `%` variable, which could interfere with Jinja templating. To ensure a smooth transition, `%` will continue to work for workflows with multiple VMs enabled, but is now marked as deprecated. This update improves compatibility and reliability when automating VM deployments using cloud-init with Xen Orchestra. To know more about Jinja, check out [their official website](https://jinja.palletsprojects.com/?ref=xen-orchestra.com). ### Xen Orchestra 5.99 URL: https://xen-orchestra.com/blog/xen-orchestra-5-99/ Last updated: 2024-09-30T16:59:03.000Z Summer’s officially behind us (in our hemisphere at least), and we’ve got a solid new release to show for it. The sheer size of this blog post speaks for itself—it’s been a packed month full of features and announcements. At this rate, I can’t help but wonder how we’ll handle releases in 2025 with the growing team delivering more and more features. I’m starting to feel like I’m writing a book every month! ## 👨‍🚀 Project & Community In true French fashion, September is always one of the busiest months of the year. Whether it’s big announcements or new team members, we’ve blown past all expectations. But don’t worry, we’ll break it all down step by step! ### Our stack in the Gartner Virtualization Guide Vates has been recognized as a Representative Vendor in the 2024 Gartner® Market Guide for Server Virtualization. This highlights our commitment to reliable and innovative virtualization solutions. As the market shifts, particularly after VMware's acquisition by Broadcom, this report offers valuable insights to help you stay ahead. Check the link to download your free copy today! [Vates - A Representative Vendor in Gartner’s 2024 Server Virtualization Guide![](https://vates.tech/apple-touch-icon.png)A Representative Vendor in Gartner’s 2024 Server Virtualization GuideMarket Guide for Server Virtualization (Gartner, 2024)![](https://vates.tech/assets/img/logos/logo-vates.png)](https://vates.tech/gartner-virtulization-guide/?ref=xen-orchestra.com) ### Protectli partnership It’s been four years since we first teamed up with Protectli, bringing their popular "Vault" devices into the spotlight. Over time, our partnership has only grown stronger, driven by a shared commitment to delivering reliable, high-performance hardware that plays perfectly with XCP-ng. This synergy between Protectli and XCP-ng means our users get hardware that’s thoroughly tested, certified, and optimized for their setups. More details in the blog: [New certified Protectli devicesDiscover the power and versatility of Protectli’s new fanless Vault devices, pre-installed with XCP-ng, perfect for edge computing, network security, and more.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOlivier Lambert![](https://xcp-ng.org/blog/content/images/2024/09/protectli.jpg)](https://xcp-ng.org/blog/2024/09/30/new-certified-protectli-devices/?ref=xen-orchestra.com) ### Helping Alike users to transition to XO With Quadric Software shutting down and ending support for Alike Backup, a lot of businesses are now scrambling for a reliable backup solution. Alike was a go-to for XCP-ng and XenServer users, but now, Xen Orchestra is ready to step in as the perfect replacement. If you are a Alike user, don't miss this announcement and the offer in it: [Transitioning from Alike Backup to Xen OrchestraIf you are an Alike user, find all the help you need to migrate to Xen Orchestra for your backup.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogMarc Pezin![](https://xen-orchestra.com/blog/content/images/2024/09/alike-transition.webp)](https://xen-orchestra.com/blog/transitioning-from-alike-backup-to-xen-orchestra/) ### XCP-ng 8.3 RC2: the final lap! We’re thrilled to roll out the second release candidate (RC2) for XCP-ng 8.3! This is the last stop before the official release. Don’t miss our latest blog post for all the details on what’s packed inside and what’s coming next! [XCP-ng 8.3 Release Candidate 2XCP-ng 8.3 RC2 is here, with key fixes, security updates, and improved hardware support. We’re in the final testing phase: join us in ensuring a smooth official release!![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogSamuel Verschelde![](https://xcp-ng.org/blog/content/images/2024/09/xcpng83rc2b-1.jpg)](https://xcp-ng.org/blog/2024/09/17/xcp-ng-8-3-release-candidate-2/?ref=xen-orchestra.com) ### Xen & RISC-V: what's up? At Vates, we’re all in on driving forward the progress of Xen and the RISC-V architecture. RISC-V, the fast-growing open-source hardware architecture, is making waves thanks to its flexibility, scalability, and openness—values that resonate deeply with our mission of promoting open development ecosystems. You can dive into the current state of things in our latest blog post: [Advancing Xen on RISC-V: key updatesWe’re making significant progress in porting Xen to the RISC-V architecture by integrating common code, refining bit operations, and updating CI containers, with ongoing work in interrupt handling, device passthrough, and more.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOleksii Kurochko![](https://xcp-ng.org/blog/content/images/2024/09/riscvlatest.jpg)](https://xcp-ng.org/blog/2024/09/23/advancing-xen-on-risc-v-key-updates/?ref=xen-orchestra.com) ### Growing the team Vates is on a growth spurt—faster than ever, really. Over the past two years, we’ve tripled in size, going from a team of 20 to now over 60 people working with or for us, spread across multiple continents and more than six different countries. And this is just the beginning. It’s a clear sign of our commitment to delivering more, and at an even faster pace. I had initially planned to introduce all the new faces, but honestly, with the sheer number of new arrivals, that’s become a bit impossible. And by the looks of it, that trend isn’t slowing down anytime soon. ![](https://xen-orchestra.com/blog/content/images/2024/09/astro-1.png) ### Beyond support We’re gearing up to introduce some exciting new services tailored for our bigger and more demanding customers. While we’re not ready to share all the details just yet, think of it as going the extra mile: services that cater to specific needs and provide assistance beyond traditional support. For instance, we’re exploring options like offering dedicated Technical Account Managers, personalized guidance, and specialized consulting to help you tackle unique requirements and optimize your infrastructure. Stay tuned for more on what’s coming! [![](https://xen-orchestra.com/blog/content/images/2024/09/vateslogo.png)](https://vates.tech/?ref=xen-orchestra.com) --- And now, all the details about September's release. ## 💾 Backup Backup is still one of our central effort, and we have not forgotten to deliver this month. ### Chained backups We've taken our backup capabilities to the next level with a new feature called "Sequence." While our "mirror backup" feature has been around for a while, **now you can chain multiple backup jobs to run one after the other automatically**. Once your first job finishes, the next kicks off seamlessly. For example, you can run your primary backup to local storage, and when that’s done, it’s automatically mirrored to offsite storage with different retention policies—no need to worry about timing, even if the first job takes longer than expected. Problem solved! You can also set up a replication job after a regular backup (or vice versa) for similar convenience. 💡 It’s still a good practice to keep your existing backup jobs intact, especially if they contain many VMs, rather than breaking them into dozens of smaller jobs and trying to chain them all. This new feature is really meant to simplify how you manage different levels of retention across multiple storage systems—not to overcomplicate your backup strategy. Keep in mind that chaining backup won't change the current reports and notifications: it's still one per job. To configure a chained backup, create a new sequence on your existing jobs: ![](https://xen-orchestra.com/blog/content/images/2024/09/371203187-1f6aa2ec-aabe-4cd7-b44c-3e5e1cb2ba64.png) Then you can see it in the backup view: ![](https://xen-orchestra.com/blog/content/images/2024/09/371084866-538e92db-7871-4be9-aca9-565048e883f7.png) ### More details in the backup view In the backup view, you can now see more info about your existing jobs at a glance. We’ve added key details directly in the overview, so you don’t have to click into each job to check the most important data. It’s another step towards making it quicker and easier to manage your backups without diving into the details every time. ![](https://xen-orchestra.com/blog/content/images/2024/09/365685916-dc5a08f1-3b78-4fec-9ba0-a7a872915616.png) ## 🛰️ XO 6 More than building components, since few months, we started to actually deliver them in a usual fashion. Explore what's new! 💡 To access the new preview UI, just add `/v6` in your XOA URL. If you are using it from the sources, you can build it with `yarn run turbo run build --filter @xen-orchestra/web` from the XO root folder. ### Updated design system colors We’ve made some slight tweaks to our design system colors to improve visibility and make the interface more user-friendly. These updates should enhance your overall experience without disrupting the familiar look and feel! ![](https://xen-orchestra.com/blog/content/images/2024/09/new-colors-dark-mode.png) ![](https://xen-orchestra.com/blog/content/images/2024/09/new-colors-light-mode.png) ### Dashboard additions Many components where added to the Dashboard view. But let's see first a global screenshot: ![](https://xen-orchestra.com/blog/content/images/2024/09/02-XO-6-dashboard-after.png) It’s not quite finished yet, but we’re getting there! What’s really exciting is that we’re not just adding components to fill space—we’re introducing powerful tools to help you track vital information about your infrastructure in a meaningful way! Let's check that in details. #### Backup issues panel We’ve introduced a quick overview panel to track your last three backup jobs at a glance. You’ll easily see if they succeeded or failed, with color coding: red for failures, orange for warnings, and green for successful jobs. This gives you an instant snapshot of your backup health without needing to dive into details. ![](https://xen-orchestra.com/blog/content/images/2024/09/365570567-5749cced-415d-43a7-8418-2ff8c6d7aa2b.png) #### VM protection You can now quickly see how many VMs are protected by the XO backup system at a glance. ![](https://xen-orchestra.com/blog/content/images/2024/09/370624030-1187a578-ff0f-4fcf-a7e2-8a0601bf7ec2.png) Here’s how it works: - **Protected:** the VM is included in at least one active job with a successful last execution. - **Unprotected:** the VM is in a job, but either the schedule is disabled or the last execution failed. - **Not in job:** the VM isn’t part of any job or has the `xo:no-bak` tag. This helps you instantly identify which VMs are properly backed up and which might need attention. #### S3 backup repository info You can now quickly see how much data is used for all your S3 backup repositories. ![](https://xen-orchestra.com/blog/content/images/2024/09/370356290-013a91af-1e29-4534-8351-4863b865452c.png) #### Resources overview We’ve introduced a dedicated panel that provides a clear summary of all the resources in your infrastructure, including RAM, CPU usage, and storage repository space. ![](https://xen-orchestra.com/blog/content/images/2024/09/370741511-1c4e9c90-64bb-4927-b5cb-596dc8925cd5.png) ## 🔭 XO Lite We’re currently focused on adding network configuration capabilities to XO Lite, making it easier to set up your hosts even before you have access to the full XO. So we wanted to share a mockup with you: ![](https://xen-orchestra.com/blog/content/images/2024/09/Capture_2024-09-30_15_38_33.png) ![](https://xen-orchestra.com/blog/content/images/2024/09/Capture_2024-09-30_15_37_31.png) ![](https://xen-orchestra.com/blog/content/images/2024/09/Capture_2024-09-30_15_39_49.png) This work is also paving the way for the new UI coming in XO 6, so stay tuned! ## 🪐 XOA ### Stable now at version 5.98 CBT (Changed Block Tracking) is now part of the XOA stable release! However, proceed with caution—start by using it on a subset of your backup jobs. We’ve noticed potential bottlenecks when detaching VDIs from the control domain if you’re using NBD with a concurrency greater than one. As with any new feature, take it slow and gradually migrate to it to prevent issues on a larger scale. ### Custom NTP servers on deploy We’ve added support for setting custom NTP servers during deployment, giving you more flexibility in configuring time synchronization right from the start. Additionally, we’ve switched from using Chrony to systemd-timedatectl, a more lightweight NTP client, to handle your system’s time settings. This change reduces resource usage while still ensuring your servers maintain accurate time, which is crucial for a healthy infrastructure. By customizing your NTP setup during deploy, you can ensure alignment with your organization’s time management policies or use more trusted, internal NTP servers, even in air gap scenarios. ### XOA updated We recently rebuilt the virtual appliance with the latest Debian updates, along with the new deploy capabilities we’ve talked about, including support for custom NTP servers. It’s all part of keeping things up-to-date and making sure your deployments are as smooth as possible! ## 🖥️ XO CLI We’re also continuing to improve the XO CLI for various use cases. Now, you can use it to download a file while monitoring detailed transfer speeds right in your terminal: ``` $ xo-cli rest get --output vdi.vhd vdis/1b1cf96e-85f6-41c1-8366-7f3294c913b0.vhd 3.57 MiB @ 2.38 MiB/s 11.26 MiB @ 4.5 MiB/s 23.04 MiB @ 6.58 MiB/s ``` It works the other way too: when you upload a file using the new `--input` parameter, you'll still see all the progress details, making file transfers more transparent and user-friendly. ``` $ xo-cli rest post --input vdi.vhd srs/86a9757d-9c05-9fe0-e79a-8243cb1f37f3/vdis 0% of 1.27 GiB @ 1.83 MiB/s - ETA 11m 49s 1% of 1.27 GiB @ 4.57 MiB/s - ETA 4m 42s 3% of 1.27 GiB @ 9.75 MiB/s - ETA 2m 10s ``` ## 📡 REST API The REST API is evolving quickly, with development more active than ever, especially since it’s now powering XO 6 directly. Expect more updates and improvements as we continue to enhance the API! ### Dedicated Alarms endpoint To reduce traffic on general endpoints like "dashboard," we’ve moved alarms to their own dedicated endpoint. Since alarms can generate a lot of data, this change helps streamline things. Now, you can easily access them by hitting `/alarms` to see the full list, and if you want details on a specific alarm, just do a GET request on `/alarms/`. This should make managing alarms more efficient and less of a burden on the system. ### Changes in the `dashboard` enpoint We’ve made several updates to the dashboard endpoint, delivering more detailed information across the board. These include: - S3 backup repository size - Expanded backup repository info for non-S3 storage, like backup size and additional details - Protection status for VMs - An overview of resource usage These updates give you a clearer snapshot of your infrastructure right from the dashboard endpoint (end the UI of XO 6). ## 🛡️ Air gap features We’ve updated our documentation to cover deploying XOA in a fully air-gapped environment, including using our Deploy Script offline. Check out the docs for all the details on how to set it up in a fully isolated setup! [Airgap support and deployment | XO documentationOfficial Xen Orchestra documentation![](https://xen-orchestra.com/assets/favicon.ico)XO documentation![](https://xen-orchestra.com/blog/content/images/2017/05/xo-logo.png)](https://xen-orchestra.com/docs/airgap.html?ref=xen-orchestra.com) ## **🆕** Misc Many quality of life improvements and new views in the existing UI of XO 5. ### Network view: VLAN search Now, you can filter VLANs directly in the Network view! Just use the search filter—type something like `VLAN:10` and you’ll see all the network objects associated with VLAN 10\. It’s also handy for sorting networks by VLAN number right in the UI, making it easier to manage your setup. ### Display a warning for hosts with TLS key too small This is mostly a legacy issue. When upgrading to XCP-ng 8.3, you may need to regenerate your TLS key if it was created a few years ago, as the key length might be too short by today's standards. This usually affects installations done before XCP-ng 8.2.1\. To avoid any surprises, we’ve added a warning in the Home/Host view of the UI, so you’ll know if your TLS key needs an update. ![](https://xen-orchestra.com/blog/content/images/2024/09/369005485-be41105b-6a88-4a01-8cb5-e5889c740799.png) The warning is visible in your Home/Host view ![](https://xen-orchestra.com/blog/content/images/2024/09/369005697-ed356425-8ff8-482b-9a00-e424b3bd5fdb.png) If you used the default certificates during the XCP-ng install, make sure you’re running XCP-ng 8.2.1 or higher, then run `xe host-emergency-reset-server-certificate` on each host in your pool. If you’re using custom certificates, you’ll need to import new ones with a key length of at least 2048 bits. If you have any doubt, please open a support ticket for further assistance. ### Display bond mode In the Pool/network view, you can now see directly what kind of bond mode is used: ![](https://xen-orchestra.com/blog/content/images/2024/09/371172653-7a344464-5e63-4b7b-93d6-fb3d38d685bf.png) As a reminder, XCP-ng supports active-active, active-passive and LACP bond modes. ### Netbox support for version 4.1 XO has a solid plugin that syncs a ton of data to Netbox, like VM names, descriptions, disks, IP addresses, and more. For more details, check out [our docs](https://xen-orchestra.com/docs/advanced.html?ref=xen-orchestra.com#netbox). Back in July, we announced support for Netbox 4.0 with our sync plugin, though we had to deal with a bunch of undocumented breaking changes. Now with Netbox 4.1, they’ve broken things again (but at least it’s documented this time!). So, we’ve made our code more flexible to handle the different versions more smoothly. ### Removable XO Tasks You can now remove tasks directly in the task view! We're also working on reducing the number of failed tasks, so instead of hiding them, you can now clean them up if they pile up. However, make sure to check if any of those failed tasks point to an underlying issue. ![](https://xen-orchestra.com/blog/content/images/2024/09/image-1-.png) ### Transitioning from Alike Backup to Xen Orchestra URL: https://xen-orchestra.com/blog/transitioning-from-alike-backup-to-xen-orchestra/ Last updated: 2024-09-16T07:36:44.000Z With the announcement of Quadric Software’s closure, removing commercial support for Alike Backup, many businesses are now faced with the challenge of finding a reliable, future-proof backup solution for their virtual infrastructure. While Alike Backup has long been a trusted tool for managing backups in **XCP-ng** and **XenServer** environments, Xen Orchestra presents itself as the ideal successor for this type of infrastructure, offering advanced features and being natively compatible with your existing infrastructure. 🆘 To ease the transition and offer some peace of mind for every Alike user experiencing the need for a quick change in their backup strategy, we are offering a special ****6-month free trial period** with access to our ****Pro Support team**. We’ll help you build your migration strategy and give you extra time to make the transition smoother. ## 🙏 A word about Alike We want to take a moment to thank the Alike team for their incredible work over the years. During discussions with their team, we found ourselves aligned on many philosophical aspects, especially the commitment to their customers. Also, we deeply appreciate that before ending their activities, Alike has chosen to make their code open-source. This decision ensures that years of development and innovation won’t just disappear, keeping the door open for the community to continue building on their foundation. It's this very spirit of open source that we admire and embrace at Vates. The light remains on for Alike, and we’re proud to be part of the same open-source ecosystem that values collaboration, transparency, and longevity. We also want to extend our best wishes to everyone at Quadric Software, the team behind Alike, as they embark on new journeys. Your contributions have left a lasting mark on the virtualization community, especially the Xen one, and we hope to see continued success in your future endeavors. ## ✅ **Choosing Xen Orchestra as your Alike alternative** Xen Orchestra has long been recognized as a powerful solution tailored specifically for managing XCP-ng and XenServer environments. With robust backup features, it offers an all-in-one platform for seamless virtual infrastructure management. ### **Comprehensive backup features** ![](https://xen-orchestra.com/blog/content/images/2024/09/backup-features-update-2023.png) Xen Orchestra offers a range of backup options designed to fit your business needs, ensuring maximum flexibility and security for your virtual machines: - **Full backups**: Create a complete backup of your VM's disk and metadata, ensuring that no critical information is missed. - **Incremental backups**: Save time and storage by only backing up changed data, speeding up the process and reducing resource usage. - **Incremental replication**: Stay protected with near real-time data replication to ensure your infrastructure remains resilient. - **Encryption**: Protect your backups with end-to-end encryption, securing your data both in transit and at rest. - **Backup scheduling and retention**: Set up regular, automated backups with full control over scheduling and retention policies. - **Mirror backup:** add a specific schedule for replicating your backup to another place, like an encrypted S3 storage outside your datacenter. These features ensure that your virtual environments are secure, efficient, and easy to manage, offering very similar options as the one you had with Alike. 💡 Xen Orchestra is a fully agentless tool ! ### **Seamless transition for Alike Backup users** We understand that migrating from one platform to another can be daunting, especially when it comes to crucial services like backup solutions. That’s why at Vates, we are committed to making this transition as **smooth** and **stress-free** as possible for users migrating from Alike to Xen Orchestra. We'll provide assistance with our expert team, to help you at every step of the way, ensuring that your data is backup efficiently and securely with Xen Orchestra. The easiest transition path is to have backup done by both tools for a while, so you can be confident enough during the free 6 months trial until you are out of support from Alike. If you want to be contacted by our team to start your POC, fill this form: ### Xen Orchestra 5.98 URL: https://xen-orchestra.com/blog/xen-orchestra-5-98/ Last updated: 2024-08-30T12:31:39.000Z The August release has just arrived! As we prepare to step into September, explore the latest updates in our ecosystem, along with all the exciting new features and enhancements in our latest XO 5.98 release. ## 👨‍🚀 Project & Community August was a bustling month for us, filled with numerous exciting announcements. Let's recap some of the highlights. ### Xen 4.19 The core hypervisor we utilize in XCP-ng, Xen, has been updated to version 4.19\. We are especially proud to share that a member of our team at Vates served as the official release manager for this update! For more details about the release and our contributions, be sure to check out our dedicated blog post: [Xen 4.19 is releasedWe are proud to deepen its involvement in the Xen community with the 4.19 release, contributing significant advancements and shaping the future of open-source virtualization.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOlivier Lambert![](https://xcp-ng.org/blog/content/images/2024/08/xen419-1.jpg)](https://xcp-ng.org/blog/2024/08/28/xen-4-19-is-released/?ref=xen-orchestra.com) ### XCP-ng High Availability: a guide High Availability (HA) can be a solution for maintaining a stable and reliable infrastructure, especially in environments where uptime is critical. Our newly released guide on XCP-ng High Availability offers an in-depth exploration of everything you need to implement and manage HA effectively. From understanding the core concepts and requirements to configuring your XCP-ng setup for optimal resilience, this guide covers it all: [XCP-ng High Availability: a guideLearn how to implement and manage High Availability in XCP-ng with this quick and comprehensive guide, ensuring your virtual machines remain protected and operational under various failure scenarios.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOlivier Lambert![](https://xcp-ng.org/blog/content/images/2024/08/xcpngha.jpg)](https://xcp-ng.org/blog/2024/08/22/xcp-ng-high-availability-a-guide?ref=xen-orchestra.com) ### XCP-ng Security Updates Staying up-to-date with security is vital for keeping your systems protected. As always, we recommend applying the latest XCP-ng updates to ensure your environment remains secure. Our August security bulletin outlines the most recent patches and improvements, helping you safeguard your infrastructure against emerging threats. Dive into the details and make sure your systems are fully equipped to handle the latest security challenges. [August 2024 Security UpdatesSecurity updates for Xen and Intel microcodes.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogDavid Morel![](https://xcp-ng.org/blog/content/images/2024/08/ai-generated-8136172_1920.png)](https://xcp-ng.org/blog/2024/08/16/august-security-update/?ref=xen-orchestra.com) ### Vates Ignition Training & certification We are thrilled to announce the launch of our much-awaited training course, created in response to the strong demand from our passionate users and partners. This comprehensive course is specifically designed to empower IT professionals with the crucial skills needed to master the XCP-ng hypervisor and Xen Orchestra Appliance, key components of the Vates Virtualization Management Stack (VMS). Through this training, participants will gain hands-on experience and in-depth knowledge, enabling them to optimize their virtualization environments and enhance operational efficiency. Whether you're looking to deepen your expertise or achieve official certification, this course is your gateway to advancing your skills in the Vates ecosystem. [Vates Ignition Training - Mastering Vates VMSMaster XCP-ng and Xen Orchestra with our Vates Ignition Training. This course offers hands-on labs and expert guidance, perfect for IT professionals looking to deepen their virtualization management skills.![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogMarc-André Pezin![](https://vates.tech/blog/content/images/2024/08/alexander-grey-eMP4sYPJ9x0-unsplash.jpg)](https://vates.tech/blog/vates-training-master/?ref=xen-orchestra.com) 💡 If there are no available seats, don't worry! ****You'll automatically be placed on a waiting list** and notified as soon as a spot opens up or when we schedule new sessions in the coming months based on demand. ### Vates Partners: last updates Whether you're already a valued partner or looking to join our network, don't miss the latest news and enhancements from our partner program! We've made several exciting updates, including a more intuitive partner locator, numerous improvements to the partner portal, and streamlined renewal and upgrade features. These enhancements are designed to make collaboration easier and more efficient for all our partners. To learn more about these updates and how they can benefit you, be sure to check out our dedicated article. [Vates Partners Insight #1 - Latest updates for our partnersWe’re excited to unveil our revamped Partner Locator, new enhancements in the Partner Portal, and details about our upcoming training and certification program launching this September![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogMarc-André Pezin![](https://vates.tech/blog/content/images/2024/08/andrea-a8t_xj6bYvs-unsplash.jpg)](https://vates.tech/blog/vates-partners-insight/?ref=xen-orchestra.com) --- And now, without further ado, let's dive into what's new in the latest XO release! ## 💾 Backup Backup remains a top priority for us, reinforcing XO's position as a highly competitive solution, even when compared to fully dedicated backup products. With seamless integration into our virtualization stack, XO offers a robust, reliable, and efficient backup solution that ensures data protection without compromising on performance or ease of use. ### Mirror backup VM selection In this release, we're enhancing your control over backup strategies with the new ability to select specific VMs for mirror backups. You can now create a static list of VMs to replicate to another Backup Repository (BR), giving you a fine-grained policy for precisely managing what gets replicated. As usual, you can replicate to any kind of storage, including S3 and with encryption if needed. By default, the mirror job will work on all the VMs: ![](https://xen-orchestra.com/blog/content/images/2024/08/362681293-4871333d-1d30-45d9-8a1b-69c6ed1c5168.png) But now you can only select VMs you want to be mirrored: ![](https://xen-orchestra.com/blog/content/images/2024/08/362681361-53a59af9-a086-429f-803f-b493dfc4ed3a.png) This targeted approach not only helps reduce the size of replicated data, optimizing storage usage, but also allows you to focus on protecting your most critical assets. 💡 Stay tuned for even more flexibility, as dynamic filtering options will be coming in future updates to further refine your backup strategy! ### Backup report compact mode We're introducing a new compact mode for backup reports, designed to streamline your notifications and reduce information overload. By default, compact mode is enabled for chat-based reports, such as those sent to Slack. This mode provides a more concise summary, focusing only on essential details. ![](https://xen-orchestra.com/blog/content/images/2024/08/359844723-ee517beb-aac4-490d-a410-cd5523afd0a8.png) You can also opt to enable compact mode for email reports, which will keep them brief and to the point, highlighting key information only when something goes wrong. This ensures you're informed without being overwhelmed by excessive details, allowing you to focus on what truly matters. ![](https://xen-orchestra.com/blog/content/images/2024/08/359844202-ceb0f7c2-6802-4f3c-9a0e-dd3b177539b7.png) ## 🛰️ XO 6 Our efforts on XO 6 are continually bearing fruit, and this month, we're excited to roll out the official release of our new Dashboard, along with a minor yet impactful update to the tree view. These enhancements are designed to provide a more intuitive and efficient experience for managing your virtual environments. 💡 To access the new preview UI, just add `/v6` in your XOA URL. If you are using it from the sources, you can build it with `yarn run turbo run build --filter @xen-orchestra/web` from the XO root folder. ### New dashboard We're excited to introduce the first "real" XO 6 dashboard utilizing our new REST API! This latest update provides a comprehensive and dynamic view of your environment, giving you a powerful tool to monitor and manage your infrastructure with greater ease. ![](https://xen-orchestra.com/blog/content/images/2024/08/dashboard.png) It's a first draft, more components will come and fill those gaps in the future. Let’s break down each new component featured on this dashboard. First up, we have the **Updates/Patches Panel**: ![](https://xen-orchestra.com/blog/content/images/2024/08/359524025-74be7ae0-5861-4ebb-9a6a-dc818849479c.png) Additionally, the dashboard now features a **Storage Repository (SR) Usage Panel**: ![](https://xen-orchestra.com/blog/content/images/2024/08/359393270-8b45ae3d-1093-48be-9524-aacf9dc6b977.png) We've also added a new panel dedicated to backups. This **Backup Jobs Panel** provides a summary of all backup jobs and allows you to quickly identify any issues that need attention. With this panel, you can immediately see the status of your backup jobs, ensuring that your data protection strategies are running smoothly without any interruptions: ![](https://xen-orchestra.com/blog/content/images/2024/08/359898364-cada1847-9537-4e28-aa53-1611987a74f2.png) Following the same logic, you can now also monitor the space available on your **Backup Repository (BR)**: ![](https://xen-orchestra.com/blog/content/images/2024/08/359381074-ebbdd53c-cae6-4daf-9270-c30364fb9401.png) ### Tree view We've enhanced the tree view functionality to provide more immediate insights into your virtual environment. You can now directly see the number of running VMs under both Pools and Hosts in the tree view. ![](https://xen-orchestra.com/blog/content/images/2024/08/361790531-669ebeed-3da1-4d02-8e8e-c91072bca4ae.png) This improvement makes it much more convenient to monitor your resources, as it eliminates the need to expand each node to view the count of VMs or hosts within a pool or a host. With this update, you can quickly assess your infrastructure at a glance, saving time and simplifying management tasks. ## 🔭 XO Lite This month, we've brought the same tree view enhancements from XO 6 to XO Lite. Now, just like in XO 6, you can easily view the number of running VMs under Pools and Hosts directly in the tree view, providing a quicker and more streamlined way to manage your virtual environment. And that's not all: stay tuned for more exciting updates and features coming in the next release of XO Lite! ## 🪐 XOA This section covers everything related to the Xen Orchestra virtual Appliance (XOA), our all-in-one, turnkey solution for deploying Xen Orchestra. XOA offers a fully supported and streamlined way to manage your virtualization environment, providing a hassle-free setup and seamless integration with your existing infrastructure. ### Minor update on stable channel We've decided to keep the `stable` channel on version 5.95, applying only a few minor patches for now. This cautious approach ensures we maintain a reliable and fully functional environment for our users. Our goal is to release a robust, fully working CBT (Changed Block Tracking)-enabled backup solution on the stable channel when it’s completely ready. We anticipate that this exciting update will likely be part of the current release, ensuring a smooth transition and enhanced backup capabilities for our users. ### Improved IPv6 support for xoa Helper commands According to our [documentation](https://xen-orchestra.com/docs/xoa.html?ref=xen-orchestra.com#network-configuration), configuring the XOA network is straightforward and does not require deep Linux knowledge. With simple commands like `xoa network static`, you can easily set up your network preferences. In this release, we’ve enhanced the `xoa network static` command to provide better support for IPv6 configurations. This improvement ensures that users who are leveraging IPv6 in their environments can now configure their XOA network settings more effectively, bringing more flexibility and future-proofing to your infrastructure setup. ## 📡 REST API Since our new UI will rely almost entirely on our new REST API, we've introduced an extra endpoint specifically designed to render the dashboard. Although this endpoint isn't necessarily intended for direct use via an API call -given that it may evolve along with the UI- it still offers a valuable opportunity to experiment with and obtain interesting consolidated metrics. What makes XO 6 particularly compelling is the difference in how it handles data compared to XO 5\. In XO 5, the server's role is relatively basic: it sends a large volume of raw data to the client, which then performs the necessary operations, such as counting VMs and hosts. While this method is straightforward, it does not scale efficiently for very large infrastructures, as transferring all that data can significantly slow down performance and consume more bandwidth. Although XO 5 remains usable for setups with up to a few thousand hosts, we are always seeking ways to optimize and enhance its capabilities. **XO 6 introduces a smarter approach by shifting more processing to the server. Instead of sending all raw data, the server now performs the calculations and transmits only the specific numbers and information that the client requires.** This change not only reduces the amount of data transmitted, improving UI responsiveness and conserving bandwidth, but also enhances data security by minimizing the exposure of sensitive information. This streamlined, efficient data handling makes XO 6 a superior choice for managing modern, large-scale virtual environments. ### Dashboard metrics Now, you can directly request the new dashboard endpoint with a simple call, such as: ``` curl -X GET -b authenticationToken= 'http://xoa.example.org/rest/v0/dashboard' ``` This will return a variety of metrics that we currently use to construct the new XO 6 dashboard, such as: ``` { "nPools": 2, "nHosts": 2, "missingPatches": { "nHostsWithMissingPatches": 2, "nPoolsWithMissingPatches": 2 }, "backupRepositories": { "size": { "available": 48661643264, "backups": 0, "other": 0, "total": 527295578112, "used": 451773612032 } }, "storageRepositories": { "size": { "total": 5328658349056, "used": 1693077211136, "available": 3635581137920, "other": 0, "replicated": 0 } }, "backups": { "jobs": { "disabled": 1, "failed": 0, "skipped": 0, "successful": 0, "total": 1 }, "issues": [] }, "alarms": [ { "name": "fs_usage", "object": { "type": "VM-controller", "uuid": "deb21d26-d7c1-4b3a-b7b5-7dc3228b7d0c" }, "timestamp": 1721722374, "value": 0.95 }, ]… ``` ## 🐦 VMware to Vates (V2V) We've made a few minor updates and bug fixes to our V2V (Virtual-to-Virtual) conversion tool, designed to simplify the process of migrating virtual machines from VMware to the Vates Virtualization Management Stack (VMS). ### Better template configuration One of the key improvements involves better template configuration. The tool now automatically adjusts the minimum static memory setting based on the selected template, ensuring that the recommended values from the template itself are used. This helps to get coherent memory values in XCP-ng. ### Migration check-list To assist you further, we've also published a comprehensive VM migration checklist. Before you begin using the V2V tool, we strongly encourage you to review this checklist. It provides crucial steps and considerations to help you avoid common pitfalls and save valuable time during your migration efforts: [Vates Knowledge Base - Vmware migration checklist![](https://help.vates.tech/favicon.ico)Vmware migration checklist![](https://help.vates.tech/api/v1/attachments/269690)](https://help.vates.tech/kb/en-us/37/133?ref=xen-orchestra.com) ## **🆕** Misc Welcome to our usual "Miscellaneous" section, where we highlight the latest new features and enhancements that have been added to the XO 5 user interface. ### Excluding objects in Perf Alert plugin We've introduced a new feature in the Perf Alert plugin that allows you to exclude specific objects, such as hosts, from your alert configuration. This enhancement gives you greater flexibility in managing alerts by preventing unnecessary notifications for certain pools or hosts. It's particularly useful for scenarios where most of your infrastructure needs to be monitored, but you want to exclude specific components from triggering alerts. With this update, you can tailor your monitoring strategy more precisely to suit your operational needs. ![](https://xen-orchestra.com/blog/content/images/2024/08/361487207-f9271053-2d6d-451d-b029-b299116be1e6.png) ### Improved VM list sorting by install-time We've enhanced the sorting functionality for VM lists by "install-time," allowing you to easily see the most recently created VMs at the top. Now, when sorting by this criterion, any VMs with an "unknown" install time are automatically placed at the end of the list. This change ensures that your most relevant and recently created VMs are more visible, making it easier to manage and organize your virtual environment. ### Display and copy the OTP key We've made it easier to manage your One-Time Password (OTP) setup! Previously, when activating OTP, you were provided with only a QR code, which was convenient for most users but not ideal for those using clients that require the key to be entered manually, such as Bitwarden. ![](https://xen-orchestra.com/blog/content/images/2024/08/otp.png) With this update, you now have the option to display both the QR code and the OTP key. Additionally, we've added a button that allows you to quickly copy the key to your clipboard, making it easier and more flexible to set up OTP on a wider range of authentication clients. ### Xen Orchestra 5.97 URL: https://xen-orchestra.com/blog/xen-orchestra-5-97/ Last updated: 2024-07-31T14:23:56.000Z It's been only 3 weeks since our latest release (we've been one week late last month), but we managed to make a massive release anyway ✨ I'm particularly happy about the progress made in XO 6 preview, with many components that are now used to display more information. I hope we'll be able to keep up this pace! For the rest, it's also significant, with dozens of improvements and new features, including under the hood, for example by making more robust the new CBT backup logic, or adding multiple layers of cache in XO. ## 👨‍🚀 Project & Community This month brings a lot of exciting news: the release candidate for XCP-ng 8.3, the announcement of our organization of the next Xen Project event in Grenoble, and important security updates! ### XCP-ng 8.3 RC 1 After five busy months since the release of XCP-ng 8.3 Beta 2, we are closer than ever to the final release with the XCP-ng 8.3 Release Candidate 1! This release candidate meets our quality standards and is now available for our user base to gather the final bits of feedback. XO Lite, UEFI Secure Boot, PCI passthrough API, and many other features are included in this release. Take a look, and don't forget to provide us with your feedback! [XCP-ng 8.3 Release Candidate 1The XCP-ng 8.3 Release Candidate 1 is now available! This is a perfect opportunity to join our dedicated testers from the user community. We invite you to provide feedback based on your unique use cases and hardware configurations.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogSamuel Verschelde![](https://xcp-ng.org/blog/content/images/2024/07/rc1c.jpg)](https://xcp-ng.org/blog/2024/07/12/xcp-ng-8-3-release-candidate-1/?ref=xen-orchestra.com) ### Hosting the future of Xen At Vates, our commitment to the Xen Project goes beyond technical contributions. We're excited to announce the next Xen Meetup in Grenoble, where we'll connect minds, share knowledge, and drive innovation. Join us as we bring together community members, researchers, and students to shape the future of Xen. Read more about our journey and upcoming event in our latest blog post: [Hosting the future of XenAt Vates, our deep commitment to the Xen Project and our holistic approach to the entire stack underscore our dedication to innovation, community engagement, and delivering a powerful, open-source virtualization solution.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOlivier Lambert![](https://xcp-ng.org/blog/content/images/2024/07/xenwintermeetup.jpg)](https://xcp-ng.org/blog/2024/07/25/hosting-the-future-of-xen/?ref=xen-orchestra.com) ### XCP-ng July 2024 Security Updates In our monthly round of security updates, we've included fixes for XSA-458 and XSA-459\. Remember to stay protected by regularly checking and updating your machines! [July 2024 Security UpdatesSecurity updates for xen, xapi and xsconsole.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogDavid Morel![](https://xcp-ng.org/blog/content/images/2024/07/ai-generated-8857204_1920.jpg)](https://xcp-ng.org/blog/2024/07/18/july-2024-security-updates/?ref=xen-orchestra.com) --- Let's dig into this new release now 🤿 ## 💾 Backup This month brings significant updates on the backup front! We've made major improvements and enhancements to ensure more robust and reliable backup processes. ### CBT stability improvements This month, we've focused on improving the stability of our CBT (Change Block Tracking) feature. We've ensured that the "purge snapshot data" function is called at the end of each transfer, preventing any lingering data issues. Additionally, we've enhanced the NBD (Network Block Device) functionality. NBD now respects the default backup network settings, if configured, and attempts to connect through all possible hosts before failing. This is particularly crucial when no default backup network is set, as hosts with multiple networks might have some networks that aren't accessible by XOA/proxy. Furthermore, we've retained the error message for disks still attached to dom0, as this is often the root cause of other issues. While this may increase the number of failed backups, it is a necessary step to prevent more significant infrastructure problems down the line. ⚠️ Note that with just two recent versions of Xen Orchestra (XO) available for feedback, the codebase is still relatively new. Therefore, we recommend switching to CBT only if you're not in a critical production environment or are experiencing coalesce issues with traditional backups. Feedback can be done in here: [https://xcp-ng.org/forum/topic/9268/cbt-the-thread-to-centralize-your-feedback/](https://xcp-ng.org/forum/topic/9268/cbt-the-thread-to-centralize-your-feedback/?ref=xen-orchestra.com) ### More info in backup reports Our newly revamped backup reports now include more detailed information about the backup job. You can now see if NBD is being used, if CBT is active, and if "Purge snapshot data" is enabled, providing a clearer overview of your backup operations: ![](https://xen-orchestra.com/blog/content/images/2024/07/351233159-da60488b-42f7-410e-a3d1-93c279959fd8.png) ### Avoid sending reports for skipped backups Backups can be skipped for two main reasons: VDI chain protection or an ongoing job. Sometimes, you're aware that a backup might be skipped and you don't need to be notified. To address this, we've added an option to avoid sending reports for failed jobs only, not the one skipped, reducing unnecessary notifications. ![](https://xen-orchestra.com/blog/content/images/2024/07/353467792-912e4034-8078-4cc8-b690-45992dfd8c71.png) ### Metadata backup report recipients For a while, you've been able to receive reports for your regular backups and add extra recipients. However, this functionality wasn't available for metadata backups: until now. We've fixed this issue, so you can now enjoy comprehensive reports for all your backup methods, sent to all your desired recipients. ![](https://xen-orchestra.com/blog/content/images/2024/07/343195300-27a5385c-d8fe-42bf-9a19-101c093646d8.png) ## 🦾 Hardware integration Say hello to this new section! As we continue to collaborate with more hardware partners, we are providing increasingly exclusive integration between the hardware and our virtualization stack. This effort enhances the overall performance, monitoring, and management capabilities of our solutions, delivering a more seamless and efficient user experience. ### 2CRSi hardware info This new preview is the result of our previously announced partnership with 2CRSi. If you are interested in acquiring these machines, take a look at this blog post and register: [Simplifying IT: 2CRSi’s Mona Servers with XCP-ng OnboardVates announces a partnership with 2CRSi at CloudFest! Discover Mona servers with XCP-ng pre-installed, simplifying server management and enhancing Xen Orchestra integration for a seamless out-of-the-box experience![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogOlivier Lambert![](https://vates.tech/blog/content/images/2024/03/2255566-epyc-family-full-width-01.jpg)](https://vates.tech/blog/simplifying-it-2crsis-mona-servers-with-xcp-ng-onboard/?ref=xen-orchestra.com) This is what you could view in the XO/Host view: ![](https://xen-orchestra.com/blog/content/images/2024/07/349201220-77b703d2-cc9f-4d8d-88b2-a910c87949a8.png) As shown in the screenshot, when XO detects that your machine is a 2CRSi Mona 1.14GG, it will display various hardware details: the IPMI address, total power usage, PSU status, highest CPU temperature, fan status, and more. We are collaborating with 2CRSi not only to display this information but also to monitor the values provided by them, as they are the manufacturer of the machine. These technical discussions are very interesting and allow us to provide even more vertical integration between hardware and software. ![](https://vates.tech/blog/content/images/2024/03/images.png) ## 🛰️ XO 6 Since the last release, you can already access the XO 6 preview by adding `/v6` at the end of your XOA URL. We have accelerated the pace of visible changes, and we hope you will love the new enhancements! ### New components This month, we have introduced many new components, most of which are already integrated. Rather than going into deep details, we’ll showcase a few highlights: ![](https://xen-orchestra.com/blog/content/images/2024/07/345350597-bf4d7b12-4ebf-4def-a10d-122b7b3ec729.png) A CellText component, used in tables ![](https://xen-orchestra.com/blog/content/images/2024/07/345093478-be8e129b-6d4f-4bf0-b4c1-1ce3a92ad751.png) A CellObject component ![](https://xen-orchestra.com/blog/content/images/2024/07/345732338-4eb76e0a-efe1-4e81-abe1-2599a1433a26.png) HeadBar component ![](https://xen-orchestra.com/blog/content/images/2024/07/344722763-b9220eb4-e6c1-479e-8825-bca63df9f3cb.png) ObjectLink, which… provides a link to an object. ### Pool view The pool view now features two tabs: Hosts and VMs. Each tab contains a table of all associated objects, utilizing the new components we've created. ![](https://xen-orchestra.com/blog/content/images/2024/07/349455862-442ff3b4-430e-4008-99ed-78956f80f729.png) ![](https://xen-orchestra.com/blog/content/images/2024/07/349455892-d93286b3-8ec1-4b19-ac57-da1ff3ce9eba.png) ### Host view The host view now includes a tab listing all the VMs linked to the host, providing a more organized and detailed overview. ![](https://xen-orchestra.com/blog/content/images/2024/07/351035464-51d313bc-e61c-46bb-b894-58f1b3a4b830.png) ### Quick tasks view XO 6 now displays XO tasks by fetching data directly from the new REST API! We support the full complexity of the new XO tasks, including subtasks, progress, duration, and date. ![](https://xen-orchestra.com/blog/content/images/2024/07/346071639-e3985753-3c4d-4e74-82ff-d79e14226592.png) ## 🔭 XO Lite This month, we had to split XO Lite and XO 6 category, because we had too much content at once! ### Preload online if available Traditionally, XO Lite relied on direct internet access to load its JavaScript files from an index.html hosted locally on your server. This approach had its advantages: it ensured you'd always have access to our latest "SaaS" version. However, this method had a significant drawback - it wouldn't work if you were in an airgapped environment or had blocked our website in your firewall. To address this limitation, we introduced a "local only" solution, where the JavaScript files were bundled and loaded from your server. This approach worked offline, but it also meant we'd need to distribute updates as part of XCP-ng packages - a balance that required finding the sweet spot between frequent updates and minimizing the burden on users. This month, we've implemented an even better way to strike this balance. XO Lite now includes a feature that allows you to fetch the latest JavaScript files from `lite.xen-orchestra.com` if they're accessible online. **This means you can benefit from more recent updates before they're included in an XCP-ng release. If online access isn't available, don't worry - the application will automatically fall back to the bundled version, ensuring uninterrupted functionality.** ![](https://xen-orchestra.com/blog/content/images/2024/07/353105875-6943e05e-e2f4-4884-9d3c-ef9c309dc143.png) ### XO access button URL `xo-server` has a config setting `http.publicUrl` that allows the user to force XO to report a custom URL in the pool's other\_config (along with the `networkInterfaces` fallback). With this change, the "Access XOA" button in XO Lite will open that URL if it exists and fallback to `networkInterfaces` otherwise. ### Improved tree view We have enhanced the indentation of empty items in the tree view to optimize readability. This small but significant change makes navigating and managing your resources much clearer and more intuitive. See the before and after: ![](https://xen-orchestra.com/blog/content/images/2024/07/352022063-b49b8a77-ee7b-46f7-b044-54bb4d533575-1.png) Indentation was broken and makes the tree confusing for empty items ![](https://xen-orchestra.com/blog/content/images/2024/07/352022150-3e4f4300-dcb8-4b43-b081-28831aec2f98-2.png) Everything now stays aligned, which is a lot better! And guess what's great? This improvement is valid for both XO 6 and XO Lite at once! This is another proof that working on the same design for both versions was a great idea. By maintaining a consistent UX design across XO Lite and XO 6, we ensure a seamless user experience. Users can transition between the two versions without any confusion, as the interface and functionalities remain familiar. This consistency not only improves usability but also streamlines our development process, allowing us to implement enhancements and fixes more efficiently across both platforms. Ultimately, a unified design philosophy enhances our ability to innovate and respond to user feedback, delivering a superior product. ## 🪐 XOA We are now focusing on two primary methods to deploy XOA: from XO Lite and through the web deployment on Vates.tech. To streamline our maintenance efforts, we are updating the URL of the old deployment method and deprecate it at the same time. ![](https://xen-orchestra.com/blog/content/images/2024/07/image-1.png) https://vates.tech/deploy ![](https://xen-orchestra.com/blog/content/images/size/w1000/2023/12/291548259-b7c0558d-8c69-4352-9995-c81ec83562b3.png) Deploy from inside XO Lite ## 🚀 XCP-ng 8.3 features As the release of XCP-ng 8.3 approaches, we are finalizing all the new features to be ready on Day 0 in Xen Orchestra! ### Accurate secure boot status This feature was a bit tricky due to its complex logic. However, through excellent collaboration between the XCP-ng and XO teams, we have implemented the proper logic for the VM secure boot feature in the XO UI. Now, we can handle all the different scenarios to ensure that when secure boot is enabled, the VM will indeed use it, preventing any confusion. ![](https://xen-orchestra.com/blog/content/images/2024/07/342390839-3025afcd-33a4-4980-9267-01ae09264e68.png) ![](https://xen-orchestra.com/blog/content/images/2024/07/342390820-0fff694b-23ee-478d-99e6-f0899907b583.png) ![](https://xen-orchestra.com/blog/content/images/2024/07/342390780-fd81fc94-c1d3-4b6c-97cb-b802ac8404e6.png) ## 📡 REST API ### Expose servers We are now exposing servers at the `/rest/v0/servers` endpoint. You can list all the connected servers (ie masters of a pool) by a simple HTTP `GET` command. Passwords are obviously obfuscated. ``` curl \ -X GET \ -b authenticationToken=KQxQdm2vMiv7j \ 'https://xo.company.lan/rest/v0/servers?fields=*' ``` This will return all fields: ``` [ { "allowUnauthorized": true, "enabled": true, "host": "192.168.1.1", "label": "Host1", "username": "root", "readOnly": false, "id": "1", "status": "disconnected", "href": "/rest/v0/servers/1" }, { "allowUnauthorized": true, "host": "192.168.1.10", "label": "Host2", "username": "root", "enabled": true, "readOnly": false, "id": "2", "status": "connected", "poolId": "d1a68625-e4f6-4ff0-acfb-2076d2ae6a79" "href": "/rest/v0/servers/2" } ] ``` ### Expose VDIs in VMs VDIs of a VM, or a VM snapshot, or a VM template, can now be fetched easily by appending `/vdis` at the VM's endpoint. The REST API is doing the "resolution" of the VDIs automatically, because they are not objects connected directly, but going via a VBD. This makes it easier for you to list VM's disks! To fetch it: ``` curl \ -X GET \ -b authenticationToken=KQxQdm2vMiv7j \ 'https://xo.company.lan/rest/v0/vms/66e74b91-11e7-47fa-9dbf-2bb0f0686177/vdis?fields=*' ``` And the result: ``` [ { "type": "VDI", "cbt_enabled": false, "missing": false, "name_description": "Created by XO", "name_label": "xoa root", "size": 21474836480, "snapshots": [], "tags": [], "usage": 20695233024, "VDI_type": "user", "current_operations": {}, "other_config": {}, "$SR": "1f627a63-79ec-152b-9194-46648d8c6b7a", "$VBDs": [ "f8229cd2-3d08-f27a-3f90-6379b579662f" ], "id": "6e54d687-a964-494f-bf85-8b8c4652129b", "uuid": "6e54d687-a964-494f-bf85-8b8c4652129b", "$pool": "e238a5af-eb88-75e1-0017-2c519aa297e7", "$poolId": "e238a5af-eb88-75e1-0017-2c519aa297e7", "_xapiRef": "OpaqueRef:5220a2be-f59a-43a6-89f0-73ab28e1f43b", "href": "/rest/v0/vdis/6e54d687-a964-494f-bf85-8b8c4652129b" } ] ``` ## 🐦 VMware to Vates (V2V) We've made significant strides in improving warm migration and fixing multiple bugs. By managing more VMware errors and edge cases, our system is now more robust, resulting in a higher success rate for migrations. Remember that the V2V documentation is now available in here: [Migrate to XCP-ng | XCP-ng DocumentationHow to migrate from VMware, KVM, etc. to XCP-ng.![](https://docs.xcp-ng.org/img/xcpcrop128.png)XCP-ng Documentation![](https://docs.xcp-ng.org/assets/images/xoa-v2v-1-3ce4bcbcf7edd4d024cae535628f1a27.png)](https://docs.xcp-ng.org/installation/migrate-to-xcp-ng/?ref=xen-orchestra.com#-from-vmware) ## **🆕** Misc This month, our updates aren't just about minor visible changes in the XO 5 UI; we've also made significant improvements to the underlying mechanisms, which greatly reduce the overall load, especially noticeable in medium to large infrastructures. ### Buffered tasks events Since our previous release displayed all XO tasks, we noticed a high frequency of tasks triggered every minute. To enhance efficiency, we introduced a buffer for these task events. These events are now deduplicated and handled sequentially on the next tick, avoiding potential race conditions. In simpler terms, by reducing the number of API calls, we've lowered the overall load on Xen Orchestra. ### Cache support for XAPI calls Following the same principle as buffered task events, we've improved how Xen Orchestra sends calls to your XCP-ng hosts (or XenServer, if you're still using it). This is crucial because, as the central component, `xo-server` can now group and cache hundreds of calls simultaneously, drastically reducing the number of XAPI calls. This optimization saves both bandwidth and XAPI load for all these requests. We are confident that at a decent scale (like dozens of XO clients at once), these improvements will significantly reduce your XO load and the number of XCP-ng API calls. ### Force leaf coalescing This feature is somewhat niche and shouldn't be necessary for most users. However, for those using thick provisioned storage, when space is fully allocated and freeing up some space doesn't seem to help, you might want to expedite the coalescing process rather than waiting for the garbage collector to trigger automatically. In such cases, you can now use the "Coalesce Leaf" button. Use this option wisely if you are not fully aware of its implications. ![](https://xen-orchestra.com/blog/content/images/2024/07/347815179-decd729e-d948-4a44-b7b8-02dd5bbcbadb.png) Behind the scenes, this process will suspend the VM, start the coalescing, and then resume the VM. There are specific scenarios where this could be beneficial. However, given the variety of configurations, we cannot test this feature in all environments. Therefore, we strongly advise using it only in desperate situations and ensuring you have backups. You can read the [XenServer doc about this](https://docs.xenserver.com/en-us/xenserver/8/storage/manage.html?ref=xen-orchestra.com#reclaim-space-by-using-the-offline-coalesce-tool) for more details. ### Reattach SR with extra warning To enhance clarity and prevent accidental data loss, we've added an extra warning window when re-attaching a Storage Repository (SR). This additional step ensures that users do not inadvertently recreate a fresh SR on top of an existing one, safeguarding your data and configurations. ![](https://xen-orchestra.com/blog/content/images/2024/07/349872854-709e4378-5215-4f4c-a1fe-19099f069c6f.png) ### Self service bypass quota as an admin Before this release, even an admin could not create, modify, or add a VM in the self-service portal if it exceeded the configured quota. However, there are exceptional cases where this limitation might need to be bypassed. Now, the super admin has the flexibility to bypass quotas and perform necessary actions without restrictions. This enhancement ensures that admins have the control they need in critical situations. ### More translations We're thrilled to continue bringing Xen Orchestra to a global audience! A huge thank you to our amazing community for providing translations, which we're delighted to incorporate and make XO even more accessible worldwide. #### Xen Orchestra 5 We added Persian (Farsi) language in Xen Orchestra 5, available in your user zone (the "user" icon under the "Sign out" entry): ![](https://xen-orchestra.com/blog/content/images/2024/07/image-2.png) We've expanded our language support to reach a new total of **14 languages with XO 5!** We also added Swedish this month, to our existing choice of English, French, Russian, Spanish, Hungarian, Italian, Polish, Portuguese, Swedish, Turkish, Hebrew, Chinese, Japanese - making Xen Orchestra more accessible than ever. #### XO Lite XO Lite is now also available in Persian, added after English, French and German. ### Xen Orchestra 5.96 URL: https://xen-orchestra.com/blog/xen-orchestra-5-96/ Last updated: 2024-07-09T11:21:47.000Z We’re excited to introduce Xen Orchestra 5.96! This update brings various improvements and highlights our ongoing commitment to the open-source community. We're focused on delivering tools that meet the needs of virtualization, staying true to our values of transparency and collaboration. We hosted a brief live session to discuss this release; you can watch the replay here: ## 👨‍🚀 Project & Community Our mission remains clear: we're dedicated to addressing the biggest challenge in virtualization today – helping organizations migrate away from VMware. ### Growing our team We’re expanding our team to meet the increasing demand for VMware alternatives. Our sales, support, and development/product teams are all growing rapidly. While it might take some time to see the full impact, this growth is crucial for positioning us as a leading end-to-end virtualization provider, from hypervisor development to orchestration. Additionally, we’re building a dedicated "Solution Architect Team" to enhance our migration services from VMware to the Vates virtualization stack. Look out for more updates on this in the coming months! ### Organizing the next Xen event We’re excited to announce the upcoming Xen Project Winter Meetup. This event is all about fostering in-person collaboration through engaging design sessions and technical talks. It will be held at Grenoble University's IMAG building, where we’re also working to strengthen our connections with the academic community, including students and researchers. If you’re a Xen developer or contributor, be sure to pre-register for the event! [Xen Project Winter Meetup - Grenoble![](https://campaign.vates.tech/favicon.ico)Grenoble![](https://content.vates.tech/assets/grenobleimag.jpg)](https://campaign.vates.tech/xen-project-winter-meetup?ref=xen-orchestra.com) Vates is taking care of most of the event's organizational details, including covering costs for the Xen Project. Our aim is to ensure a smooth and enriching experience for everyone, within the Xen Project budget. This event highlights our belief in collaboration and our support for the Xen Project’s growth. We look forward to sharing knowledge, networking, and building lasting relationships within the community. ### XOSTOR webinar In case you missed it, we recently hosted a webinar on XOSTOR. The session featured Philipp, CEO and co-founder at LINSTOR (the technology behind XOSTOR), Marc and Chris from our marketing team and finally Ronan, our lead XOSTOR developer being here to answer specific technical questions in the end. It was a great opportunity to dive into XOSTOR’s capabilities and our future vision for storage solutions within our ecosystem. ### XCP-ng Security & Maintenance update This month, our updates go beyond just security. We've introduced a new largeblock storage driver. This local SR driver addresses the current limitation in our storage stack with 4KiB-block-only devices by transparently emulating a 512B block size. This enhancement ensures better compatibility and performance for your storage needs. [June 2024 Security and Maintenance UpdateSecurity update for qemu, openssh, curl, sudo, microcode\_ctl, linux-firmware. Bugfix and update of xapi and tzdata. New feature in sm adding largeblock driver.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogDavid Morel![](https://xcp-ng.org/blog/content/images/2024/06/technology-6701509_1920.jpg)](https://xcp-ng.org/blog/2024/06/17/june-2024-security-and-maintenance/?ref=xen-orchestra.com) Now let's talk about this XO release! --- ## 💾 Backup We have some big changes this time, and one of them explains why we are one week late! ### Better backup reports Over the past two months, we've completely revamped the way reports are generated. In other words, we've cleared a lot of technical debt. The most noticeable change is the new, nicer email reports that now use variables and the MJML format, making them easier to modify. This lays the groundwork for even more new features in the future, as the code is now in much better shape. ![](https://xen-orchestra.com/blog/content/images/2024/06/342640241-d7223188-794a-40d7-82b1-77bf58af9f46.png) ### Introducing CBT Changed Block Tracking (CBT) introduces features to improve incremental backups in XCP-ng. Note that CBT is available to all XCP-ng users, unlike XenServer, where it is restricted to the Premium Edition. #### How changed block tracking works[](https://docs.xenserver.com/en-us/xenserver/developer/changed-block-tracking-guide?ref=xen-orchestra.com#how-changed-block-tracking-works) When CBT is enabled for a virtual disk image (VDI), any changes to the blocks in that VDI are recorded in a log file. Each time the VDI is snapshotted, this log file identifies the blocks that have changed since the last snapshot. This allows for backing up only the changed blocks. After exporting the changed blocks, the full VDI snapshots can be converted into metadata-only snapshots by removing the associated data and retaining only the changed block information. These metadata-only snapshots are linked, creating a chain that records the full history of changes since CBT was enabled. It also leverages network block device (NBD) capabilities to export the data from the changed blocks. #### Advantages Over VHD Differential Mechanism Currently, with our VHD differential mechanism, we must keep the snapshot until the next backup. The longer you keep the snapshot, the larger the differential becomes, resulting in more data to coalesce when it's removed. And more space used! With CBT, we can remove your snapshot data just after its creation, significantly reducing the amount of data to coalesce. This makes the entire coalesce process more efficient and less time-consuming. #### How to test it If you are using NBD-enabled backups, CBT will start automatically. However, the snapshot data removal after backup is **opt-in, meaning NOT enabled by default**. For 2 reasons: 1. This might change some behavior in your current infrastructure: the coalesce process -despite being a lot smaller- will happen in a different manner than the original VHD one. You need to keep an eye to see if that doesn't cause any problem. 2. Despite our extensive QA (and many reviews/patches), it's still a fresh code base. To recap, if you are NOT using NBD, this won't change anything for you, you'll still use the previous incremental system. If you are already using NBD, CBT will be enabled, but snapshot data will NOT be removed until the last backup. See the following screenshot in your backup job: ![](https://xen-orchestra.com/blog/content/images/2024/07/image.png) If you want to enable the new snapshot data purge, you need to toggle it here! We'll continue to improve the whole process, but for now, we managed to get it stable. If you want to provide your feedback and/or report any issues, visit this forum thread: [CBT: the thread to centralize your feedbackWe are moving forward to implement CBT, and in this thread, we’ll centralize everything you need to test and report issues. More instructions to come![](https://xcp-ng.org/forum/assets/images/touch/512.png)XCP-ngolivierlambert![](https://xcp-ng.org/forum/assets/uploads/profile/uid-1/1-profileavatar-1620659303584.jpeg)](https://xcp-ng.org/forum/topic/9268/cbt-the-thread-to-centralize-your-feedback?ref=xen-orchestra.com) Your feedback is invaluable to us, so please give it a try and let us know your thoughts! ## 🔭 XO 6 & XO Lite We are continuing to move forward with our "core" web framework, based on VueJS, bringing new features and enhancements to improve your experience. ### XO 6 One of the exciting updates in XO 6 is the addition of a new search function within the treeview. This feature allows you to filter and find what you need quickly and efficiently, streamlining your workflow. We believe this will greatly enhance usability and make navigation more intuitive. ![](https://xen-orchestra.com/blog/content/images/2024/06/image.png) 💡 For those eager to explore, you can access the XO 6 preview via its dedicated endpoint: [https://xoa.example.org/v6](https://xoa.example.org/v6?ref=xen-orchestra.com). We encourage you to try it out and share your feedback with us. ### New components As usual, we are making progress on the new components we are developing. This month, we have completed the following components: ![](https://xen-orchestra.com/blog/content/images/2024/06/341713684-ca19bcca-13e1-4912-902d-66b9cb65e715.png) A doughnut with a legend integrated (previously, it was in 2 different components) ![](https://xen-orchestra.com/blog/content/images/2024/06/337218571-bed1afcc-e233-44f0-bb68-ea103886a6d0.png) A card with a subtitle/legend ![](https://xen-orchestra.com/blog/content/images/2024/06/337169152-d02ce092-d197-4c96-b884-914bd72fc62c.png) Our future search bar! Additionally, in both XO Lite and XO 6, all external links will now open in a new tab. This small but significant change aims to improve navigation and usability. ## 🪐 XOA We’ve made some quality of life improvements to XOA to enhance your experience. Firstly, with the `xoa` CLI, you can now add secondary IP addresses on an existing interface. This flexibility allows for more advanced network configurations. ```console $ xoa network static --add ? Static IP for this machine 192.168.200.120/24 ``` Additionally, the network configuration via the CLI now supports CIDR notation, making it more straightforward and user-friendly. These updates aim to simplify and improve the way you manage network settings in XOA. ```console $ xoa network static ? Static IP for this machine 192.168.100.120/24 ? Gateway 192.168.100.254 ? IP of the DNS server 192.168.100.254 ``` ## 🚀 XCP-ng 8.3 features As we approach the release of XCP-ng 8.3, our focus is to ensure that Xen Orchestra is fully compatible from day one, while also leveraging new features! ### Exclude disks when doing a snapshot You might already be familiar with the `[NOBAK]` feature, which is convenient for excluding a virtual disk from backups. We’ve introduced a new string, `[NOSNAP]`, which allows you to ignore the disk during a regular snapshot. You can combine both strings to exclude a disk from both VM snapshots and VM backups: `[NOSNAP] [NOBAK]`. ## 💠 XOSTOR We continue to enhance XOSTOR by fixing bugs and improving the user interface. This month, we’ve implemented two quality of life improvements. You can now easily see the state of your resources (Diskful vs Diskless): ![](https://xen-orchestra.com/blog/content/images/2024/06/343852604-24fbf1ab-37ef-40ff-9b64-23ef3406f49c.png) Additionally, we’ve added a feature that allows you to directly navigate to your XOSTOR SR via a clickable link: ![](https://xen-orchestra.com/blog/content/images/2024/06/341691037-9b9d800c-a14c-4ab1-8647-326bbd59163d.png) ## **🆕** Misc We continue to deliver improvements across the application while laying the groundwork for future enhancements. ### RPR/RPU with task progress The Rolling Pool Update (RPU) and Rolling Pool Reboot (RPR) actions are now tracked with task progress. This is great for administrators because it provides a precise idea of the time needed to complete the RPU and shows exactly where you are in the process. This transparency allows for better planning and management of updates, minimizing downtime and ensuring a smoother update experience. ![](https://xen-orchestra.com/blog/content/images/2024/06/343171071-4734295d-d6ed-4b0f-a7d2-d51ff7d88d6c.png) ### Logging failed API calls via XO tasks We are now monitoring all failed API calls (due to bugs or various potential failures) via XO tasks. This not only helps track issues but also demonstrates the evolution of our internal XO task management, paving the way for gradually replacing the current logging system with a more refined, centralized task management system, giving better control over complex API calls. ### Netbox v4 support Netbox recently released version 4.0, which introduced many changes: [NetBox 4.0 is now available.NetBox Labs is excited to announce the general availability of NetBox 4.0\. get the full scoop on the enhancements made to NetBox.![](https://netboxlabs.com/wp-content/uploads/2023/10/cropped-favicon-270x270.png)NetBox LabsJeff Gehlbach![](https://netboxlabs.com/wp-content/uploads/2024/05/NetBox-Community-and-Technical-Hub-5.png)](https://netboxlabs.com/blog/announcing-netbox-4-0/?ref=xen-orchestra.com) This update was significant enough to break several plugins. Despite our efforts to read the changelog, some breaking changes were undocumented. We have now adapted our plugin to be compatible with Netbox 4.x! ### SCSI ID displayed at SR creation To make iSCSI SR creation more detailed, we’ve added the display of the SCSI ID directly in the UI when you select your LUN: ![](https://xen-orchestra.com/blog/content/images/2024/06/340968224-7afbeaec-2f1d-4360-9a00-61323a049c19.png) ## ### Xen Orchestra 5.95 URL: https://xen-orchestra.com/blog/xen-orchestra-5-95/ Last updated: 2024-05-31T14:01:24.000Z It's time for our May release! This month, our main focus has been on advancing XO Lite and XO 6, with the highlight being the first visible preview of XO 6\. Beyond displaying a few new components, this preview showcases our significant progress under the hood, introducing innovative mechanisms for communication between the server and the web interface. As always, this is not the only update we have for you. We have also made numerous improvements across various parts of our stack. Enjoy the latest enhancements! ## 👨‍🚀 Project & Community May has been a busy month for us, as usual. We gained significant recognition from the market, with notable mentions from Gartner and CommVault. These are major names, and their acknowledgment is a testament to our progress and impact. Moreover, we have been successfully converting an increasing number of very large customers, including Fortune 500 companies, from VMware to our stack. This shift is driving demand for even larger alliances and new features, propelling our growth and innovation. ### More recognition from Gartner We have been acknowledged as a "Representative Vendor" in the Gartner Market Guide for Integrated Systems. This prestigious recognition places Vates alongside industry giants like Broadcom/VMware, Microsoft, and Nutanix. It underscores the reliability and performance of our solutions, XCP-ng and Xen Orchestra, highlighting our growing reputation in the virtualization market. This acknowledgment is a testament to our commitment to delivering top-tier, open-source virtualization solutions tailored to evolving customer needs. The full article is available below: [Vates Recognized in Gartner’s Market Guide for Integrated SystemsVates proudly stands alongside industry leaders in Gartner’s Market Guide for Integrated Systems, showcasing our commitment to innovation and excellence in virtualization.![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogOlivier Lambert![](https://vates.tech/blog/content/images/2024/05/gartner3.jpg)](https://vates.tech/blog/vates-recognized-in-gartner-market-guide-for-integrated-systems/?ref=xen-orchestra.com) ### A growing ecosystem We have expanded our ecosystem by adding more third-party software vendors. The most recent addition is CommVault, a leading backup solution provider in the market. CommVault now offers native compatibility with XCP-ng, enhancing our platform's backup and data protection capabilities. This integration underscores our commitment to providing robust and versatile solutions for our users! ![](https://docs.xcp-ng.org/assets/images/commvault-1339ae58b3207452480d1f4c16b1b40c.png) We also had a dedicated article from Starwind doing a recap on our stack: [Security updates and new features in XCP-ng and Xen Orchestra 6Explore the benefits of XCP-ng: long-term support, new features in Xen Orchestra 6, easy transition from VMware, REST API, and reliable backups.![](https://www.starwindsoftware.com/blog/wp-content/uploads/2022/02/favicon.png)StarWind BlogVladan Seget![](https://www.starwindsoftware.com/blog/wp-content/uploads/2024/05/1200_628_XCP-NG-LTS-has-10-years-of-platform-support@2x.png)](https://www.starwindsoftware.com/blog/xcp-ng-lts-has-10-years-of-platform-support?ref=xen-orchestra.com) For more information and to discover the other third-party vendors we have recently added, please visit our dedicated ecosystem page: [Ecosystem | XCP-ng DocumentationProjects and technological partners around XCP-ng.![](https://docs.xcp-ng.org/img/xcpcrop128.png)XCP-ng Documentation![](https://docs.xcp-ng.org/assets/images/vates-partner-6f2342ecbddfe80d5f69b0e21cdc1df1.png)](https://docs.xcp-ng.org/project/ecosystem/?ref=xen-orchestra.com) ### LINBIT+Vates webinar on XOSTOR Join us for an exciting upcoming webinar co-hosted by LINBIT and Vates, focusing on XOSTOR, the cutting-edge solution for storage management. This webinar will provide in-depth insights into XOSTOR's features, benefits, and real-world applications, helping you optimize your storage infrastructure. The webinar will take place on **June 26th - 4PM** (CET timezone) - more information coming soon! ![](https://xen-orchestra.com/blog/content/images/2024/05/xostorsmall.png) ### Our first Vates Innovation Summit Last week, we proudly hosted our inaugural Vates Venice Innovation Summit at the historic [SerenDPT](https://www.serendpt.net/home?ref=xen-orchestra.com) venue in Venice. The event was a tremendous success, gathering some of the most influential figures in technology and innovation in Italy, where we opened a branch few years ago. ![](https://xen-orchestra.com/blog/content/images/2024/05/4096-2731-max.jpg) ![](https://xen-orchestra.com/blog/content/images/2024/05/4096-273111-max.jpg) We were honored to welcome representatives from major companies such as [Leonardo](https://www.leonardo.com/en/home?ref=xen-orchestra.com), [Clever Cloud](https://www.clever-cloud.com/?ref=xen-orchestra.com), and [StormShield](https://www.stormshield.com/?ref=xen-orchestra.com), alongside key public sector leaders, including the head of the *Technical Secretariat at the Office of the Undersecretary for Innovation* and General Giovanni Gagliano, Head of Cyber and Telecommunications at the [Italian Ministry of Defense](https://www.difesa.it/eng/?ref=xen-orchestra.com). A complete recap of the event is [available here](https://vates.tech/blog/vates-venice-innovation-summit-recap/?ref=xen-orchestra.com). ![](https://xen-orchestra.com/blog/content/images/2024/05/vatesvenice-2.png) ### A new strategic partner: Clever Cloud [Clever Cloud](https://www.clever-cloud.com/?ref=xen-orchestra.com) and [Vates](https://vates.tech/?ref=xen-orchestra.com) have announced a strategic partnership to enhance cloud autonomy in France and Europe. By combining their expertise in PaaS (Platform as a Service) and IaaS (Infrastructure as a Service), they aim to offer a robust, open-source alternative to major global providers. This partnership focuses on reducing dependency on hyperscalers, promoting technological independence, and rejecting vendor lock-in strategies, while delivering high-performance cloud solutions tailored to modern business needs. For more details, read the full article here: [Clever Cloud and Vates: two French tech leaders join forces to create comprehensive and autonomous Cloud solutionsClever Cloud and Vates announce a strategic partnership aimed at enhancing the cloud’s strategic autonomy in France and Europe.![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogMarc-André Pezin![](https://vates.tech/blog/content/images/2024/05/sean-pollock-PhYq704ffdA-unsplash.jpg)](https://vates.tech/blog/clever-cloud-and-vates-two-french-tech-leaders-join-forces/?ref=xen-orchestra.com) ![](https://xen-orchestra.com/blog/content/images/2024/05/vates-clever.png) ### New Air Gap plans for sensitive installations We are excited to introduce our new Air Gap plans, developed in response to the unique needs of sensitive installations and environments that require complete isolation from the internet, such as boats, planes, and other high-security settings (energy, defense, healthcare…) We have successfully replaced many VMware deployments in these scenarios. Recognizing the demand for tailored solutions, we have created custom options for XCP-ng and Xen Orchestra (XOA) that operate fully disconnected, eliminating the need for internet-based pre-configuration, license binding, or registration. These services are now available on demand. Please [contact us for more information](https://vates.tech/contact?ref=xen-orchestra.com). ![](https://xen-orchestra.com/blog/content/images/2024/05/image-1.png) ### Xen Summit 2024 A significant portion of the XCP-ng team will be attending the annual Xen Summit in Lisbon next week. We have multiple talks scheduled and several design sessions planned. Stay tuned for a recap blog post in the following days! ![](https://xen-orchestra.com/blog/content/images/2024/05/image-2.png) [AMD SEV talk by Vaishali](https://xenprojectsummit2024.sched.com/event/1bCFk/enabling-amd-sev-in-xen-vaishali-thakkar-vates?ref=xen-orchestra.com): > AMD Secure Encrypted Virtualization (SEV) technologies represent a significant advancement in confidential computing by offering hardware-based memory encryption capabilities. SEV aims to protect VMs' data from various threats, including unauthorised access by the hypervisor or other VMs running on the same host. In this talk, we will discuss ongoing development efforts related to incorporating AMD SEV technologies in Xen. We will focus on covering various enhancements, such as modifications to ASID allocation and TLB flushing mechanisms for SEV-enabled guests, as well as the implementation of the ASP driver and related support within the xl toolstack. [Rust Xen tools by Yann](https://xenprojectsummit2024.sched.com/event/1bCFU/looking-back-at-rust-usage-for-guest-tools-yann-dirson-vates?ref=xen-orchestra.com): > Rust ecosystem is a big change from long-supported-by-every-OS languages like C. This presentation will try to summarize the pitfalls and challenges, some coming from the variety of guest OS we support (portability), some applicable more largely (security support). We hope it will provide valuable input for possible further usage of Rust in the Xen project. --- **And now, let's switch to our monthly release announcements!** ## 🔭 XO 6 & XO Lite This month brings many cool updates for XO 6 and XO Lite. ### XO 6 first preview We are thrilled to announce that the basic layout of XO 6 is now accessible in your XOA via the `/v6` endpoint, eg `https://xoa.example.org/v6`. This preview includes our first visible features such as logout, console access, and a tree view. This milestone marks a significant achievement due to the extensive work completed behind the scenes. XO 6 introduces a completely new method for fetching objects in the web interface, leveraging the REST API. This shift not only unifies and completes the API but also accelerates its development as xo-web becomes its primary "customer." In XO 6, we are transitioning entirely to VueJS and have implemented new routing. A store with subscription has been introduced to fetch objects efficiently, making the process at least ten times more efficient than the existing XO 5 strategy. This enhancement speeds up the initial load display and significantly reduces the amount of data transferred between XOA and your browser. To illustrate the difference in design, let's compare the initial load times of the current app with around 300 VMs: While the load time isn't perfectly linear with the number of VMs (it's more dependent on the number of objects), the improvement with a "medium" infrastructure is already significant. And this is just the beginning! While we have additional improvements planned, this release showcases that XO 6 is not just a refresh but a comprehensive revamp of Xen Orchestra, designed to be faster, more modern, and future-proof. #### Our initial layout The current preview offers a simple layout with a header (including a disconnect button), a menu, and the first version of the tree view. We have also included the console, allowing you to test the latest version of the console component, which addresses some bugs found in XO 5 consoles with non-US layouts. ![](https://xen-orchestra.com/blog/content/images/2024/05/334134271-92ca3652-29d7-4cfe-80c8-d39a90cde0f8.png) This is just the beginning. We are planning to develop a proper dashboard and use this opportunity to create an outstanding backup management UI, replacing the "old" XO 5 interface. As we progress, XO 6 will gain more features step by step and release after release. Eventually, XO 6 will become the default interface, while XO 5 will remain accessible via the `/v5` URL, until it will disappear completely. ### New components We are accelerating our implementation of new components, and this month we are excited to introduce several newcomers: ![](https://xen-orchestra.com/blog/content/images/2024/05/327699294-b2a8295b-fdce-4dcc-8b86-51c4bcc74151-1.png) Pills that we be used to display a backup job status ![](https://xen-orchestra.com/blog/content/images/2024/05/334351111-f00806b4-4a7f-440c-92a1-a6c3019c0a1d-1.png) The "card number" component ![](https://xen-orchestra.com/blog/content/images/2024/05/331592409-8105164e-9885-4ed9-b265-f1d3ee14c4f5-1.png) Doughnut chart with various properties ![](https://xen-orchestra.com/blog/content/images/2024/05/334041631-1dc3b638-f548-4a5c-9513-1efb1561b125-1.png) This components allows to easily add a legend for some content, with a tooltip. ![](https://xen-orchestra.com/blog/content/images/2024/05/327779654-774da91c-ed49-4c8e-a756-5ae84d6e10fb-1.png) An improved "chip" component ![](https://xen-orchestra.com/blog/content/images/2024/05/334733399-1b245c21-fbc0-4f5f-8590-36b8f3f979e3.png) A progress bar supporting multiple percentages ### XO Lite Despite the needed effort to bring the first XO 6 preview visible, we also made some progress in XO Lite. #### Button to link to XOA If XO Lite detects that an XOA has been deployed on the pool, it will automatically display a button to access it, replacing the regular "Deploy XOA" option: ![](https://xen-orchestra.com/blog/content/images/2024/05/332738875-99b4fe4d-2d3c-4388-86e0-a2bcfe4133de.png) #### Remove CD drives from storage usage Our main dashboard displays disk space usage per storage repository (SR). However, including CD drives in this calculation was unnecessary. Therefore, we have removed CD drives from the storage usage metrics. #### German translation XO Lite is now available in German, thanks to the contribution from [Alexander Schulz](https://github.com/borzel?ref=xen-orchestra.com). To change the language, go to the "Settings" section in the top right corner of the XO Lite screen. ![](https://xen-orchestra.com/blog/content/images/2024/05/294561650-c20a05c7-4c08-4f3a-bce8-99a6bd8f56fc.png) #### Tree view improvements We have made numerous small tweaks to enhance the tree view's usability. XO Lite has fully transitioned to the "common" version used between XO Lite and XO 6, called `web-core`. The extensive work behind the scenes over the past months is now paying off, delivering a smoother and more efficient experience. ![](https://xen-orchestra.com/blog/content/images/2024/05/image.png) ## 🖥️ XO CLI We have enhanced the usability of XO CLI, making it significantly easier to use. Now, you can bypass the registration phase by using a token directly when calling the xo-server URL (i.e., your XOA IP address). Additionally, by combining this with a shell alias, you can effortlessly control multiple XOAs simultaneously, such as a development and a production XOA: ``` # alias xo-dev='xo-cli --url https://token@dev.company.net' # alias xo-prod='xo-cli --url https://token@prod.company.net' ``` And then you can simply use: ``` # xo-prod vm.start id= ``` Or: ``` # # xo-dev vm.stop id= ``` ## 📡 REST API While our primary focus has been on integrating the REST API into our new UI for XO 6, we are excited to announce another addition to our REST API this month! ### VM export in OVA You can now easily export a VM in the OVA format directly from our REST API. This enhancement demonstrates our commitment to interoperability. To export a VM in OVA, simply make a call to the `/rest/v0/vms/.ova` path. Here is a quick example: ``` curl \ -X GET \ -b authenticationToken=KQxQdm2vMiv7j \ 'https://xo.company.lan/rest/v0/vms/.ova' \ > MyVM.ova ``` ## ⚖️ Load balancer Previously, our load balancer made decisions based solely on host load, migrating VMs only when the configured threshold was exceeded. This approach, now termed "Conservative," remains the default. Recently, we introduced an option to balance vCPU usage by pre-positioning VMs for optimal vCPU/CPU ratios. ![](https://xen-orchestra.com/blog/content/images/2024/05/334768569-54779e01-7364-48be-a223-3a0cbb609dba.png) Today, we have introduced a new "Preventive" behavior that triggers load balancing when there is uneven utilization within the pool. This option also seeks to reduce CPU usage disparities between hosts. For instance, it aims to prevent scenarios where one host is at 60% CPU usage while others are at 10%, a situation that the default performance plan behavior would permit. ## 🐦 VMware to Vates (V2V) When selecting a VM to import, you have the option to choose the appropriate template for it. This choice ensures optimal performance by applying the correct Xen/BIOS settings tailored to the VM's needs. If you plan to import multiple VMs simultaneously, it is crucial to ensure that they all belong to the same "family" of operating systems and use the same template. ![](https://xen-orchestra.com/blog/content/images/2024/05/326505744-92ee2772-a14c-4a5f-a019-80d7b5eaa013.png) This consistency guarantees that all VMs benefit from the same performance enhancements and compatibility settings. By carefully selecting templates, you can maximize the efficiency and reliability of your imported VMs. ## 🚀 XCP-ng 8.3 features Our highly anticipated release of XCP-ng 8.3 is just weeks away! We're thrilled to share that we are diligently working to ensure full XO support from day one. Explore the exclusive features already available in XO that are designed to work seamlessly with XCP-ng 8.3, delivering enhanced performance and capabilities. Stay tuned for more updates as we approach the release date! ### PCI passthrough from the UI We began our work on PCI passthrough last month, and we are excited to announce that our upstream patch has now landed in XCP-ng 8.3\. This means you can now passthrough any PCI devices directly from the UI, making it easier than ever to manage your hardware resources! ![](https://xen-orchestra.com/blog/content/images/2024/05/311300384-a956d297-a252-465a-b033-56403899c162.png) ### VM migration compression For environments with slow network connections between hosts, you can now enable compression on the migration stream during live VM migrations. This feature uses additional resources on the involved hosts, but can significantly speed up the migration process if your network bandwidth is limited. However, since the effectiveness of this feature can vary, we recommend testing it in your environment before deciding to keep it enabled. ![](https://xen-orchestra.com/blog/content/images/2024/05/332744667-f3468ceb-1bb0-43c5-a88d-b21c99669f9e.png) Please note that if you have an XCP-ng host running a version prior to 8.3, this feature will not be available: ![](https://xen-orchestra.com/blog/content/images/2024/05/332744535-9a1a5b9c-f59f-45f0-88d0-d71c0e008764.png) ## 🛡️ Air gap features This section is dedicated to highlighting improvements related to XO or XCP-ng usage in air-gapped environments. We will update it with every release featuring relevant enhancements. ### Pre-configured XOAs We now offer pre-configured XOAs on demand. These XOAs come bound to your account and are fully up-to-date. You can simply transfer the XVA file to your portable drive and deploy it in your fully isolated environment. Contact us to get access to your custom/pre-configured XOA file! ### Air gap deploy script Our deploy script for Dom0/host can now be used offline. Simply copy the content of [https://xoa.io/deploy](https://xoa.io/deploy?ref=xen-orchestra.com) and paste-it in a file (it's a simple bash script). Then, make it executable, and finally target the path to your local `XOA.xva` file, allowing you to configure everything from password, static or DHCP network config and so on! On a Linux machine, creating the script is straightforward: ``` # curl https://xoa.io/deploy > deploy.sh # chmod +x deploy.sh ``` You can also use this opportunity to download the appliance locally too: ``` # curl https://xoa.io/xva > XOA.xva ``` A quick check on the XVA file to verify the MD5 sum is correct: ``` # md5sum XOA.xva c3dd6102bef4d9aa2b7c5fc2c38c2bda XOA.xva ``` Now, move the XVA and the script to your air gap XCP-ng machine. Just pass as a first and unique parameter, the path to your XOA file: ``` # deploy.sh XOA.xva ``` That's it! ## 💠 XOSTOR We continue to improve and enrich XOSTOR features after our initial 1.0 last month. #### Copy VDI UUID in XOSTOR view You can now easily copy a disk UUID from the XOSTOR dedicated view. That's a pretty important thing to help you investigating any kind of trouble you could have, or to search more efficiently a VDI. ![](https://xen-orchestra.com/blog/content/images/2024/05/328171290-31c8007b-013a-4af2-b130-30b54ca7c3f6.png) #### XOSTOR extra warning We added a warning at XOSTOR creation, to be sure that your replication count is never higher than the number of available disks and hosts. ![](https://xen-orchestra.com/blog/content/images/2024/05/327390856-e9f15cb7-c61f-4e52-a40c-5ad6d82283a2.png) ## **🆕** Misc We always try to find a balance between "long term work" versus quality of life improvements. Obviously, it's easier while our team is growing. Anyway, this month, we managed (again) to release various extra improvements all around XO. ### Better display when the VM is busy When you migrate a VM, its icon is going yellow from the initial green state. This is the case but not everywhere in the UI. Now we added the icon change at different place to be 100% sure you aren't missing what's going on! ![](https://xen-orchestra.com/blog/content/images/2024/05/332747263-e42963a3-529e-484b-817d-cf9d153dcf32.png) #### ### Parse the result of async XAPI tasks XAPI tasks sometimes return an XML content, that was displayed "as is" in our UI. Now, this content is correctly parsed for a far more readable and structured result and display. ### Improved Task ETA calculation Initially, we calculated the estimated end time (ETA) for tasks as soon as they started, leading to significant variability due to the task's "warm-up" phase. For instance, a VM migration or import could start slowly, showing a long ETA (e.g., 10 hours), which would then correct itself as the task reached its "cruise speed." To enhance accuracy, we now wait 10 seconds before computing the ETA. This change significantly improves the reliability of the displayed ETA for tasks. ### Xen Orchestra 5.94 URL: https://xen-orchestra.com/blog/xen-orchestra-5-94/ Last updated: 2024-12-20T13:58:46.000Z We've packed this update with awesome new features and key improvements aimed at simplifying your workflow. XOSTOR is a major highlight, but that's not all. If you're transitioning from VMware, you’ll appreciate our even better V2V (VMware to Vates) tool. Take a look into these updates and other exciting additions that make managing your virtual environments more intuitive than ever! ## 👨‍🚀 Project & Community Another "interesting" month with even more projects that are yielding interesting results! ### The VMware exodus isn't slowing down It’s been another eventful month, packed with progress across multiple projects! The trend of users migrating from VMware to our XCP-ng & Xen Orchestra, the [Vates Stack](https://vates.tech/?ref=xen-orchestra.com), continues to grow. To support this influx, we've updated our V2V guide with further improvements, check out the enhanced details later in this article: [Migrate from VMware to XCP-ngVmware v6 is now end of life, the right time to migrate to an open source, less expensive and constantly evolving solution: XCP-ng.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOlivier Lambert![](https://xcp-ng.org/blog/content/images/2022/10/chris-briggs-V72Hk6LjjjI-unsplash.jpg)](https://xcp-ng.org/blog/2022/10/19/migrate-from-vmware-to-xcp-ng/?ref=xen-orchestra.com) Additionally, we've expanded our XCP-ng documentation to include more alternative migration paths for VMware users: [Migrate to XCP-ng | XCP-ng DocumentationHow to migrate from VMware, KVM, etc. to XCP-ng.![](https://docs.xcp-ng.org/img/xcpcrop128.png)XCP-ng Documentation![](https://docs.xcp-ng.org/assets/images/xoa-v2v-1-3ce4bcbcf7edd4d024cae535628f1a27.png)](https://docs.xcp-ng.org/installation/migrate-to-xcp-ng/?ref=xen-orchestra.com#-from-vmware) ### XCP-ng R&D: full throttle ahead Our commitment to research and development is stronger than ever, as we invest significant resources into the future of virtualization. We're in it for the long haul, dedicated to pushing the boundaries of technology. Don't miss our two blog posts exploring new possibilities for running Xen on ARM architectures and also the related work on enhanced device management in Xen with IOMMU paravirtualization: [Integrating Xen on the Ampere Platform: a first lookHere’s our initial update on integrating Xen into an Ampere-based platform.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOleksii Kurochko![](https://xcp-ng.org/blog/content/images/2024/03/altra.jpg)](https://xcp-ng.org/blog/2024/04/03/integrating-xen-on-the-ampere-platform-a-first-look/?ref=xen-orchestra.com) [IOMMU paravirtualization for XenA technical article describing our current work on IOMMU PV for Xen.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogTeddy Astie![](https://images.unsplash.com/photo-1550751827-4bd374c3f58b?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDEzfHxzZXJ2ZXJ8ZW58MHx8fHwxNzEzMzY5NTY0fDA&ixlib=rb-4.0.3&q=80&w=2000)](https://xcp-ng.org/blog/2024/04/18/iommu-paravirtualization-for-xen/?ref=xen-orchestra.com) ### Future storage stack updates Exciting progress on SMAPIv3! We’ve developed our first "usable" local driver utilizing ZFS. For more details on this significant advancement, check out the full blog post: [First SMAPIv3 driver is available in previewLearn more and test our first SMAPIv3 preview driver, using ZFS.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOlivier Lambert![](https://xcp-ng.org/blog/content/images/2024/04/zvolsr.jpg)](https://xcp-ng.org/blog/2024/04/19/first-smapiv3-driver-is-available-in-preview/?ref=xen-orchestra.com) ### XCP-ng Security Update Don’t forget to keep your XCP-ng hosts up-to-date! For the latest updates on security measures, take a look at our recent security bulletin: [April 2024 Security UpdateSecurity update for Xen latest XSAs.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogDavid Morel![](https://xcp-ng.org/blog/content/images/2024/04/computer-6560745_1920.jpg)](https://xcp-ng.org/blog/2024/04/13/april-2024-security-update/?ref=xen-orchestra.com) --- Let's talk about our new XO release now! As usual, the full change log is [available on this link](https://github.com/vatesfr/xen-orchestra/blob/master/CHANGELOG.md?ref=xen-orchestra.com#5940-2024-04-30). ## 💠 XOSTOR We're thrilled to officially introduce XOSTOR, our new hyperconverged storage system developed in partnership with [LINBIT](https://linbit.com/?ref=xen-orchestra.com). This collaboration represents a significant milestone in our mission to provide a fully integrated solution for any virtualized environments. [Take off with XOSTORXOSTOR is the latest addition to Vates VMS and brings the power of hyperconvergence to your infrastructure. With XOSTOR, users can efficiently consolidate their server local storage spaces, creating a robust Virtual SAN that enhances data accessibility and resource management.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogChristopher Weatherwax![](https://images.unsplash.com/photo-1591616369924-833532b76ebc?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDIyfHxjb252ZXJnZW5jZXxlbnwwfHx8fDE3MTQxMzk3NzN8MA&ixlib=rb-4.0.3&q=80&w=2000)](https://xen-orchestra.com/blog/take-off-with-xostor/) But that's not all: alongside the official launch, we've also made substantial improvements to the user interface. Now, you can easily configure XOSTOR to suit your specific needs, whether it involves multiple disks, diskless nodes, or other configurations. Additionally, we've enhanced visibility into the network setup for replication, ensuring a seamless experience for managing your storage infrastructure. ![](https://xen-orchestra.com/blog/content/images/2024/04/xostor-1.png) ### Select networks/interfaces With this update, you can now specify which network interface XOSTOR will use to replicate blocks. This allows for greater flexibility in optimizing network traffic and ensuring efficient data replication across your infrastructure: ![](https://xen-orchestra.com/blog/content/images/2024/04/321338038-d12777a6-0872-425f-8795-b9b4696e4634.png) ### LINSTOR health check Now, you can access information about your LINSTOR cluster directly from the XO UI. Simply navigate to the XOSTOR tab within the SR view to gain insights into the health of your LINSTOR setup: ![](https://xen-orchestra.com/blog/content/images/2024/04/325241932-4cae93e2-38b4-491d-bd2a-f4c34de0a985.png) As always, we value your feedback. If you encounter any issues or have suggestions for improvement, please don't hesitate to share them with us on our forums, in the dedicated section: [XOSTORXCP-ng community forum![](https://xcp-ng.org/forum/assets/images/touch/512.png)XCP-ng![](https://xcp-ng.org/forum/assets/uploads/system/site-logo.png)](https://xcp-ng.org/forum/category/20/xostor?ref=xen-orchestra.com) ## 💾 Backup We’ve made several minor improvements this month, focusing mainly on bug fixes. Additionally, we’ve enhanced the automated backup health-check experience. ### Health-check timeout configuration Now, you can configure the health-check timeout to suit your needs. By default, it's set to 10 minutes, but for VMs that take longer to boot—especially when using advanced health checks like application-specific validations—you can adjust this timeout. Modify the timeout setting in your `config.toml` file under the`[backups.defaultSettings]` section: ``` healthCheckTimeout = '10 minutes' ``` ## 📡 REST API We're excited to introduce new endpoints to our REST API, making it even easier to track live events! ### Expose audit log records Access detailed audit logs through the new endpoint `/rest/v0/plugins/audit/records`, ensuring all activities are securely recorded and tamper-proof. By the way, let's use this example to call the REST API with something else than `curl` and discover that it could be done with `xo-cli rest get`: ``` $ xo-cli rest get 'plugins/audit/records' limit=2 [ 'plugins/audit/records/$5$$cbd3e34d6882728a1fc8ebb9bb6f9fa5dd30710eb420648b75f1315df7326a18', 'plugins/audit/records/$5$$80db6f58739f4dd65596a0b0135627ee9caef919831b14d4e5ddecf369e3311e' ] $ xo-cli rest get 'plugins/audit/records/$5$$6456cfdba8baa14f740110933766e56741c5e0d06cebe3e7f19697a336c71939' { data: { callId: '5xcm7ixbosr', duration: 41799, method: 'proxy.upgradeAppliance', params: { id: '73382711-6072-42f5-b805-afbcb74269db' }, result: true, timestamp: 1714298152094 }, event: 'apiCall', id: '$5$$6456cfdba8baa14f740110933766e56741c5e0d06cebe3e7f19697a336c71939', previousId: '$5$$80db6f58739f4dd65596a0b0135627ee9caef919831b14d4e5ddecf369e3311e', subject: { userId: 'eb9bdc88-99bc-422a-a453-57623271f273', userIp: '::ffff:10.200.200.10', userName: 'julien.fontanet' }, time: 1714298152094 } ``` ### Implement watchmode for tasks collection The watch mode in the REST API is particularly useful because it enables real-time monitoring of system activities directly from your terminal or application interface. When you enable watch mode on the tasks collection endpoint, it dynamically streams updates about tasks as they happen. This means you can immediately see when a task is added, updated, or removed without needing to manually refresh or poll the server for updates. The new endpoint `/rest/v0/tasks?ndjson&watch` will display a flow of events in live, for example: ``` ["remove",{"id":"0lv13orww","href":"/rest/v0/tasks/0lv13orww"}] ["update",{"id":"0lv13otzz","properties":{"method":"acl.getCurrentPermissions","params":{},"name":"API call: acl.getCurrentPermissions","userId":"287d34e8-e5ca-48b3-bf32-8499fa167211","type":"api.call"},"start":1713194362080,"status":"pending","updatedAt":1713194362080,"href":"/rest/v0/tasks/0lv13otzz"}] ``` Yes, you can now start a `curl` or `xo-cli rest get` and see the tasks being displayed and tracked dynamically in your terminal! ## 🐦 VMware to Vates (V2V) It’s been nearly two years since the debut of our V2V tool, and it keeps getting better. Driven by a surge of VMware users with diverse configurations, we’ve been continuously refining our approach. Notably, Xen Orchestra transfers data directly through vCenter or ESXi's API without needing direct storage access, making it robust and versatile. Thanks to extensive feedback from our vibrant community and customers, we've enhanced our V2V tool significantly: - **Bypassing the XO HTTP Proxy**: we've refined the V2V tool to access internal resources directly, bypassing the XO HTTP proxy which is not suited for internal data flows. - **Multi-datacenter Support**: with the latest updates, you can connect to a centralized vCenter to manage and migrate resources across multiple data centers seamlessly. - **Enhanced VM Metadata Parsing**: we've improved our ability to interpret and utilize a broader array of VM metadata options found in the `.vmx` file, expanding compatibility and simplifying migrations for diverse environments. And that's not it… We now finally support… 🥁 ### vSAN datastore migration We've successfully integrated support for another VMware storage type: vSAN, which utilizes a distinct format compared to VMFS versions 5 and 6\. Migrating VMs from a vSAN datastore was a complex challenge, primarily because vSAN does not allow direct access to underlying VMDK files. Nevertheless, we've developed a method that enables effective migration of your VMs to XCP-ng, though it requires shutting down the VM first, and the process isn't the fastest. But it works! ![](https://xen-orchestra.com/blog/content/images/2024/04/vsan1-1.jpg) Interestingly, this update coincides with the availability of XOSTOR, allowing for a seamless transition from vSAN to XOSTOR storage solutions. ## 🚀 XCP-ng 8.3 features As we approach the release of XCP-ng 8.3, our focus is to ensure that Xen Orchestra is fully compatible from day one. ### PCI passthrough A key feature in development is PCI passthrough via the API, aimed at simplifying its implementation directly through the XO UI. This feature required extensive groundwork, including the development of a new API structure in close collaboration with the XAPI project. You can track Benjamin’s contributions and our joint efforts here: [PCI passthrough API by benjamreis · Pull Request #5542 · xapi-project/xen-apiAs discussed here: xapi-project/xapi-project.github.io#286 New methods: PCI.disable\_dom0\_access: Hide a PCI from dom0 kernel PCI.enable\_dom0\_access: Unhide a PCI from dom0 kernel PCI.get\_dom0\_acce…![](https://github.githubassets.com/assets/pinned-octocat-093da3e6fa40.svg)GitHubxapi-project![](https://opengraph.githubassets.com/01390fb5c9f2ef324dacac6decbf68a4b164ead0fe198e258679f2a8d695db74/xapi-project/xen-api/pull/5542)](https://github.com/xapi-project/xen-api/pull/5542?ref=xen-orchestra.com) And we already packaged the update: [PCI passthrough API in XAPI by benjamreis · Pull Request #62 · xcp-ng-rpms/xapiSee: xapi-project/xen-api#5542![](https://github.githubassets.com/assets/pinned-octocat-093da3e6fa40.svg)GitHubxcp-ng-rpms![](https://opengraph.githubassets.com/10c043e6f427a7ec8110d5209f011c8dfb5d076840a9b5001dac00843dc32710/xcp-ng-rpms/xapi/pull/62)](https://github.com/xcp-ng-rpms/xapi/pull/62?ref=xen-orchestra.com) Although it’s not fully integrated into 8.3 yet, we’ve taken the initiative to merge our progress into XO UI in anticipation. This early integration means there may be initial hiccups, but we're preparing for a seamless experience in the upcoming updates. Stay tuned for the official package release! #### List the PCI devices available on the host In the host view, Xen Orchestra now displays a list of all PCI devices available on your host. An "Enabled" row indicates that the devices are hidden from Dom0 and are available for passthrough to any VM. ![](https://xen-orchestra.com/blog/content/images/2024/04/311300384-a956d297-a252-465a-b033-56403899c162.png) #### Attach a PCI device to a VM A new button in the Advanced View of your VM allows for the selection and attachment of available PCI devices to the VM. This interface also displays currently attached devices, providing immediate utility regardless of your XCP-ng version: ![](https://xen-orchestra.com/blog/content/images/2024/04/312148747-81329a36-f8d8-4068-ad85-32f4360c61a4.png) ## 🔭 XO 6 & XO Lite We're excited to share updates on our new user interface, leveraging the unified components from both XO Lite and XO 6\. For a closer look at our sleek, redesigned components, remember to check out our [public Figma showcase](https://www.figma.com/file/l2O2VvzJRnOCvqxhM7d124/1.-Vates---Product-Design-System?type=design&node-id=11-733&mode=design&ref=xen-orchestra.com). ### New components implemented We've implemented innovative icon components that enhance information delivery through a single icon, simplifying the interface while enriching user interactions. Similar advancements have been made with "object" icon components, designed to intuitively represent VM, SR, or network states: ![](https://xen-orchestra.com/blog/content/images/2024/04/324744994-2f9837c5-e579-4976-bbe7-1f73f75528ab.png) ![](https://xen-orchestra.com/blog/content/images/2024/04/323147554-81aee01b-769c-43c6-99f8-e0e8c7588055.png) ### XO 6 general layout The introduction of the new "base" layout marks a significant advancement, featuring a CoreLayout component with a structured interface including a header, resizable sidebar, content header, main content, and a right panel. This layout is ready for internationalization, keyboard shortcuts, and smarter REST API connectivity. ![](https://xen-orchestra.com/blog/content/images/2024/04/324853900-80291109-1c0d-4091-b156-576f7030cbae.png) We're gearing up to unveil a preview of XO 6 next month via a dedicated /v6 endpoint, incorporating adaptive design elements for varying screen sizes and detailed improvements for a more efficient and dynamic user experience. ### XO 6 Treeview The first treeview for XO 6 is also finished, and can be now integrated in the previous layout: ![](https://xen-orchestra.com/blog/content/images/2024/04/xo6---tree-view.png) We are really eager to make this visible next month! ### XO Lite `0.2.2` If we’ve completed the first treeview for XO 6, and it’s now seamlessly integrated into our new layout. This development enhances navigation and organization, making it easier to manage and access various components. For XO Lite, this tree view is also now exactly like the Figma template: ![](https://xen-orchestra.com/blog/content/images/2024/04/xo-lite---tree-view.png) We are thrilled to showcase this feature next month, bringing a more intuitive and streamlined experience to XO 6! [Release xo-lite-v0.2.2 · vatesfr/xen-orchestraThe global orchestration solution to manage and backup XCP-ng and XenServer. - Release xo-lite-v0.2.2 · vatesfr/xen-orchestra![](https://github.githubassets.com/assets/pinned-octocat-093da3e6fa40.svg)GitHubvatesfr![](https://opengraph.githubassets.com/c8b0b19359a7c49c814e8f27d5670a74aab3752d8baafa78a80a5db1253ca324/vatesfr/xen-orchestra/releases/tag/xo-lite-v0.2.2)](https://github.com/vatesfr/xen-orchestra/releases/tag/xo-lite-v0.2.2?ref=xen-orchestra.com) ## **🆕** Misc In addition to the standout features of this release, we've also rolled out several smaller but equally valuable updates. These enhancements, though minor, are designed to improve user experience and system functionality, demonstrating our commitment to continuous improvement across all aspects of our platform. ### RPU & RPR task tracking We've expanded the use of XO tasks to include long, asynchronous, or complex operations, such as Rolling Pool Update (RPU) and Rolling Pool Reboot (RPR). These operations are now fully tracked, providing detailed insights into each stage of the process, from evacuating a host to applying updates. This enhancement ensures greater transparency and allows users to monitor the progress of each sub-task more effectively. ![](https://xen-orchestra.com/blog/content/images/2024/04/xotask.png) ### Enhanced Secure Boot feedback When creating a VM, we've added a new feature to enhance security awareness: if secure boot is enabled but the pool is not set up to support it, a clear message will now be displayed. This ensures that users are fully aware and not misled into believing their VM is protected by secure boot when it is not. This update enhances security transparency and user understanding of VM setup requirements. ![](https://xen-orchestra.com/blog/content/images/2024/04/324857125-54327541-7c00-4812-ac6a-c0d618c83723.png) ### Japanese translation This addition reflects our commitment to inclusivity and accessibility, ensuring that our platform can be enjoyed by a broader global audience. Whether you're a native Japanese speaker or simply prefer to navigate in Japanese, you can now experience Xen Orchestra with ease, thanks to this new translation. A big thanks to [Taki Yasushi](https://github.com/kohju?ref=xen-orchestra.com) for his work! ![](https://xen-orchestra.com/blog/content/images/2024/04/image-2.png) ### Take off with XOSTOR URL: https://xen-orchestra.com/blog/take-off-with-xostor/ Last updated: 2024-05-13T07:45:41.000Z We're excited to announce that the eagerly awaited release of XOSTOR 1.0 is almost here! Transitioning from its beta phase, XOSTOR will officially launch on April 30th, coinciding with the release of Xen Orchestra 5.94\. This milestone marks its readiness for production environments, offering users a seamless upgrade and enhanced functionality. 📹 Join us live on our [YouTube channel](https://www.youtube.com/@Vates%5Ftech?ref=xen-orchestra.com) this Tuesday, the 30th at 3 PM CEST, for our special release session! Tune in to witness the launch and get firsthand insights directly from our team. ![](https://xen-orchestra.com/blog/content/images/2024/04/Xen-Orchestra-5.93-Socail-Media-1-.png) ### 🤝 A Powerful Alliance Creating a Powerful Tool XOSTOR is the new hyperconvergence addition to Vates VMS, positioning itself as a compelling alternative to vSAN. This release is the culmination of four years of dedicated collaboration with our partner, LINBIT, the developers behind the DRDB software that forms the foundation of XOSTOR. With XOSTOR, users can efficiently consolidate their server local storage spaces, creating a robust Virtual SAN that enhances data accessibility and resource management. ![](https://xen-orchestra.com/blog/content/images/2024/04/xostor-hyper-converged-infrastructure-invert.svg) ### ✉️ Setting up your XOSTOR We continue our commitment to delivering top-tier experiences with your Virtual Management System, highlighted by the introduction of our new tool, XOSTOR 1.0\. If you are considering deploying XOSTOR 1.0 in your production environment, please contact us. We will assign a dedicated team member to facilitate a seamless integration of XOSTOR and ensure a smooth rollout and an excellent POC. [Contact us](https://vates.tech/contact/?ref=xen-orchestra.com) ⚠️ XOSTOR is currently compatible only with ****XCP-ng 8.2** and designed for infrastructures ranging ****from 3 to 7 hosts per pool**. ### 🏗️ Creating a Trial If you're eager to discover the full range of features and capabilities that XOSTOR offers, you can initiate a demo directly within XOA. This demo provides you with a month of access to all the functionalities of XOSTOR, allowing you to experience the power of hyperconvergence with your infrustructure. ⚠️ XOSTOR allows for the deployment of one trial per user. Should you require a reset or wish to establish an additional trial with XOSTOR, please submit your request through our [contact form](https://vates.tech/contact/?ref=xen-orchestra.com)! #### 1\. Updating Hosts and XCP-ng Patches: Before starting a trial you must update all of your hosts and apply all XCP-ng patches before deploying XOSTOR. If you have not deployed XOSTOR before, you can simply update your hosts and apply XCP-ng patches as you normally would. 💡 If you had deployed XOSTOR in the past (during the Beta phase), you need to update your hosts, but you won't be able to use the Rolling Pool Update features. The proper methods for updating your hosts and applying XCP-ng patchs can be found in our [XCP-ng Update Documentation](https://docs.xcp-ng.org/management/updates/?ref=xen-orchestra.com#pool-updates). #### 2\. Update XOA: The next step is updating your XOA. To access XOSTOR you will need to update to the "latest" branch of the 5.94 XO release. Both the "latest" branch and "stable" branch are production ready environments. The "latest" branch provides updates as soon as they become avliable and the "stable" branch provides those same updates a month after release. Once you have updated your XOA reboot the updated hosts. #### 3\. Install XOSTOR: After rebooting and logging into your XOA, you are ready to begin your trail of XOSTOR. To do this, select XOSTOR from the menu on the left side of your screen. ![](https://xen-orchestra.com/blog/content/images/2024/04/Capture-d--cran-de-2024-04-17-15-50-42.png) Once inside of the XOSTOR Menu, if you have not created an XOSTOR Cluster before, you will see the menu below. ![](https://xen-orchestra.com/blog/content/images/2024/04/Capture-d--cran-de-2024-04-26-17-07-04.png) To create your XOSTOR click "+ New". This will begin the creation of your first XOSTOR hyperconvergence system. After selecting "+ New", you will then see the form for creating your XOSTOR Cluster containing, a storage name, a pool where to install the storage and disks that will be used for creating the XOSTOR cluster. Once the form is compleated, click "+ Create" to launch your first XOSTOR. After creating your XOSTOR you will be redirected directed to the general tab of the freshly created storage. 💡 An XOSTOR Trial License can only be created once. If you do not have a current trial license or have not had one in the past, one will be created automatically when you click "+ Create" ![](https://xen-orchestra.com/blog/content/images/2024/04/image-1.png) Congratulations on creating your first XOSTOR Hyperconvergence storage. Don't forget to view our end of month [Youtube live](https://www.youtube.com/@Vates%5Ftech?ref=xen-orchestra.com) session on Tuesday the 30th of April for more information and updates to Vates VMS. ### Xen Orchestra 5.93 URL: https://xen-orchestra.com/blog/xen-orchestra-5-93/ Last updated: 2024-03-29T14:31:21.000Z In the latest Xen Orchestra release, we are talking about exciting advancements include many new partnerships, but also brings improvements and bug fixes in backup functionalities, VMware to Vates (V2V) import capabilities, and high availability features directly manageable from Xen Orchestra. Furthermore, USB passthrough is now more accessible, and there's notable progress on Project Pyrgos for Kubernetes cluster creation. The update also focuses on user experience improvements with various UI enhancements. 🎵 And [here is the podcast version](https://podcasters.spotify.com/pod/show/vates7/episodes/Episode-14---VMware-to-Vates-improvement--High-Availability--XO6-improvements-and-more-e2hnf21?ref=xen-orchestra.com) of the release! ## 👨‍🚀 Project & Community March was also a very very busy month. Since the CloudFest, we announced so many things, I don't know where to start! ### Back from the CloudFest If you want to read what happened there, you can read the full recap here: [CloudFest 2024: highlightsCloudFest 2024 has been a landmark event for our team, filled with pivotal announcements and significant moments. While you may have caught some of the headlines last week (see below), there’s much more to share about our experiences and the promising opportunities that unfolded! Bringing modern virtualization in the Arm-powered![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogOlivier Lambert![](https://vates.tech/blog/content/images/2024/03/AE3ABAB6-6508-4D1B-950C-49A5BBD7BAFA-1.jpg)](https://vates.tech/blog/p/c00d5a12-608c-4f14-bd3e-dd2c6cfc7f43/?ref=xen-orchestra.com) To put it simply, we connected with hundreds of people, showing them how our technology works through many live demos, including with a real server at our booth. We also had great talks with big companies like OVH, Hetzner, HPE, SuperMicro… which was really exciting for us! But first, let's focus on the actual partnership we announced 👍 ### Our first OEM partnership with a server manufacturer In partnership with [2CRSi](https://2crsi.com/?ref=vates.tech), known for their efficient and powerful computing solutions, we, at Vates, are introducing an important advancement in server technology: the [Mona series](https://2crsi.com/mona-series-servers-mainstream?ref=vates.tech), powered by AMD, bundled with XCP-ng out-of-the-box! [Simplifying IT: 2CRSi’s Mona Servers with XCP-ng OnboardVates announces a partnership with 2CRSi at CloudFest! Discover Mona servers with XCP-ng pre-installed, simplifying server management and enhancing Xen Orchestra integration for a seamless out-of-the-box experience![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogOlivier Lambert![](https://vates.tech/blog/content/images/2024/03/2255566-epyc-family-full-width-01.jpg)](https://vates.tech/blog/simplifying-it-2crsis-mona-servers-with-xcp-ng-onboard/?ref=xen-orchestra.com) Read the article to learn more about the great tech specs of those machines, and if you are interested, **please let us know in the form.** The exact pre-configured models are not set yet, we want to discuss that with you so we can provide the best configurations available! ![](https://vates.tech/blog/content/images/size/w1000/2024/03/Mona-1.44-rear.png) ### A new partner: IONOS, hosting/Cloud provider Yes: We've teamed up with [IONOS](https://www.ionos.com/?ref=vates.tech), a giant in cloud services, and we are working to get our virtualization platform XCP-ng as a "turnkey" option (ie pre-installed) in the servers you want to rent. This is all about making it simpler for you to set up your own private cloud, offering an alternative to the usual options like an hosted VMware environment for example. [Vates and IONOS partnershipDiscover how our partnership with IONOS will help you to deploy XCP-ng very quickly on a turnkey environment.![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogOlivier Lambert![](https://vates.tech/blog/content/images/2024/03/ionos.jpg)](https://vates.tech/blog/vates-and-ionos-partnership/?ref=xen-orchestra.com) But first, to build the best offers, we need to know exactly what kind of offers you would be interested into. Like how many machines, the environment and such. With this kind of information, IONOS and us could build together the most adapted offer for your business. **So please, fill the form in there so we can keep in touch: you'll have both someone from Vates and IONOS on the line to understand your requirements!** ![](https://xen-orchestra.com/blog/content/images/2024/03/unclesam.png) We need your feedback to build those offers! ### Technological collaboration with Ampere Computing [Bringing modern virtualization in the Arm-powered DatacenterLearn about our exciting collaboration with Ampere Computing, a major stride in advancing efficient virtualization within the datacenter.![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogOlivier Lambert![](https://vates.tech/blog/content/images/2024/03/ampereblogpost.jpg)](https://vates.tech/blog/bringing-modern-virtualization-in-the-arm-powered-datacenter/?ref=xen-orchestra.com) We are thrilled to announce the start of a technical collaboration project between us and [Ampere Computing](https://amperecomputing.com/?ref=vates.tech), pioneer in energy-efficient & high performance arm-based processors. This not a "short term" collaboration, in fact pretty much the opposite. It's a commitment to open our world from x86 to Arm in the datacenter. The road is long, but we have now a powerful ally to help us delivering a battle-tested solution on top of their cool CPUs! ### VEEAM as supported agent-based backup solution If you are a VEEAM fan, be assured that you can use VEEAM agents in XCP-ng VMs to do your "application-aware" backups. [We added it in the XCP-ng documentation](https://docs.xcp-ng.org/project/ecosystem/?ref=xen-orchestra.com#veeam). Note that we have many users here coming originally from VMware & VEEAM, finding Xen Orchestra easier to use for VM backups. However, if you are a hardcore fan of it, feel free to [let VEEAM knows about it](https://forums.veeam.com/veeam-backup-replication-f2/xcp-ng-support-t93030.html?ref=xen-orchestra.com), so they can build a native VM backup capability into it. ![](https://xen-orchestra.com/blog/content/images/2024/03/veeam.png) --- And now, it's time to talk about our XO release! The full [changelog is available here](https://github.com/vatesfr/xen-orchestra/blob/master/CHANGELOG.md?ref=xen-orchestra.com#5930-2024-03-29). ## 💾 Backup This month, while we didn't introduce new features in the backup area, we focused on enhancing existing functionalities and resolving bugs. Most notably, after years of refinement, we're proud to announce that our S3-backup feature has achieved stable status, having operated flawlessly for months. Similarly, our backup encryption has proven its reliability and moves beyond beta to be deemed production-ready. ## 🐦 VMware to Vates (V2V): another import capability Our current process for importing VMs from VMware directly connects to your ESXi host or vCenter to pull all VM metadata and data, streaming this content into XCP-ng. For older VMware versions, we can reduce downtime significantly. However, for VMware versions above 6.5 using VMFS, disk file locks prevent snapshot exports. To address this, we’ve introduced a workaround: - On VMware, you'll need to create an NFS datastore and migrate your VM disks to it. - In Xen Orchestra, connect to this NFS datastore and name it `[VMWARE]datastorename`, where `datastorename` is the exact name of the datastore on VMWare side. This connection allows Xen Orchestra to bypass the disk locks and directly fetch VM disks from the NFS share, facilitating a smoother import process regardless of the VMware version. This new method provides flexibility and efficiency in VM imports, offering a solution to the challenges presented by newer VMware versions. ## 🔄 High Availability While it was possible to set it with the `xe` CLI before, it's now possible to enable XCP-ng HA directly from Xen Orchestra. First, please read more about it in our XCP-ng documentation: [High availability | XCP-ng DocumentationHigh availability (or HA) in XCP-ng world is the ability to detect a failed host and automatically boot all the VMs that were running on this host to the other alive machines.![](https://docs.xcp-ng.org/img/xcpcrop128.png)XCP-ng Documentation![](https://docs.xcp-ng.org/img/xcpcrop128.png)](https://docs.xcp-ng.org/management/ha/?ref=xen-orchestra.com) Then, to enable it, you need to go in the Pool "Advanced" tab and toggle the "High Availability" setting: ![](https://xen-orchestra.com/blog/content/images/2024/03/317220059-2f1a07f5-3d85-4ee1-a4ef-3289f7d6f6f0.png) Then, a modal window will let you set the heartbeat SR: ![](https://xen-orchestra.com/blog/content/images/2024/03/317220949-c3f0c00f-d71f-4bb0-9d3a-84f64d1c0ecf.png) You can also disable it easily, which is **required for every maintenance task**: ![](https://xen-orchestra.com/blog/content/images/2024/03/317220644-89d0f27f-cf75-474a-bbbf-e095f7223904.png) ⚠️ High Availability (HA) management requires thorough understanding before activation, ****as improper use can ironically decrease service availability**. Enabling HA in an unstable network or storage environment may lead to frequent host reboots and lower uptime. The essential consideration is whether HA is a desire or a necessity for your business operations; if it's merely a want, it might be best to reconsider its implementation. ## 🔭 XO 6 and XO Lite We continue to work on the new UI, both for XO 6 and XO Lite, sharing the same base components. ### New components This month, we've introduced numerous new components, closely aligned with the design system we unveiled last month. We're nearing completion on crafting these from the UX designs, setting the stage for their integration into the new user interfaces for both XO 6 and XO Lite. The progress showcases the extensive effort put into development recently, although not all components are displayed here, it gives a glimpse into the work accomplished. ![](https://xen-orchestra.com/blog/content/images/2024/03/314470226-7a18afce-a626-47d0-a585-17873047616e.png) The tag component ![](https://xen-orchestra.com/blog/content/images/2024/03/314426917-579133c2-d5da-458c-b5f8-8e364f76c171.png) The "chip" component ![](https://xen-orchestra.com/blog/content/images/2024/03/313113386-5f394e8d-3e6c-4a86-b279-816f20f90310.png) The UiCounter component ![](https://xen-orchestra.com/blog/content/images/2024/03/305477751-c9014ab8-5160-4424-ab98-86c4d6416acb.png) ![](https://xen-orchestra.com/blog/content/images/2024/03/305477719-81665e3b-d086-410f-979d-e5349d213a68.png) The Tree view component ![](https://xen-orchestra.com/blog/content/images/2024/03/311637052-4ac376f7-9389-4f6a-9430-0080d9c76343.png) ![](https://xen-orchestra.com/blog/content/images/2024/03/311637032-aa725847-982c-4e4d-975e-1b476d8d1f90.png) ![](https://xen-orchestra.com/blog/content/images/2024/03/311636984-96f80f65-75c2-4f91-81ef-0dedecbc22aa.png) The UiButton component ![](https://xen-orchestra.com/blog/content/images/2024/03/308660211-3eb62744-a0fc-4d3a-bfcd-802d4846d292.png) ![](https://xen-orchestra.com/blog/content/images/2024/03/308660476-170913b0-8580-4565-9b3c-433ef5f09139.png) The dropdown component Our intensive development phase is nearing completion, preparing us to start incorporating the newly developed components into the XO Lite and XO 6 interfaces. With this groundwork laid, you can anticipate seeing tangible updates in the UI next month, marking a significant milestone in our project's progress. ## ⚖️ Load balancer We've introduced a feature in the load balancer plugin allowing the spread of VM vCPUs across the maximum number of physical CPUs, enhancing performance by optimizing hypervisor scheduling. ![](https://xen-orchestra.com/blog/content/images/2024/03/299960144-ca7f69c8-1496-4efa-9377-ab9d92c661c9.png) This optimization kicks in when pool usage is below 40%, ensuring efficient resource allocation without unnecessary overhead. While this setting isn't customizable yet, we're open to feedback for future adjustments. This strategy ensures VMs are primed for peak performance when needed, utilizing available physical cores to their fullest. ## 🖱️ USB passthrough USB passthrough functionality is now integrated into Xen Orchestra's web UI, allowing for straightforward management of USB devices. From the host's 'Advanced' tab, users can view and enable available USB devices, making them assignable to VMs: ![](https://xen-orchestra.com/blog/content/images/size/w1000/2024/02/308502576-78318517-a7a4-4127-989c-54461af81c97.png) Additionally, within the VM's "Advanced" view, it's possible to create and attach vUSB devices to the VM: ![](https://xen-orchestra.com/blog/content/images/2024/03/image.png) 💡 Note that while new USB devices can only be connected when the VM is off, they can be unplugged while the VM is running. ## ☸️ Project Pyrgos (k8s) Over the past few months, there hasn't been much news about our project Pyrgos, which simplifies the process of creating a Kubernetes cluster from the Xen Orchestra UI with just a few clicks. The reason behind this silence is that we've been dedicated to enhancing its capabilities. We've transitioned from utilizing apt for the installation of Kubernetes binaries to a more reliable method that guarantees the capacity to install every version we list. Significant updates have been made, including upgrading `containerd` to version 1.7.13, CNI plugins to version 1.4.0, `Crictl` to version 1.29.0, and `Runc` to version 1.1.12, which notably addresses a severe vulnerability CVE-2024-21626. ![](https://xen-orchestra.com/blog/content/images/2024/03/image-1.png) Additionally, we've laid the groundwork that will enable us to manage clusters directly from XOA, marking a significant advancement in our project's development! ## **🆕** Misc Another busy month, even for the "Misc" section! ### Using ISO 8601 format for numeric dates Initially, Xen Orchestra displayed dates in the user interface language, accommodating 11 different languages. Yet, almost all our users are setting the application language in "English", and they found the US date format confusing and impractical, especially for sorting (sorry for my US friends in here). To address this, we've adopted the ISO 8601 standard, which is both universal and user-friendly, facilitating easier handling and consistency across various regions. This change aims to enhance usability and efficiency in managing dates within Xen Orchestra. Before: ![](https://xen-orchestra.com/blog/content/images/2024/03/314451499-5ffa8f13-c970-471b-9334-882dd8dd8962.png) And after: ![](https://xen-orchestra.com/blog/content/images/2024/03/314158806-89d8ed93-e32b-4f42-889a-b7e36421b013.png) If you want to learn more about it, you have this excellent Wikipedia article: [ISO 8601 - Wikipedia![](https://en.wikipedia.org/static/apple-touch/wikipedia.png)Wikimedia Foundation, Inc.Contributors to Wikimedia projects![](https://upload.wikimedia.org/wikipedia/commons/4/45/MontreGousset001.jpg)](https://en.wikipedia.org/wiki/ISO%5F8601?ref=xen-orchestra.com) ### Automatically create a vTPM when needed When you select a vTPM-required template (like Windows 11), XO will automatically create the vTPM device for the VM. XO is fetching this information from the template itself. ### OTP now requires validation This prevents users from forgetting to add OTP account in their application and thus being locked out from their own XO: ![](https://xen-orchestra.com/blog/content/images/2024/03/314006524-fee4b474-1611-43e3-abad-15fe304c5184.png) ### OTP supported on the JSON-RPC API When we introduced OTP support in XO, we enforced the check during the login on the web UI. However, it wasn't checked during the usage of our JSON-RPC API. It's now required to also use it, for example with our XO CLI tool: ``` xo-cli --register --otp 157218 xo.example.org jane.smith Password: ********* Successfully logged with jane.smith ``` 💡 The REST API isn't affected because you need to generate first a token from it. ### Show current tags in advanced tag creation Previously, adding a color to an existing VM tag in Xen Orchestra required searching for the tag, a cumbersome process especially with multiple tags. Now, there's a streamlined way to view all your tags and easily modify their colors, enhancing usability and efficiency in tag management ![](https://xen-orchestra.com/blog/content/images/2024/03/309801627-89abe989-bb50-40db-ae7e-67779654e096.png) ### Boot firmware check If you are using a VM template that does NOT support BIOS (or UEFI), you will be warned if you decide to change for an incompatible boot firmware: ![](https://xen-orchestra.com/blog/content/images/2024/03/316892495-6fa2e0d7-16bb-4679-9dca-7c796d355567.png) To do that, we read the recommendation that built-in within the template itself. ### Default SR is easier to setup Previously, you could already setup a default SR by hovering on your SR list and clicking on a dedicated icon. However, the discoverability of this feature was sub-optimal, so we decided to add a dedicated selector in the SR/Advanced tab: ![](https://xen-orchestra.com/blog/content/images/2024/03/310907200-2526c6b9-82a3-4c4c-a678-baf3bb091aaf.png) ### Replug all VIFs and PIFs after MTU change During our last release, we added the capability to change the MTU. However, you needed to either reboot your host or replug all the physical interface objects (PIFs) for the change to take effect. XO will do that replug automatically for you now! ### Display console zoom While it was already possible to zoom on your VM/host console, it wasn't really practical with only a slider.. We added a field to enter a percentage value (100% by default), so you can zoom and unzoom pretty easily to the level of your choice! ![](https://xen-orchestra.com/blog/content/images/2024/03/314115813-95131b52-b98c-4aa8-846a-23db6f237a33.png) ### Display more information for auth tokens data We improved the view that's displaying all the auth tokens in use, with capital information: the last used date for the token but also the IP address using it. This way, you can monitor really easily what's going on. ![](https://xen-orchestra.com/blog/content/images/2024/03/313710548-5bde196b-6725-4552-a0ce-c5115616fb16.png) It's a global improvement on security, because you could easily spot things that are not usual. ### Remove a protected template All the "default" templates (bundled with XCP-ng) are protected against deletion, and it's the same for templates coming from VMs with the "protect from deletion" attribute. Now, if for whatever reason you want to delete them, you can from XO directly. ![](https://xen-orchestra.com/blog/content/images/2024/03/316943602-df4bc33f-9c34-4f36-899e-29626e3b18d8.png) ### Correctly report large BR size It could have been only a bug fix, which is usually not presented here but in our changelog. However, this change is meaningful for people with large backup repository, where we can now correctly report the size used and the total size! ### Xen Orchestra 5.92 URL: https://xen-orchestra.com/blog/xen-orchestra-5-92/ Last updated: 2024-02-29T15:36:35.000Z Right after the Chinese New Year, we're bringing out XO 5.92\. This new update comes with lots of new features that we're excited about. We're all about being open here: not just with our code, which we've always shared, but now with the whole project too. This means it's easier for you to see what we're planning and to help out if you want. We hope you like what you find in this latest version! 🎵 And [here is the podcast version](https://podcasters.spotify.com/pod/show/vates7/episodes/Episode-13---Backup-retry--refreshed-XO-Appliance-e2gf0fq?ref=xen-orchestra.com) of the release! ## 👨‍🚀 Project & Community Welcome back to our regular section where we dive into the latest happenings with Xen Orchestra and the broader [Vates community](https://vates.tech/?ref=xen-orchestra.com). It's always exciting to share what's new and how our project continues to evolve, thanks to the vibrant community that supports us. ### Popularity Yes, it's happening! The shift from VMware is real, and the numbers back it up. To put it simply, everything has doubled: our website visitors, trial requests, inquiries, and community engagement. It's clear we're on a rapid ascent to becoming even more well-known and loved ❤️ But don't worry, we're staying true to what sets us apart: our commitment to openness (and we're not just talking about our software) and transparency. Now, more than ever, you can rely on us. Let's look at some exciting stats from February, which, by the way, outdid January's record: - Forum activity soared with a 30% increase in unique visitors (reaching 311,000) and posts jumped by more than 60%. - Registrations for XOA and trial sign-ups doubled: yes, increased by 100%! This is truly remarkable. - Requests for demos went through the roof, up by 300%. And no, that's not a typo. **But it's not just about more people visiting; it's about deeper engagement from those who do**. This is crucial for us, and we're thrilled to see such vibrant participation. ### Articles, podcasts & videos Our technology is getting a lot of attention lately, which means more people are talking and writing about us. We've put together a list of some really interesting stuff related to what we do. One thing you shouldn't miss is an interview with one of our team on the "Great Things with Great Tech!" podcast by Anthony Spiteri. It's a great way to learn more about our journey and what we're working on. Also, check out a piece by StarWind Software that talks about how to switch to using our technology. It's full of helpful tips and shows why making the switch can be a good move. Even TrueNAS is listing us in their recent blog post about VMware alternatives! [Community Driven Open Source Virtualization with Vates | Episode #78In this episode, we sit down with Olivier Lambert, CEO and co-founder of Vates, the innovative company behind XCP-ng and Xen Orchestra. Established in Grenoble, Fra…![](https://images.podpage.com/https%3A%2F%2Fd3t3ozftmdmh3i.cloudfront.net%2Fproduction%2Fpodcast_uploaded%2F6409516%2F6409516-1654831774363-a5a7cd1154f8d.jpg?auto=format&h=720&w=180&s=dea54675d8071f11ac9a988d647fc81a)Great Things with Great Tech!Great Things with Great Tech!![](https://images.podpage.com/https%3A%2F%2Fimages.podpage.com%2Fhttps%3A%2F%2Fimages.podpage.com%2Fhttps%253A%252F%252Fd3t3ozftmdmh3i.cloudfront.net%252Fproduction%252Fpodcast_uploaded%252F6409516%252F6409516-1654831774363-a5a7cd1154f8d.jpg%3Fblend-alpha%3D75%26blend-color%3DA72B97%26blend-mode%3Dnormal%26blur%3D500%26fill%3Dblur%26fit%3Dcrop%26h%3D630%26ixlib%3Dpython-4.0.0%26w%3D1200%26s%3D76c306598346c12100786e684b28e8b3%3Fblend%3Dhttps%3A%2F%2Fimages.podpage.com%2Fhttps%253A%252F%252Fd3t3ozftmdmh3i.cloudfront.net%252Fstaging%252Fpodcast_uploaded_episode%252F6409516%252F6409516-1707401206090-f5e662827debe.jpg%3Fh%3D550%26ixlib%3Dpython-4.0.0%26w%3D550%26s%3D2e77e3b065b6a98eed8bc4e4c16dda50%26blend-align%3Dleft%2Ctop%26blend-mode%3Dnormal%26blend-x%3D40.0%26blend-y%3D40.0%26ixlib%3Dpython-4.0.0%26mark%3Dhttp%3A%2F%2Fassets.imgix.net%2F~text%3Fw%3D530.0%26txt64%3DQ29tbXVuaXR5IERyaXZlbiBPcGVuIFNvdXJjZSBWaXJ0dWFsaXphdGlvbiB3aXRoIFZhdGVzIHwgRXBpc29kZSAjNzg%253D%26txt-align%3Dleft%252Ctop%26txt-size%3D50%26txt-color%3DFFFFFF%26txt-font%3DAvenirNext-DemiBold%26mark-x%3D630.0%26mark-y%3D40.0%26s%3D2128a664dbc4c9699f807b12ce509e0f?auto=format&fill=blur&fit=fill&h=630&w=1200&s=f11789e8faa32cb9b855085e0a4ad5c1)](https://www.gtwgt.com/community-driven-open-source-virtualization-with-vates-episode-78/?ref=xen-orchestra.com) [Exploring XCP-ng: A Cost-Effective VMware Alternative | StarWind BlogHow to discover the benefits of XCP-ng, an open-source virtualization platform that offers a cost-effective and fully-featured alternative to VMware. Learn how migrating to XCP-ng can reduce costs and provide flexibility, with insights on ease of transition and the advantages of choosing a community-driven solution.![](https://www.starwindsoftware.com/blog/wp-content/uploads/2022/02/favicon.png)StarWind BlogVladan Seget![](https://www.starwindsoftware.com/blog/wp-content/uploads/2024/02/1200x628@2x.png)](https://www.starwindsoftware.com/blog/why-you-should-consider-xcp-ng-as-an-alternative-to-vmware?ref=xen-orchestra.com) [Beyond VMware: Exploring Virtualization AlternativesExplore community-driven insights on virtualization alternatives to VMware. TrueNAS offers compatibility and flexibility for various hypervisors.![](https://www.truenas.com/wp-content/uploads/2020/08/cropped-TN-favicon-284x284.png)TrueNAS - Welcome to the Open Storage EraLadislav Sirový![](https://www.truenas.com/wp-content/uploads/2024/02/Top-Alelternatives-for-VMware.png)](https://www.truenas.com/blog/exploring-virtualization-alternatives-to-vmware?ref=xen-orchestra.com) Also there's many new great YouTube videos from Tom (Lawrence Systems): - [How to get started with Vates ](https://www.youtube.com/watch?v=2wMmSm%5FZeZ4&ref=xen-orchestra.com)[VMS (XCP-ng+XO)](https://www.youtube.com/watch?v=2wMmSm%5FZeZ4&ref=xen-orchestra.com) - [XCP-ng networking explained](https://www.youtube.com/watch?v=H5PJ%5FtHQlZk&ref=xen-orchestra.com) - [How to setup Windows VMs with vTPM](https://www.youtube.com/watch?v=MqHuNu4hjJo&ref=xen-orchestra.com) 2GuysTek also made a [video about "XCP-ng vs ESXi"](https://www.youtube.com/watch?v=cSwmtg7sJb4&ref=xen-orchestra.com). Oh and finally, if you are a Reddit fan, notice there's a [dedicated xcpng subreddit](https://www.reddit.com/r/xcpng/?ref=xen-orchestra.com) since a while, but it started to be really alive recently! ### XO CONTRIBUTING.md We've always had guidelines for [contributing in our documentation](https://xen-orchestra.com/docs/contributing.html?ref=xen-orchestra.com), but we decided it was time for an upgrade to make it even more straightforward. That's why we've introduced a `CONTRIBUTING.md` file right at the root of our Git repository. Now, it's simpler for anyone who wants to get involved with the project to see exactly how to do it. This update is all about making it easier for you to become a part of our community! ### Our design is now public Exciting news for our community and UX/UI enthusiasts! As promised last month, we've now made our entire Figma design system publicly accessible. This open approach to our design process allows everyone to view, comment, and even contribute to the development of our future interfaces and components. 💡 If you want to provide a feedback on this design system, [we created a dedicated thread on our community forum to discuss it!](https://xcp-ng.org/forum/topic/8490/our-new-design-system?ref=xen-orchestra.com) This move to share our UX/UI work publicly is a testament to our commitment to transparency and community involvement. By opening up our design process, we invite feedback and ideas that can help shape the future of our platforms, ensuring they meet the needs and expectations of our users. [![](https://xen-orchestra.com/blog/content/images/2024/02/Design-System---Screenshot-1.png)](https://www.figma.com/file/l2O2VvzJRnOCvqxhM7d124/1.-Vates---Product-Design-System?type=design&node-id=11-733&mode=design&ref=xen-orchestra.com) Whether you're a designer, developer, or simply interested in the behind-the-scenes of product development, you can now dive into our Figma files to explore the thought process behind our interfaces. It's a great opportunity to see how we're working to make Xen Orchestra & XO Lite more intuitive, efficient, and user-friendly. Check out our Figma designs today and be a part of shaping the future of Xen Orchestra: [Discover our Design System](https://www.figma.com/file/l2O2VvzJRnOCvqxhM7d124/1.-Vates---Product-Design-System?type=design&node-id=11-733&mode=design&ref=xen-orchestra.com) After clicking on the link, to see all the design system, you need to click on the top left menu and select the components you want to see: ![](https://xen-orchestra.com/blog/content/images/2024/02/image-3.png) If you don't remember what's a "Atom/Molecules/Organism", please refer to our previous blog post: [Unleashing the Power of Atomic Design SystemExploring the Atomic Design System in open-source virtual infrastructure: enhancing user experiences, inclusivity, and accessibility while empowering teams.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogClémence Barthoux![](https://xen-orchestra.com/blog/content/images/2023/05/Cover.png)](https://xen-orchestra.com/blog/unleashing-the-power-of-a-unique-atomic-design-system/) ### Using Packer with XCP-ng In an insightful contribution from our community member, [Cécile](https://www.linkedin.com/in/cecilemorange/?ref=xen-orchestra.com) (a big thank you!), we're excited to share a new post that dives into the practicalities of utilizing Packer with XCP-ng. This guide walks you through a hands-on example of building a Debian 12 VM from scratch, fully automated with Packer. It's an excellent resource for those looking to streamline their VM creation process. We're committed to producing more guides of this nature in the future. Your expertise and insights are invaluable to us, and [we encourage anyone interested in contributing to our blog to reach out](https://vates.tech/contact?ref=xen-orchestra.com). We place great importance on community-generated content, recognizing its potential to enrich our collective knowledge base and support others in their journey with XCP-ng. [Using Packer with XCP-ngDiscover how to keep your VM templates always up-to-date and ready to go!![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogCécile MORANGE![](https://xcp-ng.org/blog/content/images/2024/02/packerxcpng.jpg)](https://xcp-ng.org/blog/2024/02/22/using-packer-with-xcp-ng/?ref=xen-orchestra.com) ### XCP-ng 8.3 beta 2 After seven months of relentless effort, we're thrilled to present the second beta release of XCP-ng 8.3\. This milestone reflects our team's dedication and commitment to enhancing the XCP-ng platform. While we're excited about the progress, please note that this version remains a beta. It's not yet recommended for deployment in critical production environments due to its pre-release status. The updates and improvements are too numerous to detail in this brief announcement. Therefore, we encourage you to explore the full range of enhancements and features by visiting the following link: [XCP-ng 8.3 Beta 2XCP-ng 8.3 Beta 2 is now available.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogSamuel Verschelde![](https://xcp-ng.org/blog/content/images/2024/02/xcpng83beta2.jpg)](https://xcp-ng.org/blog/2024/02/15/xcp-ng-8-3-beta-2/?ref=xen-orchestra.com) ### Join us at CloudFest 2024! We're excited to [announce our participation in CloudFest 2024](https://vates.tech/blog/cloudfest-2024/?ref=xen-orchestra.com), the premier event for the world's leading cloud, hosting, and internet service providers. This year is especially significant as we celebrate CloudFest's 20th anniversary at the iconic Europa Park. It's set to be the most memorable edition yet, with an array of engaging activities and networking opportunities. This is a unique opportunity to connect with our leadership team, including CEO & Co-Founder Olivier Lambert, CMO Marc-André Pezin, and Channel Partner Răzvan Roșca. We're eager to discuss the future of cloud technology and share insights into the Vates Roadmap for 2024\. Expect to hear about our innovative upcoming features, the latest bundle offers for the Vates Virtual Management Stack, and the launch of our new partner campaign, VMove. Join us to discover how these developments can transform your business operations and enhance your service offerings. ![](https://xen-orchestra.com/blog/content/images/2024/02/52812024709_3bf49b13f4_c.jpg) --- And now, let's talk about our new XO release! ## 💾 Backup You know the drill: we always start to talk about backup. ### Backup retry This feature was asked since a while, but we wanted to be sure to do it right. Now, you can configure a number of retries if the VM backup fails. It's pretty easy to do, in your backup job configuration: ![](https://xen-orchestra.com/blog/content/images/2024/02/303700908-aae6448c-8b9e-44fd-b703-339222453cd7.png) This can be useful if you had a transient issue (like a network glitch during your backup job), leaving you more chances to make it instead of just realizing on the morning that it just failed. In the backup log, you can see (for example) when the first try was failed, it made an attempt after that succeeded: ![](https://xen-orchestra.com/blog/content/images/2024/02/307077256-156754de-3811-4967-bbfd-e8d6587fcad0.png) Don't forget to set a number of retry that won't cause you issues, 2 or 3 seems to be a sweet spot to avoid transient issues while still error out rather quickly if you have a bigger problem. ### Improved VHD loop detection Our [mirror backup capability](https://xen-orchestra.com/docs/mirror%5Fbackup.html?ref=xen-orchestra.com) is a great feature. However, it can be tricky to synchronize many backup mirrors at once when one is failing and not the others. So we needed to be certain to validate the chain to send the right incremental to each mirror. In short, we refactored the code to reuse something that's already doing it, making the result both better and simpler. ## 🪐 New XOA Our previous XOA was built 3 years ago, with an old XOA version (5.60) and also Debian 11\. We finally took time to regenerate a new fresh XOA, and this time we are building it in a fully automated fashion, [thanks to Packer!](https://xcp-ng.org/blog/2024/02/22/using-packer-with-xcp-ng/?ref=xen-orchestra.com) This new XOA is available as we speak when you make a new deploy, and if you want to switch to the new one, just follow our documentation: [Vates Knowledge Base - Migrate to new XOA![](https://help.vates.tech/favicon.ico)Migrate to new XOA![](https://help.vates.tech/api/v1/attachments/46162)](https://help.vates.tech/help/en-us/9-xen-orchestra-appliance-xoa/31-migrate-to-new-xoa?ref=xen-orchestra.com) Anyway, it's now based on Debian 12 fully up-to-date, and we'll regenerate the XOA more often (maybe once a quarter or even once a month, we'll see). ## 📡 REST API We added 2 endpoints this month, both from customer & community request. Don't forget to ask for what you need in the [dedicated forum section!](https://xcp-ng.org/forum/category/18/rest-api?ref=xen-orchestra.com) ### Expose user's groups and group's users To be able to fetch user's groups and group's users. For example, if you want to get the name of the group for a user (and their URL to request for details): ``` curl \ -X GET \ -b authenticationToken=KQxQdm2vMiv7j \ 'https://xo.company.lan/rest/v0/users//groups?fields=name' ``` This will return: ```json [ { "name": "administrators", "href": "/rest/v0/groups/b19d3685-ce23-4d7d-9b32-62f8902a29e4" }, { "name": "developers", "href": "/rest/v0/groups/9c7f5831-533b-4821-8d67-5d6d192e2af8" } ] ``` 💡 Reminder: if you want to list all the users, just GET on [https://xo.company.lan/rest/v0/users](https://xo.company.lan/rest/v0/users?ref=xen-orchestra.com). It's the same principle for groups. And to list all users from a group: ``` curl \ -X GET \ -b authenticationToken=KQxQdm2vMiv7j \ 'https://xo.company.lan/rest/v0/groups//users?fields=email' ``` ```json [ { "email": "user@example.net", "href": "/rest/v0/users/eb9bdc88-99bc-422a-a453-57623271f273" } ] ``` ### Host SMT/Hyperthreading status Few years ago, we added a plugin in XCP-ng to detect if a host was using hyperthreading/SMT. It's useful for security but also for licensing reasons (eg when you use a proprietary system in a VM, the number of cores can be important. Glad, happy that's nothing to worry about with XCP-ng!). Despite being exposed in the UI, we've been asked to add it in the REST API. It's now done: ``` curl \ -X GET \ -b authenticationToken=KQxQdm2vMiv7j \ 'https://xo.company.lan/rest/v0/hosts//smt' ``` It will return this: ```json { "enabled": true } ``` #### Another upstream contribution To remove the need of a dedicated plugin, we made a contribution upstream in the XAPI project to directly include this information in the host API/database: [Add ‘threads\_per\_core’ in ‘Host.cpu\_info’ by benjamreis · Pull Request #5464 · xapi-project/xen-apiDiscussed here: #5462![](https://github.githubassets.com/assets/pinned-octocat-093da3e6fa40.svg)GitHubxapi-project![](https://opengraph.githubassets.com/dbf6ff3552c63c5922a96f55e014c7413e7b8c283788c0cec78e8c61bea6b57d/xapi-project/xen-api/pull/5464)](https://github.com/xapi-project/xen-api/pull/5464?ref=xen-orchestra.com) It should be merged soon, and might land in XCP-ng 8.3 at some point. ## 🔭 XO 6 and XO Lite Those two projects are going to share more and more components, that's why we are doing one section for both this month. ### XO Lite 0.2.0 We're aligning XO Lite updates with Xen Orchestra releases. The latest XO Lite 0.2.0 is now part of XCP-ng 8.3, ready for you through Xen Orchestra's available updates or a `yum update`. 💡 If you're using XCP-ng 8.2 and want to test XO Lite 0.2.0 without making any changes to your host, just visit your host's URL in your browser (ensure you use https) to confirm the certificate. Then, navigate to the following URL, substituting "host\_IP\_address" with your actual host's IP address: [https://lite.xen-orchestra.com/#/?master=host\_IP\_address](https://lite.xen-orchestra.com/?ref=xen-orchestra.com#/?master=host%5FIP%5Faddress). This easy step lets you explore XO Lite's new features instantly! ### Back end work Behind the scenes, there's a lot of important work happening that you might not see, but it's key to making everything better. Right now, we're focusing on moving parts of our user interface, like certain components, tools, and helpers, into something called `web-core`. This is so both XO Lite and XO 6 can use them more effectively. This foundation work is really important. It involves a lot of discussions and meetings to improve how we organize and name parts of our system in web-core. Getting this right is crucial for building a strong base for all the new features and improvements we want to bring you in the future. #### A great collection system To address the similarities across different component behaviors (such as treeview, multiselect, tasks/subtasks, etc.), we have developed a versatile system for managing data collections and their child elements. Each item within a collection can be activated, selected, or filtered, and is also assigned a list of CSS classes based on its status (`active`, `selected`, `matches`). Furthermore, an element can serve as a group, containing children and introducing new behaviors (like expansion, descendant selection, and tracking descendant selection status) along with additional CSS classes (`selected-partial`, `selected-full`, `expanded`). An optional feature also allows for programmatic navigation within a collection (for instance, binding functions to keyboard keys to move through items), enhancing user interaction and accessibility. ### New tree view components The tree view is kind of the biggest new interactive component we need in both XO Lite (already there) and XO 6 (coming with a more complete capabilities, since it could orchestrate many many pools). We took time to update the tree view UI components to match the new version of the design system (see the Figma design system). We also added visual indicators (vertical and horizontal lines) to connect items: ![](https://xen-orchestra.com/blog/content/images/2024/02/305477719-81665e3b-d086-410f-979d-e5349d213a68.png) ![](https://xen-orchestra.com/blog/content/images/2024/02/305477751-c9014ab8-5160-4424-ab98-86c4d6416acb.png) We also updated icons placement and styles: a new `VmIcon.vue` component for VM power state and updated `UiCounter.vue` component to match design system's last version. Also, we moved all UI menu components into web-core (will be used for "quick actions" dropdowns), and finally added automatic indentation for sub lists. ### New dropdown components We've completely revamped all our dropdown components to align with our Design System. This update is a big step in bringing our design principles into the real world, creating a seamless match between theory and practice: a challenge we're proud to have tackled successfully. Now, our dropdowns not only look better but also work more smoothly, enhancing your experience with our interface. ![](https://xen-orchestra.com/blog/content/images/2024/02/308660476-170913b0-8580-4565-9b3c-433ef5f09139.png) ### Custom scrollbar We had to make improvements for the scrollbar, which can be used at many places in XO Lite and XO 6\. That's why we changed only browsers native CSS properties to avoid accessibility issues, and providing a better integration and consistency within the design system. ![](https://xen-orchestra.com/blog/content/images/2024/02/303590597-fa4d4e5e-7cbf-445a-bc87-fea9d13c8e4a.png) ### Improve color context The purpose of the color context is to colorize a component and its descendants by applying a single CSS class on the parent component (e.g., applying the class on a modal component container will style all children components using the context). It's a pretty long and complicated thing to do, but crucial to give a consistent and accessible result for everyone, regardless where you are in the application. In terms of concrete actions: - Updated the color context: use CSS custom properties/variables (instead of CSS properties like `background-color` in the precedent version) for better flexibility on the component level - Any component can use the context by applying these variables on any CSS property - Integration side, we only need to apply the context color on the parent component (info, success, warning, error), and children components will automatically inherit the color (no need to configure the `color` prop on each component) - If we need to override one component's color, we can still configure the color with a `color` prop or with CSS ## ⚖️ Load balancer In our load balancer feature, you now have the option to stop it from moving certain hosts or VMs. This can be useful if you have a host or VM that you don't want to be moved around. You can set this up by using the "Excluded hosts" setting for each plan you have. There's also a setting for VMs called "Ignored VM tags," which works for all your plans. This way, you can keep some hosts or VMs in place, even when the load balancer is adjusting others to keep things running smoothly. ![](https://xen-orchestra.com/blog/content/images/2024/02/exclude.JPG) ## **🆕** Misc Like every month, we have a lot of small updates to share. This section covers all the little changes we've made to make XO better. These might be small fixes or improvements, but they all add up to help make everything run more smoothly and make your experience better. Keep an eye out for these updates, as they're all about making things easier and more reliable for you. ### USB passthrough development Responding to widespread user requests, we've initiated the development to integrate USB passthrough functionality directly within Xen Orchestra's user interface. As a preliminary step in this process, users can now view available USB devices from the 'Advanced' tab in the host view. This feature allows you to "enable" a USB device, preparing it for passthrough to a virtual machine (VM). ![](https://xen-orchestra.com/blog/content/images/2024/02/308502576-78318517-a7a4-4127-989c-54461af81c97.png) This update marks the beginning of our efforts to simplify USB passthrough, making it more accessible and manageable directly from Xen Orchestra's UI. We're excited to announce that the upcoming XO 5.93 release is set to include the complete process for connecting your USB devices to VMs seamlessly. 💡 In the meantime, for users looking to use USB passthrough today, the [XCP-ng documentation](https://docs.xcp-ng.org/compute/?ref=xen-orchestra.com#%EF%B8%8F-usb-passthrough) remains a valuable resource, offering detailed instructions on achieving this via the CLI. ### Manage auto power on pool level In XCP-ng, the "auto power on" functionality is crucial for ensuring VMs automatically start up following a host reboot. This feature, however, requires enabling at both the individual VM and the pool levels to work effectively. Recognizing the potential for oversight, Xen Orchestra introduces a streamlined process to manage this feature more efficiently. In short, when "auto power on" is activated for a VM, Xen Orchestra will intelligently ensures it's also enabled at the pool level, if it wasn't already. This automation removes a manual step, facilitating a smoother setup process. But a problem may arise when importing a VM that already has "auto power on" activated but the pool setting remains disabled. Previously, this mismatch would prevent the VM from auto-starting after a host reboot, leading to potential service disruptions. That's why we added to new capabilities. First, you can now directly enable "auto power on" at the pool level via the pool's advanced settings. This ensures that all VMs within the pool are eligible for auto-start, provided their individual settings are also configured. ![](https://xen-orchestra.com/blog/content/images/2024/02/307041723-02606ac8-cbec-4ed1-ab09-debdc5ac76ac.png) And then, even better: if there's a discrepancy -such as when a VM is set to auto power on but the pool setting is disabled- XO now alerts you to this inconsistency. This notification allows you to promptly rectify the configuration, ensuring seamless auto-start functionality: ![](https://xen-orchestra.com/blog/content/images/2024/02/307042594-ac4968b4-6908-42b0-a3e2-92d203459467.png) ### Robots.txt To enhance privacy and security, we've introduced a default `robots.txt` file in Xen Orchestra. This measure is designed to prevent search engines from indexing Xen Orchestra instances, addressing concerns about visibility on the internet. With this update, users can have peace of mind knowing their Xen Orchestra interface won't appear in search engine results, adding an extra layer of protection against unwanted online exposure. 💡 If you're planning to expose your Xen Orchestra to the Internet, it's crucial to enhance your security measures. ****Always enable** Two-Factor Authentication (2FA) or use authentication protocols like OpenID Connect or SAML. These added layers of security significantly reduce the risk of unauthorized access, ensuring that only verified users can interact with your XO environment. Implementing these security features is essential for safeguarding your infrastructure against potential online threats. ### New XAPI stat format The recent XCP-ng 8.3 update introduced a new version of XAPI (v23.31), leading to an unexpected issue where Xen Orchestra was unable to properly display statistics. This issue was quickly identified thanks to the vigilance of our community and the collaborative efforts of our XCP-ng, Xen Orchestra & XO Lite teams. Upon investigation, two main changes were discovered to be the cause: a bug that scrambled the JSON file generated by XAPI, and a modification in the JSON structure itself, which now utilizes strings for all values instead of integers or floats. The reason for that: dealing with `NaN`, `Infinity` and `-Infinity` cases. Thanks to the prompt and efficient teamwork between our community and developers, these issues have been resolved in both XCP-ng, Xen Orchestra & XO Lite with this latest release. **This experience highlights the strength and effectiveness of our collaborative approach, demonstrating how community engagement and developer responsiveness can lead to swift problem resolution and improvements in our ecosystem.** ### Sort XO config backups Addressing a practical aspect of Xen Orchestra's usability, we've refined how XO configuration backups are presented during the restoration process. Previously, the list of available backups was displayed in an unsorted and reverse order, which could be confusing and inefficient for users trying to locate a specific backup. We've implemented a fix to sort these backups logically, now displaying them from the most recent to the oldest. This small but significant adjustment streamlines the restoration process, making it more intuitive and less time-consuming to find and restore the desired XO configuration backup. ![](https://xen-orchestra.com/blog/content/images/2024/02/image-1.png) ### New units added (PiB and TiB) To stay ahead of technological advancements and cater to environments requiring large-scale storage management, we've expanded the unit options available when defining the size of objects within Xen Orchestra. Recognizing the growing need for handling vast amounts of data, users can now select from additional units, including Pebibytes (PiB) and Tebibytes (TiB), when specifying storage sizes: ![](https://xen-orchestra.com/blog/content/images/2024/02/304765854-9fd8f76c-9f07-465c-8f18-26bf2cee5e06.png) ### Enhanced VM container logic In Xen Orchestra, we've refined how we handle the `VM.$container` field, which indicates the current location or association of a virtual machine (VM). Initially, the logic was straightforward: if a VM was running or paused, it was considered to be residing on a physical host, and thus the `$container` would reflect the host's UUID. Conversely, if the VM was stopped, it was associated with the pool. We've now improved this logic to better accommodate scenarios where a VM's booting options are limited to a single host due to storage constraints. Specifically, when a VM's disk resides on a Storage Repository (SR) that is local to a particular host, it's clear that the VM can only be started on that host, regardless of its current state. In such cases, we maintain the $container as the host's UUID, even if the VM is not currently running. This update provides a more accurate representation of a VM's potential locations and constraints, improving the management and scheduling of VMs within Xen Orchestra. ### Network change MTU In the Pool/network tab, you can now change the MTU for the network: ![](https://xen-orchestra.com/blog/content/images/2024/02/306277049-0249ee5e-afe3-4b9e-95d3-4385566307b1.png) ⚠️ ****Is adjusting the MTU worth it?** Changing the MTU size is often considered by network administrators aiming to optimize network performance. However, the general advice regarding MTU adjustments is cautious: it's typically not necessary. The decision to modify the MTU should be made with specific requirements in mind, as it can introduce complexity and potential issues. Many support cases and community discussions have highlighted problems arising from incomplete configurations, especially related to jumbo frames on network switches. ### Add link to VM for suspend VDIs In our latest update, we've made it easier to identify which suspend VDIs are associated with which VMs in the SR/disk view. A suspend VDI, which stores the memory (RAM) of a VM during snapshot or suspension, previously lacked a direct link to its corresponding VM. This enhancement addresses that issue by clearly displaying and linking each suspend VDI to its respective VM, improving clarity and management in the interface: ![](https://xen-orchestra.com/blog/content/images/2024/02/306014389-570533db-a48d-424e-ad41-b0bcc32d8ec2.png) ### Xen Orchestra 5.91 URL: https://xen-orchestra.com/blog/xen-orchestra-5-91/ Last updated: 2026-02-16T16:11:30.000Z Welcome to our inaugural 2024 release! This update is particularly robust, featuring an array of new additions: **it's one of our largest in terms of new features**. A special shout-out to our new users transitioning from VMware; your enthusiasm is greatly propelling the entire Vates ecosystem, including XCP-ng and Xen Orchestra. In case you haven't heard, we've introduced a new 'bundled' pricing structure. For more details on this, please check out the following link: [Introducing Vates Virtualization Management StackIn 2024, we are going to introduce new offerings that will embed both XCP-ng Pro Support and Xen Orchestra Appliance: the Bundles.![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogMarc-André Pezin![](https://vates.tech/blog/content/images/2023/11/newpricingbundle-1.jpg)](https://vates.tech/blog/introducing-vates-virtualization-management-stack/?ref=xen-orchestra.com) ## 👨‍🚀 Project & Community We have a multitude of topics to discuss, yet we've chosen to concentrate on the most significant ones. ### Our insights on the VMware exodus As one of the leading alternative to VMware, we're right at the heart of the action, engaging with numerous companies exploring their options or already actively transitioning. Our recognition in the "[Gartner Virtualization Market Guide](https://vates.tech/blog/vates-continued-recognition-in-gartners-server-virtualization-guide/?ref=xen-orchestra.com)" for two consecutive years certainly helps, but there's more to the story. And we wanted to share that with you! Our numbers clearly illustrate the trend: - More than 95% of our new customers are coming from VMware. - We're handling migrations for installations of all sizes, ranging from a few hosts in small businesses to extensive networks in universities and hospitals. - Smaller systems typically migrate more quickly (thank you Captain Obvious!) - For larger setups, we strategically migrate sections that are simpler to transition. This approach helps mitigate risks associated with VMware's pricing changes and gradually reduces dependency. Our platform demonstrates that managing our stack doesn't have to be daunting – a Linux expertise isn't a necessity. Our role in the market is not just about "winning awards" or being quoted in a Gartner guide; it's about making a real difference with easy-to-use solutions for our customers. Finally, we've noticed that VMware partners are greatly affected by Broadcom's new policy changes. To address this, we've specifically designed a supportive program tailored for them: [VMOVE Campaign: Unlock 40%-70% Partner Margins with Our Exclusive OfferFrom Jan. 8 to April 01st 2024, embark in a lucrative journey as a Vates’ Partner and get extra partner margin credit for each customer you are migrating from VMware to Vates VMS.![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogMarc-André Pezin![](https://vates.tech/blog/content/images/2024/01/DALL-E-2024-01-04-16.50.07---Create-an-abstract-and-artistic-banner-for-the-blog-post-titled--VMOVE-Initiative_-Unlock-40--70--Partner-Margins-with-Our-Exclusive-Offer-.-The-banne--1---1-.png)](https://vates.tech/blog/vmove-get-40-to-70-of-partner-margin-special-operation/?ref=xen-orchestra.com) ### **Our community's rapid growth** We're really **excited to see our community booming more than ever**. Whether it's the number of people visiting our websites, engaging in our forums, or signing up: everything's shooting up! We're talking about a solid 30% to 50% jump in pretty much all areas. It's incredible to see such enthusiasm and growth. And hey, with so many new faces around, we thought it'd be great to put together something helpful. So, we've crafted a fresh, easy-to-follow guide for getting started with XCP-ng & Xen Orchestra, which we're calling "Vates VMS." It's perfect for anyone who's just joining us and wants to dive right in: [How to start with Vates Virtualization Management StackKickstart your Vates VMS journey with these top tips: how to install XCP-ng, deploy XOA, create your VMs, configure your backup jobs and leverage our pro support.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogMarc Pezin![](https://xen-orchestra.com/blog/content/images/2024/01/12photostory--nDIecoK1nQ-unsplash.jpg)](https://xen-orchestra.com/blog/how-to-start-with-vates-virtualization-management-stack/) ### XCP-ng security updates A nice bug fix (but also a security issue) has been fixed recently. You can read more details here: [January 2024 Security UpdateSecurity update for the netback network driver in the Linux kernel.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogDavid Morel![](https://xcp-ng.org/blog/content/images/2024/01/secpatchjan.jpg)](https://xcp-ng.org/blog/2024/01/26/january-2024-security-update/?ref=xen-orchestra.com) Don't forget to keep an eye on the ["security" tag](https://xcp-ng.org/blog/tag/security/?ref=xen-orchestra.com) to filter our blog post on XCP-ng security releases. ### Updated Linux/FreeBSD Rust tools Here we go again – another month, another cool update for our Rust guest tools. This time, we've gone the extra mile with a statically linked dependency. What does this mean for you? Well, it boils down the entire deployment process to just a single binary. Talk about making things more convenient! [Rust guest tools 0.4.0Explore what’s new in our new Rust guest tools.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOlivier Lambert![](https://xcp-ng.org/blog/content/images/2024/01/guestrusttools040.jpg)](https://xcp-ng.org/blog/2024/01/29/rust-guest-tools-0-4-0/?ref=xen-orchestra.com) ### Open Source XenCenter is dead So, XenCenter as an open-source project is officially a thing of the past. Cloud Software Group, through its XenServer division, has decided to pull the plug on it. And how did they announce it? Just a quiet update in the README file – a classic move. The message was clear: the XenCenter repository is archived, no more updates, no more pull requests: > Please note that as of December 2023 this copy of the XenCenter repository is considered archived. As such it will not reflect the latest state of XenCenter development, and any pull requests will not be reviewed/merged. If you have any feedback regarding XenCenter, please send it to [feedback@xenserver.com](mailto:feedback@xenserver.com). Here's the source for those who want to see it firsthand: [https://github.com/xenserver/xenadmin/#xencenter](https://github.com/xenserver/xenadmin/?ref=xen-orchestra.com#xencenter) It's a "subtle" exit from the open-source world for another component. And yes, they can do that, thanks to the BSD-2 license. This just goes to show how crucial open-source software (OSS) licenses are. We take pride in using aGPLv3 for XO – it's a big deal for us. What's the fallout from this move? Well, Borzel, a key community contributor for XCP-ng Center, which is a fork of XenCenter, has [decided to stop contributing](https://xcp-ng.org/forum/topic/8202/eol-xcp-ng-center-has-come-to-an-end?ref=xen-orchestra.com). But it's not all bad news. We're now helping him shift his contributions to XO Lite! In a way, this is positive for us all, as it means we're shedding another dependency on the upstream XenServer. And it seems this might be just the beginning. XenServer's reluctance to collaborate on shared components has been a recurring theme. But here's our take: if collaboration isn't on the cards, we're just going to do things better on our own. 🤷‍♂️ ### Doubling down on Open Source While XenServer seems to be retreating (again) from the open-source ethos (seriously, how many times already?), we're going full throttle in the opposite direction. Our mission? To make contributing straightforward and accessible for everyone. It's all about transparency and sharing. For instance, **our Figma designs will be completely open to the public in the next weeks**. This move is a clear invitation for you to jump in and start developing alongside us. We've also wrapped up a new architecture that lets us share components between XO 6 and XO Lite (see below in the release details).. With this new setup, we're gearing up to review our external code contributions very soon. Why is this a big deal? Well, with our community growing by the day, just think of the massive impact this could have on XCP-ng, XO, and XO Lite. It's all about harnessing the collective power of our community to make things even better! ### Expanding our support team Big news on the team front: Dan P, a standout figure and a [familiar name on our forums](https://xcp-ng.org/forum/user/danp?ref=xen-orchestra.com), has officially joined the Vates family. He's stepping into the support team, bringing his wealth of knowledge and experience with him. And yes, he'll definitely keep on being a pillar of support for our community! 💡 Fun fact: Dan P is the second community member to join our ranks. This speaks volumes about the talent in our community and the great opportunities we offer. We're proud to see our active members become key team players! ![](https://xen-orchestra.com/blog/content/images/2023/10/astronaut.png) --- **Now let's dive into this month's release. Brace yourselves, it's a substantial one with lots to cover!** ## 🐦 VMware to Vates (V2V): now 20 times faster Reflecting on the VMware shift: It's been a year since we launched our V2V tool, designed to streamline your VM migration from VMware to XCP-ng. This tool is a real game-changer – with just a few clicks, your VMs are seamlessly replicated on the other side: ![](https://xen-orchestra.com/blog/content/images/2024/01/xoa-v2v-2-1-.png) **We've achieved a monumental leap in transfer speed for our V2V tool**. In our internal tests, we've astonishingly increased the speed of VM transfers from VMware to XCP-ng by nearly 20 times! Take our test case, for example: an Ubuntu VM with a 25GiB size, of which only 4GiB is actively utilized. Check out the dramatic difference in our 'before and after' results: It's not just one trick that did the job, but a mix of smart changes. Let's start with the 'import' side on XCP-ng. We ditched the old VHD import system and switched to the XVA format, leveraging the super-fast [xxHash algorithm](https://xxhash.com/?ref=xen-orchestra.com). Sure, generating XVA on XCP-ng (exporting) isn't lightning-fast, but when it comes to importing, it's way better than handling a VHD. Here's another cool thing about using XVA behind the scenes: unlike VHD, you don't need to read the entire VMware disk to create the block allocation table (BAT). This means we can really stream the disk, ensuring a 'thin' replication every single time in just one read. Now, all imports are thin by default! And there's more. We've also tweaked how we query VMware, opting for more sequential reads when we can. All these changes combined? In our lab, they rocketed a sluggish 10MiB/s transfer speed to a whopping 200MiB/s! Results might vary, but we're expecting this level of improvement for nearly everyone. If your network is the bottleneck (like if it's less than 1Gbit), you've still got options. Run the XOA VM on top of your VMware cluster. Why? Because between XOA and XCP-ng, we eliminate the zeros. For instance, in our lab, we hit about 330 MiB/s in read speed with XO on the VMware host, maxing out the 1Gbit/s link to send the "removed-zero-disk" to XCP-ng. Your feedback is always welcome in [our dedicated thread](https://xcp-ng.org/forum/topic/6714/vmware-migration-tool-we-need-your-feedback?ref=xen-orchestra.com). ## 💾 Backup In the realm of backups, the advancements we've achieved with our V2V tool and its fast XVA import hold promising potential for future developments. For the present, though, we're excited to announce a significant new feature currently in preview: immutability! ### Immutability (preview) We made a pretty long explanation/intro on it last month, you can take a look if you missed it: [Xen Orchestra 5.90Xen Orchestra 5.90, marks a significant milestone in backup and XO Lite.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2023/12/xo590.jpg)](https://xen-orchestra.com/blog/xen-orchestra-5-90/#advancements-in-on-prem-immutability) But this month, you can test it in preview mode! Here is how to install and operate it directly in your Backup Repository (BR). 💡 It's pretty easy to install and run it into any Linux box with an NFS share, acting as your Backup Repository (BR). We wanted to have a first "target" that is pretty simple to deal with, but expect a broader compatibility in the future, as our solution gets more flexible. We started to develop a solution in NodeJS to deliver fast, but it won't be an issue to get a simple "drop-in" binary in Rust or Go. #### Installation and configuration in your BR First thing first, you need to connect to your BR server. The pre-requisite is to install NodeJS, and then to install our package globally: ```Bash npm install -g @xen-orchestra/immutable-backups ``` Then, you need to configure it. Since it's installed globally, you will need to create a config files at `/etc/xo-immutable-backups/config.toml`. Inside this file, you will provide where and how do you want to secure your backup files: ``` #[remotes.remote1] root = "/mnt/ssd/vhdblock/" # the absolute path of the root of the backup repository immutabilityDuration = "7d" # mandatory # optional, default value is false will scan and update the index on start, can be expensive #rebuildIndexOnStart = true ``` Let's analyze quickly this example configuration: - `root` is where your backup files are stored, and where XO will write it during a backup - `immutabilityDuration` is for how long a file can't be removed (here, 7 days) - `rebuildIndexOnStart` at true will rescan the backup files to check everything complies, during the program start Now, you can start our `xo-immutable-remote` program, that will protect those target files from deletion for a period, as requested in your configuration. You should see any potential misconfiguration in the output. If everything works well, you can then start it as a service, for example with `systemd` (we'll provide an example service file). If everything is correctly configured, you could start a backup on this BR from XO, and those files won't be removable remotely. **There is no communication channel with XO to change the configuration, and it's on purpose: even if your XO is compromised, an attacker won't be able to modify those backups!** Your feedback is welcome on [our dedicated forum thread!](https://xcp-ng.org/forum/topic/8292/feedback-on-immutability?ref=xen-orchestra.com) ## 📡 REST API Despite an already busy month in terms of features, we also managed to release two exciting new API endpoints. ### Pool emergency shutdown This feature was asked in the context of having a power cut detected by your UPS. You can just make a simple HTTP call to tell your target pool to immediately shutdown correctly all the VMs and hosts, in the right order. Nothing else than a single call! We added it as a "actions", and as usual, you can list the available actions (here on the pool) via a simple HTTP GET: ``` curl \ -X GET \ -b authenticationToken=KQxQdm2vMiv7j \ 'https://xo.company.lan/rest/v0/pools//actions' \ ``` You should have this answer: ``` [ "/rest/v0/pools//actions/create_vm", "/rest/v0/pools//actions/emergency_shutdown", "/rest/v0/pools//actions/rolling_update" ] ``` It means you can RPU or Emergency Shutdown your pool. So to call the emergency shutdown, it's just a PUT HTTP request: ``` curl -k -X POST -b authenticationToken=KQxQdm2vMiv7j 'http://localhost:8080/rest/v0/pools//actions/emergency_shutdown' ``` ### VM creation Our REST API is now able to do VM creation. If it was already possible (since ever) with the JSON-RPC API, you can now also use the REST one. Let's me show you how the structure is made: ``` { "params": { "affinity": { "type": "string", "optional": true }, "auto_poweron": { "type": "boolean", "optional": true }, "boot": { "type": "boolean", "default": false }, "clone": { "type": "boolean", "default": true }, "install": { "type": "object", "optional": true, "properties": { "method": { "enum": [ "cdrom", "network" ] }, "repository": { "type": "string" } } }, "memory": { "type": "integer", "optional": true }, "name_description": { "type": "string", "minLength": 0, "optional": true }, "name_label": { "type": "string" }, "template": { "type": "string" } }, "href": "/rest/v0/pools//actions/create_vm" }, ``` `create_vm` is called on a Pool. As you can see, many parameters are optional, mostly because already provided by the template. ## ♻️ Rolling Pool Reboot There are times when you need to physically reboot your host for various reasons, be it firmware updates, manual updates you've already installed, or an interrupted Rolling Pool Update (RPU) process. To cater to these needs, we've introduced the capability to initiate a rolling pool reboot whenever required. ![](https://xen-orchestra.com/blog/content/images/2023/12/291530590-a6ef0a82-f0c1-4540-b253-a03812386ca5.png) This new feature works similarly to the RPU, but with a key difference. Instead of downloading and applying updates, it focuses solely on rebooting. The process starts with evacuating the master host (by live migrating VMs away), then rebooting it, and finally repopulating it. After the master host is up and running, the same process is repeated for all non-master hosts in the pool. This ensures a smooth and orderly reboot of your entire pool without disrupting your operations. ## 🏷️ Colored tags Building on the success of our last release's "scoped tags," we've taken tagging a step further – especially useful for those managing large infrastructures serving a diverse range of customers (internal or external). We've expanded beyond just scoped tags to introduce the ability to create and edit colored tags: ![](https://xen-orchestra.com/blog/content/images/2024/01/297415521-81cbe7c8-6294-4e01-a83a-7614e761457d.png) With our newly designed "Advanced tag creation" UI, you now have the option to assign colors to your tags, regardless of whether they are scoped. This feature enables quick and effortless identification of different elements within your infrastructure, making it more efficient to manage and navigate through your VMs and resources. It's all about enhancing visibility and organization with just a splash of color! ![](https://xen-orchestra.com/blog/content/images/2024/01/298131570-213488ea-cdae-420d-965d-ea4409ffcb1f.png) ## 🗒️ VMs note field To make managing your VMs even smoother, we've introduced a new feature: editable note fields. Think of it as a space for jotting down anything you need to remember about your VM. And guess what? **It supports Markdown!** This means you can use it for a variety of purposes: - Creating a TODO list for operations on the VM. - Describing in detail what's inside or the services it's running. - Storing any relevant information you want to keep handy or share with your team. It's all about making your VM management more efficient and collaborative. ![](https://xen-orchestra.com/blog/content/images/2024/01/299635747-e795bca1-20e4-49dd-acc7-393e790017f6.png) ![](https://xen-orchestra.com/blog/content/images/2024/01/297768406-aa1a005e-cbb2-41b2-961f-0e45577f9eb0.png) ## ⚖️ Load balancer After some dedicated work, we've updated the code for our Load Balancer. The most noticeable change? We've set the default for live migrating VMs during load balancing to two VMs simultaneously. This significantly minimizes the impact on running VMs – to the point where it's practically undetectable from a guest's perspective. Yet, it efficiently shuffles things around as needed. We've made this parameter adjustable, though our testing suggests that two is the sweet spot for most scenarios. And that's not all – we've got a bunch of other enhancements in the pipeline for the Load Balancer. Keep an eye out for more updates! ## 🔭 XO 6 and XO Lite: foundations As you know, our team has been engaged in the development of two key web applications "from scratch": XO Lite and XO 6\. XO Lite, our new and streamlined version of our XO series, has been under development for about a year now. Its design and architecture have always been intended to serve as the foundational base for our next major project, XO 6\. XO 6, envisioned as the successor to XO 5, is being rewritten from scratch, leveraging the groundwork laid by XO Lite. The latest structure is centered around three main components: XO Lite, XO 6, and the newly introduced XO Web Core. 💡 As a reminder, XO Lite, a simplified yet powerful version of XO, designed to be lightweight and efficient, also serves as the foundational codebase for the development of XO 6\. And XO 6 is the next iteration of XO, following XO 5: it's a complete rewrite, incorporating advanced features and functionalities, building upon the core principles and components of XO Lite. So what's "XO Web Core"? It's a centralized repository hosting shared code elements between XO Lite and XO 6\. It ensures code reusability and consistency across both applications. It will be crucial for our code sharing and migration strategy: essential components, utilities, and configurations are being progressively shifted from XO Lite to XO Web Core. **This transition facilitates a unified codebase that benefits both XO Lite and XO 6.** Also, we'll use "component modularization": specific components of XO Lite, initially tailored for its environment, are being modularized. This involves relocating the UI layer to XO Web Core for shared access and retaining the implementation specifics within XO Lite and customizing them for XO 6 as needed. ### The TreeView example The TreeView component exemplifies our modularization approach. Originally part of XO Lite, its UI has been transferred to XO Web Core, while the implementation layers are adapted within XO Lite and XO 6\. Indeed, XO 6 is providing many extra features, but we keep the same "chassis" for both! This restructured approach marks an important shift in our web application development strategy. By leveraging the synergy between XO Lite and XO 6, and centralizing shared resources through XO Web Core, we are set to deliver more robust, scalable, and maintainable web applications, ready to meet the evolving demands of our users. It took time to organize all of this, but now we are ready to accept more easily external contributions for both projects! ## **🆕** Misc This release is also pretty large on the "Misc" side of things. Most of the improvements are community feedback, especially from our new users that are not used to our stack. For them, we decided to improve many things in the UI so it's harder to make a mistake! ### SMB share SR creation It was already possible to do it via the CLI or via the now defunct XCP-ng Center UI. It's now exposed in XO UI (and JSON-RPC API and CLI, obviously). Just follow the guide, it's pretty simple: ![](https://xen-orchestra.com/blog/content/images/2024/01/298638207-4b5b7957-dabc-45d4-bc04-4ec19b7da06f.png) 🙋 **Should I use SMB/CIFS over NFS?