The module lifecycle stage: Generally available version
The module has requirements for installation
v1.12.2
Release date: September 30, 2026.Highlights
- Running virtual machines (VMs) no longer restart because of a change in the module settings and no longer show errors of operations that have already finished.
Fixes
Virtual machines
- Enabling the
HotplugMemoryWithLiveMigrationfeature gate no longer restarts running virtual machines. - Fixed the status of an operation still being shown after the operation has actually finished. Now only the operation being performed at the moment is shown.
Module
- Fixed the permissions to view pools of virtual machines for the users whose access is granted through a ClusterAuthorizationRule.
v1.12.1
Release date: September 24, 2026.Highlights
- Updating the module in Deckhouse Platform Open (DP Open) no longer blocks the Deckhouse queue. The release also patches vulnerabilities in the module.
Fixes
Module
- Updating the module in DP Open no longer blocks the Deckhouse queue.
Security
Module
- Fixed vulnerabilities:
- CVE-2026-81870
- CVE-2026-81871
v1.12.0
Release date: September 21, 2026.Highlights
- PCI devices of cluster nodes can now be attached to virtual machines (commercial editions, experimental).
- A virtual machine can now be accessed over a SPICE display, with guest sound, USB redirection from the client and a shared clipboard.
- A node can now be freed by allowing the restart of the virtual machines that cannot be live migrated.
New features
Virtual machines
- Added the ability to attach PCI devices of cluster nodes to virtual machines. The functionality is available in the commercial editions of the platform and is experimental. To use it, the cluster must run Kubernetes
1.34or newer. - Added the SPICE display, which gives a virtual machine the guest sound, USB redirection from the client and a shared clipboard.
- A node can now be freed by allowing the restart of the virtual machines that cannot be live migrated.
- New snapshots of virtual machines and disks are now taken through the
state-snapshottermodule if it is enabled. - The
Migratablecondition now reports that a virtual machine has no node to migrate to. - Added the
OperationInProgresscondition, which reports the operation being performed on a virtual machine and the failure of the last one.
Monitoring
- Metrics now tell which node a virtual machine migrates from and which node it migrates to, and the dashboards show how the migrations in progress are going.
- Added metrics of the launch, shutdown and migration time of a virtual machine and of the disk provisioning time.
- The cluster overview dashboard now also shows the actual CPU, memory and disk space consumption of virtual machines.
- Added the
d8_virtualization_virtualmachine_eviction_requiredmetric about the state of a virtual machine while its node is taken out of service. TheD8VirtualizationVirtualMachineHoldsNodeMaintenancealert names a virtual machine that holds such a node. - The dashboards now show how many virtual machines cannot migrate and which nodes they run on.
- Live migration now reports how long the virtual machine was actually paused.
Improvements
Virtual machines
- VNC now uses less traffic thanks to a better compression of the picture.
Disks and images
- Disks are created from images faster, and a raw image takes several times less space because it is now stored compressed.
Fixes
Virtual machines
- A node no longer waits for a reboot because of a virtual machine pod left on it by a live migration.
- Deleting a virtual machine after its live migration on NFS no longer leaves the machine, its disks and the namespace in
Terminating. - A VirtualMachineOperation of the
Evicttype no longer hangs inTerminatingafter its virtual machine is deleted. - A virtual machine with local disks is no longer reported as non-migratable if its disks can move along with it.
- A virtual machine is no longer left pinned to the node where its local disks used to live.
- A virtual machine whose disk is available on a single node only is no longer reported as migratable.
- Automatic rebalancing no longer tries to evict virtual machines that cannot be live migrated.
- The provisioning secret cannot be deleted while a running virtual machine still needs it.
- A virtual machine on an unresponsive node now reports its state as unknown.
- An additional network is now unplugged from the guest as soon as it is removed from a running virtual machine.
- A virtual machine whose additional network changed its MAC address during creation now starts with all its interfaces.
- A migration now reports at once that it has no suitable node to move the virtual machine to.
Disks and images
- An interrupted image download now fails the import.
- An interrupted disk import now completes on the next attempt.
- A large image import no longer loops because the importer runs out of memory.
- A failed disk or image import now names the reason instead of staying in
Provisioningforever. - An image import blocked by a project quota resumes by itself once the quota is raised.
- Image and disk import and upload now work in Deckhouse projects with an isolated network.
- A virtual machine can now be restored and cloned from a snapshot even if the default storage class of the cluster uses another CSI driver.
- A virtual machine restored from a snapshot on local storage no longer hangs in
Pending. All of its volumes now end up on the same node. - Restoring a disk with a size of zero or less is now rejected with a clear reason.
Monitoring
- The CPU utilization panel of the cluster overview dashboard no longer reports values about a thousand times lower than the real ones.
- The cluster overview dashboard opens with the default Prometheus data source.
- The
D8VirtualizationNodeEvacuationStuckalert no longer fires while a live migration of a virtual machine is running.
Module
- The module no longer stops working because of a VirtualMachineClass created before its installation finished.
- PCI devices are now available in clusters with the legacy
user-authzaccess model.
Security
Virtual machines
- Virtual machine pods now run with the
RuntimeDefaultseccomp profile. A running machine gets it after a restart or a migration.
Module
- Module-reserved labels and annotations are no longer propagated from user resources onto internal objects.
- Fixed vulnerabilities:
- CVE-2026-56854
- CVE-2026-84304
- CVE-2026-84445
Breaking changes
Monitoring
- The
d8_virtualization_virtualmachine_migration_start_time_seconds,d8_virtualization_virtualmachine_migration_end_time_seconds,d8_virtualization_virtualmachine_migration_succeededandd8_virtualization_virtualmachine_migration_failedmetrics moved under thed8_internal_virtualization_kubevirt_prefix. Dashboards and alerts that use them require an update, and the same data is now reported by thed8_virtualization_virtualmachine_migration_infometric. - The
d8_virtualization_virtualmachine_migratablemetric gained thereasonlabel and is no longer dropped to zero by a cordon of a neighbouring node, so alerts matching on its value alone change their meaning.
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.11.1
Release date: September 9, 2026.Highlights
- The release fixes problems with the disks of virtual machines (VMs). It also patches vulnerabilities in the module.
Fixes
Virtual machines
- Attaching and detaching a disk during a migration of a VM now happens after the migration completes.
Disks and images
- A VM now boots from a disk created from a gzip- or xz-compressed image.
Security
Module
- Fixed vulnerabilities:
- CVE-2026-10722
- CVE-2026-33818
- CVE-2026-39821
- CVE-2026-56853
- CVE-2026-56854
- CVE-2026-56858
- CVE-2026-56859
- CVE-2026-56860
- CVE-2026-56862
- CVE-2026-84304
v1.11.0
Release date: August 25, 2026.Highlights
- Physical GPUs can now be attached to virtual machines (EE/SE+, experimental).
- The
Legacytype of.spec.osTyperuns guest operating systems without built-inAHCIandvirtiodrivers, such as Windows XP and Windows Server 2003. - Image upload can now be published through the Gateway API instead of an Ingress.
