The module lifecycle stage: Generally available version

The module has requirements for installation

v1.12.2

Release date: September 30, 2026.

Highlights

  • Running virtual machines (VMs) no longer restart because of a change in the module settings and no longer show errors of operations that have already finished.

Fixes

Virtual machines

  • Enabling the HotplugMemoryWithLiveMigration feature gate no longer restarts running virtual machines.
  • Fixed the status of an operation still being shown after the operation has actually finished. Now only the operation being performed at the moment is shown.

Module

  • Fixed the permissions to view pools of virtual machines for the users whose access is granted through a ClusterAuthorizationRule.

v1.12.1

Release date: September 24, 2026.

Highlights

  • Updating the module in Deckhouse Platform Open (DP Open) no longer blocks the Deckhouse queue. The release also patches vulnerabilities in the module.

Fixes

Module

  • Updating the module in DP Open no longer blocks the Deckhouse queue.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2026-81870
    • CVE-2026-81871

v1.12.0

Release date: September 21, 2026.

Highlights

  • PCI devices of cluster nodes can now be attached to virtual machines (commercial editions, experimental).
  • A virtual machine can now be accessed over a SPICE display, with guest sound, USB redirection from the client and a shared clipboard.
  • A node can now be freed by allowing the restart of the virtual machines that cannot be live migrated.

New features

Virtual machines

  • Added the ability to attach PCI devices of cluster nodes to virtual machines. The functionality is available in the commercial editions of the platform and is experimental. To use it, the cluster must run Kubernetes 1.34 or newer.
  • Added the SPICE display, which gives a virtual machine the guest sound, USB redirection from the client and a shared clipboard.
  • A node can now be freed by allowing the restart of the virtual machines that cannot be live migrated.
  • New snapshots of virtual machines and disks are now taken through the state-snapshotter module if it is enabled.
  • The Migratable condition now reports that a virtual machine has no node to migrate to.
  • Added the OperationInProgress condition, which reports the operation being performed on a virtual machine and the failure of the last one.

Monitoring

  • Metrics now tell which node a virtual machine migrates from and which node it migrates to, and the dashboards show how the migrations in progress are going.
  • Added metrics of the launch, shutdown and migration time of a virtual machine and of the disk provisioning time.
  • The cluster overview dashboard now also shows the actual CPU, memory and disk space consumption of virtual machines.
  • Added the d8_virtualization_virtualmachine_eviction_required metric about the state of a virtual machine while its node is taken out of service. The D8VirtualizationVirtualMachineHoldsNodeMaintenance alert names a virtual machine that holds such a node.
  • The dashboards now show how many virtual machines cannot migrate and which nodes they run on.
  • Live migration now reports how long the virtual machine was actually paused.

Improvements

Virtual machines

  • VNC now uses less traffic thanks to a better compression of the picture.

Disks and images

  • Disks are created from images faster, and a raw image takes several times less space because it is now stored compressed.

Fixes

Virtual machines

  • A node no longer waits for a reboot because of a virtual machine pod left on it by a live migration.
  • Deleting a virtual machine after its live migration on NFS no longer leaves the machine, its disks and the namespace in Terminating.
  • A VirtualMachineOperation of the Evict type no longer hangs in Terminating after its virtual machine is deleted.
  • A virtual machine with local disks is no longer reported as non-migratable if its disks can move along with it.
  • A virtual machine is no longer left pinned to the node where its local disks used to live.
  • A virtual machine whose disk is available on a single node only is no longer reported as migratable.
  • Automatic rebalancing no longer tries to evict virtual machines that cannot be live migrated.
  • The provisioning secret cannot be deleted while a running virtual machine still needs it.
  • A virtual machine on an unresponsive node now reports its state as unknown.
  • An additional network is now unplugged from the guest as soon as it is removed from a running virtual machine.
  • A virtual machine whose additional network changed its MAC address during creation now starts with all its interfaces.
  • A migration now reports at once that it has no suitable node to move the virtual machine to.

Disks and images

  • An interrupted image download now fails the import.
  • An interrupted disk import now completes on the next attempt.
  • A large image import no longer loops because the importer runs out of memory.
  • A failed disk or image import now names the reason instead of staying in Provisioning forever.
  • An image import blocked by a project quota resumes by itself once the quota is raised.
  • Image and disk import and upload now work in Deckhouse projects with an isolated network.
  • A virtual machine can now be restored and cloned from a snapshot even if the default storage class of the cluster uses another CSI driver.
  • A virtual machine restored from a snapshot on local storage no longer hangs in Pending. All of its volumes now end up on the same node.
  • Restoring a disk with a size of zero or less is now rejected with a clear reason.

Monitoring

  • The CPU utilization panel of the cluster overview dashboard no longer reports values about a thousand times lower than the real ones.
  • The cluster overview dashboard opens with the default Prometheus data source.
  • The D8VirtualizationNodeEvacuationStuck alert no longer fires while a live migration of a virtual machine is running.

Module

  • The module no longer stops working because of a VirtualMachineClass created before its installation finished.
  • PCI devices are now available in clusters with the legacy user-authz access model.

Security

Virtual machines

  • Virtual machine pods now run with the RuntimeDefault seccomp profile. A running machine gets it after a restart or a migration.

Module

  • Module-reserved labels and annotations are no longer propagated from user resources onto internal objects.
  • Fixed vulnerabilities:
    • CVE-2026-56854
    • CVE-2026-84304
    • CVE-2026-84445

Breaking changes

Monitoring

  • The d8_virtualization_virtualmachine_migration_start_time_seconds, d8_virtualization_virtualmachine_migration_end_time_seconds, d8_virtualization_virtualmachine_migration_succeeded and d8_virtualization_virtualmachine_migration_failed metrics moved under the d8_internal_virtualization_kubevirt_ prefix. Dashboards and alerts that use them require an update, and the same data is now reported by the d8_virtualization_virtualmachine_migration_info metric.
  • The d8_virtualization_virtualmachine_migratable metric gained the reason label and is no longer dropped to zero by a cordon of a neighbouring node, so alerts matching on its value alone change their meaning.

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.11.1

Release date: September 9, 2026.

Highlights

  • The release fixes problems with the disks of virtual machines (VMs). It also patches vulnerabilities in the module.

Fixes

Virtual machines

  • Attaching and detaching a disk during a migration of a VM now happens after the migration completes.

Disks and images

  • A VM now boots from a disk created from a gzip- or xz-compressed image.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2026-10722
    • CVE-2026-33818
    • CVE-2026-39821
    • CVE-2026-56853
    • CVE-2026-56854
    • CVE-2026-56858
    • CVE-2026-56859
    • CVE-2026-56860
    • CVE-2026-56862
    • CVE-2026-84304

v1.11.0

Release date: August 25, 2026.