* In general, the answer is "no" if you have a decent NFS server. If you are limited inside the Windows world only, then SMB might be your best option though. ### Tooltip for special tags A quality of life feature, telling you more about special tags, for example the "no-bak" tag, avoiding to replicate an already replicated VM: ![](https://xen-orchestra.com/blog/content/images/2024/01/299605730-775037f1-0031-44d1-8087-bf0c23e28812.png) ![](https://xen-orchestra.com/blog/content/images/2024/01/299608303-6d117c36-8907-4fa0-b8f0-4b6dab4b1641.png) ### Warning when restarting a slave host A common mistake if you are not a seasoned XCP-ng admin, is to update your pool and then start to reboot a pool member (slave) first. This is causing issues, because you should always start with the master, regardless the situation. To ensure people won't make the mistake, we added a warning when we detect this kind of situation: ![](https://xen-orchestra.com/blog/content/images/2024/01/297436348-7a950d05-f32b-4be8-9bae-a584ddaee41c.png) ### Warning on host version in pool In the same idea than the previous feature, we want to avoid getting different host versions when running in a pool. That's OK while doing an upgrade, but you shouldn't keep that state for long: it can cause various issues, especially when live migrate VMs around. That's why you'll be notified now: ![](https://xen-orchestra.com/blog/content/images/2024/01/294231511-07655218-d3ff-4ff4-be10-78a281c652e8.png) ![](https://xen-orchestra.com/blog/content/images/2024/01/294232011-4c45cb9d-423a-4d57-b0af-215ce3fafc0a.png) ### Update VM creator As requested by the community, following the display on the user who created the VM, an admin can now change this (if it's unknown for example). Simple but useful in the context of having many XO user creating VMs often: ![](https://xen-orchestra.com/blog/content/images/2024/01/293937664-86e77dcb-fbfd-4b7e-8b08-e6827c612b9f.png) ### XOSTOR In some cases, at XOSTOR creation, you might want to really wipe the previous content of the target drives. We added this option in the UI with a checkbox to wipe the previous installed filesystems: ![](https://xen-orchestra.com/blog/content/images/2024/01/xostorcheck-1.png) ### Logs Ref & UUID translation In your Settings/Logs but also in the Audit log feature of Xen Orchestra, you also have messages displaying object UUIDs or Ref. That can be used to debug further, but it's sometimes not convenient to track. That's why we added a new feature that is automatically translating those identifiers into clickable links: ![](https://xen-orchestra.com/blog/content/images/2024/01/295977713-03396dfb-f4ff-4856-92d4-95980b34f0a4.png) This way, you immediately know which is the object in question, routing you to the object page for example (VM view in the previous screenshot). It's a really nice quality of life improvement! ### Rolling Pool Update guidance Instead of always enable the possibility to click on "RPU" to do a Rolling Pool Update, XO is now able to detect if this operation is possible or not. If the button is disabled, a tooltip will explain why it's not possible: ![](https://xen-orchestra.com/blog/content/images/2024/01/294855355-6ce6351c-706d-4bad-8440-54feeab429ff.png) Again, we wanted to guide more our users with this kind of features. ### Self-service current usage even if unlimited As a member of the self-service, you are always aware on how much resources you are using. But we did not implement the current usage if it was set to "unlimited". Our community requested to still know the amount despite there's no limit, and it is now done! ### Auto load all plugins automatically For our sources users, this will allow you to enjoy 100% of our plugins automatically! ### Debian 12 template available from the Hub Thanks to [Cécile](https://twitter.com/AtaxyaNetwork?ref=xen-orchestra.com), we got a fresh Debian 12 Cloud-init ready template available in your XO Hub. ![](https://xen-orchestra.com/blog/content/images/2024/01/image-9.png) ### How to start with Vates Virtualization Management Stack URL: https://xen-orchestra.com/blog/how-to-start-with-vates-virtualization-management-stack/ Last updated: 2025-11-04T10:20:26.000Z ## ## Welcome to Vates Virtualization Management Stack! We're happy to welcome you to the Vates platform! Whether you're just getting started or looking to get started, this guide will provide you the tools you need to succeed with the Vates Virtualization Management Stack. ## 1\. How to install XCP-ng Let's get things started by installing XCP-ng, the hypervisor layer of your virtualization stack. ℹ️ XCP-ng is the turnkey, bare-metal virtualization platform with a hypervisor that can be installed directly on your physical server. XCP-ng delivers high-end performance and allows you to efficiently partition your hardware. You can simply download the ISO of the latest version of XCP-ng on the official website. [Download XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com#easy-to-install) You will see 2 available options for installing XCP-ng: - You can download the ISO (current version is XCP-ng 8.3) and create a bootable USB key. Rufus is available for Windows users to create a bootable USB key - You can perform a NET-install with the smaller dedicated ISO. Installing XCP-ng on your physical server is as easy as plugin your USB key and following the installation wizzard. Here is a Youtube tutorial to help you with the installation process: ## 2\. How to deploy Xen Orchestra 💡 At this stage, you should have installed XCP-ng hypervisor on one or several hosts already. Also, you should have an account created on the [Vates portal](https://account.vates.fr/?ref=xen-orchestra.com#/signup), that will make the registration process of your appliance easier. The next step is to deploy your Xen Orchestra Appliance. Xen Orchestra is the management, administration and backup interface for your virtual infrastructure. Xen Orchestra includes a complete set of features ranging from VM creation, live migration, resources delegation, full or incremental backup or replication. We have a dedicated tool for XOA deployment. [Deploy XOA now](https://vates.tech/deploy/?ref=xen-orchestra.com) From there, you just have to follow the instruction. ![](https://xen-orchestra.com/blog/content/images/2024/01/XEN-Install-.png) For additional help we have a tutorial video for this step: If the deploy tool does not work for you. We have other deployment methods available in our [official documentation](https://xen-orchestra.com/docs/xoa.html?ref=xen-orchestra.com#alternative-install). 💡 ****Stay up-to-date:** Xen Orchestra is committed to excellence with monthly updates, easily accessible via the 'Update' button on the XOA > update panel. For insights into each update, visit the [Xen Orchestra Blog](https://xen-orchestra.com/blog/). Choose between the '**Stable Branch*' for a thoroughly tested, slightly delayed version ensuring maximum stability, or the '**Latest Branch*' to access the most current features. Both are designed to enhance your Xen Orchestra experience while catering to different operational needs. ## 3\. How to begin your trial period To start your trial, create your Vates Account. It's free, requires no credit card and there is no commitment. ![](https://xen-orchestra.com/blog/content/images/2024/01/image-1.png) Once you have created your account, you need to register your Xen Orchestra Appliance with this same email. Take a look on the [official documentation](https://xen-orchestra.com/docs/updater.html?ref=xen-orchestra.com#register) if you need more guidance for this step. From there, click the "**Start Trial**" button and then click on the "**update**" button of your appliance and that's it. Once your trial with Vates has begun you will have 1 month to work on the Vates Virtualization Management Stack with our Trial Enterprise Bundle (that embeds the legacy XOA Premium edition). Our Bundles provide you the optimal way to experience Vates VMS with all features, tools and the expertise of our Pro Support Team. To ensure the best experience, the Trial Enterprise Bundle also includes all of these benefits with the exception of the guaranteed response time or the 24/7 support coverage ## 4\. A quick tour of your VM Interface ![](https://xen-orchestra.com/blog/content/images/2024/01/main-xoa-dashboard-1.jpg) Above is your view on the Xen Orchestra homepage. 1. In the main dashboard, you can see all your VMs, description, running status and the pool on which they are deployed. 2. The menu in blue along the leftside of the page gives you access to all the important features (VM creation, backup, self-service...) 3. By clicking the user icon, you can access to the UI settings tab in which you can personalize your experience in XOA (eg. set default filter) 💡 ****Leveraging Tags in Xen Orchestra:** Tags, in XOA are a versatile feature that allows you to categorize, organize, and manage your VMs more efficiently. They are particularly useful in complex or large-scale environments. By assigning tags to your VMs, you can: \- Categorize them based on criteria such as purpose or environment, \- It makes it easier to filter and perform batch actions on a specific group of VMs \- Used in conjunction with the Smart Backup feature, you can set up backup jobs to automatically include or exclude VMs based on their assigned tags ## 5\. How to create your first VM From the homepage of Xen Orchestra, on the blue menu along the left side, click "+ New". ![](https://xen-orchestra.com/blog/content/images/2024/01/image-6.png) #### Prerequisites: Add your XCP-ng server to Xen Orchestra - You need to have an XCP-ng (or XenServer) server available in your Xen Orchestra. You can add your first server by reaching the homepage and clicking on "Add server" button available there. - You need to have an available ISO SR with the ISO OS you want to install. #### Step 1: Prepare to Create a New VM 1. Once the server is added, go to the "+ New VM" section. 2. First, choose the pool in which you want to host your VM. 3. Pick the template you want to use. 4. Then, you'll be presented with a form to specify the details of the new VM. 💡 In XCP-ng hypervisor, you will have roughly 50 templates pre-configured directly available that covers most of the known OS. You also have the ability to convert your own VM into a custom template. #### Step 2: Configure Your VM 1. **Template:** Choose a template for the OS you plan to install. 2. **Name and Description:** Give your VM a meaningful name and description. 3. **CPUs and Memory:** Allocate the number of CPUs and the amount of memory. 4. **ISO/DVD**: Attach your ISO SR with the OS you want 5. **Storage:** Choose the storage repository and size for the virtual disk. 6. **Network:** Select the network you wish the VM to connect to. #### Step 3: Install settings & OS 1. Once the VM is created, start the VM from the home view. 2. Go to the console tab to proceed with the installation of the operating system as you would on a physical machine. #### Step 4: Finalize and Optimize - Once the OS is installed, install the appropriate guest tools for better performance and management. 💡 Learn more about [guest tools in the XCP-ng documentation](Virtual Machines %28VMs%29 | XCP-ng Documentation 🏘️ All VMs https://docs.xcp-ng.org/vms/#%EF%B8%8F-guest-tools). Your VM is now created, you can now adjust your settings like auto power-on, dynamic RAM adjustment, Protect from deletion or shutdown directly in the advanced tab of your newly created VM. ## 6\. Save/Export your XOA settings After finalizing your basic configuration in Xen Orchestra Appliance (XOA), it's essential to export your settings for safekeeping. Navigate to **Settings > Config** to access the export and import option. Regularly saving and exporting your XOA configuration is a prudent practice. It not only facilitates rapid redeployment in case of host failure but also simplifies the process of locating your backup/restore paths, ensuring a smoother recovery and management experience. This way, even if you lose your original XOA, you can confidently redeploy a new appliance and restore very easily your VMs. To simplify this process and ensure your settings are up-to-date, Vates users with a support bundle can create an automated export of your XOA settings. ### Step 1: Access Backup View - Navigate to the "Backup" section in the main menu. ### Step 2: Initiate New Backup Job - Click on the "+ New" button located at the top right corner of the Backup section. ### Step 3: Type of Backup - Select XO config & Pool metadata Backup from the top right - After selecting XO config & Pool metadata backup you can choose to backup one or both. ### Step 4: Create a schedule - Create a schedule of how frequently you would like the backup to run - That's all, and you now have a regularly running backup of your XO config & Pool metadata ## 7\. How to create a backup ![](https://xen-orchestra.com/blog/content/images/2024/01/image-7.png) Backup view in XOA 5 ### Step 1: Access Backup View - Navigate to the "Backup" section in the main menu. ### Step 2: Initiate New Backup Job - Click on the "+ New" button located at the top right corner of the Backup section. ### Step 3: Configure Basic Settings - **Select Backup Type:** Choose the type of backup you want to create. Your options are: - **Rolling Snapshot:** Suitable for frequent, point-in-time snapshots. - **Full Backup:** A regular backup, good for daily or weekly backups. - **Incremental Backup:** Efficient for saving space as it only backs up the differences since the last backup. - **Full/Incremental Replication:** Similar to the Full and Incremental backup feature except that you will target another XCP-ng host to minimize downtime in case of disaster. - **Name Your Backup Job:** Assign a descriptive name to your backup job for easy identification. 💡 The list above highlights the primary backup features in Xen Orchestra. However, a variety of advanced options and functionalities are available to fine-tune your backup strategy. For an in-depth understanding and additional guidance, please consult our [official documentation](https://xen-orchestra.com/docs/backup.html?ref=xen-orchestra.com). ### Step 4: Configure Specific Settings - Based on the type of backup you've selected, the interface will present specific options. Here are some common settings you might want to configure: - **VMs to Backup:** Choose which VMs or group of VMs you want to include in the backup job. - **Schedule:** Decide how often the backup should occur (e.g., daily, weekly, custom). - **Storage:** Select where you want the backups to be stored. - **Retention:** Specify how many backups you want to keep. ### Step 5: Create a Backup Schedule - Decide how often the backup should occur (e.g., daily, weekly, custom). - if needed you can define more than one schedule for the same backup job - Decide if you want to run a health check of your backup. ### Step 6: Review and Save - Once you've configured all the necessary settings, review your configuration to ensure everything is correct. - Click "Create" or "Save" to establish your new backup job. - A automated backup ### Step 7: Monitor and Manage - After creating the job, you can monitor its progress and manage it through the "Backup" section. You'll be able to see upcoming tasks, history, and the status the latest backup operation performed. 💡 ****Testing your backup** You should test the integrity of your backup files on a regular basis. Xen Orchestra allows you to perform automatic or manual recovery tests. ## 8\. How to restore a VM Also located on the Backup page, the restore tab is visible among the top panels of this page. Restoring your VM with Xen Orchestra is a straightforward process: 1. Select your remote and click on the eye icon to see the VMs available 2. Choose the backup you want to restore 3. Select the SR where you want to restore it 💡 ****File Level Restore:** Xen Orchestra provides the capability for file level restoration, offering a precise and convenient recovery option. However, it's important to note that this feature is exclusively available with the Incremental Backup type. ## 9\. Use your Health dashboard Within the **Dashboard > Health** view, you gain a comprehensive insight into your infrastructure and VMs' status. This dashboard is crucial for predictive maintenance and should be reviewed regularly. If you encounter any listings under 'Unhealthy VDIs,' 'Orphan VDI,' 'Orphan Snapshots,' or other tables, it's advisable to seek support. Pro users (or those in a trial period) should consider opening a support ticket (you can do so directly from the XOA > Support section of your appliance). If you are using the source version as a homelabber, you may find valuable assistance by initiating a discussion on the [community forum](https://xcp-ng.org/forum/?ref=xen-orchestra.com). 💡 ****Managing Storage Space Utilization:** Maintaining ample free space in your Storage Repository is critical to ensuring smooth operation and data integrity: \- ****For NFS** (or any thin-provisioned SR), strive to maintain a minimum of ****10%** free space as a buffer. \- ****For iSCSI** (or any thick-provisioned SR), keep at least ****20%** of the storage space free. ## 10\. How to get support for Vates VMS Vates is dedicated to enhancing your virtualization journey with versatile support options. For businesses utilizing our Virtualization Management Stack in production environments, we provide professional support for both XCP-ng and Xen Orchestra through our bundled offers. Discover our 2024 Bundles, combining XCP-ng Pro Support with Xen Orchestra Appliance in a single subscription in this blogpost: [Introducing Vates Virtualization Management StackIn 2024, we are going to introduce new offerings that will embed both XCP-ng Pro Support and Xen Orchestra Appliance: the Bundles.![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogMarc-André Pezin![](https://vates.tech/blog/content/images/2023/11/newpricingbundle-1.jpg)](https://vates.tech/blog/introducing-vates-virtualization-management-stack/?ref=xen-orchestra.com) We are committed to superior pro-support, redefining industry standards. Dive into our philosophy and unique approach to open-source professional support in our blogpost: [My vision for Open Source pro supportEven if everyone seems to agree on what “pro support” means, in fact it’s not something I imagined. Discover why.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOlivier Lambert![](https://xcp-ng.org/blog/content/images/2022/05/xcp-ng-pro-support.jpg)](https://xcp-ng.org/blog/2022/05/06/my-vision-for-open-source-pro-support/?ref=xen-orchestra.com) For individuals, home enthusiasts, and students, our vibrant [community forums](https://xcp-ng.org/forum/?ref=xen-orchestra.com) are the ideal place for support. Engage with categories dedicated to XCP-ng and Xen Orchestra, where insights, user experiences, and community assistance thrive. ### Xen Orchestra 5.90 URL: https://xen-orchestra.com/blog/xen-orchestra-5-90/ Last updated: 2023-12-29T10:32:50.000Z And this is it! The final release of the year marks the end of an incredibly significant 2023 for everyone at our team, as well as our vibrant community. 🎵 As usual, our release is available both on [Youtube](https://www.youtube.com/watch?v=ilE9iGICgv4&ab%5Fchannel=Vates&ref=xen-orchestra.com) and [spotify in a podcast format](https://podcasters.spotify.com/pod/show/vates7/episodes/Episode-11---Xen-Orchestra-5-90---Scoped-tags--XO-Lite--backup-performances--more-e2dphgu?ref=xen-orchestra.com). ## 🧑‍🚀 Project & Community With each Xen Orchestra release, we seize the moment to update you on the progress of our ongoing projects and share exciting developments within our community. There's a lot to discuss, as 2023 was a pivotal year for [Vates](https://vates.tech/?ref=xen-orchestra.com). ### Our new bundles An essential update: the future of our commercial offerings. We've dedicated time to meticulously develop what we believe is the finest product available, integrating the complete stack with straightforward pricing and offerings. [Introducing Vates Virtualization Management StackIn 2024, we are going to introduce new offerings that will embed both XCP-ng Pro Support and Xen Orchestra Appliance: the Bundles.![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogMarc-André Pezin![](https://vates.tech/blog/content/images/2023/11/newpricingbundle-1.jpg)](https://vates.tech/blog/introducing-vates-virtualization-management-stack/?ref=xen-orchestra.com) ### Release of Linux/BSD Rust Guest Tools We're excited to report substantial progress on the VM/guest tools for Linux & BSD. A new version has now been released and is readily accessible in the Debian/Ubuntu repositories. Its performance is outstandingly quick, decisively surpassing the speed of XenServer guest tools written in Go, especially in terms of reporting VM data. The new tools can relay guest information on boot in just a few milliseconds, compared to the minutes previously required. [Rust guest tools 0.3.0Discover the seamless integration and enhanced functionality of the new Rust guest agent in its latest 0.3.0 version for Linux and BSD systems.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOlivier Lambert![](https://xcp-ng.org/blog/content/images/2023/12/rust030.jpg)](https://xcp-ng.org/blog/2023/12/15/rust-guest-tools-0-3-0/?ref=xen-orchestra.com) ### New release of our Terraform provider If you want to learn more, the changelog is available here: [Release v0.26.0 · terra-farm/terraform-provider-xenorchestraWhat’s Changed \[New feature\] Allow VM resource’s power\_state to be managed by @ddelnano in #278 \[Security fix\] Bump golang.org/x/net from 0.13.0 to 0.17.0 by @dependabot in #273 \[Security fix\] Bum…![](https://github.githubassets.com/assets/pinned-octocat-093da3e6fa40.svg)GitHubterra-farm![](https://opengraph.githubassets.com/56dea7af6c2b5f97f81dbc03906fee02c61db38bee683263b5a15bfa84a618b8/terra-farm/terraform-provider-xenorchestra/releases/tag/v0.26.0)](https://github.com/terra-farm/terraform-provider-xenorchestra/releases/tag/v0.26.0?ref=xen-orchestra.com) ### A fresh ISO for XCP-ng 8.2.1 We're thrilled to unveil the updated installation images for XCP-ng 8.2.1. [Updated installer for XCP-ng 8.2.1We are happy to announce the release of updated installation images for XCP-ng 8.2.1, with better hardware support and all the updates since the initial 8.2.1 release.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogSamuel Verschelde![](https://xcp-ng.org/blog/content/images/2023/12/821refresh.jpg)](https://xcp-ng.org/blog/2023/12/11/updated-installer-for-xcp-ng-8-2-1/?ref=xen-orchestra.com) It includes **all the security and maintenance updates** published since the initial release of XCP-ng 8.2.1 (almost 2 years ago!), as well as **improved hardware support and drivers**. Now, let's redirect our focus to this Xen Orchestra release! We're eager to dive back into discussing the latest enhancements and features that make this update noteworthy. --- ## 💾 Backup In line with our tradition, this release introduces some exciting new backup features. We're also giving you a sneak peek into the extensive work being done behind the scenes as we gear up for the next major leap forward. ### Add tasks for NBD enabled backup With the introduction of NBD-capable backups, we've observed a significant increase in backup speed and a decrease in CPU load on the host. This efficiency has encouraged more users to adopt this method. However, unlike the traditional VHD transfer method, NBD exports don't display as an export task, leading to some confusion. Users have found it difficult to discern the progress of a transfer, which is a valid concern. To address this, we've decided to implement a new feature: the generation of a XAPI task for NBD transfer via Xen Orchestra. This task will not only indicate when an export is underway but will also track its progression in percentage. This enhancement brings clarity and transparency to the backup process, allowing you to monitor the status of your backups directly from XO Lite or the xe CLI, ensuring you're informed no matter where you are or what interface you're using. ![](https://xen-orchestra.com/blog/content/images/2023/12/289120504-b5532268-7ba3-4eaf-828c-bca0d1d40ddd.png) An NBD transfer is now visible in the task view ### Optimizing backup performance on high latency links Utilizing NBD for backups has proven to be significantly faster and more resource-efficient. This efficiency stems from the streamlined export process NBD employs, which minimizes the "translation" layers involved, thereby accelerating the operation and reducing CPU usage. However, the advantages of NBD extend beyond speed and resource conservation. It introduces several functionalities that are unattainable with traditional VHD exports, including: - the ability to pause and resume downloads - the flexibility to seek any position within the data blocks - the option to customize the number of data blocks downloaded simultaneously. - the capability to download multiple blocks in parallel. It's this last feature that we've put to the test, and the results are promising, particularly in addressing a well-known challenge: enhancing backup speed over high-latency connections. By leveraging the ability to download blocks in parallel, we've significantly mitigated the impact of distance and network delays, ensuring faster, more reliable backups regardless of your geographic location or network conditions. See the impressive results below! ### Mitigating the impact of latency on backup speed Latency can significantly hinder backup speed, especially when the backup repository is located far from the production setup. Under ideal conditions (latency <1ms), NBD can facilitate impressively high speeds, exceeding 250 MiB/s. However, as the distance to the storage increases, you'll notice a substantial drop in backup speed, a phenomenon consistent across both NBD and VHD export methods: Here's the crucial difference with NBD: it allows for the simultaneous download of multiple blocks. Leveraging this capability can drastically alter the performance landscape: Implementing parallel block downloads with NBD can significantly mitigate the impact of higher latencies. For instance, a 10ms latency link, which would typically slow down the process, becomes almost negligible with this approach. The speed enhancement is remarkable, with parallel downloads proving to be **more than five times faster**. Even for backup repositories (BR) located at considerable distances (20ms latency and beyond), the speeds remain within a usable range. This makes remote backups more feasible and efficient. 💡 ****Beyond 50ms Latency**: when dealing with extremely high latency (over 50ms), the most effective strategy is to first make a local backup using XO Proxies and then employ the Backup Mirror feature to asynchronously transfer the data to a distant site. To tailor the backup process to your specific needs and infrastructure, you can adjust the number of NBD connections per exported disk. This setting is accessible in the Advanced backup job section and allows for further customization to optimize performance according to your network conditions and backup requirements: ![](https://xen-orchestra.com/blog/content/images/2023/12/288082324-80bd94c9-5581-40ad-939a-8098168d5d4f.png) ### Advancements in on-prem immutability We're making strides in enhancing data protection with our ongoing work on immutability, particularly for on-premises environments. While it's currently possible to secure your S3 backups using the "object lock" policy available through your S3 provider's console (like AWS), our focus is on providing a direct, on-premises solution that doesn't rely on external providers. We've made significant headway in preparing the immutability feature for an upcoming release. Our objective is to establish a Backup Repository (BR, or "remote") that Xen Orchestra can write to but cannot alter during the predefined immutability period. This restriction ensures that backups cannot be deleted, tampered with, or held ransom (encrypted) during this time, safeguarding them against ransomware attacks as long as the attacker doesn't have root access to the BR. ☝️ In data protection, ****governance mode** allows select admins with root access to modify immutability settings, offering flexibility while safeguarding data. ****Compliance mode**, on the other hand, locks settings so no one, not even admins, can alter them, meeting stringent regulatory standards. However, on your own hardware, physical access can override these protections. Choosing between ****governance** and ****compliance** depends on your security needs and trust in administrators. We're targeting a governance type of immutability, where the local root account of the remote server retains the capability to override the immutability settings. This approach relies on the file system's capabilities, which we assess at the start of the protection process. Notably, this method is compatible with Xen Orchestra's encryption at rest feature. Both the protection and lifting processes require root access on the BR/remote. Upon initiation, the protection process records its status in the remote's `metadata.json` file, detailing the most recent protection applied and lifted. To ensure robust immutability, it's crucial that Xen Orchestra does not control the immutability parameters directly. Your backups must remain secure even in the event of a compromise within Xen Orchestra. Consequently, achieving true immutability will always necessitate an "external" program and/or configuration independent of Xen Orchestra. Our current testing phase is yielding promising results. Stay tuned for updates early in 2024 as we prepare to launch the first usable version of on-premises immutability. This feature aims to provide an added layer of security and peace of mind for your infrastructure's backup strategy. ## 🏷️ Scoped tags Tags are incredibly versatile, used for everything from Smart Backup modes and sorting VMs to creating custom views and facilitating IT automation. But what if we could enhance their utility further? Enter scoped tags. These allow for more nuanced categorization, perfect for when you have similar tags across different projects or clients but need to distinguish context. For instance, a "database" tag might have different implications in production vs. development environments. Our solution? Use scoped tags like "prod=database" and "devel=database" for clear, context-specific labeling. ![](https://xen-orchestra.com/blog/content/images/2023/12/image-6.png) You can also imagine to have scope "by customers": ![](https://xen-orchestra.com/blog/content/images/2023/12/image-5.png) But also, you can use emojis: ![](https://xen-orchestra.com/blog/content/images/2023/12/image-4.png) The potential applications for this new feature are as diverse as your needs, offering you the flexibility to optimize its use in your unique scenarios. ## **🆕** Misc Santa is also delivering many improvements… Take a look! 🎁 🎅 ### http.useForwardedHeaders You can already use your XO behind a reverse proxy (Nginx, HA Proxy…). But XO won't be able to log the IP of the "end user", only the reverse proxy one. Which isn't really useful in your logs and for security audits. That's why we added the capability to fetch clients IP addresses from `X-Forwarded-*` headers. To enable it, you must modify your `config.toml` file with: ```toml [http] useForwardedHeaders = true ``` If you want to use the headers only for your "validated" reverse proxies, just replace `true` with a list of trusted addresses (ie your reverse proxy hosts). ### SAML improvements The improvements to SAML (Security Assertion Markup Language) integration in Xen Orchestra focus on enhancing security, particularly for sensitive applications. Initially, with a valid ongoing session, users wouldn't need to re-authenticate to access Xen Orchestra. However, for added security, especially when accessing sensitive software, it's sometimes preferable to require users to re-authenticate to confirm their identity. The updated feature in the Auth SAML plugin for Xen Orchestra addresses this need by allowing an option to enforce re-authentication for all users, regardless of their session's validity. When enabled, this feature ensures that users and administrators must re-authenticate against the designated authentication provider, adding an extra layer of security known as "defense in depth." This means that even if a session is hijacked or otherwise compromised, the attacker would need to authenticate again, providing a significant barrier to unauthorized access. This improvement is particularly useful in environments where security is paramount, and user credentials need to be verified regularly to protect sensitive data and systems. ![](https://xen-orchestra.com/blog/content/images/2023/12/291939206-46290ca2-3742-4a37-9ffb-40e6a63c0162.png) ### Change memory in a running VM Adjusting the "static" memory allocation traditionally necessitates halting the virtual machine (VM), modifying the memory settings, and then restarting the VM. To streamline this process, we've introduced a simplified "two-click" method. When you alter the VM's static memory, Xen Orchestra (XO) recognizes if the VM is active and presents the following popup: ![](https://xen-orchestra.com/blog/content/images/2023/12/291844150-72145078-c94a-4fd9-940b-617ba6fe2bc8.png) Now, with a single click on "Reboot," XO will automatically shut down the VM, apply the memory change, and restart it. This enhancement significantly reduces the steps and time needed to adjust memory in a running VM, making your daily operations more efficient. ### Better error message on XO CLI XO CLI needs to be "registered" (ie logged) on the XO server before doing anything. However, it wasn't obvious if you missed this step, especially because of a cryptic error like: ``` ✖ TypeError [ERR_INVALID_URL]: Invalid URL ``` Not great, indeed. Now, you'll have a very more explicit feedback: ``` Please use `xo-cli --register` to associate with an XO instance first. See `xo-cli --help` for more info. ``` ## 📡 REST API Some changes in the REST API, while adding more endpoints to manage XO via simple HTTP requests. ### Expose mirror, metadata & config backup jobs You can now request all the metadata & mirror backup existing jobs from our REST API. It's very easy to fetch them, just do a GET on `/backup/jobs/metadata` and `/backup/jobs/mirror` respectively. ### Other changes We also made various changes in the URLs, but for every change, we put redirections in place so it's transparent for you. First, `/backups` has been renamed to `/backup`. Then *VM backup & Replication* jobs have been moved from `/backup/jobs/:id` to `/backup/jobs/vm/:id` ## 🚀 XCP-ng 8.3 features The latest features of Xen Orchestra (XO) are tailored for the newest, not-yet-in-production version of XCP-ng: 8.3\. Here's what's new: ### Show/edit IPv6 PIFs With XCP-ng 8.3, you can now configure IPv6 settings directly on the host's physical interfaces. This long-awaited IPv6 support allows for more complex networking configurations and modern protocol support. ![](https://xen-orchestra.com/blog/content/images/2023/12/291914344-1219f00e-deb2-476a-85fa-09b9e63a04a5.png) ### **Enhanced coalesce detection** XCP-ng 8.3 introduces improved detection of ongoing coalesce tasks. The user interface has been refined to show which Storage Repositories (SRs) are currently coalescing across multiple views. This enhancement provides a clear, real-time insight into storage activities, helping you understand and manage storage performance better. ![](https://xen-orchestra.com/blog/content/images/2023/12/291345343-c402f9e8-a991-4b90-9d6d-1728771576b5.png) ## 🔭 XO Lite As we wrap up 2023, we're excited to introduce the first "functional" iteration of XO Lite. Key updates are displayed here, but you can also take a look at the [official changelog](https://github.com/vatesfr/xen-orchestra/blob/master/%40xen-orchestra/lite/CHANGELOG.md?ref=xen-orchestra.com#017-2023-12-28). ### XOA quick deploy Deploying a Xen Orchestra virtual Appliance is now straightforward from the XO Lite interface. This new feature ensures you retain all capabilities known from the previous interface, streamlining the deployment process. ![](https://xen-orchestra.com/blog/content/images/2023/12/291548823-6d449ef4-f755-40c3-b2d2-36f8610501da.png) ![](https://xen-orchestra.com/blog/content/images/2023/12/291548251-4c45013f-eae0-431f-8dfc-48a3d9faf8f0.png) ![](https://xen-orchestra.com/blog/content/images/2023/12/291548259-b7c0558d-8c69-4352-9995-c81ec83562b3.png) ### Number of running VMs in the tree view To provide a clearer overview of your environment, we've added a small indicator ("pill") next to each host in the tree view. This indicator displays the number of running VMs, offering a quick snapshot of activity and load: ![](https://xen-orchestra.com/blog/content/images/2023/12/289514913-35af97ae-3126-4f50-b36a-9454083044ea.png) ### Better status panel component We've paid attention to the finer details too. The status panel component now boasts better alignment, with all content correctly centered vertically. By using a generic component for all entries, the panel's readability and aesthetic appeal are significantly enhanced. ![](https://xen-orchestra.com/blog/content/images/2023/12/Capture-d--cran-du-2023-12-20-17-32-30.png) ### Xen Orchestra 5.89 URL: https://xen-orchestra.com/blog/xen-orchestra-5-89/ Last updated: 2023-12-04T09:09:39.000Z It's time for a new release! November is now almost done, last stop before December release and the end of 2023\. Despite it's not Christmas yet, we managed to deliver more than 20 ~~presents~~ new features in one month! ## 🧑‍🚀 Project & Community In just a single month, many things happened. The most notable is Broadcom's monumental acquisition of VMware for over $60 billion, a move that has resonated across the tech industry. However, the developments don't stop there: Xen Orchestra team is expanding and Xen 4.18 landed alongside numerous other news. ### The new virtualization landscape In this blogpost I wrote (Olivier' speaking), I dug into the staggering $100 billion worth of acquisitions and consolidations in the virtualization market, a phenomenon that's causing a seismic shift in the industry: [The new virtualization landscapeIn light of Broadcom’s $61 billion acquisition of VMware and the shifting dynamics in the virtualization industry, Vates stands out with its innovative ‘Bundles’, offering a unique, cost-effective solution in an era marked by technological consolidation and evolving cloud trends.![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogOlivier Lambert![](https://vates.tech/blog/content/images/2023/11/vmwarebroadcom.jpg)](https://vates.tech/blog/the-new-virtualization-landscape/?ref=xen-orchestra.com) ### Xen 4.18 is here The latest Xen Project hypervisor version just landed, in 4.18\. We are proud to demonstrate our commitment upstream since one of our developer made into the Top 10 contributors! [Xen 4.18 releaseA fresh release of Xen just landed. Discover what’s inside!![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOlivier Lambert![](https://xcp-ng.org/blog/content/images/2023/11/xen418.jpg)](https://xcp-ng.org/blog/2023/11/21/xen-4-18-release/?ref=xen-orchestra.com) ### XO team still growing [Bastien](https://github.com/b-Nollet?ref=xen-orchestra.com) has recently become a part of our team, primarily focusing on the backend part of XO. His addition is a significant boost to our efforts, as he collaborates closely with Julien and Florent to accelerate our development pace. We also now have a [dedicated person](https://github.com/shinuza?ref=xen-orchestra.com) to get focus on [Project Pyrgos](https://xen-orchestra.com/blog/announcing-project-pyrgos/) (k8s cluster creation/lifecycle directly from Xen Orchestra), so expect new features for the next releases! ![](https://xen-orchestra.com/blog/content/images/2023/10/astronaut.png) ### Community feedback on our Rust Linux tools If you missed the announcement, take a look here: [New Guest Tools in RustDiscover the latest blog on integrating Rust into Xen Project. We’re building a flexible Rust-based agent for VM-Dom0 communication, showing promise in supporting various guest OS with room to grow!![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogYann Dirson![](https://xcp-ng.org/blog/content/images/2023/03/xenrusttools-1.jpg)](https://xcp-ng.org/blog/2023/03/30/new-linux-guest-tools-in-rust/?ref=xen-orchestra.com) And here: [Updates on the Rust guest toolsPeek into our journey redesigning VM guest tools in Rust! From enhancing compatibility to broadening UNIX system support, there’s plenty to catch up on.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOlivier Lambert![](https://xcp-ng.org/blog/content/images/2023/10/rusttools.jpg)](https://xcp-ng.org/blog/2023/10/12/updates-on-the-rust-guest-tools/?ref=xen-orchestra.com) There's now a dedicated thread where you can test our new tools: [https://xcp-ng.org/forum/topic/7974/new-rust-xen-guest-tools/](https://xcp-ng.org/forum/topic/7974/new-rust-xen-guest-tools/?ref=xen-orchestra.com) Please test and provide your feedback! ### XO Lite changelog We have now a dedicated changelog for XO Lite! Feel free to take a look: [https://github.com/vatesfr/xen-orchestra/blob/master/%40xen-orchestra/lite/CHANGELOG.md#changelog](https://github.com/vatesfr/xen-orchestra/blob/master/%40xen-orchestra/lite/CHANGELOG.md?ref=xen-orchestra.com#changelog) --- ## 💾 Backup Backup functionality has always been a top priority for us in Xen Orchestra. This month, we're excited to announce the release of several new features and various enhancements! ### Differential restore Our XO Backups features have always stand out as a very flexible tool, allowing you to restore a VM to any location on any storage, without any prerequisites. However, we've identified and enhanced a specific scenario: restoring your VM to a storage unit that already houses your original VM. Our latest improvement significantly cuts down the restoration time for this use case. Here's how it works: instead of a full restore, we utilize the existing VM disk or snapshot as a base, restoring only the differential data to a new disk. This approach drastically reduces restore time, particularly for large VMs. For instance, with a transfer rate of 60MiB/s, restoring a 200GiB VM would typically take about an hour. But with our differential restore method, even a 600GiB disk can be restored in a fraction of the time: mere minutes instead of hours. Most importantly, this process is designed with data integrity in mind. The original VM disk remains untouched during the restore; we only read from the latest snapshot to use it as a foundation for creating the new VM and disk. ### Show backup date and description of restored VM Restoring a VM often requires extensive context, especially when navigating through multiple versions to find the correct one. To simplify this process, we managed to add more information in the restored VM. This includes the original description of the VM, supplemented with useful data like the time of restoration and the source Backup Repository (BR). This feature is particularly useful in complex environments where multiple restorations are common, ensuring that each restored VM is easily identifiable and its lineage is clearly documented. ![](https://xen-orchestra.com/blog/content/images/2023/11/284582246-07f83b10-fd1f-4b95-80d3-b14b0a8343cb.png) This addition ensures that you can confidently identify and utilize the specific version of the VM you intended to restore. ### API/CLI file level restore Xen Orchestra already offers a convenient feature for file-level restoration directly through the XO user interface. This is particularly handy when you need to retrieve specific files without restoring the entire VM. Simply select the files you need, download them, and you'll receive a ZIP file right in your browser! However, there are scenarios where you might want to transfer these files to a different destination or use tools like `rsync` to synchronize them with files on an existing VM. Let's explore how to do so with `xo-cli`! First, we need to list the remotes: ```bash $ xo-cli remote.getAll [ { benchmarks: [ { readRate: 370947830.1903045, timestamp: 1644844831515, writeRate: 107656040.17545153 } ], enabled: true, id: '6d77e904-b28d-4055-b1cb-041df77c9e2c', name: 'Local', url: 'file:///srv/xo-backups' } ] ``` Now we'll list all the backups on this remote: ```bash $ xo-cli backupNg.listVmBackups remotes=json:'["6d77e904-b28d-4055-b1cb-041df77c9e2c"]' { '6d77e904-b28d-4055-b1cb-041df77c9e2c': { '123e4f2b-498e-d0af-15ae-f835a1e9f59f': [ { disks: [ { id: '/xo-vm-backups/123e4f2b-498e-d0af-15ae-f835a1e9f59f/vdis/86898a59-15bd-463c-91e9-ebc55f42adf5/2da1102c-9be3-43a0-82f5-9111e362c66f/20231116T120859Z.vhd', name: 'backup QA - system', uuid: '80dfc4ec-41f3-4d0f-823c-61d4287ca628' }, { id: '/xo-vm-backups/123e4f2b-498e-d0af-15ae-f835a1e9f59f/vdis/86898a59-15bd-463c-91e9-ebc55f42adf5/0a1d2e50-5a59-47e4-b0bd-4bbff7765d86/20231116T120859Z.vhd', name: 'backup QA - data', uuid: 'a449d2c3-c457-41bf-bb2b-82e9cb09aaab' } ], id: '6d77e904-b28d-4055-b1cb-041df77c9e2c//xo-vm-backups/123e4f2b-498e-d0af-15ae-f835a1e9f59f/20231116T120859Z.json', jobId: '86898a59-15bd-463c-91e9-ebc55f42adf5', mode: 'delta', scheduleId: '58f593e1-afa4-43f9-85f7-5bf8ed199584', size: 1533407744, timestamp: 1700136539071, vm: { name_description: 'Cloud Ready from XO', name_label: 'backup QA' } } ] } ``` Great! Now we want to specifically get the list of partitions for a disk: ```bash $ xo-cli backupNg.listPartitions remote=6d77e904-b28d-4055-b1cb-041df77c9e2c disk=/xo-vm-backups/123e4f2b-498e-d0af-15ae-f835a1e9f59f/vdis/86898a59-15bd-463c-91e9-ebc55f42adf5/2da1102c-9be3-43a0-82f5-9111e362c66f/20231116T120859Z.vhd [ { id: '8d8f3f0f-01', name: '', nr: '1', size: 4292870144, start: 2048, type: 131 } ] ``` Almost there! Now, we'll ask to mount the partition in XOA so we can access the files: ```bash $ xo-cli backupNg.mountPartition remote=6d77e904-b28d-4055-b1cb-041df77c9e2c disk=/xo-vm-backups/123e4f2b-498e-d0af-15ae-f835a1e9f59f/vdis/86898a59-15bd-463c-91e9-ebc55f42adf5/2da1102c-9be3-43a0-82f5-9111e362c66f/20231116T120859Z.vhd partition=8d8f3f0f-01 /tmp/bujxvyk72mr ``` It's now mounted! If you want to check the currently mounted partition, a simple call will do the trick: ```bash $ xo-cli backupNg.listMountedPartitions [ { disk: '/xo-vm-backups/123e4f2b-498e-d0af-15ae-f835a1e9f59f/vdis/86898a59-15bd-463c-91e9-ebc55f42adf5/2da1102c-9be3-43a0-82f5-9111e362c66f/20231116T120859Z.vhd', partition: '8d8f3f0f-01', path: '/tmp/bujxvyk72mr', remote: '6d77e904-b28d-4055-b1cb-041df77c9e2c' } ] ``` When it's done, just unmount it: ```bash $ xo-cli backupNg.unmountPartition remote=6d77e904-b28d-4055-b1cb-041df77c9e2c disk=/xo-vm-backups/123e4f2b-498e-d0af-15ae-f835a1e9f59f/vdis/86898a59-15bd-463c-91e9-ebc55f42adf5/2da1102c-9be3-43a0-82f5-9111e362c66f/20231116T120859Z.vhd partition=8d8f3f0f-01 true ``` The unmount time in Xen Orchestra is set with a 5-minute timer, which activates after a period of inactivity. This feature is designed to ensure that the unmounting process does not interrupt any ongoing file restoration activities. If, for any reason, you forget to manually unmount, Xen Orchestra takes care of it by automatically unmounting after 24 hours. ## 🔭 XO Lite This month has been significant for XO Lite, with various enhancements made to its functionality. We're proud to witness the evolution of Xen Orchestra's "little brother," as it becomes increasingly capable and user-friendly for a variety of tasks. ### A more compact UI Following valuable input from our community, we decided to optimize space usage in Xen Orchestra by crafting a more compact overall interface. The result is a fine balance between compactness and usability. To appreciate the improvements, take a look at the "before and after" comparison! ![](https://xen-orchestra.com/blog/content/images/2023/11/F-RId19XwAA2ZjB-1.jpg) The recent interface optimizations in Xen Orchestra have led to a notable increase in efficiency, particularly evident in the tree view of VMs. Previously, the interface could display approximately 18 VMs, but with our latest updates, it can now show up to 24 VMs! (+30%) We've also refined the dashboard side of the interface. It now provides more information at a glance, enhancing the user's ability to monitor and manage their resources efficiently. ### XVA export You can now export a VM directly from XO Lite, as an XVA file you can download in your browser: ![](https://xen-orchestra.com/blog/content/images/2023/11/283829763-e78c31a0-d1f9-4cb3-991e-95981f6d9c21.png) But it's also possible to download multiple VMs at once! For example: ![](https://xen-orchestra.com/blog/content/images/2023/11/282496453-3be70499-10a4-465e-8bf9-2e250baea657.png) It even comes with the capability to detect if your browser is blocking pop-ups: ![](https://xen-orchestra.com/blog/content/images/2023/11/282496535-12cce67b-6186-4e7c-a15a-a5824213c462.png) ### VM migration You can now live migrate a VM inside a pool, directly from XO Lite UI: ![](https://xen-orchestra.com/blog/content/images/2023/11/281064059-8f113258-356b-46ee-a06b-29bdf994abc1.png) ### Connecting on a pool member To enhance navigation and clarity when accessing pool members. If you open the URL of a pool member that is **NOT** the pool master, this status is now clearly displayed on the interface. Moreover, for added convenience, there is a direct link provided to navigate to the pool master. ![](https://xen-orchestra.com/blog/content/images/2023/11/281748439-1eb49b2a-f6d8-4adb-9f28-35d91bb17ec6.png) ### Redirecting XO Lite to another master This one is fun: you can use the XO Lite for one pool to then decide to connect to another pool that does NOT have XO Lite installed! ![](https://xen-orchestra.com/blog/content/images/2023/11/283795063-647236cf-7ae0-452c-9e03-08424439fdc4.gif) ## 📡 REST API Many updates on the REST API side of things. These improvements are geared towards making the API even more versatile and effective for a wide range of operations and automation tasks. ### Display and list XO users You can now list all your XO users with a simple: ```bash curl \ -X GET \ -b authenticationToken=KQxQdm2vMiv7j \ 'https://xo.company.lan/rest/v0/users' \ ``` This will return an array of users: ```bash [ "/rest/v0/users/fbd24be9-3ed6-498e-a0a0-62badf7564ff", "/rest/v0/users/421c8487-3aa5-4281-b5d9-dadafb9c0914" ] ``` You can then display details on one user, even get his public SSH keys! ```bash { "id": "421c8487-3aa5-4281-b5d9-dadafb9c0914", "email": "user@example.org", "groups": [], "permission": "admin", "preferences": { "sshKeys": [ { "title": "mykey@mypc", "key": "ssh-rsa AAAAB3NzaC1yc2EAA[...] mykey@mypc" } ], "filters": { "VM": { "test": "power_state:running" } } ``` ### Import a VDI content You can now import a VHD or raw file content into an existing VDI. The only limitation is the size of the VDI must match the size of the VDI previously exported: ```bash curl \ -X PUT \ -b authenticationToken=KQxQdm2vMiv7j \ -T myDisk.vhd \ 'https://xo.company.lan/rest/v0/vdis/1a269782-ea93-4c4c-897a-475365f7b674.vhd' \ | cat ``` This might be pretty useful to inject whatever content you have, for example in some automation scripts to get back on a disk state you had locally. ### Import an XVA You can now import an XVA file directly into XO via the REST API. Here is an example with `curl`: ```bash curl \ -X POST \ -b authenticationToken=KQxQdm2vMiv \ -T myVm.xva \ 'https://xo.company.lan/rest/v0/pools/355ee47d-ff4c-4924-3db2-fd86ae629676/vms \ | cat ``` This will import the XVA into the pool default storage repository (SR). If you want to specificy the target SR, you can simple add the SR UUID in the URL: `?sr=86a9757d-9c05-9fe0-e79a-8243cb1f37f3` 💡 As usual, the final | cat ensures cURL's standard output is not a TTY, which is necessary for upload stats to be dislayed. ### Tags management You can now edit or remove a tag very easily. It's using what we call the "collection", and it works that way: To add a tag: ```bash curl \ -X PUT \ -b authenticationToken=KQxQdm2vMiv7jB \ 'https://xo.company.lan/rest/v0/vms/770aa52a-fd42-8faf-f167-8c5c4a237cac/tags/My%20tag' ``` Removing a tag is also trivial: ```bash curl \ -X DELETE \ -b authenticationToken=KQxQdm2vMiv7jB \ 'https://xo.company.lan/rest/v0/vms/770aa52a-fd42-8faf-f167-8c5c4a237cac/tags/My%20tag' ``` Relying on tags is a great way to identify resources and apply actions on them automatically with whatever logic you need in your system. ## 🗃️ Netbox Last July, we already supercharged our Netbox plugin, see this as a reminder: [Xen Orchestra 5.85We’ve supercharged our Netbox plugin, enhancing synchronization, refining VM migration, and introducing smarter error messages for a seamless user experience. Dive into our revamped tool that promises efficiency, clarity, and a smoother workflow.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2023/07/lavender-g81f97420a_1280.jpg)](https://xen-orchestra.com/blog/xen-orchestra-5-85/) We're taking our integration with Netbox to the next level by introducing an optional synchronization feature between your XO users and the "tenant" entity in Netbox. **This feature allows for the tracking of user activities within Netbox, specifically enabling you to see which user created which VM!** Don't forget to add the `uuid` field for the Tenancy>Tenant object in Netbox configuration if you want to do that sync: ![](https://xen-orchestra.com/blog/content/images/2023/11/customfield.18580820.png) ## 🚀 XCP-ng 8.3 features In this section, we're focusing on the new features that have been added to Xen Orchestra, specifically tailored for compatibility with XCP-ng 8.3\. It's important to note that most of the recent modifications made in XCP-ng are not backported to the Long-Term Support (LTS) version, for obvious stability reasons. ### Detailed task for coalesce A key enhancement in XCP-ng 8.3 is the ability to closely monitor storage coalescing tasks. What sets this feature apart is the added functionality where each coalescing task is directly linked to the specific pool and Storage Repository (SR) involved in the process. This direct linkage makes it much easier to understand the ongoing coalescing activities and allows for quick exploration and management of the associated pool and SR. ![](https://xen-orchestra.com/blog/content/images/2023/11/taskcoalesce.png) ## 🆕 Misc The "Misc" section this month is still quite substantial, despite the numerous other features we've already delivered. And we will continue to raise the pace! ### Ignore empty VDIs One of the useful aspects of the dashboard/health view in Xen Orchestra is its ability to highlight potential misconfigurations or issues with your disks. However, VDIs with a size of 0, such as udev devices or other special devices, should not clutter this view. We've now updated the system to exclude these empty VDIs from the dashboard/health view, ensuring that only relevant data is displayed. ### Better token management Each time you login, you have a token. It's manageable, but results in a long list of tokens displayed to the user. We've already fixed this on the backend, and now we've made improvements on the UI front as well. Now, we're reusing tokens throughout their duration, and we're providing more detailed information about each tokens: - The user agent through which you logged in - The time of login ![](https://xen-orchestra.com/blog/content/images/2023/11/image.png) This means there's now one token per "device" from which you access XO, typically a web browser. This enhancement greatly improves both security and transparency, allowing you to clearly see the details of each login and the device used, streamlining token management and enhancing overall system security. ### Boot a VM with disk with an ISO You can now boot a VM with an existing disk using an ISO file. Previously, this wasn't considered necessary since a disk with data, like a template with an operating system, was thought to be sufficient. However, based on community feedback highlighting certain use cases, this feature has been added for increased flexibility. ### Disabling the console view In XenCenter, if you add the key `other-config:disable_pv_vnc=1` to the VM object, the console view for the user is hidden. To increase compatibility and interoperability between XenCenter and Xen Orchestra, we have also implemented this feature. When this configuration is set, the console will be hidden in Xen Orchestra as well. ![](https://xen-orchestra.com/blog/content/images/2023/11/281001780-aa5817f3-b30f-400b-b3c8-1fc5388e8898.png) ### Show disk import status in labels When importing a disk or a VM with disks, the name of the drive is now altered during the import phase. This update removes any confusion about whether a disk is currently being imported or not. ### Show import task progress in the disk views In earlier versions, tracking the progress of an imported VM (either directly or via backup restore) required going to the global task view. Now, you can see the progress of importing disks directly in the Disk tab of the VM being imported, making it easier to monitor the import process. ![](https://xen-orchestra.com/blog/content/images/2023/11/285474208-f3997f47-9692-42b6-93ba-6ddf06fc627e.png) ### Storage forget: clearer message When deciding to forget a SR, a clearer warning message now informs you about the consequences of this action. Additionally, to confirm the action, you need to type "Forget this SR," which helps prevent accidental validations. ![](https://xen-orchestra.com/blog/content/images/2023/11/280303336-1ff0fb4c-f64f-4366-9e1d-a07202153a25.png) The complete changelog for XO is [available here](https://github.com/vatesfr/xen-orchestra/blob/master/CHANGELOG.md?ref=xen-orchestra.com#5890-2023-11-30). ### Xen Orchestra 5.88 URL: https://xen-orchestra.com/blog/xen-orchestra-5-88/ Last updated: 2025-02-19T21:04:52.000Z October release is here 🎃 And it's unreal 👻 How it's possible to cram like one quarter of work in one month? I really wondered when writing this blog post. As usual, here is the video log of this release: You can also listen to it in a [podcast version on Spotify](https://podcasters.spotify.com/pod/show/vates7/episodes/Episode-9---Xen-Orchestra-5-88---XOSTOR-first-UI--progress-on-XO-6-and-much-more-e2b9mtt?ref=xen-orchestra.com). ## 🧑‍🚀 Project & Community Since Xen Orchestra is a lot more than code, but an entire project with a vibrant community, we wanted to show you what's up in this area. ### SFSCON 2023: Elevating Open Source Innovation in Europe SFSCON 2023 is an important Open Source event in Europe focused on new ideas, working together, and leading the way in the Open Source world. The conference, happening in Bolzano, Italy, will have more than 100 speakers from all around Europe. One of them will be our own Chief Strategy Officer, Charles Schulz. He'll talk about why open digital infrastructure is crucial and how we can keep control of our digital future. This year's conference is all about discussing the potential of free software and how we can work together to keep our digital freedom. Read more about Charles' talk in our Vates blog post: [SFSCON 2023: Elevating Open Source Innovation in EuropeThe SFSCON 2023 is taking place in Bolsano on Nov. 10th and Nov. 11th. More than 100 speakers will participate in the event, making it a great place for innovation, collaboration and thought leadership.![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogMarc-André Pezin![](https://vates.tech/blog/content/images/2023/10/headway-F2KRf_QfCqw-unsplash.jpg)](https://vates.tech/blog/sfscon-2023-elevating-open-source-innovation-in-europe/?ref=xen-orchestra.com) ### CloudStack Collaboration Conference 2023 This time, it's an event dedicated to [CloudStack](https://cloudstack.apache.org/?ref=xen-orchestra.com), in Paris on 23-24 November. I will be there to host a workshop called "**Zero to Cloud Hero: Crafting a Private Cloud from Scratch with XCP-ng, Xen Orchestra, and CloudStack."** Charles will also make a talk on Open Source specifically, while Andrei will present "**Enabling DPU Hardware Accelerators in the XCP-ng Cloud Platform Environment**." More details here: [Meet Vates at CloudStack Collaboration Conference 2023Vates is proud to be a partner for the upcoming CloudStack Collaboration Conference in Paris on 23-24th November. This event is a great platform where industry pioneers, passionate developers, and tech aficionados come together. Vates continuous participation as a sponsor reaffirms its commitment t…![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogMarc-André Pezin![](https://vates.tech/blog/content/images/2023/09/product-school-dJICd7b_LlE-unsplash.jpg)](https://vates.tech/blog/meet-vates-at-cloudstack-collaboration-conference-2023/?ref=xen-orchestra.com) ### A new card preview and README file for XO We added a new card (in your Github project settings by the way), to display a nice image preview when you post it on social networks and such: [GitHub - vatesfr/xen-orchestra: The global orchestration solution to manage and backup XCP-ng and XenServer.The global orchestration solution to manage and backup XCP-ng and XenServer. - GitHub - vatesfr/xen-orchestra: The global orchestration solution to manage and backup XCP-ng and XenServer.![](https://github.com/fluidicon.png)GitHubvatesfr![](https://repository-images.githubusercontent.com/8077957/6dcf71fd-bad9-4bfa-933f-b466c52d513d)](https://github.com/vatesfr/xen-orchestra/?ref=xen-orchestra.com) Also, if you are browsing Github to find new exciting projects, the first thing you will notice will be the README file. We neglected it (in favor of [our official documentation](https://xen-orchestra.com/docs?ref=xen-orchestra.com)) but now it's a lot better! I mean, take a look by yourself. Before and after. I think we can tell it's clearly better now! ![](https://xen-orchestra.com/blog/content/images/2023/10/old.png) ![](https://xen-orchestra.com/blog/content/images/2023/10/Capture-d--cran-du-2023-10-25-14-44-00-1.png) ### XO team is growing We welcome [Mélissa](https://github.com/Pizzosaure?ref=xen-orchestra.com) in the XO team, and it's not the only one joining the team. Two more developers will be joining us in the coming months. So keep an eye out—our team is expanding, and it couldn't come at a better time with all the exciting new projects we have on the horizon! ![](https://xen-orchestra.com/blog/content/images/2023/10/astronaut.png) ### A community investigation on Netbox Sometimes, users expect unknown behaviors, and in this case, the right move is to open a thread in our forums. And that's exactly what was done [for this issue](https://xcp-ng.org/forum/topic/7887/netbox-only-working-for-1-pool?ref=xen-orchestra.com): during a Netbox sync, we had an error message telling: `The selected cluster is not assigned to this site (None).` After various investigations (thanks to Pierre!) we managed to track down the problem, due to a behavior change in Netbox between multiple versions: - Prior to Netbox **v3.3.0**: no "site" field on VMs - **v3.3.0**: "site" is REQUIRED and MUST be the same as cluster's site - **v3.3.5**: "site" is OPTIONAL (auto-assigned in UI, not in API). `null` and cluster's site are accepted. - **v3.4.8**: "site" is OPTIONAL and AUTO-ASSIGNED with cluster's site. If passed: ignored except if site is different from cluster's, then error. So updating Netbox to v3.4.8 or later fixed the issue. Obviously, we also managed to get a patch to workaround the problem if you are running on an older Netbox version. But you know, it's always important to keep your software up to date, mostly for potential security flaws. ### A new external contribution We are please to report another external (outside Vates) contribution. Every time someone is contributing, we do our best to help her/him, and we never forget to credit the person! This month, it's a big thanks to [Malcolm Scott](https://github.com/mas90?ref=xen-orchestra.com)! See below for details on the feature "Preserving current page across reauth". --- ## 💾 Backup There's always a lot of work in this area. This month, it was mostly improving the existing code and fixing bugs. But we also managed to deliver an important optimization for those using S3 with full backups (large XVA files). ### S3 full backup improvements As soon you sent XVAs larger than 50GiB, you could had various issues, depending on your S3 provider, who usually wanted to split the files or at least sending some error messages about that. We found a way to get it in a better way, that will also make it more robust and consume less XO memory! --- ## 🌍 Terraform Many new things and improvements for our Terraform provider! The latest release (`v0.25.1`) and the one before are offering the management of XenServer/XCP-ng bonded network, support for `destroyCloudConfigVdiAfterBoot` and `source_pif_device`. Among many other things, feel free to check the changlogs at [https://github.com/terra-farm/terraform-provider-xenorchestra/releases](https://github.com/terra-farm/terraform-provider-xenorchestra/releases?ref=xen-orchestra.com) [GitHub - terra-farm/terraform-provider-xenorchestra: Xen Orchestra provider for TerraformXen Orchestra provider for Terraform. Contribute to terra-farm/terraform-provider-xenorchestra development by creating an account on GitHub.![](https://github.com/fluidicon.png)GitHubterra-farm![](https://opengraph.githubassets.com/fc0e988d0aac64e182350068dd1ce90f964319cf071782bfb1c97c40f5fc36f0/terra-farm/terraform-provider-xenorchestra)](https://github.com/terra-farm/terraform-provider-xenorchestra?ref=xen-orchestra.com) It was also the opportunity to improve XO internal API (the JSON RPC one, used by the Terraform plugin) to expose xenstore attributes. This is useful for a Citrix/Cloud Software Group developper to do some nice automation with Citrix VDI with Terraform on top of Xen Orchestra! 💡 What about OpenTofu? We are [proud supporters](https://opentofu.org/supporters/?ref=xen-orchestra.com) of the OpenTofu project, and be sure we'll also validate our Terraform provider to work with OpenTofu! --- ## **🔭** XO Lite More actions can be achieved in XO Lite this month! You can now clone and/or snapshot your VM: ![](https://xen-orchestra.com/blog/content/images/2023/10/274330878-d3f7eec0-5ac2-4f70-8e5a-d7a298a6e69f.png) We also added the very much needed "Ctrl Alt Del" button in the console view so you can finally login to your Windows guest: ![](https://xen-orchestra.com/blog/content/images/2023/10/274545275-d8ebd7fc-855f-492e-a0e6-1bb481e0e48d.png) Various improvements also in the UI, like nice icons when loading a graph, putting the title instead of the XO Lite logo on the header: ![](https://xen-orchestra.com/blog/content/images/2023/10/277361824-71644544-dfdc-44c6-a1c1-6623024f74de.png) And finally a simple but nice extra, a "remember me" checkbox on the login form: ![](https://xen-orchestra.com/blog/content/images/2023/10/267048624-a4fd908e-b25a-4ee4-897d-03bd9c55f743.png) --- ## 🛰️ Xen Orchestra 6 We wanted to keep you posted on the progress we are making for XO 6\. It's hard to juggle between bug fixes, XO 5 and XO Lite improvements but we are still moving forward! Most of the work is mostly on designing that new UI (see the "New mockups" paragraph below) but also re-designing on the technical aspects. We started to build a basic bootstrapping for the new `xo-web`, which will serve as the cornerstone for our entirely revamped user interface. That's also where we start to work on a truly poweruly new subscription system, fetching only the required objects. This will solve so many limitations or performances issues, we are pretty excited to demonstrate something before the end of the year. Stay tuned and enjoy the new mockups in the meantime! ### New mockups XO 6 will focus on providing a massively upgraded experience on what we think is the most important stuff to improve: **backup management**. Obviously, we'll also have a fresh/new dashboard, which we refined: ![](https://xen-orchestra.com/blog/content/images/2023/10/Capture_2023-10-25_14-16-41.png) But the real deal will be the backup management experience. For example, here is the new "flat" backup view without specific grouping of your backups: ![](https://xen-orchestra.com/blog/content/images/2023/10/Capture_2023-10-25_14-20-41.png) That's already many times better than the current XO 5 view. It's a lot clearer, and directly build with the capability to interact with all your backups, that you have one or hundreds of them. Check the "Add group" button on the top right. That's the real deal: it's a very efficient way to restore your entire site or a large chunk of your infrastructure. You can group all your backups by BR (Backup Repository), VMs, jobs etc. ![](https://xen-orchestra.com/blog/content/images/2023/10/Capture_2023-10-25_14-18-51.png) Finally, the file level restore view is also vastly improved, with many extra information without cluterring the UI: ![](https://xen-orchestra.com/blog/content/images/2023/10/Capture_2023-10-25_14-19-51.png) As you can see, this will give a far more pleasant experience when dealing with your backups. And it will be the first part of XO 6 that will be available in a dedicated path of your UI in Xen Orchestra virtual Appliance, so you can play with it as soon it's there. --- ## ☄️ First XOSTOR interface As we are moving forward with XOSTOR (and still having our share of new bugs but hey! better now than later!), we wanted to provide a simple UI to create our hyperconverged storage, so we can gather more feedback from our XOA users. As a first step, we just finished to provide the UI to create a new XOSTOR storage. It wasn't trivial, since we needed to expose the physical disks (inside your hosts) to the Xen Orchestra web UI. After writing some new plugins on the host side, and a some glue in XO, here is the first result: ![](https://xen-orchestra.com/blog/content/images/2023/10/278352020-1a472b83-6b27-41c0-8806-3193875cef2a.png) We tried to make the UI as simple as possible, hiding pools and disks where you can't create any XOSTOR (missing requirements), make it easier to interact with, limiting the potential issues. It's even possible we'll make it even simpler in the next iteration. After that, we'll have a dedicated view (like we had in XOSAN) to manage your XOSTOR, with many interesting health data directly displayed in XOA. 💡 If you are using XO from the sources, you won't be able to enjoy this view, but you can always install XOSTOR manually without any limitations. All feedback is welcome, we also have a [100% dedicated section to XOSTOR in our forums](https://xcp-ng.org/forum/category/20/xostor?ref=xen-orchestra.com)! --- ## 🚀 XCP-ng 8.3 features This section is dedicated to new features we added in Xen Orchestra, that are only compatible with XCP-ng 8.3: most of the new modifications we are doing in XCP-ng are not backported to the LTS version, for obvious stability reasons. ### vTPM management in the UI Most of the vTPM work was done by XenServer (we wanted to contribute but we can understand they were already advanced enough to need some help, even if we think it would have been helpful for review but hey, you can't force someone to accept contributions). But at least, we "finished" the work by exposing the features in a centralized and web UI (and API, and CLI): you guessed… Xen Orchestra! You can now do the entire "cycle" of using a vTPM to run a Windows 11 VM, or any other OS by the way. Just create the vTPM for your VM (in the Advanced tab): ![](https://xen-orchestra.com/blog/content/images/2023/10/273971439-e440e27e-5593-470d-bd72-8b61c51f1455.png) And that's it! ![](https://xen-orchestra.com/blog/content/images/2023/10/273971424-0f3bdd90-753a-47bf-ac26-643638a82aa2.png) You can delete it anytime if needed. ### `host.evacuate` max limit When doing a "maintenance mode" on a host in Xen Orchestra (or a Rolling Pool Update), at some point it will call the `host.evacuate` XAPI method from XCP-ng. This call will live migrate all VMs from a host to any other available host in the same pool. It will do that by concurrently migrating 10 VMs at once to speed up the evacuation. However, if your storage system is pretty under stress already (or your host), this might affect the "freezing" time of a VM in the process. For example in a very crowded and noisy environment, in some cases, one VM can be paused around 30 seconds, far from the usual hundreds of milliseconds in a "normal" case. There's a workaround already: add a configuration file in `/etc/xapi.conf.d/`, and change the value to a lower one in that file. However, this requires a modification on all your hosts, so it's really not a definitive solution. We wanted something integrated! To answer that requirement, we decided to upgrade the XAPI method with an optional parameter, the "batch size": [Choose size of batch VM evacuation by benjamreis · Pull Request #5203 · xapi-project/xen-apiNew optional argument to Host.evacuate: evacuate\_batch\_size When provided uses it instead of xapi.conf’s evacuation\_batch\_size When not provided uses the xapi.conf option Fixes: #5202![](https://github.com/fluidicon.png)GitHubxapi-project![](https://opengraph.githubassets.com/29093d380e57d3022f02084c3b42a7f2725cdab3cfc0afb5b6132c891eaacd56/xapi-project/xen-api/pull/5203)](https://github.com/xapi-project/xen-api/pull/5203?ref=xen-orchestra.com) Thanks to a very reactive XAPI team, our modification was merged pretty quickly. But that's not it! Now you have an optional parameter in the method, Xen Orchestra is also using it, with a concurrency at 3 by default. 3 is a sweet spot between speed to migrate and avoiding long pause time in live migrations. And it doesn't change any default configuration on your hosts! This feature is another great demonstration how great is the fact we -at Vates- can deliver the whole stack at once: when we modify the API of the host (XCP-ng) we can also leverage it to apply the thing we wanted directly in Xen Orchestra! --- ## **🆕** Misc Despite all the "behind-the-scenes" work done for new XCP-ng 8.3 features, XOSTOR, XO Lite & XO 6 (that's a lot 🥵), we also have **many improvements in the existing Xen Orchestra version**. ### Preserve current page after re-authentication This one is not that big in terms of lines of code, but **really** handy for both our users and developers. First, mostly for developers: if your restart `xo-server`, you won't lose your current page after re-login. And for most users: if you need to re-log (eg after one night), you will be re-transferred to the previous page you were before. Very very handy, pretty simple to achieve but… we never really managed to work on that. Thanks a lot to our external contributor to push us to make it real! [fix(signin): try to preserve current page across reauthentication by mas90 · Pull Request #7013 · vatesfr/xen-orchestraIf an authentication session expires or is lost for whatever reason, XO redirects to /signin. This redirect generally preserves the URL fragment (hash) which contains the page selected prior to re…![](https://github.com/fluidicon.png)GitHubvatesfr![](https://opengraph.githubassets.com/9d13bfeba37b1a1993ec1372cb84f6e06f31c716d45626c6d72e39fd49e82f0b/vatesfr/xen-orchestra/pull/7013)](https://github.com/vatesfr/xen-orchestra/pull/7013?ref=xen-orchestra.com) ### Netbox Thanks to a nice investigation lead on the forum and Pierre's dedication (see the community section before), we managed to solve the synchronization issues one could encounter if not running on a recent version of Netbox. But keep up on the updates, because like Xen Orchestra, the great Netbox project is releasing often and fixing security issues on new versions! ### Show network name in PIF Sounds trivial, but in fact it is very helpful. Now, we show the network name in PIF selectors as it can help differentiate PIFs that have the same device/deviceName. ### Check version for source users Our [documentation is pretty clear](https://xen-orchestra.com/docs/community.html?ref=xen-orchestra.com#current-version) about this: ![](https://xen-orchestra.com/blog/content/images/2023/10/image-2.png) But it's a common issue we have in the community: people are eager to report a problem, but forgeting -at first- to check if your XO is correctly up-to-date on the latest commit on our `master` branch. That's why we decided to help our source users to display if they are up-to-date or not, directly in the "About" view: ![](https://xen-orchestra.com/blog/content/images/2023/10/274903667-86e87a08-4161-4f00-be16-2c84ffcddcb0.png) ### Self service improvement In the self service view, you can now have a precise number of VMs using a specific self service (or resource set). ![](https://xen-orchestra.com/blog/content/images/2023/10/image-4.png) And by clicking on the link, you'll go to an automaticallyt filtered view of these VMs: ![](https://xen-orchestra.com/blog/content/images/2023/10/276933855-1c1a676b-a39b-45ac-839d-212a047d9239.png) This is pretty useful if you administrate multiple self services and want to keep an eye on who is doing what. ### VDI health display improvements This month, we managed to generate various improvements related to your VM disks, or VDIs. First, in the Dashboard/health view, where we a displaying "Orphaned VDIs", in other words, VDI not connected to any VM will appear here. However, some VDIs are special and shouldn't be displayed there (like some virtual iDRAC devices). Those devices are sized at "0", so we used that to filter them out. We also improved the computation of the number of VDI to coalesce, because we were a bit pessimistic on the number, since you can have the same chain with multiple branches. And since we now have a correct number, we also provided the exact amount: before it was "more than 10" for example. ### Token management revision Token management could have a dedicated blog post, since the topic is pretty large. But in short, we previously generated many many tokens from the original one created (for example) with XO CLI. And cluttered the interface and was confusing. Now, your freshly created token will stay unique and the UI to see your token will be a lot more understandable! ### Xen Orchestra 5.87 URL: https://xen-orchestra.com/blog/xen-orchestra-5-87/ Last updated: 2023-12-03T12:17:45.000Z Welcome aboard to our invigorating September release! We've been industrious across numerous fronts. From project management down to the nuts and bolts of Xen Orchestra, every component including XO Lite has received our careful attention. Dive in and enjoy the array of updates we've crafted for you! As usual, you can also find this release note in a video format! And the podcast format: ## 🧑‍🚀 Project & Community Under the umbrella of continuous community improvement, we have made several enhancements around the Xen Orchestra Project and our community interactions. ### Forum reorganization Swiftly adapting to the ever-growing needs of our community, we have restructured the forum by creating sub-categories. This simple change allows for a streamlined topic sorting process and provides an effortless way to follow specific discussions: ![](https://xen-orchestra.com/blog/content/images/2023/09/image-1.png) In an effort to encourage more feedback and interactive discussions, we have dedicated an entire section to the Xen Orchestra REST API. You can view and participate in the conversations here: [https://xcp-ng.org/forum/category/18/rest-api](https://xcp-ng.org/forum/category/18/rest-api?ref=xen-orchestra.com) #### Share Your Setup! We've launched a new eye-catching section in our forum for sharing your personal setups. Be it a home lab or a production-grade setup, we invite you to share, ideally with pictures, and discuss the choices you've made. For inspiration, you can view how the backbone of our own production setup, where this engaging community exists: [https://xcp-ng.org/forum/topic/7772/xcp-ng-xo-at-vates](https://xcp-ng.org/forum/topic/7772/xcp-ng-xo-at-vates?ref=xen-orchestra.com) ![](https://xcp-ng.org/blog/content/images/2020/06/dc2-small.jpg) And not only this forum, but Vates' entire self-hosted Open Source infrastructure: [Our self-hosting journey with Open SourceExplore Vates’ journey to self-hosted success, championing open-source solutions for unparalleled uptime and total data control. Dive into a blueprint of cost-effective, secure, and autonomous IT infrastructure.![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogOlivier Lambert![](https://vates.tech/blog/content/images/2023/08/dc.jpg)](https://vates.tech/blog/our-self-hosting-journey-with-open-source/?ref=xen-orchestra.com) ### GitHub repository cleanup In our mission to enhance the Xen Orchestra project, we took major steps to tidy up our Github repository. We resolved a high number of issues that were already taken care of or simply no longer applied. Today, **only 233 issues remain open out of a once colossal total**, with the majority related to our up-and-coming V6\. This means that now, a mere 7% of all reported issues are still awaiting resolution - demonstrating our team's consistent commitment. ![](https://xen-orchestra.com/blog/content/images/2023/09/image-2.png) Moreover, we've only got 4 issues not tied to a milestone, reflecting our team's systematic approach towards managing the repository. This organized method of assigning issues to specific milestones supports an environment conducive to productive problem-solving and smooth project progression. ### 2CRSi partnership The future of [Vates](https://vates.tech/?ref=xen-orchestra.com) – and Xen Orchestra by extension – is taking a significant leap forward as we embark on a closer cooperation with hardware and server manufacturers, such as 2CRSi. Our goal is to offer a comprehensive commercial proposition that bundles hardware, XCP-ng, and Xen Orchestra together. This "off-the-shelf" solution will enable our customers to access a complete setup all at once, assured with the knowledge that everything is vetted for optimal performance and compatibility. The partnership serves to simplify the user experience, ensuring that every element of the package works flawlessly right out of the box. You can read more here: [2CRSI and Vates join forces to create a joint offeringWe’re proud to share that Vates, our company specialized in open-source virtualization, is partnering with 2CRSi, a pioneer in energy-efficient, high-performance IT servers.![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogMarc-André Pezin![](https://vates.tech/blog/content/images/2023/09/fidel-fernando-DubQVeFFbFQ-unsplash.jpg)](https://vates.tech/blog/2crsi-and-vates-partnership/?ref=xen-orchestra.com) Stay tuned for exciting news on this topic! ## 🔭 XO Lite XO Lite continues to receive an array of enhancements. ### RPM package We are excited to share that XO Lite now comes as a standard RPM package within XCP-ng 8.3 (currently in beta version). At some point, we aim to keep pace with updates for those with an internet connection. Yet, even if you're offline, you can still reap the benefits of XO Lite. ### Bulk actions: VM migration & snapshot You can now execute multiple VM migrations at the same time with a new bulk action command. Also, we've introduced the ability to take a VM snapshot on numerous VMs simultaneously. ![](https://xen-orchestra.com/blog/content/images/2023/09/VMs-bulk-migration.png) ### ### Pool dashboard patches Great news on the pool dashboard front! While it took us a tad longer than anticipated, we've added a summary of missing patches for your XCP-ng host directly in the main dashboard. This means you can now keep track of critical updates with ease. ![](https://xen-orchestra.com/blog/content/images/2023/09/Dashboard.gif) ## 💾 Backup Over the past month, we've made several bug fixes and improvements to enhance system resilience and add failsafes for specific scenarios. ### Block migration during backup Migrating a VM during backup could lead to unexpected results. Thankfully, this situation is likely rare but, we are aware that some users carry out various actions while a backup is running. To shield against any unpredictable outcomes, we now secure the VM just before the backup by locking any migration operation. This lock is then removed after completion. If we detect that the VM is already under a migration process, Xen Orchestra will simply skip it, ensuring we uphold system integrity at all times. ## **🆕** Misc This release is packed with numerous quality-of-life enhancements and useful features that we believe you will appreciate! ### Download all host system logs With a simple button press, Xen Orchestra will prompt your host to generate a comprehensive tarball with all logs. This is a substantial operation (several hundred MiB), but invaluable for deep investigations. ![](https://xen-orchestra.com/blog/content/images/2023/09/270393406-c210c652-78b2-4069-98c1-17167b45beb3.png) With a modal warning about the fact it's a pretty beefy operation: ![](https://xen-orchestra.com/blog/content/images/2023/09/270553178-75e8fb70-e661-419b-bc14-2fd78cdd2190.png) We've also added a REST API endpoint allowing downloads from any terminal: ``` curl \ -b authenticationToken=KQxFkTbs \ 'https://xo.company.lan/rest/v0/hosts//logs.tar' ``` ### Disk health monitoring Thanks to an [external contribution by Cécile](https://github.com/xcp-ng/xcp-ng-xapi-plugins/pull/37?ref=xen-orchestra.com), XCP-ng 8.3 will come with a new XAPI plugin that employs `smartctl`, which means you can now monitor disk status via an API call. Which Xen Orchestra is displaying in the UI now! ![](https://xen-orchestra.com/blog/content/images/2023/09/271327875-aea3c985-4fea-4c04-8c8f-bd561c1c4e5d.png) Displaying the disk status when all are "PASSED" ![](https://xen-orchestra.com/blog/content/images/2023/09/271237796-40612f6e-15f1-4acc-a594-9786b92a07c7.png) When some disks are not healthy This is just the beginning of hardware monitoring improvements we intend to implement in partnership with our hardware collaborators, aimed at simplifying hardware management tasks, such as health tracking and firmware updates. This grants increased security by flagging outdated firmware and enhances safety by detecting potential issues directly within Xen Orchestra. ![](https://xen-orchestra.com/blog/content/images/2023/09/271237812-e27c00fe-824a-4017-b103-a0fa8c770151.png) Disk details ### Restart `xo-server` You can now restart the Xen Orchestra server directly from the UI, providing a handy tool to quickly cancel blocked tasks or unlock stuck processes. ![](https://xen-orchestra.com/blog/content/images/2023/09/270627038-e3f0c331-00a0-48db-8dab-b9a9dd399ae7.png) ![](https://xen-orchestra.com/blog/content/images/2023/09/270627054-f5d36680-2adc-4884-9881-3c598524f287.png) ### Thin-reclaim for block based SRs If your SAN supports it, Xen Orchestra can instruct your XCP-ng host to send a trim command to perform some cleaning - a useful addition you'll appreciate. ![](https://xen-orchestra.com/blog/content/images/2023/09/270361445-a3694b45-6e44-40ee-81b9-89432b509dd0.png) ![](https://xen-orchestra.com/blog/content/images/2023/09/270361432-37d122f0-9f78-4509-8a76-53582098a108.png) ### Add failed sign in to the tasks Our task system now logs failed sign-in attempts, keeping you informed about potential brute-force attempts on your Xen Orchestra account. ![](https://xen-orchestra.com/blog/content/images/2023/09/image-10-.png) ### Add product brand and version on host/pool In the Home/Host view, you can expand your host and pools for additional details, such as if you're using XCP-ng or XenServer. Fun fact: less than 2% of our Xen Orchestra users are still on XenServer! ![](https://xen-orchestra.com/blog/content/images/2023/09/270373429-bd42a52b-6406-4ce4-b1e6-4e1b3a840dba.png) Speaking of which… ### New XenServer patches system As XenServer now functions as a separate business unit within the "Cloud Software Group", updates have fallen behind a paywall. Understanding this new system took time, but in essence, you now need a token from a Citrix.com website (lol): ![](https://xen-orchestra.com/blog/content/images/2023/09/xs-client-id-download.png) Once saved allows Xen Orchestra to fetch and download patches for your XenServer system. You can upload it in XO UI now: ![](https://xen-orchestra.com/blog/content/images/2023/09/269878777-1dab328d-2506-4dbd-899b-f5c02f26c50d.png) Perhaps it's time to consider a switch to XCP-ng? ### Xen Orchestra 5.86 URL: https://xen-orchestra.com/blog/xen-orchestra-5-86/ Last updated: 2023-08-31T13:00:57.000Z Following our summer hiatus, we're excited to unveil the latest iteration of Xen Orchestra, in its version 5.86, now accessible to everyone. This month, we've enhanced various backup functionalities while exploring deduplication, and made significant strides in the ongoing development of both XOSTOR and XO Lite. And here is the podcast format! ## 💾 Backup Various improvements but also some exploration on potential gain related to deduplication! ### Retry on write error on S3 backup The S3 protocol became a *de facto* standard to store many things. The issue with that: many different S3-compatible providers are providing different error codes depending on the issue. The "standard" isn't really a standard when you have errors. This make the retry very difficult: we started by reading the actual error, but since there's hundreds (thousand likely) different providers with their own error code, it was not really reliable. That's why we decided to be more aggressive on retry, regardless the details error code returned by your S3 provider. This will mitigate failures and provide a better reliability without restarting a whole backup job! ### Parallelize merge worker This new features enables parallel merging of multiple VMs within the merge worker, a feature designed specifically for high-performance BR (Backup Repositories). When you have fast SATA SSDs or NVMe drives, you might have faster merge when doing in parallel on multiple VM disks. ⚠️ Merging is a resource-intensive task; exercise caution and ensure your infrastructure has the necessary capacity to handle the increased resource consumption this option demands. ### Exploring deduplication with ZFS This month, we investigated backup deduplication with ZFS, examining its efficiency, potential challenges, and prerequisites in order to create our own in-house deduplication solutions. **Why using ZFS for deduplication?** Storing backups as VHD files doesn't work well with ZFS block-based deduplication: even identical backups might have different ZFS block alignments within the file, making deduplication inconsistent and generally not very effective. Switching to block storage backup ensures that each 2MiB backup block contains exactly the same content. This approach works smoothly with ZFS deduplication. When you create two key (full) incremental backups, they only occupy as much space as one full backup, without significantly compromising reliability. If a block from the older backup is changed or corrupted externally, it's saved as a new block in the new key backup, ensuring the integrity of the backup chain. The effectiveness of deduplication also depends on the duplication between your disks. You can check the duplication ratio using the ZFS tool `zfs -S tank`. You can test this without actually enabling it on an existing backup repository. Here's a guide: [Testing ZFS Deduplication](https://www.oracle.com/technical-resources/articles/it-infrastructure/admin-o11-113-size-zfs-dedup.html?ref=xen-orchestra.com). **Extra Note:** - Deduplication on ZFS consumes a significant amount of memory. If you don't have enough memory available, it will use disk space instead, but this can slow down performance. Our tests indicate that you need at least 1% of your disk's capacity in memory for efficient deduplication. That is 10GiB of memory per disk TiB - Deduplication doesn't work with encrypted backups because encryption adds a unique identifier at the beginning of the file, making it completely different on disk. This doesn't apply to full backups. **What's coming next?** We'll explore testing on Btrfs, especially with [bees](https://github.com/Zygo/bees?ref=xen-orchestra.com), which claims to use only 0.1GB of storage per terabyte. In the end, we're in the process of developing our own in-house deduplication method: we plan to make it available to users only if it proves to be notably more effective and easy to use than the currently existing approach, by knowing the structure of the data stored. ### Exploring a fast path for backup For now, the usual bottleneck in XO backup speed is on the host itself (XenServer/XCP-ng). Mostly because the program that exports the VM will make many conversions (VHD to raw to VHD). Our initial tests to simply bypass it and rely on a small Python PoC (far from being optimized) is giving very promising results, like around twice the backup speed. We are working on a PoC to explore this more, while discussing with the upstream (XAPI project) about how to achieve similar speeds natively. ## **🔭**XO Lite This month, a huge rework was done to get a better management of collections and events. This will be also very helpful for XO 6\. The experience we get on XO Lite is really important to be able to develop a solution at scale for thousand hosts. If you are interesting into the coding details, enjoy the read! ![](https://xen-orchestra.com/blog/content/images/size/w2000/2022/06/XO-Blog---UX-UI-Design-for-XO-and-XOLite.jpg) ### New iteration for XenApi records stores and collections Long story short, we are revamping the way XenApi functions, introducing an event-based system for more streamlined data handling and better performance, all while simplifying the coding experience through new helpers and a cleaner organizational structure. #### XenApi Rather significant change in the way `XenApi` works. Previously, you had to call `injectWatchEvent`, `registerWatchCallback` and `startWatch`. On connection, we would load all existing types from the server. Every second or so, we would call `event.from` for *all* previously loaded types. Then, for each result returned, the previously defined callback method was called, with the result as a parameter. It was then up to this callback to handle each result, check its type, find the corresponding store and insert/update/delete the record, etc. This had several drawbacks: - All types had to be loaded at startup - We had to call `event.from` with all types every second - We had to check the type of each result in the callback to see if it was supported - We had to find the corresponding collection in the callback - We had to check whether a component had subscribed to this collection - The callback had to insert/update/delete the record in the collection. Instead, we decided to bring up an event system within `XenApi`! It's now up to each store to add listeners to the events it's interested in. These events are named `.add`, `.mod` and `.del`. For example, as soon as there is at least 1 subscription to the `messageStore`, it will call `xenApi.addEventListener` for the `message.add`, `message.mod` and `message.del` events. Now, every second or so, a call is made to `event.from` with only the list of types for which at least one event has been registered. Consequently, if components on a page have subscribed to the `vm` and `host` stores only, then the call to to `event.from` will only be made for these two types. And callbacks will be called accordingly. If a VM has been deleted, only the callbacks registered for the the `vm.del` event (if any) will be executed and the store itself will update its own collection. Finally, as soon as there are no more subscriptions, the store will remove these callbacks via `xenApi.removeEventListener`. #### Stores & Collections These new modifications also bring back the store usage to handle XenApi collections: it uses a kind of a mix of the solutions used in previous iterations. The problem with the exclusive use of composables was that the collection extension was executed on every call. So if 10 components call `useVmCollection`, then anything added to the base collection (addition of computed, functions, etc.) is repeated 10 times. Using a store solves this problem, as the store setup function is only executed once. The problem with using a store is that it has no way of knowing how many times it has been used. It is therefore impossible to automatically `subscribe`, or to pass parameters to `useVmStore()` (for deferring for example). A basic store is therefore created as follows: ```js export const useVmStore = defineStore('vm', () => createXenApiStore("vm")); ``` If you want to extend this store with additional data, it's very simple: ```js export const useVmStore = defineStore('vm', () => { const baseStore = createXenApiStore("vm"); return { ...baseStore, recordsCount: computed(() => baseStore.records.value.length) }}); ``` But as I was saying, it's not possible to do a `subscribe` automatically. You'd have to manage the subscription manually, and also end up with all the store properties, most of which are not useful. ```js // To be done every time you want to use a store... const vmStore = useVmStore();const { records } = storeToRefs(vmStore); const id = Symbol(); onBeforeMount(() => vmStore.subscribe(id)); onUnmounted(() => vmStore.unsubscribe(id)); // vmStore. <- autocomplete with all store properties ($onAction, $subscribe, $state, _customProperties etc.) ``` This is where a new helper comes into play: `createSubscriber`. It will return a function which when called will take care of creating the `id`, subscribing, performing the `onUnmount` and managing the `defer` option, which allows you not to fetch data immediately. It will also filter out any store "noise" and perform the `storeToRefs` automatically. ```js // vm.store.tsconst useVmStore = defineStore("vm", /* store setup */) const useVmCollection = createSubscriber(useVmStore); ``` This greatly simplifies usage: ```javascript const { records } = useVmCollection();// ^-- Here, only useful properties (records, hasError, etc.) are proposed to completion. ``` #### Code reorganization XenApi code has been split to 3 files: - `libs/xen-api/xen-api.ts`: contains the `XenApi` class - `libs/xen-api/xen-api.type.ts`: contains all the typings - `libs/xen-api/xen-api.utils.ts`: contains helpers, enums etc. This XenApi could one day be published in its own package, so: - Any code concerning the `XenApi` must be in the `libs/xen-api` directory. - Any code used by any file in the `libs/xen-api` must *not* be aware of any other part of the XOL project. ### Pool dashboard: Alarms (load on demand) We added a component in XO Lite: the list of alarms message coming from your host. Initially, we loaded everything, but you can have more than thousands alerts. This has a big tool on the initial loading of the main dashboard. That's why we dedided -this time- to only load them on demand. ![](https://xen-orchestra.com/blog/content/images/2023/08/259184328-8d04bb20-83e6-420b-b605-6818aa8ae0c9.png) ![](https://xen-orchestra.com/blog/content/images/2023/08/263928199-f8ce4d9c-5cbc-47f4-958c-7f1f478581aa.png) ## **🗃️** XOSTOR Preview XOSTOR's core functionalities have reached a level of maturity suitable for production use across various infrastructures. Our current focus is on refining the User Interface, and we're pleased to report significant advancements in this area. ![](https://xen-orchestra.com/blog/content/images/2023/08/xostor-creation-ui.png) ![](https://xen-orchestra.com/blog/content/images/2023/08/xostor-ui.png) This means we entered the home straight before releasing it officially! This UI is only available on a specific branch right now, but expect to be available directly in XOA for our next release! ## **🆕** Misc There's also various improvements done during this month of August. ### Possibility to configure `crash_dump_SR` A crash dump SR is a place when you can store the memory dump of a crashed VM. It might be helpful to use when your guest OS is crashing and you want to understand why. While configuring a `crash_dump_SR` via XO CLI was feasible, we've streamlined the process to offer a more user-friendly approach: ![](https://xen-orchestra.com/blog/content/images/2023/08/set-crash-dump-sr.png) ### Expose use NBD settings on backup jobs We added a setting in the advanced tab of incremental backup to allow users to set NBD setting directly from the UI: ![](https://xen-orchestra.com/blog/content/images/2023/08/nbd-settings.png) As a reminder, NBD-enabled backup are in general faster than the traditional VHD handler, generated by the XAPI. ### Xen Orchestra 5.85 URL: https://xen-orchestra.com/blog/xen-orchestra-5-85/ Last updated: 2023-07-31T12:11:24.000Z Even as we bask in the peak of the Northern hemisphere's summer, our commitment hasn't taken a vacation. We're thrilled to roll out intricate updates, notably to our V2V (VMware to Vates) tool and the much-anticipated Netbox synchronization plugin 2.0\. And the excitement doesn't stop there: explore the new additions to XO Lite and a host of other enhancements. Dive in and make the most of them! You can also listen it as a Podcast : ## 🐦 VMware migration tool (V2V) We're thrilled to announce that our VMware to Vates (V2V) tool now fully supports warm migrations to XCP-ng across all VMware versions, including the most recent ones. For those new to this, our V2V tool simplifies the migration process by letting you effortlessly connect a vSphere setup from Xen Orchestra. All you need to do is select the VMs you wish to migrate and hit "Migrate." The magic of warm migration? Your VM will be snapshotted and sent to XCP-ng while it's still running. After the completion, we'll shut it down, send any differential data, and then boot it up on the XCP-ng end. This means minimal disruptions and downtime for you. For those who love the nitty-gritty, we've also updated our guide, ensuring you have a comprehensive understanding of every step: [Migrate from VMware to XCP-ngVmware v6 is now end of life, the right time to migrate to an open source, less expensive and constantly evolving solution: XCP-ng.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOlivier Lambert![](https://xcp-ng.org/blog/content/images/2022/10/chris-briggs-V72Hk6LjjjI-unsplash.jpg)](https://xcp-ng.org/blog/2022/10/19/migrate-from-vmware-to-xcp-ng/?ref=xen-orchestra.com) If you're looking for some real-world inspiration, check out this recent success story on a migration from VMware to Vates: [Leading the Pack: MANI Indústrias Plásticas SA’ Journey with Vates Virtualization Management StackSituated at the forefront of the industry, MANI SA exemplifies a commitment to innovation and forward-thinking. This implementation serves as a stellar instance of Industry 4.0 in action, seamlessly integrating cutting-edge technology with traditional manufacturing operations.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogMarc Pezin![](https://xcp-ng.org/blog/content/images/2023/05/mani-banner.png)](https://xcp-ng.org/blog/2023/05/15/leading-the-pack-mani-industrias-plasticas-sa-journey-with-vates/?ref=xen-orchestra.com) ☝️ A little behind-the-scenes tidbit: To ensure compatibility with VMware versions after 6.5, we had to navigate the proprietary SESparse format, which unfortunately lacks official documentation. But, kudos to the Qemu project! Their prior efforts in reverse engineering the format became our guiding light, enabling us to reimplement it in Javascript. ## 🗃️ Netbox Remember the Netbox plugin we introduced two years ago? We've taken a trip down memory lane, reflecting on its capabilities and limitations. We realized it was high time to supercharge it. After an immense amount of work, we're delighted to unveil the revamped Netbox plugin! [DevBlog #9 - Netbox synchronization with XOWhen you start to have a lot of virtual machines and IP addresses, you might need to organize a bit with an IPAM. Netbox is such a thing.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2021/05/netboxsyncheader.jpg)](https://xen-orchestra.com/blog/netbox-sync-with-xen-orchestra/) We considerably improved the synchronization, to manage many use cases that weren't covered by our previous code. ### Prerequisite You must add an UUID custom field for 3 objects in Netbox: "Virtualization > cluster", "Virtualization > virtual machine" and "Virtualization > interface". See this screenshot: ![](https://xen-orchestra.com/blog/content/images/2023/07/customfield.png) ### Improvements & fixes Here's a rundown of the most significant changes: 1. **Comments Integration**: VM descriptions now sync seamlessly into the 'Comments' field of the VM Netbox object. It's a small touch, but it makes a world of difference by adding context when you're browsing through your Netbox tab. 2. **Operating system information**: the distro name and number is also sent to Netbox! 3. **Migrating VMs**: We've enhanced the migration process. Now, rather than deleting and recreating a VM during migration, we update the existing VM object. This ensures that any manually added data remains intact. 4. **No More VM Duplication**: In the past, actions like replacing a pool in your setup (for instance, migrating all VMs, connecting/syncing the new pool, and disconnecting the old one) would result in VM duplication in Netbox. We've ironed out this issue to ensure a smoother experience. 5. **IP Prefix Handling**: We've corrected an inconsistency where IPs would sometimes bind to the largest IP prefix rather than the smallest. 6. **Synchronization Enhancements**: Disconnecting a pool from Xen Orchestra won't derail the synchronization process anymore. If a pool is unreachable, our plugin simply sidesteps it, ensuring the rest of the sync proceeds smoothly. 7. **Clearer Error Messages**: Troubleshooting has never been easier. We've fine-tuned error messages to display a sample of objects causing sync issues. This makes it easier to identify and rectify problems. 💡 This huge revamp of the Netbox sync plugin is also opening the door to more features and improvements in the future: synchronize VM tags, sync to multiple Netbox instances, with the VM DNS name, IP range exclusion, but also host synchronization, clickable link in XO directly, tag exclusion… You name it! ## ## 🔭 XO Lite There are new available features in this XO Lite release! ### Export VMs in CSV or JSON On the Dashboard view, in the VM list, you can now export all selected VMs information into a CSV or JSON file: ![](https://xen-orchestra.com/blog/content/images/2023/07/exportcsv.jpeg) ### Pop up console You can simply display a VM console in a new pop-up window! It's convenient, especially if you want to display multiple consoles at once. The icon is easily found on the VM console page: ![](https://xen-orchestra.com/blog/content/images/2023/07/popup.gif) Also, the VM console view is even better: 0:00 / 1× ### Tasks on the dashboard All XCP-ng tasks are now visible in the dashboard: ![](https://xen-orchestra.com/blog/content/images/2023/07/tasksdashboard.jpeg) ## 🛰️ New XOA Deploy We improved the way to deploy XOA via our website. It's now available at [https://vates.tech/deploy/](https://vates.tech/deploy/?ref=xen-orchestra.com) ![](https://xen-orchestra.com/blog/content/images/2023/07/deploy1.png) ![](https://xen-orchestra.com/blog/content/images/2023/07/deploy2-1.png) ![](https://xen-orchestra.com/blog/content/images/2023/07/deploy3-1.png) ![](https://xen-orchestra.com/blog/content/images/2023/07/deploy4-1.png) ## 📂 Faster file level restore Until now, we used the ZIP format to pack and compress all the files you wanted to restore in a VM backup. This format is very common, but suffer from being bad at streaming data. We detected the issue with users having thousand of files to ZIP, it took ages or consume all XOA's memory. So instead of ZIP, we aded tar+gzip (archive + compression), which is a LOT better to do this. Our first results are displaying that tar+gzip is at least 6 times faster than ZIP alone. Nice isn't it? ![](https://xen-orchestra.com/blog/content/images/2023/07/256553067-34e189f2-3a31-45dd-aad1-2f57fd93ee50.png) ### Xen Orchestra 5.84 URL: https://xen-orchestra.com/blog/xen-orchestra-5-84/ Last updated: 2023-07-03T08:46:27.000Z Hey there! ☀️ Check out the latest Xen Orchestra release. We've got some cool stuff like automatic XOA backups, a few neat tweaks to the REST API, and some solid progress on Project Pyrgos and XO Lite. We think you're gonna like what you see! Ah and also, while you are here, we are proud to introduce you our new partner program, just take a look here: [Empowering Partnerships: An Inside Look at Vates’ New Partner ProgramWe are rolling out our new Partner Program, aimed at strengthening collaborations and accelerating growth. Built on insights from our partners and users, this program features a tiered system where you can earn points through actions, revenue, and certifications.![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogMarc-André Pezin![](https://vates.tech/blog/content/images/2023/06/markus-spiske-vrbZVyX2k4I-unsplash.jpg)](https://vates.tech/blog/empowering-partnerships-an-inside-look-at-vates-new-partner-program/?ref=xen-orchestra.com) As usual, we've encapsulated the highlights of this fresh release in a video tour: as well as in podcast format: [Episode #5 - Xen Orchestra 5.84 - XOA Config Cloud Backup, REST API and more... by Inside the Virtual MachineExplore the new features in Xen Orchestra 5.84, including XOA Config Cloud Backup, REST API, Project Pyrgos, XO Lite and much more…![](https://d12xoj7p9moygp.cloudfront.net/favicon/favicon-s4p-310x310.png)Spotify for Podcasters![](https://d3t3ozftmdmh3i.cloudfront.net/production/podcast_uploaded_nologo400/37140275/37140275-1680268571887-f778701ae270e.jpg)](https://spotifyanchor-web.app.link/e/tpNAjl5n3Ab?ref=xen-orchestra.com) ## ☁️ XOA Config Cloud Backup In this release, we're excited to introduce our inaugural version of a new feature that promises significant enhancements in the future: automatic XOA configuration backups to your Vates/xen-orchestra.com account! In essence, this ensures that even if your XOA is lost - whether due to removal, destruction, or any other cause - you can effortlessly restore its configuration. This includes all user information, backup jobs, connected hosts, and more, without requiring any additional input. This convenience and resilience extend even if you don't have any metadata backups within your infrastructure. To activate the XO configuration backup, simply navigate to your Settings view from the left-hand menu, select "XO Config" and enable the "Automated backup XO configuration": ![](https://xen-orchestra.com/blog/content/images/2023/06/249171480-cce431fc-4660-4d20-afa3-4bab8e35ac65.png) 🔒 Obviously, before your XOA configuration is transmitted to our servers, it's subjected to robust encryption within your XOA. The data we store on our end remains entirely indecipherable without a decryption key that solely you possess locally. The decryption process occurs only when restoring your configuration on a new XOA, where you'll be prompted to enter your passphrase to decrypt and ultimately restore your data. ## 📡 REST API We're back with another round of REST API updates in this June release. Also, since we never had any issue with it, we can officially announce the REST API isn't an alpha feature anymore! ### XOA Update Just last month, we introduced the ability to update your hosts, even enabling Rolling Pool Updates directly from the REST API. The next natural progression? Triggering XOA updates straight from this very API! To engage the XOA updater and verify the availability of any new versions, use the following method: ```bash curl \ -b authenticationToken=KQxFkTbs \ 'https://xo.company.lan/rest/v0/appliance/updater' ``` This should returns `{ "isUpToDate": true }` when your XOA is up to date. You can imagine using this with your alerting system (eg UptimeKuma) to detect when your XOA is NOT fully up-to-date! To initiate the update itself, use this `POST` method: ```bash curl \ -X POST \ -b authenticationToken=KQxFkTbs \ 'https://xo.company.lan/rest/v0/appliance/updater/actions/upgrade?sync' ``` That's all there is to it! ## ☸️ Project Pyrgos (k8s) For those who might have missed our introduction to Project Pyrgos: [Announcing project PyrgosHave you ever wanted to easily create and update Kubernetes clusters on top of your on-prem infrastructure? That’s exactly what Pyrgos project is.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2023/02/pyrgos-1.jpg)](https://xen-orchestra.com/blog/announcing-project-pyrgos/) In this update, we've incorporated the functionality for you to select the Kubernetes version you'd like to deploy on your cluster: ![](https://xen-orchestra.com/blog/content/images/2023/06/pyrgosversion.png) This enhancement empowers you with greater control over your Kubernetes cluster assembly. Keep an eye out - we've got a wave of additional features set to roll out this summer! ## 🔭 XO Lite Our dedication to enhancing the embedded web UI in XCP-ng continues unabated. As a refresher, the groundwork we're laying here will also form the foundation for Xen Orchestra 6\. For those keen on the design elements surrounding it: [Unleashing the Power of Atomic Design SystemExploring the Atomic Design System in open-source virtual infrastructure: enhancing user experiences, inclusivity, and accessibility while empowering teams.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogClémence Barthoux![](https://xen-orchestra.com/blog/content/images/2023/05/Cover.png)](https://xen-orchestra.com/blog/unleashing-the-power-of-a-unique-atomic-design-system/) This June, our efforts focused on several areas: - We refined the code to eliminate any confusion regarding UUIDs and OpaqueRef. - We introduced a 'closing confirmation' component, enabling a prompt for user confirmation before tab closure in the event of any pending actions. - We revamped XAPI subscriptions (the "events"). Now, record extensions are much simpler, and we've added an `immediate` option which defers the subscription until the first `start()` call. - We overhauled the pool dashboard to align it more closely with our original Figma design. - We upgraded the entire XO Lite project to Vue 3.3 and Vite 4\. This translates to fresh features for developers and improved performance! We also implemented minor changes, such as displaying an error when data loading fails, introducing enums for various VM power states and operations, fixing several bugs, and adding new keyboard shortcuts! Although this effort plays out over the long haul, it's crucial for creating a consistent and appealing UI for both XO Lite and ultimately, XO 6\. You can anticipate more noticeable changes in the coming months. ## 🆕 Misc This section consolidates other enhancements made for this new XO release. ### Allow importing ISO from URL You can now directly paste the ISO URL into your SR ISO, which will handle the rest of the process and download it. There's no need to clutter your computer with a collection of various ISOs and then manually upload them via Xen Orchestra! ![](https://xen-orchestra.com/blog/content/images/2023/06/249767013-f740f82c-242b-4624-ac15-4a0a578c4cce.png) ### Raw VDI export/import Although this feature was available in the backend, it was never exposed in the UI. With this release, you have the option to import and/or export any disk (VDI) using the `raw` format. ### RRDs performance improvements We've significantly improved the RRDs statistics performance from our web UI by addressing requests that bypassed our cache and properly closing certain fetching requests. For infrastructures with more than 20 hosts, this performance boost should be particularly noticeable. ### Various dependencies improvements We made progress with some indirect dependencies (dependencies of a dependency) by internalizing them (directly incorporating them), which gave us the opportunity to patch or update them directly. This approach helped us reduce the number of outdated versions indirectly affected by various security reports. ### Xen Orchestra 5.83 URL: https://xen-orchestra.com/blog/xen-orchestra-5-83/ Last updated: 2023-06-05T14:51:23.000Z In this month's Xen Orchestra update, we spotlight enhancements to self-service capabilities and our interface, progress in XO Lite, and the introduction of the new 'Mirror Backup' feature. With advancements in REST API and ongoing development in Project Pyrgos, we continue to elevate your user experience. Dive in to discover these developments in detail! [![](https://xen-orchestra.com/blog/content/images/2023/06/spotify-logo-1.png)](https://podcasters.spotify.com/pod/show/vates7/episodes/Episode-4---Xen-Orchestra-5-83---Mirror-backup--self-services-improvements--backup-nomenclature-and-more-e258vad?%24web%5Fonly=true&%5Fbranch%5Fmatch%5Fid=1128676735795453372&utm%5Fsource=web&utm%5Fcampaign=web-share&utm%5Fmedium=sharing&%5Fbranch%5Freferrer=H4sIAAAAAAAAA8soKSkottLXLy7IL8lMq0zMS87IL9ItT03SSywo0MvJzMvWT9WPLI%2FMdUt2j8hzTAIATmgY%2FDAAAAA%3D) 🎵 Our release live sessions are now accessible in a [brand new format - podcast](https://podcasters.spotify.com/pod/show/vates7/episodes/Episode-4---Xen-Orchestra-5-83---Mirror-backup--self-services-improvements--backup-nomenclature-and-more-e258vad?%24web%5Fonly=true&%5Fbranch%5Fmatch%5Fid=1128676735795453372&utm%5Fsource=web&utm%5Fcampaign=web-share&utm%5Fmedium=sharing&%5Fbranch%5Freferrer=H4sIAAAAAAAAA8soKSkottLXLy7IL8lMq0zMS87IL9ItT03SSywo0MvJzMvWT9WPLI%2FMdUt2j8hzTAIATmgY%2FDAAAAA%3D)! You can now listen to our live sessions on Spotify, allowing you to catch up on our latest releases anytime, anywhere. So, whether you're on the go or prefer to listen to podcasts during your downtime, we've got you covered. Don't forget to follow us on Spotify to stay up-to-date with our latest releases and never miss an episode. ## 💾 Backup This release brings a wealth of new features to the backup side of things. Let's go! ### Backup nomenclature As announced, we started to rename/clarify all our backups: ![](https://xen-orchestra.com/blog/content/images/2023/05/Schema-new-wording-backup-2.png) It's now visible in XO UI for this latest release. As a reminder: - The first run of an *Incremental Backup* is called the 'key backup'. - All subsequent runs of an *Incremental Backup* are referred to as 'delta'. - 'Full backup' specifically refers to a backup made using the F*ull Backup* feature. For the Replication: - A job previously known as a 'Disaster Recovery' job is now termed F*ull Replication*. - The initial run of an *Incremental Replication* is called the 'key replication'. - All following runs of an *Incremental Replication* are known as 'delta'. ### Mirror backup We have introduced a feature allowing you to back up a Backup Repository (**BR**) directly! But let's first understand its necessity, given that you can already include multiple BRs in a single backup job. ☝️ **Backup repository** (or simple **BR**) is our newly coined term for what we previously referred to as "remote". It's the destination you choose for all your full and incremental backups! #### Multi BR job Within a single backup job, it was already possible to configure two distinct BRs simultaneously. Imagine executing backups on hosts from two separate datacenters, and sending all those backups to two distinct BRs (A and B). Here, the data is transmitted concurrently to different backup repositories, which is quite beneficial. ![](https://xen-orchestra.com/blog/content/images/2023/05/multi-target-backup-1.png) However, since the data is synchronously dispatched to both BRs, it's important to note that **the speed of the entire backup job will be dictated by the slower BR**. Another limitation is that this multi-BR backup job will utilize the **same schedule and retention** on both backup repositories, as they are perfectly synchronized. #### Introducing Mirror backup This is where mirror backup comes into play. You can now create a specific backup job for an existing BR, entirely asynchronously. Essentially, mirror backup allows you to independently synchronize all your "direct" backups to another BR, but with your personal schedule and retention. There are numerous use cases: you might carry out all your nightly backups to a local BR (same datacenter) with a broad bandwidth, and then create a mirror to a remote site with a smaller bandwidth, but with an entirely different schedule and retention. The mirrored BR could utilize slower hardware (like spinning disks with more capacity) -while your original BR is fast for your daily backups- providing an ideal "archive" scenario for longer retention! Here is a diagram: ![](https://xen-orchestra.com/blog/content/images/2023/05/mirror-backup-1.png) **This implies the possibility to manage a completely different location, schedule, retention, encryption, and type of backup repository, based on an existing BR!** To use mirror backup, navigate to "Backup"/"New"/"Mirror Backup". You can then configure the Backup Repository ("BR", formerly "remote") to backup to another BR: ![](https://xen-orchestra.com/blog/content/images/2023/05/image-8-.png) #### Planned improvements We're planning to refine and broaden this feature further. Initially, we're focusing on the technical aspects. For instance, by creating a synthetic VHD, we can reduce the quantity of files to be transferred. The second improvement we're planning is related to filter capabilities: you'll be able to mirror only under specific conditions (like mirroring only VMs with the "Archive" tag). This dynamic approach will contribute to providing a high level of protection and automation. ☝️ **As a final advantage**, our new Mirror Backup feature is fully compatible with our Backup Health Check functions! There's no need to worry when archiving your backups, as you can automatically verify their correctness and functioning! ## 🛍️ Self service The current release brings substantial upgrades to our self-service capabilities. ### Tag selector The new release allows for a default tag configuration in self-service, increasing efficiency especially when linking these self-service created VMs to a designated backup job. An illustration of this would be establishing a self-service titled `customer1` that carries a default `customer1` tag on creation. Consequently, a "smart backup job" will initiate automatic backups for ALL VMs associated with this tag, completely eliminating any need for manual intervention. ![](https://xen-orchestra.com/blog/content/images/2023/05/235933265-8dd0ad77-f3c1-4f6f-8bd3-8f3f3807cb96.png) ### Default sharing of newly created VMs Previously, a VM created within a self-service platform was exclusively visible to its creator. With our latest release, we provide the option to automatically share all VMs among every user in a particular self-service. This feature proves particularly useful when looking to instantly share VMs within a user group such as developers or customers. ![](https://xen-orchestra.com/blog/content/images/2023/05/238966079-b6f74412-5514-42c9-9f32-c4b1e05e1c9a.png) ## 📡 REST API This new REST API release is all about updates. Our goal was to equip you with everything necessary to monitor updates and even enable a degree of automation to keep your infrastructure fully updated! ### Check updates Checking for all available updates on an entire pool is now a breeze with this simple HTTP call. We also made the effort to make the new endpoint discoverable! For example, if you just request a pool object with a regular: ```bash curl \ -b authenticationToken=KQxFkTbs \ 'https://xo.company.lan/rest/v0/pools/' ``` You'll have this new entry, see the `missing_patches_href`: ```json { "current_operations": {}, "default_SR": "86a9757d-9c05-9fe0-e79a-8243cb1f37f3", "HA_enabled": false, "haSrs": [ "86a9757d-9c05-9fe0-e79a-8243cb1f37f3" ], "master": "0aea61f4-c9d1-4060-94e8-4eb2024d082c", "tags": [], "name_description": "", "name_label": "XO Lab", [...] "cpus": { "cores": 120, "sockets": 6 }, "missing_patches_href": "/rest/v0/pools//missing_patches" } ``` So if you request this URL: ``` curl \ -b authenticationToken=KQxFkTbs \ 'https://xo.company.lan/rest/v0/pools//missing_patches' ``` Then, you'll have the available updates list, in a proper JSON array: ```json [ { "url": "https://github.com/tianocore/edk2", "version": "20180522git4b8552d", "name": "edk2", "license": "BSD and MIT", "changelog": { "date": 1665144000, "description": "- Correct the usage of memory barriers to fix an occasional hang", "author": "Andrew Cooper - 20180522git4b8552d-1.4.6" }, "release": "1.4.6.xcpng8.2", "size": 2382792, "description": "EFI Development Kit II" }, { "url": "https://github.com/xcp-ng/xe-guest-utilities", "version": "8.2.0", "name": "xcp-ng-pv-tools", "license": "BSD and GPLv2", "changelog": { "date": 1662984000, "description": "- Switch RPMs to systemd by default and provide legacy RPMs for chkconfig.\n- Merge separate -xenstore RPMs back into xe-guest-utilities RPMs", "author": "Gael Duperrey - 8.2.0-11" }, "release": "11.xcpng8.2", "size": 15129256, "description": "ISO with the Linux PV Tools" } ] ``` ### Rolling Pool Updates Now, you can even trigger the convenient Rolling Pool Updates mechanism directly with a simple HTTP call. It couldn't be easier: ``` curl \ -X POST \ -b authenticationToken=KQxFkTbs \ 'https://xo.company.lan/rest/v0/pools//actions/rolling_update' ``` This paves the way for some truly interesting capabilities. Consider setting up a CRON job (or a Systemd service) to automatically fire this call to the REST API, every Saturday night, for instance. This ensures that your cluster is always up to date! ## ☸️ Project Pyrgos (k8s) For those who might have overlooked our initial announcement, here's a recap on Project Pyrgos: [Announcing project PyrgosHave you ever wanted to easily create and update Kubernetes clusters on top of your on-prem infrastructure? That’s exactly what Pyrgos project is.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2023/02/pyrgos-1.jpg)](https://xen-orchestra.com/blog/announcing-project-pyrgos/) It's now possible to create Kubernetes clusters with multiple control-planes, improving the resiliency of your cluster: ![](https://xen-orchestra.com/blog/content/images/2023/05/236158209-a21e07e7-effe-4e07-9171-d0ffc4afe7af.png) With a solid foundational cluster in place, the next stages of development are set to bring more enhancements. **Keep an eye out for our forthcoming release!** ## 🔭 XO Lite In the previous month, we mentioned the intensive work on multiple components without immediate visible progress. This behind-the-scenes work is crucial in crafting superior user experience (UX) and user interface (UI) – **there are simply no shortcuts!** This month, we are thrilled to present tangible outcomes of our efforts! For an in-depth understanding of our approach towards UX and UI, do not miss this insightful article by Clemence, our accomplished UX/UI designer. It provides a sneak peek into the upcoming interface for both XO Lite and XO 6: [Unleashing the Power of Atomic Design SystemExploring the Atomic Design System in open-source virtual infrastructure: enhancing user experiences, inclusivity, and accessibility while empowering teams.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogClémence Barthoux![](https://xen-orchestra.com/blog/content/images/2023/05/Cover.png)](https://xen-orchestra.com/blog/unleashing-the-power-of-a-unique-atomic-design-system/) ### Better consoles Now, all our consoles are a lot better to use! First, the space usage of the console is really fitting the screen regardless the size: 0:00 / 1× The big bonus is that now you have a button to **detach the console** in a dedicated window: ![](https://xen-orchestra.com/blog/content/images/2023/05/241870481-a68bb680-f75a-46c0-9135-79a0d4a112f1.gif) ### Other improvements And there's also many other improvements, like: - Better tool-tips components - Tabs added for the VM view - Better modals (easier to read and can be closed with escape key) - New form component - Better spinner - More actions available in bulk (copy, remove, power state) - Dynamic page titles An example of copying a VM: ![](https://xen-orchestra.com/blog/content/images/2023/05/239463872-f1293e74-2c48-42b6-8b78-7869bf5fdc04.gif) And in bonus, here is a nice preview of the next XO 6 Dashboard: ![](https://xen-orchestra.com/blog/content/images/size/w1600/2023/05/Desktop---Pool-dashboard---Default.png) ## 🆕 Misc While the new additions to backup, XO Lite, REST API, and Pyrgos are substantial, we haven't overlooked the need for quality-of-life enhancements for the existing interface. ### Introducing XO Tasks in UI We've taken the first step to incorporate our bespoke tasks, known as "XO tasks". As you might be aware, we've been displaying pool tasks in the "Task" view. However, as Xen Orchestra extends its orchestration features and performs increasingly complex asynchronous tasks, sometimes spanning different clusters, we've found the need to create dedicated XO tasks. This is a critical part of our major architectural revamp for XO 6. ![](https://xen-orchestra.com/blog/content/images/2023/05/240912588-e1386b1f-0a9d-4ce5-813d-078bf946552e.png) The first application of this will be our V2V import system, enabling a seamless transition of VMware to Vates (the XCP-ng+XO stack). **Over time, this will prove invaluable for other use cases such as backups, Rolling Pool Updates, and more, enabling easy tracking of overall progress.** ### Oracle VM OVA import While VMware and HyperV users are our most common converts to XCP-ng, Oracle VM is also being phased out from an inscreasing number of our new customers. **This marks a notable shift in the virtualization market!** Oh and by the way, don't forget our recent article on how Vates with XCP-ng and Xen Orchestra is making an meaningful impact in this revived market: [Vates’ Continued Recognition in Gartner’s Server Virtualization GuideWe’re thrilled to announce, just as we did last year, that Vates has once again been recognized in the Gartner Market Guide for Server Virtualization.![](https://vates.tech/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogMarc-André Pezin![](https://vates.tech/blog/content/images/2023/05/reign-abarintos--cKXtsJWU-I-unsplash.jpg)](https://vates.tech/blog/p/3353eab2-010d-43bd-9e9c-9f0c666eb938/?ref=xen-orchestra.com) Back to the topic: The OVA import from Oracle VM had some peculiarities, including a discrepancy in size between metadata and actual data (disks). I don't think it was meant on purpose, but anyway, we had to adapt our import code to make it work with their OVAs. Now it works well, so if you're looking to migrate from Oracle VM, you're more than welcome! ### Plugin Filter by Name A minor but convenient improvement: with an ever-growing list of plugins, we've enabled a simple filter to focus on a specific plugin. All it takes is a click on the plugin name. ### Editable Proxy Address Yet another life improvement: for users who make network modifications after setting up several proxies, we've made the proxy IP address editable directly from XO. This will inform the proxy appliance to use the new address! ### Warning on hosts lacking HVM Now, if you have a host that doesn't support HVM mode (hardware assisted virtualization), you'll see a warning in the host view. It's an important heads-up, as there's little reason to not have an HVM-capable host today: ![](https://xen-orchestra.com/blog/content/images/2023/05/238376884-f33a8e47-7f68-4150-b606-c3952822e135.png) If you really know what you are doing, you can simple ignore this message. ### Unleashing the Power of a Unique Atomic Design System URL: https://xen-orchestra.com/blog/unleashing-the-power-of-a-unique-atomic-design-system/ Last updated: 2023-05-25T14:08:39.000Z In the realm of virtualized infrastructure management, design of interfaces plays a vital role in empowering users and organizations to efficiently handle their datacenters. However, developing them so they are both functional and aesthetically pleasing can be a challenging task. Our goal is to ensure a seamless experience for you, where we can introduce new features on a regular basis while maintaining coherence in your usage. We understand the importance of enabling you to unlock the full potential of the solution without requiring constant tutorials. Additionally, we prioritize effortless transitions between XO Lite and XO 6, minimizing the time and resources needed to relearn the system. This blogpost is part of a series about the component design and UI/UX of XO Lite and XO 6, you can learn more in the following blog posts: [UX/UI Design for XO and XOLiteWith the launch of XOLite and the redesign of Xen Orchestra itself, UX/UI Design is getting a revisit in the XO world.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogClémence Barthoux![](https://xen-orchestra.com/blog/content/images/2022/06/XO-Blog---UX-UI-Design-for-XO-and-XOLite.jpg)](https://xen-orchestra.com/blog/ux-ui-design-for-xo-and-xolite/) [XO Lite componentsExplore the inner workings of XO Lite’s component-based design and how it enhances user experience in virtualization management through our in-depth blog post.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogThierry Goettelmann![](https://xen-orchestra.com/blog/content/images/2023/03/xolitedevblog-1.jpg)](https://xen-orchestra.com/blog/xo-lite-components/) **That's where creating a unique Design System for both software comes into play.** In this blog post, we will delve into the concept of design systems, explain why we chose the Atomic Design System approach, and explore why it is crucial to adopt a common system for both XO Lite and XO 6\. Furthermore, we will discuss the impact on inclusivity and accessibility, and how it contributes to the success of involved teams. ☝️ We started to work on the design of XO 6 while continuing to improve XO Lite. You’ll see some sneak pics of our first drafts here. There is much to do for the design and development teams before any release date can be communicated so we thank you in advance for your patience! ## Understanding Design Systems Design systems serve as a holistic approach to creating cohesive user interfaces (UI) and exceptional user experiences (UX). They encompass a collection of reusable components, guidelines, and principles that streamline the design and development processes. Design systems ensure consistency, efficiency, and scalability, enabling teams to maintain a unified visual language and user interface across multiple platforms or applications. For XO 6 and XO Lite, we define 3 main design principles: ### ****Open-source** Designing from open-source materials only. ### **Accessibility & Inclusivity** Designing for the needs of people with permanent, temporary, situational, or changing disabilities, and acknowledging diversity and difference: - Consider situation - Be consistent - Give control - Offer choice - Prioritize content ### Dev-friendly Designing with developers' needs in mind: - Scale for responsiveness - Choose relative over absolute - Choose easy-to-code over fancy-look - Be consistent ## Unveiling the Atomic Design System The Atomic Design System, coined by Brad Frost in 2013, is an approach that breaks down the design process into five distinct levels: atoms, molecules, organisms, templates, and pages. Atoms represent the smallest building blocks, such as colors, typo,s or shadows, while molecules combine atoms to form small components like a button or an input. Organisms assemble molecules to create complex components like a card or a navigation block. Templates establish the overall layout and structure. Finally, pages bring it all together to showcase the complete user interface. ![Atomic Design System.png](https://xen-orchestra.com/blog/content/images/2023/05/Atomic-Design-System.png) By adopting a unique Atomic Design System for both interfaces, we can ensure that the design language, component hierarchy, and user interaction patterns remain consistent across the applications, allowing you to seamlessly transition between the two, reducing cognitive load and improving your overall experience. With that in mind, we decided to create a common Design System base for XO 6 and XO Lite for the two first layers of the Atomic Design System: atoms, and molecules. Always in Light and Dark mode, the two share the same components for many elements: colors, typography, shadows, corners, spacing, icons, buttons, inputs, info messages, tags, counters, tables cells and tables menus, and menu elements. This library of components will grow as both software grow. ![Colors - Light.png](https://xen-orchestra.com/blog/content/images/2023/05/Colors.png) ![Buttons.png](https://xen-orchestra.com/blog/content/images/2023/05/Buttons.png) ![Buttons guidelines.png](https://xen-orchestra.com/blog/content/images/2023/05/Buttons-guidelines.png) But starting the organism's level in the Atomic Design System, and then templates and pages, they split, so the features are richer in XO6 but it still feels like home. The tree view is a fair example of an organism: ![XOLite - Treeview.png](https://xen-orchestra.com/blog/content/images/2023/05/Treeviews.png) ## Inclusivity and Accessibility Reading Open-source software aims to be accessible to all individuals, regardless of their abilities or disabilities. By prioritizing inclusivity and accessibility **in the design**, the whole team can ensure that everyone can effectively utilize the software. Incorporating features such as keyboard navigation, proper color contrast, and screen reader compatibility allows individuals with visual impairments or motor disabilities to interact with the software effortlessly. Such considerations are easier to make at the design stage and make the interfaces more inclusive, providing equal opportunities for all users. That is not a small thing to reach! ## Empowering Team Success Finally, the Atomic Design System approach positively impacts the success of the collaboration between developers and designers. It provides a shared language and a set of predefined design elements, enabling us to collaborate seamlessly. By utilizing a consistent system, all teams can save time on design decisions, streamline the development process, and improve the maintainability of the code-base. Moreover, the system serves as a foundation for documentation, ensuring that knowledge is easily transferable, reducing on-boarding time for new team members or external contributors, and enabling the team to focus on innovation and problem-solving. ![XOA - Pool dashboard.png](https://xen-orchestra.com/blog/content/images/2023/05/XOA---Pool-dashboard.png) ![](https://xen-orchestra.com/blog/content/images/2023/05/Desktop---Pool-dashboard---Default.png) ## Conclusion In the realm of open-source virtualized infrastructure management, a Design System proves to be a game-changer. It enhances coherence, improves the user experience, promotes inclusivity and accessibility, and empowers the success of involved teams. By adopting a common system for both XO 6 and XO Lite, we hope to unleash the full potential of open-source virtualized infrastructure. In line with Vates' enduring commitment to open-source principles, we are actively considering ways to share our solutions' design system with our community. We are evaluating several potential approaches at present. If you're interested in contributing to this dialogue, we welcome your input on our forum! [XCP-ngXCP-ng community forum![](https://xcp-ng.org/forum/assets/images/touch/512.png)XCP-ng![](https://xcp-ng.org/forum/assets/uploads/system/site-logo.png)](https://xcp-ng.org/forum/?ref=xen-orchestra.com) ### Xen Orchestra 5.82 URL: https://xen-orchestra.com/blog/xen-orchestra-5-82/ Last updated: 2023-04-28T17:31:49.000Z We're super excited to bring you the latest and greatest Xen Orchestra release - version 5.82\. Trust us, we were just as surprised as you when we realized this "little" update turned out to be jam-packed with awesome new features. So buckle up, and let's dive in to explore the fabulous world of Xen Orchestra 5.82! 🎵 Our release live sessions are now accessible in a [brand new format - podcast](https://spotifyanchor-web.app.link/e/DWKdjbbRmzb?ref=xen-orchestra.com)! You can now listen to our live sessions on Spotify, allowing you to catch up on our latest releases anytime, anywhere. So, whether you're on the go or prefer to listen to podcasts during your downtime, we've got you covered. Don't forget to follow us on Spotify to stay up-to-date with our latest releases and never miss an episode. ## 💾 Backup Get ready, because this release is all about leveling up your backup game! We've made significant improvements and introduced some essential naming changes that'll pave the way for even more awesome updates in the future. Let's take a closer look at what's new in the world of Xen Orchestra backups. ### Advanced backup restore check Remember when we introduced VM restore health checks [a year ago](https://xen-orchestra.com/blog/xen-orchestra-5-70/#%E2%9A%95%EF%B8%8F-restore-healthcheck)? It was a game-changer, and we took it a step further with the "Auto restore check" just a [month later](https://xen-orchestra.com/blog/xen-orchestra-5-71/#%E2%9A%95%EF%B8%8F-auto-restore-check). Well, fasten your seatbelts, because we're going even deeper now with the "Advanced backup restore check" (a.k.a. "Application aware restore check"). Let's break it down. During the usual backup restore check, the "restored" VM is booted on the SR of your choice. In the past, we'd only wait for the guest tools to be available, which indicated that the OS had booted successfully. Now, we're also waiting for a custom script to run inside your VM, allowing you to test your local app or service and report whether everything is A-OK (or not). Magic happens via the XenStore, meaning Xen Orchestra can be aware of the result of your check. 💡 **Quick XenStore refresher*:* XenStore is a handy key/value database that lets you exchange values between a VM and the Dom0 (and, by extension, its API). It's how we fetch IPs and other info like the current Operating System and memory usage from inside the VMs. To set this up, you'll need to do the following: 1. Add a tag `xo-backup-health-check-xenstore` on the VM. 2. Make sure the VM is part of a job with health check enabled. 3. Ensure the script starts automatically on VM boot. Keep in mind, there won't be any network access during the check. We perform it offline to avoid interfering with your production VM. #### Example: testing a SQLite Database To give you an idea of how to create your own checks, let's walk through an example script. In this Bash script, we'll test whether a SQLite database is present and working properly: ```bash #!/bin/sh # must be executed as root to be able to use xenstore-read and xenstore-write # fail in case of error or undefined variable set -eu # stop there if a health check is not in progress if [ "$(xenstore-read vm-data/xo-backup-health-check 2>&1)" != planned ] then exit fi # not necessary, but informs XO that this script has started which helps diagnose issues xenstore-write vm-data/xo-backup-health-check running # put your test here # # in this example, the command `sqlite3` is used to validate the health of a database # and its output is captured and passed to XO via the XenStore in case of error if output=$(sqlite3 ~/my-database.sqlite3 .table 2>&1) then # inform XO everything is ok xenstore-write vm-data/xo-backup-health-check success else # inform XO there is an issue xenstore-write vm-data/xo-backup-health-check failure # more info about the issue can be written to `vm-data/health-check-error` # # it will be shown in XO xenstore-write vm-data/xo-backup-health-check-error "$output" fi ``` It's pretty straightforward, but let's do a quick analysis of this example: 1. `if [ "$(xenstore-read vm-data/xo-backup-health-check 2>&1)" != planned ]` means this check won't be done on a regular boot, **ONLY** when used in the backup restore health check process. That's why you can confidently have this script on boot. 2. `if output=$(sqlite3 ~/my-database.sqlite3 .table 2>&1)` means we'll list the tables in a SQLite database. If the DB is fine, the command will return 0 (success) then we'll write that in the XenStore with `xenstore-write vm-data/xo-backup-health-check success` 3. And if it's a failure, then: `xenstore-write vm-data/xo-backup-health-check failure`. We can even provide the detailed error via `xenstore-write vm-data/xo-backup-health-check-error "$output"` so your backup job will report it! Definitely, any other language can do the same thing, as long as you are able to write into the XenStore using the right keys. ### Introducing block retry for NBD backup We've got another great addition for you in this release: the implementation of block retry for NBD backups. If you're using NBD-enabled backups, you already know they're fast and light on Dom0 resources. But now, they're even more robust! The beauty of NBD is that, unlike the VHD handler for exporting VM disks, it allows us to retry fetching blocks without losing the entire transfer. Currently, our retry capability is hard-coded to retry 5 times, but we'll make it configurable in the future. So why is block retry such a big deal? With thousands of XO users worldwide performing backups every day, there's always a chance that something could go wrong with the infrastructure – a faulty switch, cable, network interface, internet link, or even a memory issue on the Dom0\. With block retry, backups can now handle transfer or network issues, and keep everything running smoothly in a fully transparent fashion! Get ready to experience an even more reliable and resilient backup process. ### Changes to come in backup naming We're always looking to improve and refine Xen Orchestra, and that includes making things clearer for our users. Over time, we've added features one after another, sometimes without fully anticipating what might come next. This has led to some confusion in our backup naming conventions, so we're making a few changes to set things straight. Here's a short recap: ![](https://xen-orchestra.com/blog/content/images/2023/04/Schema-new-wording-backup-2.png) Previously, the term "full" could refer to either a full backup (XVA format) or the initial run of our former "delta" backup. And "delta" was another run of our Delta Backup – talk about confusing! 🙃 To clear things up, we're introducing the following naming changes: - The first run of an Incremental Backup will be called the *base*. - Subsequent runs of an Incremental Backup will be called *delta* (as before). - A *full backup* will only refer to a backup from the full backup feature. For replication, we'll use similar naming conventions: - A Disaster Recovery job will be called *full replication*. - The first run of an incremental replication will be called the *base*. - Subsequent runs of an incremental replication will be called *delta*. These changes should make it easier to understand and discuss Xen Orchestra backups and replications, setting the stage for even more exciting features in future releases. Enjoy the newfound clarity! ## ❄️ Smart host reboot Or also known as "Reboot your host without losing VM memory". For those using a pool with shared storage, rebooting a host is a breeze; VMs are migrated to other nodes seamlessly. This is also true for our [Rolling Pool Upgrade](https://xen-orchestra.com/docs/manage%5Finfrastructure.html?ref=xen-orchestra.com#rolling-pool-updates-rpu) mechanism. But what if you don't have shared storage or only have a single host? How can you reboot without losing VM memory or having to reboot the VMs themselves? We've got you covered with our new Smart Host Reboot feature! The solution is to freeze your VMs (using suspend to RAM) during the host reboot and resume them once the host is back. With our new dedicated button, you no longer have to go through the cumbersome manual process: ![](https://xen-orchestra.com/blog/content/images/2023/04/smartreboot.png) But wait, there's more! If you only have one host, your Xen Orchestra VM is likely running locally. If we suspend it, the Smart Host Reboot process would be interrupted. Fear not! We've managed to detect if a VM is Xen Orchestra and exclude it from the process. While the XOA VM will reboot, its `autopower_on` setting allows it to start back up, detect the previously suspended VMs, and resume them. Now, you can reboot a single host without any shared storage (e.g., for security updates) without causing a VM reboot from the VM OS perspective. There's no excuse to avoid applying updates anymore! ## ☸️ Project Pyrgos (k8s) If you missed the original announcement about what is Project Pyrgos, you can catch up here: [Announcing project PyrgosHave you ever wanted to easily create and update Kubernetes clusters on top of your on-prem infrastructure? That’s exactly what Pyrgos project is.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2023/02/pyrgos-1.jpg)](https://xen-orchestra.com/blog/announcing-project-pyrgos/) ### Ability to create multiple control plane You can now create multiple control plane, to remove a previous SPOF. It's a good way to play with Kubernetes and kill some control plane VMs and observe the result. In any case, now you can make your cluster resilient from one click. ![](https://xen-orchestra.com/blog/content/images/2023/04/k8sexample.webp) An example of a highly available k8 cluster. ### Naming modification We also updated some wording to match the current Kubernetes official naming convention, like "Control plane" instead of "Master Node". It seems rather a small change, but it's important to keep up on how things are called! ## 🔭 XO Lite We're not just focused on rolling out a ton of Xen Orchestra features every month – we're also committed to improving XO Lite! While the latest enhancements are more behind-the-scenes, they're still significant and contribute to an even better user experience. ### Object subscriptions Previously, when you loaded XO Lite, you had to wait for all XAPI objects to load before the page was displayed, much like how regular Xen Orchestra works. This approach was inefficient, slow, and resource-consuming. That's where object subscriptions come in to save the day! With object subscriptions, each displayed component individually subscribes to the data it requires. For example, if a table component lists VMs, it will "ask" to load only the VM objects and nothing else. If another component on the same page requires the same objects, they will share the collection. When you navigate to another page (e.g., Host) that doesn't need the VM collection, it will no longer be used. This new approach is highly efficient and fast, offering a much-improved user experience in XO Lite. ### New components incoming We've got even more in store for you! Next month, we'll be unveiling a host of new components and features for XO Lite, adding even more value to your experience. Keep an eye out for these upcoming enhancements, and stay tuned for more updates as we continue to improve and expand XO Lite's capabilities. Get ready for some exciting times ahead! ![](https://xen-orchestra.com/blog/content/images/2023/04/xolitebadge.png) ## 📡 REST API We're excited to announce that our REST API is now more stable and has officially exited its alpha status! We're thrilled with its performance and simplicity, and we're confident you'll appreciate it too. ### Technical improvements Our REST API is now capable of streaming objects, which means less memory usage for large collections. Additionally, we start streaming objects as soon as possible, rather than waiting for all objects to load. This enhancement provides a more efficient and faster experience. ### Quick tips As the REST API continues to gain traction, we'd like to share some tips and tricks to help you unlock its full potential. #### Browsing the REST API If you've already accessed the XO web UI previously, you already have a token. This means you can easily browse the REST API directly from your current browser and explore the available data. This convenient access allows you to better understand the API's capabilities and how to use it effectively. ![](https://xen-orchestra.com/blog/content/images/2023/04/restSR.png) Checking a SR via the REST URL, directly in your browser ![](https://xen-orchestra.com/blog/content/images/2023/04/resthost.png) You can also browse all your objects (hosts here) #### An example script to list VMs without any backup What about creating a simple script to list all the VMs that are not in any backup job? Here is an example in Javascript (but any programming language will do it): [https://gist.github.com/olivierlambert/a7d4a0add61c96d837db81970bc7212f](https://gist.github.com/olivierlambert/a7d4a0add61c96d837db81970bc7212f?ref=xen-orchestra.com) This will return a CSV output that you can use for any inventory work you have to do, example: ```bash # node restapi.mjs "VM-NAME";"VM-UUID"; "HOST/CLUSTER";"Tags" "Test Debian 11";"29d19fd6-6337-2f5c-1dd8-789e2463271d";"c1d386df-990a-a892-ca89-267e7b3b5afd/c1d386df-990a-a892-ca89-267e7b3b5afd";"Prod" "dml-netperf-zen4-1";"b85e7d22-c63d-3fcf-3f3c-5f22e599d2c8";"6362271f-abdc-40ac-a59b-a447c2570ed1/c1d386df-990a-a892-ca89-267e7b3b5afd";"Test" ``` It's just a simple example how requesting the REST API can be used. Obviously, there's many many other ways to use it! We created a dedicated thread in our forum so we can all share our scripts: [XO REST API: share your tips and scripts!As our REST API is going better and better, we wanted to centralize the community efforts on building scripts and solutions on top of it Our first example on our side, is to help returning a CSV with all VMs without any backup job: https://gist.github.co…![](https://xcp-ng.org/forum/assets/images/touch/512.png)XCP-ngolivierlambert![](https://xcp-ng.org/forum/assets/uploads/profile/1-profileavatar-1620659303584.jpeg)](https://xcp-ng.org/forum/topic/7253/xo-rest-api-share-your-tips-and-scripts?ref=xen-orchestra.com) ## 🆕 Misc In addition to the main announcements, we're also introducing several quality of life features and enhancements. ### Eject the CD on template conversion When converting a VM, it's possible you might forget to remove the inserted ISO, which can cause issues when using the template later. To avoid this problem, the ISO is now automatically ejected before the template conversion. Thank you, [Cécile](https://github.com/vatesfr/xen-orchestra/issues/6752?ref=xen-orchestra.com), for the idea/report! 👍 ### Identify VM creator and template As an admin, you can now easily see which user created a VM and from which template, directly in the VM overview. ### Compatibility with older XenServer Eight years ago, Citrix announced XenServer 6.5, which brought many improvements, including a new XAPI transport capability: JSON-RPC instead of XML-RPC. This change significantly improved Xen Orchestra's performance, thanks to JSON being faster to parse than XML. Citrix also added a mixed mode called "JSON in XML-RPC." [Improving Xen Orchestra performancesXen Orchestra is now going 250 times faster. Period.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2022/10/Vates_Fond-nuages-sans-planete.png)](https://xen-orchestra.com/blog/improving-xen-orchestra-performances/) In Xen Orchestra, we built an "auto" transport capability that adapts to the XAPI's response. We always started with JSON-RPC (the best protocol) and downgraded to JSON inside XML-RPC or XML-RPC if there were errors. However, we decided to create a more precise fallback mode this year. Even though JSON-RPC works for most operations, there are some subtle bugs in XAPI's transport implementation. These issues are mainly related to improper integer and float number casting. We've seen these bugs up to XenServer 7.1 (which is EoL since). Since we know some users still run older XenServer versions, we added a specific option to force the transport to XML-RPC for any XenServer versions earlier than 7.1: ``` [xapiOptions] transport = 'xml-rpc' ``` 🎭 **Are you still running on an old XenServer version?** You should really do something, because you are in a big security risk right now. [Please contact us](https://vates.tech/contact/?ref=xen-orchestra.com), the migration assistance is part of our XCP-ng support service! ### XO config compression When you backup or export your XO configuration, it's now compressed by default. It's a rather minor feature in terms of size impact, but in ratio it's 50% saved at least. Not bad! This also open the door to a future exciting feature. But shhh! 🤫 You will discover it next month. ### Display free space on your SRs In the Dashboard/Health view, we added a row showing the free space available on your Storage Repositories: ![](https://xen-orchestra.com/blog/content/images/2023/04/230618510-07151222-076a-46e6-9965-aa10f95cd7c2.png) ### Xen Orchestra 5.81 URL: https://xen-orchestra.com/blog/xen-orchestra-5-81/ Last updated: 2023-04-02T17:13:55.000Z We're excited to present our latest 5.81 monthly release, packed with a multitude of improvements and new features. While our team has been hard at work refining "under the hood" aspects of the platform, we've still managed to deliver a substantial update that enhances your overall experience. This release showcases our commitment to continuous development and innovation, and we're thrilled to share these updates with you. So, without further ado, let's dive into the enhancements and additions you'll find in Xen Orchestra 5.81! ## 🐦 VMware migration tool (V2V) Over the past three months, we have been diligently enhancing our V2V tool to simplify the migration process from VMware to XCP-ng. With this release, our VMware-to-Vates V2V tool has become even more efficient and user-friendly! ### Multi VM import We are excited to introduce the ability to import multiple VMs simultaneously (either in parallel or sequentially) using our V2V web interface. You'll have access to a list of each VM to transfer, including its name, description, and settings. In other words, you can initiate a large batch transfer and then sit back and enjoy your coffee! This feature is **fully compatible with our unique warm migration system**, minimizing downtime to just a few minutes per VM. ![](https://xen-orchestra.com/blog/content/images/2023/03/224075249-17268999-5759-4c19-abeb-7ee4964f9fd9.png) ☝️ We also provided various options to help you on the automation side of things: you can stop if there's one error for one VM, or decide to only report errors in the end. Finally, you can also decide how many VMs in parallel you want to import! ### Better error handling We have now a better error message when importing a VM is failing. We covered 2 extra cases: - if the `*.vmx` file missing on the VMware side - if we don't support warm migration because of the VMware version (6.5+), giving you also the solution to do a normal conversion (consolidate and having the VM halted) ## 💾 Improved backup This release brings a multitude of enhancements to XO backups. We've introduced the ability to set a transfer speed limit, making the platform more aligned with your infrastructure requirements. Additionally, we've expanded the use of NBD to accelerate backups, irrespective of whether a "block-based" system is being utilized or not. Overall, these improvements significantly boost the performance, flexibility and reliability of our platform. ### Backup Transfer Rate Control When configuring your backup job, you now have the option to set a speed limit for the entire process. XO will enforce the maximum speed you specify, irrespective of the number of hosts, disks, and VMs involved. If no speed limit is provided, the platform will continue to operate as before, with no restrictions on the transfer speed. ![](https://xen-orchestra.com/blog/content/images/2023/03/Capture-d--cran-de-2023-03-29-14-40-01.png) ☝️ The speed limit is applied to the data transferred to Xen Orchestra, rather than when it's pushed to your backup repository. For instance, if you set a maximum speed of 10 MiB/s for your job, the "input" traffic for that job will never exceed this limit. However, if you have three backup repositories for the same job, the data might be sent at a combined rate of up to 3x 10 MiB/s! ### Faster backups In our quest of faster backups, we started, few months ago, to enable NBD-capable backups. You can read more about our initial work in this blog post: [Xen Orchestra 5.76Xen Orchestra 5.76 has landed. Discover what’s new!![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2022/10/xooctober.jpg)](https://xen-orchestra.com/blog/xen-orchestra-5-76#%F0%9F%9A%85-faster-backups-preview) We managed to add NBD "lower" in the stack, meaning that any disk export, regardless its origin (VHD, VMDK, OVA, Continuous Replication), will be exported via NBD if it's possible. Also, it works now even if you rely on existing VHD file storage, not only for "Block mode". In other words: faster backups for everyone! There's only one downside: right now, the export task doesn't work for VBD, so it will be up to Xen Orchestra to compute the progress and "feed" XAPI with the progress. This will come in a next release! You can see if your backup is using NBD for the transfer inside the backup log: ![](https://xen-orchestra.com/blog/content/images/2023/03/image-6--1.png) To enable this option, you need to edit your `config.toml` file, in the following way: ``` [xapiOptions] preferNbd = true ``` And then restart `xo-server`. ### More checks on the VHD stream We have enhanced XO's backup feature by introducing a more efficient method for identifying the root cause of incomplete backups. Although we previously detected these issues, our latest update provides a more comprehensive approach to troubleshooting. Now, we cross-check the anticipated size of a VHD file with the actual size read from the XAPI and the size written on the remote. This enables us to determine whether any errors occurred during the transfer process, either when pulling data from the host or pushing it to a remote location. Additionally, our new feature offers more precise error reporting, as it identifies the specific size transferred before a failure. This allows us to pinpoint unique cases, such as issues occurring during metadata or block transfers, or at the end of the data stream. This update effectively replaces the previous error message `footer1 !== footer2`, offering a more streamlined and accurate diagnostic tool for our users. ### Improved S3 Compatibility Originally, we developed S3 backup functionality with a focus on AWS S3\. As more users started utilizing alternative providers, we received valuable feedback that allowed us to eliminate certain AWS S3-specific checks, enhancing our compatibility with other providers. ## 📡 REST API We added 2 endpoints for the REST API, mostly linked to the backup jobs and logs. You can list all the enpoints with a simple `GET` on the API URL, eg `https://myxoa.example.org/rest/v0`. The new ones are: ```json [ "/rest/v0/backups", "/rest/v0/restore" ] ``` You can see everything related to the backup by also fetching the endpoint "backup", eg `https://myxoa.example.org/rest/v0/backups` ### Backup logs You can now list all the backup logs on `https://myxoa.example.org/rest/v0/backups/logs`. Example: ```json [ "/rest/v0/backups/logs/1583325989421", "/rest/v0/backups/logs/1583396152258", "/rest/v0/backups/logs/1583396182726" ] ``` If you want to take a look at a specific logs, just request its unique ID: ```json { "data": { "mode": "delta", "reportWhen": "always" }, "id": "1583325989421", "jobId": "d3d8e979-d02a-448c-88a6-c2ca21b54b71", "jobName": "QA", "message": "backup", "scheduleId": "0767e335-9b7a-478c-85c7-62e502d4d101", "start": 1583325989421, [...] } ``` ### VM restore logs You can also check backup **restore** logs! Like our previous example, with `https://myxoa.example.org/rest/v0/restore/logs`. Same principle, you'll have a list of unique restore job, and you can pick one to get all the details: ```json { "data": { "backupId": "e37988bd-2dd4-423f-b8d9-a01dca0913de//xo-vm-backups/123e4f2b-498e-d0af-15ae-f835a1e9f59f/20230306T165313Z.json", "jobId": "d3d8e979-d02a-448c-88a6-c2ca21b54b71", "srId": "86a9757d-9c05-9fe0-e79a-8243cb1f37f3", "time": 1678121593431 }, "id": "1678121829279", "message": "restore", "start": 1678121829279, "status": "success", [...] } ``` ### Backup job You can also list your current backup jobs at any time on the `https://myxoa.example.org/rest/v0/backup/jobs` endpoint. It will list all the jobs, and then you can request one specifically to get all the details: ```json { "remotes": { "id": { "__or": [] } }, "name": "test", "mode": "full", "settings": { "bbc34094-aa92-4879-beca-bd0b9474f7e2": { "snapshotRetention": 1 } }, "type": "backup", [...] } ``` ## 🆕 Misc We are releasing various qualify of life improvements for XO 5. ### Enhanced Network Configuration When creating a network, you can choose a physical network card, known as a `PIF` in XAPI terminology. However, if multiple VLANs are associated with the same `PIF`, the selection menu wouldn't display this information, leading to a confusing list of seemingly identical NICs without their corresponding VLANs. We have now resolved this issue by displaying the `PIF` VLAN alongside the network card. For example, for `eth2`, you will now see the associated VLAN clearly displayed, making network configuration more intuitive and user-friendly: ![](https://xen-orchestra.com/blog/content/images/2023/03/225024608-1344c645-df2d-4459-962e-77d19d440164.gif) ### Grouping icons on pool and host view Xen Orchestra is providing more and more information for each host or pool: NTP out of sync, updates available among many other things. It's now grouped into one icon, providing the details when clicked. For example, on an old XenServer version, it was like a christmas tree: ![](https://xen-orchestra.com/blog/content/images/2023/03/216643969-5ab76b98-f5eb-4f72-9b5e-da6dbabcb25d.png) Now, it's a lot better: ![](https://xen-orchestra.com/blog/content/images/2023/03/223987994-f3041e4a-e436-49c4-95c3-93078007ec20.png) ![](https://xen-orchestra.com/blog/content/images/2023/03/223147225-60f62b50-fc7e-4880-89ee-f7e8af6acaf2.png) ### Better experience for supported hosts Previously, we only displayed if you had XCP-ng Pro support at the pool level. However, it wasn't clear when browing on the host view. Now, have a clear information about the support status for a specific host: ![](https://xen-orchestra.com/blog/content/images/2023/03/225867273-e61abb70-026b-49d3-a2bd-5cd2c6084f5c.png) ### OIDC improvements Our feature released last month is already improved on two aspects: - the plugin will use the standard well-known suffix for auto-discovery - `email` field is now supported as username ### Add Suse icon for all their distros Sometimes, we endure the joy of marketing from some software companies. Especially when you want to match the distro name with its icon. Suse is probably the "best" for that. Let's take a look on how we match the Ubuntu icon from the tools: `ubuntu: ['ubuntu']`. Easy right? Now for Suse, every year there's another name to add… See for yourself: `suse: ['sles', 'suse', 'opensuse-leap', 'opensuse-microos']` I asked GPT4 about what's next: > While I cannot predict the future naming decisions of SUSE, I can provide a playful suggestion based on their naming pattern. The next name could be something like "OpenSuse Nano OS" or "OpenSuse Quantum OS," emphasizing the notion of a compact, lightweight, and efficient operating system. Get ready for Nano OS then… ## 🔭 XO Lite Despite a lot of our work is mostly done "behind the scene" (see below), we managed to get new features in XO Lite for this release. Also, don't miss our previous article on the way we are building our XO Lite components! [XO Lite componentsExplore the inner workings of XO Lite’s component-based design and how it enhances user experience in virtualization management through our in-depth blog post.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogThierry Goettelmann![](https://xen-orchestra.com/blog/content/images/2023/03/xolitedevblog-1.jpg)](https://xen-orchestra.com/blog/xo-lite-components/) ### VM Filters and Sort In the Pool/VMs view, you can now create filters and/or sort your VMs. It's still a work in progress, but it's already a very powerful tool, that we will likely re-use on XO 6. ![](https://xen-orchestra.com/blog/content/images/2023/03/image.png) See the "+ Add filter" and "+ Add sort" buttons ![](https://xen-orchestra.com/blog/content/images/2023/03/image-1.png) First step for your filter, selecting the property and some extra conditions ![](https://xen-orchestra.com/blog/content/images/2023/03/image-2.png) Current condition are name, description and power status. More to come! The filter is now visible: ![](https://xen-orchestra.com/blog/content/images/2023/03/image-4.png) You can obviously combine multiple filters If you click on it, it's easy to update it: ![](https://xen-orchestra.com/blog/content/images/2023/03/image-3.png) Sort is very similar: you can sort per name, description and power status. To revert between ascending and descending, you just have to click on the created sort: ![](https://xen-orchestra.com/blog/content/images/2023/03/image-5.png) ☝️ You can already experiment those features yourself, see this thread for deploying XO Lite on your host. ### Enhanced Console Response Time We've made significant improvements to the console response time after a VM reboot, ensuring you won't miss the Grub menu or the virtual BIOS/UEFI during the boot process. This enhancement proves valuable in various situations, and although it may not sound remarkable, the results genuinely contribute to more efficient VM management! ### Multiple pages and modals improved We've made numerous enhancements across multiple pages and modals in our ongoing effort to provide an exceptional user experience. Although some elements are still missing in the current interface, these improvements aim to address key areas. Here are some examples: ![](https://xen-orchestra.com/blog/content/images/2023/03/224005351-8cc38087-e1cc-464f-ab8d-52f15b76a761.png) We added more info on the XCP-ng version from the "About" page ![](https://xen-orchestra.com/blog/content/images/2023/03/201111114-cd70bf22-08c5-4c27-bc7f-5f48776907ff.png) If you lose the connection with the host, it's not correctly handled ![](https://xen-orchestra.com/blog/content/images/2023/03/219096556-4ef8bdd1-f8e2-451f-8018-5177cf9b67ea.png) Missing sections are clearly a work in progress instead of being empty ### CPU provisioning You can now track the total number of vCPUs in use across your pool, compared to the available number of cores. This feature provides a clearer understanding of your resource utilization: ![](https://xen-orchestra.com/blog/content/images/2023/03/215520064-dc870c66-d69d-4c88-a57e-a619e998feb8.png) ### Available updates You can now see the available updates from XO Lite: ![](https://xen-orchestra.com/blog/content/images/2023/03/223751338-424a107b-d468-46b7-8bb5-918483ed8aaf.png) ## ☄️ Improved deploy script If you don't want to use our [web deploy form](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xoa), you can -as an alternative- our deploy script in Bash. We updated it to be more user friendly, with more detailed steps and also some friendly emojis 😜 ![](https://xen-orchestra.com/blog/content/images/2023/03/deploy.png) ## 🚀 Other stuff to check out Don't forget to catch up on some cool articles from the XCP-ng and Vates blog. Here are a few highlights: [Vates joins the Xen ProjectVates, the European system management and virtualization stack company, announced today that the company has joined the Xen Project.![](https://vates.fr/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogMarc-André Pezin![](https://vates.fr/blog/content/images/2023/03/xensummit22.jpg)](https://vates.fr/blog/vates-joins-xen-project/?ref=xen-orchestra.com) [March 2023 Security UpdateWe published an update that fixes XSA-\[427-428-429\]. At the same time, we’ve included bugfixes and enhancements for Xen such as an update to version 4.13.5 and Initial Sapphire Rapids support.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogGaël Duperrey![](https://xcp-ng.org/blog/content/images/2023/03/xensec.jpg)](https://xcp-ng.org/blog/2023/03/23/march-2023-security-update/?ref=xen-orchestra.com) [Bringing Rust to the Xen ProjectBringing the Rust language to the Xen Project? Yes! But how? And where to start? Discover more in our first article in a future series dedicated to our journey in the Rust and Xen world!![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOlivier Lambert![](https://xcp-ng.org/blog/content/images/2023/03/xenrust.jpg)](https://xcp-ng.org/blog/2023/03/17/bringing-rust-to-the-xen-project/?ref=xen-orchestra.com) [New Guest Tools in RustDiscover the latest blog on integrating Rust into Xen Project. We’re building a flexible Rust-based agent for VM-Dom0 communication, showing promise in supporting various guest OS with room to grow!![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogYann Dirson![](https://xcp-ng.org/blog/content/images/2023/03/xenrusttools-1.jpg)](https://xcp-ng.org/blog/2023/03/30/new-linux-guest-tools-in-rust/?ref=xen-orchestra.com) ## 🎯 Conclusion In conclusion, we're delighted with the progress and updates in the Xen Orchestra 5.81 release, and we believe you'll appreciate the enhancements as well. As we look forward to our April release, we're excited to share that it will be even more impressive, with further advancements and news about our Project Pyrgos, which focuses on Kubernetes integration. Stay tuned for more details, and as always, thank you for your continued support and enthusiasm for Xen Orchestra! ### XO Lite components URL: https://xen-orchestra.com/blog/xo-lite-components/ Last updated: 2023-03-28T11:40:43.000Z After giving you an overview of the general design in a previous blog post, we're now ready to dive into the finer details, focusing on the key components that make XO Lite so intuitive and user-friendly. If you missed the first article, it's here: [UX/UI Design for XO and XOLiteWith the launch of XOLite and the redesign of Xen Orchestra itself, UX/UI Design is getting a revisit in the XO world.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogClémence Barthoux![](https://xen-orchestra.com/blog/content/images/2022/06/XO-Blog---UX-UI-Design-for-XO-and-XOLite.jpg)](https://xen-orchestra.com/blog/ux-ui-design-for-xo-and-xolite/) ☝️ Stay tuned for Clémence's upcoming post on the development of our comprehensive "Design System" that will be applied to all our apps, including XO and XO Lite. Don't miss out on this exciting update! If you're unfamiliar with the concept of a design system, we encourage you to explore some [examples](https://diff.wikimedia.org/2022/12/22/creating-the-wikimedia-design-system/?ref=xen-orchestra.com) [available](https://www.lightningdesignsystem.com/?ref=xen-orchestra.com) [online](https://medium.com/carbondesign/benefits-of-a-design-system-bb77416af097?ref=xen-orchestra.com). This time, we'll talk about components! But first, why working with a component approach? ## 🧱 Components Embracing a component-based approach to web design is crucial for several reasons. Here are some of the key advantages that have informed our decision to use this methodology for XO Lite: - **Reusability**: Components are modular building blocks that can be reused throughout the application, resulting in a more efficient development process. This reduces the need for repetitive code, streamlines updates, and minimizes the risk of introducing bugs. - **Scalability**: As your application grows in complexity, a component-based architecture allows for seamless scaling. By encapsulating functionality into self-contained components, developers can easily add, modify, or remove parts of the application without disrupting the overall system. - **Maintainability**: A well-structured component-based architecture makes it easier for developers to understand, maintain, and troubleshoot the codebase. With a clear separation of concerns and a predictable structure, it becomes simpler to diagnose and fix issues, ensuring a stable and high-quality end product. - **Collaboration**: By breaking down the UI into individual components, teams can work more efficiently by focusing on specific parts of the application. This promotes parallel development and enables team members with different skill sets to contribute effectively. - **Customization**: Component-based design allows for greater flexibility in tailoring the application to specific needs. Developers can easily swap out or modify components to create a customized experience without compromising the integrity of the overall system. Components are great, but we need to build something that fits with the user need, we can be called a "story". ## 🧚 A quick recap on the "story" In web development, the term "story" is often used in the context of a development methodology called "User Story" within Agile software development frameworks, such as Scrum. A User Story is a short, informal description of a software feature from the perspective of an end-user. It helps developers and designers understand the user's needs and expectations, ensuring that the final product aligns with the target audience's requirements. Mixing both components and the capability of building stories? **You have your component stories!** ## 🪄 Component Stories In our quest for better documentation and testing, as we were not satisfied with existing options, we've developed our own story system for our components. This system allows us to thoroughly document component properties, types (numbers, strings, objects, etc.), requirements, and default values. ![](https://xen-orchestra.com/blog/content/images/2023/03/Story-example.png) Component Story UI Our story system is fully interactive. Developers can modify prop values and instantly see the results, enhancing the documentation experience. Furthermore, we've included comprehensive documentation for component events, including function types, arguments, and a real-time logging system to monitor triggered events. ![](https://xen-orchestra.com/blog/content/images/2023/03/Props-editor-example.gif) Props live editor Our system also supports the documentation of component slots, including named slots and scoped slots. For scoped slots, we even provide documentation for slot props and their respective types. To further enhance customization, we've incorporated settings that aren't part of the component itself but allow dynamic values (e.g., for use as slot content). The system also enables developers to define presets, which pre-fill props and/or settings. Additionally, we've developed a basic generator that allows users to select a component and automatically generate a story skeleton, making it easier to create new stories for components: ![](https://xen-orchestra.com/blog/content/images/2023/03/Component-Story-generator.png) Component Story skeleton generator Lastly, we've made it simple to include supplementary information by allowing users to add a Markdown file next to the story file. This file is parsed and displayed alongside the component story page, providing a seamless documentation experience. In summary, our interactive component story system offers a powerful and user-friendly way to document and test components while providing real-time feedback and customization options. With this system in place, developers can create, modify, and understand components more effectively than ever before. **Constructing these tools demands time and effort, yet they will prove to be immensely beneficial in accelerating the development process for both XO Lite and the new user interfaces in Xen Orchestra 6.** ### Xen Orchestra 5.80 URL: https://xen-orchestra.com/blog/xen-orchestra-5-80/ Last updated: 2024-02-28T14:30:42.000Z Despite a previous release including a lot of new features, we managed to strike again with even more content packed into this shorter month. XO 5.80 has landed with a lot of new stuff available: VMware migration tool from the web UI, OpenID Connect support, REST API async actions and VM replication health-check for the biggest changes. But also with many other things. ## 🔐 OpenID Connect support You can now login to your Xen Orchestra using OpenID Connect, which is a very convenient and secure protocol. It's the 3rd generation of OpenID technology, built on top of the OAuth 2.0 authorization framework. We also managed to enable auto discovery, to make it very simple to configure. It's also very extensible and easy to use. We'll show here how to use it with KeyCloak, an open source Single Sign-On platform. ☝️ You can also configure your KeyCloak platform to use 2FA (like TOTP) methods to have strong authentication for your users. Since it's managed by your SSO platform, it's entirely transparent for Xen Orchestra. ### Creating the client in KeyCloak We wanted to provide a real example with KeyCloak. Obviously, any SSO server with OpenID Connect will also work. First, you need to create the "client" (the application that will use OpenID): ![](https://xen-orchestra.com/blog/content/images/2023/02/1clientcreate-2.png) First step in Keycloak: create a new client In the client creation wizard, you need to select the "OpenID Connect" type, and choose a client ID (you need to keep this in mind to configure it in Xen Orchestra). Here, we are using `xoa`: ![](https://xen-orchestra.com/blog/content/images/2023/02/2clientcreation.png) Add the client details Don't forget to switch "Client authentication" to **On**: ![](https://xen-orchestra.com/blog/content/images/2023/02/3clientcreation.png) Don't forget to switch Client authentication to "On" Now you also need to add a URL in the "Valid redirect URIs": in short, that's where KeyCloak will send you after a successful authentication. Use your XO URL (or IP address) on a format `https://xoa.example.org/*`. Note that if you access your XO both with IP and name, you can add multiple URIs. ![](https://xen-orchestra.com/blog/content/images/2023/02/5configureurl.png) Now the client is created, you can edit it and check the "Credentials" tab, in order to copy the "Client secret": it will be needed in XO plugin configuration: ![](https://xen-orchestra.com/blog/content/images/2023/02/4getcreds.png) Click on the "copy" icon to put the secret in your pastebin Last thing needed to configure the plugin on the XO side: the "Auto-discovery URL". It's available in the left menu "Realm settings". Copy the "OpenID Endpoint Configuration" somewhere. ![](https://xen-orchestra.com/blog/content/images/2023/02/image.png) Now you should have, in our example: - the client ID, `xoa` - the Client secret - the "Auto-discovery URL" ### Enabling and configuring the plugin This is pretty straightforward: ![](https://xen-orchestra.com/blog/content/images/2023/02/image-1.png) Don't forget to enable and save the plugin configuration! ### Login to XO That's it! With this configured with a strong auth process in KeyCloak, you can safely expose Xen Orchestra on the internet. Note the new login button on the top: ![](https://xen-orchestra.com/blog/content/images/2023/02/image-2.png) ## 🐦 VMware migration tool Our VMware migration tool, logically called **V2V (Virtual to Virtual, or VMware to Vates)**, is now usable directly from the Xen Orchestra web UI, in the "Import" menu. A new entry there: "From VMware": ![](https://xen-orchestra.com/blog/content/images/2023/02/221530744-2544bcec-efdd-4c10-8dd1-0e76dd0d37fa-1.png) After giving the vCenter credentials, you can click on "Connect" and go to the next step: ![](https://xen-orchestra.com/blog/content/images/2023/02/221530828-92a31c03-2244-44f5-804d-1447322fc809.png) On this screen, you will basically select which VM to replicate, and to which pool, storage and network. When it's done, just click on "Import" and there you go! Don't forget to give your feedback on our [dedicated forum thread](https://xcp-ng.org/forum/topic/6714/vmware-migration-tool-we-need-your-feedback?ref=xen-orchestra.com). ☝️ You can choose to enable "thin mode": it's longer ("double read") but the disk created on XCP-ng side will only use the space used in the VMware disk. For now, there's no progress on this initial read, but we have plans to expose the "XO task" for it in the next release. ### Current limitations and next steps We have various improvements in the pipes. So far, the delta import is only supported up to VMware 6.5\. This will be solved in our next release, to support all VMware versions in delta mode. If you use something more recent, you can just shutdown the VM, the replication will work, but not in "warm" mode (ie: delta). Also, our internal XO task system is about to be exposed with this feature, so even in case of using the "thin mode" (mode we recommend to use), you'll be notified of the progress of the first read. And finally, multi-VMs import will also land for our next release. ## 💾 Pool Metadata restore If you lose all your hosts, but not your shared storage, it might be shorter to re-install XCP-ng on some fresh hardware, and restore the pool metadata. Thanks to this, all your VMs will be back (and the configuration with it!) in a minute. No need to restore all your backups! Now, the restore menu is more complete: ![](https://xen-orchestra.com/blog/content/images/2023/02/218695231-3be932b9-2d64-4123-b7f5-15eeb39254b3.png) It will overwrite any previous configuration on your pool: ![](https://xen-orchestra.com/blog/content/images/2023/02/218698610-04696adc-5594-47d2-bd1d-26574243fab6.png) As you can see, it's also multi-pool compatible: it means you can restore multiple metadata backups to multiple pools at once! Despite the fact we've had the pool metadata restore for a while, it wasn't practical due to a limitation we removed. Now, this is another life saver for your XCP-ng/XenServer infrastructure. ## ⚕️ Continuous Replication health check We integrated a way to automatically test your backups, a few releases ago: [Xen Orchestra 5.71It’s time for XO 5.71! Backup auto restore check, RPUv3, backup VMs with vUSB and more.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2022/05/mayrelease.jpg)](https://xen-orchestra.com/blog/xen-orchestra-5-71/#%E2%9A%95%EF%B8%8F-auto-restore-check) Now, we extended this feature to the Continuous Replication backup type. You just have to enable the feature in your backup job, and that's it! After each VM is replicated on the destination, we'll start a copy of it (to avoid any replication disruption, also without networking) and see if it boots until the VM tools are started. Then, we remove it. Simple and efficient. If any VM fails, you'll be notified directly in your backup logs. ## 📡 REST API async actions You can now start, reboot or shutdown (both soft & hard) and snapshot your VMs with the REST API! Since those operations can be long, we plugged it to our new task system. Yes, the task system we already told you about for the next big XO release, XO 6. ### List the available actions To see the actions available on a given object, get the collection at `/rest/v0///actions`. For example, to list all actions on a given VM: ```bash curl \ -b authenticationToken=KQxFkTbs \ 'https://xo.company.lan/rest/v0/vms/770aa52a-fd42-8faf-f167-8c5c4a237cac/actions' ``` ### Start an action Post at the action endpoint which is `/rest/v0///actions/`. For instance, to reboot a VM: ```bash curl \ -X POST \ -b authenticationToken=KQxFkTbs \ 'https://xo.company.lan/rest/v0/vms/770aa52a-fd42-8faf-f167-8c5c4a237cac/actions/clean_reboot' ``` ### Force an action in sync mode For some cases, you might prefer to send a sync action, meaning the HTTP call will only return when the action is finished. To do that, just add the `?sync` query string to your HTTP call. ## 🔭 XO Lite We continue to work on XO Lite, and this time we made some progress on displaying tasks and also listing all the available updates for your pool. ### Tasks In the "Dashboard" and in "Task tab" of your pool, you can now see the XCP-ng active tasks running: ![](https://xen-orchestra.com/blog/content/images/2023/02/221537606-902bc194-3655-49cb-8409-2849ba3efd9c.png) ### List of updates available In the dashboard view (or at the pool level), you can see all the available updates. ## 🆕 Misc And there's always various stuff added that doesn't fit in a specific category 😊 ### XOA check: free memory When you do an XOA check (on your XO virtual Appliance), we added an extra check to see if you have enough RAM to run everything without any issue. It's helpful to reduce the time to find potential issues, or even fixing problems before they appear. ### Warning modal with PV tools If you enable "Windows Update tools", you'll have a confirmation modal with a warning, avoiding some mistakes: ![](https://xen-orchestra.com/blog/content/images/2023/02/220663775-d0fd81d9-2a34-4785-a54c-33de9b5e2908.png) ### Backup logs improved We improved the logs of your backup jobs. if you are using NBD, it will be visible: ![](https://xen-orchestra.com/blog/content/images/2023/02/221518751-dad2153a-505d-469f-a129-b9e7f3b9629c.png) ## ☸️ Announcing Project Pyrgos: turnkey k8s Just announced yesterday, if you are **interested in deploying production-ready Kubernetes clusters easily**, don't miss our previous blog post: [Announcing project PyrgosWe are please to announce a project we are starting, related to Kubernetes and Xen Orchestra. Context As you may know, the name Kubernetes originates from Greek, meaning ‘helmsman’ or ‘pilot’. This container orchestration platform is widely used, even in XCP-ng/Xen Orchestra, with nodes running i…![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2023/02/pyrgos-1.jpg)](https://xen-orchestra.com/blog/p/507b076d-d49f-4593-b72d-3e8012726558/) ### Announcing project Pyrgos URL: https://xen-orchestra.com/blog/announcing-project-pyrgos/ Last updated: 2023-02-27T13:32:47.000Z For our users who want to easily deploy a production-ready Kubernetes clusters on top of their XCP-ng/Xen Orchestra infrastructure, well, you'll be pleased to discover our new project Pyrgos, built on top of Xen Orchestra. ## Context As you may know, the name Kubernetes originates from Greek, meaning *"helmsman" or "pilot*". This container orchestration platform is widely used, even in XCP-ng/Xen Orchestra, with nodes running in VMs. Right now, our users are relying on various tools to get some automation deploying Kubernetes (k8s) clusters on top of our virtualization platform. To deploy a k8s cluster, a part of those users are installing it manually, while most of them are using the XO API directly, our CLI, or our Terraform provider to bring automation to this task. It works well, but we wanted to reduce the load of our beloved system admins to be able to create production-grade k8s clusters, while also helping them to keep them up to date, directly from the XO web UI! ![](https://xen-orchestra.com/blog/content/images/2019/12/kubernetes-logo.png) The goal is to give your dev teams a "ready to work" k8s cluster so they can run their application inside it, without spending time on your side to create and update those clusters. ## Project Pyrgos Pyrgos (πύργος) means "*Watchtower*" in Greek. Which seems like a valid analogy for our Kubernetes "*pilots*". A kind of ground control, helping to centralize and keep the pilots running. ### Helping k8s cluster creation We already have a "recipe" to create k8s clusters in XO, in fact since almost 3 years: [DevBlog #5 - Kubernetes cluster on XOIt’ll soon be possible to deploy easily and quickly a kubernetes cluster on XO thanks to a new coming feature: XO recipes.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogBenjamin REIS![](https://xen-orchestra.com/blog/content/images/2020/12/untitled-poster_43002514-7-.jpg)](https://xen-orchestra.com/blog/devblog-5-kubernetes-clutser-on-xo/) However, this current tool doesn't give a lot of choice during the creation, and it's not "production-grade" since you need more **control planes** nodes to be safe (at least 3). Improving this tool to allow multi-control planes (with any number), but also more choices in the tooling used, while providing a dedicated small weight Linux template to it, is our goal. In the long run, choosing your CNI, Ingress and many other things will be provided in this screen. ### Display your current clusters We also want to dedicate a view in Xen Orchestra, where you can see all your created k8s clusters, with some important information on them. Number of worker nodes, control planes, main data but also including their current versions, and if they are up to date (or not). ### Updating your cluster Another exciting feature for our project, is the ability to just update your cluster to a newer Kubernetes version with one click, leaving Xen Orchestra to do it for you. In short, XO will redeploy a fresh node in the latest k8s version, join the cluster, and replace one by one all the nodes, while "evacuating" the old workers, so it's entirely transparent for your application. Similar to our "Rolling Pool Update" feature for XCP-ng pools. ### Providing the tools We also want to help our Kubernetes community to easily deploy the tooling they need to manage their clusters. Through our "hub" of VMs, we can also prepare some tools to be deployed and connected to your clusters, reducing again the amount of work needed to manage it. ### And more! **This is just a start, with our first priorities**. Clearly, we don't want to expose the whole Kubernetes "run" details for your application inside Xen Orchestra (that would be too complex), but focus on the usual pain points from our users, so they can focus on **using it** without the complexity of deploying and updating it. Stay tuned for more. If you want to discuss or test it in preview, feel free to join our dedicated thread on the forum! ![](https://xen-orchestra.com/blog/content/images/2023/02/pyrgostower.jpg) ## Next steps We'll release more Kubernetes features step by step. Expect improvements to our Kubernetes recipe in our next release in March. Stay tuned! ### Xen Orchestra 5.79 URL: https://xen-orchestra.com/blog/xen-orchestra-5-79/ Last updated: 2024-04-28T10:05:44.000Z Let's take a deeper dive into what's inside this 5.79 version. A large part is dedicated to the VMware migration tool, but there's also many other new things and improvements, even in our current web UI version. TL;DR: we are sorry for your mouse wheel, there's a lot to talk about! ## 🐦 VMware migration tool It's our first official release for our VMware migration tool, logically called **V2V (Virtual to Virtual, or VMware to Vates)**! **No agent to install, and no need to export a VM anywhere** (e.g in OVA) to finally re-import it in XCP-ng, it's entirely done in streaming "**on the fly**". We also now support official warm migration with it (see below). ### Warm migration from VMware to XCP-ng We are really proud to introduce **warm migration available from ESXi 6.3 or older**. You can do it very easily, and we also added various parameters to tune the way it works for your own requirements. The warm migration process works like this: ![](https://xen-orchestra.com/blog/content/images/2023/01/xoa-v2v-1-1-.png) The initial situation: a running VM on ESXi on the left, your Xen Orchestra in the middle, and your Vates XCP-ng host on the right. ![](https://xen-orchestra.com/blog/content/images/2023/01/xoa-v2v-2.png) The initial sync: the empty VM is created on XCP-ng, and after a snapshot, the content is transferred from VMware side to the new VM disk on XCP-ng. This takes time, but your original VM is up all along (no service interruption). ![](https://xen-orchestra.com/blog/content/images/2023/01/xoa-v2v-3.png) After the initial sync, the original VM is shutdown, another snapshot is done and only the diff is sent to the VM on XCP-ng side. Since it's a small amount of data, the downtime will be minimal. ![](https://xen-orchestra.com/blog/content/images/2023/01/xoa-v2v-4-1-.png) After the transfer, the VM on XCP-ng side is started. This process is fully automated, without any human intervention after it starts on step 1. To start the warm migration, you can use `xo-cli` with the following arguments: ``` vm.importFromEsxi host= user= password= sslVerify=false vm= network= sr= stopSource=true thin=true ``` The extra args you might be wondering about: - `stopSource` is used to shutdown the original VM (false by default, use `true` for a real warm migration). - `thin` is transferring the content in thin mode on XCP-ng. We advise to always set it to `true`, otherwise, you'll also transfer empty blocks. The only drawback is reading the content twice on the VMware side to get the structure of the disk, but in the end, your disks will be smaller on the XCP-ng side. ☝️ ****Being safe:** we decided to leave stopSource at false by default so you can use the script without any impact on your running ESXi VMs. Don't forget to set it to true when you want to shutdown the original VM and make a true warm migration! ### Cold migration It's also possible to make a cold migration for **any ESXi version**. It's very simple, but this needs a longer VM downtime, since the VM will be halted during the full -and only- transfer. To do the cold migration, it's very simple: it's exactly the same process as with warm migration, but **your VM should be halted first** on your VMware host before starting the process. That's it! An example: ``` vm.importFromEsxi host= user= password= sslVerify=false vm= network= sr= thin=true ``` #### How to get your VM ID When you use vCenter, navigate to your VM. In the URL field of your browser, you'll see the ID, here the number **4**: ![](https://xen-orchestra.com/blog/content/images/2023/01/image1.jpeg) ☝️ Don't forget to remove your VMware guest tools before starting the migration! Feedback is always welcome, you can participate in [this dedicated forum thread](https://xcp-ng.org/forum/topic/6714/vmware-migration-tool-we-need-your-feedback?ref=xen-orchestra.com). ### What's next Our goal is to release warm migration for any ESXi version in our February release, and to continue to optimize it. And ideally, to even get rid of VM ID questions or finding the VM, instead directly using the tool to list everything in Xen Orchestra. Stay tuned! ## 📡 REST API Our work continues on providing more content to our REST API, in parallel of our existing JSON-RPC over websocket API. As a quick reminder, this REST API is made to be simple to use and request from anywhere, even using a simple `curl` command in a command shell. ### Resident VMs on a host This feature was asked for by the community, and the use case is pretty simple but powerful: how to quickly list any host having no VMs running on it? Now, you can simply run this: ```bash curl \ -b authenticationToken= \ http://xoa.example.com/rest/v0/hosts?filter=residentVms:length:0 ``` ☝️ ****Filter bonus:** you can also use this filter in the XO web UI! Another example to only display hosts with less than 2x VMs for example: residentVms:length:<=2 ### Exporting disks in raw format It's very similar to our previous disk export capability, but this time, you can decide the export format, eg using `raw` if you want to export the content without any format. This can be useful in various scenarios: ```bash curl \ -b authenticationToken= \ 'https://xoa.example.org/rest/v0/vdis/1a269782-ea93-4c4c-897a-475365f7b674.raw' \ > myDisk.raw ``` ### Change name or description of any object This is the first method that is now able to modify an object property. This is done via an HTTP `PATCH` request. We decided to start with `name_label` and `name_description`, because it's pretty simple to implement: ```bash curl \ -X PATCH \ -b authenticationToken= \ -H 'Content-Type: application/json' \ -H 'Accept: application/json' \ -d '{ "name_label": "The new name", "name_description": "The new description" }' \ 'https://xo.example.org/rest/v0/vms/770aa52a-fd42-8faf-f167-8c5c4a237cac' ``` ### Removing VMs and VM disks This is also the first destructive method we've implemented! Using it with caution, the HTTP `DELETE` request is pretty explicit. To remove a VM: ```bash curl \ -X DELETE \ -b authenticationToken= \ 'https://xo.example.org/rest/v0/vms/770aa52a-fd42-8faf-f167-8c5c4a237cac' \ | cat ``` And to remove a disk: ```bash curl \ -X DELETE \ -b authenticationToken= \ 'https://xo.example.org/rest/v0/vdis/1a269782-ea93-4c4c-897a-475365f7b674' \ | cat ``` ## ☸️ Kubernetes recipe updated Another minor -but useful- improvement for people who want to test our fully automated Kubernetes cluster deployment: you can now rely on specific static IP addresses for your deployed Nodes. It can be handy for a lab where you don't want to install a DHCP server. Obviously, it's mostly meant for Kubernetes testing purposes. ![](https://xen-orchestra.com/blog/content/images/2023/01/Kubernetes-Logo-1.png) ## 🔭 XO Lite Another leap forward for XO Lite, the local web UI to manage your host (or one pool). We still spend a lot of time crafting all the new components, but this is also for a good reason: **providing a very nice and coherent interface**. For this release, the whole XO Lite team is happy to present new features, allowing the tool to enter a new phase: **it's now possible to perform actions on your VMs!