- A virtual machine with an attached USB device can now be live migrated and evacuated during a node drain.
New features
Virtual machines
- Added the ability to attach physical GPUs to virtual machines. The functionality is experimental and available in the EE/SE+ commercial editions. To enable it, add
GPUto.spec.settings.featureGatesin the ModuleConfig of thevirtualizationmodule; the cluster must run Kubernetes1.34or newer. - Added the
Legacyvalue for.spec.osTypeto support guest operating systems without built-inAHCIandvirtiodrivers, such as Windows XP and Windows Server 2003. - Added the
Autovalue for.spec.cpu.coreFraction. The functionality is available in the EE commercial edition. To enable it, addVerticalVirtualMachineAutoscalerandHotplugCPUAndMemoryWithInPlaceResizeto.spec.settings.featureGatesin the ModuleConfig of thevirtualizationmodule. - The cloud-init configuration can now be detached from a virtual machine without restarting the machine.
- Malformed cloud-init data is now reported as a warning when the resource is created, and in the
ProvisioningReadycondition of an existing resource. - Added the ability to find out who is connected to the serial console or VNC session of a virtual machine and to disconnect them.
- A live migration queued behind concurrency limits now reports which limit is blocking it.
Disks and images
- Images and disks from an HTTP source can now be verified with SHA-1, SHA-512, and GOST R 34.11-2012 (Streebog) checksums.
- Image upload can now be published through the Gateway API instead of an Ingress. This requires the
albmodule; to enable it, addUploadViaAPIGatewayto.spec.settings.featureGatesin the ModuleConfig of thevirtualizationmodule. - Added the
Deletingcondition that reports why a resource is being deleted. - Disk and image import is faster.
Monitoring
- Added metrics export for VirtualMachineClass.
- Added a metric that reports whether a virtual machine can be live migrated.
- Added alerts for unavailable USB passthrough and for required module components missing on some nodes.
Module
- The module’s runtime images have been migrated to a distroless base, which reduces the size of the virtualization image by about 91 MB.
Fixes
Virtual machines
- A virtual machine with an attached USB device can now be live migrated and evacuated during a node drain.
- Detaching a network interface from
.spec.networksno longer leaves a stale interface in the virtual machine’s pod. - The live migration of a virtual machine with additional networks no longer hangs waiting for the network on the target node.
- Fixed a crash loop of a virtual machine with an additional network interface.
- The service components of a virtual machine with Secure Boot no longer hang during its migration.
- Fixed a not-ready image blocking the attachment and detachment of a virtual machine’s disks.
- Fixed image mounts leaking on the target node after a live migration of a virtual machine.
- A virtual machine no longer starts booting before its boot disk is attached.
- Fixed the loss of access to disks when a USB device is attached to a running virtual machine.
- The virtual machine migration queue is no longer blocked when one of the migrations ends abnormally.
- Fixed the force stop of a virtual machine when a regular stop was already in progress.
Disks and images
- Not-ready images and disks no longer hang when deleted while their data is being imported.
- The creation of an image or a disk with a long name no longer hangs.
- A resource with the
Uploadtype that receives no data within 10 minutes moves to theFailedphase with theWaitForUserUploadTimeoutreason. To upload the image, recreate the resource. - Creating a virtual disk from a raw image in the registry onto a block device no longer makes an extra copy of the data.
- The creation of a virtual disk no longer hangs when the target virtual machine runs on dedicated nodes with taints.
- Fixed the restore of a virtual disk from a snapshot on storage that rounds volume sizes up (
ceph-rbd,sds-elastic). - During an image upload, the phase of a ClusterVirtualImage no longer flips back to
Pending.
Monitoring
- Fixed the module’s alerts suppressing the platform alert about unavailable components.
- Alerts now point to the component that failed; a stuck controller queue and a missing leader are tracked separately.
- Removed the metric that reported virtual machines with local disks as impossible to migrate: such machines can be migrated.
Module
- Fixed device handling for virtual machines on cgroup v2 nodes.
- The Deckhouse queue is no longer blocked when the
virtualizationmodule is enabled while its controllers are not ready. - Fixed the renewal of TLS certificates in the virtualization components while the cluster is degraded.
Security
Module
- Fixed vulnerabilities:
- CVE-2025-27144
- CVE-2026-10722
- CVE-2026-34986
- CVE-2026-46600
- CVE-2026-54332
- CVE-2026-54345
- CVE-2026-56852
- CVE-2026-56864
- CVE-2026-56865
- GHSA-gcjh-h69q-9w9g
- GHSA-hrxh-6v49-42gf
- GO-2026-5932
v1.10.5
Release date: September 3, 2026.Highlights
- The release fixes possible data loss during a disk migration and a VM with an attached image that could not be migrated at all. It also patches vulnerabilities in the module.
Fixes
Virtual machines
- An operation on a virtual machine (VM) created without any labels and annotations no longer fails.
- A VM with an attached image can now be live migrated.
- A migration of a VM with a corrupted block device now names the reason and suggests a restart.
- An automatic VM update no longer gives up after the first failed migration and retries it up to three times.
- The service components of a VM are no longer left on the source node after a live migration.
Disks and images
- Fixed possible data loss during a disk migration.
- A disk can be migrated again right after a canceled migration.
- A ClusterVirtualImage no longer returns to the
Pendingphase while it is being uploaded. - A zero-size disk no longer blocks disk operations and VM migrations.
- Fixed the overstated size reported for an image in the
rawformat.
Module
- Fixed an error that kept the module from being enabled on the first attempt.
Security
Module
- Fixed vulnerabilities:
- CVE-2026-56854
- CVE-2026-84304
- GHSA-w67g-5rqw-f597
v1.10.4
Release date: August 28, 2026.Highlights
- The release fixes the cases where a virtual machine (VM) could fail to start because of its own disks. It also patches a vulnerability in the module.
Fixes
Virtual machines
- A VM with disks on SDS storage is now placed on a node with enough space for them.
- Fixed a VM with paravirtualization disabled hanging at startup on a
WaitForFirstConsumerstorage class.
Security
Module
- Fixed vulnerabilities:
- CVE-2026-10722
v1.10.3
Release date: August 24, 2026.Highlights
- Fixed potential data loss during a virtual disk migration.
- Disk hotplug, migrations, and status updates of virtual machines are no longer interrupted by periodic crashes of a service component on the nodes.
- Virtual machines with USB devices are now scheduled only on nodes where USB passthrough is available.
Fixes
Virtual machines
- Fixed an issue where an additional network of a virtual machine was not configured if another network of the same VM had an explicitly specified MAC address.
- Fixed empty launch statistics for virtual machines:
.status.stats.phasesTransitionsand.status.stats.launchTimeDurationare reported again. - Fixed an issue where virtual machines with USB devices could be scheduled on nodes without a USB gateway and then failed to start or started without their USB devices.
Disks and images
- Fixed potential data loss during a virtual disk migration.