Highlights

  • Physical GPUs can now be attached to virtual machines (EE/SE+, experimental).
  • The Legacy type of .spec.osType runs guest operating systems without built-in AHCI and virtio drivers, such as Windows XP and Windows Server 2003.
  • Image upload can now be published through the Gateway API instead of an Ingress.
  • A virtual machine with an attached USB device can now be live migrated and evacuated during a node drain.

New features

Virtual machines

  • Added the ability to attach physical GPUs to virtual machines. The functionality is experimental and available in the EE/SE+ commercial editions. To enable it, add GPU to .spec.settings.featureGates in the ModuleConfig of the virtualization module; the cluster must run Kubernetes 1.34 or newer.
  • Added the Legacy value for .spec.osType to support guest operating systems without built-in AHCI and virtio drivers, such as Windows XP and Windows Server 2003.
  • Added the Auto value for .spec.cpu.coreFraction. The functionality is available in the EE commercial edition. To enable it, add VerticalVirtualMachineAutoscaler and HotplugCPUAndMemoryWithInPlaceResize to .spec.settings.featureGates in the ModuleConfig of the virtualization module.
  • The cloud-init configuration can now be detached from a virtual machine without restarting the machine.
  • Malformed cloud-init data is now reported as a warning when the resource is created, and in the ProvisioningReady condition of an existing resource.
  • Added the ability to find out who is connected to the serial console or VNC session of a virtual machine and to disconnect them.
  • A live migration queued behind concurrency limits now reports which limit is blocking it.

Disks and images

  • Images and disks from an HTTP source can now be verified with SHA-1, SHA-512, and GOST R 34.11-2012 (Streebog) checksums.
  • Image upload can now be published through the Gateway API instead of an Ingress. This requires the alb module; to enable it, add UploadViaAPIGateway to .spec.settings.featureGates in the ModuleConfig of the virtualization module.
  • Added the Deleting condition that reports why a resource is being deleted.
  • Disk and image import is faster.

Monitoring

  • Added metrics export for VirtualMachineClass.
  • Added a metric that reports whether a virtual machine can be live migrated.
  • Added alerts for unavailable USB passthrough and for required module components missing on some nodes.

Module

  • The module’s runtime images have been migrated to a distroless base, which reduces the size of the virtualization image by about 91 MB.

Fixes

Virtual machines

  • A virtual machine with an attached USB device can now be live migrated and evacuated during a node drain.
  • Detaching a network interface from .spec.networks no longer leaves a stale interface in the virtual machine’s pod.
  • The live migration of a virtual machine with additional networks no longer hangs waiting for the network on the target node.
  • Fixed a crash loop of a virtual machine with an additional network interface.
  • The service components of a virtual machine with Secure Boot no longer hang during its migration.
  • Fixed a not-ready image blocking the attachment and detachment of a virtual machine’s disks.
  • Fixed image mounts leaking on the target node after a live migration of a virtual machine.
  • A virtual machine no longer starts booting before its boot disk is attached.
  • Fixed the loss of access to disks when a USB device is attached to a running virtual machine.
  • The virtual machine migration queue is no longer blocked when one of the migrations ends abnormally.
  • Fixed the force stop of a virtual machine when a regular stop was already in progress.

Disks and images

  • Not-ready images and disks no longer hang when deleted while their data is being imported.
  • The creation of an image or a disk with a long name no longer hangs.
  • A resource with the Upload type that receives no data within 10 minutes moves to the Failed phase with the WaitForUserUploadTimeout reason. To upload the image, recreate the resource.
  • Creating a virtual disk from a raw image in the registry onto a block device no longer makes an extra copy of the data.
  • The creation of a virtual disk no longer hangs when the target virtual machine runs on dedicated nodes with taints.
  • Fixed the restore of a virtual disk from a snapshot on storage that rounds volume sizes up (ceph-rbd, sds-elastic).
  • During an image upload, the phase of a ClusterVirtualImage no longer flips back to Pending.

Monitoring

  • Fixed the module’s alerts suppressing the platform alert about unavailable components.
  • Alerts now point to the component that failed; a stuck controller queue and a missing leader are tracked separately.
  • Removed the metric that reported virtual machines with local disks as impossible to migrate: such machines can be migrated.

Module

  • Fixed device handling for virtual machines on cgroup v2 nodes.
  • The Deckhouse queue is no longer blocked when the virtualization module is enabled while its controllers are not ready.
  • Fixed the renewal of TLS certificates in the virtualization components while the cluster is degraded.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2025-27144
    • CVE-2026-10722
    • CVE-2026-34986
    • CVE-2026-46600
    • CVE-2026-54332
    • CVE-2026-54345
    • CVE-2026-56852
    • CVE-2026-56864
    • CVE-2026-56865
    • GHSA-gcjh-h69q-9w9g
    • GHSA-hrxh-6v49-42gf
    • GO-2026-5932

v1.10.5

Release date: September 3, 2026.

Highlights

  • The release fixes possible data loss during a disk migration and a VM with an attached image that could not be migrated at all. It also patches vulnerabilities in the module.

Fixes

Virtual machines

  • An operation on a virtual machine (VM) created without any labels and annotations no longer fails.
  • A VM with an attached image can now be live migrated.
  • A migration of a VM with a corrupted block device now names the reason and suggests a restart.
  • An automatic VM update no longer gives up after the first failed migration and retries it up to three times.
  • The service components of a VM are no longer left on the source node after a live migration.

Disks and images

  • Fixed possible data loss during a disk migration.
  • A disk can be migrated again right after a canceled migration.
  • A ClusterVirtualImage no longer returns to the Pending phase while it is being uploaded.
  • A zero-size disk no longer blocks disk operations and VM migrations.
  • Fixed the overstated size reported for an image in the raw format.

Module

  • Fixed an error that kept the module from being enabled on the first attempt.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2026-56854
    • CVE-2026-84304
    • GHSA-w67g-5rqw-f597

v1.10.4

Release date: August 28, 2026.

Highlights

  • The release fixes the cases where a virtual machine (VM) could fail to start because of its own disks. It also patches a vulnerability in the module.

Fixes

Virtual machines

  • A VM with disks on SDS storage is now placed on a node with enough space for them.
  • Fixed a VM with paravirtualization disabled hanging at startup on a WaitForFirstConsumer storage class.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2026-10722

v1.10.3

Release date: August 24, 2026.

Highlights

  • Fixed potential data loss during a virtual disk migration.
  • Disk hotplug, migrations, and status updates of virtual machines are no longer interrupted by periodic crashes of a service component on the nodes.
  • Virtual machines with USB devices are now scheduled only on nodes where USB passthrough is available.