** ![](https://xen-orchestra.com/blog/content/images/2023/01/xolitebadge-1.png) ### VM actions We managed to add all the VM "power" actions in this XO Lite release: starting a VM (even on a specific host), pause, suspend, resume, reboot, force reboot, shutdown and force shutdown. For people who previously could only rely on the `xe` CLI for simple operations like this, you have now a more graphical alternative without installing anything anywhere! ![](https://xen-orchestra.com/blog/content/images/2023/01/211571167-6cd1d8a5-5b88-4275-9b8c-0f94d76b20ba.png) ### Improved responsive design and new graphs The dashboard view is now optimized and correctly uses the space without generating extra horizontal scroll: ![](https://xen-orchestra.com/blog/content/images/2023/01/pooldashboard.png) You can now see a network and a RAM usage graph for your pool dashboard: ![](https://xen-orchestra.com/blog/content/images/2023/01/212869140-144ace7e-73ab-4450-8eba-a1070642b2c0.png) ## 🆕 Current Web UI improvements We continue to also improve the current XO 5 web interface, providing "quality of life" features, so managing your infrastructure is easier than ever. ### Toggle for Viridian extensions This is a parameter that is normally enabled by default for all Windows templates after Windows 2012\. Those extensions (called "Viridian enlightenments" by Microsoft) are used by any "recent" Windows OS to work properly. However, during some external VM imports, they might be disabled. The VM Advanced tab now allows to enable them: ![](https://xen-orchestra.com/blog/content/images/2023/01/image-3.png) ### Enable NBD for a network As a quick reminder, we managed to improve the backup speed by relying on NBD, you can read more in our previous release announcement: [Xen Orchestra 5.76Xen Orchestra 5.76 has landed. Discover what’s new!![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2022/10/xooctober.jpg)](https://xen-orchestra.com/blog/xen-orchestra-5-76/#%F0%9F%9A%85-faster-backups-preview) But until now, you had to enable NBD using the CLI. Since it's more important now, we decided to expose this feature in the Xen Orchestra web UI: ![](https://xen-orchestra.com/blog/content/images/2023/01/215509166-54f2b21b-a08a-4796-b124-490dcc9e69ed.png) On Network creation, you can enable NBD support And for existing networks, you have now a new row allowing you to enable/disable NBD from the UI: ![](https://xen-orchestra.com/blog/content/images/2023/01/215490204-fa3634b0-5aad-4802-b53a-9ff2ea7f1918.png) ### Rounding host memory It sounds like nothing, but I have to admit it bothered me for years. Xen Orchestra fetched the API information on the total memory usable for a host, and it was usually something like this: ![](https://xen-orchestra.com/blog/content/images/2023/01/image.png) Why 127.48GiB? Well, remember you are using Xen. It's a microkernel booting on the metal. It is very small, and require to use a small fraction of your host memory to operate. The rest is used by your Dom0 and your regular VMs. Since this information isn't really relevant for your everyday usage (especially since it's always a small fraction of your total memory, like few MiB on a small system), we decided to hide it by rounding it: ![](https://xen-orchestra.com/blog/content/images/2023/01/image-1.png) ### Renaming Citrix PV tool A classic mistake that users could potentially make in Xen Orchestra: you are using XCP-ng tools in your Windows VM, and then you decide to enable Windows Update for PV tools. However, this is only working if you have Citrix tools installed, because mixing them will cause at best a loss of PV drivers, and at worst a crash of your VM. To prevent this situation happening, we decided to rename the feature in the UI to more accurately reflect this: ![](https://xen-orchestra.com/blog/content/images/2023/01/image-2.png) ## Closing thoughts As you can see, it's a pretty large release. We hope to maintain this fast pace of innovation and improvement for the whole year. Stay tuned for exciting news coming during this quarter! ![](https://xen-orchestra.com/blog/content/images/2023/01/Vates_XO-Badge.png) ### Xen Orchestra 5.78 URL: https://xen-orchestra.com/blog/xen-orchestra-5-78/ Last updated: 2023-01-19T20:11:07.000Z Merry Christmas and welcome to XO 5.78, the last release of the year! 🎄🎄🎄 We are doing our release a little bit earlier than usual, so we can have some time to rest before a new year 🎅 ## 📸 VM snapshot ignoring disks Thanks to a contribution made by XCP-ng team to the XAPI Project (see below), we can now snapshot partially a VM while calling `VM.snapshot` method. Partially means if the VM got 2 or more disks, we can ignore any disk we want. Why is it a great thing? Because previously, with the `[NOBAK]` name of the disk, we indeed ignored the tagged disk in the export/backup process. However, the disk was still snapshot on the storage, using space for nothing. With this new feature, XO detecting `[NOBAK]` will automatically make the new call asking XAPI to ignore this specific disk. No more "useless" disk snapshot! Our contribution in XAPI Project for this feature is visible here: [Add \`ignore\_vdis\` to \`VM.snapshot\` method by benjamreis · Pull Request #4563 · xapi-project/xen-apiThis allow to snapshot a VM and ignore some VDIs during the snapshotThis can lead to a gain of time & space ignoring non essential dataSee: #4551Signed-off-by: BenjiReis benjamin.reis@vates.fr![](https://github.com/fluidicon.png)GitHubxapi-project![](https://opengraph.githubassets.com/16d25136bf209cd5225329a2da47018553a9b96ac7c33e682084f8314b4a713f/xapi-project/xen-api/pull/4563)](https://github.com/xapi-project/xen-api/pull/4563?ref=xen-orchestra.com) ☝️ Note: it works with a recent version of the XAPI, already available in XCP-ng 8.3 alpha. This is also 100% transparent for you: when you'll migrate to 8.3, it will work "out-of-the-box" with your existing \[NOBAK\] disks! ## 🐦 VMware warm migration tool Do you remember our previous blog post on how to migrate to VMware to XCP-ng? We announced something in there but now it's coming: [Migrate from VMware to XCP-ngVmware v6 is now end of life, the right time to migrate to an open source, less expensive and constantly evolving solution: XCP-ng.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng BlogOlivier Lambert![](https://xcp-ng.org/blog/content/images/2022/10/chris-briggs-V72Hk6LjjjI-unsplash.jpg)](https://xcp-ng.org/blog/2022/10/19/migrate-from-vmware-to-xcp-ng/?ref=xen-orchestra.com) Yes, warm migration from VMware to XCP-ng! We are really excited with this feature. In short, we are working on a tool to apply the concept of "warm migration" implemented in our previous release (see the dedicated blog post below). However, instead of migrating between two XCP-ng hosts, this time it's between an EXSi/vSphere host to… XCP-ng! [Warm migration with XODiscover how warm migration can help you to handle different and complex migration scenarios.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2022/11/warm.jpg)](https://xen-orchestra.com/blog/warm-migration-with-xen-orchestra/) You might ask "how?", and well, even if we use the same principle, it's a bit harder to implement as you can imagine. **Phase 1: metadata.** First, our tool will create a similar VM on XCP-ng (same name, disk, network…). We'll replicate automatically all the metadata: you just have to choose on which storage repository, which network to create the disks and the virtual interfaces respectively. The rest is handled automatically! **Phase 2: initial replication (full).** Then, we snapshot the VMware guest and we export this "full" toward the XCP-ng VM, injecting directly the content in the previously created disks. This phase is done without shutdown the current VM on VMware side. Yes, this is taking some time, but your service stays up during this first phase. Alternatively, you can decide to keep the VM shutdown if you don't care, meaning you won't have to go for the next phase. **Phase 3: send the diff (delta).** Now we have an initial sync between those two sides, we will shutdown the VMware guest and immediately export all the modified blocks (diff/delta) since the first snapshot. And we finally merge them on XCP-ng side "on the fly". As soon it's done (should be few minutes only!), we can boot the VM on XCP-ng side, and… that's it! Sure, you might need to change some details inside the VM (like the network configuration, installing XCP-ng tools), but most things should work roughly out of the box. ### Current status For this release, we managed to get a preview working up to the **Phase 2**. The VMware compatibility is relatively broad, most versions on the market should be compatible with our tool (from VMware 4.x to 8.x). However, we'd like to test it outside our lab and get some feedback from it. That's why we opened a forum thread so you can try it on your side: [XO Forum: VMware migration feedback](https://xcp-ng.org/forum/topic/6714/vmware-migration-tool-we-need-your-feedback?ref=xen-orchestra.com) Also, since we could only export the "raw blocks" from VMware (see below), a direct transfer into VHD would have created a "thick VHD". For example, on a 40GiB disk with Ubuntu inside using only 2GiB, the copy on XCP-ng would have use 40GiB on the storage, regardless the usage of thin or thick SR. 🤷 It seems impossible to export a VM disk in a VMDK format from the VMware API. The only way we found is to pass the VM file path in the URL, having acess to the raw blocks only. It works, but it requires some tricks to make the transer on used blocks only. Obviously, if you know better, please tell us! That's why we had to make a "double read" solution: the first will be used to count and note the used blocks on the whole disk, and the second to only transfer them, without any empty blocks! It works well, meaning your destination VHD will be now only 2GiB (per our example). ### Testing it To test this new tool, you need to switch your XOA to the `vmware` release channel. If you are using it from the sources, switch to the `vmware` branch and rebuild. At this point, you can use `xo-cli` to call the migration tool: ``` xo-cli vm.importFromEsxi host= user= password= sslVerify= vm= sr= network= ``` As you can see, it's pretty obvious. Just gather all the information needed to contact the VMware side (IP, credentials, ssl check or not and the ID of the VM). On the XCP-ng side, just provide the destination SR and network. 💡 On the VMware side: in order to get a working transfer, you need either to have one snapshot of your VM **OR** to get it halted. Now, you can see the transfer progress in the "Task" view of your Xen Orchestra UI. As soon it's done, you can directly boot the VM! ## ☸️ Kubernetes recipe with Flannel It's been a while, but we decided to update our Kubernete recipe. The things evolved a bit in this world: we now must rely on a Network Plugin, using the "Container Network Interface" (CNI). We made the choice of [Flannel](https://github.com/flannel-io/flannel?ref=xen-orchestra.com), because it's very simple and works with our Kubernetes automated deployment. It's entirely transparent for you, so if you want to make a test with a small k8s cluster, go ahead! [![](https://xen-orchestra.com/blog/content/images/2022/12/flannel-horizontal-color.png)](https://github.com/flannel-io/flannel?ref=xen-orchestra.com) ## 🔭 XO Lite: new features Reminder: XO Lite is meant to be the XCP-ng embedded UI to manage/bootstrap your host locally. Here is the new components available. ### Graphs Our first graph is related to CPU usage. More graphs will come soon after, since most of the work is to create the initial component. ![](https://xen-orchestra.com/blog/content/images/2022/12/208007327-cc74c538-1343-4a7b-9379-5fa7db6a07e1.gif) Our first CPU graph, used with the dark theme (default) ### 404 or missing data page It's part of building a nice tool: managing the error cases and accessing missing resources. That's why we added 2 pages to handle those cases: ![](https://xen-orchestra.com/blog/content/images/2022/12/205610510-ddfc0f2e-2d48-4e49-ae21-84b20a0b5dcb-1.png) ![](https://xen-orchestra.com/blog/content/images/2022/12/188904784-f83ba9ed-e818-4861-bdb3-c20924fd7b2c-1.png) ## 🔄 XO tasks: a work in progress One of the big feature of the next big Xen Orchestra release, "XO 6", will be a complete new task system. If you want an overview on XO 6, you can read this previous article: [XO 6: what’s on the horizonA quick review of our progress on XO 6 front, the full rewrite of Xen Orchestra UI and part of the server!![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogJulien Fontanet![](https://xen-orchestra.com/blog/content/images/2022/07/xo6sunrise.jpg)](https://xen-orchestra.com/blog/xo-6-whats-on-the-horizon/) Anyway, at the moment, we only rely on XCP-ng/XenServer tasks. Which is fine for "simple" action (VM migration, export…) but not great when you trigger more complex operations, like "Rolling Pool Upgrade" or "Warm migration". The new goal is to create an "XO task", including other tasks inside, so you can follow a complex process easily. For example, a "warm migration" contains at least 7 steps: snapshot, VM creation on destination, transfer, shutdown source VM, re-snapshot, delta transfer, boot on destination. So we can have a precise "current step" tracked with this system, so you know exactly what's going on! We recently made good progress on this new task system. We expect it to be used first with the warm migration in the next releases, early next year. And also, this "generic" task system will be exposed in the UI in XO 6, with some extra bonus features (like cancellation), and a "history" of them so you can get details on them (success, failure, at which step, how long…) ## ⭐ 2022: a recap It's our tradition: we release an infographic providing a recap of the year for Xen Orchestra, XCP-ng and Vates in general. Go take a look to our article so get a sum up of what happened! [Vates in 2022Like every year, we share with you some figures and a summary of the things accomplished this year by our teams. As every year, we thank our community without whom XCP-ng simply could not exist! See you next year, we have a lot of new things to come soon.![](https://vates.fr/blog/content/images/size/w256h256/2022/07/logo64.png)Vates BlogMarc-André Pezin![](https://vates.fr/blog/content/images/2022/12/vates2022.jpg)](https://vates.fr/blog/vates-in-2022/?ref=xen-orchestra.com) ### Xen Orchestra 5.77 URL: https://xen-orchestra.com/blog/xen-orchestra-5-77/ Last updated: 2022-11-30T14:08:21.000Z There is a lot of exciting stuff ✨ I wanted to thanks everyone involved in this 5.77: we managed to deliver a lot constantly, despite having only 30 days between each new version. Congrats to our XO team and the community! ## 🛰️ XO Proxy major improvements Now you can easily scale your entire XCP-ng/XenServer infrastructure all around the world without a "shared"/extended network, still using just **one XOA to control everything**, while doing CR via the proxy, and deploying it with a one-liner. More in this article: [XO Proxy: a concrete guideA introduction on how to create a global XCP-ng infrastructure managed by a central Xen Orchestra. In a secure manner without any 3rd party network tool.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra NewsOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2022/11/tianjin-ga7a996daa_1280.jpg)](https://xen-orchestra.com/blog/xo-proxy-a-concrete-guide/) As promised in the article, you can also simply add an existing XO Proxy from your central XOA via this new interface: ![](https://xen-orchestra.com/blog/content/images/2022/11/204312137-18cc89bf-5727-4ca0-9310-a1ae599ca8ec.png) ![](https://xen-orchestra.com/blog/content/images/2022/11/204504311-a8913ba2-7e8f-4579-9aec-77fcd1977c1d.png) And we managed to get XO automatically utilize the proxy for any operation (management, backup, replication…) ## 🌡️ Warm migration Another proof that you can create brand new features by orchestrating multiple XCP-ng hosts at the same time. But let's rewind a bit first. Some context: imagine you have a datacenter where all your VMs are running on Intel Xeon CPUs, and some of those VMs have pretty large disks. Now, you want to migrate those to a new datacenter running on AMD EPYC CPUs. You can't live migrate, and offline migration will take a long time. ![](https://xen-orchestra.com/blog/content/images/2022/11/202231167-39cb6f2b-f354-4e5a-a513-d002d072ea7a-1.png) The new button is available in your VM view, Advanced tab. That's why we created the warm migration: reducing your downtime to migrate to only few minutes, while allowing to move your VMs between various hosts, even if they are running different CPU manufacturers, or even from old XenServer hosts to our latest XCP-ng version. All the details (and more!) in our dedicated article: [Warm migration with XODiscover how warm migration can help you to handle different and complex migration scenarios.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2022/11/warm.jpg)](https://xen-orchestra.com/blog/warm-migration-with-xen-orchestra/) ## 📡 REST API: snapshots Our REST API now has 2 new endpoints to request: `vm-snapshots` and `vdi-snapshots`. This way, you can fetch any info related to your snapshots (VMs or disks). The list of available collections is under the path `/rest/v0`. Remember to take a look at the [official documentation](https://xen-orchestra.com/docs/restapi.html?ref=xen-orchestra.com) for more details. Remember that you can [use filters](https://xen-orchestra.com/docs/manage%5Finfrastructure.html?ref=xen-orchestra.com#live-filter-search) to only fetch what you need! Here is an example to get only the snapshots of one VM: ``` curl -b authenticationToken= \ https://xoa.example.com/rest/v0/vm-snapshots?filter=%24snapshot_of: ``` Enjoy! And keep us posted on what you need. We have plans to get more than read only calls, but this requires creating a queue and using tasks, which is something we are working on with Xen Orchestra 6\. More to come on that topic next month! ## 🚀 XCP-ng 8.3 Alpha If you missed it, we are proud to announce we released a first alpha for our next release: XCP-ng 8.3\. There are so many things to talk about, that you should really read the dedicated blog post. However, if you need to remember 2 important things: it's not an LTS version, and it's a decent base for a LOT more stuff coming in 2023\. The future is exciting! [XCP-ng 8.3 AlphaXCP-ng 8.3 first alpha release is now available. Download and try it!![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng NewsOlivier Lambert![](https://xcp-ng.org/blog/content/images/2022/11/NASA-Artemis-1-full-moon-20221115.jpg)](https://xcp-ng.org/blog/2022/11/18/xcp-ng-8-3-alpha/?ref=xen-orchestra.com) 💡 This alpha is **bundled with XO Lite by default!** Just go to the URL of your host, and you'll land directly on the login page. ## 🔭 XO Lite improvements Expect bigger news in December with more content and directly usable features. This month however, we did various components that will be integrated soon, while also improving our responsive design for smaller devices: ![](https://xen-orchestra.com/blog/content/images/2022/11/203949969-d35c70ea-d02e-475f-bf87-26f0c2d5f2df.gif) ## 📤 Nagios backup reports improved In our first iteration of our backup report capability on Nagios (ie: sending backup reports to Nagios), only one job status (failure or success) was sent to your monitoring server. We've been asked to improve our plugin to support individual backup reports for each VM in a backup job. The plugin UI is very similar: ![](https://xen-orchestra.com/blog/content/images/2022/11/Screenshot-from-2022-11-29-13-14-31.png) However, you now have the detail for an individual VM reported, with its job name: ![](https://xen-orchestra.com/blog/content/images/2022/11/202678157-72da844b-0e07-4913-b734-cfd0ac176238.png) But that's not all! We added a **template system** for your report, so you can add any kind of description for the service and host. For example, we use `{vm.name_label}` but you can add `xo-backup-{vm.name_label}` before. It's exactly the same thing for the Job name and description, with `{job.name}` available by default. ## 🔑 Remove TOTP for a user It happens: sometimes, a user will lose their TOTP recovery password. To prevent a lock-out, you can now disable it for him, only as an administrator obviously: ![](https://xen-orchestra.com/blog/content/images/2022/11/203808054-6201050d-8f2e-4a49-84ed-3549d8b44517.png) ## 🚄 OVA generation: twice as fast In our interoperability quest, we always want to allow people to try our platform without any lock-in. That's why we invest time and effort to get a decent standard support for VM formats, so you can export your XCP-ng VMs to VMware, KVM and anything else supporting OVA format. However, generating an OVA with VMDK disks inside it isn't really trivial. Due to format differences and some missing features on the XCP-ng API side (knowing the size of what we export), we previously had to make the OVA generation in 2 stages. We found a way to remove this extra stage, at the cost of some padding, increasing a bit the OVA size as a result. But as it's twice as fast, it's a no brainer. With this release, you can now enjoy faster OVA generation! ## 💾 Backup resiliency improved As usual in software, it's relatively easy to write something in the "best case", when everything is working around you. Sadly, there's always a problem happening somewhere (it might be DNS, network, hardware or firmware related. Even if it's ~~always~~ often DNS). Anyway, our work on improving the whole backup experience is never finished. This time, we fixed/improved various parts of the backup (the "block", not the VHD one), mostly to be more resilient when something is going wrong on your backup storage. We worked on 3 different parts: - **Merge process refactoring:** we made it easier to test and maintain - **Fixing an edge case:** sometimes, block folders weren't created. - **Allowing merge restart:** if an issue happened during the rename/deletion phase (at the end of the merge process), we allowed a merge process restart to resume it on the next job iteration. It's also a quality of life improvement, since issues on the previous run will be auto-corrected automatically! ## 🐘 We are on Mastodon! Maybe you've heard about the Twitter drama. Since there's an uncertain future for this non-free and centralized platform, we used this opportunity to **deploy our own Mastodon instance**. Obviously, inside an XCP-ng VM running in our production, managed and backed up by Xen Orchestra 😉 You can find our server at [https://social.vates.tech](https://social.vates.tech/?ref=xen-orchestra.com) with our various accounts: - XCP-ng: [https://social.vates.tech/@xcpng](https://social.vates.tech/@xcpng?ref=xen-orchestra.com) - Xen Orchestra: [https://social.vates.tech/@xenorchestra](https://social.vates.tech/@xenorchestra?ref=xen-orchestra.com) - Vates: [https://social.vates.tech/@vates](https://social.vates.tech/@vates?ref=xen-orchestra.com) And myself (shameless plug): [https://social.vates.tech/@olivier](https://social.vates.tech/@olivier?ref=xen-orchestra.com) ![](https://xen-orchestra.com/blog/content/images/2022/11/Mastodon_Logotype_-Simple-.svg) We'll continue to post on Twitter, but likely only sending links toward our "toots" ("tweets" in Mastodon language). We love the decentralized and open source approach offered by this platform! ### Warm migration with XO URL: https://xen-orchestra.com/blog/warm-migration-with-xen-orchestra/ Last updated: 2022-11-29T11:40:19.000Z This is a cool feature (pun intended) coming in our next release, which is tomorrow! I wanted to give you a preview on this exciting feature, and since it's a bit long to explain, having a dedicated article on it was the right thing to do. First, let's give some context on why this feature was born. Imagine you have a first datacenter where all your VMs are running on Intel Xeon CPUs, and some of those VMs have pretty large disks. Now you want to migrate those to a new datacenter running on AMD EPYC CPUs. There's 3 options: 1. **Live migrate**: won't work in this situation, CPUs are different vendors. 2. **Shutdown the VM**: you need to shutdown the VM, then "cold" migrate to the destination. **Pro**: relatively simple. **Con**: your VM will be offline for a while. 3. **Create a continuous replication job**:replicate the VM to the destination while it's running, shutdown, re-replicate the delta, and boot on destination. Then remove the source. **Pro**: downtime reduced, pretty solid way to migrate. **Con**: complicated process. Even if it's complicated, **option 3 is the most reasonable one**. So we wanted to offer you this option in a simple manner, with the same simplicity of option 2\. Best of both worlds, right? So **automation is key**. When you click on the "Warm migration" button, you'll select the destination SR and if you want to keep the VM on the old source: ![](https://xen-orchestra.com/blog/content/images/2022/11/202231167-39cb6f2b-f354-4e5a-a513-d002d072ea7a.png) ![](https://xen-orchestra.com/blog/content/images/2022/11/203995394-4c4c9cde-6334-40e8-bff2-f64866721537.png) ## Under the hood As soon you click OK, Xen Orchestra **will do all of that automatically.** Here are the details for each step happening with our previous example, on a rather large VM with a 2TiB disk, filled with 1TiB of actual data: ![](https://xen-orchestra.com/blog/content/images/2022/11/Warm-migration-step1-1.png) **You have 2 different hosts with different CPU vendors, but you want to move the VM from one place to the other.** ![](https://xen-orchestra.com/blog/content/images/2022/11/Warm-migration-step2-1.png) **Just after you clicked the "Warm migration" button, the process will kick-in. First, a snapshot is done on the source VM, and entirely transferred to the "replicated" VM. This step is the longest one, but it happens while the original VM is running. No visible impact, despite, in this example, we have to move 1TiB worth of data.** ![](https://xen-orchestra.com/blog/content/images/2022/11/Warm-migration-step3-1.png) **The critical step: source VM is shutdown, a new snapshot is done and we transfer the differential between the initial and the latest snapshot. In this example, there's only 3GiB to replicate, so the downtime will be minimal (few minutes tops).** ![](https://xen-orchestra.com/blog/content/images/2022/11/Warm-migration-step4.png) **As soon this minimal diff is sent, we will boot the destination VM and remove the source one (if you tick "boot after migration" and "remove source VM after migration").** And that's it! With a simple click of a button, we did all the heavy lifting for you. Your **downtime is greatly reduced** and you can do this kind of migration in ANY CASE, regardless of the CPU model on destination. It's very safe. ## Various use cases Migrating from one CPU type to another isn't the only use case for this feature. For example, we have customers coming from XenServer, sometimes pretty old versions. Live migration might work, but sometimes it's risky. With the warm migration, **we support risk-less migrations down from XenServer 6.5!** It's also useful when you are migrating to a completely different environment, with a different network architecture, and you know that a live migration will cause more problems than it will solve. And there's probably even more use cases than we thought! Finally, we also decided to stay on the safe side: we made the choice to NOT toggle "start on destination" and "remove on source" by default, so it won't be destructive if you click on this migration without thinking about the implications. ### XO Proxy: a concrete guide URL: https://xen-orchestra.com/blog/xo-proxy-a-concrete-guide/ Last updated: 2023-10-24T06:35:06.000Z If your infrastructure spans between multiple sites, and you're not dealing with any tunnels or extended L2 networking, proxies are great to connect everything together, regardless of your location and networks, as long as you have a basic Internet access. Let's explore a very concrete case on how we use these proxies to **manage, monitor and replicate our production infrastructure to any other site**, hundreds of kilometers away from a production Datacenter. **All of that, without any overlay networking tools** like Zerotier, Tailscale and such. ## 🥽 Best practices You don't want to expose any XCP-ng host to the Internet. At best, you only want to have Xen Orchestra visible - ideally with TOTP enabled- or your proxy, behind a firewall, NAT and/or a security gateway. Nothing else. Security wise, it's the reasonable way to go, but the other perk is to avoid consuming any public IPv4 for your XCP-ng hosts, nor even for your XOA or XO proxies! 👷 Using another site provides great protection against natural or industrial disasters, even in the case of having your main Datacenter in a warzone (which is sadly not impossible as we've seen recently). **Because you don't need any specific link or network configuration or overlay between your sites, it means you can rely on proxies with a very minimal investment.** We'll see how to achieve that. First, let's check what we already have, and then we'll deploy the proxy. ## 🌎 Multi-sites setup Assuming you already have something like this on your main site: ![](https://xen-orchestra.com/blog/content/images/2022/11/arch0.png) Now, let's imagine you'd like to manage your other site, with "only" Internet in the middle, while: - Still using your central XOA to manage everything (regardless of firewall NAT, having access to VM consoles, stats and so on). - Having the ability to use continuous replication in case you lose your main site. - And anything else you can already do inside your main site without exposing your hosts outside **while keeping everything behind a firewall**. This is possible by deploying an XO proxy on the other site, like this: ![](https://xen-orchestra.com/blog/content/images/2022/11/arch1-1.png) The only common network is the Internet. And without -at any time- having to expose your "remote" hosts to your main XOA. 🌍 **It scales:** obviously, you can do the same thing for any number of extra sites, and have dozens of proxies deployed all around the world. ## 1️⃣ Deploy the proxy remotely This is the usual chicken and egg problem 🐣: how do you deploy the proxy easily if you don't have external API access to the existing hosts? Indeed, in XOA, there's the "usual"/simple way to deploy a proxy: ![](https://xen-orchestra.com/blog/content/images/2022/11/image-2.png) However, this simple way to deploy the proxy requires an existing connection to the destination XCP-ng host to deploy it. So what's the alternative to deploy the proxy when you can't reach it directly? ### 👨‍💻 Deploy from a terminal Enter our "**proxy deploy script**". Similar to our one-liner to deploy an XOA from a shell on your XCP-ng, you will use this to deploy your new proxy. Just SSH to your host and run : ``` bash -c "$(wget -qO- https://xoa.io/proxy/deploy)" ``` From there, just follow the prompt (this will deploy the proxy on the configured default SR): ```bash [myXCPng-host]# bash -c "$(wget -qO- http://xoa.io/proxy/deploy)" Welcome to the XO Proxy auto-deploy script! Network settings: IP address? [dhcp] Your XO Proxy will be started using DHCP Your Xen Orchestra account (email)? myname@example.org Your Xen Orchestra account password? (hidden) Importing XO Proxy VM... Booting XO Proxy VM... Waiting for your XO Proxy to be ready… Your XO Proxy IP address is: 192.168.2.20 XO Proxy UUID: 8803d4c7-ca48-4a37-9ac5-84ccd3ae3c65 XO Proxy Token: H9WwSAeoTEENI8ddxeosejpz7L8DZLvLJafuncyh ``` And that's it: the proxy is deployed and running on your host. Note that you have multiple pieces of information available when it's done: the local IP address, the XO Proxy UUID and its token. **You need to keep the token and the UUID for the next steps,** they are needed to add the proxy in XO. ### 🧱 Behind your firewall You can NAT/firewall your proxy to expose it indirectly to the Internet, which is very simple to do. In our example, we decided that the proxy will be available only at `203.0.113.23:4443` (via our public IP on the firewall) and NATed internally to `192.168.2.20:443`. It doesn't matter for our proxy system, it will handle/redirect everything correctly to the main XOA. ## 2️⃣ Add the proxy in XOA ⏭️ The ability to add an existing proxy from the web UI will be available in the next release. So this will be even easier! Now, we want to "attach" this existing proxy to our main XOA. To do that, you can do it from the UI or the CLI of XOA. ### From the UI Go in the left menu, "Proxies", then "Register a proxy": ![](https://xen-orchestra.com/blog/content/images/2023/10/image.png) And fill with the previous information: ![](https://xen-orchestra.com/blog/content/images/2023/10/image-1.png) ### From the CLI (alternative) First, install the CLI and register it: ```bash [xoa@xoa]# sudo npm i -g xo-cli [xoa@xoa]# xo-cli --register http://localhost xoa Password: ******** Successfully logged with xoa [xoa@xoa]# ``` Next step, add the proxy: ``` [xoa@xoa]# xo-cli proxy.register authenticationToken=H9WwSAeoTEENI8ddxeosejpz7L8DZLvLJafuncyh address=203.0.113.23:4443 vmUuid=8803d4c7-ca48-4a37-9ac5-84ccd3ae3c65 36aa8061-525d-4580-8574-9007f7cae3d8 ``` That's it! Now the proxy is visible right in your XOA: ![](https://xen-orchestra.com/blog/content/images/2022/11/Capture-d--cran-du-2022-11-02-15-51-51.png) ## 3️⃣ Use the proxy Now you can enjoy all the benefits of the proxy, like doing backups on the remote site on a "local" backup repository (backup traffic will stay on the remote site) but also use it as a real XAPI proxy to manage the whole site from your main XOA, without direct access to the host. ### 🔗 Add a pool via the proxy Go into your Settings > Server page, and add the host from your main XOA. Here is the catch: use the URL of your proxy. To know that URL, go into the XO Proxy view, open the menu and click on the "Copy proxy URL": ![](https://xen-orchestra.com/blog/content/images/2022/11/image.png) You will paste this URL when you'll add the server in Settings/server: ![](https://xen-orchestra.com/blog/content/images/2022/11/Capture-d--cran-du-2022-11-02-16-45-35.png) - **Label**: whatever human readable label you'd like. Could be "Replication site" for example. - **Address**: the local address inside the remote site. For example, if your XCP-ng primary host is using `192.168.2.10` on that site, that's what you need to add there. **Remember it's from the proxy point of view!** - **Username**/**password**: your XCP-ng credentials. - **HTTP proxy URL**: paste the URL from the "Copy proxy URL". In our example, it should be something like: `https://@203.0.113.23:4443/` **And that's it! Now you should see your configured pool from your main XOA.** ### ♊ Continuous Replication to the remote site In order to do more than just manage your pools and hosts all over the world in a secure manner, we also added the capability for the main XOA to be smarter and detect when you use a continuous replication job, **flowing the data automatically through the right proxy.** So now, configuring a continuous replication job between sites with the proxy in the middle is **entirely transparent**. As any other CR job, just select the destination storage repository (on any host at the remote site), because it's now visible on your main XOA. And finally, on the next run, the traffic will flow from "source" XCP-ng to XOA, then to the proxy and finally the destination XCP-ng host on the remote site. You can also do the opposite: replicate VMs from site B to your main site. Or any other site all around the world! ### 💾 Configure a backup job via the proxy At the "Backup repository" creation screen, you can specify to which proxy it will make the connection and transfer data (in the "Proxy selector"): ![](https://xen-orchestra.com/blog/content/images/2022/11/image-1.png) Like for the XCP-ng API proxy, you need to fill the information from the proxy point of view (so the local/private IP of your NAS on that remote site), since the proxy will connect to it, and not your main XOA. ## Conclusion Thanks to XO proxies, it's entirely possible to use XCP-ng hosts at any number of sites while keeping a single "central" XOA to manage them all. This is also a powerful way to scale horizontally for all your backups on each site. And the most important thing: the whole setup is entirely secure. All the traffic is encrypted and no hosts are exposed/visible on Internet. **Without relying on any 3rd party "overlay network" tools.** ### Xen Orchestra 5.76 URL: https://xen-orchestra.com/blog/xen-orchestra-5-76/ Last updated: 2022-11-29T09:37:36.000Z Happy Halloween! 🎃 This month, many new features and improvements are on the menu. Is it a monster release? We'll leave it up to you to judge 👻 ## 🚅 Faster backups (preview) Almost one year ago, we started to work on massive improvements for our backup system. First, the S3 compatibility with our new Backup Repository (BR) format, storing 2MiB files instead of one big VHD. Thanks to this, we managed to provide ultra-fast backup merges, native compression, and encryption. But also, in the following months: a new tiering system, deduplication, instant restore, immutability and much more (stay tuned!) There's also another opportunity given by this kind of "2MiB file splitting": fetching blocks in parallel. However, parallel fetching is not possible with the default VHD export capability. So what? Well, we can use something else: NBD. ### NBD: Network Block Device NBD is a network protocol that can be used to expose a block device (ie your VM disk) to another machine (your Xen Orchestra appliance). See the [Wikipedia page for more details](https://en.wikipedia.org/wiki/Network%5Fblock%5Fdevice?ref=xen-orchestra.com). It's not new, but it's entirely open and documented, plus also available inside XenServer and XCP-ng. It must be enabled manually (see below for a how-to if you want to test the feature). What's nice with NBD? Well, you can access any block on the device, and read them in parallel if you like. Interesting, isn't it? ### Targeting the right blocks However, having the whole drive visible in blocks is useless if you want to do a delta backup. That's why we'll still rely on the VHD format, just to take a look at the Block Allocation Table (BAT), to discover modified blocks. In other words, an exposed VHD will become useful only to read what changed, and then we'll use the NBD handler to download the blocks we need. And we'll be doing this while fetching data in parallel (downloading up to 16 different blocks at the same time!) ### Immediate benefits Our initial tests are showing multiple benefits. First, the **max backup speed is higher**. Indeed, parallelism is providing a nice boost on transfer! We are also seeing a **reduced load on the Dom0** while doing the export (vs the usual VHD method). Obviously, this depends a lot on your setup, and we'll provide more benchmarks in the future. ### Other opportunities and next steps The other perk with NBD download is the ability to read a block device the way you want (at any position). This means that we could provide a way to resume interrupted backups! This is a big deal when you have a failure on a large transfer. In the future, we'd like to add other improvements: - Display in the UI if your backup is done using this NBD option or not - Making the block size configurable: it's 2MiB today, but early benchmarks are showing improved speed on smaller blocks, depending on various factors: that's why the ability to configure the block size will allow you to find the sweet spot for your very own use case. ### How to test it So, you want to take a look yourself? You need to enable NBD on your pool first (in fact, on a pool network). You can [read this documentation](https://github.com/citrix/xenserver-changed-block-tracking-guide/blob/master/docs/enabling-nbd.md?ref=xen-orchestra.com) for more details, but in short: ``` xe network-param-add param-name=purpose param-key=nbd uuid= ``` This will enable NBD on your targeted network, where XO is pulling the backups. **XO is using TLS by default, so the transfer is secure.** In case you want to benchmark the difference, you can also disable TLS with "insecure NBD", but it's obviously not recommended for production usage. ⚠️ Only enable NBD on the network used by Xen Orchestra! No need to expose more things elsewhere. All your virtual interfaces on this network will be visible with a "lock" in the new "NBD" row, eg from a VM network view: ![](https://xen-orchestra.com/blog/content/images/2022/10/198310452-a99f2f29-9ff3-4278-8da1-4d26e97edd8a.png) Now you can edit your XO `config.toml` file (near the end of it) with: ```toml [backups] useNbd = true ``` And don't forget to restart `xo-server` after that! **Remember that it works ONLY with a remote (Backup Repository) configured with "multiple data blocks".** That's it, you are ready to test it! ![](https://xen-orchestra.com/blog/content/images/2022/10/Vates_XO-Badge-1.png) ## ☁️ Cloud config drive removal after VM creation When using cloud-init config, we create a small drive that contains the configuration you defined in the VM creation screen. For most users, this disk is no longer useful after the config is actually done and the VM boots for the first time. So we simply added an option allowing the user to remove that disk automatically after the VM creation. 💡 VM boot detection to remove the Cloud config drive is done thanks to the guest tools. Remember to **always install VM tools** in your templates, otherwise this feature won't work! ## 🔐 Improved backup encryption After our initial release of backup encryption, we replaced the original encryption algorithm `AES-256-CBC` by `AES-256-GCM` instead. This was needed to avoid a potential padding oracle attack, targeting the "CBC" part. You can learn more about the [Padding Oracle attack article on Wikipedia](https://en.wikipedia.org/wiki/Padding%5Foracle%5Fattack?ref=xen-orchestra.com). ![](https://xen-orchestra.com/blog/content/images/2022/10/CBC_decryption.svg) Note that `AES-256-GCM` is -of course- not affected by this kind of attacks. 💪 This security issue has been reported by **Tom W.** (Sr Security Engineer) working at a major video game publisher security team. Thank you Tom! ### Security process Through this example, we wanted to remind you we [have a security policy in place](https://github.com/vatesfr/xen-orchestra/blob/master/SECURITY.md?ref=xen-orchestra.com) so anyone can make a report. All requests are investigated very seriously. We also have a similar process for XCP-ng, see [https://xcp-ng.org/docs/security.html](https://xcp-ng.org/docs/security.html?ref=xen-orchestra.com#security) ## ↔️ Evolution of our cache system for VM restore We improved our system to fetch existing VM backup information, in order to display everything fast inside your Xen Orchestra web UI. And it's a lot faster, see for yourself: ![](https://xen-orchestra.com/blog/content/images/2022/10/benchcache-1.png) Time to list VMs to restore, before and after cache (lower is better). You can read more here: [Evolution of our cache system for VM restoreLearn how we improved our system to fetch existing VM backup information, in order to display everything fast inside your Xen Orchestra web UI.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2022/10/squaresmallxo-1.png)Xen Orchestra NewsOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2022/10/cacheperf.jpg)](https://xen-orchestra.com/blog/evolution-of-our-cache-system-for-vm-restore/) ## 🔭 XO Lite This month, and as promised, we delivered some new components and views. First, you now have a dedicated "settings page" with language selection, dark/light mode selection and various information: ![](https://xen-orchestra.com/blog/content/images/2022/10/Capture_2022-10-28_09_54_37.png) We are also making progress on the Dashboard page for your pool, adding CPU usage info for your hosts and your VMs: ![](https://xen-orchestra.com/blog/content/images/2022/10/Capture_2022-10-28_09_54_00.png) ☝️ This XO Lite latest build is already available for you to test. [Read our previous blogpost](https://xen-orchestra.com/blog/xen-orchestra-5-74/#%F0%9F%8F%81-xo-lite-alpha-one) to learn how to deploy it. If it's already deployed, then… just refresh! ### Coming soon The next steps on XO Lite are: - Providing actions for all your VMs (start, shutdown, reboot, snapshot…) - Adding resource graphs for CPU, memory and so on. Our components are almost done! ![](https://xen-orchestra.com/blog/content/images/2022/10/Capture_2022-10-28_10_09_56.png) ## 🎫 XCP-ng support license binding Until now, it wasn't convenient to know which hosts were being [protected by our XCP-ng Pro Support](https://xcp-ng.com/?ref=xen-orchestra.com). That's why we decided to allow our customers to assign their existing (or future) XCP-ng support licenses to the host/pool of their choice, directly from the Xen Orchestra web UI. Then, to make it easier, you can **assign support to an entire pool automatically:** ![](https://xen-orchestra.com/blog/content/images/2022/10/198677679-7d244ee2-5427-4c87-a49b-76029c915d14.png) You can see here, with a green "file icon", pools with a valid pro support contract: ![](https://xen-orchestra.com/blog/content/images/2022/10/198677695-5e6d3afe-a4fe-465f-856e-3809c3d2d2f4.png) It's also possible to **move a license from one host to another** (in case of machine replacement for example), in just a few clicks. The whole system was meant to help you to track your supported hosts, not to be in your way. This is also a good opportunity to remind you about our vision on our pro support: [My vision for Open Source pro supportEven if everyone seems to agree on what “pro support” means, in fact it’s not something I imagined. Discover why.![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng NewsOlivier Lambert![](https://xcp-ng.org/blog/content/images/2022/05/xcp-ng-pro-support.jpg)](https://xcp-ng.org/blog/2022/05/06/my-vision-for-open-source-pro-support/?ref=xen-orchestra.com) ## 🕒 XOA Check: adding NTP sync "XOA Check" is a feature available inside our turkey Xen Orchestra appliance. We already cover various checks to be sure your XOA is running in an optimal fashion, but sometimes we add another verification when we discover a problem. ![](https://xen-orchestra.com/blog/content/images/2022/10/Capture-d--cran-du-2022-10-28-17-55-24.png) In this case, it was an issue related to our Time-based One Time Password (TOTP) feature in Xen Orchestra: for our customer, it simply didn't work. In fact, it wasn't XOA's fault but it was very hard and subtle problem. ![](https://xen-orchestra.com/blog/content/images/2022/10/Capture-d--cran-du-2022-10-28-17-56-32.png) In your user zone, you can enable OTP. It works with various providers, like Authy for example. We realized then that the XOA NTP client was enabled, but unable to reach any public NTP servers (and no other NTP server was configured). Since TOTP is a time sensitive algorithm, this created the issue. That's why we decided to consider NTP important enough to be checked in our "checklist". ## 🗞️ XO logs to external syslog Since this release, all your XO logs can now be sent to an external syslog server! This is very useful when you want to centralize all your logs in one place, so you can easily analyze them, without having to connect to all your machines one by one. It's also a great plus to find common patterns and correlation for some events, helping you greatly to debug some issues. Or even intrusions, since the logs are sent somewhere else, they can be removed locally but they will stay on your destination machine! In order to enable it, you just have to add this to your configuration file: ```toml [logs.transport.syslog] target = 'tcp://syslog.example.org:514' ``` In short, all the logs you can see from `journalctl -u xo-server` will be forwarded to your central syslog server. This will work with any syslog server, like Rsyslog, Splunk, Logstash, Graylog… You name it! ### Evolution of our cache system for VM restore URL: https://xen-orchestra.com/blog/evolution-of-our-cache-system-for-vm-restore/ Last updated: 2022-10-21T08:42:44.000Z In any software, there's always a lot more happening behind the scenes than you can actually see. And there's also a time when you need to optimize internal things to improve visible performance. Today, we'll show you how we managed to drastically reduce the loading time from your "Restore backup" view, even in cases where you have a lot of VM backups stored. ## 💾 Backup Repository A backup repository ("BR", also called "remote" in Xen Orchestra) is the place where we store all the VM backups you perform (full/standard or delta). Usually, this repository is a network share, likely behind NFS or SMB protocol. One of our goals with Xen Orchestra was the ability to **keep the backup data AND metadata fully self-contained** and separate from your Xen Orchestra. This way, if you even lose your Xen Orchestra VM and/or even all your physical XCP-ng hosts, you can still restore everything by deploying a new XO on your fresh hardware from scratch, find all your existing backups on the BR, restore and get back on your feet! 💡 What we call "metadata" is a JSON file containing all records of your VM (name, description and so on). Xen Orchestra is saving both the data (VM disks) and its metadata with it. So, what's the issue then ? Well, it starts to be slow to parse and read when the number of metadata files is big. Let's see why. ## ↔️ Query all available backups When you enter into the "Backup" view, then the "Restore" tab, XO will list for you all the available backups to restore (for each VM, with the number of available backups per VM). Users with medium/large sized infrastructure started to have hundreds (and even more sometimes) backups. And we discovered it took time to load that screen. ### Without any cache This is what we had before XOA 5.71: when we listed all available backups, the requests behind the scenes were pretty simple: - read the content of the `xo-vm-backups/` folder on all available Backup Repositories (BR) - then, inside each BR, read all subfolders, `xo-vm-backups/*` - finally, read all the metadata info of each backup for each VM, `xo-vm-backups/*/*.json` Even if those JSON files aren't big in size, remember that the BR is stored in a network share. Each file to read will take a network roundtrip: even a latency of 10ms, multiplied by the number of VMs and each backup (retention), you start to have more than a few seconds to load everything. And clearly, this had to happen each time you were navigating to this restore view! As you can see, it doesn't scale well. ![](https://xen-orchestra.com/blog/content/images/2022/10/Vates_XO-Hubble-only-2.png) ### Adding a first cache system That's why we decided to add a new cache system, to avoid unnecessary requests on files that weren't modified: - VM cache was generated on demand when listing the backups - VM cache was deleted on backup creation/deletion In order to avoid listing and loading a LOT of different files (read folder + read file), we decided to add a "static" file with an obvious path and name so we don't have to list a folder to find it: `xo-vm-backups/*/cache.json.gz`. As you can see, the JSON is also compressed to reduce the amount of data stored AND going over the network, adding another benefit to the overall improvement. And it was fine… for a while. Our main target, medium/large sized infrastructure users, had a lot of backup creation and deletion activity invalidating the cache very often, making it almost useless to them. And at this point, we decided to improve further that cache system. ### Going even faster This new cache implementation is available since XO 5.75\. This time, we decide to… update the cache directly! (at each backup creation/deletion) It might sound subtle, but in fact, this changed everything: the new cache is always available and up-to-date. Obviously, we had to also get some cache coherency checks: when a backup is finished, we have a "clean VM" set of instructions we use to verify if the cache is consistent or not. If not, then we remove it. Luckily, there's no good reason for this to happen! ## 🎯 Result and conclusion To sum up, the new cache system is a lot more efficient, but allows direct modification (ie: no invalidation in a normal run), serving compressed files at a predictable path. The result? Let's compare before and after the cache, on a modest backup repository: 22x VMs with a average retention around 45\. This already means 1000 JSON files to list, read and parse. ![](https://xen-orchestra.com/blog/content/images/2022/10/benchcache.png) Time to list VMs to restore, before and after cache (lower is better). It's pretty simple: we improved the performance by dividing the load time by 8\. Not bad 😎 And remember: this is only on a relatively small backup repository, on a pretty fast network. The gap is even bigger on larger and/or slower infrastructures. > We hope you like this kind of "behind the scenes" content, let us know about your reaction on [our community forum!](https://xcp-ng.org/forum/category/12/xen-orchestra?ref=xen-orchestra.com) ### Xen Orchestra 5.75 URL: https://xen-orchestra.com/blog/xen-orchestra-5-75/ Last updated: 2022-10-01T00:25:42.000Z Time for Xen Orchestra 5.75! Multiple improvements related to backups (file level restore for S3-like backups!), but there's also a lot of other things related to the whole stack. Enjoy the read. Video version of this blog post: ## 🗃️ File level restore on S3 backup Our new mode of backup ("split" VHD where each block is a small file) is now compatible with the file level restore feature. Not only can you use file level restore on an **S3 backup** but also while using **backup encryption.** It also works using any NFS/SMB backup repository when you enable "split VHD" mode. For those who are wondering, we rely on a custom Fuse driver to be compatible with our new format. It works very well! ## 📸 Webhooks for snapshots \[beta\] ⚠️ This feature is currently *unstable* and might change in the future, depending on users feedback. Use it with caution! It's now possible to notify a VM via an HTTP request before a snapshot. Xen Orchestra will wait for an answer before starting the actual snapshot. We believe there's a lot of use cases for this feature, which is fully customizable by users: - Flush/dump your database before a backup job - Empty the trash bin or /tmp before the snapshot to avoid saving useless data - Shutdown/restart a service - Disconnect your users - Purge sensitive data... The complete documentation to use this new feature is available, for now, on our Github repository: [xen-orchestra/vm-sync-hook.md at master · vatesfr/xen-orchestraThe global orchestration solution to manage and backup XCP-ng and Citrix Hypervisor. - xen-orchestra/vm-sync-hook.md at master · vatesfr/xen-orchestra![](https://github.com/fluidicon.png)GitHubvatesfr![](https://opengraph.githubassets.com/bcbc786d3af17bbe92dffbe6db1a513b8d315eda4ed61b636db1099498eec665/vatesfr/xen-orchestra)](https://github.com/vatesfr/xen-orchestra/blob/master/%40xen-orchestra/xapi/docs/vm-sync-hook.md?ref=xen-orchestra.com) ## 📂 Allow NFS subdir on SR creation We've been asked about this for a while now, and we managed to finally improve it! When creating a VM storage repository in Xen Orchestra, you can now point directly to a subdirectory, without needing to export it from NFS: ![](https://xen-orchestra.com/blog/content/images/2022/09/nfs-subdir.png) ## 📖 Xen Summit feedback Our XCP-ng team was at the *Xen Developer & Design Summit* last week. It's an important yearly event in the Xen World and it helps us to define the future roadmap for both the XCP-ng hypervisor and Xen Orchestra. Olivier, our CEO wrote a [feedback blogpost](https://xcp-ng.org/blog/2022/09/24/xen-summit-2022-a-recap/?ref=xen-orchestra.com) about this year's event with some crunchy news: [Xen Summit 2022: a recapDon’t miss our quick feedback on the latest Xen Developer and design Summit!![](https://xcp-ng.org/blog/content/images/size/w256h256/2022/09/SVG-_XCPNG---Badge.png)XCP-ng newsOlivier Lambert![](https://xcp-ng.org/blog/content/images/2022/09/xensummit22.jpg)](https://xcp-ng.org/blog/2022/09/24/xen-summit-2022-a-recap/?ref=xen-orchestra.com) ## 📅 Open Source Summit Experience Another important upcoming event for our team is the [Open Source Experience](https://www.opensource-experience.com/en/?ref=xen-orchestra.com), on 08 and 09 November in Paris. Like last year, we will be present with a booth at the event. In addition to meeting us there, I, Marc-André (CMO), will also have the opportunity to talk about virtual infrastructure sovereignty during a conference. [![](https://xen-orchestra.com/blog/content/images/2022/09/OSX-2022-fond-1.png)](https://vates.fr/blog/open-source-experience-2022/?ref=xen-orchestra.com) [Open Source Experience 2022For its second edition, the Open Source Experience is back on September 8th and 9th at the Palais des Congés in Paris and we are very happy to participate again this year.![](https://vates.fr/blog/content/images/size/w256h256/2022/07/logo64.png)Vates NewsMarc-André Pezin![](https://vates.fr/blog/content/images/2022/09/OSX-2022-fond-1.png)](https://vates.fr/blog/open-source-experience-2022/?ref=xen-orchestra.com) ## 🔭 XO Lite components We are currently working on multiple components for Xen Orchestra Lite and XO 6\. Specifically, the selectors, modal windows and radio buttons. Here is a preview of what you can except in the next build (in the next weeks!): ![](https://xen-orchestra.com/blog/content/images/2022/09/Capture-2022-09-14-at-18.34.10--1-.gif) ![](https://xen-orchestra.com/blog/content/images/2022/09/Capture-2022-09-14-at-18.33.37--1-.gif) ![](https://xen-orchestra.com/blog/content/images/2022/09/demo-2.gif) Obviously, this is only a part of what's coming, so stay tuned on the XO Lite front! ## ## ### Xen Orchestra 5.74 URL: https://xen-orchestra.com/blog/xen-orchestra-5-74/ Last updated: 2022-09-05T11:00:14.000Z ## 🔒 Backup Encryption Backup encryption is a long awaited feature, now made possible as we added a "block mode" to store your data. Initially, this "block mode" was created to work with any S3-capable software: however, it's also very flexible, allowing us to quickly add new features we couldn't with plain VHD files, like compression -enabled by default already-, encryption and even deduplication in the future. ⚠️ Backup encryption is currently in **preview mode** for people running on the "latest" XOA channel. You should NOT use it as the main source of backup for your infrastructure until it lands on "stable". Test it, but remember to use it at your own risk! Anyway, it's now possible to create an encrypted backup repository in Xen Orchestra: this way, you can backup your VM data in any location, even untrustworthy ones, for example without physical access control, or a lack of secure network and so on. ### How it works When you create your encrypted backup repository, you'll be asked to enter a passphrase. This passphrase is used to encrypt your VM data, so don't lose it or don't forget it. The passphrase is obviously NOT stored on the backup repository, only in your XOA. In the near future, we are planning to implement the ability to store your passphrase directly on your Xen Orchestra account in order to allow a recovery mechanism even if you both remove your XOA and forgot the passphrase. ☝️ Backup encryption works at the backup repository level. You must create a new "remote" that will be encrypted. It's not possible for encrypted and non-encrypted data to coexist on the exact same backup repository. ## 🏁 XO Lite alpha one We announced a few weeks ago that we were switching the [framework used for the development of XO Lite in order to use VueJS](https://xen-orchestra.com/blog/xo-6-whats-on-the-horizon/). We are happy to announce that we have made great progress on our new implementation and we've already caught up to the React version we started last year. This new XO Lite version is available for you to try and we are really eager to get your feedback on it. How to deploy XO Lite if you don't have it yet? Very easy: ```Bash wget https://lite.xen-orchestra.com/dist/ -O /opt/xensource/www/xolite.html ``` Then, pay a visit to your XCP-ng host with the URL: `https:///xolite.html` You should see that: ![](https://xen-orchestra.com/blog/content/images/2022/08/xolitelogin.png) We are intending to update this version on a regular basis so you will be able to test all the new features coming in the next releases. Stay tuned! 💡 If you already had the React version deploy, just force refresh the page and you'll enjoy the new VueJS version! ## 🏷️ HA label added on SR As a QoL feature, we added an HA label on SRs that are used for High Availability in your pool. This way, you can now see which SR you don't want to mess around too much with when working on your pool. ![](https://xen-orchestra.com/blog/content/images/2022/08/label-ha.png) ## ⚕️ Detect VDI with invalid parent VHD We added a new view in the health dashboard: **Unhealthy VDIs**. ![](https://xen-orchestra.com/blog/content/images/2022/08/unhealthy-vhd.png) During various actions, such as snapshot creation for example, the XAPI creates VHD chains as a way to link disks one to another. Sometimes, some disks fail to be linked to its parents disks - which can be a sign of storage issues. This view should help you identify such problems before they trigger a bigger problem on your storage. ## ✏️ New graphic Identity As you know, we recently reworked the graphic Identify of our company: [Vates](https://vates.fr/blog/vates-is-10-years-old/?ref=xen-orchestra.com). In the interests of continuity, we also decided to rework the identities of our products in order to homogenize our overall brand identity. Marc, our marketing manager wrote a complete blogpost on the topic, aiming to explain the context and motivation behind that big graphic rework. And yes, the new logos are displayed, so don't miss it 😮 [Our new graphic identityWe want to share with you some progress about the new graphic identity we are building for our company and provide some deeper explanation about why we are doing this big rework.![](https://vates.fr/blog/content/images/size/w256h256/2022/07/logo64.png)Vates NewsMarc-André Pezin![](https://vates.fr/blog/content/images/2022/08/Vates_Fond_Illustre.png)](https://vates.fr/blog/our-new-graphic-identity/?ref=xen-orchestra.com) ### Xen Orchestra 5.73 URL: https://xen-orchestra.com/blog/xen-orchestra-5-73/ Last updated: 2022-07-29T14:25:29.000Z The end of the month arrives and with it, a new release of Xen Orchestra. Despite we are in July (which is usually quieter), we managed to deliver two new features. Moreover, our teams take advantage of this holiday period to fix bugs and lay the groundwork for big new features. ## 🔒 Integrated Let's Encrypt support For people who want to publicly expose Xen Orchestra, having a valid HTTPS certificate is vital. For a long time now, you can configure Xen Orchestra to deploy your own certificates (self-signed or not). However for some of our users, they wanted to enjoy the flexibility and the simplicity of [Let's Encrypt certificates](https://letsencrypt.org/?ref=xen-orchestra.com). This brings free valid HTTPS certificates without even having to renew them, because **Xen Orchestra will handle that for you!** To configure your Xen Orchestra Appliance with Let's Encrypt, it's very simple: 1. Add an entry `autoCert = true` and an entry `acmeDomain = example.org` in the HTTPS section of your [XO configuration file](https://xen-orchestra.com/docs/configuration.html?ref=xen-orchestra.com) 2. Load `https://example.org` in your browser 3. After a few seconds, the certificate will be auto generated and installed More complete documentation is available [at this page](https://github.com/vatesfr/xen-orchestra/blob/master/%40xen-orchestra/mixins/docs/SslCertificate.md?ref=xen-orchestra.com). ☝️ This new feature will also auto renew your certificate 30 days before expiration! And unlike "normal" certificates, no need to restart `xo-server` to enjoy your renewed certificate! ![](https://xen-orchestra.com/blog/content/images/2022/07/letsencrypt.png) ## 📡 REST API: ISO import Previously, disks could only be imported in the VHD format, this release brings the `raw` format support which is especially useful to upload new ISOs: ```sh curl \ -X POST \ -b authenticationToken=KQxQdm2vMiv7jBIK0hgkmgxKzemd8wSJ7ugFGKFkTbs \ -T alpine-linux.iso \ 'https://xo.example.org/rest/v0/srs/5abb8fcc-98f9-49e2-9164-5259c8a5fe89/vdis?raw&name_label=alpine-linux' \ | cat ``` The [documentation](https://xen-orchestra.com/docs/restapi.html?ref=xen-orchestra.com#vdi-import) has been updated to reflect this new feature. ## 🔭 XO Lite As you may have noticed, the development of XO Lite has not been very fast the last few months. Recently, we welcomed a new full-time developer and a lot of discussions have been taking place around XO Lite. From these exchanges, the choice was made to restart the project from scratch, on a new technological basis and we therefore abandoned the *Webpack + React* stack in favor of *Vite + Vue*. In addition to the intrinsic advantages of the framework (lightness, performance, documentation, modularity, Single File Components, Composition API…), we also have the advantage of having a developer with several years of experience in *Vue* as well as a team enthusiastic to embrace this pivot. Since we have a great web designer, we also abandoned the usage of the Material UI components library in favor of creating our own components based on the mockups made by Clémence ([see this previous blog post about it](https://xen-orchestra.com/blog/ux-ui-design-for-xo-and-xolite/)). Additionally, the first version of XO Lite used the xen-api Node module, which required the use of many polyfills for the browser. We have therefore decided to develop, in parallel to XO Lite, a new "xen-api lite" library, exclusively dedicated to the browser. **As a result of these decisions, the velocity on the development of the new version of XO Lite has exploded** and in just a few weeks we have surpassed the level of the previous version that was developed for almost a year. This is great news, especially since XO Lite will be the basis of the future XO 6. As you can see below, many things are added, **including a powerful filter system, a dark mode and other components!** ![](https://xen-orchestra.com/blog/content/images/2022/07/CleanShot-2022-07-28-at-10.26.03.gif) ![](https://xen-orchestra.com/blog/content/images/2022/07/montage-xo-lite--1-.png) ![](https://xen-orchestra.com/blog/content/images/2022/07/CleanShot-2022-07-29-at-15.18.46.gif) ## 🧪 XO 6 Devblog As you know, one of the big projects this year in addition to the creation of XO Lite, is the new major update of Xen Orchestra: Xen Orchestra 6. Our XO CTO, Julien has written a dedicated blogpost to tell you more about the technological choices we made for Xen Orchestra 6: [XO 6: what’s on the horizonA quick review of our progress on XO 6 front, the full rewrite of Xen Orchestra UI and part of the server!![](https://xen-orchestra.com/blog/content/images/size/w256h256/2020/11/logoxo.png)XO BlogJulien Fontanet![](https://xen-orchestra.com/blog/content/images/2022/07/xo6sunrise.jpg)](https://xen-orchestra.com/blog/xo-6-whats-on-the-horizon/) ## 💾 The future of backup Recently, you might have seen some changes in our backups, like the use of what we call "VHD directories". It was a needed storage format change to be compatible with the S3 protocol, but it was also a very good basis to add new features in the near future. The first one is remote level encryption: giving you the ability to encrypt all the files in a backup repository with AES 256, allowing you to store your backups in a non-trusted location. Since the key isn't stored with the backup, your data is safe! ![](https://xen-orchestra.com/blog/content/images/2022/07/undraw_cloud_files_wmo8.png) Another big topic is related to backup speed. We are experimenting with an alternative way to fetch the VM disks, making use of the NBD server present since Xenserver 7.3 (and XCP-ng since 7.4) with our delta snapshot functionality. Our preliminary results are very promising: **it's not only a lot faster to export versus the VHD handler, this will also decrease the dom0 CPU usage during the transfer!** The next steps will be backup tiering: backup to a storage repository, and then asynchronously transfer the data to another slower storage . This will allow you to backup to something like Amazon Glacier for example. Then, we are also working on providing backup repository deduplication, with the target of reducing data transferred by 20-30%. This will be possible to configure "per backup repository". Finally, and in parallel of all of this, we are committed to making continuous improvements with our backup code, to make it more resilient (retry on failure, faster resuming) and more transparent for the user (progress bar, more alerts, ...). All of that with new methods available directly in the REST API, so you can monitor actively AND passively the status of your backup jobs. ## 🧬 Pricing evolution Our pricing will evolve this fall (end of Q3 or start of Q4). There are many reasons for this, past and future. We are telling you everything about it in a dedicated blog post. We share everything in a transparent way as we always do: [XO pricing evolutionA review on our pricing evolution, since we started to today, and why we must adapt.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2020/11/logoxo.png)XO BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2022/07/evolution.jpg)](https://xen-orchestra.com/blog/xo-pricing-evolution/) Also, we'll introduce new offers in the next months: indeed, since most of our new customers are coming from the VMware world these days, we need to provide "bundled" offers containing the whole stack in one product, so it's easier to purchase and understand. Obviously, we'll keep the "standalone" offers available, but the new ones will be an attractive option to get both XCP-ng and XO together. ## 🤝 A new partnership We are also happy to announce a new partnership with Excellerent, a US-based company providing technological and human resource solutions to deliver digital transformation. Read this blog post to get more details: [Vates and Excellerent partnershipVates and Excellerent Technology Solutions are proud to announce the signing of their partnership agreement.![](https://vates.fr/blog/content/images/size/w256h256/2022/07/logo64.png)Vates NewsMarc-André Pezin![](https://vates.fr/blog/content/images/2022/07/gift-habeshaw--C5cJ41YPDg-unsplash.jpg)](https://vates.fr/blog/vates-and-excellerent/?ref=xen-orchestra.com) ### XO 6: what's on the horizon URL: https://xen-orchestra.com/blog/xo-6-whats-on-the-horizon/ Last updated: 2025-07-28T08:36:31.000Z Hello there! I'm Julien, CTO of the [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com) project and [Vates](https://vates.fr/?ref=xen-orchestra.com) co-founder. In this article, I'll explain what's coming for XO 6, why we decided to do it, and more details about our technical choices. ## Back in time: XO 5.0 XO 5.0 was already a big revamp, switching from Angular 1 to React, addressing some shortcomings of Xen Orchestra 4\. It was made to be faster, more scalable but also to have internationalization built-in, among other things. See the original announcement: [Xen Orchestra 5.0New major release of Xen Orchestra, bringing XenServer to the Cloud!![](https://xen-orchestra.com/blog/content/images/size/w256h256/2020/11/logoxo.png)XO BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2021/11/riscvbanner2-1.jpg)](https://xen-orchestra.com/blog/xen-orchestra-5-0/) Frankly, it went so well that we could keep XO 5 architecture until recently, despite **70 releases** on top of it and countless new features! It's impressive and we are glad to have made the right choices 7 years ago. But now it's time to make a true leap ahead: this current design starts to have the weight of its years, and our customers are even more demanding than before (which is good!). ## Why we need XO 6 Xen Orchestra changed a lot since XO 5, and now we have a better idea on "where to go" and what's needed, functionally and technically. This is also an opportunity to build the UI from scratch, with the help of our UX designer. On that topic, you can read our preliminary work on the XO Lite UI: [UX/UI Design for XO and XOLiteWith the launch of XOLite and the redesign of Xen Orchestra itself, UX/UI Design is getting a revisit in the XO world.![](https://xen-orchestra.com/blog/content/images/size/w256h256/2020/11/logoxo.png)XO BlogClémence Barthoux![](https://xen-orchestra.com/blog/content/images/2022/06/XO-Blog---UX-UI-Design-for-XO-and-XOLite.jpg)](https://xen-orchestra.com/blog/ux-ui-design-for-xo-and-xolite/) But the UI is just a part of the big change opportunity given by Xen Orchestra 6\. We truly want to add missing pieces in the current architecture, to make it more secure, faster and easier to use. ### XO Web: going to Vue.js `xo-web` is the web UI for Xen Orchestra. If you remember, Xen Orchestra is split in multiple parts: - `xo-server`, the server - `xo-web`, the web UI - various plugins - various libs For the web part, we decided to switch to Vue.js, an open-source front end Javascript framework. ![](https://xen-orchestra.com/blog/content/images/2022/07/kindpng_4529223.png) Vue is better in our case for various reasons. First, it's a complete solution, unlike React. Indeed, React itself is only a part of the solution, since other components are needed to build Xen Orchestra. We even created some custom components for our needs, e.g [Reactlette](https://github.com/JsCommunity/reaclette?ref=xen-orchestra.com). Vue offers a more complete toolbox to our project. This is also a way to iterate faster, meaning delivering features faster: we've seen excellent results when we switched from React to Vue for XO Lite. This experience will be also valuable when working on `xo-web`. ## A new architecture For the backend, `xo-server`, we wanted to use this opportunity to drastically improve the whole architecture. As Xen Orchestra is becoming a true management and backup layer for your entire virtualized infrastructure, we needed to go deeper and improve/revamp entire parts of it. ### Single object collection In XO 5, we currently rely on 2 collections of objects: - XAPI objects, which are stored in a dedicated collection and plugged to XAPI events (all VMs, hosts and other records coming from your hosts) - XO objects (servers, users, backup jobs, logs…), which are fetched via polling and not with events. Outside the fact it's simply **hard** to keep track on which object is in which collection, we wanted to unify everything and get a **global event system**, getting rid of polling once for all. This will help us to develop in a more efficient manner but mostly to reduce a LOT of the data transfer between your browser and the server backend. The UI will be more responsive, and using a **subscription based** system will allow us to only send what's displayed or needed. This means that people with a slow connection (or a very large infrastructure!) will finally reduce their initial load time by a lot. I mean, it will be probably orders of magnitude faster! ![](https://xen-orchestra.com/blog/content/images/2022/07/undraw_Programmer_re_owql.png) ### Integrated task system Right now, we rely on XAPI tasks to track asynchronous operations, like a VM migration, a VM export and so on. However, Xen Orchestra is now doing a lot of complex operations on top of XAPI itself. Backups, but other things too. We need to keep track of that, and the solution is to create a true global task object for Xen Orchestra. Not only for host operations, but anything else that can take some time from XO itself! This task system will be also very helpful in the UI, since you won't lose track of your async actions. Note that a task could also contain "subtasks" for complex operations. A good example: our rolling pool update feature. It's great but you can't really view an overview of the progress currently, except by watching XAPI tasks spawning. With our new system, you'll have a complete log on what's going on in each step! ![](https://xen-orchestra.com/blog/content/images/2022/07/undraw_Code_review_re_woeb.png) ### Events This is also something we want to develop for XO 6, even if it might come a bit later. It's more and more important to know what's going on when you are not in front of your management interface. Like if a pool was disconnected or things like that. The ability to have an event system to be actively notified (and not only for backups as we have now) is important to have more automation and transparency on what's happening in your infrastructure when you are not looking at it. ## The next steps I'm currently working on creating the new unified object collection. In the meantime, the web team is making progress on XO Lite (also on Vue.js) which is helping to prepare the new XO 6 UI, since it will share common components. As soon as we get something that you can test, we'll deliver it in XOA as a tech preview (likely available first in a dedicated URL, like `https://your-xoa-url.com/xo6`) until we are satisfied with it. In any case: stay tuned! ![](https://xen-orchestra.com/blog/content/images/2022/07/undraw_navigator_a479.png) ### XO pricing evolution URL: https://xen-orchestra.com/blog/xo-pricing-evolution/ Last updated: 2022-09-21T09:23:41.000Z At Vates, we've been always 100% transparent about our development processes, quality control and the conduct of our businesses. In 2014, when we started selling Xen Orchestra, we offered 3 paid tiers for companies of different sizes and needs. Those three tiers were intended to cover most types of structures that we identified at the time (you can even [read the original blog post here](https://xen-orchestra.com/blog/pricing-model/)). Today we are announcing a change of this pricing, and explaining the reasons behind it, in the same fully transparent manner. ## TL;DR For those who are not really interested in the causes of this change, here are the main changes in pricing that will take place starting **October 1st** for new customers (and at your renewal date for older customers): ![](https://xen-orchestra.com/blog/content/images/2022/07/new-pricing-2.jpg) --- ## An evolving economic context In 2019 with the COVID-19 crisis, 2020 and 2021 with various lock-downs around the world, and finally 2022 with the start of the war in Ukraine, the world is going through a difficult period overall. We at Vates are thankful that we are in a country that is at peace and where the epidemic is "relatively under control". One of the direct consequences of this complex period is that global inflation, which had been virtually non-existent until now, has become very high. This has a direct impact on our current team working at [Vates](https://vates.fr/?ref=xen-orchestra.com), and since we want to keep people on board while continuing to hire people (at a higher price), it's inevitable that we need simply… more money! With this in mind, first and foremost, we must adapt and change the pricing of our solutions. We will, during the year to come, continue to monitor the inflation and might adjust our pricing according to the global context. ![](https://xen-orchestra.com/blog/content/images/2022/07/undraw_Growth_curve_re_t5s7.png) ### IT job market and skills In line with inflation, the cost of hiring in the IT sector has risen considerably over the last 3 years. We attach particular importance to the quality of the profiles we recruit, both to ensure a satisfactory level of development and to deliver quality support to all of our users. As you know, [our vision of support](https://xcp-ng.org/blog/2022/05/06/my-vision-for-open-source-pro-support/?ref=xen-orchestra.com) is unique and we want to continue to offer this quality of support in the future. This price change is a way to keep allowing us to grow our team with skilled people at all levels, while keeping up with revenue for our existing talents. 👪 And we are still hiring! Just in 2022, we already have 3 new team members and we're not finished yet. We are now close to 30 people working for Vates: remember that **we were only 3 in 2015**. Cool, eh? As you can imagine, almost all our expenses are related to paying our skilled teams. ![](https://xen-orchestra.com/blog/content/images/2022/07/undraw_Online_cv_re_gn0a.png) ## A necessary change Since 2015, the year of its first paid release, Xen Orchestra has gained: - 84 releases - 400 new features - 3 times larger development team - 3 times larger support team While our pricing has **remained unchanged for the past eight years**, our team has grown steadily, developing Xen Orchestra and strengthening its performance, stability and security over that time, with our steady monthly release pace. Xen Orchestra (and XCP-ng, our virtualization platform) can now easily compare to some of the major players in the virtualization market ([Gartner has even listed us and put us in their Market Virtualization Guide!](https://vates.fr/blog/gartner-market-guide-for-server-virtualization/?ref=xen-orchestra.com)), and yet our pricing has remained the same since launch. One could argue we should probably have raised it sooner. And I agree, we did not spend enough time to think about it. But now, external factors made us realize how critical it is today. So we can say with confidence that both the tools we provide and the level of support that goes with them is **much higher than it was 8 years ago** \- so we feel that this change is not only legitimate, but necessary in order to maintain our momentum and continue to deliver in the years to come. ## And ever more to come Obviously, this great evolution in 8 years is in fact not the only "product" related reason: today, **we are investing more than we ever did**, continuing to improve our stack. Just on Xen Orchestra, we are now working on XO Lite, [XO 6](https://xen-orchestra.com/blog/xo-6-whats-on-the-horizon/), a [brand new UI build with an UX designer](https://xen-orchestra.com/blog/ux-ui-design-for-xo-and-xolite/), a new backup process that will be a lot faster and more secure (encryption, compression, deduplication…). Without forgeting about our [huge R&D investments in XCP-ng!](https://xcp-ng.org/?ref=xen-orchestra.com) [XO 6: what’s on the horizonA quick review of our progress on XO 6 front, the full rewrite of Xen Orchestra UI and part of the server!![](https://xen-orchestra.com/blog/content/images/size/w256h256/2020/11/logoxo.png)XO BlogJulien Fontanet![](https://xen-orchestra.com/blog/content/images/2022/07/xo6sunrise.jpg)](https://xen-orchestra.com/blog/xo-6-whats-on-the-horizon/) And as we continue to do since the start, we are transparently sharing what's going on, like our [roadmap for Xen Orchestra](https://xen-orchestra.com/docs/roadmap.html?ref=xen-orchestra.com) and also [XCP-ng](https://xcp-ng.org/docs/roadmap.html?ref=xen-orchestra.com). There's exciting new features and improvements coming in the following months, so stay tuned! **Finally, we wanted to collectively thank you for your trust in our products and values we share together: providing an integrated, secure, truly open source and community driven solution for your IT infrastructure.** ![](https://xen-orchestra.com/blog/content/images/2022/07/undraw_Team_collaboration_re_ow29.png) --- ## Pricing guide for existing subscribers Here is a quick recap on what it means for you, as an existing subscriber. #### For a monthly subscription To smooth the transition and giving you some time, we agreed to make this new pricing change for you **only starting in October**. For example, if you subscribed to Xen Orchestra Premium plan on February the 12th, you will only be charged with the new price on October the 12th during your monthly renew. ♥️ Since there's no commitment, you can cancel anytime, but **it's better to [contact us and discuss](https://vates.fr/?ref=xen-orchestra.com#contact)** if you can't make it with our new pricing. Also note we want to offer an alternative with new offers that will come with attractive bundle pricing for XCP-ng and Xen Orchestra (see below). [Feel free to ask us too](https://vates.fr/?ref=xen-orchestra.com#contact). #### For a yearly subscription The new pricing will be taken into account on your renewal date. If you subscribed for 1 year in February, then the new pricing will apply on your renew next year! If you purchased a 3 year subscription, congrats, your price will stay the same for the remaining time of your contract 😉 ### New offers coming in the following months Since we are changing the pricing of Xen Orchestra, we also wanted to provide new competitive offers for people interested in the entire combo "XCP-ng + Xen Orchestra". Those offers will be tailored to be easier to adopt and scale better for your infrastructure. [Contact us](https://vates.fr/?ref=xen-orchestra.com#contact) if you want to learn more before it's officially announced! ### Xen Orchestra 5.72 URL: https://xen-orchestra.com/blog/xen-orchestra-5-72/ Last updated: 2023-11-23T13:49:14.000Z Summer is here! At least in our Northern hemisphere. Enjoy this refreshing release and don't miss any new features. ## 🚀 Faster backup merge A new opt-in merge mode for Delta Backups, allowing zero-copy on the storage repository. In short, instead of storing VHDs directly, we are splitting each 2MiB VHD block into a dedicated file. This is exactly the same implementation we are using for S3 backup. We have a "block allocation table", pointing to each 2MiB "block file". The great advantage with this "split" storage method is that we do not need to read the full delta VHD to merge it. We just rename 2MiB blocks around and… that's it! All of this is very efficient and fast. To configure it, edit your current remote (or create a new one) and check "Store backup as multiple data block instead of a whole VHD file": ![](https://xen-orchestra.com/blog/content/images/2022/06/faster-backup-merge.png) ⚠️ **Enable it with caution**. Some filesystems aren't able to support that many files. If you only have 100GiB of backups, it means more than 50k files. And with Terabytes of backup, it's huge. `ext4` supports 4 billions files max, which means 8PiB of backup tops (and reasonably less if you want some wiggle room, like 4PiB). With modern filesystems like ZFS or Btrfs however, you are on the safe side. ## 🌐 IPv6 support for XOA deploy We are now supporting IPv6 to deploy the Xen Orchestra virtual Appliance, via our [deploy page](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xoa) or our dedicated [CLI script](https://xen-orchestra.com/docs/xoa.html?ref=xen-orchestra.com#alternative-install). IPv6 is the future, and now you can avoid using any IPv4 for your management VM! Dual stack is also possible, obviously. ![](https://xen-orchestra.com/blog/content/images/2022/06/v4vsv6-1.png) ## 🛰️ Xen Orchestra Proxy Release after release, our "backup proxy" is adding more and more features. It's now a fully fledged proxy used to manage your infrastructure at scale! ### Channel sync for XO proxy XO proxies are now able to use the [current release channel](https://help.vates.fr/kb/en-us/9-xen-orchestra-appliance-xoa/21-release-channel?ref=xen-orchestra.com) configured by the user instead of a unique "proxy" channel. This allows users to switch to `latest` for both XOA and XO Proxy in case you want to check recent features, while being sure both are "sync" with the same release. ### Display Proxy URL On the proxy list, in your Xen Orchestra menu, you have now the ability to copy the proxy URL to your clipboard. While this URL can sometimes be requested by our support team when you have an issue with a proxy, it's not the main usage we have in mind. This feature is also a great help in order to allow you to turn an XO proxy into an full HTTP proxy when deploying it inside a private network. Indeed, with this URL, you can then add your distant site to access to your host in Settings/server from your main XOA. ![](https://xen-orchestra.com/blog/content/images/2022/06/copy-proxy-url.png) ## **🔧** Storage maintenance mode Need to shutdown your storage for maintenance? Now you have a button that will shutdown related VMs and disconnect the storage from your hosts. ![](https://xen-orchestra.com/blog/content/images/2022/06/SR-maintenance-mode.png) This way, you can do whatever is needed on the storage, and when done, re-enable it: all the hosts will be reconnected to it. No manual process to find all VMs related to this SR, shut them down, then disconnect all the `PBDs`. Automation is king! ## 📡 REST API token generation It's now easier to generate a token for our REST API access. Go in your user zone, and manage all your tokens. No need to use `xo-cli` anymore! ![](https://xen-orchestra.com/blog/content/images/2022/06/rest-api-token-reg.gif) If you want a quick demo on what the XO REST API can do, take a look at [the official documentation](https://xen-orchestra.com/docs/restapi.html?ref=xen-orchestra.com#collections-request). ## ## 👁️ Related tasks visible for non-admins Non-admin users were not previously able to see any tasks in XOA. In some situations, especially for users of the self-service feature, this was not logical. We have corrected this situation, so it is now possible for self-service users to see the tasks of their own VMs: ![](https://xen-orchestra.com/blog/content/images/2022/06/self-service-tasks.gif) ## ## ✏️ Xen Orchestra Lite & Xen Orchestra 6 [![](https://xen-orchestra.com/blog/content/images/2022/06/XO-Blog---UX-UI-Design-for-XO-and-XOLite-1.jpg)](https://xen-orchestra.com/blog/ux-ui-design-for-xo-and-xolite/) Last month, we told you that our UI/UX designer, Clémence from [BXdesign](https://www.bxdesign.io/?ref=xen-orchestra.com), was working on a Devblog to present you in detail the decisions leading to the conception of the interfaces of XO Lite and XO6\. [This devblog is now available for you to read.](https://xen-orchestra.com/blog/ux-ui-design-for-xo-and-xolite/) ## ### UX/UI Design for XO and XOLite URL: https://xen-orchestra.com/blog/ux-ui-design-for-xo-and-xolite/ Last updated: 2022-12-08T10:31:59.000Z With the launch of XOLite (a light version of Xen Orchestra that doesn't require users to host a virtual appliance) and the redesign of Xen Orchestra itself, UX/UI Design is getting a revisit in the XO world. ## **What is UX/UI Design again?** **UX Design** refers to the term "User eXperience Design", while **UI Design** stands for "User Interface Design". ### **UX Design, the architect** UX Design is focused on creating the best user experience, so you can find your way around and meet your goals on the platform without needing a full manual to do so. As IT people, we often joke that issues find their roots between the keyboard and the chair, but you would be surprised how often a good design can reduce frustrations and unexpected behavior from the user. In UX Design, a product should meet four expectations: - It should be **usable**, meaning the design, structure, and purpose of the product is clear and easy to use. - It should be **equitable**, meaning the design is helpful to people with diverse abilities and backgrounds. In other words, the product’s design addresses the needs of a diverse audience and ensures that a high-quality experience is delivered to all users, regardless of background, gender, race, or ability. - It should be **enjoyable**, meaning the design is nice for users to look at. An interface such as XOLite doesn’t have to be enjoyable for it to function properly. But an enjoyable design adds to an already functional product and enhances your experience as a user. - It should be **useful**, meaning the design solves user problems. In other words, the design intentionally solves a user problem that has been identified. It’s important to note that while similar, useful and usable have different meanings. A useful product isn’t always usable and vice-versa. The distinction between the two is that usability refers to the product working well and being easy to use, while usefulness refers directly to the ability to solve user problems. A UX Designer is quite like an architect, but for a web interface or software instead of a house. We define the number and size of rooms and their use (the pages), how we are going to move from one to another, where we put doors, lights, and light switches (menus, buttons, forms), etc. ### **UI Design, the interior designer** UI Design considers all the visual interactive elements of a product interface, such as buttons, icons, spacing, typography, color schemes, and responsive design. The goal is to visually guide the users through the interface, making sure the design is consistent, coherent, and aesthetically pleasing. In our house metaphor, a UI Design would be the interior designer. We define the colors and visual theme of the rooms (graphic identity), the shape of the light switches and doors (a button or a link?), and decide whether we should pick drawers with a silent closing system (instant or dissolve animation), etc. The key to a successful UX/UI Design is to put the users at the core of arguments, prioritization, and decisions. UX Design must be backed up by data: surveys, interviews, user tests, and so on. As individuals and humans ourselves, even with the best intention, we are full of biases! Allowing the users to express themselves is key for a mindful design. ## **What is UX/UI Design bringing to XOLite?** At the beginning of the year, we launched surveys to better understand who our users are and what their needs and issues are with the XO interface. If you answered one of our surveys, thank you again! Your feedback gave us a better understanding of what was working and what needed improving. Out of 116 answers, we learned that most of the open-source community uses Xen Orchestra for personal lab (64%) and/or enterprise purposes (53%). The vast majority use only XCP-ng hypervisors (84%) for 1 to 4 hosts (62%), where less than 100 VMs are running (75%). 2 out of 5 people are running containers (39%), which is more than we expected. Almost 9 out of 10 people use Xen Orchestra at least once a week (45% weekly, 44% daily). While a lot of users are working from a laptop or a desktop with a big screen, almost 20% of people open the interface on a smartphone or a tablet, especially "when shit goes south" as someone wrote us in the survey. Almost 9 out of 10 people are using Mozilla Firefox (47%) or Google Chrome/Chromium (42%). Your use of XO is mostly motivated by your values, the community we share, the trust you have in the robustness of the software, and the support quality. A lot of you aspire for some freedom in using virtualization software, and simply no longer want to support some other vendor’s product policy. In terms of user experience, you are mostly satisfied with and very supportive (thank you!) but we have room for improvement. Some features are missing and others "are not visible until you know where to look for them". A lot of back and forth between tabs to work around. The feedback told us we are lacking some consistency and coherence: "UX design consistency isn't ideal", "error messages are often not particularly informative", and some of you wish to turn off some warning messages or disable features that required an upgrade if you "can't afford it or can't convince management to purchase it." The Tree View is in high demand, as are having more interactions and shortcuts with the keyboard and improving the search bar. Out of 106 answers, you are almost only male users (97%), which might put in the spotlight our lack of participation in the parity of the IT world (the whole problem doesn't fall on our shoulders though we can ask ourselves how we can act at our level by creating interfaces where everyone feels that they belong, and where teenage girls in high school might fall in love with IT and infrastructure). 3 out of 5 are between 25 and 44 years old (65%), mostly educated (86% have at least a high school degree or equivalent), and are located all around the world. 70% are employed full-time and 19% are self-employed. Most of you are infrastructure specialists, but we also have some developers, project and product managers, and DevOps. What do those answers bring to XOLite, and later to XO 6? ### **The new Tree View alongside the Flat View** Yes, the Tree View is finally here! It will help you to move easily from one object to another in your infrastructure without having to go back and forth too much. For now, the Tree View presents only the pool with its hosts and VMs. Later on, we would like to present network and storage objects in the same way. However, the Flat View remains so if you have a large infrastructure you can easily filter and sort your list of objects to find your way. ![XOLite - Tree View](https://xen-orchestra.com/blog/content/images/2022/06/XOLite---Treeview-2.jpg) ![XOLite - Tables](https://xen-orchestra.com/blog/content/images/2022/06/XOLite---Tables-1.jpg) ### **Menus navigation** Our wish has been to simplify a lot of the navigation. Each object will present with a set of menus where all settings will be organized by subject: System, Network, and Storage. The Advanced Settings menus that easily become "carry-all bags" are officially banned, and each object will have its own dashboard and its alarm details within reach. ![XOLite - Pool menu](https://xen-orchestra.com/blog/content/images/2022/06/XOLite---Pool-menu-1.jpg) ### **Search bar** In future versions of Xen Orchestra and XOLite, the search bar will be present in the header on all pages so no matter where you are, you can quickly access the object you are searching for. Filters, sorting, and table properties will be easier to use. Also, as it is not always easy to write advanced search requests and benefit from the full power of XO search engine, we will add a toolbox to help you to follow the right syntax. ![XOLite - Advanced filter](https://xen-orchestra.com/blog/content/images/2022/06/XOLite---Advanced-filter-1.jpg) ### **Keep it simple** We are keeping what is working great in XO like the one-page forms, and we are putting a focus on consistency in the design and wording choices. ### **Seamless visual identity rebrand for the whole XO ecosystem** The Xen Orchestra ecosystem is getting a little identity rebranding thanks to our good friends at [Les Alfredines](https://www.lesalfredines.com/?ref=xen-orchestra.com). Our goals are - To be more coherent between all interfaces so you will quickly move from XOLite to XO and vice-versa, and later with the whole XO ecosystem - To make them pleasant to work with all-day - To make them more accessible to everyone ## **Why is accessibility so important?** With XO and XOLite, we are committed to providing interfaces that are accessible to as wide an audience as possible, regardless of circumstances and abilities. We are working towards meeting the[ Web Content Accessibility Guidelines](https://www.w3.org/WAI/standards-guidelines/wcag/?ref=xen-orchestra.com) (WCAG 2.0, Level AA), published by the[ World Wide Web Consortium](https://www.w3.org/?ref=xen-orchestra.com) (W3C). Web accessibility encompasses all barriers that affect access to the Web, like the well-known auditory, cognitive, neurological, physical, speech, and/or visual impairments, but also the circumstances of use: - People use mobile phones, smart watches, smart TVs, and other devices with small screens, different input modes, etc. - Older people with changing abilities due to aging - People with “temporary restrictions” such as a broken arm or lost glasses - People with “situational limitations” such as in bright sunlight or in an environment where they cannot listen to audio - People using a slow Internet connection, or who have limited or expensive bandwidth As open-source actors, we are keen to do our part for a more accessible web world. For the first version of XOLite, and later for XO 6, we decided to focus on 4 main aspects: ### **Visual impairment** - All texts are written big enough and with enough contrast to be read easily, no matter the quality of your sight. - Color codes are always backed up by shapes and/or text so people who don't distinguish colors well, or don't distinguish them at all, can have the same level of information. - No flashy colors or blinking items to prevent epileptic issues for those at risk, and/or unnecessary headaches. ### **Responsiveness** We decided to start by not making every page perfectly responsive, but instead focusing on the ones that matter. We are working with a simple use case: you are on your lunch break and there is an alert on your infrastructure. How can we make sure that you can quickly get all the information needed to decide if you have time to finish your lunch or not? So all consultation pages will be responsive, such as dashboards, stats, and alerts pages. ### **Situational limitations** - 2 color modes, light and dark to adjust to your preference and surroundings. - Keyboard-only visual navigation will be enhanced so you can use it more often, and if your mouse and/or your touchpad are out of service, you can easily continue with your day. - No fancy interactions or big illustration files so your web pages can be loaded in a reasonable timeframe even if you do not have the best bandwidth. ### **Inclusivity** In our choice of words and illustrations, we endeavored to include everyone and make sure that you feel you belong here. Like many actors in the industry, we dropped the "master/slave" vocabulary in favor of "primary/secondary" and we picked up the open-source illustrations database [Undraw](https://undraw.co/?ref=xen-orchestra.com) where all genders and people of color are represented. UX/UI Design is an ongoing discussion. We want to create interfaces that meet your needs as individuals but also as a group. Feel free to reach out to us and share your thoughts, your frustrations, and your needs for the new XO and XOLite interfaces. ### Xen Orchestra 5.71 URL: https://xen-orchestra.com/blog/xen-orchestra-5-71/ Last updated: 2022-05-31T13:30:28.000Z We are proud to deliver some new exciting features both in backup and every day management of your infrastructure. As you can see, it's a pretty dense release! Let's discover in detail what's in store. 🗞️ **If you missed it**: there's a lot of fuss with [Broadcom acquiring VMware for $60B+](https://www.theregister.com/2022/05/26/broadcom%5Fvmware%5Fmerger/?ref=xen-orchestra.com). Maybe it's time to read our success story on [how BedRock Streaming migrated their on-prem infra from VMware to XCP-ng](https://xcp-ng.org/blog/2022/04/13/how-bedrock-streaming-migrated-from-vmware-to-xcp-ng/?ref=xen-orchestra.com). ## 💾 Backup This release contains a number of pretty interesting features related to backups. We care about your data, and this is an example of our commitment. ### ⚕️ Auto restore check Performing backups is great. Automatically testing them to see if they worked is even better. It's now possible in this XO release! Basically, you'll just have to tick the "Health check" checkbox in your backup job: ![](https://xen-orchestra.com/blog/content/images/2022/05/auto-restore-check.png) Then you can select which VM you want to check thanks to its tags (it's an "OR" so if you have any of those tags, it will be tested): ![](https://xen-orchestra.com/blog/content/images/2022/05/back-restore-check2.png) It will be restored at each run of this schedule, and you can see auto restore will be started backup report directly: ![](https://xen-orchestra.com/blog/content/images/2022/05/healthrestore.jpg) This new safety mechanism is now allowing you to regularly check if your backup VMs are booting. 💡 If you want to get the Auto Restore Check (ARC) happening only the week-end, despite doing a nightly backup, just create a new schedule in this existing job. And just for this new schedule, enable the ARC option! ### 🔌 VMs with vUSB device attached XO is now able to automatically unplug vUSB devices before doing a snapshot, working around a XenServer/XCP limitation. Indeed, you can't snapshot a VM when it's using a vUSB device. Previously this meant you couldn't backup these VMs at all, or you would have to manually unplug it before starting a (manual) backup. Now this is fully automated, meaning that you can backup even your VMs with a vUSB device. The only condition is we have to do an "offline snapshot" (shutdown the VM, unplug the vUSB device, snapshot, re-attach the device, start the VM). This is because vUSB devices do not support hotplugging while the VM is running. However, it's a small price to pay to enjoy the safety of doing backups! ### ⏭️ `[NOBAK]` for basic backups In Delta backups, you could already avoid exporting a disk by adding \[NOBAK\]. It wasn't possible in Basic backups (full backups using XVAs) until now. The concept is pretty simple: we'll detach the disk from the VM snapshot before exporting it. It can be very useful when you are using large disks you don't want to backup for various reasons. ### 🏎️ Cache system for restore view We added a cache system to reduce a lot the load time for the "Backup/Restore" view. It's really fast now! It was initially loading all information before displaying your VMs to restore: the more backups you had, the longer it would take to load the view. And it was doing the same again and again! The new cache system is fixing this, providing a huge boost in responsiveness for this view. ## 🖥️ Management While backup is an important part of this Xen Orchestra release, we also managed to slip in various improvements on the management side. ### ♻️ Rolling Pool Update v3 A new incremental release of our RPU system, allowing you to do "one click" whole-pool upgrades without any impact on your production. ![](https://xen-orchestra.com/blog/content/images/2022/05/rpuv3.png) ℹ️ Don't forget to take a look at our official [documentation for the Rolling Pool Update feature](https://xen-orchestra.com/docs/manage%5Finfrastructure.html?ref=xen-orchestra.com#rolling-pool-updates-rpu). This time, it's about detecting if your pool is either a source or a target for any kind of backup job (or both). If it's the case, then we'll tell you and if you agree, disable the backup job until the RPU is finished. This way, you'll avoid any bad interactions between a backup job trying to run while you are shutting down/rebooting your physical hosts (which is happening in a RPU situation). Also, if there's a currently running backup (and not just scheduled), you'll be notified: ![](https://xen-orchestra.com/blog/content/images/2022/05/168092860-acee42fc-8b07-4d25-96f5-58e40665510f.png) These two protections are here to be sure RPU is safe while being 100% automated, reducing the management burden for system administrators. ### ⬆️ Improved web updater Our web updater is now able to handle cases where XOA is interrupted in the middle of a download (or if a download is corrupted). In fact, we apply a similar strategy that we use for our backups. If the file is corrupted, we'll remove it locally and re-download it. ### 🔎 Default filter for SR view You could already save your filters and display them by default on VM and host views. However, it wasn't possible for the SR view! We've been asked to add this a few weeks ago, so we delivered. ### 🕹️ REST API: disk import You can now import a VHD file directly with the REST API! It's very handy if you want to fetch it from a remote system without having to download the file locally, and then dragging it and dropping it into the Xen Orchestra web UI. Let's see a simple example: ```bash curl \ -b authenticationToken=KQxQdm2vMiv7jBIK0hgkmgxKzemd8wSJ7ugFGKFkTbs \ --progress-bar \ --data-binary @myDisk.vhd \ 'https://xo.example.org/rest/v0/srs/357bd56c-71f9-4b2a-83b8-3451dec04b8f/vdis' ``` In this example, the VHD file called `myDisk.vhd` will be directly imported into the SR with the UUID `357bd56c-71f9-4b2a-83b8-3451dec04b8f`. And remember, if you want to get your SR UUID without leaving your current console, just get them with a `GET /rest/v0/srs?fields=name_label,uuid` request. This new API endpoint is already [documented at the usual place](https://xen-orchestra.com/docs/restapi.html?ref=xen-orchestra.com#vdi-import). ## 🏗️ XO Lite and XO 6 We are still making progress on the XO Lite front. Expect a devblog about it relatively soon, where we'll explain our current technical and UX choices while showcasing our default theme which is really beautiful 😍 Regarding XO 6, our "under the hood" work has already started. Also expect a devblog this summer to learn more about what's next. ## Don't miss anything! If you want to be 100% sure you catch any future announcements, don't forget that you can register with our monthly XO newsletter: > Note: we'll NEVER share your email, everything is self-hosted with Open Source software. You can unsubscribe anytime. ### Xen Orchestra 5.70 URL: https://xen-orchestra.com/blog/xen-orchestra-5-70/ Last updated: 2022-04-29T13:28:51.000Z Want to take a look at our video version of this announcement? Take a look here: ## **✨** XO Lite - Pool dashboard ![](https://xen-orchestra.com/blog/content/images/2022/04/dashboard-xo-lite.png) Pool dashboard in XO Lite Xen Orchestra Lite is a great project that paves the way for our next major release of Xen Orchestra. We're working hard to get this new, lighter management interface for small infrastructures out as soon as possible. This month, we are completing the integration of the pool dashboards, which include the progress circle component that will be used in most dashboards related to the health of the infrastructure. We are also actively working on the table component which we want to refine as it is an essential component that will be used almost everywhere in Xen Orchestra Lite as well as in Xen Orchestra 6. 💡 XO Lite is still very new, most of the work is "behind the scenes" (UX, layout, components). However, you can always follow the progress on your host directly, if you [follow the instructions](https://xcp-ng.org/forum/topic/5018/xo-lite-building-an-embedded-ui-in-xcp-ng?ref=xen-orchestra.com). ![](https://xen-orchestra.com/blog/content/images/2022/04/table-xo-lite.png) Table preview in XO Lite ## ⚕️ Restore healthcheck For even more data safety assurance we have added the possibility (manually, for the time being) to perform test restorations. This restoration will work in the same way as a classic VM restore, but at the end of the test, the VM will be removed. To avoid any interference with your running VMs, the test restore will: 1. Disable all the network cards 2. Boot the VM 3. Wait for the VM guest tools to be up 4. Remove the VM The objective of this test restore is to be sure the VM is still able to boot: indeed, if the guest tools are loaded, it means that your operating system is able to boot and load them, which is a simple yet efficient way to test the backup content. In the near future, we will make this health-check **entirely automated**, and we are currently thinking about the best way to implement this. Expect more to come in a future release! ![](https://xen-orchestra.com/blog/content/images/2022/04/restore-healthcheck.gif) ## 🌐 DNS cache Xen Orchestra performs a large number of DNS queries to the XAPI on your hosts in various situations (especially during backups). This represents thousands of requests for which Xen Orchestra does not cache anything... well, until now. In this release, we have implemented a cache that should considerably reduce the number of queries made and consequently have an impact on backup performance as well as avoid overloading the network. ## 🕸️ HTTP proxy in XO Proxy It's now possible to connect to your distant host using the Xen Orchestra proxy as an HTTP proxy. This way, you will connect to your host but only expose the XO Proxy, therefore protecting the rest of your infrastructure. Our initial implementation was using a kind of "reverse proxy". However, this method is far more flexible: you don't need to manually add all your hosts, you just configure it once, and then you'll have access to all the hosts in the XO Proxy network! And obviously the usual benefit of not exposing your management interface publicly, as you can see of this before and after: ![](https://xen-orchestra.com/blog/content/images/2022/04/proxybeforeafter-1.png) More than being easier to use than our original reverse proxy, it's also working with consoles and statistics, which is a great plus. ☝️ For now, this feature isn't exposed directly through a graphical interface. You must follow [this documentation to configure your proxy](https://github.com/vatesfr/xen-orchestra/blob/master/@xen-orchestra/mixins/docs/HttpProxy.md?ref=xen-orchestra.com#set-up). This will be improved in the future. ## 💾 OVA export For both XCP-ng and Xen Orchestra, our ambition is to develop a turnkey virtualization platform with **excellent interoperability.** With this in mind, we wanted to make available the possibility of exporting directly in OVA format, which is very popular with some of our competitors. It took us some time and effort to make this feature available, as interoperability was not the priority of the platforms using this format (the VMDK format is something…) ☝️ We tested and validated our exported OVA VMs with both VMware and Virtualbox. ![](https://xen-orchestra.com/blog/content/images/2022/04/export-ova.gif) ## ☁️ Upload ISO to NFS/SMB We know this was awaited for a long time. And believe me, this feature has a great story behind it. For years, we were almost certain that ISO import wasn't possible in XenServer API (since ISO SRs are meant to be mounted in read only). And guess what? There's a way to do it. It's not documented nor excessively trivial, but still, it works: we import the ISO as a raw VDI, and well… this works. The consequence is the possibility to upload an ISO directly from the Xen Orchestra interface to an NFS/SMB share, even a local ISO SR: ![](https://xen-orchestra.com/blog/content/images/2022/04/import-iso2.gif) For the next release, we'll add various "places" around the current UI to upload an ISO easily (like near the ISO selector), so it will be even easier to add whatever ISO you want during a VM install or management. ⚠️ If you are using a local ISO SR, remember to avoid filling your root partition until it's full! This will lead to some bad consequences. The recommended practice is to use network shares to store your ISOs. ## ## ### Xen Orchestra 5.69 URL: https://xen-orchestra.com/blog/xen-orchestra-5-69/ Last updated: 2022-03-31T12:34:15.000Z We are continuing the work on our new public REST API and offer a preview of the first dashboards that will be available in XO Lite. Want to take a look at our video version of this announcement? Take a look here: ## 📦 Update improvements This release brings various improvements to updating XCP-ng. Our goal is to provide a smooth way to get all the important updates (security or not) for all your XCP-ng hosts, with no hassle. ### 🔀 Rolling Pool Update We have reworked the algorithm behind the Rolling Pool Update feature. Overall, this new algorithm is safer and more efficient: we changed the operation order to bring more resilience in your infrastructure. The previous implementation began with updating all the hosts in the pool starting with the master. In a second step, we evacuated the VMs on the pool master first, rebooted it, and so on for other pool members. This implementation worked for small updates, but could cause issues as updated components might have a different version than the running (in memory) programs. A recent example was the `8.2.1` big update, changing both XAPI and `qemu` on the host. If you didn't reboot or restart the toolstack after the update, you wouldn't be able to start a new VM (as long as XAPI wasn't restarted or rebooted). In the new implementation, the master host is evacuated, then updated one by one before being restarted in turn. ### 🚫 Disable patch installation when HA is enabled High availability can be the cause of many problems when upgrading your infrastructure. For this reason, it is essential to disable it for the duration of such an operation. To avoid our users getting into problematic situations, we have disabled the ability to upgrade a host when HA is enabled. ![](https://xen-orchestra.com/blog/content/images/2022/03/disable-ha.png) ### 🔄 Restart toolstack after update After an update on a pool or host (without using the rolling pool update feature), the toolstack may not be able to work correctly. We have implemented the automated restart of this toolstack and integrated a warning message when a user decides to start to update a single host or a pool. ☝️ Note that restarting the toolstack won't affect the running VMs. ![](https://xen-orchestra.com/blog/content/images/2022/03/restart-toolstack.png) ![](https://xen-orchestra.com/blog/content/images/2022/03/restart-toolstack2.png) ## 📡 Public REST API (alpha stage) As announced in [our previous release (5.68)](https://xen-orchestra.com/blog/xen-orchestra-5-68/#%F0%9F%86%95-public-api-alpha-stage), we are creating a new public API (REST based) that aims to provide an additional tool for our users that is supported and properly documented. It's also meant to be very simple to use, that's why we always provide examples with a simple `curl` command. ⚠️ This is an alpha feature that may change significantly in the coming months - do not use this feature in a production environment. However, your feedback is VERY welcome! ### 📥 VM and VDI export This REST API is now able to support VDI export and VM export. Here is a simple example to export a VM with `zstd` compression into a `myVM.xva` file: ```bash curl \ -b authenticationToken=KQxQdm2vMiv7jFEAZXOAGKFkTbs \ 'https://xoa.example.org/rest/v0/vms/770aa52a-fd42-8faf-f167-8c5c4a237a12.xva?compress=zstd' \ > myVM.xva ``` For a VHD export, it's very similar: ```bash curl \ -b authenticationToken=KQxQdm2vMiv7FkTbs \ 'https://xoa.example.org/rest/v0/vdis/1a269782-ea93-4c4c-897a-475365f7b674.vhd' \ > myDisk.vhd ``` The documentation is available here: [xen-orchestra/rest-api.md at master · vatesfr/xen-orchestraThe complete web solution to manage and backup XCP-ng and Citrix Hypervisor. - xen-orchestra/rest-api.md at master · vatesfr/xen-orchestra![](https://github.com/fluidicon.png)GitHubvatesfr![](https://opengraph.githubassets.com/955cace75aad1cad8c2d9b61719d7021046e9f7dc3f8a7a8a239336129786e18/vatesfr/xen-orchestra)](https://github.com/vatesfr/xen-orchestra/blob/master/packages/xo-server/docs/rest-api.md?ref=xen-orchestra.com#authentication) ## ✨ XO Lite dashboard That's it! After presenting our project and mockups, the first operational dashboard of Xen Orchestra Lite is ready. We are still working on the dark mode version, but the UI components are being put in place and we should be able to move forward more quickly once the main ones have been created: ![](https://xen-orchestra.com/blog/content/images/2022/03/dasboard-xo-lite.png) ☝️ We are working on a dedicated Devblog about the Xen Orchestra Lite and Xen Orchestra 6 UI/UX work we have started since the beginning of this year. Stay tuned! ## 💽 Delta Backup: selective VDIs restore Xen Orchestra's backup tools aim to be both resilient and flexible. With this in mind, we have added options to the delta backup and restore operations. When restoring a VM from a delta backup job, you now have the possibility to exclude any VDIs from the disks to restore: ![](https://xen-orchestra.com/blog/content/images/2022/03/exclude-vdi.png) ## 📰 Misc We also continue to improve various Xen Orchestra features and tools. This time, it's two things that are really helpful in some situations and an improved deploy script. ### 🌐 Allow VM import from URL You can now import a VM into Xen Orchestra using a URL directly. This way, you no longer need to download your VM locally before importing it into your XOA! ![](https://xen-orchestra.com/blog/content/images/2022/03/import-from-url.png) ### 🕸️ Support console & stats with HTTP proxies You were already able to connect Xen Orchestra to a pool via an HTTP proxy. However, until now, this mode of operation caused some issues, particularly regarding the stats and console access. In this version of Xen Orchestra, these problems are solved which means you can fully use your appliance by placing it behind an HTTP proxy, allowing you to get even further with XO in air-gapped environments! ### 🛫 Deploy script improvement ☝️ If you didn't know, you can easily deploy a Xen Orchestra appliance by visiting [this page](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xoa). The whole process takes only a few minutes. In order to make our Xen Orchestra virtual Appliance even easier to deploy and use, we also have improved the deployment script available that you can use with: ```text bash -c "$(wget -qO- https://xoa.io/deploy)" ``` Now, before booting the VM, it will automatically set XOA virtual network card on the management network. This is helpful in various situations, and also fixing a deploy failure when you only had bonds in your pool. ### 🛄 New templates on XOA Hub We recently added 3 new OS templates, ready to deploy with Cloudinit on XOA Hub: - Rocky Linux 8.5 - Alma Linux 8.5 - Debian 11 All those VMs can be directly deployed as template in the pool/SR of your choice, and then created with Cloudinit, with a default user (`rocky`, `alma` and `debian` respectively). We provided support for network, growable disk and all Cloudinit features. ![](https://xen-orchestra.com/blog/content/images/2022/03/xoatemplates.png) ### Xen Orchestra 5.68 URL: https://xen-orchestra.com/blog/xen-orchestra-5-68/ Last updated: 2022-03-03T12:06:06.000Z We are now doing a Live Session on Youtube for every release! Don't forget to subscribe to [our channel](https://www.youtube.com/channel/UCNjvBiVTxBt-madrH2Kt7iA?ref=xen-orchestra.com) and to [follow us on Twitter](https://twitter.com/xenorchestra?ref=xen-orchestra.com) to be kept in the loop. ## ✨ XO Lite - one more glimpse For some time, our team has been busy working on the interface of our new Xen Orchestra Lite. Here's a little preview of what's coming in the next few months. Clemence, our UX designer, will talk about it in a dedicated DevBlog coming soon. Here are the new VM creation screens: ![](https://xen-orchestra.com/blog/content/images/2022/02/light.png) Default display for VM creation on XO Lite ![](https://xen-orchestra.com/blog/content/images/2022/02/dark.png) Dark Mode ## 🆕 Public API (alpha stage) ⚠️ This is an alpha feature that may change significantly in the coming months - do not use this feature in a production environment. We originally developed our existing API to be used between the Web UI `xo-web` and the server backend, `xo-server` . That's why it's a JSON-RPC API connected via *websockets*, allowing us to update objects live in the browser. This is perfect for our usage, but a bit complicated for others. Also, this API wasn't meant to be public, but over the years some users have expressed a desire to be able to use it for their own purpose. This led us to add more tooling around it, like `xo-cli` and to answer specific requests. For those reasons, we decided to build a new API, not an evolution of the current one, but 100% new. It is meant to be public and REST-like. So a simple `curl` command can request it. We will also document it as the intended goal is to be public this time. For this release, we have laid the foundations of what this future API will be. Although this is a very early version, you can already explore its first features and give us your feedback and expectations. #### Principle and example 🔄 This is an example, and details might change fast. Please refer to the [official documentation here](https://github.com/vatesfr/xen-orchestra/blob/master/packages/xo-server/docs/rest-api.md?ref=xen-orchestra.com#authentication). In order to make the REST API available, you need to create a token, for now with `xo-cli`, but in the near future, directly in the web UI: ``` # xo-cli --createToken http://xoa.example.com myUser Password: ********** Successfully logged with myUser Authentication token created 0OQIKwb1WjeHtch25Ls ``` Now, you can use this token to perform calls with this REST API: ``` # curl -b authenticationToken=0OQIKwb1WjeHtch25Ls http://xoa.example.com/rest/v0/vms?fields=name_label,power_state [ { "name_label": "FreeNAS", "power_state": "Running", "href": "/rest/v0/vms/0fc14abc-ae7a-4209-79c4-d20ca1f0e567" }, { "name_label": "Ubuntu 20.04 test", "power_state": "Halted", "href": "/rest/v0/vms/d505eb99-164e-5516-27e1-43837a01be45" }, { "name_label": "Rocky Linux 8", "power_state": "Halted", "href": "/rest/v0/vms/38f423b7-1498-ee8c-ca8d-d3bb8fcffcf2" }, { "name_label": "XOA 🎷", "power_state": "Running", "href": "/rest/v0/vms/857e34e5-c61a-f3f1-65e6-a7a9306b347b" } ] ``` ## ☑️ SR creation improvements When creating certain local SR formats, such as `ext` or `LVM`, the operation includes formatting the disk on which you are creating the SR. To avoid unpleasant surprises for users who are not familiar with these types of storage, we have added a confirmation box that warns the user in this case. ![](https://xen-orchestra.com/blog/content/images/2022/02/new-sr.png) ## ⚕️ Health view - coalescing VDIs The Health view of Xen Orchestra now includes a table that shows the number of VDIs currently needing to be coalesced in your infrastructure. An additional alert will also be visible in the menu of your interface in case more than 10 VDIs require a coalesce on the same SR. 🐨 The need to coalesce virtual disks is normal and occurs when you delete snapshots from your VDIs (among other possible triggers, like backups which also utilize snapshots). The coalesce process usually takes care of these regularly. However if you have SR issues, the regular coalesce process can fail or fall behind, leading to many uncoalesced VDIs piling up. Now you will be able to see at a glance if this happens! ![](https://xen-orchestra.com/blog/content/images/2022/02/coalesce-health-view.png) The new table in the Health view ![](https://xen-orchestra.com/blog/content/images/2022/02/coalesce-alert.png) Alert on the menu ## 💽 Delta backup - select target SR for VDIs when restoring ⚠️ This feature only works for Delta Backups. To give you more flexibility when restoring a backup, we have added the ability to choose the SR you want to target for each VDI you restore. So if a VM you'd like to restore had multiple disks, you can assign them to separate SRs while restoring! In the future, we would like to develop this feature to also allow you to exclude certain VDIs when restoring a backup. ![](https://xen-orchestra.com/blog/content/images/2022/02/target-sr.png) ## XCP-ng 8.2.1 is here Today is a big day, as we're also announcing the general availability of XCP-ng 8.2.1\. It's simply an **update** and it's available now (just update your XCP-ng hosts as usual). We also rebuilt a new ISO containing all updates since our initial LTS release. ![](https://xen-orchestra.com/blog/content/images/2022/02/mainlogo.png) If you want to learn more about it, visit our XCP-ng blog! [XCP-ng 8.2.1 update for 8.2 LTSXCP-ng 8.2.1 is available as an update, also available with a fresh new ISO.![](https://xcp-ng.org/blog/favicon.png)XCP-ng newsSamuel Verschelde![](https://xcp-ng.org/blog/content/images/2022/02/datacenterxcp.jpg)](https://xcp-ng.org/blog/2022/02/28/xcp-ng-8-2-1-update/?ref=xen-orchestra.com) ## Kubernetes users: we need your feedback! We'd like to learn more about your container usage, with Kubernetes or otherwise. In fact, we'd like to know how we could improve our XCP-ng/XO platform so it's easier for you to deal with container orchestration and so on. So if you already use XCP-ng and XO, and Kubernetes or containers in parallel, please tell us in this dedicated thread: [Containers or Kubernetes users? We need your feedback!We’d like to learn more about your container usage, with Kubernetes or not. In fact, we’d like to know how we could improve our XCP-ng/XO platform so it’s easier for you to deal with container orchestration and so on. More details soon.![](https://xcp-ng.org/forum/assets/images/touch/512.png)XCP-ngolivierlambert![](https://xcp-ng.org/forum/assets/uploads/profile/1-profileavatar-1620659303584.jpeg)](https://xcp-ng.org/forum/topic/5624/containers-or-kubernetes-users-we-need-your-feedback?ref=xen-orchestra.com) ### Xen Orchestra 5.67 URL: https://xen-orchestra.com/blog/xen-orchestra-5-67/ Last updated: 2025-07-28T08:35:39.000Z Our first release of the year for Xen Orchestra. We have many projects for this year that we can't wait to present to you. We were live on YouTube to talk about our **2022 roadmap** a week ago - [check the replay](https://youtu.be/h0Qu64qvt0Y?t=287&ref=xen-orchestra.com) to catch up. We were also live on Friday to preview the 5.67 release, and we plan to do that for every release this year. To be kept informed, don't forget to subscribe to our different social networks where we communicate the exact dates and times of this kind of live session: 🙆 [Facebook](https://www.facebook.com/vatesfr) 🐦 [Twitter](https://twitter.com/xenorchestra?ref=xen-orchestra.com) 🤖 [Discord](https://discord.gg/RECjrfeW?ref=xen-orchestra.com) ## Video review We did an exclusive live session with our followers on social media. If you want to watch a replay of the livestream, you can find it below: ## ✨ XCP-ng 8.2.1 ![](https://xcp-ng.org/blog/content/images/2020/11/xcp-ng82-LTS.png) XCP-ng 8.2.1 will be available very soon. We currently have a release candidate that you can test for this new update. All the information you need for testing is available in the [dedicated forum post](https://xcp-ng.org/forum/topic/5492/xcp-ng-8-2-1-maintenance-update-ready-for-testing?ref=xen-orchestra.com). ## 🆕 XO proxy as reverse proxy for XCP-ng ![](https://xen-orchestra.com/content/images/2019/04/xo-5c-20proxy_38106051.png) ⚠️ We now have a HTTP proxy feature directly embedded in the proxies. Take a look on [release blogpost on the topic](https://xen-orchestra.com/blog/xen-orchestra-5-70/#%F0%9F%95%B8%EF%B8%8F-http-proxy-in-xo-proxy). Until now, XO proxies were only used to facilitate backups in remote sites. It is now possible to use them as reverse proxies and thus avoid your central XOA needing to communicate individually with several remote hosts or pools through the internet. It's also less rules to add or traffic to monitor in your firewall! This new feature should provide an additional layer of security for your remote infrastructure, as it will go from: ![](https://xen-orchestra.com/blog/content/images/2022/01/no-proxy.png) Request from XOA without proxy to: ![](https://xen-orchestra.com/blog/content/images/2022/01/proxy.png) Request from XOA with proxy To start using your XO proxy as a reverse proxy for XOA, you will need to create a configuration file in `/etc/xo-proxy/config.toml` on this very proxy, with for example: ```toml [reverseProxies] '/xcp1' = 'http://192.168.100.1' '/xcp2' = 'http://192.168.100.10' ``` In that case, `192.168.100.1` and `192.168.100.10` are your two pool masters. You'll need to add each pool master in this configuration file. Then, from your central Xen Orchestra, you can add your pools in Settings/Server via the following URLs: - `https://xo-proxy.example.com/proxy/v1/xcp1/` - `https://xo-proxy.example.com/proxy/v1/xcp2/` With `xo-proxy.example.com` as your XO Proxy address or IP. Then, all your connections to your XCP-ng/XenServer hosts will flow through your XO Proxy! ## 🔧 Resilience enhancements ### Fallback process when pool master is unresponsive In order to avoid service interruptions due to loss of connection with the pool master, XOA will now keep track of the IPs of all hosts in the pool upon first connection. In case of loss of contact with the usual pool master, XOA will try to reach the other hosts until one of them answers. ### Rolling pool update improvement To avoid problematic situations during a rolling pool update for users of the load balancing plug-in, we have improved the rolling pool update feature so that it automatically disables the load balancing plug-in in order to avoid problematic behaviour that could occur when it is active during an upgrade sequence. ### Health view - Pool with no default SR In the "health" view of your infrastructure, we have added a table allowing you to identify the pools for which no default SR is specified. Not having a default SR can lead to unexpected behaviours within your infrastructure. ## 💽 Backup ### S3 performance improvements ![](https://xen-orchestra.com/blog/content/images/2021/12/s3-backup.png) We have fixed and improved many things within our Backup S3 feature. The most notable change is the merge optimization in `vhdDirectory` \- this optimization has increased merge performance **by at least 10 times!** ## 🔄 Interoperability We are always working to improve the interoperability of our stack with all IT infrastructure. ### VMDK export We have now added the possibility to export your VMs in VMDK format, while keeping the VHD export feature too. Click on the usual disk export button, then you'll have the choice on format: VHD or VMDK! ![](https://user-images.githubusercontent.com/7724491/146158209-f344c03a-f9f5-4036-9313-5db162d8e8fe.gif) ### VirtOps#4: track any change in your virtualized infrastructure URL: https://xen-orchestra.com/blog/virtops-4-track-any-change-in-your-virtualized-infrastructure/ Last updated: 2021-12-29T14:23:32.000Z This is another blog post in our [VirtOps series](https://xen-orchestra.com/blog/tag/devops/). This time, we'll cover a new topic: tracking changes in your virtualized infrastructure (XCP-ng or XenServer/Citrix Hypervisor) thanks to our Netbox plugin in Xen Orchestra. ## Context 6 months ago, we added a new plugin in Xen Orchestra: our great Netbox sync feature. Since then, you can synchronize all your VMs and host IP addresses to your Netbox instance. See our initial announcement below: [DevBlog #9 - Netbox synchronization with XOWhen you start to have a lot of virtual machines and IP addresses, you might need to organize a bit with an IPAM. Netbox is such a thing.![](https://xen-orchestra.com/blog/favicon.png)XO BlogOlivier Lambert![](https://xen-orchestra.com/blog/content/images/2021/05/netboxsyncheader.jpg)](https://xen-orchestra.com/blog/netbox-sync-with-xen-orchestra/) But Netbox is more than just [an IPAM](https://en.wikipedia.org/wiki/IP%5Faddress%5Fmanagement?ref=xen-orchestra.com). It's a real way to manage your whole infrastructure (virtual and real) from one web UI. For example, you can have your own rack displayed, like we do for our own production and lab infrastructure: ![](https://xen-orchestra.com/blog/content/images/2021/12/rack.jpg) Our current production rack displayed in Netbox UI But this is not the main topic today. We'll talk about change tracking in your infrastructure, when you modify anything on your VMs, to keep a trace of this change. Regardless the fact that change was made by Xen Orchestra or any other client! ## Change tracking If you already have a fully automated infrastructure, for example, thanks to our Terraform provider, then you already know and manage correctly all your changes. On that topic, take a look at our previous articles on Terraform: [VirtOps #1: XO Terraform providerDevOps series is back, and with great content about Terraform and Xen Orchestra!![](https://xen-orchestra.com/blog/favicon.png)XO BlogDom Del Nano![](https://xen-orchestra.com/blog/content/images/2020/11/terraformmars-2.jpg)](https://xen-orchestra.com/blog/virtops1-xen-orchestra-terraform-provider/) [VirtOps #2: Managing existing infrastructure with TerraformHow can Terraform be used for existing infrastructure outside of Terraform’s management?![](https://xen-orchestra.com/blog/favicon.png)XO BlogDom Del Nano![](https://xen-orchestra.com/blog/content/images/2021/01/nasa-E7q00J_8N7A-unsplash.jpg)](https://xen-orchestra.com/blog/managing-existing-infrastructure-with-terraform-2/) But even in that case, checking what really changed in your virtualized infrastructure is important. And that's exactly **where the Xen Orchestra combo with Netbox is great**. ### Any change, any client To understand the power of change tracking via Xen Orchestra + Netbox sync, you need first to remember the big picture: ![](https://xen-orchestra.com/blog/content/images/2021/12/xo-arch.94e9d75a.jpg) In short, Xen Orchestra is connected to your whole infrastructure and get **all changes and events** happening, 24/7\. That's a good way to remember why XO is superior to other clients, thanks to the ability to run via a central daemon, `xo-server`. It means that any change made via `xe`, XenCenter, Xen Orchestra or any other client will be visible in a next Netbox sync. > For how to configure the Netbox plugin, please check our documentation: [https://xen-orchestra.com/docs/advanced.html#netbox](https://xen-orchestra.com/docs/advanced.html?ref=xen-orchestra.com#netbox) Note that you can create a dedicated netbox user for your sync from Xen Orchestra, this way, your changelog will be more clear. ### Netbox UI The default Netbox dashboard will have a "Change Log" panel on the bottom: ![](https://xen-orchestra.com/blog/content/images/2021/12/netboxdash.png) In the bottom: the change log list all modifications on your infrastructure But you can also access the changelog panel on your main menu, "Other" then "Changelog" entry, and you'll have this: ![](https://xen-orchestra.com/blog/content/images/2021/12/changeloglist.png) Obviously, you can filter on objects, users and whatnot to discover all the changes. > Note: in our production context, we decided to sync XO to Netbox every hour. ### Explore a modification You can click on the ID in the previous table, and this will show you the details. You can imagine a wide number of interesting data to track, outside the obvious IP address change: memory, VM power status, disk size, placement and so on! Let's explore some changes that has been made in our infrastructure, and how Xen Orchestra Netbox plugin sync is helping in this context. #### Disk size changed ![](https://xen-orchestra.com/blog/content/images/2021/12/disksize.png) It's pretty clear that we added 10GiB of disk space for this VM #### VM power status changed ![](https://xen-orchestra.com/blog/content/images/2021/12/Capture-d--cran-de-2021-12-29-14-56-13.png) We decided to shutdown this VM: the change is visible just after a sync ## Conclusion As you can see, any change is **very** visible and clearly explained. Combining Xen Orchestra and Netbox together can do more than their respective features. Thanks to a Xen Orchestra plugin originally made for synchronizing IP addresses, you can now even control and inspect any configuration change in your whole virtualized infrastructure! Netbox is truly a great tool, we recommend to deploy and use it 👍 ![](https://xen-orchestra.com/blog/content/images/2021/12/netbox.png) ### Xen Orchestra 5.66 URL: https://xen-orchestra.com/blog/xen-orchestra-5-66/ Last updated: 2021-12-21T16:25:57.000Z Let's start with our progress on XO Lite, then new features, improvements, and also asking you to help us to shape the future of XO. Don't miss our next live on Youtube and take a look on our 2021 retrospective. Grab a hot drink and enjoy the read ☕ ## ✨ Xen Orchestra Lite We've been working on the design of Xen Orchestra Lite ([read this blog post](https://xen-orchestra.com/blog/xen-orchestra-lite/) if you forgot what it is). In a nutshell, this will be the default simple web UI when connecting on your host. It's not meant to replace Xen Orchestra, as it will be only "local" (for your pool) and non-persistent. Thanks to our new UX designer, [Clémence](https://www.bxdesign.io/?ref=xen-orchestra.com), we've established our first mock-ups. Take a look: ![](https://xen-orchestra.com/blog/content/images/2021/12/dashboard-default-light-mode.png) Pool dashboard view, "light" theme. ![](https://xen-orchestra.com/blog/content/images/2021/12/dashboard-default-dark-mode.png) Pool dashboard view. And yes, we also planned a dark mode ;) We'll share more in 2022 and obviously, we'll need you to get your feedback on our prototypes! ## 🆕 New features and improvements ![](https://xen-orchestra.com/blog/content/images/2021/12/s3-backup.png) ### S3 backup lands to stable Thanks to some feedback from the user community, we have been able to fix some final things in our S3-capable backup storage. S3 backup will land, this month, in the `stable` branch of Xen Orchestra and therefore be available for everyone. ### S3 compression While the main S3 backup feature is now available for production environments in the `stable` release branch, we are still improving the solution. This month, we are introducing compression in S3 backups. It's active per default on `latest`, it uses the Brotli compression algorithm and it should (hopefully) save you some space in your S3 storage. During our tests, we saw size reduction going **from 30% to 60%** depending on the VMs we were backing up. However, note that this could vary a lot depending on your data. ### Ability to set suspend SR To make the snapshot with RAM more accessible and easier to configure, we exposed in XOA the ability to set the suspend SR (where suspended VMs RAM is stored): ![](https://user-images.githubusercontent.com/7724491/145981210-dc542562-f857-4ee8-b457-06d29f2ecaa9.gif) We found that snapshots with memory were used in various cybersecurity related investigations: it's very handy to inspect the memory after you've been hit by an attack (or thinking you could have). It might also help to find valuable information on the attacker, keys and all objects in memory. Being able to customize what SR this RAM image is stored on should allow even more flexibility. ### Warning when default SR is not shared on multiple hosts pools When you configure a default SR in a pool, all hosts in that pool must have access to that SR in order to work properly. To avoid issues in your infrastructure, we decided to add a warning in the Dashboard/Health view that detects default SRs that are not shared on multiple hosts in a pool. ![](https://user-images.githubusercontent.com/70369997/145582786-0b45ece9-d53f-491b-8e6d-146af1a046d9.png) ### Disable HA during rolling pool update When doing rolling pool updates, you need to be sure that HA is disabled to avoid issues: indeed, it's normal to restart the master host first, without promoting any slave to master while it's rebooted. Until now, disabling HA was a manual action that you had to perform on your side before actually running a pool update. It is now a fully automated process which is part of the rolling pool update feature! ## 📅 Events and community ![](https://xen-orchestra.com/blog/content/images/2021/12/youtube-1-1.png) ### We are going live on YouTube To celebrate the coming new year, we decided to try something new! We will gather some of our team members and host a livestream on Youtube on **January 18th, 3PM CET.** During this livestream, we will review the year 2021, the major projects we have started and those to come in the near future. It will also be an opportunity to ask your questions directly to our team. So we are waiting for you on our [Youtube channel on January 18th](https://www.youtube.com/channel/UCNjvBiVTxBt-madrH2Kt7iA?ref=xen-orchestra.com)! ### We need your feedback We want to involve our community as early as possible in the process of designing and creating the new XO6 UI, look, and functionality. That's why we need you to tell us a little bit about yourself and your infrastructure. Note that this questionnaire is only the first step in our community involvement process, if you want to be involved in several stages of Xen Orchestra 6 development, start by completing this questionnaire. Launch me > *If you don't see the button on the right side, here is the direct [link to the form](https://xenorchestra.typeform.com/to/Cr43RpMU?ref=xen-orchestra.com)* ### Our support platform is evolving As you know, our core business, before providing a software solution, is to offer an outstanding user experience. At the heart of this experience is the quality of our support, provided directly by a team of developers who are experts in the technologies we use. In an effort to provide an ever-improving support experience, we have recently changed our platform. This new support platform will allow us to better process your tickets, ensure better follow-up, but also offer greater comfort to users. In particular, this new support platform allows users to create an organization and thus allow several different accounts to access support in this way. A highly requested feature! We updated our knowledge base consequently: [Vates Knowledge Base - Open a support ticket![](https://help.vates.fr/favicon.ico)Open a support ticket![](https://help.vates.fr/api/v1/attachments/19705)](https://help.vates.fr/kb/en-us/8/15?ref=xen-orchestra.com) ## 🏢 Vates in 2021 And to finish this year, here is a recap on what happened for [Vates](vates.fr) in 2021! ### Xen Orchestra 5.65 URL: https://xen-orchestra.com/blog/xen-orchestra-5-65/ Last updated: 2021-11-30T20:01:32.000Z First, the long requested Amazon S3 backup feature is finally available and we're looking forward to your feedback to bring the last optimizations to this new backup option. Then, on the infrastructure-as-code, we have a new shiny thing: the Ansible inventory plugin. It's another commitment on getting XO as a real central point -or middleware- for your entire virtualized infrastructure. ## Amazon S3 backup As we announced in the Xen Orchestra 5.63 release, [Florent](https://xcp-ng.org/forum/user/florent?ref=xen-orchestra.com), our new developer, joined our team in order to work on this very anticipated feature. ![](https://xen-orchestra.com/blog/content/images/2021/11/s3-backup.png) We are very happy to say that a lot of progress has been made. So much in fact, that we are confident to say that the Amazon S3 backup feature is fully functional in Xen Orchestra. S3 backup is not only working with AWS directly, but also with any providers offering the ability to backup on an S3 storage or even internally on a [minIO](https://min.io/?ref=xen-orchestra.com) instance for example - this is the reason we made it compatible with non-signed certificates. We are confident in the robustness of this feature, but to cover a wide range of configurations and make sure we leave nothing to chance, we need feedback from users outside our lab. If you are testing this feature, please feel free to open a support ticket to give us your feedback. For users of the community version, [this is the place to go](https://xcp-ng.org/forum/topic/5256/s3-backup-try-it?ref=xen-orchestra.com). Finally, a technical blog post will come soon, with more details on how we solved the "remote coalesce challenge", speeding up the process to make it almost instant instead of running for hours. ## Ansible inventory plugin > Ansible is an open-source provisioning, configuration management, and application-deployment tool enabling [infrastructure as code](https://en.wikipedia.org/wiki/Infrastructure%5Fas%5Fcode?ref=xen-orchestra.com). ![](https://xen-orchestra.com/blog/content/images/2021/11/Ansible_logo.png) A few days ago, we released a blog post about a new plugin in Xen Orchestra: the Ansible plugin. This plugin allows the listing ****and** grouping of XOA virtual machines, hosts and pools. We decided to add Ansible capabilities on top of Xen Orchestra for the same reasons we [created a Terraform plugin](https://xen-orchestra.com/blog/virtops1-xen-orchestra-terraform-provider/) for it: XO is acting as a real central point -or middleware- for your entire infrastructure. We wrote a complete blog post about this plugin, so if you want to learn more, [it's happening here.](https://xen-orchestra.com/blog/virtops3-ansible-with-xen-orchestra/) ## Save your CloudInit network config You can now save your network configuration when using the CloudInit feature. This feature works the same way as the user configuration. We extended this so it's really helpful to prepare your "template" of network configs and deploy your CloudInit-ready VMs even faster. ## Identify XAPI errors in backup logs Occasionally, we have some support tickets created by users because they have an error with one of our backup features. Even more regularly, it appears that the error is in fact coming from the hypervisor layer (XCP-ng/Citrix Hypervisor), in particular from the XAPI (Xen API). ![](https://xen-orchestra.com/blog/content/images/2021/11/142422226-043e6c10-ad11-495c-96e1-ae937e814ba7.png) To avoid confusion, we decided to display in a visible way the origin of errors occurring during backup jobs. It is useful for the user to better identify issues they might have in their infrastructure but it's also useful for our support team to better dispatch support tickets to the XO team or the XCP-ng team. ## Allow exporting VM checkpoint memory VDI A few weeks ago, one of our users suffered a ransomware attack. Thanks to our efficient DR and backup strategy, this attack was without major consequences for our customer infrastructure and transparent for most users. On the other hand, in order to carry out feedback and to understand the origin of this attack, he requested a memory export from a "checkpoint snapshot" for forensic analysis. It was possible with some XCP-ng experience with \`xe\` CLI, but we thought it would be easier to expose that feature directly in Xen Orchestra UI. ![](https://xen-orchestra.com/blog/content/images/2021/11/143428193-ffe980f0-e15b-43f4-9c2e-fde18914a048.png) We thought it would be a nice addition in XOA so we made it a feature! This is an important step for our growing "security" use-cases. > You can create a snapshot with memory in Xen Orchestra, VM view/snapshot tab/New snapshot with memory. ## Extra check on XOA deploy from XCP-ng Recently, one of our best ambassadors, Tom from [Lawrence Systems, made a live stream](https://www.youtube.com/watch?v=HfqmaAa9awU&ab%5Fchannel=LawrenceSystems&ref=xen-orchestra.com) talking about Xen Orchestra. [Olivier](https://xen-orchestra.com/blog/author/olivier/) participated, and it was a great opportunity to hear a number of comments to improve our XCP-ng/XO stack. We started the work on some suggestions, and this month, we already started to deliver one simple but useful feature: you can't deploy your XOA with the same IP address as your XCP-ng host. Sounds obvious, but we had some users confused, triggering IP address conflicts. This will be now prevented, as you can see in the following screenshot: ![](https://xen-orchestra.com/blog/content/images/2021/11/143887159-19c2f87a-eedd-4e28-94b0-aa39693e1bc2.png) ## XO CLI filters This is another example of a feature asked by our community. This time, it's about improving filters when using our CLI. You could already use Xen Orchestra advanced filters in XO web UI (using the search field). But now, you can use the exact same filters for XO CLI. Here is some examples. Return all VMs with more than 2 snapshots: ```bash xo-cli xo.getAllObjects filter='type:/^VM$/ snapshots:length:>2' ``` All VMs with HA enabled: ```bash xo-cli xo.getAllObjects filter='type:/^VM$/ high_availability? ``` And all other examples available in our [official doc regarding our live filter search](https://xen-orchestra.com/docs/manage%5Finfrastructure.html?ref=xen-orchestra.com#live-filter-search). ## XO Lite More work under the hood this month, mainly to build some future UI components. But it's already visible on the login page, which is nicer than previously: ![](https://xen-orchestra.com/blog/content/images/2021/11/Capture-d--cran-de-2021-11-30-16-51-47.png) > Don't forget to force refresh your XO Lite with `Ctrl`\+ `Shift` \+ `R`. Initial feedback is welcome on our [dedicated topic!](https://xcp-ng.org/forum/topic/5018/xo-lite-building-an-embedded-ui-in-xcp-ng?ref=xen-orchestra.com) ## XO 6 and the future We started to work with an UX designer, [Clémence](https://www.bxdesign.io/?ref=xen-orchestra.com). We are building together the next look and feel for our next big revamp of Xen Orchestra. Also, the initial concepts will be likely implemented in XO Lite first (it's easier since we start completely on a blank page). More to come on that topic next month, we hope to show you our initial mockups! ### VirtOps #3: Ansible with Xen Orchestra URL: https://xen-orchestra.com/blog/virtops3-ansible-with-xen-orchestra/ Last updated: 2021-11-25T09:53:39.000Z With the release of [Ansible Community 4.1.0](https://github.com/ansible-collections/community.general/blob/stable-4/CHANGELOG.rst?ref=xen-orchestra.com#v4-1-0) came a new inventory plugin for Xen Orchestra. This plugin allows the listing **and** grouping of XOA virtual machines, hosts and pools. In this article we will see how to install and use it. ## Ansible: a quick intro ![](https://xen-orchestra.com/blog/content/images/2021/11/Ansible_logo.png) Ansible is an open-source software provisioning, configuration management, and application-deployment tool enabling [infrastructure as code](https://en.wikipedia.org/wiki/Infrastructure%5Fas%5Fcode?ref=xen-orchestra.com). It helps to manage multiple machines by selecting portions of Ansible's inventory stored in simple ASCII text files. The inventory is configurable, and target machine inventory can be sourced dynamically or from cloud-based sources in different formats (YAML, INI). If you want to learn more about it, check the [Wikipedia page](https://en.wikipedia.org/wiki/Ansible%5F%28software%29?ref=xen-orchestra.com), or the [official website](https://www.ansible.com/?ref=xen-orchestra.com). ### Ansible Collections Collections are a distribution format for Ansible content that can include playbooks, roles, modules, and plugins. ## Ansible + Xen Orchestra = 💖 We decided to add Ansible capabilities on top of Xen Orchestra for the same reasons we [created a Terraform plugin](https://xen-orchestra.com/blog/virtops1-xen-orchestra-terraform-provider/) for it: XO is acting as a real central point -or middleware- for your entire infrastructure. ![](https://xen-orchestra.com/blog/content/images/2021/11/xoxcpmulti.png) One Xen Orchestra to rule all your hosts! At some point, that's the same architecture choice VMware did with vCenter. ### Xen Orchestra Inventory plugin This package is not included in `ansible-core`, you will have to install it using `ansible-galaxy`: ```bash $ ansible-galaxy collection install community.general ``` Let's start by creating the plugin configuration file, its filename must end with `xen_orchestra.yml` or `xen_orchestra.yaml`: ```yaml plugin: community.general.xen_orchestra api_host: 192.168.1.255 user: xo password: xo_pwd ``` my.xen\_orchestra.yml You can now explore our inventory: ```bash ansible-inventory -i my.xen_orchestra.yml --list ``` ```json { "_meta": { "hostvars": { "099c01b4-6e21-4466-a6c8-037d41d36d7c": { "address": "192.168.1.11", "cpus": { "cores": 16, "sockets": 1 }, "enabled": true, "hostname": "r740", "memory": { "size": 34287759360, "usage": 7765843968 }, "power_state": "running", "product_brand": "XCP-ng", "tags": [], "type": "host", "version": "8.2.0" }, "df4577f2-efa2-685f-af98-e82da3050dc0": { "ansible_host": "192.168.1.12", "cpus": 1, "has_ip": true, "ip": "192.168.1.12", "is_managed": true, "memory": 2147463168, "name_label": "Test machine", "os_version": { "distro": "ubuntu", "major": "20", "minor": "04", "name": "Ubuntu 20.04.3 LTS", "uname": "5.4.0-90-generic" }, "power_state": "running", "tags": [], "type": "VM", "uuid": "df4577f2-efa2-685f-af98-e82da3050dc0" } } }, "all": { "children": [ "halted", "paused", "running", "suspended", "ungrouped", "with_ip", "xo_host_r740", "xo_hosts", "xo_pool_xcp_ng_main", "xo_pools" ] }, "running": { "hosts": [ "df4577f2-efa2-685f-af98-e82da3050dc0" ] }, "with_ip": { "hosts": [ "df4577f2-efa2-685f-af98-e82da3050dc0" ] }, "xo_host_r740": { "hosts": [ "df4577f2-efa2-685f-af98-e82da3050dc0" ] }, "xo_hosts": { "hosts": [ "099c01b4-6e21-4466-a6c8-037d41d36d7c" ] }, "xo_pool_xcp_ng_main": { "hosts": [ "099c01b4-6e21-4466-a6c8-037d41d36d7c", "df4577f2-efa2-685f-af98-e82da3050dc0" ] } } ``` This is the inventory generated from with one Virtual Machine named "Test Machine" hosted on "R740" in the "XCP Ng Main" Pool. Let's break it down! - `halted`, `running`, `paused` and `suspended` group Virtual Machines by their power states - `with_ip` and `without_ip` group Virtual Machines by our ability to get an IP address from them. If we cannot find the IP (most likely because the `guest-tools` are not installed), then the Virtual Machine is added to the `without_ip` group. - `xo_host_*` will group Virtual Machines that are hosted on a given host - `xo_hosts` are the UUIDs of all the known hosts - `xo_pool_*` will group Virtual Machines that are hosted in a given pool ### Going further The default groups would allow you to ping every known running machines for example: ```bash $ ansible running -i my.xen_orchestra.yml -m ping ``` ```bash df4577f2-efa2-685f-af98-e82da3050dc0 | SUCCESS => { "ansible_facts": { "discovered_interpreter_python": "/usr/bin/python3" }, "changed": false, "ping": "pong" } ``` But we could also do something more useful, let's go back to our plugin configuration: ```yaml plugin: community.general.xen_orchestra api_host: 192.168.1.255 user: xo password: xo_pwd groups: webservers: "'webserver' in tags" ``` my.xen\_orchestra.yml And add a `webserver` tag on our Virtual Machine ![](https://xen-orchestra.com/blog/content/images/2021/11/image-1.png) If we explore our inventory again: ```bash $ ansible-inventory -i my.xen_orchestra.yml --list ``` We now have a `webservers` group ``` ... "webservers": { "hosts": [ "df4577f2-efa2-685f-af98-e82da3050dc0" ] }, ... ``` ## Real world usage Let's create a playbook and run it: ``` --- - name: Update web servers hosts: webservers remote_user: root tasks: - name: Ensure apache is at the latest version ansible.builtin.yum: name: httpd state: latest - name: Write the apache config file ansible.builtin.template: src: /srv/httpd.j2 dest: /etc/httpd.conf ``` main.yml ```bash $ ansible-playbook main.yml -i my.xen_orchestra.yml ``` ```bash PLAY [Update web servers] TASK [Update web servers : Ensure apache is at the latest version] ok: [df4577f2-efa2-685f-af98-e82da3050dc0] TASK [Update web servers : Write the apache config file] ok: [df4577f2-efa2-685f-af98-e82da3050dc0] ``` ### A small note We use `uuid` as what Ansible calls `host`, this is because we cannot guarantee that all the Virtual Machines returned by the Xen Orchestra API will have an IP address, for example if `guest-tools` are not installed. For Virtual Machines that do not have an known IP address, the value of the magic variable `ansible_host` will not be defined and therefore Ansible will try to use the value of the `uuid` variable to connect. This will fail. For this reason, you may need to disable fact gathering with `gather_facts: no`. ## Doing more With that list of Virtual Machines, Hosts and Pools, you could imagine doing: - Applying updates to a list of outdated machines 🚨 - Doing specific tasks on a group of distros 🧑‍🔧 - Patching hosts 🩹 - And many other things! 🚀 Finally, this initial inventory plugin is just a start. We'll add more Ansible-related features, through our great community input. On that, please [share your feedback on our dedicated forum thread!](https://xcp-ng.org/forum/topic/5235/ansible-with-xen-orchestra?ref=xen-orchestra.com) ### Xen Orchestra 5.64 URL: https://xen-orchestra.com/blog/xen-orchestra-5-64/ Last updated: 2022-02-16T17:39:03.000Z The new update of Xen Orchestra is available. This update focuses on quality of life improvements, better backup and usability, while our team continues their work on Xen Orchestra Lite and Xen Orchestra 6. ## QoL improvements "QoL" stands for *Quality of Life*: all improvements to make XO everyday's usage better, faster or just easier. ### More readable tasks page ![](https://user-images.githubusercontent.com/7724491/136574045-f782bda4-98d7-4729-b806-9689c0d55e9d.png) Short tasks in the task view are hidden by default, in order to avoid an overload of information when a lot of small things are happening in your infrastructure (like `SR.scan` for example). This should make the task view more readable and useful for users. ### Proxy update notification [XO Proxies](https://xen-orchestra.com/?ref=xen-orchestra.com#!/proxy-home) are one of the handy solutions among the products our team is working on. We regularly update this solution and it is important that our users stay up to date. We added a notification icon on the proxy menu available in Xen Orchestra when an update is available for proxy deployments. This way, you can't miss it! ![](https://user-images.githubusercontent.com/7724491/137459289-b6a8d297-45da-4dc3-b67a-3f2014aaf246.png) ### Disable host without triggering host evacuate When you put a host in maintenance mode, Xen Orchestra automatically triggers an evacuation of all the VMs to another host, and then disabling the host. Disabling a host will prevent VMs on that host from being shut down. In some infrastructures, this maintenance mode can cause some issues and must be bypassed (eg. if you only have one host in your infrastructure). We added an option allowing you to disable a host without triggering the automatic `evacuate` command. ![](https://xen-orchestra.com/blog/content/images/2021/10/137502316-eaf261fb-0e05-4d2f-9950-4e7620fd1ecf.png) ![](https://xen-orchestra.com/blog/content/images/2021/10/137702594-a726a402-9c63-4189-8d54-e930bab0304c.png) ![](https://user-images.githubusercontent.com/7724491/137505155-5b1b48ff-ec8e-4e87-ad07-d4c981b0ca5a.png) ### Retrocompatibility with older Netbox ![](https://xen-orchestra.com/blog/content/images/2021/10/netbox.png) We improved our netbox plugin compatibility with older versions of Netbox. While we are encouraging our users to keep their infrastructure up-to-date as much as possible, we also know that in some distributions that include Netbox, it is impossible to update the software easily. This is the reason why we improved old Netbox version compatibility in the Xen Orchestra plugin for Netbox. ## XO Lite We are still making progress on XO Lite. If you want a recap on the project's goal, and maybe test or give feedback to it, take a look [at this link](https://xcp-ng.org/forum/topic/5018/xo-lite-building-an-embedded-ui-in-xcp-ng?ref=xen-orchestra.com). ### Treeview - Highlight selected VM Treeview is improved with the active selected VM is visible. Here is a quick glimpse of the new look: ![](https://user-images.githubusercontent.com/7724491/136571905-ea411369-e718-475b-a4c2-12cd66ac1dc2.gif) ## Backup One of the most used features in XO are backup. And good news, there's various improvements in that area! ![XO-backup](https://xen-orchestra.com/blog/content/images/2021/10/XO-backup.png) ### Enable merge worker by default Merge workers have been announced in [Xen Orchestra 5.62](https://xen-orchestra.com/blog/xen-orchestra-5-62/#betavhdmergeworker). We got some useful feedback during that period and we think that merge workers are now ready to be used in production environments. For this reason, merge workers will now be activated by default on the `latest release` branch. ### Backup Network A while back, we decided to use the default migration network configured in XOA for the backup export. It appears that this option is not suitable, because you can configure a default migration network that XOA cannot access, making impossible for XOA to actually use this network for backup purposes. That's the reason why we introduced a new configurable network: backup network. To configure this network, you need to go into the advanced view tab of the pool. ### Proxy field for servers *We are continually working to improve the security of our tools without compromising performance. This new feature is a step in that direction.* We added a field during the creation or the editing of a server allowing the user to add a url for a HTTP proxy. This way, you will now be able to connect XOA to a server which is behind a HTTP proxy. ![](https://user-images.githubusercontent.com/50174/138430569-378a906a-477b-4271-b674-5c7f8eb35243.png) ## VM export URL While Xen Orchestra is designed as a very user-friendly tool that you can 100% use from a browser interface, sometimes, our users find it handy to have some extra capabilities. Instead of directly exporting a VM from the web browser, we now allow an option to copy a URL so it can be used elsewhere, with `wget` for example. This will allow VM downloads outside of the browser, which can be VERY handy sometimes. When downloading a VM/disk from XO, instead of directly opening the URL, it will now open a modal displaying a link to the export URL. You can either copy it or use it directly, it's now up to you. > Note that it's a single use URL and that it's only valid for a short period of time. ![](https://user-images.githubusercontent.com/70369997/138905226-71d98b42-a6a1-45fe-a006-1d23bc476530.gif) ### Xen Orchestra 5.63 URL: https://xen-orchestra.com/blog/xen-orchestra-5-63/ Last updated: 2021-11-30T20:04:01.000Z September release is now available. This release is focused on improving the overall user experience in Xen Orchestra. We also have part of our team still working on XO Lite. ## Duplicated MAC adresses view improved ![](https://user-images.githubusercontent.com/10992860/134886367-c194d28c-2bc3-4636-8134-6c6790181d83.png) In the health view of Xen Orchestra, we display all VMs that have duplicated MAC adresses. While this is a very interesting feature to avoid conflict in your infrastructure, there are situations where duplication of MAC addresses is not problematic and sometimes even desired. For example, if you are doing [Continuous Replication jobs](https://xen-orchestra.com/docs/continuous%5Freplication.html?ref=xen-orchestra.com#continuous-replication), it's highly possible that you will have some duplicated MAC adresses without it being an issue. To improve the usability of our health view, we are now automatically hidding all VMs that have the `start` operation blocked - as they are likely to be related to CR. In addition, we also added a switch to allow you to hide all VMs with duplicated MAC adresses if they are shutdown. ## Improved backup job edition After editing a backup job, the user is automatically returned to the overview page. Until now this page was reset with no regard to search filters, forcing users to refilter the page according to their needs. To improve the user experience, we are now keeping all filters active when you are going back on this page after a job edition. In addition, we also moved the filter selector on the top of the page instead of the bottom as it's easier to use it from there and make more sense than having it on the bottom of the page. ## Amazon S3 backup ![s3-backup](https://xen-orchestra.com/blog/content/images/2021/09/s3-backup.png) This feature is one of the most expected by our users who want to make backup in the cloud. A brand new developer (Florent) joined our development team last month specifically to work on the issues we encountered between our merge algorithm and the Amazon API. Good news is that we are making progress - we changed a lot our architecture, especially the way we are handling backup storage and it should allow us to get better overall performances as well as better merge time. This new architecture we are working on also allows us to think about future feature extension as compression and encryption, which was not possible before. ## XO Lite - treeview XO team is still working on the [XO Lite project](https://xen-orchestra.com/blog/xen-orchestra-lite/), and we started the work on the UI part. This month, we are introducing the treeview! This treeview is very important for us because it will probably serve as a beta version of the one we will use in the future Xen Orchestra 6\. Note this is very early design but this will give you an idea of it: ![](https://user-images.githubusercontent.com/10992860/135293641-d095da3e-f535-473a-a453-3c5e445a2d53.gif) ## Beta - VHD Merge worker Thanks to all the feedback we got from the first beta step, we changed the way to manage syncronisation between different instances using VHD Merge worker. We are also working on the possibility to run Merge Worker on the remote to improve performances (for example, running our merge binary program on your NAS directly, to enjoy local performances). ## Netbox plugin improvements ![](https://xen-orchestra.com/content/images/2021/05/netbox_logo.svg) We are continuously working on improving our users experience in Xen Orchestra. This month, we worked on the Netbox plugin in particular. ### Improved error message We improve the way we handle error message in the Netbox plugin. In case you didn't configure properly the UUID in your netbox plugin, you will now have a clear message explaining you the configuration process you must follow. ![](https://user-images.githubusercontent.com/10992860/134887066-c9c2b8de-2e0b-4456-9719-e82c2d67c89b.png) ### Support nested IPs range Nested IPs range are now handled correctly by our Netbox plugin. We compute automatically which IP is synchronized to which sub-IP range configured in Netbox, even if you have a nested ranges. ### Xen Orchestra 5.62 URL: https://xen-orchestra.com/blog/xen-orchestra-5-62/ Last updated: 2021-08-31T12:45:02.000Z Xen Orchestra 5.62 is available on the `latest` release branch! This release is mainly focused on improving performance and Quality of Life in Xen Orchestra. ## Allow users to create networks with ACLs Until now, creating networks within a pool was a privilege of super admins in Xen Orchestra. We have changed this rule to the following: a user who has admin rights on a pool will now be able to create networks on this pool. ## IP addresses: handle old tools In some situations, when multiple IP addresses were configured on a single VM, the old Xen tools were not able to handle them properly. We improved our compatibility with older versions to make it possible to manage multiple IPs on a single VM, even with older Xen tools. ## Display warning on EoL XCP-ng/Citrix Hypervisor versions We will now display a warning when your XCP-ng or XenServer version is reaching End of Life. It appears to us that displaying a warning for this information right in XOA is important to improve the security, stability and the support you expect. ![](https://user-images.githubusercontent.com/70369997/126182315-9276cf10-686a-4851-8447-e3fa7927ac4e.png) ## Use default migration network in backups Since [Xen Orchestra 5.55](https://xen-orchestra.com/blog/xen-orchestra-5-55/#defaultmigrationnetwork) you have the ability to select a default network in Xen Orchestra. To configure your network, you need to go into the advanced section of the pool. ![](https://user-images.githubusercontent.com/7724491/102532244-f50c4100-40a3-11eb-9cdd-5741da617d5e.png) ![](https://user-images.githubusercontent.com/7724491/102532238-f473aa80-40a3-11eb-86f5-15ba130bb42a.png) This network will now also be used by backup jobs in Xen Orchestra (during the export process). If you have infrastructure with a dedicated network that communicates with your storage, this will allow you to define this nework as the default and Xen Orchestra will automatically use it. > Note: You need to define a default migration network for each pool. ## Beta - VHD merge worker > If you are interested in this feature, please open a support ticket to request access. Note that you should not request this feature to use in a production environment for now. As we explained [last release](https://xen-orchestra.com/blog/xen-orchestra-5-61/#whatsnext), we intend to move the merge part of a backup job into a separate and independent process. This action will be performed for each remote. One worker will merge all the jobs one after the other. ### Xen Orchestra 5.61 URL: https://xen-orchestra.com/blog/xen-orchestra-5-61/ Last updated: 2022-01-08T13:14:56.000Z Xen Orchestra 5.61 is available and comes with some QoL improvements. The focus of our team is still on Xen Orchestra Lite as well as the future majore release: **Xen Orchestra 6**. ## XO Lite & Material UI ![](https://xen-orchestra.com/content/images/2021/05/xo-lite.png) As we announced last month, our team is hard at work with XO Lite. As we are making choices, we are willing to share some of them with you. XO Lite will be designed using Material UI, a very well known react framework. We chose this framework for multiple reasons, firstly because we think it looks good. It's also because it's a very popular framework, used by a lot of people and that will most likely be maintained for a long time. Finally, it has very good integration with React, which is the library we are using for Xen Orchestra for a while now. ## Use default migration network Xen Orchestra will now use the default migration network when XO performs a `host evacuate` action. > Host evacuate is an action made by the XAPI in various situations (eg. rolling pool updates) that will migrate all the VMs on a host. ## Force Shutdown ![](https://user-images.githubusercontent.com/10992860/127010030-02f10502-9340-4d86-824f-2f19f6b6ae82.png) If a clean shutdown/reboot of a VM failed, the user will now have the ability to force shutdown the VMs in the same dialog. ## Netbox plugin: allow self-signed certificate ![](https://user-images.githubusercontent.com/10992860/127155803-d20c0650-bcac-4fd7-bee9-9de4ec3d71fa.png) In the Xen Orchestra [Netbox plugin](https://xen-orchestra.com/docs/advanced.html?ref=xen-orchestra.com#netbox), you can now activate an option allowing you to use a self-signed certificate. ## Show active VDI for base copy ![](https://user-images.githubusercontent.com/70369997/123428510-2d965580-d5c6-11eb-92f2-f0be7ea87bc6.png) Base copies will now display the VDI to which they are attached. This will provide a better comprehension of chain disks of a given infrastructure but also be helpful to solve coalesce issues when they occur. ## What's next ### Merge worker The change of architecture (backup workers) has multiplied the number of I/O in parallel on the remotes. To solve this problem, we will remove the merge task from the backup execution in a separate process. In the long term it is possible that this worker will be deferred directly to the storage platform which will greatly improve the performance. ### Xen Orchestra 5.60 URL: https://xen-orchestra.com/blog/xen-orchestra-5-60/ Last updated: 2021-07-02T07:13:32.000Z This month, our Xen Orchestra team has been very busy with the development of Xen Orchestra Lite. As a reminder, this lite version of Xen Orchestra which will run directly at the host level, is also an important step in the development of the next major version of Xen Orchestra: **Xen Orchestra 6**. ## Xen Orchestra Lite ![](https://xen-orchestra.com/content/images/2021/05/xo-lite.png) Xen Orchestra Lite is, as its name suggests, a lightweight version of Xen Orchestra allowing you to manage your XCP-ng host via a user friendly web interface, requiring no installation and running directly from your web browser. Like the classic version of Xen Orchestra, it's based on the XAPI but won't require you to deploy an appliance to be used. Each XCP-ng host will expose an XO Lite app, which will allow you to perform basic management of its pool. Pierre, the lead developer of the XO lite project [wrote a complete DevBlog about all the work going on with XO Lite](https://xen-orchestra.com/blog/xen-orchestra-lite/) and how it will impact Xen Orchestra 6 in the future. ## XOSTOR beta Meanwhile, the XCP-ng team is still working on XOSTOR, our joint hyperconvergence solution with LINBIT. The closed beta is still in progress and if you want to join as a beta tester, you can still [register your email on this page](https://xcp-ng.com/xostor-beta?ref=xen-orchestra.com). ## QoL improvements ### Rescan ISO SRs You now have the ability to rescan all ISO SRs with a simple button. This is a QoL improvement that should make it much easier to update an ISO file over SFTP or other upload means by simply rescanning the ISO SR using a button right on any VM console page instead of having to go to the SR view to do it. ![](https://user-images.githubusercontent.com/70369997/122403555-c0a80d80-cf7e-11eb-8de3-fa5e93340b2d.png) ### Current snapshot We have added an extra piece of information for your VMs. You will now be able to see information about the current version of a snapshot your are using. ![](https://user-images.githubusercontent.com/10992860/123237493-03696880-d4de-11eb-9a8d-1e9caf09a72e.png) ### DevBlog #10 - Xen Orchestra Lite URL: https://xen-orchestra.com/blog/xen-orchestra-lite/ Last updated: 2021-06-30T13:58:13.000Z XO Lite is an ongoing project revolving around a XAPI-based web application -just like Xen Orchestra- but it doesn't require you to host any virtual appliance. Each XCP-ng host will expose an XO Lite app, which will allow you to do basic management of its own pool. ![xo-lite](https://xen-orchestra.com/blog/content/images/2021/06/xo-lite.png) > During the whole development phase, we had to find a way to move fast and update often, meaning users will be able to enjoy latest bits without any specific operation. That's why -for now- XO Lite code is hosted directly on our servers. > Join the discussion about XO Lite project on [the forum](https://xcp-ng.org/forum/topic/4731/xen-orchestra-lite?ref=xen-orchestra.com). ## How it works The XCP-ng host will serve a very simple HTML document (1) that looks pretty much like this: ```html ``` This loads a [React JS](https://reactjs.org/?ref=xen-orchestra.com) app from our servers (2) and runs it. Which means that even though you'll access it from the host's URL, the browser will grab all the code that really matters from our servers. Once the application is loaded, it will then autonomously communicate with your host in order to manage it through XAPI (3). ![XO Lite architecture](https://xen-orchestra.com/blog/content/images/2021/06/XoLite-1-1.png) ## Updates This architecture will allow us to deploy XO Lite updates without you having to install the update on your host, just like a website. Your XCP-ng host will always serve the same tiny HTML document without needing to update it and `lite.xen-orchestra.com` will be updated by us to serve the latest version of the application. ## Features Unlike XO which has a client side and a server side, XO Lite will only run in your browser, which means everything has to fit in it and some types of features that require a server side will never be able to be implemented in XO Lite. ### What's possible Everything that's possible to do with XAPI calls, like starting VMs, creating new SRs, managing networks and much more! You'll also be able to see and interact with VM consoles. ### What's not Since XO Lite is running **entirely in your browser**, it doesn't have a database nor persistent storage so it can't handle features like Users, Backups, Self Service, etc. In the end of the day, just remember **there's no persistence, and it's on purpose.** You can imagine that as a kind of "XenCenter from the Web". The other difference is that's made to be a "Per pool management" tool. So if you have to manage multiple pools, then you need to have multiple tabs opened. But at this point, that's exactly **when Xen Orchestra makes sense: a central tool to manage your whole infrastructure**. ## XO Lite & XO 6 In addition to XO Lite, we'll also be developing the next major version of XO itself: XO 6\. While the 2 projects are quite different, we're hoping to be able to mutualize a lot of development efforts between them. We decided to use [React JS](https://reactjs.org/?ref=xen-orchestra.com) (a JavaScript front-end framework) not only because all the XO developers at Vates already know that framework -since we already use it for XO 5- but also because it works with components that could be reused in any other React project. So we're hoping to be able to reuse most of the self-contained components in XO 6, like modals, forms with complex logic, components used to display all kinds of XO-related data or even a tree view for VMs. ## HTTPS & Self Signed Certificates For security reasons, a client and a server should always communicate using HTTPS rather than HTTP. Furthermore, the server should use a valid SSL certificate signed by a trusted certification authority so that the client is able to know for sure that it's talking to the right server. However, getting and updating a valid certificate for all your XCP-ng hosts isn't always easy and/or worth it, depending on the network configuration. So we're aware that most XO Lite users will have a self-signed certificate on their XCP-ng hosts. But here's the issue: if a web page tries to make an HTTPS request in the background to a server that sends a self-signed certificate, then most modern browsers will refuse to make that request. However, if you try to access a web page in HTTPS on a server that sends a self-signed certificate, then in that case, the browser won't immediately refuse it and will usually show a warning to the user, asking them if they want to bypass the certificate check and access the page anyway. If the user says yes, then the browser will remember that decision and will allow any further requests to the same origin (e.g. `xcpng1.company.net`). ![Self-signed certificate warning in Firefox](https://xen-orchestra.com/blog/content/images/2021/06/XoLite-2.png) Luckily, XO Lite will be served from the same origin as XAPI (ie your XCP-ng host), which means that, in order to access it with HTTPS, you'll first have to go through the browser warning about self-signed certificates and allow it. And once you do that, XO Lite will be able to communicate with XAPI securely and without any issues. ## Console XO Lite needs to be able to access the VMs' consoles, which isn't as straightforward as doing it from XO because of the lack of a server side: 1. XAPI's console endpoints can only communicate with raw TCP, which browsers aren't able to do yet. That's why xo-server has a WebSocket-to-TCP proxy: the browser can talk to xo-server with WebSockets and xo-server can translate it to TCP. However, XO Lite doesn't have a server side. But, conveniently, XAPI also exposes a [WebSocket proxy](https://github.com/xapi-project/wsproxy?ref=xen-orchestra.com) for consoles, which is what we'll be using. [XO was actually using wsproxy in the past](https://xen-orchestra.com/blog/faster-consoles-in-xo/) but then switched to a proxy directly in xo-server for performance reasons. However, the performance gap doesn't seem to be noticeable anymore. 2. Another issue with using wsproxy in XO Lite is that there was a small issue in wsproxy that prevented the console from working in Firefox: in order to initiate a WebSocket connection, an HTTP/1.1 handshake needs to be made between the client and the host. However, wsproxy was responding with HTTP/1.0, which Firefox doesn't accept as a valid response, unlike Chrome. [This tiny change XCP-ng team made](https://github.com/xapi-project/xen-api-libs-transitional/commit/c77ad87cb6f34894f32ccf051e3bf0bc7c12ff45?ref=xen-orchestra.com) fixed the issue in Firefox. That's **another example of great interactions between XO and XCP-ng teams!** Here is a working demo of a console working directly in your browser, connected to an XCP-ng VM: ![xolite1](https://xen-orchestra.com/blog/content/images/2021/06/xolite1.png) ## User session How can we keep an open XO Lite session across windows and tabs that survives page reloads and can be terminated by the user? Remember that we can't create our own session mechanism like we did with xo-server since there's no server in this case. But XAPI has its own session mechanism that xo-server itself already uses: XAPI provides a session ID on login, xo-server saves it and sends it back with every request. So we can also use that for XO Lite: if we have a valid session ID, we can store it in a cookie and XO Lite will be considered as "logged in" until the session ID expires, the cookie expires or the user explicitly disconnects from the session, which will invalidate the XAPI session ID. XO Lite won't have a user management feature since there's no way to authenticate a user or even create an account. So the only "user" there will be is the XCP-ng host's internal root user and its password. ### Xen Orchestra 5.59 URL: https://xen-orchestra.com/blog/xen-orchestra-5-59/ Last updated: 2021-05-31T13:33:38.000Z This month, our teams have been working hard on background tasks that pave the way for our next major releases: namely, Xen Orchestra Lite and Xen Orchestra 6 - we explain it all. ## XO Lite ![xo-lite](https://xen-orchestra.com/blog/content/images/2021/05/xo-lite.png) ### What it is Xen Orchestra Lite is, as its name suggests, a **lightweight** version of Xen Orchestra allowing you to manage your XCP-ng host via a web interface, user friendly, requiring no installation and running directly from your web browser. Xen Orchestra Lite aims to meet the needs of users with very small infrastructures (eg: 1 host) and for whom Xen Orchestra is an overkill tool for their needs. It's only "stateless" like *XCP-ng Center*, but in your browser. ### What it will do Unlike the full version of Xen Orchestra, which is a complete solution for companies to administer a virtual infrastructure from management to resource delegation and VMs backup, the Lite version aims to deliver a minimum of essential features - creating VMs, deleting VMs, migration and some additional surprises. Again, Xen Orchestra Lite aims to meet the needs of those who have virtually no administration to do on their infrastructure other than typical basic tasks. ### Why it matters for Xen Orchestra 6 The current work done by our teams on Xen Orchestra Lite, especially regarding the interface presentation, is paving the way for what will be our next major release for **Xen Orchestra: XO6**. This new interface, which we have already talked [about here](https://xen-orchestra.com/blog/devblog-3-working-on-xo-6/), will be more flexible, more customizable, and will answer to long lasting community expectations, such as a **treeview**. ## Netbox synchronization with XO ![](https://xen-orchestra.com/content/images/2021/05/netbox_logo.svg) When you start to have a lot of virtual machines and IP addresses, you might need to organize everything with an IPAM. Check how Xen Orchestra can help you to enjoy your IPAM (Netbox) without having to do any manual input! We have a [dedicated DevBlog](https://xen-orchestra.com/blog/netbox-sync-with-xen-orchestra/) on the topic with everything you need to know about this new feature. ## Report missing pools in smart backup When running a smart backup job, until now, a missing pool was simply ignored by the system and the user was never notified. This defect of behavior has been corrected in Xen Orchestra 5.59\. You will now get an error message in the UI as well as in your backup report informing you that a pool that should have been backed up in the job was missing. ![](https://user-images.githubusercontent.com/21563339/117156269-caeebd80-adbd-11eb-8094-9a1c89cfb63a.png) ![](https://user-images.githubusercontent.com/21563339/117156312-d5a95280-adbd-11eb-9f08-d3fb6cae56e9.png) ## Alert when restoring Metadata backup Restoring backup metadata is not a trivial action. Performing this operation on a healthy host can even have significant negative repercussions. That's why we have added an alert when a user is about to perform a metadata restore operation. ![](https://user-images.githubusercontent.com/21563339/117159875-f030fb00-adc0-11eb-8ada-c76dc0c99f1d.png) ![](https://user-images.githubusercontent.com/21563339/117159931-fd4dea00-adc0-11eb-9770-858259c37d3d.png) ### DevBlog #9 - Netbox synchronization with XO URL: https://xen-orchestra.com/blog/netbox-sync-with-xen-orchestra/ Last updated: 2021-05-27T09:51:11.000Z When you start to have a lot of virtual machines and IP addresses, you might need to organize everything with an [IPAM](https://en.wikipedia.org/wiki/IP%5Faddress%5Fmanagement?ref=xen-orchestra.com). Check how Xen Orchestra can help you to enjoy your IPAM (Netbox) without having to do any manual input! ## Netbox ![netbox_logo](https://xen-orchestra.com/blog/content/images/2021/05/netbox_logo.svg) NetBox is an open source web application designed to help manage and document computer networks. Initially conceived by the network engineering team at DigitalOcean, NetBox was developed specifically to address the needs of network and infrastructure engineers. It encompasses the following aspects of network management: - **IP address management (IPAM)** \- IP networks and addresses, VRFs, and VLANs - **Equipment racks** \- Organized by group and site - **Devices** \- Types of devices and where they are installed - **Connections** \- Network, console, and power connections among devices - **Virtualization** \- Virtual machines and clusters - **Data circuits** \- Long-haul communications circuits and providers - **Secrets** \- Encrypted storage of sensitive credentials ## The problem Having an IPAM is great, but if you are doing a lot of operations in your infrastructure (adding/remove VMs, same for IP addresses and so on), you'll have to make any modifcation twice: once in your Xen Orchestra and VMs, and once in your IPAM. This means more work and potential input typos. And bigger your infrastructure, harder it is to get accurate and up-to-date information between the reality and your IPAM. **This might even lead to dangerous situations** where you might use an IP address that's… already in use but not documented as such! ## The solution The solution is to synchronize Xen Orchestra data we have on your pools and VMs, directly to your Netbox! This way, every time you change an IP address in your VM or add new ones, no need to fill that in your Netbox instance. ![hexagon-synchronize--1](https://xen-orchestra.com/blog/content/images/2021/05/hexagon-synchronize--1.png) Indeed, as a central point to managed your whole infrastructure, XO already got everything we need: - all your VMs and pools UUIDs, names, descriptions and resources (vCPUs, memory, disk space) - VMs IP addresses (reported by xen tools) - VM status (active/offline) Basically, we'll sync that to your Netbox instance, to keep it entirely up-to-date. ### How it works Thanks to a new XO plugin, you can select **which pools** will be sync to your Netbox instance, but also how often (in hours) \* *if you want a full auto-sync solution:* ![netboxplugin](https://xen-orchestra.com/blog/content/images/2021/05/netboxplugin.png) At some point, you might want to trigger a manual sync, now you can do that in the pool view, advanced tab: ![netboxtriggersync](https://xen-orchestra.com/blog/content/images/2021/05/netboxtriggersync.png) Now, all the VMs on the selected pools will be visible in Netbox, with their detailed information (and modification history!). Here is some screenshots: ![vmlist](https://xen-orchestra.com/blog/content/images/2021/05/vmlist.png) ![vmobject](https://xen-orchestra.com/blog/content/images/2021/05/vmobject.png) ![ipprefix](https://xen-orchestra.com/blog/content/images/2021/05/ipprefix.png) You can even monitor the IP prefix usage: ![prefixusage](https://xen-orchestra.com/blog/content/images/2021/05/prefixusage.png) ### Documentation The whole setup is already [described in our documentation](https://xen-orchestra.com/docs/advanced.html?ref=xen-orchestra.com#netbox). > This feature will be available in our May release, for XOA 5.59 version on `latest` channel. ### Xen Orchestra 5.58 URL: https://xen-orchestra.com/blog/xen-orchestra-5-58/ Last updated: 2021-05-12T08:15:48.000Z It's april's release time and the third wave of improvements for Xen Orchestra backup features are coming with it. In addition, we are also making progress regarding our Amazon S3 plugin as well as our load balancing features which will become more and more complete in the next few months. ## NFS version update Xen Orchestra is no longer using NFS 3 version for NFS remote. We are now using the highest available version of NFS available. It should brings better performances and security for the concerned remote. However, if you want to stick with the previous behavior, you can put `vers=3` in the field `Custom mount options` in the remote view of your appliance. ## Xen Developers & Design summit ![Capture-d--cran-de-2021-04-30-11-17-00](https://xen-orchestra.com/blog/content/images/2021/04/Capture-d--cran-de-2021-04-30-11-17-00.png) This year again we are proud to sponsor the Xen Developers & Design summit alonside Arm! ![Capture-d--cran-de-2021-04-30-13-24-19](https://xen-orchestra.com/blog/content/images/2021/04/Capture-d--cran-de-2021-04-30-13-24-19.png) As last year, because of the COVID-19 pandemics, the event will be held online from 25th to 28th of May. You can visit the [official website](https://events.linuxfoundation.org/xen-summit/?ref=xen-orchestra.com) to register. **And this year, we have 4 talks!