- Fixed an issue where a virtual disk storage class migration was canceled if another virtual machine in the same namespace was migrating.
- Fixed a virtual disk export hanging in the
Pendingphase. - Fixed an issue where virtual disk import failed in clusters with containerd image integrity checks enabled.
- Fixed an issue where disks could be unintentionally preempted from the virtual machine node. The priority class of the VM service components is now set according to
.spec.priorityClassof the VM. - The time a virtual disk spends in the
Provisioningphase is no longer counted in.status.stats.creationDuration.waitingForFirstConsumer.
Module
- USB devices are now provided only from nodes where the
usbipkernel modules are known to be available. - Fixed an issue where the Deckhouse queue could be blocked if the
usbipkernel modules could not be installed on a node, including nodes running Astra Linux, ALT Linux, and RED OS. - Fixed disk hotplug, migration, and status update failures caused by
virt-handlercrashing with a fatal error several times a day.
Security
Module
- Fixed vulnerabilities:
- CVE-2026-33818
- CVE-2026-39821
- CVE-2026-54332
- CVE-2026-54345
- CVE-2026-56853
- CVE-2026-56858
- CVE-2026-56859
- CVE-2026-56860
- CVE-2026-56862
- CVE-2026-56864
- CVE-2026-56865
- GHSA-gcjh-h69q-9w9g
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.10.2
Release date: August 3, 2026.Highlights
- USB device passthrough works again on hosts running more than one usbip host controller.
- Enabling the module or changing its version no longer blocks the Deckhouse queue in clusters without the
vertical-pod-autoscalermodule.
Fixes
Module
- Fixed an issue where the task queue would block when enabling a module or changing its version in a cluster without the
vertical-pod-autoscalermodule enabled. The cause was an infinite loop of attempts to delete VPA objects. Instead ofPatchCollector, a separate request is now used that ignores the absence of VPA objects and prevents the queue from being blocked. - Fixed an issue where USB device passthrough to virtual machines was unavailable on hosts where the usbip driver was running more than one virtual host controller.
- Fixed a
CrashLoopBackOfferror in thevirtualization-drapod on hosts with USB devices, caused by starting controller worker processes before the initial connection information had been collected. Initialization now occurs before the workers start, which prevents the error caused by accessing data that has not yet been populated.
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.10.1
Release date: July 29, 2026.Highlights
- The module now requires
sdn0.6.2 or later when thesdnmodule is enabled. - Fixed vulnerabilities in the module’s components.
Fixes
Module
- An optional dependency has been added for the virtualization module, requiring that the
sdnmodule be version 0.6.2 or later. This prevents launching virtualization from running with earlier versions ofsdn. The dependency applies only when thesdnmodule is enabled.
Security
Module
- Fixed vulnerabilities:
- CVE-2026-46600
- CVE-2026-56852
- GHSA-hrxh-6v49-42gf
- CVE-2026-34986
- CVE-2025-27144
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.10.0
Release date: July 23, 2026.Highlights
- VirtualMachinePool (EE/SE+) manages a group of identical virtual machines (VMs) declaratively and scales through the standard
scalesubresource and HPA. - CPU and memory of a running virtual machine can be changed without live migration (in-place resize, behind a feature gate).
- Virtual machine networks moved to eBPF, so additional networks connect more reliably and with lower overhead.
- Live migration became more predictable — a target that never becomes ready no longer holds migration slots, and migration traffic can be routed over a dedicated SystemNetwork.
- Names of virtual disks and images are no longer capped below the Kubernetes limit.
New features
Virtual machines
- Added the VirtualMachinePool resource (EE/SE+) for declarative group management of identical virtual machines. The pool supports scaling via the standard
scalesubresource and HPA. - Added the ability to change CPU and memory of a running VM without live migration (in-place resize). To enable this functionality, add
HotplugCPUAndMemoryWithInPlaceResizeto.spec.settings.featureGatesin the ModuleConfig of thevirtualizationmodule. - Switched VM networks to eBPF, providing more stable connectivity for additional networks with lower overhead.
- VirtualMachineOperation resources can now supersede other active operations on the same VM.
Disks and images
- Added automatic recovery of VirtualImage and ClusterVirtualImage from the
ImageLostphase when the image reappears in DVCR, without re-importing the data. - The VirtualDisk name length limit has been raised from 60 to 253 characters.
- The name length limit has been raised from 49 to 253 characters for VirtualImage and from 48 to 253 for ClusterVirtualImage.
- Added per-namespace authorization for DVCR: image access is isolated between namespaces.
Network
- Added the ability to route live migration traffic over a dedicated SystemNetwork via
liveMigration.networkin the ModuleConfig of thevirtualizationmodule.
Module
- Virtual disks and virtual images in
WaitForFirstConsumermode are created 22% faster. - Added a limit on concurrent inbound live migrations per target node.
- Added the ability to use the module without specifying subnets for the
Mainnetwork. For this, thesdnmodule must be enabled.
Fixes
Virtual machines
- Fixed VM update failures while an image is being attached via VirtualMachineBlockDeviceAttachment (hotplug): VM changes could previously be interrupted at the moment of attachment.
- Fixed flapping of the
VirtualMachineIPAddressReadycondition: guest-agent data now augments rather than clears the VM’s already-known IP address. - Fixed disks and CD-ROMs remaining on the SATA bus after enabling paravirtualization, which prevented unplugging ISO drives from a running VM.
- Fixed a live migration hanging when its target never became ready (
OOMKilled, unschedulable, a disk that never attaches): it now fails by timeout and the migration slots it held are released. - Fixed virtual machines with local disks getting stuck and unable to migrate while a restart was pending; they can now be evacuated, updated, and re-migrated.
- Fixed a false reboot requirement for VMs with only the
Mainnetwork caused by implicit default network template synchronization. - Fixed CPU and memory hotplug updates failing when project quota cannot fit migration-time resources. Such changes now fall back to a restart.
Disks and images
- Fixed Upload-type disks and images getting stuck in
Pendingwhen the upload host certificate becomes invalid, and restored automatic recovery when the upload host changes (for example, afterpublicDomainTemplateis updated). - Fixed PVC storage-type virtual images being attached to virtual machines in read-write mode; they are now attached read-only, like ContainerRegistry storage-type images.
Module
- Closed unauthorized access to the virtualization USB/IP gateway port.
Security
Module
- Fixed vulnerabilities:
- CVE-2026-2303
- CVE-2026-25680
- CVE-2026-25681
- CVE-2026-27136
- CVE-2026-33814
- CVE-2026-39821
- CVE-2026-39822
- CVE-2026-39824
- CVE-2026-39827
- CVE-2026-39828
- CVE-2026-39829
- CVE-2026-39830
- CVE-2026-39831
- CVE-2026-39832
- CVE-2026-39833
- CVE-2026-39834
- CVE-2026-39835
- CVE-2026-41579
- CVE-2026-42502
- CVE-2026-42505
- CVE-2026-42506
- CVE-2026-42508
- CVE-2026-46595
- CVE-2026-46597
- CVE-2026-46598
- GO-2026-5932
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.9.6
Release date: August 3, 2026.Highlights
- USB device passthrough works on hosts with xz- or gzip-compressed usbip kernel modules and with more than one usbip host controller.
