github Vateron-Media/XC_VM 2.6.0
v2.6.0

pre-release5 hours ago

XC_VM v2.6.0

Overview

This release delivers significant improvements to cluster security, load balancing, streaming reliability, proxy support, installation, and operational monitoring. It strengthens communication between MAIN and load balancer nodes, improves credential management, and expands automated testing across distributed streaming workflows.

✨ New Features

Proxy Checker and YouTube Streaming

  • Added a Proxy Checker page for bulk proxy validation, including checks for YouTube-compatible proxies.
  • Added support for resolving and fetching YouTube stream sources through the configured stream proxy.
  • Extended proxy support to streaming daemon workflows.
  • Added documentation explaining how to restream YouTube sources through proxies.
  • Improved proxy diagnostics so unreachable ports produce readable error messages.

Cluster Security and Credential Management

  • Introduced per-node viewer-token signing keys, reducing reliance on shared credentials across the cluster.
  • Strengthened MAIN-to-node communication with bidirectional channel signatures.
  • Added authenticated, encrypted cluster relay traffic and sealed file-transfer mechanisms.
  • Introduced cluster credential rotation for database passwords, Redis passwords, stream secrets, and signing keys.
  • Added operator controls for pinning a node's core version, removing database credentials, and applying or reversing cluster lockdown.
  • Added lease-fencing mechanisms to restrict operations when a node's licence or cluster lease is no longer valid.
  • Improved protection against replayed requests, malformed records, and invalid file-chunk responses.

Cluster Monitoring and Administration

  • Added node clock-skew monitoring and dashboard warnings.
  • Added indicators for connection divergence, lane lag, and unreachable MAIN endpoints.
  • Expanded Cluster Nodes administration with lease-fence information, diagnostics, and credential-rotation controls.
  • Added cluster diagnostic commands and improved node enrolment and re-enrolment workflows.

Streaming and Load Balancing

  • Extended the xc_fanout daemon to handle VOD and timeshift delivery, moving file-serving work away from PHP-FPM workers.
  • Added support for direct-proxy VOD and timeshift HLS segments through the streaming daemon.
  • Expanded load-balancer support for live channels, VOD files, timeshift files, and off-air stream identification.
  • Improved stream assignment, queue notifications, and node synchronization after stream changes.
  • Added safeguards for node rollouts, including canary checks, rollback handling, and controlled release of held rollouts.

🚀 Improvements

Installation and Updates

  • Updated the installation process to fetch xcvm_core separately instead of bundling it with the binaries archive.
  • Improved load-balancer installation diagnostics and SSH failure reporting.
  • Ensured node enrolment is reported only after the node agent starts successfully.
  • Improved update handling so load balancers follow MAIN's release, including nightly development builds.
  • Prevented updates from reinstalling binaries unnecessarily or downgrading xcvm_core.
  • Improved binary distribution handling when a release does not contain the current distribution's bundle.
  • Standardized binary updates and self-healing workflows across cluster nodes.
  • Restricted supported installation distributions to Ubuntu 20.04, 22.04, and 24.04, and Debian 12 and 13. Ubuntu 18.04 and RHEL-family distributions are no longer supported by the installer.

Redis and Connection Management

  • Improved Redis connection handling with bounded connection attempts, shorter timeouts, and controlled retries.
  • Improved viewer cleanup across Redis and MySQL modes.
  • Fixed connection tracking for simultaneous viewers, duplicate client identifiers, RTMP sessions, and HLS viewers moving between streams.
  • Improved handling of expired lines, stopped workers, and viewers that no longer send heartbeats.
  • Ensured ended viewers cannot be revived by subsequent check-ins.
  • Optimized viewer cleanup by processing Redis records in batches.
  • Improved signal expiration and Redis restart behavior.