Fixes

Virtual machines

  • Fixed an issue where an additional network of a virtual machine was not configured if another network of the same VM had an explicitly specified MAC address.
  • Fixed empty launch statistics for virtual machines: .status.stats.phasesTransitions and .status.stats.launchTimeDuration are reported again.
  • Fixed an issue where virtual machines with USB devices could be scheduled on nodes without a USB gateway and then failed to start or started without their USB devices.

Disks and images

  • Fixed potential data loss during a virtual disk migration.
  • Fixed an issue where a virtual disk storage class migration was canceled if another virtual machine in the same namespace was migrating.
  • Fixed a virtual disk export hanging in the Pending phase.
  • Fixed an issue where virtual disk import failed in clusters with containerd image integrity checks enabled.
  • Fixed an issue where disks could be unintentionally preempted from the virtual machine node. The priority class of the VM service components is now set according to .spec.priorityClass of the VM.
  • The time a virtual disk spends in the Provisioning phase is no longer counted in .status.stats.creationDuration.waitingForFirstConsumer.

Module

  • USB devices are now provided only from nodes where the usbip kernel modules are known to be available.
  • Fixed an issue where the Deckhouse queue could be blocked if the usbip kernel modules could not be installed on a node, including nodes running Astra Linux, ALT Linux, and RED OS.
  • Fixed disk hotplug, migration, and status update failures caused by virt-handler crashing with a fatal error several times a day.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2026-33818
    • CVE-2026-39821
    • CVE-2026-54332
    • CVE-2026-54345
    • CVE-2026-56853
    • CVE-2026-56858
    • CVE-2026-56859
    • CVE-2026-56860
    • CVE-2026-56862
    • CVE-2026-56864
    • CVE-2026-56865
    • GHSA-gcjh-h69q-9w9g

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.10.2

Release date: August 3, 2026.

Highlights

  • USB device passthrough works again on hosts running more than one usbip host controller.
  • Enabling the module or changing its version no longer blocks the Deckhouse queue in clusters without the vertical-pod-autoscaler module.

Fixes

Module

  • Fixed an issue where the task queue would block when enabling a module or changing its version in a cluster without the vertical-pod-autoscaler module enabled. The cause was an infinite loop of attempts to delete VPA objects. Instead of PatchCollector, a separate request is now used that ignores the absence of VPA objects and prevents the queue from being blocked.
  • Fixed an issue where USB device passthrough to virtual machines was unavailable on hosts where the usbip driver was running more than one virtual host controller.
  • Fixed a CrashLoopBackOff error in the virtualization-dra pod on hosts with USB devices, caused by starting controller worker processes before the initial connection information had been collected. Initialization now occurs before the workers start, which prevents the error caused by accessing data that has not yet been populated.

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.10.1

Release date: July 29, 2026.

Highlights

  • The module now requires sdn 0.6.2 or later when the sdn module is enabled.
  • Fixed vulnerabilities in the module’s components.

Fixes

Module

  • An optional dependency has been added for the virtualization module, requiring that the sdn module be version 0.6.2 or later. This prevents launching virtualization from running with earlier versions of sdn. The dependency applies only when the sdn module is enabled.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2026-46600
    • CVE-2026-56852
    • GHSA-hrxh-6v49-42gf
    • CVE-2026-34986
    • CVE-2025-27144

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.10.0

Release date: July 23, 2026.

Highlights

  • VirtualMachinePool (EE/SE+) manages a group of identical virtual machines (VMs) declaratively and scales through the standard scale subresource and HPA.
  • CPU and memory of a running virtual machine can be changed without live migration (in-place resize, behind a feature gate).
  • Virtual machine networks moved to eBPF, so additional networks connect more reliably and with lower overhead.
  • Live migration became more predictable — a target that never becomes ready no longer holds migration slots, and migration traffic can be routed over a dedicated SystemNetwork.
  • Names of virtual disks and images are no longer capped below the Kubernetes limit.

New features

Virtual machines

  • Added the VirtualMachinePool resource (EE/SE+) for declarative group management of identical virtual machines. The pool supports scaling via the standard scale subresource and HPA.
  • Added the ability to change CPU and memory of a running VM without live migration (in-place resize). To enable this functionality, add HotplugCPUAndMemoryWithInPlaceResize to .spec.settings.featureGates in the ModuleConfig of the virtualization module.
  • Switched VM networks to eBPF, providing more stable connectivity for additional networks with lower overhead.
  • VirtualMachineOperation resources can now supersede other active operations on the same VM.

Disks and images

  • Added automatic recovery of VirtualImage and ClusterVirtualImage from the ImageLost phase when the image reappears in DVCR, without re-importing the data.
  • The VirtualDisk name length limit has been raised from 60 to 253 characters.
  • The name length limit has been raised from 49 to 253 characters for VirtualImage and from 48 to 253 for ClusterVirtualImage.
  • Added per-namespace authorization for DVCR: image access is isolated between namespaces.

Network

  • Added the ability to route live migration traffic over a dedicated SystemNetwork via liveMigration.network in the ModuleConfig of the virtualization module.

Module

  • Virtual disks and virtual images in WaitForFirstConsumer mode are created 22% faster.
  • Added a limit on concurrent inbound live migrations per target node.
  • Added the ability to use the module without specifying subnets for the Main network. For this, the sdn module must be enabled.

Fixes

Virtual machines

  • Fixed VM update failures while an image is being attached via VirtualMachineBlockDeviceAttachment (hotplug): VM changes could previously be interrupted at the moment of attachment.
  • Fixed flapping of the VirtualMachineIPAddressReady condition: guest-agent data now augments rather than clears the VM’s already-known IP address.
  • Fixed disks and CD-ROMs remaining on the SATA bus after enabling paravirtualization, which prevented unplugging ISO drives from a running VM.
  • Fixed a live migration hanging when its target never became ready (OOMKilled, unschedulable, a disk that never attaches): it now fails by timeout and the migration slots it held are released.
  • Fixed virtual machines with local disks getting stuck and unable to migrate while a restart was pending; they can now be evacuated, updated, and re-migrated.
  • Fixed a false reboot requirement for VMs with only the Main network caused by implicit default network template synchronization.
  • Fixed CPU and memory hotplug updates failing when project quota cannot fit migration-time resources. Such changes now fall back to a restart.

Disks and images

  • Fixed Upload-type disks and images getting stuck in Pending when the upload host certificate becomes invalid, and restored automatic recovery when the upload host changes (for example, after publicDomainTemplate is updated).
  • Fixed PVC storage-type virtual images being attached to virtual machines in read-write mode; they are now attached read-only, like ContainerRegistry storage-type images.