Fixes
Module
- Fixed an issue where USB device passthrough to virtual machines was unavailable on hosts where the preinstalled usbip kernel modules were compressed (using xz or gzip). USB device passthrough is now available if kernel modules are compressed using xz or gzip, not just zstd. Also, for Debian, the
linux-modules-extra-${kernel_release}package is now used instead of attempting to install the Ubuntu-specificlinux-modules-extra. - Fixed an issue where USB device passthrough to virtual machines was unavailable on hosts where the usbip driver was running more than one virtual host controller.
- Fixed a
CrashLoopBackOfferror in thevirtualization-drapod on hosts with USB devices, caused by starting controller worker processes before the initial connection information had been collected. Initialization now occurs before the workers start, which prevents the error caused by accessing data that has not yet been populated.
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.9.5
Release date: July 29, 2026.Highlights
- An interrupted delivery of audit logs is now reported instead of failing silently.
- Fixed vulnerabilities in the module’s components.
Fixes
Monitoring
- Fixed an issue where no notification was displayed when the transmission of audit logs was interrupted due to the use of outdated certificate authority data or because the audit resources lacked a certificate and key: when the transmission of audit logs is interrupted, a warning now appears prompting the user to take action.
Module
- An optional dependency has been added for the virtualization module, requiring that the
sdnmodule be version 0.6.2 or later. This prevents launching virtualization from running with earlier versions ofsdn. The dependency applies only when thesdnmodule is enabled.
Security
Module
- Fixed vulnerabilities:
- CVE-2026-46600
- CVE-2026-56852
- GHSA-hrxh-6v49-42gf
- CVE-2026-34986
- CVE-2025-27144
- CVE-2026-39822
- CVE-2026-42505
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.9.4
Release date: July 13, 2026.Highlights
- The audit server starts even when TLS certificate paths are not passed explicitly.
Fixes
Monitoring
- Fixed an issue that prevented the audit server from starting when TLS certificate paths were not passed explicitly.
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.9.3
Release date: July 7, 2026.Highlights
- Images attach to virtual machines (VMs) faster, downloading them from DVCR to the node is no longer slow.
- Deleting a virtual machine with hotplugged images no longer leaves it stuck in the Terminating state.
Fixes
Virtual machines
- Fixed a volume mount leak that could leave a VM with hotplugged images stuck in the Terminating state during deletion.
Module
- Fixed slow downloading of images from DVCR to the node when attaching them to a virtual machine.
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.9.2
Release date: July 1, 2026.Highlights
- Restored live migration throughput and the speed of importing images into DVCR.
- Audit events are no longer lost while the certificate of the
virtualization-auditpod is rotated.
Fixes
Virtual machines
- Fixed reduced throughput during live migration of running virtual machines (VMs) compared to v1.8.3.
Disks and images
- Fixed slow import and upload of images to DVCR when network bandwidth was not the bottleneck.
Monitoring
- Fixed loss of audit events and false
D8LogShipperDestinationErrorsalerts during certificate rotation of thevirtualization-auditpod.
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.9.1
Release date: June 24, 2026.Highlights
- Live migration of virtual machines (VMs) with disks on local storage works again, including after a failed migration.
- Virtual machines with only the Main network no longer request a restart they do not need.
Fixes
Virtual machines
- Fixed live migration of VMs with disks on local storage attached via VirtualMachineBlockDeviceAttachment (hotplug). The target node no longer matches the source node.
- Fixed an issue that prevented a VM from starting after a failed migration of a disk on local storage.
- Fixed a false reboot requirement for VMs with only the
Mainnetwork after upgrading to v1.9.1. Such VMs now do not receive theRestartRequiredstatus if their configuration has not actually changed.
Disks and images
- Fixed cancellation of virtual disk storage class changes and cancellation of local disk migration.
Security
Module
- Fixed vulnerabilities:
- CVE-2026-42504
- CVE-2026-27145
- CVE-2026-42507
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.9.0
Release date: June 10, 2026.Highlights
- Virtual disks, images and additional network interfaces attach and detach without restarting the virtual machine (VM).
- The
coreFractionof a running virtual machine changes without a restart, through live migration. - System virtual machine pods run as the
deckhouseuser, without root privileges. - The deprecated VirtualMachineRestore resource has been removed in favour of VirtualMachineOperation.
New features
Virtual machines
- A restart is no longer required to attach and detach virtual disks and images via the virtual machine’s
.spec.blockDeviceRefs.- Works for new virtual machines starting from v1.9.0.
- For previously created virtual machines, a restart is required to enable this behavior.
- Added the ability to attach additional network interfaces without a restart via the virtual machine’s
.spec.networks. - Added the ability to change
coreFractionon a running VM without a restart. The new value is applied via live migration. - The VM status now includes a “No bootable device” message when the VM cannot find a bootable disk to start.
- Added the
Uptimecolumn to VirtualMachine resources, showing the time since the VM started. - Compatible VirtualMachineOperation resources can now supersede another active operation on the same VM.
- Added the
Attachedcondition andATTACHEDcolumn to the NodeUSBDevice resource, reflecting the USB device’s connection state in the namespace.
Improvements
CLI
- Added the
domain jobsandblock-jobssubcommands to thevlctlutility.
Fixes
Virtual machines
- Fixed VM hanging in the
Startingphase when the StorageClass of a disk withWaitForFirstConsumermode is updated while the VM is stopped. - Fixed scheduling issues for a VM after changing the VirtualMachineClass in the VM spec from the
Discoverytype to another. - Fixed an issue with VM migration cancellation that prevented new migrations from starting.
- Improved Windows guest OS handling in clusters with frequent CPU frequency changes.
Disks and images
- Time spent in the
WaitForFirstConsumerphase is no longer included in.status.stats.creationDuration.totalProvisioningof virtual disks.
Monitoring
- Fixed duplicate series on the
Virtualization / Overviewdashboard.
Module
- Fixed an issue where invalid
virtualizationmodule ModuleConfig settings could block the Deckhouse queue.
Security
Virtual machines
- System virtual machine resources (pods with
d8v-hp-andd8v-vm-prefixes) now run as thedeckhouseuser, without root privileges.
Breaking changes
Virtual machines
- Removed the deprecated VirtualMachineRestore resource. Use VirtualMachineOperation with the
CloneorRestoretype, or VirtualMachineSnapshotOperation instead.
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.8.4
Release date: July 13, 2026.Highlights
- A security update: vulnerabilities in the module’s components are fixed, with no functional changes.