Cluster Synchronization and Reliability

  • Improved cluster event delivery to prevent commands from being silently lost.
  • Added larger-section transfers using 4 MiB parts.
  • Improved atomic file writes, connection identity validation, and stored-record handling.
  • Improved synchronization after stream changes, blocklist updates, and node recovery.
  • Added safer handling of offline nodes, lease transitions, and licence changes.
  • Improved cluster API behavior by opening database connections only for operations that require them.
  • Added IPv6 support for cluster API listeners.

FFmpeg and Binary Distribution

  • Updated the FFmpeg distribution workflow so each node downloads builds appropriate for its operating system from the configured XC_VM_FFMPEG source.
  • Improved handling of unreadable build hash files and retry behavior.
  • Clarified MD5 checksum verification behavior in documentation and security analysis.

🛠️ Bug Fixes

  • Fixed fanout proxy configuration so the daemon receives the expected host:port value.
  • Fixed proxy status reporting for direct-proxy streams.
  • Fixed stream-source validation to prevent driver URLs from being assigned to incompatible engines while preserving supported FFmpeg schemes.
  • Fixed stream review workflows so EPG-only changes can be saved independently.
  • Fixed import workflows to update only the intended stream columns.
  • Fixed module stream-form validation when optional fields are not submitted.
  • Fixed authorization handling to reject save actions that are not covered by an applicable rule.
  • Fixed authentication sessions for users who no longer exist.
  • Fixed language-file updates to save changes safely and consistently.
  • Fixed Redis configuration ownership and permissions, including protection against symlink-based configuration changes.
  • Fixed signal processing so cron jobs no longer terminate the signal daemon.
  • Fixed cluster API handling of signatures, stored keys, file chunks, and failed event batches.
  • Fixed load-balancer status reporting to use MAIN's address for Redis connectivity.
  • Fixed node revocation when a server is deleted.
  • Fixed node update behavior, licence checks, and cluster status reporting.
  • Fixed server configuration saves to reject ports already occupied by another process.
  • Fixed installer temporary-file naming and root-owned file writes over SSH.
  • Fixed stream-limiter cleanup so each disconnected viewer is handled once.
  • Fixed load-balancer playback-limit accounting to count viewers only when their streams are actually flowing.

🧪 Testing and Quality Assurance

  • Expanded end-to-end coverage for cluster administration, load-balancer installation, stream delivery, and playback limits.
  • Added tests for live channels, VOD, timeshift files, and file transfers through load-balancer daemons.
  • Added coverage for cluster settings, member groups, transcoding profiles, RTMP IPs, HMAC keys, and cluster management pages.
  • Improved test synchronization around heartbeats and stream-flow transitions.
  • Added tests for node rollout, rollback, credential handling, and cluster API behavior.
  • Expanded documentation and architecture decision records to capture validated operational procedures and security design decisions.

🧹 Refactoring and Maintenance

  • Consolidated repeated cluster settings, connection identity rules, file operations, request validation, and queue SQL into shared helpers.
  • Simplified stream-state handling and stored connection record access.
  • Removed unused module middleware infrastructure that was not being executed.
  • Improved code documentation, formatting, and static-analysis compatibility.
  • Updated language files to match the current English translation keys.
  • Improved documentation for cluster installation, credential rotation, binary distribution, viewer lifecycle management, and troubleshooting.

📌 Important Notes

  • Supported distributions: Ubuntu 20.04, 22.04, and 24.04; Debian 12 and 13.
  • Ubuntu 18.04 and RHEL-family distributions: no longer supported by the installer.
  • Cluster security: credential rotation, lease fencing, node signing keys, and encrypted relay traffic introduce important changes to distributed-node operation. Review the cluster documentation before upgrading production environments.
  • FFmpeg distribution: nodes obtain compatible builds from the configured XC_VM_FFMPEG source rather than relying on FFmpeg binaries stored in the repository.

This release focuses on improving the security, reliability, and maintainability of XC_VM deployments, particularly those using distributed streaming and load-balancer nodes.

Don't miss a new XC_VM release

NewReleases is sending notifications on new releases.