** Olivier, our CEO, will talk about [the emergence of DPU in the datacenter](https://xen2021.sched.com/event/jAEX/on-the-emergence-of-dpus-in-the-datacenter-olivier-lambert-vates?iframe=no&ref=xen-orchestra.com) and provide some insight about [XCP-ng project state and perspectives](https://xen2021.sched.com/event/jC3j/keynote-session-xcp-ng-project-state-and-perspectives-olivier-lambert-vates?iframe=no&ref=xen-orchestra.com). Bobby, our Xen specialist, will have also 2 talks: - [Xen and RISC-V](https://xen2021.sched.com/event/jAEy/keynote-session-hypervisor-extensions-in-risc-v-robert-eshleman-vates-sas?ref=xen-orchestra.com) - [Secure boot in Xen](https://xen2021.sched.com/event/jAEv/enabling-secure-boot-and-lockdown-on-xen-robert-eshleman-vates-sas?ref=xen-orchestra.com) ## Backup performance & security improvements ![](https://xen-orchestra.com/content/images/2021/01/XO-backup.png) Xen Orchestra 5.58 is the third wave of improvements regarding our backup features. ### Recoverable VHD merge During delta backup jobs, an important phase of the process is the merging of the VHD files on the remote. Until now, this merging was one of the weak points of the solution, because an interruption of the job at this point often meant that the entire backup chain was corrupted. This meant it now had to redo a full backup the next time the job ran in order to restart on a healthy basis. With our new backup code, we have now introduced the ability to recover from an interruption during this step. This is a big step forward in improving the reliability and robustness of our delta backup functionality. ### Lock VMs dir during backup We have added an extra security layer in our backup features to avoid corruption by locking the VMs backup directory on the remote when a backup job is running. The main objective of this lock is to avoid a single backup job running twice on the same VM, at the same moment. This event could occur in some rare situations. For example, if you deploy a new appliance, using the configuration of your old appliance, without deactivating the previous one. ### Clean VM during backup job Before starting a backup job, there will now be an automatic cleaning of the VM's backup directory on the remote. This operation will: - delete VHDs, XVAs files that are not linked to a backup - delete broken VHDs - delete delta VHDs with missing parent - delete backups with missing files (VHDs or XVAs) This cleaning function will allow to check the integrity of the backups, to avoid bad surprises at the restoration and also make free space on disk by checking that all broken or useless files or deletes as expected. ### VDI destruction retrial When a backup job is over, we are supposed to destroy the VDI used for the job. We noticed that sometimes, the VDI was not ready to be destroyed at the end of the job (as it should be). This issue is an XAPI bug, and we are currently working with the Xen developer team in order to fix this. However, as a workaround, we have implemented an automatic retry of the VDI destruction when it fails - 10 retries every 5 seconds. ## Create template from snapshot You could already create VMs from a snapshot - now you have the ability to create a template from a snapshot. ![](https://user-images.githubusercontent.com/70369997/115743059-97f60400-a391-11eb-9d15-9bb280194750.png) ## Display proxy upgrade on XO updates Until now, when updates were available for the Xen Orchestra proxy, you had to go into the proxy view to get the information which was not very convenient. ![](https://user-images.githubusercontent.com/7724491/115375363-04280a80-a1ce-11eb-9a74-1fb9e25b94e2.png) Available proxy updates are now visible directly in the update view of your main Xen Orchestra Appliance. ## \[Beta\] Amazon S3 improvement ![](https://user-images.githubusercontent.com/10992860/116100068-e1559480-a6ac-11eb-8cd9-8cb75c2e6b52.png) We fixed a bug impacting our AWS S3 plugin and also added the ability to select the region, if you want to backup is specific places. Please test and report! ## Ignore load balancing VMs via tag You can now ignore VMs in the load balancer plugin by using tags. We also did various load balancer improvements to fit in more use cases. On the long run, this plugin will be more and more a "resource scheduler" than just a load balancer. ## \[Beta\] XOSTOR ![](https://mcusercontent.com/f1ab72021fb8816f4d5e72773/images/c205c419-ad73-47f2-9f95-1ffabb561314.png) The beta of XOSTOR has started. If you are interested in our hyperconvergence solution developed jointly with LINSTOR, the DRBD technology specialists - you can register [on this page](https://xcp-ng.com/xostor-beta?ref=xen-orchestra.com). ### Case study #4 - Web.com's fireproof backups URL: https://xen-orchestra.com/blog/web-com-fireproof-backups/ Last updated: 2023-11-03T14:14:51.000Z Here's a new story about the best practices of our users and how they can sometimes save your infrastructure. This time, we are going to take a look at the UK infrastructure of the Web.com company and more particularly, a look at their excellent backup policy. ## A bit of context On March 10, 2021, a fire broke out in one of the four datacenters of OVH, the leader in cloud infrastructure in France. This dramatic fire led to the complete destruction of the Strasbourg datacenter (SBG2), and seriously damaged a second site nearby (SBG3). At the time of the incident, an estimated **3.2 million** websites were impacted by the event, and still today (5 days later), **10 to 15,000** companies and administrations are partially or totally affected by this event. ![ovh-sbg2](https://xen-orchestra.com/blog/content/images/2021/03/ovh-sbg2.jpg) If you want to learn more about the event, a complete FAQ is available on the [OVH website](https://help.ovhcloud.com/en-gb/faq/strasbourg-incident/?ref=xen-orchestra.com). ## Web.com We had the opportunity to talk with *Mark Hewitt*, Systems Administrator at Web.com, who told us how the fire in the OVH datacenter in Strasbourg (where part of their infrastructure was located) **had almost no impact on their production thanks to an efficient and careful backup policy**. ![webcom-logo](https://xen-orchestra.com/blog/content/images/2021/03/webcom-logo.png) With over 20 years of experience providing a full range of online marketing services, Web.com helps businesses compete and succeed in the online market. This wealth of experience, and an excellent eye for detail allowed them to shape solutions for many clients across a wide range of sectors. The UK offices alone, based in the North East of England and London serve approximately 3.5 million customers worldwide. The virtual machine infrastructure of web.com is running on XCP-ng, with around fifty dedicated hosts, all managed with Xen Orchestra, distributed in several datacenters in Europe, mainly in France and England. 2 hosts were on the SBG2 and SBG3 sites when the fire broke out and Mark remembers: > *I received two notifications within ten minutes of each other on Wednesday night \[March 10\] telling me some services were unavailable. Nothing really critical. It was the next morning when I logged into the OVH panel that I learned about the fire. One host completely gone up in smoke and a second, at SBG3, of uncertain status but likely not to come back online until Friday at best.* Between 10 and 20 VMs were distributed between these two hosts. Immediately, Mark starts the recovery procedures: > *This is not the first time we have had to perform restorations. Whether it's because of faulty drives, or some other failed hardware, this kind of thing happens. What is a first is to have a host that is totally destroyed, with no repair possibility.* In this case, Mark's backup policy has proven to be a good practice: > *As a matter of policy, we make sure that our backups are never on the same site as our hardware. In this case, restoring all the VMs lost at SBG2 & 3 to another of our data centers was a breeze with Xen Orchestra. We use deltas backup, which allowed us to recover all the lost machines in just under an hour and a half.* Finally, Mark concluded: > *This event that may have been catastrophic for some companies, for us, with our backup policy and Xen Orchestra was a non-event. In fact, we didn't even need to notify our customers, as the data recovery was quick and almost transparent for end-users.* We hope that this feedback from a Xen Orchestra user will confirm your choice to use our backup solutions or will allow you to question your own situation if you do not yet have a backup policy worthy of the name. Don't forget that when it comes to hardware, it's not a question of knowing **if** a failure will happen or not, it's a question of knowing **when** it will happen and what procedure you will be able to apply at that time. If you are not sure what type of backup solution you need, take a look at this [article we did a while ago](https://xen-orchestra.com/blog/choose-your-backup-solution-xenserver/) but still accurate, or our webinar we recorded with timecode on each backup type: ### Xen Orchestra 5.57 URL: https://xen-orchestra.com/blog/xen-orchestra-5-57/ Last updated: 2021-03-31T17:14:51.000Z With Xen Orchestra 5.57 we continue the work we started with version 5.56, on the improvement of backup features in the appliance. We are also starting to work on our Load Balancing plugin to make it more like a Resource Scheduler. Also, our beta for the upcoming new product, XOSTOR, is coming soon. > Note: the actual release is still in progress as we write those lines. Expect the availability later tonight! ## XOSTOR Beta ![bannerlinbitvates](https://xen-orchestra.com/blog/content/images/2021/03/bannerlinbitvates.png) XOSTOR is the virtual SAN and software hyperconvergence solution we are working on in partnership with LINBIT, specialist of the DRBD technology. The beta is going to start very soon and, if you are interested in testing the solution, you should register your email in our waiting list, [on this page.](https://xcp-ng.com/xostor-beta?ref=xen-orchestra.com) ## Backup improvements Xen Orchestra 5.57 is the second wave of our backup improvements. The major improvements this month will be the backup workers in xo-server: ![](https://xen-orchestra.com/content/images/2021/01/XO-backup.png) ### Backup workers in xo-server One job - one process. Currently, running a whole backup job will create a single large process. The bigger the job is, the heavier the process will be. Consequently, if a part of the backup job is not working, it will often bring the whole process to fail. Additionally, a very large process can also create performance issues and cannot run on multiple CPU cores. ![](https://xen-orchestra.com/content/images/2020/10/one-job-one-process.png) Backup workers in Xen Orchestra will allow us to split each backup job into a different process. It should bring multiple benefits: - XOA should be more responsive when large backup jobs are running. - A single part of the job crashing won't stop the whole backup job, only the faulty process - Backup performance will be less CPU limited as multiple processes means that you can add more vCPUs to get faster backups. ![](https://user-images.githubusercontent.com/21563339/110966764-e907e680-8355-11eb-80ab-d06a809f5f39.png) ### Better handling of disabled/unreachable targets When a backup job is launched with an unreachable or disabled target (SR or remote), the job won't be cancelled anymore with a failure. Instead, the job will continue for all available targets. At the end of the job, you will have a failure status for all tasks that couldn't be performed because of an unreachable target. ### Automatically clean orphan objects from VMs When doing support in some users infrastructure, our team was often using a script allowing them to remove all orphaned objects tied to a backup job previously failed or cancelled (eg. snapshot unused because the job failed before the export). We have now integrated a variation of this script in our backup code in order to clean VMs from these unecessary objects automatically. ## Easy setup for another network interface Some of you are using multiple network interfaces, usually one for the SAN or NAS connection and one for the appliance. Until now, configuring multiple network interfaces in Xen Orchestra required the editing of the system interfaces file, and, therefore some knowledge in Linux configuration. To make it easier, we have added a simpler method to setup another interface, using a simple script. ## Avoid booting VMs with duplicated MAC address To avoid issues in your infrastructure, you will now get an alert when you try to boot a VM using a MAC address already in use in your infrastructure. ![](https://user-images.githubusercontent.com/7724491/112132495-fbdab080-8bca-11eb-98ab-974160130f46.png) > You can still force the boot of the VM if you want to, at your own risk. ## Anti-affinity in Load Balancer > The Load Balancer in Xen Orchestra is becoming more and more of a Resource Scheduler. The plugin will likely change it's name in one of our future releases consequently to become **XORS**. Anti-affinity in the Load Balancer will allow you to avoid VMs with the same chosen tag to be run on the same host. **This way, you will avoid having pairs of redundant VMs or similar put on the same host.** Let's see a simple example: you have multiple VMs using MySQL and Postgresql with high availability/replication. Obviously, you don't want to lose the replicated database inside VMs on the same physical host. Just create your plan like this: ![antiaffinity](https://xen-orchestra.com/blog/content/images/2021/03/antiaffinity.png) - Simple plan: means no active load balancing mechanism here. - Anti affinity: we added our 2x tags, meaning any VMs with one of these tags will never run on the same host (as possible) with another VM having the same tag. ### Xen Orchestra 5.56 URL: https://xen-orchestra.com/blog/xen-orchestra-5-56/ Last updated: 2021-02-26T16:15:30.000Z ## Backup code major upgrade ![XO-backup](https://xen-orchestra.com/blog/content/images/2021/01/XO-backup.png) A few months ago, we started working on an overhaul of our backup code. Xen Orchestra 5.56 marks the first phase of deployment of this new backup code and its accompanying new features. If you want to learn more about our backup improvements project, you can take a look on our [dedicated devblog](https://xen-orchestra.com/blog/backup-performance/). ### New main backup code The backup code we wrote for the XO proxies is the most advanced backup code we have in Xen Orchestra. We developed it from scratch with our experience on previous code base, improving almost all of it. Making it both more flexible and more robust. In Xen Orchestra 5.56, this code became the main backup code, in all Xen Orchestra components, main appliance as well as proxies. We are expecting it to bring many improvements in the performances of backup jobs. It's a faster but also more resilient when it comes to failures or corruption and overall much more reliable. This is the biggest and initial step in our major backup code upgrade process. And this will help to build very cool features! ### Coming soon: backup workers in xo-server A direct consequence of this new code: in our next release, each backup jobs will be executed in a different worker. It means those new threads will bring more scalability and performance when there's multiple jobs running at the same time. But it will also keep the main event loop free for any other backup process happening in the background. In other words, XO UI will be more responsive regardless the amount of jobs running behind! ![](https://xen-orchestra.com/content/images/2020/10/one-job-one-process.png) Among the benefits of such method: - It will make XO more responsive - A single process crashing will not stop everything - Backup performance will be less CPU limited - a single process runs in a single CPU, but multiple processes means you can add vCPUs to get faster backups So stay tuned for our March release! ### Schedule a forced full backup in delta job In order to avoid particularly long VHD chains in delta backup jobs, it is recommended to make a full backup on a regular basis. It is now possible to schedule a full backup when creating a delta backup job (and not just tell every xx backup). ### Custom disk snapshot Before this, we relied on `VM.snapshot` call in host API to make snapshot of the VM. However, this method isn't capable of bypassing some disks. It means even if `[NOBAK]` in the disk name prevented to transfer it, it was still snapshoted anyway. Now, we can do snapshot at the disk level directly with `VDI.snapshot` and avoid specifically `[NOBAK]` drives. However, this option is now working only for halted VM, because of XAPI limitations. We'll push upstream to upgrade the `VM.snapshot` method to pass extra args, asking for some VDI to be NOT snapshoted. ## Display more information on tasks progress In the current task view, you will now have an estimate of the elapsed time and the time remaining before the task is completed: ![](https://user-images.githubusercontent.com/70369997/106112674-d8a4ff00-614d-11eb-80cc-f4349ae1bb1d.png) It's a pretty crude estimation, but still interesting to get a rough idea. ## Remove disconnected objects When `xo-server` is losing connection with the pool master, we didn't flush the objects. That's why, sometimes, you would think those VMs/hosts etc. were still there despite they are not. Now, the behavior is different: when we lose contact with the pool master, all related objects are directly flushed (we clear the object cache). No more confusion or "ghost" task/VM and so on! The ideal way could be to "grey" them at some point (at least for a bit), but we wanted to get rid of this first. ### Xen Orchestra 5.55 URL: https://xen-orchestra.com/blog/xen-orchestra-5-55/ Last updated: 2021-01-29T13:57:57.000Z The first release of the year for Xen Orchestra! We continue our work on backup performance and continuous interface improvements. We have a lot of upcoming projects for this year 2021 and we can't wait to tell you about them. ## Appliance update required > WARNING: The new version of Xen Orchestra is not compatible with very old appliances due to an update in a major component. > If you run into this error message trying to update, you will need to deploy a new appliance. ![error-message](https://xen-orchestra.com/blog/content/images/2021/01/error-message.png) Here is the process to follow: 1. Export your appliance configuration (Settings > Config) 2. Deploy a new appliance (Here are all the [deploy option](https://xen-orchestra.com/docs/installation.html?ref=xen-orchestra.com)) 3. Import your configuration ## Proxy improvements ![](https://xen-orchestra.com/content/images/2019/04/xo-5c-20proxy_38106051.png) ### Support for backup modifier tags - Proxy > A special thanks to [Jerome CHARAOUI](https://github.com/jcharaoui?ref=xen-orchestra.com) which is the original author of this feature that makes another external contribution to Xen Orchestra project! You can now add specific tags on your VMs to define particular rules that will apply during a backup job. The list of usable tags is available on our [official documentation](https://xen-orchestra.com/docs/backups.html?ref=xen-orchestra.com#backup-modifier-tags) ### Metadata backup - proxy You can now define a proxy to execute a metadata backup job. ![](https://user-images.githubusercontent.com/21563339/60709903-caf7ab00-9f11-11e9-8adf-d75dd34884fa.png) ## Default migration network You can now select your default migration network at a pool level in the advanced section of the pool. ![](https://user-images.githubusercontent.com/7724491/102532244-f50c4100-40a3-11eb-9cdd-5741da617d5e.png) ![](https://user-images.githubusercontent.com/7724491/102532238-f473aa80-40a3-11eb-86f5-15ba130bb42a.png) ## Duplicated MAC addresses In the health view, you will now have a view showing you if you have duplicated MAC addresses in your infrastructure. ![](https://user-images.githubusercontent.com/70369997/103783771-6dc64380-5039-11eb-9e56-aac95decbe57.png) ## Webhooks waiting response from server In the 5.53 release, we announced the addition of a webhook for backup jobs. Until this release, one key element was missing to make this feature really useful: the ability for webhooks to wait for the server to return. ![](https://user-images.githubusercontent.com/70369997/102504834-9b931a80-4081-11eb-898e-24ec38c88db7.png) Among other uses, this feature will allow users to perform operations in their infrastructure (save database, standby VMs..) before actually starting a backup job. ## UI Improvements ### Link to the changelog on the update page We added a link for each release branch allowing you to get access to the complete changelog directly from your appliance. ![changelog](https://xen-orchestra.com/blog/content/images/2021/01/changelog.gif) ### Custom field - date We now support date formats for the custom field ![](https://xen-orchestra.com/blog/content/images/2021/01/customfields.gif) ### RDP connection button We have added a button to open RDP access directly from the console view of your VM. It is a simple url that follows the following format: `rdp://` ![](https://user-images.githubusercontent.com/7724491/105691124-24149e80-5efd-11eb-9d35-1952210a6447.png) ![](https://user-images.githubusercontent.com/7724491/105691126-24149e80-5efd-11eb-80ad-e66d765bb820.png) ### VirtOps #2: Managing existing infrastructure with Terraform URL: https://xen-orchestra.com/blog/managing-existing-infrastructure-with-terraform-2/ Last updated: 2021-01-14T09:29:37.000Z In the previous tutorial, we used Terraform to provision and update a new VM on Xen Orchestra. This hopefully demonstrated the power of Terraform but how can Terraform be used for existing infrastructure outside of Terraform's management? Fortunately, Terraform was designed to interoperate with existing infrastructure to make these transitions easy. In this post, we will discuss Terraform's import functionality and walk through the process for importing an existing VM. Bringing infrastructure under Terraform's management follows these main steps: 1. Identify the existing infrastructure to import 2. Import the infrastructure into Terraform's state 3. Write the Terraform configuration that matches the infrastructure 4. Review the Terraform plan to ensure the configuration matches the expected state and infrastructure. 5. Repeat steps 3 and 4 until Terraform's plan is a noop 6. Apply Terraform to update the state The code for this tutorial can be found on [GitHub](https://github.com/ddelnano/terraform-provider-xenorchestra-intro/tree/master/importing-vms-blogpost?ref=xen-orchestra.com) and we will assume you have a VM outside of Terraform's management. The following VM will be used throughout the rest of these steps. ![Screen-Capture_select-area_20201117221511](https://xen-orchestra.com/blog/content/images/2020/11/Screen-Capture_select-area_20201117221511.png) While your terraform code will be different, it will follow the same process as outlined below. The first step is to identify the ID associated with the VM and decide on the name for the resource. The example below imports the VM with id `5019156b-f40d-bc57-835b-4a259b177be1` into the `xenorchestra_vm.imported` resource. ``` $ terraform import xenorchestra_vm.imported 5019156b-f40d-bc57-835b-4a259b177be1 Error: resource address "xenorchestra_vm.imported" does not exist in the configuration. Before importing this resource, please create its configuration in the root module. For example: resource "xenorchestra_vm" "imported" { # (resource arguments) } ``` Terraform will let us know that the resource hasn't been defined in code yet. Create a `vm.tf` file with the following placeholder for the resource and run `terraform import` again. ``` # vm.tf resource "xenorchestra_vm" "imported" { } ``` Terraform will now successfully import the resource. ``` $ terraform import xenorchestra_vm.imported 5019156b-f40d-bc57-835b-4a259b177be1 xenorchestra_vm.imported: Importing from ID "5019156b-f40d-bc57-835b-4a259b177be1"... xenorchestra_vm.imported: Import prepared! Prepared xenorchestra_vm for import xenorchestra_vm.imported: Refreshing state... [id=5019156b-f40d-bc57-835b-4a259b177be1] Import successful! The resources that were imported are shown above. These resources are now in your Terraform state and will henceforth be managed by Terraform. ``` Terraform found the VM from the Xen Orchestra API and stored the relevant information about it in its state (more details on state can be found [here](https://www.terraform.io/docs/state/index.html?ref=xen-orchestra.com)). The state that Terraform retrieved can be displayed with the `terraform state show` command. > Note: your state will be dependent on the specific VM you imported and will likely not match the details below ``` $ terraform state show xenorchestra_vm.imported # xenorchestra_vm.imported: resource "xenorchestra_vm" "imported" { auto_poweron = false cpus = 2 id = "5019156b-f40d-bc57-835b-4a259b177be1" memory_max = 2147483648 name_description = "Debian 10 Cloudinit ready template from XO Hub" name_label = "Debian 10 Cloudinit self-service" disk { attached = true name_label = "debian root" position = "0" size = 4294967296 sr_id = "86a9757d-9c05-9fe0-e79a-8243cb1f37f3" vbd_id = "981bf2ef-01ff-5430-8f8b-cdfdbe49f9cd" vdi_id = "062a3cae-cf00-4008-9c96-2d840b2c22f8" } network { attached = true device = "0" mac_address = "c2:03:35:47:79:8f" network_id = "6c4e1cdc-9fe0-0603-e53d-4790d1fce8dd" } timeouts {} } ``` Running a `terraform plan` will show that the missing arguments cause an error. ``` Error: Missing required argument on template.tf line 36, in resource "xenorchestra_vm" "imported": 36: resource "xenorchestra_vm" "imported" { The argument "template" is required, but no definition was found. Error: Missing required argument on template.tf line 36, in resource "xenorchestra_vm" "imported": 36: resource "xenorchestra_vm" "imported" { The argument "name_label" is required, but no definition was found. Error: Missing required argument on template.tf line 36, in resource "xenorchestra_vm" "imported": 36: resource "xenorchestra_vm" "imported" { The argument "cpus" is required, but no definition was found. ``` Now it's our responsibility to write the Terraform code that matches the infrastructure. Since terraform is able to accurately "diff" the state of the infrastructure against the current code, we will iteratively write code until the `terraform plan` shows no changes. At that point, the code will accurately reflect the VM. Since the `terraform state show` printed out HCL, we can copy the following lines and update `vm.tf` with the following content. I also added a fabricated `template` attribute since the error message from the provider indicated those fields were required. ``` resource "xenorchestra_vm" "imported" { auto_poweron = false cpus = 2 memory_max = 2147483648 name_description = "Debian 10 Cloudinit ready template from XO Hub" name_label = "Debian 10 Cloudinit self-service" template = "template" disk { attached = true name_label = "debian root" size = 4294967296 sr_id = "86a9757d-9c05-9fe0-e79a-8243cb1f37f3" } network { attached = true mac_address = "c2:03:35:47:79:8f" network_id = "6c4e1cdc-9fe0-0603-e53d-4790d1fce8dd" } } ``` This leads to the following `terraform plan` ``` Terraform will perform the following actions: # xenorchestra_vm.imported must be replaced -/+ resource "xenorchestra_vm" "imported" { auto_poweron = false + core_os = false + cpu_cap = 0 + cpu_weight = 0 cpus = 2 ~ id = "5019156b-f40d-bc57-835b-4a259b177be1" -> (known after apply) memory_max = 2147483648 name_description = "Debian 10 Cloudinit ready template from XO Hub" name_label = "Debian 10 Cloudinit self-service" + template = "template" # forces replacement ~ disk { attached = true name_label = "debian root" ~ position = "0" -> (known after apply) size = 4294967296 sr_id = "86a9757d-9c05-9fe0-e79a-8243cb1f37f3" ~ vbd_id = "981bf2ef-01ff-5430-8f8b-cdfdbe49f9cd" -> (known after apply) ~ vdi_id = "062a3cae-cf00-4008-9c96-2d840b2c22f8" -> (known after apply) } ~ network { attached = true ~ device = "0" -> (known after apply) mac_address = "c2:03:35:47:79:8f" network_id = "6c4e1cdc-9fe0-0603-e53d-4790d1fce8dd" } - timeouts {} } Plan: 1 to add, 0 to change, 1 to destroy. ``` As seen from the plan above, Terraform thinks it needs to recreate the resource. This is unexpected since we want Terraform to think our infrastructure is the source of truth rather than recreating it! Since the `template` attribute was a placeholder and changing that attribute creates a new resource, we must instruct Terraform to ignore that field. We could provide the correct value, but the Terraform provider isn't yet able to identify what template the VM originated from (see [this improvement](https://github.com/terra-farm/terraform-provider-xenorchestra/issues/100?ref=xen-orchestra.com) for more details). Add the following to the `xenorchestra_vm.imported` resource to have Terraform ignore the attribute change. ``` resource "xenorchestra_vm" "imported" { ... ... lifecycle { ignore_changes = [ template, ] } } ``` Terraform now thinks it needs to edit the resource rather than re-create it! ``` $ terraform plan ... # xenorchestra_vm.imported will be updated in-place ~ resource "xenorchestra_vm" "imported" { auto_poweron = false + core_os = false + cpu_cap = 0 + cpu_weight = 0 cpus = 2 id = "5019156b-f40d-bc57-835b-4a259b177be1" + memory_max = 1073741824 name_description = "Debian 10 Cloudinit ready template from XO Hub" name_label = "Debian 10 Cloudinit self-service" disk { attached = true name_label = "debian root" position = "0" size = 4294967296 sr_id = "86a9757d-9c05-9fe0-e79a-8243cb1f37f3" vbd_id = "981bf2ef-01ff-5430-8f8b-cdfdbe49f9cd" vdi_id = "062a3cae-cf00-4008-9c96-2d840b2c22f8" } network { attached = true device = "0" mac_address = "c2:03:35:47:79:8f" network_id = "6c4e1cdc-9fe0-0603-e53d-4790d1fce8dd" } timeouts {} } Plan: 0 to add, 1 to change, 0 to destroy. ------------------------------------------------------------------------ Note: You didn't specify an "-out" parameter to save this plan, so Terraform can't guarantee that exactly these actions will be performed if "terraform apply" is subsequently run. ``` Continue to update your terraform code to reflect the changes terraform is trying to make. Eventually the plan will be a noop and you can proceed to apply the change. > Note: `ignore_changes` should be used sparingly because it means your infrastructure is only partially defined in code.\* The same process can be used for importing any infrastructure that Terraform supports. If you are interested in learning more about Terraform's import functionality, check out Hashicorp's [import guide](https://learn.hashicorp.com/terraform/state/import?utm%5Fsource=WEBSITE&utm%5Fmedium=WEB%5FIO&utm%5Foffer=ARTICLE%5FPAGE&utm%5Fcontent=DOCS) which explains more details about the process. Up next in the devops series, we will explore how to create and manage VM templates with [Packer](https://www.packer.io/?ref=xen-orchestra.com), another popular Hashicorp tool, and deploy VMs from these templates with Terraform. This allows you to specify your machine images in code as well as making the images easily reproduced. ### Xen Orchestra 5.54 URL: https://xen-orchestra.com/blog/xen-orchestra-5-54/ Last updated: 2021-01-05T08:34:56.000Z Last release of the year! The least we can say is that 2020 was not a normal year and we all have been through a lot, we talk about this topic a little bit more on our [traditional end of the year infography](https://xen-orchestra.com/blog/2020-is-finally-over/). Hopefully, 2021 will be better for the whole world. Anyway, we are proud to announce that Xen Orchestra 5.54 is now available and, on behalf of our whole team: ![newyear-xoxcp](https://xen-orchestra.com/blog/content/images/2020/12/newyear-xoxcp.png) ## Rolling pool updates When applying patches, there's often a need to reboot hosts. To avoid any service interruption, you need to migrate VMs around manually. This can be a long and tedious process for any system administrator, especially when you have a lot of hosts in your pool. The rolling pool updates feature will save you a lot of time and trouble by handling all the pool updates automatically! > Right now, this feature will handle the update automatically and that's it, we are planning in a future release to bring some improvements such as an operation report. ## Dom0 Memory set You now have the ability to manage the memory allocated to Dom0 directly in Xen Orchestra. We have some recommended values you can use for XCP-ng available on our official [documentation](https://xcp-ng.org/docs/guides.html?ref=xen-orchestra.com#recommended-values) ## Choose network for multiple VMs migration Until now, you were able to select the used network when migrating a single VM, but that was not possible when migrating multiple VMs. With this release, you can now select the network of your choice, even when migrating multiple VMs. ## Host maintenance mode ![](https://user-images.githubusercontent.com/70369997/102108435-3813ad80-3e33-11eb-93dd-e720890c9882.png) Maintenance mode is a state you can put your hosts in for... well, maintenance purposes. Activating the maintenance mode will have two effects: 1. It will evacuate all the VMs on the host to another host available in the same pool. 2. It will suspend the host, making it impossible to start or create VMs on this host as long as the maintenance mode is active ## UI Improvements ### Show LUN Serial When creating an SR via HBA, we are now displaying the LUN serial and ID in the selector. ### Sort VM by disk physical size ![](https://user-images.githubusercontent.com/7724491/100736433-0af6e200-33d3-11eb-9b59-39008d31d30f.png) You can now sort the VMs on the home view by physical disks size. ### Remove irrelevant SR from the top SR usage In the overview section of the Dashboard panel, there is a graph showing you the Top 5 SR usage (in %). This would have been a relevant graph if we were not showing the `udev` SR in it, that are, per nature, always 100% used. We are now excluding automatically these SRs to provide you only relevant information. ![](https://user-images.githubusercontent.com/70369997/102354780-543a5a80-3fab-11eb-8bbb-d0e1b6aecaad.png) ### 2020 is finally over URL: https://xen-orchestra.com/blog/2020-is-finally-over/ Last updated: 2021-11-18T09:43:41.000Z Since 2017, we developed the habit of creating a special blogpost at the end of the year to sum up all the important accomplishments of the year. As for (almost) the whole world, 2020 has been a very special year for us and we couldn't take a look back without having a few words about it. ### Xen Orchestra 5.53 URL: https://xen-orchestra.com/blog/xen-orchestra-5-53/ Last updated: 2020-11-30T15:17:06.000Z For Thanksgiving we are offering you a new Xen Orchestra release! This one comes with some big improvements for our proxies as well as some other features. ## Backup improvements > ⚠ *The proxy backup code is currently the most advanced backup code that exists in Xen Orchestra. We improved almost every aspect of the existing code. Next release, we are intend to start using this new proxy backup code in the main Xen Orchestra appliance.* ### File level restore - proxy ![filelevel](https://xen-orchestra.com/blog/content/images/2020/11/filelevel.png) You can now use the file level restore through proxies. This was the last bit missing in the proxy code to make it fully functional with all the options that are available in Xen Orchestra Appliance. ### Custom disk snapshot - proxy > This feature is experimental, therefore it's disabled by default. > To activate the feature, you need to add in the `/etc/xo-proxy/config.toml` file > > ``` > [backups.defaultSettings] > customSnapshot = true > > ``` With the current XAPI implementation of snapshots, ignored disks need to be snapshotted and then removed before the export. This unnecessary operation can take some time, especially if the ignored disk is large. Therefore, we implemented a new way of doing snapshots, directly in Xen Orchestra. We are expecting this new method to improve the backup performance in two aspects: 1. It will reduce the space needed on the hosts to create the snapshot (especially if you have thick provisioned storage) 2. It will reduce the time needed for the snapshot operation as ignored disks won't be snapshotted anymore This new way of doing snapshots is part of our [backup performance improvement project](https://xen-orchestra.com/blog/backup-performance/). ### Recoverable VHD merge - proxy Our new backup code is able to resume a merge job even after an unexpected interruption. This should reduce failure situations and, more importantly, avoid corrupted VHD in delta backups. ### Webhooks for backup jobs ![Screenshot-from-2020-11-27-16-32-48](https://xen-orchestra.com/blog/content/images/2020/11/Screenshot-from-2020-11-27-16-32-48.png) Hooks were only available for called methods in the XO API until now. You can now use the webhooks plugin in relation with scheduled backup jobs. This feature will allow you to send some alerts or instructions to some services allowing advanced scripts to be executed. > Note that for now, even if you can call webhooks, we are not waiting for an answer to execute the backup jobs, that means that you should avoid using it to send instructions that could affect the backup job execution. ## Various improvements ### Better support when Dynamic Memory Control is Disabled Dynamic Memory control allows you to adjust the memory of running VMs. This feature was causing issues with some OS distributions and therefore is deprecated in Citrix Hypervisor. Xen Orchestra is now able to manage RAM allocation even when DMC is disabled. ### Add any allowed IP (IPv4 & IPv6) We are improving our [IP management features](https://xen-orchestra.com/blog/xenserver-vm-ip-management/) in Xen Orchestra with the support for IPv6 and the ability to manually add an IP of your choice. We added a text field that allows admins to: - add an IPv6 address - add an IP address without using IP pools ![](https://user-images.githubusercontent.com/10992860/98561455-36d9e880-22a9-11eb-8ce5-8ff46d927990.png) ![](https://user-images.githubusercontent.com/10992860/98561434-2e81ad80-22a9-11eb-9811-771d91949246.png) ### Custom field support We've added the ability to add a free field attached to a VM with data of your choice. This feature is retrocompatible with the one existing in XenCenter/XCP-ng Center. ![](https://user-images.githubusercontent.com/7724491/99656847-b2802600-2a5d-11eb-9244-4f48f56b8470.png) ![](https://user-images.githubusercontent.com/7724491/99657050-ee1af000-2a5d-11eb-89b1-4919e1ff85cb.png) ### Change the number of items per page Each table in Xen Orchestra now supports a display of 20, 50 or 100 objects. ![](https://user-images.githubusercontent.com/7724491/97879704-9885da00-1d20-11eb-918d-6f1da906215d.png) ### VirtOps #1: XO Terraform provider URL: https://xen-orchestra.com/blog/virtops1-xen-orchestra-terraform-provider/ Last updated: 2025-10-24T08:11:54.000Z Welcome to the next installment in the devops series! With its growing popularity, no devops series would be complete without discussing Terraform. This post explains how to get setup with Terraform, launch VMs on your Xen Orchestra deployment and adapt that infrastructure over time. > A big welcome to Dom! A chemical engineer turned SRE (Site Reliability Engineering). Dom has spent the last 5 years working on cloud infrastructure and has an interest in bringing popular cloud tooling to the bare metal world. [Vates](vates.fr) is currently sponsoring Dom to work on the Terraform Xen Orchestra provider in his spare time. ## Terraform background Terraform is a cloud/platform agnostic tool for building, changing, and versioning infrastructure. Terraform can manage existing and popular service providers as well as custom in-house solutions (like Xen Orchestra). It can manage resources through their entire lifecycle or even manage infrastructure it didn't initially create. ![terraformlogo](https://xen-orchestra.com/blog/content/images/2020/11/terraformlogo.png) Terraform safely and predictably creates infrastructure through its two step workflow. The `terraform plan` command will describe the resources terraform will create, update or delete with your current code. This gives you a clear understanding of the actions terraform will perform when you are ready to apply the configuration. Once you are satisfied with the plan, the `terraform apply` command will cause terraform to perform the actions in the plan. This workflow gives you confidence that terraform will perform the change you expect and also makes the process of provisioning infrastructure easy to code review. ## Launching Virtual Machines in XO with Terraform This section provides a walkthrough on how to use the terraform provider to create a VM and later add another network interface to it. Below are the steps explained throughout this post: 1. Install terraform 2. Create a VM template for the new VM 3. Provision the VM with terraform 4. Add an additional network interface to the VM after creation The code in this tutorial can be found on [GitHub](https://github.com/ddelnano/terraform-provider-xenorchestra-intro?ref=xen-orchestra.com) but we will write it from scratch step by step. ### Installing terraform If you don't have terraform installed, follow [this Hashicorp tutorial](https://learn.hashicorp.com/tutorials/terraform/install-cli?in=terraform/aws-get-started&ref=xen-orchestra.com) to install it. > Note: we will be using features from the latest terraform version (0.13.0 at the time of this writing). Make sure you have installed atleast 0.13.0. ### Creating a VM template The terraform provider expects a VM template with an already installed OS. In a later post, we will describe how to create and manage these VM templates with another popular devops tool, Packer. For now we will create a VM template manually through the XO UI. > Note: if you already have a VM template with an installed OS you can skip this and proceed to the next step. ![Screen-Capture_select-area_20201011205232](https://xen-orchestra.com/blog/content/images/2020/10/Screen-Capture_select-area_20201011205232.png) I will create a Ubuntu Bionic VM template but use an available ISO in your existing deployment. Once the VM starts, use the XO UI to finish the OS install through the VM console. ![Screen-Capture_select-area_20201011205644](https://xen-orchestra.com/blog/content/images/2020/10/Screen-Capture_select-area_20201011205644.png) Once the installation is complete, stop the VM and convert it to a template. ![Screen-Capture_select-area_20201011211653](https://xen-orchestra.com/blog/content/images/2020/10/Screen-Capture_select-area_20201011211653.png) ### Provisioning a VM with terraform Now that a template is created, we can move on to writing the terraform code. The first step is to configure terraform to install the [xenorchestra terraform provider](https://github.com/vatesfr/terraform-provider-xenorchestra?ref=xen-orchestra.com). The following code will instruct terraform to download the xenorchestra module from the [terraform registry](https://registry.terraform.io/providers/vatesfr/xenorchestra/latest?ref=xen-orchestra.com). ``` # provider.tf terraform { required_providers { xenorchestra = { source = "vatesfr/xenorchestra" version = "~> 0.9" } } } ``` Running `terraform init` should now download the XO provider. ``` $ terraform init Initializing the backend... Initializing provider plugins... - Finding vatesfr/xenorchestra versions matching "~> 0.9"... - Installing vatesfr/xenorchestra v0.9.1... - Installed vatesfr/xenorchestra v0.9.1 (self-signed, key ID DDBA1674AA3EA0EE) Partner and community providers are signed by their developers. If you'd like to know more about provider signing, you can read about it here: https://www.terraform.io/docs/plugins/signing.html Terraform has been successfully initialized! You may now begin working with Terraform. Try running "terraform plan" to see any changes that are required for your infrastructure. All Terraform commands should now work. If you ever set or change modules or backend configuration for Terraform, rerun this command to reinitialize your working directory. If you forget, other commands will detect it and remind you to do so if necessary. ``` The terraform provider needs credentials to authenticate with the XO api. These can be provided directly in the terraform code, however, the safest way to provide these credentials is through environment variables (to avoid storing sensitive data in version control). Create a `~/.xoa` file (shown below) and then source the credentials into the current shell with `eval $(cat ~/.xoa)`. ``` # ~/.xoa export XOA_URL=ws://hostname-of-your-deployment export XOA_USER=YOUR_USERNAME export XOA_PASSWORD=YOUR_PASSWORD ``` With the provider installed and credentials configured, it's time to write the terraform code for the VM. The three main components for creating a VM are storage, a network and a VM template. We will use data sources to have terraform look up the necessary storage, networking and template inputs required to create a VM resource. [Data sources](https://www.terraform.io/docs/configuration/data-sources.html?ref=xen-orchestra.com) are read only and are often used to retrieve dynamic values or IDs that would provide little context in code (UUIDs, autogenerated numbers, etc). The following code will retrieve the storage, networking and VM template. > Note: Update the name\_label of the data sources with the names of your pool, network, storage repository and VM template respectively ``` # vm.tf data "xenorchestra_pool" "pool" { name_label = "lab-pool-1" } data "xenorchestra_template" "vm_template" { name_label = "Terraform template VM" } data "xenorchestra_sr" "sr" { name_label = "ZFS" pool_id = data.xenorchestra_pool.pool.id } data "xenorchestra_network" "network" { name_label = "Pool-wide network associated with eth0" pool_id = data.xenorchestra_pool.pool.id } ``` At this point, we can run `terraform plan` to ensure that all the data sources are properly found. ``` $ terraform plan Refreshing Terraform state in-memory prior to plan... The refreshed state will be used to calculate this plan, but will not be persisted to local or remote state storage. data.xenorchestra_pool.pool: Refreshing state... [id=355ee47d-ff4c-4924-3db2-fd86ae629676] data.xenorchestra_template.vm_template: Refreshing state... [id=08701be4-52f0-c201-a208-16e765d33e5e] data.xenorchestra_network.network: Refreshing state... [id=a12df741-f34f-7d05-f120-462f0ab39a48] ------------------------------------------------------------------------ No changes. Infrastructure is up-to-date. This means that Terraform did not detect any differences between your configuration and real physical resources that exist. As a result, no actions need to be performed. ``` Since we've only used data sources up to this point, terraform is merely looking up existing resources and a `No changes` plan is expected. Now that the inputs for the VM are identified, it's time to write the terraform for the VM resource. ``` resource "xenorchestra_vm" "vm" { memory_max = 2147467264 cpus = 1 name_label = "XO terraform tutorial" template = data.xenorchestra_template.vm_template.id network { network_id = data.xenorchestra_network.network.id } disk { sr_id = data.xenorchestra_sr.sr.id name_label = "VM root volume" size = 50212254720 } } ``` Running `terraform plan` we will see that terraform will attempt to create a vm resource. ``` Terraform will perform the following actions: # xenorchestra_vm.vm will be created + resource "xenorchestra_vm" "vm" { + auto_poweron = false + core_os = false + cpu_cap = 0 + cpu_weight = 0 + cpus = 1 + id = (known after apply) + memory_max = 2147467264 + name_label = "XO terraform tutorial" + template = "08701be4-52f0-c201-a208-16e765d33e5e" + disk { + attached = true + name_label = "VM root volume" + position = (known after apply) + size = 50214207488 + sr_id = "86a9757d-9c05-9fe0-e79a-8243cb1f37f3" + vbd_id = (known after apply) + vdi_id = (known after apply) } + network { + attached = true + device = (known after apply) + mac_address = (known after apply) + network_id = "a12df741-f34f-7d05-f120-462f0ab39a48" } } Plan: 1 to add, 0 to change, 0 to destroy. ``` We can now apply the change and have terraform create the VM. ``` $ terraform apply data.xenorchestra_template.vm_template: Refreshing state... data.xenorchestra_pool.pool: Refreshing state... data.xenorchestra_network.network: Refreshing state... data.xenorchestra_sr.sr: Refreshing state... An execution plan has been generated and is shown below. Resource actions are indicated with the following symbols: + create Terraform will perform the following actions: # xenorchestra_vm.vm will be created + resource "xenorchestra_vm" "vm" { + auto_poweron = false + core_os = false + cpu_cap = 0 + cpu_weight = 0 + cpus = 1 + id = (known after apply) + memory_max = 2147467264 + name_label = "XO terraform tutorial" + template = "08701be4-52f0-c201-a208-16e765d33e5e" + disk { + attached = true + name_label = "VM root volume" + position = (known after apply) + size = 50214207488 + sr_id = "86a9757d-9c05-9fe0-e79a-8243cb1f37f3" + vbd_id = (known after apply) + vdi_id = (known after apply) } + network { + attached = true + device = (known after apply) + mac_address = (known after apply) + network_id = "a12df741-f34f-7d05-f120-462f0ab39a48" } } Plan: 1 to add, 0 to change, 0 to destroy. Do you want to perform these actions? Terraform will perform the actions described above. Only 'yes' will be accepted to approve. Enter a value: yes xenorchestra_vm.vm: Creating... xenorchestra_vm.vm: Still creating... [10s elapsed] xenorchestra_vm.vm: Creation complete after 18s [id=4028c860-9c86-cec7-df02-4bddf1d32ead] Apply complete! Resources: 1 added, 0 changed, 0 destroyed. ``` With that you should have a newly launched VM! Any future changes to this VM can now be easily code reviewed and version controlled. In order to demonstrate this, let's imagine that this VM needs a second network interface. Update the terraform code to add a second network block like the following ``` # vm.tf resource "xenorchestra_vm" "vm" { memory_max = 2147467264 cpus = 1 name_label = "XO terraform tutorial" template = data.xenorchestra_template.vm_template.id network { network_id = data.xenorchestra_network.network.id } network { network_id = data.xenorchestra_network.network.id } disk { sr_id = data.xenorchestra_sr.sr.id name_label = "VM root volume" size = 50212254720 } } ``` Running `terraform plan` shows that terraform is going to add a network interface to the VM. ``` $ terraform plan ... ... Terraform will perform the following actions: # xenorchestra_vm.vm will be updated in-place ~ resource "xenorchestra_vm" "vm" { auto_poweron = false core_os = false cpu_cap = 0 cpu_weight = 0 cpus = 1 id = "4028c860-9c86-cec7-df02-4bddf1d32ead" memory_max = 2147467264 name_label = "XO terraform tutorial" template = "08701be4-52f0-c201-a208-16e765d33e5e" disk { attached = true name_label = "VM root volume" position = "0" size = 50214207488 sr_id = "86a9757d-9c05-9fe0-e79a-8243cb1f37f3" vbd_id = "633ccda8-51fb-0cf9-b257-d8ca565ee124" vdi_id = "3d24f84a-298d-41aa-90a6-690508e1770d" } network { attached = true device = "0" mac_address = "8e:8b:c5:f3:df:4a" network_id = "a12df741-f34f-7d05-f120-462f0ab39a48" } + network { + attached = true + network_id = "a12df741-f34f-7d05-f120-462f0ab39a48" } } Plan: 0 to add, 1 to change, 0 to destroy. ``` You would continue to update the code and re-run `terraform plan` until you are satisfied with the actions terraform will take. You would then open up a pull request (code review) on your repository and attach the terraform plan for review. Once the change is approved, merge your branch into master and continue to apply the change. ``` $ terraform apply data.xenorchestra_template.vm_template: Refreshing state... [id=08701be4-52f0-c201-a208-16e765d33e5e] data.xenorchestra_pool.pool: Refreshing state... [id=355ee47d-ff4c-4924-3db2-fd86ae629676] xenorchestra_vm.imported: Refreshing state... [id=5019156b-f40d-bc57-835b-4a259b177be1] data.xenorchestra_network.network: Refreshing state... [id=a12df741-f34f-7d05-f120-462f0ab39a48] data.xenorchestra_sr.sr: Refreshing state... [id=86a9757d-9c05-9fe0-e79a-8243cb1f37f3] xenorchestra_vm.vm: Refreshing state... [id=4028c860-9c86-cec7-df02-4bddf1d32ead] An execution plan has been generated and is shown below. Resource actions are indicated with the following symbols: ~ update in-place Terraform will perform the following actions: # xenorchestra_vm.vm will be updated in-place ~ resource "xenorchestra_vm" "vm" { auto_poweron = false core_os = false cpu_cap = 0 cpu_weight = 0 cpus = 1 id = "4028c860-9c86-cec7-df02-4bddf1d32ead" memory_max = 2147467264 name_label = "XO terraform tutorial" template = "08701be4-52f0-c201-a208-16e765d33e5e" disk { attached = true name_label = "VM root volume" position = "0" size = 50214207488 sr_id = "86a9757d-9c05-9fe0-e79a-8243cb1f37f3" vbd_id = "633ccda8-51fb-0cf9-b257-d8ca565ee124" vdi_id = "3d24f84a-298d-41aa-90a6-690508e1770d" } network { attached = true device = "0" mac_address = "8e:8b:c5:f3:df:4a" network_id = "a12df741-f34f-7d05-f120-462f0ab39a48" } + network { + attached = true + network_id = "a12df741-f34f-7d05-f120-462f0ab39a48" } } Plan: 0 to add, 1 to change, 0 to destroy. Do you want to perform these actions? Terraform will perform the actions described above. Only 'yes' will be accepted to approve. Enter a value: yes xenorchestra_vm.vm: Modifying... [id=4028c860-9c86-cec7-df02-4bddf1d32ead] xenorchestra_vm.vm: Still modifying... [id=4028c860-9c86-cec7-df02-4bddf1d32ead, 10s elapsed] xenorchestra_vm.vm: Still modifying... [id=4028c860-9c86-cec7-df02-4bddf1d32ead, 20s elapsed] xenorchestra_vm.vm: Still modifying... [id=4028c860-9c86-cec7-df02-4bddf1d32ead, 30s elapsed] xenorchestra_vm.vm: Still modifying... [id=4028c860-9c86-cec7-df02-4bddf1d32ead, 40s elapsed] xenorchestra_vm.vm: Modifications complete after 49s [id=4028c860-9c86-cec7-df02-4bddf1d32ead] Apply complete! Resources: 0 added, 1 changed, 0 destroyed. ``` This makes infrastructure changes easily code reviewed and allows changes to your infrastructure to be tracked. Stay tuned for later posts in this series that will show how terraform can manage existing infrastructure and how VM templates can be created and managed with Packer (another popular Hashicorp tool). If you have any questions about the provider or other terraform use cases please reach out through [Discord](https://discord.gg/ZpNq8ez?ref=xen-orchestra.com) or create a [GitHub issue](https://github.com/vatesfr/terraform-provider-xenorchestra?ref=xen-orchestra.com). ### Xen Orchestra 5.52 URL: https://xen-orchestra.com/blog/xen-orchestra-5-52/ Last updated: 2020-10-30T15:22:20.000Z ## Resumable VHD Merge - Proxy From time to time, a delta backup job can fail during the VHD merge process. Until now, this was a very complicated situation because it could not only break the existing VHD file on the remote side and force us to recreate a full backup job during the next run, or, a bit less problematic, it would force us to restart the merge process at the very beginning. In the Xen Orchestra proxies, we have improved this situation and implemented a new feature giving us the ability to continue a merge after an interruption. > Currently, this option is only available in the XO Proxy as proxies benefits from the most recent backup code we are currently working on. This will soon be available in Xen Orchestra Appliance also. ## XCP-ng/Xenserver hosts certificates manager A new panel is available in the advanced section of the pages for your hosts allowing you to manage your host certificates and to install new ones. ![](https://user-images.githubusercontent.com/21563339/96735645-0f83b000-13bc-11eb-830b-816b3c32a081.png) ![](https://user-images.githubusercontent.com/21563339/97194051-f9099a00-17a9-11eb-83c7-d9ba73a344d4.png) ## CPU scheduling > ⚠ XCP-ng 8.2 exclusive feature As we announced in the [beta release of XCP-ng 8.2](https://xcp-ng.org/blog/2020/09/30/xcp-ng-8-2-lts-beta/?ref=xen-orchestra.com#coreschedulingexperimental), we introduced an XAPI method allowing you to select different granularity for your core scheduling. In Xen Orchestra, you now have a panel allowing you to manage your core scheduling the way you want. This feature will allow you to use hyperthreading with extra bits of security, in particular regarding side channel attacks (as Spectre, Meltdown, Fallout...). ![](https://user-images.githubusercontent.com/70369997/95732470-13f3ee80-0c81-11eb-935a-4d843d431c12.png) ## Allow self users to set network Self services users are now allowed to set a network if the said network is within the resources allocated to this user. ![](https://user-images.githubusercontent.com/7724491/95761128-2a636f80-0cac-11eb-9087-a5b258070422.png) ## QoL improvements ### Add old packaged version installed We will now display the current (old) version currently installed in your infrastructure when informing you about available updates for Xen Orchestra. ### Audit log documentation Audit log documentation is now [available and complete](https://xen-orchestra.com/docs/users.html?ref=xen-orchestra.com#audit-log) in our official documentation. ### Ability to update HTTP proxy configuration We added the ability to edit the http proxy configuration after a proxy deployment (and not only during the initial deployment). ![](https://user-images.githubusercontent.com/21563339/88305396-be571800-cd09-11ea-98ff-1b4c01b31b17.png) ### DevBlog #8 - Improving backup performance in Xen Orchestra URL: https://xen-orchestra.com/blog/backup-performance/ Last updated: 2020-12-07T10:59:51.000Z One of the most important projects for the next few months in Xen Orchestra will be to improve the backup performance in our solution and to bring new tools for our users to improve their infrastructure. ## First step - Identification We have some ideas about what can be improved in our solution, but no certainty. This is the reason why the first step in our improvement process will be to integrate Stream probes (or "stream tracers"). The main job of these tracers will be to identify where the slowdowns are (XO itself? XCP-ng/Citrix Hypervisor export or import? I/O on the remote?) These probes might bring far more than just identifying when Xen Orchestra is the limitation and help us to work on that, it can also bring new features to allow a user to visualize bottlenecks in their infrastructure (network, storage, XO proxy...) and bring corrective action. Maybe even in XCP-ng itself! ![backup-perf-tra_crop](https://xen-orchestra.com/blog/content/images/2020/10/backup-perf-tra_crop.png) ## Improvements exploration ### VHD merge in delta backups Currently when a delta backup job reaches its retention time, we are merging the oldest delta VHD file with the Full VHD. The consequence of this mechanism is that each block of data in the VHD file is, first, read (downloaded) from the delta and then written (uploaded) to the full. It's not completely optimal on a "remote" (here, a network share), because this action will use network and disks resources. Additionally, editing the full VHD directly can be slower with some Copy on Write (CoW) filesystems used in your remote (`btrfs` seems to be affected). A way to avoid this process would be to "explode" the VHD itself, which means that each block of the VHD would have its own file. With this implementation, instead of merging the VHD block in the full VHD, we will simply have to rename the file and remap the full VHD metadata. This solution will surely improve the merge speed - but there is a big drawback. Having a file for each datablock will generate a very large number of files (eg. for a full 2TiB disk, that will represent a little bit more than 2 Million files!). Consequently, this feature will only work with remotes supporting lots of files (`btrfs`, `zfs` and some others). Another issue would be that it will no longer be possible to directly upload the full VHD file to XCP-ng/XenServer. Of course for all the previous reasons, this feature would be something optional in Xen Orchestra, or at least useful to see the progress we can make with the VHD merge process. ### New backup code As a more general improvement, the whole backup code has been rewritten when we worked on the Xen Orchestra proxy. However, this newer and better code, (refactored, cleaner and simpler) is not yet the one used in Xen Orchestra itself. In the near future, this code will become the main code used in Xen Orchestra. ### One job - One process Another thing we already know is that currently, running a whole backup job will create a single process. This may create performance issues when it comes to very large backup jobs, with a lot of VMs to backup. Splitting all the jobs into different processes for each should have multiple benefits: - It will make XO more responsive - A single process crashing will not stop everything - Backup performance will be less CPU limited - a single process runs in a single CPU, but multiple processes means you can add vCPUs to get faster backups ![one-job-one-process](https://xen-orchestra.com/blog/content/images/2020/10/one-job-one-process.png) ### Custom snapshot implementation We are also thinking about a custom snapshot implementation allowing us to avoid snapshotting ignored disks (which is currently impossible, we are snapshotting them, and deleting them before the export). It should improve the performance of the snapshot process and reduce the disk space required for the snapshot (especially for thick provisioned storage). A little drawback to this is that it won't be compatible anymore with quiesced snapshots (which is a deprecated feature in Citrix hypervisor anyway). ### NBD implementation This is the latest thing we are exploring. Instead of using the VHD format we are looking forward to completely changing the way backup works in Xen Orchestra and using block tracking instead of VHD. This topic is particularly vast and will require a lot of experimentation first on our side, so we won't get deeper about this in this devblog, a dedicated one will come in the future. But clearly, it will be interesting to compare with the current VHD mechanism (in terms of speed for example). ### VirtOps #0: Intro on DevOps URL: https://xen-orchestra.com/blog/virtops0-intro-on-devops/ Last updated: 2020-10-08T13:16:45.000Z Hi everyone! Welcome to this new series of blog posts related to DevOps on the Xen Orchestra stack (combined with both XCP-ng or Citrix Hypervisor). We call it "VirtOps", which is because we'll do DevOps on top of XO. And today, we'll start by explaining clearly what DevOps is, and how XO will help you there. ## What's DevOps? Definition I think this is the hardest part of this series: giving a clear definition of what DevOps is. You've probably heard the term a LOT, and it was badly "translated" to non-technical people (👋 HR or head hunters, searching for "DevOps" people! 😉). The very first important thing to get is: > DevOps **is a set of practices**. This set of practices combines software development (the **Dev** part) and IT operations (**Ops**). It's like *Karate*: you aren't a *Karate* (except Chuck Norris maybe 🥋). You are **doing** *Karate*. Same for DevOps: you aren't a DevOps, you are **doing** DevOps. ![unnamed](https://xen-orchestra.com/blog/content/images/2020/09/unnamed.png) ## Why? Goal of DevOps DevOps to do what? Well, that's in fact a very good question. I suppose you are aware of it or similar "trendy" words. Here, I'm focusing on what matters: the real impact of DevOps for your IT environment. No bullshit! > DevOps is a set of practices intended to reduce the time between committing a change to a system and the change being placed into normal production, while ensuring high quality. *Len Bass, Ingo Weber, and Liming Zhu—three computer science researchers from the CSIRO and the Software Engineering Institute* This is the definition from an academic perspective. However, that's the best one to me. "Reducing the gap between the dev world and the sysadmin world" is another way to say it, and this should bring (credits to the great *Wikipedia* page on [DevOps](https://en.wikipedia.org/wiki/DevOps?ref=xen-orchestra.com)): - Improved deployment frequency; - Faster time to market; - Lower failure rate of new releases; - Shortened lead time between fixes; - Faster mean time to recovery (in the event of a new release crashing or otherwise disabling the current system). Sounds great, doesn't it? But is it really working? ![Things you should do in DevOps](https://xen-orchestra.com/blog/content/images/2020/09/1-AwvDJDfErlD34ox2QpwGoA.png) ### Cultural shift This is a real transformation, made to get Ops and Devs teams working more closely. And believe me, that's not trivial! In fact, that might be the biggest challenge in adoption. So you need to go step by step. My personal experience: go with bringing solutions to each other. Eg: - Devs have good experience on working together regarding text files (sources, eg with source code management tools). This process can be used in the Ops side, so use your devs to train your ops on it! - Ops have good experience delivering apps in a matter "that works". This experience is really valuable, and training devs on best practices can help to build code that's easier to deploy for ops. Better collaboration between Devs and Ops teams is a big part of DevOps success. You can also get people that are already trained in DevOps practices. But remember: you won't replace pure Devs magically with Ops and vice-versa. The experience of everyone matters! ![culturalshift](https://xen-orchestra.com/blog/content/images/2020/09/culturalshift.jpg) ## How? Various examples Here are some examples on how software development best practices help a lot in the context of IT operations. It's entirely possible you will realize you were already doing DevOps without knowing it! The first simple and however game changer example, is to use **Git** to manage your app/system configuration. [Git](https://git-scm.com/?ref=xen-orchestra.com) was made by Linus Torvalds to work together on the Linux Kernel, but it's far more than that now: this is a fantastic tool to both collaborate but also track the history of who did what and when. What's next is also a big leap ahead for Ops: using automation. ### Automation Automation is a great way to integrate DevOps principles. For example, when you deploy a new version of your application, the ideal world will tell you that there's nothing to do. No manual tests, deploy or checks. But this requires a lot of tooling or experience. That's why this series of blog posts will help you to go in the right direction to achieve that. ![automation](https://xen-orchestra.com/blog/content/images/2020/09/automation.png) ### What about Dev side? I gave various example on the Ops side, in order to expose the DevOps side of things. But what about Devs? This is not the focus of this blog post (targeting more Ops to DevOps than the opposite), however, if you are interested: take a look at deployability, modifiability, testability and monitorability. And Microservices! Also, you can imagine modifying your dev process to include connections to your XCP-ng/Xen Orchestra infrastructure. More on that later! ## Xen Orchestra: the central piece So what about DevOps in a XCP-ng/Xen Orchestra environment? (or even with Citrix Hypervisor). Since its inception, Xen Orchestra was built with an idea in mind: being a central component, **managing your whole infrastructure in one place**. Without this central architecture, each client has to connect to various pools or hosts at once: ![without-xo.1dac9032](https://xen-orchestra.com/blog/content/images/2020/10/without-xo.1dac9032.jpg) But with a central point, it's far easier. You can rely on a fully available "middleware" to do everything you need: ![with-xo.9643d3bb](https://xen-orchestra.com/blog/content/images/2020/10/with-xo.9643d3bb.jpg) And that's not all. Xen Orchestra was also built with different components, including an API you can query: ![xo-arch.94e9d75a](https://xen-orchestra.com/blog/content/images/2020/10/xo-arch.94e9d75a.jpg) In a DevOps context, it's a formidable opportunity to use Dev practices in your Ops, with only one thing to query! ## Coming next: API, CLI and more! In our coming blog posts, we'll give you some examples on how to access Xen Orchestra programmatically, using its CLI (`xo-cli`) or its API. This way, you can do any kind of action in a completely automated fashion. Use cases are infinite: CI/CD, updates, rollback, deployments, migration etc. Or just connect to your IT infrastructure and report whatever you need! Finally, we'll also have some articles regarding great DevOps tools working with Xen Orchestra, like Terraform! Stay tuned by registering on [https://xen-orchestra.com](https://xen-orchestra.com/?ref=xen-orchestra.com) or by [following us on Twitter](https://twitter.com/xenorchestra?ref=xen-orchestra.com). ### Xen Orchestra 5.51 URL: https://xen-orchestra.com/blog/xen-orchestra-5-51/ Last updated: 2020-10-01T12:32:58.000Z Xen Orchestra 5.51 is available and brings important improvements regarding group management in Xen Orchestra, especially regarding LDAP as well as some updates on the backup side, especially concerning Amazon S3 backup. ## XCP-ng 8.2 available in beta ![logo82_48177581--3-](https://xen-orchestra.com/blog/content/images/2020/09/logo82_48177581--3-.png) The latest version of our hypervisor is now available in beta test. This version will be the very first one in LTS (Long Term Support) so we are paying a very special attention to make it a rock solid release. All you need to know about this new version is available on this [blogpost](https://xcp-ng.org/blog/2020/09/30/xcp-ng-8-2-lts-beta/?ref=xen-orchestra.com) and you can provide all your constructive feedback during the beta phase on this [forum thread](https://xcp-ng.org/forum/topic/3634/xcp-ng-8-2-0-beta-now-available?ref=xen-orchestra.com). ## Group management improvements ### Import LDAP Group ![ad-and-ldap](https://xen-orchestra.com/blog/content/images/2020/09/ad-and-ldap.jpg) You now have the ability to synchronize your LDAP groups directly in Xen Orchestra. ![users-groups-term](https://xen-orchestra.com/blog/content/images/2020/09/users-groups-term.png) This is useful if you already have configured user groups in your LDAP directory and don't want to create them again manually in Xen Orchestra, and update them whenever a new user is added or a new group is created. ![groups-config](https://xen-orchestra.com/blog/content/images/2020/09/groups-config.png) Once you have filled out the configuration fields under "Synchronize group" in the plugin configuration, every time a user will log into Xen Orchestra using their LDAP/AD credentials, it will check which LDAP groups the user belongs to, create new groups with the same names in Xen Orchestra if necessary, and automatically add the user to those groups. Note that you can still create groups manually within Xen Orchestra, it won't disturb the synchronization. ![groups](https://xen-orchestra.com/blog/content/images/2020/09/groups.png) Tip: If you want to find which groups were imported from LDAP and which groups are native, you can go to the Groups page and enter these queries in the search bar: `provider:ldap` and `!provider:ldap` respectively. ### Migrate VDIs for self services users Self service users now have the ability to migrate VDIs in their ressources set. ![](https://user-images.githubusercontent.com/7724491/89293518-5506cb80-d65e-11ea-8f23-f48df1f3f314.png) ![](https://user-images.githubusercontent.com/7724491/89650335-90a1cf80-d8c2-11ea-936c-0b361ea2fa65.png) ## Backup improvements ### Amazon S3 backup ![amazon-web-service-logo-1](https://xen-orchestra.com/blog/content/images/2020/09/amazon-web-service-logo-1.jpg) We introduced Amazon S3 backup in beta a few months ago, this features is now available, ready for production, on the **latest release branch**. In one month, this feature will be available directly in the stable release branch. ### Backup logs improvements In large backup jobs, it was sometimes difficult to browse through the backup log to get specific information. We have improved the backup log with a filtering system and a pagination system for a better lisibility. #### Filtering ![](https://user-images.githubusercontent.com/21563339/89624149-1d826400-d896-11ea-8965-a234304dc693.png) #### Pagination ![](https://user-images.githubusercontent.com/21563339/89644588-84187980-d8b8-11ea-8428-d9da62ba3f1c.png) ## Display linked object in tasks In the tasks panel, you will now have a link on every object displayed, so you can easily reach the page interesting you. ![](https://user-images.githubusercontent.com/7724491/93437451-4998f800-f8cc-11ea-844a-29534185d02e.png) ### Xen Orchestra 5.50 URL: https://xen-orchestra.com/blog/xen-orchestra-5-50/ Last updated: 2020-08-27T13:52:05.000Z It's our back to school release time, and Xen Orchestra 5.50 is now available! XCP-ng 8.2 beta is also on its way and our cloud offer is expanding with a new partnership with OVHcloud. ## Some XCP-ng news ### XCP-ng 8.2 - beta is coming ![xcp-ng82](https://xen-orchestra.com/blog/content/images/2020/08/xcp-ng82.png) Our developer team is working on the latest XCP-ng 8.2 and we are now really close to a beta release. An announcement is coming very soon on our [XCP-ng blog](https://xcp-ng.org/?ref=xen-orchestra.com) so stay tuned! Also, we have an important announcement coming regarding the support model of XCP-ng 8.2 - those of you subscribed to the [XCP-ng pro newsletter](http://eepurl.com/gtPpWb?ref=xen-orchestra.com) are already informed, all the others, take a guess! ### XCP-ng security patch We recently released a security patch for XCP-ng 8.0 and XCP-ng 8.1\. All you need to know about this patch is available on the [dedicated blogpost](https://xcp-ng.org/blog/2020/08/26/august-2020-xcp-ng-security-updates/?ref=xen-orchestra.com). ### XCP-ng infrastructure in the OVH cloud ![marketplaceovh](https://xen-orchestra.com/blog/content/images/2020/08/marketplaceovh.jpg) Another important step regarding XCP-ng is our partnership with OVH, a French hosting company with infrastructure all over the world. [![ovhoffer](https://xen-orchestra.com/blog/content/images/2020/08/ovhoffer.jpg)](https://marketplace.ovhcloud.com/rechercher?query=xcp-ng&ref=xen-orchestra.com) We recently joined their marketplace with [three different offers](https://marketplace.ovhcloud.com/rechercher?query=xcp-ng&ref=xen-orchestra.com) designed for companies that want a turnkey XCP-ng infrastructure, hosted on OVH hardware including XCP-ng installation, configuration as well as Xen Orchestra and pro support for your complete infrastructure. > Note that if you want to build a tailored XCP-ng infrastructure in the cloud, you can also request more information on [this page](https://xcp-ng.com/cloud/?ref=xen-orchestra.com). ## Xen Orchestra 5.50 ### Display orphan VDIs In the Health view, we added a new view listing VDIs and VDI snapshots that are orphaned (not attached to a VM). Orphaned VDIs are, most of the time, related to an incomplete VM deletion, or a migration that somehow failed. This new view should help you to clean unnecessary VDIs from your disks. ![](https://user-images.githubusercontent.com/10992860/90903119-c7510d00-e3cd-11ea-9426-9655359f30a8.png) ### Audit log - clouded fingerprints In the [Xen Orchestra audit log](https://xen-orchestra.com/blog/xo-audit/), you now have the ability to store the [generated fingerprints](https://xen-orchestra.com/blog/xo-audit/#generateanewfingerprint) in our secure infrastructure instead of your own. ![](https://xen-orchestra.com/content/images/2020/02/modal4.png) This is extra insurance that fingerprints cannot be altered by any means and that you can trust the integrity check done within the audit log. ![](https://xen-orchestra.com/content/images/2020/02/schema-audit-log-1.png) ### Edit VIF locking mode For release 5.49, we exposed a clearer way to view the VIF locking mode status. ![](https://user-images.githubusercontent.com/7724491/88414126-a56b6700-cddc-11ea-935e-65f2f4947f39.png) This release, we are giving you the ability to easily edit the VIF locking mode. ![](https://user-images.githubusercontent.com/7724491/88930670-13e87300-d27c-11ea-8c1f-b23b2967adb7.png) ![](https://user-images.githubusercontent.com/7724491/90113319-75671200-dd51-11ea-9efb-4b324952bb2a.png) ### Protect VM from accidental shutdown We have added a toggle in the advanced view of the console that will prevent VM to be shutdown accidentaly. ![](https://user-images.githubusercontent.com/1211016/85650820-f0724d00-b66b-11ea-95a4-3ab6b041fc92.png) ## UI improvements ### TX checksum offload TX checksum is a feature offered by some network cards allowing you to offload the checksum generation process for packets to your network card. Unfortunately, because of the way this works in a virtualized environment, there are a handful of network stacks where this can cause issues in VM guests. The primary incompatibility is with `pf` in FreeBSD, so PfSense users commonly encounter this. When it comes to XCP-ng infrastructure, you can solve issues related to this by disabling the TX checksum offload feature with minimal performance impact. Until now, this was a [pretty long and annoying process](https://xcp-ng.org/docs/guides.html?ref=xen-orchestra.com#pfsense-vm) using `xe` CLI commands. We now directly expose the option to enable/disable TX checksumming directly in the network tab of your VMs in Xen Orchestra. No more having to use the CLI for your PfSense or OPNsense installs! For most OS's, we do not recommend altering this option. ![](https://user-images.githubusercontent.com/21563339/89899130-1b940a00-dbe2-11ea-9f17-0cd155dfd928.png) ![](https://user-images.githubusercontent.com/21563339/89899147-22228180-dbe2-11ea-8c8f-524ee5bbf48d.png) ### PIF scan refresh When adding a physical network card, you need to do a `PIF.scan` on the host so the XAPI will add it. We added an option to refresh the PIF with a single click. ![PIF-scan](https://xen-orchestra.com/blog/content/images/2020/08/PIF-scan.png) ### Xen Orchestra 5.49 URL: https://xen-orchestra.com/blog/xen-orchestra-5-49/ Last updated: 2020-07-31T13:07:36.000Z Our July release is now available and it comes with a lot of new features, as well as major improvements to some existing features such as the Xen Orchestra Proxy and backups. Indeed, despite being both summer time combined to a complicated worldwide situation -euphemism-, this is a pretty large release (the [changelog](https://github.com/vatesfr/xen-orchestra/blob/master/CHANGELOG.md?ref=xen-orchestra.com#5490-2020-07-31) is speaking for itself). > Did you know? Today is [SysAdmin Day](https://sysadminday.com/?ref=xen-orchestra.com). So… Happy SysAdmin Day! ## XO Proxy improvements New features coming right from the field, where our proxy is already heavily used! ![](https://xen-orchestra.com/content/images/2019/04/xo-5c-20proxy_38106051.png) ### Pass HTTP proxy to xo-proxy ![](https://user-images.githubusercontent.com/21563339/87927826-1c72c980-ca84-11ea-8b5c-73dc8cff6221.png) You have now the ability to deploy a Xen Orchestra proxy with an http-proxy configuration to make it possible to access the Internet. Remember Inception? Sounds like it! ### Display available updates In the proxy view, we are now displaying information regarding available updates for the Xen Orchestra proxy: ![](https://user-images.githubusercontent.com/21563339/88184935-9d23f800-cc33-11ea-95a8-3864476b45d0.png) --- ## Backup improvements 💾 Backup is still the core of Xen Orchestra. And we continue to improve that after each release. ### Cloud Backup on Amazon S3 - Beta ![amazon-s3](https://xen-orchestra.com/blog/content/images/2020/07/amazon-s3.jpg) Xen Orchestra now supports Amazon S3 storage as a target for backup jobs storage. This is still a beta feature and we have some improvements to do before shipping this in production. However, you can already test this feature and [provide any relevant feedback to us](https://xcp-ng.org/forum/category/12/xen-orchestra?ref=xen-orchestra.com). Note this is a "native" integration, we are directly using AWS S3 library, not a filesystem emulation. ### Delta Backup - warning display for long retention chain ![](https://user-images.githubusercontent.com/7724491/86943044-376d4180-c146-11ea-81df-30b5f5632c8f.png) ![](https://user-images.githubusercontent.com/7724491/86943042-363c1480-c146-11ea-9617-7eb16fcafec5.png) We usually consider it a good practice to avoid too long of delta backup chains. Having reasonable retention time and/or having a short full backup interval will avoid corruption or issues with the file level restore tools. Therefore, we have added an alert when you are configuring backup jobs with retention values that are considered too large for safe operation in time. ### Display snapshots with missing jobs/VMs/schedules ![](https://user-images.githubusercontent.com/7724491/86264947-738f2800-bbc3-11ea-935e-54b59b901dfa.png) In the health view of the backup section, you will now see a list of snapshots with missing jobs/VMs or schedules. This should help the user to clean up useless snapshots that are not tied to an existing job or VMs in the infrastructure. --- ## SDN controller rules 🌐 A new feature is now included inside the XO SDN controller: the ability to control the VM's network traffic via XO's SDN controller. [![](https://xen-orchestra.com/blog/content/images/2020/07/show-acl.png)](https://xen-orchestra.com/blog/vms-vif-network-traffic-control/) Our main developer of the SDN controller, Benjamin, wrote a [detailed blogpost](https://xen-orchestra.com/blog/vms-vif-network-traffic-control/) about this new ability. --- ## UI improvements Still more and more improvements in the UI you start to know well. ### Locking mode In the VIFs view, we have improved the way we display the locking mode with a clear icon and tooltip. ![](https://user-images.githubusercontent.com/7724491/88414126-a56b6700-cddc-11ea-935e-65f2f4947f39.png) ### Power state selector in Home view You now have the ability to filter the VMs from the home view depending on their power state - this filter can be used in combination with the current search you are doing. ![](https://user-images.githubusercontent.com/7724491/86807062-c95b4880-c079-11ea-9150-fd380226cb13.png) ### Copy IP addresses into the clipboard It's now easier to copy/paste any IP address from the network view of the VM, within the Network tab! This one was suggested by [Tom](https://twitter.com/TomLawrenceTech?ref=xen-orchestra.com) from [Lawrence system](https://www.lawrencesystems.com/?ref=xen-orchestra.com). Now, just click on the IP, and it's in the clipboard! ![ipcopy](https://xen-orchestra.com/blog/content/images/2020/07/ipcopy.png) --- ## Misc 💡 There's always a misc category, insn't it? ### Better default boot order We have improved the way we are handling the boot order during the creation of a VM in a more logical way. If you have a disk attached during the VM creation, it will be used first instead of the network. ### Support added for OVA with Gzipped VMDK Support for importing OVA files with Gzipped VMDK has been added in Xen Orchestra. ### Citrix Hypervisor 8.2 URL: https://xen-orchestra.com/blog/citrix-hypervisor-8-2/ Last updated: 2022-06-01T14:43:54.000Z ⚠️ XCP-ng 8.2 is also available as an LTS (Long Term Support). You can [download XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com) here, providing a 100% compatibility with Citrix Hypervisor with all features for free. ![logo](https://xen-orchestra.com/blog/content/images/2020/07/logo.png) Citrix Hypervisor 8.2 has been available for about two weeks and Xen Orchestra is **[fully compatible](https://xen-orchestra.com/docs/supported%5Fhosts.html?ref=xen-orchestra.com#citrix-hypervisor-formerly-xenserver)** with this new version of Citrix Hypervisor. ## What's new? ![ch](https://xen-orchestra.com/blog/content/images/2020/07/ch.png) The complete changelog for Citrix Hypervisor is available on [this page](https://docs.citrix.com/en-us/citrix-hypervisor/whats-new.html?ref=xen-orchestra.com). This new version of Citrix Hypervisor 8.2 is a bit light regarding new features for a good reason: Citrix Hypervisor 8.2 is a release specifically oriented towards stability as it will be the new [LTSR version for Citrix Hypervisor](https://www.citrix.com/blogs/2020/06/25/citrix-hypervisor-8-2-ltsr-is-here/?ref=xen-orchestra.com). The previous LTSR release, XenServer 7.1 LTSR, will still be supported for 3 years. Consequently, the main improvements of this version are the following: - Increased configuration limits (maximum host RAM and maximum number of logicial processors per host) - Security improvements (server TLS certificates, TLS 1.2 protocol) On the other hand, there are a few notable changes that can cause difficulties to some users: - Disaggregation of the Citrix VM tools (now split in two differents sets, one for Windows, one for Linux). > Unfortunately, that means that the tools are not anymore available directly in Citrix Hypervisor and that you will need to download them from the Citrix website - Support for Windows 7, Windows Server 2008 SP2, and Windows Server 2008 R2 SP1 has been removed > Which makes sense since Microsoft does not support it anymore - Ivy Bridge CPUs support has been removed > Which also makes sense since Intel stopped the microcodes updates for this family - The vSwitch Controller appliance has been removed > Note that if you are using Xen Orchestra, you can use our [SDN controller feature](https://xen-orchestra.com/docs/sdn%5Fcontroller.html?ref=xen-orchestra.com) as an alternative ## XCP-ng status ![logo-xcp-ng-8-2-small](https://xen-orchestra.com/blog/content/images/2020/07/logo-xcp-ng-8-2-small.png) We are currently working on the new version of XCP-ng: XCP-ng 8.2\. Our goal is to release a first **beta version** this summer (August) and a **Release Candidate** should be ready in September. XCP-ng 8.2 definitive release should be for the end of September/early October. > More information about XCP-ng 8.2 will be available on [XCP-ng blog](https://xcp-ng.org/blog/?ref=xen-orchestra.com) very soon. ## How to update CH 8.2 with Xen Orchestra Citrix Hypervisor 8.2 is not a major update, which means that the upgrade from previous version should be easy. > ⚠: The update process can take a while (up to 15min+ per host). **DO NOT RESTART TOOLSTACK OR HOSTS DURING THE PROCESS.** 1. Download the ISO of the edition of Citrix Hypervisor you need from [this page](https://www.citrix.com/downloads/citrix-hypervisor/?ref=xen-orchestra.com). > ⚠ You will need to have a Citrix account to reach the download page. ![download-ch-82](https://xen-orchestra.com/blog/content/images/2020/07/download-ch-82.png) 1. In Xen Orchestra, go to the home/pool view and select the pool you want to upgrade to CH 8.2 ![](https://xen-orchestra.com/content/images/2017/12/pools-view.png) 1. Go into the "Advanced" tab and click on "Browse file" in the "Install supplemental pack on every host", then select the file you downloaded earlier: ![](https://xen-orchestra.com/content/images/2017/12/uploadpack.png) 1. Now you only have to wait. See the "Monitor update process" section below to see what's happening on your host. While there is a update task in the "Task" view, **DO NOT reboot or restart toolstack on your host!** ![](https://xen-orchestra.com/content/images/2017/12/tasks.png) When there is no `pool_update.apply` task left, you can reboot the hosts to have all updates validated. You can do it later, but it's recommended to do it ASAP. ### Xen Orchestra 5.48 URL: https://xen-orchestra.com/blog/xen-orchestra-5-48/ Last updated: 2020-06-30T16:27:26.000Z Xen Orchestra 5.48 is now available and brings new management tools as well as some UI improvements. ## Pass the Salt conference Olivier will give a conference during the French cybersecurity and Open Source software event tomorrow (July 1st) at **3:20PM CEST**. It's free to attend and in English language - more information available on our [dedicated blogpost](https://xcp-ng.org/blog/2020/06/04/pass-the-salt-2020-virtual-conference/?ref=xen-orchestra.com). > To attend the event, you will need to register on [this page](https://pretix.eu/passthesalt/2020/?ref=xen-orchestra.com) (**it's free**) [![](https://xcp-ng.org/content/images/2020/05/pass-the-salt.png)](https://pretix.eu/passthesalt/2020/?ref=xen-orchestra.com) ## Filter backups with missing jobs/schedules/VMs When a change occurs in a backup job (eg. a VM is deleted or a VMs is removed from a backup job), old files related to the jobs such as snapshotd on the SR or backup files on the destination remote will be left untouched and won't be automatically cleared up because clearing old files is a thing usually handled during the backup job itself. As it's a situation related to backups, we don't want to remove automatically those files, even if the backup jobs they were connected to completely disappeared. Instead, we have implemented a filter, allowing the user to track this kind of backup with missing parts and therefore allowing you to manage it the way that suits you the best. ![](https://user-images.githubusercontent.com/7724491/84305831-f429ae00-ab5a-11ea-8c84-d5e977fb9138.png) ## Protect VM from accidental deletion You can now activate an option on your critical VMs to avoid accidental deletion. This feature will forbid all deletion operations when it's active. ![](https://user-images.githubusercontent.com/10992860/83541796-6a466900-a4fa-11ea-9476-6c8a1cfbf09a.png) ## Copy/Clone VM templates You have now the ability to clone or copy a VM template (eg. In case you want to migrate it to another pool). ![](https://user-images.githubusercontent.com/7724491/82465547-b2f43000-9abf-11ea-82d7-a34738782759.png) ![](https://user-images.githubusercontent.com/7724491/84640924-a31f0e80-aefa-11ea-8dfa-17beaf7dfda3.png) ## UI Improvements ### SR Status In the SR view of your VMs we will now display the SR status: **thin**, or **thick** provisioned. ![](https://user-images.githubusercontent.com/7724491/84521265-092a4c80-acd5-11ea-88cd-a374eb9298c6.png) ![thinvsthick](https://xen-orchestra.com/blog/content/images/2020/06/thinvsthick.png) ### Proper detection for PV drivers and management agent We are now doing a clear differentiation between the management agent and the PV drivers. Therefore we are now able to detect both of them. > PV drivers not detected > ![](https://user-images.githubusercontent.com/21563339/84161734-e3503e00-aa6f-11ea-8547-7179edfc093c.png) > PV drivers detected and Management agent not detected > ![](https://user-images.githubusercontent.com/21563339/84157861-805ca800-aa6b-11ea-9d30-e57f25c0f751.png) > PV drivers detected and Management agent detected > ![](https://user-images.githubusercontent.com/21563339/86018927-448f7f80-ba26-11ea-9fd5-9388b045c6fe.png) ### Show IP addresses next to the VIFs IP addresses of VMs are now displayed directly in the network panel in each VM view. ![](https://user-images.githubusercontent.com/7724491/82071424-5e733e00-96d6-11ea-9d1c-77f02b74928f.png) ## What's next We are currently working on some important features coming soon in Xen Orchestra. ### OpenFlow rules with XO SDN controller 🛡️ Controlling the VM's network traffic via XO's SDN Controller will soon be possible thanks to the OpenvSwitch capabilities. This feature will be available next month, in the meantime, you can learn more about it on the [dedicated devblog](https://xen-orchestra.com/blog/vms-vif-network-traffic-control/) our developer, Benjamin, wrote on the topic. ### Auditlog fingerprints in the Cloud 🔍 We will increase the security in the audit log by providing an option to store the fingerprints in your online xen-orchestra.com account. This way, fingerprints cannot be altered by a malicious user locally, without triggering an alert. If you want to learn more about the Audit log in general, take a look on the [dedicated devblog](https://xen-orchestra.com/blog/xo-audit/) ### DevBlog #7 - VM's VIFs network traffic control in XO URL: https://xen-orchestra.com/blog/vms-vif-network-traffic-control/ Last updated: 2020-12-07T10:58:13.000Z An exciting new feature will soon be released: controlling the VM's network traffic via XO's SDN Controller. Very soon you'll be able to enable/disable traffic on a specific VM network interface. # How does it work? This feature is implemented thanks to the [OpenFlow v1.1 protocol](https://www.opennetworking.org/wp-content/uploads/2014/10/openflow-spec-v1.1.0.pdf?ref=xen-orchestra.com): an OpenFlow controller, in XO's SDN Controller plugin, sends OpenFlow messages to a XCP-ng's [OpenVSwitch](https://www.openvswitch.org/?ref=xen-orchestra.com) (virtual switch managing the traffic for the host and its VMs). An OpenFlow message allows the controller to add/modify/delete traffic routing rules, this is how we can enable or disable part of the traffic on a VM VIF. ## Taking control of OpenVSwitch OpenvSwitch is the virtual switch of an XCP-ng host, it can have a manager and a controller. The manager will use [OVSDB](https://tools.ietf.org/html/rfc7047?ref=xen-orchestra.com) to manage the switch bridges, ports and interfaces, the controller will control the traffic thanks to OpenFlow messages. The plugin needs to do both, here's how it's done: - Becoming the SDN controller of the host thanks to [XAPI](https://xapi-project.github.io/xen-api/classes/sdn%5Fcontroller.html?ref=xen-orchestra.com): `xe sdn-controller-introduce protocol=pssl`, we use `pssl` to allow many controllers at the same time as long as teir certificate match the same ca-certificate installed on the host. This allow the plugin to send OVSDB commands to OpenVSwitch. - Becoming the manager of OpenVSwitch bridges thanks to OVSDB: A OVSDB command is send by the plugin to insert our plugin as manager for each bridges of OpenVSwitch. Now the plugin can send OpenFlow messages. ![SDN-controller-resize2](https://xen-orchestra.com/blog/content/images/2020/05/SDN-controller-resize2.png) > The need for OVSDB is the reason this feature is added to the SDN Controller plugin instead of a new one, the OVSDB protocol was already immplemented for private networks creation in it. ## Controlling the traffic Once the plugin has control over the host's OpenVSwitch its time to control the traffic by sending OpenFlow messages giving rules to apply for specific parts of the traffic to OpenVswitch. Here's an example of an OpenFlow rule: ``` priority=65527,tcp,in_port=4,dl_src=ae:f7:4b:84:6c:8b,nw_src=192.168.5.242,nw_dst=192.168.5.55,tp_dst=5060 actions=drop ``` This means to *drop* any traffic matching all the following conditions: - Traffic is TCP on port 5060 (so SIP traffic) - Traffic comes from the VIF with MAC address: ae:f7:4b:84:6c:8b and IP address: 192.168.5.242 - Traffic goes to IP address: 192.168.5.55 In a nutshell, SIP traffic from 192.168.5.242 to 192.168.5.55 is disabled. # How does the feature look like? In the VM network tab of XO, a new column has been added to the VIF list: this column allows to view the existing rules and to add one. ![show-acl](https://xen-orchestra.com/blog/content/images/2020/04/show-acl.png) When adding a rule, you can choose to: - enable/disable the traffic - for a specific protocol (optional) - on a specific port (optional) - for a specific IP or IP range (optional) - outgoing from the VIF / incoming to the VIF/ both For instance: ![add-rule](https://xen-orchestra.com/blog/content/images/2020/04/add-rule.png) Adding this rule would allow UDP traffic on port 1212 ougoing to and incoming from all IPs in range 12.12.12.12/12 on the selected VIF. # Access the feature The feature will be released with version 1.0.0 of the SDN Controller (coming soon!). An XCP-ng update will be provided as well for XCP-ng 8.X, it will open the OpenFlow port (TCP 6653) when a SDN Controller is set and close it when there's not: `yum update xapi-core xapi-doc xapi-tests xapi-xe --enablerepo=xcp-ng-testing` ## Older versions On a version of XCP-ng older than 8.0, the following command will open the OpenFlow port: `iptables -A xapi-INPUT -p tcp -m conntrack --ctstate NEW -m tcp --dport 6653 -j ACCEPT` # Under the hood For our own requirements, we had to build a JS library from scratch, because any other we found were at least very incomplete or simply broken. Here is the code: [https://github.com/vatesfr/xen-orchestra/tree/master/@xen-orchestra/openflow](https://github.com/vatesfr/xen-orchestra/tree/master/@xen-orchestra/openflow?ref=xen-orchestra.com) If you are interested to get it available in a dedicated repo (eg for your own project), let us know! # What's next? ## More rule levels For now rule can only be applied to a VIF, in the future (probaly with XO6 new design) rule could be added to more levels (VM, Network, Pool, All pools) to have more complex set of rules. ## More protocols pre-configured At the moment the pre-configured protocol are: IP, ARP, ICMP, UDP and TCP. More protocol can be added to ease the use instead of having to specify the port. For instance: - HTTP: TCP on port 80 - HTTPS: TCP on port 443 - SIP: TCP on port 5060 - etc ### Xen Orchestra 5.47 URL: https://xen-orchestra.com/blog/xen-orchestra-5-47/ Last updated: 2020-05-29T11:44:21.000Z Xen Orchestra 5.47 is now available and it comes with a lot of different improvements on different existing features: Backups, SDN controller, OVA 2 support, Audit log, and security. ### Xen Orchestra proxy trial ![](https://xen-orchestra.com/content/images/2019/04/xo-5c-20proxy_38106051.png) **XO proxies** are out of beta and ready for production for a month now. For those who would like to test it and that didn't get the opportunity to do it during the beta phase, you have now the opportunity to activate a trial period for proxies. The process is very easy, you simply need to deploy a proxy on the host of your choice, if no license for proxy is available, you will have the option to start a trial. ![proxy-trial-5](https://xen-orchestra.com/blog/content/images/2020/05/proxy-trial-5.png) ## Support for OVA2 OVA (Open Virtual Application) is one of the most common formats for virtual appliances and is already supported since a long time in Xen Orchestra. As OVA2 is getting more and more popular out there we implemented the support for OVA2 import in Xen Orchestra as well. ![ova](https://xen-orchestra.com/blog/content/images/2020/05/ova.png) ## SDN controller rules SDN controller is still evolving and this month, in addition of a [small bug fix](https://github.com/vatesfr/xen-orchestra/pull/4996?ref=xen-orchestra.com), we are introducing a new feature: **preferred center at network creation** When you create a GPN, all the hosts in the network are connected to a central host. Until now, this host was randomly selected. ![sdn-controller_46874975](https://xen-orchestra.com/blog/content/images/2020/05/sdn-controller_46874975.jpg) This is now possible to select a preferred central host at the network creation. ![](https://user-images.githubusercontent.com/12529066/82024436-14676980-9690-11ea-9a67-b6c6425df989.png) ## Security improvements We are always working in Xen Orchestra and XCP-ng to improve the overall security of your infrastructure. This month, we added different features and support going down this path. ### 🛡️ LDAP over TLS `StartTLS` is a modern encryption protocol you can now use with LDAP in Xen Orchestra. ### 🔐 Config encryption You can now encrypt the content of your configuration using a passphrase. This feature is based on `OpenPGP` and uses `AES256` encryption algorithm. ![exportconfigenc](https://xen-orchestra.com/blog/content/images/2020/05/exportconfigenc.png) ### 🕵️ Record failed user attempts to log to the audit log We improved the Audit log by recording the users failed attempt to connect. This is an extra step to improve the security around the Audit log. ![Audit log](https://xen-orchestra.com/blog/content/images/2020/05/82794861-6f107a80-9e73-11ea-8276-9f06efce456a.png) ## Backup Improvements Backups are the core of Xen Orchestra. We are working on improving them every day! ![backups-solutions](https://xen-orchestra.com/blog/content/images/2020/05/backups-solutions.png) ### 🛂 List of VMs (not) backed up In our improvement process regarding security tools for your infrastructure, we have added a new comprehensive and quick view directly in the XO home to provide an overview of the backup states of your infrastructure. You can now filter the list of VMs backed up or not. ![](https://user-images.githubusercontent.com/7724491/81094723-3af50a00-8f04-11ea-9891-790c9a5ed603.png) ![](https://user-images.githubusercontent.com/7724491/82681556-3cd20380-9c4e-11ea-9f86-02bca2839a99.png) ### 🏎️ Backup listing performances improved Until now, we were sending a lot of data back to the Xen Orchestra appliance in order to display the list of backups available for restoration. While it was not an issue for a lot of users out there, it was one for very large infrastructure with hundreds of backed up VMs and jobs, making loading time very long and in some cases, resulting in a `timed out` error. In this release, we filtered the data we send more accurately, resulting in a size reduction between 10 to 100 times compared to the previous time. We are expecting a clear improvement in loading time for our backup list in large infrastructures. ### 🔬 Backup performances optimization We are currently working on the improvement of all our backup features. To do so, the first big step is to implement backup performance metrics inside Xen Orchestra. To begin with this project we added stream speed tracers in the Xen Orchestra proxy. The main goal for these tracers will be to indentify bottlenecks in the data stream during backup execution. We will keep you informed with our progress in the next few months. > Note: For now, the data collected thanks to the tracers won't be displayed in your infrastructure. The data are stored in the log server proxies. ### 🗄️ CSV file included in the backup report Along with the PDF we are sending, you will now have a CSV file containing all the raw data of the report. This will allow users to perform extra reporting or data consolidation using the tool of their choice. ## New License system Our new license management system [introduced two months ago](https://xen-orchestra.com/blog/xen-orchestra-5-45/#betterlicensemanagementsystemforxoa) will be fully operational starting with this release. It is now required for evey customer to bind a Xen Orchestra license to the appliance of his choice. Follow the [documentation](https://xen-orchestra.com/docs/license%5Fmanagement.html?ref=xen-orchestra.com) to get the complete process. > Note: All license types will now be displayed in your the `Licenses` section of your appliance ### SaltStack CVE-2020-11651 and CVE-2020-11652 incident URL: https://xen-orchestra.com/blog/saltstack-cve-2020-11651-and-cve-2020-11652-incident/ Last updated: 2020-05-04T11:35:05.000Z Sunday night, we were hit by an attack that was caused by 2 SaltStack vulnerabilities[\[1\]](#fn1), also affecting the rest of the world[\[2\]](#fn2). We are sharing transparently with you exactly what happened and how it affected us. > TL;DR: A coin mining script ran on some of our VMs, and we were lucky nothing bad happened to us: no RPMs affected and no evidence that private customer data, passwords or other information has been compromised. GPG signing keys were not on any affected VMs. We don't store any credit card information nor plain text credentials (securely hashed with argon2+salt). Lesson learned. ## What happened: detailed timing > Note: timing is in UTC. ![time-3098699_640-1](https://xen-orchestra.com/blog/content/images/2020/05/time-3098699_640-1.jpg) - At **1:18AM**, Sunday, May 3: some services on our infrastructure were unreachable. Only a subset of them, but almost at the same time on various virtual machines in various datacenters. High CPU usage was also another visible symptom. - At **7:30AM**, the same day: Olivier noticed the outage on some services. Immediately affected VMs were rebooted, and all services came back. However, feeling that something was wrong, a full investigation started. Only a dev machine was kept "as-is" after reboot, all others were investigated and some non-essential services disabled. At this time, we already knew precisely which VMs and services were affected. Firewalls were re-enabled after being "mysteriously" disabled. - At **11:30AM**, the dev machine was displaying the same previous symptom again. But now, it was visible live. The culprit was identified quickly as a "rogue" Salt Minion process mining coins (hence the CPU usage, a process that also stopped web servers). It didn't happen again on other VMs because Salt Minion was disabled on them. This is when we understood SaltStack [CVE-2020-11651](https://nvd.nist.gov/vuln/detail/CVE-2020-11651?ref=xen-orchestra.com) and [CVE-2020-11652](https://nvd.nist.gov/vuln/detail/CVE-2020-11652?ref=xen-orchestra.com) were the attack vector. - From there, more targeted investigations started about the payload. These investigations lasted all Sunday (and part of the night), to see if something else happened outside the "basic attack". Using VM backups from Xen Orchestra, we were able to check/diff entire filesystems before, during and after the attack. It helped us to be **confident about which payload version affected us and that nothing else was involved**. - No other sign of the attack since then, with close monitoring of all VMs metrics. That's also why we knew exactly what happened. | ![attackduration](https://xen-orchestra.com/blog/content/images/2020/05/attackduration.png) | | ------------------------------------------------------------------------------------------- | | *Whole attack duration is very visible from VM metrics* | **At this stage, it was clear we were caught in a broad attack affecting tons of people. We believe the initial assessment that "thousand of infrastructures targeted" might be an understatement [\[3\]](#fn3). Good news in this case, was the very generic payload, built probably really quickly to generate money fast without being stealthy.** > Note: no XCP-ng hosts were attacked because we don't use SaltStack on them! ## Payload analysis Because of the attack behavior, we were able to analyze the payload. The version of `salt-store` in cause was "V1", with the following md5sum: `8ec3385e20d6d9a88bc95831783beaeb`. Luckily, this payload version is pretty basic: - disable all firewalls - disable some CPU intensive processes (NGINX, Apache, etc.) - tune your system for more efficient mining - mine coins ![2092976-blu_bombcart_1_-2](https://xen-orchestra.com/blog/content/images/2020/05/2092976-blu_bombcart_1_-2.png) Also, Version 1 is not persistent: it comes from the SaltStack vulnerability, but doesn't survive a reboot (matching the behavior of what happened to us). However, we double checked all crontabs because further versions later added persistence. Also, no suspicious network activity was seen during the attack: because all webservers went down, there was almost no extra traffic on the affected VMs and it helped to see what's going on. > A big thanks to the SaltStack community who shared all the details together, helped us to go faster and crowdsource all the results and analysis! Read more there: [https://github.com/saltstack/salt/issues/57057](https://github.com/saltstack/salt/issues/57057?ref=xen-orchestra.com) and here [https://saltstackcommunity.slack.com/archives/C01354HKHMJ/p1588535319018000](https://saltstackcommunity.slack.com/archives/C01354HKHMJ/p1588535319018000?ref=xen-orchestra.com) ## Why we were vulnerable SaltStack is used to push updates or configure multiple VMs at once. We trusted its communication protocol (using keys) and we used that flexibility to add new VMs dynamically, without using a VPN or a secure tunnel. This was a mistake: it allowed the attackers to access the available Saltmaster port to inject their payload in available minions. Also, a salt master patch wasn't available in our master distro repository before the attack. We were just unaware of this coming. It's on us, and it's a good lesson. ## On the good side - Our most important stuff is hosted in Git repositories: it's trivial to validate nothing was changed on our internal applications - We are happy to trust an external Credit Card provider (Stripe) so we don't have to deal with any credit card data - We also don't have any plain text credentials (securely hashed with argon2+salt) - XO Backups were really useful to compare what happened before, during and after - We could validate that no Xen Orchestra package was affected nor modified - **XCP-ng RPMs repository were not touched**. Even if they had been altered, it would not have been able to affect our user's hosts thanks to [metadata and RPMs GPG signing](https://xcp-ng.org/docs/mirrors.html?ref=xen-orchestra.com#security). - XCP-ng GPG signing key is safe: the signing server wasn't affected by the attack ## Actions Assessing the damages (luckily none) was the first step. We are aware it might have been far more dangerous, so we took a set of measures to increase our level of protection: 1. SaltStack won't be used anymore, at least in the short term. Master node is off, and Salt minions were removed on all VMs. Due to the relatively small infrastructure size, we decided it's not essential for our operations. 2. We are changing all system passwords anyway, and also all token/keys with external services. 3. Management network is being revamped to be entirely private (using VPNs/tunnels) 4. Having our platforms in various DCs at various bare-metal providers was also a cause of not using a private network: it's less convenient. We already had plans to host our infrastructure ourselves, using the same racks used for our [https://xcp-ng.com/cloud](https://xcp-ng.com/cloud?ref=xen-orchestra.com). We'll accelerate our plans. 5. We continue to closely monitor VM activity: new alerts were created that matches payload behavior (CPU usage). So far, so good. 6. We continue to assess all our systems in case we missed something, by participating with the SaltStack community, also helping people affected. 7. We communicate (here!) regarding what happened. 8. We are improving our alert system to react more quickly in case of incidents on our own infrastructure. Weirdly enough, we are more reactive for customer issues on their premises than for our own machines. ![up-2081170_640](https://xen-orchestra.com/blog/content/images/2020/05/up-2081170_640.jpg) ## Conclusion In short, we were caught in a storm affecting a lot of people. We all have something in common: we underestimated the risk of having the Salt Master accessible from outside. Luckily, the initial attack payload was really dumb and not dangerous. We are aware it might have been far more dangerous and we take it seriously as a big warning. The malware world is evolving really fast: having an auto update for our management software wasn't enough! The attack came before any update was available in our SaltMaster Linux distribution. Lesson learned: we are hardening everything, creating a dedicated management network, only exposing what's needed. We'll provide guides to harden your own XCP-ng/Citrix Hypervisor infrastructure, from what we've learned here. > If you are running SaltStack in your own infrastructure, please be very careful. Newer payloads could be far more dangerous. You can follow the [Salt GitHub issue](https://github.com/saltstack/salt/issues/57057?ref=xen-orchestra.com) about what's going on! --- 1. [https://labs.f-secure.com/advisories/saltstack-authorization-bypass](https://labs.f-secure.com/advisories/saltstack-authorization-bypass?ref=xen-orchestra.com) [↩︎](#fnref1) 2. [https://www.ibtimes.sg/hackers-take-down-googles-android-substitute-lineageos-server-ghost-blogging-platform-44314](https://www.ibtimes.sg/hackers-take-down-googles-android-substitute-lineageos-server-ghost-blogging-platform-44314?ref=xen-orchestra.com) [↩︎](#fnref2) 3. "A scan revealed over 6,000 instances of this service exposed to the public Internet" *F-Secure* [↩︎](#fnref3) ### Xen Orchestra 5.46 URL: https://xen-orchestra.com/blog/xen-orchestra-5-46/ Last updated: 2020-04-30T13:47:55.000Z The big release for this month is the availability of Xen Orchestra proxies for production environment! We also improved the self-service and the OVA format import in Xen Orchestra. On other news, we also reached [100.000 downloads for XCP-ng](https://xcp-ng.org/blog/2020/04/17/100-000-downloads-for-xcp-ng/?ref=xen-orchestra.com)! ## Xen Orchestra proxies [![](https://xen-orchestra.com/content/images/2019/04/xo-5c-20proxy_38106051.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/proxy-home) > If you are a Premium edition customer for Xen Orchestra, one XO proxy is available for free in your edition! Xen Orchestra proxies are now available. The main usecase for using XO proxy is: - Having a distant location in which you want to perform backup - Having a very large VMs infrastructure, and therefore, a large number of backup job and you want to increase performances by splitting the data load. We wrote a [complete blogpost](https://xen-orchestra.com/blog/xen-orchestra-proxy/) dedicated to the new XO proxy product and the subscription process for it. ![](https://user-images.githubusercontent.com/21563339/80114537-fe302700-8583-11ea-9bf5-598e0b143021.png) If you are interested into the conception and the way XO proxies are working, you can also take a look on our [Devblog on the topic](https://xen-orchestra.com/blog/backup-proxies/). ### Proxy logs > The Proxies logs are coming in a patch release next week! Additionally to the relase, we will also introduce a logs feature for backup achieved using Xen Orchestra proxies. Logs will be a very useful tools for our developers team, especially when delivering support in user infrastructure. ## Italian language support Thanks to [@Infodavide](https://github.com/infodavide?ref=xen-orchestra.com) on Github, the Italian language support is now available in Xen Orchestra. ![1200px-Flag_of_Italy](https://xen-orchestra.com/blog/content/images/2020/04/1200px-Flag_of_Italy.jpg) > 💡 To select your language in Xen Orchestra you simply need to go in your profile section. ## Self snapshot We improved the self-service features by adding the ability to a user in such environement to create and manage snapshot. > ⚠ Snapshots created this way will consume the quota allocated to the user. ## Better OVA import ![ova-file](https://xen-orchestra.com/blog/content/images/2020/04/ova-file.jpg) OVA is a very standard format among the virtualization industry (eg. Vmware, Oracle...) We fixed some issues that were occuring sometimes during an OVA import making the whole import process more reliable in this new Xen Orchestra release. It should be easier now to migrate infrastructure from VMware to XCP-ng. ## New XO documentation! We revamped our official documentation, which is far easier to read, and more clear. Also with a working research bar! Go take a look now at [https://xen-orchestra.com/docs](https://xen-orchestra.com/docs?ref=xen-orchestra.com) ### Xen Orchestra Proxy URL: https://xen-orchestra.com/blog/xen-orchestra-proxy/ Last updated: 2024-10-30T07:52:36.000Z > Xen Orchestra proxies are available if you are using the latest branch release. ![](https://xen-orchestra.com/content/images/2019/04/xo-5c-20proxy_38106051.png) ## What is it? Xen Orchestra proxy is a new product working with Xen Orchestra, specifically with all the Xen Orchestra backup features. The main use case for backup proxy is the need to execute backup in distant location, or in location with a very large number in VMs and therefore, a very large number of jobs executed at the same moment. XO Proxy will have the ability to stream the data for any backup job instead of your main Xen Orchestra appliance, very handy when your backup job needs to be done in a location different of the one in which you deployed Xen Orchestra. > Proxies should be used in one of this two situation: > > - You need to do backup in a distant location and want to avoid useless back and forth of the data streamed > - Your VMs infrastructure is very large and you need to split the load between XO and proxies to increase performances ## How it works? Technically speaking, the process is rather easy to understand. Proxies are working as a "minimalistic" Xen Orchestra appliance whose only purpose is to execute backup jobs when they are required to do so by a central Xen Orchestra. To go a little bit deeper in the explanation, we wrote, a while back, a [Devblog explaining the choices we made](https://xen-orchestra.com/blog/backup-proxies/) regarding the proxies implementation, and some of the ideas we have for the future of this product. ![](https://xen-orchestra.com/content/images/2019/04/withproxy-2.png) ## Purchase process With the XO Proxies is also coming a brand new licensing system in Xen Orchestra to allow you to deploy multiple proxies in different infrastructure. As always, our goal was to create an easy and turnkey process for purchase and licenses activation. ### Purchase 1. On the [Proxy page](https://xen-orchestra.com/?ref=xen-orchestra.com#!/proxy-home) click on the "Buy" button 2. Once in the store, you will have the ability to select one or multiple proxies to purchase at once 3. Follow the step-by-step in the store (if you need help, you can still use our [documentation](https://xen-orchestra.com/docs/directpurchase.html?ref=xen-orchestra.com)) ### Bind your license > Once the purchase is complete. 1. In the proxy section of your appliance, deploy a proxy. ![](https://user-images.githubusercontent.com/21563339/80114306-b6110480-8583-11ea-8722-83f22e5be778.png) ![](https://user-images.githubusercontent.com/21563339/80114537-fe302700-8583-11ea-9bf5-598e0b143021.png) 2. If you have an available proxy license, it will automatically be used for your newly created proxy. 3. That's it, your proxy is now deployed and licensed. You can create a backup job. ![](https://user-images.githubusercontent.com/21563339/80116365-29b41100-8586-11ea-9746-e01ca3e53996.png) ### Xen Orchestra 5.45 URL: https://xen-orchestra.com/blog/xen-orchestra-5-45/ Last updated: 2020-03-31T17:15:29.000Z In the difficult context of COVID-19's pandemic, our team, [confined at home](https://xen-orchestra.com/blog/how-we-handle-covid-19/) is still working to deliver a reliable and flexible web interface for you to manage your virtual infrastructure from any device and from anywhere! This month, we deliver a very interesting and exclusive feature: **RAM enabled backup**. This feature works exclusively with the most recent version of [XCP-ng: 8.1](https://xcp-ng.org/blog/2020/03/31/xcp-ng-8-1/?ref=xen-orchestra.com). > Remember, as usual, all the new features are available first on the `latest` release branch in Xen Orchestra and will come in the `stable` branch for the next release. ## XCP-ng 8.1 is available The latest version of XCP-ng is now available. Performance improvements, security patches and new features embedded directly in the virtualization platform, you can check all the major highlights on this release blogpost. Among new features, the support for **RAM enabled backup** is natively supported in XCP-ng 8.1. [![](https://xcp-ng.org/content/images/2020/01/xcp81.png)](https://xcp-ng.org/blog/2020/03/31/xcp-ng-8-1/?ref=xen-orchestra.com) ## RAM enabled backup > Note: RAM enabled backup is still an experimental feature, we do not recommend it to be used in a production environment yet. It will allow you to perform backup in which we will also export the RAM contents in order to avoid corruption of the backup file. This is especially useful when it comes to database backup (as MS SQL or Active Directory VMs). This also means less time to resume your VM: no OS boot time, you are just resuming at the same you were during the backup. No session or context loss. Our developer, Benjamin, wrote a dedicated [DevBlog](https://xen-orchestra.com/blog/devblog-6-backup-ram/) on this feature. ![](https://xen-orchestra.com/content/images/2020/03/REB.png) > RAM backup is (for now) only compatible with XCP-ng 8.1\. It's already in `testing` repo of XCP-ng 8.0, so expect it soon there. ## XO Proxy - Network configuration Xen Orchestra Proxies are expected to be ready for production for the April release. Until that moment, proxies are still in release candidate and you can deploy and test them for free. This month, we added **network configuration** during the proxy deployment phase. ![](https://user-images.githubusercontent.com/21563339/76201770-14f90500-61f4-11ea-980b-06ed966eaf96.png) ![](https://xen-orchestra.com/content/images/2019/04/xo-5c-20proxy_38106051.png) ## Audit log - integrity check We improved the integrity check in the Audit Log feature. You will now have contextualization available for errors during the check to provide more insight about the issue (missing, altered...). ![](https://user-images.githubusercontent.com/21563339/77325602-e3665a80-6d18-11ea-8016-33c2a1601a92.png) ![](https://user-images.githubusercontent.com/21563339/77325817-3213f480-6d19-11ea-8d70-cbef064c2405.png) ## Backup list for each VM For each VM, you will have a new view, in which you will find a list of backup jobs in which your VM is currently enrolled. This will allow users to get an easy view of the current backup state for a particular VM and, eventually, avoid backing up a VM multiple times for no reason. This new view is part of a milestone we are currently working on, to provide to users accessible and fast ways to check the backup situation in their infrastructure. More is coming around that idea in the next release. Stay tuned ![](https://user-images.githubusercontent.com/7724491/77627983-0165d200-6f48-11ea-8173-994127b6b069.png) ## Migration enhancements ### Migrate VDI from SR's view We have added an option to allow you to migrate VDIs directly from the SR's view. ![](https://user-images.githubusercontent.com/7724491/74142839-f6561d00-4bf9-11ea-83b0-1bcd8ab3d4b6.png) ![](https://user-images.githubusercontent.com/7724491/76862314-35f9cf80-685e-11ea-9c67-6132dfe01e28.png) ### Migration network You can now, optionally, select a migration network when you migrate a VM, even within a pool. ![](https://user-images.githubusercontent.com/7724491/76073490-f4357300-5f99-11ea-9683-76895b713d35.png) ## Better license management system for XOA > Note: Binding (or not) your licenses will not be a problem for your Xen Orchestra immediately after the update. You will have until the June release to bind all your Xen Orchestra Appliances or proxies with a valid license. We are introducing a new management system for licences in Xen Orchestra. This system will make it easier to manage Xen Orchestra and proxies licenses which are coming soon. We are also aiming for more flexibility in the future, thanks to a license system which does not rely entirely on a single email address. Consequently to this new system, some action will be required on your side to bind correctly your license within Xen Orchestra. Here is the step-by-step guide. 1. Go in the Licenses section in your Xen Orchestra Appliance 2. All the licenses you paid for should be visible on this page. Unbinded licenses should have a green `activate license` button. ![](https://user-images.githubusercontent.com/10992860/77639410-08e1a700-6f59-11ea-9e2b-37eada0d11b1.png) 1. By clicking on the activate license button, you will start the process of binding the license on the **current Xen Orchestra Appliance** you are using. ![](https://user-images.githubusercontent.com/10992860/77639550-3b8b9f80-6f59-11ea-9ab6-9a0a60ca7a39.png) ### DevBlog #6 - RAM enabled backups and replication URL: https://xen-orchestra.com/blog/devblog-6-backup-ram/ Last updated: 2020-03-30T10:33:15.000Z The next release of XO (5.45) will bring to XCP-ng 8.1 a big new feature: **RAM enabled backups and replication**. ![REB](https://xen-orchestra.com/blog/content/images/2020/03/REB.png) # What we've done We modified XAPI to enable VMs to be created in a `Suspended` state with a `suspend_VDI` property set. When a VM is suspended, all of its memory contents are written into a disk called `suspend_VDI`. When the VM is restored, the `suspend_VDI` is read to recreate the memory of the VM. Once the resuming is done it's as if the VM was never suspended. # Usecases ## Backup with RAM It is already possible to snapshot a VM with its RAM, however when restoring a VM, the VM was created in the `Halted` state so it wasn't possible to restore the VM with its RAM. With our XAPI modification a VM can now be created in a `Suspended` state with preset memory contents, so when snapshotting a VM with RAM, the snapshotted VM will also have the RAM contents set. This can be very useful when you're running a VM that needs RAM coherence to run: - For instance, snapshotting a Windows VM used to be very tricky for this reason. The Citrix VSS script previously answered part of this problem, when snapshotted, the VM flushed its cache but if it happened that the snapshot had coherence issues, the restored VM would be broken. And the VSS script is no longer available. - VMs running databases could also need such a feature in order to keep transient transactions. - A VM can be restored on a different host, now the RAM can be as well. In a nutshell this functionality can be seen as *hot copy*, similar to *hot migration* but the original VM is not deleted. ## Continuous replication with RAM This feature allows you to regularly send a copy of a VM to a target SR. The copied VM will be `Suspended` and ready to be resumed if the original VM encounters issues. As the copied VM is `Suspended`, no reboot will be required, resuming it is much faster. For instance, if an hourly continuous replication is configured on a VM, if the VM is lost, you can quickly resume a running VM with a memory loss of one hour tops. > **Warning:** In order to use this functionality, the CPU of the host the VM is restored on should be the same or more recent than the CPU of the host the VM was originally running on. # Access the feature This feature will be available in beta on XO 5.45 with XCP-ng 8.1. > On XCP-ng 8.0, run `yum update xapi-core xapi-xe xapi-tests --enablerepo=xcp-ng-testing` to have the package with the feature available. # Possible enhancements - The CPU warning above can be addressed in future versions, only allowing the replication in the first place if the CPUs between source and destination hosts are compatible. ### How we're handling the COVID-19 Crisis at Vates URL: https://xen-orchestra.com/blog/how-we-handle-covid-19/ Last updated: 2020-03-20T15:09:23.000Z > Are you currently in the healthcare sector, actively fighting the COVID-19 virus as a hospital or research center? > We are ready to provide free advice and support for your infrastructure. Contact us at [contact@vates.fr](mailto:contact@vates.fr). As you all know, a lot of countries in the world are living in difficult times due to the pandemic of COVID-19. In this difficult period, the first thing we want to do is tell all our users, customers, partners and everyone we are in contact with one thing: **we send our wishes to you and your loved ones: Stay safe!** Since we are in France, we are now in confinement, which means that our office is empty and that all our collaborators are now working from their homes. But no worries, **our support system is still up and running and we are still delivering all the services you might expect from our company!** As the situation is rather exceptional, we wanted to share with you a bit of how we are working right now to ensure the continuity of our business and maybe provide some tips to all of you out there, looking for solutions for your own company. At Vates, as the bunch of nerds we were before the crisis occured, we already had a lot of tools deployed in order to allow our collaborators to work remotely, so it was not a large effort to provide comfortable solutions for our team. Some of our developers were already 100% remote and we even have someone located in the United States: Jon (@fohdeesha). As you know, all our code is on [Github](https://github.com/vatesfr/xen-orchestra?ref=xen-orchestra.com), consequently, our developers are still pushing, reviewing and merging bug fixes and new features in Xen Orchestra on a daily basis. For asynchronous communication, we are using [Mattermost](https://mattermost.com/?ref=xen-orchestra.com), a very useful solution to chat with people and share information (and some jokes) together. ![mattermost-1](https://xen-orchestra.com/blog/content/images/2020/03/mattermost-1.jpg) For direct communication, we are using a SaaS solution for an online meeting room: [Whereby](https://whereby.com/?ref=xen-orchestra.com). Thanks to this, we can still exchange information live with people within the company or outside the company when it's required. It's also helpful in order to keep some sort of human relations. ![wholeteam-2](https://xen-orchestra.com/blog/content/images/2020/03/wholeteam-2.jpg) Meet our team! To conclude, here are some of our work-from-home setups, which one is your favorite? @Olivier' setup ![olivier-1](https://xen-orchestra.com/blog/content/images/2020/03/olivier-1.jpg) @NRaynaud' setup: ![nraynaud-1](https://xen-orchestra.com/blog/content/images/2020/03/nraynaud-1.jpg) @Marc' setup (mine): ![marc-1](https://xen-orchestra.com/blog/content/images/2020/03/marc-1.jpg) ### XO 5.44 URL: https://xen-orchestra.com/blog/xen-orchestra-5-44/ Last updated: 2020-02-28T14:14:44.000Z Xen Orchestra 5.44 is available and brings a major feature with it: the Audit Log. > Remember, if you want to have all the latest features available in Xen Orchestra you need to select the `latest` release branch in the Xen Orchestra Appliance. ## XO Audit log The Xen Orchestra audit log is a powerful tool for administrators to use. The main purpose of the audit log is to provide an overview of actions that have been performed in your infrastructure, by any user. Badr, the project's developer, wrote a [detailed devblog](https://xen-orchestra.com/blog/xo-audit/) on the topic where you can learn more about the new tool and how it works. ## Xen Orchestra Proxies - beta progress ![](https://xen-orchestra.com/content/images/2019/04/xo-5c-20proxy_38106051.png) We are making progress on the proxies implementation and we added new features as well as some bug fixes in this release. ### Deploy proxies with network configuration Some users faced an issue regarding the network configuration when deploying proxies, resulting in an error preventing the deployment. It is now possible to define a network configuration before the deployment. ![](https://user-images.githubusercontent.com/21563339/74914752-43d54580-53c3-11ea-8daa-85122fff3a03.png) ### Delta backup and continuous replication It's now possible to schedule Delta backup and continuous replication jobs running on a proxy. ![](https://xen-orchestra.com/content/images/2015/12/delta_final.png) ### Restore from proxies You now have the ability to restore a backup directly from a proxy on a distant host. ### What's next Once we are satisfied with the behavior of the proxies in beta, we will progress towards the implementation of the proxies backup logs, one of the last steps before the definitive release. ## Copy BIOS string from host to VM You have now the ability to copy the BIOS string from the host to the VM, in cases where you are using licensed software bound to this. ![](https://user-images.githubusercontent.com/7724491/74956890-114d3c00-5407-11ea-9bbf-a2b145df38c1.png) ## UI improvements ### Clickable SR graph ![](https://user-images.githubusercontent.com/7724491/75333231-0e7a9d00-5886-11ea-97d6-726f4923aa37.png) We improved the way information is displayed on the SR graph. Now, you will be able to click on the graph to see detailed information about the VDIs and the snapshots on the SR. ### Max vCPU configuration You can define the maximum vCPUs a VM will have the ability to use at the creation, in the advanced settings. ![](https://user-images.githubusercontent.com/21563339/71978327-5896b900-321b-11ea-9ea4-cd05f435c4ad.png) ### Missing patches display in the home view You will now be informed directly from the Home view if you have missing patches. An up-to-date host is less prone to errors, more stable, and more secure. Therefore, we made it more obvious when you have missing patches. ![](https://user-images.githubusercontent.com/7724491/69799566-c9d25d80-11d3-11ea-942e-11f150ee5d80.png) ### DevBlog #5 - Xen-Orchestra Audit Log URL: https://xen-orchestra.com/blog/xo-audit/ Last updated: 2020-12-07T10:59:34.000Z XO Audit Log is a tool that records all important actions performed by users and provides the administrator an overview of these logs to help them investigate in case of suspicious or problematic activities. > Please note that this is the very first version of the Audit Log and that it will be improved in the upcoming months, so feel free to send us your feedbacks :-) # Why use Audit Log? 1. It prevents dangerous manipulations by giving admins visibility into users behavior inside their infrastructure 2. It identifies which user accessed Xen Orchestra at a given time and what actions they have performed 3. It allows admins to know how many times a user has used the VM/Host console # Trustability of the records As we've said before, Audit Log is a tool which can help detect and analyze the activity of malevolent actors, but it is obviously not helpful at all if it's been compromised and its logs have been altered to hide the tracks of the nefarious activity. That's why we have taken steps to make sure that logs can not be changed or deleted without detection. To achieve this goal, records are chained using a [**hash chain structure**](https://en.wikipedia.org/wiki/Hash%5Fchain?ref=xen-orchestra.com), which means that each record is linked to its parent in a cryptographically secure way. This is done recursively so that the latest record can ensure the integrity of the journal as a whole: ![schema-audit-log-1](https://xen-orchestra.com/blog/content/images/2020/02/schema-audit-log-1.png) If a record has either been deleted or altered, the Audit Log will be able to detect it and tell you which one: ![schema-audit-log-2](https://xen-orchestra.com/blog/content/images/2020/02/schema-audit-log-2.png) # Usage To access the Audit Log, simply click on `Settings/Audit`: ![menu](https://xen-orchestra.com/blog/content/images/2020/02/menu.png) There, a table of chronological records is displayed, they show all actions that have been performed by XO users: ![menu-1](https://xen-orchestra.com/blog/content/images/2020/02/menu-1.png) By clicking the eye button to the right of a record, you can display the complete raw data associated with it. ## Generate a new fingerprint To ensure the integrity of the journal, it is first necessary to generate a fingerprint of the existing records. This fingerprint will then be usable in the future to ensure that the related records have not been deleted and or altered. > Note: this is a manual process for the first version of Audit Log, but in the future fingerprints will be generated automatically and sent to a secure server (they do not contain any confidential data). Generating a new fingerprint is usually done after checking the integrity of past records using a previous fingerprint, that's why to do it you need to click on the **Check integrity** button. The first time you do this, simply leave the *Fingerprint* field empty, click **OK** and then click on **Generate a new fingerprint**. You will then be presented with a new fingerprint that you will be be able to use in the future: ![modal4](https://xen-orchestra.com/blog/content/images/2020/02/modal4.png) ## Check the integrity To check the record integrity simply click on the button **Check integrity**, and enter a previously generated fingerprint in the *Fingerprint field*: ![modal1](https://xen-orchestra.com/blog/content/images/2020/02/modal1.png) When clicking `OK` you will be informed of the health of your record. Successful integrity check: ![modal2](https://xen-orchestra.com/blog/content/images/2020/02/modal2.png) Failure integrity check: ![modale3](https://xen-orchestra.com/blog/content/images/2020/02/modale3.png) ### Xen Orchestra 5.43 URL: https://xen-orchestra.com/blog/xen-orchestra-5-43/ Last updated: 2020-01-31T15:48:00.000Z ## Compatibility with CH 8.1 Citrix Hypervisor 8.1 has been [available for a few weeks](https://xen-orchestra.com/blog/citrix-hypervisor-8-1-is-available/) and Xen Orchestra is now fully compatible with it. > ⚠: For Windows VMs, Citrix has removed the *quiesce snapshot* feature which was required in order to avoid corruption when doing backup of Windows DBs or Active Directory. We have [troubleshooted](https://github.com/vatesfr/xen-orchestra/pull/4736?ref=xen-orchestra.com) this issue by creating a fallback to standard snapshots when we catch the error. ### XCP-ng 8.1 In the meantime we are working to release XCP-ng 8.1\. A [beta version](https://xcp-ng.org/blog/2020/01/28/xcp-ng-8-1-beta/?ref=xen-orchestra.com) of it is already available for testing. [![xcp81-1](https://xen-orchestra.com/blog/content/images/2020/01/xcp81-1.png)](https://xcp-ng.org/blog/2020/01/28/xcp-ng-8-1-beta/?ref=xen-orchestra.com) ## XO Proxy public beta ![](https://xen-orchestra.com/content/images/2019/04/xo-5c-20proxy_38106051.png) We are still progressing with Xen Orchestra proxies. We are now ready to open the solution to a public beta for everyone to test. For now you will have the ability to deploy a proxy and make tests only with **Full Backup job** and **Disaster Recovery**. If you are part of the testers, your feedback is really valuable and welcome in this dedicated [forum thread](https://xcp-ng.org/forum/topic/2379/xen-orchestra-proxies-test-feedback?%5F=1580114183653&ref=xen-orchestra.com)! > To try the Xen Orchestra proxies, you need to be on the `latest` release branch. ## Full backup health check To more efficiently detect corrupted backup files, we have added a health check on Full Backup jobs. These new detection tools are working by checking if the XVA file created during the backup job is a valid file. We are not checking the content of the file itself, only the architecture of the file. > Note: This health check is only possible on uncompressed backup files and full backup jobs. ## Smart backup with tags not existing yet When creating a smart backup job, you have now the ability to create a rule which uses a tag not yet created/used in your infrastructure. ![](https://user-images.githubusercontent.com/7724491/68380548-5bf4c200-0150-11ea-9de4-d37b78dfef91.png) ![](https://user-images.githubusercontent.com/7724491/68380666-94949b80-0150-11ea-9425-947733defc81.png) ## Tag selector When you want to use a tag, you can now see the list of all existing tags and select among them. ![](https://user-images.githubusercontent.com/7724491/65158193-3c83c780-da32-11e9-8fdf-5ae6ce388e17.png) ![](https://user-images.githubusercontent.com/7724491/65158194-3c83c780-da32-11e9-9037-9b183d05fe18.png) ## Items displayed per page We have improved the way objects are displayed in your XOA interface by adding an option to select the number of items you want to display on each page. ![](https://user-images.githubusercontent.com/7724491/71002926-85eebc00-20e0-11ea-9ed4-ba6200c6f012.png) ### Citrix Hypervisor 8.1 is available URL: https://xen-orchestra.com/blog/citrix-hypervisor-8-1-is-available/ Last updated: 2022-06-01T14:42:52.000Z ⚠️ Citrix Hypervisor 8.1 is now End of Life (EOL). You can however [download XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com) instead, providing a 100% compatibility with all features for free. Citrix Hypervisor 8.1 has been available for a few weeks, and **Xen Orchestra is fully compatible with it**. If you are a CH user, you can proceed to upgrade to this latest version of the hypervisor and still enjoy all the features available in XOA. # What's new The official and complete changelog is available [here](https://docs.citrix.com/en-us/citrix-hypervisor/whats-new.html?ref=xen-orchestra.com). As usual, here is a recap of the biggest features of this version. ## Guest UEFI Boot and Secure Boot In CH 8.0, UEFI boot for Windows VMs was an experimental feature. It's now fully integrated in CH 8.1. In addition, for any OS that can support it, Secure Boot is also an available option. Secure Boot is designed to prevent unsigned, incorrectly signed or modified binaries from being executed during boot. > The official changelog only states Windows VMs for Secure Boot, but it's suppose to be supported in [Ubuntu](https://wiki.ubuntu.com/UEFI/SecureBoot?ref=xen-orchestra.com) as well. We didn't test this however. ## Improved performance for VM imports and exports There is a new checksum algorithm in Citrix Hypervisor 8.1 allowing faster imports and exports of VMs using XVA format. The increase in performance depends on the hardware you use. The larger the VM the larger the performance improvement seen. ## Storage performance improvements CH 8.1 includes performance enhancements for the following situations: - when I/O is performed in block sizes larger than 64 KiB on an NFS SR - Multipage support is now available in non-GFS2 SRs for better storage performance ## AMD Epyc Support The following CPUs are now supported in CH 8.1 - AMD EPYC 7xx2(P) ## VSS support removed > This information is NOT in the official changelog. The support for VSS has been removed from CH 8.1. VSS support was not a perfectly working feature as it had a lot of issues when you were not using Windows' VMs installed with the English Language. > This is particularly annoying regarding backup of Active directory or Windows' DB backup. We are currently working on an innovative solution to overcome this limitation. Stay tuned! # XCP-ng 8.1 Status ![xcp-81](https://xen-orchestra.com/blog/content/images/2020/01/xcp-81.png) We have been working on XCP-ng 8.1 since the release of Citrix Hypervisor 8.1\. A beta version should be available very soon - if you don't want to miss any news, don't forget to follow us on [Twitter](https://twitter.com/xcpng?ref=xen-orchestra.com) and to stay tuned on our [XCP-ng Blog](https://xcp-ng.org/blog/?ref=xen-orchestra.com)! ### Xen Orchestra 5.42 URL: https://xen-orchestra.com/blog/xen-orchestra-5-42/ Last updated: 2019-12-20T14:39:14.000Z First of all! We took a bit of time to reflect on [the features that made 2019](https://xen-orchestra.com/blog/2019-for-xen-orchestra/) for Xen Orchestra. Thank you all for your trust in 2019, Xen Orchestra 5.42 is the last release of the year. Enjoy this holiday period, and we will see you soon for an exciting new year. ![happy-holidays](https://xen-orchestra.com/blog/content/images/2019/12/happy-holidays.png) ## Xen Orchestra proxy - public alpha A very early version of Xen Orchestra proxy is available in public alpha test. ### How to To access the public alpha of the XO proxies, you will first need to change the release channel you are using in Xen Orchestra and select `proxy-alpha` Once the update is done, you should see a new option in the menu named `proxies` ![menu](https://xen-orchestra.com/blog/content/images/2019/12/menu.png) First step, is to deploy a proxy in a SR of your choice. ![](https://user-images.githubusercontent.com/21563339/71191191-3a761280-2286-11ea-9ba4-c8db6d69d0d0.png) Then you need to create a remote associated with that proxy. ![](https://user-images.githubusercontent.com/21563339/71191082-08fd4700-2286-11ea-8f04-fcb2372af76e.png) ![](https://user-images.githubusercontent.com/21563339/71190998-dfdcb680-2285-11ea-87f8-0460d7398d0f.png) Finally, you can create a backup job, running on this proxy. ![](https://user-images.githubusercontent.com/21563339/71190794-84aac400-2285-11ea-9d24-7e7db33587cd.png) > ⚠ For now, the only backup job type that will work with proxies is the **Disaster Recovery**. Any other type of backup will fail! ### Feedback process If you are among the testers, all the feedback you might want to provide can be provided on this [forum thread](https://xcp-ng.org/forum/topic/2379/xen-orchestra-proxies-public-alpha-feedback?ref=xen-orchestra.com) ## SDN controller - bonds and VLAN support We improved the capability of the SDN controller plugin in Xen Orchestra. The plugin is now able to use bonds and VLAN PIFs in addition to physical PIFs in order to create private network. ![mtu.png](https://xen-orchestra.com/blog/content/images/2019/12/mtu.png.jpg) ## Recipes - Kubernetes cluster [Kubernetes](https://kubernetes.io/?ref=xen-orchestra.com) is an open-source system allowing users to run, manage and scale containerized apps. ![](https://xen-orchestra.com/content/images/2019/12/kubernetes-logo.png) It's a very common use case to run Kubernetes clusters inside VMs. This is why we added the ability in Xen Orchestra to automate the creation of Kubernetes nodes! [Benjamin](https://xen-orchestra.com/blog/author/benjamin/) wrote a [detailed devblog](https://xen-orchestra.com/blog/devblog-5-kubernetes-clutser-on-xo/) about this new feature. ![](https://xen-orchestra.com/content/images/2019/12/kub-form.png) ## FOSDEM 2020 Our team will attend the FOSDEM event in Brussels the first weekend of February (1st & 2nd). You will have the opportunity to meet us at our booth, which we will be sharing with the fellas from the [Xen Project](https://xenproject.org/?ref=xen-orchestra.com). Stay tuned, we have some big things to announce at this occasion. ![logo_FOSDEM-1-1](https://xen-orchestra.com/blog/content/images/2019/12/logo_FOSDEM-1-1.png) ### XOA Year 2019 URL: https://xen-orchestra.com/blog/2019-for-xen-orchestra/ Last updated: 2023-12-08T10:03:51.000Z ![Loading...](https://create.piktochart.com/loading.gif) Loading... ### DevBlog #5 - Kubernetes cluster on XO URL: https://xen-orchestra.com/blog/devblog-5-kubernetes-clutser-on-xo/ Last updated: 2025-06-20T12:57:01.000Z [Kubernetes](https://kubernetes.io/?ref=xen-orchestra.com) is an open-source system allowing its users to run, manage and scale containerized apps. This great tool is about to be automatically deployable in XO! ![kubernetes-logo](https://xen-orchestra.com/blog/content/images/2019/12/kubernetes-logo.png) # XO recipes A new feature is coming to the hub: XO recipes! Based on the hub's template feature and cloudinit, XO recipes will allow a user to deploy several VMs at once in order to create turnkey deployments very easily. # Kubernetes cluster recipe The first recipe available in the hub will be a [kubernetes cluster](https://kubernetes.io/docs/reference/glossary/?all=true&ref=xen-orchestra.com#term-cluster). It will be possible from XO to deploy in a few clicks: - a kubernetes master - a configurable number of kubernetes nodes working for the master The cluster will be ready to be used at the end of the deployment. ![kubernetes-cluster](https://xen-orchestra.com/blog/content/images/2019/11/kubernetes-cluster.png) *Here's a Kubernetes cluster with 1 master and 3 nodes* ## How it looks in XO This is a work in progress so the UI might change a bit between the following screenshots and the released feature. 1 - Where to find the recipe? > The hub page now has a recipes tab ![recipes-view](https://xen-orchestra.com/blog/content/images/2019/12/recipes-view.png) 2 - How to execute a recipe? > Each recipe has a specific form to fill to customize the execution ![kub-form](https://xen-orchestra.com/blog/content/images/2019/12/kub-form.png) *Here's the form to fill for the kubernetes cluster* 3 - How do you know the recipe is finished? > A toast message will appear in the top right corner of XO allowing you to view the created VMs ![recipe-finished](https://xen-orchestra.com/blog/content/images/2019/12/recipe-finished.png) Keep in mind that a recipe can take some time to be executed successfully as some VMs need other VMs to boot to completion. 4 - How to manage the VMs of a recipe? > The VMs of a recipe have a common tag `xo:recipe::` allowing you to group them ![created-vms](https://xen-orchestra.com/blog/content/images/2019/12/created-vms.png) # Coming soon ## Enhanced Kubernetes cluster recipe - Possibility to create a cluster with more than 1 master ## More recipes to come - PHP/Apache/MySQL - pfSense ### Xen Orchestra 5.41 URL: https://xen-orchestra.com/blog/xen-orchestra-5-41/ Last updated: 2019-11-29T16:12:35.000Z ## Innovation contest - I-nov We already announced in a [XCP-ng blogpost](https://xcp-ng.org/blog/2019/11/19/xcp-ng-innovation/?ref=xen-orchestra.com) that our Open Source virtualization platform, XCP-ng will benefits from an investment of about **1.3M USD** during then next three years that will be dedicated to innovation. ![](https://xcp-ng.org/content/images/2019/11/i-Nov_baseline_reference.png) While this investment won't directly benefits to Xen Orchestra itself, the work we will achieve in XCP-ng platform to improve security and performances might open interesting tracks for Xen Orchestra to explore as well as better performances in XCP-ng means better performances in Xen Orchestra. This is a good news for XOA too. ## New XOA We have released an updated version of **Xen Orchestra virtual Appliance** (XOA) running on the most recent version of Debian: Debian 10. ![debianlogo](https://xen-orchestra.com/blog/content/images/2019/11/debianlogo.png) In this version of Xen Orchestra, we have also embeds new components, such a Netdata - related to the new features we are delivering: [Advanced Live Telemetry](https://xen-orchestra.com/blog/xen-orchestra-advanced-telemetry/) ![ipmistats_small](https://xen-orchestra.com/blog/content/images/2019/11/ipmistats_small.png) This version of Xen Orchestra will benefits from all the security and performances improvements that have been done in the past year inside Debian 10. ## Advanced live telemetry > This feature is exclusive to XCP-ng 8.0 hypervisor users. For those who are familiar with Netdata, you already know how powerful this tool is when it comes to gather a lot of information regarding hosts. Our new XOA embeds Netdata and it's now a matter of a single click to deploy a secured Netdata interface directly from your appliance. ![](https://xen-orchestra.com/content/images/2019/11/advancedenable.png) We wrote a [detailed blogpost](https://xen-orchestra.com/blog/xen-orchestra-advanced-telemetry/) about this new feature and the design choices we made in order for you to deploy it without compromising the security of your infrastructure. ## Webhooks You have now the ability to use **webhooks** in Xen Orchestra. To do so, you need to configure in XOA *method* and *type* and the webhook will perform an `HTTP POST` request, with a body containing `JSON` with some values ![](https://xen-orchestra.com/content/images/2019/11/webhooksXO.jpg) There are many different application for this features and Olivier wrote a [complete blogpost](https://xen-orchestra.com/blog/webhooks-in-xen-orchestra/) dedicated to it with explanation and example of things you can do with this powerful tool. ## Configurable backup report email We improved our backup report email plugin. You have now the ability to configure **who** will receive the backup report depending on the situation and to **add multiple recipient** for the backup report. ![](https://user-images.githubusercontent.com/21563339/68465417-bf472880-0212-11ea-9a71-3f93d337b984.png) Join the discussion about this release on our [community forum](https://xcp-ng.org/forum/category/11/news?ref=xen-orchestra.com) ### XO Advanced Live Telemetry URL: https://xen-orchestra.com/blog/xen-orchestra-advanced-telemetry/ Last updated: 2019-11-29T16:30:49.000Z When you are working on your virtualized infrastructure, you might need a very detailed view on what's going on. From resource consumption analysis (CPU/RAM) to network traffic, but also storage, having a kind of **very** detailed dashboard per host can be really useful. > Note: this feature will be only available in XCP-ng+XOA. If you are a hardcore Citrix Hypervisor user, let us know if you want this. ## Today For now, Xen Orchestra is exposing host stats from XAPI (Citrix Hypervisor or XCP-ng API). Those stats are good, but very generic and only every 5 seconds for the last 10 minutes: ![currentXOstats](https://xen-orchestra.com/blog/content/images/2019/11/currentXOstats.png) In some case, you may want to go deeper on various metrics, like: - resource usage by program - number of sockets opened - CPU interrupts by device/call - connection tracker, ie number of opened connections (firewall) - packets errors - IPMI info (temperatures, voltages, fans…) And **with a very thin tick (second) for the last hour**. Obviously, XAPI RRDs aren't fit for this. So enters "Advanced Live Telemetry". ## Advanced Live Telemetry: design Having those advanced metrics with this kind of specifications is not easy. We want: - a nice dedicated web UI - with a lot of live metrics (I mean, **A LOT**) - not exposing a web UI on each host - having only one entry point for all the hosts you monitor - no hassle to configure this Ideally, the solution should work on a *push* model. It means data is sent from the host to a "central" place. This way, adding host is easy without adding any extra configuration (eg: unlike Centreon or Nagios). Also, streaming the data on a central place avoid to open any port on the host itself: this means no extra attack surface despite the new feature. That's why we chose the following bricks: - Our new XOA (Xen Orchestra virtual Appliance) embeds **Netdata** - It's only accessible within Xen Orchestra itself, acting as a reverse proxy. A non-authenticated XO user won't be able to access it! Your advanced live telemetry is **protected by design** - Hosts **will only stream metrics** toward XOA, which will act as a central Netdata host. No firewall port opened on the host And all of this, with only a few steps, in fact, just clicking on that button in your host view: ![advancedenable](https://xen-orchestra.com/blog/content/images/2019/11/advancedenable.png) By clicking here, XOA will handle everything: installing netdata on the host, and configure a secured/encrypted streaming toward your XOA. ## A great tool This will be really helpful, for you but also for our own XOA and XCP-ng Pro Support: it means, in case of remote access, that we could access the live metrics of your XOA and your hosts, to be able to see what's going on in details. This will participate to an even better resolution time of potential problems. This is also a way to find bottlenecks in various cases! ## Screenshots As soon it's installed, the button will now be replaced by a "Go to Advanced Live Telemetry". As soon you'll click on it, you'll be redirected to the netdata page of the host. If you have multiple host, you can access any of them directly from the top menu of the netdata UI. IMPI info (power, temperatures, voltages, fans…): ![ipmistats](https://xen-orchestra.com/blog/content/images/2019/11/ipmistats.png) XCP-ng management network stats: ![xenbrstats](https://xen-orchestra.com/blog/content/images/2019/11/xenbrstats.png) Firewall stats: ![firewallstats](https://xen-orchestra.com/blog/content/images/2019/11/firewallstats.png) Memory stats: ![memorystats](https://xen-orchestra.com/blog/content/images/2019/11/memorystats.png) ### DevBlog #4 - Xen Orchestra 6 URL: https://xen-orchestra.com/blog/devblog-3-working-on-xo-6/ Last updated: 2025-07-28T08:36:09.000Z We are currently working on a new major version of our Xen Orchestra interface which is planned to be released during the year 2020\. We will completely revamp our web interface as well as a lot of components as listed below. ## Why we are working on Xen Orchestra 6 We developed the first version of Xen Orchestra in 2015\. In the beginning, Xen Orchestra was designed to manage small infrastructure (from 2 to 10 hosts) and many design choices we made at the time were dictated by the needs of users with this kind of infrastructure (including ourselves). Then our customer base grew up and the userbase of Xen Orchestra became more diverse, so needs for new options and features became evident. With our monthly release, we are answering some of those needs, but not all of them. ![](https://d2.alternativeto.net/dist/s/xen-orchestra_787640_full.png?format=jpg&width=1600&height=1600&mode=min&upscale=false) *This is what XOA looked like back in 2015* Because of some technologies currently used in Xen Orchestra, our development team is facing technical challenges to implement some of the new features you requested. Some of these challenges cannot be cleanly overcome with the current version of Xen Orchestra 5, like an object tree view and a better way to apply bulk actions. In the end of 2018, we decided it was time to think about a new major version of XO: **Xen Orchestra 6**. Our goal is not only to revamp the design of our appliance, it's also to make big "under the hood" upgrades in order to unlock new possibilities for our team to implement new features, as well as improve some existing ones. Since we decided to work on this new version of XOA, we also gathered a lot of community feedback (and still are) by asking you [what you were expecting from our tool](https://xcp-ng.org/forum/topic/962/why-are-you-using-xcp-ng-center/116?ref=xen-orchestra.com), and what you would like it to look like. We discussed the community's expectations, the dev team's expectations, and the new "market standard", then started working on the project. ![xo5-dashboard](https://xen-orchestra.com/blog/content/images/2019/11/xo5-dashboard.png) *This is what Xen Orchestra currently looks like* ## Xen Orchestra 6 > Note: We are still very early in the development process of this new Xen Orchestra version. A lot of things can still change before we release it. ![mockup-xo6.png](https://xen-orchestra.com/blog/content/images/2019/11/mockup-xo6.png.jpg) *XO6 - design mockup* In this mockup, you can see the "big" changes we want to implement in the next version of Xen Orchestra. - A treeview for the presentation of your infrastructure - this is something that has been requested for a long time by the community and this is going to be added in XO6 - Pre-existing filters to choose what you want to display (Pools, VMs...) - A revamped search function allowing you to perform then save searches Using this mockup as a start, we began to work on the UI itself. It's still early progress, but here is a WiP of the new UI: ![new_xo-web-6_screenshot.png](https://xen-orchestra.com/blog/content/images/2019/11/new_xo-web-6_screenshot.png.jpg) ## How we will implement these changes ### The technology under the hood #### TypeScript We decided to choose typescript as the main language of the project, because it's easier to read and can help us to avoid painful bugs that developers commonly run into when writing JavaScript by type checking the code. On the other hand, given that typescript is a superset of javascript, our devs will adapt rapidly to it. #### ReactJS Given that Xen Orchestra 5 was written in ReactJS which is a technology that we've mastered and liked, we decided to use the latest release of ReactJS in order to reuse our already developed components. #### Reaclette Managing the state of components is mandatory in complex applications, that's why we developed our personal library for managing the state called [reaclette](https://github.com/JsCommunity/reaclette?ref=xen-orchestra.com). #### Emotion Emotion is a library designed for writing css styles with JavaScript. It provides powerful and predictable style composition in addition to a great developer experience with features such as source maps, labels, and testing utilities. The issues and challenges we have to solve: - Code lazy loading: only load necessary pages - Data lazy loading: only load displayed data ### Webhooks in Xen Orchestra URL: https://xen-orchestra.com/blog/webhooks-in-xen-orchestra/ Last updated: 2019-11-18T14:06:50.000Z A new feature is coming for our next release: webhooks. What's the big deal with them? Well it's huge infact, and we'll see why. ## What's a webhook? The shortest definition you can find is: > Webhooks are user-defined HTTP callbacks In other words when there is an event, it will "notify" a target URL of your choice. Let's take a simple example: you want to be notified in a chat application (eg inside a Slack channel) when a VM is created. Possibilities are endless, as you will see in this blog post. ## In Xen Orchestra A webhook is very simple: it will perform an HTTP POST request, with a body containing JSON with some values. You can set it up in the UI: ![webhooksXO](https://xen-orchestra.com/blog/content/images/2019/11/webhooksXO.jpg) > In this example, we'll send a webhook to `https://my-domain.net?action=vm.start` just **before** ("pre") executing `vm.start` (starting a VM). ## Examples Here are a few examples, obviously your imagination is the limiting factor here. ### Continuous Integration/delivery Now you can ping your CI/CD platform when VMs are created. Notice that you can use the XO API in one way to create VMs and be notified when it's done thanks to our webhooks. We are now **closing the loop** to offer you a complete solution that can be fully integrated. ### Automation These webhooks are also a great way to have more automation in your infrastructure. For example: - a custom application managing your HA database could be notified in case of VM migration, and change a master/slave configuration accordingly - load balancing applications can be aware of VM operations (eg HA proxy) - trigger an action on your infrastructure in case of the emergency shutdown feature of XO (eg calling the UPS) - change a firewall or network rule automatically (migration/creation) - change a DHCP rule from a VM MAC address on VM creation - billing: you can use a CRM/billing platform to know who created VMs in a self service environment and make the right decision/invoicing automatically - store the UUID of all VMs created in your infrastructure tracking/database ### Notifications/alerts Obviously, you can imagine notifications based on specific actions: - a chat application can be notified every time a VM is created in Xen Orchestra (or if a VM is shutdown) - you can page/alert (using PagerDuty or any external tool) if someone decides to shutdown a host, migrate a VM or perform any unexpected operations in XO - security alerts on user creation ## Pre or post webhooks A webhook can be called before the command is executed, or after it returned. Both can be useful: if you know that live migration will trigger consequences, a "pre" webhook can already perform necessary actions on your infrastructure. Post webhooks can be useful to trigger something after the call ends, and can forward the results. > Note: the migration action will start immediately after, so keep that in mind in case your custom action is longer than a potential live migration. ## Your webhook use cases? Feel free to share your potential use cases [in our forum!](https://xcp-ng.org/forum/topic/2230/webhooks-in-xen-orchestra?ref=xen-orchestra.com) ### Xen Orchestra 5.40 URL: https://xen-orchestra.com/blog/xen-orchestra-5-40/ Last updated: 2019-10-29T12:38:00.000Z This month's release is focused on feature improvements. We refactored the code for the SDN controller, introduced a new option in the backup system and added information in the Xen Orchestra hub. Also, we are currently at the [Linux Open Source Summit in Lyon](https://xen-orchestra.com/blog/linux-open-source-summit-europe/), if you are not at the event, you can still [follow us on Twitter](https://twitter.com/xcpng?ref=xen-orchestra.com) to get a glimpse! ## Xen Orchestra proxies ![](https://xen-orchestra.com/content/images/2019/04/xo-5c-20proxy_38106051.png) The tests are underway, we are adding new testers in the pool progressively. If you have registered on our [interest list](https://xen-orchestra.us13.list-manage.com/subscribe?u=f1ab72021fb8816f4d5e72773&id=3eba0dcca8&ref=xen-orchestra.com) but havn't been contacted yet, no worries, we currently have very few testers running. ## New support UI embeds in XOA Until now, we had two very interesting support tools that you could use only with command line. The `xoa check` and the `xoa support tunnel`. To improve the Quality of Life and accessibility, we have added a dedicated support section in the menu. ### XOA Check This option will check the global status of your appliance and check that primary services of your appliance will work as intented. ![xoacheck](https://xen-orchestra.com/blog/content/images/2019/10/xoacheck.png) ### Support tunnel Support tunnel is one of our strongest tool, it allows our developers to access your infrastructure remotely and in a fully secured way. You can now open (and close) a tunnel in a single click. ![](https://user-images.githubusercontent.com/10992860/67384755-10f47f80-f592-11e9-974d-bbdefd0bf353.gif) ## Backup Legacy menu removal About one year ago, we introduced our [new generation of backup tools](https://xen-orchestra.com/blog/migrate-backup-to-backup-ng/) in Xen Orchestra. We kept the legacy backup view in the Xen Orchestra menu for a long time and it's time to let it go! Consequently, we have removed the legacy backup view and renamed the `Backup NG` label as `Backup`. If you still have old backup jobs active, they will now be displayed in the Backup view, in a dedicated space before your regular backup jobs. If you have such jobs, you should really consider [migrating](https://xen-orchestra.com/blog/migrate-backup-to-backup-ng/) to the new version of backups. We are not maintaining the old backup code, nor supporting it anymore. ## Offline backup To create a backup, Xen Orchestra is creating a snapshot, and then this snapshot is exported as a backup file to a remote location of your choice. The point is to have a fixed state of the VM you want to backup in order to create a clean backup. However, creating a snapshot can sometimes be an issue, especially when you are in a **thick provisoned** environment where that snapshot takes up the same size as the allocated space of the VM. We have added a new option in backup jobs: **offline backup**, that does not require a snapshot to be made, but will shutdown the VM for the time of the export. ![](https://user-images.githubusercontent.com/21563339/66755032-7f04bc80-ee97-11e9-9143-73a993639ec0.png) > ⚠ - If you don't set a concurrency, all the VMs within a single job will be shutdown at the start of the job. ## Global Private Network refactored Our SDN controller has been introduced in [June](https://xen-orchestra.com/blog/xo-sdn-controller/) and since that time, we have worked on improving it and adding [new features](https://xen-orchestra.com/blog/devblog-3-extending-the-sdn-controller/) inside of it. This month, the code and the topology of our GPN in Xen Orchestra has been optimized and refactored. While it is mostly an advancement useful for our developer team in order to maintain the code in the future, refactorization also has an impact on performance, and contributes to solving some issues related to the use of *IPsec*. ![refactor-small-1](https://xen-orchestra.com/blog/content/images/2019/10/refactor-small-1.png) ## Xen Orchestra Hub - v2 ![](https://xen-orchestra.com/content/images/2019/08/XOhub-1.png) We are still working on the Xen Orchestra hub. This month, we worked on **Quality of Life** improvements. - We have improved the way information is displayed in the hub page - We have added **important information** about the template available - When updating a template in your infrastructure, we will automatically detect older versions of this template on your hosts and replace it with the newest version ## Icinga2 support for backup report ![Logo-icinga](https://xen-orchestra.com/blog/content/images/2019/10/Logo-icinga.png) Similar to Nagios transport plugin, you can now send your backup report directly to your Incinga2 instance. ![](https://user-images.githubusercontent.com/12529066/67288824-e6e18580-f4dd-11e9-9fe7-24afde8715d2.png) ### Xen Orchestra 5.39 URL: https://xen-orchestra.com/blog/xen-orchestra-5-39/ Last updated: 2019-09-30T14:41:50.000Z > As usual, all the new features are available on the `latest` release branch in your appliance. ## Xen Orchestra Hub - XVA store ![](https://xen-orchestra.com/content/images/2019/08/XOhub-1.png) Last month, we introduced this new feature our team is working on: the Xen Orchestra Hub. The very first version of the hub is now available in a beta version and you can find an XVA catalog with some popular VM templates to deploy in your own infrastructure. Share your feedback or request new templates in the dedicated forum thread. The most requested templates by the community will definitely be added in a future update. ## XO proxies alpha ![](https://xen-orchestra.com/content/images/2019/04/xo-5c-20proxy_38106051.png) A **very early** version of our XO proxies feature is available for (some) people to test. For now, we have only selected a few people that were registered on the *interest list* and deployed the first iteration of our proxy in their infrastructure. After the initial feedback period and probable fixes that will come with it, we will progressively add new people into the test. If you want to be part of the tests or simply stay tuned to the latest news regarding this feature, don't forget to subscribe to this [list](https://xen-orchestra.us13.list-manage.com/subscribe?u=f1ab72021fb8816f4d5e72773&id=3eba0dcca8&ref=xen-orchestra.com). Our first goal with the XO proxies is to create a more viable backup solution, especially when you want to perform backups at distant sites. More information is available on [this devblog](https://xen-orchestra.com/blog/backup-proxies/). ![](https://xen-orchestra.com/content/images/2019/04/withproxy-2.png) ## Direct connection to SSH button > ⚠ This feature might require you to properly configure your browser or OS in order for the console to be handled properly. We have added a button directly in Xen Orchestra, on the VM console view, to allow you to quickly access your favorite SSH terminal in a single click. ![](https://user-images.githubusercontent.com/46941/62692709-71cbdd00-b9d1-11e9-98cc-483fddd94bc1.png) ![](https://user-images.githubusercontent.com/10992860/65032311-2c40ef00-d943-11e9-95bb-043546839744.png) ## Network encryption > You need to use XCP-ng 8.0 (or higher versions) in order to use encryption. You now have the ability to encrypt your networks when you use the **SDN controller** thanks to **ipsec encryption**. ![](https://user-images.githubusercontent.com/12529066/65020793-25f44800-d92e-11e9-8441-02a88b2bf6bf.png) In order to be able to encrypt the networks, you need to install the `openvswitch-ipsec` package on all your hosts (only available for XCP-ng 8.0): ``` yum install openvswitch-ipsec --enablerepo=xcp-ng-testing systemctl enable ipsec systemctl enable openvswitch-ipsec systemctl start ipsec systemctl start openvswitch-ipsec ``` ## Web-ui performances improvement We have added a short term cache for the backup logs. This modification should greatly improve the performances while dealing with the backup logs, especially if you have a lot of clients viewing backup at the same time. This should also reduce the charge of your XOA VM. ## Open Source Summit - Lyon As we previously announced it, we will attend the Open Source Summit in Lyon from the **28th to 30th October**. You can meet us in our booth : **B3** ![Capture-d--cran-de-2019-09-27-14-13-01](https://xen-orchestra.com/blog/content/images/2019/09/Capture-d--cran-de-2019-09-27-14-13-01.png) More information about the event are available on the [official website](https://events.linuxfoundation.org/events/open-source-summit-europe-2019/?ref=xen-orchestra.com) [![xcpng_dc1-3](https://xen-orchestra.com/blog/content/images/2019/09/xcpng_dc1-3.jpg)](https://xcp-ng.com/?ref=xen-orchestra.com) ### Xen Orchestra 5.38 URL: https://xen-orchestra.com/blog/xen-orchestra-5-38/ Last updated: 2019-08-29T15:31:14.000Z It's back to school time and Xen Orchestra 5.38 is now available. As usual, our team mostly used this holiday month to focus on bugfixes, cleaning, and also on big features that will come in the next few months. As before, if you want to get the all the new stuff, you need to use the `latest` branch and not the `stable` one. ## Global Private Network ![gpn](https://xen-orchestra.com/blog/content/images/2019/08/gpn.png) Two months ago [we introduced the SDN controller](https://xen-orchestra.com/blog/xo-sdn-controller/) which is a plugin providing the ability to create private networks within a pool. This month, the SDN controller is evolving to introduce a new ability: **creating cross-pool private networks!** This is what we call **"Global Private Network"**. ![ovsdb-gretunnel-small](https://xen-orchestra.com/blog/content/images/2019/08/ovsdb-gretunnel-small.png) Our developer, [Benjamin](https://xen-orchestra.com/blog/author/benjamin/), wrote an extensive devblog about this awesome new feature that you can discover [here](https://xen-orchestra.com/blog/devblog-3-extending-the-sdn-controller/). Now in Xen Orchestra, you can select multiple pools when creating this private network, and **everything will be configured automatically** on all your hosts: ![](https://user-images.githubusercontent.com/12529066/62857139-1cf0d500-bcf7-11e9-9b6d-50c2e166f807.png) Use cases are infinite, but you can now build your infrastructure regardless of your physical networks, every VM in this network will be able to reach each other, privately! A quick example, with a web server and database (let's say Nginx+Postgresql): now they can be hosted in different places or live migrated from one site to another, they will maintain reachability in the same virtual network, without requiring public IP addressing for this dedicated backend. Your database will be safe because it's only listening on the private network side. ### Multiple private networks We also introduced unique network identifiers (VNI), allowing the creation of multiple private networks. Main use case: hosting XCP-ng and having private networks for each customer. Now you can do it! ### Encryption Very soon, these networks will be able to have IPSEC encryption, so you could use them confidently accross insecure networks (ie: between sites with Internet in the middle). This will be bundled with an XCP-ng update to support the latest and most secure encryption libraries. ## Other big features in the pipe The end of 2019 will be full of big surprises, with new products and features. Brace yourself for deeper integrations between [XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com) and Xen orchestra ;) ### XO Proxies The next big thing coming soon in Xen Orchestra are XO proxies. We've been teasing them for a while, but we are finally coming to the point where a beta release will be possible. If you are interested in these new products, don't forget to register to the beta testers list for our coming [XO Proxies](https://xen-orchestra.com/blog/backup-proxies/): the [registration form is available at this link](https://xen-orchestra.us13.list-manage.com/subscribe?u=f1ab72021fb8816f4d5e72773&id=3eba0dcca8&ref=xen-orchestra.com). ### Xen Orchestra Hub ![XOhub-1](https://xen-orchestra.com/blog/content/images/2019/08/XOhub-1.png) Our team is also working on a very exciting new feature, and we are seeing many possible applications in the future: the **Xen Orchestra Hub**. As a first step for this new feature, we will create an **XVA store**. A catalog of VM templates that have been created and carefully tested by our team. It will be a matter of two clicks to deploy the template you need to the pool you want. More information on this project coming soon! ## Open Source Summit Europe This **October 28 - 30, 2019** is one of the biggest European events regarding the Open Source world. ![](https://xcp-ng.org/content/images/2019/08/oss-event.png) We will be attending this event and will have a booth at which you will have the opportunity to meet us during the whole event! More information is available on this [page](https://xen-orchestra.com/blog/linux-open-source-summit-europe/) ## Hosted XCP-ng A quick intro to something people have asked us about for months now: the ability to use turnkey managed XCP-ng/XOA infrastructure (compute/network/storage), designed, installed and hosted by us, bundled with our support. Guess what? We are doing it now! A validated and pre-built XCP-ng platform hosted just for you, with our expert support. Check [https://xcp-ng.com/cloud](https://xcp-ng.com/cloud?ref=xen-orchestra.com) to know more! [![hostedxcpng](https://xen-orchestra.com/blog/content/images/2019/08/hostedxcpng.jpg)](https://xcp-ng.com.cloud/?ref=xen-orchestra.com) ### DevBlog #3 - Extending the SDN Controller URL: https://xen-orchestra.com/blog/devblog-3-extending-the-sdn-controller/ Last updated: 2019-12-06T10:37:41.000Z # The SDN Controller The SDN Controller is an XO plugin allowing the creation of private networks connecting all the `hosts` and `VMs` of a `pool`. It is described in [its dedicated DevBlog](https://xen-orchestra.com/blog/xo-sdn-controller/). To give a quick recap: the private network is based on a star topology connecting the `hosts` with `tunnels` (either `GRE` or `VxLAN` according to the user choice). The SDN Controller also monitors the `hosts` and `VMs` to maintain the network. # The new feature With this coming update, **the SDN Controller will allow the creation of cross-pool private networks**: this type of private network won't only be pool wide but will connect all the hosts of different pools together in an isolated network. ## The topology When designing this new feature, 2 topologies came to mind: - keep it star centered: A single host is elected as star center and has a tunnel to each host of the network's pools [![pool-1-small](https://xen-orchestra.com/blog/content/images/2019/08/pool-1-small.png)](https://xen-orchestra.com/blog/content/images/2019/08/pool-1.png) - add a level of abstraction, make a *star of stars*: Create a private network per pool, connect the star-center of the private networks together in a high-level star topology [![pool-connection-small-1](https://xen-orchestra.com/blog/content/images/2019/08/pool-connection-small-1.png)](https://xen-orchestra.com/blog/content/images/2019/08/pool-connection.png) In order not to have too much workload put on a single host, and to build upon the existing design (and because it is a beautiful image), the choice has been towards the *star of stars*. Also with this design, only the star-centers of the private networks are aware they are in a meta cross-pool private network. All the other hosts behave like they're in a pool-wide private network. The meta network is a star where each branch is another star of hosts. The star-center of each branch is connected to the star center of the network at the center of the higher level star: Here's 3 pools, each with a private network, connected together in a cross-pool pivate network, the pool center is `P2`. ![ovsdb-gretunnel-small](https://xen-orchestra.com/blog/content/images/2019/08/ovsdb-gretunnel-small.png) ## How it works Essentially, this is a lot like a pool-wide private network, the SDN Controller monitors all the `hosts` and `PIFs`. Here are 2 notable events that require changes in the cross-pool private network: - When a star-center goes down, the private network is recreated and a new star-center is elected, then the new star-center is connected to the star-center of the pool-center of the pool-wide private network. - When the star-center of the pool-center of the pool-wide private network goes down, a new pool-center is elected, all the star-centers are connected to the pool-center's star-center. ## Features - All the `hosts` (and their `VMs`) can reach one another in the private network (**even when in different pools!**). - Anything outside the private network can't reach it. - The network is **robust**, even to `hosts` and `VMs` rebooting, shutting down, being added or removed from the pool, `VMs` migrating in other pools in the network, etc. # What's next Next step is adding encryption. And guess what: our initial tests are promising! We'll probably have encrypted IPSEC tunnels relatively soon, allowing **all your traffic to flow even on insure networks**. ### Meet us at the Linux Open Source Summit Europe URL: https://xen-orchestra.com/blog/linux-open-source-summit-europe/ Last updated: 2019-10-23T08:18:36.000Z From October **28th to 30th, 2019** the **Linux Foundation Open Source Summit in Lyon** (Lyon Convention Center) will take place. Our booth number is **B3** ![](https://xcp-ng.org/content/images/2019/08/oss-event.png) For those who are not aware, OSS is one of the biggest European events in the Open Source world. It's a leading conference for developers, architects and many technologists and industry leaders from inside and outside the Open Source industry. This year, Vates is proud to be a sponsor of the event and you will have the opportunity to meet our team at our own booth and share with us during the event! ![Open-Source-Summit](https://xen-orchestra.com/blog/content/images/2019/08/Open-Source-Summit.png) More information about the event as well as the registration process is available on the [official event website](https://events.linuxfoundation.org/events/open-source-summit-europe-2019/?ref=xen-orchestra.com). We also created a dedicated thread on our [community forum](https://xcp-ng.org/forum/topic/1800/open-source-summit-lyon-oct-28-30?ref=xen-orchestra.com) to talk about the upcoming event on which you can also request a meeting with us. Of course, we will have some shiny goodies for all the people passing by! Speaking of, we have added a link to our Redbubble store on the website main menu for those interested in wearing some XCP-ng swag. ![Capture-d--cran-de-2019-10-23-10-05-47](https://xen-orchestra.com/blog/content/images/2019/10/Capture-d--cran-de-2019-10-23-10-05-47.png) ### Xen Orchestra 5.37 URL: https://xen-orchestra.com/blog/xen-orchestra-5-37/ Last updated: 2024-07-26T08:19:52.000Z > ⚠ All the new features introduced in this blogpost are available only if you are on the `latest` release branch. They will be available next month on the `stable` release branch. You can change your release branch in the XOA menu section of your appliance. In the heat of the summer, the eagle has landed. Xen Orchestra 5.37 is now available. However, it's also the release of the very anticipated XCP-ng 8.0, a major release for our hypervisor based on Xen! The detailed changelog is available [here](https://github.com/vatesfr/xen-orchestra/blob/master/CHANGELOG.md?ref=xen-orchestra.com#5370-2019-07-25). ## XCP-ng 8.0 If you are an XCP-ng user, you can now safely upgrade your infrastructure to XCP-ng 8.0 - the major release is finally available and everything you need to know about it is [here](https://xcp-ng.org/blog/2019/07/25/xcp-ng-8-0/?ref=xen-orchestra.com)! If you are not yet an XCP-ng user, what are you waiting for? [![](https://xcp-ng.org/content/images/2019/07/xcp-ng-80-1.png)](https://xcp-ng.org/blog/2019/07/25/xcp-ng-8-0/?ref=xen-orchestra.com) ## Pool Join Multihost In Xen Orchestra, you might sometimes want to create a pool and add multiple hosts into this newly created pool. Until now, you could only join one host at a time in a pool. Since XCP-ng and XenServer are now able to have **up to 64 hosts in a pool**, we figured out that providing the ability to join multiple hosts at the same time was a good idea. > Adding multiple hosts using this option will also install all the required patches on all of them in order for all hosts in the pool to be at the same level. ![](https://user-images.githubusercontent.com/7724491/55632856-6ebea700-57bb-11e9-9ae2-dbb95f30c719.png) ## New SR graph We decided to change the SR graph representation because the previous one was a bit difficult to understand and sometimes misleading, especially regarding `base copy` space consumption in XCP-ng and XenServer. The new graph is expected to be more comprehensive: ![](https://user-images.githubusercontent.com/7724491/61055659-51205f80-a3f2-11e9-8348-da4c9b0e887f.png) ![](https://user-images.githubusercontent.com/7724491/60677235-3ba2b700-9e81-11e9-9cb2-c243ab1355d1.png) ## ACLs - Operators can now revert snapshots The condition to be able to revert snapshots on a VM has been changed to be more coherent. To have this ability, the conditions are now: - operator of the VM - viewer of the snapshot This means that any VM operator is now able to revert to any snapshot available on the VM, including snapshots made by the admin. ## Ability to force manual backup Since the introduction of backup NG last year, Xen Orchestra comes with a health detection feature regarding VDI chains in XenServer/XCP-ng. Most of the time, this feature will stop the infrastructure from becoming unhealthy because backups are being done faster than the coalesce process in XenServer/XCP-ng. In rare occasions, a coalesce process itself might be stuck, which can lead to a situation in which a user is no longer able to properly backup their infrastructure. This is the reason why we introduced the ability to bypass the protection and force a backup to be done without regard for the state of the VDI chain. > ⚠ This features is only intended to allow a user to safely backup their infrastructure before attempting to fix a problem in their infrastructure. Otherwise, you should never ignore an unhealthy VDI chain alert. ![](https://user-images.githubusercontent.com/25125613/61359915-b1455480-a87d-11e9-89dc-f794985341a2.png) ## Copy/paste command Sometimes, using the console inside Xen Orchestra can be painful. Especially if you are following instructions in which you are supposed to send numerous commands that you don't know in your console. This is why we introduced the ability to copy/paste multiline commands and to send them directly into your console. ![](https://user-images.githubusercontent.com/7724491/61619273-cdc30180-ac6e-11e9-9b0d-3c886a6b5c4e.png) > *Yes, the cover of this article is our hommage to the 50th anniversary of the Apollo 11th landing on the moon (a bit late)! You know we love rockets.* ### Xen Orchestra 5.36 URL: https://xen-orchestra.com/blog/xen-orchestra-5-36/ Last updated: 2019-06-28T16:26:05.000Z > ⚠ All the new features introduced in this blogpost are available only if you are on the `latest` release branch. They will be available next month on the `stable` release branch. You can change your release branch in the XOA menu section of your appliance. This year's first summer release for Xen Orchestra is here and we have some fresh news to share with you! **ZFS** and **UEFI** support are is available in Xen Orchestra! Our new **DVSC plugin** is also in beta. Finally, we are proud to be gold sponsors for the next **[Xen Summit](https://xcp-ng.org/blog/2019/06/19/xen-developer-summit/?ref=xen-orchestra.com)** event in Chicago this summer (July 9th - 11, 2019). ## ZFS support > ⚠ *This feature is only available for XCP-ng users* > ZFS RPMs for ZFS on Linux (ZoL) 0.8.1 are now available in XCP-ng 8.0\. To install the latest version of ZFS you can simply run a `yum install zfs` in your XCP-ng installation. Since ZFS is now supported in XCP-ng, we added the ability to select a ZFS SR in Xen Orchestra. As there are many possibilities during the creation of a ZFS storage repository, you still need to use the command line (eg. `zpool create zdata /dev/sdb`) to create a ZFS pool before creating the corresponding SR. Check [this documentation](https://github.com/zfsonlinux/zfs/wiki/FAQ?ref=xen-orchestra.com#selecting-dev-names-when-creating-a-pool) for more information about ZFS SR creation. Once the ZFS pool is created and mounted, you will have the option to select the mountpoint during the SR creation directly in Xen Orchestra. ![](https://user-images.githubusercontent.com/25125613/58800555-760dff80-8608-11e9-92d1-75f4d0b09f39.png) > Note: our contribution to ZFS on Linux ([to fix a small bug](https://github.com/zfsonlinux/zfs/pull/8866?ref=xen-orchestra.com)) was **merged** and now available in 0.8.1! We are really happy to contribute to various Open Source project around XO and XCP-ng. ![zfs-linux](https://xen-orchestra.com/blog/content/images/2019/06/zfs-linux.png) ## Hyperthreading detection v2 Since Intel's latest major security flaw, we introduced in the previous version of Xen Orchestra a feature able to [detect the hyperthreading activation on your host](https://xen-orchestra.com/blog/xen-orchestra-5-35/#hyperthreadingdetection). ![](https://xen-orchestra.com/content/images/2019/05/htenabled.png) However, it appears that this feature was **unreliable**. The first version of our tool was only able to detect if the hyperthreading was activated in your Citrix Hypervisor (or XCP-ng) options. It means that, even if hyperthreading was disabled on the hypervisor level, it might still be activated on the BIOS level. For **XCP-ng users**, we added a new detection plugin directly at the `Dom0` level. This plugin is able to provide precise information about hyperthreading which is therefore displayed correctly in your Xen Orchestra interface. If you are using Citrix Hypervisor, you will still get unreliable information along with a warning in Xen Orchestra. ## UEFI support Guest UEFI support is now available for both Citrix Hypervisor and XCP-ng (8.0). Consquently, we added in Xen Orchestra a new advanced option during VM creation: **boot firmware**. ![](https://user-images.githubusercontent.com/25125613/58881729-0f0d4b00-86db-11e9-8beb-184d70476399.png) You also have the option to change the boot firmware on a VM already created in the advanced options of the VM: ![](https://user-images.githubusercontent.com/25125613/58881732-0f0d4b00-86db-11e9-95f5-3144abcf4d2f.png) Using **UEFI guests** instead of **BIOS** is recommended when using some specific operating systems, such as the most recent Windows version. In fact, Microsoft announced in 2017 their intent to [remove legacy BIOS support](https://www.anandtech.com/show/12068/intel-to-remove-bios-support-from-uefi-by-2020?ref=xen-orchestra.com) from its UEFI by 2020 in an effort to improve security. UEFI support exposed in Xen Orchestra is also the first step for a feature we plan to support in the close future: **Secure Boot**. ## New DVSC plugin > ⚠ *This feature is still in beta testing, [feedback](https://xcp-ng.org/forum/topic/1606/xo-sdn-controller-beta?ref=xen-orchestra.com) is welcome* Until now, to create a private network at the pool level, you had to deploy a dedicated appliance provided by Citrix, which was closed source and only worked in Internet Explorer. **It was painful to deploy and to use**. In this release, we are introducing our brand new SDN controller plugin - it **directly embeds in Xen Orchestra** and will allow you to deploy private networks amongst all hosts of a pool. ![sdn-controller-3](https://xen-orchestra.com/blog/content/images/2019/06/sdn-controller-3.png) Our new plugin aims to allow the creation of private networks in XCP-ng and Citrix Hypervisor which are: - reachable by all the hosts in a pool - unreachable by anything outside the network - reactive when the pool changes (new host, host ejected, PIF unplugged etc) Benjamin, the dev behind this new plugin wrote a detailed [devblog](https://xen-orchestra.com/blog/xo-sdn-controller/) dedicated to this new plugin. ![sdn-controller-2-1](https://xen-orchestra.com/blog/content/images/2019/06/sdn-controller-2-1.png) ## Ultra easy deploy for Xen Orchestra Until now, the easiest way to deploy the Xen Orchestra Appliance in your infrastructure was to use a single bash command line. ![bashlinexoa](https://xen-orchestra.com/blog/content/images/2019/06/bashlinexoa.png) Today, we are introducing the [new ultra easy deploy for Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xoa): ![super-easy-xo-deploy](https://xen-orchestra.com/blog/content/images/2019/06/Capture-d--cran-de-2019-06-19-14-21-14.png) With this new ultra easy deployment for Xen Orchestra, you only need to provide a couple of details and the appliance will be automatically deployed and configured in your infrastructure! > Note that everything happening in the quick deploy section will stay between you, your browser and your host. Nothing is sent on our servers and we collect 0 information! ## Display size for full VM backup You can now check directly in Xen Orchestra the total size of your full backup files on your remote. ![](https://user-images.githubusercontent.com/6813755/58432161-4fecda80-80b1-11e9-97e3-26d791763c4b.png) When restoring a full backup from your remote, you will see the size of this specific backup display. ![](https://user-images.githubusercontent.com/6813755/58432160-4f544400-80b1-11e9-8dfe-417ac671c7f4.png) ## NFS version selection Considering that multiple versions of NFS can be used amongst our users infrastructure, we have added the ability to select the NFS version of your choice in Xen Orchestra during the SR creation process. ![](https://user-images.githubusercontent.com/25125613/59754024-9a631080-9285-11e9-8826-42c239c8b741.png) ## PBD detail We added the PBD detail on the SR and the hosts view so you can have information about the way your host is connected to a SR. ![](https://user-images.githubusercontent.com/7724491/59604286-0f123f80-910c-11e9-97d9-0ec771663477.png) ![](https://user-images.githubusercontent.com/7724491/59604278-07eb3180-910c-11e9-9441-01fbc5df52f6.png) ## MS Azure AD compatibility ![Azure-Active-Directory](https://xen-orchestra.com/blog/content/images/2019/06/Azure-Active-Directory.jpg) We improved the compatibility of Microsoft Azure AD in Xen Orchestra. Security is now improved even further. ### DevBlog #2 - XO SDN controller URL: https://xen-orchestra.com/blog/xo-sdn-controller/ Last updated: 2019-06-27T08:03:17.000Z # What is an SDN controller? An SDN controller (Software-Defined Networking controller) is a tool allowing you to manage software network bridges (i.e: [OpenVSwitch](https://www.openvswitch.org/?ref=xen-orchestra.com)). A bridge works well alone, however when there's many of them it can be useful to have a centralized controller that manages all of the bridges in an orchestrated way. # Why create an SDN controller? Networking on Xen is quite easy and scalable, yet one feature was missing: creating a private network amongst all hosts of a pool. It was possible to create a private network on a specific host for all its VMs but not for higher scales. This introduces some issues as it's only on one host - the private network can't handle VM migrations to/from other hosts, plus if the host goes down, so does the network. Hence the need to create a tool enabling more scalability with private networks was realized, the solution is an SDN controller. After searching for existing solutions ([OpenDayLight](https://www.opendaylight.org/?ref=xen-orchestra.com), [Project Floodlight](http://www.projectfloodlight.org/floodlight/?ref=xen-orchestra.com), etc) we decided to create our own SDN controller, so that it would be better incorporated into our XOA solution. Indeed, already existing open source controllers are too complex for our needs, we prefer to develop our own small and simple solution. Citrix offers a similar solution for Citrix Hypervisor (XenServer): the Distributed Virtual Switch Controller (DVSC) appliance. However this solution also has some issues that led us to make our own: - it is closed source - it seems to be usable only in internet explorer - it is an appliance, therefore you're required to install it as a VM - it uses an active SSL connection with the OVSDB server of the virtual switches, it means the OVSDB server can be connected to only one controller as it is bound to one IP - it uses the `--bootstrap-ca-cert` option of the OVSDB server to give its SSL certificate, this is weak against *man in the middle* (MitM) attacks - from our testing experience, it is not very robust against restart/stop of the pool's hosts For all of these reasons implementing our own solution seemed to be the best option. The solution we're working on solved all the problems above: - it is open source - it is incorporated with XO therefore usable on any web browser, and doesn't require you to install a new VM - it uses a passive SSL connection on the standard IANA OVSDB port (6640), therefore many SDN controllers can share the control of a pool as long as they're signed with the same CA certificate - the SSL CA certificate is installed on the hosts through XAPI (`pool.certificate_install`, `pool.certificate_sync`), it means if the XAPI connection is over HTTPS then a MitM attack won't work - As for robustness against host restart/stop, we tested it thoroughly and it seems to work well, we are waiting for feedback from our community, when the beta will be available, to improve it if necessary # How does it work? First let's define what we mean by private network, we want a network that is: - reachable by all the hosts in a pool - unreachable by anything outside the network - reactive when the pool changes (new host, host ejected, `PIF` unplugged etc) ## Creation of the network Now, we can start creating the controller. Let's have a pool and its hosts. In order to create the network and the associated PIFs, the controller needs an XAPI connection to the pool's master. For creating interfaces and ports and the OpenVSwitch (OVS) bridges it also needs an [OVSDB](https://tools.ietf.org/html/rfc7047?ref=xen-orchestra.com) connection to each host. Once all the connections have been created, the fun begins. The controller creates a `tunnel` on each host, a `tunnel` is a "fake" `PIF` (not physical) simulated over a physical PIF. This tunnels will be the `PIF`s of the network. After that we need to connect all the hosts' bridges together. We chose a star topology instead of mesh to avoid loops in the network, as mesh would require us to use Spanning Tree Protocol which complicates the solution. To create the topology, a star-center is elected, all other hosts are connected to star-center via OVSDB: a port and interface connecting via a tunnel (either `GRE` or `VxLAN`) to the star-center is added to the bridge corresponding to the private network. Here's an example with a pool of 4 hosts connected via `GRE` tunnels: H1(master), H2(star-center), H3 & H4. ![sdn-controller-1](https://xen-orchestra.com/blog/content/images/2019/06/sdn-controller-1.png) ## Maintaining the network Once the star topology is created, we need to keep it in sync with the pool's events. When a `PIF` is unplugged or a host is removed/stopped OVS removes the ports and interfaces automatically. Same for all VM events: additions, removals, migrations, `VIF` connections and deconnections, they're all managed by OVS. The cases to handle: - a new host is added to the pool: the controller adds a tunnel to the new host and add the corresponding ports and interfaces to add it to the star topology. - a stopped host is started: if the host has a tunnel for the network, the tunnel is plugged and the corresponding ports and interfaces are added. - a tunnel `PIF` is plugged: the corresponding ports and interfaces are added. - Removal/Disconnection of the star-center (or its `PIF`): as said before, the removals of ports and interfaces are done automatically, however the star-center of the topology is the backbone of the network therefore we need to elect a new star-center and recreate the star topology from scratch with all the remaining hosts. # What about the future? - The private networks created by the SDN controller are isolated, the network could also be cyphered with `IPSEC`. ### Xen Orchestra 5.35 URL: https://xen-orchestra.com/blog/xen-orchestra-5-35/ Last updated: 2019-05-31T11:40:33.000Z Xen Orchestra 5.35 is available! The big news this month is the introduction of our brand new release channel. For some time now, we wanted to provide our users with more freedom regarding how and when they wanted to upgrade their appliance, so they can choose between **stability** and **cutting edge** features. Since this is the first month with new channels, if you stick with the stable channel you will not have many updates in May. You will have to wait for June to benefit from this month's enhancements. ## Release channel As a user, you can now make a choice between two different release channels: #### Stable The stable channel is intended to be a version of Xen Orchestra that is already a month old (and therefore will benefit from one month of community feedback and various fixes). This way, users more concerned with the stability of their appliance will have the option to stay on a slightly older (and tested) version of XO (still supported by our pro support). #### Latest The latest channel will include all the latest improvements available in Xen Orchestra. It is basically the old "default" channel before you could choose. The version available in latest has already been QA'd by our team, but issues may still occur once deployed in vastly varying environments as our user base has. ### How to select your release channel > By default, the release channel your appliance will use is `stable`. Because it's the first update including channels, you will need to perform a CLI command to access the `latest` channel and update if you so choose. To stay on stable, no action is necessary. 