Security
Module
- Fixed vulnerabilities:
- CVE-2026-25680
- CVE-2026-25681
- CVE-2026-27136
- CVE-2026-27145
- CVE-2026-33814
- CVE-2026-39821
- CVE-2026-39827
- CVE-2026-39828
- CVE-2026-39829
- CVE-2026-39830
- CVE-2026-39832
- CVE-2026-39835
- CVE-2026-41579
- CVE-2026-42502
- CVE-2026-42504
- CVE-2026-42506
- CVE-2026-42507
- CVE-2026-42508
- CVE-2026-46595
- CVE-2026-46597
- CVE-2026-53935
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.8.3
Release date: June 3, 2026.Highlights
- Virtual machines (VMs) with additional network interfaces migrate again.
- Hot-unplugging a disk no longer leaves duplicate service pods behind.
Fixes
Virtual machines
- Fixed an issue that blocked virtual machine migration for VMs with additional network interfaces.
- Fixed duplicate service pods (
d8v-hp-*) when hot-unplugging disks from VMs.
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.8.2
Release date: May 20, 2026.Highlights
- A security update: vulnerabilities in the module’s components are fixed, with no functional changes.
Security
Module
- Fixed vulnerabilities:
- CVE-2026-29181
- CVE-2026-33811
- CVE-2026-33814
- CVE-2026-39820
- CVE-2026-39823
- CVE-2026-39825
- CVE-2026-39826
- CVE-2026-39836
- CVE-2026-41520
- CVE-2026-42499
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.8.1
Release date: April 28, 2026.Highlights
- Virtual disks no longer get stuck in the Provisioning state with a StorageClass in WaitForFirstConsumer mode.
- Virtualization dashboards show correct values during virtual machine migration and in HA clusters.
Fixes
Disks and images
- Fixed a potential issue where a virtual disk could get stuck in the
Provisioningstate when using a StorageClass withWaitForFirstConsumermode. - CDI metrics now use
d8_internal_virtualization_kubevirt_cdi_*names, matching other internal virtualization metrics.
Monitoring
- Fixed CPU usage calculation on the virtual machine dashboard in HA clusters, where duplicated controller metrics could affect the displayed value.
Module
- Fixed incorrect resource calculations on the
Virtualization / Overviewdashboard that could occur during virtual machine migration. - Added missing RBAC permissions for virtualization resources, including virtual machine MAC addresses, snapshot operations, and node USB devices.
v1.8.0
Release date: April 22, 2026.Highlights
- The number of CPUs and the amount of memory of a virtual machine can be changed without stopping it manually, the new value is applied through live migration.
- Virtual machine migration uses the host MTU, which speeds up the transfer of the machine’s memory.
- Snapshots are created correctly for a virtual machine without the Main network and while the machine is being migrated.
New features
Virtual machines
- Added the
progressfield to the status of VirtualMachineOperation resources with theEvictandMigratetypes to show operation progress. The correspondingPROGRESScolumn is displayed when runningd8 k get vmop. - Added the ability to change the number of CPUs in a virtual machine without manually stopping it. The new value is applied via live migration. To enable this functionality, add
HotplugCPUWithLiveMigrationto.spec.settings.featureGatesin theModuleConfigof thevirtualizationmodule. - Added initial support for changing virtual machine memory without manually stopping the virtual machine. The new
.spec.memoryvalue is applied via live migration. To enable this functionality, addHotplugMemoryWithLiveMigrationto.spec.settings.featureGatesin theModuleConfigof thevirtualizationmodule.
Fixes
Virtual machines
- Optimized virtual machine migration: it now uses
hostNetwork, allowing the host MTU to be used instead of the pod MTU. - Fixed an issue with an unfrozen filesystem during virtual machine snapshot creation if the freeze occurred during migration.
- Fixed removal of the
Mainnetwork from a virtual machine: the virtual machine no longer uses an IP address from the virtualization CIDR after the network is removed. - Added automatic cleanup of NodeUSBDevice resources that are absent on the node and are not assigned to a namespace or project.
- Fixed snapshot creation for a virtual machine without the
Mainnetwork.
Module
- When uploading disks and images with the
Uploadtype, theWaitForUserUploadphase no longer occurs prematurely while the resource is not yet ready for upload.
Security
Module
- Fixed vulnerabilities:
- CVE-2026-39883
- CVE-2026-32280
- CVE-2026-32281
- CVE-2026-32282
- CVE-2026-32283
- CVE-2026-32288
- CVE-2026-32289
- CVE-2026-34986
- CVE-2026-25679
- CVE-2026-27142
- CVE-2026-27139
- CVE-2026-33186
- CVE-2026-34040
- CVE-2026-33997
v1.7.2
Release date: May 20, 2026.Highlights
- A security update: vulnerabilities in the module’s components are fixed, with no functional changes.
Security
Module
- Fixed vulnerabilities:
- CVE-2026-29181
- CVE-2026-33811
- CVE-2026-33814
- CVE-2026-39820
- CVE-2026-39823
- CVE-2026-39825
- CVE-2026-39826
- CVE-2026-39836
- CVE-2026-41520
- CVE-2026-42499
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.7.1
Release date: April 21, 2026.Highlights
- A virtual machine with a connected USB device now reports what to do for its firmware to be updated, instead of silently staying unavailable for migration.
- Fixed vulnerabilities in the module’s components.
Fixes
Virtual machines
-
To update the firmware on virtual machines with a connected USB device, one of the following actions is required. A corresponding message will appear in the virtual machine status:
- Disconnect the USB device and migrate the virtual machine.
- Restart the virtual machine.
Until then, the virtual machine will continue running, but it will not be available for migration. After either action is completed, the virtual machine will be updated to the current firmware version and will be available for migration again.
Security
Module
- Fixed vulnerabilities:
- CVE-2026-32283
- CVE-2026-27139
- CVE-2026-32289
- CVE-2026-32288
- CVE-2026-32281
- CVE-2026-27142
- CVE-2026-33997
- CVE-2026-33726
- CVE-2026-32282
- CVE-2026-32280
- CVE-2026-25679
- CVE-2026-34040
- CVE-2026-34986
- CVE-2026-39883
- CVE-2026-33186
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.7.0
Release date: March 31, 2026.Highlights
- TCP connections survive live migration of a virtual machine.
- The order of additional network interfaces stays the same across virtual machine restarts.
- USB devices are taken into account when scheduling virtual machines, and their downtime during migration is shorter.
- Block devices can be attached and detached on a cordoned node, and a virtual machine is no longer evicted before its block device pods.
New features
Virtual machines
- The order of additional network interfaces is now deterministic and does not change after virtual machine restarts. For this to work for virtual machines created on earlier versions, they must be restarted.
- Added a mechanism to prevent TCP connection drops during live migration of a virtual machine.
- Reduced USB device downtime during virtual machine migration.
- Added a garbage collector for completed and failed virtual machine pods:
- Pods older than 24 hours are deleted.
- No more than 2 completed pods are retained.
- When scheduling virtual machines on nodes, the system now takes into account whether a USB device uses USB 2.0 (High-Speed) or USB 3.0 (SuperSpeed).
Fixes
Virtual machines
- Fixed double storage quota consumption during migration of a virtual machine with local storage.