Module

  • Closed unauthorized access to the virtualization USB/IP gateway port.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2026-2303
    • CVE-2026-25680
    • CVE-2026-25681
    • CVE-2026-27136
    • CVE-2026-33814
    • CVE-2026-39821
    • CVE-2026-39822
    • CVE-2026-39824
    • CVE-2026-39827
    • CVE-2026-39828
    • CVE-2026-39829
    • CVE-2026-39830
    • CVE-2026-39831
    • CVE-2026-39832
    • CVE-2026-39833
    • CVE-2026-39834
    • CVE-2026-39835
    • CVE-2026-41579
    • CVE-2026-42502
    • CVE-2026-42505
    • CVE-2026-42506
    • CVE-2026-42508
    • CVE-2026-46595
    • CVE-2026-46597
    • CVE-2026-46598
    • GO-2026-5932

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.9.6

Release date: August 3, 2026.

Highlights

  • USB device passthrough works on hosts with xz- or gzip-compressed usbip kernel modules and with more than one usbip host controller.

Fixes

Module

  • Fixed an issue where USB device passthrough to virtual machines was unavailable on hosts where the preinstalled usbip kernel modules were compressed (using xz or gzip). USB device passthrough is now available if kernel modules are compressed using xz or gzip, not just zstd. Also, for Debian, the linux-modules-extra-${kernel_release} package is now used instead of attempting to install the Ubuntu-specific linux-modules-extra.
  • Fixed an issue where USB device passthrough to virtual machines was unavailable on hosts where the usbip driver was running more than one virtual host controller.
  • Fixed a CrashLoopBackOff error in the virtualization-dra pod on hosts with USB devices, caused by starting controller worker processes before the initial connection information had been collected. Initialization now occurs before the workers start, which prevents the error caused by accessing data that has not yet been populated.

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.9.5

Release date: July 29, 2026.

Highlights

  • An interrupted delivery of audit logs is now reported instead of failing silently.
  • Fixed vulnerabilities in the module’s components.

Fixes

Monitoring

  • Fixed an issue where no notification was displayed when the transmission of audit logs was interrupted due to the use of outdated certificate authority data or because the audit resources lacked a certificate and key: when the transmission of audit logs is interrupted, a warning now appears prompting the user to take action.

Module

  • An optional dependency has been added for the virtualization module, requiring that the sdn module be version 0.6.2 or later. This prevents launching virtualization from running with earlier versions of sdn. The dependency applies only when the sdn module is enabled.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2026-46600
    • CVE-2026-56852
    • GHSA-hrxh-6v49-42gf
    • CVE-2026-34986
    • CVE-2025-27144
    • CVE-2026-39822
    • CVE-2026-42505

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.9.4

Release date: July 13, 2026.

Highlights

  • The audit server starts even when TLS certificate paths are not passed explicitly.

Fixes

Monitoring

  • Fixed an issue that prevented the audit server from starting when TLS certificate paths were not passed explicitly.

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.9.3

Release date: July 7, 2026.

Highlights

  • Images attach to virtual machines (VMs) faster, downloading them from DVCR to the node is no longer slow.
  • Deleting a virtual machine with hotplugged images no longer leaves it stuck in the Terminating state.

Fixes

Virtual machines

  • Fixed a volume mount leak that could leave a VM with hotplugged images stuck in the Terminating state during deletion.

Module

  • Fixed slow downloading of images from DVCR to the node when attaching them to a virtual machine.

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.9.2

Release date: July 1, 2026.

Highlights

  • Restored live migration throughput and the speed of importing images into DVCR.
  • Audit events are no longer lost while the certificate of the virtualization-audit pod is rotated.

Fixes

Virtual machines

  • Fixed reduced throughput during live migration of running virtual machines (VMs) compared to v1.8.3.

Disks and images

  • Fixed slow import and upload of images to DVCR when network bandwidth was not the bottleneck.

Monitoring

  • Fixed loss of audit events and false D8LogShipperDestinationErrors alerts during certificate rotation of the virtualization-audit pod.

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.9.1

Release date: June 24, 2026.

Highlights

  • Live migration of virtual machines (VMs) with disks on local storage works again, including after a failed migration.
  • Virtual machines with only the Main network no longer request a restart they do not need.

Fixes

Virtual machines

  • Fixed live migration of VMs with disks on local storage attached via VirtualMachineBlockDeviceAttachment (hotplug). The target node no longer matches the source node.
  • Fixed an issue that prevented a VM from starting after a failed migration of a disk on local storage.
  • Fixed a false reboot requirement for VMs with only the Main network after upgrading to v1.9.1. Such VMs now do not receive the RestartRequired status if their configuration has not actually changed.

Disks and images

  • Fixed cancellation of virtual disk storage class changes and cancellation of local disk migration.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2026-42504
    • CVE-2026-27145
    • CVE-2026-42507

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.9.0

Release date: June 10, 2026.

Highlights

  • Virtual disks, images and additional network interfaces attach and detach without restarting the virtual machine (VM).
  • The coreFraction of a running virtual machine changes without a restart, through live migration.
  • System virtual machine pods run as the deckhouse user, without root privileges.
  • The deprecated VirtualMachineRestore resource has been removed in favour of VirtualMachineOperation.

New features

Virtual machines

  • A restart is no longer required to attach and detach virtual disks and images via the virtual machine’s .spec.blockDeviceRefs.
    • Works for new virtual machines starting from v1.9.0.
    • For previously created virtual machines, a restart is required to enable this behavior.
  • Added the ability to attach additional network interfaces without a restart via the virtual machine’s .spec.networks.
  • Added the ability to change coreFraction on a running VM without a restart. The new value is applied via live migration.
  • The VM status now includes a “No bootable device” message when the VM cannot find a bootable disk to start.
  • Added the Uptime column to VirtualMachine resources, showing the time since the VM started.
  • Compatible VirtualMachineOperation resources can now supersede another active operation on the same VM.
  • Added the Attached condition and ATTACHED column to the NodeUSBDevice resource, reflecting the USB device’s connection state in the namespace.

Improvements

CLI

  • Added the domain jobs and block-jobs subcommands to the vlctl utility.

Fixes

Virtual machines

  • Fixed VM hanging in the Starting phase when the StorageClass of a disk with WaitForFirstConsumer mode is updated while the VM is stopped.
  • Fixed scheduling issues for a VM after changing the VirtualMachineClass in the VM spec from the Discovery type to another.
  • Fixed an issue with VM migration cancellation that prevented new migrations from starting.
  • Improved Windows guest OS handling in clusters with frequent CPU frequency changes.