1. Log into the Xen Orchestra VM console. If it's the first time you're accessing the XO console, you can find the default credentials in the [official documentation](https://xen-orchestra.com/docs/xoa.html?ref=xen-orchestra.com#first-login) 2. Use the following command: `xoa-updater --configure-channel=latest` 3. In your appliance, you should now be able to upgrade to the latest version > All of the following enhancements are available only if you are using the `latest` release channel, and will be released for stable users in June. ## Forget all authentication tokens For security purposes (eg. if you suspect someone is using your access and just changed your password), you now have the ability to forget all connection tokens. > ⚠ This option will not sign out other active sessions, but will forget existing sessions and require authentication for new connections. ![](https://user-images.githubusercontent.com/10992860/58262166-08e1ab00-7d7a-11e9-99f6-5c3980c8e8dd.png) ## Hyperthreading detection You probably heard about major Intel MDS/Zombie load security flaw. We did a [very detailed post](https://xcp-ng.org/blog/2019/05/21/xcp-ng-security-bulletin-mds-hardware-vulnerabilities-in-intel-cpus/?ref=xen-orchestra.com) on XCP-ng blog. To know if your host is currently using hyperthreading, we added a dedicated section in the "Advanced" host tab, just in the hardware section: ![htenabled](https://xen-orchestra.com/blog/content/images/2019/05/htenabled.png) ## Citrix hypervisor License Restriction warning For Citrix hypervisor users with a free or a standard edition, you may sometimes encounter an error message labeled `LICENCE_RESTRICTION`. This error message is **not** related to any Xen Orchestra restrictions. It's related to **Citrix Hypervisor** restrictions in the *Express*/*Free* and *Standard* edition of the hypervisor. As a workaround for this error message, you can migrate your infrastructure to the [XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com) hypervisor which comes with **no feature restrictions**. This option is now suggested when the `LICENCE_RESTRICTION` error is occuring. ![](https://user-images.githubusercontent.com/10992860/58243851-c1dfbf80-7d51-11e9-8d6b-e89429e8b714.png) ## XCP-ng 8.0 beta is available If you are not signed up to our [XCP-ng dedicated mailing list](http://eepurl.com/dhF9ij?ref=xen-orchestra.com) you may have missed that the XCP-ng 8.0 hypervisor is now available in beta version. ![](https://xcp-ng.org/content/images/2019/05/xcp-ng-8beta-1.png) If you want more details about the release, take a look on the [official blogpost](https://xcp-ng.org/blog/2019/05/22/xcp-ng-8-beta-release/?ref=xen-orchestra.com). If you are seeking an installation method, the [official announcement](https://xcp-ng.org/forum/topic/1370/xcp-ng-8-0-0-beta-now-available?ref=xen-orchestra.com) on the forum will be the right place. > ⚠ Do not use XCP-ng 8.0 in production yet, this is still a beta version and unexpected issues can occur. ### Xen Orchestra 5.34 URL: https://xen-orchestra.com/blog/xen-orchestra-5-34/ Last updated: 2019-04-30T14:22:25.000Z Xen Orchestra 5.34 has landed. It comes with a gift for the free edition, more features for Cloud-init, as well as logs and backup reports for metadata backup jobs. Also as usual we've included many minor improvements and bug fixes. The complete changelog is available [here](https://github.com/vatesfr/xen-orchestra/blob/master/CHANGELOG.md?ref=xen-orchestra.com) ## Stats panel is now free The stats panel available in Xen Orchestra was, until now, an Enterprise feature. This panel is now available directly in the **free version of Xen Orchestra**. ![statpanel](https://xen-orchestra.com/blog/content/images/2019/04/statpanel.png) > Remember that you can also activate a **premium trial** anytime you want directly in your appliance. If you already used yours, [contact us on the chat](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xo-home) to ask for an extension 😉 ## Network config in Cloud-init Until now, in Xen Orchestra, the box exposed for cloud-init allowed you to configure parameters that will go to a `user-data` file. It is now also possible to pass network settings in a dedicated configuration box. ![](https://user-images.githubusercontent.com/25125613/56584705-9b0c5d00-65dc-11e9-823a-26ffbb25c492.png) > If you want to learn more about the networking configuration in Cloud-init, here is the [official documentation](https://cloudinit.readthedocs.io/en/latest/topics/network-config-format-v1.html?ref=xen-orchestra.com) ## Metadata backup feature improvements Since Xen Orchestra 5.32, you have the ability to backup your VMs metadata in Xen Orchestra. We've now made this feature complete with the following: - Metadata backup logs - Reports on metadata backup jobs are now included in backup reports #### Metadata backups logs ![](https://user-images.githubusercontent.com/21563339/55616345-e8419f80-5791-11e9-8174-2db9794b4bb5.png) ![](https://user-images.githubusercontent.com/21563339/55618621-4cb32d80-5797-11e9-85c3-a015ce340dfe.png) #### Metadata backup reports ![](https://user-images.githubusercontent.com/21563339/56131782-b518c080-5f88-11e9-9859-c4ab62a1356e.png) ## Better migrate VM modal We have improved the migration modal. Local storage is now selected by default which should be helpful in most cases. The optional SR selection is still available but not shown by default. Before ![](https://user-images.githubusercontent.com/1241401/44221015-84c21d80-a180-11e8-89ab-9925a12530bc.png) After ![](https://user-images.githubusercontent.com/7724491/55735652-0de4d800-5a22-11e9-892c-55a0df987d96.png) ## XO Proxy - Alpha test is coming ![xo-5c-20proxy_38106051-1--1](https://xen-orchestra.com/blog/content/images/2019/04/xo-5c-20proxy_38106051-1--1.png) ![xoproxies](https://xen-orchestra.com/blog/content/images/2019/04/withproxy-2.png) As we had announced in our [first Devblog](https://xen-orchestra.com/blog/backup-proxies/) we are going to start tests on Xen Orchestra proxy in the end of May. If you want to be part of these tests, or simply if you want to be informed about the progression of XO Proxy, you can subscribe to our dedicated mailing list. ## Subscribe \* indicates required Email Address \* Company name ## Citrix Hypervisor 8.0 is available Citrix Hypervisor (formerly XenServer) is now available. Consequently, we have started to work on a new release of our alternative solution [XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com). You can discuss this news and share your expectations for the next XCP-ng release on [our community forum](https://xcp-ng.org/forum/topic/1251/citrix-hypervisor-8-0-landed?ref=xen-orchestra.com) ### Devblog #1 - XO Proxy URL: https://xen-orchestra.com/blog/backup-proxies/ Last updated: 2020-04-29T11:39:58.000Z > In this new series of blogposts, we will introduce some of the major upcoming features from our development team perspective. In this first Devblog, we will talk about **XO proxy**, also known as **Backup Proxy**, one of the most requested features for Xen Orchestra. *Our beta version for these proxies should be released at the end of May*. ## Backup today When created, Xen Orchestra was designed to be deployed and used as a central management tool. That's still the case, and today, more and more people are using Xen Orchestra to manage distant locations or datacenters. This centralized model is a strength because you have only one UI to rule all your XenServer or [XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com) hosts! All our backup features work in a similar way: Xen Orchestra is performing a request to the Xen API, which then will listen to be streamed from XO itself. Indeed, XAPI isn't able to **push** data, it's only working via a **pull** model. So XO will fetch (pull) this data, and push it to the remote destination. In other words, a stream will flow from the host, through XO and finally to the remote. ![Paper.Vates.2019.04.13-2-2](https://xen-orchestra.com/blog/content/images/2019/04/Paper.Vates.2019.04.13-2-2.png) This is a really efficient and secure way to proceed, as long as your hosts, your Xen Orchestra appliance and your remote are all in the same location. However, when you are managing multiple sites, in different locations, using only one Xen Orchestra instance, it won't be optimal in terms of network traffic for your backup. Indeed, all the backups are streamed through Xen Orchestra! So you'll have a "back and forth" stream between your 2 sites (A and B) despite the "remote" also being near the host on the B side too: this will consume time and bandwidth. ![Paper.Vates.2019.04.13-2-1-1](https://xen-orchestra.com/blog/content/images/2019/04/Paper.Vates.2019.04.13-2-1-1.png) ## XO proxy ![xo-5c-20proxy_38106051](https://xen-orchestra.com/blog/content/images/2019/04/xo-5c-20proxy_38106051.png) This is where proxies enter the spotlight. Backup proxies are intended to provide the ability to keep backup streams in a remote site instead of going back and forth from your distant site to your XOA site. ## What does the proxy look like? Xen Orchestra Proxy will be an appliance by itself, a "lighter Xen Orchestra" you could say. Therefore, it will be a VM created from your main Xen Orchestra appliance and deployed in your distant pool. Once deployed, you will have the ability to add remotes to the proxy and to select the proxy in your backup job options during a backup job creation. ![withproxy-2](https://xen-orchestra.com/blog/content/images/2019/04/withproxy-2.png) ## What we are doing In XO proxy, we are using part of the existing code in Xen Orchestra. This is an opportunity for us to improve and make it stronger. This code will benefit not only the proxies, but also our classic backup code as well. On the other hand, Backup through proxies is just the first step in what we want to achieve with proxies, other things may benefit from the proxy appliance as well. As an example, we could also use them to improve the patching system in Xen Orchestra or even spread some load to manage very large and distributed infrastructures. When developing XO proxy, these are the things we are already thinking about, in order to create a solution that will be able to evolve in the future without needing a complete rewrite. We are also investigating a solution to be able to convert a current Xen Orchestra Appliance into an XO proxy. This way, we would like to provide people currently using multiple XO appliances a way to convert their current job instead of recreating it from scratch. ## When will XO proxies be available The solution is currently in its final development phase. We are expecting a public beta available at the end of May. If you are interested in this beta, please subscribe via [this form](http://eepurl.com/gpwpoP?ref=xen-orchestra.com) and we will contact you as soon as we have more details about the best way to proceed. ### Xen Orchestra 5.33 URL: https://xen-orchestra.com/blog/xen-orchestra-5-33/ Last updated: 2019-03-29T15:57:32.000Z Spring is in the air, and it brings the latest Xen Orchestra release: Xen Orchestra 5.33\. This release brings **key delta backup** for more secure backup jobs, the fully complete **metadata backup and restore** feature, as well as a brand **new patching system**! ## Event program #### DORS/CLUC 2019 ![Capture-d--cran-de-2019-03-27-11-35-15-1](https://xen-orchestra.com/blog/content/images/2019/03/Capture-d--cran-de-2019-03-27-11-35-15-1.png) We introduced XCP-ng hypervisor during the Croatian Linux's users day last year and the time has come to take a look back to celebrate one year of achievements! The conference will be given in the FER in Zagreb on the **18th of April**. More information are available on the [official website](https://2019.dorscluc.org/talk/9/?ref=xen-orchestra.com) of the event. ## Webinar video Our latest webinars are now available in video on our Youtube channel. If you missed them, here is your chance to catch-up. - [Full Open Source VDI stack - Joint webinar with our partner UDS Enterprise](https://www.youtube.com/watch?v=Lq8UudzwL5s&t&ref=xen-orchestra.com) - [Upgrade from XenServer to XCP-ng with Xen Orchestra](https://www.youtube.com/watch?v=WNcuyRThfso&ref=xen-orchestra.com) # Xen Orchestra 5.33 ## Key Delta backup [Delta backup](https://xen-orchestra.com/docs/delta%5Fbackups.html?ref=xen-orchestra.com) is one of the most used features in Xen Orchestra. Currently, when creating a Delta Backup Job, the first time the job runs, it does a Full backup and all the following runs will be delta. This is a perfect method to consume less bandwidth and space on your remote. ![](https://xen-orchestra.com/content/images/2015/12/delta_final.png) One of the biggest risks associated with Delta Backup is related to chain corruption. If an undetected issue occurs on any of the exports, this will corrupt the entire backup chain and you won't be able to restore as expected. This is the reason we introduced the **Key backup** for Delta Backup in Xen Orchestra. This features gives you the opportunity to do a full backup once in a while within your delta backup job. This will consume a bit more space on your SR, but will reduce the chain corruption risk. ![key-delta](https://xen-orchestra.com/blog/content/images/2019/03/key-delta.png) To configure this in your appliance, you need to set a Full Delta backup interval in the advanced settings of your jobs. This is the interval that full key backups will be performed. ![](https://xen-orchestra.com/blog/content/images/2019/03/key-delta-backup-ui.jpg) ## Metadata restore option In Xen Orchestra 5.32 we released the new ability to backup your pools metadata. As announced in the last release, you have now the ability to restore (and delete) your metadata backup. ![](https://user-images.githubusercontent.com/21563339/54678242-f2fb0400-4b04-11e9-8b11-1f731ecf6f98.png) ![](https://user-images.githubusercontent.com/21563339/54678304-1d4cc180-4b05-11e9-9a05-b599b547eb56.png) ![](https://user-images.githubusercontent.com/21563339/54678344-3c4b5380-4b05-11e9-891f-4fc6134939f9.png) ## Patching system rewrite The patching system in Xen Orchestra has been rewritten from scratch to offer more flexibility and stability. Any issues or feedback? Let us know on [Github](https://github.com/vatesfr/xen-orchestra/issues?ref=xen-orchestra.com) ## Automatic network assigned on VM creation When you are creating a VM, if you have an automatic network specified, it will automatically assign this network to the VM. ![](https://user-images.githubusercontent.com/6813755/53816640-2dd93580-3f64-11e9-81ee-66e445f28c41.png) ## Better sort of SR migrate selector During VDI migration, you will now see SRs which are on the same pool first in the selector. ![](https://user-images.githubusercontent.com/7724491/53501962-659c3500-3aad-11e9-8d4c-c64b93f6680a.png) ### Xen Orchestra 5.32 URL: https://xen-orchestra.com/blog/xen-orchestra-5-32/ Last updated: 2019-02-28T18:55:17.000Z This is the end of February and the time has come for a new Xen Orchestra release! ## Webinar progam Save the dates in your agenda. In March, you will have the opportunity to register to 2 webinars to learn more about [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xo-home), [XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com) and [UDS Enterprise](https://www.udsenterprise.com/en/?ref=xen-orchestra.com)! ### XCP-ng and UDS Enterprise On **March 20th**, discover a full stack solution from the hypervisor (XCP-ng) layer to the Virtal Desktop Infrastructure (UDS Enterprise) during a joint webinar with our trusted partner [UDS Enteprise](https://www.udsenterprise.com/en/?ref=xen-orchestra.com). ### Migrate from XenServer to XCP-ng You're not familiar with how to migrate your XenServer infrastructure to XCP-ng? Are you unsure if you should do it? Do you have questions about the process? You can attend [our webinar on March the 26th](http://)! Don't forget to register: Loading... ## Event program ### Open Source day - Lyon (Journée du Libre) For all the French speakers among you, we will be giving a talk during the [Journée du Libre (Open Source Day)](https://www.jdll.org/?ref=xen-orchestra.com) in Lyon, on the **06th of April**. More information soon on the [programme](https://www.jdll.org/programme?ref=xen-orchestra.com) ### DORS/CLUC 2019 Last year, we introduced the XCP-ng hypervisor for the first time. This year, we will come back to Zagreb (Croatia) to celebrate [one year of achievements](https://2019.dorscluc.org/talk/9/?ref=xen-orchestra.com)! # Xen Orchestra 5.32 ## Metadata backup It is now possible to backup your pool metadata and to automate the backup of your Xen Orchestra configuration! To create a job dedicated to your metadata, you just have to create a new job and select the "backup metadata" option. ![](https://user-images.githubusercontent.com/21563339/53413921-bd636f00-39cd-11e9-8a3c-d4f893135fa4.png) In the new backup view, you will have the ability to choose and to configure your new job. ![](https://user-images.githubusercontent.com/21563339/52416838-d2de2b00-2aea-11e9-8da0-340fcb2767db.png) ![](https://user-images.githubusercontent.com/21563339/52471527-65390a00-2b91-11e9-8019-600a4d9eeafb.png) Your new metadata backup job will be visible in the same page than your classic backup jobs. ![](https://user-images.githubusercontent.com/21563339/52416802-c0fc8800-2aea-11e9-8ef0-b0c1bd0e48b8.png) > Note: For now, the restore option for metadata is not available and should be in the next release. ## Better sorting ### Better sorting of VM Migrate selector When you want to migrate a VM, it's often within the same pool. To make it easier for you to select the appropriate pool during migration, we decided to sort the hosts starting with the current pool and then the other pools available. This should make the migration process easier for you. ![](https://user-images.githubusercontent.com/7724491/52355569-d3b38600-2a32-11e9-927b-60df736279d1.png) ![](https://user-images.githubusercontent.com/7724491/52625729-e81fd480-2eb1-11e9-9d6c-581bc1f49751.png) ![](https://user-images.githubusercontent.com/7724491/52625737-ec4bf200-2eb1-11e9-93da-d0c9f3a22a36.png) ### New VM sorting option - Start time It can be useful to sort the VMs by their start time in order to display VMs booted for a long time first, or, at the contrary, the most recently started VM first. ![](https://user-images.githubusercontent.com/6813755/52845652-ee0ef300-3107-11e9-85b2-9771d0897196.png) ## New network page You can now manage your network creation on a dedicated page directly in Xen Orchestra. ![](https://user-images.githubusercontent.com/7724491/52845052-683e7800-3106-11e9-9cb7-6cf5d00109e8.png) You just need to select the pool on which you want to create the new network and then it's straightforward. ![](https://user-images.githubusercontent.com/7724491/52845054-68d70e80-3106-11e9-9d8b-24d781b09976.png) ![](https://user-images.githubusercontent.com/7724491/52845056-68d70e80-3106-11e9-8a6f-22e0cbad78f0.png) ## Download your logs You already have the option to copy the Xen Orchestra logs to clipboard. However, logs are sometime so big it's not possible to copy them in a message. To troubleshot this issue, we have added the ability to download your XO logs to share them as an attached document in your message. ![](https://user-images.githubusercontent.com/6813755/53116010-ef954c80-3547-11e9-8b21-ec4ab3831b2f.jpg) ### Xen Orchestra webinar - How to upgrade from XenServer to XCP-ng? URL: https://xen-orchestra.com/blog/xen-orchestra-webinar-how-to-upgrade-from-xenserver-to-xcp-ng/ Last updated: 2019-03-25T14:57:56.000Z On **Tuesday March 26th**, **4PM UTC** we will host a webinar about the XCP-ng hypervisor. More precisely, we will show you the best way to migrate your infrastructure from XenServer to XCP-ng and the reasons why you should do it. > The webinar will take place on [our Youtube Channel](https://www.youtube.com/channel/UCNjvBiVTxBt-madrH2Kt7iA?view%5Fas=subscriber&ref=xen-orchestra.com) at 4PM UTC - Join us and don't forget to register! :) This webinar will cover: 1. The main differences between XenServer and XCP-ng 2. The best way to upgrade your infrastructure 3. The features in XCP-ng to keep your infrastructure up-to-date! This webinar is intended to last around **45 minutes**. You want to join us? Fill out the registration form here (more instructions will be sent by email). Loading... ### Xen Orchestra 5.31 URL: https://xen-orchestra.com/blog/xen-orchestra-5-31/ Last updated: 2019-01-31T15:39:03.000Z ## FOSDEM 2019 ![FOSDEM_logo-2](https://xen-orchestra.com/blog/content/images/2019/01/FOSDEM_logo-2.png) Again this year, some of us are going to one of the greatest OSS convention in Europe, FOSDEM in Brussels. This year, it takes place on the 2 & 3 of February. If you are going too, this is the opportunity to learn more about the XCP-ng story during Olivier Lambert's (CEO) talk: [XCP-ng - From Kickstarter to Datacenter](https://fosdem.org/2019/schedule/event/vai%5Fxcp%5Fng%5Fbuilding%5Fan%5Fopen%5Fsource%5Fand%5Fturnkey%5Fvirtualization%5Fplatform/?ref=xen-orchestra.com). You may even have the opportunities to get some of our shiny stickers. ## zstd compression support for backup **⚠ Warning: This feature is only available using the [XCP-ng hypervisor](https://xcp-ng.org/?ref=xen-orchestra.com).** Download it [here](https://xcp-ng.org/?ref=xen-orchestra.com#easy-to-install). The [Zstd compression algorithm](https://facebook.github.io/zstd/?ref=xen-orchestra.com) is now supported in XCP-ng. Consequently, we added the option to choose `zstd` compression in the Xen Orchestra backup menu for **full backup** and **Disaster recovery**: ![](https://user-images.githubusercontent.com/21563339/51480041-4ca6b280-1d90-11e9-97ab-3354f9d7a5ff.png) Zstd compression in our real case test scenarios is around **6 times faster than the XenServer default compression (GZIP)** and delivers between **5% and 10% smaller backup files**. zstd compression is not only saving space on your remote, it makes your backup even faster than without compression: depending on your disk content and host CPU, **this can be up to 4 times faster!** A picture is better than a thousand words, so lets take a look on the performance of backups with `zstd` in Xen Orchestra, here with a cheap *Xeon E3-1225 v5* on a small VM: ![zstd](https://xen-orchestra.com/blog/content/images/2019/01/zstd.png) Now with a better CPU (*EPYC 7401P*) and a bigger VM, it's even more impressive: ![zstd2](https://xen-orchestra.com/blog/content/images/2019/01/zstd2.png) This feature is (for now) only available in the [XCP-ng hypervisor](https://xcp-ng.org/?ref=xen-orchestra.com). This might be the right moment to try our open source alternative to Citrix if you haven't yet adopted it! [![Logo-fuse-e-glossy_rvb-texttest-small-1](https://xen-orchestra.com/blog/content/images/2019/01/Logo-fuse-e-glossy_rvb-texttest-small-1.png)](https://xcp-ng.org/?ref=xen-orchestra.com) And for companies requiring support for their production environment, [XCP-ng provides pro support plans](https://xcp-ng.com/?ref=xen-orchestra.com). ## More information displayed ### Backup remote space and usage The remote space used and left is now directly displayed in the backup view of Xen Orchestra. This is particularly useful if you want to monitor the space consumed by your backup and choose a remote with enough space left when creating a new backup job. ![](https://user-images.githubusercontent.com/6813755/50014879-75839d00-ffc5-11e8-9189-9fb5e992188a.png) ### Display free RAM on the host selector When selecting a host for migrating a VM, you will now see the RAM available on that host. ![](https://user-images.githubusercontent.com/7724491/51174379-f03b2300-18b7-11e9-87c3-a5d722df35b9.png) ## Snapshot improvements ### Grouped VM snapshots You can now snapshot a group of VMs. If you deploy a bunch of VMs that you want to snapshot at different moment (eg. after you have done the basic configuration) - you can now snapshot all the VMs at the same time instead of one by one. ![](https://user-images.githubusercontent.com/7724491/50886551-05640d80-13f1-11e9-97d3-3d82e8bf4001.png) ### snapshot VM memory You have now the ability to snapshot a VM's memory. ![](https://user-images.githubusercontent.com/21563339/50343118-07d7f380-0526-11e9-99fe-3030a0935eb7.png) ![](https://user-images.githubusercontent.com/21563339/50345411-41f9c300-052f-11e9-983d-920222824276.png) ![](https://user-images.githubusercontent.com/21563339/50345424-53db6600-052f-11e9-9512-bbda97edb53f.png) ## Enable/Disable multipathing You now have the option in the SR view to enable or disable iscsi multipath. ![](https://user-images.githubusercontent.com/21563339/51167920-1bb61180-18a8-11e9-85e4-4a760cdc3ed7.png) ![](https://user-images.githubusercontent.com/21563339/51167973-46a06580-18a8-11e9-945d-8d6ba0f02a77.png) ## ACL's management from VM view You can now set ACLs for a VM directly in the VM view. This will also allow you if the VM is already linked to existing ACLs. ![](https://user-images.githubusercontent.com/7724491/49747130-fe879500-fca2-11e8-9fb8-17c7126d8f4b.png) ![](https://user-images.githubusercontent.com/7724491/50288929-a5b8b900-0467-11e9-887f-c39ebc8a1059.png) ## SMB performances improved We have improved the overall performances when using a SMB remote storage. ## PIF speed display The information about the PIF speed is now display. It will allow you to check if the speed negociation is the right one. ![](https://user-images.githubusercontent.com/7724491/51897061-2398aa00-23ae-11e9-86f3-4b2e02e1af56.png) ## Notification system ### Notifications improved for backup health You are now notified when there are orphan snapshots to delete in your infrastructure. This notification is visible directly in the backup view. ![](https://user-images.githubusercontent.com/21563339/50593087-28de0400-0e97-11e9-8ff7-aa584fcaf5a4.png) ![](https://user-images.githubusercontent.com/21563339/50593103-372c2000-0e97-11e9-92a0-a9acac7fb374.png) ### Notification in app You will now receive notifications directly in your Xen Orchestra appliance for important information (eg. your license is about to expire). ![](https://user-images.githubusercontent.com/10992860/51738889-77468300-2090-11e9-95f4-3722d1cab589.jpg) ## One Time Password Authentication You can now activate for each user the OTP authentication. This is an easy and secure way to allow your user to log in Xen Orchestra ![](https://user-images.githubusercontent.com/6813755/51380735-af8b1600-1b12-11e9-8a60-922dc5771b98.png) [![sign-up-1000x300](https://xen-orchestra.com/blog/content/images/2018/07/sign-up-1000x300.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup?pk%5Fcampaign=blogbanner) ### Xen Orchestra 5.30 🎄 URL: https://xen-orchestra.com/blog/xen-orchestra-5-30/ Last updated: 2018-12-20T15:22:10.000Z Last release of 2018 for Xen Orchestra! Happy holiday to all of you and our best wishes for 2019\. This year was epic, thanks to you! ![happyholidays](https://xen-orchestra.com/blog/content/images/2018/12/happyholidays.png) ## A look back This year, we added a lot of features in Xen Orchestra and improved a lot of aspects - some performances related, other UI related. Xen Orchestra is better than ever and will continue to be improved in 2019. In 2018, we recreated our **backup features** from scratch, making them stronger and more reliable. [Our very first webinar](https://youtu.be/FfUqIwT8KzI?t=761&ref=xen-orchestra.com) provides a lot of explanation about all the backup options and how to use it. We also welcomed **2 new collaborators** in our team, dedicated to Xen Orchestra - therefore it's now a team of **6 peoples**, working daily on making Xen Orchestra the best **admnistration, backup and management** tool for XenServer and XCP-ng. ## XCP-ng **Happy birthday to XCP-ng!** 2018 was also the first year of XCP-ng existence. You should already have heard of our open source hypervisor, but if you don't, take a look [here](https://xcp-ng.org/?ref=xen-orchestra.com). To celebrate, we have created a review of this first year available [on this page](https://xcp-ng.org/blog/2018/12/10/1-year-of-xcp-ng/?ref=xen-orchestra.com). Finally, we have initiated a lot of [exciting thing around **R&D for XCP-ng**](https://xcp-ng.org/blog/2018/12/19/xcp-ng-research-initiative/?ref=xen-orchestra.com) and some [innovations in XCP-ng built-in compression algorithm](https://xcp-ng.org/blog/2018/12/19/zstd-compression-for-xcp-ng/?ref=xen-orchestra.com). The leads to [faster backups in Xen Orchestra](https://xen-orchestra.com/blog/faster-backups-a-new-frontier/). ## What's new in XO 5.30? ### XOSAN view improved You now have the possibility to sort SRs by name, size and free space in the XOSAN view. ![](https://user-images.githubusercontent.com/7724491/49638377-463ec000-fa08-11e8-8499-f494bb6ae2c8.png) ### Auto-connect to ejected hosts When you are ejecting an host from a specific pool, Xen Orchestra will now automatically connect this host to your infrastructure. Therefore, the host ejected will stay visible in your infrastructure. ### User group display On the users management interface, you can now see all the group in which a user is assigned. ![](https://user-images.githubusercontent.com/21563339/49291377-64596d00-f4aa-11e8-816d-7ac65b3402f3.png) ### Tooltip for VMs status There is now a tooltip to know the status of a specific VM (Running, Off, Pause...). ![](https://user-images.githubusercontent.com/7724491/49580160-8d687a80-f94e-11e8-909b-416777f61f2d.jpg) ### Backup job status for the last run In the backup view, the status of the last run for each backup job is now displayed and you can access detailed informations from it. This option is especially useful if you have a lot of jobs running and that you want to have a quick glimpse on the health of all your backup jobs. ![](https://user-images.githubusercontent.com/21563339/49878400-c65d8f00-fe27-11e8-974c-28b669bd0863.png) ### Faster backups: a new frontier URL: https://xen-orchestra.com/blog/faster-backups-a-new-frontier/ Last updated: 2018-12-19T15:22:05.000Z When you are performing a full VM backup, you want it to be done fast and efficiently (small file size). But until today, you only had 2 options: - no compression: relatively fast, but big files to transfer and to store - built-in compression: very slow, but smallest files to store ## Exports: one order of magnitude faster What if we found a solution that's the best of both worlds? Ultra fast AND with better compression? That's exactly [what we achieved in XCP-ng](https://xcp-ng.org/blog/2018/12/19/zstd-compression-for-xcp-ng/?ref=xen-orchestra.com), in its last update (available in XCP-ng 7.6 very soon): this new extra compression method is both faster and outputs smaller files. And it beats the default XenServer compression by **an order of magnitude**. ### Local benchmark Here is a benchmark on a 12 core setup with NVMe drives: The new compression in XCP-ng is **11,5 times faster** than XenServer default compression, and still deliver a 10% smaller file. Against uncompressed export, it's still faster, but more interestingly 50% smaller. ### Network benchmark Testing on a local drive is more theoretical. What about a test that's more closer to the truth, ie an export toward a NFS share? Let's run the numbers again! Let's compare total backup time accross a NFS behind a Gbit network: For the same VM, the new compression is: - 50% faster than uncompressed backup - 80% faster than XenServer/legacy compression So what about dividing your backup time by 2 and still using 50% less storage? [Just switch to XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com) :) Another image, CPU and network usage in this exact scenario, between GZIP and the new compression. Remember, it's **the same VM** we export twice: ![gzipvszstd_annoted](https://xen-orchestra.com/blog/content/images/2018/10/gzipvszstd_annoted.png) And that's not all! ## Improved restore speed Making backups faster is great, but what about the restore speed? Same platform, here is the results: It's simple: restoring using the new compression format is more than twice as fast. So in short, in the event of a problem, **your recovery time is divided by two**. And still using smaller files. ![](https://xcp-ng.org/wp-content/uploads/2018/04/logo1glossy.png) ## In Xen Orchestra Xen Orchestra will be the **first and unique backup solution supporting these enhanced compressed backups**. Just go into your backup view, create a job and select the "zstd" method: ![compressionmethod](https://xen-orchestra.com/blog/content/images/2018/10/compressionmethod.png) That's it! > Note: this feature will be available in the next weeks, stay tuned! ## The future Are we going even further? Yes. We'll also work on implementing compression on the VDI level, so your Delta Backups and Continuous Replication speed **will be doubled**. Want an example? Let's export a VDI into an NFS share (1GBit/s network): It's half the exported size and twice as quick total transfer time. **In the end, this means twice as fast delta AND faster Continous Replication**. ### Xen Orchestra 5.29 URL: https://xen-orchestra.com/blog/xen-orchestra-5-29/ Last updated: 2018-11-29T15:14:24.000Z Brace yourselves, the November update is here. Some improvements in the VMs settings, an option for nested virtualization, as well as some UI fixes and enhancements. As always, the complete changelog is available [here](https://github.com/vatesfr/xen-orchestra/blob/master/CHANGELOG.md?ref=xen-orchestra.com). Before jumping right into the Xen Orchestra update, some news about XCP-ng! ## XCP-ng security policy XCP-ng is proud to announce that XCP-ng is now **officially a member of the Xen Advisory pre-disclosure mailing list**! ![xen](https://xen-orchestra.com/blog/content/images/2018/11/xen.jpg) ### Security bulletin Xen announced multiple security issues during the last week: XSA-275, XSA-279, XSA-280 and finally XSA-282\. You can view the details of all these vulnerabilities on our [official blogpost for XCP-ng](https://xcp-ng.org/blog/2018/11/21/xcp-ng-security-bulletin-multiple-vulnerabilities/?ref=xen-orchestra.com) all these vulnerabilities are patched and already available in XCP-ng updates **(for both XCP-ng 7.5 and 7.6)**. You can simply update your XCP-ng using the Xen Orchestra pool patching features. ![](https://xcp-ng.org/content/images/2018/10/installpoolpatches.png) > Note: updating won't interrupt anything, you can update confidently in production. It will be taken into account only after a host reboot and you decide when you want to reboot. ## Nested virtualization It is now possible to select nested virtualization in the VM settings directly in Xen Orchestra, no more command line to use! ![](https://user-images.githubusercontent.com/6813755/47993688-666d1d80-e0f0-11e8-8a85-e9ee20299626.png) ## Warning displayed in case of missing VMs When you are trying to backup a VM that no longer exists, you will now see a warning displaying the UUID of the missing VM(s). ![](https://user-images.githubusercontent.com/21563339/48058147-004ace00-e1b6-11e8-960a-4ac49413dfd6.png) ## Switch virtualization mode It's now possible to switch the virtualization mode (PV/HVM) of an existing VM. Simple and turnkey to use! > Warning: you must know what you are doing. Switching without the correct configuration may break your setup (eg: if you didn't install the bootloader in the MBR while switching from PV to HVM, or even worse, in HVM to PV, if you don't have the correct PV args)! **Use with caution**. ![](https://user-images.githubusercontent.com/6813755/48277342-aa428880-e44a-11e8-85a1-494b18ae9dec.png) ## Performance alert - alert when below a threshold We added a new option in the performance alert plugin. It was already possible to setup an alert when the usage of your host, VM or SR was above a certain value in order to avoid throttling in your infrastructure. It is now possible to set an alert when the usage is below a threshold you defined. It's especially useful if you are expecting a minimum of network activity and can help you to detect issues in your infrastructure. ![](https://user-images.githubusercontent.com/21563339/48474443-de2afe80-e7fa-11e8-8791-9ae3a6a341a2.png) ## Server connection enhancement When you add a new pool to Xen Orchestra, you only have to connect the pool master in the Servers option page, adding every host in the pool can result in some unexpected issues. As we noticed it's a pretty common mistake, so you will now get an error message display in order to prevent new connections if the pool is already connected. ## Pause/Resume VM option You may be familiar with the "suspended" VM status which, in short, is copying the RAM data to the disk before suspending the VM. This is a very useful option, however it can take some time for the data to be copied to the disk. The pause VM option is exactly what you need when you need to freeze a VM in its current state in order to resume it later, but have no time to copy the RAM contents to disk. > Warning: The Pause VM option is way faster than suspension but it can lead to data loss because the RAM won't be saved on a disk before the pause. Use with caution. [![sign-up-1000x300](https://xen-orchestra.com/blog/content/images/2018/07/sign-up-1000x300.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup?pk%5Fcampaign=blogbanner) ### Xen Orchestra 5.28 URL: https://xen-orchestra.com/blog/xen-orchestra-5-28/ Last updated: 2018-10-31T17:06:09.000Z Everything you need to know about Xen Orchestra 5.28, our new versioning system, improvements to ACL's and the latest XCP-ng 7.6 release! ## New versioning system You may have noticed that our release numbering during the last few months could be confusing. The reason is that we decided to separate the "**technical**" and the "**product**" release. Consequently, you can see now that the current XO version in your update page and this version are no longer related to `xo-web` nor `xo-server` current versions. We now have a dedicated number for the whole product, `xen-orchestra` itself. This will allow us to have a more streamlined and "linear" release process (ie: without "holes" in numbering). Also, don't forget that you can always access the complete and detailed [changelog here](https://github.com/vatesfr/xen-orchestra/blob/master/CHANGELOG.md?ref=xen-orchestra.com#5280-2018-10-05). ## XCP-ng 7.6 is available! After a month or so of tests, the [latest version of XCP-ng is now available](https://xcp-ng.org/blog/2018/10/31/xcp-ng-7-6/?ref=xen-orchestra.com) and ready for production. You can download XCP-ng 7.6 hypervisor from the [official website](https://xcp-ng.org/?ref=xen-orchestra.com). A lot of security-related things on the menu, go read the official blog post there! Also don't miss the [latest XCP-ng security bulletin!](%28https://xcp-ng.org/blog/2018/10/29/xcp-ng-security-bulletin-xsa-278/%29) ![](https://xcp-ng.org/assets/img/mainlogo.png) # Xen Orchestra ## Patching pools improvement Patching pools within Xen Orchestra is now an even more turnkey experience. We added an extra modal for XenServer users to be able to choose a default SR before patching if none is already defined. We also added an alert displaying VMs with CDs attached to it and an option to eject them all. ![](https://user-images.githubusercontent.com/10992860/46397659-0cdd9180-c6f3-11e8-8ccd-0ba11794240a.jpg) ![](https://user-images.githubusercontent.com/10992860/46398427-61820c00-c6f5-11e8-83e7-eb9da5b69a1d.jpg) ![](https://user-images.githubusercontent.com/10992860/46398044-48c52680-c6f4-11e8-9149-7868abbd137c.jpg) ## ACLs improvement #### VM operator can now create snapshots VMs operators have now the ability to create snapshots on their VMs. They are defined as admin of the snapshots they are creating, allowing them to remove snapshots they have previously created. #### VM clone Cloning a VM will now provide the admin ACLs to the users that made the VM clone. > Note: No other ACLs will be copied from the cloned VMs. #### Global UI performance improvement for non-admin users with ACLs We have greatly improved overhall performance of Xen Orchestra for users with a large number of ACLs objects, especially for the non-admin users interface. ## Backup improvements #### Error message improvement for backups When trying to backup a VM that no longer exists, we now display an explicit error: `unknown item` ![](https://user-images.githubusercontent.com/21563339/47139626-8dd48580-d2bc-11e8-8920-bf522bbba03d.png) #### Selection and interval can be mixed You can now schedule your backup jobs by mixing the time and interval selection. (eg. Run every 4 minutes...) ![](https://user-images.githubusercontent.com/21563339/47008634-eb40c900-d13a-11e8-99e4-9c98b113fcf5.png) ![](https://user-images.githubusercontent.com/10992860/47021002-cfe5b600-d15a-11e8-80b7-d37027f68b2f.gif) #### Daily report A daily report for all your backup jobs is now an option when configuring backup reports. ## IOPS read/write/total per VM in usage report In the usage report, we are now displaying the IOPS for read, write and total for each VM. ![](https://user-images.githubusercontent.com/21563339/46601546-b5259880-caed-11e8-86b8-c9c8d6725055.png) You can also consult the top three IOPS VM usage: ![](https://user-images.githubusercontent.com/21563339/46607732-59193f00-cb02-11e8-8bc3-26b89e01096e.png) ![](https://xen-orchestra.com/content/images/2018/06/XO-logo-name.png) ## Last but not least ![halloween](https://xen-orchestra.com/blog/content/images/2018/10/halloween.png) ### Case study #3 - XOA at Optanex URL: https://xen-orchestra.com/blog/xoa-at-optanex-a-case-study/ Last updated: 2021-03-15T13:33:30.000Z **Optanex[\[1\]](#fn1)** is part of our Xen Orchestra partner program since **2016**, located in Malta. They are our most performant partner in Europe. This case study is about the way Optanex is using Xen Orchestra in their infrastructure as well as the way they are promoting our solution to their own customers as a partner. ![home](https://xen-orchestra.com/blog/content/images/2018/10/home.svg) **Can you tell us a bit more about your company? What is your business?** > We are a small company focused on: > > - web applications (ecommerce, web development) > - Web marketing and SEO > - IT services and security: online backup (Barracuda), D&R (Xen-Orchestra), vulnerability Assessment. **Why did you become a Xen Orchestra partner in the first place? Are you using Xen Orchestra in your own infrastructure? Does it help you to sell the appliance?** > We do a lot of research and testing; Xen-Orchestra came out after a lot of testing on XenServer VM backup problems. > It solved brilliantly the need of web access to XenServer and a fast disaster recovery of Windows and linux VMs. > With differential backup on an NFS NAS we have reached an excellent backup speed. **What are the features in XO your customers are the most interested in? Can you give a classic selling scenario?** > Customers that love XenServer and want to get rid of agent-based backups (Acronis and others) because they have 10 to 100 VMs running in their environment. > The other two big drivers that we frequently find are: > > - fast backup: night is becoming too short if you have plenty of VMs to save; they now need backup window shorter than 3-4 hours. XOA addresses this. > - long backup history needed: companies need many weeks or months of backup sets, not just days. > Less frequently, but increasingly, some customers ask for a second, independent host/storage on which they replicate all or some key VMs; XOA can replicate them easily. --- 1. Interested in working with Optanex? Want to learn more about the services they can provide your company? Reach them on [their website](https://www.optanex.com/it/?ref=xen-orchestra.com) [↩︎](#fnref1) ### Why you should subscribe to Xen Orchestra URL: https://xen-orchestra.com/blog/why-you-should-subscribe-to-xo/ Last updated: 2018-10-03T12:39:28.000Z Xen Orchestra is a user friendly all in one administration tool. It allows you to effectively **reduce the administration time** for your infrastructure, **easily delegate access** to your teams and provide a complete range of **backup solutions**. ## All-in-One tool #### Reduce your administration time All the **administration**, **management**, **backup** and **Cloud** related features you need are regrouped into one unique solution: Xen Orchestra. It's the one tool you need to subscribe to and learn in order to **manage your entire infrastructure** from A to Z. #### Delegate access easily With **ACLs and Self-Service features**, it's easy to provide the right access to specific persons in your team. The Access Control List feature allows you to delegate existing resources in your infrastructure so users can access it on their own, **without interfering** with your global XenServer/XCP-ng infrastructure. On the other hand, with self-service, you can **define a limited set of resources** your users can access to create VMs and use them when they need it. ![](https://xen-orchestra.com/docs/assets/acllist.png) #### Access your infrastructure from anywhere Xen Orchestra is a **web-ui**. It means that as long as you have an internet connection, you can connect to your XenServer/XCP-ng infrastructure and manage it from any device, from anywhere and at any moment! And as a web interface, you no longer need to rely on a desktop with a Windows OS. #### Easy to learn interface Xen Orchestra has been designed to be a user-friendly interface and comes with [complete documentation](https://xen-orchestra.com/docs/?ref=xen-orchestra.com), live chat assistance and our pro support ticket services. It should not take long for you to become an expert! #### Performance Because we are using NodeJS and asynchronous technologies, our architecture is able to manage from 1 to more than 4000+ VMs. Xen Orchestra is much faster and reliable than XenCenter! Even if you only take into account loading time, you will already save a lot of time. ## Backup your VMs and save money Did you know that the estimated cost of a lost file is around **$154 USD** and that every week in the US, 140,000 Hard Drives fail? Xen Orchestra provides a complete range of backup features for XenServer and XCP-ng that will help you to backup your entire infrastructure and VMs. Protect your data the right way, it's invaluable. > Note: Even if you need to change your entire infrastructure, as long as you have your backup stored in a remote, you just need to deploy a brand new XO appliance to recover everything. Xen Orchestra backs up your infrastructure to remote stores automatically! ![](https://xen-orchestra.com/content/images/2017/08/backups-solutions.PNG) You can read [this article](https://xen-orchestra.com/blog/choose-your-backup-solution-xenserver/) for a complete overview about why you should backup your infrastructure, and which features are the best for your specific case. ## Health monitoring to prevent bottlenecks Xen Orchestra is not only an administration tool that helps you to solve your issues when they occur, it's also a solution that will help you to prevent issues before they happen. With a global vision of your infrastructure and a complete dashboard of statistics, you will be able to detect bottlenecks before they start to create trouble in your environment. ![](https://xen-orchestra.com/docs/assets/visualizationdashboard.png) You can also get regular reports directly to your email, Slack or Mattermost channel. ## Multi hypervisor support Xen Orchestra is optimized to run on both **Citrix XenServer** and **XCP-ng** hypervisors. XCP-ng is a Citrix XenServer based hypervisor - an open source project powered by the community and delivering high performance for any type of user, from homelab to world-class datacenters. While the XCP-ng hypervisor itself is entirely free with no license restrictions, you can still subscribe to pro support in order to always be covered by our experts. [Learn more here](https://xcp-ng.com/?ref=xen-orchestra.com). ## Conclusion Xen Orchestra is a tool that will help you: - To save administration time - To save learning time - To delegate resources - To backup your data - To prevent bottlenecks - To improve your overall ROI ### Xen Orchestra 5.27 URL: https://xen-orchestra.com/blog/xen-orchestra-5-27/ Last updated: 2018-10-02T12:05:10.000Z September release! And it contains a LOT of enhancements and bug fixes. Let's take a tour of what's new. Missed our backup live webinar on YouTube? [Catch up here!](https://youtu.be/FfUqIwT8KzI?t=12m38s&ref=xen-orchestra.com) > XCP-ng 7.5: [don't miss the latest news about XCP-ng](https://xcp-ng.org/2018/09/21/xcp-ng-new-install-features/?ref=xen-orchestra.com): software RAID 1 support during install and even a new net install ISO that's just 100MiB big! ## UI enhancements #### Start on host For various reasons, you would like to boot a VM on a particular host. Easy now, in the "Advanced" tab of your VM: ![](https://xen-orchestra.com/blog/content/images/2018/09/booton.jpg) #### PVHVM status You can know if your VM is of PVHVM type. You can read more on our detailed article regarding [virtualization modes in Xen](https://xen-orchestra.com/blog/xen-virtualization-modes/). Info is displayed both in General and Advanced tab of your VM: ![pvhvm](https://xen-orchestra.com/blog/content/images/2018/09/pvhvm.png) #### Set NIC type For Windows users who don't have the tools installed yet (or for other specific software requirements), you can know set the "device type" as emulated "Intel e1000" instead of the default "Realtek RTL819". ![](https://xen-orchestra.com/blog/content/images/2018/09/intell.png) #### Tasks If you are in the task view and the task disappeared (because finished), we added a section "Previous tasks". This way you are sure to not miss anything! ![](https://xen-orchestra.com/blog/content/images/2018/09/previoustask.jpg) By the way, self service users won't see those tasks anymore! ## Backups #### Restore whole folder No need to select individual files manually like before, one click and you get the whole folder content restored: ![](https://xen-orchestra.com/blog/content/images/2018/09/folderrestore.jpg) #### Restart all failed VMs in a job A pretty handy shortcut, if you have just few VMs that messed up in a backup job, just click on the right button and it will be retried just for them: ![](https://xen-orchestra.com/blog/content/images/2018/09/restartbackup.png) #### Total transferred and merged size For any job, whatever the number of VMs, you have now the total size of transfer and merge. This counter is refreshed in real time during the job execution: ![](https://xen-orchestra.com/blog/content/images/2018/09/mergesize.png) #### Job name in restored VM When your VM is restored, you are now sure where it came from (which job): ![](https://xen-orchestra.com/blog/content/images/2018/09/jobname.png) [![sign-up-1000x300](https://xen-orchestra.com/blog/content/images/2018/07/sign-up-1000x300.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup?pk%5Fcampaign=blogbanner) ### XenServer 7.6 URL: https://xen-orchestra.com/blog/xenserver-7-6/ Last updated: 2022-06-01T14:42:10.000Z ⚠️ XenServer 7.6 is now End of Life (EoL). You can however [download XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com) instead, providing a 100% compatibility with all features for free. In time for the "one release per quarter" cycle, here is XenServer 7.6! ## What's new? The official changelog [is here](https://docs.citrix.com/en-us/xenserver/current-release/whats-new.html?ref=xen-orchestra.com). In short, **experimental features from 7.5 are now considered stable**. ### Bug fixes We are proud to say we fixed (or assisted) some issues existing in previous XenServer 7.5: - We found, reported and helped XS/XAPI devs to pinpoint an overflow issue while exporting large VHD files (>1TiB), due to signed int usage ([XSO-868](https://bugs.xenserver.org/browse/XSO-868?ref=xen-orchestra.com)) - We found, reported and fixed a critical regression happening in XS 7.5\. We even submitted a pull request toward XS code ([XSO-873](https://bugs.xenserver.org/browse/XSO-873?ref=xen-orchestra.com)). Fun fact: our fix was even merged in XCP-ng 7.5, weeks before 7.6 was available. Read more on the [story here](https://xen-orchestra.com/blog/full-stack-power/). - We found, reported and fixed a bug regarding a first boot file incorrectly packaged on XS 7.5 update package ([XSO-877](https://bugs.xenserver.org/browse/XSO-877?ref=xen-orchestra.com)) - And more minor issues reported on the official bug tracker ## XCP-ng status More to come for XCP-ng very soon: software RAID support during install, and other cool stuff :) XCP-ng 7.6 dev cycle is now open, we'll have an RC relatively soon. You can stay tuned on the [XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com) website, in the news section, or subscribe to the newsletter via the same page. ![raid1](https://xen-orchestra.com/blog/content/images/2018/09/raid1.png) ### Xen Orchestra 5.25 URL: https://xen-orchestra.com/blog/xen-orchestra-5-25/ Last updated: 2018-08-31T12:17:47.000Z > *Note: You might have noticed that version 5.25 is immediately following the 5.22 release on our blog. This is due to changes in the way our devs are working. You will see some more changes in the "versioning" of Xen Orchestra in the next few months. We will explain in detail soon, stay tuned!* ## XCP-ng 7.5 pro support The latest XCP-NG version, 7.5 has been available for a few weeks. Starting with this version we are also offering pro support options for companies that want to use XCP-ng in a production environment with the security of our pro support. [Learn more on the official website](https://xcp-ng.com/?ref=xen-orchestra.com) [![prosupport](https://xen-orchestra.com/blog/content/images/2018/08/prosupport.png)](https://xcp-ng.com/?ref=xen-orchestra.com) ## Import/Export VDI content You can now export and import VDI content directly from Xen Orchestra. ![](https://user-images.githubusercontent.com/10992860/42810564-8547d87e-89b8-11e8-8101-1796eab7cde0.png) ![](https://user-images.githubusercontent.com/10992860/43002158-111ee092-8c28-11e8-80e4-cfb7d37e5ccc.png) ![](https://user-images.githubusercontent.com/10992860/43002160-12d861f6-8c28-11e8-8c26-e3d573d40da1.png) ## Improved search filter The search filter is a very powerful tool to manage your infrastructure. You can even use it to find some outdated Linux kernel for some distro, with: `"debian 9.5" !4.9.0-8-amd64`. This will display **all your outdated Debian 9 VMs kernel**, which is critical for security reasons. But now, it's even more powerful. See below! ### Wildcard support A simple string in the search filter can contain a wildcard character (`*`) to match any character in a portion of the string: `foo*bar`: matches `foobar`, `foo` \- `bar`, etc. ### Regular expression For more advanced string matching, you can use regular expressions: - `/^DNS server \d+$/:` matches `DNS server 1`, `DNS server 05` but not `DNS server` - `/foo/i:` with the `i` flag, it ignores the case, therefore it matches `Foo` and `FOO` See more information about supported regular expressions in the [documentation](https://xen-orchestra.com/docs/search.html?ref=xen-orchestra.com#regular-expression) ## Ability to set a job timeout You can now set a timeout for jobs. This timeout is calculated in seconds. ![](https://user-images.githubusercontent.com/21563339/43074871-0f45cf20-8e7f-11e8-8e3a-32e641b9f60c.png) ## Remote option improvements ### Ability to change the type of remote ![](https://user-images.githubusercontent.com/21563339/42871755-689d6f54-8a7b-11e8-9076-128b05618b73.png) ### Edit/Delete remotes with invalid url When you add a remote with an invalid url, you will now have an error message displayed and the ability to change the url. ![](https://user-images.githubusercontent.com/21563339/43250947-d96cdf5a-90be-11e8-9718-b7427f96b8bb.png) ## New SR type: Local EXT Local EXT is the thin provisioned version of Local LVM. VHD files are used and it works well to create snapshots without taking a lot of space. ![](https://user-images.githubusercontent.com/1241401/44276423-a9cd9380-a247-11e8-8297-60d1ca9831c1.png) ## Minor enhancements - You now have the ability to edit a backup job schedule's name - You now have the option to remove the previous backup before making a new one. **Use this feature with caution** \- only if you lack space on your remote. If anything goes wrong during the backup, you will still lose the previous backup with this option enabled. ![](https://user-images.githubusercontent.com/21563339/43641294-689a6e58-9723-11e8-8d06-016a5acadbf3.png) - The SMB subfolder field is now optional - There is now a custom mount option field for NFS remotes ![](https://user-images.githubusercontent.com/10992860/44515721-96954a80-a6c3-11e8-9101-50af041436bb.jpg) [![sign-up-1000x300](https://xen-orchestra.com/blog/content/images/2018/07/sign-up-1000x300.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup?pk%5Fcampaign=blogbanner) ### Foreshadow vulnerability on XenServer and XCP-ng URL: https://xen-orchestra.com/blog/foreshadow-vulnerability-on-xenserver-and-xcp-ng/ Last updated: 2018-08-15T13:58:15.000Z This is a recap on the latest Foreshadow vulnerability and how it affects XenServer and XCP-ng. ## Foreshadow, XSA-273 Yet another Intel x86 security issue… Basically, someone could steal data in RAM, outside the VM boundaries (ie: from other VMs on the same host). If you have non-trusted users in your VMs, it's time to patch ASAP. And maybe disable hyper-threading. [![foreshadow](https://xen-orchestra.com/blog/content/images/2018/08/foreshadow.png)](https://foreshadowattack.eu/?ref=xen-orchestra.com) You can find more details [here](https://xenbits.xen.org/xsa/advisory-273.html?ref=xen-orchestra.com) and [here](https://foreshadowattack.eu/?ref=xen-orchestra.com). ### Should I disable hyper-threading? No obvious answer sadly: > If an HVM guest kernel is untrusted (i.e. not under host admin control), it is probably not safe to be scheduled with hyper-threading active. But if you have control on your VMs, please be sure you have all recent fixes available from your OS vendor. Then, no "need" to disable HT. ## XAPI security issue, XSA-271 Let's quote the [XSA document](https://xenbits.xen.org/xsa/advisory-271.html?ref=xen-orchestra.com): > An unauthenticated user with access to the management network can read arbitrary files from the dom0 filesystem. This includes the pool secret `/etc/xensource/ptoken` which grants the attacker full administrator access. This is… big. Update ASAP (see below on how) or close your XAPI from outside, now! If you have hosts all around the world, another possibility is to let your XAPI only reachable from a secured tunnel, without external access. ### On XenServer There are multiple patches, depending on your current XenServer version. Citrix did a recap on those vulnerabilities here: [https://support.citrix.com/article/CTX236548](https://support.citrix.com/article/CTX236548?ref=xen-orchestra.com) Patched versions are: - 7.0 - 7.1 CU1 - 7.4 - 7.5 You can patch directly from Xen Orchestra UI as soon Citrix publishes them in [their official online XML](https://updates.xensource.com/XenServer/updates.xml?ref=xen-orchestra.com) (few days in general). #### XenServer 7.2/7.3 If you are using XenServer 7.2 (and 7.3) you have 2 options: - upgrade ASAP to XenServer 7.5 (**WARNING FOR XENSERVER FREE USERS**: you'll lose [some features previously free](https://xen-orchestra.com/blog/xenserver-7-3/)!) - upgrade to [XCP-ng 7.5](https://xcp-ng.org/?ref=xen-orchestra.com) (you won't lose any feature, 100% free, easy upgrade path) > If you already have a paid contract with Citrix, 7.2 and 7.3 aren't supported anymore, **please upgrade to XenServer 7.5!** ### On XCP-ng You can read this [official XCP-ng blog post](https://xcp-ng.org/2018/08/15/xcp-ng-security-bulletin/?ref=xen-orchestra.com) regarding both XSAs. As usual [and as documented](https://github.com/xcp-ng/xcp/wiki/Updates-Howto?ref=xen-orchestra.com), 2 possibilities: - CLI: `yum update` on each host - Web UI in Xen Orchestra (see screenshots below) ![poolpatches](https://xen-orchestra.com/blog/content/images/2018/08/poolpatches.png) ![listupdates](https://xen-orchestra.com/blog/content/images/2018/08/listupdates.png) Please reboot your hosts then, and **always** reboot the pool master first. > Note: a toolstack restart is enough to fix `XSA-271`, but reboot is needed for `XSA-273` ![](https://xcp-ng.org/wp-content/uploads/2018/04/logo1glossy.png) ### XCP-ng 7.5 URL: https://xen-orchestra.com/blog/xcp-ng-7-5/ Last updated: 2018-08-10T13:44:07.000Z The latest release of the turnkey Xen hypervisor is here! Let's discover what's inside. The official announcement is [available here](https://xcp-ng.org/2018/08/10/xcp-ng-7-5/?ref=xen-orchestra.com). It's obviously 100% compatible with Xen Orchestra. But even better: XCp-ng fixed a big regression that affected disk export (= backups) on XenServer 7.5\. If you missed it, go read [our story on how we chased and fixed a nasty issue in XS 7.5](https://xen-orchestra.com/blog/blog/full-stack-power/). ## A real community effort XCP-ng is not driven by one company or one individual: it's a real community effort. It all started with a very [successful Kickstarter campaign](https://www.kickstarter.com/projects/78495858/xcp-ng?ref=xen-orchestra.com), and now it gather 500 members on its very [active forum](https://xcp-ng.org/forum?ref=xen-orchestra.com), with also its own [GitHub organization](https://github.com/xcp-ng?ref=xen-orchestra.com). ## New stuff and bug fixes There is so much to say, but in short: - XenServer bugs were fixed (not just one!) - ZFS and Ceph experimental support added - USB passthrough, Networking SR-IOV, bigger pools… Go [read the official blog post](https://xcp-ng.org/2018/08/10/xcp-ng-7-5/?ref=xen-orchestra.com) to learn more. ## Download or upgrade You can [download it here](https://xcp-ng.org/download/?ref=xen-orchestra.com). If you want to upgrade, [please read this guide](https://xcp-ng.org/2018/08/10/xcp-ng-7-5-upgrade/?ref=xen-orchestra.com). ### "Administer and backup your VM infrastructure the easiest way" - A Xen Orchestra Webinar URL: https://xen-orchestra.com/blog/webinar-backup/ Last updated: 2018-09-10T12:15:41.000Z On **Tuesday 11th September**, **3PM UTC** we will host a webinar about the Xen Orchestra Appliance. More precisely, we will cover the major features you will find in our solution, and how to use it in the best way possible in your XenServer or XCP-ng infrastructure. *UPDATE: The webinar will take place on [our Youtube Channel](https://www.youtube.com/channel/UCNjvBiVTxBt-madrH2Kt7iA?view%5Fas=subscriber&ref=xen-orchestra.com) at 3PM UTC - Join us and don't forget to register! :)* This webinar will cover: 1. All the basics required to administer your infrastructure using Xen Orchestra as a web-UI 2. Backup features, their options and how to get the best from each This webinar is intended to last around **45 minutes**. You want to join us? Fill out the registration form here (more instructions will be send by email). Loading... ### Xen Orchestra 5.22 URL: https://xen-orchestra.com/blog/xen-orchestra-5-22/ Last updated: 2018-07-31T14:21:04.000Z Summer is here, with a new release! We've taken a step back and improved on what's already available. This release focuses primarily on minor improvements and bug fixes to make your Xen Orchestra experience even more enjoyable. XCP-ng is making progress as well with a 7.5 release candidate available! ## XCP-ng 7.5 - Release Candidate available The latest version of XCP-ng 7.5 is available via a Release Candidate. Download and install instructions are provided [here](https://xcp-ng.org/2018/07/31/release-candidate-for-xcp-ng-7-5/?ref=xen-orchestra.com). Give it a go and give us your feedback on the [community forum](https://xcp-ng.org/forum/topic/241/xcp-ng-7-5-0-release-candidate?ref=xen-orchestra.com). The production release is coming soon! A **lot** of exciting stuff inside it, even **ZFS experimental support!** > Note: this RC is not suitable for production environments - Wait for the definitive release! ## Optional port for NFS You can now specify the port for your NFS remotes, allowing you to use remotes running on a non-default port. ![](https://user-images.githubusercontent.com/21563339/42222184-a66bdd28-7ed4-11e8-929b-cd9cf5f9509d.png) ![](https://user-images.githubusercontent.com/21563339/42222381-57e0c212-7ed5-11e8-8c71-c982694be218.png) ## Offline snapshot You now have the option to automatically shutdown your VM before snapshotting. Then the VM is immediately started after, offering a minimal downtime for those who prefer to do an offline snapshot. ![](https://user-images.githubusercontent.com/21563339/42313321-ba9f1124-8042-11e8-8d1e-83ee42d1e682.png) > Note: offline snapshot is better if you have non-cooperatives VMs when it's time to snapshot them. Like some Windows VMs and quiesce that can't keep up the pace. ## Turkish translation Thanks to one of our contributors, the Turkish language is now available in Xen Orchestra. > Note: The translations may be incomplete, especially regarding the latest features. ## Various enhancements - If you have no remote connected to XO, you will now have a link to the remote settings page directly from the backup view, so you can add one quickly. ![remotesettings](https://user-images.githubusercontent.com/21563339/42163641-ab90059e-7e03-11e8-9f70-da5b8a124e9e.png) - Copy to clipboard and report buttons are now always available (even for pending jobs) - When creating a local remote, you will now have a warning displayed ![localremotewarning](https://user-images.githubusercontent.com/10992860/42280482-256f6186-7fa1-11e8-83d3-8d7670c5c65d.png) - Concurrency and offline snapshot option status will now be displayed as "notes" on the backup NG view, for better convenience ![concurrency](https://user-images.githubusercontent.com/21563339/42318257-b8f57d98-804e-11e8-9b17-cef120e2bd6a.png) - When reverting a VM, you will now be notified of the result ![revertnotification](https://user-images.githubusercontent.com/21563339/42369381-0caf30f8-810a-11e8-9f75-9bd37a46a0e7.png) - You can now select fast clone as an option when creating a VM ![fastclonevm](https://xen-orchestra.com/blog/content/images/2018/07/fastclonevm.jpg) [![sign-up-1000x300](https://xen-orchestra.com/blog/content/images/2018/07/sign-up-1000x300.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup?pk%5Fcampaign=blogbanner) ### Full stack power URL: https://xen-orchestra.com/blog/full-stack-power/ Last updated: 2018-08-06T08:36:43.000Z This is the story on a epic bug hunt. Our XCP-ng knowledge demonstrates that we could solve a nasty XenServer regression that critically impacted Xen Orchestra backups. And this was solved in a very short time frame. When you are able to master the full stack, from the hypervisor to the backup solution, no issue can stand against XCP-ng+XOA combo! > Update: we validated a "definitive" fix with Citrix devs, and it's now merged! ## VDI I/O error It all started with more and more people complaining about `VDI I/O Error` when doing backups with Xen Orchestra. The common thing between all those people was XenServer 7.5\. But we couldn't reproduce it easily in our lab. So we started digging to understand what could be the issue, obviously something **introduced in XenServer 7.5**. Immediately, we opened an issue on [Citrix XenServer bug tracker](https://bugs.xenserver.org/browse/XSO-873?ref=xen-orchestra.com). But our needs aren't obviously completely aligned with Citrix, which doesn't seems to do extensive testing on VDI export, used in Xen Orchestra to make backups. That's why we couldn't wait weeks or months to get a resolution. We had to investigate ourselves. ### Streams First, let's do a quick recap on a backup works. We use NodeJS streams. Basically, we: - fetch the content from a XCP/XS host (input stream) - write the content on the "remote", eg NFS share (output stream). As you can imagine, sometimes, the "remote" can be slower than the content export. In this case, there is what's called **backpressure**. Here is an exemple of a bottleneck in the middle: ![nodestreams](https://xen-orchestra.com/blog/content/images/2018/07/nodestreams.png) Basically, this can cause Xen Orchestra **to pause fetching data on XenServer**. Which wasn't a problem before. But now, it seems as soon the data is not fetched for few seconds, it stops the export with a `VDI I/O error`. And you got a failed backup job. ### First idea: XO workaround We tried to implement a workaround in Xen Orchestra, but it was overcomplicated and despite [it working](https://github.com/vatesfr/xen-orchestra/issues/3205?ref=xen-orchestra.com) for some people, it wasn't the case [for everyone](https://github.com/vatesfr/xen-orchestra/issues/3242?ref=xen-orchestra.com). Indeed, you have to choose between more buffer inside XO during the transfer, but also having potential RAM issues if backupressure never ends. And the side effects could be problematic for previous version of XenServer/XCP. So we had to fix the issue in XenServer/XCP-ng directly! ## Investigating vhd-tool In XenServer/XCP, the library the do the HTTP handler for exporting VHD data is `vhd-tool`. So, since 7.4 was released, we examined each commit on GitHub, to find a potential culprit. And a commit caught our attention: [Catch EAGAIN from sendfile and retry ](https://github.com/djs55/vhd-tool/commit/1ec2644866294bae907e53094796b678e8c6306d?diff=unified&ref=xen-orchestra.com). `EAGAIN`? Sounds familiar. After rechecking the `/var/log/xensource.log`, we found this: ``` VDI Export R:24d4f0381f9c|vhd_tool_wrapper] vhd-tool failed, returning VDI_IO_ERROR VDI Export R:24d4f0381f9c|vhd_tool_wrapper] vhd-tool output: vhd-tool: internal error, uncaught exception: Unix.Unix_error(Unix.EAGAIN, "sendfile", "") Raised at file "src/core/lwt.ml", line 3008, characters 20-29 Called from file "src/unix/lwt_main.ml", line 42, characters 8-18 Called from file "src/impl.ml", line 811, characters 4-23 Called from file "src/cmdliner_term.ml", line 27, characters 19-24 Called from file "src/cmdliner.ml", line 27, characters 27-34 Called from file "src/cmdliner.ml", line 106, characters 32-39 ``` Basically, the new code will try 20 times if `EAGAIN` is triggered (a system call telling "we couldn't write now"), waiting 100ms every loop, which is 2 seconds tops. Then failing with `VDI I/O error`. Obviously, this is **not enough** is a lot of cases, eg a busy network or a slow NFS share where you store your backups. ## A quick but working fix So the idea was to make a test by [raising considerably](https://github.com/xapi-project/vhd-tool/pull/68?ref=xen-orchestra.com) the number of tries before giving up: ![ghfix](https://xen-orchestra.com/blog/content/images/2018/07/ghfix.png) > We offered the solution direclty to Citrix via GitHub, helping them to get a fix very quickly without even having to do it. The Pull request can be improved if necessary. We hope they could push a fix quickly into XenServer. Because we know how to build packages for XS/XCP-ng, we were able to build a new VHD-tool RPM package and deploy it on our XCP-ng 7.5 RC1 hosts. Guess what? **It worked perfectly**, even of very slow NFS share, even by shutting down NFS for few seconds, and bringing back online then. We decided to **include the fixed VHD-tool version** directly in XCP-ng 7.5, this way people won't have to wait to get Xen Orchestra backup to work again. The fix is not very elegant, but it's harmless, so we'll continue to assist Citrix if they want to implement a better solution. ## Update: final fix Good news! We validated a "definitive" fix with Citrix devs. It's far more elegant: ![definitivefix](https://xen-orchestra.com/blog/content/images/2018/08/definitivefix.png) This fix removed the need of `sleep` in the loop, and the PR is now merged! This improved version is also already in XCP-ng 7.5 :) #### XCP-ng 7.5 Release Candidate Want to test our latest XCP-ng 7.5? It's available now as a first release candidate, [see the post on our forum!](https://xcp-ng.org/forum/topic/241/xcp-ng-7-5-0-release-candidate?ref=xen-orchestra.com) and our blog post announcement. It's not just embedding our `VDI I/O error` fix, but also ZFS experimental support and much more! ![](https://xcp-ng.org/wp-content/uploads/2018/04/logo1glossy.png) ### Xen 4.11 is available URL: https://xen-orchestra.com/blog/xen-4-11-is-available/ Last updated: 2018-07-13T10:08:05.000Z Xen Hypervisor 4.11 is now available, after 1206 commits from 406 patches. What's inside? The full official [Xen blog post can be read here](https://blog.xenproject.org/2018/07/10/whats-new-in-the-xen-project-hypervisor-4-11/?ref=xen-orchestra.com). ### Increased security You're probably aware of the Meltdown and Spectre vulnerabilities. Xen 4.11 was focused on finding solutions to mitigate them. "XPTI" and "Branch Predictor Hardening" are the main solutions implemented in this release. ### PVH PVH is a virtualization mode that offers the best of both "HVM" and "PV" modes. This is not new, but it's not straightforward to develop. Xen 4.11 adds PVH support for Dom0, although it's experimental. However it's going in the right direction, and we should see even more support in future releases. In short PVH is faster, lightweight, and removes some dependencies (QEMU), therefore reducing the attack surface. ### Misc Various optimizations have been added for the CPU scheduler, along with more instruction support (AVX2…) and some ARM stuff. ![Xen-Panda-Summit-500px](https://xen-orchestra.com/blog/content/images/2018/07/Xen-Panda-Summit-500px.png) [![sign-up-1000x300](https://xen-orchestra.com/blog/content/images/2018/07/sign-up-1000x300.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup?pk%5Fcampaign=blogbanner) ### Xen Orchestra 5.21 URL: https://xen-orchestra.com/blog/xen-orchestra-5-21/ Last updated: 2018-07-02T12:46:55.000Z Summer is in the place and our Xen Orchestra monthly update has landed with many enhancements and fixes! ## XCP-ng pro support For those who are already using XCP-ng in production, note that it's now possible to subscribe to pro support for XCP-ng. Pricing is easy to understand: per host and per year subscription. You can find all the details you need, as well as ask for a quote on the [dedicated website](https://xcp-ng.com/?ref=xen-orchestra.com). A new release for XCP-ng should be available soon! [![logo300x300](https://xen-orchestra.com/blog/content/images/2018/06/logo300x300.png)](https://xcp-ng.com/?ref=xen-orchestra.com) ## Backup NG improvements ### Better display during export When a Delta Backup or a Continuous Replication job is running, Xen Orchestra will now display the type of backup during the export (full or delta). ![delta-display](https://xen-orchestra.com/blog/content/images/2018/06/delta-display.jpg) ### Different backup/replication retention settings With Backup NG you have the ability to create multiple backup types in a single job. You can create a Delta Backup task and a Continuous Replication task within the same job. For these jobs with more than one task, you can now define different retention periods for each task within the job. > *Eg. Continuous Replication is usually designed to recover as fast as possible, with minimum data loss. This kind of use case does not require a long retention period (1 may be enough).* > *On the opposite side, you may want to secure your infrastructure for a longer period of time with a delta backup job and always keep 7 days of rentention.* ### Enable/Disable scheduled job It's now possible to enable or disable a scheduled backup job in the backup view. ![enable-disable-scheduled-job](https://xen-orchestra.com/blog/content/images/2018/06/enable-disable-scheduled-job.png) ### Offline snapshot Sometimes it's better to create a snapshot while the VM is offline (eg. to prevent broken VSS or a broken Active Directory due to VSS). In the advanced settings view, you have now an option to activate offline snapshot. ![offline-snapshot](https://xen-orchestra.com/blog/content/images/2018/06/offline-snapshot.png) ### Health view In Backup NG, the new health view will display the list of snapshots related to backup jobs that are not used anymore (eg. the backup job no longer exists). You will also have a section related to the legacy backup snapshots. Once you have migrated your legacy job to backup NG, you can delete all the old snapshots from this view in a few clicks. > ⚠ You should delete the snapshots related to legacy backup jobs AFTER having migrated your job to the backup NG. ![legacy-backup-snap](https://xen-orchestra.com/blog/content/images/2018/06/legacy-backup-snap.png) ## Various improvements ### VDI UUID's now copyable You can now copy a VDI's UUID directly from Xen Orchestra. ![copyable-uuid](https://xen-orchestra.com/blog/content/images/2018/06/copyable-uuid.png) ### Use fast-clone to create a VM from a snapshot You can now use the fast clone option to create a VM copy from a snashopt. This process will generate a linked VHD clone disk, which means that the VM created from a template will have its disk linked to the template's disk, resulting in very fast creation. > ⚠ *When done excessively, performance could degrade because this process will create a long linkage tree - use it with caution.* ![fast-clone](https://xen-orchestra.com/blog/content/images/2018/06/fast-clone.png) ### Cloud config templates You can now create templates, using customized cloud configs you use on a regular basis. You can access the cloud config manager in the Settings > Cloud Configs menu and start creating your templates. ![cloud-config](https://xen-orchestra.com/blog/content/images/2018/06/cloud-config.jpg) ![customize-cloud-template_4](https://xen-orchestra.com/blog/content/images/2018/06/customize-cloud-template_4.jpg) When creating a VM with a cloud ready template, you will now have the ability to select a cloud config template. ![vm-creation-customize-cloud-config_1](https://xen-orchestra.com/blog/content/images/2018/06/vm-creation-customize-cloud-config_1.png) [![sign-up-1000x300](https://xen-orchestra.com/blog/content/images/2018/07/sign-up-1000x300.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup?pk%5Fcampaign=blogbanner) ### From Backup Legacy to Backup NG URL: https://xen-orchestra.com/blog/migrate-backup-to-backup-ng/ Last updated: 2018-07-02T12:51:57.000Z As you might have noticed in the last couple of months, we've been working on a new generation of backup features in Xen Orchestra. Backup NG is better, faster, stronger and more reliable than our legacy backup system. Everything has been rebuilt from scratch to offer a better experience to all users, from small infrastructure to big datacenters running on XenServer or XCP-ng. As the old Backup system is now deprecated, you cannot create jobs in the Backup view in XO anymore, all new jobs need to be created through the Backup NG panel. The jobs previously created will still run as scheduled and you can still edit them - however, it's highly recommended to migrate your legacy jobs to the new Backup NG panel. This blog post will help guide you through the process. ## Backup NG is only one click away The first step is actually very simple to achieve. 1. Select the job you want to migrate in the backup legacy view 2. Click on the "migrate to backup NG" button That's it, your job has been moved to the Backup NG panel and should be running as scheduled previously. ![backup-migrate-legacy-to-NG.png](https://xen-orchestra.com/blog/content/images/2018/06/backup-migrate-legacy-to-NG.png.jpg) ## Removing the old snapshot(s) > Note : If the job you migrated was a full backup job, you can skip this step. The Xen Orchestra backup system creates a snapshot per VM during the backup process. When you are migrating your job, backup NG will create a new snapshot and use it as a base snapshot. Consequently, the old snapshots related to your old backup jobs are no longer required and need to be deleted, to avoid consuming space on your SR. There are two ways to get rid of the old snapshots - you can do it manually, VM after VM or you can use the health view available in the backup NG panel. ### Health View in Backup NG All the snapshots related to old backup jobs are listed in the health view in backup NG. Once you have done the migration of your legacy jobs, you can select all of them and delete them. ![](https://xen-orchestra.com/content/images/2018/06/legacy-backup-snap.png) ### Manually You can also manually delete the snapshots by looking for it on each VM. - For **Continuous Replication** jobs you need to search and delete snapshots starting with `XO_DELTA_EXPORT` - For **Delta Backup** jobs you need to search and delete snapshots starting with `XO_DELTA_BASE_VM_SNAPSHOT` - For **Rolling snapshot**, you need to search and delete snapshots starting with `Rollingsnapshot_` ![xo-snapshot-backup](https://xen-orchestra.com/blog/content/images/2018/06/xo-snapshot-backup.png) ## Delete the old backup files > Note: Proceed with this step once you are sure that you won't need to restore a VM using an old backup file, eg: you have a new backup file via a Backup-NG job. When you are sure that everything is working fine for your new backup jobs, the last step is to clean your remote storage on which you were sending the backup. > With the old backup system - you could not remove a file on the remote from the Xen Orchestra interface, however it's now possible with Backup NG jobs. For this step, you will need to manually connect to your remote and delete the file(s) related to your old backup jobs. > ⚠ **Do not touch the directory named `xo-vm-backups` \- it contains everything related to the Backup NG jobs. If you want to delete one of the files here, use the XO interface to do so.** ### Discover Xen Orchestra You didn't know that Xen Orchestra provides a complete features panel for XenServer VM backups (or XCP-ng)? [Sign-up and try Xen Orchestra for free](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup)! [![XO-logo-name](https://xen-orchestra.com/blog/content/images/2018/06/XO-logo-name.png) ](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xo-home) [![sign-up-1000x300](https://xen-orchestra.com/blog/content/images/2018/07/sign-up-1000x300.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup?pk%5Fcampaign=blogbanner) ### Xen Orchestra 5.20 URL: https://xen-orchestra.com/blog/xen-orchestra-5-20/ Last updated: 2018-05-31T19:13:19.000Z Our monthly release is here, with a bunch of new features and bug fixes. Time to update and discover what's new! ## XCP-ng updates Xen Orchestra is now able to update your [XCP-ng hosts](https://xcp-ng.org/?ref=xen-orchestra.com) directly from the UI! This is a major improvement in XCP-ng usability, without sacrificing our promise to move closer to the upstream: we still rely on `yum` like any other CentOS, but we can now also do that from XO! [![](https://xen-orchestra.com/content/images/2018/05/hostpatches2.png)](https://xen-orchestra.com/blog/blog/xcp-ng-updates-from-xen-orchestra/) [Read our blog post](https://xen-orchestra.com/blog/blog/xcp-ng-updates-from-xen-orchestra/) to learn how it works. ## UI improvements ### Better usage reports Usage reports now filter useless objects and more clearly display the evolution of each resource (host CPU, RAM, etc.) ![reports](https://xen-orchestra.com/blog/content/images/2018/05/reports.png) ### List useless VM snapshots When you remove a backup job, the snapshots associated aren't removed. To avoid a long hunt of those useless snapshots, we are now able to detect them automatically in the "Health view", so you can remove them in one click! ### HA advanced options You can now configure the XCP-ng/XenServer HA behavior for each VM: "restart", "restart if possible" and "disable". For more details, please [read the documentation on HA](https://docs.citrix.com/de-de/xencenter/6-1/xs-xc-protection/xs-xc-pools-ha/xs-xc-pools-ha-restartsettings.html?ref=xen-orchestra.com). ### Show control domain in VDI list We now display the Control Domain if a VDI is attached to it. This is helpful to understand what's happening on your storage. ### Set a remote syslog host You can now set a remote syslog host directly from the UI: ![rsyslog](https://xen-orchestra.com/blog/content/images/2018/05/rsyslog.png) This feature is really useful when you want to centralize all your hosts logs somewhere, for various reasons: - compliance - security - log analyze/parsing - and more! ## Backup ### Backup concurrency A new option is available: you can decide to have a max concurrency of a backup process **per VM**. For example, you could decide to have maximum of 10 VMs backup in parallel. By default, there is no limit ("0" in the text field) BUT we still enforce maximum values. Please [read our blog post regarding backup concurrency in Xen Orchestra](https://xen-orchestra.com/blog/blog/xen-orchestra-backup-concurrency/). [![concurrency](https://xen-orchestra.com/blog/content/images/2018/05/concurrency.png)](https://xen-orchestra.com/blog/blog/xen-orchestra-backup-concurrency/) ### Improved backup logs A lot more details in the backup logs! Now, each step is individually visible with its duration, current status etc. ![newLogsWeb](https://xen-orchestra.com/blog/content/images/2018/05/newLogsWeb.png) Now, you can know in real time which steps failed (snapshot, transfer, merge) and how long which one succeeded. ### Improved backup reports Same story for backup reports, it's far more detailed: ![newLogsReport](https://xen-orchestra.com/blog/content/images/2018/05/newLogsReport.png) ### Retry a single failed VM backup In a job log view, if a VM failed to be backup, you can retry it now. Very handy when it was for a specific reason, like protecting the VDI chain or one failure within hundreds of succeeded VMs: no need to restart the whole job! ### Xen Orchestra backup concurrency URL: https://xen-orchestra.com/blog/xen-orchestra-backup-concurrency/ Last updated: 2018-07-02T12:52:12.000Z Backup concurrency is a vast topic. Since we added new features in XO 5.20 to handle it, we wanted to give a recap on how it works. There are multiple concurrency levels, for a lot of reasons. But first lets explain some basics. ### Backup process #### 1\. Snapshot creation When you do a backup in XCP-ng/XenServer, the first operation performed is to "freeze" the data at a specific time - this is done by **making a snapshot**. This operation is pretty quick, only a few seconds in general. However it uses a lot of I/O on your storage, therefore more I/O activity means longer times to snapshot. Still, the order of magnitude is seconds per VM. #### 2\. Export Xen Orchestra will fetch the content of the snapshot made in step 1\. This operation can be very long, obviously depending on the size of the snapshot to export: exporting 1TiB of data will take far longer than exporting 1GiB! #### 3\. Snapshot removal When it's done exporting, we'll remove the snapshot. Note: this operation will trigger a coalesce on your storage in the near future. ![snapshottime](https://xen-orchestra.com/blog/content/images/2018/05/snapshottime.jpg) ### Concurrency Let's say you want to backup 50 VMs (each with 1x disk) at 3:00 AM. There are **2 different strategies**: 1. backup VM°1 (snapshot, export, delete snapshots) **then** backup VM°2 -> *fully sequential strategy* 2. snapshot all VMs, **then** export all snapshots, **then** delete all snapshots for finished exports -> *fully parallel strategy* The first purely sequential strategy will lead to a big problem: **you can't predict when a snapshot of your data will occur**. Because you can't predict the first VM export time (let's say 3 hours), then your second VM will have its snapshot taken 3 hours later, at 6 AM. We assume that's not what you meant when you specified "backup everything at 3 AM". You would end up with data from 6 AM (and later) for other VMs. Strategy number 2 is better in this aspect: all the snapshots will be taken at 3 AM. However **it's risky without limits**: it means potentially doing 50 snapshots or more at once on the same storage. **Since XenServer doesn't have a queue**, it will try to do all of them at once. This is also prone to race conditions and could cause crashes on your storage. So what's the best choice? Let's dig! ![time](https://xen-orchestra.com/blog/content/images/2018/05/time.jpg) #### Best choice By default the *parallel strategy* is, on paper, the most logical one. But we need to give it some limits on concurrency. > Note: Xen Orchestra can be connected to multiple pools at once. So the concurrency number applies **per pool**. Each step has its own concurrency to fit its requirements: - **snapshot process** needs to be performed with the lowest concurrency possible. 2 is a good compromise: one snapshot is fast, but a stuck snapshot won't block the whole job. That's why a concurrency of 2 is not too bad on your storage. Basically, at 3 AM, we'll do all the VM snapshots needed, 2 at a time. - **disk export process** is bottlenecked by XCP-ng/XenServer - so to get the most of it, you can use up to 12 in parallel. As soon a snapshot is done, the export process will start, until reaching 12 at once. Then as soon as one in those 12 is finished, another one will appear until there is nothing more to export. - **snapshot deletion** can't happen all at once because the previous step durations are random - no need to implement concurrency on this one. This is how it currently works in Xen Orchestra. But sometimes, you also want to have *sequential* backups combined with the *parallel strategy*. That's why we introduced a sequential option in the advanced section of backup-ng: ![advancedconccurrency](https://xen-orchestra.com/blog/content/images/2018/05/advancedconccurrency.png) > Note: 0 means it will be fully **parallel** for all VMs. If you job contains 50 VMs for example, you could specify a sequential backup with a limit of "25 at once" (enter 25 in the concurrency field). This means at 3 AM, we'll do 25 snapshots (2 at a time), then exports. As soon as the first VM backup is completely finished (snapshot removed), then we'll start the 26th and so on, to always keep a max of 25x VM backups going in parallel. [![sign-up-1000x300](https://xen-orchestra.com/blog/content/images/2018/07/sign-up-1000x300.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup?pk%5Fcampaign=blogbanner) ### XenServer 7.5 URL: https://xen-orchestra.com/blog/xenserver-7-5/ Last updated: 2022-06-01T14:41:23.000Z ⚠️ XenServer 7.5 is now End of Life (EOL). You can however [download XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com) instead, providing a 100% compatibility with all features for free. One release per quarter - this is the CR cycle of Citrix. And now the latest release is available: XenServer 7.5! ## What's new? The official changelog [is here](https://docs.citrix.com/content/dam/docs/en-us/xenserver/current-release/downloads/xenserver-release-notes.pdf?ref=xen-orchestra.com), but here is a simple recap. #### Increased pool size You can now run pools with **up to 64 hosts!** That's really good news, it means you can use XOSAN with the same flat per-pool pricing, but with a LOT more hosts/storage in your pools! > XenServer Free is limited to 3 hosts max. You need at least Standard edition to enjoy this. Or [XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com)! #### USB passthrough You can now pass a physical USB device to a VM, as if it was plugged directly into it. This could cause some security questions, but ould probably be handy in certain use cases. > Note: this feature is only available in XenServer Enterprise Edition, or wait for the coming free XCP-ng 7.5 release! #### Networking: SR-IOV This is still experimental, but should allow you to use ultra-fast networking by having multiple VM's "directly" connected to the NIC. Less overhead too. To enable it: `xe-enable-experimental-feature network_sriov` > Note: this feature is only available in XenServer Enterprise Edition, or wait for the coming free XCP-ng 7.5 release! #### Thin provisioning for block storage This is really exciting! This feature has been the big missing piece for years… Good news: you can now have thin provisioning on iSCSI/HBA, with GFS2 technology. Bad news: you need to create a new SR (you can't "convert" an existing iSCSI SR to thin pro), nor can you migrate a VDI from this SR to another type (see "Bonus" section. > Note: this feature is only available in XenServer Enterprise Edition, or wait for the coming free XCP-ng 7.5 release! #### Bonus: qcow2 is here For the new thin pro on block storage (GFS2), you can create VDIs that are 16TiB in size thanks to the use of `qcow2` format. This will trigger some questions (you won't be able to export these in VHD format anymore, as the 2TiB limit is within the VHD format itself). So you won't be able to migrate those 2TiB+ disks to any other SR type than GFS2. ## XCP-ng 7.5 status As soon as we validate the update process, we'll provide a 7.5 release for XCP-ng. As usual you'll have 2 choices: upgrade using the ISO (old way) or save some hassle and just use `yum update`. You can now even upgrade via the XO UI! [See the new yum-based updater inside Xen Orchestra](https://xen-orchestra.com/blog/blog/xcp-ng-updates-from-xen-orchestra/). Stay tuned on the [XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com) website, in the news section! (or subscribe to the newsletter via the same page) [![sign-up-1000x300](https://xen-orchestra.com/blog/content/images/2018/07/sign-up-1000x300.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup?pk%5Fcampaign=blogbanner) ### XCP-ng updates from Xen Orchestra URL: https://xen-orchestra.com/blog/xcp-ng-updates-from-xen-orchestra/ Last updated: 2018-07-02T12:52:23.000Z You may already know: we decided to include a better update mechanism in XCP-ng (vs XenServer). We are using the CentOS method with `yum`. However it would also be interesting to update directly from a UI, and also to avoid updating each host one by one. Guess what? That's why we developed an XAPI (XenServer/XCP-ng API) plugin! You'll see it is now **very** easy to keep all your hosts up-to-date, while also having **more transparency** into what's going on! > This feature is coming in XO 5.20 - available in 2 days! ## Install the plugin The plugin will be included in the next XCP-ng release. Until then, you'll have to install it, with a simple `yum install xcp-ng-updater` command. Yes, that's it! ## Updates via Xen Orchestra Take for example a fresh install of XCP-ng 7.4.1\. Since its release, some patches have been released. First, just go into the Home/Pool view in Xen Orchestra, and you'll see some pools that need updates: ![poolviewupdates](https://xen-orchestra.com/blog/content/images/2018/05/poolviewupdates.png) "XCP Pool" needs to be updated (it's not XenServer but XCP-ng based). You can see clearly that there are 6 updates available. If you click on the pool, you can go into the dedicated view and then the "Patches" tab: ![poolpatches](https://xen-orchestra.com/blog/content/images/2018/05/poolpatches.png) By clicking on "Install pool patches", all your hosts will be updated automatically! But wait, there's more? **You want to know what needs to be updated?** Click on the host, then go into the "Patches" view: ![hostpatches2](https://xen-orchestra.com/blog/content/images/2018/05/hostpatches2.png) You can even see the changelog (here, the only changelog available is for `microcode_ctl`): ![changelog2](https://xen-orchestra.com/blog/content/images/2018/05/changelog2.png) Anyway, as soon as your patches/updates are installed, we'll inform you if the patched hosts need to be rebooted: ![needreboot](https://xen-orchestra.com/blog/content/images/2018/05/needreboot.png) Hovering over it: ![hover](https://xen-orchestra.com/blog/content/images/2018/05/hover.png) Same in the host view, you can't miss it: ![big-inhostview](https://xen-orchestra.com/blog/content/images/2018/05/big-inhostview.png) > Note: It's up to you to reboot anytime you like (always start with the pool master by the way). Updating **won't reboot anything automatically**. You are the admin, you know when it's the best time to do so. If you don't have the plugin installed, you'll see a message explaining how to do so: ![installplugin](https://xen-orchestra.com/blog/content/images/2018/05/installplugin.png) In the end updating XCP-ng is very simple, and still follows the "upstream" way: using `yum` and a repository. This is the proof that it's possible to achieve! [![sign-up-1000x300](https://xen-orchestra.com/blog/content/images/2018/07/sign-up-1000x300.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup?pk%5Fcampaign=blogbanner) ### XOA without commitment URL: https://xen-orchestra.com/blog/xen-orchestra-without-commitment/ Last updated: 2018-10-03T12:28:42.000Z Since a while now, we wanted to change our policy regarding the commitment period in Xen Orchestra. It's now live! ## No more commitment! Xen Orchestra has always been a yearly subscription with a **1 year of commitment period**. However, we also offer an ease of payment, via a monthly payment by credit card. It seems unclear to some users that the monthly payment was subject to the same commitment period than the yearly one. From time to time, some users also expressed their will to get a plan for a shorter period of time. That's why we have decided to get rid of the commitment period in Xen Orchestra. It means, that, for all **new user** starting the 16th of May 2018, you can subscribe to Xen Orchestra on a monthly basis - with no commitment. ![Freedom](https://xen-orchestra.com/blog/content/images/2018/05/Freedom.jpg) ## Monthly pricing Consequently, the monthly pricing has evolved. The Starter edition costs now $77 monthly, the Enterprise edition $220 and the Premium edition $550. > Note: if you are already a customer, your current pricing remains the same, nothing changes for you! ## Yearly pricing **Yearly pricing remains unchanged**. Starter is still $840 a year, Enterprise $2400 a year and Premium $6000\. It means that, when you choose to subscribe on a yearly basis, you will **save 10% on the total price**. In addition, you can also benefits from **one month for free** if you choose to subscribe for two years, and **2 months for free** if you subscribe for three years. Last but not least, Xen Orchestra is still (and will remain) a **flat rate product**, which means that you can have as many hosts, sockets or VMs as you want without any change in the pricing! ### Xen Orchestra 5.19 URL: https://xen-orchestra.com/blog/xen-orchestra-5-19/ Last updated: 2018-05-01T15:33:25.000Z New month, new release! And right on time with [latest XCP-ng too](https://xcp-ng.org/2018/05/01/xcp-ng-7-4-1/?ref=xen-orchestra.com). This release is relatively important, with new features available from UI and improvements in backup-ng. ## Backup-ng It's now compatible with reports plugins, allowing to get notified about your backup status, by email, Slack or XMPP. Logs are also vastly improved to provide more information on the backup process (each step will be visible in the end, from snapshot to merge process). This is very important because it means we'll be able to have more fine grained details on which steps is longer and improve those specifically. Finally, we also made file level restore working for backup-ng! ## New features ### SR statistics You can now monitor your SR performance directly from XO UI: ![srperfsstats](https://xen-orchestra.com/blog/content/images/2018/04/srperfsstats.png) You have various metrics, like: - IOPS (input/output per second, in read and write) - IO throughput (in read and write) - latency (in read and write) - IOwait (in %) ### Perf alert for disk space Since this year, you can monitor your [XenServer or XCP-ng infrastructure with various alerts](https://xen-orchestra.com/blog/blog/xenserver-performance-alerts/). We added a new alert for storage repository used space. It's trivial to setup in your perf alert plugin: ![perfalertplugin](https://xen-orchestra.com/blog/content/images/2018/04/perfalertplugin.png) Here is the result in your inbox: ![perfalertresult2](https://xen-orchestra.com/blog/content/images/2018/04/perfalertresult2.png) ![perfalertresult1](https://xen-orchestra.com/blog/content/images/2018/04/perfalertresult1.png) ### HBA SR creation You can now create a new SR of "HBA" type: ![newhba](https://xen-orchestra.com/blog/content/images/2018/04/newhba.png) ### New VDI from SR view In the SR view, you can directly create a new VDI/disk: ![newvdifromsrview](https://xen-orchestra.com/blog/content/images/2018/04/newvdifromsrview.png) ### Exposing Xen tools version Because it's not possible to really know if tools are up to date or not, we decided to display their version number in advanced VM view anyway: ![toolsversion](https://xen-orchestra.com/blog/content/images/2018/04/toolsversion.png) ### Windows Update tools management This new setting will allow you to enable automatic tools update for Windows VMs. This feature is available in **XenServer Enterprise** (with a paid license) or for free in **XCP-ng**. Just turn on the feature for your VM, and you'll see Windows Update giving you tools to install as an update: ![toolswinupdate](https://xen-orchestra.com/blog/content/images/2018/04/toolswinupdate.png) ![pvdevices](https://xen-orchestra.com/blog/content/images/2018/04/pvdevices.png) ### Sort VMs by hosts You can now simply sort VM by "containers" (container could be either the host or the pool where is the VM). ## XCP-ng+XOA = full stack solution Now XCP-ng is more and more mature, we'll be able to deliver pro support on both products in one offer. Want to stay tuned about this? [Keep and eye there](https://xcp-ng.com/?ref=xen-orchestra.com) and register. ![](https://xcp-ng.org/wp-content/uploads/2018/04/logo1glossy-1.png) ### XCP-ng first release landed URL: https://xen-orchestra.com/blog/xcp-ng-first-release/ Last updated: 2018-07-02T12:52:35.000Z For those who missed it, the first XCP-ng release is now available! And it landed in the exact same day than XO 5.18, exactly in the Q1 objective. **First things first: Xen Orchestra is 100% compatible with XCP-ng!** ## Install XCP-ng To install it, please jump to the "Install procedure" paragraph in the [XCP-ng release blog post](https://xcp-ng.github.io/news/2018/03/31/first-xcp-ng-release.html?ref=xen-orchestra.com). It's really similar to XenServer install: - [download the ISO](https://xcp-ng.github.io/news/2018/03/31/first-xcp-ng-release.html?ref=xen-orchestra.com) - burn it or copy it into an USB key (eg `dd if=XCP-ng_7.4.iso of=/dev/sdX bs=8M status=progress oflag=direct`) - install it! ![](https://xcp-ng.github.io/assets/images/xcpinstall/install1.png) ## Use Xen Orchestra with XCP-ng If you already have XOA, just go into your Settings/server view, and add the IP of your XCP-ng pool master: ![](https://xcp-ng.github.io/assets/images/connectxo.png) That's it! ![](https://xcp-ng.github.io/assets/images/xoxcpng.png) And XCP-ng **all features are enabled**, even those [lost since XenServer 7.3 release](https://xen-orchestra.com/blog/blog/xenserver-7-3/). [![sign-up-1000x300](https://xen-orchestra.com/blog/content/images/2018/07/sign-up-1000x300.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup?pk%5Fcampaign=blogbanner) ### Xen Orchestra 5.18 URL: https://xen-orchestra.com/blog/xen-orchestra-5-18/ Last updated: 2018-03-31T14:30:43.000Z This is a relatively big new release: massive improvement in Backup-ng, but not only. Discover what's new! ## Backup Backup is still a priority for us. That's why, since we started to redesign it, we are pushing new exciting features. ### Workers NodeJS is by design working on a single process (due to the event loop). That's perfect for high I/O, but could be a bottle neck for some CPU intensive tasks. **That's why backup-ng is now able to merge VHD in a separate worker** (process). Number of worker spawned is equal to the number of XOA vCPUs - 1 (1 vCPU left for main process). In the end, your XOA will deliver faster delta backup! > Note this is just a start, more "features" will live in a worker in the future. It means more performances with more vCPUs usage! ![nodeeventloop-1](https://xen-orchestra.com/blog/content/images/2018/03/nodeeventloop-1.jpeg) ### Existing backup management You can now remove an existing backup directly in the UI for backup-ng! **Even if you use a delta and remove an entry in the middle of the chain**, we'll automatically merge to the previous delta and then destroy the file. ![removebackup-1](https://xen-orchestra.com/blog/content/images/2018/03/removebackup-1.png) ### Synthetic restore Also in backup-ng, restoring a delta is now a LOT faster. Let's imagine you have a daily delta backup, with a retention of 14\. Before our change, restoring the latest backup will require to: 1. Restore the full 2. Apply all the delta, from the oldest to the most recent one, 13 times! **With our synthetic restore, it will "recreate" in live the correct backup and send only the right data, at once**! ![restore_backup](https://xen-orchestra.com/blog/content/images/2018/03/restore_backup.png) ### Multi-schedule Still in backup-ng, you can add more schedule per job (ie: daily and weekly schedule for the same job). ![](https://xen-orchestra.com/content/images/2018/02/multischedule.jpg) ### Updater checks If you **try to update while a backup job is running, you'll be notified** (and you can chose what to do). This is something we wanted to do a long time ago, but this was possible recently because of the backend improvements. ### Job migrate to backup-ng You can migrate your "legacy" backup job to backup-ng with a new icon: ![migrate1](https://xen-orchestra.com/blog/content/images/2018/03/migrate1.png) ![migrate2](https://xen-orchestra.com/blog/content/images/2018/03/migrate2.png) > Note: this doesn't actually move the existing legacy backup files on the remote. Backup-ng will use a new folder in the remote to put all the new files. So it's up to you to decide to keep them or remove those old files. ### Improved smart backup You can now specify both tags to include AND tags to exclude in your smart backup: ![tagsexcludesincludes](https://xen-orchestra.com/blog/content/images/2018/03/tagsexcludesincludes.png) ## Extended usage report Usage report originally reported the Top 3 SRs/VMs/Hosts usage. You can now activate the "extended" report option, to export also the list of **all resources**, and their evolution since the latest report! ![Hosts-stats.png](https://xen-orchestra.com/blog/content/images/2018/03/Hosts-stats.png.jpg) ## UI improvements ### Memory usage Memory display is now improved for host view, and more coherent with pool view: ![](https://user-images.githubusercontent.com/1241401/37522430-27c29094-2924-11e8-9834-2e63cb9bc71b.png) Pool: ![](https://user-images.githubusercontent.com/1241401/37522431-27db49ea-2924-11e8-9025-286f6dcda709.png) ### Home view - Sort criteria is now stored in the URL, eg `http://xoa.example.net/#/home?s=power_state%3Arunning+&sortBy=memory.size` will sort bigger VM in RAM first. - Always show the toolbar in the home view, even when you scroll down (usefule on smaller screens): ![scroll](https://xen-orchestra.com/blog/content/images/2018/03/scroll.png) ## What's next? We are currently redesigning the logs to allow more information (and even steps!), for example on backup. This also will lead to have backup-ng compatible with backup report. This should come very soon,at worst for next release, probably a bit before in a patch release. Another overhaul is in progress: the stats management. It will be more optimized and also lead to display SR stats (IOPS etc.) Finally, we'll continue to "break down" the backend into smaller pieces (workers) to improve the performance and reactivity, especially for larger infrastructures. ## XCP-ng Don't miss the [latest news about it](https://xcp-ng.github.io/news/2018/03/31/first-xcp-ng-release.html?ref=xen-orchestra.com): it's now available! [![xcpsmall](https://xen-orchestra.com/blog/content/images/2018/03/xcpsmall.png)](https://xcp-ng.github.io/news/2018/03/31/first-xcp-ng-release.html?ref=xen-orchestra.com) ### Xen Orchestra 5.17 URL: https://xen-orchestra.com/blog/xen-orchestra-5-17/ Last updated: 2018-03-03T00:04:10.000Z Here it comes! This release is officially the first milestone in our improved backup process. For a LOT of reasons. > Note: the new UI for backup-ng is still incomplete. But next patch release ([and your feedback!](https://github.com/vatesfr/xen-orchestra/issues/2711?ref=xen-orchestra.com)) will improve this in the next weeks! ## Backup-ng Because we made a full rewrite of backup code, we decided to keep the "legacy" at the same place, and to add a brand new UI in parallel. This way, you can test the new backup features on new jobs, without fearing for your previous/existing schedules. To test and use our new backup code, just go into the new Backup-ng menu! ![backupngmenu](https://xen-orchestra.com/blog/content/images/2018/03/backupngmenu.png) The list of new possibilities is so long that we created a dedicated blog post. So if you want to discover all the new features, go [read our previous blog post on all the new XenServer backup possibilities!](https://xen-orchestra.com/blog/blog/better-faster-and-stronger-backups/) In short: - multi-remote jobs - multi-schedule jobs - faster exports - faster merge (works also for legacy backup code!) - more resilient process - better logs - smart backup preview [![](https://xen-orchestra.com/content/images/2018/02/newbackup.png)](https://xen-orchestra.com/blog/blog/better-faster-and-stronger-backups/) ## New filters! You can use the search field/filter with number comparison, eg to display only VMs with more than 2 snapshots: ``` snapshots:length:>2 ``` Or maybe VMs with more 4 or more disks attached? ``` $VBDs:length:>=4 ``` Same concept for the number of network interfaces: ``` VIFs:length:>=2 ``` > You can also filter on memory, but it's not optimal for now: eg `memory:dynamic:1:<1073741824` will filter to all VMs with less than 1GiB or dynamic max memory! ## Self-service share You can now share an existing VM into a self-service: this will make this VM accessible from all member of the resource set. ## Disconnect VDIs You can now disconnect or "forget" VDIs to their VMs directly from the SR view: ![disconnectVDI](https://xen-orchestra.com/blog/content/images/2018/03/disconnectVDI.png) ### Better, faster and stronger backups URL: https://xen-orchestra.com/blog/better-faster-and-stronger-backups/ Last updated: 2018-07-02T12:52:45.000Z After spending some times on improving backup code, we'll deliver it for 5.17 version (next Friday!). Changes are very important and lay the foundation of exciting new features. Let's see why it's a big leap ahead! # Better 👑 "Better" here means more new features! We got a new UI to make a backup. You'll start now by choosing which VM to backup, then where, and finally how. ## Multi-remote In the step of choosing the destination of your backup, you'll have 2 possibilities: - a remote (a place to store your backup, NFS/SMB/local) - a SR (storage repository), to make Disaster Recovery or Continuous Replication But you can select **BOTH** and do for example, a **delta backup** to store it AND a **continous replication** at once (or both basic backup and disaster recovery). ![newbackup](https://xen-orchestra.com/blog/content/images/2018/02/newbackup.png) So, with one snapshot on the VM, data will be sent both in your remote and on the target XenServer storage. Yes, **at once!** That's not it! You can also select multiple remotes (let's imagine "backup site A" and "backup site B")… or both multiple remotes and multiple SR in the same job. No excuses, your backups can be stored everywhere without anything more than two clicks :) > Obviously, data flowing through XOA can't be kept in memory, so due to "back pressure", backup speed can't be faster than the slowest destination (remote or SR). ## Multi-schedule In one job, you can choose to make the backup at various schedules. For example, you can now do, in the same one job, those schedules: - a daily backup (at 3AM) - a weekly backup (Sunday, at 6AM) - a monthly backup (Friday at 1AM) ![multischedule](https://xen-orchestra.com/blog/content/images/2018/02/multischedule.jpg) ## Cancelable It's now possible to cancel a backup, for whatever reason. Also, a timeout will automatically cancel it for real (it wasn't the case before). # Faster 🚀 ## Concurrency We have now a fine-grained concurrency management. It means we selected the best action to do in parallel, depending the type of backup you do. Let's see the changes made for delta backup! ## Delta backup concurrency You can do multiple things at once, but you need to be careful. ### VDI exports XenServer VDI export is not ultra fast: in fact, it's a big bottleneck. Basically, on a 1Gbit/s link, exporting one VDI in VHD format is around 30MiB/s. Pretty slow, right? But does it scale? If you export more VDI at once? Here is a graph, with the average VDI export speed (per VDI) and the total export speed: ![exportvdi](https://xen-orchestra.com/blog/content/images/2018/02/exportvdi.png) Exporting 1x VDI at +30MiB/s, but 2x at 20MiB/s each! It means you can double the total export speed just by using a concurreny at 2. We can continue to scale and see that more VDI we export at once, more the total export speed is high. That's why we extended the VDI export concurrency limit to 12 per pool (doing more isn't really faster). ### Snapshots concurrency On the other hand, doing multiple snapshots at once seems to cause issues in XenServer (probably "race conditions" related). So we decided to limit snapshot concurrency to… 1! This helps to get rid of XenServer race condition, without impacting backup speed in the end. ## Delta merge process If you know about continuous delta backup, you know that Xen Orchestra need to merge the oldest delta into the initial full, when the retention number is reached. And it was slow! On an NFS share, it was around 15MiB/s max on our test setup, due to a lot of open/close on the VHD file. Indeed, on a network filesystem, a lot of open/close cost a LOT due to latency. So we decided to make one `open()` at the start, and one `close()` call at the end. Check the result on the merge speed: ![newmergespeed](https://xen-orchestra.com/blog/content/images/2018/02/newmergespeed.png) That's right: almost 60MiB/s, which is 4 times faster than before! # Stronger 👊 The hard part of doing a backup workflow, is when something doesn't work as expected. We improved overall resiliency. For example, you should be able to adapt/fix automatically those potential situations during a backup: - host reboot - toolstack restart - XOA reboot/restart - network loss - reference snapshot removal (delta backup) - merge failure (delta backup) That's why we spent a lot of time dealing with the maximum number of issues. Now, we are able to detect the majority of problems and fail correctly (removing failed snapshots and/or temp file on the remote). Also, logs are reporting "Interrupted" jobs correctly (it doesn't stay on "Pending" state): ![interruptedbackup](https://xen-orchestra.com/blog/content/images/2018/02/interruptedbackup.png) # Just a start 💡 And this is just a start. We'll continue to improve backup incrementally, from these solid foundations. Expect more and more cool features in the next months, still with those 3 words in mind: **faster, better, stronger!** [![sign-up-1000x300](https://xen-orchestra.com/blog/content/images/2018/07/sign-up-1000x300.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup?pk%5Fcampaign=blogbanner) ### Upgrade to XenServer 7.4 URL: https://xen-orchestra.com/blog/upgrade-to-xenserver-7-4/ Last updated: 2018-07-02T12:52:59.000Z XenServer 7.4 [is now available](https://xen-orchestra.com/blog/blog/xenserver-7-4/). Let's see how to upgrade (or update!) it. > Some free features **are removed since 7.3**. Please [read this](https://xen-orchestra.com/blog/blog/xenserver-7-3/) before upgrading. **Xen Orchestra is 100% compatible with XenServer 7.4!** ## From XenServer 7.3 If you are running XenServer 7.2, the process will be only an **update**, not an upgrade. > WARNING: whatever solution you use (XO or xe), the update process takes a while (15min+ per host), because there is a lot of RPMs packages to upgrade in this pack. **DO NOT RESTART TOOLSTACK OR HOSTS DURING THE PROCESS.** ### Via Xen Orchestra Download the pack [here](https://www.citrix.com/downloads/xenserver/product-software/xenserver-74-free-edition.html?ref=xen-orchestra.com) (Update ISO) and save it on your PC. Go into the Home/pool view and select the pool you want to update: ![pools-view](https://xen-orchestra.com/blog/content/images/2017/12/pools-view.png) Go into the "Advanced" tab and click on "Browse file" in the "Install supplemental pack on every host", then select the file you downloaded earlier: ![uploadpack](https://xen-orchestra.com/blog/content/images/2017/12/uploadpack.png) Now, you have to wait for a while. See the "Monitor update process" section below to see what's happening on your host. While there is a update task in the "Task" view, DO NOT reboot or restart toolstack on your host: ![tasks](https://xen-orchestra.com/blog/content/images/2017/12/tasks.png) When there is no `pool_update.apply` task left, you can reboot the hosts to have all updates validated. You can do it later, but it's recommended to do it ASAP. ### Via XE cli You need to download the update "pack". You can do it directly from your pool master. Grab it from itrix website, copy it on your pool master. Then, still on your pool master, you can upload the update on the storage of your choice (even not shared): ``` $ xe update-upload file-name=XenServer-7.4.0-update.iso sr-uuid= ``` This will return the patch UUID. Keep it in your pastebin. Now, we'll apply the update on all hosts ``` $ xe update-pool-apply uuid= ``` Finally, keep in mind this command can take up to half an hour. #### Monitor update process Because it's very long, it could be hard to tell what's going on. But you can actually check what's happening: ``` # tail -f /var/log/yum.log Dec 15 12:59:37 Updated: vendor-update-keys-1.3.3-2.noarch Dec 15 12:59:38 Updated: bugtool-conn-tests-1.1.7-1.noarch Dec 15 12:59:39 Installed: update-XS73-1.0-1.noarch Dec 15 13:01:17 Erased: control-XS72E012-1.0-1.noarch Dec 15 13:01:18 Erased: update-XS72E012-1.0-1.noarch Dec 15 13:01:19 Erased: control-XS72E010-1.0-1.noarch Dec 15 13:01:20 Erased: control-XS72E005-1.0-1.noarch Dec 15 13:01:20 Erased: update-XS72E005-1.0-1.noarch Dec 15 13:01:23 Erased: kpatch-modules-0.3.2-4.x86_64 Dec 15 13:01:23 Erased: kpatch-4.4.0+10-modules-0.3.2-4.x86_64 ``` ## From older XenServer This is the standard upgrade procedure. You can upgrade your previous XenServer version directly to 7.4 since XenServer 6.2, 6.5, 7.0, 7.1 and 7.2. If you are using XenServer 7.3, please read the previous section. ### ISO download You can fetch the ISO here: [https://www.citrix.com/downloads/xenserver/product-software/xenserver-74-free-edition.html](https://www.citrix.com/downloads/xenserver/product-software/xenserver-74-free-edition.html?ref=xen-orchestra.com) The ISO can be burn to a CD but see the next section for USB install. ### Install from USB From any Unix/Linux: ``` dd if=XenServer-7.4.0-install-cd.iso of=/dev/sdX bs=8M status=progress oflag=direct ``` Replace `sdX` with the name of your USB key. On Windows, use a dedicated program that can write ISO to USB drives. ## Partitioning It's exactly the same as all previous XenServer 7.x version (see our previous blog post: [upgrade to XenServer 7.1](https://xen-orchestra.com/blog/upgrade-to-xenserver-7-1/#newpartitionscheme)): - / (root) 18GB - /boot/efi 512M - /var/log 4GB - Swap 1GB > Are you upgrading from an older version than XenServer 7.0? Or do you have the old partition scheme? Please [follow instructions in our previous blog post](https://xen-orchestra.com/blog/upgrade-to-xenserver-7/#usingthenewpartitions) to switch to the new one. ## Rolling pool upgrade If you have a pool with multiple hosts, there is some basic rules to follow: **Always upgrade the pool master first**: 1. Migrate VMs from your pool master to slaves 2. Upgrade the pool master 3. Migrate VMs from one slave to the pool master 4. Migrate this slave 5. Etc. > You can always live migrate VMs from an older XenServer to a newer. The opposite IS NOT POSSIBLE. Also, always check to empty your VM CD drives and disable HA during the operation. [![sign-up-1000x300](https://xen-orchestra.com/blog/content/images/2018/07/sign-up-1000x300.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup?pk%5Fcampaign=blogbanner) ### XenServer 7.4 URL: https://xen-orchestra.com/blog/xenserver-7-4/ Last updated: 2022-06-01T14:41:05.000Z ⚠️ XenServer 7.4 is now End of Life (EOL). You can however [download XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com) instead, providing a 100% compatibility with all features for free. A new version of Citrix XenServer is [now available](https://www.citrix.com/blogs/2018/02/27/another-two-firsts-in-gpu-virtualization-announcing-xenserver-7-4/?ref=xen-orchestra.com). So what about this XenServer 7.4 release? Let's see! ## New features? Live vGPU migration seems to be the only big new feature in this Citrix XenServer 7.4\. And it's only for **Enterprise** customers. For more details, see the [feature matrix here](https://www.citrix.com/content/dam/citrix/en%5Fus/documents/product-overview/citrix-xenserver-feature-matrix.pdf?ref=xen-orchestra.com). AMD MxGPU is also officially supported now! ### Under the hood Let's dig a big with a `xl info` command: ``` # xl info host : xenserver-7-4 release : 4.4.0+10 version : #1 SMP Mon Feb 19 10:31:57 UTC 2018 machine : x86_64 nr_cpus : 2 max_cpu_id : 14 nr_nodes : 1 cores_per_socket : 1 threads_per_core : 1 cpu_mhz : 3320 hw_caps : 07cbfbff:f7fa3203:2c100800:00000121:0000000f:009c6fbb:00000000:00000000 virt_caps : total_memory : 4091 free_memory : 3085 sharing_freed_memory : 0 sharing_used_memory : 0 outstanding_claims : 0 free_cpus : 0 xen_major : 4 xen_minor : 7 xen_extra : .4-4.1 xen_version : 4.7.4-4.1 xen_caps : xen-3.0-x86_64 xen-3.0-x86_32p xen_scheduler : credit xen_pagesize : 4096 platform_params : virt_start=0xffff800000000000 xen_changeset : 9a6cc4f5c14b, pq b46900fe4252 xen_commandline : dom0_mem=752M,max:752M watchdog ucode=scan dom0_max_vcpus=2 crashkernel=192M,below=4G console=vga vga=mode-0x0311 cc_compiler : gcc (GCC) 7.2.0 cc_compile_by : mockbuild cc_compile_domain : [unknown] cc_compile_date : Mon Feb 19 10:52:37 UTC 2018 build_id : e27b2d1991e7dffe5968ed95af7cb8cc16fb32dd xend_config_format : 4 ``` In short: - same Dom0 kernel than XenServer 7.3 - Xen in `4.7.4-4.1` vs `4.7.4-3.2` of 7.3 ## Download You can download it here: [https://www.citrix.com/downloads/xenserver/product-software/xenserver-74-free-edition.html](https://www.citrix.com/downloads/xenserver/product-software/xenserver-74-free-edition.html?ref=xen-orchestra.com) > Note: you need a Citrix account to do so. ## What about XCP-ng? It will likely based on XenServer 7.4, and it's still planned for end of Q1! Stay tuned on [http://xcp-ng.github.io](http://xcp-ng.github.io/?ref=xen-orchestra.com)! ![logo1glossy](https://xen-orchestra.com/blog/content/images/2018/02/logo1glossy.png) ### Xen Orchestra 5.16 URL: https://xen-orchestra.com/blog/xen-orchestra-5-16/ Last updated: 2018-01-31T19:04:09.000Z First release of the year. And it's already awesome! > Side news: guess what? XCP-ng, the free/libre alternative to XenServer is [now on Kickstarter!](https://www.kickstarter.com/projects/78495858/xcp-ng?ref=xen-orchestra.com) Read more on the [XCP-ng blog post](https://xcp-ng.github.io/news/2018/01/31/xcp-ng-kickstarter-campaign.html?ref=xen-orchestra.com). ## Performance alert plugin Keep an eye on your infrastructure usage: set CPU or memory limits for your hosts or your VMs, and never stay in the dark on what's happening. And as usual, it's pretty easy to configure! [![](https://xen-orchestra.com/blog/content/images/2018/01/perfsalerts5.png)](https://xen-orchestra.com/blog/blog/xenserver-performance-alerts/) Read more about this feature in our dedicated blog post: [monitor your XenServer with performance alert plugin!](https://xen-orchestra.com/blog/blog/xenserver-performance-alerts/) ## Self-service usage A user of a self-service is now able to see more data on its own usage. Very useful for your dev teams, or your customers! ### Quotas The user is able to see it's quota more easily: no need to create a new VM to see it, the use just has to be into "Dashboard" view to see it: ![userqutoa](https://xen-orchestra.com/blog/content/images/2018/01/userqutoa.png) ### Visualizations But this is also the opportunity to let your users explore their resource usage in depth. Indeed, we added visualizations and stats tabs: ![datavizself](https://xen-orchestra.com/blog/content/images/2018/01/datavizself.png) ### Add virtual interface A self-user can add a new network interface itself, only on the authorized networks: ![self_vif_add](https://xen-orchestra.com/blog/content/images/2018/01/self_vif_add.png) ### Add an existing VM into a self It's been a while people asked for that :) An admin can add an existing VM into a self-service, refreshing the quota to reflect the new usage resources! ![addvmtoself](https://xen-orchestra.com/blog/content/images/2018/01/addvmtoself.png) ## Health view per pool As an admin, your whole XenServer health infrastructure is displayed, in the current dashboard/health view. We added a select if you want to narrow numbers on one specific pool. Or even on multiple pools at once (excluding maybe dev infrastructure!). Here is a result for a specific test pool: ![health_filter](https://xen-orchestra.com/blog/content/images/2018/01/health_filter.png) ## Ghost tasks fixed This one is really a GREAT step forward in XO: for a long time ago, we had an issue of ghost tasks. Basically, this is an issue on how XenServer API is handling `task` object. If you restart the toolstack, we never get the message that tasks were destroyed. So we kept them, despite they aren't here anymore. Frankly, we aren't able to find a net solution for this. Until we had a discussion with a XAPI engineer (thank you [Jon Ludlam](https://github.com/jonludlam?ref=xen-orchestra.com) ;) ) about a undocumented field, giving the number of objects of each class everytime. This allowed us to make **cache invalidation**: if you task number is not the same than XenServer pool, we'll decide to remove our "local" tasks and re-fecth the remote ones. And that's it! Say goodbye to ghost tasks! ![halloween-1746354_640](https://xen-orchestra.com/blog/content/images/2018/01/halloween-1746354_640.jpg) ## Autopatching skips 7.3 You probably know that [XenServer 7.3 removed a lot of free features](https://xen-orchestra.com/blog/xenserver-7-3/). And this latest XS release is also distributed as a patch. Because we recommend to patch from the pool view of XO, this also installed the 7.3 "patch", finally updating your 7.2 to 7.3. And this is probably something you didn't want. Right now, you can install all pool patches without fear of being updated to 7.3, because we simply skip the patch! ![pool_patches](https://xen-orchestra.com/blog/content/images/2018/01/pool_patches.png) ## News on backup front We are still improving multiple things related to backup: - better concurrency - more live reports on what's going on - enhanced capabilities (multi-remote…) - and so on (more details here) If you want to test our improved concurrency algorithm, please comment, we'll give you a version of `xo-server` with it! ### Meet us at FOSDEM 2018 URL: https://xen-orchestra.com/blog/meet-us-at-fosdem-2018/ Last updated: 2018-01-26T15:32:21.000Z The **February 3rd and 4th**, one of the biggest European event around open source solutions, takes place in **Brussels** (Belgium, Europe, Earth): [FOSDEM](https://fosdem.org/2018/?ref=xen-orchestra.com) As every year since 2013, the XO team will be a part of it! ### Where? During all the event we will borrow some space to the [Xen Project team](https://www.xenproject.org/?ref=xen-orchestra.com). It will be in the K bulding (level 1, group C) ![Fosdem-event-2018](https://xen-orchestra.com/blog/content/images/2018/01/Fosdem-event-2018.jpg) ### Why? This year, you will have the opportunity to speak with two of our founders, [Julien Fontanet](https://www.linkedin.com/in/julien-fontanet-58733625/?ref=xen-orchestra.com) (CTO) and [Olivier Lambert](https://www.linkedin.com/in/olivier-lambert-22316b26/?ref=xen-orchestra.com) (CEO). A great opportunity to ask all the questions you may have about Xen Orchestra! But this year, we are also the herald of the [XCP-ng project](https://xcp-ng.github.io/?ref=xen-orchestra.com). A 100% community project to create a free and open-source **Citrix XenServer alternative**. Not enough? OK, we will also have some surprises for you. **⚠ Spoiler alert ⚠** ![fosdem2018](https://xen-orchestra.com/blog/content/images/2018/01/fosdem2018.jpg) ### XenServer performance alerts URL: https://xen-orchestra.com/blog/xenserver-performance-alerts/ Last updated: 2018-04-16T08:56:09.000Z New year, new features in Xen Orchestra: "performance alerts". In short, you can decide which **VMs or hosts** you want to monitor, and XO will send you an email if some thresholds are reached. Let's see how it works! > Note: this feature is completely independent of the existing XenServer performance alert implementation. It means this works **regardless XenServer version or license**. > Performance alerts is a **Premium edition** plugin. ## Configuring alerts In your plugin page, check the "perf-alert" plugin and click on the "+" icon to open details: ![perfsalert1](https://xen-orchestra.com/blog/content/images/2018/01/perfsalert1.png) Now, we'll configure one alert for a test VM, named `OLT CPU test` (running on host `pe2`). If those settings are met, we'll send a notification: - CPU usage - used more than 40% - during 60 secs Now, we'll add a list of recipients for this alert (here, 2 emails): ![perfslaert3-1](https://xen-orchestra.com/blog/content/images/2018/01/perfslaert3-1.png) ### Live test A fresh CentOS VM was created in order to show you how it works. We just installed `stress` package and ran it: ``` # yum install stress # stress --cpu 2 stress: info: [10438] dispatching hogs: 2 cpu, 0 io, 0 vm, 0 hdd ``` Now the VM starts to use its CPU at max: ![perfsalerts4](https://xen-orchestra.com/blog/content/images/2018/01/perfsalerts4.png) And indeed, we had an email! ![perfsalerts5](https://xen-orchestra.com/blog/content/images/2018/01/perfsalerts5.png) If you click on the link, you'll be redirected directly to the VM stat view :) Also, when the alert is finished, you'll be also notified: ![perfsalertsend](https://xen-orchestra.com/blog/content/images/2018/01/perfsalertsend.png) ### More to come! Right now, you can create any number of alerts, regarding CPU or memory. But we'll add more features soon! ### XCP-ng on tracks URL: https://xen-orchestra.com/blog/xcp-ng-on-tracks/ Last updated: 2018-01-22T16:36:02.000Z The first XCP-ng proof-of-concept is working. The future is open. You can read more about it here: [https://xcp-ng.github.io/news/2018/01/22/xcp-ng-on-tracks.html](https://xcp-ng.github.io/news/2018/01/22/xcp-ng-on-tracks.html?ref=xen-orchestra.com) In short: we managed to validate the feature check removal, but also added a RPM repo to get the packages without using any supplemental pack install. The road to the first XCP-ng release is open! > Don't forget to [register here](https://mailchi.mp/3bc90e48d2f7/xcp-ng?ref=xen-orchestra.com) to get latest news about XCP-ng project into your inbox! ## What's next? A crowdfunding campaign will be opened soon, giving the opportunity for everyone to contribute :) **2018 will be the year of Open Source and community backed version of XenServer!** [![xcpng400](https://xen-orchestra.com/blog/content/images/2018/01/xcpng400.png)](https://mailchi.mp/3bc90e48d2f7/xcp-ng?ref=xen-orchestra.com) ### XenServer licencing - How it works URL: https://xen-orchestra.com/blog/xenserver-licencing-how-it-works/ Last updated: 2022-06-02T16:14:33.000Z ⚠️ **Don't miss it**: since 2018, XCP-ng works as a 100% free and compatible drop-in replacement for Citrix Hypervisor. Go [read more on XCP-ng website!](https://xcp-ng.org/?ref=xen-orchestra.com) **90%+ of our Xen Orchestra users already switched to XCP-ng** instead of XenServer/Citrix Hypervisor. > EDIT October 2018: As we are now developing the [XCP-ng hypervisor](https://xcp-ng.org/?ref=xen-orchestra.com) as an alternative to Citrix XenServer, we are no longer XenServer provider. We strongly encourage your to take a look on our open source solution! As you know, we are now Citrix Solution Advisor, which is the title of nobility allowing us to sell Citrix XenServer licenses among others Citrix products. Since the [XenServer 7.3 release](https://xen-orchestra.com/blog/blog/xenserver-7-3/), some features have been removed from the free edition but also host number limitation in a pool (3 hosts max). Getting a commercial license from xenserver is something you can think of. The pricing policy of XenServer is, somewhat, unclear. And that's why I wanted to clarify the situation in this article. ![Xen_Server_Logo_original-1](https://xen-orchestra.com/blog/content/images/2018/01/Xen_Server_Logo_original-1.png) ## Why get a license? A XenServer license will brings many benefits: 1. You will get access to additional features only available for standard and enterprise edition (this is especially true for XenServer 7.3) 2. You will access a commercially certified product, rigorously tested for a production environment 3. You will benefits from the Citrix maintenance, with world class support 24x7 4. You will have the opportunity to get every updates & releases, including **security patches and version upgrade**. > *To sum up, getting a commercial edition will allow you to unlock the features you need and to keep your infrastructure *up to date* for *EVERY XenServer edition*. It means, that if you apply your license for XenServer 7.3 you can still upgrade to XenServer 7.4 without investing in new license!* > Note : The CSS (Customer Success Service), which include the support and the update have an annual cost and is MANDATORY to keep getting access to updates after the first year. ## Which edition should I choose? For homelab, **free edition** deliver all the features you need for a basic utilisation. Free edition comes with some limitation, you can’t have more than 3 hosts in a pool and, obviously, you won’t have support from the Citrix team. > If you want all features without paying a license, please see below the XCP-ng alternative. For production environment and mid-market companies, the **standard edition** will allow you to get rid of the pool limitation, unlock storage XenMotion, live migration and GPU pass-through among other features. This edition is, more or less, the previous XenServer free edition (before 7.3) with support. For GPU virtualization and large scale datacenter, **Enterprise edition** make sense since you will unlock specific features related to GPU, Changed Block Tracking and PVS-accelerator. > Before taking any decision, be sure to take a look on the complete [Citrix XenServer features matrix for XenServer 7.3](https://www.citrix.com/content/dam/citrix/en%5Fus/documents/product-overview/citrix-xenserver-feature-matrix.pdf?ref=xen-orchestra.com) ## Pricing Here it is! You need a quote? [Contact us](mailto:sales@vates.fr) ![XS-pricing-2018](https://xen-orchestra.com/blog/content/images/2018/01/XS-pricing-2018.png) ## Alternative? If you don't want to have Citrix support, but enjoy all features, please check the new XCP-ng project. It will be 100% community backed! In other words, XCP-ng is a community project on which we are working in order to deliver an alternative to XenServer commercial edition. If you want to learn more about it: - [Check the presentation page](https://xcp-ng.github.io/?ref=xen-orchestra.com) - [Subscribe to the dedicated mailing list](https://mailchi.mp/3bc90e48d2f7/xcp-ng?ref=xen-orchestra.com) - [Join us on Twitter](https://twitter.com/xcpng?ref=xen-orchestra.com) - [Join us on Facebook](https://www.facebook.com/XCPng) Until a first official release available, you can stay on 7.2 free edition, which get the [Meltdown/Spectre patches available](https://xen-orchestra.com/blog/blog/meltdown-and-spectre-for-xenserver/), and no pool size restriction nor other features removed. ![xcpng_small](https://xen-orchestra.com/blog/content/images/2018/01/xcpng_small.png) ### Meltdown and Spectre for XenServer URL: https://xen-orchestra.com/blog/meltdown-and-spectre-for-xenserver/ Last updated: 2018-07-02T12:53:15.000Z A recap on how Spectre and Meltdown can affect your Citrix XenServer infrastructure. And a full guide on how to mitigate it. If you weren't in a desert this week, you probably heard about [Meltdown and Spectre vulnerabilities](https://spectreattack.com/?ref=xen-orchestra.com). But how it can affect your infrastructure running Citrix XenServer? ## Meltdown ![meltdown.min](https://xen-orchestra.com/blog/content/images/2018/01/meltdown.min.svg) ### What's the problem? Someone having **access to the VM** will be able to read the memory outside the VM itself, and therefore read data from other VMs on this same physical host (let's call them "untrusted VMs"). You are NOT affected if you only have trusted VMs, but note that an attacker could enter via other application exploits (web server etc.) on your VMs. In short, you just lost a protection in a defense-in-depth. Not good. > **Meltdown** is the easiest exploit to run (we'll see that **Spectre** is more subtle to exploit but also to "solve"). ### Am I affected? Meltdown is using a design flaw into **Intel** CPUs only. This is called by [Xen sec team](http://xenbits.xen.org/xsa/advisory-254.html?ref=xen-orchestra.com) "**SP3**" (aka *rogue data cache load*). You are impacted only if you are using: - 64-bits PV type VM (HVM/PVHVM aren't affected!) - Intel CPUs (AMD chip design is a bit different and not affected) - untrusted VMs, ie untrusted users having VM access (even non-root!) - All XenServer versions are affected > 64-bits PV guests are vulnerable because guest and hypervisor share the same address space, but with different privileges. HVM aren't. ### What can I do? You can mitigate the risk by **migrating your PV guest to HVM**. To know if a VM is PV or HVM, you can check it in the VM view of [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com), eg here is one PV and one HVM guest: ![pv](https://xen-orchestra.com/blog/content/images/2018/01/pv.png) ![hvm](https://xen-orchestra.com/blog/content/images/2018/01/hvm.png) Or even better, use the filter `virtualizationMode:pv` to see them all directly: ![searchpv](https://xen-orchestra.com/blog/content/images/2018/01/searchpv.png) If you don't have [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com) yet, you can use `xe` command to list all your PV guests with `xe vm-list HVM-boot-policy= is-control-domain=false`: ``` uuid ( RO) : 49e3ee6c-f387-fb91-3b2c-1aa52f20c6a7 name-label ( RW): XenServer DDK 7.1.0-137272c import power-state ( RO): running uuid ( RO) : 2c49f8a1-1139-6dd3-7869-5ddc5ddd6be1 name-label ( RW): XenServer DDK 7.0.0-125770c import power-state ( RO): running uuid ( RO) : 7dba3f40-eeef-5398-e21a-756418368830 name-label ( RW): Citrix License Server Virtual Appliance v11.14.0.1 power-state ( RO): running ``` Then you can migrate your Citrix XenServer VMs from PV to HVM! ### Migrating from PV to HVM You need to have, **in your VM**: - Compatible kernel (2.6.24) - Grub installed in the MBR (eg `grub-install`) Then you just have to change the `HVM-boot-policty` value of the VM: ``` xe vm-param-set HVM-boot-policy="BIOS\ order" uuid= ``` Halt and start your VM, you are now in HVM. If something is wrong, empty the previous parameter, shutdown and start again to be back in PV. ### Inside the VM Solving/mitigating the hypervisor won't solve your issue on the VM level: remember to upgrade your VM OS too, or untrusted users could read part of the VM memory that you don't want to! ## Spectre ![spectre.min](https://xen-orchestra.com/blog/content/images/2018/01/spectre.min.svg) ### What's the problem? Like **Meltdown**, someone having **access to the VM** will be able to read the memory outside the VM itself, and therefore read data from other VMs on this same physical host (let's call them "untrusted VMs"). Again, you are NOT affected if you only have trusted VMs, but note that an attacker could enter via other application exploits (web server etc.) on your VMs. > **Spectre** is the NOT easy to exploit (more complicated and slow to access memory, something like 1500 bytes/second). But it's also trickier to mitigate it and affects everyone. ### Am I affected? Short answer: **yes**. **Spectre** contains both "**SP2**", aka "*Branch Target Injection*" and "**SP1**" aka "*Bounds-check bypass*". For now, there is **no known exploit** for "**SP1**". The issue then is on "**SP2**". If you have untrusted VMs, **you are vulnerable**, whatever XenServer version you are using, or the virtualization mode. ### What can I do? #### On XenServer 7.x All XenServer 7.x versions have now a patch from Citrix. In Xen Orchestra, you should see it in Dashboard view, or pool view. It's also available on any latest XS version (7.3). > Note: [XenServer 7.1 patch](https://support.citrix.com/article/CTX230788?ref=xen-orchestra.com) (same for 7.0), needs a Citrix license. Another reason to take a look on [XCP-ng](https://xcp-ng.github.io/?ref=xen-orchestra.com) to avoid a paywall for critical security issues, right? > Update: A "free" patch was released for 7.2, due to the massive security issue (you can install it on XS free version). #### On XenServer older than 7.x You will need to upgrade! If you are in an isolated environment, the risk will be lower but keep in mind you have a potential breach that won't be fixed. ## Conclusion All those vulnerabilities affect infrastructure with untrusted VMs. If you run your on-premise/isolated "cloud", you are relatively safe (still losing one "defense" anyway). **This must be a reminder that even on the cloud, your applications still run on some hardware.** > Remember that having VMs on a public cloud is like having multiple unknown random flatmate. ![meltdown-spectre-logos](https://xen-orchestra.com/blog/content/images/2018/01/meltdown-spectre-logos.jpg) [![sign-up-1000x300](https://xen-orchestra.com/blog/content/images/2018/07/sign-up-1000x300.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup?pk%5Fcampaign=blogbanner) ### Xen Orchestra 5.15 URL: https://xen-orchestra.com/blog/xen-orchestra-5-15/ Last updated: 2018-01-29T10:20:23.000Z Latest 2017 release! Full Citrix XenServer 7.3 compatibility, XOSAN available in tech preview, plus many improvements and bug fixes. **Also, don't miss our post on the [new xcp-ng project!](https://xen-orchestra.com/blog/blog/introducing-xcp-ng/)** (community backed build of XenServer, without feature limits). [![xcpng_small](https://xen-orchestra.com/blog/content/images/2017/12/xcpng_small.png)](https://xen-orchestra.com/blog/blog/introducing-xcp-ng/) ### Full XenServer 7.3 compatibility Some external changes were released with [Citrix XenServer 7.3](https://xen-orchestra.com/blog/blog/xenserver-7-3/), but also internal modifications. For some of them, we needed to adapt our code, **that could even "bypass" some feature restrictions**. For example, VDI move is not possible in XS 7.3 Free, so if we got the license restriction error, we make the move ourselves (with a copy then a remove of the origin). Note that it works for a halted VM. And **it's fully transparent for you!** Memory change was also optimized to reflect the new XenServer's code. In short, XO is 100% compatible with XenServer 7.3 and even improve the user experience for its free edition. If you want to upgrade to XenServer 7.3, follow our [guide on how to upgrade to Citrix XenServer 7.3](https://xen-orchestra.com/blog/blog/upgrade-to-xenserver-7-3/). ![](https://xen-orchestra.com/blog/content/images/2017/12/citrix_7_3.png) > Do you need licenses for your XenServer hosts? Contact us on [https://xen-orchestra.com](https://xen-orchestra.com/?ref=xen-orchestra.com), we are official resellers! ### XOSAN in tech preview XOSAN is now available in tech preview. Beta is over! Now, **everyone** can install it without any feature restriction, **for free**. The total space is limited to 50GiB (thin provisioned!), which is enough to let you play with it. ![](https://xen-orchestra.com/blog/content/images/2017/09/disperse5.png) To create a new XOSAN, go into your XOSAN view, and click on create, that's it! > We managed to remove the 2TiB limit by XOSAN node. You can enjoy big disks to make huge XOSAN storage! ## Improvements #### Backup Merge time is now displayed in your logs. We got a [lot of work coming in Q1 related to backup](https://xen-orchestra.com/blog/blog/big-milestone-for-xo-backup/), that's one of our priority. We also added continuous replication tag, this way you can't be confused on which VM is the replicated one or not. We also improve the code of "basic" backup is case of failure. #### VM perfs overview We added small live stats on home/VM view! You can enjoy the status of your VMs at a glance: ![](https://xen-orchestra.com/blog/content/images/2017/11/home_vm_stats.png) You can read more details on this [blog post](https://xen-orchestra.com/blog/blog/xenserver-vms-performance-overview/). #### UI improvements - you can now go to log view with a button when there is an alert/error message - placeholders aren't used anymore to describe fields - do not display LDAP password in logs if login fails - and more… ### Introducing XCP-ng URL: https://xen-orchestra.com/blog/introducing-xcp-ng/ Last updated: 2018-07-02T12:53:25.000Z Would you like all the power of XenServer without limits, backed by the community? Discover XCP-ng project, and **it's on the launchpad!** > You can now [register here to stay tuned](https://mailchi.mp/3bc90e48d2f7/xcp-ng?ref=xen-orchestra.com) on what's next regarding XCP-ng! Since [XenServer 7.3 was released](https://xen-orchestra.com/blog/blog/xenserver-7-3/), people using the free version were a bit disappointed: Citrix removed some interesting features (see our previous blog post on Citrix XenServer 7.3 release). However, XenServer is open source: it's possible to modify and build it, hence removing feature restrictions. And also creating a real community around it! > Obviously, if you need XenDesktop or other Citrix ecosystem product, this won't make sense for you. But if you are doing only server virtualization and/or don't need Citrix support, this project could be a nice opportunity! > **Update**: since the original post, we made an official release. All the news are here: [https://xcp-ng.org](https://xcp-ng.org/?ref=xen-orchestra.com) ## Where? The project repo will be hosted in this GitHub org: [https://github.com/xcp-ng](https://github.com/xcp-ng?ref=xen-orchestra.com) [![](https://i.imgur.com/W9ZCqee.png)](https://github.com/xcp-ng?ref=xen-orchestra.com) If you want to be part of the project, please contact us (comments here or live chat on [https://xen-orchestra.com](https://xen-orchestra.com/?ref=xen-orchestra.com)) to be added as a maintainer. ## When? This is a community backed project, but we (XO team) actually put some resources in it (ie: time and money). It's hard to tell, but we aim for a Q1 release for having an initial working solution that **will be 100% XOA compatible!** ## How to participate? We'll need your help, in any way: ideas, time, money, testing, participating on GitHub (any CentOS package specialist out there?), building infrastructure, RPMs repo and whatever will be needed to make it real. **Again, we want this to be 100% community backed**, so anyone can appropriate how it works, improve it etc. ## Objective Ideally, the goal would be to have just a RPM repo to install everything needed to have this XCP-ng started, and a simple `yum upgrade` to fetch the latest bits. This is also the opportunity to include extra storage drivers (gluster and ceph). We'll add our open source Gluster driver in there too! > Keep in mind we are early in the exploration, the road won't be straight, but we'll do our best to release something with your help :) **So, are you in? Please add your comments below!** [![sign-up-1000x300](https://xen-orchestra.com/blog/content/images/2018/07/sign-up-1000x300.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup?pk%5Fcampaign=blogbanner) ### Upgrade to XenServer 7.3 URL: https://xen-orchestra.com/blog/upgrade-to-xenserver-7-3/ Last updated: 2017-12-19T09:18:13.000Z XenServer 7.3 [is now available](https://xen-orchestra.com/blog/blog/xenserver-7-3/). Let's see how to upgrade (or update!) it. > Some free features **are removed in 7.3**. Please [read this](https://xen-orchestra.com/blog/blog/xenserver-7-3/) before upgrading. **Xen Orchestra is 100% compatible with XenServer 7.3.** ## From XenServer 7.2 If you are running XenServer 7.2, the process will be only an **update**, not an upgrade. > WARNING: whatever solution you use (XO or xe), the update process takes a while (15min+ per host), because there is a lot of RPMs packages to upgrade in this pack. **DO NOT RESTART TOOLSTACK OR HOSTS DURING THE PROCESS.** ### Via Xen Orchestra Download the pack [here](http://downloadns.citrix.com.edgesuite.net/13372/XenServer-7.3.0-update.iso?ref=xen-orchestra.com) and save it on your PC. Go into the Home/pool view and select the pool you want to update: ![pools-view](https://xen-orchestra.com/blog/content/images/2017/12/pools-view.png) Go into the "Advanced" tab and click on "Browse file" in the "Install supplemental pack on every host", then select the file you downloaded earlier: ![uploadpack](https://xen-orchestra.com/blog/content/images/2017/12/uploadpack.png) Now, you have to wait for a while. See the "Monitor update process" section below to see what's happening on your host. While there is a update task in the "Task" view, DO NOT reboot or restart toolstack on your host: ![tasks](https://xen-orchestra.com/blog/content/images/2017/12/tasks.png) When there is no `pool_update.apply` task left, you can reboot the hosts to have all updates validated. You can do it later, but it's recommended to do it ASAP. ### Via XE cli You need to download the update "pack". You can do it directly from your pool master: ``` $ wget http://downloadns.citrix.com.edgesuite.net/13372/XenServer-7.3.0-update.iso ``` Then, still on your pool master, you can upload the update on the storage of your choice (even not shared): ``` $ xe update-upload file-name=XenServer-7.3.0-update.iso.1 sr-uuid= ``` This will return the patch UUID. Keep it in your pastebin. Now, we'll apply the update on all hosts ``` $ xe patch-pool-apply uuid= ``` Finally, keep in mind this command can take up to half an hour. #### Monitor update process Because it's very long, it could be hard to tell what's going on. But you can actually check what's happening: ``` # tail -f /var/log/yum.log Dec 15 12:59:37 Updated: vendor-update-keys-1.3.3-2.noarch Dec 15 12:59:38 Updated: bugtool-conn-tests-1.1.7-1.noarch Dec 15 12:59:39 Installed: update-XS73-1.0-1.noarch Dec 15 13:01:17 Erased: control-XS72E012-1.0-1.noarch Dec 15 13:01:18 Erased: update-XS72E012-1.0-1.noarch Dec 15 13:01:19 Erased: control-XS72E010-1.0-1.noarch Dec 15 13:01:20 Erased: control-XS72E005-1.0-1.noarch Dec 15 13:01:20 Erased: update-XS72E005-1.0-1.noarch Dec 15 13:01:23 Erased: kpatch-modules-0.3.2-4.x86_64 Dec 15 13:01:23 Erased: kpatch-4.4.0+10-modules-0.3.2-4.x86_64 ``` ## From older XenServer This is the standard upgrade procedure. You can upgrade your previous XenServer version directly to 7.3 since XenServer 6.2, 6.5, 7.0 and 7.1. If you are using XenServer 7.2, please read the previous section. ### ISO download You can fetch the ISO here: [http://downloadns.citrix.com.edgesuite.net/13371/XenServer-7.3.0-install-cd.iso](http://downloadns.citrix.com.edgesuite.net/13371/XenServer-7.3.0-install-cd.iso?ref=xen-orchestra.com) The ISO can be burn to a CD but see the next section for USB install. ### Install from USB From any Unix/Linux: ``` dd if=XenServer-7.3.0-install-cd.iso of=/dev/sdX bs=8M status=progress oflag=direct ``` Replace `sdX` with the name of your USB key. On Windows, use a dedicated program that can write ISO to USB drives. ## Partitioning It's exactly the same as all previous XenServer 7.x version (see our previous blog post: [upgrade to XenServer 7.1](https://xen-orchestra.com/blog/upgrade-to-xenserver-7-1/#newpartitionscheme)): - / (root) 18GB - /boot/efi 512M - /var/log 4GB - Swap 1GB > Are you upgrading from an older version than XenServer 7.0? Or do you have the old partition scheme? Please [follow instructions in our previous blog post](https://xen-orchestra.com/blog/upgrade-to-xenserver-7/#usingthenewpartitions) to switch to the new one. ## Rolling pool upgrade If you have a pool with multiple hosts, there is some basic rules to follow: **Always upgrade the pool master first**: 1. Migrate VMs from your pool master to slaves 2. Upgrade the pool master 3. Migrate VMs from one slave to the pool master 4. Migrate this slave 5. Etc. > You can always live migrate VMs from an older XenServer to a newer. The opposite IS NOT POSSIBLE. Also, always check to empty your VM CD drives and disable HA during the operation. ### XenServer 7.3 URL: https://xen-orchestra.com/blog/xenserver-7-3/ Last updated: 2022-06-01T14:40:31.000Z ⚠️ XenServer 7.3 removed free features and it's now End of Life (EOL). You can however [download XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com) instead, providing a 100% compatibility with all features for free. It's out! Latest CR version of [XenServer is available](https://www.citrix.com/products/xenserver/whats-new.html?ref=xen-orchestra.com). So what's new there? ## What's new? ![citrix_7_3](https://xen-orchestra.com/blog/content/images/2017/12/citrix_7_3.png) ### Removed features If you don't have a licensed version of XenServer, upgrading/udpating to this version **will remove those features**: - Xen storage motion - Dynamic Memory Control - Basic GPU Passthrough - Pool size limited to 3 hosts max - and more, [details here](https://www.citrix.com/content/dam/citrix/en%5Fus/documents/product-overview/citrix-xenserver-feature-matrix.pdf?ref=xen-orchestra.com) > If you need a license, you can [contact us](https://xen-orchestra.com/?ref=xen-orchestra.com) (live chat of our website), as we are a Citrix partner and reseller. We'll help you about licensing. ### Added features If you have an Enterprise license for XenServer, you'll have: - Efficient multicast support via IGMP snooping - Support for NVIDIA Pascal graphics cards - Nested virtualization for Bromium Secure Platform - Changed Block Tracking We reviewed the CBT features: in short, the only advantage vs current Delta backup, is that you can remove the reference snapshot (and leave only the metadata). But it doesn't solve the main problem about block based storage that aren't thin-provisioned anyway. **Because you still need to create the snapshot at the first place**. However, there is interesting features hunder the hood of CBT: `nbd` protocol, which will be probably useful for Xen Orchestra in the future, to have more flexible fetch of VM content. Right now, it doesn't change anything: **Xen Orchestra is fully compatible with XenServer 7.3!** ## Should I upgrade? Depends: - If you are on 7.1 LTS, and happy with it, stay. - If you are on 7.2 without license, you'll lose some features. - If those are too important for you, you can stay in 7.2 - Or buy a license [![sign-up-1000x300](https://xen-orchestra.com/blog/content/images/2018/07/sign-up-1000x300.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/signup?pk%5Fcampaign=blogbanner) ### XenServer VMs performance overview URL: https://xen-orchestra.com/blog/xenserver-vms-performance-overview/ Last updated: 2017-11-08T15:59:59.000Z A quick announcement for a very interesting feature coming soon: you can now display -in live- VMs performance in the home VM view. ## User need and UI challenge You can currently see VMs stats in 2 ways. The classic stats view: ![stats1](https://xen-orchestra.com/blog/content/images/2017/11/stats1.png) Or the small sparklines in the General or Console tab: ![stats2](https://xen-orchestra.com/blog/content/images/2017/11/stats2.png) But sometimes, you need to get a look on multiple VMs stats at the same time (eg: a database VM and a webserver VM). You can always open 2 tabs in your browser, but when you need to compare more than 2 VMs in real time it starts to be really painful. Why not using our sparkline in the home view then? But there's more. You can use this to compare only what you want to compare! ## Combine it with our powerful search Let's take our previous example: you want to compare your VMs activity regarding your whole web stack. Let's imagine you got: - 1x firewall - 2x proxies - 1x database - 1x webserver If you got a tag "myApp" on all of them, just search for this tag to filter. Then you can get your whole application VM usage in one view! Example: ![home_vm_stats](https://xen-orchestra.com/blog/content/images/2017/11/home_vm_stats.png) You can now monitor your whole application stack at once! ### Big milestone for XO backup URL: https://xen-orchestra.com/blog/big-milestone-for-xo-backup/ Last updated: 2017-11-08T09:30:37.000Z XOA is able to backup your XenServer VMs since 2014\. But we added many features, step by step, until we faced a wall: we needed to redesign it to improve current capabilities. But also to deliver new exciting features! ### Once upon a time… XOA backup story started 3 years ago: we managed to have scheduled jobs to **export full VMs**, on a "remote" (eg: NFS storage). Then, we added **Disaster recovery**: instead of "remote" target, we allowed to use a distant XenServer host (in fact, a SR). In this case, your recovery time was reduced to 0. Then came **Delta backup!** To be fair, "Continuous Delta backup", because after the first full, you never had to make other full. And finally, **Continuous Replication** was the logical following (it's the "DR of full backup" applied to delta) ![continuous-replication](https://xen-orchestra.com/blog/content/images/2017/11/continuous-replication.jpg) ## A new ambition But this is just a start, and more possibilities are coming: - get more info on the backup process, with the ability to cancel it - improved backup logs/reports (like transfer vs merge speed) - fine grained concurrency to allow faster multiple backups - multiple schedule job (eg: daily and monthly) - multiple remotes (eg: to stream backup at 2 different places) - job retry (don't skip directly to the next schedule) And also brand new things would be doable, like: - *XOA proxies for backup*: ability to keep backup stream in a remote site - *Cloud backup*: send your backups in our cloud for disaster recovery That's a LOT of new stuff! And a brand new backup code is required to achieve it. That's why we started to work on it few months ago. We hope now that this revamped code will turn into actual features for our next release. Which ones? You'll know it soon, stay in touch! ![Our architecture work](https://xen-orchestra.com/blog/content/images/2017/11/startup-photos.jpg) ### Xen Orchestra 5.14 URL: https://xen-orchestra.com/blog/xen-orchestra-5-14/ Last updated: 2017-10-31T19:42:06.000Z Happy Halloween release 🎃 🎃 🎃 You can now manage your vGPUs directly in Xen Orchestra. We also added numerous UI improvements and bug fixes. Oh and by the way, we are also officially Citrix Solution Advisor! We are glad to improve our partnership with Citrix every day :) ![](https://xen-orchestra.com/blog/content/images/2017/10/Citrix_solution_advisor.png) You can even find us on the [official Citrix marketplace](https://citrixready.citrix.com/vates/xen-orchestra.html?ref=xen-orchestra.com). ## GPU management Nowadays, GPU are more and more used for a lot of tasks, even in the pure server world and not only in remote desktop usage. GPU computing is obviously a big thing and able to realize some tasks 10 to 100 times faster than traditional CPUs. ### vGPUs Despite it's been a while since Xen knows how to manage multiple vCPUs (it's a "simple" scheduling thing), managing vGPUs is newer. Like for CPUs, you can use "parts" of a physical GPU in multiple VMs. So your GPU compute time is scheduled across your VMs. Here is as example using Nvidia GRID technology: ![](https://xen-orchestra.com/blog/content/images/2017/10/VDI_Diagrams_v1-3_NVIDIA_GRID_vGPU-1024x794.png) So you can enjoy all the GPU capabilities in the VM, like if you had direct access to the whole GPU in the "bare metal" way. ### UI for vGPUs We exposed GPU capabilities of XenServer, and as usual, in the easiest way possible for you to use it. #### Pool view We list the GPU group: ![gpugroups](https://xen-orchestra.com/blog/content/images/2017/10/gpugroups.png) #### Host view We display the physical GPU in the host: ![host_view](https://xen-orchestra.com/blog/content/images/2017/10/host_view.png) #### VM view If you don't have any vGPU in your VM: ![vmnogpu](https://xen-orchestra.com/blog/content/images/2017/10/vmnogpu.png) You can add a new one: ![vmaddgpu](https://xen-orchestra.com/blog/content/images/2017/10/vmaddgpu.png) ![vpdisplaygpu2](https://xen-orchestra.com/blog/content/images/2017/10/vpdisplaygpu2.png) It's also displayed in VM general tab: ![vmdisplaygpu](https://xen-orchestra.com/blog/content/images/2017/10/vmdisplaygpu.png) #### VM creation You can also create a vGPU directly at VM creation: ![vm_create_vgpu](https://xen-orchestra.com/blog/content/images/2017/10/vm_create_vgpu.png) ## UI improvements #### VM snapshot description Pretty straightforward but useful: ![](https://xen-orchestra.com/blog/content/images/2017/10/vmsnapdescr.png) #### Continuous replication time Date are usually added at the end of the replicate VM name. But the granularity was days only, which isn't enough when you replicate a VM every hour for example. That's why we added a more precise date (using UTC based on `ISO 8601` but more compact): ![](https://xen-orchestra.com/blog/content/images/2017/10/CR_date.png) > This VM was replicated at 4:16PM, 4:17PM and 4:18PM UTC, the same day (October 26) #### Sort VMs by number of snapshots We never thought that would be so helpful! You can now sort your VMs by their number of snapshots: ![](https://xen-orchestra.com/blog/content/images/2017/10/vm_sort_by_snapshots.png) #### Display XS version in host view Simple but also very useful: you can now easily spot which host got which XS version (here: `v7.1` and others with `v7.2`): ![](https://xen-orchestra.com/blog/content/images/2017/10/versionXS.png) ## What's next? We are currently working on a **major improvement under the hood on the backup side**. This will allow us to make significant progress on Cloud backup and Backup proxies. Also, XOSAN will be commercially release in the next weeks! ### Xen virtualization modes URL: https://xen-orchestra.com/blog/xen-virtualization-modes/ Last updated: 2018-10-05T14:30:13.000Z Let's take a quick look on various Xen virtualization modes in terms of pros and cons. For a deeper understanding, you can [read this excellent Xen Wiki page](http://wiki.xen.org/wiki/Virtualization%5FSpectrum?ref=xen-orchestra.com). > Spoiler: in the end, **there is only 2 modes**. But we'll see some interesting variations in the HVM world. ## PV mode Guest OS (the VM) uses only the unpriviledged CPU ring. #### Pros - Fast boot time - No QEMU usage (smaller attack surface, less processes on Dom0) - Fast [context switches](https://en.wikipedia.org/wiki/Context%5Fswitch?ref=xen-orchestra.com). #### Cons - Expensive memory management updates (Xen is auditing all memory modifications on the guest) - "Complicated" boot management (PyGrub). Historically, PV was the first mode available. Perfect in a world when the hardware assisted features was still inexistent. ![Xen-Panda-Summit-500px](https://xen-orchestra.com/blog/content/images/2017/10/Xen-Panda-Summit-500px.png) ## HVM mode This mode uses hardware extensions and emulated devices, existing everywhere since almost 10 years now. #### Pros - Fast memory management (hardware management) - Less complicated boot process (emulated BIOS) #### Cons - One QEMU process for each guest - "Slow" boot process (starting the emulated BIOS first) - Emulated hardware (an extra layer which has a cost). This mode uses the capabilities of your hardware to management the memory. It can be interesting, but in general pretty limited without extra drivers. > So that's it? Not really. You have extra "modes", **all of them based on HVM**. ### PVHVM mode HVM guest with an operating system detecting it, and therefore using virtualized Xen interupts and timers + drivers for disks and network. For Linux VMs, it's done automatically by the kernel, for Windows guests, you need to install special drivers. #### Pros - Same than HVM… - … but better performances than HVM (less layers). #### Cons - Same cons than plain HVM. Note than in the vast majority of workload, [PVHVM outperform PV from 15 to 30%](https://xen-orchestra.com/blog/blog/pv-vs-pvhvm-on-next-xenserver/). ![Xen-Panda-Running-500px](https://xen-orchestra.com/blog/content/images/2017/10/Xen-Panda-Running-500px.png) ### PVH mode The last step in virtualization: best of both PV and HVM. Story of this mode is a bit complicated: first step was trying to use PV guest (PVHv1) but it happened to be the wrong way. Due to hardware improvements (and other reasons), the new way, nammed **PVHv2** \-formerly **HVMLite**\- is HVM based. But this time ditching Qemu (less attack surface), reducing boot time and so on. How? Accessing directly the hardware for almost every operations. #### Pros - No QEMU usage (less complex, smaller attack surface) - Fast boot - Fast memory management #### Cons - not 100% finished yet - not available yet in XenServer As you can see, PVH mode (**PVHv2** actually) is the future. We'll continue to monitor closely when it will be available in XenServer. Stay tuned! ![Xen-Panda-Ecosystem-1-500px](https://xen-orchestra.com/blog/content/images/2017/10/Xen-Panda-Ecosystem-1-500px.png) ### XenServer: is my VM PV or HVM? That's easy to spot in [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com), in your VM view, General tab: ![pvhvm](https://xen-orchestra.com/blog/content/images/2018/09/pvhvm.png) Or in the Advanced tab: ![advancedmode](https://xen-orchestra.com/blog/content/images/2018/10/advancedmode.png) You can also use the search bar to display all your HVM guests at once (or PV guest), using the following syntax: `virtualizationMode:hvm` ![filter](https://xen-orchestra.com/blog/content/images/2017/10/filter.png) ### Case study #2 - XOA at the Geneva Gaming Convention URL: https://xen-orchestra.com/blog/xoa-ggc-case-study/ Last updated: 2021-03-15T13:33:50.000Z ### Interview with the network coordinator - Romain Pfund *This interview is translated from French.* ##### Can you present to us the infrastructure for the GGC? The GGC takes place in the Palexpo in Geneva and is split in two parts: - the Hall 1 with the exposition and the "big scene" - the LAN and the "small scene" in the *Congress Center* Regarding the network infrastructure, we have **39** Cisco switches, **1** PFSense firewall, **1** Beaglebone BLACK and **2** physical servers. Most of the hardware is lent by several associations that are part of the collective, but also by some individuals and companies from the region Geneva/Vaud. We are a small team of volunteers with 6 computer scientists for the preparation, deployment and maintenance during the event. For the small scene and the LAN, we have **24** switches for players, **2** switches for admins, **1** for the cast, **1** for the scene and **1** for the network administration and servers. Everything is connected with optical fiber channels. For the Hall 1, we have **3** switches for various exhibitors connected to the network via the Palexpo infrastructure (QinQ). For the Big scene, we have a distribution switch connected with a direct optical fiber from our head of control. This switch is connected (still optical fiber) to **2** switches for the players, **1** for the cast tower, **1** for the control room and finally **1** for the backstage. Regarding the physical servers, we chose **XenServer** because it was OpenSource and the features met our expectations. For the Management, we chose **Xen Orchestra**. We were seduced by its user friendly aspect, the ease of deployment, the completeness of the tool and finally because it was a solution "close to us". (*Note: Xen Orchestra is based in Grenoble, not far from Geneva*) Our main VMs are: - XO virtual Appliance - Debian with Observium and SmokePing for the network monitoring - Debian VM for Ebot (dedicated for the CS:GO matches management) - 8 Debian VMs for CS:GO servers (4 per host) Finally, the Beaglebone BLACK is useful for routing broadcasts between VLANs (mandatory for some games), we could have virtualized this feature, but we chose to keep it this way to experiment. ![](https://xen-orchestra.com/blog/content/images/2017/10/ggc-network.png) ##### Which are the obligations you have to take care of for this event? Specifications were to provide all the network infrastructure to host: - a LAN with 500 players maximum (finally we got 380 players); - being able to provide servers for 8 CS:GO matches at the same time + the management of these matches; - 16 computers for the big scene for the finals (including casters and players); - provide the stage system (eg. sound via Dante...); - 12 computers for the small scene; - 1 Wi-Fi network for the players, 1 Wi-Fi network for the admins; - 1 public Wi-Fi for the exponent and 1 for the visitors (managed by Palexpo). And we have some constraints: - the infrastructure had to be stable 24/24 during the whole event; - players cannot be more than 10 meters away from a switch; - our cable management must not be visible or bother people; - deliver 10/100/1000 for every stage and casters; - use the Palexpo infrastructure for the Wi-Fi. ![](https://xen-orchestra.com/blog/content/images/2017/10/GGC-photo.jpg) ##### Which XO features helped you to accomplish your mission? The first feature that helped us and made us save time was the VMs import (from VirtualBox). We had many VMs ready (eg. for the network monitoring) - it would have cost us a lot of time to recreate them. The physical servers patching helped us too. We also used the console access a lot for network configuration of the imported or duplicated VMs. Regarding the configuration of CS:GO servers, snapshots were very useful. The cloning of VM via a snapshot has also been very helpful during the live duplication of these servers. We appreciated the ease of declaration of remotes as well as the creation of Library for ISO, and the backups features. The ease of utilization and the quick response of the XO features were very appreciated, as we are all volunteers, we are preparing the event on our free time. ##### Are there some features you would like to experiment next year? Our servers are second hand and I would like to experiment Disaster Recovery, for some VMs, to a third physical server. On the other hand, XOSAN seems interesting (depends on the duration of the event and its growth). Finally, ACLs to create dedicated access for CS:GO admins so they can manage their VMs independently. ### Xen Orchestra 5.13 URL: https://xen-orchestra.com/blog/xen-orchestra-5-13/ Last updated: 2017-10-30T22:58:54.000Z September release folks! Improved UI, bug fixes and better XOSAN. Oh and by the way, XOA is now officially Citrix Ready! [![](https://xen-orchestra.com/blog/content/images/2017/09/277x125_Citrix_Partner_1879B9.png)](https://xen-orchestra.com/blog/blog/xen-orchestra-citrix-ready/) ### Self service disk management It's now possible for a **self service user to create a new disk and attach it to its VM**. Obviously, it will consume the quota of the self service automatically. If the disk is removed, the quota will computed accordingly: ![](https://xen-orchestra.com/blog/content/images/2017/09/self_add_new_disk.png) It means less work for the administrator and more efficiency for your customers or dev teams :) ### Case insensitive login People who log using LDAP could have issues because XO was used case sensitive. It's now not the case, so you won't have issues on that side. ### VM copy We improved VM copy to report errors more clearly if the copy couldn't happen. Remember that our copy mechanism is cross-pool capable, using our exclusive streaming capabilities. ## UI improvements This release added a lot of improvements on user interface. It's really an important thing to deliver a good experience while working on a virtualized infrastructure. ### Improved sorted tables We improved one of our UI component: sorted table. You are probably already using it, but we generalized the usage in various part of the application. #### Server view It's now also in the Settings/server view: ![](https://xen-orchestra.com/blog/content/images/2017/09/setings_server_sorted_table.png) It means you can sort your servers by name, hostname/IP, username whatever. You can also use the filter. People with a lot of pools will really enjoy this new UI ;) #### Share search But that's not all! We also added the ability to **share a filter/search** for a sorted table in the URL. Eg filtering on "test" in the Storage view (to match all VDIs with "test" on their name or description) will also be reflected in the URL. Eg: ![](https://xen-orchestra.com/blog/content/images/2017/09/filter_vdi.png) ![](https://xen-orchestra.com/blog/content/images/2017/09/filter_vdi_url.png) The search string is saved if you use the "previous" button of your browser, and you can send the link to someone to share the filtered view. #### Select all And finally, a **select all** possibility, eg in the VDI list or storage view, to select all VDIs on all pages at once: ![](https://xen-orchestra.com/blog/content/images/2017/09/select_all1.png) ![](https://xen-orchestra.com/blog/content/images/2017/09/select_all2.png) #### Keyboard shortcuts You can use `j`, `k` to move line focus, `x` to select the current line and `/` to enter the search field. #### Simplified iSCSI SR creation We fixed previous issues on iSCSI SR creation with CHAP password, but we also added a LUN autoselect if there is only one. Less clicks, yaayyy! ### XOSAN #### Custom network address ranges By default, XOSAN will create its dedicated network with a 172.31.100.0/24 range. We added the possibility to enter any `/24` private IP range you prefer: ![](https://xen-orchestra.com/blog/content/images/2017/09/xosan_advanced_range.png) #### Detailed deploy progress Now you can track progress of all steps to deploy XOSAN on your infrastructure (outlined in red): ![](https://xen-orchestra.com/blog/content/images/2017/09/xosan_progress.png) ### Xen Orchestra is Citrix Ready URL: https://xen-orchestra.com/blog/xen-orchestra-citrix-ready/ Last updated: 2017-10-30T22:48:08.000Z As you know, Xen Orchestra subscription started more than 3 years ago. But until now, we didn't do the "administrative" procedure (a little bit painful) to become a "Citrix Ready" product. A few weeks ago, we finally complete the form and exchange with Citrix team and this morning… we received this email: ![](https://xen-orchestra.com/blog/content/images/2017/09/citrixready.png) **Xen Orchestra** is officially **Citrix Ready**! Hurray! ![](https://xen-orchestra.com/blog/content/images/2017/09/citrixready-xologo.png) What will be our next step? We have a lot of awesome new stuff that will come very soon. If you want to be kept in the loop, don't forget to join us on [Twitter](https://twitter.com/xenorchestra?ref=xen-orchestra.com) and [Facebook](https://www.facebook.com/vatesfr/). ### XOSAN at Datapacket URL: https://xen-orchestra.com/blog/xosan-on-10gbps-io/ Last updated: 2018-03-16T15:05:46.000Z ## About [DataPacket](https://datapacket.com/?ref=xen-orchestra.com) > We are a dedicated server provider based in London, currently offering our services across 14 Datacenters worldwide. We focus on high-end solutions for businesses of all sizes. Our standard servers on offer are ideal for virtualization as we always use the latest CPUs with a full support of virtualization: > - Intel 10Gbps NICs with SR-IOV for maximum performance and network throughput even in a virtualized environment. > - up to 64GB RAM in a server with a 4x Core Intel Xeon E3 family CPU. Custom servers for large virtualized environments can be provided upon request (up to 4U - 1TB of RAM/ 24x SSD storage) > - 5x IPv4 addresses and all IPv6 addresses are for free. Additional IPv4 addresses can be ordered for $1/month per IP address. > We have many years of experience with virtualization (xen, kvm, vmware) therefore we can help with the setup if needed. For urgent requests that need to be solved in real-time, we offer a [private Slack channel support](https://datapacket.com/slack-support?ref=xen-orchestra.com). More on Datapacket [here](https://https//datapacket.com?ref=xen-orchestra.com) ![profile_400x400](https://xen-orchestra.com/blog/content/images/2018/03/profile_400x400.png) ### General setup Tests were made on Supermicro 1U server with dual E5-2620, and Intel SSD 540s series: ![](https://xen-orchestra.com/blog/content/images/2017/09/hardware_10gbpsio.png) Installation on all hosts was done via remote KVM, using **XenServer 7.2**. ![](https://xen-orchestra.com/blog/content/images/2017/09/install_ipmi-1.png) Each host got 2x 10GiB/s network interfaces. One was used for outside/internet access, and the other one for XOSAN networking. Regarding storage, we'll use one SSD of 480GiB in each host. > Because we use SSDs, it's better to use *replicated* mode. But *disperse* is also possible. ### 4 nodes This is a 4 node setup with XOSAN. In this case, up to 2 XenServer hosts can be lost without service interruption. The total capacity of XOSAN is around 900GiB: ![](https://xen-orchestra.com/blog/content/images/2017/09/10gbps_io-1.png) ### 6 nodes In a 6 nodes setup, you can enjoy up to **1.3TiB** and lose up to 3 hosts! ![](https://xen-orchestra.com/blog/content/images/2017/09/10gbps_io_6-2.png) ### Benchmark Remember this is a benchmark on one VM only, **performance is increased when you use multiple VMs at once**: - Random sequential read: 320 MB/s - Random sequential write: 300 MB/s > Benchmark done with FIO on a 10GB file, without FS caching of any kind. With 3 VMs at the same time? On each, we got: - Random sequential read: 300 MB/s - Random sequential write: 200 MB/s It means in total, around 900 MB/s in read and 600 MB/s in write! ## Conclusion XOSAN works perfectly within [Datapacket](https://datapacket.com/?ref=xen-orchestra.com) infrastructure! ![hosted_with_datapacket_black](https://xen-orchestra.com/blog/content/images/2018/03/hosted_with_datapacket_black.png) ### Hyperconvergence benefits URL: https://xen-orchestra.com/blog/hyperconvergence-benefits/ Last updated: 2017-10-30T22:17:07.000Z As you know we are currently developing a solution for [XenServer hyperconvergence: XOSAN](https://xen-orchestra.com/blog/tag/xosan/). To fully understand the objectives of our virtual SAN, it's important to take a step back and look at the benefits brought by hyperconvergent infrastructure (HCI). ## What is hyperconvergence? Hyperconverged infrastructure are software centric IT architecture that unify **compute** and **storage** in order to reduce the complexity and benefits from several advantages. On one hand, you may find solutions providing a combination of **hardware and software** to manage storage, servers and networking as a single system. In the other hand, you will find software defined storage solutions (virtual SAN), in which you won't have off-the-shelf servers, and that aim to convert your existing hardware into an hyperconvergent infrastructure. ![](https://xen-orchestra.com/content/images/2016/12/XOSANpool.jpg) Hyperconvergence brings several benefits to any IT organization as **data efficiency** (save storage and bandwidth), **data mobility**(migrate easily your VM), **data security**(data deduplication) and **costs reduction**(overall optimization and saving). ![](https://xen-orchestra.com/blog/content/images/2017/08/hyperconvergenc_24090883.png) ## Software defined hyperconvergence Software centric solutions have its own set of benefits and it's the orientation we choose for XOSAN. Using your existing hardware infrastructure to create a virtual SAN and enable hyperconvergence for your XenServer is a great way to get the benefits from hyperconvergence without the disadvantages. #### No vendor lock-in The most obvious benefits from a [software defined hyperconvergence solution as XOSAN](https://xen-orchestra.com/docs/xosan.html?ref=xen-orchestra.com) is that you can use the infrastructure you already have, add the storage solution you want on the long run and change it the way you want because you have no obligation regarding the hardware part! It will make a massive pricing difference as a DIY server configuration will be far way costless than a turnkey hyperconverged infrastructure with the hardware included. #### Modularity The same thing applies regarding the modularity of your infrastructure. It's easier to modify your HCI. You can mix old hardware and new one, scale resources in or out and make your infra grow without massive additional costs. The main point is that you can choose among a various of hardware manufacturers and if you have the ability of sourcing your hardware material, you will drastically reducing the TCO. #### Keep up with tech evolution Last but not least, you can keep up with the latest innovations in terms of storage and/or servers. You don't rely only on your hyperconverged solution provider to bring the latest tech evolution in is own offer. Switching to better components is entirely up to you. It's a good way to ensure that your hyperconvergent infrastructure always delivers top level performances. ![](https://xen-orchestra.com/content/images/2017/09/disperse5.png) ## Conclusion Hyperconvergence is **THE** thing companies are getting into for some years now. More mobility, more security, less costs, HCI are really a good way to reduce the overall costs and optimize your infrastructure. Here, we deeply believe that a real software defined solution is able to deliver top level performances, maybe even better than a solution that includes hardware and at an unbeatable price, that is for sure. For now, the tests we did with our own infrastructure using XOSAN are very promising. Here is a glimpse of the latest bench ([the complete one is here](https://xen-orchestra.com/blog/improving-xenserver-storage-performances-with-xosan/)) ![](https://xen-orchestra.com/content/images/2017/08/dbench128.png) ![](https://xen-orchestra.com/content/images/2017/08/pgbenchR.png) ### Geneva Gaming Convention - A XO partner URL: https://xen-orchestra.com/blog/geneva-gaming-convention/ Last updated: 2017-10-30T22:18:04.000Z The second edition of the Geneva Gaming Convention will take place from the 22nd until the 24th of September 2017\. More than 15,000 visitors, 80 booths and 500 athletes are awaited for this weekend in Palexpo with an evident mission: to offer an unifying event, accessible and familial. Furthermore, the Geneva Gaming Convention offer the biggest cash prize of Switzerland for an e-Sport competition tournaments (LAN). Over 30,000 CHF (around $35,000 USD) will be offered to the winners of competitions in the following games: Overwatch, Counter-Strike GO, Hearthstone, League of Legends and Rocket League. ![](https://xen-orchestra.com/blog/content/images/2017/09/ggc_2017_logo-rs2.jpg) ### Geneva Gaming Convention powered by XenServer And now, you wonder why we are talking about a gaming event on this blog, right? It's very simple, when you are planning a gaming convention implying competitive game including a significant cash prize, you want to be sure that you can rely on your servers infrastructure and guess what: the Geneva Gaming Convention choose to work with **XenServer** to ensure this task and **Xen Orchestra** is the tool they needed to get the best from their XenServer infrastructure! ![](https://xen-orchestra.com/blog/content/images/2017/09/xo-logo-small.png) As the event is pretty close from our location, we will probably make a little jump in it in order to provide you some photographies and a use case, so, stay tuned! ### Ticket You can access the program and buy your ticket for the convention on the [official website](https://en.ggc.ch/?ref=xen-orchestra.com). ### Improving Xenserver storage performances with XOSAN URL: https://xen-orchestra.com/blog/improving-xenserver-storage-performances-with-xosan/ Last updated: 2017-10-30T22:18:43.000Z Thanks to [XOSAN](https://xen-orchestra.com/blog/xenserver-hyperconverged/), you can dramatically improve your storage performance on your XenServer hosts, **without any new hardware to buy** and with only few clicks. But how exactly? ## Cheap hardware with high performances? Let's do extensive testing with very accessible hardware: - 5x Dell T30 (Xeon E3 V5, 32 GiB RAM, 1 TiB disk in each) - HDDs are cheap [Toshiba DT01ACA100](https://www.newegg.com/Product/Product.aspx?Item=N82E16822149382&ref=xen-orchestra.com) ($45!) - 1x Ubnt 16x10GB/s switch for storage network ![](https://xen-orchestra.com/blog/content/images/2017/08/lab-1.jpg) > Those 5x Dell T30 hosts were used for this article On the software side, we got: - **XenServer 7.1** as the Hypervisor - Debian 9 VM to run the benchmarks (2 vCPUs, 4GiB RAM) in **PVHVM** mode - XOSAN in Disperse 5 mode (**you can lose 1 node without service interruption**) > **No extra hardware used, no external NAS or SAN, just the hyperconverged software XOSAN solution**. All hosts are XenServer hypervisors able to run VM but also member of the XOSAN storage. Note: XenServer is installed itself on the HDD, using around 60GiB on 1TiB. It's not a problem to use the same disk with the remaining space for XOSAN. **You don't even need to buy new disks!** ![](https://xen-orchestra.com/blog/content/images/2017/08/xosan_1disk_setup-1.png) ## Flexibility and High Availability Configuration is in **Disperse 5**, it means if one host is down, it will continue to work (read AND write) without any service interruption. And using 80% of the total disk space possible! (4TiB available on the 5x1TiB disks). ![](https://xen-orchestra.com/blog/content/images/2017/09/disperse5.png) It also means that we have a virtual shared storage between each host, allowing: - Live migration (only migrating RAM, so extremly fast) - XenServer HA (reboot automatically all VMs that were on the disconnected/down host) We could also add hosts in the future **to grow our current XenServer and XOSAN setup**: - 6 nodes will allow disperse 6 with redundancy 2 (so allowing lost of 2 hosts) with 66% of total disk space available - 8 nodes would allow disperse 8 with redundancy 2 with 75% of total disk space available - and more! But now, let's talk about performances! # Local disk vs XOSAN We want to compare XOSAN performances against using the local HDD, obviously on the same VM. **Do we have to pay a performance penalty to have flexibility and HA?** Let's check this! ## Quick FIO benchmarks This is just some quick FIO benchmark, on a 10G file, for seq reads and writes, plus the really interesting IOPS bench for the usual 75% R/W random load: | | Local disk | XOSAN | Difference | | ------------------- | ---------- | --------- | ---------- | | Sequential reads | 165 MB/s | 286 MB/s | **+73%** | | Sequential writes | 160 MB/s | 210 MB/s | **+31%** | | IOPS Random R/W 75% | 154/51 | 4100/1400 | **+2600%** | FIO benchmarks are clear: XOSAN is faster. What about more real load or apps? ## Phoronix Benchmarks We made benchmarks using [Phoronix Test Suit](https://www.phoronix-test-suite.com/?ref=xen-orchestra.com), **which is perfect to make quick benchmarks on various applications**. It will also help us to learn a bit more of XOSAN potential trade off. ![sqlite](https://xen-orchestra.com/blog/content/images/2017/08/sqlite.png) XOSAN is a bit better, but the difference is not huge. Anyway, if you use SQLite, you'll have a slight boost with XOSAN (12% faster) ![apache](https://xen-orchestra.com/blog/content/images/2017/08/apache.png) A first trade off? XOSAN is 5% behind local disk, maybe because working on a lot of small files? ![kernel](https://xen-orchestra.com/blog/content/images/2017/08/kernel.png) Both systems are on par while unpacking a tarball. This is interesting: despite there is a lot of small files, there is no performance impact for XOSAN! ![postgresql](https://xen-orchestra.com/blog/content/images/2017/08/pgbenchR.png) ![postgresql](https://xen-orchestra.com/blog/content/images/2017/08/pgbenchW.png) While using PostGres in "heavy contention", XOSAN is outperforming local disk a LOT, both in read and write mode. ![dbench1](https://xen-orchestra.com/blog/content/images/2017/08/dbench1.png) ![dbench12](https://xen-orchestra.com/blog/content/images/2017/08/dbench12.png) ![dbench128](https://xen-orchestra.com/blog/content/images/2017/08/dbench128.png) More you add clients, better it is: **XOSAN is 17 times faster than local disk**. I think we can recap the DBENCH test with this GIF: ![dbench rocket](https://xen-orchestra.com/blog/content/images/2017/08/dbenchrocket.gif) ## Bonus: Windows Benchmarks Just added in extra some bench using Crystal DiskMark: XOSAN: ![](https://xen-orchestra.com/blog/content/images/2017/08/xosanphaseIIbenchwindows.png) You can compare to the local disk itself: ![](https://xen-orchestra.com/content/images/2017/07/localSRW.png) Recap in a chart: ![](https://xen-orchestra.com/blog/content/images/2017/08/xosanVSlocal.png) # Going even beyond But that's not all. We also planned to add new features in the coming month: **tiering**. It will mean we could add "small" SSDs for hot files. In other words, to go even faster than our current benchmarks. ![](https://xen-orchestra.com/blog/content/images/2017/08/xosan_tiering.png) # Try it now! XOSAN is **already available** in Beta phase II. So you'll be able to test it on your existing XenServer infrastructure :) You can register to the free beta [following those simple instructions](https://xen-orchestra.com/blog/xosan-beta-phase-1/). ![](https://xen-orchestra.com/blog/content/images/2017/09/replicate3x2_full.png) ### Xen Orchestra 5.12 URL: https://xen-orchestra.com/blog/xen-orchestra-5-12/ Last updated: 2017-10-30T23:01:02.000Z Holidays are over and it's release time for Xen Orchestra. The version 5.12 has landed and you can now update your XOA. This release focuses mostly on "filters" in order to enhance existing features as backup or self-service! You can also enjoy **retention** (depth) for Continuous Replication. Finally, **it's also time to test XOSAN Beta in Phase II**. ### Continuous Replication retention This new feature can now combine continuous replication AND retention (depth), to give you some previous backup on your destination. Exactly like in DR, but with our exclusive delta capability! ![](https://xen-orchestra.com/blog/content/images/2017/08/cr-retention.png) You have now a better protection for your replicated VMs: you can boot an older replicated version in a second. ### Grouped disk actions In the SR/disk view, you can now select multiple disks to remove them at once. It will also work if you filter your search. Very very useful if you want to make some cleaning without making hundreds of clicks: ![](https://xen-orchestra.com/blog/content/images/2017/08/multidiskselection.png) You have: - the number of disks selected - all disks of the page if you want - white "delete" button to delete all selected disks ### New filters! In order to provide a more lean experience, we added some new awesome filters. As a result, you can now filter display to watch only tasks running on a specific pool: ![](https://xen-orchestra.com/blog/content/images/2017/08/filtertask.png) We also added a filter for self service VM in the home view, it's now easy to see which VM is in which resource set: ![](https://xen-orchestra.com/blog/content/images/2017/08/resourceset.png) And for our backup users, you can now filter the backup log in order to find specific backup status within a job (eg. Only the failed backup VMs in a job): ![](https://xen-orchestra.com/blog/content/images/2017/08/failed-backup-filter.png) ### Disks that need to be coalesced We also added the total number of disks that need to be coalesced when you have a VDI chain. This information will give you a hint of the time your infrastructure requires to coalesce properly the VDI when you are running a backup job. ## XOSAN PHASE II Here we are, the second beta phase for XOSAN is released. This is a big step forward regarding the final release for our hyperconverged and software defined storage solution for XenServer. We worked a lot on performance and stability during the first stage of the beta. ![](https://xen-orchestra.com/blog/content/images/2017/08/xosan_disperse5_bench-1.png) #### Discover XOSAN If you are not yet familiar with our software defined hyperconvergence solution for XenServer, we highly recommend you to consult the previous blog post we made about it: - [Learn more about XOSAN technology](https://xen-orchestra.com/blog/xenserver-hyperconverged-with-xosan/) - [Learn about the stage I of the beta](https://xen-orchestra.com/blog/xosan-beta-phase-1/) - [Discover our latest benchmarks](https://xen-orchestra.com/blog/new-xosan-benchmarks/) ![](https://xen-orchestra.com/blog/content/images/2017/08/XOSANpool.jpg) #### Beta phase III The last phase (and final!) will be about tiering and multi-disks by XOSAN VM controller. If you are interested in our solution, now is the moment to join the beta and make us as much feedback as possible to shape the product the way you will enjoy it when it's released. To join the beta, follow the explanation on our [dedicated documentation](https://xen-orchestra.com/docs/xosan.html?ref=xen-orchestra.com). This beta phase is open to everyone and we are waiting for your feedback. You should also take a look on our XOSAN : getting started guide. ![](https://xen-orchestra.com/content/images/2017/08/xosan_tiering.png) ### XOSAN - Getting started URL: https://xen-orchestra.com/blog/xosan-getting-started/ Last updated: 2017-12-29T16:12:01.000Z XOSAN, our software defined solution for Xenserver hyperconvergence is now entering phase II. You can now regroup all your existing local storage into a hyperconverged architecture to allow a better data efficiency, fast VM migration, data scalability, enabling High Availability and decrease your storage costs. ## XOSAN is in tech-preview The beta is over, XOSAN is now in tech preview. You can start playing with it and activate a trial with 50GiB limited cluster. Learn more about XOSAN [here](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xosan-home) ![](https://xen-orchestra.com/content/images/2017/02/xosan-menu.png) ## XOSAN creation guide ### Prerequisites XOSAN will need a pool with: - Xenserver 7 or more (7.0, 7.1 or 7.2) - Local LVM SR with at least 15 GiB of free space on each host - 2 GiB of free RAM on each host for the XOSAN VM - a working connection with the updater (same way as the XO trial) - Our XOSAN pack installed on each hosts (it's automatically deployed during the first XOSAN install) > The pack will install user-space packages and add a new SR type: "xosan". Their will be no other modification. The tool stack has to be restarted to be able to deal with XOSAN (no VM or service interruption). It's also fully automated in the XOSAN install process. #### Optional - An extra/dedicated physical network for storage to deliver high performances - 10G networks will deliver higher throughput ### XOSAN Creation After you have complete all the requirements, you can install XOSAN itself. 