- When using VirtualMachineOperation with the
CloneorRestoretype, disks now also restore their association with the virtual machine (owner reference). - Fixed virtual machine eviction during node drain: pods responsible for block device attachments are no longer removed from a cordoned node before virtual machine migration is complete.
- Block devices can now be attached and detached even if the virtual machine is running on a cordoned node.
- Fixed validation for the
AlwaysForcedvirtual machine migration policy: VirtualMachineOperation resources with theEvictorMigratetype without explicitforce=trueare now rejected for this policy. - Fixed an issue where a virtual machine could get stuck in the
Maintenancestate during restore from a snapshot. - Added storage-side error messages (from the CSI driver) to the virtual machine status for block device attachment failures.
- Stabilized USB device support for virtualization on Deckhouse Kubernetes Platform version
>=1.76and Kubernetes version>=1.33. - Fixed USB device detection on the host: duplicate USB devices could previously appear.
Disks and images
- Fixed the creation of block devices from VMDK files (especially for VMDKs in the
streamOptimizedformat used in exports from VMware).
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.6.3
Release date: April 21, 2026.Highlights
- A security update: vulnerabilities in the module’s components are fixed, with no functional changes.
Security
Module
- Fixed vulnerabilities:
- CVE-2026-32283
- CVE-2026-27139
- CVE-2026-32289
- CVE-2026-32288
- CVE-2026-32281
- CVE-2026-27142
- CVE-2026-33997
- CVE-2026-33726
- CVE-2026-32282
- CVE-2026-32280
- CVE-2026-25679
- CVE-2026-34040
- CVE-2026-34986
- CVE-2026-39883
- CVE-2026-33186
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.6.2
Release date: March 23, 2026.Highlights
- The module requires Deckhouse Kubernetes Platform 1.74.2 or later, which fixes quota validation when creating a virtual machine.
Fixes
Module
- The
virtualizationmodule requires Deckhouse Kubernetes Platform version 1.74.2 or later. This version includes a fix for quota validation when creating disks.
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.6.1
Release date: March 10, 2026.Highlights
- USB devices are discovered on nodes reliably, and a virtual machine with connected USB devices can be cloned.
- Restored the previous placement of virtual machine dashboards, which could block the Deckhouse queue.
Fixes
Virtual machines
- Fixed USB device discovery on nodes: corresponding NodeUSBDevice resources might not have been created.
- Fixed cloning of a virtual machine with connected USB devices when using VirtualMachineOperation with the
Clonetype inBestEffortmode.
Monitoring
- Restored the previous placement of virtual machine dashboards due to a validation issue that could block the Deckhouse queue.
Security
Module
- Fixed vulnerabilities:
- CVE-2026-24051
- CVE-2025-15558
v1.6.0
Release date: March 2, 2026.Highlights
- USB devices can be attached to virtual machines through
.spec.usbDevices, with the NodeUSBDevice and USBDevice resources to manage them. - The
Virtualization / Overviewdashboard shows the state of the virtualization platform as a whole. - DVCR is cleaned up daily by default, on a schedule that can be changed in the module configuration.
New features
Virtual machines
- Added support for attaching USB devices to virtual machines via
.spec.usbDevices. - Added NodeUSBDevice and USBDevice resources to manage USB devices in the cluster:
- NodeUSBDevice (cluster-scoped): Represents a USB device discovered on a specific node. Allows assigning a USB device for use in a specific namespace.
- USBDevice (namespace-scoped): Represents a USB device available for attachment to virtual machines in a given namespace.
Disks and images
- Enabled DVCR cleanup in clusters by default: daily at 02:00. You can override the schedule via
dvcr.gc.schedulein thevirtualizationmodule ModuleConfig.
Monitoring
- Added the
Virtualization / Overviewdashboard with an overview of the virtualization platform status. - Added information about virtual machine pods to the virtual machine dashboard.
Improvements
CLI
- Added the
--from-fileflag to thevlctlutility for viewing domain information from a local libvirt XML file.
Fixes
Virtual machines
- If only the
Mainnetwork is specified in.spec.networks, thesdnmodule is no longer required. - Fixed virtual machine migration with disks attached via VirtualMachineBlockDeviceAttachment (hotplug): the target pod could exceed memory limits (
OOMKilled). - Fixed an incorrect
Pendingphase for the VirtualMachineBlockDeviceAttachment resource during virtual machine migration. - To remove disks and images attached to a virtual machine via VirtualMachineBlockDeviceAttachment (hotplug), you must first detach them from the virtual machine by deleting the corresponding
vmbda. This information has been added to thevmbdastatus.
Disks and images
- Fixed virtual disks hanging during creation in
WaitForFirstConsumermode on nodes with taints.
v1.5.2
Release date: March 5, 2026.Highlights
- Creating a virtual disk on NFS no longer risks an OOMKill.
Fixes
Disks and images
- Fixed a potential
OOMKillduring the virtual disk creation on NFS.
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.5.1
Release date: February 16, 2026.Highlights
- A virtual disk can again be created from a virtual image stored on a PersistentVolumeClaim.
Fixes
Disks and images
- Fixed an issue with creating a virtual disk from a virtual image stored on a
PersistentVolumeClaim(with.spec.storageset toPersistentVolumeClaim).
v1.5.0
Release date: February 9, 2026.Highlights
- A virtual machine (VM) can be migrated to a chosen node through a VirtualMachineOperation resource.
- Resources of system components and the temporary double consumption during migration are no longer counted in project quotas.
- Fixed several cases where a virtual machine could hang during migration or cloning when the StorageClass changed.
New features
Virtual machines
- Added the ability to migrate a VM to a chosen node. To do this, create a VirtualMachineOperation resource with the
Migratetype and specify the node in.spec.migrate.nodeSelector.
Monitoring
- Added a table with virtual machine operations to the
Namespace / Virtual Machinedashboard.
Improvements
Disks and images
- When viewing disks, the name of the virtual machine they are attached to is now displayed (
d8 k get vd).
Fixes
Virtual machines
- Fixed an issue with cloning a virtual machine whose disks use storage in
WaitForFirstConsumermode. - Fixed a possible virtual machine hang in the
Pendingstate during migration when changing the StorageClass.
Disks and images
- Fixed an issue with live migration of a virtual machine between StorageClass with the
Filesystemtype.
Module
- Fixed an issue with starting virtual machines using the
EFIWithSecureBootbootloader when configured with more than 12 vCPUs. - System component resources required for starting and running virtual machines are no longer counted in project quotas.
- During virtual machine migration, temporary double consumption of resources is no longer counted in project quotas.
- Platform system components in user projects are protected from deletion by users.
Security
Module
- Fixed vulnerabilities:
- CVE-2025-61726
- CVE-2025-61728
- CVE-2025-61730
- CVE-2025-68121
v1.4.1
Release date: February 16, 2026.Highlights
- A security update: vulnerabilities in the module’s components are fixed, with no functional changes.