Disks and images

  • Time spent in the WaitForFirstConsumer phase is no longer included in .status.stats.creationDuration.totalProvisioning of virtual disks.

Monitoring

  • Fixed duplicate series on the Virtualization / Overview dashboard.

Module

  • Fixed an issue where invalid virtualization module ModuleConfig settings could block the Deckhouse queue.

Security

Virtual machines

  • System virtual machine resources (pods with d8v-hp- and d8v-vm- prefixes) now run as the deckhouse user, without root privileges.

Breaking changes

Virtual machines

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.8.4

Release date: July 13, 2026.

Highlights

  • A security update: vulnerabilities in the module’s components are fixed, with no functional changes.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2026-25680
    • CVE-2026-25681
    • CVE-2026-27136
    • CVE-2026-27145
    • CVE-2026-33814
    • CVE-2026-39821
    • CVE-2026-39827
    • CVE-2026-39828
    • CVE-2026-39829
    • CVE-2026-39830
    • CVE-2026-39832
    • CVE-2026-39835
    • CVE-2026-41579
    • CVE-2026-42502
    • CVE-2026-42504
    • CVE-2026-42506
    • CVE-2026-42507
    • CVE-2026-42508
    • CVE-2026-46595
    • CVE-2026-46597
    • CVE-2026-53935

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.8.3

Release date: June 3, 2026.

Highlights

  • Virtual machines (VMs) with additional network interfaces migrate again.
  • Hot-unplugging a disk no longer leaves duplicate service pods behind.

Fixes

Virtual machines

  • Fixed an issue that blocked virtual machine migration for VMs with additional network interfaces.
  • Fixed duplicate service pods (d8v-hp-*) when hot-unplugging disks from VMs.

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.8.2

Release date: May 20, 2026.

Highlights

  • A security update: vulnerabilities in the module’s components are fixed, with no functional changes.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2026-29181
    • CVE-2026-33811
    • CVE-2026-33814
    • CVE-2026-39820
    • CVE-2026-39823
    • CVE-2026-39825
    • CVE-2026-39826
    • CVE-2026-39836
    • CVE-2026-41520
    • CVE-2026-42499

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.8.1

Release date: April 28, 2026.

Highlights

  • Virtual disks no longer get stuck in the Provisioning state with a StorageClass in WaitForFirstConsumer mode.
  • Virtualization dashboards show correct values during virtual machine migration and in HA clusters.

Fixes

Disks and images

  • Fixed a potential issue where a virtual disk could get stuck in the Provisioning state when using a StorageClass with WaitForFirstConsumer mode.
  • CDI metrics now use d8_internal_virtualization_kubevirt_cdi_* names, matching other internal virtualization metrics.

Monitoring

  • Fixed CPU usage calculation on the virtual machine dashboard in HA clusters, where duplicated controller metrics could affect the displayed value.

Module

  • Fixed incorrect resource calculations on the Virtualization / Overview dashboard that could occur during virtual machine migration.
  • Added missing RBAC permissions for virtualization resources, including virtual machine MAC addresses, snapshot operations, and node USB devices.

v1.8.0

Release date: April 22, 2026.

Highlights

  • The number of CPUs and the amount of memory of a virtual machine can be changed without stopping it manually, the new value is applied through live migration.
  • Virtual machine migration uses the host MTU, which speeds up the transfer of the machine’s memory.
  • Snapshots are created correctly for a virtual machine without the Main network and while the machine is being migrated.

New features

Virtual machines

  • Added the progress field to the status of VirtualMachineOperation resources with the Evict and Migrate types to show operation progress. The corresponding PROGRESS column is displayed when running d8 k get vmop.
  • Added the ability to change the number of CPUs in a virtual machine without manually stopping it. The new value is applied via live migration. To enable this functionality, add HotplugCPUWithLiveMigration to .spec.settings.featureGates in the ModuleConfig of the virtualization module.
  • Added initial support for changing virtual machine memory without manually stopping the virtual machine. The new .spec.memory value is applied via live migration. To enable this functionality, add HotplugMemoryWithLiveMigration to .spec.settings.featureGates in the ModuleConfig of the virtualization module.

Fixes

Virtual machines

  • Optimized virtual machine migration: it now uses hostNetwork, allowing the host MTU to be used instead of the pod MTU.
  • Fixed an issue with an unfrozen filesystem during virtual machine snapshot creation if the freeze occurred during migration.
  • Fixed removal of the Main network from a virtual machine: the virtual machine no longer uses an IP address from the virtualization CIDR after the network is removed.
  • Added automatic cleanup of NodeUSBDevice resources that are absent on the node and are not assigned to a namespace or project.
  • Fixed snapshot creation for a virtual machine without the Main network.

Module

  • When uploading disks and images with the Upload type, the WaitForUserUpload phase no longer occurs prematurely while the resource is not yet ready for upload.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2026-39883
    • CVE-2026-32280
    • CVE-2026-32281
    • CVE-2026-32282
    • CVE-2026-32283
    • CVE-2026-32288
    • CVE-2026-32289
    • CVE-2026-34986
    • CVE-2026-25679
    • CVE-2026-27142
    • CVE-2026-27139
    • CVE-2026-33186
    • CVE-2026-34040
    • CVE-2026-33997

v1.7.2

Release date: May 20, 2026.

Highlights

  • A security update: vulnerabilities in the module’s components are fixed, with no functional changes.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2026-29181
    • CVE-2026-33811
    • CVE-2026-33814
    • CVE-2026-39820
    • CVE-2026-39823
    • CVE-2026-39825
    • CVE-2026-39826
    • CVE-2026-39836
    • CVE-2026-41520
    • CVE-2026-42499

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.7.1

Release date: April 21, 2026.

Highlights

  • A virtual machine with a connected USB device now reports what to do for its firmware to be updated, instead of silently staying unavailable for migration.
  • Fixed vulnerabilities in the module’s components.

Fixes

Virtual machines

  • To update the firmware on virtual machines with a connected USB device, one of the following actions is required. A corresponding message will appear in the virtual machine status:

    • Disconnect the USB device and migrate the virtual machine.
    • Restart the virtual machine.

    Until then, the virtual machine will continue running, but it will not be available for migration. After either action is completed, the virtual machine will be updated to the current firmware version and will be available for migration again.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2026-32283
    • CVE-2026-27139
    • CVE-2026-32289
    • CVE-2026-32288
    • CVE-2026-32281
    • CVE-2026-27142
    • CVE-2026-33997
    • CVE-2026-33726
    • CVE-2026-32282
    • CVE-2026-32280
    • CVE-2026-25679
    • CVE-2026-34040
    • CVE-2026-34986
    • CVE-2026-39883
    • CVE-2026-33186

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.7.0

Release date: March 31, 2026.