1. Select all local SR you want to participate to the new SR ![](https://xen-orchestra.com/content/images/2017/02/xosan1beta.png) 2. Choose the mode you want to test. Disperse or replicate which will allow you to lose one or many host whithout experiencing data loss. To get more information about the XOSAN modes, check our [documentation](https://xen-orchestra.com/blog/xosan-beta-phase-1/). 3. Test it! Now your XOSAN is ready, you can play with it as much as you want and provide us feedback. ### XOSAN Documentation We have also an [official documentation for XOSAN](https://xen-orchestra.com/docs/xosan%5Ftypes.html?ref=xen-orchestra.com), you will find plenty of informations in it. ## Provide your feedback During all the beta period, it is very important for us to get as much feedback as possible from you. There is many way you can provide us some useful feedback. - Send us an email with the [contact form](https://vates.fr/contact.html?ref=xen-orchestra.com) - Chat directly with us on the [website](https://xen-orchestra.com/?ref=xen-orchestra.com#!/) - Join the discussion on the [forum](https://xen-orchestra.com/forum/topic/453/xosan-feedback?ref=xen-orchestra.com) on the dedicated thread You need some inspiration regarding the feedback you can make to us? Here are some ideas. - Report a bug - You think you have found a bug? Take some screenshots and contact us, explaining the process that leads to the bug as much as possible so we can reproduce it and fix it ! - Request a new feature - Something is missing in XOSAN? Explain us what feature you would like to be added into XOSAN. Give us as much context as possible so we can fully understand what you need and the best way for us to deliver it. - Ask for help, discuss with other users, suggest improvement, share your benchmarks, join the discussion on the [community forum](https://xen-orchestra.com/forum/?ref=xen-orchestra.com)! ## XOSAN phase III agenda The Phase I was mostly focused on delivering a strong and powerful back end. The second stage of the beta is focusing a lot more on the user experience. XOSAN is intended to become a turnkey solution. And finally, the last phase (III) will be on tiering (using SSD as cache for your hot files). ![](https://xen-orchestra.com/content/images/2017/08/xosan_tiering.png) ### Why backup is essential for your company and how to choose your solution URL: https://xen-orchestra.com/blog/choose-your-backup-solution-xenserver/ Last updated: 2018-09-26T09:56:33.000Z How important is your virtual infrastructure and how important are your data? What if you lose all of you infrastructure tomorrow? Are you prepared to recover efficiently? If your answer is "No" , or "I don’t know" it’s time to get some clues. ![why backup is strategic](https://xen-orchestra.com/blog/content/images/2017/08/loss-and-recove_23667814_4484923ac2bc97a7a4fde57591b5610f9f39643c.png) The probability of a disk to fail one day or another is literally 100%. The question is not **"Is there a risk that I lose my data ?"** The question is **"When will I lose data ?"** and **"Which are the data I can’t afford to lose ?"** Of course, all data don't have the same value, and all the backup solutions don't have the same cost. Continuous replication is a wonderful solution, but maybe it's not the solution you need. The only thing you need to be convinced right now, is that you must be prepared for a data loss. ## How to choose your solution? To protect your XenServer infrastructure, solutions are numerous. Full backup, incremental delta backup, Continuous replication and even file level recovery tools... Xen Orchestra is providing a whole range of backups solutions. And you may wonder the one you really need for your company and how to choose it. Answer to the following questions will give you a big hint about the solution you **really** need. 1. How quickly do you need to recover from an IT disaster? Can you afford days of downtime? An hours? Few minutes? 2. What are the amount of data you are prepared to lose? Days worth? One day worth? Nothing more than an hour? 3. Are you prepared to handle what you need? The financial cost? The bandwidth cost? The storage cost? ## Which solution for which needs ? ![](https://xen-orchestra.com/blog/content/images/2017/08/backups-solutions.PNG) Now that you have answered the three previous questions, you should find the best option for you in the following features. - Downtime is not a major issue and I'm ready to lose potentially days (or more) of data. The biggest consideration is the cost. And backup storage space or speed is less important. Your solution is **Full backup**. - You can afford some downtime but you don't want to lose a lot of data. You want fast backups done every day using a minimal space possible. Your solution is **Delta backup**. - Downtime is the biggest preoccupation, you want to recover as quickly as possible. Cost is an issue, but not backup speed and/or bandwidth usage across remote sites. Your solution is: **Disaster Recovery**. - You can't afford downtime nor data loss. Your solution is: **Continuous replication**. ### Why choosing Xen Orchestra for your XenServer backup? Xen Orchestra is providing a wide range of backups solutions dedicated to XenServer or XCP-ng infrastructure. - We are XenServer experts and we develop XCP-ng, our product is dedicated to these two hypervisors users and include the pro support - Our flat rate pricing system is easy to understand and very competitive whatever the solution you need - Xen Orchestra is much more than a simple backup solution, it's the XenServer best ally for administration, backup and Cloud > Note that **all backup solutions** (full and delta) are able to be fully recovered on a brand new XenServer, whenever and wherever you need. Even a freshly imported XOA is able to recover the backup stored on your remote. [Discover our backups features](https://xen-orchestra.com/?ref=xen-orchestra.com#!/features/backup) [Learn more about our backup technology](https://xen-orchestra.com/docs/backups.html?ref=xen-orchestra.com) ### Xen Orchestra 5.11 URL: https://xen-orchestra.com/blog/xen-orchestra-5-11/ Last updated: 2017-10-30T23:36:35.000Z This new release will allow you to discover which disks need to be coalesced/merged by XenServer. And we made various fixes. ## VDIs that need to be coalesced In the SR view, go into the Advanced Tab, you can see which VDIs need to be merged, and the chain length: ![](https://xen-orchestra.com/blog/content/images/2017/07/disk_to_coalesce.png) Very helpful, and combined with our unique coalesce detection in XO backups, you can be relaxed about your storage health! ## XOSAN Phase II incoming We finished the hard backend work on XOSAN, we can now: - better cluster situation into the UI - enhanced resiliency - replace faulty nodes - add nodes to raise the replication/space available - remove nodes to lower the replication/space available So you'll have enough flexibility to play with it without destroying it again and again (vs Phase I) Right now, we are working on providing a better UI, because right now it's a bit complex, and we want a simple to use product. Anyway, hang on for the 5.12 release ;) ![](https://xen-orchestra.com/content/images/2016/12/XOSANpool.jpg) ### Some data about Xen Orchestra URL: https://xen-orchestra.com/blog/xen-orchestra-data/ Last updated: 2017-10-30T22:37:08.000Z We have gathered some data about Xen Orchestra that you may find interesting or at least funny ;) Launched in 2014, we have now customers almost all around the globe and XO is used to managed more that 130.000 VMs. **That's awesome and it's thanks to ALL of you!** This is the kind of stuff we are happy to share on [Twitter](https://twitter.com/xenorchestra?ref=xen-orchestra.com), [Facebook](https://www.facebook.com/vatesfr/) and even [Linkedin](https://fr.linkedin.com/compan/vates-sas?ref=xen-orchestra.com), so if you want more don't forget to follow us. ![](https://xen-orchestra.com/blog/content/images/2017/07/xen-orchestra-i_23571454.png) ### Special discount for companies with less than 3 sockets URL: https://xen-orchestra.com/blog/xo-small-business-discount/ Last updated: 2018-10-03T12:29:19.000Z Here, at Xen Orchestra, we are pretty proud of our [flat rate pricing strategy](https://xen-orchestra.com/?ref=xen-orchestra.com#!/flatratepricing). For most of the companies, it's the perfect system. It's easy to understand, you keep control of your own infrastructure and can make it grow without any pricing consideration regarding our solution. Plus, it's a very economic solution! ### But! Sometimes, it's not so perfect. For small business or companies with very small infrastructure, features from the premium edition will not always be "worth it" even if these companies need it. So we have been thinking about a solution for them... and here it is! ### Small business offer For business with 3 sockets or less, we are bringing a special discount. From **24th of July to 24th of September**, you can subscribe to get all the Premium edition features, at the price of the Enterprise edition. The small business edition is **$200/month instead of $500/month** and it's not a discount you will enjoy for a month or two, it's a a discount for a **the whole year** of commitment. ![Small Business Offer](https://xen-orchestra.com/blog/content/images/2017/07/small-business-offertiny.png) So, in a nutshell: - If your company have **3 sockets or less** - You can **save 60%** on the **premium edition** ($200 USD instead of $500 USD) - For **a whole year** of subscription And all you need to do in order to enjoy this discount is to subscribe to the Small business Edition on this [page](https://xen-orchestra.com/?ref=xen-orchestra.com#!/small-business-offer). Don't wait too long, this edition will disappear on the **24th of September**. > *Note: If you don't have the offer displayed on your personal space even if your company have 3 sockets or less, please contact us on the [chat on our website](https://xen-orchestra.com/?ref=xen-orchestra.com#!/).* ### Premium features? File level restoration, continuous replication, and self service are just a glimpse of all the features you can access with premium edition. Take a look on our [features matrix](https://xen-orchestra.com/?ref=xen-orchestra.com#!/featuresmatrix) to have a more complete overview. ### New XOSAN benchmarks URL: https://xen-orchestra.com/blog/new-xosan-benchmarks/ Last updated: 2017-10-30T23:32:53.000Z For those following us on [Twitter](https://twitter.com/xenorchestra?ref=xen-orchestra.com) or [Facebook](https://www.facebook.com/vatesfr), you probably saw this recently: ![](https://pbs.twimg.com/media/DD1n8n8XkAADAFt.jpg:large) The new lab is on the right. We have here: - 5x Dell T30 (Xeon E3 V5, 32 GiB RAM, 1 TiB disk) - 1x Ubnt 16x10GB/s switch for storage network We'll benchmark [XOSAN](https://xen-orchestra.com/blog/xenserver-hyperconverged-with-xosan/) with this (decent but cheap) hardware! ## XOSAN on cheap HDDs In each Dell T30, we got a Toshiba DT01ACA100: ![](https://xen-orchestra.com/blog/content/images/2017/07/DT01ACA100-unit.jpg) Check the specs: - 7200 rpm - SATA - around 50€ only! - no RAID controller, no cache into the Dell T30 Total "raw" capacity on 5 machines: 5 TiB. But XenServer is installed on each node, and left roughly 890 GiB available per host (\~4,3 TiB usable in total) But if you lose one host using a local storage, everything on that local storage is lost forever. ### Disperse 5 Creating a XOSAN on those five nodes with disperse mode will make you lose only 20% of the overall capacity, so you'll **still enjoy around 3,5 TiB available!** And **if you lose one host, the cluster will continue to work**. ![](https://xen-orchestra.com/blog/content/images/2017/07/disperse5.png) > Here, you can lose 1 disk/node/XS host without losing your data, and in this case, without even service interruption! Let's benchmark this! #### Benchmarks I added a benchmark when using one local SR only directly. This way, you'll know the performance trade off to enjoy a single converged shared storage! > FIO is used to make the benchmarks, on a Debian 9 VM. It's done on a 10GiB file (enough to avoid caching). Throughput is fetched from XenServer VDI RRDs values, which is pretty accurate and close to the "reality". IOPS are fetched from FIO directly. You can find some FIO examples in this [Sam's blog post](https://smcleod.net/benchmarking-io/?ref=xen-orchestra.com). | | Local SR | XOSAN Disperse 5 | | ------------------- | -------- | ---------------- | | Sequential reads | 177 MB/s | 214 MB/s | | Sequential writes | 174 MB/s | 106 MB/s | | IOPS Random R/W 75% | 170/50 | 2500/835 | As expected, we got a reduced performance for writes. Reads are better (because we can read on multiple disks at the same time). ##### IOPS huge boost But the real interesting thing is about IOPS: in a 75% mixed read/write mode (which is usually a good "every day" usage), **we got a tremendous boost against local SR**. x15 is both read and write! That's because **we can spread IOPS on various device**. And remember that in bonus you get: - a shared SR (XenServer HA compatible!) - you can handle one host down without any service interrupt - all of this without extra hardware needed! ### Replicated 2 In this case, you have 2 mirrors gathered in one resource (RAID0 of 2xRAID1 if you prefer, like RAID10). This will lead to roughly 1.7 TiB available, but you can lose up to 2 disks/node/XenServer host (1 per mirror). What about perfs? #### Benchmarks Same tests than Disperse, keeping previous result in order to compare: | | Local SR | XOSAN Disperse 5 | XOSAN Replicate 2 | | ------------------- | -------- | ---------------- | ----------------- | | Sequential reads | 177 MB/s | 214 MB/s | 200 MB/s | | Sequential writes | 174 MB/s | 106 MB/s | 500 MB/s | | IOPS Random R/W 75% | 170/50 | 2500/835 | 425/141 | ##### Write speed to the roof In this setup, we still beat the local HDD in terms of IOPS (by 2,5 times in read and **28 times in write**). IOPS are less impressive than in disperse, but sequential writes are ultra high (spreading write into 2 mirrors without complicated computation). #### Bonus: Windows benchs Quick benchs with Crystal DiskMark. For Replicated 2: ![](https://xen-orchestra.com/blog/content/images/2017/07/replicate2W.png) And Disperse 5: ![](https://xen-orchestra.com/blog/content/images/2017/07/distribute5W.png) And in comparison, the local storage: ![](https://xen-orchestra.com/blog/content/images/2017/07/localSRW.png) As you can see, local storage is way behind XOSAN. In a graph: ![](https://xen-orchestra.com/blog/content/images/2017/07/xosanrecapWindows.png) ## Conclusion Remember in this case, we didn't cheat with a SSD cache or anything like that. There is some options to improve sequential workload, but that's it. If we take the disperse 5 example, we got a shared SR with the cost of: - 6% of total RAM usage (2GiB per XOSAN VM) - 20% disk overhead But on this other hand: - we improved the performances a LOT - we got a virtual shared SR (XS HA possible) - you can live migrate only the VM RAM between hosts! - …which is resilient to one node failure! - **without any extra hardware to purchase!** **XOSAN turned your 5 XenServer host into a storage solution**, without consuming the compute power! > To read all our previous article on XOSAN, check our [dedicated XOSAN tag](https://xen-orchestra.com/blog/tag/xosan/). ### Xen Orchestra 5.10 URL: https://xen-orchestra.com/blog/xen-orchestra-5-10/ Last updated: 2017-08-24T06:48:58.000Z June release! It's a maintenance release with code cleanup and improved robustness. But also a big news: consoles with support of all non-US layout! ## Better consoles 6 months ago, we reported to Citrix [a problem in XenServer console management](https://bugs.xenserver.org/browse/XSO-650?ref=xen-orchestra.com) (also the cause and the solution). They backported the fix recently, so you could enjoy consoles in your local keyboard layout :) ![](https://xen-orchestra.com/blog/content/images/2017/06/keyboardlayout.png) If you want to know more about this, read our previous blog post about [XenServer consoles](https://xen-orchestra.com/blog/blog/xenserver-consoles/). > WARNING: to make it work, you need to have XS65ESP1051 (for XenServer 6.5) and XS70E033 (for XenServer 7.0). It works natively on XenServer 7.1 and 7.2\. If you have an older XenServer than 6.5, please upgrade. ## More robust backup jobs We spend a lot of times understanding XenServer behavior while exporting VM disks. It's really subtle, but we test it a LOT to improve our own code and handle better all the possible situations. Failures are now handled better, and some previous failed jobs are now even working! ### Various backup improvements More details on backup logs are provided like speed, size, status: ![](https://xen-orchestra.com/blog/content/images/2017/06/backuplogs.png) Delta backup VM disks can be restored on different SRs: ![](https://xen-orchestra.com/blog/content/images/2017/06/restore_multiple.png) ## Improved patching We also improved our patching algorithm. Get more details in [our dedicated blog post about XenServer automated patching](https://xen-orchestra.com/blog/blog/improved-xenserver-patching/). ![](https://xen-orchestra.com/blog/content/images/2017/06/patches_now_small.png) ### XenServer consoles URL: https://xen-orchestra.com/blog/xenserver-consoles/ Last updated: 2017-10-30T23:32:21.000Z In order to access your VM console, we are using a VNC HTML5 console, called "noVNC". No plugin to install, it just works ©, 3 years from now. But if you used a non-US keyboard, you probably experienced some issues with the layout. Why? ## Qemu setting issue The main problem is for all non-US layouts: you got inconsistent results in a lot of cases. Because in XenServer, the console is started with the **hardcoded keyboard layout**: ``` qemu-dm -k en-us ``` It means all other layouts will lead to strange results, and therefore being really uneasy to work with. It's confirmed on this [RedHat mailing list](https://www.redhat.com/archives/libvir-list/2009-May/msg00234.html?ref=xen-orchestra.com) message: > Our recommendation is to never set the '-k' /keymap option at all these > days. Recent QEMU / KVM and GTK-VNC releases support a VNC extension for > sending raw keycodes, instead of localized keysyms. Thus is best to leave > off the keymap in the config, and just configure it inside the guest OS. And this is exactly what we wanted to do! But first we had to wait for the wrong QEMU settings to be removed in XenServer! ## Solution in XenServer 7.1 But, since 7.1 [it changed](https://github.com/xapi-project/xenopsd/commit/0066fbf7ca30082fd97e1dce04f90f1f2994a07a?ref=xen-orchestra.com): we could just send the raw keycodes! But why waiting then? Because the bug was still present in all previous XenServer versions. So we opened an issue on [XenServer bug tracker](https://bugs.xenserver.org/browse/XSO-650?ref=xen-orchestra.com) to ask Citrix to backport their fix. Otherwise your consoles won't work. And very recently, it was available for 6.5 AND 7.0! So we merged our code (which was ready since a bit) and it will be available in our next release :) The patch in question is `XS65ESP1051` (for XenServer 6.5) and `XS70E033` (for XenServer 7.0). What about earlier versions? **They aren't supported by Citrix anymore, so there is nothing we could do!** Anyway, you'll be able to enjoy console in your preferred VM keyboard layout! ![](https://xen-orchestra.com/blog/content/images/2017/06/keyboardlayout.png) Believe me, that was a long way since we spotted the problem. Sometimes, there is some issues like this we are really glad to close. ### Improved XenServer patching URL: https://xen-orchestra.com/blog/improved-xenserver-patching/ Last updated: 2017-10-31T12:27:29.000Z Despite we already streamed the patches all the way along (download, unzip, upload **on the fly** at once), we still have ways to improve the patch fetching mechanism, **since everything changed on XenServer 7.1 and 7.2!** > Note that it was already optimized for XenServer 7.0 and before It changed so much that we had to do it a bit less "optimized" way than expected: ![](https://xen-orchestra.com/blog/content/images/2017/06/patches_before.PNG) So right now, you'll have only one stream for all: ![](https://xen-orchestra.com/blog/content/images/2017/06/patches_now.PNG) - less bandwidth used - faster to deploy - still streamed in the whole process And still, using just one click for your whole pool! ### Xen Orchestra 5.9 URL: https://xen-orchestra.com/blog/xen-orchestra-5-9/ Last updated: 2017-06-01T08:16:21.000Z Here it comes! Xen Orchestra 5.9 is now available. ## Storage health We added a new view in the existing "Health" section of Xen Orchestra. You can now monitor if there is disks mounted on your Control Domain. This is the kind of stuff that could happen in XenServer if a VM import or export failed in the middle. XenServer doesn't clean it, so right now, you can control it and remove those useless links. ![](https://xen-orchestra.com/blog/content/images/2017/05/controldomain1.png) ## Prevent storage chain issues Thanks to **our unique algorithm**, we are able to prevent storage issue while using snapshots and backup intensively. More details on our previous blog post on [coalesce detection in XenServer](https://xen-orchestra.com/blog/blog/xenserver-coalesce-detection-in-xen-orchestra/). ![](https://xen-orchestra.com/content/images/2017/05/beforemerge.png) If your chain is not healthy, a backup will fail with the `unhealthy VDI chain` message. We'll also introduce soon a dedicated chain view to be able to spot exactly which disk need to be coalesce in your storage. ## Improved continuous replication DR and CR will now also be secured by the storage chain health test before being replicated. But that's not the only improvement: you can now start easily the replicated copy on destination. **Your recovery time is now down to 0!** ## DR using less space You can now ask our DR mechanism to remove first the copied VM on destination and then to copy the new one. **It uses twice less space**, but it's more risky because if something goes wrong, you'll miss the latest copy. ## Auto patching while joining a pool When you add a host into an existing pool, you must have the same level of patching. That's a bit boring to do manually, so XOA is now managing it automatically for you if needed! ![](https://xen-orchestra.com/blog/content/images/2017/05/patchjoin.png) ## Faster patch system Patch download is optimized: download once and stream it to multiple hosts (even if there is no shared SR). This is more **bandwidth friendly** but also faster! ## Better backup reports Speed and data is now displayed in the backup reports. You can read more in our dedicated blog post regarding our [improved backup reports for XenServer](https://xen-orchestra.com/blog/blog/better-backup-reports-for-xenserver/). ![](https://xen-orchestra.com/content/images/2017/05/successfulbackup.png) ## Misc We did also a lot of small improvements: - RAM usage in memory bars while hovering them - backup report timezone - task description added - improved selects - "add all button" in self-service - and many more! ### Better backup reports for XenServer URL: https://xen-orchestra.com/blog/better-backup-reports-for-xenserver/ Last updated: 2017-10-31T12:26:44.000Z We improved our [backup report](https://xen-orchestra.com/blog/blog/xen-orchestra-4-10/#emailnotificationsforbackup) feature in Xen Orchestra. Let's see what's new. Remember that our backup reports can be sent by: - [Email](https://xen-orchestra.com/blog/blog/xen-orchestra-4-10/#emailnotificationsforbackup) - [Slack or MatterMost](https://xen-orchestra.com/blog/blog/xen-orchestra-backup-reports-to-slack/) - [XMPP](https://xen-orchestra.com/blog/blog/xmpp-for-xenserver-backups/) ### Average throughput and backup size Now we count the data transferred for each VM in your job, and the time to made it. This way, we could compute the average throughput. Example: ![](https://xen-orchestra.com/blog/content/images/2017/05/successfulbackup.png) In this case we had a backup job named "production" that have been done at **70 MiB/s** and transferred almost **4 GiB**. ### Give me colors We also added UTF-8 char to give more colors in your reports: they are supported everywhere today (email clients, Slack, MatterMost, XMPP etc.). In our case, it's not just a cosmetic change, it helps to see what's wrong more quickly in the subject: ![](https://xen-orchestra.com/blog/content/images/2017/05/failedbackup.png) ### Limit reports to failed VMs If you don't want to have a complete list of what VMs failed and what VMs have been correctly saved, we filtered that. By selecting "failure" in notifications of your job, you'll now get only which job failed. ![](https://xen-orchestra.com/blog/content/images/2017/05/failureonly.png) ## Conclusion Combined with our [new improvements on coalesce detection](https://xen-orchestra.com/blog/blog/xenserver-coalesce-detection-in-xen-orchestra/), **creating backup of your XenServer VMs is now safer AND easier to supervise**. ### Upgrade to XenServer 7.2 URL: https://xen-orchestra.com/blog/upgrade-to-xenserver-7-2/ Last updated: 2017-10-31T00:09:01.000Z Since [XenServer 7.2 is now available](https://xen-orchestra.com/blog/blog/xenserver-7-2/), we'll see how to upgrade. > Note: XenServer 7.1 is still in LTS. No emergency to upgrade on 7.2\. Though, since it's a "small" revision, the risk to upgrade is low. **[Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fupgrade%5F7.2) is 100% compatible with XenServer 7.2.** ## Download the ISO You can find it here: [http://downloadns.citrix.com.edgesuite.net/12636/XenServer-7.2.0-install-cd.iso](http://downloadns.citrix.com.edgesuite.net/12636/XenServer-7.2.0-install-cd.iso?ref=xen-orchestra.com) ## Install from USB You can also burn a CD, but USB is in general faster and easier. On a Linux system, it's trivial: ``` dd if=XenServer-7.2.0-install-cd.iso of=/dev/sdX bs=8M status=progress oflag=direct ``` On Windows, use a dedicated program that can write ISO to USB drives. ## Direct upgrade path You can upgrade your previous XenServer version directly to 7.2 since XenServer 6.2, 6.5, 7.0 and 7.1. ## Partitioning It's exactly the same as all previous XenServer 7.x version (see our previous blog post: [upgrade to XenServer 7.1](https://xen-orchestra.com/blog/upgrade-to-xenserver-7-1/#newpartitionscheme)): - / (root) 18GB - /boot/efi 512M - /var/log 4GB - Swap 1GB > Are you upgrading from an older version than XenServer 7.0? Or do you have the old partition scheme? Please [follow instructions in our previous blog post](https://xen-orchestra.com/blog/upgrade-to-xenserver-7/#usingthenewpartitions) to switch to the new one. ## Rolling pool upgrade If you have a pool with multiple hosts, there is some basic rules to follow: **Always upgrade the pool master first**: 1. Migrate VMs from your pool master to slaves 2. Upgrade the pool master 3. Migrate VMs from one slave to the pool master 4. Migrate this slave 5. Etc. > You can always live migrate VMs from an older XenServer to a newer. The opposite IS NOT POSSIBLE. Also, always check to empty your VM CD drives and disable HA during the operation. ### XenServer 7.2 URL: https://xen-orchestra.com/blog/xenserver-7-2/ Last updated: 2022-06-01T14:38:57.000Z ⚠️ XenServer 7.2 is now end of life. If you want a more recent version with all features, you can [download XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com). XenServer 7.2 is already here! Not a lot had changed since 7.1, which is pretty normal since the last release is only few months old. Official Citrix XenServer 7.2 change notes [are here](http://docs.citrix.com/content/dam/docs/en-us/xenserver/current-release/downloads/xenserver-release-notes.pdf?ref=xen-orchestra.com). > The main thing is that 7.2 clear the road for a more "continuous release" cycle, providing more regular updates via patches toward future versions on 7.x branches. **[Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=xenserver%5F7.2) is 100% compatible with XenServer 7.2.** You can download the fresh ISO here: [http://downloadns.citrix.com.edgesuite.net/12636/XenServer-7.2.0-install-cd.iso](http://downloadns.citrix.com.edgesuite.net/12636/XenServer-7.2.0-install-cd.iso?ref=xen-orchestra.com) Check our [blog post on how to upgrade to XenServer 7.2](https://xen-orchestra.com/blog/blog/upgrade-to-xenserver-7-2/). ### One-liner to deploy XOA URL: https://xen-orchestra.com/blog/one-line-to-deploy-xoa/ Last updated: 2023-04-24T17:36:02.000Z You want to quickly deploy [XOA](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xoa) (Xen Orchestra virtual Appliance) on your XenServer infrastructure? It's already **fully agentless** \-nothing to install on your hosts or VMs-, but you had to: - install XOA by downloading the XVA file on your computer - then importing it on XenServer. - finally, configuring the network inside the VM (without a console, it's a classical chicken-egg issue). But today, everything changes: **you can deploy a fresh XOA with a one-liner script!** ## Directly on XenServer SSH on your XenServer, and execute this: ``` bash -c "$(wget -qO- https://xoa.io/deploy)" ``` That's it! The script will just ask you network settings, like this for example: > Obviously, you can set a fixed IP configuration too. Just click on the URL given and XO will be displayed in your browser: - it's fast - easy - **no XVA file stored on your XenServer, it's directly streamed into your Storage Repository!** ![](https://xen-orchestra.com/blog/content/images/2017/05/xoalogin-1.png) > Why not HTTPS for the Curl thing? Because basically HTTPS is broken in XenServer host for 6.x versions (curl version from 2006…). Also, we had to write our own HTTP server to make it work because of HTTP/1.1 [compatibility](https://bugs.xenserver.org/browse/XSO-584?ref=xen-orchestra.com) [issues](https://bugs.xenserver.org/browse/XSO-740?ref=xen-orchestra.com) known in XenServer 7.0 and 7.1. ### Improving security in Xen Orchestra URL: https://xen-orchestra.com/blog/improving-security-in-xen-orchestra/ Last updated: 2021-08-10T09:35:19.000Z Since our latest update in 5.8.1, we decided to provide an extra security step for connecting to non-valid HTTPS certificates. ## Default in HTTPS As usual when you try to add a new pool/host in Xen Orchestra, we'll try to connect to XenServer API in HTTPS by default. In other words, adding a host with `myxenserver.org` is the same than adding `https://myxenserver.org`. However, since 5.8.1, **Xen Orchestra won't connect if the certificate is not valid** (self-signed or expired). ![](https://xen-orchestra.com/blog/content/images/2017/05/httpsfailed.png) By clicking on the warning message, you'll have a modal window: ![](https://xen-orchestra.com/blog/content/images/2017/05/httpsalert.png) Now, it will be automatically by-passed, as you can see with this toggle button activated: ![](https://xen-orchestra.com/blog/content/images/2017/05/ignore_cert.png) > Remember to use a HTTPS on a non-valid certificate won't protect you from man-in-the-middle attacks. ![](https://xen-orchestra.com/blog/content/images/2017/05/https.png) ## HTTP only If you want to connect in HTTP, it's possible: you'll need to explicitly set it: `http://myxenserver.org`. However, all the traffic between XOA and your pool will be in clear. ## Change a certificate in XenServer As of Xenserver and XCP-ng 8.2 and beyond, if you want to change the certificate of your hosts (used by XAPI), there are `xe` commands dedicated to this. Please follow [the documentation](https://docs.citrix.com/en-us/citrix-hypervisor/hosts-pools.html?ref=xen-orchestra.com#install-a-tls-certificate-on-your-server). You'll have to do it on all hosts of the pool. ### XOA improvements URL: https://xen-orchestra.com/blog/xoa-improvements/ Last updated: 2017-10-31T12:34:27.000Z [Xen Orchestra Appliance](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xoa) (XOA) is now providing more integrated assistance, like: - XOA health checks - XOA auto-tunnel creation for [easy remote SSH pro-support](https://xen-orchestra.com/?ref=xen-orchestra.com#!/features/support) - XOA assisted network configuration ## Helpers commands We added a `xoa` command that can deliver multiple services. ### XOA Health This command will help us to diagnose trivial issues: ``` $ xoa check ✔ Node version ✔ Disk space for /var ✔ Disk space for / ✔ XOA version ✔ xo-server config syntax ✔ Appliance registration ✔ Internet connectivity ``` We check if your XOA appliance is the [recent one](https://xen-orchestra.com/blog/blog/new-xo-virtual-appliance-2/), enough disk space on `root` and `var`, if the Node version is correct and finally if your `xo-server` configuration is YAML valid. ### Remote support By creating automatically a reverse-SSH tunnel, **we can assist you securely** even if your XOA is not exposed outside. And that's trivial for you: ``` $ xoa support tunnel The support tunnel has been created. Do not stop this command before the intervention is over! Give this id to the support: 40713 ``` With this number, we are able to access your XOA with the integrated `xoa-support` user. And when you exit the command, the secured tunnel is closed. ![](https://xen-orchestra.com/blog/content/images/2017/05/supportxoa-1.jpg) ### Assisted network configuration When you import your XOA for the first time, if you don't want to use the default DHCP option, you had to manually configure the network. Now, it's just a command to start: ``` $ xoa network static ? Static IP for this machine 192.168.100.120 ? Network mask (eg 255.255.255.0) 255.255.255.0 ? Gateway 192.168.100.254 ? IP of the DNS server 192.168.100.254 ``` If you want to come back to DHCP, also easy: ``` $ xoa network dhcp Internet Systems Consortium DHCP Client 4.3.1 Copyright 2004-2014 Internet Systems Consortium. All rights reserved. For info, please visit https://www.isc.org/software/dhcp/ Listening on LPF/eth0/5a:89:a9:a5:67:c3 Sending on LPF/eth0/5a:89:a9:a5:67:c3 Sending on Socket/fallback DHCPDISCOVER on eth0 to 255.255.255.255 port 67 interval 6 DHCPREQUEST on eth0 to 255.255.255.255 port 67 DHCPOFFER from 192.168.100.254 DHCPACK from 192.168.100.254 bound to 192.168.100.110 -- renewal in 32526 seconds. ``` ![](https://xen-orchestra.com/blog/content/images/2017/05/networkassist.jpg) ## Better support workflow Also, we improved our support platform, which is more integrated with an assisted workflow. Previously, it was mainly done by emails, now it's a full solution with history (assignment and comments date, live refresh for quick conversation etc.) And it's available in one click from your XOA! ### XenServer and XCP-ng coalesce detection URL: https://xen-orchestra.com/blog/xenserver-coalesce-detection-in-xen-orchestra/ Last updated: 2023-06-06T07:51:05.000Z We are proud to present a new feature that will help a lot to improve current [XenServer backups](https://xen-orchestra.com/?ref=xen-orchestra.com#!/features/backup) with [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com), but also to notify you when a storage repository is coalescing its disks. ## A backup problem The initial work on this was triggered by 2 symptoms. Some people could have: - `The Snapshot Chain is too Long` - `SR_BACKEND_FAILURE_44 (insufficient space)` But it was all related to the same cause. Before digging on this, let's go back to how a snapshot works. ## Quick recap on snapshots > Don't forget to take a look of this great [Citrix resource](https://support.citrix.com/supportkc/filedownload?uri=/filedownload/CTX122978/XenServer%5FUnderstanding%5FSnapshots.pdf&ref=xen-orchestra.com) on how snapshots are working. When you make a snapshot, a "base copy" is created (in read only), the "active" disk will live its own life, same for the freshly created snapshot. Example here: `A` is the parent, `B` the current/active disk and `C` is the snapshot: ![](https://xen-orchestra.com/blog/content/images/2017/05/legendsnap.png) ![](https://xen-orchestra.com/blog/content/images/2017/05/snapshot1.png) That's OK. But what about creating a new snapshot on `B` after some data are written? You got this: ![](https://xen-orchestra.com/blog/content/images/2017/05/beforemerge.png) ## Backup scenario When you make XO backup on regular basis, we'll remove old/unused snapshots. So in our case, `C` will disappear. And without this snapshot, XenServer will **coalesce** `A` and `B`: ![](https://xen-orchestra.com/blog/content/images/2017/05/parent.png) This process will take some time to finish (especially if you VM stays up and worst if you have a lot of writes on its disks). You start to get the point? ## Faster than coalescing speed What about creating snapshot (ie call backup jobs) faster than XenServer can coalesce? Well, **the chain will continue to grow**. And more you have disks to merge, longer it will take. You will hit a barrier, 2 options here: - if your VM disks are small enough, you could reach the max chain length (30) - if you VM disks are big, you'll hit the SR space limit before. Sounds familiar right? But, how to avoid this case? Hard to verify yourself if your SR can keep up the pace… ## Solution We managed something to avoid taking a new backup if the coalesce is still not finished! In fact, **we are able now to detect this** behavior and to prevent new snapshot creation. You'll be also notified (job fail) with your configured backup reports. So it won't clog your SR with a mountain of snapshots that will require hours (days!) to finish. In other words, you are now protected: you **can't backup faster than your resources could allow**. During the next job call, if the chain is correct, the backup will work. ## Going further But now we can avoid to go directly toward a wall, we could go even further: having this info in "health" section of Xen Orchestra that will report chains that are coalescing, and on which storage. This way, for any reasons (manual snapshots done too often), you will know it. ### Data Deduplication for XO backups URL: https://xen-orchestra.com/blog/data-deduplication-for-xo-backups/ Last updated: 2017-10-31T08:48:01.000Z Let's try to answer this question: by doing [XO Delta Backup](https://xen-orchestra.com/?ref=xen-orchestra.com#!/features/backup), is it possible to save some space on the remote storage while using deduplication? The answer is a bit more complicated than "yes" or "no": **it depends**. > Ultra-quick recap on deduplication: it means that the storage system identifies a block which it has already stored, only a reference to the existing block is stored, rather than the whole new block. [Read this for more](https://en.wikipedia.org/wiki/Data%5Fdeduplication?ref=xen-orchestra.com). ### Remote configuration In this example, we use a Debian VM with [ZFS on Linux](http://zfsonlinux.org/?ref=xen-orchestra.com), and enabling the deduplication feature. A NFS share is running on this, and added as a remote in XOA. ![](https://xen-orchestra.com/blog/content/images/2017/05/zfs-linux.png) ### VMs from the same template In this case, 4x VMs are created from the same template ([Debian 8 Cloud Init ready Template](https://xen-orchestra.com/blog/debian-cloud-template-for-xenserver/)). FYI, each exported VM is around 1.7GiB independently. Then, those 4 VMs are started and then the backup job manually triggered, toward the NFS Remote. Let's see the result on the disk: ``` [1.7G] 20170426T114146Z_full.vhd [1.7G] 20170426T114153Z_full.vhd [1.7G] 20170426T114021Z_full.vhd [1.7G] 20170426T114015Z_full.vhd ``` Is deduplication working? ``` # zpool list NAME SIZE ALLOC FREE EXPANDSZ FRAG CAP DEDUP HEALTH ALTROOT tank 496G 1.69G 494G - 0% 0% 4.06x ONLINE - ``` Hell yes! Only 1/4 on the space is used, because blocks from those 4 VMs are almost identical. **Dedup ratio is 4x**, but for 10 VMs from the same initial template, it would have been 10x. To good to be true? Let's try the same experiment, but by creating **manually 4 VMs with the same Operating System**. ### VMs created separately This time, the "empty" XenServer template Debian 8 is used, with a Debian ISO to install it. 4 VMs are installed separately, then started, followed by the backup task. Files seems exactly the same when I list them, but what about dedup? ``` # zpool list NAME SIZE ALLOC FREE EXPANDSZ FRAG CAP DEDUP HEALTH ALTROOT tank 496G 5.28G 491G - 0% 1% 1.29x ONLINE - ``` Only **1.29x**! Well, having up to 25% space saved in not bad, but it's not really impressive. Why? That's because blocks are not written exactly in the same place during the Debian installation on 4 different VMs. So it's harder to get the benefit of deduplication. But if you create all your VMs from the same template, it's another story. Also, keep in mind you'll get a LOT of space saved from the identical blocks (ie the initial template), then next backup with "random" data between all your VMs will limit the deduplication relevance. ## Conclusion Deduplication is not a miracle solution: **it works if there is exact same block position between your VMs disks**. In other words: VMs from the exact same base disk template. Is there another way for your backup to use less space? Delta backup are already taking only the space needed after the first full. But continuous merging is "fragmenting" the full itself: the solution would be to "compact" it (ie: remove all the useless 0's in all the blocks). That's totally doable, just need sometime to run, because we must read the whole full. And it's already in our roadmap! ### Xen Orchestra 5.8 URL: https://xen-orchestra.com/blog/xen-orchestra-5-8/ Last updated: 2017-05-01T16:24:32.000Z April release! A lot of small issues fixed plus nice enhancements: faster [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5F5.8) and streamlined XOSAN deployment. ### Faster Xen Orchestra We made good progress to [improve performances of XOA](https://xen-orchestra.com/blog/blog/xen-orchestra-always-going-faster/), especially when you fetch new 7.0 and 7.1 pool info (at the connection). In the end you got: - faster connection - less bandwidth used - less memory and CPU used [![](https://xen-orchestra.com/content/images/2017/04/bandwidthneed-1.png)](https://xen-orchestra.com/blog/blog/xen-orchestra-always-going-faster/) ### Smarter XOSAN install The process of installing XOSAN is now more optimized: - We download the pack once and multiplex the stream to all your hosts automatically - We ask for toolstack restart on your hosts when the supplemental pack is deployed the first time (to be able to connect to the XOSAN SR) In the end, it's a smoother experience to play with XOSAN! We are working hard to enter Phase II, should be a matter of weeks. Right now, we managed to: - replace a faulty node **in live** (ie: online without stopping the SR) - change a local SR for XOSAN on a node **in live** - add a new Node into XOSAN (eg from 2 to 3 nodes or more) ![](https://xen-orchestra.com/blog/content/images/2017/01/XOSANpool.jpg) ### Improved patching workflow We optimized patching for 7.1 hosts: it's not only faster to patch your whole pool in one click, it also uses less bandwidth! Another new thing is to advise users that's better to patch from the pool view with a warning message. Because we can handle all the logic (update the master first etc.) ### Backup timeout In your backup jobs, you can set a timeout (in seconds) per VM that is saved. This allows to entered in a "failed" state if your backup time took too long. And therefore, to be alerted by our plugins (email, slack, etc.) ### UI improvements - Filter for snapshots in the SR disk view: ![](https://xen-orchestra.com/blog/content/images/2017/04/filtersnaps1.png) ![](https://xen-orchestra.com/blog/content/images/2017/04/filtersnaps2.png) - Better boot menu order + disable view: ![](https://xen-orchestra.com/blog/content/images/2017/04/bootorder1.png) Possibility to edit VGA/Video RAM in VM view: ![](https://xen-orchestra.com/blog/content/images/2017/04/vga.png) - Orange icon when a host is not enabled ### Polish translation XOA is now available in Polish! ## What's next? We got a TON of exciting stuff coming soon.Stay tuned, this year will be really a new huge leap ahead for XOA! ### Xen Orchestra is always going faster URL: https://xen-orchestra.com/blog/xen-orchestra-always-going-faster/ Last updated: 2017-10-31T12:36:34.000Z We are currently working on a new optimisation of [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Ffaster) (server side), that makes everything going faster: connection time and bandwidth reduced, plus in bonus smaller memory and CPU footprint on the process itself. ## Faster connection Let's compare adding a small pool with new `xo-server` vs the current one: ![](https://xen-orchestra.com/blog/content/images/2017/04/newxofast-1.png) Initial synchronisation during pool connection is **almost twice faster** (6s vs 10s). And this should be even better on a larger infrastructure! ## Bandwidth friendly The initial sync data transfer (pool connection): ![](https://xen-orchestra.com/blog/content/images/2017/04/bandwidthneed-1.png) In other words, **30% less bandwidth used**. ## Smaller footprint What about memory and CPU usage during this first sync? Memory usage: ![](https://xen-orchestra.com/blog/content/images/2017/04/memusage.png) Basically, **7% less memory used**. But the best thing is to come, about CPU usage. First using the new `xo-server` (until second n°50), then using the old: ![](https://xen-orchestra.com/blog/content/images/2017/04/cpu-graph2.png) The **CPU load is 35% smaller** with the optimization! When this will be available (next release?), feel free to share your benchmarks! ![](https://xen-orchestra.com/blog/content/images/2017/04/fasterXO.jpeg) ### Case Study #1 - XOA at The Joint BioEnergy Institute URL: https://xen-orchestra.com/blog/xoa-at-the-joint-bioenergy-institute-a-case-study/ Last updated: 2021-03-15T13:34:09.000Z > During XO Tour 2017 in San Francisco, we met some of our customers there. Discover their stories, working with XenServer and [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fcase%5Fjbei) Appliance (XOA) on the field. ![](https://xen-orchestra.com/blog/content/images/2017/03/tour1.jpg) This case study is about Xen Orchestra Appliance deployment at [The Joint BioEnergy Institute, a place dedicated to developing advanced biofuels](https://www.jbei.org/about/?ref=xen-orchestra.com)[\[1\]](#fn1) ### Interview with the sysadmin team **Why purchasing XOA at the first place?** > JBEI's IT Operations group initially purchased XO to help us with disaster recovery. We currently use it for continuous delta backups. Reports are sent both to email addresses and a Slack channel. After purchasing some new equipment we plan to use it for continuous replication as well. Our goal is to build a cost-effective, robust, highly-available virtual infrastructure for our web servers. **What kind of features you have in mind that will help you to go to a "next level"?** > We're also moving from legacy management tools and workflows to a more automated devops model. We want to do more with fewer resources. XO's WebUI frees us from having to depend on a Windows desktop client in order to manage our VMs. XO's charts and heatmaps help us identify bottlenecks. The weekly XO resource reports warn us about missing patches and potential capacity issues and give us a one-page overview of our entire virtual infrastructure. ### About JBEI The Joint BioEnergy Institute (JBEI) is a U.S. Department of Energy (DOE) Bioenergy Research Center dedicated to developing advanced biofuels—liquid fuels derived from the solar energy stored in plant biomass that can replace gasoline, diesel and jet fuels. ![](https://xen-orchestra.com/blog/content/images/2017/03/feature-about-700x350.jpg) --- 1. "Reference in this case study to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not necessarily constitute or imply its endorsement, recommendation, or favoring by the United States Government, the U.S. Department of Energy, or The Regents of the University of California or the Lawrence Berkeley National Laboratory and its Joint BioEnergy Institute. The views and opinions expressed in the case study do not necessarily state or reflect those of the United States Government, the U.S. Department of Energy, The Regents of the University of California or the Lawrence Berkeley National Laboratory or its Joint BioEnergy Institute." [↩︎](#fnref1) ### Xen Orchestra 5.7 URL: https://xen-orchestra.com/blog/xen-orchestra-5-7/ Last updated: 2017-05-01T16:26:46.000Z March release! Almost 40 issues closed, better global UI usability and bug fixes. Oh, and **[XOSAN](https://xen-orchestra.com/blog/xosan-beta-phase-1/) is now working on XenServer 7.1!** > The complete changelog [is available here](https://github.com/vatesfr/xo-web/blob/stable/CHANGELOG.md?ref=xen-orchestra.com#570-2017-03-31). ## Shared VMs in resource set Before now, when adding a VM to a resource set, only the user could see it. Now, by clicking on "Share this VM", a user of self service can **share it to all the other users in its group!**. Very useful for a dev team :) ![](https://xen-orchestra.com/blog/content/images/2017/03/sharevm.png) ## Improved Reports The reports on your whole infrastructure are now improved. More clear, you can spot easily what's changed since the last report, having names of all your VMs and hosts displayed (instead of UUIDs). ## Install supplemental packs pool wide You have a supplemental pack that you want to install on ALL your hosts of your pool? No need to do it for each host, now just go into pool view, in "Advanced" tab: ![](https://xen-orchestra.com/blog/content/images/2017/03/packpool.png) ## Host affinity You can now choose the affinity of a VM at creation: XenServer will try to run it on your preferred host as possible. It's available in the "Advanced Settings": ![](https://xen-orchestra.com/blog/content/images/2017/03/affinity.png) You can also change the affinity anytime in the VM view into its "Advanced" tab. ## Hungarian Translation Our 6th language translated! Welcome to the Hungarian translation into XO! ![](https://xen-orchestra.com/blog/content/images/2017/03/hui18n.png) ## Auto VLAN matching when you migrate a VM to another pool, we tried previously to match the networks with the same name. If it fails, we fallback to the default network. We added an extra step before fallback: if there is no network with the same name, then we try to match the network VLAN. ### Upgrade to XenServer 7.1 URL: https://xen-orchestra.com/blog/upgrade-to-xenserver-7-1/ Last updated: 2017-10-31T00:36:52.000Z The new version of XenServer is here! And it's 100% compatible with Xen Orchestra! What's inside? - Xen 4.7 (live patching capable) - A recent Linux kernel (more drivers!) - XenServer API improvements But the most important thing: a **huge** boost in VM import/export performance. This will speed up all your Xen Orchestra backup jobs! More details about non-purely server virtualization details? Check the [official Citrix blog post](https://www.citrix.com/blogs/2017/02/23/xenserver-7-1-now-available-for-download/?ref=xen-orchestra.com). ![](https://xen-orchestra.com/blog/content/images/2015/08/Xen_Server_Logo_original.png) ## Download ISO file You can find it here: [http://downloadns.citrix.com.edgesuite.net/11988/XenServer-7.1.0-s1-install-cd.iso](http://downloadns.citrix.com.edgesuite.net/11988/XenServer-7.1.0-s1-install-cd.iso?ref=xen-orchestra.com) ## Install from USB Despite you can burn a CD with the ISO, using an USB drive is easier. On a Linux distro, it's one command: ``` dd if=XenServer-7.1.0-s1-install-cd.iso of=/dev/sdX bs=8M status=progress oflag=direct ``` On Windows, you can use any USB drive creator program. ## Default partitioning It's exactly the same as XenServer 7 (see our previous blog post: [upgrade to XenServer 7.0](https://xen-orchestra.com/blog/upgrade-to-xenserver-7/#newpartitionscheme)): - / (root) 18GB - /boot/efi 512M - /var/log 4GB - Swap 1GB > Are you upgrading from an older version than XenServer 7.0? Or do you have the old partition scheme? Please [follow instructions in our previous blog post](https://xen-orchestra.com/blog/upgrade-to-xenserver-7/#usingthenewpartitions) to switch to the new one. ## Upgrade order in a pool **Always upgrade the pool master first**: 1. Migrate VMs from your pool master to slaves 2. Upgrade the pool master 3. Migrate VMs from one slave to the pool master 4. Migrate this slave 5. Etc. > You can always live migrate VMs from an older XenServer to a newer. The opposite IS NOT POSSIBLE. ### XOSAN Beta Phase 1 URL: https://xen-orchestra.com/blog/xosan-beta-phase-1/ Last updated: 2017-07-05T21:49:32.000Z The first beta stage for XOSAN is now open! To activate your XOSAN beta, just go in the "XOSAN" menu in your (up-to-date) XOA, and click on "Register for Beta". ![](https://xen-orchestra.com/blog/content/images/2017/02/xosan-menu.png) > As soon we unlocked your beta, **you'll receive an email!** This could take some time, we'll start with a few testers first, then unlock more and more people. Be patient ;) ## XenServer Hyperconvergence The goal of this beta is to provide a first scale test of XOSAN, a thin-provisioned storage that turns all your local disks into a virtual SAN. **No SPOF, simple to use and resilient**. WARNING: **Don't use XOSAN SR for production VMs yet**. This phase 1 will allow us to test: - *Adaptability:* deploy XOSAN on a lot of various situations (ie your own XenServer infrastructure, which is *de facto* unique in terms of hardware/network/software setup) - *Resilience:* please shutdown one host and see what happens. It shouldn't be possible to lose data or even lose service if you are in the redundancy zone. At worst (ie outside redundancy number), you should expect read-only behavior. - *Automation:* if XOSAN auto-deployment works correctly ![](https://xen-orchestra.com/blog/content/images/2017/01/XOSANpool.jpg) ## XOSAN creation guide It's pretty simple. There is mainly 2 steps. ### Step 1: pre-flight check XOSAN will need a pool with: - XenServer 7 (7.1 compatibility coming soon) - Local LVM SR with at least 15 GiB of free space on each host - 2 GiB free RAM on each host for the XOSAN VM - a working connection with the updater (exactly like when you are in trial) - Our XOSAN pack installed on each hosts > The pack will just install user-space packages and add a new SR type ("xosan"). No other modification is done. Toolstack has to be restarted to be able to deal with XOSAN (no VM/service interruption). ##### Optional requirements - if you have an extra physical network for storage, that would be better - 10G networks will deliver better perfs - SSDs too, obviously ### Step 2: XOSAN creation After all the requirement are met, you can install XOSAN itself. First step is to select all local SR you want to participate to the new SR: ![](https://xen-orchestra.com/blog/content/images/2017/02/xosan1beta.png) > Here, we selected 3x SRs on 3 hosts, with each SR having 70GiB free For this small setup (3 nodes), XOSAN will suggest you 2 modes: ![](https://xen-orchestra.com/blog/content/images/2017/02/xosantypes.png) As you can see, "disperse" will offer you almost 120GiB, with the possibility to lose 1 host entirely. "Replica" for 3 hosts will mean to "triplicate" data on 3 hosts, so only 60 GiB available, but you can lose 2 hosts! We also generate a picture that recap the situation, respectively for "disperse" and "replicate", with in red the disk/nodes/hosts that can fail without losing availability: ![](https://xen-orchestra.com/blog/content/images/2017/02/disperse1xosan.png) > Disperse mode for 3 hosts: one can be lost. ![](https://xen-orchestra.com/blog/content/images/2017/02/replicate3xosan.png) > Replicate 3 mode for 3 hosts: two can be lost. You have also to select on which physical interface it will communicate: Then, just click on "Create XOSAN" and wait a bit: it will do everything until the Storage is ready: ![](https://xen-orchestra.com/blog/content/images/2017/02/xosancreate-1.png) You can now enjoy XOSAN! ### Step 3: test it! Now your XOSAN is created, it's "like" any other SR (pretty close than a NFS SR, but better: no SPOF) ![](https://xen-orchestra.com/blog/content/images/2017/02/xosancreated.png) You'll have running VMs for the storage: ![](https://xen-orchestra.com/blog/content/images/2017/02/xosanVMs.png) ### What can I expect? Probably removing/reinstalling XOSAN multiple times to test various settings, no promises on perfs for this first stage. This beta won't be able to update and modify the initially created XOSAN, so it's really "create and destroy" for now. ![](https://xen-orchestra.com/blog/content/images/2017/01/it-838384_960_720.jpg) ### What about perfs? **It's not the priority right now**: tuning will come after we are sure of reliability and easy deployment. We can always improve things after, and maybe even distribute a common benchmark template to deploy on XOSAN to centralize/compare results. ### Current limitations - you can't add new hosts to an existing XOSAN - you can't replace faulty hosts - you can't extend an existing XOSAN - some storage "combo" (redundancy/number of disks) are not yet available For all of those limitations, for now it's simple: just remove and recreate it. ### Need to add a local storage? You need a local LVM SR on each host you want to participate to XOSAN. How to do this? If you already have a free disk but if it's not a LVM SR already: - get the device name (eg with `fdisk -l`) - add the SR in XO (Add/SR/Local/Path of the device) Eg you have a free SSD into your host, called `/dev/sdc`, use this path to create the local SR. It will be used then by XOSAN to create the "shared SR" with all other local SR on all other hosts. ## What's next? This is Phase I. But then, after the first feedback and some time to develop it, another phases are in the pipes: - **Phase II:** introduce flexibility (remove/replace failed nodes, extend XOSAN when adding new nodes) - **Phase III:** performance tuning, cache system support (HDD+SSD), multiple disks per hosts… ## GlusterFS under the hood We'll create a blog post on how XOSAN works in details. **We want to thanks the GlusterFS community for their assistance and availability to answer quickly all our questions.** ![](https://xen-orchestra.com/blog/content/images/2017/02/glusterfs-square-logo.png) ### Xen Orchestra 5.6 URL: https://xen-orchestra.com/blog/xen-orchestra-5-6/ Last updated: 2017-05-01T16:26:54.000Z First release of the year, and it's a pretty nice one! A lot of new features but also the usual pile of bug fixes. > Want to meet us? If you are in Europe next Februray 4 and 5, we'll be at [FOSDEM 2017](https://fosdem.org/2017/?ref=xen-orchestra.com) near (or on) the **[Xen booth](https://blog.xenproject.org/2017/01/26/fosdem-here-we-come/?ref=xen-orchestra.com)**. Come to say hi! [![](https://xen-orchestra.com/blog/content/images/2017/01/fosdemlogo.png)](https://fosdem.org/2017/?ref=xen-orchestra.com) ### Integrated Pro Support Create an issue directly from XOA to our dedicated pro issue tracker. In the Settings/logs view, you can click on "Report issue" button, it will pre-fill the report with the issue itself: ![](https://xen-orchestra.com/blog/content/images/2017/01/bugopen.png) ![](https://xen-orchestra.com/blog/content/images/2017/01/bugopen2.png) This way, it's easier for you to report a bug and easier for us to understand it! At the end, it means better and faster support :) ### XenServer reporting For more details about this, [read our previous blog post about "XenServer PDF Reports"](https://xen-orchestra.com/blog/blog/xen-orchestra-pdf-reports/). [![](https://xen-orchestra.com/blog/content/images/2016/12/pdf.png)](https://xen-orchestra.com/blog/blog/xen-orchestra-pdf-reports/) ### File level restore improved #### Multi files zip File level restore supports multiple file restore: select each file you need, then download a ZIP containing everything! ![](https://xen-orchestra.com/blog/content/images/2017/01/multifilerestore.png) #### LVM restore Xen Orchestra is now able to restore a XenServer VM with its **disk formatted in LVM**. ![](https://xen-orchestra.com/blog/content/images/2017/01/Logical-Volume-Manager.jpg) ### Supplemental packs management You can now see all the supp pack installed on your hosts: ![](https://xen-orchestra.com/blog/content/images/2017/01/supppacks.png) **You can also upload/install packs directly from your browser!** > You have created some supplemental packs? Contact us! It would be possible to create a repository of packs accessible directly from XO: this way, pack installation will be really simple :) ### Improved patching We now handle patching in case of Xen Tools are mounted in your VMs: if a patch request to have all Xen Tools unmounted, **we'll do it automatically**! ### UI improvements This version is also improved for a lot of small things. Follow the guide! #### Better scheduler It's easier to understand how to do something "every X" (minutes, days, etc.): ![](https://xen-orchestra.com/blog/content/images/2017/01/schedulerv5.png) #### Disconnected servers Before, it was hard to understand a current host status in the Server view. Now, you can see instantly if it's connected or not: ![](https://xen-orchestra.com/blog/content/images/2017/01/serverstatus.png) #### Links to filtered home view In the pool view, clicking on big icons will lead you to a filtered view of hosts, SR or VMs from this pool: ![](https://xen-orchestra.com/blog/content/images/2017/01/poolinks.png) #### Combined stats in pool view Check [our previous article about this](https://xen-orchestra.com/blog/blog/combined-xenserver-pool-stats/). In short, you got a new consolidated overview of your pool activity: ![](https://xen-orchestra.com/blog/content/images/2017/01/newpoolstats_small.png) #### Quiesce snapshot display We forgot to re-implement this feature from previous XO UI (in 4.x). Fixed! ![](https://xen-orchestra.com/docs/assets/quiesced1.png) #### Mount local DVD or device to a VM Want to mount a local DVD or usb key to your VM? Now it's possible! ## Are you a VPS vendor? Recently, we started to have some non-negligible traction about a [WHMCS](https://www.whmcs.com/?ref=xen-orchestra.com) plugin integration with XOA. This is technically possible, but we need your help to make it real. [A thread on our forum is open to share your experience and feedback](https://xen-orchestra.com/forum/topic/401/whmcs-integration/1?ref=xen-orchestra.com), because it's invaluable to us. **Let's build this together!** ![](https://xen-orchestra.com/blog/content/images/2017/01/whmc.png) ## What about XOSAN? We are still working on it, we want to release a first beta soon, stay tuned. We'll probably make an announcement a bit after the FOSDEM. We'll send a dedicated email for registration on the closed beta, and creating the maximum feedback possible with everyone use case. Keep in mind our priorities in XOSAN development are: - Phase I: deployment and resiliency tests (validate all possible failure scenarios) - Phase II: introduce flexibility tests (remove/replace failed nodes) - Phase III: performance tuning tests All along, we'll ask testers to provide benchmarks to eliminate non-satisfactory cases (eg too slow to be in production). ![](https://xen-orchestra.com/blog/content/images/2016/12/hyperpool.jpg) ### XOSAN with 10GB link on XenServer URL: https://xen-orchestra.com/blog/xosan-with-10gb-link-on-xenserver/ Last updated: 2017-07-05T21:49:44.000Z A quick post regarding new hardware that just came for our lab: 10GB network cards to benchmark (again) [hyperconverged XenServer storage with XOSAN](https://xen-orchestra.com/blog/xenserver-hyperconverged-with-xosan/). > At the same time, a new release of XO is planned next week! Stay tuned! ## Hardware We selected compatible NICs (cf [Citrix XenServer HCL](http://hcl.xenserver.org/networkadapters/112/Intel%5F%5FEthernet%5FController%5F10%5FGigabit%5FX540%5FAT2?ref=xen-orchestra.com)): [Intel X540-AT2](http://ark.intel.com/products/60020/Intel-Ethernet-Controller-X540-AT2?ref=xen-orchestra.com). ![](https://xen-orchestra.com/blog/content/images/2017/01/10G_1_small.jpg) The switch is a [Netgear XS708E-100NES](https://www.netgear.com/support/product/XS708E?ref=xen-orchestra.com). ## New benchmarks On the existing hardware, on **3 hosts** and the possibility to lost 1 (using 66% of cumulative disk space on each host), with only one Samsung 750 EVO SSD per host, here is the new results in *Erasure Code 1*: | | XOSAN 1GBit | XOSAN 10GBits | diff | | ----------------- | ----------- | ------------- | --------- | | Sequential reads | 172 MB/s | 242 MB/s | **+40%** | | 4K reads | 24 MB/s | 24 MB/s | draw | | Sequential writes | 72 MB/s | 231 MB/s | **+220%** | | 4k writes | 13 MB/s | 13 MB/s | draw | As you can see, a 10GB network can improve a **lot** XOSAN performances for sequential data (especially writes). Note there is maybe room for improvement, there is a lot of things to tune to find the right settings. Also, small blocks aren't affected by the network performances. ## What's next? We are continuing to work on having a turnkey solution to deploy XOSAN. We are making significant progress, we hope to deliver our beta around [FOSDEM](https://fosdem.org/2017/?ref=xen-orchestra.com) event (a bit before or after). Our new 10GB network infrastructure will be also used to benchmark backup speed with XenServer and Xen Orchestra! ### XenServer hyperconverged with XOSAN URL: https://xen-orchestra.com/blog/xenserver-hyperconverged-with-xosan/ Last updated: 2017-07-05T21:49:52.000Z This is the second blog post related to make [XenServer hyperconverged](https://xen-orchestra.com/blog/blog/xenserver-hyperconverged/) in a simple way (check the previous link if you missed it!) Today, we'll see how the main replication mode will work. A next post will explain about tiering (not planned for now, but very likely this year). ## Current storage choices in XenServer In the current XenServer storage paradigm, you can: - store locally - store in a shared storage repository (SR) Both got pros and cons (this is a rough example but still): | | Local SR | Shared SR | | -------------------- | ---------------------------------------- | ------------------------------------ | | Speed | great (local hardware limit) | average to good (eg: network limits) | | Data security | none | better (depends of your SR) | | XS High availability | impossible | possible | | Cost | cheap | dedicated hardware, can be expensive | | Scalability | good (just add local disks and/or hosts) | bad (or not cheap) | To workaround this situation, you can use both techniques, but it's a kind of a manual thing to manage. So, what do we want? We need a solution which is: - fast (at least, not slow) - secure (losing one host won't destroy data) - HA compatible (native XenServer HA) - cheap (no extra/dedicated hardware to buy) - scalable (just by adding hosts in my pool) ## Solutions That's why we started to think here at Xen Orchestra. Why not providing more than an UI to administrate, a backup solution and a cloud tool? Why not having an awesome stack and keep things easy to use? So we started to work on "XOSAN", to unify **compute** and **storage**! ![](https://xen-orchestra.com/blog/content/images/2016/12/XOSANpool.jpg) ### Replication? Obviously, the initial blog post on [XenServer hyperconverged](https://xen-orchestra.com/blog/blog/xenserver-hyperconverged/) was on a very small setup (2 nodes) replicated. But on a 10 nodes setup, this solution is: - still fast - still secure (you can lost all your hosts minus 1) - HA compatible - **NOT cheap** (waste a **LOT** of space) - **NOT scalable at all** Indeed, replicating on more than 1 hosts will give a lot of overhead. Eg, if you have 12 hosts with a 500GB SSD each, you don't want to replicate data on every node. Well, this is **very** safe but you can only use 500GB of disk space. **So what can we do? We need something better!** ### Erasure code to the rescue Let's take our previous scenario: 12x hosts in the same pool, with a free 500GB SSD drive in each. Total space combined is 6TB. It means, if you use local storage on each host, you can use 6TB of space for your VMs (if you can fill each 500GB drive). **But if you lose 1 host, all the data on it are just… gone forever!** And what about replication? 500GB on 6TB means 5.5TB wasted (ouch, but you can lose all but one host, which is an ultra resilient pool!). Not good. **This is where erasure code mode come to the rescue**: this mode allows you to choose how many host you can lose without actually losing your data. - "Erasure 2" will mean I can lose 2 hosts without any problem (by losing I mean fully destroyed and unrecoverable) - "Erasure n" will allow *n* hosts lost without anything going bad. ![](https://xen-orchestra.com/content/images/2016/12/hyperpool.jpg) Let's re-use our example pool with 12 hosts and their 500GB SSD drive: | | Total space available | Space overhead | Tolerated max failures | | ------------- | --------------------- | -------------- | ---------------------- | | Local Storage | 6000GB | 0% | 0 | | Replication | 500GB | 92% | 11 | | Erasure 2 | 5000GB | 16% | 2 | | Erasure 4 | 4000GB | 33% | 4 | As you can see, this mode is really useful: it combines **a really small space overhead AND security/resiliency on your data**. > Which mode to choose in this example? Well, it's up to you! 2 failures tolerance is already good, and you'll have 5TB in your storage, which is pretty nice! #### Scalability Is it scalable? Yes, absolutely. **Even better: 12 nodes will be faster than 3**, because each piece of data will be accessed on different hosts (depending on the replication level and your network speed). Obviously, we'll run benchmark in multiples situations to validate that claim. #### A quick benchmark Remember the first replication benchmark on 2 hosts? Now I got a third node, and I can use erasure mode with 1 failure possible. In my case, I got 3x SSDs with 60GB available on each. So with "Erasure 1" mode, it means I got 120GB available in total, and if one host is down, that's OK. It's the same (cheap) hardware and (cheap) network: | | ZFS NAS | XOSAN Erasure 1 | diff | | ----------------- | -------- | --------------- | ----- | | Sequential reads | 122 MB/s | 172 MB/s | +40% | | 4K reads | 14 MB/s | 24 MB/s | +70% | | Sequential writes | 106 MB/s | 72 MB/s | \-32% | | 4k writes | 8 MB/s | 13 MB/s | +60% | The only thing that's slower is sequential write speed. This makes sense, because of the extra computing power needed to send data on all 3 nodes at the same time. And it's not bad at all, because 3 nodes is the "worst" setup possible: remember, more nodes, better performances! Also the 1 gig network could be a bottleneck, we'll investigate on a 10 gig net to check if it changes something. > **Updates**: check the numbers on a 10GiB network: ### Combined XenServer pool stats URL: https://xen-orchestra.com/blog/combined-xenserver-pool-stats/ Last updated: 2017-10-31T12:38:22.000Z Happy new year! Let's discover a new cool feature of Xen Orchestra: combined pool statistics. It means, in your XenServer pool view, there is a new "Stats" tab: ![](https://xen-orchestra.com/blog/content/images/2017/01/newpoolstats_small.png) What about it? **It combines all your hosts stats to make a great recap of what's happening in your pool!** From a really simple things to compare (load average or RAM): ![](https://xen-orchestra.com/blog/content/images/2017/01/loadavgcompare.png) ![](https://xen-orchestra.com/blog/content/images/2017/01/ramcompare.png) To more subtle stuff, like network and CPU usage: ![](https://xen-orchestra.com/blog/content/images/2017/01/cpucompare.png) > For CPUs, the sum of all cores usage for each host is made (therefore explaining the scale here at 400%) ![](https://xen-orchestra.com/blog/content/images/2017/01/networkcompare.png) > For network, all RX for each host are combined, same for TX And guess what: **it's already available in the today's patch release!** This is another step to improve your understanding of all your XenServer hosts. Enjoy :) ### XenServer Infrastructure Reports URL: https://xen-orchestra.com/blog/xen-orchestra-pdf-reports/ Last updated: 2017-10-31T12:40:25.000Z A new feature is coming soon: [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Freports) Reports: a recap of activity and usage of your whole [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver?pk%5Fcampaign=blog%5Freports) infrastructure. Those reports can be scheduled weekly or monthly and send to any email address you like. ![](https://xen-orchestra.com/blog/content/images/2016/12/pdf.png) ## A recap of all your XenServer You'll have a lot of information on your XS infrastructure: - Average usage of CPU, RAM, Disks and network for all your VMs - Top 3 VMs (in CPU, RAM, Disk and network) - Same for your hosts (average usage and Top 3) - Top 3 SRs - Hosts missing patches Here is just a quick example with page 5 of a report: ![](https://xen-orchestra.com/blog/content/images/2016/12/xoreportpage5.png) But that's not all! ## Trends After the initial report, the next one will compare automatically with previous values: this way, you can't miss any trend modification in your entire XenServer infrastructure! The report will compare: - all changes in VMs (+/- number of VMs before previous), all changes in average resource usage (in %) - same for hosts - display all new created hosts, VMs and users. But also all those have been removed. ![trend example](https://xen-orchestra.com/blog/content/images/2016/12/xoreporttrends-1.png) The goal of this feature is to help you to: - comply with some regulatory things (having the list of updates etc.) - having a clear report of what's happening - explain why you need to buy more toys for your DC ;) ### Xen Orchestra 5.5 URL: https://xen-orchestra.com/blog/xen-orchestra-5-5/ Last updated: 2017-05-01T16:27:01.000Z [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5F5.5) last release of the year and this is a pretty big one. **THE** big new feature is **file level restore** for any existing (and future) delta backups. ![](https://xen-orchestra.com/blog/content/images/2016/12/file.png) But there is even more! ## File level restore This new features is a big step forward: you can now restore individual files against restoring the whole VM. And it works on **all your existing backups** (even those done before this release). A new tab is available in the Backup view: ![File level restore tab](https://xen-orchestra.com/blog/content/images/2016/12/filelevelrestore1.png) This is the initial release of the feature, but right now, you can already: - first, select the VM backup where you want to restore file - then, select from all the previous existing backups (with their date) - next, select the VM disk and its partitions, it will display all the files inside - finally, browse the files and download those you need! ![File level restore tab II](https://xen-orchestra.com/blog/content/images/2016/12/filelevelrestore2.png) Indeed, there is room for improvement, next releases will add multiple folder/files download, send files to a remote machine directly (SMB/SSH…), temporary exposing content of a disk for users without XOA account (temporary generated link) and so on. If you have ideas and feedback, you are welcome! Current limitations are: - you must use the latest XOA ([download it from here](https://xen-orchestra.com/?ref=xen-orchestra.com#!/member/products) and [migration doc is here](https://xen-orchestra.com/docs/xoa.html?ref=xen-orchestra.com#migrate-from-an-older-xoa)) - it's not yet compatible with SMB remote. This will be fixed in the next release! ## Exclude any VM disk from backup During a delta backup job, you can avoid saving all disks of the VM. To do that, it's trivial: just edit the VM disk name and add `[NOBAK]` before the current name, eg: `data-disk` will become `[NOBAK] data-disk` (with a space or not after, doesn't matter). ## Smart backup improved Smart backup is now improved: you can use "reverse" conditions. For example, "please backup all the VMs that are…": - NOT on this pool (so all the others) - NOT having the "dev" tag - etc. This will give you a better flexibility. ![](https://xen-orchestra.com/blog/content/images/2016/12/xo5reversesmartbackup.png) ## Better select filters It's now easier to ACLs on type of objects. You can reduce the content of a select by only displaying VMs, or hosts, or pools etc. You can also add all of these objects at once with the "plus" icon: ![](https://xen-orchestra.com/blog/content/images/2016/12/xo5aclselect.png) ## Nagios backup alerts Leveraging Nagios passive checks, you can now integrate XOA Backup in your Nagios infrastructure! For more details and configuration, [read our previous article](https://xen-orchestra.com/blog/xo-backup-reports-in-nagios/). [![](https://xen-orchestra.com/content/images/2016/12/Nagios_XI_Featured_Image_Updated_Dashboard_2.jpg)](https://xen-orchestra.com/blog/xo-backup-reports-in-nagios/) ## An impressive year 2016 was an impressive year. Let's just have a quick look of all the new features we released: - [Continuous delta backup](https://xen-orchestra.com/blog/continuous-delta-backup/) - [Self service portal](https://xen-orchestra.com/blog/xenserver-self-service-portal/) - [Load balancing](https://xen-orchestra.com/blog/green-it-with-xen-orchestra-and-xenserver/) - [New UI](https://xen-orchestra.com/blog/xen-orchestra-5-0/) - [Smart backup](https://xen-orchestra.com/blog/xenserver-smart-backup-with-xo/) - [OVA Import](https://xen-orchestra.com/blog/import-ova-in-xenserver/) - [IP management for self service](https://xen-orchestra.com/blog/xenserver-vm-ip-management/) - File level restore in this very release ;) So what's next for [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5F5.5) in 2017? A **LOT** of exciting new stuff (take a look at [XenServer hyperconverged storage](https://xen-orchestra.com/blog/xenserver-hyperconverged/)). Stay in touch! [![](https://xen-orchestra.com/blog/content/images/2016/12/XOSANpool-1.jpg)](https://xen-orchestra.com/blog/xenserver-hyperconverged/) ### XenServer Hyperconvergence URL: https://xen-orchestra.com/blog/xenserver-hyperconverged/ Last updated: 2018-01-02T08:59:18.000Z Have you heard about hyperconvergence? Let's (re)discover it and explore what's possible to do with XenServer and [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fhyperconv1). **EDIT: Discover [XOSAN](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xosan-home), our software defined solution for XenServer hyperconvergence** ## Current XenServer storage paradigm In a traditional XenServer virtualization scenario, you have 2 choices to store your VM disks: **Local storage** (local HDD/SSD) or **Shared storage** (NAS/SAN). **Local storage** usage can be simple, cheap and fast. But not really appropriate in a pool of hosts: - Each time you need to migrate, it can take ages to transfer the disk content to another host. - If your host disk is destroyed, you'll lose everything on it. - no HA possible on hypervisor level. What about a **Shared storage**? That's great to migrate VMs fast (only the RAM), it's XenServer HA compatible and you have one central point to connect to. But on the other hand: - it's a dedicated piece of equipment (cost, maintenance etc.) - it's not scalable directly (it's not growing with your XenServer hosts) - it's a bit tricky when you have maintenance on your NAS/SAN The situation can be sum up like this: ![Traditional storage](https://xen-orchestra.com/blog/content/images/2016/12/classicpool.jpg) ## Hyperconvergence The goal of hyperconvergence is to merge best of both worlds (local and shared storage). Each host will be a part of a global storage, in addition to its traditional compute role. What does it look like? ![Hyperconverged setup](https://xen-orchestra.com/blog/content/images/2016/12/hyperpool.jpg) ### XenServer Hyperconverged So you want to achieve that with XenServer? Good news, we started to work on **XOSAN**. The goal of XOSAN is to provide a simple way to turn all your local storage of XenServer into a shared storage within the pool. With the help of [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fhyperconv1) :) It will bring you: - Data security (content replicated on multiple hosts) - Fast VM migration (just the RAM) between hosts because of the "shared storage" - Data scalability (size, performance and security) - High availability (if one host is down, data is still accessible from the others) - Working with XenServer HA on this shared storage to automatically bring back to life VMs that were on the faulty host. ![](https://xen-orchestra.com/blog/content/images/2016/12/XOSANpool.jpg) ### Initial tests Tests have been done with the **smallest setup possible** (2 hosts). With almost the ~~worst~~ most common hardware you can find: - 2x XS7 hosts, installed directly on 1x Samsung EVO 750 (128 GiB) each - dedicated 1Gbit link between those 2 machines (one Intel card, the other is a cheap Realtek) - data replication on both nodes As you can see, cheap SSDs and 1Gbit network only. We'll be able to analyze performances against a NAS. > The "competing" NAS is a Debian box with ZFS RAID10 (6x500GiB HDDs) and 16GiB of RAM. Let's do a quick benchmark into a VM created on this XOSAN storage (Windows 2016 + CrystalDisk benchmark on 4GiB): ![](https://xen-orchestra.com/blog/content/images/2016/12/wintoolsXOSAN4GiB.png) | | ZFS NAS | XOSAN | diff | | ----------------- | -------- | -------- | ----- | | Sequential reads | 122 MB/s | 307 MB/s | +150% | | 4K reads | 14 MB/s | 35 MB/s | +150% | | Sequential writes | 106 MB/s | 104 MB/s | draw | | 4k writes | 8 MB/s | 20 MB/s | +150% | Not bad: **2.5x faster** for read speed, 4k read speed and write speed. Sounds logical for writing on a SSD, but remember they are replicated on both hosts! > How it possible to have more than 1Gbit speed on a Gbit network for read speed? That's because the content is on both hosts. And the VM running the benchmark can read "locally" the data without be slowed down by the network. Pretty cool eh? #### Thin provisioned Also, because using a file backend, this "shared SR" is thin provisioned: ![](https://xen-orchestra.com/blog/content/images/2016/11/xosan1.png) #### More than 2 nodes This is smallest scenario possible, but next tests will come in larger installation. It will be to use not just replication but stripping data to multiple disks/hosts (like a giant RAID, sort of). #### Closed beta planned We'll create a closed beta for [XOA users](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xoa?pk%5Fcampaign=blog%5Fhyperconv1) early in 2017, for people who want to try it on non-production setup. In this way, we'll be able to validate the concept at a larger scale and streamline the process until reaching a full featured product. ## Future of XenServer and hyperconvergence The current tested setup is a first step to validate the concept. It's far from being automated yet, and some pieces will require a bit of work to stay easy to deploy. But the fantastic work of XenServer and XAPI teams on the future modular storage stack will be a very good base for pushing XOSAN to another level. ![](http://xapi-project.github.io/xapi/futures/smapiv3/smapiv3.png) > SMAPIv3 diagram Stay tuned for the Closed Beta program :) ### Xen Orchestra now available in Chinese URL: https://xen-orchestra.com/blog/xen-orchestra-available-in-chinese/ Last updated: 2016-12-05T15:22:59.000Z A quick post to tell you that [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fchinese) is now available in Chinese! Go into your user settings and switch to it: ![](https://xen-orchestra.com/blog/content/images/2016/12/xoa5Chinese3.png) Instantly, the whole app is now in simplified Chinese! ![](https://xen-orchestra.com/blog/content/images/2016/12/xoa5Chinese1.png) ![](https://xen-orchestra.com/blog/content/images/2016/12/xoa5Chinese2.png) Thanks a lot to **Kaven Chen** for the translation! ### XO Backup reports in Nagios URL: https://xen-orchestra.com/blog/xo-backup-reports-in-nagios/ Last updated: 2017-10-31T12:21:29.000Z You are probably using [XO reports](https://xen-orchestra.com/docs/backups.html?ref=xen-orchestra.com#notifications) when making XenServer backup with Xen Orchestra. You can already send those reports via emails, [XMPP](https://xen-orchestra.com/blog/xmpp-for-xenserver-backups/) or even [Slack/MatterMost](https://xen-orchestra.com/blog/xen-orchestra-backup-reports-to-slack/). But this time, we decided to also provide you a way to check if your backups were done correctly via [Nagios](https://www.nagios.com/?ref=xen-orchestra.com). ![](https://xen-orchestra.com/blog/content/images/2016/12/Nagios_XI_Featured_Image_Updated_Dashboard_2.jpg) ## Passive checks To do that, the best way is to use **passive checks**: it means it's not Nagios that will request your XOA (for backup purpose, it doesn't make sense: how could you know when to check if the backup is finished?). In fact, it's the opposite: when a backup is done, XOA will send a message to Nagios. Without any news coming from XOA after a time, Nagios can trigger an alarm. And if the backup went wrong, XOA can send the message. In order to contact Nagios, you must have NSCA running on this Nagios host. The architecture is like this: ![NSCA](https://xen-orchestra.com/blog/content/images/2016/12/nsca.png) ### On Nagios host #### Nagios configuration Just create a host for XOA: ``` define host{ use generic-host ; Name of $ host_name xoa alias Xen Orchestra Appliance address 192.168.0.245 } ``` Now, we'll create a dedicated service for XOA backups: ``` define service{ name passif-generic use generic-service service_description xoabackups host_name xoa active_checks_enabled 0 passive_checks_enabled 1 is_volatile 1 max_check_attempts 1 check_freshness 1 freshness_threshold 86400 check_command no-backup-report!0!No backup message sent in the last 24 hours } ``` Basically, this service will just wait for XOA to send backup news in the last 24 hours. By the way, the `check_command` is very basic: ``` define command{ command_name no-backup-report command_line /usr/lib/nagios/plugins/check_dummy 2 "Results of backup job were not reported!" } ``` You are set! The service is ready. If the service doesn't have news from XOA it will be in CRITICAL state like this: ![Nagios service ready](https://xen-orchestra.com/blog/content/images/2016/12/xo5nagiosset.png) #### NSCA Check your config file and add a password and a least XOR encryption: ``` password=mypassword decryption_method=1 ``` ## In XOA Just go for the Nagios plugin and configure it properly: ![](https://xen-orchestra.com/blog/content/images/2016/12/xo5nagiosplugin.png) You can even test the plugin: ![](https://xen-orchestra.com/blog/content/images/2016/12/xo5nagios2.png) If your backup is successful, you'll have this: ![](https://xen-orchestra.com/blog/content/images/2016/12/xo5nagios.png) That's it! Now, all your backups can be reported to Nagios. You are covered :) ### Xen Orchestra 5.4 URL: https://xen-orchestra.com/blog/xen-orchestra-5-4/ Last updated: 2017-05-01T16:27:08.000Z Here is a new release of Xen Orchestra, the management stack for XenServer. In this release: better UI, new views, Slack plugin for backup reports… and many more! As usual, the "raw" changelog is [available here](https://github.com/vatesfr/xo-web/blob/stable/CHANGELOG.md?ref=xen-orchestra.com#540-2016-11-23). > Don't forget to download our [brand new appliance](https://xen-orchestra.com/blog/new-xoa-available/)! ![](https://xen-orchestra.com/blog/content/images/2016/11/xoa1.png) ## Backup reports to Slack Now, your backup reports can be send directly to slack! [![](https://xen-orchestra.com/blog/content/images/2016/11/Slack_Icon.png)](https://xen-orchestra.com/blog/blog/xen-orchestra-backup-reports-to-slack/) It works also for MatterMost: ![](https://xen-orchestra.com/blog/content/images/2016/11/xo5mattermost.png) You can read more about [XenServer backup reports to slack here](https://xen-orchestra.com/blog/blog/xen-orchestra-backup-reports-to-slack/). ## UI A lot of small improvements in this version, to ease your everyday XenServer administration work. ### Dedicated SR view A new home view is available, dedicated to Storage Repositories (SRs). It's also available with the keyboard shortcut "g s": ![](https://xen-orchestra.com/blog/content/images/2016/11/xo5srhome.png) SR are sorted by size by default, but you can change the order easily: ![](https://xen-orchestra.com/blog/content/images/2016/11/xo5srhomesort.png) You can also expand lines to see the number of VDIs in the SR: ![](https://xen-orchestra.com/blog/content/images/2016/11/xo5srhomesexp.png) Obviously, you can select multiple SRs to make bulk actions. And finally, the SR status has 3 colors: - green: SR connected to all its hosts - orange: SR partially connected (one host at least but not all) - red: SR not connected to any hosts This way, you can detect quickly if you have unexpected disconnected SRs! ### Clickable tags When you click on a tag, it will automatically send you to the home view and filter on it. Very useful to "group" your VMs or whatever objects. ![](https://xen-orchestra.com/blog/content/images/2016/11/xo5tagsprod.png) ### Backups The restore backup UI is now more unified and easier to use: we are displaying all VMs at once, regardless where they are stored. You can search and filter for any VM you want to restore. ![](https://xen-orchestra.com/blog/content/images/2016/11/xo5newrestore.png) Also, restored VMs are suffixed with the date of the backup. Eg: you did a backup of a VM with the name `Alpine Mini`, November the 7th. The restored VM will have the name `Alpine mini (2016-11-07)`. ## Test plugins Some plugins require configuration that could be hard to test easily. For example, sending emails for backup reports. So we added a "Test plugin" button after an email field to send the test: ![](https://xen-orchestra.com/blog/content/images/2016/11/xo5testpluginemail.png) You'll receive an email: ``` Hi there, The transport-email plugin for Xen Orchestra server seems to be working fine, nicely done :) ``` In case of any error, it will be displayed. ## Boolean filters Want to search for shared Storage? You can use this syntax now: `shared?`. Same for `auto_poweron?` to check which VM will boot automatically if XenServer is rebooted. ## Under the hood We started to create a complete backend to report precisely all XenServer error. It's the first step toward better understanding of what's happening in some cases. ## What's next? In December, the final release of the year will deliver a very exciting new feature. Stay in touch ;) ### Xen Orchestra backup reports to Slack URL: https://xen-orchestra.com/blog/xen-orchestra-backup-reports-to-slack/ Last updated: 2016-11-18T14:16:47.000Z A nice feature for the coming [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com) 5.4 release: you already had XenServer [backup reports by emails](https://xen-orchestra.com/blog/blog/xen-orchestra-4-10/#emailnotificationsforbackup) or [via XMPP](https://xen-orchestra.com/blog/blog/xmpp-for-xenserver-backups/). Now it works with [Slack](https://slack.com/?ref=xen-orchestra.com)! ![](https://xen-orchestra.com/blog/content/images/2016/11/xo5slack.png) It's really easy to configure, it's just a plugin in XO: ![](https://xen-orchestra.com/blog/content/images/2016/11/xo5slackplugin.png) ![](https://xen-orchestra.com/blog/content/images/2016/11/Slack_Icon.png) Our [Xen Orchestra documentation](https://xen-orchestra.com/docs/backups.html?ref=xen-orchestra.com#slack-or-mattermost-notifications) is up-to-date and configuration on Slack UI is explained there. #### MatterMost And we also support MatterMost (which is an Open Source alternative) :) ![](https://xen-orchestra.com/blog/content/images/2016/11/xo5mattermost.png) Stay tuned for the 5.4 release! ### New XOA available URL: https://xen-orchestra.com/blog/new-xoa-available/ Last updated: 2017-05-01T16:27:14.000Z We [announced it](https://xen-orchestra.com/blog/blog/new-xo-virtual-appliance-2/) few days back. It's now there: the new Unified Xen Orchestra virtual Appliance. [![](https://xen-orchestra.com/assets/xoa1.png)](https://xen-orchestra.com/?ref=xen-orchestra.com#!/member/products?pk%5Fcampaign=blog%5Fnew%5Fxoa%5Fdownload) You can [download it here](https://xen-orchestra.com/?ref=xen-orchestra.com#!/member/products?pk%5Fcampaign=blog%5Fnew%5Fxoa%5Fdownload). ## Easy migration from the previous XOA 2 steps only: export the configuration from your existing XOA, in "Settings/Config" view: ![](https://xen-orchestra.com/blog/content/images/2016/10/xo5_export.png) And then, import it in the new one with a simple drag and drop: ![](https://xen-orchestra.com/blog/content/images/2016/10/xo5_import.png) That's it! Don't forget to refresh your browser to be sure everything is OK. ## Faster, better, stronger Firewall, ready for SSH support, better shell, faster because of PVHVM mode, using Debian 8, more secure with a changed password after the first login and a lot of other cool stuff. Don't forget to read the [previous blog post on the new XOA](https://xen-orchestra.com/blog/blog/new-xo-virtual-appliance-2/). ![](https://xen-orchestra.com/blog/content/images/2016/10/new_XOA.png) ### Xen Orchestra 5.3 URL: https://xen-orchestra.com/blog/xen-orchestra-5-3/ Last updated: 2017-05-03T16:26:38.000Z A new month, a new release! This one offers a big focus on overall quality (a lot of bugs fixed, that's even a new record in numbers). But there is also nice new features. ### Keyboard shortcuts You can now navigate through the app with keyboard shortcuts! By pressing the "h" (or "?") key, you'll have a popup with the list of existing shortcuts: [![](https://xen-orchestra.com/content/images/2016/09/xo5shortcuts1.png)](https://xen-orchestra.com/blog/blog/keyboard-shortcuts-in-xen-orchestra/) "Global" means those shortcuts will be available **everywhere** in the application. "Home" means they are only working in the home view. You can [discover more about shortcuts here](https://xen-orchestra.com/blog/blog/keyboard-shortcuts-in-xen-orchestra/). ### Hosts and pools RAM usage In the home view, when you are on "host": ![](https://xen-orchestra.com/blog/content/images/2016/10/notexpanded.png) Blue bars indicates the RAM usage. If you hover on it, you'll have a tooltip with a recap: ![](https://xen-orchestra.com/blog/content/images/2016/10/ram_bars_hover.png) It works the same way in the home/pool view: ![](https://xen-orchestra.com/blog/content/images/2016/10/pool_ram_usage.png) ### Hosts live usage overview In the home/host view, you can now have a stat display for all your hosts in live: ![](https://xen-orchestra.com/blog/content/images/2016/10/expanded.png) This is a good way to quickly see hosts using a lot of ressources. ### More options at VM creation We simplified the VM creation process by adding "advanced" stuff in a dedicated category. Therefore, we got more possibilities for adding extra features without render the interface unusable. You can now, during VM creation, to: - set "auto power on" - add tags - memory limits (dynamic/static min/max) ![](https://xen-orchestra.com/blog/content/images/2016/10/advanced_vm_creation.png) ### VIF edition Edit a virtual interface is not directly possible in XenServer API. The "trick" is to remove it and recreate it on the fly. It's transparent for you and now it works in Xen Orchestra! ### Network Bond creation Now, you can create a network based on multiple interfaces: a bond. ![](https://xen-orchestra.com/blog/content/images/2016/10/bondednetwork.png) ![](https://xen-orchestra.com/blog/content/images/2016/10/bondednetwork_modal.png) ## Preparing for the future We also made some very interesting explorations on backup side. Some exciting new features will come on this side in few next releases. Stay tuned! ### New XO virtual Appliance URL: https://xen-orchestra.com/blog/new-xo-virtual-appliance-2/ Last updated: 2016-10-31T09:49:20.000Z > **Update**: it's now in "stable", see In the next weeks, we'll release a new version of the virtual appliance itself, which is running Xen Orchestra. This new appliance will be unified, more secure, faster and easier to use. Let's see why! > Unified XOA? It means one XOA to rule them all. No dedicated version of Free, Starter, Enterprise or Premium. Because our updater is able to "transform" it on-the-fly. Doesn't matter if you upgrade or downgrade, just run the update and you are OK! ![](https://xen-orchestra.com/blog/content/images/2016/10/new_XOA.png) ### Security #### Sudo Root account password is now *disabled*. You'll connect via a `xoa` user, and use `sudo` to make system operations. #### Password change After your first connection to XOA with *xoa* user and *xoa* password (SSH or via console), the system will ask you to change your password. #### Firewall By default, XOA is now behind a firewall. SSH is even protected with a rate limit rule. We'll update the doc to give you more details on how to configure it if necessary, but only needed ports are open. XOA stays turnkey (you can reach it without any pre-configuration), but it's far more secure! ![](https://xen-orchestra.com/blog/content/images/2016/10/xoa_firewall.png) ### Speed This new appliance is running in PVHVM mode. In general, this give a 15% performance boost, see our previous article on [PV vs PVHVM XenServer benchmark](https://xen-orchestra.com/blog/blog/pv-vs-pvhvm-on-next-xenserver/). ### Simplicity #### Bashrc We added a bashrc file to have a beautiful prompt, helping you to have a distinct shell on XOA. The prompt also display any change in a Git repository (see the next paragraph). #### /etc in Git This will allow to track changes done in the XOA conf, and rollback if necessary. ![](https://xen-orchestra.com/blog/content/images/2016/10/xoa_git.png) #### SSH support ready A `xoa-support` account exists, but can only log via a SSH key pair (no password), that we only have (ie the private key). If you don't want this, you can disable the account with the `chage -E 0 xoa-support` command. ### Built for tomorrow Extra packages are also include for future possibilities in XOA. It also includes the latest LTS version of Node (6). ### Want to test it? > **Update**: it's now in "stable", see ### Keyboard shortcuts in Xen Orchestra URL: https://xen-orchestra.com/blog/keyboard-shortcuts-in-xen-orchestra/ Last updated: 2016-10-03T08:22:29.000Z We just introduced keyboard shortcuts in Xen Orchestra. That's just a start, but it will be very useful to accelerate your every day Xen management operations. ## Discover your shortcuts Just press the "h" (or "?") key, it will display a modal window with the list of all existing shortcuts: ![](https://xen-orchestra.com/blog/content/images/2016/09/xo5shortcuts1.png) We use combo keys, which is better to keep it simple and not to clash with browser/OS shortcuts. ### Global Those shortcuts are available everywhere (in any view). You can go to the home view (displaying VM or pools or hosts) or create a new VM ### Home view You can get the search field focus, or browser all the lines with the keyboard and with enter, going in the object detail. This way, you can avoid using your mouse for some operation. ### What's next? We'll add needed shortcuts: our goal is to avoid creating too many of them but just select those are really important for your productivity. Feel free to drop comments for suggestions :) ### Xen Orchestra 5.2 URL: https://xen-orchestra.com/blog/xen-orchestra-5-2/ Last updated: 2017-05-01T16:27:20.000Z Xen Orchestra 5.2 is here! In this **big** release, there is 30 bug fixes and more than 30 enhancements, like: - Smart backup - OVA import - IP management (VIF locking and IP reservation) - SSH keys management - new VM from a snapshot - log view - lot of improvements and bug fixes Want to see the changelog? [Follow this link.](https://github.com/vatesfr/xo-web/blob/stable/CHANGELOG.md?ref=xen-orchestra.com#520-2016-09-09) ### Smart backup No need to pick your VMs one by one: you can automatically backup bulk VMs by location (pool, host), status (all, running, halted) or even by tags. [Go read more on our dedicated blog post!](https://xen-orchestra.com/blog/blog/xenserver-smart-backup-with-xo/) [![](https://xen-orchestra.com/blog/content/images/2016/08/xo5smartbackup1.png)](https://xen-orchestra.com/blog/blog/xenserver-smart-backup-with-xo/) ### OVA import You can now import your OVA files (tested with OVF 1.0 format, coming from VirtualBox)! [![](https://xen-orchestra.com/blog/content/images/2016/08/xo5import2.png)](https://xen-orchestra.com/blog/blog/import-ova-in-xenserver/) It's just a drag and drop inside the UI, and you're set. Read more in our blog post about [how to import OVA in XenServer](https://xen-orchestra.com/blog/blog/import-ova-in-xenserver/). ### IP management You can now, as an admin, make IP range reservation that you will assign to some VIFs of your VMs. What does it mean? It means non authorized IPs in the VM will be blocked. Want to know more? Go [read our dedicated blog post about XenServer IP management](https://xen-orchestra.com/blog/blog/xenserver-vm-ip-management/). > This feature was sponsored by [Neuronnexion](http://www.neuronnexion.coop/?ref=xen-orchestra.com) ![](http://www.as9036.net/images/nnx_logo.png) ### SSH keys management For your [compatible CloudInit XenServer VM templates](https://xen-orchestra.com/blog/blog/full-cloudinit-power-in-xenserver/), you can store your SSH keys. But also manage them. We already made a blog post about it: [SSH key management with Xen Orchestra for XenServer](https://xen-orchestra.com/blog/blog/ssh-keys-management-in-xen-orchestra/). [![](https://xen-orchestra.com/blog/content/images/2016/08/xo5sshinstall3.png)](https://xen-orchestra.com/blog/blog/ssh-keys-management-in-xen-orchestra/) ### New VM from a snapshot You created a snapshot and you want to check what's inside. But you don't want to revert your current VM? Now it's easy to create a VM from this snapshot, just by clicking on a button: ![](https://xen-orchestra.com/blog/content/images/2016/09/xo5newvmfromsnapshot.png) ### Logs You have now a dedicated log view, in "Settings". It allows to check every error possible in XO without the need to SSH on XOA and read the `syslog`. You can filter in live, and display the stack trace. It will be very useful to track any issues (both on XenServer or XOA side). ![](https://xen-orchestra.com/blog/content/images/2016/09/xo5logview.png) ![](https://xen-orchestra.com/blog/content/images/2016/09/xo5logviewdetails.png) ### Better console view 2 new possibilities: collapse the top content in the console view, and/or resize on the fly the console. Non-collapsed vs collapsed (left to right): ![](https://xen-orchestra.com/blog/content/images/2016/09/xo5console4.png) Console size changed: ![](https://xen-orchestra.com/blog/content/images/2016/09/xo5console3.png) ### Max concurrent jobs When you start to use [smart backup feature for XenServer](https://xen-orchestra.com/blog/xenserver-smart-backup-with-xo/) using Xen Orchestra, you could trigger a LOT of simultaneous (concurrent) jobs. We fixed this by allowing 2 jobs in parallel at max. It solves all previous issues regarding XenServer host performances while doing those backups. ### Better backup reports Your emails for backup reports are better now. First, the subject will be using this format: `[Xen Orchestra][Success | Failure] Backup report for $tag` So a failed backup job will be: `[Xen Orchestra][Failure] Backup report for PROD_VMs` Also, the email will embed the exact error message during the backup, therefore you will be able to track the problem easily! ## Bug fixes We also fixed a lot of small annoying issues, in general the whole application handle more XenServer edge cases! The complete change log is available here: [Xen Orchestra 5.2 changelog](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#520-2016-09-09). ### XenServer VM IP management URL: https://xen-orchestra.com/blog/xenserver-vm-ip-management/ Last updated: 2016-09-09T07:20:20.000Z This blog post is intended as a quick guide to VM IPs restriction and management for your XenServer infrastructure. ## Concepts The API of XenServer, XAPI, is working at the hypervisor level. In other words, it can't interfere with things inside VM's operating system. On the other hand, it can block/authorize network communication regarding the IP of the VM. This is called "VIF Locking" (VIF = Virtual InterFace) ### Add IPs (or full range) From an administrator perspective, adding IP addresses is simple: just declare addresses (or ranges), on which network, and you're done! ![](https://xen-orchestra.com/blog/content/images/2016/09/createip-range.png) ![](https://xen-orchestra.com/blog/content/images/2016/09/displayiprange.png) ### VIF locking By default, nothing is locked. A user can set any IP in its VM, and it will work. If you add restricted IPs, the VIF will be locked and then, only those assigned IPs will be able to do get out of the VM. In the VM view, on Network tab, see the new row "Allowed IPs": ![](https://xen-orchestra.com/blog/content/images/2016/09/addip.png) Click on the "Plus" icon to add authorized IPs: ![](https://xen-orchestra.com/blog/content/images/2016/09/addiplist.png) Done! ![](https://xen-orchestra.com/blog/content/images/2016/09/ipadded.png) ### Network locking mode To change the default behavior (from "everything authorized" to "allow only authorized IPs"), you can modify a network, where VIF resides, to block everything until IPs are allowed. See the "Default Locking mode" row: ![](https://xen-orchestra.com/blog/content/images/2016/09/networklock.png) This time, a VM without allowed IP won't be able to do anything. ## Sponsor This feature was sponsored by [Neuronnexion](http://www.neuronnexion.coop/?ref=xen-orchestra.com). [Neuronnexion](http://www.neuronnexion.coop/?ref=xen-orchestra.com) is an internet operator providing network and hosting services based as much as possible on Free Software. ![](http://www.as9036.net/images/nnx_logo.png) Neuronnexion wanted to provide a simple yet complete and easy to use web interface to allow their customers to manage their own server infrastructure. ### Testimony > We fell in love with Xen Orchestra and the reactivity of its team. > The self service functionality of Xen Orchestra was perfect to allow our customers to autonomously manage their server infrastructure but one crucial feature was missing: IP Addresses management. > How would users know which IP address they are allowed to use? How can we prevent IP spoofing? > **We hadn't the resources to contribute to Xen Orchestra with a patch, instead we thought about sponsoring that feature.** > **Thanks to the fantatic Xen Orchestra's developper team, and their awesome coding skills, we are glad to see the IP resource management feature released in this new version of Xen Orchestra!** ### OVA import in XenServer URL: https://xen-orchestra.com/blog/import-ova-in-xenserver/ Last updated: 2016-08-31T15:21:51.000Z This is a very exciting feature coming for the next release of Xen Orchestra: **a simple and powerful way to import your OVA files into XenServer!** ## Just a drag'n drop The goal, as usual, is to make this very easy. We currently support OVA with VMDK disks included, exported from VirtualBox. Let's see a real example! ### From VirtualBox to OVA This Debian VM is running fine on VirtualBox: ![](https://xen-orchestra.com/blog/content/images/2016/08/vbox1.png) Now, we'll stop and export it: ![](https://xen-orchestra.com/blog/content/images/2016/08/vbox2.png) ![](https://xen-orchestra.com/blog/content/images/2016/08/vbox3.png) ![](https://xen-orchestra.com/blog/content/images/2016/08/vbox4.png) That's it! You got an OVA file (roughly 600MB): ![](https://xen-orchestra.com/blog/content/images/2016/08/xo5ova.png) ### Drag'n drop into Xen Orchestra This is trivial: go into the import view, then choose your Pool and on which storage you want to import it. Then drag and drop the OVA file: ![](https://xen-orchestra.com/blog/content/images/2016/08/xo5import1.png) You can modify the OVA configuration as needed: ![](https://xen-orchestra.com/blog/content/images/2016/08/xo5import2.png) When the import is started, there is a task ongoing: ![](https://xen-orchestra.com/blog/content/images/2016/08/xo5import3.png) On the VM new, you can see the VM is labelled "\[Importing...\] Debian": during the transfer, **you can't boot it**. This will avoid any data corruption. ![](https://xen-orchestra.com/blog/content/images/2016/08/xo5import4.png) It's done, now just boot it, you're in! ![](https://xen-orchestra.com/blog/content/images/2016/08/xo5import5.png) #### OVA support We support all OVA with bundled disks (OVF 1.0), in the "Streamable VMDK format": basically, all VirtualBox exports. ### SSH keys management in Xen Orchestra URL: https://xen-orchestra.com/blog/ssh-keys-management-in-xen-orchestra/ Last updated: 2016-08-12T07:44:43.000Z Remember our article on playing with [CloudInit and XenServer](https://xen-orchestra.com/blog/blog/full-cloudinit-power-in-xenserver/) thanks to Xen Orchestra? We managed to improve our UI to get it even easier. Let's take a tour. ### Manage your SSH keys In your user zone, you can manage your keys (create, remove). Click on "New SSH key": ![](https://xen-orchestra.com/blog/content/images/2016/08/xo5sshkeys1.png) Then fill the key zone. We'll automatically fetch the key name (user@host at the end): ![](https://xen-orchestra.com/blog/content/images/2016/08/xo5sshkeys2.png) You're done: ![](https://xen-orchestra.com/blog/content/images/2016/08/xo5sshkeys3.png) ### Create a VM to use your key(s) Now we got our "brucewayne@mypc" key, let's create a VM. Use a template with existing disks and CloudInit ready. For those who want a recap, don't forget to read our previous blog posts on this topic: - [use CloudInit with XenServer](https://xen-orchestra.com/blog/blog/cloudinit-support-for-xenserver/) - download free CloudInit [XenServer templates of CentOS](https://xen-orchestra.com/blog/blog/centos-cloud-template-for-xenserver/) or [Debian](https://xen-orchestra.com/blog/blog/debian-cloud-template-for-xenserver/) In the "Install settings" category, activate "Config drive" option: ![](https://xen-orchestra.com/blog/content/images/2016/08/xo5sshinstall1.png) We automatically add the first existing key. If you create a VM right now with this setting, user "brucewayne" with his key can access the VM without a password. But we did more. #### Create keys on the fly Maybe you want to add a key without going back to your user zone (because you set a lot of things in the current VM creation view). No problem, just fill the "SSH key" field and click on "+" icon. It will add the key in the select and save it for later use: ![](https://xen-orchestra.com/blog/content/images/2016/08/xo5sshinstall2.png) And it's added: ![](https://xen-orchestra.com/blog/content/images/2016/08/xo5sshinstall3.png) If you create the VM now, both users with their keys can access the VM without a password. And if you go back to your user zone, you can see all these news keys: ![](https://xen-orchestra.com/blog/content/images/2016/08/xo5sshrecap.png) **This feature will help you to create VMs in few clicks and seconds, without anything to manually enter after your keys are saved.** ### Install XenServer tools in your VM URL: https://xen-orchestra.com/blog/install-xenserver-tools-in-your-vm/ Last updated: 2022-06-02T15:55:01.000Z This blog post is for people discovering Citrix Hypervisor/XenServer, and wonder about how to install tools (or xen tools) in their VMs. And also what are those tools. ℹ️ **Did you know?** XCP-ng is a drop-in free and 100% compatible replacement for XenServer/Citrix Hypervisor. Go take a look on [XCP-ng website](https://xcp-ng.org/?ref=xen-orchestra.com)! It's also a guide to install xentools for both Linux and Windows VMs. First, we'll see how to check if tools are installed, and then, install those if necessary, on both Linux and Windows. 💡 This guide is 100% identical if you are using [XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com) instead of Citrix Hypervisor/XenServer! ## Are tools installed? It's really easy to check this with [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com): in the home view, a running VM without any operating system icon don't have tools: ![](https://xen-orchestra.com/blog/content/images/2016/08/noOSiconnotools.png) See the difference with a "correct" VM (Debian logo): ![](https://xen-orchestra.com/blog/content/images/2016/08/xentoolsvisible.png) You can also **display all running VMs without tools thanks to the following search**: `power_state:running !xenTools:""` ![](https://xen-orchestra.com/blog/content/images/2016/08/noxentoolsfilter.png) > Here, two running VMs are without tools In the VM view, you can also read "No Xen tools detected.": ![](https://xen-orchestra.com/blog/content/images/2016/08/noxentoolsdetected.png) ## Install XenServer tools Next step is to install those tools. Also I'll give you some tips. For any VM, go in the console view on your VM, and insert the appropriate ISO: - `xs-tools.iso` for XenServer 6 and older - `guest-tools.iso` for XenServer 7 and high Then, each system is a bit different. ### For Linux VMs #### Debian, Ubuntu (deb based) For a Debian VM, it's pretty simple, as `root`: - `mount /dev/cdrom /mnt` - `bash /mnt/Linux/install.sh` - `umount /dev/cdrom` In a real example: ``` root@myVM:~# mount /dev/cdrom /mnt mount: block device /dev/xvdd is write-protected, mounting read-only root@myVM:~# bash /mnt/Linux/install.sh Detected `Debian GNU/Linux 7.9 (wheezy)' (debian version 7). The following changes will be made to this Virtual Machine: * update arp_notify sysctl. * packages to be installed/upgraded: - xe-guest-utilities_7.0.0-24_all.deb Continue? [y/n] Y (Reading database ... 37679 files and directories currently installed.) Preparing to replace xe-guest-utilities 6.2.0-1133 (using .../xe-guest-utilities_7.0.0-24_all.deb) ... Stopping xe daemon: OK Unpacking replacement xe-guest-utilities ... Setting up xe-guest-utilities (7.0.0-24) ... Installing new version of config file /etc/init.d/xe-linux-distribution ... $Detecting Linux distribution version: OK $Starting xe daemon: OK You should now reboot this Virtual Machine. root@myVM:~# ``` That's all! You can eject the ISO now. As soon the `.deb` is installed, tools will report their info: **no need to reboot!** #### CentOS, RHEL (rpm based) Same principle, almost same procedure than on a Deb based distro: ``` # mount /dev/cdrom /mnt/ mount: block device /dev/xvdd is write-protected, mounting read-only [root@localhost ~]# bash /mnt/Linux/install.sh Detected `CentOS release 6.6 (Final)' (centos version 6). The following changes will be made to this Virtual Machine: * update arp_notify sysctl. * packages to be installed/upgraded: - xe-guest-utilities-7.0.0-24.x86_64.rpm - xe-guest-utilities-xenstore-7.0.0-24.x86_64.rpm Continue? [y/n] y Preparing... ########################################### [100%] 1:xe-guest-utilities-xens########################################### [ 50%] 2:xe-guest-utilities ########################################### [100%] You should now reboot this Virtual Machine. [root@localhost ~]# ``` > Nope, rebooting is not mandatory. ### For Windows VMs After loading the appropriate ISO, you should see a CD with tools: ![](https://xen-orchestra.com/blog/content/images/2016/08/windowsxentools.png) Start the `setup.exe`: ![](https://xen-orchestra.com/blog/content/images/2016/08/windowsxentools2.png) ![](https://xen-orchestra.com/blog/content/images/2016/08/windowsxentools3.png) This time, you must reboot. After the initial reboot, your Windows OS has tools but also extra drivers for Xen (better perfs), eg in your device manager: ![](https://xen-orchestra.com/blog/content/images/2016/08/windowsxentools4.png) #### Windows quiesce snapshots You have the agent management, but that's not enough if you want to take quiesced snapshots! ![](https://xen-orchestra.com/blog/content/images/2015/11/quiesceinstall2.png) You can read mon on quiesce snapshots on our previous blog post: [XenServer quiesce snapshots](https://xen-orchestra.com/blog/xenserver-quiesce-snapshots/) ## What those tools are doing? Basically, goals of those tools are: - to report extra VM info (that only the Operating system can know, not your underlying hypervisor), like VM IP address, kernel version etc. - communicate with the OS in case of quiesce snapshots (Windows and its VSS) - allow sending signals to the OS (clean reboot, hotplug hardware etc.) ## Update tools You want to update tools? Just do the same procedure than for installing them. XenServer Enterprise users can enjoy Windows Update doing the work of updating those tools too (but sadly, it's not in the free edition of XenServer). 💡 [XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com) users can rely on Windows Update to keep their drivers up-to-date, and that's 100% free! ### XenServer smart backup with XO URL: https://xen-orchestra.com/blog/xenserver-smart-backup-with-xo/ Last updated: 2016-08-01T10:14:43.000Z This summer, we'll release an exciting new backup feature for [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver). ## Current backup process To backup one or more VMs in [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/), you need to select them initially. For example, you want to backup VMs "prod\_1", "prod\_2", "prod\_3" and "prod\_4": ![](https://xen-orchestra.com/blog/content/images/2016/08/xo5normalbackup.png) But if later, you decide to create a new VM, let's say "prod\_5", you **must edit the backup job** to add it. Targeting specific VMs for backup is great in some cases, but less in others. ## New smart backup So we created "smart backup"! You have now more flexibility: you won't select specific VMs, but VMs status/tag/placement **at the time backup job will be executed**. Let's see some examples! #### Backup all VMs on a pool This job will backup all VMs on a pool "Lab Pool" when scheduled: ![](https://xen-orchestra.com/blog/content/images/2016/08/xo5smartbackup1.png) It means: **every VM existing on this pool at the backup schedule will be backup**. Doesn't matter if you create a new VM, it will be backup too without editing any backup job. **You can now plan a smart backup on a production pool when only important VMs are**. Want to narrow the job a bit? See below. #### Backup filters You can also: - backup only running (or halted) VMs when the job is executed - backup only VMs with a tag Remember the Prod VMs? I added a tag "prod" for each of them: ![](https://xen-orchestra.com/blog/content/images/2016/08/xo5smartbackuptag.png) Now if you do this: ![](https://xen-orchestra.com/blog/content/images/2016/08/xo5smartbackup2.png) It means any VMs on "Lab Pool" with the "prod" tag will be backup. > This feature will be available in Xen Orchestra 5.2, planned this month! ### Xen Orchestra 5.1 URL: https://xen-orchestra.com/blog/xen-orchestra-5-1/ Last updated: 2017-05-01T16:27:26.000Z And it's done: Xen Orchestra 5.1 is available! In short: - new UI is by default, the old one is still accessible when adding "/v4" in the URL - we added a lot of great UI features (see the content below) - we fixed a lot of small issues due to fresh UI In fact, that's a pretty big release: **we closed 75 issues in one month!** ### UI improvements Thanks to a lot of feedback from everywhere (customers, community), we were able to improve greatly the new UI. Let's take a tour of what you can do now. #### Save your (default) search That's the big step forward for a powerful AND customizable interface. ##### Save a search Want to use a search you are doing often? Type it, see the result, and then use the "Save" icon. Example: I want to only display my production running VMs. Let's say I use a "prod" tag for those VMs: `power_state:running tags:prod` ![](https://xen-orchestra.com/blog/content/images/2016/07/xo5searchfilter1.png) Now, if I click on "Save", I can save this search and give it a name: ![](https://xen-orchestra.com/blog/content/images/2016/07/xo5searchfilter2.png) Finally, I can find it in the existing Filter list (see "Prod"): ![](https://xen-orchestra.com/blog/content/images/2016/07/xo5searchfilter3-1.png) Obviously, you can use it (and combine it!) for far more advanced filters, like filtering by pool, hosts, virtualization mode, whatever you need! ##### Managing saved search Now you have saved a search, let's manage it: edit or remove it. Go inside your user settings: ![](https://xen-orchestra.com/blog/content/images/2016/07/xo5searchfilter4.png) You can remove or edit an existing filter. You can also set a default filter for each type view (VM, Host or Pool view). This way, every time you go on the home view, this default filter will be applied! #### Smart migration system Migrating multiple VMs at once can be complicated. Imagine you want to migrate various VMs from various pools to a specific host: - some VMs can be on the same host that you want to migrate to (no need to migrate) - some others can be on another host in the same pool (no need to migrate networks) - plus some of them can be on a shared SR (no VDI migration needed) - finally, others can be on a different pool (need to migrate both storage and network) We are now managing all of these cases at once: don't bother to think, select any VMs you want to move and do it. Also, we have a "smart network mapping": if we found a same network name on the destination, we'll bind to it. #### Improved backup scheduler We are now able to display the XOA timezone for scheduled backup. You can also select your own timezone when you set your backup/DR/whatever! ![](https://xen-orchestra.com/blog/content/images/2016/07/xo5backupTZ.png) #### Better patches display It's very easy now to see any missing patch. See our previous blog post: [now you can't miss a XenServer patch](https://xen-orchestra.com/blog/hotfix-xs70e004-for-xenserver-7-0/#nowyoucantmissapatch). ![](https://xen-orchestra.com/blog/content/images/2016/07/patches1v5.png) #### Submenu for Home view You can now directly select which type of object you want to display in the home view, via the menu: ![](https://xen-orchestra.com/blog/content/images/2016/07/xo5menuhome.png) #### Plugin presets For helping users to manage their plugins, we added "presets" to guide you. ### Hotfix XS70E004 for XenServer 7.0 URL: https://xen-orchestra.com/blog/hotfix-xs70e004-for-xenserver-7-0/ Last updated: 2016-07-08T08:19:08.000Z > WARNING: everyone using XenServer 7 **MUST** update with this patch. We'll provide more details about this issue in a coming blog post, until then, you read more about [possible data loss or corruption on XenServer 7.0](http://support.citrix.com/article/CTX214768?ref=xen-orchestra.com) Good news: it's easier than even with Xen Orchestra 5 and its powerful new UI! Installing a patch need few clicks, and **everything is automated**: patch will be fetched, downloaded and uploaded at once, without anything more to do! ## Now, you can't miss a patch Xen Orchestra will give you the info on a missing patch in multiple ways. Let's see each one of them. ### Dashboard The place where we recap all data of every pool, host and VM connected to your XOA. And there is a place where it lists all hosts which need an update (and how many of them): ![](https://xen-orchestra.com/blog/content/images/2016/07/patches4v5.png) > Note that you can install all updates for all hosts on all your pools in one click! ### Home view on pool When you select to display all pools, you'll see a "red pill" with a number of missing fixes: ![](https://xen-orchestra.com/blog/content/images/2016/07/patches1v5.png) ### Pool view In the patch tab, you can update all host at once, or host by host: ![](https://xen-orchestra.com/blog/content/images/2016/07/patches2v5.png) ### Host view Host view will notify of an update with a "red pill" in the Patch tab. In this tab, you'll see all missing patches, and all installed patches: ![](https://xen-orchestra.com/blog/content/images/2016/07/patches3v5.png) ### Better XenServer graphs with Xen Orchestra URL: https://xen-orchestra.com/blog/better-xenserver-graphs-with-xen-orchestra/ Last updated: 2016-07-01T12:31:43.000Z We are now one week after the [release of Xen Orchestra 5.0](https://xen-orchestra.com/blog/xen-orchestra-5-0/), and we managed to made significant progress on resource reporting. This is a first glimpse of what's already done! ## Parallel coordinates graph > Parallel coordinates is a common way of visualizing high-dimensional geometry and analyzing multivariate data. *[Wikipedia](https://en.wikipedia.org/wiki/Parallel%5Fcoordinates?ref=xen-orchestra.com)* This graph is now also available in 5.0, and it's very useful! We currently have 5 dimensions: vCPUs number, RAM quantity, VIF number, VDI number and total disk space. ![](https://xen-orchestra.com/blog/content/images/2016/07/parcoords.png) You can interact with the graph in various ways: - hover on each line to discover the VM name - select ranges to highlight automatically VMs in this range (eg VMs between 0 and 1,5 GiB of RAM used) - combine this on multiple axis It's really helpful to discrimated specific VMs or to understand your most common VM configuration. ## Sum graph Want to know the total disk writes of all VM your disks? Toggle the "sum" button in any stat view, and you'll see new lines. Example: ![](https://xen-orchestra.com/blog/content/images/2016/07/XO5graphsum.png) > Sum of all writes for a VM on the dotted black line ## Next? Stay tuned, as usual, a lot of awesome stuff is on the way ;) ### Xen Orchestra 5.0 URL: https://xen-orchestra.com/blog/xen-orchestra-5-0/ Last updated: 2017-05-01T16:27:32.000Z Here we are! Xen Orchestra 5.0 is available, and **it's awesome**. Also, it's our biggest release ever (**[60 issues closed](https://github.com/vatesfr/xo-web/issues?q=milestone%3A5.0+is%3Aclosed&ref=xen-orchestra.com)** on the 5.0 milestone). TL;DR: - new UI from scratch - awesome performances - a bunch of new features - translated in **English, French, Portuguese and Hebrew** - and bug fixes This is also the start of a brand new branch [with a lot of exciting innovations](https://xen-orchestra.com/blog/blog/xo-5-x-goals/). Let's already see what we got in this 5.0 version. As you can see, the commit activity is huge since we started to work on 5.0: ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5commitsactivity.png) > Parallel release > For the first time, we decided to release it in parallel (ie without replacing) the 4.16 version. All XOA users can access this new UI by adding `/v5` in their current XOA URL. > Eg: `https://myXoaUrl/v5` > The "old" interface will be still the default until a next release: we want to be sure everything is fine before changing this! > Please report feedback in our dedicated topic: [https://xen-orchestra.com/forum/topic/250/xoa-v5-feedback](https://xen-orchestra.com/forum/topic/250/xoa-v5-feedback?ref=xen-orchestra.com) ### Perfect XenServer 7 support It's not only we support the great new XenServer 7: Xen Orchestra is now even better with it. Because Citrix teams made a fantastic job in fixing issues, we can leverage more and more features without any bugs. Check [our blog post on how XenServer 7 (Dundee) is great](https://xen-orchestra.com/blog/xenserver-7/). ### Serious scale We built this release by checking constantly the performances on installations with more than 1000 VMs. Yes, you read it correctly. **It's blazing fast, even with thousands VMs**. Oh and by the way, it consumes less memory! ![](https://xen-orchestra.com/blog/content/images/2016/06/seriousscale.png) > Things getting serious Here is the home view loading time between XO 4 (current) and XO 5 (in ms, less is better), with respectively 50 and 1200 VMs: > **Respectively 8 and 38 times faster!** ### More tests We found some ways to make more tests, on both XenServer and Xen Orchestra, to do more QA before releasing anything. We are injecting artificial events in the XAPI (XenServer API) to simulate huge infrastructures. Also, some of our customers were very helpful and gave us the opportunity to make real scale tests in their own XenServer environment. It helped a lot to improve global quality of Xen Orchestra! ### New UI We've made some previous blog posts about the new awesome web interface we got in Xen Orchestra, giving you the best XenServer web solution than ever: - [dev report 1](https://xen-orchestra.com/blog/blog/dev-report-1-on-xen-orchestra-5-0/) - [dev report 2](https://xen-orchestra.com/blog/blog/dev-report-2-on-xen-orchestra-5-0/) - [dev report 3](https://xen-orchestra.com/blog/blog/dev-report-3-on-xen-orchestra-5-0/) - [dev report 4](https://xen-orchestra.com/blog/blog/dev-report-4-on-xen-orchestra-5-0/) What does it bring for real? See below. #### Responsive at all stages Combining break points and viewport-percentage lengths, we could deliver a smooth experience on a lot of devices: ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5responsive.png) #### Editable fields everywhere You can edit VMs names, disks, hosts, whatever in one click! Everywhere you see a dotted underlined text, it's quick and easy: ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5editable.png) ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5editable2.png) ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5editable3.png) You can even undo the operation by clicking on the green check. ![](https://xen-orchestra.com/blog/content/images/2016/06/68648056.jpg) But what about content which is a link? (meaning clicking on a VM name will send you on this VM?). The trick is to do a long click and it will be editable! In the home view: ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5longclickedtiable0.png) ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5longclickedtiable.png) This new shiny feature also allows modifying even remote store or other things which weren't editable before. #### By the power of the search The new home view unlock a very exciting thing: a powerful search engine for your VMs and hosts. ##### UI assisted filters When you start with a powerful filter system, it's always a good idea to have pre-configured filters in the UI. For example, you can filter your VMs by Pools, Hosts or even tags! ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5hostfilter.png) Also, the search bar itself got some pre-existing search: ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5filters.png) ##### Share your search Any search will generate a URL. So you can share this URL with anyone to get the correct filter, eg a search of **running VMs** with the **production** tags will be accessible from [https://xoaUrl/#/home?s=power\_state%3Arunning+tags%3Aproduction](https://xoaurl/?ref=xen-orchestra.com#/home?s=power%5Fstate%3Arunning+tags%3Aproduction) ##### Advanced use cases - Finding all your outdated tools in your wholes VMs? `xenTools:"out of date"` - Displaying VMs with pending operations? `current_operations:"" ` - HVM guests: `virtualizationMode:hvm` - Filter by OS and running state? `power_state:run os_version:distro:!debian` Also, **not** (`!`) **and** and **or** (`|`) operators works, eg all non-windows VMs: `os_version:distro:!windows`, or even more precise, all non-windows AND non-debian VMs: `os_version:distro:!windows |(os_version:distro:!debian)`. ![](https://xen-orchestra.com/blog/content/images/2016/06/bythepowerofthesearch.jpg) ##### Sort You can also sort your VM or host with some criteria: ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5sort.png) #### XenServer Tasks view We got a dedicated XenServer task view now: ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5tasks.png) Obviously, those bars are moving in live while we got new numbers from XenServer. They are grouped by Pools (clickable to go there, and the host where is the task is also clickable). Also, the total number of tasks is visible in the main menu: ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5tasksnumber.png) #### Easy wizards Adding a storage, creating a VM, etc: those operations are now: - easier - more accessible (left menu) Just a quick example: ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5newobject.png) #### Powerful VM import Our import UI is now totally new, and support: - Pool/SR selection (select the default SR automatically) - multiple files - drag and drop - upload progress ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5import.png) #### More stats I bet you love live stats on your hosts or VMs. You'll be happy here: ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5stats.png) #### Large infrastructure support We also managed to never slow down the interface, even when you open a selector with 10000+ objects. We are supporting very large infrastructure without breaking a sweat in the UI! This is possible, for example, with *[React Virtualized](https://bvaughn.github.io/react-virtualized/?ref=xen-orchestra.com)*, which display only current selection and do not draw all objects at once. ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5reactvirt.png) #### Default welcome views We are now display more stuff when you haven't any objects to display. Eg without server connected: ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5welcome2.png) Or without any existing VMs: ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5welcome1.png) #### Better CPU/RAM edition You can now configure min/max static/dynamic RAM, and the number max of VCPUs. Everything inline, both in main tab: ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5memoryedit.png) ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5memoryedit2.png) In advanced tab: ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5advancededit-1.png) #### Sorted/filtered tables For example, in the "Health" view, you can sort & filter all your VDI's SRs easily. In the following example: **show me all non-lvm storage sorted by usage:** ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5health.png) ### Better heatmaps Our current heatmap uses better colors and is really faster to fetch all needed metrics ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5heatmap.png) > Network TX (upload) usage on a email server. You could clearly see that the most of activity came during working hours. ### Health view improved The new health view display sorted tables, with pagination and filters. You got: - a sorted list of all SRs - same thing for orphaned VMs and VDIs - and an alerts lists (alerts message from your XS hosts) ### Internationalization You can now use Xen Orchestra in your own language. English is activated by default, but translations exists in French, Portuguese and Hebrew. The main work was to have an internationalization system for everything in the interface. Now it's done, a lot of new translations are coming fast. Do you want to help? Go there and create your own language file in few hours! ![](https://xen-orchestra.com/blog/content/images/2016/06/Tower_of_Babel.png) ### Better DR process Before this release, you would have to select a destination pool for VM replication. Now, you can select **any SR** you want. That's more flexible! ### Improved restore VM If you restore a VM which is saved with continuous delta backup, we are now trying to re-attach all interface on previous networks (if they are found). Also, we are using a brand new UI for this, which is far better, especially on large infrastructure, because: - we display only one line per VM - restore detail is in a modal window - you can filter VMs, and it's paginated ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5restore1.png) ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5restore2.png) ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5restore3.png) ### VM creation with copy By default, we were creating template VMs with disks using the clone ability (snapshots from your SR). Now, you can also choose to copy the template disk: this will be longer but performances will be better in the long run. ## What's next Hey this is a great release. But guess what? That's just a start! We just dropped the first bricks of what would be the future of UI for your virtualized infrastructure, and/or your own Cloud! Coming in 5.1: - improve the UI thanks to your feedback - better handling error messages coming from XenServer - smart backup on the way! - better self-service management ### Dev report 4 on Xen Orchestra 5.0 URL: https://xen-orchestra.com/blog/dev-report-4-on-xen-orchestra-5-0/ Last updated: 2016-06-19T11:30:49.000Z The latest dev report before a release! We are almost there :) So, what's new? ## Heatmap is back We replaced the previous heatmap with a brand new one, with: - better colors - waaaay faster metrics fetching time Visual example, for our mail server, with the network input on the last 7 days: ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5heatmap-1.png) You can clearly see the pattern: activity is happening on working hours (and the weekend is calm). ## Restore backup improved The restore backup process is more clear, and support a high number of backups or storage repositories to target. Before, it was a bit messy under some circumstances. ## VM disks We finished to implement the disk management for a VM. Obvious feature, but easy to use. ### Drag and drop boot order It's now trivial to change the boot order of a VM. Just drag and drop to put in the order you want: ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5bootorder.png) ### Attach or add disk Attach an existing disk, or create a new one. ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5newdisk.png) ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5attachdisk.png) ## Health view improved The new health view display sorted tables, with pagination and filters. The SR list, displaying **all your SRs** of your infrastructure, is now sorted by occupation (in %) by default. For example, here: **show me all non-lvm storage sorted by usage:** ![](https://xen-orchestra.com/blog/content/images/2016/06/XO5health.png) ## What's next? Next step: the release itself! Stay tuned, it will be very soon :) ### Dev report 3 on Xen Orchestra 5.0 URL: https://xen-orchestra.com/blog/dev-report-3-on-xen-orchestra-5-0/ Last updated: 2016-06-06T15:37:16.000Z Third dev report! You can check [dev report 1](https://xen-orchestra.com/blog/dev-report-1-on-xen-orchestra-5-0/) and [dev report 2](https://xen-orchestra.com/blog/dev-report-2-on-xen-orchestra-5-0/) if you missed them! Let's see what's new on the performance side. And because we have some users willing to let us test, we could validate XO performances before a release. And that's very cool. ## 38 times faster Our goal is to give you an UI which load almost instantly. So we spent time to optimize our data model in `xo-web` to be blazing fast. And guess what? We did it! Real example? The time needed to load the home view when you are coming from the VM view (could be anywhere else in the application). In milliseconds, in 2 cases: - with 50 VMs - and with 1200 VMs Here is the loading time between XO 4 (current) and XO 5 (less is better): > **Respectively 8 and 38 times faster!** In short: it doesn't depend of your infrastructure size anymore! But that's not all: we also fixed some `xo-server` to be more memory efficient and faster. For larger infrastructure, XOA can still fit in a 2GB RAM for the whole system! As you can see, this next release of Xen Orchestra will be really a huge leap in many ways! ![](https://xen-orchestra.com/blog/content/images/2016/06/zCrlcrS.jpg) > XO 5 almost ready to take off ### Upgrade to XenServer 7 URL: https://xen-orchestra.com/blog/upgrade-to-xenserver-7/ Last updated: 2016-10-04T14:25:12.000Z Now [XenServer 7 is here](https://xen-orchestra.com/blog/blog/xenserver-7), you'll probably wonder how to upgrade your existing hosts. That's a big release, so upgrading will be a bit more complicated than from 6.2 to 6.5, due to the new partition scheme. ## Before upgrading ### Download You can find XenServer 7 ISO here: [http://downloadns.citrix.com.edgesuite.net/11616/XenServer-7.0.0-main.iso](http://downloadns.citrix.com.edgesuite.net/11616/XenServer-7.0.0-main.iso?ref=xen-orchestra.com) ### Install XenServer 7 from an USB drive Despite you can burn a CD with the ISO, using an USB drive is far easier. On a Linux distro, it's one command: `dd if=XenServer-7.0.0-main.iso of=/dev/sdX` On Windows, you can use [any USB drive creator program](http://www.linuxliveusb.com/?ref=xen-orchestra.com). ### New partition scheme XenServer 7 has a new (better) partition scheme: - / (root) **18GB** - /boot/efi **512M** - /var/log **4GB** - Swap **1GB** Against the 4GB of XenServer 6, for everything. This time, if your logs grows, it won't affect your system. So what about your current partition scheme on XenServer 6 during the upgrade? 2 possibilities: - you can keep the old partitions - or you can "upgrade" it to the new scheme **I strongly recommend to upgrade with the new partition scheme** (see below for the procedure). The condition needed to do that is to have your local SR (created during the install of previous XS version) to be empty. This way, the XenServer 7 install could use this space for re-partinioning the whole drive in a proper way. > You can live migrate your VDIs from this local SR to another one. If you don't have any other SR available, a solution would be to migrate VMs to another host before upgrading. In last resort, you could export your VM to re-import it later. #### Using the new partitions In order to migrate using the new partition scheme, on your host before any upgrade, enter this command: `$ touch /var/preserve/safe2upgrade` Also check you are using GPT partitioning and not MBR. **Lastly, check your local SR doesn't not have any VDI.** > If you have any VDIs remaining in your local SR, **THEY WILL BE REMOVED** #### Using the old partitions Nothing to do. But you'll keep the small root partition. It's your call! ## Upgrading Just put the media and boot from your machine on it. The install will ask to upgrade or replace your current XenServer installation. Select "upgrade" and follow the simple guide :) ### Migration without downtime 1. Live migrate your VMs from the pool master to other hosts 2. Upgrade your pool master 3. Live migrate VMs from a another host to your pool master 4. Upgrade this host 5. Repeat until everything is updated! ### Upgrade order > Always upgrade your pool master first, and then other hosts. You can live migrate VMs from older versions of XenServer to newer host. **But the opposite is not possible**. ### XenServer 7 URL: https://xen-orchestra.com/blog/xenserver-7/ Last updated: 2016-05-24T16:12:45.000Z XenServer 7 (aka "Dundee") is [officially available!](http://xenserver.org/blog.html?view=entry&id=118&ref=xen-orchestra.com) ## Download You can download it here: [http://downloadns.citrix.com.edgesuite.net/11616/XenServer-7.0.0-main.iso](http://downloadns.citrix.com.edgesuite.net/11616/XenServer-7.0.0-main.iso?ref=xen-orchestra.com) ## What's inside This new release is great, for multiple reasons: more stable, more powerful, more resilient. ### Faster Why faster? Just check first what's inside: - CentOS 7 for the Dom0 (vs CentOS 5 in XS 6.5) - Better Dom0 disk usage (new partition scheme) - UEFI boot support - CGroups - NFSv4 and FCoE support for Storage - Xen 4.6.1 (vs 4.4.1 in XS 6.5) And a lot of libraries used in the toolstack are also now updated. It means globally faster operations for everything (export thus backup speed!) Some benchmarks could be found here: ### 100% Xen Orchestra compatible In fact, XenServer 7 is **more** compatible with Xen Orchestra, because the toolstack is more reliable than in 6.5\. So you'll have: - less bugs in XAPI with JSON-RPC - full JSON-RPC support (faster XO!) - more securiry with XAPI isolation via control groups (cgroups) You'll be happy to have your XenServer tasks displaying properly the real progress in % during any long process (migrate, copy, etc.). This was broken (in JSON) in previous XenServer versions. #### Faster Continuous Replication Our great replication feature is more resilient in Xen Orchestra, because XenServer can stand **[a replication down to the minute](https://xen-orchestra.com/?ref=xen-orchestra.com#!/features/backup)** on VMs you want to protect. This wasn't possible in 6.5, due to some random VHD delta issues. ## Upgrade process You can read this blog post dedicated to the upgrade process to XenServer 7\. It's a big release, thus there is big changes: [how to upgrade to XenServer 7](https://xen-orchestra.com/blog/blog/upgrade-to-xenserver-7). ## Bonus: XO 5.0 Beta Another good news: Xen Orchestra 5.0 will be available in beta soon! Keep an eye on our blog :) ### Dev report 2 on Xen Orchestra 5.0 URL: https://xen-orchestra.com/blog/dev-report-2-on-xen-orchestra-5-0/ Last updated: 2016-05-07T18:59:19.000Z Hi everyone! Here is a new report on our work to release a Xen Orchestra 5.0. This time, we are talking about a big change from all previous versions, even those from the beginning. We could say a new paradigm: to be "search" centered in the home view. > The interface is still "work in progress", thus GUI in those screenshots is far from definitive. ### Large infrastructures It appears we got some kind of non-planned XO usage: a **LOT** of XO deployments are done in medium/large infrastructures. Let's say, "medium" is about 50 to 100 VMs, and "large" up to 2000+ VMs. And XO was initially developed for a very small infrastructure (10 VMs?), as tool for everyday Xen usage. Today, XO is another beast (replication, continuous delta backup, load balancing, cloud capabilities, self-server for XenServer etc.) but we never changed the UI concept. > If `xo-server` is able to handle a lot VMs and hosts, GUI is another challenge! ### A new home view The current home view is useful for people with less than \~20 VMs. The "hierarchical" display allows you to have a spatial representation of your whole infrastructure: ![](https://xen-orchestra.com/assets/main_view.jpg) > Basically, you can see the "Pool > Host > VM" organisation. But what about this view with hundreds of VMs? Answer: - you won't find anything by scrolling - displaying hundreds of VMs in the browser is horribly slow... - ... and useless! 6 months ago, we implemented [an "advanced" search bar](https://xen-orchestra.com/blog/blog/improved-search-for-your-xenserver-infrastructure/): not bad, but far from being perfect. You could only filter, not sort or make actions on those filtered results. What could be a good solution for everyone? ### A solution The idea is not just to provide a good search engine, but also a complete solution for managing all your XenServer infrastructure. Ideally: - less clicks to see or make what you want - find a subset of interesting object - make bulk actions on all results found - sort your result for more pertinent insight This combo of ideas could lead you to almost never use another view than this one to manage your whole infrastructure! But let's use some real examples to give you some ideas. #### Default filter By default, the interesting stuff is basically your running VMs. And probably, the first action you'll do, is to type some text in the search filter. So we've done 2 things in the XO home page: - pre-loaded the search for all running VMs - giving you directly the focus on the search field ![](https://xen-orchestra.com/blog/content/images/2016/05/xo_default_home.png) You can also see directly that: - your search is already filled with `power_state:running` - you are working only on "VM" objects (blue button) - you got 25 VMs displayed (on 60 in total) - you got 5 pools, 6 hosts and 20 tags in your whole XenServer infrastructure You can clear the search by clicking in the button inside the search field, you'll see all VMs. #### Details You can also expand a VM (or all) to see more detailed informations, like vCPUs number, RAM, number of disks and network interfaces, IP addresses and tags. ![](https://xen-orchestra.com/blog/content/images/2016/05/expanded_tags.png) You can also see we are filtering on tags, meaning all VMs with the "dundee" tag. #### Syntax The filter syntax is pretty simple: you can search in any object property or on everything (if you don't specify any property). A space between two expressions is a "AND" ("OR" is `|`). You also have a **not** filter (`!`), e.g all *non-running VMs* could be displayed with `!power_state:running` (so you'll have all halted, paused, suspended VMs). But we can do even more fun stuff! Examples: - `virtualizationMode:hvm` will show you all HVM guests (replace it by `pv` to see your PV guests) - `xenTools:"out of date"` will display all VMs without outdated tools! Handy isn't it? More? - `power_state:run os_version:distro:!debian` will display all running VMs **which are not having Debian running on it**. ![](https://xen-orchestra.com/blog/content/images/2016/05/nondebiandistrorunning.png) **Find me all Debian 7 versions!** Possible too thanks to Xen tools (`os_version:major:7 os_version:distro:debian`) You could even find distros with their kernel versions! #### Pre-made filters and GUI Okay, good, but you won't remember this, especially at the start. So we built some pre-made filters to give you this in 2 clicks: "Running VMs" or "Halted VMs", Virtualization mode etc. You can also choose some pools or hosts via their "select" fields: they will display only VMs which are on them. Same for tags, you can add multiple tags to find what you want. That's not it! What about clicking on a VM state (Running for example, the "green dot") and filtering instantly all running VMs? Same story on a tag inside a VM: just click on it, it will add this tag in the filter. Oh and also, saving user searches will be possible ( #### Sort! Sorting those results is the next step to give you a perfect control on your whole XenServer environnement. You could sort by VM name, CPU number, OS name, number of disks, whatever. You can do a lot of stuff with this, especially to get an quick insight, even if you have a large number of VMs. #### Bulk actions Now you get your results, maybe you want to do actions on those VMs? Remove them, migrate them, stop them? No problem, just select those who want, or even all with the "super" select box. Then, a toolbar will be displayed, and you can fire the bulk action: ![](https://xen-orchestra.com/blog/content/images/2016/05/smallactionbar.png) #### Pagination/infinite scroll 2 reasons: 1. performance 2. user experience First, the slowest thing on a browser is the DOM. Render a page with hundreds of elements is really, really (really) slow. The idea is to avoid it at all costs. Two possibilities: pagination or infinite scroll. They are similar in performance perspective. Then anyway, why display 1000 VMs at the same time? Even if the browser is fast enough, could you even find something in this pile of VMs? That's why having a good filter/search system is **really** important. We are pretty sure than combining a nice UI with pre-configured searches (for people who are not used to search syntax) AND a advanced filters is something we want to release for the 5.0 release of Xen Orchestra. ### Xen Orchestra 4.16 URL: https://xen-orchestra.com/blog/xen-orchestra-4-16/ Last updated: 2016-04-29T14:08:01.000Z Hi everyone, 4.16 is mainly a maintenance release to fix some issues. We are also fully dedicated on the new 5.0 and its brand new interface. By the way, this month was really interesting for the project, because: - we were at [the Xen Hackathon 2016](https://xen-orchestra.com/blog/blog/xen-hackathon-2016/) - and then we visited the home of XenServer, at Citrix offices in Cambridge. ## Improvements This maintenance release is possible thanks to the help of Citrix teams: we have now a deeper knowledge on XenServer and how to workaround some stuff: - Continuous replication is more reliable, we found and fixed a race condition for Windows VMs using the quiesce mechanism - We reviewed some features with XenServer/XAPI teams, to be sure we are doing it fine - We learnt a lot about internal XS mechanism, and improved our software accordingly (eg for live migration) ![](https://xen-orchestra.com/blog/content/images/2016/04/citrix.jpg) > Citrix offices in Cambridge We had the opportunity to make a techtalk there to explain a bit our software architecture and the future of XO: ![](https://xen-orchestra.com/blog/content/images/2016/04/techtalk.jpg) ## XenServer Beside working on XO, we also discussed about what's coming next on XenServer. And believe me, there is a lot of exciting stuff coming, and of course we'll cover it in blog post. ## Xen Orchestra 5.0 In theory, we'll only release patches until the first 5.0: it will be the start of a big step for Xen Orchestra! Don't forget to read the blog post about it: [the future of Xen Orchestra 5.x branch](https://xen-orchestra.com/blog/blog/xo-5-x-goals/) ![](https://xen-orchestra.com/blog/content/images/2016/04/newnetworkstatssmall.png) ### XO 5.x goals URL: https://xen-orchestra.com/blog/xo-5-x-goals/ Last updated: 2016-04-29T09:54:52.000Z Almost 2 years ago, [we published a blog post](https://xen-orchestra.com/blog/blog/xo-4-x-goals/) about our objectives for Xen Orchestra 4.x branch. We made even more than we thought on it. And now, it's time for our goals on the 5.x branch. It doesn't mean everything will be available at the 5.0, but like the 4.x, we'll release the following features step by step (except the new interface, which will be the starting point of 5.0) ### New interface You can read [our introduction about it in this article](https://xen-orchestra.com/blog/blog/announcing-xen-orchestra-5-x/), and [our recent progress there](https://xen-orchestra.com/blog/blog/dev-report-1-on-xen-orchestra-5-0/). ![](https://xen-orchestra.com/blog/content/images/2016/04/dashboardfull.png) ### Smart and flexible backup Mainly 2 things: - be able to select specific disks to backup VMs, not all the disks (eg: not the big data disk if it's not relevant) - make a smart backup job, ie not specifiying VMs you want to backup, but some rules (all running VMs on some hosts, all VMs starting with "prod-\*" etc) executed at the time of the scheduled operation. We'll explain this further soon. ### Cloud backup Cloud backup will be a new option available for XOA users: you could make your backup into an online secured space we'll provide. This way, even if your whole infrastructure is destroyed, your data are still available off site. ![](https://xen-orchestra.com/blog/content/images/2015/12/rocket.png) ### Customized ACLs Here, the idea is to allow admins to create custom ACLs roles to your users. ### Advanced load balancing We already started to provide VM load balancing, see: - [XenServer VM load balancing with Xen Orchestra](https://xen-orchestra.com/blog/blog/load-balancing-with-xo/) - [Green IT with XenServer and Xen Orchestra](https://xen-orchestra.com/blog/blog/green-it-with-xen-orchestra-and-xenserver/) ![](https://xen-orchestra.com/blog/content/images/2016/03/loadbalance4.png) The goal is to continue to improve the system, and if it's possible, to provide predictive possibilities (heuristics). ### Report system We already have everything we need, in terms of data. The thing now, is to generate reports and insights on your infrastructure usage. This is also something useful to compare the evolution of the use and what VMs are eating the most of your resources ### A new appliance We'll bring you a new XOA, this time using a recent version of Debian, using PVHVM and its performance boost. It will come with a way to transfer all your previous XOA configuration to the new one, in a very easy way. ### Faster updater Our new updater will be faster, but also less exposed to complicated network situations (transparent proxies and that kind of stuff). ### Xen Hackathon 2016 URL: https://xen-orchestra.com/blog/xen-hackathon-2016/ Last updated: 2016-04-22T09:57:32.000Z This article is a small recap about our participation in the last Xen Hackathon, located at *ARM Ltd.* in Cambridge. ![Group photo at ARM](https://xen-orchestra.com/blog/content/images/2016/04/hackathon1-1.JPG) > Hackathon: an event, typically lasting several days, in which a large number of people meet to engage in collaborative computer programming. This is a very accurate description of what happened this week at Cambridge, inside ARM walls. But more than just collaborative work, which was already **very** productive, it's also the occasion to know people you usually only met online, and create a real bond with them. This is very important to speed up any project. And believe me, Xen community is really good at this! ![photo during the Hackathon](https://xen-orchestra.com/blog/content/images/2016/04/hackathon2.JPG) ## XO perspective On our side, we had a lot of questions related to XenServer and XAPI, for Xen Orchestra. Thanks to the precious help of Jon Ludlam and Andrew Cooper, we managed to have clear and precise answers to our issues. It will be quickly visible in the next releases of Xen Orchestra, like displaying the start time of a XenServer host, parsing of alert messages, understanding more VSS snapshots mechanism etc. But we also reviewed some of our current features to be sure we are not doing "bad stuff" with XenServer/XAPI. Good news, everything is fine :) ## Around the Hackathon But the Hackathon is not only the place to think together: it's also a lot of fun! Cambridge is a really nice city. We made punting for example (as you can see beer is not the only way to hang together). Patching while punting is something you won't see everyday. ![Fun with all Xen teams](https://xen-orchestra.com/blog/content/images/2016/04/hackathon3.JPG) **A big thanks to Xen teams for their availability, and ARM for hosting the event!** ### Dev report 1 on Xen Orchestra 5.0 URL: https://xen-orchestra.com/blog/dev-report-1-on-xen-orchestra-5-0/ Last updated: 2016-04-15T12:09:06.000Z Hello everyone! This is a blog post about our progress on Xen Orchestra 5.0, which is a complete rewrite of the web interface, from scratch (for those who wonder why, [read this previous post about announcing Xen Orchestra 5.x](https://xen-orchestra.com/blog/announcing-xen-orchestra-5-x/)). Before releasing it, we want to reach 2 goals: - avoid any major features regression against 4.x - provide new UI possibilities to give you the best of XenServer The first is obvious, but let me explain what we already have, despite not been released yet. > This is work in progress and not a definitive design. But it will give you a good taste of what's coming! ### XenServer the easy way Because you want probably access various part of the UI quickly, we decided to create a side menu. But that's not all: we also reduced the number of entries and added "usual actions": ![](https://xen-orchestra.com/blog/content/images/2016/04/sidemenu.png) In this way, you can quickly create a VM or add SR/host and even import a VM. Backup menu is also easier: ![](https://xen-orchestra.com/blog/content/images/2016/04/backupmenu.png) It's only in the New backup view where you could choose between all our supported XenServer backup modes: Rolling snapshots, Basic backup, Continuous delta backup, DR and Continuous replication. ### Better dashboard Here is the new dashboard with more info than the current one (menu is collapsed): ![](https://xen-orchestra.com/blog/content/images/2016/04/dashboardfull.png) In extra from 4.x, we already have: - total storage usage (on all VDI SRs) - alarm messages number - pending tasks number - number of users - Top 5 SR usage in % ### Enhanced VM view The goal here is to provide a quick recap of the VM without giving too many info: ![](https://xen-orchestra.com/blog/content/images/2016/04/vm_overview.png) Here, you got: - number of vCPUs, RAM usage, number of networks, total disk usage - last 10 minutes activity for CPU, RAM, network and disks combined - relative start time, Xen virt mode, IP address and the distro - and finally tags (see below) #### Tags Tags are really useful for managing your infrastructure. We focused on this to give you the best Ux with them: Just click on the plus icon in Tags section, it will open a text field: ![](https://xen-orchestra.com/blog/content/images/2016/04/tags1n.png) Just validated with enter, it recreates a new text field: ![](https://xen-orchestra.com/blog/content/images/2016/04/tags2n.png) This way you could enter multiple tags without leaving your keyboard! #### Editable text Just click on the VM description, title or whatever, you could edit it: ![](https://xen-orchestra.com/blog/content/images/2016/04/editn1.png) You got a green check after a successful modification: ![](https://xen-orchestra.com/blog/content/images/2016/04/editn2.png) Revert your change just by hovering the green check: ![](https://xen-orchestra.com/blog/content/images/2016/04/editn3.png) #### Better stats Stats are great, and now you can even change the granularity: stats from last 10 min, 2 hours, 1 week or even last year! ![](https://xen-orchestra.com/blog/content/images/2016/04/statsn.png) Close up on the time selector: ![](https://xen-orchestra.com/blog/content/images/2016/04/timeselector.png) #### Better console The new console view allows you to keep control of VM usage thanks to the spark lines graphs: ![](https://xen-orchestra.com/blog/content/images/2016/04/consolen.png) ### Internationalization We added other languages support from the start. We already have a French translation, but others will come quickly (Portuguese, Chinese, and a lot more with community support). The interface could be instantly switched when you select the language, without refreshing anything. Remember the stats? Change the language in French, now everything is translated, even the date format! ![](https://xen-orchestra.com/blog/content/images/2016/04/statsfrn.png) ## Conclusion This is a first post about the new interface, more will come as soon we could present you our results :) ### Green IT with Xen Orchestra and XenServer URL: https://xen-orchestra.com/blog/green-it-with-xen-orchestra-and-xenserver/ Last updated: 2016-04-04T19:59:08.000Z This post is a sequel of our [load balancing introduction with XenServer](https://xen-orchestra.com/blog/blog/load-balancing-with-xo/). This time, we'll explore the [Xen Orchestra](https://xen-rchestra.com/?ref=xen-orchestra.com) **density mode** for your XenServer hosts. But why green IT? Because we are about to shutdown your useless hosts "on the fly" with our new load balancing mode! ![](https://xen-orchestra.com/blog/content/images/2016/04/xo_green_it.jpg) ## Density mode The goal of density mode is to detect XenServer hosts with a very small CPU load. You can set a custom threshold, by default it's an 10% average on all your CPUs. For all hosts under this level, we'll choose the one with less memory usage, to migrate its VMs on either: - the pool master (which we won't shutdown anyway) - or the most busy (in RAM) host This way, we'll "empty" the maximum number of XenServer machines. Of course, we'll avoid to saturate hosts with a heavy CPU load: we made a projection/estimation of CPU load impact on the targeted host. And if you empty a [XenServer host which has wake on LAN support](https://xen-orchestra.com/blog/how-to-use-wake-on-lan-on-xenserver-6-2/), guess what? We can halt it! ## Green IT Let's take a simple example: we have 3 XenServer hosts with their VMs: Step 1: The initial configuration before starting **density** mode Step 2: The load balancer detects low CPU usage on both Host 2 and 3\. VMs are migrated to Host 1 (Pool master) Step 3: Host 2 and 3 are empty, thus halted by the load balancer. They will be restarted if we switch in **performance mode** (or manually if density is just disabled) ![](https://xen-orchestra.com/blog/content/images/2016/04/Density_small.png) ### Energy saving Let's say each XenServer host is using roughly 400W. In this case, you save energy for 2 hosts (thus 800W). **And even using density mode for half of a day (12h)**, we'll save you 9600 Wh per day. > Why density only half of the day? Our load balancing feature can be triggered on schedule, it means if you don't need too much CPU power during the night, just activate density mode from 7PM to 7AM. And what about cooling? A sleeping server won't heat your IT room, and with a PUE of 2, it will be 19200 Wh saved for one day[\[1\]](#fn1)! And for 1 year? Using [official](https://www.eia.gov/electricity/monthly/epm%5Ftable%5Fgrapher.cfm?t=epmt%5F5%5F6%5Fa&ref=xen-orchestra.com) figures for commercial use and the average within US (0.0998 $/kWh), **it means $700 saved**, only on a very small infrastructure like this (3 hosts!). We could also count weekends to raise the total. ### Another example "But your example with a PUE of 2 is bad, in my DC got 1.30!". Yep, but your DC is probably hosting more than 3 hosts. Let's imagine you have 100 hosts then. If density mode allowing you to cut half of your hosts, even only half of the day, it means 312 kW[\[1:1\]](#fn1) saved. In one year, it's **$11,360** removed from your energy bill. Not bad! ## Load balancer scheduler The density mode is already available, but the scheduler will be released soon, allowing you to switch from "performance" to "density" automatically when needed. See you soon for other exciting stuff coming in [Xen Orchestra!](https://xen-orchestra.com/?ref=xen-orchestra.com) \[^n\]: 800W \*2 (PUE) = 1600W. Then 1600 \* 12h = 19200 Wh (or 19kWh) --- 1. 400W \*50 (hosts) \* 1.3 (PUE) = 26,000W, thus 26kW. For 12h, it means 312 kWh. [↩︎](#fnref1) [↩︎](#fnref1:1) ### Xen Orchestra 4.15 URL: https://xen-orchestra.com/blog/xen-orchestra-4-15/ Last updated: 2016-03-21T17:23:20.000Z XO 4.15 is out, with a beta of the load balancer, a new dashboard for the self-service, and also a nice list of new stuff: - [XenServer VM load balancing](https://xen-orchestra.com/blog/blog/load-balancing-with-xo/) - [Migration queue](https://xen-orchestra.com/blog/beyond-xenserver-limits/) for Storage XenMotion - a complete rework of the XenServer network management (parity with XenCenter) - better migration panel - auto match destination networks for cross pool migration - Citrix license status for pools - Advanced host info (BIOS strings) - CIFS ISO SR creation - Delta backup support quiesce snapshots (Windows VM delta backup is now fully supported) - SMB support for delta backup Plus usual bug fixes (full [changelog here](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#4150-2016-03-21)). ## Load balancing > This feature is working in beta so far, we need your feedback! [More on load balancing on XenServer with Xen Orchestra.](https://xen-orchestra.com/blog/blog/load-balancing-with-xo/) [![](https://xen-orchestra.com/blog/content/images/2016/03/loadbalance4.png)](https://xen-orchestra.com/blog/blog/load-balancing-with-xo/) ## Self-service dashboard [Discover our new self-service dashboard for XenServer in this article.](https://xen-orchestra.com/blog/blog/self-service-dashboard/) [![](https://xen-orchestra.com/blog/content/images/2016/03/dashboard_hover.png)](https://xen-orchestra.com/blog/blog/self-service-dashboard/) ## Network configuration reworked You can create create pool wide networks with VLAN, make the IP configuration etc. ![](https://xen-orchestra.com/blog/content/images/2016/03/network.png) ## Misc - We now support continuous delta backup on SMB remote shares. - Plus, we changed our way to make delta backup to allow quiesce snapshots for Windows VM: this way, even your delta backup will be consistent! ## What's next The new technical layer for XO 5.0 web interface is ready! It's time now to focus on UI creation itself (views, styles, etc.) We'll continue to improve the load balancing feature too (with density, halting servers with wake-on-lan and also implementing the density mode). ### XenServer load balancing with XO URL: https://xen-orchestra.com/blog/load-balancing-with-xo/ Last updated: 2016-03-18T13:11:47.000Z Hi everyone! Today, I'll introduce you a new feature of [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com): **live load balancing of your XenServer VMs**. As usual here, we'll first explore quickly the concept of load balancing, then the problems, and finally our solution. ## Concepts Starting with [Wikipedia](https://en.wikipedia.org/wiki/Load%5Fbalancing%5F%28computing%29?ref=xen-orchestra.com): > In computing, load balancing distributes workloads across multiple computing resources, such as computers, a computer cluster, network links, central processing units or disk drives. Short and accurate definition! What about XenServer now? ### In virtualization In the case of virtualization, you have multiple physical hosts, which runs your virtual machines (VMs). Each host has a limited set of resources: CPU, RAM, network bandwidth etc. > Maybe you already heard about VMWare DRS (Distributed Resource Scheduler): that's the same principle here, but for XenServer. So the first objective is to **adapt your VM placement in live** (without service interruption), depending of the load. Let's take a simple example: These 2 hosts are running 6 VMs: ![](https://xen-orchestra.com/blog/content/images/2016/03/loadbalance1.png) > Let's say both hosts are using only 5% of all their CPUs Suddenly, one of your VM starts to have a very high CPU load (**in yellow**): performance of other VMs on this same host could be impacted negatively (**in pink**): ![](https://xen-orchestra.com/blog/content/images/2016/03/loadbalance3.png) > Host 1 still using 5% of its CPUs, but host 2 is now a 95%. We are detecting it and now move others VM to the other host, like this: ![](https://xen-orchestra.com/blog/content/images/2016/03/loadbalance4.png) > Host 1 has a slightly increased load, but host 2 can be fully used for the "problematic" VM without disrupting service of other VMs. This way, the impact of your high load usage on one VM doesn't penalize everyone. But it's not the only way to see this: there is multiple possibilities to "optimize" your existing resource usage: 1. maybe you want to **spread the VM load** on the maximum number of server, to get the most of your hardware? (previous example) - maybe you want to **reduce power consumption** and migrate your VMs to the minimum number of hosts possible? (and shutdown useless hosts) - or maybe **both**, depending of your own schedule? Those ways can be also called **modes**: "performance" for 1, "density" for number 2 and "mixed" for the last. ## In Xen Orchestra We started to work on the "performance" mode inside Xen Orchestra. Our first objectives were: - to provide an easy way to create "plans" to supervise load balancing with simple rules - to work only on the host CPU usage - to start a detection every 2 minutes - to work across various pools - to be able to exclude hosts ### Creating a plan Creating a plan is the first step. In our example, we want to create a plan called "perf1", using "performance mode", and acting only on one pool, labelled "Lab Pool": By default, the CPU threshold is 90%, but it could be set manually (here at 80%): ![](https://xen-orchestra.com/blog/content/images/2016/03/plan_creation.png) ## Let's play! Here is the initial situation: ![](https://xen-orchestra.com/blog/content/images/2016/03/beforeload-1.png) > 4x VMs on 2 hosts, *lab1* and *lab2* CPU usage on both hosts is very low: ![](https://xen-orchestra.com/blog/content/images/2016/03/lab1.png) > CPU usage on *lab1* ![](https://xen-orchestra.com/blog/content/images/2016/03/lab2.png) > CPU usage on *lab2* Let's trigger a very high CPU load on the VM "Windows Server NFS Share" (using Prime95), which is on *lab1*: ![](https://xen-orchestra.com/blog/content/images/2016/03/maxloadlab1.png) > *lab1* starts to work at 100% on all it's CPUs Both "nfs share" and "Salt Master" VMs will suffer this concurrent CPU usage and won't have enough power to deliver if necessary. And when the average on last 2 minutes hits the threshold (80% here), actions are taken: ![](https://xen-orchestra.com/blog/content/images/2016/03/actionloadbalancing.png) ![](https://xen-orchestra.com/blog/content/images/2016/03/migrated.png) > *lab1* is now working a full speed with the only the VM using all it's CPUs. Let's check the new CPU load on *lab2*: ![](https://xen-orchestra.com/blog/content/images/2016/03/aftermigration.png) > Load is only slightly increased due to 2 new VMs ## Conclusion With this simple but first initial algorithm, we managed to mitigate automatically an issue of VM resource usage. Of course, it works also in cases when you have to really spread the load on all your servers (ie when the sum of all VM usage is higher than the threshold): that's the exact same principle. You have more than 2 hosts? Again, same idea, it will also work. ### Beyond XenServer migration limits URL: https://xen-orchestra.com/blog/beyond-xenserver-limits/ Last updated: 2016-03-16T12:13:03.000Z If you are using extensively the [Storage XenMotion feature](https://www.citrix.com/content/dam/citrix/en%5Fus/documents/products-solutions/storage-xenmotion-live-storage-migration-with-citrix-xenserver.pdf?accessmode=direct&ref=xen-orchestra.com) in [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver), you probably encountered some limitations. Let's recap first what is [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver) Storage XenMotion and then a limitation you can discover while using it. ## Storage XenMotion: definition What is exactly "Storage XenMotion" in XenServer? Well, it's the ability to **move a VM within it's storage in live**, without service interruption, even between hosts sharing nothing. Use cases: - adopting a new SAN (just move the VM disks to it) - migrate VMs between hosts without shared storage - migrate VMs between different pools As you can see, that's more than very convenient in a lot of cases. So what's the big deal? ## Maximal number of concurrent migrations Imagine you want to migrate **all your VMs** on another pool. Let's say 6 VMs. Today, with XenCenter or `xe`, you need to do it manually for each of them (painful if you have e.g 20 VMs!). You could already do that with Xen Orchestra: ![](https://xen-orchestra.com/blog/content/images/2016/03/vmselect.png) > Selecting 6 VMs at once and migrate them to another host ("Lab3" here) But only 3 will actually migrate, because XenServer has a built-in limit: no more than 3 Storage XenMotion at once on the same destination. Let's see the solution! ## Solution: a migration queue To keep our example with 6 VMs, when we start to migrate all the VMs at once, we got an error from the API of XenServer (XAPI): `TOO_MANY_STORAGE_MIGRATES(3)` Now, to avoid manually migrate VMs 3 per 3, we catch this exception for each failed VM, and we try again seconds later. This way, as soon one of the migration is finished, the next VM asking to migrate will pass. Until every VMs made it! **You can now migrate using Storage XenMotion any number of VMs, and just let the process finish itself!** ### Self Service dashboard URL: https://xen-orchestra.com/blog/self-service-dashboard/ Last updated: 2016-03-03T08:43:31.000Z Coming for the [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com) next release (4.15), here is a dashboard dedicated to the resource usage of your configured self-service for XenServer. You can read a recap of the feature itself in our previous blog post: [XenServer self service portal](https://xen-orchestra.com/blog/blog/xenserver-self-service-portal/). Let's see first the new shiny thing: ![](https://xen-orchestra.com/blog/content/images/2016/03/dashboard_self.png) In this example, it means you have created 3 resource sets: - **QA**, which is obviously used for creating VMs to test software installation/deployment. - **tests**, which can be used for continuous integration (CI), VMs are generally created and destroyed quickly. - **sandbox** is the place to make experiments for your dev team. Installing any OS they want and play with it. Also, hovering on a doughnut will give you the usage detail: ![](https://xen-orchestra.com/blog/content/images/2016/03/dashboard_hover.png) Finally, you can "expand" a resource set to display actual hosts/networks/SR behind it: ![](https://xen-orchestra.com/blog/content/images/2016/03/dashboard_expand.png) ### Xen Orchestra 4.14 URL: https://xen-orchestra.com/blog/xen-orchestra-4-14/ Last updated: 2016-02-24T14:44:36.000Z XO 4.14 is now available with **a brand new self-service system** plus a full CloudInit support. And as usual, bug fixes and various enhancements. ## Self-service This is a feature we wanted for a long time. But it's not trivial. Users creating VMs leads to a lot of consequences: - a running VM will use RAM and CPUs of a host - even halted, VM will use storage space To avoid any resource problem, you **need** to set limits. In other words, you need to have **quotas** for enforcing those limits. The other challenge is to be sure the set of resource will be used, without any side effects on resources beside it. If it runs on one host only, it shouldn't run on another one. [![](https://xen-orchestra.com/content/images/2016/02/selfservice_quotas.png)](https://xen-orchestra.com/blog/xenserver-self-service-portal/) For the complete story about self service, you can check our previous dedicated blog post about it: [XenServer self service portal](https://xen-orchestra.com/blog/xenserver-self-service-portal/) ## CloudInit custom data During the VM creation phase, if your template is compatible (ie: already has CloudInit installed), you can now put your own custom config: ![](https://xen-orchestra.com/blog/content/images/2016/02/CloudInit.png) You can [check this blog post](https://xen-orchestra.com/blog/full-cloudinit-power-in-xenserver/) to discover a fraction of all what you can do with CloudInit! ## Proxy for patches Auto-patching is very convenient. But before this release, if you were behind a corporate proxy, it wasn't possible to check your XenServer updates or patch it automatically. [Read our doc to configure a proxy server for fetching patches directly from Citrix](https://xen-orchestra.com/docs/configuration.html?ref=xen-orchestra.com#proxy-for-xenserver-updates-and-patches). ## Better backup reports Backup reports were done on Rolling snapshot and "normal" backups. They are now extended to: - Disaster Recovery - Continuous replication - Continuous delta backup You can also choose to always have reports, also only when you got an error... or never! Thanks to [@Danp2](https://github.com/Danp2?ref=xen-orchestra.com) for the contribution! ## What's next We'll probably release small enhancements and fixes, but we are clearly focusing on the new interface for XO 5.0 Also, we started to draft the [load balancing feature](https://xen-orchestra.com/docs/load%5Fbalancing.html?ref=xen-orchestra.com), a first initial version will be out in March. ### XenServer self service portal URL: https://xen-orchestra.com/blog/xenserver-self-service-portal/ Last updated: 2016-02-22T16:41:54.000Z This is something our [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com) users asked for a long time: **a self service portal for creating VMs without bothering the system administrator**. But this is not something you make in few minutes, because giving access to VM creation means resource usage, and maybe uncontrolled resource utilization. You won't be pleased to find your storage is out of space because of a user creating a LOT of VMs eh? That's why **you need quotas**. ## Resource set We created the concept of "resource set". Basically, you can see it like a "sandbox" where resources will be used. A set has: - a name - users or groups attached to it - Xenserver pools (one or more) - Templates - Storage repositories - Networks - Quotas (max vCPUs, RAM and disk usage) After selecting those resources, you'll be able to **see on which hosts VMs could run**. E.g, if you selected a SR (Storage Repository) which is available on one host only, then you'll have only this host capable of running VMs from this set. So to create a new set in [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com), as an administrator, go inside the "Self Service" view: ![](https://xen-orchestra.com/docs/selfservice_menu.png) Then create your set: ![](https://xen-orchestra.com/blog/content/images/2016/02/selfservice_quotas.png) In this example, I created a set named "sandbox", where: - all users of the group "devs" can create VMs - Those VMs will be created on "Lab pool" - With only one template ("Debian 8 Cloud Ready"), on the "SSD NFS" SR and using one network (on eth0) ### Quotas But that's not all. What if you want users to use a part of this resource set. I mean, this pool could be also used for other stuff. So in my example, I also **limited resource usage in this set with quotas** of: - a total disk usage at 100 GiB max - a total of vCPUs at 8 and RAM at 16 GiB After the creation, you have a recap of your existing set on the bottom: ![](https://xen-orchestra.com/blog/content/images/2016/02/selfservice_recap_quotas.png) ## On user side Now, **every user inside the "devs" group will be able to create VMs**, and in a predictable way (thanks to quotas). On their main view, a new green icon will appear: ![](https://xen-orchestra.com/docs/selfservice_newvm.png) This new create VM view is a bit different: you can select your "Resource set" (because a user can have multiple sets!) and only use specified templates, networks etc. All of this within limits defined by quotas: ![](https://xen-orchestra.com/docs/selfservice_createvm.png) See the recap panel with in green the new resources used and in blue the previous resources of this set: ![](https://xen-orchestra.com/blog/content/images/2016/02/selfservice_summary_quotas.png) ## Going further But to really leverage self service efficiently, it's even better to combine it with [Cloudinit ready templates](https://xen-orchestra.com/blog/create-vms-ready-in-less-than-30-sec/). This way, your users can **put directly their own SSH keys and work without asking for password**. They became completely independent, and they can create VMs in less than 20 secs. You can also learn more about CloudInit possibilities in our previous blog post: [Full CloudInit power in XenServer](https://xen-orchestra.com/blog/full-cloudinit-power-in-xenserver/). ![](https://pbs.twimg.com/media/CYMt2cJUkAAWCPg.png) **Your XenServer infrastructure is now Cloud capable, without any complicated installation or agent to deploy on your hosts!** ### Full CloudInit power in XenServer URL: https://xen-orchestra.com/blog/full-cloudinit-power-in-xenserver/ Last updated: 2016-02-17T10:13:39.000Z This is a new article, related to [our previous CloudInit](https://xen-orchestra.com/blog/cloudinit-support-for-xenserver/) introduction, and how it works thanks to [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com): without any extra plugin to install on your hosts! Also, if you need help to build a template (or to download our cloud ready template), please read [this post](https://xen-orchestra.com/blog/debian-cloud-template-for-xenserver/) and [this one](https://xen-orchestra.com/blog/centos-cloud-template-for-xenserver/). ## Unlock full CloudInit potential We started by using CloudInit with hostname and the SSH key, as you can see: ![](https://xen-orchestra.com/blog/content/images/2015/12/sshkey.png) It means, when you create your VM, the hostname will be the VM name, and your SSH key will allow you to SSH it directly without any password. **But what about using directly any configuration you want?** For that, we added a free form, "Custom config": ![](https://xen-orchestra.com/blog/content/images/2016/02/cloudinit.png) > You can also import a text file with your CloudInit configuration In this field, you can add any valid CloudInit configuration. Let's explore those new possibilities! ### Basic stuff You can do the same we already did: ``` #cloud-config hostname: proxy ssh_authorized_keys: - ssh-rsa ``` This VM will have the hostname **proxy** with your added key. You want to add more than one SSH key? (maybe the one of your colleague?), trivial: ``` ssh_authorized_keys: - ssh-rsa - ssh-rsa ``` ### Packages Now, let's go further. In theory, we got a light template without any extra package installed. But, let's continue with our example of a VM making a "proxy" role. We don't even want to install a package after the VM is created, but during the first boot. That's possible: ``` packages: - squid3 ``` > With this config, your VM will be up and running with [Squid Proxy Server](http://www.squid-cache.org/?ref=xen-orchestra.com) up and running. By adding any package, CloudInit, during the initial boot, will update all packages sources (`apt-get update`), and **then** install any specified packages. You can also decide to upgrade your packages by using `package_upgrade: true`. This way, even if you template is old, you'll have it upgraded each time it boots! ### Adding files Okay, that's great, but how about pushing a configuration file for your proxy server? ``` write_files: - content: | # Squid config file http_access allow all http_port 3128 path: /etc/squid3/squid.conf ``` ### Install a Salt Minion For those who don't know what's [SaltStack](http://saltstack.com/?ref=xen-orchestra.com), it's like Ansible (and kind of like Puppet/Chef). In order to have your VM connected to the Salt Master, you just have to: - install the minion package - having a DNS entry pointing to the master, like `salt.mydomain.com` So it's very easy to install the Minion with CloudInit, just add the right package: ``` packages: - squid3 - salt-minion ``` That's it! ### Recap Now, let's recap what will do your freshly created VM during its first boot: - changing the template hostname to "proxy" - adding two SSH keys for the default user - install `squid3` and `salt-minion` packages - deploy the config file for Squid ``` #cloud-config hostname: proxy ssh_authorized_keys: - ssh-rsa - ssh-rsa packages: - squid3 - salt-minion write_files: - content: | # Squid config file http_access allow all http_port 3128 path: /etc/squid3/squid.conf ``` Your system is ready, and you didn't even connected once to it. ### Other examples There is other examples in the [official CloudInit documentation](http://cloudinit.readthedocs.org/en/latest/topics/examples.html?ref=xen-orchestra.com). Now, you can unlock the full potential on it using XenServer and Xen Orchestra! ### Xen Orchestra 4.13 URL: https://xen-orchestra.com/blog/xen-orchestra-4-13/ Last updated: 2016-02-05T08:42:18.000Z Welcome to XO 4.13! This one is all about security, stability and fixes, plus UI improvements. One of the major feature is the possibility to use SMB remote for full backups. ## SMB remotes You can add SMB (ex-CIFS) remotes for your backups. It doesn't work yet with Continuous Delta backup, but it will be the case soon. So you can export now your backups to a Windows share if you like! ![](https://xen-orchestra.com/blog/content/images/2016/02/smb.png) ## Checksum for backups Making backups is great. But what about corrupted files between the backup operation and the restore? We are now recording the MD5 hash of any delta file, and save it along the file itself. This way, when you restore your backup, you can know if it's corrupted or not! The only thing left is to check the hash of the full image: this is not trivial, because making a MD5 sum of a big file will take a lot of bandwidth (imagine your full disk image of 1 TiB is on a remote NFS share: it means reading the whole file to make the sum). We focused on delta file protection, which is far faster. ## More HTTPS security Thanks to [Helmet](https://github.com/helmetjs/helmet?ref=xen-orchestra.com) library, we can now offer more security to HTTPS inside XOA! HSTS, XSS & click jacking protections and more! ![](https://xen-orchestra.com/blog/content/images/2016/02/https.png) We also got **HTTPS redirection** for admins who want to redirect automatically from HTTP to the secure protocol. ## Health view This view is now regrouping data about XenServer anomalies, like orphaned VDIs or VM snapshots. Filled SR are also displayed here: ![](https://xen-orchestra.com/blog/content/images/2016/02/health.png) > Orphaned elements could happen when migrating VMs or VDIs to other SRs. This way, you can't miss them anymore! Those orphaned VDIs are also displayed individually in the SR view: ![](https://xen-orchestra.com/blog/content/images/2016/02/orphanindividual.png) ## UI improvements A lot of small improvements, from tooltips to a complete live migration handling (selecting the destination storage, the migration network etc.), removing old backup logs etc: ![](https://xen-orchestra.com/blog/content/images/2016/02/tooltip.png) ![](https://xen-orchestra.com/blog/content/images/2016/02/migration_full.png) You also have now a dedicated field for units, which is way user friendly than typing the unit yourself: ![](https://xen-orchestra.com/blog/content/images/2016/02/units.png) ## What's next We started to work on the self service portal, **and we are currently writing it**. This is now a priority, and will be out for the next release! ### PV vs PVHVM on next XenServer URL: https://xen-orchestra.com/blog/pv-vs-pvhvm-on-next-xenserver/ Last updated: 2016-01-24T18:58:36.000Z Here is a new set of benchmarks using latest XenServer Beta (Dundee Beta 2), comparing Xen in **PV and PVHVM modes**[\[1\]](#fn1). And on a decent hardware (Haswell CPU with AVX2 instructions). Last benchmarks [we made 2 years ago](https://xen-orchestra.com/blog/debian-pvhvm-vs-pv/) gave roughly +15% boost on PVHVM vs PV for intensive CPU/memory cases. Is it still true? ## Testing protocol ### Hardware - Intel Core i5-4460 (with AVX2 instructions) - Gigabyte GA-H97-N (mini-ITX) - RAM: 8GiB ![](https://xen-orchestra.com/blog/content/images/2016/01/testing_hardware.jpg) ### Software - XenServer Dundee (beta 2) - AVX2 active - Xen 4.6 - Guests running Debian Stretch (current testing) - Comparing **PV** mode vs **PVHVM** with XSAVE instruction ## Benchmarks All those results can be found [on Phoronix benchmarking website](http://openbenchmarking.org/result/1601243-HA-1601245HA57?ref=xen-orchestra.com). Let's start with the least non-surprising test: ![](https://xen-orchestra.com/blog/content/images/2016/01/opensslbench.png) > OpenSSL is not at all influenced by virtualization mode. It's a draw here! What about PHP? ![](https://xen-orchestra.com/blog/content/images/2016/01/phpbench.png) > There is a small difference, around 4% better for **PVHVM**. This time, compression using 7zip: ![](https://xen-orchestra.com/blog/content/images/2016/01/7zipbench.png) > **PVHVM** first, by a 6% difference. Let's compile a kernel: ![](https://xen-orchestra.com/blog/content/images/2016/01/kernelbench.png) > A visible gap now, **PVHVM** wins by a large 16% boost. Now, ladies and gentleman, the real deal: Apache. The number of static pages served during this benchmark: ![](https://xen-orchestra.com/blog/content/images/2016/01/apachebench.png) > Wow. **PVHVM** is **41% better** than PV. ## VS older benchmarks Can we compare with the previous benchmarks? Not really. CPUs are not from same generation (Ivy Bridge vs Haswell), but in fact pretty close: see the comparison on [Intel ARK](http://ark.intel.com/compare/68316,80817?ref=xen-orchestra.com). The main difference is more on software side: XenServer 6.2 vs Dundee beta 2, and a recent Debian distro. RAM, CPU number are the same. Tested software version are slightly different too. That's a too much to compare directly. **But what about the difference between PV and PVHVM between those old benchmarks and the new ones?** Here the chart about the new and the old delta (in %) between PV and PVHVM, on CPU/Memory intensive tasks: ![](https://xen-orchestra.com/blog/content/images/2016/01/delta_old_new_pvvspvhvm.png) ## Conclusion - **PVHVM** is better in any situation (at worst the same, at best 40% better) - The gap is bigger and bigger in favor of **PVHVM**. That's not really surprising: new hardware tends to include more and more instructions to assist virtualization. So in fact, the "cost" of virtualization (in terms of performances) is reduced. #### Addendum: vs bare metal Some people asked results of bare metal compared to the previous benchmarks. So compared to **PVHVM**, bare metal is slightly faster at various levels: - Kernel compilation time: **4%** faster - PHP: draw! (<0,2%) - 7Zip: **2%** faster - Apache: **9%** faster - OpenSSL: can't run the test, the OpenSSL tarball is somehow missing. --- 1. you can read more about virtualization modes [on the Xen wiki](http://wiki.xen.org/wiki/Virtualization%5FSpectrum?ref=xen-orchestra.com). [↩︎](#fnref1) ### Xen Orchestra 4.12 URL: https://xen-orchestra.com/blog/xen-orchestra-4-12/ Last updated: 2016-01-18T12:03:56.000Z Happy new year! And happy new release :) This one **add 2 major things: continuous replication and continuous delta backup** for your XenServer hosts. Without having any extra hardware or software to install, only with [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5F4.12). ## VM Continuous replication Protect your VMs by streaming them to another Storage every 10 minutes (or more). This target storage can be local or inside any distant XenServer host! [Read our previous blog post to learn more!](https://xen-orchestra.com/blog/xenserver-vm-continuous-replication) [![](https://xen-orchestra.com/blog/content/images/2016/01/replication.png)](https://xen-orchestra.com/blog/blog/xenserver-vm-continuous-replication) > Note: it works since for XenServer 6.5 ## Continuous Delta backup It means to backup by exporting full disks once for all. Indeed, after this initial export, we'll manage to only use delta blocks forever! [Read our previous blog post to learn more!](https://xen-orchestra.com/blog/blog/continuous-delta-backup/) [![](https://xen-orchestra.com/blog/content/images/2016/01/deltamergesmall-1.png)](https://xen-orchestra.com/blog/blog/continuous-delta-backup/) [![](https://xen-orchestra.com/blog/content/images/2016/01/finaldeltasmall.png)](https://xen-orchestra.com/blog/blog/continuous-delta-backup/) > This feature also works since XenServer 6.5 ## Multiple VM creation Create spawn a bunch of VMs just with one click! Want to see it in action? [Check our complete blog post](https://xen-orchestra.com/blog/blog/create-multiple-vms-at-once/). ![](https://xen-orchestra.com/blog/content/images/2016/01/vmcreation2.png) ## Autoboot VMs Just after clicking on "Create VM", you can choose to boot it automatically. Very useful, and it helps to give you an [operational VM is less than 30 secs!](https://xen-orchestra.com/blog/blog/create-vms-ready-in-less-than-30-sec/) [![](https://xen-orchestra.com/content/images/2016/01/vmcreation3.png)](https://xen-orchestra.com/blog/blog/create-multiple-vms-at-once/) ## Misc We also made a lot of small improvements, bug fixes and stuff. [The full changelog is available here](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#4120-2016-01-15). # What's next? We'll continue to improve the UI and try to release a first **self service portal** for 4.13\. Which should be one of the latest [before XO 5.0](https://xen-orchestra.com/blog/announcing-xen-orchestra-5-x/)! ### XenServer VM continuous replication URL: https://xen-orchestra.com/blog/xenserver-vm-continuous-replication/ Last updated: 2016-01-16T08:37:51.000Z What about having a **continuous replication system for your XenServer VMs without any storage vendor lock-in?** We just did it in [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fcontinuous%5Freplication). You can now replicate a VM every xx minutes/hours on a any storage repository. It could be on a distant XenServer host or just another local storage. Your copied VM is always ready to boot if necessary! ![](https://xen-orchestra.com/blog/content/images/2016/01/replication.png) ## Objectives This feature covers multiple objectives: - no storage vendor lock-in - no configuration (agent-less) - low Recovery Point Objective, from 10 minutes to 24 hours (or more) - flexibility - no intermediate storage needed - atomic replication - efficient DR (disaster recovery) process All of this, with your existing XenServer infrastructure. **No new hardware to buy!