Security
Module
- Fixed vulnerabilities:
- CVE-2025-61726
- CVE-2025-61728
- CVE-2025-61730
- CVE-2025-68121
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.4.0
Release date: January 23, 2026.Highlights
- Virtual machines with local disks attached through VirtualMachineBlockDeviceAttachment can be migrated, and the StorageClass of such disks can be changed.
- A virtual machine can be started without the Main network.
- An image that disappears from DVCR is now reported in the status of the corresponding resource.
New features
Virtual machines
- Virtual machines can now be started without a
Mainnetwork.
Disks and images
- Added support for changing the StorageClass of disks attached via VirtualMachineBlockDeviceAttachment (hotplug).
- Added support for migrating virtual machines with local disks attached via VirtualMachineBlockDeviceAttachment (hotplug).
Fixes
Virtual machines
- Fixed IP address attachment when the corresponding VirtualMachineIPAddress resource was created manually in advance.
- Added support for cloning virtual machines in the
Runningphase via VirtualMachineOperation of typeClone.
Disks and images
- Added tracking of image availability in DVCR. If an image disappears from DVCR, the corresponding VirtualImage and ClusterVirtualImage resources enter the
Lostphase and report an error.
Module
- Fixed project quota accounting for resources used by system components required to create disks/images and operate virtual machines.
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.3.0
Release date: December 16, 2025.Highlights
- The default
coreFractionfor a class of virtual machines can be set in VirtualMachineClass. - Attaching a disk in WaitForFirstConsumer mode to a virtual machine became faster.
New features
Virtual machines
- Added the
.spec.sizingPolicies.defaultCoreFractionfield to the VirtualMachineClass resource, allowing you to set the defaultcoreFractionfor virtual machines that use this class.
Fixes
Disks and images
- Accelerated disk attachment in
WaitForFirstConsumermode for virtual machines. - Fixed an issue with restoring labels and annotations on a disk created from a snapshot.
Monitoring
- Fixed the display of virtual machine charts in clusters running in HA mode.
Module
- Added the ability to use system nodes to create project and cluster images.
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.2.2
Release date: December 5, 2025.Highlights
- The
d8:use:role:userrole can manage VirtualMachineOperation resources again.
Fixes
Module
- Fixed RBAC access permissions for the
d8:use:role:userrole that prevented it from managing the VirtualMachineOperation resource.
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.2.1
Release date: December 4, 2025.Highlights
- Removed a deprecated part of the configuration that could prevent the module from upgrading.
Fixes
Module
- The deprecated part of the configuration has been removed, which could have prevented the virtualization module from upgrading in clusters running Kubernetes version 1.34 and above.
v1.2.0
Release date: November 28, 2025.Highlights
- VirtualMachineSnapshotOperation creates a virtual machine from a snapshot, and the VirtualMachineRestore resource is deprecated.
- Version
v1alpha2of VirtualMachineClass is deprecated, usev1alpha3. - DVCR can be cleaned up of images that no longer exist, and its storage can no longer be shrunk by mistake.
- Audit events name the virtual machine and the user who acted on it.
New features
Virtual machines
- The VirtualMachineRestore resource is deprecated. Use the following resources instead:
- VirtualMachineOperation with type
Clone: For cloning an existing virtual machine. - VirtualMachineOperation with type
Restore: For restoring an existing virtual machine to a state from a snapshot. - VirtualMachineSnapshotOperation: For creating a new virtual machine based on a snapshot.
- VirtualMachineOperation with type
- Added the VirtualMachineSnapshotOperation resource for creating a virtual machine based on a VirtualMachineSnapshot.
- For the VirtualMachineClass resource, version
v1alpha2is deprecated. Use versionv1alpha3instead:- In version
v1alpha3, the.spec.sizingPolicies.coreFractionfield is now a string with a percentage (for example, “50%”), similar to the field in a virtual machine.
- In version
- Added detailed error output in the
Attachedcondition of the VirtualMachineBlockDeviceAttachment resource when a block device is unavailable on the virtual machine node.
Module
- Added validation for the virtualization ModuleConfig that prevents decreasing the DVCR storage size and changing its StorageClass.
- Improved audit events by using more informative messages that include virtual machine names and user information.
- Added the ability to clean up DVCR from non-existent project and cluster images:
- By default, this feature is disabled.
- To enable cleanup, set a schedule in the module settings:
.spec.settings.dvcr.gc.schedule.
- Added new metrics for disks:
d8_virtualization_virtualdisk_capacity_bytes: Metric showing the disk size.d8_virtualization_virtualdisk_info: Metric with information about the disk configuration.d8_virtualization_virtualdisk_status_inuse: Metric showing the current use of the disk by a virtual machine or for creating other block devices.
Fixes
Virtual machines
- Added the ability to modify or delete the VirtualMachineClass resource named “generic”. The virtualization module will no longer restore it to its original state.
- Fixed the
MethodNotAllowederror forpatchandwatchoperations when querying the VirtualMachineClass resource via command-line utilities (d8 k,kubectl).
Disks and images
- Fixed an issue that prevented deleting VirtualImage and ClusterVirtualImage resources for a stopped virtual machine.
- Fixed an error that could lead to inconsistencies between VirtualMachineSnapshot and VirtualDiskSnapshot resources when creating a snapshot of a virtual machine with multiple disks.
Module
- Fixed RBAC for the
userandeditorcluster roles. - Fixed the
D8VirtualizationVirtualMachineFirmwareOutOfDatealert, which could be duplicated when virtualization runs in HA mode.
Security
Module
- Fixed vulnerability CVE-2025-64324.
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.1.3
Release date: November 21, 2025.Highlights
- Fixed vulnerabilities in the module’s components.
- The virtual machine dashboards show more detail about the machines and their pods.
Improvements
Monitoring
- The virtual machine overview dashboards (
Namespace / Virtual MachineandNamespace / Virtual Machines) have been improved: in addition to the cluster level, they are now also available at the project level.
Security
Module
- Fixed vulnerabilities:
- CVE-2025-64324
- CVE-2025-64435
- CVE-2025-64436
- CVE-2025-58183
- CVE-2025-58186
- CVE-2025-58187
- CVE-2025-58188
- CVE-2025-52565
- CVE-2025-52881
- CVE-2025-31133
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.1.2
Release date: November 5, 2025.Highlights
- Live disk migration works between StorageClasses that use different drivers.
- A failed live migration now explains in the machine status what went wrong.
Fixes
Virtual machines
- In the
Migratingstate, detailed error information is now displayed when a live migration of a virtual machine fails.
Disks and images
- Fixed live disk migration between StorageClasses that use different drivers. Restrictions:
- Migration between
BlockandFilesystemis not supported. Only migrations between the same volume mode are allowed:Block→BlockandFilesystem→Filesystem.
- Migration between
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.1.1
Release date: October 16, 2025.Highlights
- Disks and images report in their status when the data source is unavailable.
- Fixed several validation gaps in virtual machine networks and IP addresses.
- Fixed vulnerabilities in the module’s components.