Highlights

  • TCP connections survive live migration of a virtual machine.
  • The order of additional network interfaces stays the same across virtual machine restarts.
  • USB devices are taken into account when scheduling virtual machines, and their downtime during migration is shorter.
  • Block devices can be attached and detached on a cordoned node, and a virtual machine is no longer evicted before its block device pods.

New features

Virtual machines

  • The order of additional network interfaces is now deterministic and does not change after virtual machine restarts. For this to work for virtual machines created on earlier versions, they must be restarted.
  • Added a mechanism to prevent TCP connection drops during live migration of a virtual machine.
  • Reduced USB device downtime during virtual machine migration.
  • Added a garbage collector for completed and failed virtual machine pods:
    • Pods older than 24 hours are deleted.
    • No more than 2 completed pods are retained.
  • When scheduling virtual machines on nodes, the system now takes into account whether a USB device uses USB 2.0 (High-Speed) or USB 3.0 (SuperSpeed).

Fixes

Virtual machines

  • Fixed double storage quota consumption during migration of a virtual machine with local storage.
  • When using VirtualMachineOperation with the Clone or Restore type, disks now also restore their association with the virtual machine (owner reference).
  • Fixed virtual machine eviction during node drain: pods responsible for block device attachments are no longer removed from a cordoned node before virtual machine migration is complete.
  • Block devices can now be attached and detached even if the virtual machine is running on a cordoned node.
  • Fixed validation for the AlwaysForced virtual machine migration policy: VirtualMachineOperation resources with the Evict or Migrate type without explicit force=true are now rejected for this policy.
  • Fixed an issue where a virtual machine could get stuck in the Maintenance state during restore from a snapshot.
  • Added storage-side error messages (from the CSI driver) to the virtual machine status for block device attachment failures.
  • Stabilized USB device support for virtualization on Deckhouse Kubernetes Platform version >=1.76 and Kubernetes version >=1.33.
  • Fixed USB device detection on the host: duplicate USB devices could previously appear.

Disks and images

  • Fixed the creation of block devices from VMDK files (especially for VMDKs in the streamOptimized format used in exports from VMware).

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.6.3

Release date: April 21, 2026.

Highlights

  • A security update: vulnerabilities in the module’s components are fixed, with no functional changes.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2026-32283
    • CVE-2026-27139
    • CVE-2026-32289
    • CVE-2026-32288
    • CVE-2026-32281
    • CVE-2026-27142
    • CVE-2026-33997
    • CVE-2026-33726
    • CVE-2026-32282
    • CVE-2026-32280
    • CVE-2026-25679
    • CVE-2026-34040
    • CVE-2026-34986
    • CVE-2026-39883
    • CVE-2026-33186

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.6.2

Release date: March 23, 2026.

Highlights

  • The module requires Deckhouse Kubernetes Platform 1.74.2 or later, which fixes quota validation when creating a virtual machine.

Fixes

Module

  • The virtualization module requires Deckhouse Kubernetes Platform version 1.74.2 or later. This version includes a fix for quota validation when creating disks.

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.6.1

Release date: March 10, 2026.

Highlights

  • USB devices are discovered on nodes reliably, and a virtual machine with connected USB devices can be cloned.
  • Restored the previous placement of virtual machine dashboards, which could block the Deckhouse queue.

Fixes

Virtual machines

  • Fixed USB device discovery on nodes: corresponding NodeUSBDevice resources might not have been created.
  • Fixed cloning of a virtual machine with connected USB devices when using VirtualMachineOperation with the Clone type in BestEffort mode.

Monitoring

  • Restored the previous placement of virtual machine dashboards due to a validation issue that could block the Deckhouse queue.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2026-24051
    • CVE-2025-15558

v1.6.0

Release date: March 2, 2026.

Highlights

  • USB devices can be attached to virtual machines through .spec.usbDevices, with the NodeUSBDevice and USBDevice resources to manage them.
  • The Virtualization / Overview dashboard shows the state of the virtualization platform as a whole.
  • DVCR is cleaned up daily by default, on a schedule that can be changed in the module configuration.

New features

Virtual machines

  • Added support for attaching USB devices to virtual machines via .spec.usbDevices.
  • Added NodeUSBDevice and USBDevice resources to manage USB devices in the cluster:
    • NodeUSBDevice (cluster-scoped): Represents a USB device discovered on a specific node. Allows assigning a USB device for use in a specific namespace.
    • USBDevice (namespace-scoped): Represents a USB device available for attachment to virtual machines in a given namespace.

Disks and images

  • Enabled DVCR cleanup in clusters by default: daily at 02:00. You can override the schedule via dvcr.gc.schedule in the virtualization module ModuleConfig.

Monitoring

  • Added the Virtualization / Overview dashboard with an overview of the virtualization platform status.
  • Added information about virtual machine pods to the virtual machine dashboard.

Improvements

CLI

  • Added the --from-file flag to the vlctl utility for viewing domain information from a local libvirt XML file.

Fixes

Virtual machines

  • If only the Main network is specified in .spec.networks, the sdn module is no longer required.
  • Fixed virtual machine migration with disks attached via VirtualMachineBlockDeviceAttachment (hotplug): the target pod could exceed memory limits (OOMKilled).
  • Fixed an incorrect Pending phase for the VirtualMachineBlockDeviceAttachment resource during virtual machine migration.
  • To remove disks and images attached to a virtual machine via VirtualMachineBlockDeviceAttachment (hotplug), you must first detach them from the virtual machine by deleting the corresponding vmbda. This information has been added to the vmbda status.

Disks and images

  • Fixed virtual disks hanging during creation in WaitForFirstConsumer mode on nodes with taints.

v1.5.2

Release date: March 5, 2026.

Highlights

  • Creating a virtual disk on NFS no longer risks an OOMKill.

Fixes

Disks and images

  • Fixed a potential OOMKill during the virtual disk creation on NFS.

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.5.1

Release date: February 16, 2026.

Highlights

  • A virtual disk can again be created from a virtual image stored on a PersistentVolumeClaim.

Fixes

Disks and images

  • Fixed an issue with creating a virtual disk from a virtual image stored on a PersistentVolumeClaim (with .spec.storage set to PersistentVolumeClaim).

v1.5.0

Release date: February 9, 2026.

Highlights

  • A virtual machine (VM) can be migrated to a chosen node through a VirtualMachineOperation resource.
  • Resources of system components and the temporary double consumption during migration are no longer counted in project quotas.
  • Fixed several cases where a virtual machine could hang during migration or cloning when the StorageClass changed.