** #### No vendor lock-in Because Xen Orchestra works on the **hypervisor level**, you **don't need to have a specific storage backend** to support this feature. It could be **any existing storage in your infrastructure**: local storage with SSDs, or NFS storage, whatever. Do not change anything on this side! ![](https://xen-orchestra.com/blog/content/images/2016/01/nolocking.jpg) #### Agent-less No agent to install on your hosts. Just use Xen Orchestra, that's all! #### Low RPO Low RPO (Recovery Point Objective) means you can recover from a sever outage without losing time, data and thus money. By configuring the replication for every 10 minutes (for example), you can boot a copy of your VM on another site (on just another server) **even if you original infrastructure is completely lost**. Do you have only one server? No problem, protect the VM by using another local storage! #### No intermediate storage Thanks to our streaming technology, we'll send bits from the source to the destination host without storing anything between. And with our back-pressure capable software, don't worry of the host network speed. ![](https://xen-orchestra.com/content/images/2015/10/newsolution.png) #### Atomic replication What about if something goes wrong during a replication? (e.g: losing your storage). Before validate a complete transfer, we'll save the previous copied VM state. If something bad happened during the transfer, you'll still have a working VM! That's like a **double buffering**. #### Efficient disaster recovery You can use this feature as an efficient Disaster Recovery process. In fact, after the initial VM copy, we only transfer the disks block difference: it's **bandwidth friendly and very efficient**. ![](https://xen-orchestra.com/blog/content/images/2016/01/db.png) #### Best effort Your network can't handle the replication rhythm? E.g, you configured a replication every 10 minutes, but your network can't stream the delta in less than 10 minutes? No problem: if the previous scheduled operation is still running when we call a new one, it will be discarded. Until it's possible to do it at the next scheduled try! ## Configure it As you'll see, this is trivial to configure. Inside the "Backup" section, select "Continuous Replication": ![](https://xen-orchestra.com/blog/content/images/2016/01/continuous_replication.png) Then: 1. Select VMs you want to protect 2. Schedule the replication interval 3. Select the destination storage (could be any storage connected to any XenServer host!) ![](https://xen-orchestra.com/blog/content/images/2016/01/continuous_replication2.png) > In this case, we'll replicate 2 VMs to "NFS" SR which is a pool called "Other Pool". Replication will happen every 20 minutes. That's it! Your VMs are protected and replicated as requested. To protect the replication, we removed the possibility to boot your copied VM directly, because if you do that, it will break the next delta. The solution is to clone it if you need it (a clone is really quick). You can do whatever you want with this clone! ![](https://xen-orchestra.com/blog/content/images/2016/01/remplication_small.png) ### Continuous Delta Backup URL: https://xen-orchestra.com/blog/continuous-delta-backup/ Last updated: 2016-01-14T18:11:08.000Z Less than one month after our first release of [XenServer incremental backup](https://xen-orchestra.com/blog/blog/xenserver-incremental-backup/), we made a major improvement inside [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fcontinuous%5Fbackup): **Continuous Delta Backup**. And we are very happy to present you this exclusive feature on XenServer! ![](https://xen-orchestra.com/blog/content/images/2016/01/xobackup.png) It means to backup by exporting full disks **once for all**. Indeed, after this initial export, we'll manage to **only use delta blocks forever**. Benefits are huge for all your XenServer backup: - **fast backup process** - **low bandwidth usage** - **low disk usage** on the backup storage - same level of protection - no agent to install on your hosts (works out of the box!) And you can even imagine to use this to backup more often! Because delta will be smaller, and will be **always delta's**. Want to know how? The secret is **offline merging**: ![](https://xen-orchestra.com/blog/content/images/2016/01/merging.png) > For those who wondered, yes, it's similar to the "Forever Forward Incremental Backup" from VEEAM, but in this case it works for XenServer. ## How it works Nothing changes in the UI: you create a Delta backup job with a configured **retention**. Example: a job with a retention of 7: ![](https://xen-orchestra.com/blog/content/images/2016/01/deltasmall-1.png) And next, when we got the eighth backup, we won't re-export the full disks. We'll merge the older delta in the full disk, like this: ![](https://xen-orchestra.com/blog/content/images/2016/01/deltamergesmall-1.png) > You can see that we also added the last delta on Sunday Now we got merged those two, we can remove the older delta: ![](https://xen-orchestra.com/blog/content/images/2016/01/finaldeltasmall.png) The full disk is now the backup of last Monday. That's it! ### Create multiple VMs at once URL: https://xen-orchestra.com/blog/create-multiple-vms-at-once/ Last updated: 2016-01-13T15:04:54.000Z Do you ever wanted to **create multiple XenServer VMs at once**? Until now, you needed to repeat the operation as often as necessary. Boring when you need to create 10 or even 100 VMs! What about now? We added an option inside [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fmultiple%5Fvms) to do this. You'll see, it's very easy. ## Let's build an army of clones! ![](https://xen-orchestra.com/blog/content/images/2016/01/vmclones.jpg) Just go inside the "Creating a new VM" view, as usual: ![](https://xen-orchestra.com/blog/content/images/2016/01/vmcreation1.png) > We selected a template with a disk in this case, named **web** without any number. I also added my own SSH public key for later. Now let's choose the VM number we want to create from this template (7 is this case): ![](https://xen-orchestra.com/blog/content/images/2016/01/vmcreation2.png) > We'll append automatically the number after the VM name. If it's not the names you wanted, you can change them individually! Let's read the recap carefully before clicking on "Create VM": ![](https://xen-orchestra.com/blog/content/images/2016/01/vmcreation3.png) > I choose to boot the VMs after the creation process. Okay now on the main view, less than 30 seconds later, I got them up and running with their IPs! ![](https://xen-orchestra.com/blog/content/images/2016/01/vmclone.png) And because this is a template with CloudInit, I can even SSH instantly on any of them: ``` $ ssh debian@192.168.100.33 The programs included with the Debian GNU/Linux system are free software; the exact distribution terms for each program are described in the individual files in /usr/share/doc/*/copyright. Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. Last login: Wed Jan 13 05:40:02 2016 from 192.168.100.101 debian@web4:~$ ``` Pretty cool isn't it? ### Create VMs ready in less than 30 sec URL: https://xen-orchestra.com/blog/create-vms-ready-in-less-than-30-sec/ Last updated: 2016-01-08T12:34:55.000Z By ready, we mean: - from the click on "Create VM" - to a SSH access on a 100% working system And also from a generic template: which we can select the disk size dynamically and RAM/CPU. How can it be possible? Using CloudInit! You can find working templates here: - [A Debian 8 template](https://xen-orchestra.com/blog/blog/debian-cloud-template-for-xenserver/) - [A CentOS 7 template](https://xen-orchestra.com/blog/blog/centos-cloud-template-for-xenserver/) ![](https://xen-orchestra.com/blog/content/images/2016/01/performance.jpg) Let's do this! In this case, from a Debian 8 Cloud template. Remember to enter your SSH key: ![](https://xen-orchestra.com/blog/content/images/2015/12/sshkey.png) Clicking on "Create VM": ![](https://xen-orchestra.com/blog/content/images/2016/01/createdebianvm.png) VM is provisioned in approximately **8 seconds**: ![](https://xen-orchestra.com/blog/content/images/2016/01/created.png) Tools reported the IP after **15 seconds**: ![](https://xen-orchestra.com/blog/content/images/2016/01/tools.png) So you can SSH on it directly, it works! ``` $ ssh debian@192.168.100.223 The programs included with the Debian GNU/Linux system are free software; the exact distribution terms for each program are described in the individual files in /usr/share/doc/*/copyright. Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. debian@cloud1:~$ ``` And remember, you are sudoer without password: ``` debian@cloud1:~$ sudo -s root@cloud1:/home/debian# ``` **You got a VM ready in 23 seconds, from clicking on "Create VM" to a SSH shell**. These kind of templates are really handful for working on temporary instances or for your dev teams! We are also working on a complete self service portal (with quotas), stay in touch ;) ### Debian cloud template for XenServer URL: https://xen-orchestra.com/blog/debian-cloud-template-for-xenserver/ Last updated: 2016-01-08T14:09:29.000Z TL;DR: a working and validated Debian 8 (*Jessie*) template is [available here](https://cloud.vates.fr/index.php/s/jynIvCjhso47nR8/download?ref=xen-orchestra.com) if you want. The story continue, after implementing the [XenServer Cloud Init support](https://xen-orchestra.com/blog/cloudinit-support-for-xenserver/) in [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fcloud%5Fdebian), and giving you a [guide for CentOS](https://xen-orchestra.com/blog/blog/centos-cloud-template-for-xenserver): let's see now how to create a Debian compatible template "from scratch". ## Debian installation Let's create a new VM. The trivial way is to use the "Other install media". Put a Debian 8 ISO, netinstall is a good option. CPU, RAM and **even disk size** could be changed later, so no worries with that now. Just click on Create VM. > Disk size could be only extended in the future, so it's better to create a small template (4 GiB is enough). Let's go! First, when you need to fill the username, use "debian" ![](https://xen-orchestra.com/blog/content/images/2016/01/debian_username.png) ### Partitioning To allow future disk growing, you need to create only one partition on the disk: ![](https://xen-orchestra.com/blog/content/images/2016/01/manualpart.png) The recap: ![](https://xen-orchestra.com/blog/content/images/2016/01/recapformat.png) Installing: ![](https://xen-orchestra.com/blog/content/images/2016/01/installingDebiancloud.png) ### Xen tools Before setting CloudInit, you can install XenServer Xen Tools: this way, they will be shipped with your template. Like any normal tool installation: - Mount the XS Tool ISO - `mount /dev/cdrom /mnt` - `dpkg -i /mnt/Linux/xe-guest-utilities_6.5.0-1427_amd64.deb` - `umount /mnt` - eject the ISO ## CloudInit Let's install everything to have a CloudInit ready VM. But first, we'll install sudo: ``` $ apt-get install sudo ``` CloudInit installation: ``` $ apt-get install cloud-init cloud-initramfs-growroot ``` Growroot package will allow to extend your template if necessary. ### Configuration The main configuration file for CloudInit is inside `/etc/cloud/cloud.cfg`. Almost all default parameters are OK, just modify some of them, like this one: ``` preserve_hostname: false ssh_deletekeys: true ``` It's indicating that existing ssh keys should be deleted on a per-instance basis. On a public image, this should absolutely be set to 'True'. We'll also add a `sudo` without password, by editing this section at the end of the file: ``` default_user: name: debian lock_passwd: True gecos: Debian groups: [adm, audio, cdrom, dialout, floppy, video, plugdev, dip] sudo: ALL=(ALL) NOPASSWD:ALL ``` This configuration will have: - a default user "debian", with `sudo` without password. Makes sense for a cloud image (it replaces the root user). - growpart working (extend the FS if the disk is larger than the current partition) - disabled SSH password authentication (only SSH keys) - root disabled - and a lot of other things, you can [find documentation here](https://github.com/number5/cloud-init/blob/master/doc/examples/cloud-config.txt?ref=xen-orchestra.com) Let's use only the CloudInit source needed in our case: ``` $ dpkg-reconfigure cloud-init ``` Uncheck everything but "OpenStack Config Drive": ![](https://xen-orchestra.com/blog/content/images/2016/01/configdrive.png) And now, let's remove any possible root access: ``` $ passwd -l root ``` You're good! You can halt the VM. You won't be able to login anymore with this one, except by using CloudInit from now. ## Template creation The easiest part, on the halted VM view: ![](https://xen-orchestra.com/blog/content/images/2015/12/convert_to_template.png) Done! ## Usage Now, if you go inside the VM creation page: ![](https://xen-orchestra.com/blog/content/images/2016/01/debiancloudcreation.png) Then, activate the config drive and give your SSH key: ![](https://xen-orchestra.com/blog/content/images/2015/12/sshkey.png) Want the new VM bigger than the existing template? No problem, edit the root disk size (**template disk was 4 GiB originally**): ![](https://xen-orchestra.com/blog/content/images/2015/12/diskedition.png) Now start the VM and SSH on its IP, it just works! ## Extra stuff This template is very generic. For your own needs, remember that you can install anything inside it, like a better bashrc file to have a fancy prompt, Git, Docker, etc. ## Download the template This template (with Xen Tools) is available here: - [Download link](https://cloud.vates.fr/index.php/s/jynIvCjhso47nR8/download?ref=xen-orchestra.com) - MD5 sum: e1c8d3fabe00edf2b9b2af3899b5e920 And import it: ![](https://xen-orchestra.com/blog/content/images/2015/12/template_import.png) It will appears in the template list! If you want templates for other distros, just tell us in the comment section :) ### Xen Orchestra 4.11 URL: https://xen-orchestra.com/blog/xen-orchestra-4-11/ Last updated: 2015-12-22T14:55:18.000Z Last release of the year! This 4.11 is among the biggest releases ever (45 issues/enhancements closed!) Some features of this version: - Delta backup - CloudInit support - Improved filtered search - XMPP alert plugin - VDI resizing and moving (working on any XenServer version!) - better XenServer 6.1/6.2 support The complete change log [is here](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#4110-2015-12-22). ## Delta backup Delta backup is a great and major feature of this release. After a full export, you can now only save the delta from the previous backup. That's really exciting because it's: - very fast - space efficient (store only delta after a full backup) Want to discover more about this feature? [Read our previous article on incremental backup with XenServer!](https://xen-orchestra.com/blog/blog/xenserver-incremental-backup/) [![](https://xen-orchestra.com/blog/content/images/2015/12/delta_final_medium.png)](https://xen-orchestra.com/blog/blog/xenserver-incremental-backup/) ## CloudInit support Xen Orchestra is now capable to leverage XenServer and provide a CloudInit configuration to a freshly created VM. I also wrote [a detailed blog post about using CloudInit in Xenserver](https://xen-orchestra.com/blog/blog/cloudinit-support-for-xenserver/), but also a [guide to create a CentOS VM](https://xen-orchestra.com/blog/blog/centos-cloud-template-for-xenserver/) ready with this software (you'll also find a template to download!) ![](https://xen-orchestra.com/blog/content/images/2015/12/sshkey.png) ## Better support for old XenServer XenServer 6.1 and 6.2 are slightly different than 6.5: we managed to enhance the XO support for those versions, it should be far better to use now. ## Improved search Our [search feature is now faster and better](https://xen-orchestra.com/blog/blog/improved-search-for-your-xenserver-infrastructure/). By using filters like "types" or "states", you can make powerful combo to find exactly what you need! For example, to find all your disconnected SRs: ![](https://xen-orchestra.com/blog/content/images/2015/12/disconnectedsr.png) ## XMPP alert plugin What about to [receive alerts on your IM software](https://xen-orchestra.com/blog/xmpp-for-xenserver-backups/) when a backup is finished? That's now possible! ![](https://xen-orchestra.com/blog/content/images/2015/12/xmpp.png) ## Auto plugin discover No more configuration to edit: any installed plugin will be displayed automatically in your plugin view! ## Recover mode You can now recover a VM (even a PV!) if you have troubles with the bootloader for example. [Read our complete blog post about it](https://xen-orchestra.com/blog/blog/recover-your-xenserver-pv-vms/). ![](https://cloud.githubusercontent.com/assets/1241401/11213395/21178820-8d3c-11e5-8f7f-8767afe0f129.png) ## Offline VDI moving Because it's not possible to move a VDI when it's offline (ie: not used in a running VM), we made ourselves a solution for this. And it's **compatible with ALL Xenserver versions!** [Check our full article on this topic](https://xen-orchestra.com/blog/moving-a-vdi-offline-in-xenserver/). ![](https://xen-orchestra.com/blog/content/images/2015/01/vdi3.png) ## VDI resize It's now trivial to resize a VDI, indifferently of its state (online or offline). ## Misc We also improved/add other features, like: - setting a default SR - improving patch retrieval - manual run for backup jobs - read-only connection to hosts - [and more!](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#4110-2015-12-22) # Next? Next release will have: - SMB support for remote backup - probably something like a "Continuous Replication"... - ...and a "Forever Forward Incremental Backup"! - spawn multiple VMs at once - and much more :) Don't miss any news! Follow us on Twitter ([@xenorchestra](https://twitter.com/xenorchestra?ref=xen-orchestra.com)) or subscribe to our RSS feed (top right on this page). ### XenServer incremental backup URL: https://xen-orchestra.com/blog/xenserver-incremental-backup/ Last updated: 2020-05-25T06:38:28.000Z Yaay! It's now possible make incremental (or delta) backups in XenServer, and in an easy way. Thanks to [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fincremental) :) Let's explore this great feature! > Note: this feature is only available from XenServer 6.5\[^n\] ## Until now We already got 3 ways to rollback or backup your current XenServer VMs: - [Full backup](https://xen-orchestra.com/docs/full%5Fbackups.html?ref=xen-orchestra.com) - [Disaster recovery (DR)](https://xen-orchestra.com/docs/disaster%5Frecovery.html?ref=xen-orchestra.com) - [Rolling snapshots](https://xen-orchestra.com/docs/rolling%5Fsnapshots.html?ref=xen-orchestra.com) A "real" backup (ie: be able to recover your VMs even by losing all your storage or host) is only possible with the first 2 options. Indeed, snapshots are not really a backup solution, it's a rollback solution: if you lose your SR, your snapshots are lost too! But space usage of full rolling backup can be a real concern. Let's use an example! ### Example You want to backup a VM named **WindowsServer\_A**. This VM has a 500GB disk, with a real usage of 100GB. If you want to backup every night of the week with a retention of 7, it will be something like this on your backup storage: ![](https://xen-orchestra.com/blog/content/images/2015/12/nodelta.png) 7 full copies of your VM. Let's do the maths, because each .xva file will use \~100GB: it's 700GB of disk used only for this VM. At worst, during the retention of the 8th backup, you'll **use 800GB of disk** (time to write the 8th backup, then remove the oldest one). Let's see then how it works using XO delta backup! (which is the feature name for XenServer incremental backup!) ## XO delta backup By using the new capabilities of XenServer 6.5 (VHD export), we can considerably reduce the size of backups. And keeping the same level of backup for the administrator! 1. The first export will be a full backup too 2. Then, we'll export only incremental data from this VM (delta from previous... delta) 3. We'll cycle to offer the same retention policy ![delta_final](https://xen-orchestra.com/blog/content/images/2020/05/delta_final.png) From the previous example, let's imagine you modify 1GB of data on your VM everyday. You'll use only **106GB of disk**. Even in the worst case scenario (8th backup), **the difference will be almost 600GB saved** for the same backup service! But that's not all! You'll also **save a considerable amount of time for your VM backup**: exporting 1GB is not the same as exporting 100GB. Thus, it opens the possibility to make backup more often. To create them, just go inside the Backup menu and select "Delta Backup": ![](https://xen-orchestra.com/blog/content/images/2015/12/delta_menu.png) ### Restore a delta backup That's exactly the same than restoring a full backup: nothing changes! Just go inside the "Restore" view, select the VM you want to import and from which backup (also choose the target Storage to import it). That's it! You can import it on any SR, **even a freshly installed XenServer host**: all the VM data will be restored! ## More to come! This feature is just a start! We can start to work now on two things to improve [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fincremental): - improve the delta to avoid any new full export, even after the retention number is exceeded - use those delta feature to improve Disaster Recovery feature: this could lead to a **near-realtime replication on a remote host!** ### Forever incremental backup Does this name ring any bell? Yes, that's the VEEAM solution to [avoid any full export](http://helpcenter.veeam.com/backup/80/vsphere/incremental%5Fforever%5Fbackup.html?ref=xen-orchestra.com) after the first one. By merging the older full backup to the oldest delta, we could achieve this. Be sure we'll work on this very soon! ![](http://helpcenter.veeam.com/backup/80/vsphere/retention_forever_incremental3.png) ### Continuous DR protection By using delta disks, we could now improve the current Disaster Recovery feature for XenServer: - make the first full streaming copy to another XenServer host - then send only the delta regularly (every hour?) This will also considerably reduce the bandwidth needed to use the DR feature! ![](https://xen-orchestra.com/blog/content/images/2015/12/contiuousDR.png) Enjoy XO! \[^n\]: because VHD export is only available from Xen Server 6.5\. ### CentOS cloud template for XenServer URL: https://xen-orchestra.com/blog/centos-cloud-template-for-xenserver/ Last updated: 2015-12-18T16:29:33.000Z TL;DR: a working template is [available here](https://cloud.vates.fr/index.php/s/NoUNeaP24wf33Bn/download?ref=xen-orchestra.com) if you want. After implementing the [XenServer Cloud Init support](https://xen-orchestra.com/blog/cloudinit-support-for-xenserver/) in [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fcloud%5Fcentos), let's see now how to create a compatible template "from scratch". ## CentOS installation Let's create a new VM. Use the "CentOS 7" template (you can use the "Other install media" if you don't have this template). Put a CentOS ISO, netinstall is a good option. ![](https://xen-orchestra.com/blog/content/images/2015/12/vmcreation1.png) CPU, RAM could be changed later, so no worries with that now. Just click on Create VM. ![](https://xen-orchestra.com/blog/content/images/2015/12/vmcreation2.png) Let's go! ![](https://xen-orchestra.com/blog/content/images/2015/12/vmcreation3.png) ### Partitioning To allow future disk growing, you need to create only one partition on the 10 GiB disk: ![](https://xen-orchestra.com/blog/content/images/2015/12/vmcreation5.png) Choose your mirror: ![](https://xen-orchestra.com/blog/content/images/2015/12/vmcreation6.png) Configure your root password. It could be a weak password because **we'll deactivate it later**. ![](https://xen-orchestra.com/blog/content/images/2015/12/vmcreation8.png) Now your VM installed, let's configure it: - just verify your boot order: Hard-drive first! (faster to boot) - you can let DVD or Network after, in case you'll have problem with your OS. Or you can de-activate them if you don't care with your future template. ### Xen tools Before setting CloudInit, you can install XenServer Xen Tools: this way, they will be shipped with your template. Insert the "xs-tools.iso", mount it, and install them with `rpm i`. ## CloudInit Now the system is install, let's go inside the console, login as root and install Cloudinit! But first, we'll update our system: ``` $ yum update ``` CloudInit installation: ``` $ yum install cloud-init cloud-utils-growpart ... Total download size: 6.7 M Installed size: 20 M Is this ok [y/d/N]: Y ... Complete! ``` Growpart package will allow to extend your template if necessary. ### Configuration The main configuration file for CloudInit is inside `/etc/cloud/cloud.cfg`. Almost all default parameters are OK, just modify this one: ``` ssh_deletekeys: 1 ``` It's indicating that existing ssh keys should be deleted on a per-instance basis. On a public image, this should absolutely be set to 'True' (or 1 here). By the way, the CentOS shipped config will have: - a default user "centos", with `sudo` without password. Makes sense for a cloud image (it replaces the root user). - growpart working (extend the FS if the disk is larger than the current partition) - disabled SSH password authentication (only SSH keys) - root disabled - and a lot of other things, you can [find documentation here](https://github.com/number5/cloud-init/blob/master/doc/examples/cloud-config.txt?ref=xen-orchestra.com) Let's remove any possible root access: ``` $ passwd -l root ``` You're good! You can halt the VM. You won't be able to login anymore with this one, except by using CloudInit from now. ## Template creation The easiest part, on the halted VM view: ![](https://xen-orchestra.com/blog/content/images/2015/12/convert_to_template.png) Done! ## Usage Now, if you go inside the VM creation page: ![](https://xen-orchestra.com/blog/content/images/2015/12/vmcreation.png) Then, activate the config drive and put your SSH key: ![](https://xen-orchestra.com/blog/content/images/2015/12/sshkey.png) Want the new VM bigger than the existing template? No problem, edit the root disk size (**template disk was 10 GiB originally**): ![](https://xen-orchestra.com/blog/content/images/2015/12/diskedition.png) Now start the VM and SSH on its IP, it just works! ## Download the template This template (with Xen Tools) is available here: - [Download link](https://cloud.vates.fr/index.php/s/NoUNeaP24wf33Bn/download?ref=xen-orchestra.com) - MD5 sum: bd9ea10c7896d5fefc2fb7944d6965fe And import it: ![](https://xen-orchestra.com/blog/content/images/2015/12/template_import.png) It will appears in the template list! More templates will come (Ubuntu, Debian). If you want templates for other distros, just tell us in the comment section :) ### CloudInit support for XenServer URL: https://xen-orchestra.com/blog/cloudinit-support-for-xenserver/ Last updated: 2015-12-16T22:04:02.000Z We are proud to announce that you can now use the CloudInit system with XenServer, **without any plugin to install** on your hosts. Only by using [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fcloud%5Fsupport). Let's see what it can do for you and how to use it. ## What's "CloudInit"? Cloud-init is a program "that handles early initialization of a cloud instance"[\[1\]](#fn1). In other words, you can, on a "cloud-init"-ready template VM, pass a lot of data at first boot: - setting hostname - add ssh keys - grow automatically the file system - create users - and a lot more! This tool is pretty standard and used everywhere. A lot of existing cloud templates are using it. So it means customizing very easily your VM when you create it from a compatible template. It brings you closer to the "instance" principle, like in Amazon cloud or OpenStack. Let's see a real use case. First, select your template and name it: ![](https://xen-orchestra.com/blog/content/images/2015/12/template_choice.png) Then, activate the config drive and put your SSH key: ![](https://xen-orchestra.com/blog/content/images/2015/12/sshkey.png) Want the new VM bigger than the existing template? No problem, edit the root disk size (**template disk was 8 GiB originally**): ![](https://xen-orchestra.com/blog/content/images/2015/12/diskedition.png) Finally, create the VM. That's all: ![](https://xen-orchestra.com/blog/content/images/2015/12/recap.png) Now start the VM and SSH on its IP, and it's magic: **the system got the right VM hostname** (from VM name) and you don't have to use a password to access it (thanks to your SSH key): ``` $ ssh centos@192.168.100.226 [centos@tmp-app1 ~]$ ``` The default `cloud-init` configuration in CentOS allows you to be a sudoer directly: ``` [centos@tmp-app1 ~]$ sudo -s [root@tmp-app1 centos]# ``` Check the root file system size: indeed, **it was automatically grown** to what you need (remember, the template had a 8G disk): ``` [centos@tmp-app1 ~]$ df -h /dev/xvda1 20G 1,2G 18G 6% / ``` Now, you can work and make whatever you want on this VM! ### No agent, no install We managed to implement this feature without extra software to install on any XenServer. So basically, as soon you got a Xen Orchestra version up to 4.11, you have nothing to do: it just works. Pretty cool isn't it? ### Give me some templates! I was sure you wanted some of them ;) In a coming article, I'll give you some Ubuntu, Debian and CentOS templates, but also write a guide to do them properly. They will be XVA templates, ready to import in Xen Orchestra, and they will appear in your template list when you create a VM. ## Heading for the Cloud! In the future, this feature combined to a self-service with quota, will allow you to let your users to create their own VMs/instances without setting anything on your side. That's clearly another step toward the cloud! And that's not all. We'll provide soon more options for Cloud Config, e.g for creating users and directly put your own cloud-init file through the web interface if necessary! Now, XenServer has a new rocket to push it into the Cloud. And this one is fast. ![](https://xen-orchestra.com/blog/content/images/2015/12/rocket.png) --- 1. [https://help.ubuntu.com/community/CloudInit](https://help.ubuntu.com/community/CloudInit?ref=xen-orchestra.com) [↩︎](#fnref1) ### Moving a VDI offline in XenServer URL: https://xen-orchestra.com/blog/moving-a-vdi-offline-in-xenserver/ Last updated: 2015-12-15T18:29:15.000Z As you may know in XenServer, you can move a VDI -from a running VM- to another SR (Storage Repository). We exposed this feature almost 1 year ago in [our article explaining how to move a VDI in live](blog/moving-vdi-in-live/). ![](https://xen-orchestra.com/content/images/2015/01/vdi3.png) But what about a VDI on a halted VM? Until now, it wasn't possible. And it was pretty annoying. That's why we updated our VDI "migrate" API method in [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Foffline%5Fvdi) to allow this, and it's fully automated. It works **exactly** like in live: but if before you got an error, now you get what you wanted! Just edit your disk panel in the VM and select another SR for one of your VDI: ![](https://xen-orchestra.com/blog/content/images/2015/12/offlineVDImoving.png) That's it! If your VM is halted, we'll move the VDI to the new SR. If it's running, that's like before (XenServer will move it for us). So even if you created your VM on a wrong SR, you don't have to boot it to move its VDIs. Or if you want to do that offline, due to maintenance, that's also possible. ### Set the XenServer default SR URL: https://xen-orchestra.com/blog/set-the-xenserver-default-sr/ Last updated: 2022-06-02T15:56:55.000Z 💡 This guide is 100% compatible with [XCP-ng](https://xcp-ng.org/?ref=xen-orchestra.com). In XenServer, the default SR (Storage Repository) is where your VDIs are stored by default. It's very useful for a lot of things, avoiding the user to configure itself for each operation. ## With Xen Orchestra Just go inside your pool view, you'll have a list of your SRs. Just click on the "disk" icon at the end of the line corresponding to the SR you want to be the new default one: ![](https://xen-orchestra.com/blog/content/images/2015/12/setdefaultsr.png) You'll have a modal window to confirm: ![](https://xen-orchestra.com/blog/content/images/2015/12/setdefaultsr_modal.png) That's it! Your default SR is now changed: ![](https://xen-orchestra.com/blog/content/images/2015/12/setdefaultsr_label.png) ## With the CLI If you want to do it "manually", you can go on the host with SSH, and type: ``` xe pool-param-set uuid= default-SR= ``` You can find your `` using `xe sr-list`. The `` will be autocompleted using tab key. ### Recover or reinstall your XenServer PV VMs URL: https://xen-orchestra.com/blog/recover-your-xenserver-pv-vms/ Last updated: 2015-12-08T16:27:21.000Z This blog post will explain how to deal with your existing PV guests, when they can't boot anymore. ## The problem Typically, when you failed your installation of a PV guest, you got: ``` The bootloader for this VM returned an error -- did the VM installation succeed? Error from bootloader: no bootable disk ``` Or even: ``` The bootloader for this VM returned an error - did the VM installation succeed? Unable to find partition containing kernel ``` It could also happened if your /boot is corrupted for any reason (IO error, removed grub files, etc.) The previous solutions were: - if it's after a failed installation, you are good to re-create a new VM - if it occurs on a used VM, you'll need to make a lot of complicated stuff to access your data on your existing VDIs (detach the disk, attach it to another VM, or mount it inside the host...) #### Side note If you experience this error: ``` Internal error: xenopsd internal error: XenguestHelper.Xenctrl_dom_linux_build_failure(2, " panic: xc_dom_core.c:540: xc_dom_find_loader: no loader\\\"") ``` That's another story: it's because your XenServer is too old and it's not compatible with Grub2\. XenServer 6.5 solves the issue, as explained in a [previous article](https://xen-orchestra.com/blog/testing-xenserver-6-2-5-beta/#step3profit). If you don't want to upgrade, there is also [another way to fix it](http://www.jfinley.com/2014/09/citrix-xenserver-ubuntu-12-vms-fail-boot-missing-bootloader/?ref=xen-orchestra.com). ## The solution When you build a software like [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fpvrecover), you need to understand how XenServer works under the hood. One of our customers asked to allow its clients to be able to reinstall [their delegated VMs](https://xen-orchestra.com/?ref=xen-orchestra.com#!/features/cloud?pk%5Fcampaign=blog%5Fpvrecover). Very trivial with a XenServer HVM guest: just change the boot order. But what about XenServer PV guests? ### PV guests are special > If you just want the solution, go to the next paragraph. PV guests are installed with the help of scripts executed on your XenServer host (Dom0). Basically, during their first boot after be provisioned, they will be booted with a script called `eliloader`. [This Python script](http://wiki.xenproject.org/wiki/XCP%5FPV%5Ftemplates%5Fstart?ref=xen-orchestra.com) will manage all the aspects of a PV installation, for each major distro. After this first boot, it will prepare the VM to boot normally, on the grub config inside the guest. But if your installation fails, you are totally doomed for the next boot. Or if you bootloader is corrupted, you can't boot it anymore. That's why we created a "Recovery mode". It exists for HVM guest [since 4.10](https://xen-orchestra.com/blog/xen-orchestra-4-10/#startvminrecoverymode). But it's far from trivial to make the same feature for PV. Because to boot again on an ISO, you need to: - set the `PV_bootloader` to `eliloader` - put XAPI `other_config.install-repository` to `cdrom` - give the CD drive a bootable flag to `true` - remove the bootable flag on all other drives - recover the `install-distro` from its parent template All of this complicated stuff is done by just clicking on one button. ### Recovery mode Inside your VM view, just click on this button: ![](https://cloud.githubusercontent.com/assets/1241401/11213395/21178820-8d3c-11e5-8f7f-8767afe0f129.png) It will boot on the CD inside the CD drive. You can now: - install a fresh OS on top of the previous one\[^n\] - abort the installation to drop a shell, in order to recover your files, or reinstall Grub ![](https://xen-orchestra.com/blog/content/images/2015/12/shell_debian.png) All your partitions are easily accessible: ``` # fdisk -l Disk /dev/xvde: 8589 MB Device Boot Start End Blocks Id System /dev/xvde1 2048 15988735 7993344 83 Linux /dev/xvde2 15990782 16775167 392193 5 Extended /dev/xvde5 15990784 16775167 392192 82 Linux swap ``` And you can do whatever you need inside. Note that network is also working. \[^n\]: Same distro, e.g any Debian on top of a previous Debian ### Improved search for your XenServer infrastructure URL: https://xen-orchestra.com/blog/improved-search-for-your-xenserver-infrastructure/ Last updated: 2015-12-04T13:30:20.000Z Here is some news about a nice improvement coming in the next version of Xen Orchestra: an improved search bar. Our previous search system worked for filtering in live VM/host/SR/pool name, IP address, tags and whatever inside those objects. But what about advanced requests? We wanted to answer those issues: - which VMs are currently running? - do I have any SR currently disconnected from a host? - which host is halted? - display all halted VM with "production" label - avoid lag on large infrastructure It's now possible, and it's dead easy thank to search queries and the `*` special char. E.g `*vm` will display only VMs, `*halted` will only display objects in "Halted" state. The complete list of queries is accessible with the web interface (see below). #### Assist for filter possibilities Having a "format" for requests in not very hard to do. But helping the user to find them is really important. That's why we added a sub-bar in the search/flat view: ![](https://xen-orchestra.com/blog/content/images/2015/12/searchbar.png) So far, it contains to menus: "Types" and "States" ![](https://xen-orchestra.com/blog/content/images/2015/12/searchmenu1.png) ![](https://xen-orchestra.com/blog/content/images/2015/12/searchmenu2.png) By checking those boxes, it will fill the search field on the same time. Ticking "VM" and "Running" will do: ``` *running *vm ``` #### Real examples **Find a disconnected SR:** ![](https://xen-orchestra.com/blog/content/images/2015/12/disconnectedsr.png) > Damn! My "iSCSI SSD" SR isn't connected to all its XenServer hosts! But which one? See below! **Find all disconnected objects**: ![](https://xen-orchestra.com/blog/content/images/2015/12/disconnectedall.png) > You got your answer! "lab1" lost its connection to "iSCSI SSD". **Do I have any production VM halted?** (step by step, using a "production" tag) 1. All VMs: `*vm` 2. All VMs which are "Halted": `*vm *halted` 3. All VMs which are "Halted" with "Production": `*vm *halted production` Result: ![](https://xen-orchestra.com/blog/content/images/2015/12/prodhalted.png) > Damn! This VM shouldn't be halted! #### Remove the lag Because it filtered after every keystroke, people using XO on large infrastructure had some issues. Thus, we decided to add a 400 ms waiting time after each stroke before filtering. And it's far better now! ## What's next? This feature will be available in 4.11 (next week). We'll probably improve the system by adding more menus (e.g tags to search only on tags, or something to target a attribute rather than the whole object). ### XMPP notifications for XenServer backups URL: https://xen-orchestra.com/blog/xmpp-for-xenserver-backups/ Last updated: 2015-12-03T15:55:54.000Z Since [last release](https://xen-orchestra.com/blog/blog/xen-orchestra-4-10/), we added email notifications for all backup events ([full backup](https://xen-orchestra.com/docs/full%5Fbackups.html?ref=xen-orchestra.com), [rolling snapshots](https://xen-orchestra.com/docs/rolling%5Fsnapshots.html?ref=xen-orchestra.com) or even [DR](https://xen-orchestra.com/docs/delta%5Fbackups.html?ref=xen-orchestra.com)): ![](https://xen-orchestra.com/blog/content/images/2015/12/backupemail.png) Not fun enough? So go for XMPP notification then! Get your XOA talking to you directly through XMPP protocol: ![](https://xen-orchestra.com/blog/content/images/2015/12/xmpp.png) This new plugin is pretty easy to use, here with a local server (but it's compatible with any XMPP server): ![](https://xen-orchestra.com/blog/content/images/2015/12/xmppconfig.png) What about people to notify? Inside the same report plugin, you have now a specific entry for XMPP users: ![](https://xen-orchestra.com/blog/content/images/2015/12/reportsconfig.png) So after any backup event (successful or not), "[myemail@example.org](mailto:myemail@example.org)" will receive an email, but "olivier@localhost" will receive a XMPP text message too! ### Xen Orchestra 4.10 URL: https://xen-orchestra.com/blog/xen-orchestra-4-10/ Last updated: 2015-11-27T16:15:36.000Z Last release of the month! This one is **pretty big**: - 30+ issues/enhancements closed - 10 new usable features - a lot of improvements - and multiple bug fixes! In few words: we finished the first batch of backup features, and we included a lot of things you'll love :) The official change log is [available here](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#4100-2015-11-27). ### Job manager A new entry in the main menu of Xen Orchestra: the job manager: ![](https://xen-orchestra.com/blog/content/images/2015/11/jobmanager.png) You can now **schedule all actions** on your hosts, VMs, or ACLs. It's configured in 2 steps: 1. Create a job 2. Schedule it! Real example, step by step: **Creating a job called "security reboot"** (in this case, restart "nfs" and "Core1" VMs): ![](https://xen-orchestra.com/blog/content/images/2015/11/job_create.png) Note that you can execute this job **now** by clicking on the orange play button (to test it for instance): ![](https://xen-orchestra.com/blog/content/images/2015/11/job_execute.png) **Schedule the job** (every Sunday at 5:00 AM): ![](https://xen-orchestra.com/blog/content/images/2015/11/schedule_job.png) And this is it! The job is listed in the Overview: ![](https://xen-orchestra.com/blog/content/images/2015/11/schedule_recap.png) Possibilities are infinite! You can plan a LOT of things (any actions on a VM, like migrate, start, clone, suspend etc. Same thing apply on a host). Here is few examples: Example 1, save on your electric bill: - plan a live migration on your VMs at 11:00PM on a less powerful host, to shutdown the big one - start the big server at 6:00AM and migrate back VMs 15 minutes later Example 2, scale when you need: - schedule the boot of extra-VMs during your usual activity spikes (horizontal scaling) - also plan more vCPUs or RAM to these VMs at the same time - go back to the previous state when your planned load is low (e.g: during the night) Example 3, ACLs during opening hours - add and remove ACLs on your object depending of hour of the day. Example 4, your turn! Everything is possible, if you want to share ideas using this feature, tell us in the comment section :) ### Email notifications for backup This new feature closes the first milestone of backup. Thanks to 2 new plugins, you can now **be notified by emails** of finished backup processes (ie: scheduled "full backup", "snapshots" or "disaster recovery"). Now you can't forget it: we'll produce a digest and send to a list of recipients. To configure it, 2 steps. First, add a list of recipient(s) for the notifications (in the plugin "backup-reports"): ![](https://xen-orchestra.com/blog/content/images/2015/11/backup-reports.png) Then, configure the SMTP server: ![](https://xen-orchestra.com/blog/content/images/2015/11/emailtransport.png) That's it: your next scheduled jobs will be recap in a email. It will look like this: ``` Global status: Success Start time: Fri Nov 27 2015 10:54:00 GMT+0100 End time: Fri Nov 27 2015 10:54:04 GMT+0100 Duration: a few seconds Successful backed up VM number: 1 Failed backed up VM: 0 VM : miniVM UUID: 4b85a038-6fd1-30f0-75c6-8440121d8faa Status: Success Start time: Fri Nov 27 2015 10:54:00 GMT+0100 End time: Fri Nov 27 2015 10:54:04 GMT+0100 Duration: a few seconds ``` ### CoreOS+Docker VM with cloud config ![](https://xen-orchestra.com/content/images/2015/05/docker_logo.png) You can now create CoreOS VMs using the "XS Container" plugin, as explained in detail in this blog post : [Docker support in XenServer, the ultimate guide](https://xen-orchestra.com/blog/blog/docker-support-in-xenserver-the-ultimate-guide/) Basically, when you'll select the CoreOS template, you'll have a new panel appearing in the VM creation view: ![](https://xen-orchestra.com/blog/content/images/2015/11/cloudconfig.png) Don't forget to add your own SSH public key. By booting with the CoreOS iso, you'll have a SSH ready access. And a Docker panel listing your containers inside this VM: ![](https://xen-orchestra.com/blog/content/images/2015/11/dockerlist.png) In the future, if XenServer will include a dedicated CloudConfig Disk plugin, we could imagine to provision your VM with SSH ready access, auto-disk growing and all the features exposed with [CloudInit](https://cloudinit.readthedocs.org/en/latest/?ref=xen-orchestra.com). ### Snapshot with quiesce Using the same button as before, and if your VM support quiesce, XO will [automatically create a quiesced snapshot!](https://xen-orchestra.com/blog/blog/xenserver-quiesce-snapshots/) [![](https://xen-orchestra.com/content/images/2015/11/quiescechover.png)](https://xen-orchestra.com/blog/blog/xenserver-quiesce-snapshots/) > A new icon is now displayed in the snapshot panel if it's done with quiesce ### Patches report and updates Now, all hosts with missing patches are recap in the dashboard view (on the bottom): ![](https://xen-orchestra.com/blog/content/images/2015/11/dashboard1.png) You can install all missing patches for one host, or on your **whole XenServer infrastructure**! ![](https://xen-orchestra.com/blog/content/images/2015/11/dashboard2.png) Having your whole XenServer host patched and up to date never been so easy! ### Console improvements #### Clipboard support Clipboard can be used in both ways: 1. from the VM to your system 2. from your system to your VM ![](https://xen-orchestra.com/blog/content/images/2015/11/clipboard.png) #### Focus only when hovered Your keyboard events are now only grabbed when you have your mouse over the console itself. The global behavior of the console view is far better! ### Start VM in recovery mode If you want your HVM guest to boot without the installed OS (e.g to boot on a CD), you can now use the recovery start button: ![](https://cloud.githubusercontent.com/assets/1241401/11213395/21178820-8d3c-11e5-8f7f-8767afe0f129.png) ### Emergency shutdown With one button, you can now: - suspend all running VM on a host - halt it right after This button is in the host view: [![](https://xen-orchestra.com/content/images/2015/11/emergency_button.png)](https://xen-orchestra.com/blog/blog/xenserver-emergency-shutdown/) More details can be found in the dedicated article: [XenServer emergency shutdown](https://xen-orchestra.com/blog/blog/xenserver-emergency-shutdown/). You can also use `xo-cli` to trigger this action, thus connecting this call to the output of your UPS script: ``` $ xo-cli host.emergencyShutdown id= ``` No need to know which VM is currently running on it, everything will be executed automatically. ### Better backup logs Back logs are now displayed with their name/tag, not their ID. This way, it's easier to locate a specific job. ### Auto power VM Activate "Auto Power" on a VM will also configure the pool accordingly. [Read our blog post for further detail](https://xen-orchestra.com/blog/blog/auto-start-vm-on-xenserver-boot/). ![](https://xen-orchestra.com/content/images/2015/11/autopoweron.png) ### Remember disconnected servers When you chose to disconnect a server in the Settings, it won't be reconnected even if you restart `xo-server`: the state (connected/disconnected) is now saved. ### Extended logs If you need more verbose logs, you can modify the configuration of `xo-server`and add: ``` verboseApiLogsOnErrors: true ``` > Warning: this should be only used for advanced analyze. Performance impact could be important. This will display extended logs, with IP address of any connected clients, detailed methods parameters etc. ## What's next? We'll focus on the new interface, as we already [explained here](https://xen-orchestra.com/blog/blog/announcing-xen-orchestra-5-x/). But until then, you'll have a nice exclusive backup feature coming soon. Stay tuned! ### Auto start VM on XenServer boot URL: https://xen-orchestra.com/blog/auto-start-vm-on-xenserver-boot/ Last updated: 2015-11-25T11:02:34.000Z This article explains how to start automatically a VM when you boot or reboot your XenServer host. Indeed, if for a reason you need to restart your host (or if it reboots for any "non-planned" reason), it's a good thing to have your VM started automatically. #### Keep it simple Our goal in [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fautopower) is it provide the easiest way to realize actions. For instance, it means only one thing: in your VM view, just edit the General field and choose "Auto Power On" at "True": ![](https://xen-orchestra.com/blog/content/images/2015/11/autopoweron.png) Then "Save". That's it! But, behind the scene, it's a little more complicated. #### Under the hood We made some choice to simplify this settings. If you want to do it manually in XenServer with `xe` CLI, you need to: 1. Configure the Pool for "auto\_poweron": `xe pool-param-set uuid= other-config:auto_poweron=true` 2. Configure the VM: `xe vm-param-set uuid= other-config:auto_poweron=true` In [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fautopower), those 2 steps are merged in one: when you edit the parameter on a VM, it's automatically applied on the current pool! What about possible interference with HA? Yes, it's discouraged to use both `auto_poweron` and HA. That's exactly why we hide this settings only if HA is enabled on your pool! ### Docker support in XenServer, the ultimate guide URL: https://xen-orchestra.com/blog/docker-support-in-xenserver-the-ultimate-guide/ Last updated: 2021-05-07T05:39:31.000Z Because we created ourselves an interface to the [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver?pk%5Fcampaign=blog%5Fdocker%5Fguide) Docker plugin in [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fdocker%5Fguide), we learned exactly how it works, and how to use it. That's why we are sharing this here in a guide for users, but also for people who want to understand how it works. FYI, Xen Orchestra supports Docker controls in the VM view [since 4.0](https://xen-orchestra.com/blog/xenserver-xen-orchestra-and-docker/), 6 months ago! But now, we also supports VM creation with direct Docker support, using CoreOS template. > This guide is also [available in our official documentation!](https://xen-orchestra.com/docs/manage%5Finfrastructure.html?ref=xen-orchestra.com#docker-support) ## Prerequisite - [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver?pk%5Fcampaign=blog%5Fdocker%5Fguide) 6.5 or higher - Plugin installation (see below) - CoreOS ISO ([download it here](http://stable.release.core-os.net/amd64-usr/current/coreos%5Fproduction%5Fiso%5Fimage.iso?ref=xen-orchestra.com)) for CoreOS installations - [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fdocker%5Fguide) 4.10 or newer ## Docker plugin installation This first step is needed until Docker is supported nativly in the XenServer API (XAPI). > The plugin should be installed in every hosts, even if they are on the same pool. ##### For XenServer 6.5 1. SSH on your XenServer 2. Download the plugin: ``` wget http://downloadns.citrix.com.edgesuite.net/10343/XenServer-6.5.0-SP1-xscontainer.iso ``` 1. Install it: ``` xe-install-supplemental-pack XenServer-6.5.0-SP1-xscontainer.iso ``` ##### For XenServer 7.0 1. SSH on your XenServer 2. Download the plugin: ``` wget http://downloadns.citrix.com.edgesuite.net/11621/XenServer-7.0.0-xscontainer.iso ``` 1. Install it: ``` xe-install-supplemental-pack XenServer-7.0.0-xscontainer.iso ``` ##### For XenServer 7.1 1. SSH on your XenServer 2. Download the plugin: ```wget ``` 1. Install it: ``` xe-install-supplemental-pack XenServer-7.1.0-xscontainer.iso ``` ##### For XenServer 7.2 1. SSH on your XenServer 2. Download the plugin: ``` wget http://downloadns.citrix.com.edgesuite.net/11993/XenServer-7.2.0-xscontainer.iso ``` 1. Install it: ``` http://downloadns.citrix.com.edgesuite.net/12641/XenServer-7.2.0-xscontainer.iso ``` That's it! You are ready for enjoying Docker support! ## Docker managed VMs There is two ways to use the newest exposed Docker features: - install a CoreOS VM - transform an existing VM in supported Docker VM ### CoreOS [CoreOS](https://coreos.com/?ref=xen-orchestra.com) is a Linux distribution with bundled software, like `etcd`, `rkt`, `fleet` etc. The ISO install CD is also using `CloudInit` (which is the interesting thing here). ![](https://xen-orchestra.com/blog/content/images/2015/11/coreos-logo.png) #### Create the VM First thing first, create a new VM as usual: ![](https://xen-orchestra.com/blog/content/images/2015/11/createvm.png) Then, select the "CoreOS" template in the list and name it as you want: ![](https://xen-orchestra.com/blog/content/images/2015/11/coreostemplate.png) Select the [CoreOS ISO](http://stable.release.core-os.net/amd64-usr/current/coreos%5Fproduction%5Fiso%5Fimage.iso?ref=xen-orchestra.com) as source for the installation: ![](https://xen-orchestra.com/blog/content/images/2015/11/coreosiso.png) You will also notice Cloud Config panel: ![](https://xen-orchestra.com/blog/content/images/2015/11/cloudconfig.png) You'll have to uncomment the line: `# - ssh-rsa ` And replace it with your actual SSH public key: `- ssh-rsa AAAA....kuGgQ me@mypc` The rest of the configuration is identical to any other VM. Just click on "Create VM" and you are done: ![](https://xen-orchestra.com/blog/content/images/2015/11/createdockereadyvm.png) Your VM is now ready. Nothing else to do. You can see it thanks to the ship logo in the main view: ![](https://xen-orchestra.com/blog/content/images/2015/11/dockerenable.png) But also in the VM view, you'll have a Docker panel: ![](https://xen-orchestra.com/blog/content/images/2015/11/dockerpanel.png) It's empty, for sure, because you don't have any Docker container running. So now, let's boot the VM, and create some Docker containers! You should be able to access the VM with the user `core` and your SSH key (so no password to write!). Oh and the good news: because Xen tools are installed automatically, you already have the IP address displayed in Xen Orchetra: ![](https://xen-orchestra.com/blog/content/images/2015/11/dockerip.png) So in our example (use the `core` user): ``` me@mypc $ ssh core@192.168.100.209 The authenticity of host '192.168.100.209 (192.168.100.209)' can't be established. ED25519 key fingerprint is SHA256:NDOQgOqUm3J2ZsBEMNFCpXE1lTsu4DKqKN6H7YcxS3k. Are you sure you want to continue connecting (yes/no)? yes Warning: Permanently added '192.168.100.209' (ED25519) to the list of known hosts. Last login: Sun Nov 22 21:00:05 2015 CoreOS stable (607.0.0) Update Strategy: No Reboots core@core1 ~ $ ``` You are now connected! Let's make some tests before installing it on the disks. ``` core@core1 ~ $ docker run --name hello -d busybox /bin/sh -c "while true; do echo Hello World; sleep 1; done" Unable to find image 'busybox:latest' locally Pulling repository busybox 17583c7dd0da: Download complete d1592a710ac3: Download complete Status: Downloaded newer image for busybox:latest 150bc05a84971489b2dd5dc99fe0169cdbd23599d6fac55a6a8756a3c6f52853 ``` Guess what? Check in Xen Orchestra, in the VM view: ![](https://xen-orchestra.com/blog/content/images/2015/11/dockerlist.png) You can now "cycle" this container: stop, pause or reboot it! #### CoreOS installation Now it works, you can make a persistent installation of your CoreOS VM. In the same SSH terminal used before, just type: ``` core@core1 ~ $ sudo coreos-install -d /dev/xvda -o xen -C stable ``` You should have this output: ``` Downloading the signature for http://stable.release.core-os.net/amd64-usr/607.0.0/coreos_production_xen_image.bin.bz2... ... Downloading, writing and verifying coreos_production_xen_image.bin.bz2... Success! CoreOS stable 607.0.0 (xen) is installed on /dev/xvda ``` You can reboot the VM and even eject the CoreOS ISO: it will boot as a normal VM now! ### How it works During the VM creation, the XenServer "XSContainer" plugin will create an extra disk: "Automatic Config Drive", with a size of 2MB. This is where the necessary configuration you edited previously (with the SSH key) is passed to the CoreOS VM! In fact, it uses `CloudInit`. #### What is CloudInit? `CloudInit` is a software created to simplify VM provisioning for Cloud instances: it was originally developed for the Amazon Cloud, but works with all major Cloud ready systems, like OpenStack for example. Basically, it reads configuration during the boot, allowing: - SSH keys management for newly created VM/instances - Root disk filesystem growing - User/group management - Arbitrary commands execution (system update, custom scripts etc.) In our case, it's used by the XSContainer plugin to allow host communication to the Docker daemon running in the VM, thus exposing Docker commands outside it. ### Existing VMs You can also use the XSContainer plugin to "transform" an existing VM into a "Docker" managed one. You need to have this installed inside the VM: - Docker - openssh-server - ncat For Debian/Ubuntu like distro: `apt-get install docker.io openssh-server nmap`. For RHEL and derived (CentOS...): `yum install docker openssh-server nmap-ncat`. To use Docker as non-root, please add the user you want inside the "Docker" group, eg with: ``` sudo usermod -aG docker $(whoami) ``` Now, you need to access to your host (Dom0) and use the following command: ``` xscontainer-prepare-vm -v -u ``` > Because "prepare-vm" is not exposed outside the Dom0 (yet?), we can't use Xen Orchestra to give you a one-click solution so far. ## The future? Today, the XenServer "XSContainer" plugin is a nice way to start to play with Docker and expose it outside [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver?pk%5Fcampaign=blog%5Fdocker%5Fguide). With [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fdocker%5Fguide), you can already delegate rights to your developers only on dedicated VMs running CoreOS and Docker: this way, they can manage their containers in a easy way, and they can reboot the VM if necessary. But it could be also a great start for other features: - CloudInit support for other templates: using ISO reading CloudConfig Drive, we could imagine to give you the possibility to provision VMs in Xen Orchestra like any other Cloud system: pass the user SSH key, grow the disk to a desired size, create users etc. - Better Docker activation, exposed directly in the XAPI, allowing XO to transform a VM into a Docker managed one. ![](https://xen-orchestra.com/content/images/2015/05/docker_logo.png) ### XenServer emergency shutdown URL: https://xen-orchestra.com/blog/xenserver-emergency-shutdown/ Last updated: 2015-11-18T16:30:16.000Z Imagine you lost electrical power for your whole IT room. ![](https://xen-orchestra.com/blog/content/images/2015/11/In-the-Dark.jpg) Luckily, you got an UPS[\[1\]](#fn1), and that's great. But what if power doesn't come back before the batteries are depleted? You have a **limited amount of time to shutdown your XenServer hosts**, and you probably **don't want to lose your existing sessions probably stored in RAM**. That's for this scenario we created the *Emergency shutdown* feature in [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Femergency)! On the host view, clicking on this button will trigger the *Emergency shutdown* procedure: ![](https://xen-orchestra.com/blog/content/images/2015/11/emergency_button.png) 1. **All running VMs will be suspended** (think it's like "hibernate" on your laptop: the RAM will be stored in the storage repository). 2. Only after this, the host will be halted. Here, all the running VMs are being suspended: ![](https://xen-orchestra.com/blog/content/images/2015/11/suspending.png) And finally, that's it: ![](https://xen-orchestra.com/blog/content/images/2015/11/suspended.png) Now the host is being halted automatically. When the power outage is finished? 1. Start your host. 2. All your VM could be resumed, even your RAM will be preserved and in the exact same state before the power outage. --- --- 1. *uninterruptible power supply* [↩︎](#fnref1) ### XenServer quiesce snapshots URL: https://xen-orchestra.com/blog/xenserver-quiesce-snapshots/ Last updated: 2019-09-03T11:19:06.000Z Snapshots are a convenient way to rollback your system to a previous state, in other words to "point in time" a disk state. They are: - fast - small (delta) - exportable - [and can be scheduled with retention](https://xen-orchestra.com/blog/xen-orchestra-4-2/#schedulerollingsnapshots) in [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fquiesce) [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver?pk%5Fcampaign=blog%5Fquiesce) use your underlying storage repository capability. If you want to understand more how they work internally, you can read this complete [Citrix documentation](https://support.citrix.com/article/CTX122978?ref=xen-orchestra.com). ![](https://xen-orchestra.com/blog/content/images/2015/11/snapcitrixdoc.png) But for Windows VMs in XenServer, using critical services like a MS SQL server or Exchange mail service, you'll need to **tell the VM itself to write everything on the disk before the snapshot occurs**. How to do that? See below :) ## Quiesce The mechanism is called "[quiesce](https://en.wikipedia.org/wiki/Quiesce?ref=xen-orchestra.com)": > To Quiesce is to pause or alter a device or application to achieve a consistent state, usually in preparation for a backup or other maintenance. In software applications that modify information stored on disk, this generally involves flushing any outstanding writes. ### Quiesce support in your VM To enable the quiesce support in your Windows VM, you'll have to: 1. Install the XenTools 2. Execute the batch file called "install­XenProvider.cmd" (which should be in `C:\Program Files\Citrix\XenTools`) ![](https://xen-orchestra.com/blog/content/images/2015/11/quieceinstall1.png) > You can see VSS Provider installed during the XenTools installation, but that's not the last step. ![](https://xen-orchestra.com/blog/content/images/2015/11/quiesceinstall2.png) > Execute "install-XenProvider" and that's it! ## Create quiesced snapshots In [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fquiesce), we added support of auto quiesced snapshots in the coming 4.10 (Nov 27). That's very easy, as usual click on the Snapshot icon: ![](https://xen-orchestra.com/blog/content/images/2015/11/snap1.png) Is your snapshot a quiesced one? Check your snapshot panel: ![](https://xen-orchestra.com/blog/content/images/2015/11/quiesce.png) > The small icon before the snapshot name indicated that's a quiesced snapshot! ![](https://xen-orchestra.com/blog/content/images/2015/11/quiescechover.png) > By hovering on the icon, you'll see the tooltip. Well done! Now, you can revert or export your snapshot, it will be in a coherent state. ### Xen Orchestra 4.9 URL: https://xen-orchestra.com/blog/xen-orchestra-4-9/ Last updated: 2017-05-03T16:27:11.000Z First release of November! You wanted more backup options? You got it! Please also consider to [check our new documentation](https://xen-orchestra.com/docs/?ref=xen-orchestra.com). #### Auto Disaster Recovery This feature is possible thanks to our [VM streaming implementation we built few days ago](https://xen-orchestra.com/blog/vm-streaming-export-in-xenserver/): ![](https://xen-orchestra.com/content/images/2015/10/newsolution.png) It works like that: - select a tag name - choose the VMs you want to copy to another host - choose the retention for automatic VM rotation - choose the schedule (every week etc.) - select the destination host/pool You're done :) In our current interface: ![](https://xen-orchestra.com/blog/content/images/2015/11/DRexample.png) > With the "production" DR tag, we'll stream 3 VMs (XOA Free, Starter and Enterprise) to our pool named *lab3*, with a retention (depth) of 3\. All of this, every hour. Now, all your selected VMs will be copied (**running or not!**) to this pool/host, even with a dedicated tag indicating that's a DR VM. If you main site is destroyed, you can: - rename the VM (it will prevent any rotation/removal on it) - start it **That's it. Congrats, your VM is booting and running fine.** So: - no script to build/maintain - no more import time on a host after a catastrophic event: the VM is ready to start! Here is a example of a retention of 3, for 3 different VMs (`miniVM`, `miniVM 2` and `miniVM 3`): ![](https://xen-orchestra.com/blog/content/images/2015/11/DRresult.png) Your DR'ed VMs will have the following name: ``` _DR__ ``` Your VM will have the corresponding tag name in XAPI: ![](https://xen-orchestra.com/blog/content/images/2015/11/vmproperyDR.png) Thanks to this tag name, you could filter to display only DR'ed VMs: ![](https://xen-orchestra.com/blog/content/images/2015/11/disasterfilter.png) You want more again? E.g, stream a VM to multiple hosts? If you have a multi-site installation? That would be possible very soon, and by doing it smartly: only export once on the "origin" host, then stream it to all destinations at once. Okay but what about copying the VMs on this DR host to a brand new production host? Read the following paragraph! #### Manual VM copy You can now copy a VM to any SR (even on another pool!), without making a manual export then import. That's the other consequence of the VM streaming process :) This copy works for both halter or running VMs. > Copy is not Xen Storage motion: we do not **move** the VM. Here is in the VM view: ![](https://xen-orchestra.com/blog/content/images/2015/11/vmcopy.png) And the result in the destination: ![](https://xen-orchestra.com/blog/content/images/2015/11/vmcopyresult.png) #### Backup overview This view recap now all your scheduled backup jobs + the logs (see below): ![](https://xen-orchestra.com/blog/content/images/2015/11/backupoverview.png) #### Backup logs You have a now a complete report on your scheduled backup. Now, you can know, for each scheduled operation: - when did it starts and ends - the duration - details on each VMs backup process - status (success or failure) ![](https://xen-orchestra.com/blog/content/images/2015/11/backuplogs.png) #### Restore backups You can now display all your previous backups, and restore any of them to the host of your choice. They are sorted by "Store" (where you choose to export your XVAs): ![](https://xen-orchestra.com/blog/content/images/2015/11/restore.png) This will automatically import the XVA to your selected host. #### Manage remote stores It's now easier to manage your remote stores, in a directly accessible view thanks to the backup side menu: ![](https://xen-orchestra.com/blog/content/images/2015/11/newmenu.png) ![](https://xen-orchestra.com/blog/content/images/2015/11/remotestores.png) #### Disable backup compression By default, all scheduled backups are using compression. It saves space (and bandwidth if your NFS server is not on a fast link), but it could be long due to CPU needed to compress. By adding this option, you could now make your backups without compression and accelerate the process. Take a look on our previous blog post talking about the choice [to compress or not your XenServer backups and exports](https://xen-orchestra.com/blog/blog/xenserver-backup-compress-or-not-compress/). You can see how compression can affect your backup speed: [![](https://xen-orchestra.com/blog/content/images/2015/11/export_recap.png)](https://xen-orchestra.com/blog/blog/xenserver-backup-compress-or-not-compress/) ### Our new documentation We also just released a new documentation! Take the time to read it if you have any question of Xen Orchestra :) [https://xen-orchestra.com/docs/](https://xen-orchestra.com/docs/?ref=xen-orchestra.com) ### XO 5.x on tracks [Read more about it](https://xen-orchestra.com/blog/announcing-xen-orchestra-5-x/). [![](https://xen-orchestra.com/blog/content/images/2015/11/5x_small.jpg)](https://xen-orchestra.com/blog/announcing-xen-orchestra-5-x/) ### Next step Thanks to the huge work done in logs, we'll implement reports by emails when backup is done with some stats, alert thresholds etc. Stay tuned! ### Xen Orchestra documentation URL: https://xen-orchestra.com/blog/xen-orchestra-documentation-2/ Last updated: 2015-11-11T19:25:07.000Z Our new complete documentation is now available here: [https://xen-orchestra.com/docs/](https://xen-orchestra.com/docs/?ref=xen-orchestra.com) Feel free to comment if we missed something! Roughly, it's more than 70 pages exported in a PDF. ![](https://github.com/vatesfr/xo/raw/master/doc/architecture/assets/with-xo.jpg) ### XenServer backup: compress or not compress? URL: https://xen-orchestra.com/blog/xenserver-backup-compress-or-not-compress/ Last updated: 2015-11-06T14:24:30.000Z When you export a VM (eg for backup purpose) in XenServer, you can use (or not) the built-in compression of the XAPI. In the coming 4.9 version of Xen Orchestra, you can select "Disable compression" for your XenServer scheduled backups: ![](https://xen-orchestra.com/blog/content/images/2015/11/disablecompression.png) Let's try to compare a backup with and without compression activated, on the same VM. Without compression: - 25 MB/s throughput to the NFS share - time: 1m50 - 2.1 GB file With compression: - 8 MB/s speed to the NFS share - time: 2m13 - 0,5 GB file The graph recap the VM export (host stats): ![](https://xen-orchestra.com/blog/content/images/2015/11/export_recap.png) That's pretty clear, first test (w/o compression): - more bandwidth used - less CPUs - higher load average (waiting for the storage because of the high throughput) On the network graph, you could see the difference: the lighest line is the link toward the NFS (write speed). Without compression, the NFS write speed is the bottleneck. In details: ![](https://xen-orchestra.com/blog/content/images/2015/11/networkdetail.png) With the compression, the bottleneck is the compression speed of the XenServer host. Conclusion: **with our limited write speed on our NFS repo, compression is the best choice**: 30% longer, but only 25% of the uncompressed file size. If your storage can sustain much higher throughput, the answer could be really different. Do you a small backup storage and you have time to backup? Compress. If your NFS target is fast and support deduplication, **avoid compression** (dedup can't work on compressed XVAs). ### Announcing Xen Orchestra 5.x URL: https://xen-orchestra.com/blog/announcing-xen-orchestra-5-x/ Last updated: 2015-11-13T13:52:59.000Z Just after our initial [release of Xen Orchestra 4.8](https://xen-orchestra.com/blog/blog/xen-orchestra-4-8/), I'm proud to announce that we started to work for a new major release: **Xen Orcestra 5.0**, the web interface for XenServer. This first milestone of our new 5.x branch will be awesome, believe me! So why a new major version? **This future release will act the end of our complete web client rewrite, `xo-web`.** In the mean time, we'll continue to make new releases on the 4.x at the same pace. #### Years of feedback The choice of rewrite the web client is due to huge amount of feedback during years, from our users and even from our teams. We drew the current interface \~1 year ago, and since then, we added a great number of features, by "stacking" them in the web client. That's why some views started to became really busy! ![](https://xen-orchestra.com/assets/rrds.jpg) But that's not the only reason: we didn't even imagine that XOA would be **used on very large infrastructures (1500+ VMs!)**. In these conditions, it leads to: - Bad UX from this huge number of elements - Performances problems for this very high number of objects (but we already solved the server part, twice). Now, after the feedback of our users with all the various ways to use XOA, and our own utilization, we are able to see **what's really matter**. #### Making choices Few weeks ago, we started to write guidelines, to have a "common theme" for the whole web client. Few examples: max number of data per type of view, global behavior, things to avoid, performance in mind from the start, etc. This is the foundation of the next step: drawing mockups. And we are exactly here! The first view we worked on, is the **VM view**. The goal is to display quickly all the vital data to the user. So you have to make choices, by hiding less important data for example. Our first draft (far from be definitive) look like this: ![](https://xen-orchestra.com/blog/content/images/2015/10/VM_view_prop2.jpg) Want some details? Ok! ![](https://xen-orchestra.com/blog/content/images/2015/10/VM_view_prop2_legend.jpg) - Display less data at first sight, just keep the vital stuff... - ... but display a way to access everything! - Trends on performances are really important, even if they are just a rough summary: sparklines are ideal for that! By clicking on it, you'll go to the more details stats view - Value editing should be obvious: just by clicking on an item, you would be able to change the value (Name, CPU, RAM etc.) - Actions are very important and should be accessible anytime So, if you have any comments or suggestions, go ahead in the comment section :) #### Not only UI In parallel, we just started to make a "real" HTML/CSS mockup, and think on more technical issues. Remember, the goal is to release something without regressions toward the 4.x. On this aspect, our initial choice is to use Angular2, which is far better from legacy Angular. Despite it's not officially released, we'll have this new beast to make everything as a component: no code duplication, easy maintenance and performance tweaking, etc. ![](https://xen-orchestra.com/blog/content/images/2015/10/Angular-2-0.png) #### When? When it's done © ;) But be sure we'll do our max to release the best possible web interface for XenServer at our current pace, which is just... fast! #### Until then This new 5.x thing won't stop us to release exclusive features. Check [our last blog post](https://xen-orchestra.com/blog/blog/vm-streaming-export-in-xenserver/) about a new surprise coming the the 4.9 :) ### VM streaming export in XenServer URL: https://xen-orchestra.com/blog/vm-streaming-export-in-xenserver/ Last updated: 2015-10-30T20:51:46.000Z Have you ever wanted to copy a VM to another pool or host? So far, you have to do this: 1. export the VM somewhere (on a storage large enough to handle the whole VM size) 2. import the VM on a new host ![Picture of the old solution](https://xen-orchestra.com/blog/content/images/2015/10/oldsolution.png) And not only this, you need to do it for a halted VM. Or manually make a snapshot of the running VM and then export the VM. Or make a script. Is it possible to do otherwise? You have *Xen Storage Motion*, which is great and allow to **move** a **running** VM from a host to another, even without shared storage. What about not moving but **making a copy**? And what about **halted VMs**? And all of this **without using a large storage** to export then import it after? And also, by scheduling this for opening a nice **Disaster Recovery** possibility. Oh and with a retention rotating the older copies. With a coffee please. Is it possible? In fact, it wasn't. Dundee will offer new possibilities on this topic\[^n\], but on your existing XenServer hosts, you can't do that. ![](https://xen-orchestra.com/blog/content/images/2015/10/ironman.png) > Xen Orchestra to the rescue! #### Our solution Let's recap what you want: - create a copy of your VM (running or halted) on another server - no intermediate file creation on a shared storage - schedule this during the night for example - no complicated configuration, should be fully automated - have a retention of this copied VM (keep only the 3 latest copies for example) - compatible with all XenServer 6.x versions Remember what we have accomplished with [our streaming patching system](https://xen-orchestra.com/blog/xenserver-patches-the-easy-way/)? We started to experiment "exporting on one side" and "importing on the other" **at the same time**, by plugging export output to the import input. Guess what? It works :D And this is like that now: ![Picture of the new solution](https://xen-orchestra.com/blog/content/images/2015/10/newsolution.png) That's the first step to a better Disaster Recovery solution. A next article will explain this in details. And it will be out for the 4.9! --- \[^n\]: Xen Storage Motion of halted VMs would be possible, but it's moving a VM, not a copy! ### Bug hunt with Citrix URL: https://xen-orchestra.com/blog/bug-hunt-with-citrix/ Last updated: 2015-10-30T12:14:24.000Z This is the (short) story of how we discovered a bug using Xen Orchestra and [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver), then how it was fixed very quickly by Citrix team. ![](https://xen-orchestra.com/blog/content/images/2015/10/bughunt.jpg) > This is me telling calmly but firmly that we found a noticeable bug. ### Symptoms In short: **losing consoles in HVM guests**. HVM guests are using QEMU for a lot of things. One of this thing is QEMU-VNC, which allows to expose a VNC console of the virtual machine. In a lot of cases, it works perfectly. You can start a Windows VM, even install one. Or display a running Linux HVM. But when you try to install a brand new Linux in HVM, the console just vanishes after the initial menu (you know, where you can change the language or choose between Install or Live etc.) And you can't display it back, unless you reboot the guest, so you'll hit the same issue again. And again. Also, crashing QEMU things on a guest is not very a good news. ![](https://xen-orchestra.com/blog/content/images/2015/10/Terminal-icon.png) #### Consoles are tricky Our initial reaction was: "consoles issues, again, meh", but we decided to dig in order to find the issue. By using more debugging, we found that the console was closed on [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver) side. And you know what? We can't reproduce the problem on XenCenter. Is it our "fault" or not? Thanks to one of our user, we got more details on a [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver) host during this bug: ``` kernel: [718079.110218] qemu-dm[29404]: segfault at 1591000 ip 00000000004a309b sp 00007fff47ec4880 error 6 in qemu-dm[400000+122000] ``` > Figure 1: ouch. So, we (XO) are triggering a QEMU segfault by doing some VNC stuff on a VM. We quickly [reported the issue on the XenServer bug tracker](https://bugs.xenserver.org/browse/XSO-381?ref=xen-orchestra.com). #### Citrix quick answer Thanks to our contacts at Citrix, the issue was very quickly raised to their dev team: by using XO on their side, they could reproduce the problem (and not only with XO, but any other VNC client like tightVNC and Vinagre). It seems that when the VNC window size is changing for a very small size (even for few seconds), it just kills the QEMU VNC process. Guess when this is happening? Just in a lot of Linux installers. The fix itself was done very fast, and the result was incorporated [in this hotfix](https://support.citrix.com/article/CTX202404?ref=xen-orchestra.com). Why this is not happening in XenCenter? In fact, it's possible that their VNC implementation never asks for a partial frame update. Which is the thing will cause the crash. ### Conclusion Thanks to our usage of Xen Orchestra, combined to our mutual work with XenServer Citrix teams (and their very fast reaction), we helped to fix a QEMU issue, which is now backported in the following XenServer versions: - Citrix XenServer 6.5 SP1 - Citrix XenServer 6.5 - Citrix XenServer 6.2 SP1 - Citrix XenServer 6.1 - Citrix XenServer 6.0.2 - Citrix XenServer 6.0.2 - Citrix XenServer 6.0 Not bad isn't it? **Working closer with Citrix helped to improve both XenServer and Xen Orchestra. User experience is now better by using this great stack!** A big thanks for their quick reaction :) ![](https://xen-orchestra.com/blog/content/images/2015/08/xo-web.png) ### Xen Orchestra 4.8 URL: https://xen-orchestra.com/blog/xen-orchestra-4-8/ Last updated: 2015-10-29T12:09:48.000Z Second release of the month is now available with nice and various improvements. In short, we got a fully automatic patch system, a huge performance boost on statistics, ACLs with inheritance, a protection again brute force login and a lot of smaller improvements. And also bugs fixes (we closed 28 issues)! ![](https://xen-orchestra.com/blog/content/images/2015/10/xo-icons.png) #### Fully automated patching You just installed a brand new XenServer, and you see this: ![](https://xen-orchestra.com/blog/content/images/2015/10/no_patches_small.png) > This is a lot of patches to install... To avoid a click frenzy and waiting for each patch to be downloaded and applied, we added this: ![](https://xen-orchestra.com/blog/content/images/2015/10/patch_all.png) Seems trivial, but it's not: some patches conflicts with others (e.g: pre-SP1 patches), and some others have dependencies (e.g: post-SP1 patches). In order to do that properly, we made a lot of tests to find the best solution possible. Anyway, **you don't have to think anymore**: just click, and it will install all patches in the right order. Without asking you anything. You could also monitor thanks to the pending task indicating which patch is currently being transferred: ![](https://xen-orchestra.com/blog/content/images/2015/10/taskpatch.png) #### ACLs inheritance Up until now you had to give access to users to each individual objects. For instance, if a user should be able to view a pool, you had to also give it access to every contained VMs, which could be cumbersome and even worse, you had to create new ACLs for each new VM. Xen Orchestra 4.8 introduces ACLs inheritance: an ACL on a pool automatically gives access to everything inside, hosts, SRs and VMs. Similarly, giving access to a host, also grants access to all contained VMs. #### Huge leap in stats performances Remember, XML parsing is very CPU intensive. Solution? Remove it! Read more in our previous blog post about increasing performances on statistics fetching. ![](https://xen-orchestra.com/blog/content/images/2015/10/fetchtimems.png) We also made some cache to permit a nice scalability in terms of concurrent users asking for stats. #### Brute-force protection Previously, an attacker could attempt to brute-force an user's password, that is to say trying very quickly a lot of passwords until one allows it to sign in. The efficiency of this kind of attacks is directly related to the rate at which the password candidates can be tried, that's why this new release of Xen Orchestra introduces a throttling mechanism which prevents more that one attempt every 2 seconds for a given user. #### New icons for various Linux distros You can know differentiate easily your various Unix/Linux distros in the main view: ![](https://xen-orchestra.com/blog/content/images/2015/10/xo-icons.png) > Here, you got a Debian, a FreeBSD, an Ubuntu and a Windows VM. #### Network install for HVM templates The title of this section speaks for itself: ![](https://xen-orchestra.com/blog/content/images/2015/10/pxe.png) ### Next step: backup! We have a lot to do with the backup, and frankly, it's pretty exciting! - Reports and alerts on the scheduled backup process - More automated DR process - Recover a backup directly from the web interface This will be out for the 4.9 :) Stay tuned! ### How about 130x faster stats? URL: https://xen-orchestra.com/blog/how-about-130x-faster-stats/ Last updated: 2015-10-27T15:16:07.000Z A great news for those using our live stats and even our datavisualizations! We managed to provide a huge boost in performance when we fetch XenServer statistics (RRDs). ![](https://xen-orchestra.com/blog/content/images/2015/10/livestats.png) #### Until now That's not the first time we made a [tremendous leap](https://xen-orchestra.com/blog/blog/improving-xen-orchestra-performances/) in terms of performances. This time, it's also something very annoying: fetching the metrics from a host or a VM, every 5 seconds. Basically, we done this before: 1. on a host/VM view, refresh the latest stats **every 5 seconds** 2. each request on a client (`xo-web`) will trigger a request on `xo-server` 3. and it will fetch the last 120 data points (i.e last 10 minutes) 4. XenServer returns a huge XML that we have to parse (remember, every 5 seconds) 5. we send a JSON with all the values to `xo-web` And yes, this was **very** CPU intensive. Guess why? Hint: XML. Again. #### Solutions We worked on two aspects: removing CPU intensive operations and provide a cache. ##### XML: usual suspect ![](https://xen-orchestra.com/blog/content/images/2015/06/xml.jpg) Exactly as our previous performance issue, **we solved the problem by removing XML out of the equation**. Some figures maybe? On a **small host** (meaning only 4 CPUs), we spent **\~1300ms** waiting for XML parsing. Every 5 seconds. Imagine on a host with a LOT of CPUs: you have to parse a bigger XML, because more CPUs is more entries to parse. We managed to find a way to avoid XML, and we discovered that by reading the source code of XenCenter. There is some issues related to that (some metrics are not accessible as we wanted), but we found some workarounds at the end in order to get everything. **In short: it wasn't trivial but we made it.** What about the same request now? How much time we have to block the event loop for getting stats? Answer: **0ms**. Okay, great, but how about the total execution time for the same function? It's now **under 10ms** (compared to **\~1300ms** before), and again, without blocking the event loop. ![](https://xen-orchestra.com/blog/content/images/2015/10/fetchtimems.png) ##### Cache By rewriting the whole statistics stuff (thanks to [Ronan](https://github.com/Wescoeur?ref=xen-orchestra.com)), we also worked on an intelligent cache system. Mainly, that's two things: - If you have multiple clients fetching stats on the same VM (or host), we'll use the result of the first client request to give data to the other. Thus, you can't have more than 1 request every 5 seconds (minimal granularity). - You'll only request the data you need. E.g the last 5 seconds and not the 119 previous points if you already got them. ![](https://xen-orchestra.com/blog/content/images/2015/10/F14low-1.jpg) > Yeah, stats are going faster now. #### Conclusion - almost no CPU usage on `xo-server` (thus on XOA) during stats fetching - graphs are loaded almost instantly (when you visit a VM or a host view) - dataviz on RRDs metrics are also 10 to 100 times faster to display - far better scalability for XOA clients connected at the same time This will be available in 4.8, which will be out very soon! ### Xen Orchestra 4.7 URL: https://xen-orchestra.com/blog/xen-orchestra-4-7/ Last updated: 2015-10-12T19:26:11.000Z Right on time to deliver a better experience to the web interface of XenServer :) Despite new lads joined the team less then 10 days ago, we managed to make a reasonable release. They already contributed to some code in this 4.7! Usual stuff, the [complete changelog is here](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#470-2015-10-12). So what's new in this 4.7? At least, the possibility to add an existing XenServer host in a pool, but the biggest change is that the **plugin configuration is now possible right in the web interface** \\o/ No more complicated YAML indentation for huge plugins (e.g: LDAP). Furthermore, we integrated **browser notifications**: very useful for long async tasks, like migrate or VDI migration in your XenServer infrastructure. We also made some UI enhancement (**a new dataviz too!**) and bug fixes. #### Plugin configuration in the web interface It speaks for itself: good bye the complicated YAML structure to configure all your plugins. Now, you just have to put the plugin name in the config file, all its configuration will be done in the web interface: ![](https://xen-orchestra.com/blog/content/images/2015/10/configweb.png) You can enable/disable a plugin, change its config or also make tests very easily. You have a previous configuration? No worries! It will be automatically fetched and you'll retrieve everything in the web interface. Finally, in the configuration file, the only thing left for plugins is this: ``` plugins: auth-ldap: auth-github: ``` Nothing more! #### Browser notifications When you start a task, e.g a live migration or a VDI migration, it could take a lot of time. Maybe you want to focus on something else after starting the task? Now, as soon you'll leave the focus on your XO tab, you'll receive a notification when it's done (or failed) :) ![](https://xen-orchestra.com/blog/content/images/2015/10/notifs.png) > Just allow notifications for XO in your browser to enjoy it :) #### Graph selector This small improvement helps to find the dataviz you wanted: ![](https://xen-orchestra.com/blog/content/images/2015/10/datavizselector.png) #### Circle packing It's an alternative to the [sunburst visualization](https://xen-orchestra.com/blog/vdi-disk-usage-overview/) used to track your VDIs or RAM usage. The concept is similar and allow a simple way to detect problems or strange proportions in your infrastructure. Plus this chart is zoomable! ![circle packing example](https://xen-orchestra.com/blog/content/images/2015/10/circle1.png) ![circle packing example 2](https://xen-orchestra.com/blog/content/images/2015/10/circle2.png) #### Add host to a pool Behind this name is the possibility to add a host to an existing pool. Yes, so far we got only the possibility to evacuate a host from a pool, but not to make the opposite operation. How to do it? Just go on your host, and click on right button in the action bar: ![merge pool](https://xen-orchestra.com/blog/content/images/2015/10/merge.png) #### Better user creation UI Maybe it's not a big change, but it really helps when you are creating users in Xen Orchestra. Here is two things: ##### Password check on user creation Because you type the password once, you maybe have the need to check if it's correctly typed. You need to let the button clicked to reveal the password (release it will hide it again): ![password reveal](https://xen-orchestra.com/blog/content/images/2015/10/reveal.png) ##### Password generation On the same topic, generate a password is also a good way to avoid thinking of what you'll choose. Just click on the "key" icon and you're done! You can also reveal it: ![generate password](https://xen-orchestra.com/blog/content/images/2015/10/revealgenerated.png) #### Session persistence You can now check (or uncheck) a "Remember me" box. By not checking it, if you close your browser, next time you start it you won't be connected to Xen Orchestra. ![](https://xen-orchestra.com/blog/content/images/2015/10/rememberme.png) #### Bug fixes - Export options inconsistency fixed - Proper host pool removal - Sub-optimal tooltip placement fixed - Alone host can't leave its pools (remove button) - VM migrate host incorrect target ### Download 1. Already a XOA user? Just use the updater for a smooth experience, and start to use 4.7 right now! Don't forget to refresh your browser after the update. 2. Or download it in [your member zone](https://xen-orchestra.com/?ref=xen-orchestra.com#!/member) and make the update :) ## What's next Ramp up with our new team, allowing more surprises in the next release ;) Stay tuned for new features coming for the web interface for XenServer! ### Xen Orchestra 4.6 URL: https://xen-orchestra.com/blog/xen-orchestra-4-6/ Last updated: 2015-10-07T13:31:47.000Z As promised, here it comes XO 4.6! The [complete changelog is here](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#460-2015-09-25). Mainly, this release is the result of a major bug hunt plus two new cool features. #### Tags management You can now use [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver) tags and that's totally compatible with XenCenter (you will keep all your existing tags and continue to use them with both XO and XC). Now, a real example: imagine you want to add a tag on a SR to find it easily after, thanks to our search bar. That's very simple! See: ![tags example](https://xen-orchestra.com/blog/content/images/2015/09/tags1.png) ![tags example 2](https://xen-orchestra.com/blog/content/images/2015/09/tags2.png) This will be improved for gathering resources together in folders for the next interface redesign. #### Event correlation Here is the new datavisualization for your infrastructure! This time, it's about how to detect event correlation on multiple hosts or VMs. In few words, it helps to display/compare similar metrics between hosts or VMs. It's very helpful to detect or diagnose problematic events. **[Read how it will help you in our blog post](https://xen-orchestra.com/blog/blog/correlations-on-your-infrastructure/)**. It's better with an example: ![correlate events](https://xen-orchestra.com/blog/content/images/2015/09/correlate_small.jpg) #### UI of ACLs improved You can now modify a user/group ACL on the fly: ![improved acls UI](https://xen-orchestra.com/blog/content/images/2015/09/aclsimproved.png) #### User password change A user created internally (ie: not with a external authentication provided) can change his password, just by clicking on his username on the top right of the screen. ![password change](https://xen-orchestra.com/blog/content/images/2015/09/pwchange.png) #### Google account as external auth provider You developers/clients/whatever can now authenticate through their Google account. The configuration is pretty self explanatory (well, if you know Google configuration for SSO): ``` plugins: auth-google: clientID: xxxxx.apps.googleusercontent.com clientSecret: -HTDb8I4jXiLRMaRL15qCffQ callbackURL: 'http://xo.company.net/signin/google/callback' ``` ![Google Auth for Xen Orchestra](https://github.com/vatesfr/xo-server-auth-google/raw/master/add-oauth2-credentials-2.png) #### Better consoles A Console is now automatically restarted even if the connection is ended on XenServer side: it means the console will be displayed again after a reboot. #### PV Args modification Now, if you want to modify the PV args, you could do it during the VM creation process: ![pv args modification](https://xen-orchestra.com/blog/content/images/2015/09/pvargs1.png) You can check them even after the VM is created in the VM view: ![pv args done](https://xen-orchestra.com/blog/content/images/2015/09/pvargs2.png) They are also editable anytime after the VM is created. #### Name of the VM in the exported file When you export a VM through the web UI, you got a "export.xva" file previously. Not very handy to remember which one your downloaded, or you needed to rename it after the download. That's why this simple fix allows to export a XVA file with the name of the VM, e.g "webserver1.xva". #### VDI search filter When you are in a SR view, you can see a lot of VDI displayed. How to find something I want? Now with the filter, it's far easier: ![VDI filter in SR view](https://xen-orchestra.com/blog/content/images/2015/09/vdifilter.png) It (live) filters on the VDI name, description and attached VM name. #### Node 4.1 under the hood XOA 4.6 is now running with [Node 4.1](https://nodejs.org/en/blog/release/v4.1.0?ref=xen-orchestra.com)! Also, it appears to fix some memory leaks. ![node](https://xen-orchestra.com/blog/content/images/2015/09/node.png) #### Bug fixes - Login error is now more explicit - Update view is no longer broken by new downloads - Dashboard menu is now fixed - XenStorage motion now works in the same pool - ... and more! ### Download 1. Already a XOA user? Just use the updater for a smooth experience, and start to use 4.6 right now! Don't forget to refresh your browser after the update. 2. Or download it in [your member zone](https://xen-orchestra.com/?ref=xen-orchestra.com#!/member) and make the update :) ## What's next 4.7 will be release in another 15 days. But we'll just have at least 2 new guys working with us: they will need a little bit of time to discover XO before fixing issues and creating new features ;) ### Correlations on your infrastructure URL: https://xen-orchestra.com/blog/correlations-on-your-infrastructure/ Last updated: 2015-09-29T15:47:51.000Z ## Correlations > (Noun) > > A reciprocal, parallel or complementary relationship between two or more comparable objects *[Wiktionary](https://en.wiktionary.org/wiki/correlation?ref=xen-orchestra.com)* What about that? Well, you'll see, correlations are a very important thing to help you every day. We'll show you how we leverage the [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver?pk%5Fcampaign=blog%5Fcorrelation) API to give you hints about what's happening in your virtualized infrastructure. TL;DR? Okay, just a quick preview: ![correlation small preview](https://xen-orchestra.com/blog/content/images/2015/09/correlate_small.jpg) ## On your infrastructure Let's explore what we already have and what we need. ### Existing solutions Having stats and metrics on your infrastructure is a very common thing in IT now. For example, Xen Orchestra already offers you instant statistics in a VM or a host view: ![instant statistics in XenServer and Xen Orchestra](https://xen-orchestra.com/blog/content/images/2015/09/stats_small-1.png) We also introduced the concept of heatmap to notice the differences or "hot spots" on the last 7 days: ![Xen Orchestra heatmaps](https://xen-orchestra.com/blog/content/images/2015/09/heat_small.png) ### A missing piece One thing is missing: **what about displaying the same metric for various hosts or VM?** You should be able exploit this possibility to correlate through the time any spike or remarkable value. But there is multiple challenges: 1. compare various VMs or hosts in a limited (but visible) space 2. the "two scales" problem: you'll understand it just below ## The solution? Let's tackle the first problem: limited vertical space. A classical line graph or area chart will be "flattened" when displayed in a small vertical space. > If you compress a 120-pixel tall area chart to 30 pixels, you lose 75% of the resolution and it becomes harder to see small changes Source: [https://square.github.io/cubism/](https://square.github.io/cubism/?ref=xen-orchestra.com) That's why the concept of [horizon charts](http://vis.berkeley.edu/papers/horizon/?ref=xen-orchestra.com) is really good: larger values are "overplotted" in successively darker colors. Example: ![](https://xen-orchestra.com/blog/content/images/2015/09/cubism.png) Okay, done! Next :) What about the "two scales" problem? When you compare multiple objects, you can also have some of them with far higher values than others, thus **hiding small correlations**. But also sometimes, we need a "synchronized" or consistent scale. How to choose between those? The answer is: **let the user make the choice!** ### In practice Let's display the network interface n°1 upload for 14x VMs used in production, with a "synchronized" scale (consistent): ![correlation consistent scale](https://xen-orchestra.com/blog/content/images/2015/09/corr0.png) Okay, we can note: - the second to last VM upload a lot more data than all others - it seems there is a small spike on all other VMs, just left of the red cursor/line - the "balance" icon is in blue, indicated a consistent scale between all VMs. **Let's deactivate the consistent scale on this very graph and see the result:** ![correlation without consistent scale](https://xen-orchestra.com/blog/content/images/2015/09/corr2.png) Do you notice it? This spike on **all VMs** is now visible because each VM has its own scale. For those wondering: it came from a Salt Stack `pkg.upgrade` command. And with hosts? Thanks to our data consolidation, we can have an average on all CPUs of your servers and compare them: ![](https://xen-orchestra.com/blog/content/images/2015/09/corrcpu.png) Yeah, "Centaurus" is working more than "Andromeda", that's obvious ;) ## Going beyond There is some room from improvement: - display more hosts/VM (reducing the height of objects depending of their number) - various time frames (not only week, but also day or month) ## When? This feature will be available... tomorrow in the next release of Xen Orchestra (4.6). Stay tuned! ### The future of XenServer: Dundee URL: https://xen-orchestra.com/blog/the-future-of-xenserver-dundee/ Last updated: 2015-09-23T12:11:40.000Z Citrix [just announced](http://xenserver.org/blog/entry/xenserver-dundee-beta-1-available.html?ref=xen-orchestra.com) the availability of XenServer Dundee Beta 1\. So we are moving toward to a release of this brand new [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver?pk%5Fcampaign=blog%5Fdundee). What does it mean in concrete terms? Let's explore it. ### XO compatibility It works flawlessly with [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fdundee), and more: it will be even better. Why better? - Better: less bugs in XAPI with JSON-RPC - Faster: [full JSON-RPC support](https://xen-orchestra.com/blog/improving-xen-orchestra-performances/) - Stronger: XAPI isolation via control groups (cgroups) ![Xen Orchestra console with XenServer Dundee](https://xen-orchestra.com/blog/content/images/2015/09/xenserver_dundee.png) > Xen Orchestra connected to a Dundee host, with the host console. Another good news? Maybe [Storage Repositories (SR) metrics via RRDs](http://xapi-project.github.io/rrdd/futures/sr-level-rrds.html?ref=xen-orchestra.com) (I didn't verify it for the Beta 1, I'll keep you posted!) ### Super easy installation I experienced some difficulties with previous versions for install XenServer from an USB drive. Guess what? ``` dd if=XenServer-6.6.90-install-cd.iso of=/dev/sdd ``` And you're done! This is really great. ### Under the hood XenServer Dundee Beta 1 come with: - CentOS 7 for the Dom0 - Better Dom0 disk usage - UEFI boot support - CGroups - NFSv4 and FCoE support for SR - UEFI Support - **Xen 4.6** Xen 4.6? Hell yeah! What about [PVH guest support](http://wiki.xenproject.org/wiki/Linux%5FPVH?ref=xen-orchestra.com)? I don't know for now, but be sure I'll dig on this topic. Is it enough mature to be in XenServer? We'll see. > **Update**: no stable guest PVH in Xen 4.6, so maybe next time ;) ### Real tests From the original article of xenserver.org: > \[thanks to cgroups\] VM start operations no longer block as before resulting in VM start times being much more equitable. This same optimization can be seen in other VM operations such as when large quantities of VMs are shutdown. Is it real? Let's try it! On my small test machine, with a slow **HDD** SR, I booted a lot of (26x) small Debian VMs: ![a lot of small Debian VMs on XenServer Dundee](https://xen-orchestra.com/blog/content/images/2015/09/lotsmallvmdundee.png) By the way, just check the start during the boot of all of them: ![XenServer Dundee stats](https://xen-orchestra.com/blog/content/images/2015/09/dundee_stats_1.png) Let's shutdown them at once! See the stats: ![XenServer Dundee stats 2](https://xen-orchestra.com/blog/content/images/2015/09/dunde_stats_2.png) - With XenServer 6.5 (Creedence): **72 seconds** - With XenServer Dundee: **37 seconds** So roughly, Dundee is **twice** as fast for "shutdown storm" as Creedence! For sure, I'll run more benchmarks as soon as I can, but really: **XenServer Dundee will be a great (the best?) release.** ### Xen Orchestra 4.5 URL: https://xen-orchestra.com/blog/xen-orchestra-4-5/ Last updated: 2015-10-07T13:31:55.000Z XO 4.5 is out, 2 weeks after 4.4: we're back to our high release rate! And it doesn't mean we made only few things. [Check the changelog](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#450-2015-09-11): it's not bad at all ;) #### Hide non-authorized controls This was a very popular request: if a user does NOT have the right to do an action (e.g: Remove the VM), we should hide this button in the interface. Despite that's seems trivial, it is not: because `xo-server` centralize all the permissions, `xo-web` can't guess if it's authorized before sending the request. Two solutions: - re-write the ACLs in the `xo-web` side: it will duplicate the rules and leads to bugs in the long run - write a lib centralizing the ACLs, accessible from both `xo-server` and `xo-web`. For this release, we choose to hide quickly what's really needed in the first place (in the VM view). But as soon the external ACLs lib is out, we'll switch to the better solution. It will be totally transparent on your side. Before, for a "Viewer" only, you can see everything, even if you don't have the right to really make the action (like "Stop"): ![before hide buttons](https://xen-orchestra.com/blog/content/images/2015/09/before.png) After, for the same user: ![before hide buttons](https://xen-orchestra.com/blog/content/images/2015/09/after.png) We also hide where the VM is running if the user hasn't any right on the host/pool. For sure, we'll make a UI review to have a nicer UI when we hide buttons (planned for the 4.6 in 15 days). #### ACLs on networks You can now authorize users to see networks to create VIFs in their VMs: ![](https://xen-orchestra.com/blog/content/images/2015/09/selectaclnetwork.png) Plus, if you don't give any permission on the network, a user can't view any of your network in its own VM: ![](https://xen-orchestra.com/blog/content/images/2015/09/Capture-d--cran-de-2015-09-07-16-56-48.png) #### Faster consoles We no longer use the `ws-proxy` piece of code existing in XenServer, but we are connecting directly to the console in RAW HTTP. Results: consoles are displayed faster: ![](https://xen-orchestra.com/blog/content/images/2015/09/consolefaster.png) You can read [this blog post](https://xen-orchestra.com/blog/blog/ghost/editor/127/) for more details. #### GitHub sign-on After a generic SSO SAML provider available [in 4.4](https://xen-orchestra.com/blog/blog/xen-orchestra-4-4/), it's time to allow people with a GitHub account to access Xen Orchestra. This is great for our admins delegating VMs to their developers (or a contractor), without creating a account somewhere else. ![GitHub icon](https://xen-orchestra.com/blog/content/images/2015/09/github-logo-text-horizontal.png) You just have to create an app in GitHub and provide the credentials given there. Then modify the configuration of `xo-server`: ``` plugins: auth-github: clientID: xxxxxxxxxxxxxxxx clientSecret: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx ``` #### Parallel coordinates graph This kind of graph is useful to discriminate what is the "main" type of VM in your infrastructure from your "special" VMs (i.e: VMs with a configuration very different from others). But also filter to find a specific set of VMs. Example: ![Parcords example](https://xen-orchestra.com/blog/content/images/2015/09/parcorhover.png) You can learn more about it in [a previous post](https://xen-orchestra.com/blog/blog/track-your-vms-properties/). #### Heatmap improvements You can use consolidated values for CPUs in your host or VM (note the "All CPUs" in the 2nd select field): ![heatmap CPU consolidated](https://xen-orchestra.com/blog/content/images/2015/09/heatconso.png) Or you can aggregate hosts or VMs for a better global view. You want to see all network upload for a specific set of VM? Piece of cake: ![heatmap multiple VMs](https://xen-orchestra.com/blog/content/images/2015/09/heatconsoweb.png) > Consolidated valued for 3 VMs In this video, consolidated heatmap for **all my hosts** in two clicks: Your browser does not support the video tag. Neat eh? #### VM scheduled exports only with meta data Want to export a VM without its disks? (only the configuration). It's now possible. Just select this checkbox: ![Checkbox metadata](https://xen-orchestra.com/blog/content/images/2015/09/metadata.png) ### Download 1. Already a XOA user? Just use the updater for a smooth experience, and start to use 4.5 right now! Don't forget to refresh your browser after the update. 2. Or download it in [your member zone](https://xen-orchestra.com/?ref=xen-orchestra.com#!/member) and make the update :) ## What's next The 4.6 milestone is almost established, with: - XO plugin configuration in the web interface (configure SSO, LDAP and other plugin directly in the web interface, avoiding the "YAML nightmare" effect) - XenServer tags management - Google as an external login provider - A page to change its own password (for non-SSO users) - Auto ACL hierarchy and better UI - A brand new (and very nice) new visualization :) - First draft of the VM creation self service (for beta tests only) All of this in the next 15 days! ### Track your VMs properties URL: https://xen-orchestra.com/blog/track-your-vms-properties/ Last updated: 2015-09-09T11:18:43.000Z Coming (very soon) in the next release, a new dataviz. This one is based on "**parallel coordinates**" graph. ## Para.. what? Despite this is not the chart you'll see everyday, it's pretty common though. The idea is to visualize various data with various dimensions at the same time. This [great blog post](https://eagereyes.org/techniques/parallel-coordinates?ref=xen-orchestra.com) explain the concept, and you can read the [Wikipedia page](https://en.wikipedia.org/wiki/Parallel%5Fcoordinates?ref=xen-orchestra.com) if you want to know more. Here is a short but clear example: ![](http://eagereyes.org/media/2010/parcoords-80s.png) Each horizontal(-ish) line is a **car model**, with its own characteristics: - Miles per Gallon (same concept as "liters per 100km", no comment about the [US measurement system](http://kaero.wz.cz/jokes/imperial-vs-si.png?ref=xen-orchestra.com)) - Number of cylinders - Horsepower - Weight - Year of release Each vertical line is one of these characteristics. So you can **find very quickly in this set the model which is not common** and even **find one fitting your needs**. ## Applied to VMs Now, let's replace the cars with VMs. Each VM has its own characteristics: - a number of vCPUs - a RAM quantity - a number of network interfaces (VIFs) - a number of disks (VDIs) - total disk space used (by all VM's VDIs) With our small infrastructure you can see the result: ![](https://xen-orchestra.com/blog/content/images/2015/09/parcordok.png) First thing you can see, there is one VM with a lot of RAM (16G). Now, let's restrict some values in vertical axis like: - VMs with 2 vCPUs - and with 2GB of RAM - only with one VIF - VDI number and Total space doesn't matter The result is pretty interesting: it will display only those matching the previous characteristics: ![](https://xen-orchestra.com/blog/content/images/2015/09/parcorhover.png) By hovering on one, I can see its name (*windows hvm*) Want to see it in video? Go ahead: Your browser does not support the video tag. This first implementation will be probably improved from your feedback. Stay tuned for the 4.5 ;) ### Faster consoles in XO URL: https://xen-orchestra.com/blog/faster-consoles-in-xo/ Last updated: 2015-09-01T15:54:39.000Z Our previous console connection was done by using a component in [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver), named `wsproxy`. It was very simple to use, opposing to make a RAW HTTP connection. But the main drawbacks were: - slow to connect (\~2 seconds to display the console) - not supported by Citrix - prone to bugs when called often in a limited time (a lot of `wsproxy` processes still actives on the XenServer host). So we had to connect in RAW HTTP, and it works now! The result? Faster (almost instant) console display. In our lab: ![](https://xen-orchestra.com/blog/content/images/2015/09/consolefaster.png) - **\~1500ms** for displaying a console using the "old way" i.e `wsproxy` - **\~130ms** for the same result using RAW HTTP Conclusion: we managed to display consoles more than **10 times faster!** That's another step in [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver) improvement. This fix will be available for the 4.5 available in \~15 days. ![](https://xen-orchestra.com/blog/content/images/2015/09/console_faster.png) ### Xen Orchestra 4.4 URL: https://xen-orchestra.com/blog/xen-orchestra-4-4/ Last updated: 2015-08-28T17:35:18.000Z XO 4.4 is now available! The main features are the Single Sign On mechanism (SSO) and the first data visualization page. A dashboard view is also completing this release. #### SSO Single sign-on (SSO) is a property of access control of multiple related, but independent software systems ([Wikipedia](https://en.wikipedia.org/wiki/Single%5Fsign-on?ref=xen-orchestra.com)). We need some work to integrate [Passport](http://passportjs.org/?ref=xen-orchestra.com) in XO, but it's now fully operational! ![](https://xen-orchestra.com/blog/content/images/2015/08/sso_logo.png) In our case, Xen Orchestra was already compatible with LDAP (Active Directory or Open LDAP), but SSO opens new possibilities. Let's start with compatibles standards: - **SAML** is an XML-based, open-standard data format for exchanging authentication and authorization data between parties, in particular, between an identity provider and a service provider ([Wikipedia](https://en.wikipedia.org/wiki/Security%5FAssertion%5FMarkup%5FLanguage?ref=xen-orchestra.com)). That's the first strategy available for this release! - **OAuth2** protocol, which is compatible with many providers, like **Google** and thus opens the possibility to connect to XO with a Google account. - **OpenID** - **WebID** - and more! *Passport* also give you the opportunity to use pre-configured external providers for accessing the web interface of Xen Orchestra: - **Sharepoint** - **Atlassian Crowd** - **Windows Azure** (Windows Azure Store management portal) - **Drupal** (with OAuth Login module) - **Heroku Add-on** - **GitHub**: use a GitHub account to connect to your Xen Orchestra. Very useful for giving right to your dev team with existing GH account! - **BitBucket** - And [many many many more](https://github.com/jaredhanson/passport/wiki/Strategies?ref=xen-orchestra.com#providers)! For this 4.4, we implemented **SAML** in priority, but new providers are coming very fast (4.5 in \~15 days will implement many providers). #### Dashboard The dashboard view objective is to provide a recap for administrators. It answers those questions: - how many Pools/Hosts/VMs in total? - how much RAM is used right now? - how many vCPUs used by CPUs? - proportion of VM states? (running, halted, suspended?) - which SRs are the most full? You can now access it from there: ![](https://xen-orchestra.com/blog/content/images/2015/08/dashboard_menu.png) It shows this: ![](https://xen-orchestra.com/blog/content/images/2015/08/dashboard.png) #### Sunburst visualization for VDI and RAM usage We started to work on data visualization recently, to give more insight in your infrastructure. [This first post](https://xen-orchestra.com/blog/blog/dashboard-and-dataviz/) was an introduction, and [the next one](https://xen-orchestra.com/blog/blog/vdi-disk-usage-overview/) was more a real implementation. This first one implemented is the "Sunburst" recap for RAM usage: ![](https://xen-orchestra.com/blog/content/images/2015/07/sunburst-2.png) The other one is about VDI usage in your different SRs: ![](https://xen-orchestra.com/blog/content/images/2015/07/vdi_usage.png) As you can see here, that's the VDI called "tank" which is the biggest, with a 93.1GB of physical space used. This VDI is on a Shared SR called "iSCSI", in our "Lab Pool". By clicking on the SR, you go directly to the SR view. In video: Your browser does not support the video tag. #### Heatmap for infrastructure health It could be very useful to have an overview of a specific metric usage for a week (last 7 days from now). The best way to visualize relative usage in a certain amount of time is the heatmap. You probably already know the concept, here it some real examples from VM/hosts used in production: - Our **database server**. This is the heatmap for the sent packets from the main VIF (virtual interface) of the VM. Guess when we send database backups to a remote site? ![](https://xen-orchestra.com/blog/content/images/2015/08/db1.png) - This time, received packets for our **mail server**. It appears to be clear when we received most of our emails (nights are very calm): ![](https://xen-orchestra.com/blog/content/images/2015/08/mail1in.png) - How about **host load average**. Guess when I started new VMs on it? ![](https://xen-orchestra.com/blog/content/images/2015/08/loadavg.png) In a video: Your browser does not support the video tag. ## Premium in early access *Premium* version of XOA is now available through the [Early Access Program](https://xen-orchestra.com/?ref=xen-orchestra.com#!/early). We started to include the dataviz features in it. They'll continue to come each new release: every 15 days! And we'll start to work on a global scheduler (in order to plan any actions, e.g plan multiple VMs migration at 3AM on a smaller server, shutdown the big one etc.) If you have any question about it, feel free to [contact us](https://vates.fr/contact.html?ref=xen-orchestra.com). ### Partner registration We extended our website to offer a partner portal: you can now register if you [want to become a partner](https://xen-orchestra.com/?ref=xen-orchestra.com#!/partner)! ### Download 1. Already a XOA user? Just use the updater for a smooth experience, and start to use 4.4 right now! Don't forget to refresh your browser after the update. 2. Or download it in [your member zone](https://xen-orchestra.com/?ref=xen-orchestra.com#!/member) ## What's next There is various topics in the backlog, like: - more data viz (correlations, averages etc.) - a VM self service portal ([https://github.com/vatesfr/xo-web/issues/285](https://github.com/vatesfr/xo-web/issues/285?ref=xen-orchestra.com)) - a better Docker integration - expose the XO configuration in the web interface ### XenServer Challenge URL: https://xen-orchestra.com/blog/xenserver-challenge/ Last updated: 2015-08-26T18:04:15.000Z In July, we participated to an event: the *Cloud Summer Camp* at the [ETNA School](http://www.etna-alternance.net/?ref=xen-orchestra.com) (Paris). It's like a *Hackathon* for students. And the theme this year was [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver) and [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/). ![](https://xen-orchestra.com/blog/content/images/2015/08/UHXzdngc-1.jpeg) It was a perfect opportunity to give two challenges to 60 students: - one group working on a [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver) challenge - the other working on a new Xen Orchestra feature ![](https://xen-orchestra.com/blog/content/images/2015/08/group-1.JPG) > Citrix sent us a box of t-shirts for the event ## XenServer challenge Objective: create a "proof of concept" infrastructure in two weeks, with zero previous knowledge of [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver), and almost no help. All of this with "old"/refurbished hardware (HP stations with Core 2 Duo CPUs). The goal was to provide a real solution for deploying VMs, using a small NAS/SAN allowing live migrations between two hosts, having HA enabled to shutdown a physical server without any downtime. ![](https://xen-orchestra.com/blog/content/images/2015/08/hardware.jpg) > Old hardware came back to life! No license cost, no hardware cost. Just less than 2 weeks for 6 groups (up to 5 students). Not enough? All students were specialized in development, not system administration. So, will it be possible to finish the challenge in time? ![xenserver logo](https://xen-orchestra.com/blog/content/images/2015/08/Xen_Server_Logo_original.png) ### Results Each group had 30 minutes to make a demo and explain their choices. We were also interested by their feedback as [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver) and Xen Orchestra end users. ![](https://xen-orchestra.com/blog/content/images/2015/08/etna1-1.jpg) > One group presenting a demo of their infrastructure (with XenServer Dundee shirts!) **All groups were able to build the infrastructure, starting VMs, doing live migration and even shutdown a host without any service interruption**. They all use [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com) to demo the infrastructure possibilities (live migration with a drag and drop for example). #### Winners They were the group going further, and they also explored a way to use this infrastructure for a real need: install VMs with Jenkins, Docker and other useful tools for developers. By creating VMs with ACLs for specific users, they allow those developer to focus on what they need (a accessible VM running Jenkins for example). - Adrien Le Moigne - Florea George - Frank Wieser > "We explored new technologies we didn't know before, and we were able to use XenServer and Xen Orchestra very quickly without previous knowledge. It's very interesting to build something tangible with hardware and see it running our apps!" ##### Our special pick - Theo Battello - Wildine Anthony - Richard Cuvillier - Vanessa Lagardette This group made a fully working infrastructure, but they also estimate the cost for buying real hardware, as if the proof of concept was validated. They were able to understand the real challenge in a small/medium company: **run apps with flexibility with on-premise hardware, at a very reasonable cost.** ## Xen Orchestra challenge This pure developer challenge is also quite interesting: demonstrate the possibility to integrate [Passport library](http://passportjs.org/?ref=xen-orchestra.com) in Xen Orchestra. This will lead to a complete SSO integration, with connecting users thanks to: - a SAML account - OAuth2 account - Google, Twitter or Github account etc. ![xologo](https://xen-orchestra.com/blog/content/images/2015/08/xo-web.png) Some students already had a basic JS knowledge, some of them don't. The ability for students to adapt and work together for answering this challenge was something. Some of them gave "courses" on JS and GitHub workflow to others, they smartly dispatched the work etc. In the end, we got the proof that Passport could run in Xen Orchestra, with some various things to change. #### Winners - Alexandre Levy - Raphaël Karpinski - Sam Samimi By far, they won this challenge. They understand the global Xen Orchestra architecture, but they also successfully integrated Passport in XO, with the local strategy. ## Conclusion This challenge was successful for numerous reasons, and on both sides. About the students, they discovered a new technology and they had fun working on real hardware to understand -in a tangible way- how and where their apps will run. **In the cloud era, we somehow forgot that hardware is still necessary for the software revolution. And yes, it is possible to keep control on data, with great flexibility and without exploding costs.** For us, it validated the fact that even someone not used to **[XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver) \+ [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com)** can deploy a fully working infrastructure in a very short time. ### Security around Xen, XenServer and QEMU URL: https://xen-orchestra.com/blog/security-around-xen-xenserver-and-qemu/ Last updated: 2015-08-15T16:09:42.000Z You probably heard a lot of stories lately around security concerns from QEMU flaws [impacting Xen](http://xenbits.xen.org/xsa/?ref=xen-orchestra.com). Let's take the time to understand what is really going on. We'll see first what about *Xen project* and also [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver?pk%5Fcampaign=blog%5Fqemu). ### Xen guest types Because it always confuses people, I'll take the time to racap the list of possible guest (virtual machine) types, or **Modes** in Xen: - HVM - PV - PVHVM - PVH For a more complete reading, you can check my [blog post](https://xen-orchestra.com/blog/debian-pvhvm-vs-pv/), [this article on the Virtualization Spectrum](http://wiki.xen.org/wiki/Virtualization%5FSpectrum?ref=xen-orchestra.com) or [this page about Xen overview](http://wiki.xen.org/wiki/Xen%5FProject%5FSoftware%5FOverview?ref=xen-orchestra.com). ![](https://xen-orchestra.com/blog/content/images/2015/08/Xen_logo.png) Xen was originally built to run **PV** guests. In PV mode, your guest OS "knows" it's running on top of an hypervisor (the guest kernels is modified to use the right hypercalls). Sadly, this is not possible with every systems. So, it comes the need for **emulation**. And what tool to use for that? You get it: **QEMU**. ### QEMU QEMU (short for Quick Emulator) is a free and open-source hosted hypervisor that performs hardware virtualization ([Wikipedia](https://en.wikipedia.org/wiki/QEMU?ref=xen-orchestra.com)). ![](https://xen-orchestra.com/blog/content/images/2015/08/Qemu-logo.png) In the Xen **HVM** mode, **QEMU** is here to emulate disks, network, motherboard and PCI devices. And also the BIOS! But the Xen project is moving further to avoid emulation, mainly because it's costly (performances, especially for heavy I/O load, like disks and networks). That's where the **PVHVM** mode starts: a **HVM** VM running Linux, detecting Xen underneath, will "activate" the usage of **PV** interfaces, thus reducing the emulation need. > Using PVHVM could be [faster than purely PV](https://xen-orchestra.com/blog/blog/debian-pvhvm-vs-pv/), due to modern hardware capabilities (e.g hardware assisted pagetable virtualization) ### Impact So if you are using Xen in *HVM* or even *PVHVM* mode for your guests, it's possible to be affected by some *QEMU* flaws (not **all**, because only a small part of *QEMU* is needed for HVM modes). But keep in mind: **PV guests can't be affected**. Is *QEMU* that bad? Well, you can't blame them: they did an amazing job, and their software is also used in *KVM* for example. After the *[VENOM](https://xen-orchestra.com/blog/venom-vulnerability/)* flaws, it's totally normal to have more people digging into it: remember the *Heartbleed* story with *OpenSSL*? Same stuff here: don't blame a project your are using, support them! ### Mitagation There is 2 ways to mitigate the problem: 1. better community collaboration (closer to the upstream) 2. software "defense in depth" (sandbox) #### Working together So why *Xen project* doesn't split-up with *QEMU*? Because that's **not the right strategy**. The best answer is more collaboration between *QEMU* consumers and the upstream. That's exactly why there is more and more discussions and joint meetings between *KVM*, *Xen* and *QEMU* folks, from features to security. **Remember the power of Open Source, right?** *Xen project* is also [making progresses](https://blog.xenproject.org/2013/09/20/qemu-vs-qemu-traditional-update/?ref=xen-orchestra.com) to getting closer to the *QEMU* upstream, thus reducing the time to backport patches. > *KVM* is also prone to *QEMU* flaws #### Containing Containing, aka "[sandboxing](https://en.wikipedia.org/wiki/Sandbox%5F%28computer%5Fsecurity%29?ref=xen-orchestra.com)" is a way of "[defense in depth](https://en.wikipedia.org/wiki/Defense%5Fin%5Fdepth%5F%28computing%29?ref=xen-orchestra.com)". The idea is to run *QEMU* as a non-privileged user. This way, a flaw in *QEMU* won't have an dangerous impact on your system. This work already started, as you can [read here](http://lists.xen.org/archives/html/xen-devel/2015-07/msg04501.html?ref=xen-orchestra.com). ![](https://xen-orchestra.com/blog/content/images/2015/08/sandbox.jpg) ### In XenServer Because *[XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver?pk%5Fcampaign=blog%5Fqemu)* is a turnkey distro running Xen + XAPI and other patches, they also included *QEMU* running de-privileged. Despite that's a custom way to do it (at the OS level), it allows *XenServer* to be already resilient to that kind of flaws. ## Blessing in disguise After all, those flaws are a blessing in disguise. Because they helped to bring together *QEMU*, *Xen* and *KVM* to improve the software itself. But also for the *Xen project* directly, because *sandboxing* is a powerful solution to increase security. And finally, Xen already offers similar mechanism with [Dom0 disaggregation](http://wiki.xenproject.org/wiki/Dom0%5FDisaggregation?ref=xen-orchestra.com) and [stub domains](http://wiki.xen.org/wiki/Device%5FModel%5FStub%5FDomains?ref=xen-orchestra.com): ![](https://xen-orchestra.com/blog/content/images/2015/08/stub.jpg) ### VDI disk usage overview URL: https://xen-orchestra.com/blog/vdi-disk-usage-overview/ Last updated: 2015-07-27T15:39:22.000Z This is a follow up of my previous [article about data-visualization](https://xen-orchestra.com/blog/blog/dashboard-and-dataviz/) for Xen Orchestra. This time, we'll explore how we use a Sunburst visualization to quickly understand your [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver) storage infrastructure usage. ## Visualize the whole infrastructure The challenge is to be able to have a glimpse of the VDI usage for your entire storage infrastructure (all *Storage Repositories*, or *SR*). This is possible for all your connected XenServer pools at the same time! The hierarchy is: - The total SR disk capacity of the pool, compared to every other pools (first circle, proportional) - The host total disk capacity (or just SR if shared), compared to the pool (second circle) - The SR disk capacity, compared to the host (third circle) - The VDI used space, compared to the SR ### Example For example, I would like to find the biggest VDI on our test pool, called "Lab Pool", let's hover the sunburst: ![](https://xen-orchestra.com/blog/content/images/2015/07/vdi_usage.png) As you can see here, that's the VDI called "tank" which is the biggest, with a 93.1GB of physical space used. This VDI is on a Shared SR called "iSCSI", in our "Lab Pool". By clicking on the SR, you go directly to the SR view. Here the result in video: Your browser does not support the video tag. ### More As I said before, another cool way to do it is the Tree map, which looks like this: ![](https://xen-orchestra.com/content/images/2015/07/treemap.png) It allows to display labels directly on the graph. This will be probably also created in a near future. ### Dashboard and dataviz URL: https://xen-orchestra.com/blog/dashboard-and-dataviz/ Last updated: 2015-07-25T00:36:27.000Z Recently, we started to work on a new view for Xen Orchestra: a global dashboard for your whole [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver) infrastructure. Because of Xen Orchestra architecture, we can be connected to all your XenServer pools at the same time. But for displaying the data, there are some challenges, like: - be able to get quickly all the critical data in a few views - single out where the bottleneck is - highlight the most resource-intensive VMs - discover when your infrastructure is under heavy load - and more... > Screenshots in this blog post are work in progress! #### Dashboard The first (main) view of the dashboard gives: - the total numbers (pools, hosts, VMs) - the global RAM usage (on **every** pools) - the vCPUs used ratio on physical CPUs - proportion of VMs states (halter, running, paused...) - the storage list, by relative space occupied first (this way, you could see immediately the fullest disk) ![](https://xen-orchestra.com/blog/content/images/2015/07/global.png) #### Resource usage In a big infrastructure, you may want to find easily which VM uses the most resources, like you want to know which file taking all the space on your personal computer. We are using the [Sunburst](http://bl.ocks.org/kerryrodden/7090426?ref=xen-orchestra.com) tools from d3js library. By using the [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver) hierarchy, pools (if any) then hosts, and finally VMs, we can manage to build a very powerful representation of resource usage. Hovering the graph, you get details in the labels, here for "nfs" VM running on the host "lab1", on the pool "Lab Pool". You can see on the graph, the VM max (total) RAM: - "nfs" takes only a small portion of the "lab1" host - "lab1" represent the half of RAM available in the pool - the center indicates the RAM quantity in GB On the other hand, you can see clearly a VM using a huge amount of RAM (**in pink**)! And you can see it won't fit in "Lab Pool"! ![](https://xen-orchestra.com/blog/content/images/2015/07/sunburst-2.png) #### Just a start! For sure, that's just a start. We'll continue to dig into this. For example, sunbursts are cool, but we also have the Treemap possibility (here a example): ![](https://xen-orchestra.com/blog/content/images/2015/07/treemap.png) But let's go further: coupling those visualizations with XenServer metrics, we could imagine, for example, to make a weekly heatmap, showing **when your infrastructure is under heavy load** (by choosing the metric, e.g CPU or disks write): ![](https://xen-orchestra.com/blog/content/images/2015/07/calheatmap.png) This way, you can adapt your strategy. What else? Well, for stacked time series, steamgraphs are also nice. You can imagine to stack multiple VMs on the same metrics in this graph: ![](https://xen-orchestra.com/blog/content/images/2015/07/steam.png) Compacted time series are also possible thanks to the [Cubism lib](http://square.github.io/cubism/?ref=xen-orchestra.com): ![](https://xen-orchestra.com/blog/content/images/2015/07/cubism.png) You'll see quickly which one (**and when!**) eats your SAN by selecting the "disk writes" metrics for example. #### Final challenge How to display the maximum metrics on the whole infrastructure in one graph? We got some ideas, like the [force directed graph](http://bl.ocks.org/mbostock/4062045?ref=xen-orchestra.com) with various node in size/color, it could be very powerful: ![](https://xen-orchestra.com/blog/content/images/2015/07/force.png) #### When??? The first dashboard (+ sunburst) will be operational for the next 4.4 release this summer! If you have other ideas or suggestions, go ahead, the comment section is here for this ;) ### Xen Orchestra 4.3 URL: https://xen-orchestra.com/blog/xen-orchestra-4-3/ Last updated: 2015-07-22T18:36:17.000Z Welcome to the "Summer" release of XO, with a powerful backup feature for [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver)! **You can now schedule a full export of yours VMs to a NFS share (or local filesystem), directly from the web interface!** ![](https://xen-orchestra.com/blog/content/images/2015/07/backup-registry.jpg) #### Schedule full backup After our first step toward [XenServer backups](https://xen-orchestra.com/blog/xen-orchestra-4-2/), with scheduling rolling snapshots, here is a new one: full VM export, with a scheduler AND to a NFS share. That's a clear step toward Disaster Recovery. That's why we'll use the XVA format in the first place: it contains all the VM metadata (name, RAM, vCPUs, networks, disk configuration...) + all the VM data (disks). And by compressing by default, the file size will be at worst of the currently used disk space, not more (often less). And because we can export to a remote share (NFS), even if your complete infrastructure is destroyed, you can restore everything by a simple VM import! In order to achieve this goal, you need two things: - an export scheduler - a mount point manager Let's explore the possibilities with a "classical" scenario: you want to automatically export your critical VMs in a remote NFS share (in another site), every Sunday at 1:00 AM. All of this with a maximum of 4 backup files per VMs. You can do it in few clicks now, as you can see in this video: Your browser does not support the video tag. You'll have: - all the designated VMs fully exported every Sunday at 1:00 AM - with a maximum of 4 exports (the old one is removed automatically) - thus, a full backup for one month - everything stored on a distant NFS share This is perfect for a **disaster recovery** strategy: even if you lost your main site and all your XenServer hosts, no problem! You just have to import your XVA files in your brand new infrastructure and it works out of the box! (XVA files contain data AND metadata). For sure, you can imagine other scenarios: - schedule few exports for non-critical VMs, with a depth of 1 - schedule every night backups with 7 files depths for vital VMs - and so forth! #### Bug fixes We also take some time to fix subtle bugs, [read the change log](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#430-2015-07-22) for more details. #### Automated testing Since one month, we got an intern working on automated tests for `xo-server`. Thanks to [Mylène](https://www.linkedin.com/profile/view?id=407517110&ref=xen-orchestra.com), we are now covering a lot of features! For those who want to know, we are using [Mocha](http://mochajs.org/?ref=xen-orchestra.com) and [Must](https://github.com/moll/js-must?ref=xen-orchestra.com). ## Upgrade! Just use the embedded upgrade process in the XO interface. Nothing else to do :) Refresh your browser after the update, to be sure you got the last version. **WARNING**: for those willing to use remote NFS mounts for backup, please run this command in XOA as root: `apt-get install nfs-common`. Otherwise, you couldn't mount any NFS share. **NOTE**: all new XOA posted since this release (4.3) have the NFS package. ### Backup your XenServer VMs with Xen Orchestra URL: https://xen-orchestra.com/blog/backup-your-xenserver-vms-with-xen-orchestra/ Last updated: 2016-01-16T08:50:21.000Z > UPDATE: we are now supporting Delta Backup! (aka Incremental backup). **Check our blog post about using [incremental backup with XenServer](https://xen-orchestra.com/blog/xenserver-incremental-backup/)**. > UPDATE 2: now it's time for even better: **[continuous incremental backup!](https://xen-orchestra.com/blog/blog/continuous-delta-backup/)** Few days ago, we released the [4.2 version](https://xen-orchestra.com/blog/blog/xen-orchestra-4-2/) of Xen Orchestra, the web interface for [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver). One of the feature was the **Scheduler for rolling snapshots**. It means: - create a schedule (every nights at 4:00 AM, every week but not Sat/Sun etc.) - select the VMs you want to snapshot (one or multiples VMs, on various pools) - choose the snapshot depth (i.e: how many snapshot before deleting the old one: the rolling mechanism) But snapshots aren't "real" backup: if you lose your storage or your XenServer host, you lose everything. The goal was more to allow easy rollbacks, like a "time machine". Anyway, the next step was perfectly natural: **schedule full VMs exports!** **Let's build it!** ![](https://xen-orchestra.com/blog/content/images/2015/07/hackerman.png) ### Full VM exports Our first intention is to provide a way to export all the data needed to restore a VM from scratch, even on a brand new XenServer infrastructure. That's a clear step toward **Disaster Recovery**. That's why we'll use the XVA format in the first place: it contains all the VM metadata (name, RAM, vCPUs, networks, disk configuration...) + all the VM data (disks). And by compressing by default, the file size will be at worst of the currently used disk space, not more. And because we can export to a remote share (NFS), even if your complete infrastructure is destroyed, you can restore everything by a simple VM import! In order to achieve this goal, you need two things: - an export scheduler - a mount point manager #### Scheduling This was the trivial part: we are using the previous mechanism for snapshots. This view is accessible in the "Schedule" section: ![](https://xen-orchestra.com/blog/content/images/2015/07/menubackup.png) Example with a daily VM export (as seen in the screenshot below): ![](https://xen-orchestra.com/blog/content/images/2015/07/backupexample.png) - file export name will have the "daily" tag (easier to manage) - export only the VM named "Salt Master" (running on lab1) - XO will remove the oldest file if there is already 3 previous exports (rolling backup) - the exported file will be in `/var/lib/xoa/nfsmount` - the schedule will be created as soon as we clicked on "Save" (just under, not visible in this screenshot) - the schedule will start the export **every day at 04:00 AM** (with a preview of "when") #### Mount points Because fully exported VMs can be massive, we need to choose **where** we want to do it. And the next release of Xen Orchestra will have a mount point manager, allowing to mount directly within the **web interface**: - a local path on the file system (if you have enough space or you chose to mount an external drive or whatever you like) - a remote NFS share That's the first options available for the 4.3 when it's out, but we could add more possibilities later (SMB for example, SSHFS maybe?). Popular demand will drive this. Stay tuned for the new 4.3 release this month :) ### Xen Orchestra 4.2 URL: https://xen-orchestra.com/blog/xen-orchestra-4-2/ Last updated: 2015-06-29T09:00:53.000Z All ahead full! 2 releases per month is now our current pace, and it doesn't mean less features each release. As you will see, this one delivers some interesting new possibilities, combined with a huge performance boost. #### Schedule rolling snapshots The first step toward backups: you can now plan snapshots in a very natural way. Let's see this step by step. Imagine you want, for some reasons, to be able to revert a critical VM to it's previous state during the last hour, up to the last 4 hours. And only from Monday to Friday. Complicated? Not at all. You can do it in few clicks now, as you can see in this video: Your browser does not support the video tag. You'll have: - a snapshot every hour - with a maximum of 4 snapshots (the old one is removed automatically) This feature is very flexible, you can: - schedule a nightly snapshot for a group of VM, let's say at 4:30 in the morning. With a max snapshot at 7, you'll have a week of revert possibility - schedule a snapshot every week, but precisely Sunday at 11 PM, with 4 snapshots max. This will let you a month max of revert - and so forth! #### Huge performance boost You can read more in [our previous post](https://xen-orchestra.com/blog/blog/improving-xen-orchestra-performances/) about how we managed to boost Xen Orchestra up to 250 times faster in big infrastructures. On our small lab we already got a 4 times faster XO. See for yourself, lower is better, 4.1 vs 4.2: ![](https://xen-orchestra.com/blog/content/images/2015/06/perfs-1.png) And the other good news: it scales well! Bigger your infrastructure, better the boost! ![](https://xen-orchestra.com/blog/content/images/2015/06/perfs2.png) > In this kind of infrastructure, XO is now blazing fast! #### Compatibility with 5.x versions The new `event.from` system we are using is only working since XenServer 6.0\. But some people are yet using older versions! Thus, we created a fallback on `event.next`: it works now. ![](https://xen-orchestra.com/blog/content/images/2015/06/Xen_Server_Logo_original.png) #### New VM creation process We completely re-wrote the VM creation process: it's more maintainable and less prone to bugs. #### Bug fixes You can [check the change log](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#420-2015-06-29) for all the details. ## Upgrade! Just use the embedded upgrade process in the XO interface. Nothing else to do :) Refresh your browser after the update, to be sure you got the last version. ## Next? We made our first step with scheduling snapshots. The next step is clear: provide a scheduled full export of VMs, probably in a NFS share. Disaster recovery is probably the first thing you got in mind with that. ### Improving Xen Orchestra performances URL: https://xen-orchestra.com/blog/improving-xen-orchestra-performances/ Last updated: 2015-06-24T08:31:00.000Z This blog post is about how we made a leap ahead in performances for the next incoming release. It should be interesting for everyone, probably because this story will happened (or already happened) to you if you are developing software. And especially using an external API. Spoiler alert, here is a preview of our results, current stable 4.1 VS next release 4.2 (**lower is better**): ![](https://xen-orchestra.com/blog/content/images/2015/06/perfs-1.png) > - X axis: 3 pools where our tests are made > - Y axis: total time (in *ms*) to get all objects in a Pool > > Pool A is bigger than Pool B (more hosts/VMs), which is bigger than Pool C. But this is only a small fraction of the performance boost, because bigger is your infrastructure, higher is the impact! ## Find the bottleneck We are using the simple but extremely useful [blocked module](https://github.com/tj/node-blocked?ref=xen-orchestra.com) to detect when the Node event loop is blocked. You can spot the related logs called `xo:perf` in the following trace: ``` > node bin/xo-server app-conf /home/user/.config/xo-server/config.yaml xo:main Configuration loaded. xo:main Web server listening on http://0.0.0.0:9000 xo:main Setting up / → ../xo-web/dist xen-api root@192.168.1.1: session.login_with_password(...) xen-api root@192.168.1.1: connected xen-api root@192.168.1.1: event.from(...) xo:perf blocked for 3419ms xo:perf blocked for 2768ms xo:perf blocked for 9824ms ``` ### XML parsing is costly Thanks to this logs, we were able to see that the performance issues were related the reception of XAPI ([XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver) [API](http://wiki.xenproject.org/wiki/XAPI?ref=xen-orchestra.com)) messages. After some more analysis, we could tell it was due to the XML parsing of this messages. To understand why we are decoding XML, let's review our current architecture: ![](https://xen-orchestra.com/assets/xoarch.png) [XML-RPC](https://en.wikipedia.org/?title=XML-RPC&ref=xen-orchestra.com) is currently the way to talk to the XAPI. When you are connected to one pool, you got XML content to decode to get all objects in it. That's OK, until you are connected to a **TON** of other pools: Xen Orchestra have to parse a LOT of XML. And parsing XML is very CPU intensive because XML is ~~a huge crap~~ very powerful. So, we got multiple leads to improve it: - decode the XML faster thanks to [Expat](https://en.wikipedia.org/wiki/Expat%5F%28library%29?ref=xen-orchestra.com) - find a way to have less XML to parse - use a dedicated worker for this task - throttling events Each solution have drawbacks, so we needed to carefully measure the performance impact to make wise choices. ## Create a dedicated issue We choose to create an issue related to this problem. And because Xen Orchestra is modularized, we just had to work in a specific library, without modifying `xo-server` itself. [The issue](https://github.com/julien-f/js-xen-api/issues/1?ref=xen-orchestra.com) regroups all our performances tests, with branches for each experiment. This way, we can make benchmarks properly, by just switching branches. ### Parse faster Our first initiative was to try [Expat](https://en.wikipedia.org/wiki/Expat%5F%28library%29?ref=xen-orchestra.com). It parses XML faster than our previous lib. Initial results were encouraging: 3 to 4 times faster! But the progress is constant: more servers/pools you had, it "stays" 3 to 4 times faster. That's because the XML quantity is proportional to the objects number (pools, servers, VMs, etc.) The serious drawback is the library itself: because it's written in C, it had to be built on each system we have deployed. This is a risk when you don't have control of where your software is executed (i.e: inside the client company, XO is not in SaaS!) ![](https://xen-orchestra.com/blog/content/images/2015/06/orange-koenigsegg-ccx.jpg) > Parsing faster is like using a sports car to make a race: you are going indeed faster than your regular car, but it's complicated to build (and to maintain). > So we searched another way to be faster... ### Less XML Okay, so XML parsing is CPU intensive. Why not having simply less XML to parse? We asked the XAPI team if there is a way to do so. And... there is! We have the possibility to use JSON encapsulated in XML-RPC. It means, roughly: a bit of XML, and inside a *data* tag with everything we needed in JSON. This is a very good news because: - it scales very well: bigger the infrastructure, better it boosts the performances. Indeed, we'll have more data (JSON) for same quantity of XML (so less XML for same data) - it's in the XAPI since a long time (more than 3 years) - we tested it quickly and the results were very good Good how? 4 times better in our very small lab. More than 4 times on a bigger infrastructure. Will our theory be correct? See the conclusion ;) ![](https://xen-orchestra.com/blog/content/images/2015/06/1349.jpg) > Less XML is equivalent to have the finish line closer to you. You don't have to go faster if you have (a lot) less to travel. ###### Remove all XML? The perfect solution: XAPI should be able of talking JSON-RPC only... But this is not yet possible in [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver)! The next release of XenServer (7?) will probably have this, new tests will come soon. This is an ideal world for us: no more XML! We'll test it as soon as possible :) ![](https://xen-orchestra.com/blog/content/images/2015/06/xml.jpg) ### Throttling events Thanks to the XAPI event system, we have the possibility to delay some of them, to avoid a kind of "fragmentation" (a lot of small XML files with JSON in it). By throttling events, we could have bigger files, thus reducing the XML parsing cost. And also have less HTTP requests! The drawback is to sacrifice a small delay (i.e: less reactive system). This is only an idea so far, we didn't make any test yet. But still, we got a promising lead. ### Going deeper ![](https://xen-orchestra.com/blog/content/images/2014/Aug/1386271588578.jpg) More than "pure" performance, there is also another thing we can do. As you may know, Node is single threaded. But that's not true if we use workers! #### Workers Basically (and roughly), we can delegate something to a worker. It takes an input and gave us back an output. It's pretty basic, but we can imagine to delegate some intensives tasks to it (like... XML parsing?), and so exploiting multi-core capabilities without slowing the main event loop. But... this needs a non-negligible amount of work to be done carefully and properly. This lead will be probably explored in the next months. ![](https://xen-orchestra.com/blog/content/images/2015/06/nodejs.png) ## Final choices and results So we decided to be "conservative" in a first place, by using only encapsulated JSON in XML-RPC. This offers, without taking too much risks, a 4 times faster Xen Orchestra on our small infrastructure. *Expat* parser gives a small boost, but not enough facing the risks in production/deployment. ![](https://xen-orchestra.com/blog/content/images/2015/06/perfs-1.png) > - X axis: 3 pools where we make our tests > - Y axis: total time (in *ms*) to get all objects in a Pool And how about a big infrastructure? Like this one: ![](https://xen-orchestra.com/blog/content/images/2015/06/perfs2.png) Our initial calculations indicate roughly something around **250 times faster**. That is a huge leap! Stay tuned for the 4.2 coming this week. ### Xen Orchestra free Trial URL: https://xen-orchestra.com/blog/xen-orchestra-free-trial/ Last updated: 2015-06-17T12:11:17.000Z Since the [big 4.0 release](https://xen-orchestra.com/blog/blog/xen-orchestra-4-0), we offered the possibility of a trial for testing **all the XOA features** for free during 15 days. Here is how to proceed! 1. Register on [https://xen-orchestra.com](https://xen-orchestra.com/?ref=xen-orchestra.com) 2. Download the Free version 3. Deploy it 4. Request a Trial in the "Settings" and "Update" view 5. Update to get the latest bits of *Enterprise* (remember to refresh your browser to load the new version). That's all! ![](https://camo.githubusercontent.com/a8d804a7055deb81c88f1de0f3b5b0124d3fb1a2/68747470733a2f2f78656e2d6f72636865737472612e636f6d2f626c6f672f636f6e74656e742f696d616765732f323031352f30352f757064617465722e706e67) ![](https://camo.githubusercontent.com/435026d3bad8c096e10b6e8ea3fcdabe1b52462c/68747470733a2f2f78656e2d6f72636865737472612e636f6d2f626c6f672f636f6e74656e742f696d616765732f323031352f30352f747269616c2e706e67) Enjoy the full power of [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com), the [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver) web interface! ### Xen Orchestra 4.1 URL: https://xen-orchestra.com/blog/xen-orchestra-4-1/ Last updated: 2015-06-10T16:51:54.000Z 2 weeks after the major 4.0 release, this is time for the 4.1\. This is a small but cool release, bringing interesting features and also improving the update mechanism. And finally, solving minor bugs. > If you already have any recent XOA running, you can update right now thanks to the web updater released in [the 4.0](https://xen-orchestra.com/blog/blog/xen-orchestra-4-0). Otherwise, go into [your member zone](https://xen-orchestra.com/?ref=xen-orchestra.com#!/login?source=member) to download the full XOA. The full changelog is available [here](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#410-2015-06-10). ## Drag and drop live migration Really, quick and simple to understand in a very short video: Your browser does not support the video tag. Here is a screenshot for those who can't play the video: ![](https://xen-orchestra.com/blog/content/images/2015/06/dragndrop.png) ## Better ACL/group management Group view is now more efficient: you can organize all your permissions in one group. This way, you can now start to use groups to "assemble" resources. You want some user to operate VMs, and mount some ISO of their choices? Create a group, give it the right to operate VMs and to view the SR containing the ISOs. The whole process is in this video: Your browser does not support the video tag. ## Only display accessible resources As you may noticed in the previous video, you now can't see VDI (ISO or disk) without having at least the "view" permission in the SR where are those VDIs. ## Safer upgrade process Our big 4.0 release show that our updater process can be more robust. For that, we are bundling now all dependencies directly in the packages themselves. In this way, we are sure of what you'll get, even if there is new external dependencies since. ## Better proxy handling 4.1 is now working better with proxies when you upgrade or install package through the updater. If you had previously troubles with the 4.0, download XOA 4.1! ### VM live migration with XenServer and Xen Orchestra URL: https://xen-orchestra.com/blog/vm-live-migration-with-xenserver-and-xen-orchestra/ Last updated: 2015-06-09T12:49:17.000Z This week, we'll release a new version of Xen Orchestra (4.1). Only 2 weeks after the [big 4.0](https://xen-orchestra.com/blog/blog/xen-orchestra-4-0), it's already time for new features! Let's play with the powerful live migration system of [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver). It works since XO 3.6 version, you can read more about [how it works here](https://xen-orchestra.com/blog/blog/cross-pool-migration-with-xo). But in the 4.1, live migration is only one click away (true story)! Thanks to the drag'n drop features coming soon, the result is this: Your browser does not support the video tag. Here is a screenshot for those who can't play the video: ![](https://xen-orchestra.com/blog/content/images/2015/06/dragndrop.png) Note: it also works with *Xen Storage Motion* (moving a VM to another host without any shared storage). Stay tuned for the 4.1 :) ### VENOM vulnerability and XenServer URL: https://xen-orchestra.com/blog/venom-vulnerability/ Last updated: 2015-06-04T09:27:35.000Z You probably heard about the [VENOM attack](http://venom.crowdstrike.com/?ref=xen-orchestra.com) few weeks ago. And you also probably saw the logo: ![](http://venom.crowdstrike.com/assets/venom-logo-med.png) Let's have some perspective on this one. 4 things to know: - it affects only HVM guests - it needs a root access on the vulnerable guest to be exploited - there a patch available for XenServer - keep calm and uses Xen Orchestra The patch is of course already [out](https://support.citrix.com/article/CTX142483?ref=xen-orchestra.com). With Xen Orchestra, the new VENOM patch is **automatically displayed** on the host view. And you just have to install it in one click. See for yourself: Your browser does not support the video tag. This click triggers these events: - `xo-server` will automatically download the VENOM patch on the Citrix website - unzip it and upload it to your host - everything on the fly! (using the powerful *streams* in Node.js) - finally apply the patch automatically. **And that's all, your are now fully protected from the VENOM exploit.** Beside you can also doing it the "old way", but you have to: 1. Download the update to a known location on a computer that has XenCenter installed. 2. In XenCenter, on the Tools menu, select Install Update. This displays the Install Update wizard. 3. Click Next to start the wizard. 4. Click Add to upload a new update. 5. Browse to the location where you downloaded the hotfix, select it, and then click Open. 6. From the list of updates select and then click Next. 7. Select the hosts you wish to apply the hotfix to, and then click Next. 8. Follow the recommendations to resolve any upgrade prechecks and then click Next. 9. Choose how to perform post-update tasks. In the Post update options section, select automatically or manually, and then click Install update. 10. When the installation process is complete, click Finish to exit the wizard. **And all of that, if you know there is a patch to download!** 10 steps VS 1, make your choice ;) ### XenServer 6.5 SP1 URL: https://xen-orchestra.com/blog/xenserver-6-5-sp1/ Last updated: 2015-06-03T07:57:35.000Z Despite that's [almost one month ago](http://xenserver.org/blog/entry/xenserver-6-5-sp1-released.html?ref=xen-orchestra.com), it's important to remember that XenServer 6.5 has now it's Service Pack 1! So, what's new? For us, the key points are: - [Initial Docker management](https://xen-orchestra.com/blog/blog/xenserver-xen-orchestra-and-docker/) (hey, it works in [XO 4.0](https://xen-orchestra.com/blog/blog/xen-orchestra-4-0)!) - Better VM density (up to 1000 VMs per host) - GPU improvements (Intel GVT-d support and NVidia pass through for Linux) But wait, what's the best thing with this SP1? Thanks to XO 4.0, you can now just deploy it in **one click**. I mean, really. One click: Your browser does not support the video tag. Yes, this click trigger these events: - `xo-server` will automatically download the patch on the Citrix website - unzip it and upload it to your host - everything on the fly! (using the powerful *streams* in Node.js) - finally apply the patch automatically. Ok, that's cool. But how did you do to have it displayed in the patch list? **Nothing**. We fetches the available patches for your host **automatically**. Want to know how it works behind? [Read our previous article!](https://xen-orchestra.com/blog/blog/xenserver-patches-the-easy-way/) We are very happy to simplify your XenServer experience. That's one of our main goals :) Enjoy XO! ### Xen Orchestra 4.0 URL: https://xen-orchestra.com/blog/xen-orchestra-4-0/ Last updated: 2015-05-31T19:01:55.000Z Here it comes! [Announced nine months ago](https://xen-orchestra.com/blog/xo-4-x-goals/), this is the first release of the 4.x branch (codename *Double bass*). We are even ahead in terms of features of what we expected for the 4.0\. **It is the biggest release ever**. Let's take a tour of what's new. > TL;DR: download it [from your account space](https://xen-orchestra.com/?ref=xen-orchestra.com#/member). ## Table of content Beside fixed issues, you can check these improvements: - [Advanced ACLs](#advancedacls) - [XenServer update management](#xenServerupdatemanagement) - [Docker control](#dockercontrol) - [Better responsive design](#betterresponsivedesign) - [Host metrics](#hostmetrics) - [Pagination](#pagination) - [XOA web updater for everyone](#xoawebupdaterforeveryone) - [Better VM creation process](#bettervmcreationprocess) - [VM boot order](#vmbootorder) - [Under the hood](#underthehood) - [Around XOA](#aroundxoa) - [Free trial](#freetrial) - [Partner program](#partnerprogram) - [What's next](#whatsnext) The [full changelog is available here](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#400-2015-05-29). > By the way, [we opened a dedicated Twitter account now](https://twitter.com/xenorchestra?ref=xen-orchestra.com). Follow us to to stay tuned! We are also on IRC: **#xen-orchestra** (on FreeNode). ## Advanced ACLs The most requested feature ever: the possibility to have ACLs for users and groups! It means you can now use a set of permissions (a **role**) on an object. Let's take an example, with an "**operator**" role, with the authorization of start/stop/restart a VM with a web console access (and that's it, no more). It means no way to delete the VM, or to add disks, even take snapshots. Now imagine you have "dev1", "dev2" until "dev100". To give them the "operator" role, the easiest way is to create a "**dev1-team-1**" group. And to attach the role to this group (and not the users itself). This way, it's very simple to manage roles for a lot of people, once: ![](https://xen-orchestra.com/blog/content/images/2015/05/acl2.png) List of existing roles: - **viewer** (user/group can only see its objects) - **operator** (user/group can make basic cycle operation, stop/restart/console) - **admin** (user/group can modify the RAM, vCPUs, snapshots, etc.) A simple demo video (you can use full screen for a better view): Your browser does not support the video tag. ## XenServer update management You don't have to search manually for new XenServer patches, they are now detected automatically. But before you had to: - go on the Citrix website - download the ZIP file - upload the patch Now, all of this is just one click away: ![](https://xen-orchestra.com/blog/content/images/2015/05/patch_detect.png) After clicking on the "Missing" red label, it will automatically download the ZIP and send it to your server, and finally apply it. And you don't have to wait for the download to be ended for starting the patch: it's all done in streaming (first bit of download are unzipped, then sent to the host). [Read the original article for more](https://xen-orchestra.com/blog/blog/xenserver-patches-the-easy-way/) (and also [the Part 2](https://xen-orchestra.com/blog/blog/xenserver-patches-the-easy-way-part-2/)). It will be improved to automatize (more!) the process, example to install/apply all patches for a whole pool. ## Docker control You can enjoy now a basic control on your Docker containers (if they are managed by the XAPI). It's pretty basic so far, but be sure we'll develop this feature soon to allow easy "Docker-ready VMs" and container creation directly in Xen Orchestra! We wrote more about [this feature here](https://xen-orchestra.com/blog/blog/xenserver-xen-orchestra-and-docker/). Check the short demo here: Your browser does not support the video tag. We also started [to contribute to the XAPI plugin](https://github.com/xenserver/xscontainer?ref=xen-orchestra.com), so it will help to deliver a smooth ride with Docker, XenServer and Xen Orchestra! In brief, that's just a start. ## Better responsive design We introduced three mechanisms to allow a better user experience (UX) on small screens: - use "..." (ellipsis) avoiding large multi-lines in our tables. Now, even a long description won't brake the layout! - hide non-critical information: you can always interact with the software on a phone. - compact some menus when needed. You can see more examples and pics in the article about [Xen Orchestra and responsive design](https://xen-orchestra.com/blog/blog/xen-orchestra-responsive-design/). ![](https://xen-orchestra.com/blog/content/images/2015/05/phone1.JPG) These improvements are just a start, we'll dedicate more and more work done in UX for the next months! ## Host metrics You can now see the performances metrics for a host, i.e: - CPU usage - Memory usage - Network I/O - Load average ![](https://xen-orchestra.com/blog/content/images/2015/05/host-1.png) Like VM Stats, clicking on one graph will zoom it: ![](https://xen-orchestra.com/blog/content/images/2015/05/hostmetrics.png) ## Pagination Almost in the same category from the previous one, paginate our panels avoid to "destruct" the layout when we got a LOT of lines. The log panel is a good example: ![](https://xen-orchestra.com/blog/content/images/2015/05/pagination.png) ## XOA web updater for everyone This feature is really cool and it's for **all versions of XOA** (even the *Free* one). It helps to have your XOA up-to-date, without having to connect on SSH to do it. That's one step toward our goal: configure entirely XOA from its web interface. Now, if there is a new version of XOA available, you have this icon in the toolbar: ![](https://xen-orchestra.com/blog/content/images/2015/05/updatericon.png) And by clicking on it, you are on the update page, and you can start the update by clicking on the button: ![](https://xen-orchestra.com/blog/content/images/2015/05/startupdate.png) It allows also unlocking all features for a trial: this way, you can test the whole product (see the ["Free trial" chapter below](%28#freetrial%29). ![](https://xen-orchestra.com/blog/content/images/2015/05/updater.png) ## Better VM creation process We simplify the VM creation process and also allow the use of templates with existing disks: that was a limitation of previous versions. Now, it detects the disks and networks of the templates and display them. The summary zone is also more sexy, with a tooltip on icons: ![](https://xen-orchestra.com/blog/content/images/2015/05/newvmcreate.png) ## VM boot order If you need to boot on the network or the CD, you can now change the boot order by just clicking on a button in the disk panel: ![](https://xen-orchestra.com/blog/content/images/2015/05/bootorder.png) ## Under the hood ### Faster engine A brand new implementation of our previous slowest piece of code: this time, it goes faster. So now, it starts to scale on big infrastructures! ![This is not a RR Trent 1000, it's xo-server](https://xen-orchestra.com/blog/content/images/2015/05/trent.jpg) Example of a big infrastructure displayed with XOA: ![](https://xen-orchestra.com/blog/content/images/2015/05/image001.png) It means: - 31 pools - 100 hosts - 1000 running VMs - 3649 vCPUs used - \~8TB or RAM used **But** there is some room for improvement, especially on one (slow) external library (not "our" fault directly). We'll replace it soon to get a faster XO. Yeah, massive XML decoding is pretty much CPU intensive... If you have a infrastructure like that, wait for the 4.1 to try it. FYI, the bottleneck is more with a high number of hosts than VMs (e.g: one host with \~1000 VMs is a piece of cake! Not the same story with 100 hosts). ### Less coffee We progressively replace *CoffeeScript* by pure *JavaScript* (in ES6 with *Babel*). Next releases will probably get rid of the last *Coffee* pieces to reduce the variety of languages. ## Around XOA Xen Orchestra is "just" one piece in the final product: **XOA**. We also developed new features and possibilities to give you the best experience possible. ### Free trial Thanks to the updater, you can now start a Free trial for unlocking all the features of XOA. As you can see, that's easy, you just have to click on this button in the "Update" settings view: ![](https://xen-orchestra.com/blog/content/images/2015/05/trial.png) At the end of the trial period, you will be downgraded to your previous version. And if you want to upgrade, you'll have all the features unlocked the minute after your purchase. **No need to download the whole appliance!** ### Partner program We are really proud to announce the start of our [new partner program](https://xen-orchestra.com/?ref=xen-orchestra.com#/partner). And it starts... now! If you are interested, \[go register\](([https://xen-orchestra.com/#/partner](https://xen-orchestra.com/?ref=xen-orchestra.com#/partner)) to know more. We also building our program step by step: we can announce officially the first partner today! And it's just a start: the partner list will grow very soon. #### Say hi to our first partner! ###### Aswat Telecom [ASWAT Telecom & Media](http://www.aswat-telecom.com/?ref=xen-orchestra.com) is a DUBAI-UAE based company providing managed services cloud or on-premise contact center solutions, with clients in the GCC, Europe North Africa and the USA. ![](https://xen-orchestra.com/blog/content/images/2015/05/tbPhkAnQt79oQpv8KFUkmwAfiq0LpUQyvxPApRcfzgk.png) ## What's next? Because 4.0 is huge, we'll take time to improve the new features both technically and functionally, thanks to your precious feedback. It's very likely we'll release a 4.0.1 to fix minor issues. Then, a 4.1 will come in June with **SSO Support** (SAML 2.0) and other cool stuff with some surprises ;) Stay tuned! ### XenServer patches, the easy way, part 2 URL: https://xen-orchestra.com/blog/xenserver-patches-the-easy-way-part-2/ Last updated: 2015-05-25T10:42:54.000Z This post is the developments of [our previous article](https://xen-orchestra.com/blog/blog/xenserver-patches-the-easy-way/) (video demo in it) on patching XenServer in one click with [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com). This feature will be available for the incoming (this week!) Xen Orchestra 4.0. #### Incompatible patches Yes, that's great, you got all the patches you need in the host view, like this: ![](https://xen-orchestra.com/blog/content/images/2015/05/oldpatchsystem.png) But wait... Let's get a closer look: - **XS65E009** is the VENOM patch for XenServer 6.5 **without SP1** - **XSESP1002** is the VENOM patch for XenServer 6.5 SP1 Basically, they are the same patch, but not for the same version of XenServer! Display both of them will induce confusion, and if you try to install **XS65E009** on a XenServer 6.5 SP1, it will fail. Thus, we managed to get further by avoiding display of incompatible patches: ![](https://xen-orchestra.com/blog/content/images/2015/05/newpatchsystem.png) Now, with our new patch management, it displays only **what's missing and what you need to install**. **Just click, it works. Period.** #### Conclusion: patching is now dead simple In conclusion, with the incoming Xen Orchestra 4.0: - you don't have to check if there is a new patch, it will be displayed automatically - you don't have to go to any website to download it on your computer, then upload it: just click on the missing patch, it will be downloaded, uploaded and installed automatically! - you don't have to think if one patch is not compatible with another. It will be hidden if it's the case. ### Xen Orchestra responsive design URL: https://xen-orchestra.com/blog/xen-orchestra-responsive-design/ Last updated: 2015-05-18T10:42:46.000Z Some people complains (understandably) about the malformed display of Xen Orchestra on smaller devices. That's why we introduced three mechanisms to allow a better user experience (UX) on small screens: - use "..." (ellipsis) avoiding large multi-lines in our tables. Now, even a long description won't brake the layout! - hide non-critical information: you can always interact with the software on a phone. - compact some menus when needed. These new enhancements will be available for the [huge Xen Orchestra 4.0 coming soon](https://xen-orchestra.com/blog/blog/4-reasons-why-xen-orchestra-4-will-be-huge/). **Before**: ![](https://xen-orchestra.com/blog/content/images/2015/05/ui1.png) And **after** (same window size, shrink 50% in height!): ![](https://xen-orchestra.com/blog/content/images/2015/05/ui2.png) And for a very small device (phone), **before**: ![](https://xen-orchestra.com/blog/content/images/2015/05/ui3.png) **After** (yeah, we removed the Pool, which is not critical when viewed from a phone): ![](https://xen-orchestra.com/blog/content/images/2015/05/ui4.png) These improvements are just a start, we'll dedicate more and more work done in UX for the next months! Same thing for the setting view, **before**: ![](https://xen-orchestra.com/blog/content/images/2015/05/resp_settings.png) And **after**: ![](https://xen-orchestra.com/blog/content/images/2015/05/resp_settings2.png) #### On real devices ##### Tablet And the result for a real tablet? Here some shots with a 7.85" device: ![](https://xen-orchestra.com/blog/content/images/2015/05/tablet1-1.JPG) ![](https://xen-orchestra.com/blog/content/images/2015/05/tablet3-1.JPG) And in the "worst" case (vertical display), it stays usable: ![](https://xen-orchestra.com/blog/content/images/2015/05/tablet2-1.JPG) ##### Phone Ok, let's try to go further. Now on a *Moto G* with a small 4.5" screen: ![](https://xen-orchestra.com/blog/content/images/2015/05/phone1.JPG) As you may seen, we removed the *Pools* column, but this is the small price to pay for keeping to play with XO on a very small device ;) Well, at least you can now use all the possibilities of XenServer and Xen Orchestra from any device! ### XenServer, Xen Orchestra and Docker URL: https://xen-orchestra.com/blog/xenserver-xen-orchestra-and-docker/ Last updated: 2017-10-31T00:15:07.000Z > **2015 December Update**: check our complete guide to use Docker with XenServer: [Docker support in XenServer, the ultimate guide](https://xen-orchestra.com/blog/docker-support-in-xenserver-the-ultimate-guide/) Yes, [XO 4.0 is not far](https://xen-orchestra.com/blog/blog/4-reasons-why-xen-orchestra-4-will-be-huge/). But in parallel, we made a nice step further for [Docker](https://www.docker.com/?ref=xen-orchestra.com) integration in Xen Orchestra. ![](https://xen-orchestra.com/blog/content/images/2015/05/docker_logo.png) Thanks to the plugin developed [recently](http://xenserver.org/partners/docker.html?id=159&ref=xen-orchestra.com) as a "preview" by Citrix in XenServer, we started to work something to expose those data in [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com). First thing first, we now detect which VMs are "Docker ready", meaning connected to XenServer and its plugin to send more info. This is visible in the home page of XO, VM with a small ship blue logo: ![](https://xen-orchestra.com/blog/content/images/2015/05/docker.png) By clicking on this VM, you'll have some new stuff visible, first the Docker version: ![](https://xen-orchestra.com/blog/content/images/2015/05/docker2.png) But here is the **interesting stuff**: a new panel display now all the containers on the VM: ![](https://xen-orchestra.com/blog/content/images/2015/05/docker3.png) And yes, you can Stop, Start, Pause, Resume or Restart a Docker container from here! Here is a short video demo: Your browser does not support the video tag. ##### Why? Coupled with our extended ACLs coming for the 4.0, you can now imagine this: - delegate the permission to your dev team to interact only with their VMs (without other basic rights on this VM) - and to quickly act with their own containers - with the live VM metrics just above, they can **understand more what's happening in real time** - all the containers are in VMs, so you **can predict the maximum resources usage**, even with a TON of containers - you can adjust the VM settings in live (CPU, RAM) if you dev team (or client) need it. ##### What's next? Our goal is to provide an easy solution for deploying VMs "containers ready". We'll have to expose a simple way to create VMs with the SSH key you need, etc. Also note that [XenServer Dundee](https://xen-orchestra.com/blog/blog/xenserver-dundee/) will probably have a deeper Docker integration, which will open nice opportunities for us to deliver better solutions. Well, as you can see, [XO 4.0](https://xen-orchestra.com/blog/blog/4-reasons-why-xen-orchestra-4-will-be-huge/) will be the biggest release ever for Xen Orchestra (don't forget we also have in bonus [the patch detection system](https://xen-orchestra.com/blog/blog/xenserver-patches-the-easy-way/)). And all of this, soon! ### XenServer patches, the easy way URL: https://xen-orchestra.com/blog/xenserver-patches-the-easy-way/ Last updated: 2015-05-19T13:01:54.000Z That's [another reason why Xen Orchestra 4 will be huge](https://xen-orchestra.com/blog/4-reasons-why-xen-orchestra-4-will-be-huge/). It was not planned, but we managed to have this exciting feature: easy patch management! Yesterday, to be sure your XenServer was up-to-date, you have to **check for updates manually**. Then, we you knew there is a patch available, you have to do this with XenCenter: 1. Download the update to a known location on a computer that has XenCenter installed. - In XenCenter, on the Tools menu, select Install Update. This displays the Install Update wizard. - Click Next to start the wizard. - Click Add to upload a new update. - Browse to the location where you downloaded the hotfix, select it, and then click Open. - From the list of updates select and then click Next. - Select the hosts you wish to apply the hotfix to, and then click Next. - Follow the recommendations to resolve any upgrade prechecks and then click Next. - Choose how to perform post-update tasks. In the Post update options section, select automatically or manually, and then click Install update. - When the installation process is complete, click Finish to exit the wizard. That's 10 steps. With the 4.0 coming, you'll have a warning displayed in the toolbar, and on the host/pool which will not have all the current patches available. So **no need to check anywhere else if a new update is out**, you'll know it just by using Xen Orchestra! That's cool but for install those patches? Here is the good news, e.g on one of your host: Your browser does not support the video tag. With a close-up on the patch panel: ![](https://xen-orchestra.com/blog/content/images/2015/05/patch_last_recent.png) You can see automatically all missing patches. By clicking on install, the backend will do **all the work** for you: - `xo-server` will automatically download the patch on the Citrix website - unzip it and upload it to your host - everything on the fly! (using the powerful *streams* in Node.js) - finally apply the patch automatically. So yes, truly **one click only**! **1 step** :) Oh and by the way, by clicking on the description of the patch, you'll open a new tab with the Citrix official announcement regarding this hotfix. We'll also have the possibility to install **all the patches in one click**, for a host or even for the whole pool, thanks to the rolling patch mechanism in the XAPI. > Having your XenServer properly patched is really important for security issues. By simplifying the process, we think to help you to be more up-to-date, thus more secure! ### 4 reasons why Xen Orchestra 4 will be huge URL: https://xen-orchestra.com/blog/4-reasons-why-xen-orchestra-4-will-be-huge/ Last updated: 2015-04-30T19:03:13.000Z Our release rate is now nominal: one release per month. Despite this shorter cycle, we never released so much features each time! Various factors are behind this: - 100% of our focus on XO since 2015 - one new dev in January - a better organization (Kanban) And progressively, we checked every step on our roadmap. So, why 4.0 will be more special? Mainly because it was a long term goal, [planned since August 2014](https://xen-orchestra.com/blog/blog/xo-4-x-goals/). We make some features before as we planed, some others a long time after that. But we almost did it! So, 4.0 will be indeed a **HUGE** step for the Xen Orchestra project. Let's see why. #### Reason 1: Delegate your VMs and ressources in one click It's already possible from the [3.7 release](https://xen-orchestra.com/blog/blog/xen-orchestra-3-7-is-out-acls-in-early-access/), at least to create users in Xen Orchestra, and to limit their visibility only to some objects you selected, as you can see here: Your browser does not support the video tag. But we take the step further, as specified [in this report](https://github.com/vatesfr/xo-web/issues/209?ref=xen-orchestra.com): We wanted this: - a bunch of users -> a group - a bunch of permissions -> a role - a bunch of objects (VM etc.) -> a set Which can lead to: - Group (e.g: "devs"): contains user "john", "foo" and "bar" - Role (e.g: "basic"): contains action VM.start, VM.stop, console access, and VM.reboot - Set (e.g: "dev VMs"): contains VM "test1", "test2" etc. So it means, you can give the "basic" role of your "devs" group to all the VMs in the "dev VMs" set. Possibilities are endless! You can really be **flexible on how you give resources** to anyone you want. And in bonus, we already have the **compatibility to connect those user to an LDAP directory**, like *Open-LDAP* and *Active Directory*! (since 3.8 and improved in 3.9). Yes, this way, your XenServer infrastructure can be converted to a cloud-like solution in less than 1 minute! > This feature is the answer of the popular demand: filling the gap between admin tools and the cloud. #### Reason 2: High Scalability We have redesigned the storage of all events and objects in memory, **from scratch**. The architecture was good, but not the implementation. It should give us a **major performance boost**. Our goal is to be able to cope with very large infrastructures, with **thousands of VMs**! ![](https://xen-orchestra.com/blog/content/images/2015/04/070705_genxfan_02.jpg) Yeah, our new engine look like this. Approximately. #### Reason 3: Update XO from the web We choose to simplify to update process, by integrating the update process directly **in the web interface**. E.g, giving an alert when a new version is out, click on it, update and... that's it! It will also give us the possibility to offer **demo versions** to try higher plans for free for a certain amount of time. Our ambition is to provide you the **control of everything about XOA from the web**, without any need to SSH on it to configure stuff. ![](https://xen-orchestra.com/blog/content/images/2015/04/20150209031915-Software_Update_icon.png) #### Reason 4: Just the start of an epic journey This version will end the *Early Access* program. It becomes the product we targeted a long time ago. But more than tat, it will **lay the foundations** of exciting features: in fact, after making our big improvements under the hood, we'll be able to focus on functional features for the next releases. Like: - Docker integration - Nice graphs visualization for the whole infrastructure - An intelligent backup system - Download templates/images on our repo directly from XOA - And more! Release cycles could be even shorter, thanks to the updater: you won't have to download anything beside the new code (few MBs!). All of this, **in one click!** ![](https://xen-orchestra.com/blog/content/images/2015/04/logo_small.png) ## When? We released 3.9 April the 21th. We **will** respect our release rate, which is 1 version per month. So, do the maths ;) ### XenServer Dundee available in pre-release URL: https://xen-orchestra.com/blog/xenserver-dundee/ Last updated: 2015-04-29T20:15:05.000Z After XenServer *Creedence* (**6.5**), here comes *Dundee* (**7.0?** I don't know!). So what's new for this first Alpha? ### Dom0 changes The BIG news in this first Alpha is all about having a Dom0 running on CentOS 7 (*Creedence* uses CentOS 5.10, much older). So, this is great because the Dom0 will be much closer to the "mainline" than previous version. I clearly see a very interesting shift from XenServer since it's Open Source, and my opinion it won't stop. Getting closest to the mainline than possible is **really** the way to have a the best product possible. Well done! ### Docker management You can already use a supplemental pack to play with it in *Creedence*. It works by using the XAPI plugin system. In this first Alpha, the plugin is already installed. ### Xen Orchestra opportunities The docker plugin will allow [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com) to also display running containers in the VM view, with basic controls: start, stop, pause/unpause and restart a container. To be fair, it already works with our CLI, but be sure we'll have something working before July! ### Download Dundee Alpha 1 You can download it [on this page](http://xenserver.org/overview-xenserver-open-source-virtualization/prerelease.html?ref=xen-orchestra.com). ### New features in our website URL: https://xen-orchestra.com/blog/new-features-for-our-website/ Last updated: 2015-04-28T13:44:54.000Z Our objective with the Xen Orchestra's project, is to release a **full and turnkey solution**, not just the software (Xen Orchestra). XOA is a part of this: having pro support AND a virtual appliance at the same time, plus other nice possibilities. That's why we extended our website to give our product a more unified experience, and a smoother purchase process. ###### Integrated support Right in your member zone, you can now request support directly: ![](https://xen-orchestra.com/blog/content/images/2015/04/support.png) We'll update the ticket system progressively to display the ticket status, the answers and other cool struff directly here. ###### Multi-year with discount You can now purchase XOA up to 3 years! (vs only 1 year max before). Those discounts applies: - 2 years: 1 month free - 3 years: 2 month free ![](https://xen-orchestra.com/blog/content/images/2015/04/discount.png) ###### Purchaser option If you need to have XOA purchased by your purchase service or a third-party, you can do it now. Here the workflow: - your purchaser register on our website - he can ask the role of purchaser in the member zone - as soon we validate it (less than 24h!), he can buy any XOA - ... and then he can attach it to any email (and yours if you are the final user) This way, you can have XOA given by your purchaser, without to deal with invoices (that's the business of the purchaser after all). ![](https://xen-orchestra.com/blog/content/images/2015/04/purchase.png) ![](https://xen-orchestra.com/blog/content/images/2015/04/purchase2.png) ###### Newsletter unsubscribe If you don't want to receive an email when we release a new version of XOA, you can use this checkbox now: ![](https://xen-orchestra.com/blog/content/images/2015/04/unsubscribe.png) ###### What's next? We'll also deliver in the next month a better coupling between your account and your XOA, allowing trial versions for a specific timeframe. This way, you'll be able to try *Enterprise* version for free. We are also preparing a *Partner program* for companies which want to resell XOA directly to their customers. ### Xen Orchestra 3.9 URL: https://xen-orchestra.com/blog/xen-orchestra-3-9/ Last updated: 2015-04-21T14:27:56.000Z Another month, another release! On the menu: charts, network creation, VM autoboot, AD support, local LVM SR, handling server connection/disconnection etc. > TL;DR: rendezvous in your member zone to get the latest appliance. Or just [update your current installation](https://github.com/vatesfr/xo/blob/master/doc/installation/xoa%5Finstallation.md?ref=xen-orchestra.com#update-xoa) if you have the **Starter** or **Enterprise** edition! ### Charts, charts, charts! We got [metrics for VMs in XenServer](https://xen-orchestra.com/blog/blog/vm-live-metrics-in-xenserver-with-xen-orchestra/), so now you you have 4 charts giving you the last 10 minutes values for: - CPUs - RAM usage on total RAM - Interfaces Rx/Tx - Disks reads/writes In action: Your browser does not support the video tag. Now you can detect any problem/spike very quickly! It also helps to debug/benchmark anything happening in your VMs This previous article also explains how to [use XenServer metrics in Xen Orchestra](https://xen-orchestra.com/blog/blog/xenserver-metrics-in-real-examples/) for real benchmarks. ![](https://xen-orchestra.com/blog/content/images/2015/04/SDnCj1t.png) ### Server connection management We rewrote the *Settings* zone, merging ACLs, Users and Servers in one place with a lateral menu. You can now disconnect/connect any server: ![](https://xen-orchestra.com/blog/content/images/2015/04/4bl5B4K.png) We also integrated more feedback when adding a server (e.g: bad credentials) and current status of servers. ### LDAP This version is also supports officially *Active Directory*, LDAP filters and non-anonymous binds. ### Misc And in the misc category, we got: - VM autopower support (boot a VM when you boot its host) - Network creation in host view - Local SR creation (LVM) VM autopower is just easy as a checkbox: ![](https://xen-orchestra.com/blog/content/images/2015/04/ad307284-d885-11e4-92c3-b3e6b1f5bd2f.png) The complete changelog is [available at this place](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#390-2015-04-20). ### Next? 4.0 is coming! Full ACLs (groups, roles etc.) Time frame? At worst in mid-May! ### XenServer metrics in real examples URL: https://xen-orchestra.com/blog/xenserver-metrics-in-real-examples/ Last updated: 2015-04-13T14:09:24.000Z After the first introduction of how we displayed [XenServer metrics in Xen Orchestra](https://xen-orchestra.com/blog/blog/vm-live-metrics-in-xenserver-with-xen-orchestra/), here is some real examples and why it's really important to have an eyes on this kind of information. That's one of the powerful feature of the virtualization: because everything goes through the hypervisor, you can measure everything coming from your VMs and detect, analyse and understand any workload. And finally, [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com) brings you that directly in your web browser! #### Compiling a linux kernel in a Debian PVHVM This load is very interesting. First, the image: ![](https://xen-orchestra.com/blog/content/images/2015/04/load.png) 1. I made a `apt-get update`: network charts is pretty obvious (yellow) 2. This time, `apt-get dist-upgrade`: more CPU usage (blue) and disk read (light green). Also note the RAM usage also increasing by steps (red) 3. I just downloaded the latest kernel with a `wget https://www.kernel.org/pub/linux/kernel/v4.x/linux-4.0.tar.xz`, thus explains the spike in network usage (yellow) 4. Extracting the tarball displayed a increasing usage of CPU and disk read: it makes sense! FYI, the obvious: `tar xvf linux-4.0.tar.xz` 5. Let's prepare to compile the kernel, first with a `export CONCURRENCY_LEVEL=5` to use the full power of 4 vCPUs. Then, fire the command `make-kpkg --append-to-version "-customkernel" --revision "1" --initrd kernel_image kernel_headers` will make the CPU usage exploding! All the core are now working together to create Debian packages. Let's zoom on the (intensive) CPU usage: ![](https://xen-orchestra.com/blog/content/images/2015/04/cputotal.png) When it's all done, you can note the free RAM: ![](https://xen-orchestra.com/blog/content/images/2015/04/finished.png) #### Windows 7 updates in a XenServer VM Well, we didn't use any Windows OS for production purpose, but we made some tests with it. Maybe you always wondered "what's going on when an update of Windows in running?". Let's see that: ![](https://xen-orchestra.com/blog/content/images/2015/04/windows7.png) 1. The CPU (blue) is the first to make a move, probably to check/analyse existing updates 2. Then, the network (yellow) enters: updates are currently downloaded in the first place. You can also the RAM usage increasing (red) and the disk start to read data (green). 3. And during a moment, just after the updates were downloaded, CPUs and disks are extensively used (you can see when 2 vCPUs are working together). #### More! Soon, we'll redo some benchmarks [previously done for PV vs PVHVM](https://xen-orchestra.com/blog/blog/debian-pvhvm-vs-pv/), but this time with XenServer 6.5 and Xen Orchestra 3.9 to also display charts and verify the numbers. ### VM live metrics in XenServer with Xen Orchestra URL: https://xen-orchestra.com/blog/vm-live-metrics-in-xenserver-with-xen-orchestra/ Last updated: 2015-04-08T20:39:55.000Z Because this is really important, we'll release this feature next week! As a result, this post is also about announcing Xen Orchestra 3.9. Let's see it immediately in action: Your browser does not support the video tag. ## Why performance metrics matter The goal of live performance metrics are various. But in a Virtual Machine case, it's pretty clear: - you can see any problem/spike in less than 1 second - it's easy to read - it's live, so you can track a specific problem without waiting - it helps to debug/benchmark your infrastructure (what's limiting my application performance?) And because XenServer is really cool, it gives us a lot of data. The challenge is to get AND display them. > Remember: metrics are not like supervision, not the same goals. But it's also a fantastic tool. Thus, this time, imagine this scenario: - you are using XOA *Enterprise*, so you can delegate VMs to your developer team - they can only see their VM in Xen Orchestra, and thus their metrics - they can start their software, and see the impact on the VMs performances (disks, network, CPU, RAM) Great isn't it? ## Metrics in XenServer How to fetch VM metrics/data in XenServer was already covered in this previous article: [Statistics in XO](https://xen-orchestra.com/blog/statistics-in-xo/). But in a few words, those metrics are stored on RRD-like files written in XML, on each the host where the VM is currently running. Here is how it works: - the file is downloaded by `xo-server` - the XML is parsed - finally, numbers are sent to the client, in this case: `xo-web`. XenServer uses multiple sample rate: last 10 minutes, the sample rate is 5 seconds. You got also last 2 hours, last week and last year, with respectively 1 minute, 1 hour and 1 day of sample rate. ## In Xen Orchestra Since last year, we planned to integrate those metrics. Our initial draft was: ![](https://xen-orchestra.com/blog/content/images/2014/Aug/newstats.png) And the "real" result is: ![](https://xen-orchestra.com/blog/content/images/2015/04/statsIII.png) Let's zoom: ![](https://xen-orchestra.com/blog/content/images/2015/04/statsI.png) When you click on a chart, you got it on the whole panel: ![](https://xen-orchestra.com/blog/content/images/2015/04/statsII.png) This feature is also great when you make benchmarks. In this video, we'll start a disk benchmark on Windows 7 on XenServer 6.5\. You'll see instantly the Disk I/O chart rocketing to the sky! Your browser does not support the video tag. ## XO 3.9! Yes, this will be the last stop before 4.0! And this 3.9 should be out Friday, the 17th. Hang on! ### Creating a local ISO repository in XenServer URL: https://xen-orchestra.com/blog/creating-a-local-iso-repository-in-xenserver/ Last updated: 2022-05-05T19:41:50.000Z ⚠️ **If you are using XCP-ng, go check this far more recent blog post with all the details needed to [create your local ISO repository](https://xcp-ng.org/blog/2022/05/05/how-to-create-a-local-iso-repository-in-xcp-ng/?ref=xen-orchestra.com).** ℹ️ ISOs can now be uploaded directly via Xen Orchestra on recent versions. [Please see this blog post to learn how to do it.](https://xcp-ng.org/blog/2022/05/05/how-to-create-a-local-iso-repository-in-xcp-ng/?ref=xen-orchestra.com) It applies both on XenServer/Citrix Hypervisor and XCP-ng. It happens sometimes you need to install VMs with ISO, without having a shared Storage Repository (e.g NFS). Citrix XenServer allows to do this, and you can have multiples cases for that: - you have a single host, without access of any ISO share - you don't want to create a shared storage - you want a simple way to start to use ISO files > Warning: you only have 4GB of space in the root file system. So, prefer an external HDD or a large USB key, to avoid filling the Dom0 at 100%. First this first, you need to use a folder somewhere. You can use */tmp* if you like, but the content will be lost after a reboot. You can also create a dedicated folder on your host: ``` $ mkdir -p /var/opt/xen/ISO_Store ``` Before Xen Orchestra, you'll have to do this: ``` $ xe sr-create name-label=LocalISO type=iso device-config:location=/var/opt/xen/ISO_Store device-config:legacy_mode=true content-type=iso ``` But now with Xen Orchestra, it's easier! ([see the original blog post about creating any Storage Repository in XenServer](https://xen-orchestra.com/blog/create-a-storage-repository-with-xen-orchestra/)) You just have to create a Storage Repository: ![](https://xen-orchestra.com/blog/content/images/2015/04/iso1.png) Choose local ISO, use any path on your filesystem: ![](https://xen-orchestra.com/blog/content/images/2015/04/iso2.png) Click on "Create SR" and you're done! ![](https://xen-orchestra.com/blog/content/images/2015/04/iso3.png) Now, each ISO you add in this folder, will be visible in the ISO list when creating a VM! ### Xen Orchestra 3.8 URL: https://xen-orchestra.com/blog/xen-orchestra-3-8/ Last updated: 2015-03-27T19:43:27.000Z **Release often, release faster**: that's our motto this year. And we spent some time do give you a smoother experience when upgrading, with those objectives: - Avoid appliance re-download for each new version - Avoid any manual data migration on your side - Ability to rollback to a previous release if anything goes wrong > TL;DR again? [Download it now](https://xen-orchestra.com/?ref=xen-orchestra.com#/member)! ## XOA updater Those previous requirements lead to those specifications: - Include an updater in XOA - Handle download of new Xen Orchestra versions - Handle script migrations (e.g when the database structure changed) - Handle updater self-update - Handle rollbacks Not trivial eh? But we made it, and this tool is currently in last test phase. Basically, starting with the 3.8, **each new version of Xen Orchestra can be delivered directly in your XOA Starter or Enterprise** without more that calling `xoa-updater`, with that kind of output: ``` > xoa-updater Checking new versions... ok. New versions available: - xoa-register 1.0.6 - xo-server-starter 4.0.1 - xo-web-starter 4.0.1 Downloading the new packages... - xoa-register 100% - xo-server-starter 100% - xo-web-starter 100% Stopping xo-server... ok. Installing the new packages... ✔ xo-web-starter ✔ xoa-register ✔ xo-server-starter Executing migration scripts... ✔ 1316027432511-migrate-redis-to-leveldb.js (1/2) ✔ 1316027432575-updating-acls.js (2/2) Starting xo-server... ok. ``` For sure, we'll integrate something directly from the web interface, but this first step is really important. So what does it means? **More releases, more features directly in your XOA!