New features
Monitoring
- Added Prometheus metrics for virtual machine snapshots (
d8_virtualization_virtualmachinesnapshot_info) and virtual disk snapshots (d8_virtualization_virtualdisksnapshot_info), showing which objects they are associated with.
Fixes
Virtual machines
- Fixed the
NetworkReadycondition output: it no longer shows theUnknownstate and appears only when needed. - Prohibited duplicate networks in the virtual machine
.spec.networkspecification. - Added validation for static IP addresses to avoid creating a VirtualMachineIPAddress resource with an IP already in use in the cluster.
- Fixed a bug where, when detaching a virtual image through VirtualMachineBlockDeviceAttachment, the resource could get stuck in the
Terminatingstate.
Disks and images
- When creating virtual images from virtual disk snapshots, the
.spec.persistentVolumeClaim.storageClassNameparameter is now respected. Previously, it could be ignored.
Module
- Fixed an issue in the containerd v2 where storage providing a PVC with the
Filesystemtype was incorrectly attached via VirtualMachineBlockDeviceAttachment. - Added error reporting in the status of disks and images when the data source (URL) is unavailable.
Security
Module
- Fixed vulnerabilities:
- CVE-2025-58058
- CVE-2025-54410
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.1.0
Release date: October 6, 2025.Highlights
- Virtual machines (VMs) with disks on local storage can be migrated, and the StorageClass of virtual machine disks can be changed (not available in CE).
- A virtual machine can be cloned from an existing one through a VirtualMachineOperation resource.
- New alerts warn about virtual machines on a node that is about to shut down and about DVCR running out of space.
New features
Virtual machines
- Added the ability to migrate VMs using disks on local storage. Restrictions:
- The feature is not available in the CE edition.
- Migration is only possible for running VMs (
phase: Running). - Migration of VMs with local disks connected via VirtualMachineBlockDeviceAttachment (hotplug) is not supported yet.
- Added an operation with the
Clonetype to create a clone of a VM from an existing VM (VirtualMachineOperation.spec.type: Clone).
Disks and images
- Added the ability to migrate storage for VM disks (change StorageClass). Restrictions:
- The feature is not available in the CE edition.
- Migration is only possible for running VMs (
phase: Running). - Storage migration for disks connected via VirtualMachineBlockDeviceAttachment (hotplug) is not supported yet.
Monitoring
- Added the
KubeNodeAwaitingVirtualMachinesEvictionBeforeShutdownalert, which is triggered when the node hosting the virtual machines is about to shut down but VM evacuation is not yet complete. - Added the
D8VirtualizationDVCRInsufficientCapacityRiskalert, which warns of the risk of insufficient free space in the virtual machine image storage (DVCR).
Fixes
Virtual machines
- Fixed an issue in VirtualMachineClass types
FeaturesandDiscoverythat caused nested virtualization not to work on nodes with AMD processors. - Fixed behavior when creating a VM snapshot with uncommitted changes: the snapshot now instantly captures the current state of the virtual machine, including all current changes.
- Fixed garbage collector behavior: previously, all VMOP objects were deleted after restarting the virtualization controller, ignoring cleanup rules.
Monitoring
- The virtual machine dashboard now displays statistics for all networks (including additional ones) connected to the VM.
- Fixed the graph on the virtual machine dashboard that displays memory copy statistics during VM migration.
Module
- Fixed an issue with installing the module on RedOS 8.X OS.
- Improved validation to prevent adding empty values for parameters that define StorageClass for disks and images.
- Fixed the controller sometimes starting a restored VM before its disks were fully restored, so the machine started with old, unrestored disks.
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v1.0.0
Release date: September 11, 2025.Highlights
- A virtual machine (VM) can be restored from a snapshot through the Restore operation, with the annotations and labels it had at the time of the snapshot.
- A cloud image in use is protected from being deleted.
New features
Virtual machines
- Added protection to prevent a cloud image (VirtualImage / ClusterVirtualImage) from being connected as the first disk. Previously, this caused the VM to fail to start with the “No bootable device” error.
- Added
Restoreoperation to restore a VM from a previously created snapshot.
Fixes
Virtual machines
- When restoring a virtual machine from a snapshot, all annotations and labels that were present on the resources at the time of the snapshot are now restored correctly.
- Fixed
core/coreFractionvalidation in the VirtualMachineClass resource.
Module
- Fixed an issue with queue blocking when the
settings.modules.publicClusterDomainparameter was empty in the global ModuleConfig resource. - Optimized hook performance during module installation.
- When the
sdnmodule is disabled, the configuration of additional networks in the VM is not available.
Security
Module
- Fixed vulnerabilities:
- CVE-2025-47907
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
v0.25.0
Release date: August 29, 2025.Highlights
- Additional network interfaces of a virtual machine (VM) can be connected to networks provided by the
sdnmodule, with MAC address management through VirtualMachineMACAddress. - A VirtualMachineClass can be marked as the default one, so a virtual machine no longer has to name its class.
- New Prometheus metrics track the phase of snapshots and images.
New features
Virtual machines
- MAC address management for additional network interfaces has been added using the VirtualMachineMACAddress and VirtualMachineMACAddressLease resources.
- Added the ability to attach additional network interfaces to a virtual machine for networks provided by the
sdnmodule. For this, thesdnmodule must be enabled in the cluster. - An annotation has been added to set the default
VirtualMachineClass. You can designate a VirtualMachineClass as the default by adding the annotationvirtualmachineclass.virtualization.deckhouse.io/is-default-class=true. This allows creating VMs with an emptyspec.virtualMachineClassNamefield, which will be automatically filled with the default class.
Monitoring
- New Prometheus metrics have been added to track the phase of resources such as VirtualMachineSnapshot, VirtualDiskSnapshot, VirtualImage, and ClusterVirtualImage.
Improvements
Virtual machines
- Improved the garbage collector (GC) for completed virtual machine operations:
- Runs daily at 00:00.
- Removes successfully completed operations (
Completed/Failed) after their TTL (24 hours) expires. - Retains only the last 10 completed operations.
Fixes
Virtual machines
- Fixed an issue where changing the operating system type caused the machine to enter a reboot loop.
- Fixed an issue where a virtual machine would hang in the
Startingphase when project quotas were insufficient. A quota shortage message will now be displayed in the virtual machine’s status. To allow the machine to continue starting, the project quotas need to be increased.
Disks and images
- To create a virtual image on a
PersistentVolumeClaim, the storage must support theRWXandBlockmodes; otherwise, a warning will be displayed.
Module
- Added validation to ensure that virtual machine subnets do not overlap with system subnets (
podSubnetCIDRandserviceSubnetCIDR).
Upgrade notes
- During the upgrade to this version, running virtual machines will be automatically migrated to update their firmware version.
- In version v0.25.0, support for the module’s operation with CRI containerd v2 has been added. After upgrading CRI from containerd v1 to containerd v2, it is necessary to recreate the images that were created using the virtualization module version v0.24.0 or earlier.