New features

Virtual machines

  • Added the ability to migrate a VM to a chosen node. To do this, create a VirtualMachineOperation resource with the Migrate type and specify the node in .spec.migrate.nodeSelector.

Monitoring

  • Added a table with virtual machine operations to the Namespace / Virtual Machine dashboard.

Improvements

Disks and images

  • When viewing disks, the name of the virtual machine they are attached to is now displayed (d8 k get vd).

Fixes

Virtual machines

  • Fixed an issue with cloning a virtual machine whose disks use storage in WaitForFirstConsumer mode.
  • Fixed a possible virtual machine hang in the Pending state during migration when changing the StorageClass.

Disks and images

  • Fixed an issue with live migration of a virtual machine between StorageClass with the Filesystem type.

Module

  • Fixed an issue with starting virtual machines using the EFIWithSecureBoot bootloader when configured with more than 12 vCPUs.
  • System component resources required for starting and running virtual machines are no longer counted in project quotas.
  • During virtual machine migration, temporary double consumption of resources is no longer counted in project quotas.
  • Platform system components in user projects are protected from deletion by users.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2025-61726
    • CVE-2025-61728
    • CVE-2025-61730
    • CVE-2025-68121

v1.4.1

Release date: February 16, 2026.

Highlights

  • A security update: vulnerabilities in the module’s components are fixed, with no functional changes.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2025-61726
    • CVE-2025-61728
    • CVE-2025-61730
    • CVE-2025-68121

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.4.0

Release date: January 23, 2026.

Highlights

  • Virtual machines with local disks attached through VirtualMachineBlockDeviceAttachment can be migrated, and the StorageClass of such disks can be changed.
  • A virtual machine can be started without the Main network.
  • An image that disappears from DVCR is now reported in the status of the corresponding resource.

New features

Virtual machines

  • Virtual machines can now be started without a Main network.

Disks and images

Fixes

Virtual machines

Disks and images

  • Added tracking of image availability in DVCR. If an image disappears from DVCR, the corresponding VirtualImage and ClusterVirtualImage resources enter the Lost phase and report an error.

Module

  • Fixed project quota accounting for resources used by system components required to create disks/images and operate virtual machines.

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.3.0

Release date: December 16, 2025.

Highlights

  • The default coreFraction for a class of virtual machines can be set in VirtualMachineClass.
  • Attaching a disk in WaitForFirstConsumer mode to a virtual machine became faster.

New features

Virtual machines

  • Added the .spec.sizingPolicies.defaultCoreFraction field to the VirtualMachineClass resource, allowing you to set the default coreFraction for virtual machines that use this class.

Fixes

Disks and images

  • Accelerated disk attachment in WaitForFirstConsumer mode for virtual machines.
  • Fixed an issue with restoring labels and annotations on a disk created from a snapshot.

Monitoring

  • Fixed the display of virtual machine charts in clusters running in HA mode.

Module

  • Added the ability to use system nodes to create project and cluster images.

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.2.2

Release date: December 5, 2025.

Highlights

Fixes

Module

  • Fixed RBAC access permissions for the d8:use:role:user role that prevented it from managing the VirtualMachineOperation resource.

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.2.1

Release date: December 4, 2025.

Highlights

  • Removed a deprecated part of the configuration that could prevent the module from upgrading.

Fixes

Module

  • The deprecated part of the configuration has been removed, which could have prevented the virtualization module from upgrading in clusters running Kubernetes version 1.34 and above.

v1.2.0

Release date: November 28, 2025.

Highlights

  • VirtualMachineSnapshotOperation creates a virtual machine from a snapshot, and the VirtualMachineRestore resource is deprecated.
  • Version v1alpha2 of VirtualMachineClass is deprecated, use v1alpha3.
  • DVCR can be cleaned up of images that no longer exist, and its storage can no longer be shrunk by mistake.
  • Audit events name the virtual machine and the user who acted on it.

New features

Virtual machines

Module

  • Added validation for the virtualization ModuleConfig that prevents decreasing the DVCR storage size and changing its StorageClass.
  • Improved audit events by using more informative messages that include virtual machine names and user information.
  • Added the ability to clean up DVCR from non-existent project and cluster images:
    • By default, this feature is disabled.
    • To enable cleanup, set a schedule in the module settings: .spec.settings.dvcr.gc.schedule.
  • Added new metrics for disks:
    • d8_virtualization_virtualdisk_capacity_bytes: Metric showing the disk size.
    • d8_virtualization_virtualdisk_info: Metric with information about the disk configuration.
    • d8_virtualization_virtualdisk_status_inuse: Metric showing the current use of the disk by a virtual machine or for creating other block devices.

Fixes

Virtual machines

  • Added the ability to modify or delete the VirtualMachineClass resource named “generic”. The virtualization module will no longer restore it to its original state.
  • Fixed the MethodNotAllowed error for patch and watch operations when querying the VirtualMachineClass resource via command-line utilities (d8 k, kubectl).

Disks and images

Module

  • Fixed RBAC for the user and editor cluster roles.
  • Fixed the D8VirtualizationVirtualMachineFirmwareOutOfDate alert, which could be duplicated when virtualization runs in HA mode.

Security

Module

  • Fixed vulnerability CVE-2025-64324.

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.1.3

Release date: November 21, 2025.

Highlights

  • Fixed vulnerabilities in the module’s components.
  • The virtual machine dashboards show more detail about the machines and their pods.

Improvements

Monitoring

  • The virtual machine overview dashboards (Namespace / Virtual Machine and Namespace / Virtual Machines) have been improved: in addition to the cluster level, they are now also available at the project level.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2025-64324
    • CVE-2025-64435
    • CVE-2025-64436
    • CVE-2025-58183
    • CVE-2025-58186
    • CVE-2025-58187
    • CVE-2025-58188
    • CVE-2025-52565
    • CVE-2025-52881
    • CVE-2025-31133

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.1.2

Release date: November 5, 2025.

Highlights

  • Live disk migration works between StorageClasses that use different drivers.
  • A failed live migration now explains in the machine status what went wrong.

Fixes

Virtual machines

  • In the Migrating state, detailed error information is now displayed when a live migration of a virtual machine fails.

Disks and images

  • Fixed live disk migration between StorageClasses that use different drivers. Restrictions:
    • Migration between Block and Filesystem is not supported. Only migrations between the same volume mode are allowed: Block → Block and Filesystem → Filesystem.

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.1.1

Release date: October 16, 2025.

Highlights

  • Disks and images report in their status when the data source is unavailable.
  • Fixed several validation gaps in virtual machine networks and IP addresses.
  • Fixed vulnerabilities in the module’s components.

