## Virtuozzo Infrastructure 7.4 (7.4.0-80)

### Overview

This update provides stability and security fixes.

### Fixed issues

- [VSTOR-87519] Storage version bumping could remain disabled until the end of a cluster update, delaying operations such as an SPLA license upgrade.
- [VSTOR-125431] The compute service container could remain stopped on a node after a failed cluster update.
- [VSTOR-126182] Maintenance could be stopped while a cluster update was running, allowing nodes to be rebooted unexpectedly.
- [VSTOR-128648] The admin panel could fail to load with HTTP 500 on secondary high availability nodes after an update.
- [VSTOR-131556] A node already in maintenance before a cluster update could have its compute service re-enabled after the update, allowing VMs to migrate to it.
- [VSTOR-140023] Deleting an S3 bucket with a very large number of objects could be extremely slow; a delete-by-prefix operation is now available.
- [VSTOR-140223] NFSv4 directory metadata operations could intermittently return a remote I/O error immediately after directory creation, disrupting Kubernetes workloads on NFS shares.
- [VSTOR-140228] Workload reports now include the product name and version of applications discovered on Windows VMs.
- [VSTOR-140445] The backup storage could repeatedly replay the same journal without advancing, stalling backup traffic.
- [VSTOR-140477] Workload reports could retain data from the previous host after a VM was live migrated.
- [VSTOR-140619] A security fix for CVE-2026-64531.
- [VSTOR-140678] A security fix for CVE-2026-64561.
- [VSTOR-140904] An empty conflict list could be shown in the UI when the update path included a version that could not be skipped.
- [VSTOR-140988] Supported Kubernetes version limits were not defined for versions 7.3 and later, preventing update eligibility from being validated.
- [VSTOR-141189] The message for a mandatory upgrade step did not specify which version to upgrade to first.

------------------------------------------------------

## Virtuozzo Infrastructure 7.4 (7.4.0-75)

### Overview

This update provides stability and security fixes.

### Fixed issues

- [VSTOR-102068, VSTOR-102069, VSTOR-138302] Creating a VM in a server group could fail with "No valid host found" because a previously canceled or failed VM remained in the server group.
- [VSTOR-120923] VPN could stop working when the StrongSwan process hung.
- [VSTOR-127496] Cluster software updates could fail during the QEMU update step for a running virtual machine.
- [VSTOR-132089] VM migration could allow selecting an unintended target project.
- [VSTOR-135758, VSTOR-137845] A cluster update could fail when the required Leapp packages were missing after earlier upgrades or on non-management nodes.
- [VSTOR-136316] Nodes in maintenance could be force-rebooted during an update when high availability resumed incorrectly.
- [VSTOR-137061] Kubernetes CoreDNS could fail to watch EndpointSlices and log permission errors.
- [VSTOR-137553] A load balancer pool member could be created with the VM's first IP instead of the secondary IP selected in the UI.
- [VSTOR-137564, VSTOR-137769, VSTOR-138203, VSTOR-139197, VSTOR-139419, VSTOR-139498] Cluster reports could fail or be incomplete, including when traffic encryption was enabled.
- [VSTOR-137729] A security fix for CVE-2026-43499.
- [VSTOR-137775] Kubernetes API server certificates could be rejected by clients that enforce strict X.509 validation.
- [VSTOR-137957] Security fixes for CVE-2026-46242 and CVE-2026-43074.
- [VSTOR-137991] Backup gateway multi-source pull migration could leave some files empty.
- [VSTOR-138440] Kubernetes cluster autoscaling could fail to scale up worker nodes.
- [VSTOR-138466] Migration from VMware vCenter could fail when validating a source instance.
- [VSTOR-138572] S3 requests could overload a single namespace service with repeated limit lookups.
- [VSTOR-138675] Deleting a large S3 bucket could overload the namespace service, causing it to terminate.
- [VSTOR-138775] An update for the Acronis Cyber Frame connector.

------------------------------------------------------

## Virtuozzo Infrastructure 7.4

### Overview

This release updates managed Kubernetes to version 1.35.3 and Fedora CoreOS to version 43, introduces API credentials for external automation workflows, and provides the updater patches and tooling required to upgrade the product to version 8.0. It also includes object storage performance improvements, virtual router reliability enhancements, and migration service improvements.

### What's new

#### Compute service

- Kubernetes updated to version 1.35.3. The Fedora CoreOS image used for managed Kubernetes clusters has also been updated to version 43.20260413. This returns managed Kubernetes to a version that is actively supported by the upstream project.

#### Security

- Users can now create API credentials (commonly known as API tokens) for external automation tools such as Terraform, Ansible, and CI/CD pipelines. API credentials are available to every user and can be managed in both the admin and self-service panels.

#### Updates

- Upgrade path to version 8.0. This release includes the updater patches and configuration updates required to perform an in-place upgrade to version 8.0. Hardware support policy has been clarified in relation to the RHEL 10 upstream rebase in version 8.0. A hardware compatibility checker tool is now available on GitHub to verify that your cluster hardware is supported before initiating the upgrade.

### Improvements

- Improved propagation of virtual router and floating IP configuration changes. Virtual router state is now restored more reliably after a cluster outage.
- Optimized performance when adding VMware sources containing hundreds of VMs and improved VM listing efficiency. Added support for migrating VMs located within VMware folders and nested subfolders.
- Certain alerts now take node maintenance mode into account and will not trigger unnecessarily.

### Fixed issues

- [VSTOR-109558] The admin panel could not update nodes added at an older patch level after the cluster was upgraded.
- [VSTOR-120570] The storage agent could hang when accessing failed multipath devices, making nodes unmanageable.
- [VSTOR-128013] Neutron L3 agent router processing could take too long in environments with many routers, causing routing outages.
- [VSTOR-128885] HA destruction could be allowed on mixed-version clusters, leaving compute services in an inconsistent state.
- [VSTOR-129518] The admin panel could remain slow or unresponsive when the backend was overloaded without restarting automatically.
- [VSTOR-130654] Cluster update could fail while moving VMs to the storage mount point if a volume backup was still running for a VM disk.
- [VSTOR-131130] Prometheus could run on all nodes after an update instead of only on management HA nodes.
- [VSTOR-131185] A stability fix for the Intel ice network driver.
- [VSTOR-131859] Self-service UI operations could hang when telemetry endpoints were unreachable.
- [VSTOR-132221] Volume attachment updates could fail after a backup job failed on a removed compute node.
- [VSTOR-133743] Public network ports could be blocked by loop protection during node reboot.
- [VSTOR-134252] Revert to snapshot could be unavailable in the self-service panel for volumes on external storage.
- [VSTOR-134259] Load balancer metrics collection could become extremely slow due to database bloat.
- [VSTOR-134410] VM migration requests could return HTTP 500 when a migration was already in progress.
- [VSTOR-134774] Validating a migration source cloud could time out when credential storage was accessed through an external address that was not available on the cluster network.
- [VSTOR-134950] Security fixes for CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, and CVE-2026-35414 in Kubernetes cluster VM templates.
- [VSTOR-135357] Floating IP connectivity could stop working, making VMs and load balancers unreachable from outside the cluster.
- [VSTOR-136219] Logging in through an identity provider (IdP) to another domain could display the wrong domain while keeping the previous session.
- [VSTOR-137528] A security fix for CVE-2026-53359.