A maintenance + feature release on top of 1.0.
đ Languages
- Simplified Chinese (įŽäŊ䏿) â the web UI is now available in Simplified Chinese. Thanks @ranydb.
đĨī¸ Console
- SPICE is offered in every VM console entry point â a downloadable virt-viewer
.vvfor audio / USB / multi-monitor sessions, alongside the built-in noVNC.
đ Security
- Another Aikido penetration-test pass closed a set of authorization / IDOR gaps: power- and cost-rate reads are now scoped to the caller's clusters (a scoped API token can no longer enumerate every cluster's rates); the client portal's reboot action is gated on
vm.restartinstead ofvm.start; and further authz / validation / SSRF invariants from batches 1â2 are enforced. - The CIS SSH-hardening control no longer disables TCP forwarding â the built-in VNC console tunnels through it â and applied hardening controls are now selectable for rollback.
đ Fixes
- Container disks â adding a disk to a container now targets a container mountpoint (
mpN) instead of a QEMU disk key, and never overwrites an occupied slot. - Unlock â a locked VM/CT can be unlocked even on token-authenticated clusters (falls back to
qm/pct unlockover SSH). - OIDC keeps the full
preferred_usernameinstead of truncating at@(#486). - RBAC â the storage / snapshot / backup / update action bars follow their backend permissions (#644).
- Scheduled rolling + maintenance updates evacuate local disks by default (#630 / #629).
- Node temperature parsing falls back to plain
sensorstext when JSON is unavailable (#601). - In-band BMC reads fall back key â agent â password, so password-only nodes still report hardware health (#609).
- ESXi / cross-hypervisor migration lists route to their own handlers (#654).
đĻ Platform
- ARM64 / aarch64 build artifacts are now published (#674). Thanks @gyptazy.
- cryptography is pinned to
50and pyOpenSSL to26.4to keep the vulnerable49line out (#650).
â Quality
438 automated tests (authorization, integration, SSL-bootstrap, hardware, i18n) run on every PR, and the whole branch was re-audited before release.
Thank you to everyone who filed, fixed, translated and sponsored along the way. đ
đ Sponsors
PegaProx is AGPL-3.0 and built in the open. Huge thanks to our Platinum sponsors who keep it moving:
đ Platinum