** But... that's not the only new stuff in this 3.8! ## ACLs with LDAP support for Xen Orchestra With the **Enterprise** version, you can now plug your XOA to your LDAP directory: - Put the LDAP info in the config file - Log in with a LDAP user, if the user isn't already exists in the XOA database, it will be created on-the-fly without any rights - An admin can now see the new user in XOA and give him permissions (or the admin role if needed) That's all! ## First charts We also implemented first charts in host, pool and SR view: ![](https://xen-orchestra.com/blog/content/images/2015/03/host_live_charts.png) They are dynamic, so you could see the RAM or space moving in live, like in this video: Your browser does not support the video tag. Live metrics in a VM (like VM or CPU usage) need to get RRDs infos, but [we are currently working on it](https://github.com/vatesfr/xo-server/issues/51?ref=xen-orchestra.com), should be in the next update (3.9). ## Disk management The new disk panel in the VM view now gives you all this stuff: - Add a new disk to your VM - Attaching an existing disk - Mount CD from the VM view - Change disk order ![](https://xen-orchestra.com/blog/content/images/2015/03/disks1.png) In video: Your browser does not support the video tag. ## Network management Almost symetric than Disk management, you can now add a new network interface to your VM. ![](https://xen-orchestra.com/blog/content/images/2015/03/net1.png) After clicking on "Create Interface", you'll have to fill the form, e.g selecting the network, MAC address and MTU: ![](https://xen-orchestra.com/blog/content/images/2015/03/net2.png) ### Add a network interface to a VM on XenServer with Xen Orchestra URL: https://xen-orchestra.com/blog/add-a-network-interface-to-a-vm-on-xenserver-with-xen-orchestra/ Last updated: 2015-03-26T14:03:38.000Z The title is pretty much explanatory, isn't it? You'll see, that's very easy, in your VM view, you'll see it instantly, just click on "Create Interface" button: ![](https://xen-orchestra.com/blog/content/images/2015/03/net1.png) After clicking on "Create Interface", you'll have to fill the form, e.g selecting the network, MAC address and MTU: ![](https://xen-orchestra.com/blog/content/images/2015/03/net2.png) And after clicking on "Create", you're done! ![](https://xen-orchestra.com/blog/content/images/2015/03/net3.png) The new interface in now active on your VM. Enjoy Xen Orchestra! ### Disk management in Xen Orchestra URL: https://xen-orchestra.com/blog/disk-management-in-xen-orchestra/ Last updated: 2015-03-26T10:22:38.000Z 3.8 is coming soon. And we got new features we wanted for a long time! ## Overview The new disk panel in the VM view now gives you all this stuff: - Add a new disk to your VM - Attaching an existing disk - Mount CD from the VM view - Change disk order Everything is available here: ![](https://xen-orchestra.com/blog/content/images/2015/03/disks1.png) Editing the panel allow disk order be changed using the arrows: ![](https://xen-orchestra.com/blog/content/images/2015/03/disks2.png) A video demo of adding a brand new disk: Your browser does not support the video tag. ### XO live charts for host view URL: https://xen-orchestra.com/blog/xo-live-charts-for-host-view/ Last updated: 2015-03-26T10:14:16.000Z The next-release will offer a better visualization for the RAM occupied, and also the number of vCPUs used on the total number of CPUs. ![](https://xen-orchestra.com/blog/content/images/2015/03/host_live_charts.png) Those charts are animated on load: Your browser does not support the video tag. But also they are changing in live, when your host memory or vCPUs usage is modified (in this example, during a live migration of a VM in this host): Your browser does not support the video tag. Next step? Live metrics for all your VMs: CPU load, memory, network and disk usage with nice charts! ### Xen Orchestra 3.7 is out, ACLs in Early Access! URL: https://xen-orchestra.com/blog/xen-orchestra-3-7-is-out-acls-in-early-access/ Last updated: 2015-03-22T10:10:33.000Z A LOT of stuff in this 3.7, like VDI migration in live, SR creation, many UI improvements, display tasks in live etc. But that's not all! On the same time, we made significant progresses on the 4.x branch, which [started to implement **ACLs**](https://xen-orchestra.com/blog/blog/xo-4-x-starts-to-show-up/) for VM (or any objects) delegation! Let's start to review this. > TL;DR? [Register and download it](https://xen-orchestra.com/?ref=xen-orchestra.com#/?pk%5Fcampaign=blog%5F3.7) now! ## In all XOA editions These next features are available in all XOA editions (our virtual appliance), meaning also for the Free one! ###### VDI live migration from a storage to another It's exactly what it means: you got your VM disk on a storage, then you decide to move this disk to another one, **without interrupting the VM**. Example: you have your VM disk on the local storage (the SSD of your host). But you just finished to buy/build your brand new SAN. Or you want to migrate from an old SAN to a new one, without shutting down your VM. Complicated? Nope. Just go on the VM view, and precisely on the VM panel, then change its Storage Repository (SR), save and... That's it! ![](https://xen-orchestra.com/blog/content/images/2015/01/vdi1.png) As you can see, the current disk (named "*Docker*") is currently on "*Local Storage*" SR. We want to move it on another one. We selected "*ZFS*" (our iSCSI storage running ZFS)... ![](https://xen-orchestra.com/blog/content/images/2015/01/vdi2.png) And then validate the choice: ![](https://xen-orchestra.com/blog/content/images/2015/01/vdi3.png) The operation takes times (depending of the disk size). You can see the operation running in the main view: the VM dot having its VDI moving is in orange (with a tooltip), as you can see in this screenshot: ![](https://xen-orchestra.com/blog/content/images/2015/01/vdi4.png) A short video here showing the process starting (run it in if full screen if you like): Your browser does not support the video tag. [Read more here](https://xen-orchestra.com/blog/blog/moving-vdi-in-live/). ###### Add a Storage Repository You can now add a new SR. For the release, we support: - NFS VHD - iSCSI (LVM over iSCSI) - NFS ISO (for storing all your \*.iso files) - Local ISO (accessing all your \*.iso locally) It comes with a share/LUN detection system, as you can see in this video, you don't have to give all the parameters in the first place. Just an IP in enough to find all iSCSI or NFS informations! In action: Your browser does not support the video tag. More details on the [dedicated article](https://xen-orchestra.com/blog/blog/create-a-storage-repository-with-xen-orchestra/). ###### Console behind a NAT Since the start, consoles worked like that (let's call this "the XAPI's way"): - `xo-web` (your browser) asks the console to `xo-server` (the XO daemon) - `xo-server` asks to XAPI URL of the VM console - `xo-server` sends the VM console URL to `xo-web` - `xo-web` connects directly to this VM with noVNC ![](https://xen-orchestra.com/blog/content/images/2015/03/console_before.png) And thus, lead to these problems: - XAPI only exposes plain communication (no encryption for websockets): that's why HTTPS in XO and console were incompatible, like explained [in this issue](https://github.com/vatesfr/xo/issues/14?ref=xen-orchestra.com). - Consoles can't work outside the network (e.g NAT, `xo-server` will send a private class IP address to your `xo-web` which is outside: it will fail). Reported [in this issue](https://github.com/vatesfr/xo-web/issues/117?ref=xen-orchestra.com). - And finally, it was a securiry concern: currently we expose the session identifiers used to connect to pools to `xo-web`, this can able any users to access any connected servers. That's why, building a "console proxy" through `xo-server` was in the top of our [roadmap](https://github.com/vatesfr/xo/blob/master/roadmap.md?ref=xen-orchestra.com#xen-orchestra-roadmap)! In this case, you can use `xo-server` to expose all your XenServers, even if they are behind a NAT, without any problem to display their VM consoles! It's also secure, because token are kept right in `xo-server`and never sent to the client: ![](https://xen-orchestra.com/blog/content/images/2015/03/console_after.png) ###### Active tasks displayed in the toolbar Any active tasks will be displayed in the navigation menu, allowing to see them from any view of Xen Orchestra: ![](https://xen-orchestra.com/blog/content/images/2015/02/task3.png) If you click on the progress bar, you'll be redirected to the host running the task, and you'll also see the progress in the dedicated panel: ![](https://xen-orchestra.com/blog/content/images/2015/02/task4.png) You can see it in a video in [this article](https://xen-orchestra.com/blog/blog/task-management-in-xo/). ###### VM suspend and resume This allow to suspend your VM, for example shutdown your host, make a maintenance task, without losing all what you have in your RAM VM: because you just have to resume those VM after! And yes, you can do to with multiple VMs on the same time, see? ![](https://xen-orchestra.com/blog/content/images/2015/01/suspend2.png) [More here](https://xen-orchestra.com/blog/blog/xo-action-reaction/#suspending). ###### Enabling or disabling a host directly from the main view That's pretty obvious, but some people need it: ![](https://xen-orchestra.com/blog/content/images/2015/02/disable.png) ###### Space left on storage The perfect companion when you need to migrate a VDI on a new storage: ![](https://xen-orchestra.com/blog/content/images/2015/01/new-feature.png) [More here](./blog/xo-action-reaction/#freespace) ###### Better UI and feedback Like in VM creation, snapshots etc. We also switched to Twitter Bootstrap Panels: they a better than our custome CSS class! ###### SR actions You can now: - rescan all the VDI of a SR - reconnect or disconnect all hosts to this SR - forget the SR (disconnect and forget but don't do anything on the disk) - remove the SR (disconnect and "wipe" it) ###### Display the host manufacturer in the host view Trivial but useful: ![](https://xen-orchestra.com/blog/content/images/2015/02/hostmanuf.png) ## XOA Enterprise Early Access That's also a big news: **we have ACL's working**! That's the first step for our 4.x branch. You can start to play with them in the **XOA Enterprise Edition**, available in [**early access**](https://xen-orchestra.com/?ref=xen-orchestra.com#/early?pk%5Fcampaign=blog%5F3.7). > [Subscribe now!](https://xen-orchestra.com/?ref=xen-orchestra.com#/pricing?pk%5Fcampaign=blog%5F3.7) So here is what you can do now if few clicks: - create a user *john* with a password - give him the permission on the VM *Docker* - it works! In action: Your browser does not support the video tag. ![](https://xen-orchestra.com/blog/content/images/2015/03/acl_view.png) The next steps? Read more [in this article](./blog/xo-4-x-starts-to-show-up/)! Any Early access customer will have new features of ACL's as soon it's out! ## Starter Edition The *Starter Edition* is upgraded with the latest features of the Free Version, with also Import and Export features included! (you can import or export any VM or snapshot directly from your web browser!). And our new developer starts to work on backup: stay tuned! ## Feedback We'll be very happy to have your feedback [on our forum](https://xen-orchestra.com/forum?ref=xen-orchestra.com)! ### Create a Storage Repository with Xen Orchestra URL: https://xen-orchestra.com/blog/create-a-storage-repository-with-xen-orchestra/ Last updated: 2015-03-05T18:06:00.000Z This article is about creating a Storage Repository directly in Xen Orchestra, without any CLI command or without using XenCenter. I have to say, I personally awaited this feature for my own usage. Also, that's the first one released by [Fabrice](./blog/xo-team-reinforcement-have-arrived/), our new developer! ## Demo As usual, we wanted to expose this feature in a few clicks. It's not **that** easy to implement, because there is a lot a specific stuff between different storage technologies. Here is a video showing the complete process, from the Home page to the Storage view freshly created: Your browser does not support the video tag. We support those SR types (more to come): - NFS VHD - iSCSI (LVM over iSCSI) - NFS ISO (for storing all your \*.iso files) - Local ISO (accessing all your \*.iso locally) ## Edge cases We also have to deal with "edge cases". What if: 1. you want to add a SR but it's already connected to your Pool/Host? 2. you want to reattach a previously attached SR, just "forgotten" with existing VDIs on it? 3. you want to format the whole SR despite it was previously attached elsewhere? Good news: we managed to deal with that. **Case number 1**: the SR already exists! You'll see a message with a red button, linked **directly** to your current SR. And you **can't** overwrite it (thus *Create* button is disabled) ![](https://xen-orchestra.com/blog/content/images/2015/03/sr_wrong.png) **Case number 2**: the SR was previously attached to a XenServer host. We can detect it. In this case, you have two choices: reattach the SR **or** overwrite it if you want to start from scratch. You'll have a warning message: ![](https://xen-orchestra.com/blog/content/images/2015/03/reattach_sr.png) **Case number 3**: Same than the previous one, but this time, just click on OK! ![](https://xen-orchestra.com/blog/content/images/2015/03/force_sr.png) ## New actions Creating SR is a thing. But remove them is another! That's why we also introduced new actions in a SR view: ![](https://xen-orchestra.com/blog/content/images/2015/03/sr_actions.png) You can now: - rescan all the VDI of a SR - reconnect or disconnect all hosts to this SR - forget the SR (disconnect and forget but don't do anything on the disk) - remove the SR (disconnect and "wipe" it) ## Release? Should be released in the same time than the 3.7, so in theory... tomorrow! ### Task management in XO URL: https://xen-orchestra.com/blog/task-management-in-xo/ Last updated: 2015-02-23T18:09:58.000Z In the next-release, we display all the current task executed in all your servers. ## Concepts XenServer handles tasks. Basically, it's useful to **track the progress of an ongoing action**, like: - a migration - a VDI migration - anyg asyn task which can be long ## Examples Our goal is to show you running tasks, in any page you currently are in XO. That's why we choose to put the task indicator in tha navigation bar. Right here: ![](https://xen-orchestra.com/blog/content/images/2015/02/task1.png) The menu is disabled where there isn't any running task. That's another story when, for example, I start a live migration within a pool: ![](https://xen-orchestra.com/blog/content/images/2015/02/task2.png) For sure, you will see a progress bar to check the status of the task: ![](https://xen-orchestra.com/blog/content/images/2015/02/task3.png) If you click on the progress bar, you'll be redirected to the host running the task, and you'll also see the progress in the dedicated panel: ![](https://xen-orchestra.com/blog/content/images/2015/02/task4.png) ### In video Let's recap with a VDI migration to illustrate task display (go in full screen if you want to see the original resolution): Your browser does not support the video tag. ## Conclusion Despite it's not really a big feature, adding tasks display is a step further for Xen Orchestra: it helps a lot to track a progress of any kind of task, anywhere in the application. And because all the application is 100% dynamic, it gives a real feedback of what's happening right now on your whole XenServer infrastructure. ### XO 4.x starts to show up URL: https://xen-orchestra.com/blog/xo-4-x-starts-to-show-up/ Last updated: 2015-02-20T17:29:20.000Z **ACLs, ACLs, ACLs!** That's the rallying cry of our community since a long time. But we had to do a lot of work before even think on it. But yes, we take this time: our [first draft](./blog/users-roles-in-xen-orchestra/) was created nearly 1 year ago! This *big* feature will be the start of our new branch: **the 4.x**! ### Concepts People (e.g sysadmins) want to delegate VMs to other users (e.g developers), because it helps a lot to reduce the workload for them. There is a ton of use cases for delegating resources to others: - could be inside (devs, devops, anyone who want to access its resources from a web browser) - or outside (clients!). That's not the only thing the community need: a **self-service portal** where you can create your VMs very easily is another requested possibility. #### First step: first feedbacks The first step is to provide a strong security model, right in the server `xo-server`, to avoid leaking any informations to the clients (`xo-web` or `xo-cli`). After that, we need to built around it our methods to connect to this model. And that's not the end! We also need to expose the features in the UI, to manage permission in your web browser. Our initial work authorize an admin to delegate permissions to a user for specific objects (VMs, Storage Repo, hosts etc.). This is where we are so far: - our security model is implemented in `xo-server` - we got a basic UI in `xo-web`, allowing an admin to authorize a user to see a specific object - when this user is connected, he/she can only see authorized objects (VMs for example), and these only! Here is actual video of this first step: - go to the ACL view - choose the user you want to give permissions - select the object he/she will see and interact with (you can see we got live search in the select form) Your browser does not support the video tag. Here is the workflow with screenshots: Go the the **Administration** view: ![](https://xen-orchestra.com/blog/content/images/2015/02/menu_acl.png) Select the **user**: ![](https://xen-orchestra.com/blog/content/images/2015/02/acl_user.png) Give him/her permission to see the object you want (in this case the VM **xoa basic**): ![](https://xen-orchestra.com/blog/content/images/2015/02/acl_object.png) Done. You can remove the permission by clicking on the trash icon: ![](https://xen-orchestra.com/blog/content/images/2015/02/acl_overview.png) That's it! **demo** user will only see the VM **xoa basic** and nothing else. After some feedback of our users, we should be able to go to the second step! But how to have a nice feedback? - We'll start with a private **beta** with our existing clients, **TODAY**! - Quickly after that, we'll offer **XOA Enterprise** on our web site, in a **Early Access** mode to everyone registering. #### 2nd step: complete ACLs This time, the goal is to provide a better way to organize your permissions: groups, roles (respectively set of people and set of permissions) for objects. And finally, group of objects, aka VMs/SR/hosts etc. It should allow a great flexibility without increasing the complexity. This also should be the step of connecting these ACLs to an **external directory** (Open LDAP or AD). #### 3rd step: self service We'll probably create a specific permission, called "self-service", allowing those specific users to create themselves some VMs on designated hosts or pools. The current strategy in not very clear yet, but we'll have enough feedback from the previous steps to do that properly! #### 4th step: quotas The last one is about to restrict users to drain too much resources from your hosts and pools, buy giving them quotas for each (e.g: vCPUs, RAM, Disk space, VIFs etc.) ## When? As I said previously, the first private Beta started to be sent to our existing clients. The **official** early access will be available **NEXT WEEK**! Hang on ;) ### XO Forum switched to NodeBB URL: https://xen-orchestra.com/blog/xo-forum-switched-to-nodebb/ Last updated: 2015-02-05T19:42:14.000Z Hi everyone! Because EsoTalk is [no longer updated](http://esotalk.org/blog/faq.html?ref=xen-orchestra.com), we switched to [NodeBB](https://nodebb.org/?ref=xen-orchestra.com). The new forum is [accessible here](https://xen-orchestra.com/forum?ref=xen-orchestra.com). The good news: you [can login](https://xen-orchestra.com/forum/login?ref=xen-orchestra.com) with your existing **GitHub**, **FaceBook** or **Twitter** accounts! Very useful :) Finally, because there is a LOT of interesting topics [on the old forum](https://xen-orchestra.com/oldforum?ref=xen-orchestra.com), **it won't be removed** for a while. But you can't register here anymore. ### XO Console from everywhere! URL: https://xen-orchestra.com/blog/xo-console-from-everywhere/ Last updated: 2015-10-26T11:18:34.000Z The ability to access any VM or host console is not new in Xen Orchestra. It works almost from the beginning (well, sometimes with [somes glitches](https://xen-orchestra.com/blog/xen-orchestra-3-2/)). You can see an example here: ![](https://xen-orchestra.com/blog/content/images/2015/10/xenception.png) Let's recap the global architecture to have a better understanding: ![](https://xen-orchestra.com/assets/xoarch.png) Since the start, it works like that (let's call this "the XAPI's way"): - `xo-web` (your browser) asks the console to `xo-server` (the XO daemon) - `xo-server` asks to XAPI URL of the VM console - `xo-server` sends the VM console URL to `xo-web` - `xo-web` connects directly to this VM with noVNC And thus, lead to these problems: - XAPI only exposes plain communication (no encryption for websockets): that's why HTTPS in XO and console were incompatible, like explained [in this issue](https://github.com/vatesfr/xo/issues/14?ref=xen-orchestra.com). - Consoles can't work outside the network (e.g NAT, `xo-server` will send a private class IP address to your `xo-web` which is outside: it will fail). Reported [in this issue](https://github.com/vatesfr/xo-web/issues/117?ref=xen-orchestra.com). - And finally, it was a securiry concern: currently we expose the session identifiers used to connect to pools to `xo-web`, this can able any users to access any connected servers. Exactly the problems was also reported in our forum, [here](https://xen-orchestra.com/forum/94-external-console-viewing?ref=xen-orchestra.com), [here](https://xen-orchestra.com/forum/123-console-xo-don-t-open?ref=xen-orchestra.com) or [here](https://xen-orchestra.com/forum/212-proxy-vnc-console?ref=xen-orchestra.com). That's why, building a "console proxy" through `xo-server` was in the top of our [roadmap](https://github.com/vatesfr/xo/blob/master/roadmap.md?ref=xen-orchestra.com#xen-orchestra-roadmap)! In this case, you can use `xo-server` to expose all your XenServers, even if they are behind a NAT, without any problem to display their VM consoles! It's also secure, because token are kept right in `xo-server`and never sent to the client. ## And... it's done! We just managed to do that proxy [thanks to](https://github.com/vatesfr/xo-web/commit/929fce6adba6668f7feb38e1b66fe710fbd00452?ref=xen-orchestra.com) [these](https://github.com/vatesfr/xo-server/commit/b73de087d2f40856b0c1777e75fbc911d8162bcc?ref=xen-orchestra.com) [commits](https://github.com/vatesfr/xo-web/commit/c0a5e9fdccc7d9d632a51b6aa5c29e33d969731b?ref=xen-orchestra.com), it's currently in the `next-release` branch for further tests, but will be in the **3.7**, which will be out soon! ### XO at FOSDEM15: summary URL: https://xen-orchestra.com/blog/xo-at-fosdem15-summary/ Last updated: 2015-02-06T10:15:09.000Z The FOSDEM is a really nice event, and this year was very successful: a **BIG** crowd and always an excellent atmosphere! ## Xen booth Thanks to the Xen Team, I've got the opportunity to present Xen Orchestra on the stand both days. I can tell you that a lot of people were interested by some of the [Xen Orchestra features](https://xen-orchestra.com/features.html?ref=xen-orchestra.com). ![A live XO demo on the Xen Booth](https://xen-orchestra.com/blog/content/images/2015/02/1379692_10205658704095271_3786259591628129045_n.jpg) It was also the occasion to have very interesting discussions with the Xen team: ARM stuff, OpenStack and XenServer were on the menu: the **Xen ecosystem is very healthy!** ## My talk The slides of my talk are accessible [right here](https://cloud.vates.fr/public.php?service=files&t=b49efa431aad1b05263aea734ee40db4&download&ref=xen-orchestra.com). The video will be available as soon the FOSDEM team release it :) I would say around 150+ people for the talk, which is not bad compared from two years ago! ## So what's new? The main stuff to know is about ACL's: we'll release a first basic implementation soon, maybe this week! Stay tuned ;) ### GHOST Vulnerability URL: https://xen-orchestra.com/blog/ghost-vulnerability/ Last updated: 2015-01-28T20:07:15.000Z You probably have heard of the GHOST vulnerability aka [CVE-2015-0235](http://www.openwall.com/lists/oss-security/2015/01/27/9?ref=xen-orchestra.com). This one impact the glibc, which is running on XenServer. But is it dangerous for your hosts? ### What it is all about You can read more details on [this excellent blog post](http://ma.ttias.be/critical-glibc-update-cve-2015-0235-gethostbyname-calls/?ref=xen-orchestra.com). Basically, a `gethostbyname()` call can be triggered with any kind of DNS resolving stuff. So, what are the attack vectors on a XenServer host? ### Small attack surface XenServer privilegied domain (dom0) is **built to offer the smallest attack surface**. That's also why it's a best practice to let your dom0 *as is* after the install. The Citrix official statement so far is: > Analysis into the impact of this issue on XenServer is in progress. XenServer does include a vulnerable version of glibc but at present there is no known route by which a guest virtual machine would be able to invoke the vulnerable functionality through the hypervisor interface. Analysis of this is still in progress and this section will be updated when additional information is available. Source: [http://support.citrix.com/article/CTX200391](http://support.citrix.com/article/CTX200391?ref=xen-orchestra.com) I believe myself there is nothing dangerous here, but I'll keep you posted. So, what do you have to do: ![](https://xen-orchestra.com/blog/content/images/2015/01/Keep-calm-and-carry-on-scan.jpg) ### Update your VMs **Hey, but don't forget to update all your guests!** RedHat and its derivatives (CentOS etc.) with: ```bash $ yum update ``` Debian and co (Ubuntu etc.) with: ```bash $ apt-get update && apt-get upgrade ``` Oh, and if you are using *[SaltStack](http://saltstack.com/?ref=xen-orchestra.com)* (like me), just do a: ```bash $ salt '*' pkg.upgrade ``` And all your VMs are magically updated! You can also verify which services are using the `glibc` with: ```bash $ lsof | grep libc | awk '{print $1}' | sort | uniq ``` Restart all these services! ![](https://xen-orchestra.com/blog/content/images/2015/01/resized_all-the-things-meme-generator-restart-all-the-services-97b657.jpg) ### XO team at FOSDEM 15 URL: https://xen-orchestra.com/blog/xo-team-at-fosdem-15/ Last updated: 2015-01-26T11:08:28.000Z Hi everyone! If you are in Europe, come to see us at the [FOSDEM](https://fosdem.org/2015/?ref=xen-orchestra.com)! ## Xen Orchestra on Xen booth Like the [previous year](https://blog.xenproject.org/2014/02/07/xen-fosdem14-an-even-report/?ref=xen-orchestra.com), we'll be at the Xen booth. You'll see a live demo of XO and can get it touch with our roadmap. Our schedule: - Saturday, 13:00 - 14:30 - Sunday, 11:30 - 13:00 ![](https://xen-orchestra.com/blog/content/images/2015/01/20140202_100927_good.jpg) ## XO Talk If you want to know more about the project itself, don't miss [my talk](https://fosdem.org/2015/schedule/event/xorchestra/?ref=xen-orchestra.com), **Sunday at 15:00 in the Virtualization DevRoom** (UD2.120 Chavanne). **See you there!** ### Debian 8 Jessie on XenServer 6.5 URL: https://xen-orchestra.com/blog/debian-8-jessie-on-xenserver-6-5/ Last updated: 2015-08-11T15:07:58.000Z Just after the [fresh release](https://xen-orchestra.com/blog/xenserver-6-5-is-out/) of [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver?pk%5Fcampaign=blog%5Fjessie) 6.5, and maybe an [upgrade](https://xen-orchestra.com/blog/migrate-from-xenserver-6-2-to-6-5/) from 6.2, we'll start to enjoy the new possibilities! The first one is to install Debian 8 (Jessie) without any glitches. For those who tried on 6.2 and before, you know the deal: **you can't boot** your VM, due to an old version of **pyGrub** (used to read your VM Grub configuration and boot the PV domain). It's explained in [this post](http://discussions.citrix.com/topic/330126-pygrub-shipped-with-xenserver-61-still-lacks-lzma-xz-support/?ref=xen-orchestra.com), on the official Citrix forum. The workaround was to create a HVM guest.. or to wait for the next release of XenServer! Let's see now if this 6.5 solves the problem! ## Creating the VM For this tutorial, **we are using the web interface [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fjessie) to install this VM**. Do not hesitate to take a look on the [features page in video](https://xen-orchestra.com/!?ref=xen-orchestra.com#/features?pk%5Fcampaign=blog%5Fjessie), it could be relevant for your needs. First, let's go to the VM creation page by clicking on *Create VM*: ![](https://xen-orchestra.com/blog/content/images/2015/01/vmcreate0.png) You can choose the template **Debian Wheezy 7.0 (64-bit)**, it doesn't matter, because we'll use the last ISO of Debian Jessie [available here](https://www.debian.org/devel/debian-installer/?ref=xen-orchestra.com). Choose the name and description you want: ![](https://xen-orchestra.com/blog/content/images/2015/01/vmcreate.png) Now, click on *Create VM*: ![](https://xen-orchestra.com/blog/content/images/2015/01/vmcreate2.png) You're done! ## Installation Classic: choose the language, keymap and answer other questions given by the Debian installer. As you can see, we are doing everything in [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fjessie), directly in the console view. Note the presence of the ISO loaded on the top: ![](https://xen-orchestra.com/blog/content/images/2015/01/debianinstall.png) When it's done (rebooted and without the install CD mounted), the system is fully operational: ![](https://xen-orchestra.com/blog/content/images/2015/01/debianinstall2.png) ## XenServer tools Now, it's time to install the XS tools: this program is a daemon getting more metrics in your guest system, and send them to your host. Just mount the **xs-tools.iso** in the console view: ![](https://xen-orchestra.com/blog/content/images/2015/01/xstools1.png) Then: - mount the CD in the system with a `mount /dev/cdrom /mnt` - install the agent with `dpkg -i /mnt/Linux/xe-guest-utilities_6.5.0-1393_amd64.deb` - unmount the CD with `umount /mnt` **That's it!** ### Migrate from XenServer 6.2 to 6.5 URL: https://xen-orchestra.com/blog/migrate-from-xenserver-6-2-to-6-5/ Last updated: 2015-08-11T14:57:41.000Z Since Citrix [XenServer 6.5 is out](https://xen-orchestra.com/blog/xenserver-6-5-is-out/), you can start to migrate your existing installations of [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver?pk%5Fcampaign=blog%5Fmigrate) 6.2. You'll see, it's very easy, and you can do it without any service interruption! > **All the screenshots are from [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fmigrate)** web interface, a solution to manage all your XenServer's from a web browser. Do not hesitate to take a look on the videos in the [features page](https://xen-orchestra.com/!?ref=xen-orchestra.com#/features?pk%5Fcampaign=blog%5Fmigrate). ## Pre-flight check We'll use a **real example** of our Lab migration from 6.2 to 6.5\. Here is the overview: ![](https://xen-orchestra.com/blog/content/images/2015/01/overview.png) As you can see, we've got a *Lab Pool* with two hosts (*lab1* and *lab2*). First, you need to disable [High-Availability](https://xen-orchestra.com/blog/xenserver-and-vm-high-availability/) if any, with a `xe pool-ha-disable` for example. To do a proper upgrade, you need to start with the current *pool master*. Migrate all its running VM to other hosts on the pool, in two steps: 1/ Select automatically all VM on *lab1* (which is the *pool master*): ![](https://xen-orchestra.com/blog/content/images/2015/01/migrate1.png) 2/ Click on migrate on *lab2*: ![](https://xen-orchestra.com/blog/content/images/2015/01/migrate2.png) Done! Migration started: ![](https://xen-orchestra.com/blog/content/images/2015/01/migrate3.png) And finished: ![](https://xen-orchestra.com/blog/content/images/2015/01/migrate4.png) *lab1* is clear to go for an upgrade! If you need to migrate to another pool or a host without any shared storage, consider using [Xen Storage Motion](https://xen-orchestra.com/blog/cross-pool-migration-with-xo/), or move the VDI to a [shared SR](https://xen-orchestra.com/blog/moving-vdi-in-live/). Another possibility: put your VM in a [suspend state](https://xen-orchestra.com/blog/xo-action-reaction/#suspending). ## Upgrade process The upgrade process is very easy (nice job from Citrix guys!): - put the CD - restart your host and boot on the CDROM drive (you have also other possibilities, like HTTP install etc.). - the installer will ask to **Upgrade** from your existing version, or to *Reinstall*. As you might have guessed, choose **Upgrade from XenServer 6.2**. Nothing special to see here, the installer will take time to do things nicely (5/10 minutes), because: - configuration is preserved (configured SR in iSCSI, NFS or whatever) - it works out of the box, that's all! Finally, when the installer tells you, remove the CD and reboot. **You're done!** ## Without any service interruption Well, now you have to do live migrations exactly in the other way, from *lab2* (with XenServer 6.2) to *lab1* (with XenServer 6.5). Piece of cake, because it supports live migration from an older XenServer to a new one: ![](https://xen-orchestra.com/blog/content/images/2015/01/reverse1.png) Migration is done, *lab2* is empty, ready to be upgraded: ![](https://xen-orchestra.com/blog/content/images/2015/01/reverse2.png) After the upgrade and the reboot of *lab2*, your pool is finally operational with XenServer 6.5! # Conclusion You can perform a complete pool migration from 6.2 to 6.5 without any VM shutdown! No excuses, do it ;) The team behind XenServer made a fantastic job with their simple installer. If you want to learn more about the neat interface showed in the examples, don't forget to [check the feature page of Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/features?pk%5Fcampaign=blog%5Fmigrate), the web interface for managing [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver?pk%5Fcampaign=blog%5Fmigrate). ### XenServer 6.5 is out! URL: https://xen-orchestra.com/blog/xenserver-6-5-is-out/ Last updated: 2015-01-13T13:26:04.000Z Needless to say: this new version of XenServer was eagerly awaited! There is a lot of new interesting stuff, and we'll explore this in multiple articles. Let's start with an overview. The official announcement [is here](http://blogs.citrix.com/2015/01/13/xenserver-6-5/?ref=xen-orchestra.com) and you can **download it** [on this link](http://downloadns.citrix.com.edgesuite.net/akdlm/10175/XenServer-6.5.0-xenserver.org-install-cd.iso?ref=xen-orchestra.com)! ## What's new ### Performances See four yourself: ![](http://cdn.ws.citrix.com/wp-content/uploads/2015/01/xs65perfsm.png) For sure, we'll do benchmarks on our side :) ### Specs - 64 bit dom0 - Linux 3.10 kernel - **Xen 4.4** - Open virtual switch 2.1.3 - Boot storm handling improvements by using read caching - Read caching for file based SRs - TRIM and UNMAP for better storage reclaim - 32 bit to 64 bit VM migration - Storage migration from XenServer 6.2 and prior - SLES 11 SP3 support - Ubuntu 14.04 LTS support - Network, Storage and vGPU Improvements And it solves an annoying bug with Debian Jessie and other modern Grub version with LZMA kernels, as explained [here](http://discussions.citrix.com/topic/330126-pygrub-shipped-with-xenserver-61-still-lacks-lzma-xz-support/?ref=xen-orchestra.com) and [here](https://xen-orchestra.com/blog/testing-xenserver-6-2-5-beta/). The complete release notes are [available here](http://support.citrix.com/servlet/KbServlet/download/38334-102-714582/XenServer-6.5.0-releasenotes.pdf?ref=xen-orchestra.com). ## Compatibility with Xen Orchestra As a curcial release, we made tests every months with each new beta/RC to verify if it works. And as you may read on Twitter, **it works out of the box!** > Installing the latest [#xenserver](https://twitter.com/hashtag/xenserver?src=hash&ref=xen-orchestra.com) RC with [#xenorchestra](https://twitter.com/hashtag/xenorchestra?src=hash&ref=xen-orchestra.com)! [#inception](https://twitter.com/hashtag/inception?src=hash&ref=xen-orchestra.com) [pic.twitter.com/X7lpqD15IN](http://t.co/X7lpqD15IN?ref=xen-orchestra.com) > > — Vates (@vatesfr) [19 Décembre 2014](https://twitter.com/vatesfr/status/545951135568498688?ref=xen-orchestra.com) > And it works! 5 min later, you got [#xenserver](https://twitter.com/hashtag/xenserver?src=hash&ref=xen-orchestra.com) last RC running in [#xenserver](https://twitter.com/hashtag/xenserver?src=hash&ref=xen-orchestra.com) 6.2, installed with [#xenorchestra](https://twitter.com/hashtag/xenorchestra?src=hash&ref=xen-orchestra.com) [pic.twitter.com/mbMbOwHeTp](http://t.co/mbMbOwHeTp?ref=xen-orchestra.com) > > — Vates (@vatesfr) [19 Décembre 2014](https://twitter.com/vatesfr/status/545953562392801280?ref=xen-orchestra.com) ## Next We'll make soon extensive tests to provide benchmarks, tips and other useful feedback. Stay tuned! ### XO Action-reaction URL: https://xen-orchestra.com/blog/xo-action-reaction/ Last updated: 2015-01-12T13:31:04.000Z Or the importance of community feedback. This is a small story about why we love to do Open Source software and to have a community. ## Obvious facts We believe it's impossible to imagine every features people want from a product, a this is also true for Xen Orchestra. Despite I was the first "client" of the project (hey, remember I started this in 2009 to find on which hosts are my VMs), remember that: **you can't beat hundreds of brains working together**. That's the power of Open Source ! ## Examples Here is two examples, very easy to implement, but important for some of our users. ### Free space Because now [you can move a VDI of a running VM](https://xen-orchestra.com/blog/moving-vdi-in-live/) or during the VM creation process, you maybe want to know without searching how many space left on your targeted Storage Repository. That's exactly what [hoerup](https://github.com/hoerup?ref=xen-orchestra.com) ask us on [our repository](https://github.com/vatesfr/xo-web/issues/180?ref=xen-orchestra.com)! And as you can see, in the same day, we delivered! ![](https://xen-orchestra.com/blog/content/images/2015/01/new-feature.png) ### Suspending This time, it was about suspending VMs. This state is like hibernating your laptop: RAM is saved and you can shutdown all your hosts. When you resume your suspended VMs, they are restored with their contexts/sessions/RAM etc. This [was asked](https://github.com/vatesfr/xo/issues/34?ref=xen-orchestra.com) by [uweschaefer](https://github.com/uweschaefer?ref=xen-orchestra.com) this time. And we delivered today! In the VM view: ![](https://xen-orchestra.com/blog/content/images/2015/01/suspend0.png) In the main view, allowing to suspend/resume multiple VMs in one click: ![](https://xen-orchestra.com/blog/content/images/2015/01/suspend2.png) ## Conclusion For sure, a good Open Source project need to have a community, but also the capacity to release often. That's why we'll publish a new release at the end of this month. Stay tuned! ### XO team: reinforcement have arrived URL: https://xen-orchestra.com/blog/xo-team-reinforcement-have-arrived/ Last updated: 2015-01-08T10:17:13.000Z Happy new year! We are happy to announce the arrival of a new developer in the Xen Orchestra team! [Fabrice](https://www.linkedin.com/profile/view?id=38822478&ref=xen-orchestra.com) is a passionate developer giving a strong focus on code quality. His experience and capacity to release on time will be a real asset for us. As you can see, there is a real ramp-up in our resources dedicated to XO: our objective is to be **100%** on it for this whole year! Stay tuned for other news, we'll be at the [FOSDEM 14](https://fosdem.org/2015/?ref=xen-orchestra.com) with a new feature in beta ;) ### Moving VDIs in live URL: https://xen-orchestra.com/blog/moving-vdi-in-live/ Last updated: 2015-01-05T14:43:55.000Z We just added a useful feature in the `next-release` brach: the possibility to move a VDI (disk) from a storage repository to another when the VM is running. Here is how it works (remember the VM is currently **running**): First, click on the Edit icon in the Disk panel: ![](https://xen-orchestra.com/blog/content/images/2015/01/vdi1.png) As you can see, the current disk (named "*Docker*") is currently on "*Local Storage*" SR. We want to move it on another one. We selected "*ZFS*" (our iSCSI storage running ZFS)... ![](https://xen-orchestra.com/blog/content/images/2015/01/vdi2.png) And then validate the choice: ![](https://xen-orchestra.com/blog/content/images/2015/01/vdi3.png) The operation takes times (depending of the disk size). You can see the operation running in the main view: the VM dot having its VDI moving is in orange (with a tooltip), as you can see in this screenshot: ![](https://xen-orchestra.com/blog/content/images/2015/01/vdi4.png) ### New releases of XO 3.6 URL: https://xen-orchestra.com/blog/new-releases-of-xo-3-6/ Last updated: 2014-12-01T11:28:28.000Z We're back! And with a lot of new features and bugfixes. The list of new possibilities is pretty extensive (see below). ![](https://xen-orchestra.com/blog/content/images/2014/Nov/screenshot1.png) We are also excited about 2015: a new developer is coming in January and we'll be fully dedicated on Xen Orchestra, thus running at full speed for the whole year. Available in [**XOA Starter**](https://xen-orchestra.com/blog/xoa-starter-beta): - [VM import and export](https://xen-orchestra.com/blog/vm-import-and-export-incoming-in-xo/) - [Snapshot export](https://xen-orchestra.com/blog/snapshot-export-with-xen-orchestra/) - [Patch upload and apply (pool wide)](https://xen-orchestra.com/blog/patch-your-xenserver-with-xen-orchestra/) And for everyone: - [Live Storage migration](https://xen-orchestra.com/blog/cross-pool-migration-with-xo/) - [Wake on LAN directly in the web interface](https://xen-orchestra.com/blog/how-to-use-wake-on-lan-on-xenserver-6-2/) - [Display patches for a host](https://xen-orchestra.com/blog/patch-your-xenserver-with-xen-orchestra/) - [High availability controls for VMs](https://xen-orchestra.com/blog/xenserver-and-vm-high-availability/) - Possibility to plug or unplug SR to their hosts (and reconnect to all host in one click) - Better UI for managing snapshots, logs etc. - Better feedback when starting an action - Remove useless buttons - Disk editing (name, description) You can read the [complete changelog here](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#360-2014-11-28). ## Download As you may read in the title, we wrote "New releaseS". Because we released 2 things: - [XOA Starter Beta](https://xen-orchestra.com/beta.html?pk%5Fcampaign=blog1&ref=xen-orchestra.com): we officially released XOA Starter in Beta version. This XOA version contains **unlimited support** \+ VM Import and Export mechanism + Patching + Snapshot export. Check [our article to know more](https://xen-orchestra.com/blog/xoa-starter-beta) about the beta program and why we are starting it now. - XOA Basic: latest version of Xen Orchestra in a ready to roll appliance. It will give you a nice look of what you can do in it. **It's totally free!** You can download it through the [main page of our website](https://xen-orchestra.com/?pk%5Fcampaign=blog1&ref=xen-orchestra.com) (the form with "Download now" in red) - From the sources: do you want to install it manually from the sources? [Go ahead](https://github.com/vatesfr/xo?ref=xen-orchestra.com), it's Open Source! ### XOA Starter Early Access URL: https://xen-orchestra.com/blog/xoa-starter-early-access/ Last updated: 2015-02-27T12:03:55.000Z We are proud to announce the Early Access release of Xen Orchestra Appliance "Starter" Edition! Why we release a early access version ? In fact, **all the features are tested**, not the whole process around the product. But: - We want to have the most feedback possible and as soon as we can. That's the [way of lean](http://en.wikipedia.org/wiki/Lean%5Fstartup?ref=xen-orchestra.com). - We want to offer you the best service, and it's only possible with this invaluable experience we'll share. What will I get in this version? - Shipped with the corporate support, you'll have the opportunity to **report your bugs privatly** thanks to our dedicated support system. - Exceptionally, as a Early Access, we'll **NOT LIMIT** the number of possible tickets per month. Report as much as you need! - You **wont't have any commitment period**. You can start with only one month if you like and unregister just after. - You'll enjoy **Patch upload, VM Import and Export and Snapshot Export** combined with our **unlimited corporate support**. - The release process will be shorter, so you'll have cutting edge version and the opportunity to give your voice about it. What are the missing features? - **None**. We have all the feature announced in the price plan. Early Access is **about the whole process** (registration, support) and for finding bugs in a larger scale. Any drawbacks? - Because it's a pre-release, we'll probably release versions without upgrade process. You'll probably have to re-download a new version when needed. So, what are you are waiting for? [Go subscribe to the early access now!](https://xen-orchestra.com/pricing.html?ref=xen-orchestra.com) ### Snapshot export with Xen Orchestra URL: https://xen-orchestra.com/blog/snapshot-export-with-xen-orchestra/ Last updated: 2014-11-24T14:39:39.000Z Since this year, XO is fully capable of managing VM snapshots. But now, thanks to the VM export capability with XO 3.6, you can also export snapshots! Why export snapshots? Let's imagine you want to restore an old snapshot without rollback the curent VM. It's now possible in 2 clicks. ## Snapshots management Click on the VM you want to deal with, you'll see this button: ![](https://xen-orchestra.com/blog/content/images/2014/Nov/snap1.png) It will create a snapshot with a timestamped name. You can rename it as you like by editing the snapshot pane. ## Export the snapshot in XVA And now, you just have to click on the export button corresponding on the snapshot you want to export. XO will send you a \*.XVA file, which can be later imported (creating a new VM): ![](https://xen-orchestra.com/blog/content/images/2014/Nov/snap2.png) ### Patch your XenServer with Xen Orchestra URL: https://xen-orchestra.com/blog/patch-your-xenserver-with-xen-orchestra/ Last updated: 2014-11-24T15:32:13.000Z In the 3.6 release, XO is able to send patches to your server. We'll see how it works, from any browser and device. ## Patches in XenServer You can download patches for XenServer [on this page](http://www.xenserver.org/overview-xenserver-open-source-virtualization/download.html?ref=xen-orchestra.com). Every patch is a \*.zip file, you need to exctract it. When it's done, you should have a \*.xsupdate file. This file is the one you will send to Xen Orchestra to patch your pool. ## Upload patches with Xen Orchestra You just have to go on the main page, then click on the pool you want to upload patch (in the next screenshot, a pool named "Lab Pool"), and select "Patch" in the dropdown menu: ![](https://xen-orchestra.com/blog/content/images/2014/Nov/patch1.png) It will open a file selector in your browser, and select the xsupdate file and click on "Open": ![](https://xen-orchestra.com/blog/content/images/2014/Nov/patch2.png) You'll see a notification about the upload progress, then all your servers in your pool will be automatically patched. **That's all!** ## Check installed patches You can check which patches are installed/applied on each host. Go on any host in Xen Orchestra, and in the bottom, you'll see a list of patches: ![](https://xen-orchestra.com/blog/content/images/2014/Nov/patch3.png) ## What's next? Another cool feature could be the possitibity to send a patch to EVERY pools connected to XO. Not a big deal, we putted this idea as [an issue in our repository](https://github.com/vatesfr/xo-web/issues/168?ref=xen-orchestra.com). ### Understand XenServer VM High availability URL: https://xen-orchestra.com/blog/xenserver-and-vm-high-availability/ Last updated: 2017-10-31T00:33:40.000Z This article in a introduction to the VM HA mechanism in [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver?pk%5Fcampaign=blog%5Fha). Implementing VM High availability is a real challenge: first because you need to reliably detect when a server has **really** failed to avoid unpredictable behavior. But that's not the only one. If you lose the network link but not the shared storage, how to ensure you will not write simultaneously on the storage and thus corrupt all your data? That's why **XenServer is an awesome product** (as its API, the XAPI): it handles flawlessly that kind of stuff. We'll see how to protect your precious VM in multiple cases, and we'll illustrate that with real examples. ## How it works The pool concept allows hosts to exchange their data and status: - if you lose a host, it will be detected by the pool master. - if you lose the master, another host will take over the master role automatically. To be sure a host is really unreachable, HA in XenServer uses multiple heartbeat mechanisms. As you saw in the introduction, just checking the network isn't enough: what about the storage? That's why there is also a specific heartbeat for shared storage between hosts in a pool. In fact, each host regularly write some blocks in a dedicated VDI. That's the principle of the [Dead man switch](http://en.wikipedia.org/wiki/Dead%5Fman%27s%5Fswitch?ref=xen-orchestra.com). This concept is important, and it explains why you need to **configure HA with a shared storage** (iSCSI, Fiber Channel or NFS) to avoid simultaneous writing in a VM disk. Here is the possibles cases and their answers: - **lost both network and storage heartbeat**: host is considered unreachable, HA plan is started - **lost storage but not network**: if the host can contact majority of pool members, it can stay alive. Indeed, in this scenario, there is no harm for the data (can't write to the VM disks). If the host is alone, i.e can't contact any other host or less than the majority, it decides to go for a reboot procedure. - **lost network but not storage (worst case!)**: the host considers itself as problematic, and start a reboot procedure (hard poweroff and restart). This fencing procedure guarantee the sanity of your data. ## Configuration In this example, we'll have a pool **Lab pool** with 2 hosts, **lab 1** and **lab 2**. ### Prepare the pool You can check if your pool have HA enable or not. In [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver?pk%5Fcampaign=blog%5Fha), you just have to click on a pool name in order to go on a Pool view. The *General* pane displays the HA status, in this case, HA is disabled: ![](https://xen-orchestra.com/blog/content/images/2014/Nov/ha-false.png) You can enable it with this xe CLI command: `$ xe pool-ha-enable heartbeat-sr-uuids=` Remember that you need to use a shared SR. Now, it will display `true` for HA: ![](https://xen-orchestra.com/blog/content/images/2014/Nov/ha-true.png) #### Maximum host failure number Now, you have to think: how many host failures you can tolerate before running out of options? For 2 hosts in a Pool, the answer is pretty simple: **1** is the maximum number. Why? Well, after loosing one host, it will be impossible to ensure a HA policy of the last one also fails. This value can be computed by XenServer, and in our example case: ``` $ xe pool-ha-compute-max-host-failures-to-tolerate 1 ``` But it could be also **0**. Because even if you lose 1 host, is there not enough RAM to boot the HA VM on the last one? If not, you can't ensure their survival. If you want to set the number yourself, you can do it with this command: `$ xe pool-param-set ha-host-failures-to-tolerate=1 uuid=` When you have more hosts failed that this number, a system alert is raised: you are in a **over-commitment** situation. ### Configure a VM for HA This is pretty straightforward with Xen Orchestra. Go on your VM page, then edit the *General* panel: you just have to tick the HA checkbox and click on *Save*. ![](https://xen-orchestra.com/blog/content/images/2014/Nov/vm_ha2.png) Note: This feature is coming for the next release, but it's already working in our lab. You can also do that configuration with *xe CLI*: `$ xe vm-param-set uuid= ha-restart-priority=restart` ## Behavior ### Halting the VM If you decide to shutdown the VM with *Xen Orchestra*, *XenCenter* or *xe*, the VM will be stopped normally, because XenServer knows that's what you want. But if you halt it directly in the guest OS (via the console or in SSH), XenServer is NOT aware of what's going on. For the system, it seems the VM is down and that's an anomaly. So, the VM will be **started automatically!**. This behavior prevent an operator to shutdown the system and leave the VM unavailable for a long time. ### Host failure We'll see 3 different scenarios on the host **lab1**: - physically "hard" shutdown the server - physically remove the storage connection - physically remove the network connection **lab1** is not the *Pool Master*, but the results would be the same (just longer to test because of time to the other host becoming the master itself). Let's stay in our example of 2 hosts in a single pool. I configured the VM **Minion 1** for HA, and this VM is running on the host **lab1**. ![](https://xen-orchestra.com/blog/content/images/2014/Nov/ha_example1.png) After each test, **Minion 1** go back to **lab1** to start in the exact same conditions. #### Pull the power plug Now, I decide to pull the plug for my host **lab1** (true story, it's a Lab after all). This is exactly where is my VM. After sometimes (when XAPI detect and report the lost of the host), we can see that **lab1** is reported as Halted. In the same time, the VM **Minion 1** is booted on the other host running, **lab 2**: ![](https://xen-orchestra.com/blog/content/images/2014/Nov/ha_example2.png) Congrats! Despite the total loss of a host, you have nothing to do for the protected VM! I decide to re-plug the host **lab1**. Just after it booted, it's back in the business with no VM running on it, which is perfectly normal: ![](https://xen-orchestra.com/blog/content/images/2014/Nov/ha_example3.png) #### Pull the storage cable Ok, so let's try another scenario. This time, I will unplug the iSCSI link on **lab1**, despite **Minion 1** is running on it. So? **Minion 1** lost access to its disks ad after some time, **lab1** saw it can't access the heartbeat disk. Fencing protection is activated! The machine is rebooted, and after that, any `xe CLI` command on this host will give you that message: ``` The host could not join the liveset because the HA daemon could not access the heartbeat disk. ``` Immediatly after fencing, **Minion 1** will be booted on the other host: ![](https://xen-orchestra.com/blog/content/images/2014/Nov/ha_example2.png) Note: **lab1** is not physically halted, you can access it through SSH. But from the XAPI point of view, it's dead. Now, let's try to re-plug the ethernet cable... and just wait! Everything will back to normal: ![](https://xen-orchestra.com/blog/content/images/2014/Nov/ha_example3.png) #### Pull the network cable Finally, the worst case: leaving the storage operational but "cut" the (management) network interface. Same procedure: unplug physically the cable, and wait... Because **lab1** can't contact any other host of the pool (in this case, **lab2**), it decides to start the fencing procedure. The result is exaclty the same as the previous test. It's gone for the pool master, displayed as "Halted" until we re-plug the cable. ## Conclusion As you can see, [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver?pk%5Fcampaign=blog%5Fha) provides a powerful solution for high availability. We'll see more possibilities in a future article (about the restart policy and boot order). Comments are welcome if you have any questions or suggestions. Oh, and if you want to take a look at [Xen Orchestra features in videos](https://xen-orchestra.com/!?ref=xen-orchestra.com#/features?pk%5Fcampaign=blog%5Fha), follow the link ;) ### Xen security and XSA-108 URL: https://xen-orchestra.com/blog/xen-security-and-xsa-108/ Last updated: 2014-10-02T15:11:09.000Z You may have heard about Amazon or Rackspace rebooting some of their instances few days ago. It was known as a consequence of Xen Security Advisory number 108, aka XSA-108. **Update**: the article is updated with more details and a correction about the amount of memory that could be read and privilege escalation. **Update 2**: Xen Project Security Team [release a very precise article](https://blog.xenproject.org/2014/10/02/xsa-108-additional-information-from-the-xen-project-2/?ref=xen-orchestra.com) on XSA-108\. A must read if you want to know the details! ## What it is XSA-108 is also named "Improper MSR range used for x2APIC emulation". You can read more on the [official announcement here](http://xenbits.xen.org/xsa/advisory-108.html?ref=xen-orchestra.com). It affects only x86 architecture. In short, if someone has administrator access to a guest (any DomU) running in HVM, he (or she) could crash the host or read ~~any part~~ **some random part** of the memory (up to 3KiB). This memory could be from another guest or the hypervisor itself. That's why VPS vendors were very quick to deal with this problem. If **combined** with recent Bash security issue (*shellshock*), an attacker without any rights, could first get administrator access to a guest, and afterwards use XSA-108. But to be clear, XSA-108 alone needs elevated guest OS privileges. Bonus question: - is PV guest impacted? **No** - is PVHVM impacted? **Yes**. ## How Xen people deal with security Because Xen is used on major clouds on earth, the Xen team is **very** attentive to security concerns. They have a process well documented about their security policy (which [you can read here](http://www.xenproject.org/security-policy.html?ref=xen-orchestra.com)). ### XSA list You can see anytime the list of XSA on [this web page](http://xenbits.xen.org/xsa/?ref=xen-orchestra.com). Please not time are given in **UTC**. ### But why Amazon know before me? Because sometimes an advisory can be embargoed, due to its sensitive nature. Exactly like XSA-108! In this case, you need to be in the *pre-disclosure list*. It's well explained in the Xen security policy, but in short, you can apply if you want. Your application will be reviewed, depending on various standards (read the fine manual if you want to know more). That's why Amazon and Rackspace (among others) were informed before the public statement. ## Patching ### Packaged Xen (Debian, CentOS) Fix are already available, just run an upgrade from your favorite package manager. Example of the latest package in Debian Wheezy repo: ``` xen (4.1.4-3+deb7u3) wheezy-security; * Security upload. * Apply fix for Xen Security Advisory 108 (CVE-2014-7188) * Apply fix for Xen Security Advisory 104 (CVE-2014-7154) * Apply fix for Xen Security Advisory 105 (CVE-2014-7155) * Apply fix for Xen Security Advisory 106 (CVE-2014-7156) * Apply fix for Xen Security Advisory 56 (CVE-2013-2072) ``` Guido and Pasik (and other maintainers) were extremely fast to deliver those packages at the right time. Congrats guys! ### XenServer The XenServer team was also very reactive and ready to deliver on time. The patch is [available here](http://support.citrix.com/article/CTX200218?ref=xen-orchestra.com). You can patch it through `xe-cli` or `XenCenter`. Or soon, with Xen Orchestra. Oh, by the way, check this: ![](https://xen-orchestra.com/blog/content/images/2014/Oct/patch.png) Yep, it's currently working and tested right now (we patched our servers with Xen Orchestra: it worked flawlessly). The process is very neat: just click on "Patch", then select your `*.xsupdate` file and you're done. The patch will be uploaded, then applied on all your hosts in your pool without anything to do on your side. This stuff will be included soon in the next release. ### From sources If you are using Xen for sources, well, I won't explain how to apply a [patch available](http://xenbits.xen.org/xsa/xsa108.patch?ref=xen-orchestra.com) in the XSA-108 ;) ## Conclusion Even if you have only PV guests, please consider patching: you'll never know if you'll test HVM or PVHVM later. It's also a very good habit to follow what's new in term of security advisories. > Don't forget that an attacker will never exploit only one vulnerability, but all he could find. A big thanks to the Xen community for their reactivity. Do not hesitate to talk with them on the #xen irc channel on freenode. ### VM import and export landing in XO URL: https://xen-orchestra.com/blog/vm-import-and-export-incoming-in-xo/ Last updated: 2014-09-29T13:41:07.000Z As explained in a [previous article](https://xen-orchestra.com/blog/blog/import-and-export-vm-in-xo), we started to implement VM import and export in Xen Orchestra. Guess what? It just hits the next-release version! (meaning: we are testing it right now). Let's give you a taste of what you'll have -very- soon. Update: check the import and export in action [on this short video!](https://xen-orchestra.com/features.html?ref=xen-orchestra.com#import%5Fexport) ## With the web interface Import or export through the web interface is a simple way to play with your VM and distribute them. For people needing automation, check the CLI paragraph. It also opens the possibility to use public repositories with pre-made VM (like I explained in the [previous Docker article](https://xen-orchestra.com/blog/blog/xen-and-docker-for-the-best)). ### Export Our goal was to provide you a fast and easy way to export a VM you want, directly through your web browser (nothing to install), saving it on your local computer/tablet/whatever. Hard to make something more trivial: one the VM view you need to export, click on the export button: ![](https://xen-orchestra.com/blog/content/images/2014/Sep/export1.png) Then, the download start: ![](https://xen-orchestra.com/blog/content/images/2014/Sep/export2.png) #### Running VM The XAPI have no method to export a running VM (for now). So we need to find a way to give that feature for you. That's why we choose to follow this process: - create a temporary snapshot of the running VM - convert it into a VM (not a template) - export it - remove it It changes nothing for you, but it's really convenient if you want to get your file without interrupting the service. ### Import You have two ways to import a VM in our web interface. The first one is directly in the home view. Just select the "host menu" and "Import VM": ![](https://xen-orchestra.com/blog/content/images/2014/Sep/import1-1.png) Select your file: ![](https://xen-orchestra.com/blog/content/images/2014/Sep/import2.png) See the result with the progress in the notification: ![](https://xen-orchestra.com/blog/content/images/2014/Sep/import3.png) Also note the currently imported VM is already visible with its importing state: ![](https://xen-orchestra.com/blog/content/images/2014/Sep/import4.png) That's all! Easy, right? Same stuff in the host view: ![](https://xen-orchestra.com/blog/content/images/2014/Sep/import1bis.png) ## With the CLI That's the part I like with our `xo-cli` application. Because it uses introspection, it's very convenient for us to expose features of `xo-server` through the CLI. Check the example, you'll love it! Moreover, usage with CLI is very flexible, simplifying a lot of things. Remember: you can have `xo-cli` on any other host than `xo-server`. ### Import Just target the host you want (any host connected to XO), give it a file, and it will be imported. Bonus: progression, size, network usage and ETA. ``` user@host$ xo-cli vm.import host=host_UUID @=/home/user/myVM.xva 1% of 551.88MB @ 2.4MB/s - ETA 3m 47s [...] 99% of 551.88MB @ 7.19MB/s - ETA 1s 100% of 551.88MB @ 7.2MB/s - ETA 0ms ``` ### Export Same philosophy here: ``` user@host$ xo-cli vm.export vm=vm_UUID @=/home/user/myVM.xva 11.73MB @ 1.56MB/s [...] 551.88MB @ 3.53MB/s ``` That's cool, but hey, there is more incoming! ## xo-backup [Remember xo-backup](vm-backup-with-xen-orchestra) snapshotting all your running VMs in one command? Imagine now what can we do now we have import and export? Yes, **disaster recovery** in one command! [We started to think how it will be done](https://github.com/vatesfr/xo-tools/issues/2?ref=xen-orchestra.com) in a short proposal. ## When? 3.6 and Starter Edition All of this stuff will be available in the 3.6 release. At this very moment, we have all the features ready for the *Starter Edition*. We'll continue to test it and provide the interface to buy it in few clicks. After that, straight line to the *Enterprise Edition* with **user management**: [the famous 4.0 version!](xo-4-x-goals) ### Xen & Docker: made for each other! URL: https://xen-orchestra.com/blog/xen-and-docker-for-the-best/ Last updated: 2015-12-08T15:34:31.000Z > **2015 December Update**: check our complete guide to use Docker with XenServer: [Docker support in XenServer, the ultimate guide](https://xen-orchestra.com/blog/docker-support-in-xenserver-the-ultimate-guide/) Containers and hypervisors are often seen as competing technologies - enemies even. But in reality the two technologies are complementary and increasingly used together by developers and admins. [This recent Linux.com article](http://www.linux.com/news/enterprise/cloud-computing/785769-containers-vs-hypervisors-the-battle-has-just-begun?ref=xen-orchestra.com) talked about this supposed battle, noting however that developers are using Docker in traditional VMs to bolster security. Containers allow users to develop and deploy a variety of applications with incredible efficiency, while virtualization eliminates any constraints and/or exposure to outside attacks. Uniting these technologies helps developers and system administrators be even more efficient. **Let’s take a closer look at how to achieve this with Docker and Xen Project virtualization, and why we expect more and more organizations to use them together in the near future**. This will also be a key topic at the September 15 Xen Project User Summit at the Lighthouse Executive Conference Center in New York City. [Register today](http://events.linuxfoundation.org//events/xen-project-user-summit/attend/register?ref=xen-orchestra.com) to learn more about enabling Docker in Xen environments for a truly open infrastructure. ![Xen lifting docker lifting containers](https://xen-orchestra.com/blog/content/images/2014/Aug/xen-docker.jpg) *Xen in action, lifting Docker which is lifting containers. I heard you like boats. So I put boats on your boat.* ## Who's Who ### What is Xen Project Virtualization? Xen Project Hypervisor is mature virtualization technology used by many of the world’s largest cloud providers like *AWS*, *Verizon Terremark*, *Rackspace* and many more. Founded in 2003, [Xen Project virtualization](http://www.xenproject.org/about/history.html?ref=xen-orchestra.com) is proven as a highly reliable, efficient and flexible hypervisor for a [range of environments](http://www.xenproject.org/users/why-the-xen-project.html?ref=xen-orchestra.com), running perfectly from *x86* to *ARM*. It's now completely integrated in the [Linux upstream](http://en.wikipedia.org/wiki/Xen?ref=xen-orchestra.com#Xen%5Fin%5FLinux%5Fdistributions%5Fand%5FLinux%5Fupstream) and is [hosted by the Linux Foundation](http://www.xenproject.org/about/the-linux-foundation.html?ref=xen-orchestra.com). The same big cloud users mentioned above also contribute regularly to the project along with many of the world’s largest technology companies, including *Citrix*, *Cavium*, *Intel*, *Oracle* and more. Feature updates and broader community collaboration are on the upswing too: more commits, more communication, better integration, new use cases and simpler and more powerful modes, [such as PVHVM then PVH](https://xen-orchestra.com/blog/debian-pvhvm-vs-pv/). The core Xen Project team takes [security seriously](http://fr.slideshare.net/xen%5Fcom%5Fmgr/lceu13-securing-your-cloud-with-xens-advanced-security-features-ge?ref=xen-orchestra.com). The technology has also been battle-tested by many in the defense industry including the NSA. Xen Project users have benefited from this for years, and developers building, shipping and running distributed applications will profit as well. ![](https://xen-orchestra.com/blog/content/images/2014/Sep/xen_project_logo_767x314.png) ### What is XenServer and Xen Orchestra? **XenServer** is a packaged product consisting of the Xen Project Hypervisor and the Xen Project Management API (XAPI) toolstack within a performance tuned CentOS distribution. It's free and can be installed in just a few minutes; you can [download it from here](http://xenserver.org/open-source-virtualization-download.html?ref=xen-orchestra.com). **Xen Orchestra** (XO) is a simple but powerful web interface working out-of-the-box with XenServer, or any host with Xen and XAPI (the most advanced API for Xen). Take a look on the project website: [https://xen-orchestra.com](https://xen-orchestra.com/?ref=xen-orchestra.com) (hey! that's us!) Both of these tool are of course free software. ### What is Docker? In its own words, Docker defines itself as an open platform for developers and sysadmins to build, ship, and run distributed applications. Consisting of Docker Engine, a portable, lightweight runtime and packaging tool, and Docker Hub, a cloud service for sharing applications and automating workflows, Docker enables apps to be quickly assembled from components and eliminates the friction between development, QA, and production environments. ![](https://xen-orchestra.com/blog/content/images/2014/Aug/docker-logo-370x290.jpg) Main advantages: - fast (boot a container in milliseconds) - simple to use, even in complex workflows - light (same kernel) - container density on one host The other side of the coin: - all containers rely on the same kernel (isolation, security) - less maturity than traditional hypervisor (Docker is still young) - containers are using the same OS on the host (less diversity than hypervisors) - some friction between developers and admins about its usage: not Docker's fault, more a classical friction when you bring new toys to your devs ;) We'll see why and how to cope with just that below. ## Best of Both Worlds An ideal world would: > Let admins do their admin stuff without constraints and/or exposure to dangerous things. > Let developers do their developer stuff without constraints and/or exposure to dangerous things. ### Fluid Workflow In other words, they’d be able to create really cool workflows. For example: - An admin should be able to easily create a Docker ready VM running in a hypervisor, with the exact amount of resources needed at a given point in time (he knows the total amount of resources, e.g a VM with 2 CPUs and 4GB of RAM. - He should delegate (with the same simplicity) this Docker-ready VM to the dev team. - Developers can use it and play with their new toy, without any chance of breaking stuff other than the VM itself. The VM is actually a sandbox, not a jail; developers can create their containers as they need in this scenario. Now you can easily imagine other exciting things such as: - An admin can **delegate rollback snapshot** control to a developer. If he breaks the VM, he can rollback to the "clean" snapshot -- without bothering the admin staff. Live, die, repeat! - Need to clone the same container for other tests? One click in a web interface. - Need to **extend the resources** of this current VM? One click, in live. - Ideally, let a developer create its container from the same web interface. ### Xen Orchestra: A Bridge Between Docker and Xen So how do we do all this without creating a brand new tool? As you may guess, the answer is Xen Orchestra, which today achieves much of this. Updates planned for early 2015 will deliver even more efficiencies between the two technologies. #### What XO Does Today - *Adjust Resources In Live*: You can reduce/raise number of CPUs, RAM, etc., while the VM is running! Doing this, you can **grow or reduce the footprint of your Docker VM, without interrupting the service**. Check it out in a [short video here](https://xen-orchestra.com/blog/features.html#resources). - *Snapshots and Rollback*: Snapshots and rollback in XO are totally operational since XO 3.3\. [Check out how this works in this feature presentation](https://xen-orchestra.com/blog/features.html#backup). **Coupled with Docker, this is very helpful. When your fresh Dockerized VM is ready, take a snapshot. Then you can rollback when you want to retrieve this clean state. All with just a few clicks and in a few seconds.** #### Coming Soon - *Docker-Ready Templates in One Click*: This feature will be released this year. In a few words, **you can request our template directly from your XO interface**, it will be downloaded and operational in your own infrastructure, with a Docker listening and ready for action, in the resources you choose to allocate (CPU, RAM, Disk). No installation: it works out of the box. Read more in this article: . - *ACL and Delegation*: The perfect workflow rest upon integration of ACLs in Xen Orchestra is our current priority. In our case, it allows **VM delegation for your team using Docker**; the VM can be rollbacked or rebooted without asking you. [More info here](https://xen-orchestra.com/blog/blog/xo-4-x-goals/). - *Docker Control from XO*: Because we can get the IP of a VM thanks to its *Xen tools*, we should be able to **send command to the Docker API directly through XO**. In this way, you'll just have to use one interface for Docker AND Xen (at least, for simple Docker operations). And take the best of XO for both: ACLs, visualization etc. This last feature is not in our current roadmap, but will probably pop up early in 2015! ![](https://xen-orchestra.com/blog/content/images/2014/Aug/We-need-to-go-deeper_inception.jpg) ## Conclusion Docker is a really promising and growing technology. **With Docker and Xen on the same team, the two technologies work in tandem to create an extremely efficient, best-of-breed infrastructure**. Finally uniting them in one interface is a big leap ahead! Any question or comment? Go ahead! ### XO pricing model URL: https://xen-orchestra.com/blog/pricing-model/ Last updated: 2023-01-01T18:33:57.000Z After a long period of thinking, we are pushing our pricing model! ### 3 plans to cover all your needs We have tried to create plans to cover all your needs and to fit every budget. The 3 plans are *Starter* ($70 per month), *Entreprise* ($200 per month) and *Premium* ($500 per month), they each comes with an increasing number of features. You can see detailed information [on this page](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xo-pricing). Why those prices? After a survey (thanks to those who answered) and a thorough analyse of the cost of development, we have settle for these prices which we deem fair and which allow us to live and to dedicate entirely our work to Xen Orchestra. We understand that these can be too much for you but don't be afraid, Xen Orchestra will stay Open Source and you can install it by yourself for free! ## Support & appliance Because we want to deliver the **best experience** possible, these plans come **fully equiped** with support and XOA, an Xen appliance with Xen Orchestra already *installed* and *configured*. See for yourself: - It's **easier to deploy**: less than 1 minute! - It **works out of the box** with all the stuff you need. - It can be **run confidently in production**, with our support team backing you. - You have access to our **deep knowledge of Xen**. - You help us to work totally dedicated to Xen Orchestra, bringing **more quality and more features as quickly as possible**. ## Staying Open Source Don't be afraid: Xen Orchestra will stay Open Source! Neither a "freemium" model or closed source parts. If you don't want to subscribe to our offers, you can install and use it from the sources. But: - you won't have Pro support - no access to our XOA images, which are pre-installed appliances for Xen Orchestra, tuned and coming with a bunch of very useful tools - you won't support us directly (but you are welcome in the community! By reporting bug, going on our forum or by spreading the word about XO) You can also try the product with a basic XOA version **accessible for free**. ### Availability The first version available will be the *Starter Edition*, coming this fall, with a new [nice feature](https://xen-orchestra.com/blog/blog/import-and-export-vm-in-xo/). Just after that, we'll focus to release the *Enterprise Edition*. Our timing should be the end of the year (or before if everything go smooth). Finally, the *Premium Edition* will be available in 2015, as soon as we can (depending of the number of developers we'll be able to hire). Need a special appliance or any other stuff around Xen Orchestra or even Xen? [Ask us!](https://vates.fr/contact.html?ref=xen-orchestra.com). ### Cross pool migration with XO URL: https://xen-orchestra.com/blog/cross-pool-migration-with-xo/ Last updated: 2014-09-03T15:18:27.000Z Hi everyone! A blog post about a new cool feature freshly implemented in Xen Orchestra: cross pool migration, AKA migration without shared storage (or **Storage Xen Motion**). ## Concepts In XenServer, you have to type of live migration: **Xen Motion** and **Storage Xen Motion**. ### Xen Motion Easy one. That's the name of migrating hosts with hosts sharing the same storage (NFS or iSCSI+LVM). It's already working in Xen Orchestra since... a long time! In this case, the content of the RAM is sent over the network by Xen, from one host to another. Thus, RAM size and the network speed are correlated to the migration time. ### Storage Xen Motion The one I like the most. This time, a storage is not shared between hosts. In order to migrate a VM, you need to achieve multiples steps: 1. move the whole VM storage, network and configuration to another host - when it's done, migrate what's left: the RAM - finally, the "old" VM is removed on the original host This process can be quite long: if your VM have a 100Gig disks, well... You need to transfer all of it! But you stay safe: your VM is always online during the transfer! ## In Xen Orchestra ### xo-server We just implemented this feature in the *next-release* branch of **xo-server**. It's already available in **xo-cli**, see for yourself: `xo-cli vm.migrate_pool id=VM_UUID target_host_id=HOST_UUID target_sr_id=SR_UUID target_network_id=NET_UUID migration_network_id=NET_UUID` I have to say, **xo-cli** is a very useful tool to test quickly our new features in **xo-server**! Unlike `xe`, you don't have to write the IP or the host password, because you are already connected. We just tested it, and it works :) #### Simplify But hey, if I don't want to use all those parameters, just to give the VM and the host target? Well, you can do it! Because XO will automatically pick default options: - the default SR on your host/pool will be chosen by XO, as a targeted SR - the targeted network chosen by default will be the one used by the management interface. - *idem* for the migration network Thus, the previous command will be shorter: `xo-cli vm.migrate_pool id=VM_UUID target_host_id=HOST_UUID` That's it! ### Migration in the UI (xo-web) We choose to use **Xen Storage Motion** without getting another button. For doing this, the VM will be migrated normally first. If it fails (no shared storage), this window will be displayed: ![](https://xen-orchestra.com/blog/content/images/2014/Sep/xenstoragemotion.png) By clicking on "OK", the VM will be moved to the targeted host! This feature was already tested and the code is in the *next-release* branch. Stay in touch for a new release with this feature in XOA! ### New website! URL: https://xen-orchestra.com/blog/new-look/ Last updated: 2018-09-13T09:49:28.000Z We're back with a new blog and a new website :) Farewell Wordpress! Say hello to Ghost. We decided to wipe our current stack and to use better tools. ## New blog We switched from WP to Ghost. It uses Markdown for writing. And that's waaaaaaay better than WYSYWYG editor or plain HTML. It runs on NodeJS, reverse proxified by Apache. Old articles are already migrated, preserving their old URLs. ## New website Written from scratch, using Jade, Bootstrap, Gulp. Running on top of NodeJS. [Go take a look!](https://xen-orchestra.com/blog/) ![](https://xen-orchestra.com/blog/content/images/2014/Aug/new_website.png) ## Other stuff We'll publish an article about our new pricing table and why we choose to do that. We'll give you informations about the project too. Stay tuned! ### XO 4.x goals URL: https://xen-orchestra.com/blog/xo-4-x-goals/ Last updated: 2014-09-26T19:13:07.000Z In this article, you'll see what we want for the next branch of Xen Orchestra. But first, some details about our development cycle. ## Dev cycle A *leap of branch* (major number, e.g 3.x to 4.x) indicates a big feature or a an important modification in the implementation of critical functionalities. A *minor bump* (4.0 to 4.1) is used for new features or a pile of bug fixes, without changing that much the current release. Small bug fixes and security fixes uses the last digit. As the [3.5.1](https://xen-orchestra.com/blog/blog/xen-orchestra-3-5-1) for example. ### Feature creation process This is fairly simple: - Someone (us or *you*!) come up with an idea - A proposal is written (UI mock up, global architecture) - We implement it (or you via a pull request) − in a dedicated branch if the feature is important - We test it - the implementation is merged into the `next-release` branch - We test it again - `next-release` is merged into `master` to make a *brand new release!* Done! ## Permissions and roles (4.0) That's the main topic of the 4.0, aka "the first major release" in the 4.x branch. You can see it on the top [of our road-map](https://github.com/vatesfr/xo/blob/master/roadmap.md?ref=xen-orchestra.com). But we want to get it right. Here is how. ### Concepts We have choosen to separate this big feature in three parts: - *User management*: ![](https://xen-orchestra.com/blog/content/images/2014/Aug/user.jpg) - *Access Control List*: the main goal of this feature is to provide fine grained permissions. ![](https://xen-orchestra.com/blog/content/images/2014/Aug/permissions.jpg) As you can see, it allows a lot of combinations for all your existing needs: you can either use it at really low level (e.g. allowing *Bob* to restart its own VM) or at high level to ease the administration (e.g. allowing all users in the `team1` group to manage all VMs in the `team1VMs` set). - *LDAP integration*: having a powerful interface and ACL is great. But we know that as a good administrator you want to manage your users in an LDAP directory ;). Why? Because you simply don't want to create multiple accounts and a password for each of them for a single user! That's why companies use Open LDAP or Active Directory (or any other central directory). By connecting `xo-server` to your LDAP server, user creation will be trivial: - when a user logs in XO for the first time, a profile with no permissions is automatically created - later, an admin can usethe user management UI to give him some rights Like that, no passwords are stored in XO! ![](https://xen-orchestra.com/blog/content/images/2014/Aug/ldap.jpg) ## Charts and performance indicators (4.1) They will come probably just after permissions and roles. [We wrote a post about it recently](./statistics-in-xo). ## 4.2 ? We have many ideas for XO but the order in which they will be implemented in not set in the stone yet. We'll adapt priorities toward what's popular for our clients and the community (i.e. **you** :)). Already in the list: - Task scheduler in the UI - Disaster recovery and backup UI - Proxy for VNC console (accessible through a NAT/firewall) - PCI (and GPU) management in GUI (passthrough) - Advanced visualization in one dedicated page (much probably using [d3js](http://d3js.org/?ref=xen-orchestra.com)) - ...and more on [the road-map](https://github.com/vatesfr/xo/blob/master/roadmap.md?ref=xen-orchestra.com#xen-orchestra-roadmap)! ## Timing Our objective is to **release 4.0 this fall**. Could be September or October, but be sure we are fully committed to XO until the end of this year! 2015 release frequency will mainly depend on our raising rounds in the end of this year: bigger teams allows for faster release. We are, and will be totally transparent about how it goes. ### Import and export VM in XO URL: https://xen-orchestra.com/blog/import-and-export-vm-in-xo/ Last updated: 2014-08-28T12:24:07.000Z A very important (and coming!) feature in Xen Orchestra, will be VM import & export. Want to know how it will work and what will be possible to do with it? Go on! ## XenServer mechanism Before getting on use cases and UI consideration, we'll see how XenServer, and its API (XAPI) deal with VM import or export. Like the RRD for [the statistics](https://xen-orchestra.com/blog/blog/statistics-in-xo), it's not directly incorporated in the XAPI. We need to do a HTTP request to get or to push our VM. The request for exporting a VM via a **HTTP PUT** look like this: `http://myxenserver.mydomain/export/?session_id=mySessionId&ref=myVmRef&use_compression=true` For importing, it's very similar: `http://myxenserver.mydomain/import/?session_id=mySessionId` Great, but we need to pass this request from `xo-web` to `xo-server` and getting back the answer from your host. That's the major part of our work in order to have this feature in XO. ## UI considerations ### VM Export Not a problem: we just have to add an option in the VM view, with a check-box for the compression, then you'll download directly the file on your computer. ### VM Import This feature will probably need a dedicated page, with a progress bar. Because you'll want to know how it goes. ## Conclusion As you can see, the major gap for having this feature working is in the back-end. But the implementation will be relatively [similar to the statistics](https://xen-orchestra.com/blog/blog/statistics-in-xo), so it should be fast as soon as we are on it. ### How to use Wake-on-LAN on XenServer URL: https://xen-orchestra.com/blog/how-to-use-wake-on-lan-on-xenserver-6-2/ Last updated: 2017-10-31T00:38:31.000Z In this post, we'll see how to activate the Wake-on-LAN (WOL) on XenServer. ## Hardware configuration Naturally, it depends of your hardware configuration. If you don't have any Server Manager Tool, like *iLO* (HP) or *iDRAC* (Dell), you can count on the WOL feature of your network card. In our lab, we got basic hardware: ITX cards and Core i5 CPU, not the kind of hardware you'll find in a data-center, but it's compatible with WOL. ### Configure the operating system XenServer 6 is based on CentOS. By default, when you shutdown the host, it doesn't activate the network card. In this case, you can't wake the box, because your interface is completely off. So, we need to configure it: - connect in SSH to your host - do a `ethtool -s eth0 wol g` - that's all! But if you want to do this permanently, this command will do the trick: `echo '/usr/sbin/ethtool -s eth0 wol g' >> /etc/rc.d/rc.local` Now, when the system shutdown, it's ready to listen for a WOL packet. ### Configure XenServer But that's not enough to start a server using Xen Orchestra or XenCenter. You need to tell the XAPI how to wake it: because we saw there is different options to do that (WOL, *iDRAC*/*iLO*, even custom scripts). Again, go in SSH on your host (or any host in the pool) and use this: `xe host-set-power-on-mode uuid= power-on-mode=wake-on-lan` For people using *iDRAC* or *iLO*, just replace `wake-on-lan` by `DRAC` or `iLO` respectively, but that's not all. You need to give to XAPI the IP and the credentials of your Server Manager Tool. The command will look like this: `xe host-set-power-on-mode uuid= power-on-mode=DRAC power-on-config=xx.xx.xx.xx, user, password` with xx.xx.xx.xx the IP of your DRAC controller. For *iLO*, just replace `DRAC` by `iLO`. That's it! ### In Xen Orchestra Since the [3.5.2 release](https://xen-orchestra.com/?ref=xen-orchestra.com), you'll see a **Start** button in the host menu if your host is Halted. Just click and you can boot it. ![](https://xen-orchestra.com/blog/content/images/2014/Aug/start_host.png) Now, you can imagine what it's possible to do in XO with this kind of feature: - scheduled shutdown for some hosts in the evening (e.g: hosts only used for developer VMs during the day) and start them in early in the morning. A lot of energy saved! - shutdown some hosts automatically when your architecture is not stressed, then, if necessary, boot them and migrate some VM on it. - a lot of other useful cases. Everything is possible now with Xen Orchestra! ### Statistics in XO URL: https://xen-orchestra.com/blog/statistics-in-xo/ Last updated: 2014-08-27T20:38:04.000Z This coming feature in Xen Orchestra is really important. But not trivial to implement. Let's what it is all about. ## Concepts Our current architecture connects directly to the XAPI, listen to events and send orders. But statistics are not directly in the XAPI. It was the case in previous versions of XenServer (4 and before), but for performance reasons, it was placed in Round Robin Databases (RRD). Thus, you can call directly those metrics through the XAPI. ## RRD and backend Let's hear one of the main XAPI dev, Jon Ludlam: > RRDs are maintained for individual VMs (including dom0) and the host. Internally, the RRD is updated and maintained by a module similar to (but not actually) rrdtool. RRDs are resident on the host on which the VM is running, or the pool master when the VM is not running. For this reason, to obtain the data requires knowledge of where the VM is running. You can read [more about it here](http://wiki.xen.org/wiki/XAPI%5FRRDs?ref=xen-orchestra.com). - After that, we need to make a HTTP request on the targeted object (on the right host) for extracting its metrics. - Furthermore, we got an XML file we need to parse. - Finally, passing those data from `xo-server` to any client requesting it. And we're done for the backend. ## GUI display Wait a minute! Ok, we got data, but now we need to display what we want in the user interface. We already know we'll use [that kind of graphs](http://bl.ocks.org/mbostock/1483226?ref=xen-orchestra.com): ![](https://xen-orchestra.com/blog/content/images/2014/Aug/graph-1.png) A first draft of where we'll put them: ![](https://xen-orchestra.com/blog/content/images/2014/Aug/newstats.png) In this mock up, you'll have CPU, RAM, Network and Disk activity in the VM view. This not the final design, but it gaves a general idea. Thanks to our experience using a nice graph lib (d3js), we'll find the best way to show you what is really happening in your VM, host or any other object having metrics. ## Conclusion Implementing graphs and metrics in XO is not that complicated, but it requires some time to do it properly. We hope to manage this as soon as we got time to work on it. If you have any question or suggestion, do not hesitate to comment this post. ### Xen Orchesta 3.5.1 URL: https://xen-orchestra.com/blog/xen-orchesta-3-5-1/ Last updated: 2014-08-20T22:38:28.000Z A minor release for a [minor fix](https://github.com/vatesfr/xo-web/issues/139?ref=xen-orchestra.com) ;) Want to upgrade in XOA? [As explained in the documentation](https://github.com/vatesfr/xo/blob/master/doc/installation/xoa%5Finstallation.md?ref=xen-orchestra.com#restart-and-update-process-in-xoa), just type that: ``` npm update --global xo-web xo-server systemctl restart xo-server.service ``` And you're done! You should see "(xo-web 3.5.1)" in the About page. **This is also the occasion to told you we officially exceed 200 unique downloads since the [3.5 release](https://xen-orchestra.com/blog/blog/xen-orchestra-3-5/)!** Thank you! ### Xen Orchestra 3.5 URL: https://xen-orchestra.com/blog/xen-orchestra-3-5/ Last updated: 2014-08-20T18:01:27.000Z Less than three months from [the previous release](https://xen-orchestra.com/blog/blog/xen-orchestra-3-4/), and during a very busy summer for us, we officially released XO 3.5 with approximatively 20 bug fixes/enhancements. Explore what's new in this article! ## Visible changes - Add action buttons in the console view: as requested by Hoerup in [this bug report](https://github.com/vatesfr/xo-web/issues/121?ref=xen-orchestra.com), we added some action buttons (stop/start/reboot) in the console view. Very useful, see for yourself: ![buttons_console_red](https://xen-orchestra.com/blog/content/images/2014/Aug/buttons_console_red.png) - Better process in VM creation when you forgot to fill some fields: ![forgot](https://xen-orchestra.com/blog/content/images/2014/Aug/forgot.png) - Allow a real force shutdown if a VM fails. - Fix a Safari [display issue](https://github.com/vatesfr/xo-web/issues/132?ref=xen-orchestra.com). Enjoy XO, Apple users ;) - Avoid removal of the last user. - Auto redirect to the home page after deleting a VM. - We added Linux icon for Fedora distributions in the home view. - Properly handle a shutdown host in a pool in one click: As you can see, there is 2 running VMs on the first host ("Lab1"). But we choose to shutdown it: ![sh1](https://xen-orchestra.com/blog/content/images/2014/Aug/sh1.png) A confirmation message is requested: ![sh2](https://xen-orchestra.com/blog/content/images/2014/Aug/sh2.png) Then, automatically, every VM is auto-migrated to the other host: ![sh3](https://xen-orchestra.com/blog/content/images/2014/Aug/sh3.png) At the end, "lab1" is halted: ![sh4](https://xen-orchestra.com/blog/content/images/2014/Aug/sh4.png) As you can see, no big changes, but a **smooth** user experience. #### Under the hood This release is an important step for the project, for various reasons: - we finished to [migrate the whole software on NPM](https://xen-orchestra.com/blog/full-xo-stack-on-npm/): it gives us a better way to package it and a clean release cycle. This decision is really important for now and the future. - we are using [Browserify](http://browserify.org/?ref=xen-orchestra.com) now. It helps to simplify the architecture of "xo-web" and reduce the maintenance. - we migrated our HTML page to use [Jade templates](http://jade-lang.com/?ref=xen-orchestra.com). Less painful to modify our views. Those actions are just the beginning of a longer journey. #### New Appliance (XOA 3.5) with xo-backup and xo-cli included A completely new appliance, with: - a better and easier upgrade system (thanks to NPM integration) - [xo-cli](https://xen-orchestra.com/blog/blog/xen-orchestra-from-the-cli/) and [xo-backup](https://xen-orchestra.com/blog/blog/vm-backup-with-xen-orchestra/)! - Kernel 3.14 (Debian Jessie) - **Ultra fast boot time** with SystemD (also used for starting XO automatically and restart it if it crashes) - size reduced, **from 745 to less than 561MB**. #### Download You can try the [appliance on this page](https://xen-orchestra.com/blog/). As we managed to use NPM now, the upgrade process from a previous version in the **not recommended and not supported** (because we used GIT before). If you want a custom appliance (pre-configured with static IP address of proxy settings), [contact us](https://vates.fr/contact.html?ref=xen-orchestra.com). Complete change log is accessible [here](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#350-2014-08-14). #### Demo The demo is always [accessible](https://dev1.vates.fr/?ref=xen-orchestra.com#/) with user "demo" and password "demo" (read only rights). Enjoy :) #### What's next? ![xo4](https://xen-orchestra.com/blog/content/images/2014/Aug/xo4.png) This version is probably the last of 3.x branch (that being said, security fixes can always been released). Yes, it means we'll start to work on first feature on [our roadmap](https://github.com/vatesfr/xo/blob/master/roadmap.md?ref=xen-orchestra.com#xen-orchestra-roadmap) ;) **The next big event will be the [Xen User Summit](http://www.xenproject.org/about/events/viewevent/120-xen-project-user-summit-2014.html?ref=xen-orchestra.com) in September in NYC**: we hope to deliver a first preview of 4.0 there. It's all about users and permissions, here is a small hint: ![permissions](https://xen-orchestra.com/blog/content/images/2014/Aug/permissions.jpg) ### Full XO stack on npm URL: https://xen-orchestra.com/blog/full-xo-stack-on-npm/ Last updated: 2014-08-20T17:49:27.000Z This a quick post about how XO is built. [1 year ago](https://github.com/vatesfr/xo-server/commit/ae091cdb8c43eef86e7ee19f7ea53ad92b2407f6?ref=xen-orchestra.com), we choose to switch from PHP to NodeJS: what a great idea! It's easier to work with JavaScript on the whole stack (from "xo-server", the back-end, to "xo-web", the front-end), we got really better performances, better scalability, less dependencies, and so on. Plus now, when we choose to [add "clients" to our current architecture,](https://xen-orchestra.com/blog/blog/vm-backup-with-xen-orchestra/) it stays simple and efficient. Progressively, we are migrating the complete XO stack to [npm](http://en.wikipedia.org/wiki/Npm%5F%28software%29?ref=xen-orchestra.com). It's not completely done, but we made recent progress and we'll finish soon. In this way, updating and deploying XO packages and their respective dependencies will be painless. Picture is related ;) ![npm](https://xen-orchestra.com/blog/content/images/2014/Aug/npm.png) ### VM Backup with Xen Orchestra URL: https://xen-orchestra.com/blog/vm-backup-with-xen-orchestra/ Last updated: 2016-01-02T18:22:14.000Z > UPDATE: we are now supporting Rolling snapshots, Full VM backups and even Delta backup for XenServer! Read our blog post about [XenServer incremental backup with Xen Orchestra](https://xen-orchestra.com/blog/xenserver-incremental-backup/). As you may already know, we planned to integrate backups directly in Xen Orchestra: this feature is in [our current road map](https://github.com/vatesfr/xo/blob/master/roadmap.md?ref=xen-orchestra.com#xen-orchestra-roadmap). The goal is to provide a simple interface to select, plan and automatize all your VMs backups. But, until its done, one of our clients needs quickly a way to **snapshot all its running VMs in one command**. Remember this diagram? ![xo-arch](https://xen-orchestra.com/blog/content/images/2014/Aug/xo-arch-e1400585233111.jpg) Well, why not connect a kind of "client" to send order directly to "xo-server" to automatize all this stuff? After all, we had a unique entry point for all XenServer via the core of XO. That's how "xo-backup" (as a plug in) is born in **less than 2 days and 200 lines of code**! Let's see the architecture diagram with this new client: ![image](https://xen-orchestra.com/blog/content/images/2014/Aug/image-e1406501056338.jpg) As you can see, "xo-backup" is a completely standalone client, it could be executed on any machine you like, even not on the same box running "xo-server". For example, it can run on your backup server, dedicated to that kind of tasks. #### How it works Let's take a real and simple example. I will use "xo-backup" on my PC at home, to start a backup on the existing demo instance of Xen Orchestra (running in a data-center), itself connected to our small lab in our offices: `xo-backup (home) -> xo (datacenter) -> xenserver (office)` On one running VM, I've got no snapshot: ![nosnap](https://xen-orchestra.com/blog/content/images/2014/Aug/nosnap.png) Here is a simple example of this client: ``` $ xo-backup --max-snapshots 2 --user admin@vates.fr https://dev1.vates.fr/api/ [?] Password: ******** ✔︎ vm1 snapshotted ✔︎ vm2 snapshotted ✔︎ vm3 snapshotted ✔︎ vm4 snapshotted ``` As you can see, we created a snapshot on each of this VM. If I go on a VM screen in XO, now I can see: ![onesnap](https://xen-orchestra.com/blog/content/images/2014/Aug/onesnap.png) Great! Now I can revert to this snapshot in two clicks, also remove or rename it if I want: ![onesnapedit](https://xen-orchestra.com/blog/content/images/2014/Aug/onesnapedit.png) Or, but let's try to restart "xo-backup", using exactly the same command. The result is now: ![twosnap](https://xen-orchestra.com/blog/content/images/2014/Aug/twosnap.png) Remember the "--max-snapshots 2" parameter in the command line? What if I choose to start a new "xo-backup" now? ``` $ xo-backup --max-snapshots 2 --user admin@vates.fr https://dev1.vates.fr/api/ [?] Password: ******** ✔︎ vm1 snapshotted ✔︎ vm1 old snapshot deleted auto-2014-07-27T09:34:49.434Z ``` The oldest one is automatically removed! That's why you can use this script directly in a Cron job (like [the example given here](https://github.com/vatesfr/xo-tools/tree/master/backup?ref=xen-orchestra.com#with-cron)). In this way, you made a snapshot rotation, allowing a rollback D-1 etc. #### Wait! If I made my own snapshot manually between automated "xo-backup" execution? No problem! Our client filters automatically on the "auto-" prefix present in your snapshot name. If you manually create one, with for example "snap\_before\_update" name, it will **NOT** be removed by "xo-backup"! That's why you can continue to use snapshots manually in parallel of "xo-backup". #### ... wait! (again). Snapshots are NOT backups! You're totally right! That's because "xo-backup" is just at its first version. Our next objective is to allow **full exports of VM**, \*.xva files on your local disk, or any accessible mount on your system. This feature will come with parameters to target only VM you like (or all, or with a filter you give). We choose to start with snapshots, because that's the first step allowing full export of a running VM: we'll export its fresh snapshot during its execution (because you can't export directly a running VM). #### Thanks to our sponsor This client was sponsored by [OOWorx](http://www.ooworx.com/?ref=xen-orchestra.com). Thanks to them for helping XO to be better! ![](http://www.ooworx.com/sites/www.ooworx.com/themes/ooworx/xlogo.png.pagespeed.ic.pbibYpjKnD.png) Remember: you can do the same and sponsor a feature you need! [Contact us for me details](https://vates.fr/contact.html?ref=xen-orchestra.com). ### Xen Orchestra from the CLI URL: https://xen-orchestra.com/blog/xen-orchestra-from-the-cli/ Last updated: 2020-06-02T08:23:54.000Z > ⚠: Some part of this article may be outdated. Please, rely on [our documentation](https://xen-orchestra.com/docs/architecture.html?ref=xen-orchestra.com#xo-cli-cli) for correct usage of the CLI commands. As explained [in a previous post](https://xen-orchestra.com/blog/blog/users-roles-in-xen-orchestra/), Xen Orchestra is not just a web interface to Xen, it is also a modular infrastructure which can be interfaced with very easily through its API (still unstable though :p). We recently created a new XO client which allows you to manage your whole infrastructure from the command line: **xo-cli**. Here is the global architecture: ![xo-arch](https://xen-orchestra.com/blog/content/images/2014/Aug/xo-arch-e1400585233111.jpg) xo-cli is just a new client, just like XO-Web, which can be used in parallel with it. What use is it if there is already **xe** CLI? Well, first you can manage all servers from one place because of the central place of XO-Server. You can also use it to automatically register servers into your Xen Orchestra installation ([that was the initial demand](https://github.com/vatesfr/xo-server/issues/23?ref=xen-orchestra.com) after all). #### Installation We tried to make it as easy as possible to let you focus of the use instead of the boring part: `npm install -g xo-cli` and you're ready to go! You can find more about the [NPM](https://www.npmjs.org/?ref=xen-orchestra.com) package on [its page](https://www.npmjs.org/package/xo-cli?ref=xen-orchestra.com). #### Usage First, you need to associate the CLI to an existing Xen Orchestra installation: ``` xo-cli --register http://xo.my-company.net/api/admin@admin.net admin ``` You can now discover all the available commands: ``` xo-cli --list-commands ``` Good news: thanks to introspection, xo-cli can see automatically ALL the features included in XO-server. An example: ``` xo-cli server.add my.server.net root secret-password ``` ### Xen Orchestra documentation URL: https://xen-orchestra.com/blog/xen-orchestra-documentation/ Last updated: 2018-07-06T08:41:55.000Z If you want more information about Xen Orchestra, like how it works, how to use it, some recipes (like using XO with an Apache reverse proxy), [check our new "doc"](https://xen-orchestra.com/docs?ref=xen-orchestra.com). ### Xen Orchestra 3.4 URL: https://xen-orchestra.com/blog/xen-orchestra-3-4/ Last updated: 2014-08-20T17:41:08.000Z Hi everyone! Ready for a new release? Two great features: - A sign in page (no more public access, you should have at least a registered user). We've got "read" permission for people who want the same result than before. - An "end-to-end" event system (see below). Hopefully the latest version before [user permissions](https://xen-orchestra.com/blog/blog/users-roles-in-xen-orchestra/) in Xen Orchestra ;) ## Sign in page This feature is quite simple to understand: before, you could access as a "guest" (non logged with only read permissions) and see the whole infrastructure.Now you can't, because you'll be dropped to the login page: ![loginview](https://xen-orchestra.com/blog/content/images/2014/Aug/loginview.png) The green "check" icon on the bottom also indicates that you are connected to xo-server (via *WebSockets*). It will help to see quickly if it works. But you can add a "read" user with login/pass for just see the infrastructure without any rights on it: ![read_only](https://xen-orchestra.com/blog/content/images/2014/Aug/read_only.png) We've got also a feature memorizing the page you want to go, event if you are not already logged, eg: someone give you a link to a VM, but you are not registered. You'll be going through the login page, but just after been successfully logged, you'll go automatically on the requested page. ## New event system This is the biggest new feature. And we are really excited to release it! In the first place, for getting latest information on XenServer, we sent requests every 1 or 2 seconds: ![3.4](https://xen-orchestra.com/blog/content/images/2014/Aug/3-4-e1400250425324.jpg) Trivial, but not scalable at all (imagine requesting everything on "n" Xen hosts...). That's why we introduced in a later version, events handling: ![3.4_2](https://xen-orchestra.com/blog/content/images/2014/Aug/3-4_2-e1400250517869.jpg) Scaling was possible, by just listening events from XenServer. But, the quest was not complete. Until now! Let's see the result: ![3.4_3](https://xen-orchestra.com/blog/content/images/2014/Aug/3-4_3-e1400250653435.jpg) This time, we've got also events between xo-server and xo-web. Why this is really important? Because due to this change, the web interface is now: - **more reactive**: as soon as a event occurs in a XenServer host, it will be broadcasted to every web clients connected! - **more bandwidth friendly**: only update what is needed when it's needed. - **more CPU friendly** on the client. - **more scalable** About the bandwidth, with 1 pool, 2 hosts and 8 powered VM on 30, that's our average numbers before and after: ![event](https://xen-orchestra.com/blog/content/images/2014/Aug/event1.png) Test it, you'll see the difference. We also take advantage of the new release to fix small dependencies bug and optimize our release process. You can read the change log [here](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#340-2014-05-22). ## Download or upgrade You can download the full appliance, or upgrade from your existing installation with a `service xo update` in your appliance. ## Demo The demo is [now accessible](https://dev1.vates.fr/?ref=xen-orchestra.com#/) with user "demo" and password "demo". Enjoy :) ### Users roles in Xen Orchestra URL: https://xen-orchestra.com/blog/users-roles-in-xen-orchestra/ Last updated: 2014-08-20T17:48:07.000Z This post is an introduction of our users roles implementation in Xen Orchestra. Our main goal is to provide you a way to optimize your workflow with VMs, and you'll see how we found the solution. ## The need A LOT of companies ask us for user roles for managing VMs. Different cases, but the same need: - assign a VM to a defined user - hide everything else for him - choose specific rights for him (only see the VM, or ability to modify it, or every rights) - delegate VMs to developers or clients ## The solution Xen Orchestra, by design, can communicate with different pools with a single point of administration. Thus, you'll be able to delegate any VM in your whole infrastructure to the authorized person. And as the central point of control is in xo-server (and not in xo-web), you are secure! We first started to think about permissions for every objects (VMs but also storage repositories etc.). A long task to accomplish, and not the real need. After all, there is two types of people using XO: - administrators, with the need of a global and comprehensive view of the whole stuff, also capable to give rights to users on specific VMs - users, with the need of a view of their assigned VMs, and limited rights accorded by their administrator After clearing this, we've got another question: what kind of user permissions are needed? Here is the "right" model: ![](https://xen-orchestra.com/blog/content/images/2014/Aug/permissions.jpg) With it model, you can exploit your VM in many different cases: - you can provide a view for "vm-guest" users: (answering to the question: "is my VM is running? how any RAM I have? what are IP attached to my VM? How many disk space I have?"). It will also display graphs in order to monitor their own load (cpu, disks usages etc.) - for clients who need to start, shutdown or reboot their assigned VM, you can use "vm-operator". This kind of user can also access consoles. Furthermore, he can taking snapshot and revert it! In this case, your dev team can work without asking anything to your sysadmin. You can give them a proper environment to test and validate their entire deployment process, and they can re-do it anytime they want. - for advanced users (maybe developers or other sysadmins) in a dedicated pool (e.g a "test pool"), you can give them more permissions: with "vm-admin", they can modify VM resources for testing best fit for their applications ("is 2vCPU and 2GB is enough for the new app?") before entering in production. Once that's done, as an admin, you can migrate this VM in a production pool and here you go! They can also rename the VM and its description. ### Profiles, groups and permissions Giving rights user per user can be useful, but sometimes painful in your workflow. That's why we will also offer **Groups**. Let's see with a simple example: you want to give "vm-operator" **profile** for 3 VMs to the whole developers team. Without groups, you'll need to add each user in each VMs. Boring. Now, create a group named "dev-team", add each user you want in it. Now, for each VM, you just add the group "dev-team" and put the "vm-operator" right to it. You're done! But what happened if the lead developer needs more rights on the VM? Let's say "vm-editor", for rolling back when necessary. In this case, just add the user itself with higher permissions. Even if in the "dev-team" group in the same time, the higher permissions will prevail. ### Planned design We'll use something close to the way how [GitLab](https://www.gitlab.com/?ref=xen-orchestra.com) works: simple and efficient. Something like that, if you are an admin, on a VM page: ![ajout user](https://xen-orchestra.com/blog/content/images/2014/Aug/ajout-user-e1400582964907.png) When clicking on the "Edit" icon in the corner of the Users panel: ![ajout user 2](https://xen-orchestra.com/blog/content/images/2014/Aug/ajout-user-2.png) When clicking on "Add User", you'll have a list with users and auto completion. Same stuff for Groups. ### Authentication Our goal is to allow multiple auth system, like "internal" (user account directly in Xen Orchestra) or with other external services (LDAP, Google Account, Twitter, GitHub etc). In the last case, you can deliver VM access to your clients without the need to create a brand new account (with a password etc.) ### Beyond user permissions The other big plus about Xen Orchestra is its architecture: ![xo-arch](https://xen-orchestra.com/blog/content/images/2014/Aug/xo-arch-e1400585233111.jpg) "xo-web" is one element of XO, but not the only one. As you may know, we started to create "[xo-cli](https://github.com/vatesfr/xo-cli?ref=xen-orchestra.com)". After all, CLI is just an other interface. Now, **just think about combining the power of CLI (scripts, automation, deployment) with user permissions:** - your developers/devops/clients can talk directly to xo-server with a simplified API - connected to your whole Xen infrastructure (even between different pools) with their rights. - without installing a complicated stack (XO works without any agent to install on your servers and can run in a minute with our appliance). Cloud you say? ### When? As soon as we got the financial "green light". Want to speed up the process? [Come here!](https://xen-orchestra.com/blog/forum/74-users-and-roles-in-xo) ### Bounties for Xen Orchestra URL: https://xen-orchestra.com/blog/bounties-for-xen-orchestra/ Last updated: 2014-08-20T17:30:30.000Z As requested by "ngc" [on our forum](https://xen-orchestra.com/blog/forum/72-feature-requests-bounties), we are now able to register contributions for unlock features in Xen Orchestra. The main demand is [on user roles](https://xen-orchestra.com/blog/forum/74-users-and-roles-in-xo) and also [getting metrics](https://xen-orchestra.com/blog/forum/75-statistics-in-xo) in xo-web. The first good news in our official first contribution from David of B.C.C. sprl (Belgium) for users roles. Faster we'll have enough people contributing, faster we'll develop and thus unlock new exciting features for XO! Basic rules for contribution are [explained on our forum](https://xen-orchestra.com/blog/forum/73-how-to-ask-for-a-feature), but I display them here too: - if the estimated cost is achieved, we start to work on the feature - we'll release it as soon as possible (priority in our work load) - we'll deliver a post on the project website with all information and regular reports of progresses - if we've been optimistic on the cost, that's for us - if we've been pessimistic on the cost, we'll make extra-features with the funds (we guarantee ALL funds will be invested entirely in XO and nothing else) If you have a feature needed in your company, come explain it to us, we'll do our best to deliver a solution. Oh, and we are also close to a new release, stay tuned ;) ### Xen Orchestra 3.3.1 URL: https://xen-orchestra.com/blog/xen-orchestra-3-3-1/ Last updated: 2014-08-20T17:29:16.000Z We're back with a minor release, mainly for fixing bugs + update console view, which is nicer : ![console_upd](https://xen-orchestra.com/blog/content/images/2014/Aug/console_upd.png) You can read the change log [here](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com). Please update your current XOA 3.3 with this command: ``` service xo update && service xo update ``` Why twice ? Because the update script need to be updated itself (we also clean previous dependencies). And then: ``` service xo restart ``` If the restart failed, do it also twice. ### Xen Orchestra 3.3 URL: https://xen-orchestra.com/blog/xen-orchestra-3-3/ Last updated: 2014-08-20T17:27:25.000Z Here it comes the fourth release of Xen Orchestra 3.x. The main new feature is snapshots: you can now make snapshots, delete, rename or revert them! List of visible changes: - full snapshot management (create, delete, rename, revert) - host actions, like restart toolstack, reboot or shutdown - log management: you can now delete a log entry in each view: vm, SR, host, pool) - host removal: you can remove a host from a pool ## Under the hood A big change in the way of xo-web works: we are now using [Gulp](http://gulpjs.com/?ref=xen-orchestra.com) instead of Grunt. It really easier to maintain and use, because Grunt cause us troubles with update system. That's why we recommend you to update XOA by downloading the new appliance. Complete [change log here](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#330-2014-03-07). ## What's next? Next main feature will be decided by the vote of our customers ("Roadmap vote"). Want to give your vote? [Go register now!](https://xen-orchestra.com/blog/pricing.html) You will choose between those features: - Event system in xo-web for ultra-reactive interface and performance boost - Storage Repository (SR) creation page - Proxy VNC console (better security, encrypted VNC and passing through NAT) - VDI management in VM (edit, resize, remove, add) - Network management in VM (remove, add networks) - Live migration between different pools ### Testing XenServer 6.2.5 beta URL: https://xen-orchestra.com/blog/testing-xenserver-6-2-5-beta/ Last updated: 2014-08-20T17:24:46.000Z Thanks to [this tweet](https://twitter.com/lsantiagos/status/441738002914476032?ref=xen-orchestra.com), I decided to test latest build of XenServer. Let's see what we have here. First, I don't have any physical host left to install it on bare hardware. Let's play virtception! ![The famous scene in virtception with 2 XenFuPanda ](https://xen-orchestra.com/blog/content/images/2014/Aug/inception-hotel.png) The famous scene in virtception with 2 XenFuPanda ### Step1: install Xenserver 6.2.5 in... Xenserver 6.2 No problem with that, just few clicks in XO: Go to the Add Vm page and fill forms like this: - Template: Other media install - Name: xenserver 6.25 - RAM: 2GB - ISO: main.iso (name of the iso downloaded [from here](http://xenserver.org/overview-xenserver-open-source-virtualization/project-roadmap/2-uncategorised/115-development-snapshots.html?ref=xen-orchestra.com)) - Create a disk of 20GB ![install](https://xen-orchestra.com/blog/content/images/2014/Aug/install.png) Here is the summary: ![install2](https://xen-orchestra.com/blog/content/images/2014/Aug/install2.png) Let's go! After the install in the console, we need to connect this XenServer to Xen Orchestra, just add it in Settings: ![add](https://xen-orchestra.com/blog/content/images/2014/Aug/add-1024x206.png) And now, see the result on the main page (with a VM installed on it: so a VM in a VM in XenServer): ![see](https://xen-orchestra.com/blog/content/images/2014/Aug/see.png) ### Step 2: Explore Now, we open a console on your new XenServer 6.2.5 beta and see this: - kernel **3.10**.27-0.xs1.8.50.189.377584 - Xen **version 4.4**.0-xs83904-d Modern kernel, latest Xen possible! Hell yeah! But... we need to go deeper. ![We need to go deeper](https://xen-orchestra.com/blog/content/images/2014/Aug/1386271588578.jpg) ### Step 3: Profit Current stable of XenServer doesn't support Debian testing (Jessie) in paravirt mode. Why? Because [Pygrub installed lacks LZMA / XZ compression support](http://discussions.citrix.com/topic/330126-pygrub-shipped-with-xenserver-61-still-lacks-lzma-xz-support/?ref=xen-orchestra.com). Thus, do **NOT** dist-upgrade your Debian in Jessie in XenServer stable. Your VM will fail (can't boot). I choose to try it on this Beta version of XenServer. But, I prefer to replay things if I'm wrong, by doing a snapshot (this feature is accessible in XOA 3.3). ![snap](https://xen-orchestra.com/blog/content/images/2014/Aug/snap-1024x669.png) As you can see, a snapshot is created, and if I want, I can revert my VM to the previous state (also rename or delete): ![revert](https://xen-orchestra.com/blog/content/images/2014/Aug/revert.png) After a Debian upgrade and a reboot, surprise! It's works! ![consolepv](https://xen-orchestra.com/blog/content/images/2014/Aug/consolepv.png) **That's great! I hope Citrix will release soon a stable version for 6.2.5\. There is a lot of great things under the hood and it works out of the box with Xen Orchestra.** ### XOA: more than 1000 downloads! URL: https://xen-orchestra.com/blog/xoa-more-than-1000-downloads/ Last updated: 2014-08-20T17:28:14.000Z Just one month after our first XOA 3.0 release, we've got more than 1000 unique downloads (1100 right now). And we don't take into account manual installs. So, on behalf of XO team, **thank you!** We hope to continue this way, and with [your help](https://xen-orchestra.com/blog/pricing.html) dedicate all our resources to this great project. And another good news: XOA 3.3 will follow today. ### February: a big step in Xen Orchestra project URL: https://xen-orchestra.com/blog/february-a-big-step-in-xen-orchestra-project/ Last updated: 2014-08-20T17:18:26.000Z February was really an important month for the project, with our 3.x release. Also numbers sometimes talk themselves: - more than **9500 visitors** during the month (+40% compared to January, check the bump in the graph!) - more than **800 unique downloads** for XOA (all versions, without counting manual installations) - a lot of new [tweets about Xen Orchestra](https://twitter.com/search?q=xen%20orchestra&src=typd&ref=xen-orchestra.com), from very different places around the world ![feb](https://xen-orchestra.com/blog/content/images/2014/Aug/feb.png) What's next? A new release will be delivered probably next week, with nice features and a more reliable update system for the appliance. Details will following soon. Remember: **we are counting on you** to [get support](https://xen-orchestra.com/blog/pricing.html) or sponsoring us. Doing this way will allow us to dedicated all our resources to Xen Orchestra. ![Uncle-Sam](https://xen-orchestra.com/blog/content/images/2014/Aug/Uncle-Sam-270x300.jpg) ### Xen Orchestra 3.2 URL: https://xen-orchestra.com/blog/xen-orchestra-3-2/ Last updated: 2014-08-20T17:15:45.000Z We're back with a new version of Xen Orchestra! The big news is about console: it now works in Chrome browsers \\o/ Our patch sent to noVNC team [was merged yesterday](https://github.com/kanaka/noVNC/pull/338?ref=xen-orchestra.com). List of changes: - consoles in Chrome browser (do not forget to be logged to see it!) - better handling of dependencies - error notification when connection to xo-server is lost - console working for hosts (Dom0): it's also accessible directly from main view, but also in host view - deleting disks in a VM now requires a confirmation - new icon for console - all button are now functional in host view (saying "feature not implemented" if it's the case) - fix manual MAC addresses in VM creation (basically, now it works) Complete changelog is [here](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#320-2014-02-21). New appliance is available for our clients. Due to bugs in dependencies system (in bower), it's safer to re-download it than do an update. ![console in chrome](https://xen-orchestra.com/blog/content/images/2014/Aug/Capture-du-2014-02-21-104221-1024x750.png) ### Xen Orchestra 3.1 URL: https://xen-orchestra.com/blog/xen-orchestra-3-1/ Last updated: 2014-08-20T17:15:20.000Z Hi everyone! Just [one week after our first 3.0 release](https://xen-orchestra.com/blog/blog/new-major-release-for-xen-orchestra/), we are proud to present you the 3.1 version! We were efficient, with 11 bugs/enhancements fixed. Thanks people for actively reporting issues (morsik and hoerup reported more than 70% of our issues for this release!). #### New features - hosts consoles are now accessible (Dom0 console) - consoles are no longer accessible to guest users (non-authenticated) - pools and hosts names are correctly cut when too long - fix a display bug (about scrolling to the top, very annoying!) - you can now open links in a new tabs with middle-click or Ctrl+click - we display properly suspended state (blue dot) - display linux distro icon for Gentoo and Oracle - display VLAN in Interface panel for host view - natural sorting for every object displayed - display network associated to a VIF in VM view - migrate VM is now possible directly in VM view - remove actions buttons/links when they are not applicable Change log [is here](https://github.com/vatesfr/xo-web/blob/master/CHANGELOG.md?ref=xen-orchestra.com#310-2014-02-14). #### Update your existing XOA If you have already a XO Appliance running, you just have to update it: ``` service xo update ``` And after that: ``` service xo restart ``` If it fails once, try again, it will work. #### ... or download it! For our clients,the latest and up-to-date version (3.1) is available. We also made a new documentation for a [manual install](https://github.com/vatesfr/xo/blob/master/doc/installation/manual%5Finstallation.md?ref=xen-orchestra.com#manual-installation). ### New major release for Xen Orchestra URL: https://xen-orchestra.com/blog/new-major-release-for-xen-orchestra/ Last updated: 2014-08-20T17:10:58.000Z Hi everyone! After 6 months of hard work, more than 500 new commits (!), one LinuxCon, one FOSDEM, around 32000 visitors here, we are proud to present a new version of Xen Orchestra (release 3, codename "Clarinet"). Let's see what we have here! ![xo3](https://xen-orchestra.com/blog/content/images/2014/Aug/xo3.png) ## New features and cycle for 3.x branch Does it mean we found our release rate? (major version each semester). Well, hard to say, but this 3.x branch will be able to deal with a lot of new things before a new 4.x. Let's recap what's really new in our release: - new design (it seems pretty obvious :p ), single page app - everything is dynamic and auto-refreshed: everything happening on your server is immediately visible in every browser connected - auto-reconnect interface when you lost connection to xo-server, without manual refreshing - global statistics in main view - VM map, VDI map and other useful indicators in their respective views - brand new backend - almost every pieces of Xen information displayed in live on XO (from VM to task, snapshots, pools, IP, etc.) - a lot of things are editable (main objects name, description and RAM/CPU for VM etc.) - bulk actions on VM (stop, start, reboot, hard reboot/restart, deletion with associated VDI, migration) - event "current operation" on a VM ("orange dot" give you the information about what's happening right now to your VM) - nice notification messages are displayed - modal windows for critical operations (remove etc.) - VM deletion with their associated VDI. Combined with bulk action, you can really work faster - live search bar, filtering on anything (name, IP, whatever) - VM creation (with ISO or in HTTP mode, both works) - VM console with ISO mounting dialog + "Ctrl Alt Del" keys (I know how it's important for Windows users) - adding XAPI hosts - adding users with basic rights - ... and much more! Conclusion: you'll never need to manually refresh XO in your browser. ## Genesis of 3.x Here the small story of this release, if you are impatient about downloading, you can directly go to the next paragraph. - **September:** one month for [designing the main view](https://xen-orchestra.com/blog/blog/sketching-the-next-interface/) and get a rough idea of the rest. That's here we got the opportunity to redesign everything without thinking to anything else: only sketching with a pen! Plus we got a big event in New-Orleans and we also fix bugs from our current release. - **October:** we started to implement our drawings to real HTML views, with mockup data. This step was very important to calibrate our first thoughts previously done on paper. It's long process with a lot of trials and errors, new ideas/features and how to put them without losing usability. We also added features to the existing release, like an [event system for better scalability](https://xen-orchestra.com/blog/blog/new-alpha-release/). - **November:** get a nice static interface is one thing, create all the dynamic views are another. But we started it with a whole new framework: AngularJS instead of BackBone. This month gave us the opportunity to understand those new concepts. We started simply (login forms etc.) by adding complexity one step at a time. In parallel, we started to work on a better back end. A new data model, more flexible was started. At this stage, we managed to see a lot of informations from our data, but without any interaction possible so far. Noticeable breakthrough: a nice and clean search bar and its associated "flat" view. We also made some interesting benchmarks [between PV and PVHVM](https://xen-orchestra.com/blog/blog/debian-pvhvm-vs-pv/). - **December:** well, [our new design](https://xen-orchestra.com/blog/blog/introducing-new-interface/) needed to be connected properly to the new data model. And as we have a flow of real data for testing, we also see a lot of new things we didn't in the first place. Constant adaptation and evolution, Darwin will be proud ;) New features, new ideas, new problems, new solutions. But we made a lot of progresses, and it started to be usable for interactions: starting, pause, restart VM worked like a charm. - **January:** [we started to implement objects modifications](https://xen-orchestra.com/blog/blog/xo-situation-report/), first in the UI then in the backend. But we also have duplication and useless work involved to follow those new features. We choose to take the time to write some "helpers" and give again more flexibility to our back end, by an useful refactoring. We finally reach a point where maintenance is really easy now, as adding new features! (we added "bulk" action in few days only) - **February:** it started by a [great FOSDEM in Belgium](https://xen-orchestra.com/blog/blog/new-release-incoming/), and we were able to show to people how Xen Orchestra works with a real demo on the Xen booth. We also worked a lot to create VM directly in the interface: a nice challenge! And other good features were literally released each day: that's a good and firm sign that our model is strong now. We can release a new version and easily add features during next months. ## Download [Try it here](https://xen-orchestra.com/blog/) or [subscribe here](https://xen-orchestra.com/blog/pricing.html). ## Commercial support If you want professional support, it's now possible and included in our appliance:[ get more information here](https://xen-orchestra.com/blog/pricing.html). If you think our knowledge of Xen can help you in any way, contact us. If you just want to support us by getting... support (meh!), go on too! ![enter](https://xen-orchestra.com/blog/content/images/2014/Aug/enter.png) ## What's next? **What's next relies on you**. By taking [support](https://xen-orchestra.com/blog/pricing.html), you'll help us to finance this project, and by this allowing us to continue to develop new features quicker. Our ideal objective is to dedicate all our development resources on Xen Orchestra and its services. **Sponsoring** is also another way to help this project. You can also [report bugs](https://github.com/vatesfr/xo?ref=xen-orchestra.com) or give us ideas on the [community forum](https://xen-orchestra.com/forum?ref=xen-orchestra.com). ### New release incoming URL: https://xen-orchestra.com/blog/new-release-incoming/ Last updated: 2014-08-20T17:05:36.000Z We are just back from [FOSDEM14](https://fosdem.org/2014/?ref=xen-orchestra.com) :) Great event with a lot of stuff, and very interesting discussions for people getting on Xen booth seeing our demo. Thank everybody for your support! (and Xen team for sharing the booth!). We can now focus on the next release for this week: here is what's happening right now: ## Exciting new features - completely new interface - completely new backend - bulk action on VM (stop, start, reboot, migrate): send order to any number of VM simultaneously! - live search bar, filtering object when you type (filtering on name, description, IP, etc.) - Vm creation - Object edition (name, description, VM ram and CPU) - a ton of various fixes - and much more! ## New cycle We are entering in a new cycle of release: most of back-end work is done, know we can focus on adding features by short iterations (remember: "release often"). We'll publish a new appliance for the next release, and then you just have to run our update script to enjoy new features. ## Business model Our objective is to dedicate our workforce to Xen Orchestra. That's why we need to have resources on it. If you want to support the project, vote on roadmap, and/or get professional support, please [subscribe to our plans](https://xen-orchestra.com/blog/pricing.html). More we get support, more we can develop new features quickly! And if we get a large success, we can also hire new developers. You can also sponsor us in exchange of visibility in the project, or also get specific feature that you want quicker. ![enter](https://xen-orchestra.com/blog/content/images/2014/Aug/enter.png) ### XO Team at FOSDEM 2014 URL: https://xen-orchestra.com/blog/xo-team-at-fosdem-2014/ Last updated: 2014-08-20T17:03:41.000Z Want to see us during next [FOSDEM](https://fosdem.org/2014/?ref=xen-orchestra.com)? We'll be on Xen booth (Sat. 15:00 -> 17:00 and Sun. 10:00 -> 12:00), running a live demo of the next release! **The Xen booth will be in K building, level1 (number 20).** ![](https://xen-orchestra.com/blog/content/images/2014/Aug/fosdem14.png) ### XO situation report URL: https://xen-orchestra.com/blog/xo-situation-report/ Last updated: 2014-08-20T17:02:22.000Z Happy new year! 2014 will be a great year for XO, because we plan to release the first stable version with professional support. Before that, our next objective is the last alpha version (alpha 3), and probably a beta after. Today, let's make a report of our work. We manage, since October, to [redesign all the application](https://xen-orchestra.com/blog/blog/introducing-new-interface/) from both sides: a completely new interface and usage of AngularJS instead of Backbone. All this work is in the "next-release" branch in our repository. And believe me, it was a lot to do! (for Xo-web, we are almost [200 commits above](https://github.com/vatesfr/xo-web/tree/next-release?ref=xen-orchestra.com) the previous version). In consequence, this new design allows us to: - solve a LOT of bugs due to our new powerful data-model - display more informations in less views - reduce maintenance and complexity - be faster in new feature implementation ### Working stuff I can say now that our current work have no regression from the previous release, and brings new features: - more informations displayed for each object - globally a better interface - a search bar perfectly working, allowing a instant search on anything (IP of your VM, name of your SR, type of SR, you name it!) - link between each object (when you are on an host view, you can see its attached SR, click on it and you're on the SR page) - visualization tools (toolbar with space occupied by its VDI in a SR, another toolbar with RAM of VM on an host) - quick button to interact with your VM (stop, start, console view etc.) I'll try to do a demo in video as soon as I can. ### Plan Our features left for releasing this new version are (in order): 1. VM creation (we just started to work on it) 2. existing objects modification (e.g change the description or the name of an host or vm) 3. some UI improvement on main view (e.g allow bulk actions on VM's) 4. tags management We have 4 weeks to do so, but the priority is to provide at least the possibility to do basic Xen tasks (so the 2 first features are important). We are also thinking about how we can offer commercial support. This support will be our best resource to dedicate all our work on XO (we'll post something about that in next weeks). ### After that The next "next-release" (release-ception) objectives are (no order): - permissions for each objects (RBAC model) - console proxy - external user source (open-ldap, AD) - collecting metrics with RRD and display graphics in the interface And long-term ideas are still here: if we collect enough metrics, we can automate XO to take decisions, awake hosts, do scheduled tasks (snapshots, migrations), use "big" graphics views and interact with them etc. ### Introducing new interface URL: https://xen-orchestra.com/blog/introducing-new-interface/ Last updated: 2014-08-20T17:00:51.000Z As you may know, we are working on a new Alpha Release of Xen Orchestra (Alpha 3, codename "Clarinet"). This new version will introduce a totally new design, because we learned a lot of things about XAPI and what kind of information is really important to display. Thus, we searched a long time to deliver the best solution. Let's take a tour of this future release! ## Concepts Our main goal is to provide all "useful" informations in one place: that's why we made choices about what is important or not (thus, we are not rigid: we are open to suggestions/patches). More detailed views are accessible easily, with everything you need for configuring deeply your Xen infrastructure. Those screenshots are not definitives, so please consider it as a preview. ### Horizontal hierarchy For the "main view" (aka the default page), our choice were to display the hierarchy horizontally. The main order in XAPI is this one: Pool > Host > VM. So we divided our display in 3 columns. In one sight, you can understand how your VM are balanced between your hosts, and see pools separated by "blocks". As usual, an image is more explicit: ![main_view](https://xen-orchestra.com/blog/content/images/2014/Aug/main_view.png) ### Main informations, tooltips, hover... As you can see, we choose to display only few informations, but important ones: ![main_view_commented_1](https://xen-orchestra.com/blog/content/images/2014/Aug/main_view_commented_1.png) - global stats are on the "sub bar" **(1)** - each pool display its stats and its master host... **(2)** - ... and its shared SR with their allocated space **(3)**, which is very important - Hosts are displayed with their name and their respective memory allocation. **(4)** But tooltips and other informations appear when you hover on specific zones, for example: - when you hover on a shared SR, you have its allocation in %, and if you click on it, you will load the Storage Repository view: ![shared_sr_tooltip](https://xen-orchestra.com/blog/content/images/2014/Aug/shared_sr_tooltip.png) - each Pool gets a "quick" menu with useful actions: ![quick_pool_action](https://xen-orchestra.com/blog/content/images/2014/Aug/quick_pool_action.png) - when you hover on an host, you get its IP address, and % of RAM allocated on the host if you get on memory bar. You have also a quick dropdown menu: ![host_hover](https://xen-orchestra.com/blog/content/images/2014/Aug/host_hover.png) ![host_ram](https://xen-orchestra.com/blog/content/images/2014/Aug/host_ram.png) ![host_quick_menu](https://xen-orchestra.com/blog/content/images/2014/Aug/host_quick_menu.png) VMs gets our attention because they are "the main topic" of virtualization. If you use GMail, you'll be at home: ![vm_details](https://xen-orchestra.com/blog/content/images/2014/Aug/vm_details.png) - VMs gets a "grab" zone for drag n' drop (live migration) **(1)** - checkboxes allowing "bulk" actions (migrate, shutdown, start different VMs at the same time)... **(2)** - ... and its also display more option on the top toolbar **(3)** - a colored dot indicates the VM state (a tooltip will give you more details) **(4)** - when hovered, the "quick action buttons" allow to do usual actions in one click **(5)** - the "master" checkbox **(6)** allows selecting all Running (or Halted) VMs, or all VMs running on one specific host: ![supercheckbox](https://xen-orchestra.com/blog/content/images/2014/Aug/supercheckbox.png) The general menu regroup important views: ![main_menu](https://xen-orchestra.com/blog/content/images/2014/Aug/main_menu.png) When you click on "Add server", a clear view with a notice: ![add_server](https://xen-orchestra.com/blog/content/images/2014/Aug/add_server.png) The login dropdown menu is very similar to the previous alpha: ![login](https://xen-orchestra.com/blog/content/images/2014/Aug/login.png) ### Flat view with powerful search engine This time, we introduce a working search bar, using "Filter" tool from [Angular JS](http://angularjs.org/?ref=xen-orchestra.com). It's very fast, narrowing what you search from your objects (VM, host, pool, SR, tags for all objects etc.). We also created a "flat view" without any hierarchy, displaying everything. The search bar filter everything during your request. It's instantaneous! We'll introduce a more complex search system for another release (with syntax like "type: vm" etc.) The flat view with everything (yes, it's linked with detailed view of your object, e.g the vm Dev1 if I click on the line): ![flatview_all](https://xen-orchestra.com/blog/content/images/2014/Aug/flatview_all.png) When filtered with "SR" keyword (check the search field): ![flat_view_filtered](https://xen-orchestra.com/blog/content/images/2014/Aug/flat_view_filtered.png) ## Under the hood We switched from Backbone to [Angular](http://angularjs.org/?ref=xen-orchestra.com) for numerous reasons (Angular deliver more "tools" than backbone, and it's easier for us to integrate everything without writing too much code). The data model was also simplified, allowing easier contributions for people without any knowledge on XAPI. We are also working on the backend, fixing issues etc. ## When, when, when? We are doing our best to deliver as soon as possible this alpha release. Our goal stay the same: a stable version (at least beta) for this year, and a production release for early in 2014\. You want to help us? You can [subscribe](https://xen-orchestra.com/blog/pricing.html) (in order to work at full time on XO) or contribute, e.g: - test - debug ### Debian PVHVM vs PV URL: https://xen-orchestra.com/blog/debian-pvhvm-vs-pv/ Last updated: 2015-08-11T22:27:38.000Z This time, it's not a news about [Xen Orchestra](https://xen-orchestra.com/?ref=xen-orchestra.com#!/?pk%5Fcampaign=blog%5Fpvhvm), but a benchmark of virtualization modes: PVHVM vs PV. When I saw [the numbers from Rackspace](http://developer.rackspace.com/blog/welcome-to-performance-cloud-servers-have-some-benchmarks.html?ref=xen-orchestra.com), well... I choose to do my own tests here, despite it's in other context (small test lab). We'll (re)explain concepts first, then our test protocol and at least the results. ## PV, HVM and PVHVM - **PV (Paravirtualization)** is an original Xen concept, allowing running **modified** kernel in virtual machines to provide better performances than traditional way. Your virtualized OS "knows" it's running on a hypervisor, and makes call (I/O, network...) without a additional layer (he "talks" directly to the Hypervisor). That's why it will work on hardware which doesn't have any virtualization extensions (like Intel VT or AMD-V). More details can be found [on this page](http://wiki.xenproject.org/wiki/Paravirtualization%5F%28PV%29?ref=xen-orchestra.com). - **HVM (Hardware Assisted Virtualization)** is more a "traditional" way: Xen use Qemu to emulate PC hardware but extensions will boost performances. The good news is you doesn't need any modified kernel/OS: it doesn't know the presence of an hypervisor under. The "bad" is the hardware needed and the performance impact on I/O and Network load, because of this additional emulation layer - **PVHVM** is basically an HVM guest with special drivers for disks and network: those drivers are known as "GPLPV" on Windows, and are included in Linux for 2.6.36+ kernels ([details here](http://wiki.xen.org/wiki/Xen%5FLinux%5FPV%5Fon%5FHVM%5Fdrivers?ref=xen-orchestra.com)). And yes, Debian 7 (Wheezy) default kernel is compiled with those drivers. So if you install a Debian 7 in HVM mode, you are running PVHVM out of the box! More details on PVHVM perfs and architecture [here](http://www.slideshare.net/fullscreen/xen%5Fcom%5Fmgr/linux-pv-on-hvm/?ref=xen-orchestra.com). - **PV in an HVM Container (PVH)** : wait... what?? Ok, it's a surprise: PVH will be another virt mode possible in Xen 4.4\. The main difference is the "order" of mode: in PVHVM, you have PV driver IN a HVM guest. This time, it will brings hardware extensions IN a PV guest. So you'll boot a classical PV virtual machine and then uses extensions when it can. No more emulation and possibly the best combination possible. Sadly, I can't test it now, be don't forget this PVH mode, you'll probably heard about it next year. ## XenServer and PV or HVM It's not complicated to create PV or HVM Debian (or derived) guest in [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver?pk%5Fcampaign=blog%5Fpvhvm): if you install a VM with its associated template, it will be by default a PV guest. For an HVM guest, you'll use "Other install media". That's all! If you want to know in which mode you are, here is the tip for Debian: go in `/etc/default/grub` and put `"GRUB_CMDLINE_LINUX=loglevel=9"`. Reboot it, and read the dmesg output, you shall read something like: ``` Netfront and the Xen platform PCI driver have been compiled for this kernel ``` ## Benchmarks This is the first run with UnixBench, more bench will come with I/O and network soon. Our test platform consist of: - i5-3470 CPU @ 3.20GHz (4 cores and **Intel VT**) with 8GB RAM on XenServer 6.2 - iSCSI storage on Nexenta Community, 2TB with SSD L2ARC cache - Debian 7 guests, with 4 cores, 2GB RAM and 20GB of HDD. All benchmarks are done after a fresh install. ### UnixBench Two modes are used for UnixBench (in fact the default mode, started by ./Run) : first is a single test pass and the next one is a 4 parallel copies of tests. ![unixbench1](https://xen-orchestra.com/blog/content/images/2014/Aug/unixbench1.png) ![unixbench8](https://xen-orchestra.com/blog/content/images/2014/Aug/unixbench8.png) Those results are totally coherent with [the original benchmark](http://developer.rackspace.com/blog/welcome-to-performance-cloud-servers-have-some-benchmarks.html?ref=xen-orchestra.com), done by Rackspace. UnixBench running in Debian PVHVM mode offers respectively **205% and 128% performance boost over PV**. In other words, UnixBench says that **Debian in PVHVM is 2 or 3 times faster** than Debian PV. ### Kernel compilation time ![kernel_time](https://xen-orchestra.com/blog/wp-content/uploads/2013/11/kernel_time.png) This time, in "real" condition, a Kernel compilation, we saw that **PVHVM can do the task 15% faster**. Not bad! ### FIO ![fio1](https://xen-orchestra.com/blog/content/images/2014/Aug/fio11.png) ![fio2](https://xen-orchestra.com/blog/content/images/2014/Aug/fio21.png) We can tell that PVHVM brings a **clear bonus in Random Read configuration** (+16% than PV), which is pretty consistent to the Kernel compilation time benchmark. In Random Write, it's very close (+5% max). Not displayed here but also important, the **latency were slightly reduced** on PVHVM guest (14% faster in r-read and 4% in r-rwrite). CPU load is also a bit lower: only good news here! ### Phoronix Test Suite Very convenient for our case, PTS provides a "turnkey" solution for benchmarking Unix hosts. Let's see different use cases. All benchmarks are [available here](http://openbenchmarking.org/result/1311129-SO-1311125SO54?ref=xen-orchestra.com). ![p1](https://xen-orchestra.com/blog/content/images/2014/Aug/p1.png) 7-Zip compression doesn't seem to be impacted by PVHVM mode. ![p2](https://xen-orchestra.com/blog/content/images/2014/Aug/p2.png) But it's not the same for SQLite database! PVHVM is 15% faster than PV. ![p3](https://xen-orchestra.com/blog/content/images/2014/Aug/p3.png) Apache is also faster (\~14% faster in PVHVM) ![p4](https://xen-orchestra.com/blog/content/images/2014/Aug/p4.png) OpenSSL benchmark indicates absolutely no performance boost. ![p5](https://xen-orchestra.com/blog/content/images/2014/Aug/p5.png) PHP gets a small performance augmentation in PVHVM (5%). ### Conclusion PVHVM Debian Xen guests running modern hardware are faster than "classical" PV. And as Debian embed in its current kernel all the needed drivers (PVHVM work out of the box), you can get more performance for your current Xen or [XenServer](https://xen-orchestra.com/?ref=xen-orchestra.com#!/xenserver?pk%5Fcampaign=blog%5Fqemu) infrastructure for a small cost. ### 6000 visitors in October! URL: https://xen-orchestra.com/blog/6000-visitors-in-october/ Last updated: 2014-08-20T16:40:22.000Z ## Interest Getting 6000 visitors is not the only good news: our progression is very strong since June: ![october](https://xen-orchestra.com/blog/content/images/2014/Aug/october.png) And our participation to 3 events allows us to get a better visibility, that's why I want to thanks [Lars Kurth](http://wiki.xen.org/wiki/User:Lars.kurth?ref=xen-orchestra.com) for his help. But getting that much interest would not have been possible without a lot a people searching for a Xen web interface: it's time for the Web now. With powerful tools as [node.js](http://nodejs.org/?ref=xen-orchestra.com) and [Twitter bootstrap](http://getbootstrap.com/?ref=xen-orchestra.com), and of course [XAPI](http://wiki.xen.org/wiki/XAPI?ref=xen-orchestra.com) for controlling Xen, we can manage to deliver a fast, scalable and powerful solution for the end of this year. ## Participation As the interest around XO is growing, we've got a new community member working directly on the code (hello mclueppers ;) ) and more testers ready to [push the limits of our architecture](https://xen-orchestra.com/blog/blog/new-alpha-release/). If you want to join us or just have questions around XO, we are available on our IRC channel (#vates on Freenode) or in our [Forum](https://xen-orchestra.com/blog/forum). We are working hard to release in time, but remember: the more the merrier! **Update: the exact number is 6133 visitors :)** ### Sketching the next interface URL: https://xen-orchestra.com/blog/sketching-the-next-interface/ Last updated: 2014-08-20T16:38:31.000Z After our [previous release](https://xen-orchestra.com/blog/blog/new-alpha-release/), we choose to bring a better interface for XO. That's why we are currently thinking and sketching for the next step. We'll explain quickly our way to do so. ## Explore The first thing you need to build a good interface, is to know what features you want to bring to your users. For the XAPI, [there's really a lot!](https://support.citrix.com/servlet/KbServlet/download/25589-102-666255/xenenterpriseapi.pdf?ref=xen-orchestra.com) Thus, we did a full pass on all the documentation, extracting features one by one (we have currently almost finish this). Well, it's a bit tiresome, but very useful too: we discover interesting possibilities we missed before. There's probably few persons who have actually read the whole stuff (if you are an API specialist at OpenStack or Cloudstack: you are not alone!). ## Inspire We started this work a long time before, but knowing all the features and those we want to put in priority changed our way to get ideas. We are now more in the "hard facts", and we need concrete ways to deal with that. In this gigantic space which is Internet, we got a lot of material to be inspired by: indeed, we are not the first to cope complex data display and interactions. Some websites and mobile applications (e.g GitHub and Gmail) gave us nice hints for saving our balance between features and simplicity. The big JavaScript ecosystem is also a precious ally: tools can give you ideas (search, display, filter, etc.) ![Gmail interface.](https://xen-orchestra.com/blog/content/images/2014/Aug/131126.jpeg) Gmail interface. ## Draw Sometimes, our best friends are pencils, erasers and papers. Good old technologies ;) Why we don't use more advanced tools? As a first run of drawing, we need to be free as possible: a software will limit our imagination. We'll release our progresses as soon as we have tangible display. But believe me, we are working on very exciting features and displays, which will **simplify and enhance greatly your Xen usage**. ![sk](https://xen-orchestra.com/blog/content/images/2014/Aug/sk.jpg) Our first drafts ### New alpha release URL: https://xen-orchestra.com/blog/new-alpha-release/ Last updated: 2014-08-20T16:36:10.000Z Here is our new release of XO, with nice features embedded. Let's take a closer look. ### Robustness [As planned](https://xen-orchestra.com/blog/blog/new-features-incoming/), we now manage **pool master change in live**: if you decide to change your pool master while XO is connected to it, we detect it and re-create instantly a connection "on the fly" to the new master, seamlessly. And our implementation is valid for another possible case: **you can connect to any host on the pool**, we will redirect automatically the connection to the master. ### Scalability Our new **cache system, coupled with XAPI events**, allows XO to work with big XenServer infrastructure. As we get only what is changed, we can deal with more nodes: between previous and current implementation, we got by at least **one factor less CPU time**, and by 2 factors less bandwidth used. And because a picture say more than words: ![xo_scalability](https://xen-orchestra.com/blog/content/images/2014/Aug/xo_scalability.png) ### Download You can download the [XO Appliance here](https://xen-orchestra.com/blog/pricing.html) and read [instructions here](https://github.com/vatesfr/xo/blob/master/doc/installation/xoa%5Finstallation.md?ref=xen-orchestra.com) (manual install is also possible). ### What's next? Now, we are starting a new run, with these objectives: - prepare the backend for the next features (in xo-server), like Storage management, VM creation, search engine etc. - re-thinking the interface for a better integration of these features We'll share our next mock-ups and thoughts as soon as possible. You are welcome to [discuss on the project](https://xen-orchestra.com/blog/forum/) if you want. ### New design for the website URL: https://xen-orchestra.com/blog/new-design-for-the-website/ Last updated: 2014-08-20T16:33:10.000Z A short post to tell you that [our website](https://xen-orchestra.com/blog/) get a new design. If you have any comment or suggestion, feel free to comment. ### New features incoming URL: https://xen-orchestra.com/blog/new-features-incoming/ Last updated: 2014-08-20T16:29:52.000Z This week, we'll release interesting features in Xen Orchestra. ### Pool master redirect After a report from "msciciel" in [our forum](https://xen-orchestra.com/blog/forum/index.php/8-pool-master-change), we decided to implement a redirect mechanism: if you add a server and it's not the pool master, we automatically and seamlessly redirect connection to the actual master. It needs some adjustments in GUI (to tell the user that we are not connected to the slave but redirected to the master), but it works now. We are currently working on **a live** pool master change without any hiccups. Believe us, it's not trivial when the XAPI simply closes the existing connection without any other clue of what's happening. ### Event tracking It's planned in our road map since the beginning, but now it's here! Xo-Server use the event system for the XAPI to refresh its data. What does it mean? - scalability: less calls to XAPI due to our cache system, allowing more XO clients without any pressure on your Xen infrastructure - resources friendly: no longer basic polling every 5 seconds: because we fetch everything everytime, it was "CPU/RAM/Bandwitdht/whatever" consuming. It might helps people using [a LOT of VM's](https://xen-orchestra.com/blog/forum/index.php/attachment/52451395eb4f0%5Fzrzut%20ekranu3.png) - faster refresh time: as we receive immediately events from XAPI, we removed the previous polling time. Thus, information from XAPI appears faster in your web GUI We will push the code and a new XO Appliance with latest version updated this week (or week-end). We'll keep you in touch here. ### What's next? Next big steps are: 1. VM creation, allowing XO cover basic XenCenter features 2. GUI optimization with better classic views 3. Events between Xo-Server and Xo-Web (reducing again the load for Xo-Server and the latency for Xo-Web) 4. ACL's We are open to any suggestions or questions: [our forum is the best place](https://xen-orchestra.com/blog/forum) for that. ### Video from Xen User Summit/Linux Con URL: https://xen-orchestra.com/blog/video-from-xen-user-summitlinux-con/ Last updated: 2014-08-20T16:31:28.000Z If you want to get an overview of Xen Orchestra project, this news is a nice opportunity to do so. Here is our session recorded in New Orleans. Slides are also [available](http://xenproject.org/component/allvideoshare/video/latest/xen-orchestra-xapi-and-xenserver-from-the-web-xpus13-lambert.html?ref=xen-orchestra.com). Get the full story of Xen User Summit [on linux.com website!](https://www.linux.com/news/enterprise/cloud-computing/740817-great-talks-mark-first-xen-project-user-summit?ref=xen-orchestra.com) ### Users and servers persistence URL: https://xen-orchestra.com/blog/users-and-servers-persistence/ Last updated: 2014-08-20T16:28:24.000Z A short news about the software itself: we have successfully implemented users and servers persistence in a database, using NoSQL ([Redis](http://redis.io/?ref=xen-orchestra.com)). Now, you can reboot/restart, you'll never lost your users nor your configured servers. Admin view now have two "pages", Users and Servers Management. Do not forget to log-in before doing these operations, or it won't work. If you use [latest appliance available](https://xen-orchestra.com/blog/pricing.html), it's already included. If you have the previous one, please do a "service xo update" then "service xo restart" to get those features enabled. Enjoy XO! ![Multiple choice admin page](https://xen-orchestra.com/blog/content/images/2014/Aug/Capture-du-2013-09-11-170349.png) ![Servers management view](https://xen-orchestra.com/blog/content/images/2014/Aug/Capture-du-2013-09-11-170406-1024x286.png) ### Meet us at Xen User Summit (LinuxCon) URL: https://xen-orchestra.com/blog/meet-us-at-xen-user-summit-linuxcon/ Last updated: 2014-08-20T16:26:19.000Z Good news everyone! ![professor-farnsworth-right-300x241](https://xen-orchestra.com/blog/content/images/2014/Aug/professor-farnsworth-right-300x241-150x150.png) We'll be present at LinuxCon in New Orleans (September 16 - 18, 2013), precisely in the Xen User Summit. If you want to see our talk about Xen Orchestra, please [check the schedule](http://linuxconcloudopenna2013.sched.org/event/edb5791b29af0fe974dd97d29eb3f517?ref=xen-orchestra.com), it will be **Wednesday, September 18, 2:30pm to 3:00pm**. Furthermore, we'll be available before and after the talk: feel free to contact us if you want to talk or exchange ideas around the project. It's a great opportunity for us to expose our project directly to our public, so if you can be here, don't miss it! I'll put the slides here just before my talk. And we'll publish photos and feedback of the event as soon as possible, to share our thoughts about this **really** big event. See you in Louisiana! ### New XO on tracks! URL: https://xen-orchestra.com/blog/new-xo-on-tracks/ Last updated: 2014-08-20T16:20:39.000Z As you may know, we choose to rebuild XO from scratch with Javascript (node.js), [for numerous reasons](https://xen-orchestra.com/blog/blog/progress-report-and-planning/). And we did it! For now, this version is usable without any configuration in the code or config files. ### Working stuff This version use node.js for xo-server and is single web page app for xo-web. We managed to get these features working: - VM's consoles (using NoVNC): it works with Firefox, with glitches sometimes. We are working on it to provide a better integration. Plus we are helped on this stuff by Harrie, a Citrix Intern (thanks to him, we've got this first console integration working) - "Add server" button on the start page. Despite persistent storage is yet implemented, you can add every XAPI enabled server on XO, as long as you don't kill xo-server's process. - Auto refresh interface: we do it basically so far, but if anything happened (new VM, state change etc.) you'll see it "live" on XO interface - Basic VM actions: stop, pause/play, reboot buttons are working if you are authenticated - Better storage display with % of occupation. ### Next steps This a an alpha version, our goal is to fix majority of bugs and continue to add features. The next big step is about "Vm creation" feature, allowing basic usage of XO for every day utilization. Our objective (release in September) is always possible. We'll give you a beta version early in September. **Stay in touch!** ### Progress report and planning URL: https://xen-orchestra.com/blog/progress-report-and-planning/ Last updated: 2014-08-20T16:24:17.000Z *This post is a follow up of [Current state and perspectives](https://xen-orchestra.com/blog/blog/current-state-and-perspectives/).* I has been a while since my last post but here it is: a progress report of the Xen Orchestra project. This last two months we have been exploring and testing new technologies which will, IMHO, considerably improve XO. ## Current work ### Single-page client We have taken the time to better understand \_[Backbone.js\_](http://backbonejs.org/?ref=xen-orchestra.com) and \_[Marionette.js\_](http://marionettejs.com/?ref=xen-orchestra.com) by prototyping a bug tracker which we may release in October if we have enough time to work on it. Strong of that knowledge, we plan to release at the end of July a new alpha version of XO-Web, implemented only in JavaScript and which connects directly to XO-Server using the WebSocket technology. This version will be much more responsive and should feel like a local application. ### Node.js implementation XO-Server We care about choosing a good technology for XO-Server, that's why we're currently working on it :) We have started to re-implement it using [node.js](http://nodejs.org/?ref=xen-orchestra.com) instead of PHP to ease its maintenance and evolution, and we are really happy of this choice. It's not quite polished enough to be released yet but it will be very soon, stay tuned… ### Interactive visualization At last but not least we are working on a network visualization for XO. ![XO graph visualization](https://xen-orchestra.com/blog/content/images/2014/Aug/graph.png) Thanks to the wonderful [d3.js](http://d3js.org/?ref=xen-orchestra.com) we already have an interactive graph of the network topology but there still is a long way to go to have the customizing graph we dream of. The first version will be included in the next version of XO. ## Next release The next major version of Xen-Orchestra will be released next September and will include the single-page client, the new node.js-based XO-Server and the prototype of the visualization tool. ## In the future This is still very far from now but our objective is to integrate XO in an appliance, delivering our interface without any configuration or installation. A great thing will be XO installed by default in XenServer to allows user to easily see its servers simply by typing their addresses in web browsers. Packaged version in Debian or CentOS is another possible way. But we have a long way to go before getting there: we need to release this version and to have your feedback to make XO more feature complete and easy to use :) ### Migrate from Xen to XenServer URL: https://xen-orchestra.com/blog/migrate-from-xen-to-xenserver/ Last updated: 2017-11-04T17:36:01.000Z As you may know, [XenServer is now OpenSource](https://xen-orchestra.com/blog/xenserver-is-now-opensource/). It brings a lot a nice features, but your existing virtual infrastructure is on older Xen? Don't panic, here is a way to migrate to the new one, without pain. This tutorial explain how to migrate from Xen 4 on Debian 6 to XenServer 6 (6.2 precisely). First thing first, some definitions: - xenserver1 is your new XenServer; - oldxen1 is your old Xen Server on Debian 6; - vm1 and vm2 are vm existing of oldxen1. ### Prerequisite In this article, we suppose your VM are PvOps (for Debian 6 or 5 with 2.6.32 backported kernel). They also need to be PyGrub compatible (you can see how to do[ that in this Debian documentation](http://wiki.debian.org/PyGrub?ref=xen-orchestra.com)). For other distros, please read their respective doc. ### Migration So, we need to migrate those vm (vm1 & 2) from "oldxen1" to "xenserver1". You need to download a very nice Python script to do that almost automagically. You can [find it here](http://www-archive.xenproject.org/files/xva/?ref=xen-orchestra.com), it's **xva.py**. You need to put this script in your Dom0. - Shutdown your VM (I think you can maybe doing it almost live with snapshot, but I think it's too risky) - On your old dom0 (oldxen1), start the script like this (there is an help on the script, you can read it for more options): ``` ./xva.py -c /etc/xen/vm1.cfg -n vm1 -s xenserver1 --username=root --password="mypassword" ``` - see that your disk are streamed - when it's done, start the Vm on our XenServer - that's it! repeat the same operation for your others VM. If you got this error: ``` ssl.SSLError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:581) ``` You can fix it by adding `--no-ssl` in the end of the xva command, and everything will work! > Thanks Diego in the comments for the `--no-ssl` trick! **Now you can enjoy XenServer :)** #### Default SR If you have an error message telling `DEFAULT_SR_NOT_FOUND`, please choose one on your XenServer. Follow this procedure: - `xe sr-list` - get the UUID of the SR you want to be the default one - `xe pool-param-set default-SR=UUID_of_your_SR uuid=UUID_of_your_pool` (use TAB for finding the last uuid, because there is only one choice) Now you can try again to migrate your VM from old Xen to XenServer. ### Other ways - You can copy only the system disk and manually copying files for other disks. But if you have only one big disk for your VM, it's not an option. - Also, you can make a "file backup" of your VM (basically a tarball), copy the tarball on a USB drive, and untar it in a pre-existing VM on XenServer side and overwrite existing files. Remember, "Everything is a file" on Linux! ### XenServer is now Opensource URL: https://xen-orchestra.com/blog/xenserver-is-now-opensource/ Last updated: 2014-08-20T16:11:33.000Z Hi everyone, What a great news! Citrix decides to release XenServer Open Source (source [here](http://www.citrix.com/news/announcements/jun-2013/citrix-launches-open-source-xenserver.html?ref=xen-orchestra.com) and [here](http://blog.xen.org/index.php/2013/06/25/xenserver-org-and-the-xen-project/?ref=xen-orchestra.com)). It gave us a lot of possibilities. First, it confirms our first choice during XO reboot, working with XAPI. As you know, XenServer is based on it: we are on the right way to integrate XO in a complete XenServer environment. Then, we start to think about a way to deliver XO out of the box with XenServer. Despite we're not here right now, we think it can be very powerful to build virtual infrastructure quickly and without installing any software to manage it. Stay in touch, we'll push a news on XO by this week end. ### Working with giants URL: https://xen-orchestra.com/blog/working-with-giants/ Last updated: 2014-08-20T16:10:08.000Z After almost a week in Dublin, we’re back with a debrief of the [Xen Hackathon](http://www.xen.org/community/events/xenhackathondublin2013.html?ref=xen-orchestra.com). Please note this is from our point of view and that we’re not kernel or hypervisor hackers. ## Google Docks: our place to work We were really impressed by Google’s building (Google Docks). The atmosphere was really relaxed, with a lot of small places to work, and a very good food at lunch (for free!). The space dedicated to Hackathon was fantastic: on the 11th floor, no offices, and a very very exceptional view on Dublin, all around us. Oh, and a very big terrace… We can’t have any excuses regarding our productivity. Thanks to Guido for the organization and the opportunity to be here! ![A nice view of the Google Docks building.](https://xen-orchestra.com/blog/content/images/2014/Aug/gd1.jpg) A nice view of the Google Docks building. ### Participants One of thing that was very interesting was that a lot of people who are doing Open Source software here were paid by -very- big companies (Google, Oracle, Citrix, etc.). We felt very small comparatively, but at the Hackathon, people were not “representing” a company. You’re just a hacker working on a project. In my opinion, that’s the magic of Free and Open Source Software: everyone can contribute, there is no bureaucracy or hierarchy. If your project responds to a need, you’ll have people around you, no matter where you from. We felt [the Bazaar model](http://en.wikipedia.org/wiki/The%5FCathedral%5Fand%5Fthe%5FBazaar?ref=xen-orchestra.com) was very present at this event. ### How it works To ensure good participation and collaboration in the sessions, Lars put stickers on the window. Each table was identified with a number. You just have to fill a sticker and put it at the right place and you could find people working an a specific project. Simple and efficient! It was just a tool, to find people, connect and guide discussions. The Hackathon was really informal, and that’s why it was great. You can talk to everyone, get views, advice and ideas from everyone. But we needed the sticker framework to start, because many people didn’t know each other. For example, our first conversation about Xen Orchestra was with Andrew Cooper. We talked to him because he sent us a patch a few weeks ago. He uses our software, and he had some great feedback for us (see [here](https://github.com/vatesfr/xo-web/issues/13?ref=xen-orchestra.com) and [here](https://github.com/vatesfr/xo-web/issues/12?ref=xen-orchestra.com)). After few hours, we managed to fix those bugs. We also discovered that Xen Orchestra is pretty scalable, because it was tested with numerous hosts and Vms. Thanks you to Andrew for the feedback. The other good thing at the Hackathon were unexpected ideas from people working on something completely different. An example was a conversation with Boris Ostrovsky from Oracle. After seeing our molecule view, he asked if we can build a XAPI based system in Xen Orchestra using drag and drop. A real challenge, but a really exciting idea. ![Session organization, with Dublin in background.](https://xen-orchestra.com/blog/content/images/2014/Aug/hack1.jpg) Session organization, with Dublin in background.\[/caption\] ### End of the first day! Time flies. By Thursday evening the Hackathon wasn’t yet over. Lars took out everybody (40!) to a very nice restaurant, not far from Google Docks. We drank a beer first: another opportunity to talk with people. The wine and food was great (I never tasted a Gran Sasso before, thanks Dario). But it was a little harder to participate in a conversation because of the noise. Clearly normal with a lot of people! The dinner was a great way to build relationships with people and get to know them, beyond the technical work happening at the Hackathon. I admit we were very exhausted at around 11pm and we decide to go to sleep to recover. Indeed, the next day was very intense. ### Friday Last day, but a very important one: everyone now knows who’s who, and we know the place. We had a productivity leap. Discussions were very intense and focused on specific points, developing a very creative atmosphere: we saw whiteboard discussions or conversations in groups everywhere. The necessary organization in the first day provided room for more flexibility now. It’s interesting to see how the event evolved. It’s a lot better when you know who is the right person for your problem. Everything went smoothly. To get some fresh air, we enjoyed the terrace to get a group picture. Lars surprised everybody with its secret remote. Well-played! ![](https://xen-orchestra.com/blog/content/images/2014/Aug/group2.jpg) Hackers united! ### XAPI questions Our next step was to question the Citrix and Rackspace guys about XAPI behavior. We participated in a very interesting meeting about XAPI (with Lars Kurth, David Scott, Rob Hoes, John Garbutt, Jon Ludlam, Julien Fontanet and I). It was great from project management perspective. But we also learned a lot about the API and the people working on it. John Garbutt told us about HyperGlance, which provides nice 3D visualitions for OpenStack. It gaves us a great source of inspiration. Then, Jon Ludlam showed us a proof of concept of a Javascript interface for XAPI. It will provide us a very good base for getting console and RRD. I think this project will boost XO significantly because it will pave the way for us. Then he helped is using XAPI in the best way to collect metrics. Finally, we used the rest of the day to gather and write down every single idea, suggestion and the things we learned (it’s better to write everything when it’s fresh in memory) ## Global feedback This Hackathon was a mix of a good place, good people and good organization at the same time. This kind of combination allowed a lot of discussions, exchange of viewpoints, spontaneous creativity and a better understanding of the Xen Project as a whole. If the objective is “to give developers the opportunity to collaborate with other developers as well as allowing everyone to put names with faces”, I think we can say: **mission accomplished!** For the Xen Orchestra project, I can already say that it will give us a lot of thing to process: it was far beyond our expectations. We would like to thank everybody there, especially Guido for making it possible and Lars for coordinating people, which is not trivial when you are 40\. Also thank to those companies believing in Open Source community, allows us to meet despite our geographical distribution. There’s something I’ve learned at this event: **hacking is not only modifying the code, it’s sharing your knowledge.** That’s really essential for Open Source software. ### Current state and perspectives URL: https://xen-orchestra.com/blog/current-state-and-perspectives/ Last updated: 2014-08-20T16:02:45.000Z Hi everyone, The last (and first ;)) release of Xen-Orchestra go back to more than a month now and we haven't given you a lot of news. We have initially hoped to release a bug fix version since but unfortunately we have been quite busy with other projects. But do not fear for the future of XO: we are committed for the long term and we have some interesting research projects for this summer that I would like to present. :) We will receive three interns in June, one for one month and the two others for two months. Each of these trainees will be working on a different subject and will publish at least one article presenting their results on our blog. Their work is not intended to be directly integrated into the source code but will instead help us discover and try out new technologies which, if proven suitable, will quickly find their way to the final product. ## Making XO-Web a [a single-page application](https://en.wikipedia.org/wiki/Single-page%5Fapplication?ref=xen-orchestra.com) Our goal is to make Xen-Orchestra as pleasant to use as possible, and one of the key factor is *reactivity*. For instance, currently when you click a given VM on the VMs page, even if the page loads quite fast (depending on your web connection of course ;)), you can feel a small delay before the actual information shows up. The easy way to answer this latency problem is to avoid (or limit) round-trips to the web server. To achieve this purpose we would like to turn XO-Web into a single-page application. Because we are already using it throughout XO pages, \_[Backbone.js\_](http://backbonejs.org/?ref=xen-orchestra.com) (with the help of \_[Marionette.js\_](http://marionettejs.com/?ref=xen-orchestra.com)) is the library this functionality will be based upon. The key points that will be explored are: the performance (including on smartphones) and the compatibility with the web browsers. ## Implementing XO-Server using \_[node.js\_](http://nodejs.org/?ref=xen-orchestra.com) They have been some criticisms regarding our choice of developing XO-Server in PHP instead of using dedicated tools such as *node.js*. This choice was simply made because PHP was the technology we were familiar with, but indeed, it may not have been the best choice. I believe, because the project is still young, that it is the right moment to consider this question and to create a prototype of a *node.js*\-based XO-Server which may become the new official implementation. The main questions that will need to be answered are: - Is it easier to develop and maintain than the current system? (Probably) - Is it more efficient? (Ability to handle a large number of XCP servers, client connections, memory consumption) - Can the JavaScript code be as reliable as the existing one? - On which systems can this be deployed? (Debian, CentOS?) ## Designing advanced interfaces We intend to make XO not only a tool to manage your Xen network but also a great interface to view and explore it. ![Molecule design for XO.](https://xen-orchestra.com/blog/content/images/2014/Aug/img3.png) Some preliminary research has been done in this area but now we need to make it real by developing some working prototypes. We will mainly look into \_[processing.js\_](http://processingjs.org/?ref=xen-orchestra.com) but also into \_[D3.js\_](http://d3js.org/?ref=xen-orchestra.com), \_[BonsaiJS\_](http://bonsaijs.org/?ref=xen-orchestra.com) and \_[verlet-js\_](https://github.com/subprotocol/verlet-js?ref=xen-orchestra.com) to see which library fit the most our needs. Once done, we will prototype some interfaces and see how much they serve the usability of XO. As for the other subjects, we will look carefully at the performance (on smartphones too) and browser compatibility. ### Xen hackathon URL: https://xen-orchestra.com/blog/xen-hackathon/ Last updated: 2014-08-20T16:00:18.000Z We're going to Dublin this week, for the [Xen Hackathon](http://www.xen.org/community/events/xenhackathondublin2013.html?ref=xen-orchestra.com). And this year, the event will be hosted by the Ganeti team at Google EU headquarters. ![XenHackathon](https://xen-orchestra.com/blog/content/images/2014/Aug/XenHackathon.png) We'll have the opportunity to discuss with a lot of [Xen specialists](http://wiki.xen.org/wiki/Hackathon/May2013?ref=xen-orchestra.com#Confirmed%5FAttendees): from XAPI to Xen GUI, people from Google, Citrix, Oracle, Broadcom, OpenNebula, Amazon Web Services and so on, will be there. This kind of event is great for Xen Orchestra project, because we'll be able to share our ideas, questions (mainly about XAPI) and roadmap with them. You'll get a full debrief next week, with an enhanced XO's roadmap. If you are a confirmed attendee for the event, see you Thursday! ### XO forum opened URL: https://xen-orchestra.com/blog/xo-forum-opened/ Last updated: 2014-08-20T15:58:55.000Z You can now sign in and create discussions [on our new forum](https://xen-orchestra.com/blog/forum). It's a better place to talk about project or troubles you may have installing/configuring XO. **See you there!** ### First release out URL: https://xen-orchestra.com/blog/first-release-out/ Last updated: 2014-08-20T15:57:12.000Z 2 month earlier, we made a presentation at [FOSDEM about XO](https://xen-orchestra.com/blog/blog/back-from-fosdem-2013/). In this presentation, we estimated to have a first release in march. And here we are! ## XO 1.0 "Archlute" We think "release often" is a good policy, even if our software is not completed, because it's a good way to expose our work and to have feedback about it. Indeed, we would like more time to present a more "polished" product. Consider this release as a beta, but don't be afraid about connecting it to your XCP/XenServer infrastructure: there is absolutely no interaction, just a bunch a data displayed. So, there is **no risks**! ## Kind of "beta" test If you are interested to: - provide feedback - give ideas - report bugs - contribute - just test it You are welcome to download by cloning repositories ([here for xo-server](https://github.com/vatesfr/xo-server?ref=xen-orchestra.com) and [here for xo-web](https://github.com/vatesfr/xo-web?ref=xen-orchestra.com)) on Github. If you want to report issues, go on our ["meta" repository here](https://github.com/vatesfr/xo?ref=xen-orchestra.com). Now, our objective is to fix any major issues, refactoring the code and give you a full featured 1.x branch (e.g : sell all data of XCP servers). Then, we'll create a 2.x branch with enabled interactions (start, pause VM etc.) Enjoy! ### First release scheduled URL: https://xen-orchestra.com/blog/first-release-scheduled/ Last updated: 2014-08-20T15:55:37.000Z I'm happy to announce that XO 1.0 will be released at the end of march (Thursday, March 28). This first release (codename "Archlute") will offer the possibility to view all important data from your XCP servers (Vm location on server, host memory, storage repo, templates etc.). This version is compatible and tested for XCP Iso (CentOS based) or Debian + Xapi (via Kronos project). XO 1.0 will be a great step to give us feedback about installation, perfs and UI without risking anything on your XCP infrastructure, because we'll focus on interactions -e.g destroy/create VM- for the next one, the 2.0, codenamed "Baryton". How many days until the release? Play "The Final Countdown" in your head, sorry to ruin your day ;) ### Users and permissions in XO URL: https://xen-orchestra.com/blog/users-and-permissions-in-xo/ Last updated: 2014-08-20T15:54:12.000Z Users management in XO takes an important place. A recurrent question is "why managing users in XO while XCP can do it?". Let's analyze how XO is dealing with users and why it's not the same goal as XCP. ## XO location It's [more a reminder](https://xen-orchestra.com/blog/blog/first-running-prototype-is-here/), but because of its location, XO is a "hub" on top of all your pools/servers. That's why it's easy to centralize users management, you can give them rights globally: pools or stand-alone servers are no more isolated. XO make the "glue". For example, when using XCP, you need to configure every pool with its backend. If you have a lot of servers or different pools, it can be tedious. With XO, you have one place to configure user rights, plus you have one place to configure your auth backend. ## One place, one backend That's why XO will be easier: as a central place, you just need to configure your auth service once. We will provide fine grained permission for this summer, so we think that kind of feature + OpenLDAP backend can be really useful in your existing infrastructure. ## Are you trying to recreate CloudStack? Oh god, no! :D As we always think, there is a space between vanilla Xen and "big" cloud stack, like OpenStack or CloudStack. XCP is really great with its Xapi, the only thing missing is a light, open source and powerful interface for that. And we always think "modular": we DON'T want to create a big monolithic software for cloud management. First, we'll focus on core features, and then we extend it with plugins, and they'll never be mandatory for playing with your virtualized infrastructure! ### Code is available URL: https://xen-orchestra.com/blog/code-is-available/ Last updated: 2014-08-20T15:53:12.000Z If you want to see our code, you can do that by going on [our "global" github repo](https://github.com/vatesfr/xo?ref=xen-orchestra.com). Check the README for further explanations. Our objective is a first release for March, with only views on your XCP infrastructure, without interactions: it will validate our concepts and be a good start for exciting features. ### Back from FOSDEM 2013 URL: https://xen-orchestra.com/blog/back-from-fosdem-2013/ Last updated: 2014-08-20T15:52:11.000Z Here is a small article about the FOSDEM. We were there! First of all, thanks to [Lars](http://wiki.xen.org/wiki/User:Lars.kurth?ref=xen-orchestra.com) for the opportunity to be at the Xen Booth. It was great to meet directly people having interest in XO. And of course, to talk to the Xen team about our way we want to create an interface for XCP. Then, for those who want to read the slides of my presentation, it's available [here](http://www.slideshare.net/xen%5Fcom%5Fmgr/xen-orchestra-a-new-web-ui-for-xcp?ref=xen-orchestra.com). We still have some questions about how user management is handled in XCP, but when it will be clarified, you'll be able to contribute directly to the project. Stay in touch, repos will be available on our [GitHub page](https://github.com/vatesfr?ref=xen-orchestra.com) soon! ![](https://xen-orchestra.com/blog/content/images/2014/Aug/stand.jpg) Yes, look at us, on the top left! ### Meet us at FOSDEM 2013! URL: https://xen-orchestra.com/blog/meet-us-at-fosdem-2013/ Last updated: 2014-08-20T15:47:32.000Z If you want to see a quick presentation of Xen Orchestra, and if you can travel to Belgium, come to see us in the Virt Devroom ([details here](https://fosdem.org/2013/schedule/event/xen%5Forchestra/?ref=xen-orchestra.com)). Moreover, we'll be available for any questions/remarks at the Xen booth for a couple of hours. See you soon! ### Can't find hypervisor information in sysfs! URL: https://xen-orchestra.com/blog/cant-find-hypervisor-information-in-sysfs/ Last updated: 2014-08-20T15:44:09.000Z Very often, people search how to resolve this annoying message, espacially when you reboot after a fresh Xen (or XCP) install. In this post, we'll understand what does it mean and how to fix it. ## Just a fresh install If you read previous article about [installing XCP on Debian 7](https://xen-orchestra.com/blog/blog/xcp-on-debian-7-wheezy/), you have now rebooted in your fresh system, but can't do anything, because Xen tells you: ``` ERROR:  Can't find hypervisor information in sysfs! ``` This "bug" is common to all Debian versions, and it's not really a bug, but more a question of post-install script, which doesn't trigger Xen Kernel in Grub configuration file. ## Grub2 on Debian If you list all files in your /etc/grub.d folder, you'll get: ``` -rwxr-xr-x 1 root root 6.6K Oct 14 10:31 00_header -rwxr-xr-x 1 root root 5.3K Oct 14 10:07 05_debian_theme -rwxr-xr-x 1 root root 6.2K Oct 14 10:31 10_linux -rwxr-xr-x 1 root root 5.8K Oct 14 10:31 20_linux_xen -rwxr-xr-x 1 root root 5.9K Oct 14 10:31 30_os-prober -rwxr-xr-x 1 root root  214 Jan 18  2011 40_custom -rwxr-xr-x 1 root root   95 Jan 18  2011 41_custom -rw-r--r-- 1 root root  483 Jan 18  2011 README ``` It means when you build your grub config files, it starts with header, then add debian theme, then push regular kernel, then Xen Kernel etc. But it's not that we want :) ## Solution ### Propper way The propper way to do this, is the "dpkg way" as indicated in Debian documentation. So: ``` # dpkg-divert --divert /etc/grub.d/08_linux_xen --rename /etc/grub.d/20_linux_xen ``` And rebuild your Grub config file: ``` # update-grub ``` ### Old way If you want to have a Xen enabled kernel, you need to invert order, simply like that: ``` # mv /etc/grub.d/10_linux /etc/grub.d/20_linux && mv /etc/grub.d/20_linux_xen /etc/grub.d/10_linux_xen ``` And rebuild your Grub config file: ``` # update-grub ``` Now, reboot, and you're done! ### First running prototype is here URL: https://xen-orchestra.com/blog/first-running-prototype-is-here/ Last updated: 2014-08-20T15:38:58.000Z After some discussions about global architecture, we made choices, and we are testing them right now. And we have screenshots to share :) ## Global architecture Our goal is to avoid useless traffic between clients and XCP servers, for multiple reasons: - XAPI talks a lot - multiply each client connection by each server, and you have a LOT of traffic everywhere - can be slow Our solution is to provide a daemon between clients and XCP servers. This daemon provides: - connection persistence (which improve speed) - event handling (listening without interruption, unlike a simple web script) - users management - cache system (combined to events, it allows nice bandwidth reduction and extra speed) It can be summarized like that: ![](https://xen-orchestra.com/blog/content/images/2014/Aug/global.png) Overview of XO architecture ![](https://xen-orchestra.com/blog/content/images/2014/Aug/step1.png) First, we get all data on our XCP server ![](https://xen-orchestra.com/blog/content/images/2014/Aug/step2.png) Then, we listen their event to update our cache ![When you request an information not present in the cache](https://xen-orchestra.com/blog/content/images/2014/Aug/cachemiss.png) When you request an information not present in the cache ![](https://xen-orchestra.com/blog/content/images/2014/Aug/cachehit.png) When you get the information in the cache, you don't need to connect to your XCP server ! ## User interface We choose to use intensively [Twitter Bootstrap](http://twitter.github.com/bootstrap/?ref=xen-orchestra.com) and [FontAwesome](http://fortawesome.github.com/Font-Awesome/?ref=xen-orchestra.com) to bring a clear and ready to use interface. It allows us to make quickly a nice UI, which is not definitive but a good start. ![](https://xen-orchestra.com/blog/content/images/2014/Aug/Capture-du-2012-12-31-160254.png) Prototype of welcome page, with opened login menu on the right\[ ![](https://xen-orchestra.com/blog/content/images/2014/Aug/Capture-du-2012-12-31-160328.png) Prototype of server overview, only here to display what it is possible to display. We continue to think about innovative way to display an overview of pools/servers/VM with our ergonomist. But it's to early for having any implementation so far. Stay tuned for new visual ASAP. ## What's next? Now we have a first prototype and our global design, we can, in parallel: - test XO-server extensively to detect problems and doing optimizations - implement basic features in the UI - implement and test innovative design for great overview **All the team wish you happy new year! 2013 will be a great year for XO :)** ### Tell us what you want URL: https://xen-orchestra.com/blog/tell-us-what-you-want/ Last updated: 2014-08-20T15:26:10.000Z We have a lot of ideas, but we prefer to start building a software with features responding to community needs. Please read this post carefully if you want to express your needs about XO. ## Features We've decided to create a feature request, that's why we've created [an uservoice page dedicated to XO project](https://xenorchestra.uservoice.com/?ref=xen-orchestra.com). Go and tell us your ideas without thinking about technical stuff behind. Think as a user (but be reasonable, XO won't make coffee or feed your cat... please use Emacs for that) ## First step in GUI For us, the first objective for XO is displaying on overview for all VM currently running on XCP hosts/pools, with a dynamic search field, filtering in live VM like a google search. It will help us to find quickly on which physical host/pool is running a VM, and have a quick view of its CPU usage. It will validate speed and cache system implemented in the first alpha. ## Technical stuff behind? About technical architecture behind XO, we have made our first choices, providing a technical demonstrator for the end of the year. Damn! It's almost here! ### From 10 to 1 (and less) URL: https://xen-orchestra.com/blog/from-10-to-1-and-less/ Last updated: 2014-08-20T15:24:35.000Z Our first exploration of PHP calls for XAPI was based on a lib, named PHP-xenapi (btw, thanks to Andy Goodwin for [that piece of code](https://github.com/andygoodwin/PHP-xenapi?ref=xen-orchestra.com)). The "small" problem with this lib, is its slowness. I mean really slower than acceptable for us. Let's see with a small portion of code listing only "real VM" (no templates or xen dom0): ``` $ time php example.php VM3 VM1 VM2 real    0m10.103s user    0m0.360s sys    0m0.148s ``` Ok, **10 secs** for that. Wireshark tells us than approx. **2500 packets** were exchanged during the process. When we look at the code, we saw that lib recreate a entire connection each time. **After a patch** Let's factorize connections and don't recreate them if they already exist. Corrections are available [on my personal github page](https://github.com/olivierlambert/PHP-xenapi/commit/871df2e1b3bdc81a246084432dff478e6c0c1dac?ref=xen-orchestra.com). Does it change something? ``` $ time php example.php VM3 VM1 VM2 real    0m0.796s user    0m0.120s sys    0m0.016s ``` Much better: from 10 to <1 sec! Wireshark tells us **285 packets** were transfered during the same operation. Now it's more acceptable ;) ### XCP on Debian 7 (Wheezy) URL: https://xen-orchestra.com/blog/xcp-on-debian-7-wheezy/ Last updated: 2014-08-20T15:20:44.000Z ## Background Historically, XCP is more a software appliance, installed directly from an ISO, containing packaged XCP with CentOS. But some people prefer to add XCP on a existing OS (for various reasons, like for us, using Debian). That's why [project Kronos](http://wiki.xen.org/wiki/Project%5FKronos?ref=xen-orchestra.com) was born. ## Let's start We'll install XCP in bridged mode. OpenVSwitch is a great tool, but we'll discover it later (discover both in the same time will be harder). Thanks to the tremendous work of Debian packagers, it's dead easy: ``` aptitude install xcp-xapi ``` Modify or check /etc/xcp/network.conf to have this and only this: ``` bridge ``` Modify /etc/default/xen to have this: ``` TOOLSTACK=xapi ``` Modify /etc/network/interface (let's say that we are in DHCP and eth0 is your network interface): ``` # The loopback network interface auto lo iface lo inet loopback # bridge auto xenbr0 iface xenbr0 inet dhcp bridge_ports eth0 # indeed, I removed eth0 ``` Modify grub boot order to boot on Xen first: ``` mv /etc/grub.d/10_linux /etc/grub.d/21_linux update-grub ``` Reboot, and you're NOT done! Thanks to jms for this tips ;) ``` dpkg-reconfigure xcp-squeezed dpkg-reconfigure xcp-xapi ``` Then, you can check that control domain is up and running by: ``` xe vm-list ``` We'll see next time how it works (with CLI). ### XO milestones URL: https://xen-orchestra.com/blog/xo-milestones/ Last updated: 2014-08-20T15:23:14.000Z Many of you ask us "when the new version of XO will be available, at least for testing purpose?" First thing first, I'll explain important milestones. ## First "public" beta: before 2013! Yes, it can be the last day of 2012, but this first pre-version will be released as a demonstrator for our architecture choice (does it work with many XCP hosts? 40 clients? on different OS?) Don't expect nice UI, it's more about validation. If our expectations are met, we'll continue to the 1.0... ## 1.0: Xen Orchestra "Archlute" Archlute will be the first stable version of XO. When we say stable, it means usable in production. Not a lot of features for this one, but a good working base for further developments: - works with XAPI (xcp) on Debian 7 with Kronos Project - connect to XCP servers - list VM's in each server (global view as previous version of XO) - permissions and local users (R/W/Admin) - packaged in a repository for Debian, with almost few clicks to be operational ## Release often Our goal is to correct bugs and go on next version ASAP. For example, version 2.0 of XO (named "Baryton") can afford: - nice GUI for adding server - nice GUI for managing users - backend filled with all metrics - LDAP compatible - Tags for better search Of course, this is only a forecast of features: it can evolve, because it's community driven. ## But now? Currently, our team work on two things: - global architecture of XO (will be explained in a future post) - displaying smartly the -great- amount of XAPI informations to a web UI (our ergonomist is sketching right now) - think about what you need in XO (we think about doing a survey for that) ## Survey A good survey will help us to go in the right direction. XAPI expose more features than we can implement in a small amount of time. We need to make choices, and we prefer to make them relevant. Please [read this post](https://xen-orchestra.com/blog/tell-us-what-you-want/) about that question. ### We are back! URL: https://xen-orchestra.com/blog/we-are-back/ Last updated: 2014-08-20T15:15:16.000Z After two years without news, we're back! Now, Xen Orchestra is redeveloped from scratch (with a company support), in order to work with XCP (and its powerful XAPI). Of course, it'll stay Open Source (surely AGPLv3). We decide to be transparent about our development process. The goal of XO: - provide a simple and nice interface to manage VM and XCP servers - display in one view the global state of your virtualization infrastructure - expose nice functionalities of XAPI to a web GUI (migrations between pools, manage storage repositories etc.) - get ideas and dev from community Further news incoming!