New features

Monitoring

  • Added Prometheus metrics for virtual machine snapshots (d8_virtualization_virtualmachinesnapshot_info) and virtual disk snapshots (d8_virtualization_virtualdisksnapshot_info), showing which objects they are associated with.

Fixes

Virtual machines

  • Fixed the NetworkReady condition output: it no longer shows the Unknown state and appears only when needed.
  • Prohibited duplicate networks in the virtual machine .spec.network specification.
  • Added validation for static IP addresses to avoid creating a VirtualMachineIPAddress resource with an IP already in use in the cluster.
  • Fixed a bug where, when detaching a virtual image through VirtualMachineBlockDeviceAttachment, the resource could get stuck in the Terminating state.

Disks and images

  • When creating virtual images from virtual disk snapshots, the .spec.persistentVolumeClaim.storageClassName parameter is now respected. Previously, it could be ignored.

Module

  • Fixed an issue in the containerd v2 where storage providing a PVC with the Filesystem type was incorrectly attached via VirtualMachineBlockDeviceAttachment.
  • Added error reporting in the status of disks and images when the data source (URL) is unavailable.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2025-58058
    • CVE-2025-54410

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.1.0

Release date: October 6, 2025.

Highlights

  • Virtual machines (VMs) with disks on local storage can be migrated, and the StorageClass of virtual machine disks can be changed (not available in CE).
  • A virtual machine can be cloned from an existing one through a VirtualMachineOperation resource.
  • New alerts warn about virtual machines on a node that is about to shut down and about DVCR running out of space.

New features

Virtual machines

  • Added the ability to migrate VMs using disks on local storage. Restrictions:
    • The feature is not available in the CE edition.
    • Migration is only possible for running VMs (phase: Running).
    • Migration of VMs with local disks connected via VirtualMachineBlockDeviceAttachment (hotplug) is not supported yet.
  • Added an operation with the Clone type to create a clone of a VM from an existing VM (VirtualMachineOperation .spec.type: Clone).

Disks and images

  • Added the ability to migrate storage for VM disks (change StorageClass). Restrictions:
    • The feature is not available in the CE edition.
    • Migration is only possible for running VMs (phase: Running).
    • Storage migration for disks connected via VirtualMachineBlockDeviceAttachment (hotplug) is not supported yet.

Monitoring

  • Added the KubeNodeAwaitingVirtualMachinesEvictionBeforeShutdown alert, which is triggered when the node hosting the virtual machines is about to shut down but VM evacuation is not yet complete.
  • Added the D8VirtualizationDVCRInsufficientCapacityRisk alert, which warns of the risk of insufficient free space in the virtual machine image storage (DVCR).

Fixes

Virtual machines

  • Fixed an issue in VirtualMachineClass types Features and Discovery that caused nested virtualization not to work on nodes with AMD processors.
  • Fixed behavior when creating a VM snapshot with uncommitted changes: the snapshot now instantly captures the current state of the virtual machine, including all current changes.
  • Fixed garbage collector behavior: previously, all VMOP objects were deleted after restarting the virtualization controller, ignoring cleanup rules.

Monitoring

  • The virtual machine dashboard now displays statistics for all networks (including additional ones) connected to the VM.
  • Fixed the graph on the virtual machine dashboard that displays memory copy statistics during VM migration.

Module

  • Fixed an issue with installing the module on RedOS 8.X OS.
  • Improved validation to prevent adding empty values for parameters that define StorageClass for disks and images.
  • Fixed the controller sometimes starting a restored VM before its disks were fully restored, so the machine started with old, unrestored disks.

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v1.0.0

Release date: September 11, 2025.

Highlights

  • A virtual machine (VM) can be restored from a snapshot through the Restore operation, with the annotations and labels it had at the time of the snapshot.
  • A cloud image in use is protected from being deleted.

New features

Virtual machines

  • Added protection to prevent a cloud image (VirtualImage / ClusterVirtualImage) from being connected as the first disk. Previously, this caused the VM to fail to start with the “No bootable device” error.
  • Added Restore operation to restore a VM from a previously created snapshot.

Fixes

Virtual machines

  • When restoring a virtual machine from a snapshot, all annotations and labels that were present on the resources at the time of the snapshot are now restored correctly.
  • Fixed core/coreFraction validation in the VirtualMachineClass resource.

Module

  • Fixed an issue with queue blocking when the settings.modules.publicClusterDomain parameter was empty in the global ModuleConfig resource.
  • Optimized hook performance during module installation.
  • When the sdn module is disabled, the configuration of additional networks in the VM is not available.

Security

Module

  • Fixed vulnerabilities:
    • CVE-2025-47907

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.

v0.25.0

Release date: August 29, 2025.

Highlights

  • Additional network interfaces of a virtual machine (VM) can be connected to networks provided by the sdn module, with MAC address management through VirtualMachineMACAddress.
  • A VirtualMachineClass can be marked as the default one, so a virtual machine no longer has to name its class.
  • New Prometheus metrics track the phase of snapshots and images.

New features

Virtual machines

  • MAC address management for additional network interfaces has been added using the VirtualMachineMACAddress and VirtualMachineMACAddressLease resources.
  • Added the ability to attach additional network interfaces to a virtual machine for networks provided by the sdn module. For this, the sdn module must be enabled in the cluster.
  • An annotation has been added to set the default VirtualMachineClass. You can designate a VirtualMachineClass as the default by adding the annotation virtualmachineclass.virtualization.deckhouse.io/is-default-class=true. This allows creating VMs with an empty spec.virtualMachineClassName field, which will be automatically filled with the default class.

Monitoring

Improvements

Virtual machines

  • Improved the garbage collector (GC) for completed virtual machine operations:
    • Runs daily at 00:00.
    • Removes successfully completed operations (Completed / Failed) after their TTL (24 hours) expires.
    • Retains only the last 10 completed operations.

Fixes

Virtual machines

  • Fixed an issue where changing the operating system type caused the machine to enter a reboot loop.
  • Fixed an issue where a virtual machine would hang in the Starting phase when project quotas were insufficient. A quota shortage message will now be displayed in the virtual machine’s status. To allow the machine to continue starting, the project quotas need to be increased.

Disks and images

  • To create a virtual image on a PersistentVolumeClaim, the storage must support the RWX and Block modes; otherwise, a warning will be displayed.

Module

  • Added validation to ensure that virtual machine subnets do not overlap with system subnets (podSubnetCIDR and serviceSubnetCIDR).

Upgrade notes

  • During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
  • In version v0.25.0, support for the module’s operation with CRI containerd v2 has been added. After upgrading CRI from containerd v1 to containerd v2, it is necessary to recreate the images that were created using the virtualization module version v0.24.0 or earlier.